
Strong Customer Authentication (SCA) – What does it mean?
On the 14th of September 2019 authentication of online payments will be subject to new requirements under the Second Payment Services Directive (PSD2) across the whole of Europe (the UK included). One of these requirements is strong customer authentication, but what even is it?
SCA is a European regulatory requirement that’s purpose is to reduce fraud and increase the security of online payments. Once SCA goes into effect it will be necessary for online retailers to ensure there is additional authentication into their checkout flows that allow for multi-factor authentication. If you think in terms of physical card transactions they already have multi-factor authentication by having both a chip and pin whereas this has not always been typical of online transactions. You will, however, be familiar with SCA even if you don’t realise it and this is answering secret questions “What was your first pet called?”, “Where did you go to school”. Breaking it down multi-factor authentication will mean using at least two of three types of authenticators to prove the payment is being made by the customer.
Think of this in terms of: Something you know, Something you have and Something you are:
A Password
A verification code sent to your phone
Facial Recognition
Most payment gateways will use 3D Secure 2 (3DS 2) an authentication scheme to ensure they comply with SCA, this will mean customers will enter an additional password or code when purchasing online. You may have noticed when you have been making online payments recently your bank has put a notice at payment authentication to check the mobile number you have listed with the bank is correct.
SCA is required in the following three scenarios:
If a payment account is accessed online
If an electronic payment is initiated
If a payer is using a remote channel for a transaction where there is a recognised increase in the risk of payment fraud
What this really means is that SCA will apply to online payments within Europe that are started by a customer, this covers most card payments as well as all bank transfers using online and in app banking that are not considered to be business initiated (such as recurring direct debits). It is worth noting that there will be some exemptions to SCA which will include low value transactions, transactions deemed as low risk, recurring payments (subscriptions will be required to be authorised only on the initial payment), Whitelisting of transactions and secured corporate payments. While the changeover to multi-factor is likely to be phased, it is expected that banks will start rejecting payments without this form of authentication from the 14th onwards.
If you are an online retailer the last thing you want after the 14th of September is to see an increase in cart abandonment on your website. If you continue to use an old version of 3DS this will be seen as high risk and may increase the need for additional authentication for 50% of transactions, leading to increased customer frustration and a reduction in online sales. The best way to avoid this scenario is to ensure that the new 3DS 2.0 standard are met on your website.
As an online retailer, you should check how your online payment provider is dealing with SCA and that the payment gateway that you use is SCA ready. An article on WooCommerce suggests that of the payment gateways they offer, only four are officially recognised as being SCA ready, Stripe, Global Payments Gateway, Paypal and Amazon Pay. There are some big ones missing here such as Worldpay – this doesn’t mean they aren’t SCA ready but it definitely means you should get in touch with your payment gateway provider to check they have it sorted!
If you aren’t sure what you should be doing to meet the new Second Payment Services Directive requirements, get in touch with us and see how we can help.