EU Payment Services Directive (PSD2)
Evidence request list. 19 controls, 19 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
PSD2: Authorisation of Payment Transactions and Open Banking (PIS / AIS)
Article 64 sets the consent rule: a payment transaction is considered to be authorised only if the payer has given consent to execute the payment transaction; consent may be given via a form agreed between the PSU and the PSP. Article 65 establishes the confirmation-of-availability-of-funds mechanism: a card-based PSP issuing a card-based payment instrument linked to a payment account held with another account-servicing PSP (ASPSP) may request the ASPSP to confirm whether an amount necessary for the execution of a card-based payment transaction is available, subject to: (a) explicit consent of the PSU to the requesting PSP; (b) explicit consent of the PSU to the ASPSP at the time of the first request; (c) the answer is limited to a simple yes/no (no balance disclosure); (d) the answer must not allow the requesting PSP to store the response or use it for any other purpose; (e) the PSU mus
- Consent capture + record evidence (Article 64 form)
- Article 65 yes/no protocol implementation + non-storage proof + PSU-informed flow
- Confirmation-of-funds responses stored or repurposed in breach of Article 65(1)(d)
- Card-based PSP not surfacing the request to the PSU per Article 65(2)
Article 66 (PIS) gives PSUs the right to use a payment initiation service provider (PISP) when the underlying payment account is accessible online. The PISP must: be authorised; have explicit consent from the PSU; not hold the PSU's funds in connection with the provision of the PIS; not store sensitive payment data of the PSU; not request data other than necessary; not use / access / store data for purposes other than the provision of the payment initiation service explicitly requested by the PSU; not modify the amount + payee + any other feature of the transaction; treat personalised security credentials as secure. ASPSPs must communicate with PISPs in a secure manner under Article 98 RTS and must not block PISP access. Article 67 (AIS) gives PSUs the right to use an account information service provider (AISP) when the underlying payment account is accessible online. The AISP must: have
- Article 98 RTS compliant ASPSP interface (dedicated or modified PSU interface)
- PISP / AISP consent capture + audit trail
- Quarterly statistics report under SCA-RTS
- Performance + availability KPIs of the ASPSP interface
- ASPSP blocks or imposes contractual relationship on AISP / PISP in breach of Article 66(5) / 67(4)
- AISP requesting sensitive payment data (not allowed under Article 67(2)(d))
- PISP storing / repurposing PSU data beyond the requested service
Article 71 PSU notification obligation: PSU must notify the PSP without undue delay on becoming aware of any unauthorised / incorrectly executed transaction and no later than 13 months after the debit date. Article 74 liability of the payer: in case of unauthorised payment transaction the payer's maximum out-of-pocket liability is EUR 50 (reduced from EUR 150 under PSD1) unless the payer (a) was unable to detect the loss before payment + (b) the loss was not caused by acts or omissions of an employee + agent of the PSP; the payer bears all losses if acted fraudulently or with gross negligence; the payer is not liable after notification under Article 69. Article 75 PSP refund obligation: PSP must refund the payer with effect from the date the debit was made for an unauthorised transaction immediately and in any event no later than the end of the following business day, after the PSP has b
- Workflow ensuring same / next-business-day refund of unauthorised transactions after PSU notification
- Article 74 EUR 50 cap application + fraud / gross-negligence exception decision-tree
- Article 76 8-week direct-debit refund mechanism
- Refund delayed beyond next business day after notification of unauthorised transaction
- Charging the payer beyond the EUR 50 cap without documented fraud / gross-negligence determination
- Refusing the 8-week direct-debit refund without documenting that the authorisation specified exact amount and the amount was not unexpected
PSD2: Authorisation, Capital and Safeguarding of Payment Institutions
PSD2 Article 10 requires payment institutions to safeguard the funds received from PSUs (or via another PSP) for the execution of payment transactions. Two safeguarding methods are available: (a) Article 10(1)(a) segregation - funds must not be commingled with any other natural / legal person other than the PSUs on whose behalf the funds are held; if still held by the PI at the end of the next business day they must be deposited in a separate account in a credit institution OR invested in low-risk Article 4(7) UCITS-eligible secure liquid low-risk assets defined by the competent authority; in the event of insolvency the segregated funds must be insolvency-remote from PI creditors; or (b) Article 10(1)(b) insurance - funds covered by an insurance policy / comparable guarantee from an insurance company / credit institution that does not belong to the same group, for an amount equivalent to
- Safeguarding policy specifying Article 10(1)(a) segregation or Article 10(1)(b) insurance
- Daily-end safeguarding reconciliation evidence
- Insurance policy / comparable guarantee from an unaffiliated provider
- Legal opinion on insolvency-remoteness of the safeguarding arrangement
- Funds held overnight without Article 10(1)(a) end-of-next-business-day segregation
- Insurance policy from a group entity (failing the Article 10(1)(b) unaffiliated requirement)
- Failure to safeguard funds received by an agent on behalf of the PI
Article 11 requires the national competent authority to grant authorisation within 3 months of receiving a complete application; the authorisation is valid throughout the Union. Article 13 sets the grounds for withdrawal: PI does not commence business within 12 months / ceases for more than 6 months / obtained the authorisation by false statements / no longer fulfils the conditions / serious threat to the stability of / confidence in / payment system / Article 22 breach. Article 14 requires the EBA to develop, operate and maintain an electronic, central register containing information on payment institutions + their agents + Article 32 small-PI-exempted entities + Article 33 AIS-only registered entities. Article 15 sets the publication + access rules for the EBA register. Articles 28-29 + Article 30 set the EU-passport regime: PIs may exercise the right of establishment / freedom to prov
- Authorisation certificate from the home Member State competent authority
- Notification file for passporting (establishment / services)
- EBA-register search result confirming public visibility
- Passport service provision without home Member State notification + 1-month forwarding cycle
- Failure to update the EBA register when the agent network changes
Article 19 permits payment institutions to use agents to provide payment services in the name of the PI. Agents must be entered into the EBA register; the PI must communicate to the home Member State the agent's name + address + suitability of directors / persons responsible for AML / CFT + payment services to be provided. The PI remains fully liable for the conduct of its agents. Article 20 governs operational outsourcing: outsourcing of important operational functions, including IT systems, must not impair materially the quality of the PI's internal control + the ability of the competent authority to monitor; it must not deteriorate the conditions for authorisation; not affect the relationship + obligations of the PI to its PSUs; not affect PI's contractual obligations to home + host Member States. Article 20(2) prohibits letter-box-entity outsourcing arrangements; Article 20(3) requir
- Agent register + suitability checks evidence + AML/CFT controls + agent training
- Outsourcing register identifying important operational functions
- Article 20 outsourcing contract clauses (audit rights + termination + business continuity + sub-outsourcing notice)
- Article 20(3) notifications for material outsourcing arrangements
- Important operational function outsourced to a letter-box entity (Article 20(2))
- No notification to the competent authority for outsourcing of important operational functions
- Agent network without per-agent AML/CFT controls
Article 32 allows Member States to grant a derogation from the full authorisation regime for small payment institutions where the monthly average over the preceding 12 months of the total amount of payment transactions executed by the person does not exceed EUR 3 million per month + the person has not been convicted of money laundering / terrorist financing / other financial crime. Small-PI exemption does NOT confer EU-passport rights. Article 33 establishes a registration-only regime for account information service providers (AIS-only). AIS providers must hold professional indemnity insurance OR a comparable guarantee against liability under Article 90 (AIS liability for unauthorised access to a payment account). AIS-only providers must comply with Articles 5(1)(a)-(c) + (e)-(h) + (j) + (l) + (n)-(p) + (r) + Articles 14-15 + 22-25 + 28 + 29 + 30 + 31 + 95 + 96 + 98 (but not the safeguar
- Article 32 exemption application + monthly volume monitoring + EUR 3M cap evidence
- Article 33 AIS-only registration + Article 5(2) professional indemnity insurance + AIS-aware policy compliance
- Small-PI claiming EU-passport rights it does not have
- AIS-only provider without the Article 5(2) professional indemnity insurance
PSD2 Article 5 lists the application documents for payment institution authorisation: programme of operations + business plan including a forecast budget for the first 3 financial years + structural organisation including outsourcing arrangements + audited statement of initial capital + measures for safeguarding (Article 10) + governance arrangements + internal-control mechanisms + risk-management procedures + statistical-data + security policy document + security incident management + sensitive payment data management + business continuity + principles for security + identity and suitability checks on directors + qualifying shareholders + statutory auditor + legal status + head office + Article 5(3) Money-Laundering / CFT description. Article 7 sets the initial capital floor: EUR 20,000 for money-remittance-only PIs; EUR 50,000 for PIS-only PIs; EUR 125,000 for full PSPs offering Annex
- Authorisation file submitted to the national competent authority
- Annual own-funds calculation (Article 9 Methods A/B/C) and supervisory reporting
- Initial-capital and ongoing-capital monitoring against the Article 7 floor
- Initial-capital calculation that mixes the EUR 20K / 50K / 125K thresholds for different service classes
- Own-funds Method A/B/C selection without documented rationale or competent-authority approval
PSD2: Operational Security, Strong Customer Authentication and Incident Reporting
Article 94 grounds the data-processing activities of PSD2 actors (ASPSPs, PISPs, AISPs, payment systems, payment service providers + their agents and outsourcees) in the GDPR. Personal data may be processed by payment systems / PSPs only where necessary to safeguard the prevention / investigation / detection of payment fraud (Article 94(1)). PSPs shall obtain explicit consent from PSUs to access / process / retain personal data necessary for the provision of the payment service - this is a PSD2-specific consent for service-provision-purpose, distinct from GDPR consent as a lawful basis (Article 94(2)). The Article 94 consent regime is the legal hook on which the EDPB Guidelines 06/2020 + 02/2023 (on the interplay between PSD2 + GDPR) and the EDPB Letter to the Commission on PSD3 / PSR clarify that GDPR remains the data-protection framework, but Article 94(2) imposes an additional service
- Article 94(2) explicit-consent capture at onboarding / service activation
- Data-protection impact assessment (GDPR Article 35) for PIS / AIS / fraud-prevention processing
- Special-category-data handling where biometric inherence elements under Article 97 are used (GDPR Article 9 implications)
- Conflating GDPR consent (Article 6(1)(a)) with PSD2 Article 94(2) service-specific consent
- Storing biometric inherence elements without an Article 9(2) GDPR derogation
Article 95 imposes operational + security risk management obligations on PSPs. Article 95(1): PSPs must establish a framework with appropriate mitigation measures + control mechanisms to manage the operational + security risks relating to the payment services they provide. As part of that framework PSPs must establish + maintain effective incident management procedures, including for the detection + classification of major operational + security incidents. Article 95(2): PSPs must provide, on an annual basis, an updated and comprehensive assessment of the operational + security risks relating to the payment services they provide and on the adequacy of the mitigation measures + control mechanisms implemented in response to those risks. Article 95(3): EBA in close cooperation with the ECB issued the EBA Guidelines on the security measures for operational + security risks (EBA/GL/2017/17, a
- Article 95 risk-management framework documentation
- Annual Article 95(2) risk assessment + competent-authority submission
- EBA/GL/2019/04 ICT and security risk management compliance gap analysis
- Major-incident detection + classification rules tied to Article 96 reporting
- Annual Article 95(2) assessment skipped or not submitted to the competent authority
- Risk-management framework that does not cover ICT supply-chain risk (now overlapping with DORA Article 28)
Article 96 requires PSPs to notify, without undue delay, the home Member State competent authority of any major operational or security incident. Where the incident has or may have an impact on the financial interests of its PSUs, the PSP shall, without undue delay, inform its PSUs of the incident and of all measures that they can take to mitigate the adverse effects of the incident. The home competent authority shall, without undue delay, provide the EBA + the ECB with the relevant details of the incident; after assessment of the relevance of the incident to other relevant authorities in the Member State, the home competent authority shall notify them accordingly. The EBA + the ECB shall assess in cooperation with the home authority the relevance of the incident to other relevant Union authorities and shall notify them accordingly. EBA Guidelines EBA/GL/2017/10 (revised by EBA/GL/2021/0
- Article 96 reporting workflow with classification criteria from EBA/GL/2021/03
- Initial / intermediate / final report templates with submission timestamps
- PSU communication template for incidents with financial-interest impact
- Cross-reference between Article 96 (PSD2) and Article 19 DORA major-incident reporting (post-17 Jan 2025 the DORA regime applies in parallel for in-scope PSPs)
- Major incident not classified per EBA/GL/2021/03 criteria
- Delayed submission of the intermediate / final report
- Failure to inform PSUs of incidents with potential financial-interest impact
Article 97 mandates Strong Customer Authentication (SCA) by PSPs when the payer (a) accesses its payment account online; (b) initiates an electronic payment transaction; (c) carries out any action through a remote channel which may imply a risk of payment fraud or other abuses. SCA is defined in Article 4(30) as an authentication based on the use of two or more elements categorised as: knowledge (something only the user knows, e.g. password / PIN / answer to a secret question - not username / email which are identifiers); possession (something only the user possesses, e.g. token + smart card + phone running an authentication app); inherence (something the user is, e.g. fingerprint + face + voice biometric); the elements must be independent so that the breach of one does not compromise the reliability of the others. For electronic remote payment transactions (Article 97(2)) SCA must inclu
- SCA architecture documentation including category mapping (knowledge / possession / inherence)
- Dynamic-linking evidence for remote electronic payments
- Independence proof between SCA elements (Article 9 SCA-RTS, breach-isolation analysis)
- Article 97(3) credential-protection controls (encryption + secure element + tamper-evidence)
- Using 'username + password' as SCA (username is an identifier, not a knowledge element)
- Same channel + same device + no independence between elements
- Static linking of remote payment elements (amount + payee not bound to the SCA)
Article 98 empowered the EBA to develop Regulatory Technical Standards on SCA + common and secure communication (CSC). The Commission adopted these as Commission Delegated Regulation (EU) 2018/389 of 27 November 2017 on 13 March 2018 (effective 14 September 2019 after the 18-month transition). The RTS specifies: SCA elements + Article 9 independence; Article 10 information on payment accounts exemption; Article 11 contactless low-value (cumulative limits EUR 50 + 5 transactions / EUR 150 cumulative); Article 12 unattended terminals for transport + parking; Article 13 trusted beneficiaries whitelist; Article 14 recurring transactions; Article 15 credit transfers between accounts of the same PSU at the same ASPSP; Article 16 low-value remote (single EUR 30 + cumulative EUR 100 + 5 transactions); Article 17-18 corporate-payment + risk-based Transaction Risk Analysis (TRA) exemption tiered b
- SCA-RTS compliance file by exemption used
- Quarterly statistics under Article 32 SCA-RTS
- Article 33 contingency mechanism design + Article 33(6) test reports
- ASPSP-interface availability + performance KPIs (95th percentile + 99th percentile) + Article 32(5) parity-with-PSU-interface check
- Failing to publish quarterly statistics on the ASPSP interface
- Treating the SCA-RTS as a recommendation rather than directly-applicable Regulation
- No contingency mechanism documented + tested under Article 33
PSD2: Scope and Definitions
PSD2 Articles 1-4 establish the rules under which Member States must distinguish six categories of payment service providers (PSPs): credit institutions; e-money institutions; post-office giro institutions; payment institutions (PIs); ECB / national central banks acting in non-monetary-policy capacity; Member States / regional / local authorities acting in non-public-authority capacity (Article 1). Article 2 sets the territorial + currency scope including the 2-leg EU rule for all currencies + the one-leg-out rule for the parts of EU-side transactions in any currency (extending PSD1's two-leg-euro/EEA scope). Article 3 lists negative-scope exclusions including commercial-agent + limited-network + cash-machine + telecommunications (the limited-network and electronic-communication-services exclusions are narrower than under PSD1). Article 4 defines the 48 key terms including 'payment servi
- Internal scope memo identifying which PSD2 payment services (Annex I, items 1-8) the entity provides
- Definitional walk-through for PIS / AIS / payment account / sensitive payment data as transposed in national law
- Entity treats limited-network or electronic-communications-service exclusions broadly without the Article 3(k) / (l) narrowing
- Failure to register PIS/AIS activity as a regulated activity under PSD2
PSD2: Supervision, Penalties and Final Provisions
Article 104 empowers the Commission to adopt delegated acts (notably the Article 98 SCA-RTS adopted as Commission Delegated Regulation (EU) 2018/389). Articles 105-108 set the EBA's role in developing RTS / ITS / Guidelines (including EBA/GL/2017/17, EBA/GL/2019/04, EBA/GL/2017/10, EBA/GL/2021/03 + the EBA single rulebook for payment services). Article 107 sets the Commission review by 13 January 2021. Article 108 amends 2002/65/EC + 2009/110/EC + 2013/36/EU + (EU) 1093/2010. Article 109 repeals Directive 2007/64/EC (PSD1) with effect from 13 January 2018. Article 110 sets the Member State transposition deadline of 13 January 2018 and the SCA-RTS application date of 14 September 2019 (the 18-month period after the SCA-RTS Article 38). Article 111 sets the review of the Article 32 small-PI exemption + Article 33 AIS-only exemption. Article 117 sets the entry into force on the twentieth da
- EBA Guidelines / RTS register and gap-analysis (EBA/GL/2017/10 + 2017/17 + 2019/04 + 2021/03)
- PSD1-to-PSD2 transition documentation
- Tracking of the PSD3 + PSR legislative pipeline for transposition planning
- Compliance program treating PSD2 as static (failing to track EBA guidelines + RTS updates)
- No transition planning for PSD3 + PSR
Article 5(3) requires PSD2 authorisation applications to include a description of the PI's internal-control mechanisms for AML/CFT in accordance with the 4th + now 5th + 6th Anti-Money-Laundering Directives and Regulation (EU) 2015/847 on information accompanying transfers of funds. Article 19 requires the PI to verify the suitability of agents including AML/CFT-related fitness + propriety. Article 22 designates competent authorities + their AML cooperation. Article 22(2) requires PSPs to report suspicious activities to the financial intelligence unit (FIU) under the AMLD. The PSD2 AML interface remains critical for PIS / AIS providers despite their non-handling of funds because they generate authentication + transactional data relevant to fraud + AML monitoring. The AML Regulation (Regulation (EU) 2024/1624) + the 6th AMLD will fully apply from 10 July 2027 in parallel.
- Article 5(3) AML/CFT description in the authorisation file
- Agent AML/CFT fitness + propriety records
- FIU suspicious-activity reporting workflow + statistics
- Regulation 2015/847 fund-transfer information completeness check
- Outsourcing AML controls to a third party without retained accountability
- Agent network without per-agent AML/CFT controls
Article 99 obliges Member States to ensure adequate + effective out-of-court complaint + redress procedures for disputes between PSUs and PSPs. Article 100 designates competent authorities. Article 101 requires PSPs to operate complaint procedures responding within 15 business days (extendable to 35 in exceptional cases). Article 102 requires Member States to provide for effective + proportionate + dissuasive penalties for infringements of national provisions transposing PSD2. Article 103 requires home + host Member State cooperation. Member-State penalties have ranged from administrative fines (e.g. up to EUR 5 million or 10% of annual turnover under certain transpositions for serious infringements) to authorisation withdrawal. The Article 102 penalty regime sits alongside (a) the GDPR penalty regime for data-protection infringements; (b) the DORA (Regulation (EU) 2022/2554) administrat
- Article 101 complaint-handling procedure with 15 business-day response + 35-day exceptional path
- Out-of-court redress + ADR procedure + ODR-platform integration
- Article 102 transposition map for the specific Member State (penalty bands)
- Tracking of cross-border supervisory matters (Article 103)
- Complaint-response taking longer than 15 business days without invoking Article 101 exceptional grounds
- No ADR / ODR integration
PSD2 remains the in-force EU payment-services framework. The European Commission adopted, on 28 June 2023, two proposals to update the EU payments framework: (a) COM(2023) 366 - the proposed Payment Services Directive 3 (PSD3); (b) COM(2023) 367 - the proposed Payment Services Regulation (PSR). The proposals split the current PSD2 regime into a Directive (covering authorisation + supervision of payment institutions) and a directly-applicable Regulation (covering substantive rules including SCA + Open Banking + transparency + fraud liability). Notable proposed changes: harmonised IBAN + name check; tighter SCA + accessibility provisions; enhanced fraud-liability + IBAN-name-mismatch refund regime; improved Open Banking interface performance + dashboards for PSU consent management; merging the E-Money Directive 2 (EMD2) into PSD3. As of 2026-05-28 the PSD3 + PSR are in EU trilogues. Until
- Tracking of PSD3 + PSR legislative pipeline and Council / Parliament agreements
- Internal-readiness gap analysis between PSD2 + PSR (likely impact areas: IBAN name check, fraud-liability, Open Banking interface dashboards)
- No transition planning for PSD3 + PSR
PSD2: Transparency, Information and Consumer Protection
Title III imposes layered transparency + information requirements differentiated by transaction type (single payment vs framework contract) and PSU (consumer vs business / micro-enterprise can opt out of certain provisions under Article 38(2)). Common rules (Art 38-43): charges for information must be appropriate and in line with actual costs; currency-conversion rules; information must be on paper or durable medium. Single payment transactions (Art 44-48): pre-contract information including unique identifier + maximum execution time + charges + exchange rate. Framework contracts (Art 49-58): pre-contract information including PSP identity + payment service description + execution times + safeguards + charges + interest rates + change-of-terms procedure with 2-month notice + termination + dispute resolution; Art 53 minimum requirements; Art 54 change-of-terms; Art 55 termination with no
- Pre-contract + post-contract disclosure templates aligned with Articles 44-60
- Annual disclosure-quality audit
- Charges / SHA-rule documentation
- Surcharge ban compliance check at the merchant interface
- Pre-contract information missing the Article 52 minimum elements
- Mid-term change of terms without the 2-month Article 54 notice
- Surcharging SEPA CT / DD instruments in breach of Article 60(4)
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the EU Payment Services Directive (PSD2) framework page.