The EBA’s Regulatory Technical Standards Provide the “How” to PSD2’s “What”
February 2017 saw the release of the long-awaited draft regulatory technical standards (RTS) for strong customer authentication (SCA) from the European Banking Authority (EBA). The RTS defines the technical framework for the implementation of PSD2 with primary focus on SCA, and common and secure connection (CSC). In short, we could say that PSD2 covers the “what” aspect of the regulation whereas the RTS defines the “how” this is to be done.
Function over form? European Commission amendments to RTS for SCA
In June, the commission suggested several amendments to the RTS that addressed concerns around the auditing of transaction risk analysis and the addition of a new exemption from SCA for certain corporate payment processes. The amendments also proposed direct access for the EBA to fraud reports from PSPs in addition to aggregated data provided by competent authorities (national financial regulators). Finally, as an additional safeguard for third-party payment service providers (TPPs), the revisions clarified that should the unavailability or inadequate performance of the dedicated communication interface occur, banks would be expected to offer secure communication through user-facing interfaces as a contingency measure.
The final text of the RTS was confirmed on November 27 and submitted to the European Parliament for deliberation before being published in the official journal of the European Union. Scrutiny will begin in earnest in February 2018 and could last between three to six months. With PSD2 on its way in January, the European Commission has confirmed the deadline for compliance to the RTS will actually start in September 2019.
The ratification process up to this point has consisted of a fine balancing act between functional and non-functional requirements, with all parties trying to find a compromise position on the RTS. Depending on which side of the aisle you sit, be it incumbent (banks), TPPs or merchants, there are inevitably good and not-so-good things in the RTS. However, this notion of non-functional requirements (NFRs) is well established in software development and forms the backbone of common standards around which the final RTS rests.
Finding common ground on non-functional requirements
Non-functional requirements of a payments system typically include system performance, availability and security. For a banking application, a major non-functional requirement is availability of the application 24/7 with zero down time. Hardening systems, adding in redundancy, resilience and, above all, added security are all NFRs on which the commission and EBA have been striving to seek common ground.
The security measures outlined in RTS stem from two key objectives of PSD2: “ensuring consumer protection and enhancing competition.” The RTS introduces requirements that payment service providers (PSPs) “must” observe when they process payments or provide payment-related services. In the context of competition and innovation, RTS includes two new types of services, the “so-called payment initiation services” and the account information services.
The commission says it made some “limited substantive amendments” to the draft RTS submitted by the EBA. This was done to “better reflect the mandate of PSD2 and to provide further clarity and certainty to all interested parties.”
PSD2: A quick recap
Looking back at the original brief of PSD2 which set out the framework for the RTS, it is important to remember the main tenets of the directive.
The implementation of PSD2 is intended to make it easier, faster and less expensive for consumers to pay for goods and services by promoting innovation (especially by third-party providers), enhancing payments security and standardizing payment systems across Europe. PSD2 uses three mechanisms to achieve this:
- First, it expands the regulatory purview of the European Union to include new kinds of providers, such as payments initiation and account information services.
- Second, it imposes limitations on transaction fees and stricter rules on refunds to lower transaction costs for consumers.
- Third, and the most disruptive, it requires European banks to open their payments infrastructure and customer data to third-party providers of financial services.
This last mechanism has arguably been the most contentious and the amendments from the commission go some way to easing the burden on corporate players at the very least with regard to direct access. TPPs will be granted consented access to customer information through the banks’ infrastructure to deliver new value-added services.
Ensuring European payment mechanisms are fit for purpose
To enable bank account access (often referred to as payments initiation and account information services, or XS2A for short), banks are required to offer a communication interface for TPP requests. This TPP interface should have the same functionality and deliver the same level of support as for customers transacting directly with their bank. The EBA has suggested the use of ISO 20022 as a potential candidate for the interface format, but the RTS does not provide any prescriptive guidance on how exactly XS2A is to be implemented.
Thankfully, individual country regulators have been issuing implementation and compliant handling guidelines for a few weeks now, so the need to “interpret” the new regulations has been lessened somewhat. Regardless of the adoption challenges ahead, PSD2 and the RTS in particular, are sorely needed to ensure the European payment mechanisms are fit for purpose for the coming decade.
Related Blog Posts
All I Want For Christmas (Or Any Holiday) Is… Instant Payments Gratification
Mark, some of us are fast approaching the end of the holiday shopping season, some of us are fast approaching that time of year when we consume too much egg nog, and some of us are fast approaching too many viewings of Die Hard or It’s a Wonderful Life or Love Actually or Christmas in Connecticut (I’ve disclosed too much about myself). To segue slightly more than slightly, I was at Target over the weekend, braving the holiday shopping crowds, to buy toilet paper, paper towels and tissues… and I took advantage of the 5% off that I get from using my Red Card. I surveyed the throngs of other consumers in the nearby checkout lines and not once did I see another store card. During this, the biggest shopping season of the year, why wouldn’t consumers use loyalty/rewards cards when making purchases?
Fraudsters Don’t Wait for Peak, So Neither Should You: 2019 Fraud Strategy Starts Now!
In existence for barely two decades, eCommerce has transformed not only the way we shop, but also how retailers plan and execute their marketing strategies around the peak shopping season. Now that we’re deep into this period, retailers will have prepared for changes in buyer behaviors, relaxed their strategies to be within the limits of manageable review rate, and most important of all, put strategies in place for increased fraud attempts.
Instant Payments in Italy – And Beyond: Lessons from Il Salone dei Pagamenti
ACI was invited back to Il Salone dei Pagamenti – Italy’s premier payments event organized by the Italian Banking Association (ABI) – to participate in a panel, “SEPA Inst – the Future.” As expected, the session was packed with stats and advice for a more efficient roll out of instant payments – in Italy and beyond.
The Power Behind Payments – Is It Time for the ‘Slow Fintech’ Movement?
According to a freshly-minted piece of research from the Dutch central bank, choosing card payments over cash is not only convenient, it’s also good for the environment. The study considers everything from the origin of cotton that goes into the production of (Euro) banknotes and the environmental impact of armored vehicles to transport cash, through to the energy usage of POS card payment terminals in standby mode.
Women in Payments Australia: 8 Insights for Success
Women in Payments continues to go from strength to strength, expanding its footprint globally and running events from Canada (where it was born) and the U.S., to Australia and now the UK. ACI has been a proud global sponsor of Women in Payments since 2014, which has allowed me personally – along with a number of colleagues around the world – to be a part of the growing calendar of Women in Payments events that take place around the globe.
Cybersecurity: Risks, Controls and What to Expect in 2019
The world of Cybersecurity has brought about several subtle changes in 2018. For example, malware and targeted 'Spear Phishing' were on the rise, while the focus on protecting the perimeter has begun to take a back seat to hardening internal controls. As we enter 2019, the changing threat landscape is certain to result in a barrage of additional considerations in how we protect data and systems.
‘Soup To Nuts’ – A Multi-Layered Fraud Menu for the Holiday Season
The holiday shopping season is well underway, with Black Friday now behind us and many retailers around the world braced for higher levels of eCommerce fraud, from Cyber Monday all the way though until Christmas.
Success Speaks: Exploring the Future of Payments Collections in Auto-Finance with SAFCO
When it comes to improving collections, there’s one simple question your organization should ask before embarking on any type of payments project: what does “customer service” mean to our customers?
How Merchants and Consumers Can Fight Fraud This 2018 Holiday Shopping Season
For International Fraud Awareness Week, I want to bring special focus to the upcoming holiday season around the world. Here in the U.S., the holiday season kicks off with Thanksgiving, which is now only a week away. But as consumers and merchants around the world gear up for peak holiday shopping season, fraudsters are also preparing to triumph.
The ‘Internet of Things’ is the Game-Changing Next Step for Telcos… But What Are They Missing?
As I travel to meet new telcos and attend an array of trade shows around the globe, one discussion that comes up again and again is how the telco industry can gear up for the world of IoT. And it’s not just a topic that telcos are “a bit” interested in – the sector believes that IoT will drive the fourth industrial revolution, likening it in importance to the discovery of steam power.