Anyone running card deposits in Europe remembers the autumn the approval rate fell off a shelf. The authentication rules under PSD2 came into application in September 2019, national regulators phased in e-commerce enforcement over the following year, and merchants who had been quietly frictionless discovered that a meaningful share of their customers could not complete a bank authentication step on a phone. That is the operational face of a directive most people know only as the reason their banking app pings them.
PSD2 is Directive 2015/2366, applied across the European Union from 13 January 2018, replacing the first payment services directive. Two parts of it matter in practice. One created a licensed right for third parties to reach into bank accounts with the customer's consent. The other, delivered through regulatory technical standards, set the authentication rules that every online payment now runs against.
Third party access, and the two licences that carry it
Before PSD2, a fintech that wanted to read a customer's bank transactions did it by asking for the customer's online banking password and logging in as them. The directive killed that model by creating regulated alternatives. An account information service provider, an AISP, is authorised to read balances and transaction history. A payment initiation service provider, a PISP, is authorised to instruct a payment out of the customer's account after the customer authenticates at their own bank.
Banks have to make that access available and cannot charge the third party for it. Most did so through dedicated interfaces, which is where the phrase open banking comes from, with a fallback obligation if the interface fails to perform. The customer's bank remains the place where identity is proved, so the third party never holds the credentials. Our piece on open banking payments covers how that flow behaves at checkout compared with a card.
An AISP or PISP authorisation is lighter than a full payment institution licence, because these firms do not hold client money. A provider that wants to hold balances and issue accounts needs the heavier permission described in our guide to the EMI licence. Firms routinely confuse the two when they read a provider's website, and the difference decides whose balance sheet your funds sit on.
Strong customer authentication, and what it actually requires
SCA means two independent factors drawn from three categories. Knowledge, something only the customer knows. Possession, something only the customer has. Inherence, something the customer is. Independence matters: if a one-time code arrives on the same phone used to make the payment, the channel must be separated in a way the standards accept, typically through a device-bound app rather than a plain text message.
The authentication also has to be dynamically linked to the specific payment. The amount and the payee are bound into the authentication code, so a customer approving 250 EUR to one merchant cannot have that approval reused for a different amount elsewhere. On cards this is delivered through the 3-D Secure 2 protocol, which is why the modern challenge screen carries the merchant name and amount.
This article describes the rules as they operate. It is not legal advice, and the treatment of any specific business model, including trading firms and prop firms, depends on national implementation and on the position taken by the firm's own acquirer and regulator.
The exemptions, and why your approval rate depends on them
The technical standards allow authentication to be skipped in defined cases. Low value transactions below a small threshold are exempt, subject to cumulative counters that force a challenge after a run of them. Recurring payments of the same amount to the same payee are exempt after the first authentication. A customer can add a merchant as a trusted beneficiary at their own bank. And transaction risk analysis lets an acquirer request an exemption on higher amounts, with the permitted ceiling rising as the acquirer's measured fraud rate falls.
Two details decide whether any of this helps you. First, exemptions are requested by the acquirer and granted by the issuer, so a merchant can only ask. Second, exemptions move liability. A challenged transaction under 3-D Secure 2 generally shifts fraud liability to the issuer, while an exempted one leaves it with the merchant. A firm optimising purely for approval rate can quietly buy itself a chargeback problem, which is the trade-off our article on payment approval rates works through.
What changed for brokers and prop firms
Trading firms sit in a category acquirers watch closely, so the practical effect of PSD2 was to make deposit flows longer and more fragile at exactly the point where a client is most likely to abandon. A funding page that redirects to a bank app, waits, and returns is a different conversion problem from one that takes a card number. Firms respond by widening the rails: bank transfer, open banking initiation, e-wallets and, in some markets, crypto settlement, so a failed card attempt has somewhere to go rather than becoming a support ticket.
The second effect is data. PSD2 gave licensed providers a clean way to read a client's account information with consent, which some firms use for source of funds evidence rather than asking for a PDF statement by email. That is an AML process improvement rather than a payments one, and it only works with a provider that holds the right authorisation in the right country. Where a firm runs several providers side by side, the routing logic and the reconciliation belong in the CRM rather than in a spreadsheet, which is one of the things our Broker CRM is built to hold.
Where the rulebook goes next
The European Commission published proposals in June 2023 for a third payment services directive alongside a Payment Services Regulation. Putting most of the detail in a regulation rather than a directive is the significant move, because a regulation applies directly and leaves less room for the national divergence that made PSD2 compliance a country-by-country exercise. The proposals also tighten bank interface performance obligations and extend fraud reimbursement duties.
Until that completes, PSD2 and its technical standards remain the operative rules, and the United Kingdom continues on its own post-Brexit track with the Payment Services Regulations 2017 and its own open banking framework. Firms building European deposit flows in 2026 should design for authentication as the normal case and treat every exemption as a temporary optimisation that an issuer can decline on any given payment.
"Every firm I meet wants the exemption that removes the challenge screen. What they should ask first is who eats the chargeback once the screen is gone."
— Roman Onta, Executive Director, SINGUARD
Key Takeaways
- PSD2 applied from January 2018 and created two third party roles: AISPs that read account data and PISPs that initiate payments, both with the customer authenticating at their own bank.
- Strong customer authentication needs two independent factors and dynamic linking of amount and payee, delivered on cards through 3-D Secure 2.
- Exemptions are requested by the acquirer and granted by the issuer, and skipping the challenge usually keeps fraud liability with the merchant.
- The PSD3 and Payment Services Regulation proposals from June 2023 would move much of the detail into directly applicable law, reducing country-level divergence.
Frequently Asked Questions
What is strong customer authentication under PSD2?
SCA requires two independent factors from three categories: something the customer knows such as a password, something they possess such as a phone or card, and something they are such as a fingerprint or face scan. The two factors must be independent, so a code sent to the same device where the payment is being made has to be protected by separate device binding to qualify.
Does every payment need SCA?
No. The technical standards list exemptions including low value payments, recurring payments of the same amount to the same payee after the first authentication, trusted beneficiaries added by the customer at their bank, and transaction risk analysis where the acquirer's measured fraud rate is low enough. The issuer decides whether to accept a requested exemption, so an exemption is a request rather than a right.
Is PSD2 still the current EU payments rulebook?
PSD2 remains in force while the European Commission's PSD3 and Payment Services Regulation proposals, published in June 2023, work through the legislative process. The direction of travel is more prescriptive bank interface obligations, tighter rules on fraud reimbursement and a regulation rather than a directive for much of the detail, which would reduce national divergence.