Glossary
RTS (Regulatory Technical Standards)

RTS (Regulatory Technical Standards)

RTS (Regulatory Technical Standards) are detailed rules under PSD2 that define how Strong Customer Authentication (SCA) and secure communication must be implemented.

GLOSSARY
What is a
RTS (Regulatory Technical Standards)

Regulatory technical standards, usually shortened to RTS, are the detailed rules that sit under a piece of European financial law and say how it works in practice. The law itself sets out the aim. The RTS says what counts as meeting it. In payments the set that matters most is the one under PSD2. It covers strong customer checks and the access banks have to give licensed third parties. That is the document a team ends up reading when the law itself turns out to be too general to build from.

The split exists because law is slow and technology is not. A directive takes years to agree and longer to change, while the detail of what makes a valid authentication code has to move faster than that. So the principles sit in the law. The detail you can build from sits in standards drafted by a supervisor, adopted on their own, and revised as needed. The EBA holds the wider body of rules together in its single rulebook tool.

Where They Sit In The Stack

Think of three layers. The directive is the top one and states the aims, and in payments that is the PSD2 directive. The RTS is the middle layer and gives the working rules. Then come guidance, supervisory statements and scheme rules, which fill in what the standards leave open. A question that looks unanswered at the top is usually answered a layer down. Teams that read only the directive end up guessing.

What The Payments RTS Actually Covers

Two things, mainly. The first is the customer check: what counts as a valid factor, how the factors have to stand apart from each other, and how a code has to be tied to the amount and the payee. The second is access: what a bank has to offer a licensed third party and on what terms. Article 30 sets out those access duties. They include publishing the technical detail free of charge, giving notice before changes, and offering a way to test before launch.

The Carve-Outs Live Here Too

Most of the commercial interest in the RTS is in the carve-outs, not the duties, because they decide how many shoppers face a challenge. Low value payments, trusted payees, repeat payments and payments judged low risk can all qualify under conditions. Article 18 sets out the risk analysis route. Using an SCA exemption well means knowing which one applies and who carries the risk when it is used.

The Figures Are In The Standards, Not The Law

Thresholds, counters and time limits all sit at this layer, which is exactly why they are here and not in the directive. They can be revised without reopening the law, and they differ once you cross a border. So any internal note quoting a specific figure should carry the date it was written and a link to the source. An undated summary of a threshold is a very easy way for a team to end up building against a rule that has moved.

Why UK And EU Rules Have Drifted

The UK kept the substance of PSD2 after leaving the EU, through its own payment services rules, and the technical standards came across with it. The two sets started the same and have not stayed that way, since each is now revised by a different body on its own schedule. A firm trading in both cannot read one across to the other, and local jurisdiction is the theme that keeps returning.

What It Means For A Merchant

Plenty of merchants go their whole career without reading an RTS and are shaped by one daily. The bank app prompt at checkout, the cases where no prompt appears, the data a provider asks for and the reason a payment was challenged all trace back to this layer. Where a business takes bank based payments, the same standards are what oblige the bank to keep a working route open. That is what turns a payment initiation service provider into a product you can buy.

Reading Them Without A Law Degree

They are shorter and plainer than people expect, and the articles are numbered so you can go straight to the one you need. Read the article, then check whether it has been amended, then check whether your market has its own version. Where the wording is really unclear, the supervisor's own guidance usually deals with it. What does not work is relying on a summary written by somebody else two years ago, which is how most of the wrong answers in this area start.

Working From The Standards Themselves

Read the article itself, not a summary of it, and date anything you write down. Check the version in force in each market you trade in, since the UK and EU texts have separated. Track which carve-outs your provider claims on your behalf, because you carry the consequences. Watch how many shoppers finish a challenge as closely as you watch approval rate. Ask your provider which text it is building against. And treat bank based payments as an option to test, since the same standards are what make them work. Open banking payments covers that side, and this guide on whether a business is ready for open banking is a sensible first read.

‍

Table of contents

Frequently Asked Questions

Are the RTS the same thing as PSD2?

No. PSD2 is the directive and sets out the aims, while the regulatory technical standards sit underneath it and give the working detail, including what counts as a valid authentication factor and what banks have to offer licensed third parties. Teams that read only the directive tend to find their question unanswered, because the answer is usually a layer further down.

Where do the actual thresholds and figures sit?

In the standards rather than in the law, which is precisely why they are there. Putting them at this level means they can be revised without reopening the directive. It also means they differ once you cross a border and change over time, so any internal note quoting a figure should carry a date and a link to the source it came from.

Do UK and EU standards still say the same thing?

They started the same and have been diverging since, because each is now revised by a different authority on its own timetable. A firm trading in both cannot read one across to the other and assume it holds. Working out which text applies in each market, and noting when each was checked, avoids building against a rule that has since moved.

Which parts matter most commercially?

The exemptions, for a merchant. They determine how many shoppers face an authentication challenge, and therefore how many complete the purchase. The conditions attached to each one, and the question of who carries the fraud risk when an exemption is used, are set out at this level and are worth understanding rather than leaving wholly to a provider.

Does a merchant need to read them directly?

Not usually in full, though going to the article itself beats relying on a summary written by someone else two years ago. The articles are numbered and shorter than most people expect, so checking the specific one behind a decision is quick. Confirming with your provider which version it builds against is the other half of the same question.

Still Have Questions?

Let’s Find the Right Solution for You

Share this article
Glossary

Stay Connected with Us!

Follow us on social media to stay up to date with the latest news, updates, and exclusive insights!