Response to consultation on RTS specifying the requirements on strong customer authentication and common and secure communication under PSD2

Go back

Question 1: Do you agree with the EBA’s reasoning on the requirements of the strong customer authentication, and the resultant provisions proposed in Chapter 1 of the draft RTS?

NA

Question 2: In particular, in relation to the “dynamic linking” procedure, do you agree with the EBA’s reasoning that the requirements should remain neutral as to when the “dynamic linking” should take place, under the conditions that the channel, mobile application, or device where the information about the amount and the payee of the transaction is displayed is independent or segregated from the channel, mobile application or device used for initiating the payment, as foreseen in Article 2.2 of the draft RTS.

NA

Question 3: In particular, in relation to the protection of authentication elements, are you aware of other threats than the ones identified in articles 3, 4 and 5 of the draft RTS against which authentication elements should be resistant?

NA

Question 4: Do you agree with the EBA’s reasoning on the exemptions from the application of Article 97 on strong customer authentication and on security measures, and the resultant provisions proposed in Chapter 2 of the draft RTS?

NA

Question 5: Do you have any concern with the list of exemptions contained in Chapter 2 of the draft RTS for the scenario that PSPs are prevented from implementing SCA on transactions that meet the criteria for exemption?

The ASF welcomes the opportunity to respond to Consultation Paper dated on 12 August on
the draft Regulatory Technical Standards specifying the requirements on strong customer authentification and common and secure communication under PSD2.

As a unique representative body of all the French specialised credit institutions and financial institutions which represents 285 entities, ASF contributes to an appropriate recognition of the specialised financial activities like equipment and real estate leasing, factoring, consumer credit and auto loans and leases, mutual guarantee societies which – with an outstanding of more than €220 billion in 2015 – accounts for about 20% of total amount of credits to the real economy in France.

We do consider that it is fundamental to draw your attention to the point related the three-party card schemes.

The article 98 of the Directive introduces the exemptions from the application of article 97 “Authentication”. The exemptions shalll be based on the following criteria :

(a) the level of risk involved in the service provided ;
(b) the amount, the recurrence of the transaction, or both ;
(c) the payment channel used for the execution of the transaction.

In accordance with the article 98, we suggest that the future RTS Guidelines do not oblige three party card schemes to be “compliant” with a strong customer authentification for the following reasons.

Firstly, many three-party card schemes are not general purpose card payment schemes.

Secondly, the three-party card schemes operate on a national basis with a small market share of the cards market and with a small limited number of merchants.

Futhermore, the level of security measures taken depends on the recurrence and the amount of the transaction.

Finally, these three-party cards are subject to a low number of fraud : in 2015 the percentage of fraud raises at 0.068 % . We explain this low rate by a limited use of these three-party cards in a closed loop system. The compliance with the strong customer authentification is disproportionate to the level of risk and the volume of transactions.

Therefore, we suggest to modify the article 8 of the draft RTS specifying the requirements on strong customer authentification and common and secure communication under PSD2 to take into account these features.

Question 6: Do you agree with the EBA’s reasoning on the protection of the confidentiality and the integrity of the payment service users’ personalised security credentials, and the resultant provisions proposed in Chapter 3 of the draft RTS?

NA

Question 7: Do you agree with the EBA’s reasoning on the requirements for common and secure open standards of communication for the purpose of identification, authentication, notification, and information, and the resultant provisions proposed in Chapter 4 of the draft RTS?

NA

Question 8: In particular, do you agree that the use of ISO 20022 elements, components or approved message definitions, if available, should be required to ensure the interoperability of different technological communication solutions implemented between PSPs for the provision of AIS, PIS or for the confirmation on the availability of funds? Do you see any particular technical constraint that would prevent the use of such industry standards?

NA

Question 9: With regards to identification between PSPs, do you agree that website certificates issued by a qualified trust service provider under an e-IDAS policy would be suitable and allow for the use of all common types of devices (such as computers, tablets and mobile phones) for carrying out different payment services ?

NA

Question 10: With regards to the frequency with which AIS providers can request information from designated payment accounts when the payment service user is not actively requesting such information, do you agree that the proposed limit of no more than two times a day achieve an appropriate balance between allowing AISP to provide updated information to their users while not negatively impacting the availability of the ASPSP’s communication interface? If not, please indicate what would be in your view the appropriate frequency and rationale for such frequency.

NA

Please select which category best describes you and/or your organisation

[Other "]"

If you selected "Other", please provide details

As a unique representative body of all the French specialised credit institutions and financial institutions which represents 285 entities, ASF contributes to an appropriate recognition of the specialised financial activities like equipment and real estate leasing, factoring, consumer credit and auto loans and leases, mutual guarantee societies which – with an outstanding of more than €220 billion in 2015 – accounts for about 20% of total amount of credits to the real economy in France.

Please select which category best describes the services provided by you/your organisation

[Issuing of payment instruments and/or acquiring of payment transactions"]"

Name of organisation

ASF