# PSR Article 89 — Regulatory technical standards on authentication, communication and transaction monitoring mechanisms

Textual state: amended_substantial. 38 words changed

- Current text: Council final compromise text (Council document 8221/26) — not yet law.
- Compared against: COM(2023) 367 final — superseded.
- Classification is mechanical; method: https://paymentslaw.eu/method/
- Editorial review state: not_assessed. Markers are curated and selective, not a complete assessment.

Word-level diff, proposal → compromise: `{+text+}` was inserted, `[-text-]` was deleted.

## Paragraph 1

1. The EBA shall develop draft regulatory technical standards which shall specify: (a) the requirements of strong customer authentication as referred to in Article 85; (b) the exemptions from the application of Article 85(1), (8) and (9), based on the criteria laid down in Article 85(11); (c) the requirements with which security measures have to comply, in accordance with Article 85(10) in order to protect the confidentiality and the integrity of the payment service users’ personalised security credentials; (d) the requirements applicable, in accordance with Article 87, to the outsourcing agreements between the payers’ payments service providers and technical service providers concerning the provision and verification of the elements of strong customer authentication by technical service providers; (e) the requirements under Title III, Chapter 3 for common and secure open standards of communication for the purpose of identification, authentication, notification, and information, as well as for the implementation of security measures, between account servicing payment service providers, payment initiation service providers, account information service providers, payers, payees and other payment service providers; (f) supplementary provisions on secure open standards of communication using dedicated interfaces; (g) the technical requirements for transaction monitoring mechanisms referred to in Article 83. For the purposes of point (b), as regards the exemption from the application of strong customer authentication for payment transactions, based on transaction risk analysis the draft regulatory technical standards shall specify, inter alia: (i) the conditions that have to be met for a remote electronic payment transaction to be considered as posing a low level of risk; (ii) the methodologies and models to implement transaction risk analysis; (iii) the criteria for the calculation of fraud rates, including on the allocation of fraud rates between payment service providers providing issuing and acquiring services, or within payment service providers providing issuing and acquiring services through a single legal entity; (iv) detailed and proportionate reporting and audit requirements.

## Paragraph 2

2. When developing the draft regulatory technical standards referred to in paragraph 1, the EBA shall take into account: (a) the need to ensure an appropriate level of security for payment service users and payment service providers, through the adoption of effective and risk-based requirements; (b) the need to ensure the safety of payment service users’ funds and personal data; (c) the need to secure and maintain fair competition among all payment service providers; (d) the need to ensure technology and business-model neutrality; (e) the need to allow for the development of user-friendly, accessible and innovative means of [-payment. -]{+payment; (ea) the need to balance fraud risk in a service or economic activity concerned with the consumer experience, in particular with regards to low value transactions; (eb) whether or not the payers in the transactions are consumers. +}The EBA shall submit the draft regulatory technical standards referred to in paragraph 1 to the Commission by [ OP please insert the date= 1 year after the date of entry into force of this Regulation]. Power is delegated on the Commission to adopt the regulatory technical standards referred to in the first subparagraph in accordance with Articles 10 to 14 of Regulation (EU) No 1093/2010.

## Paragraph 3

3. In accordance with Article 10 of Regulation (EU) No 1093/2010, the EBA shall review and, if appropriate, update the regulatory technical standards on a regular basis in order, inter alia, to take account of innovation and technological developments, and the provisions of Chapter II of Regulation (EU) 2022/2554, and the European Digital Identity Wallets implemented under Regulation (EU) No 910/2014.
