# PSR Article 85 — Strong customer authentication

Textual state: amended_substantial. 434 words changed; 2 paragraphs removed

- Current text: Council final compromise text (Council document 8221/26) — not yet law.
- Compared against: COM(2023) 367 final — superseded.
- Classification is mechanical; method: https://paymentslaw.eu/method/
- Editorial review state: not_assessed. Markers are curated and selective, not a complete assessment.

Word-level diff, proposal → compromise: `{+text+}` was inserted, `[-text-]` was deleted.

## Paragraph 1

1. A payment service provider shall apply strong customer authentication where the payer: (a) accesses its payment account online; [-(b) accesses payment account information; -](c) places a payment order for an electronic payment transaction; (d) carries out any {+other +}action through a remote channel which [-may -]{+might +}imply a risk of payment fraud or other [-abuses. -]{+abuses, including ordering the creation or replacement of a tokenised payment instrument via a remote channel, increasing its spending limits according to Article 51, changing its password online or changing its contact information online.+}

## Paragraph 2

2. Payment transactions that are [-not -]initiated by the [-payer but by the -]payee [-only -]shall not be subject to strong customer authentication to the extent that those transactions are initiated without any interaction or involvement of the payer. {+Refunds that are initiated by the original payee in favour of the original payer against such transactions shall not be subject to strong customer authentication.+}

## Paragraph 3 (removed)

[-3. Where the payer has given a mandate authorising the payee to place a payment order for a payment transaction or a series of payment transactions through a particular payment instrument that is issued to be used by the payer to place payment orders for the payment transactions, and where the mandate is based on an agreement between the payer and the payee for the provision of products or services, the payment transactions initiated thereafter by the payee on the basis of such a mandate may be qualified as payee initiated transactions, provided that those transactions do not need to be preceded by a specific action of the payer to trigger their initiation by the payee.-]

## Paragraph 4 (removed)

[-4. The payment transactions for which payment orders are placed by the payee that are based on the mandate given by the payer shall be subject to the general provisions that apply to payee-initiated transactions as referred to in Articles 61, 62 and 63.-]

## Paragraph 5

5. Where the mandate of the payer to the payee to place payment orders for {+merchant initiated +}transactions [-referred to in paragraph 3 -]is provided through a remote channel with the involvement of the payment service provider, the setting up of such a mandate shall be subject to strong customer authentication.

## Paragraph 6

6. For direct debits, where the mandate given by the payer to the payee to initiate one or several direct debit transactions is provided through a remote channel with the direct involvement of [-a -]{+the payer’s +}payment service provider in [-the -]setting up of such a [-mandate, strong customer authentication -]{+mandate +}shall be [-applied. -]{+subject to strong customer authentication.+}

## Paragraph 7

7. [-Payment -]{+MOTO +}transactions [-for which payment orders are placed by the payer with modalities other than the use of electronic platforms or devices, such as paper-based payment orders, mail orders or telephone orders, -]shall not be subject to strong customer authentication, [-irrespective of whether or not the execution of the transaction is performed electronically, -]provided that security requirements and checks are carried out by the payment service provider of the payer allowing a form of authentication of the payment transaction.

## Paragraph 8

8. For the remote placement of a payment order as referred to in paragraph 1, point (c), payment service providers shall apply strong customer authentication that includes elements which dynamically link the transaction to a specific amount and a specific payee.

## Paragraph 9

9. For the placement of a payment order as referred to in paragraph 1, point (c), through a payer’s device using proximity technology for the exchange of information with the payee’s infrastructure, the authentication of which requires the use of internet on the payer’s device, payment service providers shall apply strong customer authentication that includes elements which dynamically link the transaction to a specific amount and a specific payee or harmonised security measures of identical effect, which ensure the confidentiality, authenticity and integrity of the amount of the transaction and the payee throughout all of the phases of initiation.

## Paragraph 10

10. For the purposes of paragraph 1, payment service providers shall have in place adequate security measures to protect the confidentiality and integrity of payment service users’ personalised security credentials.

## Paragraph 11

11. Any exemptions from the application of strong customer authentication to be designed by the EBA under Article 89 shall be based on one or more of the following criteria: (a) the level of {+fraud +}risk involved in the service [-provided; -]{+provided, in particular based on the transaction monitoring mechanism as set out in Article 83; +}(b) the amount, the recurrence of the transaction, or both; (c) the payment channel used for the execution of the [-transaction. -]{+transaction, (ca) whether or not the payer is a consumer. Exemptions from the application of strong customer authentication shall not be mandatory. A payment service provider implementing an exemption always retains the right to decide that under the circumstances and based on a risk assessment, strong customer authentication is necessary.+}

## Paragraph 12

12. The two or more elements referred to in Article 3, point (35), on which strong customer authentication shall be based [-do not necessarily -]need to belong to different categories, [-as long as their -]{+except for the category inherence, where payment service provider can implement strong customer authentication using two elements only from this category, if it demonstrates to the national competent authority that the +}independence {+of the elements +}is {+at all times +}fully {+preserved and the authentication procedure ensures at all times a high level of security. The EBA shall develop guidelines by [18 months after entry into force of this Regulation] in accordance with Article 16 of the Regulation 1093/2010 on how to assess that the independence of the two inherence elements is fully +}preserved.
