SardineCon SF/2026

Learn More
Regulation & bodies4 min de leitura

O que é PSD2?

SUBSCRIBE

PSD2 is the EU's revised Payment Services Directive, which mandates strong customer authentication for many electronic payments and opens bank account access to licensed third parties. It cut some card fraud sharply but shifted risk toward scams and account-access abuse, so your controls have to follow where the risk moved.

What is PSD2, in plain English?

PSD2 is the European Union's revised Payment Services Directive, and it did two big things at once. First, it introduced strong customer authentication, requiring most electronic payments to be verified with at least two independent factors, such as something the customer knows, has, or is. Second, it created open banking, forcing banks to let licensed third parties access account data and initiate payments with the customer's consent.

The authentication rule was aimed squarely at fraud. By requiring two factors, PSD2 made it much harder for a criminal with only a stolen card number to push a payment through, which cut certain card-not-present fraud materially. The open-banking side reshaped the payments ecosystem, adding new licensed players and new access points.

The important nuance for operators is that PSD2 did not remove fraud risk; it moved it. Harder authentication pushed criminals toward tricking the customer into approving the payment themselves, and open access created new surfaces your monitoring has to cover.

How PSD2 moved fraud risk

The clearest way to think about PSD2 is what it added and what it displaced:

What changes

Before PSD2

After PSD2

Card-not-present fraud

Stolen card number often enough

Two-factor authentication blocks many attempts

Dominant scam

Unauthorized card use

Authorized push payment scams

Account access

Bank-only

Licensed third parties via open banking

Where risk sits

At the card network

At the customer and the access layer

Who is involved?

Who

Their role

Account-servicing banks

Must apply strong customer authentication and open access to licensed third parties.

Third-party providers

Licensed firms that access accounts or initiate payments with customer consent.

Customers

Authenticate payments and, under APP scams, can be tricked into approving them.

Fraud teams

Extend monitoring to the new access points and to scam-driven authorized payments.

What it looks like in practice

In practice

After PSD2, a bank sees its unauthorized card-not-present fraud fall as two-factor authentication blocks attempts that used to sail through on a stolen number. The fraud team celebrates briefly, then notices a different curve rising.

Scammers now phone customers posing as the bank's fraud department and walk them through approving a payment to a so-called safe account, passing the authentication step themselves because the customer is doing it willingly. The loss did not disappear; it migrated from unauthorized card fraud to authorized push payment scams. The team responds by building behavioral and payee-risk monitoring around outbound transfers, because the authentication control cannot catch a payment the victim authorized.

Why PSD2 matters to operators

PSD2 is a case study in how a fraud control reshapes the threat rather than ending it. Strong customer authentication genuinely reduced unauthorized card fraud, but it made authorized push payment scams the growth area, and those defeat authentication by design because the victim approves the payment. Any team relying on authentication alone will watch losses reappear in the outbound-transfer channel.

The open-banking side adds a second lesson: new licensed third parties and access points expand the surface your monitoring must cover. PSD2 means fraud controls cannot stand still. As the directive moved the risk, effective teams moved their detection toward scam behavior, payee risk, and third-party access rather than doubling down on the login step.

What to watch

  • APP scam growth. Watch for rising authorized push payment losses even as unauthorized card fraud falls; the risk migrates, it does not vanish.
  • Coached authentication. Victims completing two-factor steps under a scammer's guidance is a signal authentication alone cannot catch.
  • Open-banking access. Monitor third-party access to accounts as a distinct surface, not just direct customer logins.
  • Payee risk. New or high-risk payees on outbound transfers deserve scrutiny, since the payment itself is authorized.
  • Exemption abuse. Attackers probe for low-risk authentication exemptions; watch for patterns that steer payments into them.

Quick questions

What is strong customer authentication?

A PSD2 requirement that most electronic payments be verified with at least two independent factors from knowledge, possession, and inherence. It makes stolen card numbers alone far less useful to fraudsters.

Did PSD2 reduce fraud?

It reduced certain unauthorized card-not-present fraud materially. But it shifted risk toward authorized push payment scams and account-access abuse, so total fraud did not simply disappear; it moved.

What is open banking under PSD2?

The requirement that banks give licensed third-party providers access to account information and payment initiation, with the customer's consent. It created new players and new access points in the payments ecosystem.

Why does PSD2 not stop APP scams?

Because in an authorized push payment scam the victim is tricked into approving the payment themselves, so they complete the authentication willingly. The control verifies identity, not whether the customer was deceived.

Does PSD2 apply outside the EU?

It is EU law, but firms serving EU customers or handling EU payments must comply, and similar authentication standards have influenced practice elsewhere. Its concepts have spread well beyond the EU.

What should fraud teams do in response?

Extend monitoring to outbound transfers, payee risk, scam behavior, and third-party access, rather than relying on authentication alone. The directive moved the risk, so detection has to follow it.

Go deeper

  • FATF ↗ — The global standard-setter for AML, counter-terrorist-financing, and counter-proliferation. Recommendations, guidance, and jurisdiction lists.
  • FinCEN ↗ — The US financial intelligence unit. Bank Secrecy Act rules, advisories, and SAR and CTR guidance.

O que saber junto com PSD2