Glossary
SCA (Strong Customer Authentication)

SCA (Strong Customer Authentication)

A regulatory requirement under PSD2 that requires multi-factor authentication for many electronic payments to reduce fraud.

GLOSSARY
What is a
SCA (Strong Customer Authentication)

Strong customer authentication, or SCA, is a rule. Many electronic payments in Europe have to be checked using two separate factors, subject to exemptions and the rules of each market. The factors come from three groups. Something the customer knows, such as a password. Something they hold, such as a phone or a card. Something they are, such as a fingerprint. Two have to come from different groups, so two passwords do not count. That single constraint is what a bank app prompt at checkout exists to satisfy.

The rule comes from PSD2, and the working detail sits in technical standards under it. PSD2 itself sets out the principle, while the standards say what counts as a valid code, how the factors have to stand apart, and when a check may be skipped. The UK kept the substance after leaving the EU through its own rules, and the two texts have been drifting apart since, so the market a payment belongs to decides which version applies.

The Three Groups, And Why They Are Separate

Keeping them apart is the bit teams get wrong. A code sent by text and typed into the same phone that is making the payment is weaker than it looks, since one stolen device beats both factors at once. The standards ask for factors separate enough that breaking one does not break the other. So a bank app prompt on a second device, or a card reader, tends to be viewed more kindly than a code on its own.

Tying The Code To One Payment

For an online payment, the code has to be tied to the exact amount and the exact payee, and a change to either has to kill it. That trait is usually called dynamic linking. It is what stops a code caught for one payment being used again on another. In practice it means the customer sees the amount and the recipient on the screen where they approve, which is also the point at which a fraud attempt tends to become visible to them.

The Carve-Outs Are Where The Money Is

Most of the commercial interest sits in when a check can be skipped, not in the check itself. Low value payments can qualify, and so can trusted payees, repeat payments of a fixed amount, and payments judged low risk. Article 18 sets out the transaction risk analysis route, with its own thresholds. Using an SCA exemption well means knowing which one applies and who carries the risk when it is used.

Who Can Claim An Exemption

Both the acquiring side and the issuing side have a say, and the issuer has the final one. A business can ask for an exemption on a payment, and the issuing bank can still decide it wants the customer checked. So an exemption plan is a matter of odds, not control. Tracking how often the asks are honoured, by issuer and by market, beats assuming the request settles it.

What Happens When The Check Is Missing

An issuer that expects a check and does not get one will often send back a soft decline instead of a flat refusal. That is an invitation to try again with the customer checked. Treating it as a hard failure can throw away a payment that might have gone through. Handling this well can be a valuable fix at checkout.

Liability Moves With The Check

Where a payment is properly checked, the fraud risk generally shifts towards the issuing bank under a liability shift. Rules vary by card network and are updated from time to time, so merchants should confirm the current position with their acquirer or the card scheme. The commercial consequence is that a challenge is not only a friction cost. It also changes who pays when a payment turns out to be fraudulent.

The Factors In Practice

A one-time password is still common, often sent as an SMS OTP. Bank apps with a fingerprint check have been taking its place where the bank has one. Whatever the method, it rests on user authentication at the bank, not at the merchant. A merchant cannot fix a poor bank flow, though it can often route around one.

Measuring The Cost Of A Challenge

A challenge that customers walk away from is a lost sale. The number worth watching is how many challenged shoppers go on to finish. Split it by issuer and by market, since the spread between banks is usually wider than the spread between checkouts. Reading that next to the approval rate shows whether a tighter policy earned anything.

Cutting Friction Without Breaking Rules

Work out which markets you trade in and which text applies in each. Get the check working cleanly before trying to avoid it. Learn the carve-outs and track which ones your provider claims for you, since you carry the consequences. Treat a soft decline as a retry with a check, not a dead sale. Watch challenge completion by issuer, not as one blended figure. And date any internal note quoting a threshold, because the standards are revised. This piece on smart 3D Secure covers the practical side, and this guide on whether an industry needs 3DS covers the trade by sector.

‍

Table of contents

Frequently Asked Questions

Which payments need strong customer authentication?

Broadly, electronic payments where both the payer's and the payee's providers are inside the relevant area, along with customer access to a payment account. Scope and carve-outs differ by jurisdiction, so the applicable rules decide the answer for a given market.

What counts as two separate factors?

The factors come from three groups: something the customer knows, something they hold, and something they are. Two are needed, and they have to come from different groups, so a password plus a security question is a single group used twice.

Does a 3D Secure card payment satisfy the rules by itself?

Not by itself. The check has to involve two qualifying factors and be linked to the specific amount and payee. A frictionless 3D Secure flow may rely on an exemption rather than a completed challenge, which is a different basis.

Who is liable if authentication is skipped?

Liability depends on the rules that apply, including who requested or applied an exemption and the relevant card scheme rules. Where an exemption is claimed on the merchant's side and the payment later proves fraudulent, the loss may fall on the acquirer or merchant under the contract, so the position is worth confirming with the acquirer.

Can a business reduce how often customers are challenged?

Yes, within limits. Exemptions cover low-value payments, trusted payees, some recurring charges and low-risk transactions under transaction risk analysis. Each has conditions, and overusing them can push a provider's fraud rate above the threshold that allows them.

Still Have Questions?

Let’s Find the Right Solution for You

Share this article
Glossary

Stay Connected with Us!

Follow us on social media to stay up to date with the latest news, updates, and exclusive insights!