# PSR Article 86 — Strong customer authentication in respect of payment initiation and account information services

Textual state: amended_substantial. 51 words changed

- Current text: Council final compromise text (Council document 8221/26) — not yet law.
- Compared against: COM(2023) 367 final — superseded.
- Classification is mechanical; method: https://paymentslaw.eu/method/
- Editorial review state: not_assessed. Markers are curated and selective, not a complete assessment.

Word-level diff, proposal → compromise: `{+text+}` was inserted, `[-text-]` was deleted.

## Paragraph 1

1. Article [-85(9) -]{+85(8), (9) and (12) +}shall also apply where payments are initiated through a payment initiation service provider. Article 85(10) shall also apply where payments are initiated through a payment initiation service provider and when the information is requested through an account information service provider.

## Paragraph 2

2. Account servicing payment service providers shall allow payment initiation service providers and the account information service providers to rely on the authentication procedures provided by the account servicing payment service provider to the payment service user in accordance with Article 85(1) and (10) and, where the payment initiation service provider is involved, in accordance with Article 85(1), (8), (9), (10) and [-(11). -]{+(12).+}

## Paragraph 3

3. Without prejudice to paragraph 2, where payment account information is accessed by an account information service provider, the account servicing payment service provider shall only apply strong customer authentication for the first access to payment account data by a given account information service provider, [-unless the account servicing payment service provider has reasonable grounds to suspect fraud, -]but not for the subsequent access to that payment account by that account information service [-provider. -]{+provider unless the account servicing payment service provider has reasonable grounds to suspect fraud.+}

## Paragraph 4

4. [-Unless the account servicing payment service provider has reasonable grounds to suspect fraud, account -]{+Account +}information service providers shall apply [-their own -]strong customer authentication when the payment services user accesses the payment account information [-retrieved by -]{+using +}that account information service provider at least 180 days after strong customer authentication was last applied. {+Account information service providers may apply their own or the account servicing payment service provider's strong customer authentication.+}
