EBA · 2019_4556 Final Q&A

Definition of payee for dynamic linking

Regulation
Directive 2015/2366/EU (PSD2)
Article
97
Topic
Strong customer authentication and common and secure communication (incl. access)
Submitted by
Other
Submitted
2019-02-15
Answered
2019-12-20
Answer provided by
ESAs (EBA, ESMA, EIOPA)

Question

Article 5 of the RTS on strong customer authentication and secure communication requires the authentication code to be specific to the amount of the payment transaction and the payee. Does it suffice to include a meaningful part of the identifier into the calculation of the authentication code? For instance, would it suffice to include only numeric characters of the IBAN in the calculation of the authentication code?

Background

This question regularly pops up in discussions about the practical implementation of strong customer authentication. A payee can be identified in multiple ways, such as an International Bank Account Number (IBAN), phone number, name, etc. These identifiers often consist of a mix of alphanumeric characters (A-Z, 0-9). For instance, an IBAN often contains alphabetic characters. Certain authentication devices (e.g. hardware tokens) only allow entry of numeric characters (0-9), and not alphabetic ones (A-Z). As a consequence, the authentication device cannot calculate the authentication code over the precise identifier (e.g. full IBAN).

Answer

Article 5(1) of the Delegated Regulation (EU) 2018/389 states that “where payment service providers apply strong customer authentication in accordance with Article 97(2) of Directive (EU) 2015/2366, in addition to the requirements of Article 4, they shall adopt security measures that meet each of the following requirements: a) the payer is made aware of the amount of the payment transaction and of the payee; b) the authentication code generated is specific to the amount of the payment transaction and the payee agreed to by the payer when initiating the transaction; c) the authentication code accepted by the payment service provider corresponds to the original specific amount of the payment transaction and to the identity of the payee agreed to by the payer; d) any change to the amount or the payee results in the invalidation of the authentication code generated”. In that regard, the authentication code shall be specific to the payee(s) agreed to by the payer. However, the Delegated Regulation does not specify how the payee should be identified for the purpose of the dynamic linking requirements in Article 5, which can be, for instance, through the IBAN (or a similar type of unique identifier). In relation to the above, it would be sufficient to include a meaningful part of the IBAN (or a similar type of unique identifier), or none at all, in the authentication code, provided that the requirements in Article 5(1) of the Delegated Regulation are met.

Original source: European Banking Authority, Q&A ID 2019_4556

This Q&A is published by European Banking Authority and is non-binding. It does not constitute legal advice. Updated weekly from official ESA sources.

Similar Q&As

More Q&As on this topic

📋 Track EU financial regulation continuously

Forseti monitors EU financial regulation and delivers personalised alerts anchored to verified official sources.

14-day free trial. No credit card required.