---
instrument_id: psr
chunk_id: psr_t03_ch07
chunk_title: Operational and security risks and authentication
path: "Title III RIGHTS AND OBLIGATIONS IN RELATION TO THE PROVISION AND USE OF PAYMENT SERVICES > Chapter 7"
source_class: operative_text
document_type: proposal
normative_weight: non_binding
legal_status: council_compromise_text
jurisdiction: EU
effective_period:
  from: null
  to: null
articles_contained:
  - 81
  - 82
  - 83
  - 83a
  - 83b
  - 84
  - 85
  - 85a
  - 86
  - 87
  - 88
  - 88a
  - 89
topics:
  - payments
  - payment_services
  - strong_customer_authentication
  - security
  - operational_resilience
  - fraud_prevention
  - refunds
  - competent_authorities
  - liability
  - data_protection
  - risk_assessment
  - outsourcing
recitals:
  - number: 82
    text: "To assess possible negligence or gross negligence on the part of the payment service user, account should be taken of all the individual circumstances of the case. The evidence and degree of alleged negligence should generally be evaluated according to national law. However, while the concept of negligence implies a breach of a duty of care, ‘gross negligence’ should mean more than mere negligence, involving conduct exhibiting a significant degree of carelessness; for example, keeping the credentials used to authorise a payment transaction beside the payment instrument in a format that is open and easily detectable by third parties. When assessing the possible gross negligence on the part of the payment service user, all the factual circumstances should be taken into account, for example: innovativeness and complexity of the fraud, means or strategies used by third parties to illegally take over the payment service user’s personalised security credentials; whether the payment service user has previously fallen victim to the same type of fraud; in the case of a new type of fraud, whether the payment service providers have complied with their obligations under Article 84, including with regard to their most vulnerable groups of customers; whether the payment service user has taken adequate steps in order to properly ensure the confidentiality of their personalised security credentials; any known characteristics of the payment service user that might make the user more likely to fall victim to fraud; whether the payment service providers offered clear, specific and bespoke warnings to the payer; whether the payment service user failed to have regard to specific, directed interventions made by their payment service provider. This list is not exhaustive, cumulative or binding and does not prejudice the discretion of national or EU courts and/or dispute resolution bodies."
---

# Chapter 7 - Operational and security risks and authentication

## Article 81 - Management of operational and security risks

1. Payment service providers shall establish a framework with appropriate mitigation measures and control mechanisms to manage operational and security risks relating to the payment services they provide. As part of that framework, payment service providers shall establish and maintain effective incident management procedures, including for the detection and classification of major operational and security incidents.

The first subparagraph shall be without prejudice to the application of Chapter II of Regulation (EU) 2022/2554 of the European Parliament and of the Council28 to:

   (a) payment service providers referred to in Article 2(1), points (a), (b) and (d) of this Regulation;

28 Regulation (EU) 2022/2554 of the European Parliament and of the Council of 14 December 2022 on digital operational resilience for the financial sector and amending Regulations (EC) No 1060/2009, (EU) No 648/2012, (EU) No 600/2014, (EU) No 909/2014 and (EU) 2016/1011 (OJ L 333, 27.12.2022, p. 1).

   (b) account information service providers referred to in Article 36(1) of Directive (EU) (PSD3); and

   (c) payment institutions exempted pursuant to Article 34(1) of Directive (EU) (PSD3).

2. The EBA shall promote cooperation, including the sharing of information, in the area of operational and security risks associated with payment services among the competent authorities, between the competent authorities and the ECB and, where relevant, the European Union Agency for Network and Information Security.

## Article 82 - Fraud reporting

1. Payment service providers shall provide, at least on an annual basis, statistical data on fraud relating to different means of payment to their competent authorities. Those competent authorities shall provide the EBA and the ECB with such data in an aggregated form.

Statistical data on fraud shall include the number and value of refunded fraudulent transactions and of transactions where refund has been refused in accordance with this Regulation, together with the reason for that refusal, such as stating that the consumer has acted fraudulently or with gross negligence.

1a. Competent authorities may allow payment service providers to fulfill the obligation in paragraph 1 by reporting fraud data under another data reporting requirement, if that requirement is not less extensive than the reporting requirement under this Article and if arrangements have been made under which the EBA and the ECB will receive the data that is due under this Article.

1b. The EBA and the ECB shall publish in an annual joint report the statistical data in aggregated form and an analysis of the trends observed on the basis of those data.

2. The EBA shall, in close cooperation with the ECB, develop draft regulatory technical standards on statistical data to be provided in accordance with paragraph 1 on the fraud reporting requirements referred to in paragraph 1.

The EBA shall submit the regulatory technical standards referred to in first subparagraph to the Commission by [ OP please insert the date= one year after the date of entry into force of this Regulation]. Power is delegated on the Commission to adopt the regulatory technical standards referred to in the first subparagraph in accordance with Articles 10 to 14 of Regulation (EU) No 1093/2010.

3. The EBA shall develop draft implementing technical standards establishing the standard forms and templates for the submission of the payment fraud data by competent authorities to the EBA, as referred to in paragraph 1. These implementing technical standards shall not be applicable if the competent authority makes use of the option referred to in paragraph 1a.

The EBA shall submit the implementing technical standards referred to in first subparagraph to the Commission by [ OP please insert the date= one year after the date of entry into force of this Regulation]. Power is delegated on the Commission to adopt the implementing technical standards referred to in the first subparagraph in accordance with Article 15 of Regulation (EU) No 1093/2010.

## Article 83 - Transaction monitoring mechanisms

1. Payment service providers shall have transaction monitoring mechanisms in place to:

   (a) support the application of strong customer authentication in accordance with Article 85;

   (b) exempt the application of strong customer authentication based on the criteria under Article 85(11), subject to specified and limited conditions based on the level of risk involved, the types and details of the data assessed by the payment service provider;

   (c) prevent and detect potentially fraudulent payment transactions, including transactions involving payment initiation services.

1a. The payment service provider of the payer shall carry out the transaction monitoring referred to in paragraph 1 prior to the execution of a payment transaction. The payment service provider of the payee shall also carry out transaction monitoring before the funds are made available to the payee in accordance with Article 69(2).

Where a payment service provider does not carry out such monitoring with respect to a transaction and the payer incurs financial damage, that payment service provider shall bear liability.

Where the payer's payment service provider does not provide evidence to the payer that such monitoring for a transaction has been carried out by both providers, it shall refund the payer the amount of the transaction.

The payer shall not bear any financial consequences from that transaction, except where the payer has acted fraudulently.

The burden to prove that there was no breach of this Article shall be on the payment service provider concerned.

1b. Transaction monitoring mechanisms shall be based on the analysis of previous payment transactions and access to payment accounts online.

2. Processing by the payment service provider of the payer shall be limited to the following data, insofar as necessary to achieve the purposes referred to in paragraph 1:

   (a) information on the payer, including the environmental and behavioural characteristics which are typical of the payer in the circumstances of a normal use of the personalised security credentials;

   (b) information on the payment account, including the payment transaction history;

   (c) transaction information, including the transaction amount, payment instrument, currency, date and time of execution, as well as unique identifier of the payee;

   (d) session data, including the device internet protocol address-range from which the payment account has been accessed, from which the transaction was initiated;

   (e) device data, including device identifiers from which the transaction was initiated;

(ea) information on the payee, including the unique identifier of the payee;

(eb) information received through the information sharing arrangements.

2a. Processing by the payment service provider of the payee shall be limited to the following data, insofar as necessary to achieve the purpose referred to in paragraph 1, as applicable:

   (a) information on the payee;

(aa) information received through the information sharing arrangements;

   (b) information on the payment account of the payee, including the payment transaction history;

   (c) transaction information, including the transaction amount, payment instrument, currency, date and time of execution, as well as the name of the payer.

2b. Payment service providers shall not store data referred to in paragraphs 2 and 2a longer than necessary for the purposes set out in paragraph 1, and, in any event, no longer than 5 years after the termination of the customer relationship.

Payment service providers shall ensure that the transaction monitoring mechanisms take into account, at a minimum, each of the following risk-based factors:

   (a) lists of compromised or stolen authentication elements;

   (b) the amount of each payment transaction;

   (c) known fraud scenarios in the provision of payment services;

   (d) signs of malware infection in any sessions of the authentication procedure;

   (e) in case the access device or the software is provided by the payment service provider, a log of the use of the access device or the software provided to the payment service user and the abnormal use of the access device or the software.

## Article 83a - Fraud information sharing

1. Payment service providers shall participate in information sharing arrangements with other payment service providers as referred to in paragraph 3 and shall exchange data to the extent necessary to comply with their obligations in Article 83(1), point (c), where the payment service provider has objectively justified reasons to suspect fraudulent behaviour by a payment service user. The categories of data to be shared shall be limited to the data listed in Article 83(2), points (a) to (ea), and 83(2a), points (a), (b) and (c), to the payment service provider’s objectively justified reasons that gave rise to the suspicion of fraudulent behaviour on basis of that data, and to notifications made by the payment service provider to a provider of hosting services in accordance with Article 16 of Regulation EU/2022/2065. Information on the environmental and behavioural characteristics which are typical of the payer in the circumstances of a normal use of the personalised security credentials shall be excluded from information sharing under this Article.

2. Payment service providers shall implement appropriate technical and organisational measures, including measures to allow pseudonymisation, to ensure a level of security and confidentiality proportionate to the nature and extent of the information exchanged.

3. Payment service providers shall not keep data obtained following the information exchange referred to in paragraph 1 for longer than it is necessary for the purposes laid down in Article 83(1), point (c), and in any case no longer than 5 years after the suspected fraudulent transaction has taken place.

4. The information sharing arrangements shall specify the details of participation and the details of operational elements, including the use of dedicated IT platforms. Before concluding such arrangements, payment service providers shall jointly carry out a data protection impact assessment in accordance with Article 35 of Regulation (EU) 2016/679 and, where applicable, prior consultation of the supervisory authority in accordance with Article 36 of that Regulation.

5. Payment service providers shall not draw conclusions or take decisions that have an impact on a business relationship with the payment service user, such as terminating the contractual relationship with the user or affecting their future onboarding, solely on the basis of information received from other payment service providers who are subject to an information sharing arrangement without having assessed that information.

## Article 83b - Platform on combatting fraud

1. The Commission shall establish a platform on combatting fraud in the area of payments services in the Union (the ‘Platform’). Its composition shall be a broad and balanced mix of representatives and experts from both the public and private sectors, who have proven knowledge and experience in the field of payment services fraud.

2. The Platform shall:

   (a) advise the Commission on developing and monitoring the implementation of legal acts aimed at combatting fraud in the area of payment services;

   (b) issue recommendations to the Commission and the European Board of Digital Services for the purpose of the drawing up of the voluntary code of conduct referred to in Article 59a(2);

   (c) share information on and analyse trends in fraud in the area of payment services;

   (d) share information on measures to combat fraud in the area of payments services, including mitigation measures;

   (e) share information on ways to improve cross-border and cross-sectoral cooperation on the means of combatting fraud in the area of payment services.

3. The Platform shall be chaired by the Commission and constituted in accordance with the horizontal rules on the creation and operation of Commission expert groups.

4. The Platform shall report annually on its activities to the European Parliament, the Council and the Commission.

## Article 84 - Payment fraud risks and trends

1. Payment service providers shall alert their customers via all appropriate means and media when new forms of payment fraud emerge, taking into account the needs of their most vulnerable groups of customers. Payment service providers shall give their customers clear indications on how to identify fraudulent attempts and warn them as to the necessary actions and precautions to be taken to avoid falling victim of fraudulent actions targeting them. Payment service providers shall inform their customers of where they can report fraudulent actions and rapidly obtain fraud-related information.

1a. Member States shall have in place adequate measures with appropriate funding to raise awareness among the public about the trends and new forms of payment fraud, the procedures to be followed in order to identify fraudulent attempts and the rights and obligations conferred by this Regulation relating to fraud. Member States shall ensure that communication measures are sufficient and well-targeted, in particular reaching out to the most vulnerable consumer groups, including younger and older persons and those with low digital skills. Member States shall inform the Commission about the measures taken.

Payment service providers, providers of very large online platforms or of very large online search engines and electronic communications service providers as defined in Article 2(4), point (b), of Directive (EU) 2018/1972 shall cooperate free of charge with the Member States in the measures referred to in subparagraph 1.

2. Payment service providers shall organise at least annually training programmes on payment fraud risks and trends for their employees that are active in designing, maintaining or offering payment services, and shall ensure that their employees are adequately trained to carry out their tasks and responsibilities in accordance with the relevant security policies and procedures to mitigate and manage payment fraud risks.

## Article 85 - Strong customer authentication

1. A payment service provider shall apply strong customer authentication where the payer:

   (a) accesses its payment account online;

   (c) places a payment order for an electronic payment transaction;

   (d) carries out any other action through a remote channel which might imply a risk of payment fraud or other abuses, including ordering the creation or replacement of a tokenised payment instrument via a remote channel, increasing its spending limits according to Article 51, changing its password online or changing its contact information online.

2. Payment transactions that are initiated by the payee shall not be subject to strong customer authentication to the extent that those transactions are initiated without any interaction or involvement of the payer. Refunds that are initiated by the original payee in favour of the original payer against such transactions shall not be subject to strong customer authentication.

5. Where the mandate of the payer to the payee to place payment orders for merchant initiated transactions is provided through a remote channel with the involvement of the payment service provider, the setting up of such a mandate shall be subject to strong customer authentication.

6. For direct debits, where the mandate given by the payer to the payee to initiate one or several direct debit transactions is provided through a remote channel with the direct involvement of the payer’s payment service provider in setting up of such a mandate shall be subject to strong customer authentication.

7. MOTO transactions shall not be subject to strong customer authentication, provided that security requirements and checks are carried out by the payment service provider of the payer allowing a form of authentication of the payment transaction.

8. For the remote placement of a payment order as referred to in paragraph 1, point (c), payment service providers shall apply strong customer authentication that includes elements which dynamically link the transaction to a specific amount and a specific payee.

9. For the placement of a payment order as referred to in paragraph 1, point (c), through a payer’s device using proximity technology for the exchange of information with the payee’s infrastructure, the authentication of which requires the use of internet on the payer’s device, payment service providers shall apply strong customer authentication that includes elements which dynamically link the transaction to a specific amount and a specific payee or harmonised security measures of identical effect, which ensure the confidentiality, authenticity and integrity of the amount of the transaction and the payee throughout all of the phases of initiation.

10. For the purposes of paragraph 1, payment service providers shall have in place adequate security measures to protect the confidentiality and integrity of payment service users’ personalised security credentials.

11. Any exemptions from the application of strong customer authentication to be designed by the EBA under Article 89 shall be based on one or more of the following criteria:

   (a) the level of fraud risk involved in the service provided, in particular based on the transaction monitoring mechanism as set out in Article 83;

   (b) the amount, the recurrence of the transaction, or both;

   (c) the payment channel used for the execution of the transaction,

(ca) whether or not the payer is a consumer.

Exemptions from the application of strong customer authentication shall not be mandatory. A payment service provider implementing an exemption always retains the right to decide that under the circumstances and based on a risk assessment, strong customer authentication is necessary.

12. The two or more elements referred to in Article 3, point (35), on which strong customer authentication shall be based need to belong to different categories, except for the category inherence, where payment service provider can implement strong customer authentication using two elements only from this category, if it demonstrates to the national competent authority that the independence of the elements is at all times fully preserved and the authentication procedure ensures at all times a high level of security. The EBA shall develop guidelines by [18 months after entry into force of this Regulation] in accordance with Article 16 of the Regulation 1093/2010 on how to assess that the independence of the two inherence elements is fully preserved.

## Article 85a - Strong customer authentication in respect of credit transfers

1. By derogation from Article 85(1), point (c), in the context of one or several recurring credit transfers initiated by the payer’s payment service provider in accordance with this Article, the obligation to apply strong customer authentication shall not apply where the following cumulative conditions are met:

   (a) the credit transfers are initiated by the payment service provider of the payer following a request from the payee;
   (b) the payee’s request is based on an agreement between the payer and the payee in which the payment conditions regarding frequency and amounts paid are set out, including where the amounts can vary, the circumstances in which the amounts can vary;
   (c) the payer agrees that its payment service provider executes the respective credit transfers in line with the agreement mentioned in point (b) and the setting up of such agreement is subject to strong customer authentication;
   (d) no additional action is required from the payer to initiate of the respective credit transfers.

2. In the case referred to in paragraph 1, the provisions referred to in Articles 61, 62 and 63 shall apply, with the exception of Article 62(1), fourth subparagraph.

## Article 86 - Strong customer authentication in respect of payment initiation and account information services

1. Article 85(8), (9) and (12) shall also apply where payments are initiated through a payment initiation service provider. Article 85(10) shall also apply where payments are initiated through a payment initiation service provider and when the information is requested through an account information service provider.

2. Account servicing payment service providers shall allow payment initiation service providers and the account information service providers to rely on the authentication procedures provided by the account servicing payment service provider to the payment service user in accordance with Article 85(1) and (10) and, where the payment initiation service provider is involved, in accordance with Article 85(1), (8), (9), (10) and (12).

3. Without prejudice to paragraph 2, where payment account information is accessed by an account information service provider, the account servicing payment service provider shall only apply strong customer authentication for the first access to payment account data by a given account information service provider, but not for the subsequent access to that payment account by that account information service provider unless the account servicing payment service provider has reasonable grounds to suspect fraud.

4. Account information service providers shall apply strong customer authentication when the payment services user accesses the payment account information using that account information service provider at least 180 days after strong customer authentication was last applied. Account information service providers may apply their own or the account servicing payment service provider's strong customer authentication.

## Article 87 - Outsourcing agreements for the application of strong customer authentication

1. The payment service provider of the payer shall enter into an outsourcing agreement with the technical service provider in case that technical service provider is providing and verifying the elements of strong customer authentication.

## Article 88 - Accessibility requirements regarding strong customer authentication

1. Without prejudice to the accessibility requirements under Directive (EU) 2019/882, payment service providers shall ensure that all their customers, including persons with disabilities, older persons, with low digital skills and those who do not have access to digital channels or payment instruments, have at their disposal at least a means, adapted to their specific situation, which enables them to perform strong customer authentication free of charge. In case the payment service user requests help or is in need of assistance, the payment service provider shall ensure that support is provided. This requirement does not extend to providing devices to the payment service user. Payment service providers shall ensure that payment service users are adequately informed about the different means available to them to perform strong customer authentication.

2. Payment services providers shall not make the performance of strong customer authentication dependant on the exclusive use of a single means of authentication and shall not make the performance of strong customer authentication depend, explicitly or implicitly, on the possession of a smartphone or other smart device, unless the payment service user has agreed to the provision of services exclusively through mobile applications on such device. Payment services providers shall develop more than one means for the application of strong customer authentication to cater for the specific situation of all their customers including those referred to in paragraph 1.

## Article 88a - Fair, reasonable and non-discriminatory access to mobile devices

1. Without prejudice to Article 6(7) of Regulation (EU) 2022/1925 of the European Parliament and of the Council of 14 September 2022 on contestable and fair markets in the digital sector and amending Directives (EU) 2019/1937 and (EU) 2020/1828, original equipment manufacturers of mobile devices and electronic communications service providers within the meaning of Article 2(4) of Directive (EU) 2018/1972 shall allow payment service providers and technical services providers acting on their behalf effective interoperability with, and access for the purposes of interoperability to, the technical features, such as hardware features and software features, that are necessary to processing and executing securely payment transactions, on fair, reasonable and non- discriminatory terms.

2. Original equipment manufacturers of mobile devices and electronic communications service providers referred to in paragraph 1 shall not be prevented from taking strictly necessary and proportionate measures to ensure that interoperability does not compromise the integrity of the hardware and software features concerned by the interoperability obligation provided that such measures are duly justified.

3. For the purpose of applying fair, reasonable and non-discriminatory terms pursuant to paragraph 1, original equipment manufacturers of mobile devices and electronic communications service providers referred to in that paragraph shall publish general conditions of effective interoperability and access.

## Article 89 - Regulatory technical standards on authentication, communication and transaction monitoring mechanisms

1. The EBA shall develop draft regulatory technical standards which shall specify:

   (a) the requirements of strong customer authentication as referred to in Article 85;

   (b) the exemptions from the application of Article 85(1), (8) and (9), based on the criteria laid down in Article 85(11);

   (c) the requirements with which security measures have to comply, in accordance with Article 85(10) in order to protect the confidentiality and the integrity of the payment service users’ personalised security credentials;

   (d) the requirements applicable, in accordance with Article 87, to the outsourcing agreements between the payers’ payments service providers and technical service providers concerning the provision and verification of the elements of strong customer authentication by technical service providers;

   (e) the requirements under Title III, Chapter 3 for common and secure open standards of communication for the purpose of identification, authentication, notification, and information, as well as for the implementation of security measures, between account servicing payment service providers, payment initiation service providers, account information service providers, payers, payees and other payment service providers;

   (f) supplementary provisions on secure open standards of communication using dedicated interfaces;

   (g) the technical requirements for transaction monitoring mechanisms referred to in Article 83.

For the purposes of point (b), as regards the exemption from the application of strong customer authentication for payment transactions, based on transaction risk analysis the draft regulatory technical standards shall specify, inter alia:

      (i) the conditions that have to be met for a remote electronic payment transaction to be considered as posing a low level of risk;

      (ii) the methodologies and models to implement transaction risk analysis;

      (iii) the criteria for the calculation of fraud rates, including on the allocation of fraud rates between payment service providers providing issuing and acquiring services, or within payment service providers providing issuing and acquiring services through a single legal entity;

      (iv) detailed and proportionate reporting and audit requirements.

2. When developing the draft regulatory technical standards referred to in paragraph 1, the EBA shall take into account:

   (a) the need to ensure an appropriate level of security for payment service users and payment service providers, through the adoption of effective and risk-based requirements;

   (b) the need to ensure the safety of payment service users’ funds and personal data;

   (c) the need to secure and maintain fair competition among all payment service providers;

   (d) the need to ensure technology and business-model neutrality;

   (e) the need to allow for the development of user-friendly, accessible and innovative means of payment;

(ea) the need to balance fraud risk in a service or economic activity concerned with the consumer experience, in particular with regards to low value transactions;

(eb) whether or not the payers in the transactions are consumers.

The EBA shall submit the draft regulatory technical standards referred to in paragraph 1 to the Commission by [ OP please insert the date= 1 year after the date of entry into force of this Regulation]. Power is delegated on the Commission to adopt the regulatory technical standards referred to in the first subparagraph in accordance with Articles 10 to 14 of Regulation (EU) No 1093/2010.

3. In accordance with Article 10 of Regulation (EU) No 1093/2010, the EBA shall review and, if appropriate, update the regulatory technical standards on a regular basis in order, inter alia, to take account of innovation and technological developments, and the provisions of Chapter II of Regulation (EU) 2022/2554, and the European Digital Identity Wallets implemented under Regulation (EU) No 910/2014.
