PAYMENT SERVICES DIRECTIVE (PSD2)

What is PSD2?

The second Payment Services Directive or PSD2 is a European law which comes into full force on 14th September 2019 and which will make it more secure for you to make electronic payments when shopping online or using online banking services.

PSD2 aims to make payments safer, increase consumer protection and continue to foster innovation and competition while maintaining a level playing field for all parties.

While some elements of the PSD2 legislation have applied from 13th January 2018, the full rollout from September 2019 will result in changes to how you use digital payments channels and shop online by introducing added security rules referred as Strong Customer Authentication (SCA).

What is Strong Customer Authentication (SCA)?

Strong customer authentication is the process that validates the identity of you the user when you log in to access online and mobile banking and for further services such as making payments or changing your address.

From September 2019 you will be asked for additional security credentials. We will be sending you notifications to ask you to confirm that you have authorised payments, logged in or wish to make changes to your accounts.  We will also implement additional fraud prevention measures. Our online terms and conditions will be updated to take account of these changes.

How does SCA work?

From the 14th September 2019 when accessing your account or approving certain actions, you will be required to authenticate yourself using two out of three of the following:

  • Something only you know e.g. Password or PIN
  • Something you have e.g. Mobile Application
  • Something you are e.g. Fingerprint or Facial Recognition

When does SCA it come into effect?

SCA comes into effect on the 14th September 2019.

Why is this happening?

The second Payment Services Directive (PSD2) came into effect on the 13th January 2018 which contained 12 mandates. One of these mandates covered Strong Customer Authentication, the Regulatory Technical Standards (RTS) which are effective from the 14th September 2019, details how the mandate should be implemented. Accordingly, all account providers, online retailers etc. are required to comply with these Standards.

When is SCA applied?

SCA will be used when you do any of the following actions on your cuOnline account:

  • Access your account
  • Initiate a payment
  • Initiate an action which may imply a risk of payment fraud, such as creating a new payee.

Can I opt out of using SCA?

No, the EU directive is mandatory and all cuOnline users will be required to complete SCA.

What do I need to do?

To make this change easier, check that your mobile phone number and personal details are up to date on your cuOnline profile, or you can call into your local branch.