Digital payments in the European Union will soon require an extra step to verify the identity of the purchaser, and banks are trying to figure out a way to not create too much of a burden for the consumer.
Banks, merchants and payment providers need to comply with the EU’s new authentication requirements for e-commerce by September 14. Part of EU directive PSD2, Strong Customer Authentication (SCA) calls for most online payments above €30 ($33.70) to go through an extra level of verification, in which purchasers enter a code sent via text message from their bank or scan their fingerprint on their smartphone. The rules are intended to fight fraud, but the problem is e-commerce customers are likely going to hate the extra steps in the payments process that those rules will mean. As a result, firms across the payments ecosystem are looking at tech solutions to avoid losing the customer during the payments process.
Guillaume Princen, head of Continental Europe at Stripe, said the payments firm has spent the last two years updating its product line to enable new authentication flows in preparation for SCA. “That is particularly complex because there are lots of players here that are involved,” he said. “There are 5,000 issuers across the entire European Union, there are different interpretations of the regulations by countries, and there are different sizes and types of payments.”
Payments companies also are working to figure out ways to navigate the complex set of exemptions to the rules. In the case of fixed-amount subscriptions, for example, SCA will be required for the customer’s first payment, but subsequent charges may be exempted. “No one merchant has the level of sophistication to figure that out and optimize what they will and will not exempt,” Princen said. “We’re trying to abstract that complexity so that merchants can enter this new SCA world in kind of an auto-pilot mode, without needing to solve these problems on their own.”
Princen said smoothing out the customer experience is key to ensuring new rules don’t negatively impact the e-commerce industry. “Already, 47% of European consumers feel like today’s online checkout process is not very easy,” he noted. “You’re basically going to add some steps here, so it is going to be getting harder to pay.”
The EU could lose €57 billion ($64 billion) in economic activity in the first year after SCA takes effect, according to a survey commissioned by Stripe and conducted by analysts at 451 Research. Less than half of the businesses surveyed said they expected to be ready in time for the September deadline.
Banks also are bracing for the new rules. Lloyds Banking Group tapped U.K.-based security fintech Callsign to provide verification of payments for nearly 15 million online and mobile banking customers across its core brands, the companies announced on July 11. Despite the regulatory driver to comply, Sarah Whipp, chief marketing officer and head of go-to-market strategy at Callsign, said there’s also a chance for firms throughout the payments ecosystem to differentiate through a low-friction customer experience.
Whipp said Callsign can “passively” verify identities using a combination of location data; behavioral data, like the way a customer types or moves their mouse; device fingerprinting; and by working with telecommunications companies to avoid SIM card swapping or call diversion fraud. “We’re not collecting or mining data or surveilling people,” she added. “We’re doing it in a way that’s very privacy friendly, and that allows people to be able to stay anonymous, except to our customers.”
Banks already are struggling to bridge the gap between providing good customer experiences and robust security when it comes to payments, Whipp noted. “If firms can take advantage of the exemptions to SCA, particularly for low-risk activity points, then they can really gain a competitive advantage,” she added.
Under SCA, firms will need to perform a two-factor authentication check on purchasers at least every 90 days or every five times an electronic payment is made. “If you don’t have a policy manager in place that allows you to build that in, you’d have to put it in place every time,” Whipp explained. “By being able to put an exemption in place, that means you’ve only got to do it once every five times.”
According to Igal Rotem, CEO of Israeli merchant-acquiring bank Credorax, which mostly serves e-commerce firms with cross-border business, his firm completed the full integration of technology that SCA will require months ago, which is likely not the case with most other firms in the payments ecosystem. Credorax’s platform will help clients sort through the exemptions to provide as many low-friction checkout experiences as possible once the new rules kick in, he said.
“The thresholds that the regulators put in place are hard to be adopted,” Rotem said. “It’s not simple, and some of these exemptions, to some degree, are not realistic.” He predicted a slow but inevitable adoption by the marketplace of SCA’s security standards.
Under mounting industry pressure, the European Banking Authority (EBA) paved the way for some firms to get extensions to comply with the new rules. In a written opinion, the EBA said the industry had enough time to prepare for SCA, first unveiled in PSD2 in 2015. The opinion also acknowledged challenges for e-commerce merchants that are not payment service providers and therefore not directly subject to PSD2. The EBA allowed for national authorities within the EU to work with stakeholders to “provide limited additional time to allow issuers to migrate to authentication approaches that are compliant with SCA…and acquirers to migrate their merchants to solutions that support SCA.”






