PaymentsJournal
No Result
View All Result
SIGN UP
  • Commercial
  • Credit
  • Debit
  • Digital Assets & Crypto
  • Digital Banking
  • Emerging Payments
  • Fraud & Security
  • Merchant
  • Prepaid
PaymentsJournal
  • Commercial
  • Credit
  • Debit
  • Digital Assets & Crypto
  • Digital Banking
  • Emerging Payments
  • Fraud & Security
  • Merchant
  • Prepaid
No Result
View All Result
PaymentsJournal
No Result
View All Result

Networks Get 18 Month Reprieve on 2 Factor Authentication for E-Commerce in the UK

By Tim Sloane
August 15, 2019
in Analysts Coverage, Fraud & Security, Security
0
3
SHARES
0
VIEWS
Share on LinkedIn
Networks get 18 month reprieve on 2 Factor Authentication for e-Commerce in the UK

Networks get 18 month reprieve on 2 Factor Authentication for e-Commerce in the UK

The European Banking Administration (EBA) dropped a time bomb on the networks June 21 when it issued the opinion that EMV 3D Secure did not meet the requirements of Strong Customer Authentication (SCA) as required under PSD2.

Now the U.K.’s Financial Conduct Authority has delivered an 18 month reprieve. In contrast, although the EBA has said more time is probably needed, it hasn’t yet offered a similarly broad reprieve, and the September 14 deadline is fast approaching:

“The UK’s financial regulator has agreed to give the country’s payments and e-commerce providers more time to comply with new user authentication rules mandated by PSD2.

The Financial Conduct Authority (FCA) said yesterday that it would provide card issuers, payments firm and online retailers with an 18-month timeline to implement the Strong Customer Authentication (SCA) checks.

This is in line with the opinion of the European Banking Authority (EBA), which recently admitted that more time was needed to implement SCA given its complexity and a lack of preparedness in the market.

Originally set for a September 14 deadline, SCA will force any firms accepting payments online to ensure they apply two-factor authentication checks on their customers. In many cases, this will come in the form of the popular 3-D Secure option.

However, exceptions are made for low value payments (under €30), recurring payments such as subscriptions, customers who have whitelisted merchants they trust, and low-risk transactions. The latter requires a real-time risk assessment on each payment, and therefore advanced fraud screening tools.

The FCA will now not take action if any firms don’t meet the September 2019 deadline, as long as they can demonstrate “there is evidence that they have taken the necessary steps to comply with the plan.”

The EBA has stated that behavioral biometrics meet the SCA requirements for “inherence,” a unique characteristic or attribute that identifies an individual. This suggests that EMV 3D Secure can add a behavioral biometric to the list of data that merchants are required to send to the issuing bank in order to deliver 2 Factor Authentication (2FA).

It remains to be seen if the networks can get a large percentage of transactions to fall under the existing exception criteria. It will be interesting to see if the networks can achieve a low-risk metric for the majority of transactions using the data they do collect under the existing EMV 3D Secure standard when that data is connected to more powerful AI-driven fraud detection methods. If they can, then the inability to enable 2FA becomes less problematic.

Quoted article by Infosecurity Magazine can be found here.

Overview by Tim Sloane, VP, Payments Innovation at Mercator Advisory Group

3
SHARES
0
VIEWS
Share on LinkedIn
Tags: 3D SecureAuthenticationEMVSCAUnited Kingdom

    Get the Latest News and Insights Delivered Daily

    Subscribe to the PaymentsJournal Newsletter for exclusive insight and data from Javelin Strategy & Research analysts and industry professionals.

    Must Reads

    AI in payment collections

    From Data to Action: How Automated Intelligence Is Changing Collections

    September 22, 2026
    circle stablecoin

    As Prepaid Fraud Evolves, So Do the Rules

    September 21, 2026
    bots fraud, bank security in data sharing, J.P. Morgan fraud protection TSYS, 3D Secure 2.0

    The Evolution of 3D Secure Puts it at the Center of Fraud Prevention

    September 18, 2026
    fraud detection signals

    Why Fraudsters Look Trustworthy and Good Customers Look Suspicious

    September 17, 2026
    Fraud Monitoring, Nacha ACH Rules, Same Day ACH

    10 Years Running, Same Day ACH Continues to Break New Ground

    September 16, 2026
    stablecoin infrastructure

    To Unlock Stablecoins’ Potential, Infrastructure Gaps Must Be Resolved

    September 15, 2026
    Latin America payment orchestration

    Navigating Latin America’s Complex Payment Ecosystem

    September 14, 2026
    upi biometric

    Beyond Authentication: Rethinking Digital Identity Security

    September 11, 2026

    Linkedin-in X-twitter
    • Commercial
    • Credit
    • Debit
    • Digital Assets & Crypto
    • Digital Banking
    • Commercial
    • Credit
    • Debit
    • Digital Assets & Crypto
    • Digital Banking
    • Emerging Payments
    • Fraud & Security
    • Merchant
    • Prepaid
    • Emerging Payments
    • Fraud & Security
    • Merchant
    • Prepaid
    • About Us
    • Advertise With Us
    • Sign Up for Our Newsletter
    • About Us
    • Advertise With Us
    • Sign Up for Our Newsletter

    ©2026 PaymentsJournal.com |  Terms of Use | Privacy Policy

    • Commercial Payments
    • Credit
    • Debit
    • Digital Assets & Crypto
    • Emerging Payments
    • Fraud & Security
    • Merchant
    • Prepaid
    No Result
    View All Result