Strong Customer Authentication (SCA) Exceptions and Exemptions
Strong Customer Authentication (SCA) is a fundamental requirement introduced by PSD2 to increase the security of digital payments. However, there are certain cases in which SCA may be waived (exceptions) or not required (exemptions), simplifying the payment process for both users and merchants.
Why is it important to understand exceptions and exemptions?
Understanding these rules allows you to:
- Optimize the user experience by avoiding unnecessary authentication steps
- Reduce cart abandonment rates
- Ensure regulatory compliance without risking disputes
Quick Overview
| Type | Case Study | Practical Example |
|---|---|---|
| Exception | One-leg transaction | Payment to the US |
| Exception | M.O.T.O. | Telephone order |
| Exception | Merchant Initiated Transaction | Automatic card debit |
| Exception | Card on file | Payment via wallet |
| Exception | Low-value | Payment under €30 |
| Exception | Risk-Based Analysis (RBA) | €50 low-risk payment |
| Exception | Recurring Payments | Netflix monthly subscription |
| Exception | Whitelisting | Payment to a trusted supplier |
SCA Exceptions
Exceptions are situations in which SCA does not apply by regulatory definition:
-
One-leg transactions
Payments in any currency where either the acquirer or the issuer is located outside the European Economic Area (EEA).
Example: Purchase from an American website using an Italian card. -
Mail Order / Telephone Order (M.O.T.O.)
Transactions performed without the physical presence of the cardholder (card-not-present), such as telephone or mail orders.
Example: Product order via call center. -
Merchant Initiated Transactions (M.I.T.)
Payments initiated by the merchant, in the absence of the buyer, but based on prior authorization.
Example: Automatic debit for subscription renewal. -
Card on File
Payments where authentication has already been carried out previously by a third party (e.g., digital wallets).
Example: Payment with PayPal where the card has already been authenticated.
SCA Exemptions
Exemptions are cases where SCA may be requested, but it is possible to avoid it if certain conditions are met:
-
Low-value transactions
Payments under €30, provided that the cumulative amount of consecutive transactions does not exceed €100 or five transactions.
Example: Online purchase of a €2 coffee. -
Risk-Based Analysis (RBA)
Payments between €30 and €500 considered low risk if the issuer or acquirer maintains fraud rates below regulatory thresholds.
Example: €50 payment on a reliable website with low fraud risk. -
Recurring Payments
Subscriptions or recurring payments with a fixed amount and beneficiary. SCA is required only for the first transaction, unless the amount changes.
Example: Monthly streaming subscription. -
Whitelisting (Trusted Beneficiaries)
The customer may add a company to their list of “trusted beneficiaries” according to the issuer’s procedures. SCA applies only to the first payment.
Example: Recurring payment to a regular supplier.
Transaction Risk Analysis (TRA)
Transaction Risk Analysis (TRA) is a mechanism used to assess the risk level of a transaction based on multiple parameters:
- Transaction amount
- Customer behavior (location, habits)
- Potential fraud scenarios
- Known fraudulent data lists (e.g., reported IBANs)
- Compromise of the customer’s device
If the transaction exceeds the defined risk threshold, SCA will be required.
FAQ
When can I avoid SCA?
When the transaction falls within the defined exceptions or exemptions and all regulatory conditions are satisfied.
Who decides whether to apply SCA?
Primarily the issuer (the customer’s bank) and the acquirer (the merchant’s bank), according to PSD2 rules and their internal risk policies.
What happens if an exemption is applied incorrectly?
You risk having the payment disputed and losing fraud liability protection.