Authentication and security

Strong customer authentication

Authentication using two or more independent elements from knowledge, possession and inherence.

Under PSD2, strong customer authentication is authentication based on two or more independent elements from the categories of knowledge, something only the user knows, possession, something only the user has, and inherence, something the user is. It is required when a payer accesses an account online, initiates an electronic payment or carries out a remote action that may imply a risk of fraud, subject to exemptions set out in the regulatory technical standards. The central question for agents is which of these steps a person must still perform and which can be covered by a prior mandate or an exemption.

Agent Minute explains this term on 11 October 2026.

Related terms