Q&A on the use of 3rd party digital ID and password for strong customer authentication (SCA)
30 november 2020Toezicht
Toezicht
Question
Does the use of a 3rd party digital ID and password for strong customer authentication (SCA) require an outsourcing agreement in order to be compliant with Regulation (EU) 2018/389 - RTS on SCA and secure communication?
Answer
Yes. If a knowledge factor used in SCA processes is not under direct control of the payment service provider, DNB expects a valid outsourcing arrangement to ensure adequate management of operational risks. A knowledge factor such as 3rd party digital ID and password, which has not been issued by the payment service provider, cannot be deemed to be under the direct control of the payment service provider. Thus, the use of 3rd party digital ID and password must be subject to a valid outsourcing arrangement between the payment service provider and the 3rd party in order to be compliant with the Regulation (EU) 2018/389 - RTS on strong customer authentication and secure communication. This outsourcing arrangement must comply not only with the Delegated Regulation, but also the EBA guidelines on outsourcing.
Op 21 december 2020 is het besluit tot wijziging van de Regeling beheerst beloningsbeleid Wft 2017 (Rbb 2017) gepubliceerd in de Staatscourant (2020, 66558), met inwerkingtreding op 29 december 2020.
Om de gebruiksvriendelijkheid van onze website te optimaliseren, maken wij gebruik van cookies. Lees meer over de cookies die wij gebruiken en de gegevens die we daarmee verzamelen in onze cookie-policy.