This affects salons and barbershops that take payments on line.
What is Strong Customer Authentication SCA?
From 14 September 2019, new EU rules will start to apply that impact the way in which banks or payment services providers verify their customers identity and validate specific payment instructions. The new rules, called Strong Customer Authentication (SCA), are intended to enhance the security of payments and limit fraud during this authentication process.
In essence, Clients who pay you on line by card will have to provide you an additional piece of information where payment is more than the equivalent of 30 euros. This is additional to their CSV number – for example: a PIN, password, smartphone fingerprint or even face recognition. Banks will start declining the payment if not.
This does not apply to payments taken over the phone.
What’s the latest?
The FCA in August 2019 agreed an 18-month plan to implement SCA with the e-commerce industry of card issuers, payments firm and online retailers. The plan reflects the recent opinion of the European Banking Authority (EBA) which set out that more time was needed to implement SCA given the complexity of the requirements, a lack of preparedness and the potential for a significant impact on consumers.
Jonathan Davidson, Executive Director for Supervision – Retail and Authorisations, said:
‘The FCA has been working with the industry to put in place stronger means of ensuring that anyone seeking to make payments is not a fraudster. While these measures will reduce fraud, we want to make sure that they won’t cause material disruption to consumers themselves; so we have agreed a phased plan for their timely introduction’.
The FCA will not take enforcement action against firms if they do not meet the relevant requirements for SCA from 14 September 2019 in areas covered by the agreed plan, where there is evidence that they have taken the necessary steps to comply with the plan. At the end of the 18-month period, the FCA expects all firms to have made the necessary changes and undertaken the required testing to apply SCA.
The FCA will also continue to monitor the extent to which banks and payment service providers are meeting its expectation that they consider the impact of SCA on different groups of consumers, and provide alternative means of authentication where needed.
What do you need to do?
If you take payments via your website, ensure your payments software provider is geared up for this change; and you may want to add additional information to your website letting your Clients know of the changes.