Interactive Single Rulebook

The Interactive Single Rulebook is an on-line tool that provides a comprehensive compendium of  the level 1 text for the Capital Requirements Regulation (CRR) and the Capital Requirements Directive (CRD IV); Bank Recovery and Resolution Directive (BRRD); the Deposit Guarantee Schemes Directive (DGSD); and the Payments Services Directive (PSD2)  the corresponding technical standards developed by the European Banking Authority (EBA) and adopted by the European Commission (RTS and ITS), as well as the EBA Guidelines and related Q&As.
The purpose of the Single Rulebook is to ensure the consistent application of the regulatory banking framework across the EU.
This Interactive Single Rulebook is meant purely as a documentation tool and the EBA does not assume any liability for its contents. For the authentic version of EU legislation users should refer to the Official Journal of the European Union.
Please click on the relevant legislative text to see technical standards, guidelines and Q&As relating to each Article.

« Back

Interactive Single Rulebook

Path Payment Services Directive > TITLE IV > CHAPTER 5 > Article 97 (Copy link to article)
Title Article 97
Description Authentication
Main content


1. Member States shall ensure that a payment service provider applies strong customer authentication where the payer:

(a) accesses its payment account online;

(b) initiates an electronic payment transaction;

(c) carries out any action through a remote channel which may imply a risk of payment fraud or other abuses.

2. With regard to the initiation of electronic payment transactions as referred to in point (b) of paragraph 1, Member States shall ensure that, for electronic remote payment transactions, payment service providers apply strong customer authentication that includes elements which dynamically link the transaction to a specific amount and a specific payee.

3. With regard to paragraph 1, Member States shall ensure that payment service providers have in place adequate security measures to protect the confidentiality and integrity of payment service users’ personalised security credentials.

4. Paragraphs 2 and 3 shall also apply 

where payments are initiated through a payment initiation service provider. Paragraphs 1 and 3 shall also apply when the information is requested through an account information service provider.

5. Member States shall ensure that the account servicing payment service provider allows the payment initiation service provider and the account information service provider to rely on the authentication procedures provided by the account servicing payment service provider to the payment service user in accordance with paragraphs 1 and 3 and, where the payment initiation service provider is involved, in accordance with paragraphs 1, 2 and 3.