BSI launches SCA code of practice

The British Standards Institution (BSI) has published a publicly available code of practice for digital identification and Strong Customer Authentication (SCA).

The new specification - PAS 499:2019 - is for organisations with regulatory requirements under the second Payment Services Directive (PSD2) and related regulations.

It focuses on management principles and takes a regulatory view of identification and strong customer authentication, including: identity validation; identity verification; enrolment; authentication; delegated authorisation; risk models; security and usability.

It also applies to management processes for creating, accessing or managing accounts digitally; users making a payment via a mobile device or other computer; users making a contactless payment using an electronic device; a retailer receiving such payments; third-party roles; delegated authority; and a bank or payment service provider administering such transactions.

It does not cover contactless payments made using plastic cards; transactions in the context of the internet of things; digital currencies; specifics of payment devices or payment terminals.

Tim McGarr, digital sector lead at the BSI, said: “At a time when cyber crime and fraud are on the rise, it is critical that organizations have robust digital identity and user authentication processes in place to minimize the risks of their online transactions.

“PAS 499:2019 provides the recommendations needed to optimise and implement a system that supports legal and regulatory requirements.”

The new code was developed by a steering committee and underwent a peer and public review, as is normal practice in such a consensus document.

    Share Story:

Recent Stories


Beyond compliance: Transforming document management into a strategic advantage for financial institutions
In this exclusive fireside chat, John Rockliffe, Pre-Sales Manager at d.velop, discusses the findings of Adapting to a Digital-Native World: Financial Services Document Management Beyond 2025 and explores how FSIs can turn document workflows into a competitive advantage.

Sanctions evasion in an era of conflict: Optimising KYC and monitoring to tackle crime
The ongoing war in Ukraine and resulting sanctions on Russia, and the continuing geopolitical tensions have resulted in an unprecedented increase in parties added to sanctions lists.

Achieving operational resilience in the financial sector: Navigating DORA with confidence
Operational resilience has become crucial for financial institutions navigating today's digital landscape riddled with cyber risks and challenges. The EU's Digital Operational Resilience Act (DORA) provides a harmonised framework to address these complexities, but there are key factors that financial institutions must ensure they consider.

Legacy isn’t the enemy: what FSIs can do to keep their systems up and running
In this webinar we will examine some of the steps FSIs have already taken to rigorously monitor and test systems – both manually and with AI-powered automation – while satisfying the concerns of regulators and customers.