iGamerKnow the game.
18+ --:--:-- UTC
All terms
Payments·advanced

Strong Customer Authentication (SCA)

A PSD2 requirement that many electronic payments be verified using at least two independent factors from knowledge, possession, and inherence.

Definition

Strong Customer Authentication is the PSD2 rule that most electronic payments in the EEA be confirmed with two of three independent factor types: knowledge (something the customer knows, such as a password), possession (something they have, such as a phone or card), and inherence (something they are, such as a fingerprint or face). For cards this is usually delivered through 3-D Secure. SCA reduces unauthorised-payment fraud but adds friction that can cause abandoned or failed transactions, so the rules include exemptions (for example low-value or low-risk transactions and trusted beneficiaries) that let issuers waive the challenge when risk is judged low.

Worked example

A deposit is approved only after the customer enters a one-time code sent to their phone (possession) and confirms with a fingerprint (inherence) in the banking app.

Why it matters

For learners, SCA is the concrete reason payments increasingly ask for two proofs of identity. For professionals, balancing SCA compliance against conversion, and using exemptions wisely, is central to keeping decline rates low.

Related

Note: SCA applies under PSD2 in the EEA (and a UK equivalent); exemption thresholds and rollout details vary by regulator and issuer.