What is strong customer authentication in the UK?
Strong Customer Authentication (SCA) is a security requirement under the Payment Services Regulations 2017 that mandates two-factor verification for online payments and open banking access. It requires authentication using at least two of three factors: something you know (password or PIN), something you have (mobile phone or card reader), and something you are (fingerprint or facial recognition). SCA reduces fraud on online transactions and open banking connections.
When is Strong Customer Authentication required?
SCA is required when you access your online banking account, make an online card payment above certain thresholds, grant a third party open banking access to your account, or initiate a payment via an open banking PISP. Some low-value or low-risk transactions are exempt — for example, small contactless payments or recurring payments where you have already authenticated the series. These exemptions are managed by your bank and the payment provider.
How does SCA affect open banking in practice?
For open banking connections, SCA means you must re-authenticate with your bank (typically every 90 days) to renew an AISP connection, even if you granted long-term consent. This is to ensure you remain in active control of which apps have access to your data. For payment initiation (PISP), you must authenticate each individual payment unless you have set up a Variable Recurring Payment with specific parameters.
Open Banking in Practice: SCA was phased in for UK e-commerce transactions between 2019 and 2022 following delays in implementation. The FCA enforces SCA compliance for all payment service providers and open banking firms operating in the UK. Strong Customer Authentication is a core element of the UK’s post-PSD2 regulatory framework. Read our guide to open banking security and SCA on openfuture.world.
FAQ
Does Strong Customer Authentication apply to all online payments?
SCA applies to most online card payments and open banking transactions, with specific exemptions for low-value, low-risk, or recurring pre-authorised payments.
Why does my banking app ask me to re-confirm open banking access every 90 days?
This is the SCA re-authentication requirement — FCA rules require AISP access to be re-confirmed every 90 days to ensure you remain in control of your data.
What is the difference between SCA and two-factor authentication (2FA)?
SCA is the regulatory requirement; 2FA is one method of meeting it — SCA specifically requires two of three defined factor types, whereas generic 2FA may use two factors of the same type.