Skip to main content

Industrial digital economy

Strong customer authentication: when the rules let it go

AuthenticationPayments & FintechPublished

Nothing about online payment irritates people more reliably than being asked to authenticate a two-euro purchase while a four-hundred-euro one goes through untouched. The pattern looks arbitrary and is not. It follows a small set of exemptions in a delegated regulation, each with conditions, and once the conditions are visible the behaviour of every checkout becomes predictable.

The rule being excepted from is the requirement to apply strong customer authentication to electronic payments: two independent elements from different categories, one of which the payer knows, has or is. The detail lives in Commission Delegated Regulation (EU) 2018/389, the regulatory technical standards that supplement the second payment services directive. Its third chapter is a list of exemptions, and four of them account for almost everything a consumer encounters.

Low value, with a running total

Article 16 is the one most people have met without knowing it. It permits authentication to be skipped for a remote electronic payment where the amount does not exceed thirty euro — and where either the cumulative total of previous exempted remote payments since the last authentication does not exceed one hundred euro, or the number of such consecutive transactions does not exceed five.

That structure is the explanation for a common experience. Several small purchases pass without a prompt and then one of them asks for a code, for no apparent reason. The counter has reached its limit. The next authentication resets it, and the sequence starts again.

Risk analysis, which is where the big ones hide

Article 18 allows an exemption where the provider's transaction monitoring classifies a payment as low risk. The conditions are cumulative: real-time analysis must show no abnormal spending pattern, no unusual device or access information, no sign of malware in the session, and the amount must be below an exemption threshold value. Article 19 sets out how the fraud rate is to be calculated, and the Annex to the regulation pairs each threshold value with a reference fraud rate the provider must be at or below to use it.

The mechanism in that table is worth understanding even without reading the numbers: the better a provider's own fraud record, the higher the value it may wave through. It is a regime that rewards institutions for their own measured performance, and it is audited — a provider relying on this exemption has to have its methodology and reported rates reviewed, periodically by an independent external auditor.

This is also the answer to the four-hundred-euro purchase that sailed through. It was not exempt because it was large. It was exempt because the provider's monitoring scored it and the provider's fraud rate entitles it to score things that size.

Corporate processes and recurring payments

Article 17 covers payment processes and protocols made available only to payers that are not consumers, where the competent authority is satisfied the arrangement achieves at least equivalent security. This is why corporate treasury systems and lodged-card travel arrangements behave differently from a retail checkout, and why consumers cannot opt into the same treatment.

Recurring payments of the same amount to the same payee are treated separately: authentication applies to the first one, and the series that follows does not require it. The condition is that the amount and the payee stay the same, which is why a subscription whose price changes can suddenly demand a code that the customer has not seen for a year.

Who chooses

The last point is the one that matters for complaints. An exemption is permission, not obligation. The merchant may request that a transaction be exempted, and the issuer decides whether to grant it, and the issuer carries the liability consequences of that decision. A customer being challenged on small payments at one shop and not at another is seeing two different commercial risk appetites applied to the same rules — and neither shop is doing anything wrong.