SlideShare a Scribd company logo
PSD2 and 3DS2 overview
November 2018
2© 2018 Worldpay, LLC and/or its affiliates. All rights reserved.
Agenda
01
PSD2 and SCA overview
02
3DS2 overview
03
Worldpay’s PSD2 and 3DS2 proposition
3© 2018 Worldpay, LLC and/or its affiliates. All rights reserved.
PSD2 is an effort to improve the efficiency of the payments market
Objectives:
• More competition
• More transparency
• More innovation
• Greater security
• Lower fraud
• Lower costs
• Greater value to
consumers
• Etc….
PSD2 will have a major impact on all banks and PSPs, traditional and new
PSD2
SEPA &
honor all
cards policy
(until now)
AML
directive &
fund
transfer
regulation
Digital
single
market General data
protection
regulation
E-money
directive
MIF
regulation
(interchange,
application
choice at the
POS)
EBA
guidelines
(RTS,
security)
4© 2018 Worldpay, LLC and/or its affiliates. All rights reserved.
What is Payment Services Directive 2 (PSD2)?
Definitions and factors affecting
PSD2
RTS
Local Law
Implementation
Brexit
 Aims to regulate payment services and payment service providers
throughout the European Union
 PSD2 Regulatory Technical standard (RTS) provide the technical
specifications by which PSD2 will be implemented
 Each Member State had to implement PSD2 into local law by 13 Jan 2018
 PSD2 implemented by UK Government under the Payment Services
Regulations 2017
 The UK Financial Conduct Authority confirmed EU regulation will remain
applicable to UK firms until any changes are made. The HMT Consultation
confirms that until Brexit negotiations are concluded the UK remains a full
member of the EU
5© 2018 Worldpay, LLC and/or its affiliates. All rights reserved.
We are nearing the conclusion of the PSD2 / SCA journey
Worldpay has played a very active role in helping to shape the new regulation
Applies +18 months after publication
WP Lobbied for Risk based exemption
(TRA) and low value exemption increased
from 10 Euro to 30 Euro
WP will continue to lobby for
level 3 guidance and Q&A on
interpretation by EBA
WP Lobbied for fraud
calculation formula to apply
to fraud prevented by SCA
Applies +2 years after adoption
Worldpay
activities and
key changes:
WP influencing RTS interpretation
with Visa as part of UK
authentication steering group
Jan-16 Q3-16 Mar-17 27/11/2017 Jan-18 14 Sept 1913 March-18
PSD2
Came into force
in Europe
Final draft RTS on
SCA by the EU
Commission
European
Commission
published the Final
RTS on SCA
PSD2
Transposed in
Member States
domestic law
First RTS on SCA
Discussion Paper
published
Publication of the
RTS on SCA in the
Official Journal
following scrutiny
by the European
Parliament and the
Council
RTS on SCA
applies for all
electronic
transactions in
Europe
6© 2018 Worldpay, LLC and/or its affiliates. All rights reserved.
PSD2 mandates SCA for all electronic transactions
Except if an exemption applies
PSD2 SCA requires at least 2 of 3 factors of authentication…
Something only the
user knows
Password
Pin
Signature
Something only the
user has
Card
Mobile phone
Wearable device
Something the user
is (biometrics)
Facial recognition
Fingerprint
Iris scan
Extra element for Remote Transactions (Internet, Mobile): each SCA must be linked dynamically
to a specific amount and a specific Payee
7© 2018 Worldpay, LLC and/or its affiliates. All rights reserved.
There are exemptions and exclusions to SCA
SCA exemptions SCA exclusions
Some transactions can be exempted from SCA to help
reduce friction
Some transactions are completely out of scope of SCA
Low risk
transactions
• Transactions that have been assessed as low risk
in real time (TRA) and where PSP is below the
fraud threshold
Low value
transactions
• Remote electronic payment transactions ≤30EUR
• Applies up to 5 consecutive payments or cumulative
amount since last SCA is ≤ EUR 100
Whitelists of
beneficiaries
• No SCA unless when payer adds a merchant to a
whitelist of the issuer
Recurring
transactions
• Recurring transactions of a fixed value where the
first and subsequent values are the same
• SCA needs to apply on first transaction
Corporate
Payments
• SCA is not required for B2B payments using a
secure dedicated process
• Corporate cards not used by persons e.g. lodged
cards, virtual cards are exempted from SCA
One leg out
transactions
• Payments where the issuer or the acquirer are
based outside of the EEA are not required to
perform SCA
Merchant
Initiated
Transactions
• Transactions initiated by the payee such as mobile
phone payments and fixed and variable amount
subscriptions or instalments
• SCA needs to apply on first transaction/mandate
MOTO • No need for SCA to be performed
8© 2018 Worldpay, LLC and/or its affiliates. All rights reserved.
Low risk exemption is based on Transaction Risk Analysis (TRA)
Transaction value (EUR) 0-100 100-250 250-500 500+
Reference fraud rate (%)
Card Not Present based
payments
0.13 0.06 0.01
N/A
SCA on all
transactions unless
other exemption
applies
Fraud rates that allow SCA exemption – applied on PSP (issuer / acquirer level)
Implications:
• Merchants can request to exempt a transaction from SCA and assume liability
• Exemption can only apply to Low Risk transactions based on real time TRA assessment
• Merchants that operate below fraud thresholds can request the exemption and provide a frictionless experience
9© 2018 Worldpay, LLC and/or its affiliates. All rights reserved.
Your fraud rate will have a major impact on your acceptance rate
Decreased
conversion
and
acceptance
rates
SCA required
on all
transactions
High
Fraud
Increased
conversion
and
acceptance
rates
Exemptions
maximised;
frictionless
user
experience
Low
fraud
Merchant A
Merchant B
10© 2018 Worldpay, LLC and/or its affiliates. All rights reserved.
Issuers are expected to employ an array of SCA methods – many of
which will be high friction. Exemptions can help avoid this
SCA high-friction flow example: authentication using banking app redirect
11© 2018 Worldpay, LLC and/or its affiliates. All rights reserved.
The whitelisting exemption is still in development. There are a number of
potential implementation options
During the payment After the payment Web/mobile banking
2 31
White Listing Prompt on
authentication page
White Listing Prompt on
separate page
White Listing via
Mobile Banking
Frameworks are still being defined to inform merchants that they have been whitelisted. Currently only
issuers can apply the exemption – we are defining technology solutions for merchant involvement
12© 2018 Worldpay, LLC and/or its affiliates. All rights reserved.
Agenda
01
PSD2 and SCA overview
02
3DS2 overview
03
Worldpay’s PSD2 and 3DS2 proposition
13© 2018 Worldpay, LLC and/or its affiliates. All rights reserved.
PSD2 mandate for SCA changes the use and model of 3DS
Now Post Sept 2019
Model
Opt-in Opt-out
Liability
Merchant
(unless 3DS applied)
Issuer
(Unless exemption applied from
Merchant / Acquirer)
User
Experience
Merchant controlled
Issuer controlled
(unless exemption applied from
Merchant/ acquirer)
14© 2018 Worldpay, LLC and/or its affiliates. All rights reserved.
3DS2 represents a significant change, and will provide a number of
benefits over 3DS1
3DS1 3DS2
Data
• 5 Authentication data elements
• Limited authentication models
• Risk Based Authentication
• Static passwords
 10x more data elements to help issuers
make better risk decisions
 Superior authentication models including
 Risk Based Authentication
 Biometrics
 One Time Passwords (OTP),
 Out of band
UX
• Limited integration with merchant UX
• Browser support only
• Fragmented UX by issuers
 Improved integration with merchant UX
 Enhanced Browser support
 Optimised for Mobile / native Apps
 Support for SCA exemptions
15© 2018 Worldpay, LLC and/or its affiliates. All rights reserved.
While 3DS1 created friction, it did bring benefits
3DS2 will enhance these benefits, supported by new mandates
3DS significantly reduces fraud 3DS increases authorisation rates
0.05%
3DS1
0.12%
Non 3DS
0.29%
3DS2
Visa / MC
Issuer
target
95%92%
3DS1 3DS2Non 3DS
84%
3DS effect on drop offs
MC Issuer
target
3DS1
15%
Non 3DS
3%
5%
3DS2
Low end
High end
Visa / MC
Issuer
target
16© 2018 Worldpay, LLC and/or its affiliates. All rights reserved.
3DS2 captures a lot more data
3DS 1.0 Current Authentication Data 3DS 2.0 Enhanced Authentication Data
Acquirer BIN
Acquirer Merchant ID
Cardholder Account Number
DS URL
Message, Extension, Version
Browser User-Agent More than
10X
Data
Source: Visa
Amount
Billing Address
Billing City
Billing country code
Billing first name
Billing last name
Billing postal code
Billing state
Card expiry month
Card expiry year
Card number Currency code
DF reference ID
Email
Mobile number
Processor ID
Merchant ID
Transaction password
Version
Transaction mode
Message type
Transaction type
Order number
Shipping address
Shipping state
Shipping city
Shipping country code
Shipping postal code
Billing phone number
Billing phone number
Billing phone
Work phone
Authentication indicator
Product code
3RI Indicator
Device channel
Message Category
Shipping method
Travel departure date
Travel passenger first name
Travel passenger last name
Travel origin
Travel destination
Travel airline carriers
Instalment
Purchase date
Recurring end
Recurring frequency
Override payment method
Category code
Account age indicator
Account create date
Transaction count day
Add card attempts
Prior authentication data
Prior authentication time
Prior authentication method
ACS window size
Merchant URL
Browser header
IP address
Account ID
Item name
Item description
Item quantity
Item price
Tax amount
Order description
Mandatory Conditional Optional (not exhaustive list)
17© 2018 Worldpay, LLC and/or its affiliates. All rights reserved.
3DS2 flows: frictionless experience
• Frictionless flow can be provided when an SCA exemption applies
• Issuers will be able to leverage the increased data to make more informed risk based decisions
• Shoppers do not see a challenge; liability is taken by the party who applied the exemption
18© 2018 Worldpay, LLC and/or its affiliates. All rights reserved.
3DS2 flows: out of band challenge experience
• Out of Band challenges take the user away from the merchant’s site to authenticate and complete
the payment
• Out of band challenges can be completed on browser or mobile and will involve the shopper
authenticating the payment in their online banking application
19© 2018 Worldpay, LLC and/or its affiliates. All rights reserved.
3DS2 flows: one time password
• One time password challenges require a single-use code to be sent to the shopper. This could be
sent via text or email
• Retrieving this code usually directs the shopper out of the payment flow
• Challenges can be completed on browser or mobile
Source: Mastercard
20© 2018 Worldpay, LLC and/or its affiliates. All rights reserved.
3DS2 flows: biometric challenge experience
• Biometrics involve using the shopper’s smart phone capabilities to authenticate themselves, this
could be through fingerprint or facial ID readers
• Visa and Mastercard are mandating that all issuers have capability to support a biometric
challenge by 2020
21© 2018 Worldpay, LLC and/or its affiliates. All rights reserved.
Agenda
01
PSD2 and SCA overview
02
3DS2 overview
03
Worldpay’s PSD2 and 3DS2 proposition
22© 2018 Worldpay, LLC and/or its affiliates. All rights reserved.
The requirement for SCA will impact you in a number of ways
Increased friction Increased cost Fraud rate scrutiny Dev work
• While 3DS2 is a
significant
improvement on
3DS1, SCA rollout will
still increase the
number of steps that
customers have to
follow to complete a
payment. This could
create a poorer
payment experience
• Drop-out rates could
increase, reducing
your revenue and
lowering customer
loyalty
• Undertaking 3DS2 will
incur additional
processing costs
• Some card schemes
have already doubled
their scheme fees, or
are expected to
introduce additional
fees, for authenticated
transactions
• Acquirers and issuers
will now have to be
below certain fraud
thresholds in order to
apply the low-risk SCA
exemption
• Therefore, there will
be much more
scrutiny of merchant
fraud rates, and
protections may be put
in place to negate the
impact of high-fraud
merchants
• While Worldpay will
help merchants to hold
this to a minimum,
some development
work will be required
to gather additional
data to complete TRA,
and supply it to
Worldpay (or any
acquirer) via extended
APIs
23© 2018 Worldpay, LLC and/or its affiliates. All rights reserved.
Worldpay will provide a full suite of products to help you manage SCA
Issuer
3DS2
Service
Acquiring
platform
SCA
Exemption
Engine
FraudSight
WP
Gateway Exemption
applied
Exemption
applied or SCA
Worldpay PSD2 and 3DS2 Service
Merchant
3 key components:
• SCA Exemption Engine to
exempt as many transactions as
possible from SCA/3DS2 –
reducing friction and cutting cost
• 3DS2 Merchant Plug In (MPI) to
ensure you can perform SCA
whenever it is required
• New industry-leading fraud tool
to help you lower your fraud and
maximise which SCA exemptions
can be used
2
3
1
2
3
1
24© 2018 Worldpay, LLC and/or its affiliates. All rights reserved.
Worldpay will provide a full suite of products to help you manage SCA
Exemption
applied or SCA
Issuer
3DS2
Service
Acquiring
platform
FraudSight
WP
Gateway Exemption
applied
Worldpay PSD2 and 3DS2 Service
Merchant
2
3
SCA
Exemption
Engine
1
SCA Exemption Engine
 Reasonably exempt as many EEA
transactions as possible from SCA
 Multiple exemption models – merchant request
and managed
 Worldpay real-time risk assessment of
transactions and validation of exemption for
submission to issuer
25© 2018 Worldpay, LLC and/or its affiliates. All rights reserved.
Worldpay will provide a full suite of products to help you manage SCA
IssuerAcquiring
platform
FraudSight
WP
Gateway Exemption
applied
Worldpay PSD2 and 3DS2 Service
Merchant
3
SCA
Exemption
Engine
1
Exemption
applied or SCA
3DS2
Service
2 Intelligent Authentication Service
 New 3DS2 MPI - PSD2 SCA compliant
 Better user experience
 Improved authentication models
including frictionless
 Better risk decisions by sharing more
data elements
 Optimised for mobile and native apps
26© 2018 Worldpay, LLC and/or its affiliates. All rights reserved.
Worldpay will provide a full suite of products to help you manage SCA
IssuerAcquiring
platform
WP
Gateway Exemption
applied
Worldpay PSD2 and 3DS2 Service
Merchant
SCA
Exemption
Engine
1
3DS2
Service
2
Exemption
applied or SCA
FraudSight
 State of the Art fraud engine using machine
learning and behavioural analytics
 Standalone fraud management product; will also
have features to help with SCA
 Full FraudSight service can assess transaction
risk and request exemptions
FraudSight
3
27© 2018 Worldpay, LLC and/or its affiliates. All rights reserved.
SCA exemptions and 3DS2 can minimise friction and maximise conversion
Issuers will support multiple SCA methods – banking app authentication and SMS
One Time Password (OTP) will be most prevalent
SCA
Exemption A
SCA with
3DS2
B
28© 2018 Worldpay, LLC and/or its affiliates. All rights reserved.
This service will benefit you in 6 key ways
Improved user experience: Maximising exemptions to avoid stepping up to 3DS2 where
possible – maintaining conversions and protecting revenue
Reduced cost: Utilising exemptions to avoid additional authentication processing costs
Simplicity: End-to-end service through a single integration
Data: As an acquirer and a gateway, Worldpay has access to significant data to better inform
SCA risk decisions
Fraud reduction: Worldpay is providing fraud consultations and new reporting tools to help you
better understand and track your fraud, as well as launching our new FraudSight risk tool
Flexibility: Within the rules of SCA, we will give you as much control as possible to ensure that
the solution works for your business
A
B
C
D
E
F
29© 2018 Worldpay, LLC and/or its affiliates. All rights reserved.
What does this mean for you?
Fraud management
• Manage and lower your fraud rates to make sure that you can utilise low-risk SCA exemptions
• Use 3DS and add SCA compliant payment options such as Apple Pay, Google Pay and Samsung Pay
3DS2 roadmap
• It is critical that you have 3DS2 on your development roadmap, well in advance of the September
2019 deadline
• If you do not use 3DS1 today, we recommend that you integrate to and test this service to increase
your familiarity with how it will work
User Experience
• When SCA must be triggered, much of the control over UX will shift to issuers
• Maximise your use of SCA exemptions for good transactions to enable a frictionless user experience

More Related Content

What's hot

PSD2 - The second Payment Services Directive
PSD2 - The second Payment Services DirectivePSD2 - The second Payment Services Directive
PSD2 - The second Payment Services Directive
Emilie Scalla
 
Real Time Gross Settlement
Real Time Gross SettlementReal Time Gross Settlement
Real Time Gross Settlement
Pratheeban Rajendran
 
Unified Payments Interface (UPI) - Introduction
Unified Payments Interface (UPI) - Introduction Unified Payments Interface (UPI) - Introduction
Unified Payments Interface (UPI) - Introduction
indiastack
 
Unified payments interface (upi)
Unified payments interface (upi)Unified payments interface (upi)
Unified payments interface (upi)
Naina Singh
 
Unified payment interface
Unified payment interfaceUnified payment interface
Unified payment interface
pranoy_seenu
 
EMV Overview
EMV OverviewEMV Overview
CCAvenue Features Presentation
CCAvenue Features PresentationCCAvenue Features Presentation
CCAvenue Features Presentation
Pramod Ganji
 
Overview of Mobile Payment Systems
Overview of Mobile Payment SystemsOverview of Mobile Payment Systems
Overview of Mobile Payment Systems
Amit Naik
 
Payment gateway/payment service providers and future trends in mobile payment...
Payment gateway/payment service providers and future trends in mobile payment...Payment gateway/payment service providers and future trends in mobile payment...
Payment gateway/payment service providers and future trends in mobile payment...Danail Yotov
 
Oppurtunities for Fintech in India
Oppurtunities for Fintech in IndiaOppurtunities for Fintech in India
Oppurtunities for Fintech in India
Fintech Nxt
 
How an online payment gateway works
How an online payment gateway worksHow an online payment gateway works
How an online payment gateway works
Ikajo International
 
E-commerce: Smart Card, Debit card & Credit card
E-commerce: Smart Card, Debit card & Credit cardE-commerce: Smart Card, Debit card & Credit card
Bharat bill payment system
Bharat bill payment systemBharat bill payment system
Bharat bill payment system
Vijaya Bank
 
Presentation safex pay
Presentation safex payPresentation safex pay
Presentation safex pay
JyotiBisht23
 
Payment Gateway
Payment Gateway Payment Gateway
Payment Gateway
Rohit Srivastav
 
Electronic payment
Electronic paymentElectronic payment
Electronic payment
Prakhar Gupta
 
Ec2009 ch11 electronic payment systems
Ec2009 ch11 electronic payment systemsEc2009 ch11 electronic payment systems
Ec2009 ch11 electronic payment systems
Nuth Otanasap
 
PPI Classifications
PPI ClassificationsPPI Classifications
PPI Classifications
Home
 
BBPS Workshop in partnership with NPCI | Product, Business & Technology Overview
BBPS Workshop in partnership with NPCI | Product, Business & Technology OverviewBBPS Workshop in partnership with NPCI | Product, Business & Technology Overview
BBPS Workshop in partnership with NPCI | Product, Business & Technology Overview
ProductNation/iSPIRT
 
Modes of Cashless Transactions - Cash-less Indian Economy
Modes of Cashless Transactions - Cash-less Indian EconomyModes of Cashless Transactions - Cash-less Indian Economy
Modes of Cashless Transactions - Cash-less Indian Economy
Rajan Chhangani
 

What's hot (20)

PSD2 - The second Payment Services Directive
PSD2 - The second Payment Services DirectivePSD2 - The second Payment Services Directive
PSD2 - The second Payment Services Directive
 
Real Time Gross Settlement
Real Time Gross SettlementReal Time Gross Settlement
Real Time Gross Settlement
 
Unified Payments Interface (UPI) - Introduction
Unified Payments Interface (UPI) - Introduction Unified Payments Interface (UPI) - Introduction
Unified Payments Interface (UPI) - Introduction
 
Unified payments interface (upi)
Unified payments interface (upi)Unified payments interface (upi)
Unified payments interface (upi)
 
Unified payment interface
Unified payment interfaceUnified payment interface
Unified payment interface
 
EMV Overview
EMV OverviewEMV Overview
EMV Overview
 
CCAvenue Features Presentation
CCAvenue Features PresentationCCAvenue Features Presentation
CCAvenue Features Presentation
 
Overview of Mobile Payment Systems
Overview of Mobile Payment SystemsOverview of Mobile Payment Systems
Overview of Mobile Payment Systems
 
Payment gateway/payment service providers and future trends in mobile payment...
Payment gateway/payment service providers and future trends in mobile payment...Payment gateway/payment service providers and future trends in mobile payment...
Payment gateway/payment service providers and future trends in mobile payment...
 
Oppurtunities for Fintech in India
Oppurtunities for Fintech in IndiaOppurtunities for Fintech in India
Oppurtunities for Fintech in India
 
How an online payment gateway works
How an online payment gateway worksHow an online payment gateway works
How an online payment gateway works
 
E-commerce: Smart Card, Debit card & Credit card
E-commerce: Smart Card, Debit card & Credit cardE-commerce: Smart Card, Debit card & Credit card
E-commerce: Smart Card, Debit card & Credit card
 
Bharat bill payment system
Bharat bill payment systemBharat bill payment system
Bharat bill payment system
 
Presentation safex pay
Presentation safex payPresentation safex pay
Presentation safex pay
 
Payment Gateway
Payment Gateway Payment Gateway
Payment Gateway
 
Electronic payment
Electronic paymentElectronic payment
Electronic payment
 
Ec2009 ch11 electronic payment systems
Ec2009 ch11 electronic payment systemsEc2009 ch11 electronic payment systems
Ec2009 ch11 electronic payment systems
 
PPI Classifications
PPI ClassificationsPPI Classifications
PPI Classifications
 
BBPS Workshop in partnership with NPCI | Product, Business & Technology Overview
BBPS Workshop in partnership with NPCI | Product, Business & Technology OverviewBBPS Workshop in partnership with NPCI | Product, Business & Technology Overview
BBPS Workshop in partnership with NPCI | Product, Business & Technology Overview
 
Modes of Cashless Transactions - Cash-less Indian Economy
Modes of Cashless Transactions - Cash-less Indian EconomyModes of Cashless Transactions - Cash-less Indian Economy
Modes of Cashless Transactions - Cash-less Indian Economy
 

Similar to PSD2 and 3DS2. The impact.

PSD2: The Advent of the New Payments Market in Europe
PSD2: The Advent of the New Payments Market in EuropePSD2: The Advent of the New Payments Market in Europe
PSD2: The Advent of the New Payments Market in Europe
TransUnion
 
Psd2 brochure
Psd2 brochurePsd2 brochure
Psd2 brochure
MirandaCarterGibbs
 
EBE 2020 Getting ready for PSD2 on time! How online fashion retailer Zalando ...
EBE 2020 Getting ready for PSD2 on time! How online fashion retailer Zalando ...EBE 2020 Getting ready for PSD2 on time! How online fashion retailer Zalando ...
EBE 2020 Getting ready for PSD2 on time! How online fashion retailer Zalando ...
E-Commerce Berlin EXPO
 
The end of passwords: Two-factor-authentication and biometrics are coming 2019
The end of passwords: Two-factor-authentication and biometrics are coming 2019The end of passwords: Two-factor-authentication and biometrics are coming 2019
The end of passwords: Two-factor-authentication and biometrics are coming 2019
JanSobczak5
 
[Ekata] Unlocking the Potential of PSD2 SCA.pdf
[Ekata] Unlocking the Potential of PSD2 SCA.pdf[Ekata] Unlocking the Potential of PSD2 SCA.pdf
[Ekata] Unlocking the Potential of PSD2 SCA.pdf
ChinmayaShrivastava1
 
Digital Payment in 2020 - Kurt Schmid, Netcetera
Digital Payment in 2020 - Kurt Schmid, NetceteraDigital Payment in 2020 - Kurt Schmid, Netcetera
Digital Payment in 2020 - Kurt Schmid, Netcetera
Netcetera
 
3D-Secure 2.2 Webinar
3D-Secure 2.2 Webinar3D-Secure 2.2 Webinar
3D-Secure 2.2 Webinar
Ivona M
 
EBE 2019 - The end of passwords: Two-factor-authentication and biometrics are...
EBE 2019 - The end of passwords: Two-factor-authentication and biometrics are...EBE 2019 - The end of passwords: Two-factor-authentication and biometrics are...
EBE 2019 - The end of passwords: Two-factor-authentication and biometrics are...
E-Commerce Berlin EXPO
 
Btl mastercard
Btl mastercardBtl mastercard
Btl mastercard
btlcoin token
 
PSD2, SCA and the EBA’s Opinion on SCA – Decoded
PSD2, SCA and the EBA’s Opinion on SCA – DecodedPSD2, SCA and the EBA’s Opinion on SCA – Decoded
PSD2, SCA and the EBA’s Opinion on SCA – Decoded
TransUnion
 
Accenture-Payments-Regulation-Will-Disrupt-EU-Card-Payment-Ecosystem
Accenture-Payments-Regulation-Will-Disrupt-EU-Card-Payment-EcosystemAccenture-Payments-Regulation-Will-Disrupt-EU-Card-Payment-Ecosystem
Accenture-Payments-Regulation-Will-Disrupt-EU-Card-Payment-Ecosystem💡 David Baratta
 
Strong Customer Authentication & Biometrics
Strong Customer Authentication & BiometricsStrong Customer Authentication & Biometrics
Strong Customer Authentication & Biometrics
FIDO Alliance
 
EPA PSD2 Presentation 23 February 2016
EPA PSD2 Presentation 23 February 2016EPA PSD2 Presentation 23 February 2016
EPA PSD2 Presentation 23 February 2016John Pauley
 
QSecure Presentation at RSA 2011
QSecure Presentation at RSA 2011QSecure Presentation at RSA 2011
QSecure Presentation at RSA 2011jhatch9418
 
PSD2 Strategic options for banks_Accenture Strategy and Accenture Payment Ser...
PSD2 Strategic options for banks_Accenture Strategy and Accenture Payment Ser...PSD2 Strategic options for banks_Accenture Strategy and Accenture Payment Ser...
PSD2 Strategic options for banks_Accenture Strategy and Accenture Payment Ser...Ilkka Ruotsila
 
Contactless Card Shipments Jump enabling Shoppers Take Advantage of Everyday ...
Contactless Card Shipments Jump enabling Shoppers Take Advantage of Everyday ...Contactless Card Shipments Jump enabling Shoppers Take Advantage of Everyday ...
Contactless Card Shipments Jump enabling Shoppers Take Advantage of Everyday ...
Smart Payment Association
 
PCM_SoftFinance Article_p22and23
PCM_SoftFinance Article_p22and23PCM_SoftFinance Article_p22and23
PCM_SoftFinance Article_p22and23Denise Gee
 
Accenture-Banking-Opportunities-EU-PSD2-v2
Accenture-Banking-Opportunities-EU-PSD2-v2Accenture-Banking-Opportunities-EU-PSD2-v2
Accenture-Banking-Opportunities-EU-PSD2-v2Petri Syvänne
 
PSD2: Making it actionable
PSD2: Making it actionablePSD2: Making it actionable
PSD2: Making it actionable
Backbase
 
Simont Braun - Webinar PSD3 PSR Evolution or Revolution?
Simont Braun - Webinar PSD3 PSR Evolution or Revolution?Simont Braun - Webinar PSD3 PSR Evolution or Revolution?
Simont Braun - Webinar PSD3 PSR Evolution or Revolution?
FinTech Belgium
 

Similar to PSD2 and 3DS2. The impact. (20)

PSD2: The Advent of the New Payments Market in Europe
PSD2: The Advent of the New Payments Market in EuropePSD2: The Advent of the New Payments Market in Europe
PSD2: The Advent of the New Payments Market in Europe
 
Psd2 brochure
Psd2 brochurePsd2 brochure
Psd2 brochure
 
EBE 2020 Getting ready for PSD2 on time! How online fashion retailer Zalando ...
EBE 2020 Getting ready for PSD2 on time! How online fashion retailer Zalando ...EBE 2020 Getting ready for PSD2 on time! How online fashion retailer Zalando ...
EBE 2020 Getting ready for PSD2 on time! How online fashion retailer Zalando ...
 
The end of passwords: Two-factor-authentication and biometrics are coming 2019
The end of passwords: Two-factor-authentication and biometrics are coming 2019The end of passwords: Two-factor-authentication and biometrics are coming 2019
The end of passwords: Two-factor-authentication and biometrics are coming 2019
 
[Ekata] Unlocking the Potential of PSD2 SCA.pdf
[Ekata] Unlocking the Potential of PSD2 SCA.pdf[Ekata] Unlocking the Potential of PSD2 SCA.pdf
[Ekata] Unlocking the Potential of PSD2 SCA.pdf
 
Digital Payment in 2020 - Kurt Schmid, Netcetera
Digital Payment in 2020 - Kurt Schmid, NetceteraDigital Payment in 2020 - Kurt Schmid, Netcetera
Digital Payment in 2020 - Kurt Schmid, Netcetera
 
3D-Secure 2.2 Webinar
3D-Secure 2.2 Webinar3D-Secure 2.2 Webinar
3D-Secure 2.2 Webinar
 
EBE 2019 - The end of passwords: Two-factor-authentication and biometrics are...
EBE 2019 - The end of passwords: Two-factor-authentication and biometrics are...EBE 2019 - The end of passwords: Two-factor-authentication and biometrics are...
EBE 2019 - The end of passwords: Two-factor-authentication and biometrics are...
 
Btl mastercard
Btl mastercardBtl mastercard
Btl mastercard
 
PSD2, SCA and the EBA’s Opinion on SCA – Decoded
PSD2, SCA and the EBA’s Opinion on SCA – DecodedPSD2, SCA and the EBA’s Opinion on SCA – Decoded
PSD2, SCA and the EBA’s Opinion on SCA – Decoded
 
Accenture-Payments-Regulation-Will-Disrupt-EU-Card-Payment-Ecosystem
Accenture-Payments-Regulation-Will-Disrupt-EU-Card-Payment-EcosystemAccenture-Payments-Regulation-Will-Disrupt-EU-Card-Payment-Ecosystem
Accenture-Payments-Regulation-Will-Disrupt-EU-Card-Payment-Ecosystem
 
Strong Customer Authentication & Biometrics
Strong Customer Authentication & BiometricsStrong Customer Authentication & Biometrics
Strong Customer Authentication & Biometrics
 
EPA PSD2 Presentation 23 February 2016
EPA PSD2 Presentation 23 February 2016EPA PSD2 Presentation 23 February 2016
EPA PSD2 Presentation 23 February 2016
 
QSecure Presentation at RSA 2011
QSecure Presentation at RSA 2011QSecure Presentation at RSA 2011
QSecure Presentation at RSA 2011
 
PSD2 Strategic options for banks_Accenture Strategy and Accenture Payment Ser...
PSD2 Strategic options for banks_Accenture Strategy and Accenture Payment Ser...PSD2 Strategic options for banks_Accenture Strategy and Accenture Payment Ser...
PSD2 Strategic options for banks_Accenture Strategy and Accenture Payment Ser...
 
Contactless Card Shipments Jump enabling Shoppers Take Advantage of Everyday ...
Contactless Card Shipments Jump enabling Shoppers Take Advantage of Everyday ...Contactless Card Shipments Jump enabling Shoppers Take Advantage of Everyday ...
Contactless Card Shipments Jump enabling Shoppers Take Advantage of Everyday ...
 
PCM_SoftFinance Article_p22and23
PCM_SoftFinance Article_p22and23PCM_SoftFinance Article_p22and23
PCM_SoftFinance Article_p22and23
 
Accenture-Banking-Opportunities-EU-PSD2-v2
Accenture-Banking-Opportunities-EU-PSD2-v2Accenture-Banking-Opportunities-EU-PSD2-v2
Accenture-Banking-Opportunities-EU-PSD2-v2
 
PSD2: Making it actionable
PSD2: Making it actionablePSD2: Making it actionable
PSD2: Making it actionable
 
Simont Braun - Webinar PSD3 PSR Evolution or Revolution?
Simont Braun - Webinar PSD3 PSR Evolution or Revolution?Simont Braun - Webinar PSD3 PSR Evolution or Revolution?
Simont Braun - Webinar PSD3 PSR Evolution or Revolution?
 

Recently uploaded

Accelerate your Kubernetes clusters with Varnish Caching
Accelerate your Kubernetes clusters with Varnish CachingAccelerate your Kubernetes clusters with Varnish Caching
Accelerate your Kubernetes clusters with Varnish Caching
Thijs Feryn
 
Assure Contact Center Experiences for Your Customers With ThousandEyes
Assure Contact Center Experiences for Your Customers With ThousandEyesAssure Contact Center Experiences for Your Customers With ThousandEyes
Assure Contact Center Experiences for Your Customers With ThousandEyes
ThousandEyes
 
SAP Sapphire 2024 - ASUG301 building better apps with SAP Fiori.pdf
SAP Sapphire 2024 - ASUG301 building better apps with SAP Fiori.pdfSAP Sapphire 2024 - ASUG301 building better apps with SAP Fiori.pdf
SAP Sapphire 2024 - ASUG301 building better apps with SAP Fiori.pdf
Peter Spielvogel
 
Essentials of Automations: The Art of Triggers and Actions in FME
Essentials of Automations: The Art of Triggers and Actions in FMEEssentials of Automations: The Art of Triggers and Actions in FME
Essentials of Automations: The Art of Triggers and Actions in FME
Safe Software
 
GenAISummit 2024 May 28 Sri Ambati Keynote: AGI Belongs to The Community in O...
GenAISummit 2024 May 28 Sri Ambati Keynote: AGI Belongs to The Community in O...GenAISummit 2024 May 28 Sri Ambati Keynote: AGI Belongs to The Community in O...
GenAISummit 2024 May 28 Sri Ambati Keynote: AGI Belongs to The Community in O...
Sri Ambati
 
Elizabeth Buie - Older adults: Are we really designing for our future selves?
Elizabeth Buie - Older adults: Are we really designing for our future selves?Elizabeth Buie - Older adults: Are we really designing for our future selves?
Elizabeth Buie - Older adults: Are we really designing for our future selves?
Nexer Digital
 
Generative AI Deep Dive: Advancing from Proof of Concept to Production
Generative AI Deep Dive: Advancing from Proof of Concept to ProductionGenerative AI Deep Dive: Advancing from Proof of Concept to Production
Generative AI Deep Dive: Advancing from Proof of Concept to Production
Aggregage
 
Epistemic Interaction - tuning interfaces to provide information for AI support
Epistemic Interaction - tuning interfaces to provide information for AI supportEpistemic Interaction - tuning interfaces to provide information for AI support
Epistemic Interaction - tuning interfaces to provide information for AI support
Alan Dix
 
Dev Dives: Train smarter, not harder – active learning and UiPath LLMs for do...
Dev Dives: Train smarter, not harder – active learning and UiPath LLMs for do...Dev Dives: Train smarter, not harder – active learning and UiPath LLMs for do...
Dev Dives: Train smarter, not harder – active learning and UiPath LLMs for do...
UiPathCommunity
 
UiPath Test Automation using UiPath Test Suite series, part 4
UiPath Test Automation using UiPath Test Suite series, part 4UiPath Test Automation using UiPath Test Suite series, part 4
UiPath Test Automation using UiPath Test Suite series, part 4
DianaGray10
 
PHP Frameworks: I want to break free (IPC Berlin 2024)
PHP Frameworks: I want to break free (IPC Berlin 2024)PHP Frameworks: I want to break free (IPC Berlin 2024)
PHP Frameworks: I want to break free (IPC Berlin 2024)
Ralf Eggert
 
Smart TV Buyer Insights Survey 2024 by 91mobiles.pdf
Smart TV Buyer Insights Survey 2024 by 91mobiles.pdfSmart TV Buyer Insights Survey 2024 by 91mobiles.pdf
Smart TV Buyer Insights Survey 2024 by 91mobiles.pdf
91mobiles
 
The Metaverse and AI: how can decision-makers harness the Metaverse for their...
The Metaverse and AI: how can decision-makers harness the Metaverse for their...The Metaverse and AI: how can decision-makers harness the Metaverse for their...
The Metaverse and AI: how can decision-makers harness the Metaverse for their...
Jen Stirrup
 
FIDO Alliance Osaka Seminar: Overview.pdf
FIDO Alliance Osaka Seminar: Overview.pdfFIDO Alliance Osaka Seminar: Overview.pdf
FIDO Alliance Osaka Seminar: Overview.pdf
FIDO Alliance
 
Leading Change strategies and insights for effective change management pdf 1.pdf
Leading Change strategies and insights for effective change management pdf 1.pdfLeading Change strategies and insights for effective change management pdf 1.pdf
Leading Change strategies and insights for effective change management pdf 1.pdf
OnBoard
 
FIDO Alliance Osaka Seminar: Passkeys and the Road Ahead.pdf
FIDO Alliance Osaka Seminar: Passkeys and the Road Ahead.pdfFIDO Alliance Osaka Seminar: Passkeys and the Road Ahead.pdf
FIDO Alliance Osaka Seminar: Passkeys and the Road Ahead.pdf
FIDO Alliance
 
Climate Impact of Software Testing at Nordic Testing Days
Climate Impact of Software Testing at Nordic Testing DaysClimate Impact of Software Testing at Nordic Testing Days
Climate Impact of Software Testing at Nordic Testing Days
Kari Kakkonen
 
Pushing the limits of ePRTC: 100ns holdover for 100 days
Pushing the limits of ePRTC: 100ns holdover for 100 daysPushing the limits of ePRTC: 100ns holdover for 100 days
Pushing the limits of ePRTC: 100ns holdover for 100 days
Adtran
 
Elevating Tactical DDD Patterns Through Object Calisthenics
Elevating Tactical DDD Patterns Through Object CalisthenicsElevating Tactical DDD Patterns Through Object Calisthenics
Elevating Tactical DDD Patterns Through Object Calisthenics
Dorra BARTAGUIZ
 
Quantum Computing: Current Landscape and the Future Role of APIs
Quantum Computing: Current Landscape and the Future Role of APIsQuantum Computing: Current Landscape and the Future Role of APIs
Quantum Computing: Current Landscape and the Future Role of APIs
Vlad Stirbu
 

Recently uploaded (20)

Accelerate your Kubernetes clusters with Varnish Caching
Accelerate your Kubernetes clusters with Varnish CachingAccelerate your Kubernetes clusters with Varnish Caching
Accelerate your Kubernetes clusters with Varnish Caching
 
Assure Contact Center Experiences for Your Customers With ThousandEyes
Assure Contact Center Experiences for Your Customers With ThousandEyesAssure Contact Center Experiences for Your Customers With ThousandEyes
Assure Contact Center Experiences for Your Customers With ThousandEyes
 
SAP Sapphire 2024 - ASUG301 building better apps with SAP Fiori.pdf
SAP Sapphire 2024 - ASUG301 building better apps with SAP Fiori.pdfSAP Sapphire 2024 - ASUG301 building better apps with SAP Fiori.pdf
SAP Sapphire 2024 - ASUG301 building better apps with SAP Fiori.pdf
 
Essentials of Automations: The Art of Triggers and Actions in FME
Essentials of Automations: The Art of Triggers and Actions in FMEEssentials of Automations: The Art of Triggers and Actions in FME
Essentials of Automations: The Art of Triggers and Actions in FME
 
GenAISummit 2024 May 28 Sri Ambati Keynote: AGI Belongs to The Community in O...
GenAISummit 2024 May 28 Sri Ambati Keynote: AGI Belongs to The Community in O...GenAISummit 2024 May 28 Sri Ambati Keynote: AGI Belongs to The Community in O...
GenAISummit 2024 May 28 Sri Ambati Keynote: AGI Belongs to The Community in O...
 
Elizabeth Buie - Older adults: Are we really designing for our future selves?
Elizabeth Buie - Older adults: Are we really designing for our future selves?Elizabeth Buie - Older adults: Are we really designing for our future selves?
Elizabeth Buie - Older adults: Are we really designing for our future selves?
 
Generative AI Deep Dive: Advancing from Proof of Concept to Production
Generative AI Deep Dive: Advancing from Proof of Concept to ProductionGenerative AI Deep Dive: Advancing from Proof of Concept to Production
Generative AI Deep Dive: Advancing from Proof of Concept to Production
 
Epistemic Interaction - tuning interfaces to provide information for AI support
Epistemic Interaction - tuning interfaces to provide information for AI supportEpistemic Interaction - tuning interfaces to provide information for AI support
Epistemic Interaction - tuning interfaces to provide information for AI support
 
Dev Dives: Train smarter, not harder – active learning and UiPath LLMs for do...
Dev Dives: Train smarter, not harder – active learning and UiPath LLMs for do...Dev Dives: Train smarter, not harder – active learning and UiPath LLMs for do...
Dev Dives: Train smarter, not harder – active learning and UiPath LLMs for do...
 
UiPath Test Automation using UiPath Test Suite series, part 4
UiPath Test Automation using UiPath Test Suite series, part 4UiPath Test Automation using UiPath Test Suite series, part 4
UiPath Test Automation using UiPath Test Suite series, part 4
 
PHP Frameworks: I want to break free (IPC Berlin 2024)
PHP Frameworks: I want to break free (IPC Berlin 2024)PHP Frameworks: I want to break free (IPC Berlin 2024)
PHP Frameworks: I want to break free (IPC Berlin 2024)
 
Smart TV Buyer Insights Survey 2024 by 91mobiles.pdf
Smart TV Buyer Insights Survey 2024 by 91mobiles.pdfSmart TV Buyer Insights Survey 2024 by 91mobiles.pdf
Smart TV Buyer Insights Survey 2024 by 91mobiles.pdf
 
The Metaverse and AI: how can decision-makers harness the Metaverse for their...
The Metaverse and AI: how can decision-makers harness the Metaverse for their...The Metaverse and AI: how can decision-makers harness the Metaverse for their...
The Metaverse and AI: how can decision-makers harness the Metaverse for their...
 
FIDO Alliance Osaka Seminar: Overview.pdf
FIDO Alliance Osaka Seminar: Overview.pdfFIDO Alliance Osaka Seminar: Overview.pdf
FIDO Alliance Osaka Seminar: Overview.pdf
 
Leading Change strategies and insights for effective change management pdf 1.pdf
Leading Change strategies and insights for effective change management pdf 1.pdfLeading Change strategies and insights for effective change management pdf 1.pdf
Leading Change strategies and insights for effective change management pdf 1.pdf
 
FIDO Alliance Osaka Seminar: Passkeys and the Road Ahead.pdf
FIDO Alliance Osaka Seminar: Passkeys and the Road Ahead.pdfFIDO Alliance Osaka Seminar: Passkeys and the Road Ahead.pdf
FIDO Alliance Osaka Seminar: Passkeys and the Road Ahead.pdf
 
Climate Impact of Software Testing at Nordic Testing Days
Climate Impact of Software Testing at Nordic Testing DaysClimate Impact of Software Testing at Nordic Testing Days
Climate Impact of Software Testing at Nordic Testing Days
 
Pushing the limits of ePRTC: 100ns holdover for 100 days
Pushing the limits of ePRTC: 100ns holdover for 100 daysPushing the limits of ePRTC: 100ns holdover for 100 days
Pushing the limits of ePRTC: 100ns holdover for 100 days
 
Elevating Tactical DDD Patterns Through Object Calisthenics
Elevating Tactical DDD Patterns Through Object CalisthenicsElevating Tactical DDD Patterns Through Object Calisthenics
Elevating Tactical DDD Patterns Through Object Calisthenics
 
Quantum Computing: Current Landscape and the Future Role of APIs
Quantum Computing: Current Landscape and the Future Role of APIsQuantum Computing: Current Landscape and the Future Role of APIs
Quantum Computing: Current Landscape and the Future Role of APIs
 

PSD2 and 3DS2. The impact.

  • 1. PSD2 and 3DS2 overview November 2018
  • 2. 2© 2018 Worldpay, LLC and/or its affiliates. All rights reserved. Agenda 01 PSD2 and SCA overview 02 3DS2 overview 03 Worldpay’s PSD2 and 3DS2 proposition
  • 3. 3© 2018 Worldpay, LLC and/or its affiliates. All rights reserved. PSD2 is an effort to improve the efficiency of the payments market Objectives: • More competition • More transparency • More innovation • Greater security • Lower fraud • Lower costs • Greater value to consumers • Etc…. PSD2 will have a major impact on all banks and PSPs, traditional and new PSD2 SEPA & honor all cards policy (until now) AML directive & fund transfer regulation Digital single market General data protection regulation E-money directive MIF regulation (interchange, application choice at the POS) EBA guidelines (RTS, security)
  • 4. 4© 2018 Worldpay, LLC and/or its affiliates. All rights reserved. What is Payment Services Directive 2 (PSD2)? Definitions and factors affecting PSD2 RTS Local Law Implementation Brexit  Aims to regulate payment services and payment service providers throughout the European Union  PSD2 Regulatory Technical standard (RTS) provide the technical specifications by which PSD2 will be implemented  Each Member State had to implement PSD2 into local law by 13 Jan 2018  PSD2 implemented by UK Government under the Payment Services Regulations 2017  The UK Financial Conduct Authority confirmed EU regulation will remain applicable to UK firms until any changes are made. The HMT Consultation confirms that until Brexit negotiations are concluded the UK remains a full member of the EU
  • 5. 5© 2018 Worldpay, LLC and/or its affiliates. All rights reserved. We are nearing the conclusion of the PSD2 / SCA journey Worldpay has played a very active role in helping to shape the new regulation Applies +18 months after publication WP Lobbied for Risk based exemption (TRA) and low value exemption increased from 10 Euro to 30 Euro WP will continue to lobby for level 3 guidance and Q&A on interpretation by EBA WP Lobbied for fraud calculation formula to apply to fraud prevented by SCA Applies +2 years after adoption Worldpay activities and key changes: WP influencing RTS interpretation with Visa as part of UK authentication steering group Jan-16 Q3-16 Mar-17 27/11/2017 Jan-18 14 Sept 1913 March-18 PSD2 Came into force in Europe Final draft RTS on SCA by the EU Commission European Commission published the Final RTS on SCA PSD2 Transposed in Member States domestic law First RTS on SCA Discussion Paper published Publication of the RTS on SCA in the Official Journal following scrutiny by the European Parliament and the Council RTS on SCA applies for all electronic transactions in Europe
  • 6. 6© 2018 Worldpay, LLC and/or its affiliates. All rights reserved. PSD2 mandates SCA for all electronic transactions Except if an exemption applies PSD2 SCA requires at least 2 of 3 factors of authentication… Something only the user knows Password Pin Signature Something only the user has Card Mobile phone Wearable device Something the user is (biometrics) Facial recognition Fingerprint Iris scan Extra element for Remote Transactions (Internet, Mobile): each SCA must be linked dynamically to a specific amount and a specific Payee
  • 7. 7© 2018 Worldpay, LLC and/or its affiliates. All rights reserved. There are exemptions and exclusions to SCA SCA exemptions SCA exclusions Some transactions can be exempted from SCA to help reduce friction Some transactions are completely out of scope of SCA Low risk transactions • Transactions that have been assessed as low risk in real time (TRA) and where PSP is below the fraud threshold Low value transactions • Remote electronic payment transactions ≤30EUR • Applies up to 5 consecutive payments or cumulative amount since last SCA is ≤ EUR 100 Whitelists of beneficiaries • No SCA unless when payer adds a merchant to a whitelist of the issuer Recurring transactions • Recurring transactions of a fixed value where the first and subsequent values are the same • SCA needs to apply on first transaction Corporate Payments • SCA is not required for B2B payments using a secure dedicated process • Corporate cards not used by persons e.g. lodged cards, virtual cards are exempted from SCA One leg out transactions • Payments where the issuer or the acquirer are based outside of the EEA are not required to perform SCA Merchant Initiated Transactions • Transactions initiated by the payee such as mobile phone payments and fixed and variable amount subscriptions or instalments • SCA needs to apply on first transaction/mandate MOTO • No need for SCA to be performed
  • 8. 8© 2018 Worldpay, LLC and/or its affiliates. All rights reserved. Low risk exemption is based on Transaction Risk Analysis (TRA) Transaction value (EUR) 0-100 100-250 250-500 500+ Reference fraud rate (%) Card Not Present based payments 0.13 0.06 0.01 N/A SCA on all transactions unless other exemption applies Fraud rates that allow SCA exemption – applied on PSP (issuer / acquirer level) Implications: • Merchants can request to exempt a transaction from SCA and assume liability • Exemption can only apply to Low Risk transactions based on real time TRA assessment • Merchants that operate below fraud thresholds can request the exemption and provide a frictionless experience
  • 9. 9© 2018 Worldpay, LLC and/or its affiliates. All rights reserved. Your fraud rate will have a major impact on your acceptance rate Decreased conversion and acceptance rates SCA required on all transactions High Fraud Increased conversion and acceptance rates Exemptions maximised; frictionless user experience Low fraud Merchant A Merchant B
  • 10. 10© 2018 Worldpay, LLC and/or its affiliates. All rights reserved. Issuers are expected to employ an array of SCA methods – many of which will be high friction. Exemptions can help avoid this SCA high-friction flow example: authentication using banking app redirect
  • 11. 11© 2018 Worldpay, LLC and/or its affiliates. All rights reserved. The whitelisting exemption is still in development. There are a number of potential implementation options During the payment After the payment Web/mobile banking 2 31 White Listing Prompt on authentication page White Listing Prompt on separate page White Listing via Mobile Banking Frameworks are still being defined to inform merchants that they have been whitelisted. Currently only issuers can apply the exemption – we are defining technology solutions for merchant involvement
  • 12. 12© 2018 Worldpay, LLC and/or its affiliates. All rights reserved. Agenda 01 PSD2 and SCA overview 02 3DS2 overview 03 Worldpay’s PSD2 and 3DS2 proposition
  • 13. 13© 2018 Worldpay, LLC and/or its affiliates. All rights reserved. PSD2 mandate for SCA changes the use and model of 3DS Now Post Sept 2019 Model Opt-in Opt-out Liability Merchant (unless 3DS applied) Issuer (Unless exemption applied from Merchant / Acquirer) User Experience Merchant controlled Issuer controlled (unless exemption applied from Merchant/ acquirer)
  • 14. 14© 2018 Worldpay, LLC and/or its affiliates. All rights reserved. 3DS2 represents a significant change, and will provide a number of benefits over 3DS1 3DS1 3DS2 Data • 5 Authentication data elements • Limited authentication models • Risk Based Authentication • Static passwords  10x more data elements to help issuers make better risk decisions  Superior authentication models including  Risk Based Authentication  Biometrics  One Time Passwords (OTP),  Out of band UX • Limited integration with merchant UX • Browser support only • Fragmented UX by issuers  Improved integration with merchant UX  Enhanced Browser support  Optimised for Mobile / native Apps  Support for SCA exemptions
  • 15. 15© 2018 Worldpay, LLC and/or its affiliates. All rights reserved. While 3DS1 created friction, it did bring benefits 3DS2 will enhance these benefits, supported by new mandates 3DS significantly reduces fraud 3DS increases authorisation rates 0.05% 3DS1 0.12% Non 3DS 0.29% 3DS2 Visa / MC Issuer target 95%92% 3DS1 3DS2Non 3DS 84% 3DS effect on drop offs MC Issuer target 3DS1 15% Non 3DS 3% 5% 3DS2 Low end High end Visa / MC Issuer target
  • 16. 16© 2018 Worldpay, LLC and/or its affiliates. All rights reserved. 3DS2 captures a lot more data 3DS 1.0 Current Authentication Data 3DS 2.0 Enhanced Authentication Data Acquirer BIN Acquirer Merchant ID Cardholder Account Number DS URL Message, Extension, Version Browser User-Agent More than 10X Data Source: Visa Amount Billing Address Billing City Billing country code Billing first name Billing last name Billing postal code Billing state Card expiry month Card expiry year Card number Currency code DF reference ID Email Mobile number Processor ID Merchant ID Transaction password Version Transaction mode Message type Transaction type Order number Shipping address Shipping state Shipping city Shipping country code Shipping postal code Billing phone number Billing phone number Billing phone Work phone Authentication indicator Product code 3RI Indicator Device channel Message Category Shipping method Travel departure date Travel passenger first name Travel passenger last name Travel origin Travel destination Travel airline carriers Instalment Purchase date Recurring end Recurring frequency Override payment method Category code Account age indicator Account create date Transaction count day Add card attempts Prior authentication data Prior authentication time Prior authentication method ACS window size Merchant URL Browser header IP address Account ID Item name Item description Item quantity Item price Tax amount Order description Mandatory Conditional Optional (not exhaustive list)
  • 17. 17© 2018 Worldpay, LLC and/or its affiliates. All rights reserved. 3DS2 flows: frictionless experience • Frictionless flow can be provided when an SCA exemption applies • Issuers will be able to leverage the increased data to make more informed risk based decisions • Shoppers do not see a challenge; liability is taken by the party who applied the exemption
  • 18. 18© 2018 Worldpay, LLC and/or its affiliates. All rights reserved. 3DS2 flows: out of band challenge experience • Out of Band challenges take the user away from the merchant’s site to authenticate and complete the payment • Out of band challenges can be completed on browser or mobile and will involve the shopper authenticating the payment in their online banking application
  • 19. 19© 2018 Worldpay, LLC and/or its affiliates. All rights reserved. 3DS2 flows: one time password • One time password challenges require a single-use code to be sent to the shopper. This could be sent via text or email • Retrieving this code usually directs the shopper out of the payment flow • Challenges can be completed on browser or mobile Source: Mastercard
  • 20. 20© 2018 Worldpay, LLC and/or its affiliates. All rights reserved. 3DS2 flows: biometric challenge experience • Biometrics involve using the shopper’s smart phone capabilities to authenticate themselves, this could be through fingerprint or facial ID readers • Visa and Mastercard are mandating that all issuers have capability to support a biometric challenge by 2020
  • 21. 21© 2018 Worldpay, LLC and/or its affiliates. All rights reserved. Agenda 01 PSD2 and SCA overview 02 3DS2 overview 03 Worldpay’s PSD2 and 3DS2 proposition
  • 22. 22© 2018 Worldpay, LLC and/or its affiliates. All rights reserved. The requirement for SCA will impact you in a number of ways Increased friction Increased cost Fraud rate scrutiny Dev work • While 3DS2 is a significant improvement on 3DS1, SCA rollout will still increase the number of steps that customers have to follow to complete a payment. This could create a poorer payment experience • Drop-out rates could increase, reducing your revenue and lowering customer loyalty • Undertaking 3DS2 will incur additional processing costs • Some card schemes have already doubled their scheme fees, or are expected to introduce additional fees, for authenticated transactions • Acquirers and issuers will now have to be below certain fraud thresholds in order to apply the low-risk SCA exemption • Therefore, there will be much more scrutiny of merchant fraud rates, and protections may be put in place to negate the impact of high-fraud merchants • While Worldpay will help merchants to hold this to a minimum, some development work will be required to gather additional data to complete TRA, and supply it to Worldpay (or any acquirer) via extended APIs
  • 23. 23© 2018 Worldpay, LLC and/or its affiliates. All rights reserved. Worldpay will provide a full suite of products to help you manage SCA Issuer 3DS2 Service Acquiring platform SCA Exemption Engine FraudSight WP Gateway Exemption applied Exemption applied or SCA Worldpay PSD2 and 3DS2 Service Merchant 3 key components: • SCA Exemption Engine to exempt as many transactions as possible from SCA/3DS2 – reducing friction and cutting cost • 3DS2 Merchant Plug In (MPI) to ensure you can perform SCA whenever it is required • New industry-leading fraud tool to help you lower your fraud and maximise which SCA exemptions can be used 2 3 1 2 3 1
  • 24. 24© 2018 Worldpay, LLC and/or its affiliates. All rights reserved. Worldpay will provide a full suite of products to help you manage SCA Exemption applied or SCA Issuer 3DS2 Service Acquiring platform FraudSight WP Gateway Exemption applied Worldpay PSD2 and 3DS2 Service Merchant 2 3 SCA Exemption Engine 1 SCA Exemption Engine  Reasonably exempt as many EEA transactions as possible from SCA  Multiple exemption models – merchant request and managed  Worldpay real-time risk assessment of transactions and validation of exemption for submission to issuer
  • 25. 25© 2018 Worldpay, LLC and/or its affiliates. All rights reserved. Worldpay will provide a full suite of products to help you manage SCA IssuerAcquiring platform FraudSight WP Gateway Exemption applied Worldpay PSD2 and 3DS2 Service Merchant 3 SCA Exemption Engine 1 Exemption applied or SCA 3DS2 Service 2 Intelligent Authentication Service  New 3DS2 MPI - PSD2 SCA compliant  Better user experience  Improved authentication models including frictionless  Better risk decisions by sharing more data elements  Optimised for mobile and native apps
  • 26. 26© 2018 Worldpay, LLC and/or its affiliates. All rights reserved. Worldpay will provide a full suite of products to help you manage SCA IssuerAcquiring platform WP Gateway Exemption applied Worldpay PSD2 and 3DS2 Service Merchant SCA Exemption Engine 1 3DS2 Service 2 Exemption applied or SCA FraudSight  State of the Art fraud engine using machine learning and behavioural analytics  Standalone fraud management product; will also have features to help with SCA  Full FraudSight service can assess transaction risk and request exemptions FraudSight 3
  • 27. 27© 2018 Worldpay, LLC and/or its affiliates. All rights reserved. SCA exemptions and 3DS2 can minimise friction and maximise conversion Issuers will support multiple SCA methods – banking app authentication and SMS One Time Password (OTP) will be most prevalent SCA Exemption A SCA with 3DS2 B
  • 28. 28© 2018 Worldpay, LLC and/or its affiliates. All rights reserved. This service will benefit you in 6 key ways Improved user experience: Maximising exemptions to avoid stepping up to 3DS2 where possible – maintaining conversions and protecting revenue Reduced cost: Utilising exemptions to avoid additional authentication processing costs Simplicity: End-to-end service through a single integration Data: As an acquirer and a gateway, Worldpay has access to significant data to better inform SCA risk decisions Fraud reduction: Worldpay is providing fraud consultations and new reporting tools to help you better understand and track your fraud, as well as launching our new FraudSight risk tool Flexibility: Within the rules of SCA, we will give you as much control as possible to ensure that the solution works for your business A B C D E F
  • 29. 29© 2018 Worldpay, LLC and/or its affiliates. All rights reserved. What does this mean for you? Fraud management • Manage and lower your fraud rates to make sure that you can utilise low-risk SCA exemptions • Use 3DS and add SCA compliant payment options such as Apple Pay, Google Pay and Samsung Pay 3DS2 roadmap • It is critical that you have 3DS2 on your development roadmap, well in advance of the September 2019 deadline • If you do not use 3DS1 today, we recommend that you integrate to and test this service to increase your familiarity with how it will work User Experience • When SCA must be triggered, much of the control over UX will shift to issuers • Maximise your use of SCA exemptions for good transactions to enable a frictionless user experience

Editor's Notes

  1. This journey started in Jan 2016 when the directive came in force Lobbying with some major merchants on topics such as MIT
  2. SCA needs to be based on 2 out 3 elements Dynamic linking – links authentication to authorisation, so that the authenticatoin can only be used once and for one specific transactoin PSD2 – liability always with issuer Dimensions opt-in / opt-out Liability Low risk / high risk Each SCA must be linked to a specific amount and payee (merchant) Payer must be made aware of merchant details and amount when authenticating Authentication code can only be used once Authentication code is only for the transaction linked to specific merchant and amount Cryptographic token must be send by acquirer to issuer only for that specific transaction Issuer to validate that authentication token matches with merchant name and amount in authorisation
  3. Low value 6th payment has SCA Voice commerce
  4. We want to make sure our merchants can use this exemption as much as possible to maintain a frictionless experience We believe we will be able to offer our merchants exemptions in the first two bands – merchants that Merchants need to reduce their fraud or risk for SCA to be applied to all their transactions 6 data points Abnormal behaviour/ spending Device ID Location of payer Location of payee Malware detection Fraud patterns
  5. 3DS not mandated (EU issuer adoption rates by country between 10 – 60%) Issuer has obligation to apply SCA on all transactions – acquirers can request an exemption to be applied Many merchants apply 3DS only to a subset of transactions – typically the high risk one to shift the liability
  6. 3DS 1 was developed in 1999 – almost 20 years old 3DS is a very effective mechanism to reduce fraud
  7. How are we