{
  "name": "PSR obligations register",
  "locale": "en",
  "url": "https://openfinanceguide.com/en/dsp3/obligations",
  "license": "CC BY-SA 4.0",
  "numbering": "Provisional numbering of the April 2026 compromise (Council doc. 8221/26). `articleFinal` is filled once the Official Journal publishes the text; ids never change.",
  "documents": {
    "8221/26": "https://data.consilium.europa.eu/doc/document/ST-8221-2026-INIT/en/pdf",
    "8222/26": "https://data.consilium.europa.eu/doc/document/ST-8222-2026-INIT/en/pdf"
  },
  "stetEdition": "1.6.3",
  "count": 73,
  "obligations": [
    {
      "id": "OB-IF-001",
      "url": "https://openfinanceguide.com/en/dsp3/obligations/ob-if-001",
      "article": "PSR 35(1)",
      "alsoIn": [],
      "articleFinal": null,
      "actors": [
        "aspsp"
      ],
      "roles": [
        "compliance",
        "api",
        "infra"
      ],
      "appliesAt": "T+21",
      "title": "At least one dedicated interface per ASPSP",
      "level1": "Every ASPSP offering a payment account accessible online must have at least one dedicated interface for exchanging data with AISPs and PISPs.",
      "level2": null,
      "origin": [
        {
          "act": "rts-2018-389",
          "articles": "31"
        }
      ],
      "stet": {
        "1.6.3": {
          "status": "present",
          "note": "STET 1.6.3 specifies a dedicated interface for the AISP, PISP and CBPII roles.",
          "pages": [
            "https://openfinanceguide.com/en/stet/1.6.3/endpoints/aisp",
            "https://openfinanceguide.com/en/stet/1.6.3/endpoints/pisp",
            "https://openfinanceguide.com/en/stet/1.6.3/endpoints/cbpii"
          ]
        }
      },
      "verification": null,
      "sources": [
        {
          "document": "8221/26",
          "page": 238,
          "url": "https://data.consilium.europa.eu/doc/document/ST-8221-2026-INIT/en/pdf#page=238"
        }
      ],
      "verifiedAt": "2026-10-04"
    },
    {
      "id": "OB-IF-002",
      "url": "https://openfinanceguide.com/en/dsp3/obligations/ob-if-002",
      "article": "PSR 35(2)",
      "alsoIn": [],
      "articleFinal": null,
      "actors": [
        "aspsp"
      ],
      "roles": [
        "compliance",
        "infra"
      ],
      "appliesAt": "T+21",
      "title": "Interface live within three months of authorisation",
      "level1": "A newly authorised ASPSP puts its dedicated interface in place within three months, hands the documentation without undue delay to TPPs and applicants, and always keeps access open so their business can continue.",
      "level2": null,
      "origin": [],
      "stet": {
        "1.6.3": {
          "status": "out-of-scope",
          "note": "The deadline and business continuity belong to operations, not to the specification.",
          "pages": []
        }
      },
      "verification": null,
      "sources": [
        {
          "document": "8221/26",
          "page": 238,
          "url": "https://data.consilium.europa.eu/doc/document/ST-8221-2026-INIT/en/pdf#page=238"
        }
      ],
      "verifiedAt": "2026-10-04"
    },
    {
      "id": "OB-IF-003",
      "url": "https://openfinanceguide.com/en/dsp3/obligations/ob-if-003",
      "article": "PSR 35(3)",
      "alsoIn": [],
      "articleFinal": null,
      "actors": [
        "aspsp"
      ],
      "roles": [
        "api",
        "compliance"
      ],
      "appliesAt": "T+21",
      "title": "Recognised communication standards",
      "level1": "The dedicated interface uses communication standards issued by European or international standardisation bodies, including CEN and ISO, or other relevant, widely recognised standards offering equivalent security.",
      "level2": {
        "mandate": "PSR 89(1)(f)",
        "instrument": "rts",
        "deadline": "T+12",
        "link": "reading"
      },
      "origin": [
        {
          "act": "rts-2018-389",
          "articles": "30(3)"
        }
      ],
      "stet": {
        "1.6.3": {
          "status": "present",
          "note": "STET reuses ISO 20022 data elements but is issued neither by CEN nor by ISO. It is the clause on other widely recognised standards that covers it.",
          "pages": [
            "https://openfinanceguide.com/en/stet/1.6.3/framework/3-prerequisites-and-technical-details"
          ]
        }
      },
      "verification": null,
      "sources": [
        {
          "document": "8221/26",
          "page": 239,
          "url": "https://data.consilium.europa.eu/doc/document/ST-8221-2026-INIT/en/pdf#page=239"
        }
      ],
      "verifiedAt": "2026-10-04"
    },
    {
      "id": "OB-IF-004",
      "url": "https://openfinanceguide.com/en/dsp3/obligations/ob-if-004",
      "article": "PSR 35(3)",
      "alsoIn": [],
      "articleFinal": null,
      "actors": [
        "aspsp"
      ],
      "roles": [
        "api",
        "product",
        "compliance"
      ],
      "appliesAt": "T+21",
      "title": "Free technical documentation and public summary",
      "level1": "The ASPSP documents its interface's technical specifications, hands them free of charge and without undue delay to authorised TPPs and applicants who ask, and publishes a summary on its website.",
      "level2": null,
      "origin": [
        {
          "act": "rts-2018-389",
          "articles": "30(3)"
        }
      ],
      "stet": {
        "1.6.3": {
          "status": "out-of-scope",
          "note": "The STET specification is public. What remains to document is each bank's own, such as URLs, scopes, the options it took and its limits.",
          "pages": []
        }
      },
      "verification": null,
      "sources": [
        {
          "document": "8221/26",
          "page": 239,
          "url": "https://data.consilium.europa.eu/doc/document/ST-8221-2026-INIT/en/pdf#page=239"
        }
      ],
      "verifiedAt": "2026-10-04"
    },
    {
      "id": "OB-IF-005",
      "url": "https://openfinanceguide.com/en/dsp3/obligations/ob-if-005",
      "article": "PSR 35(4)",
      "alsoIn": [],
      "articleFinal": null,
      "actors": [
        "aspsp"
      ],
      "roles": [
        "api",
        "product",
        "compliance"
      ],
      "appliesAt": "T+21",
      "title": "Two months' notice before any change",
      "level1": "Except in emergencies, any change to the dedicated interface's specifications is published, at least on the ASPSP's website, as early as possible and at least two months before it goes live, and emergencies are documented for the authority.",
      "level2": null,
      "origin": [
        {
          "act": "rts-2018-389",
          "articles": "30(4)"
        }
      ],
      "stet": {
        "1.6.3": {
          "status": "out-of-scope",
          "note": "Notice is handled in the bank's release cycle. The 2018 RTS require three months.",
          "pages": []
        }
      },
      "verification": null,
      "sources": [
        {
          "document": "8221/26",
          "page": 240,
          "url": "https://data.consilium.europa.eu/doc/document/ST-8221-2026-INIT/en/pdf#page=240"
        }
      ],
      "verifiedAt": "2026-10-04"
    },
    {
      "id": "OB-IF-006",
      "url": "https://openfinanceguide.com/en/dsp3/obligations/ob-if-006",
      "article": "PSR 35(5)",
      "alsoIn": [],
      "articleFinal": null,
      "actors": [
        "aspsp"
      ],
      "roles": [
        "infra",
        "compliance"
      ],
      "appliesAt": "T+21",
      "title": "Quarterly statistics published",
      "level1": "Each quarter the ASPSP publishes on its website the availability, unplanned unavailability and performance of the dedicated interface and of the customer interface, performance being the success rate of AIS requests and of PIS requests by number and by amount.",
      "level2": {
        "mandate": "PSR 38(5)",
        "instrument": "rts",
        "deadline": "T+9",
        "link": "named"
      },
      "origin": [
        {
          "act": "rts-2018-389",
          "articles": "32(4)"
        }
      ],
      "stet": {
        "1.6.3": {
          "status": "out-of-scope",
          "note": "Measurement and publication happen on the operations side. The method will come from the Article 38(5) RTS.",
          "pages": []
        }
      },
      "verification": null,
      "sources": [
        {
          "document": "8221/26",
          "page": 241,
          "url": "https://data.consilium.europa.eu/doc/document/ST-8221-2026-INIT/en/pdf#page=241"
        }
      ],
      "verifiedAt": "2026-10-04"
    },
    {
      "id": "OB-IF-007",
      "url": "https://openfinanceguide.com/en/dsp3/obligations/ob-if-007",
      "article": "PSR 35(6)",
      "alsoIn": [],
      "articleFinal": null,
      "actors": [
        "aspsp"
      ],
      "roles": [
        "api",
        "infra"
      ],
      "appliesAt": "T+21",
      "title": "Testing facility with support",
      "level1": "The ASPSP gives authorised TPPs and applicants a testing facility with support, for connection and functional testing, with no sensitive payment data or other personal data.",
      "level2": null,
      "origin": [
        {
          "act": "rts-2018-389",
          "articles": "30(5)"
        }
      ],
      "stet": {
        "1.6.3": {
          "status": "out-of-scope",
          "note": "STET does not describe a sandbox. Each bank provides its own.",
          "pages": []
        }
      },
      "verification": null,
      "sources": [
        {
          "document": "8221/26",
          "page": 241,
          "url": "https://data.consilium.europa.eu/doc/document/ST-8221-2026-INIT/en/pdf#page=241"
        }
      ],
      "verifiedAt": "2026-10-04"
    },
    {
      "id": "OB-IF-008",
      "url": "https://openfinanceguide.com/en/dsp3/obligations/ob-if-008",
      "article": "PSR 35(7)",
      "alsoIn": [],
      "articleFinal": null,
      "actors": [
        "aspsp"
      ],
      "roles": [
        "api"
      ],
      "appliesAt": "T+21",
      "title": "Error messages that explain the cause",
      "level1": "When an unexpected event or error occurs during identification, authentication or data exchange, the ASPSP sends the TPP a message explaining the reason.",
      "level2": null,
      "origin": [
        {
          "act": "rts-2018-389",
          "articles": "36(2)"
        }
      ],
      "stet": {
        "1.6.3": {
          "status": "present",
          "note": "The `ErrorModel` schema carries a mandatory `message` and a list of `details`, and the Framework defines codes such as `FORMAT_ERROR` or `ACCESS_EXCEEDED`.",
          "pages": [
            "https://openfinanceguide.com/en/stet/1.6.3/resources/error-model",
            "https://openfinanceguide.com/en/stet/1.6.3/framework/3-prerequisites-and-technical-details"
          ]
        }
      },
      "verification": null,
      "sources": [
        {
          "document": "8221/26",
          "page": 242,
          "url": "https://data.consilium.europa.eu/doc/document/ST-8221-2026-INIT/en/pdf#page=242"
        }
      ],
      "verifiedAt": "2026-10-04"
    },
    {
      "id": "OB-IF-009",
      "url": "https://openfinanceguide.com/en/dsp3/obligations/ob-if-009",
      "article": "PSR 36(2)(b)",
      "alsoIn": [
        "PSR 36(1)(a)",
        "PSR 36(1)(b)"
      ],
      "articleFinal": null,
      "actors": [
        "aspsp"
      ],
      "roles": [
        "api",
        "pentest"
      ],
      "appliesAt": "T+21",
      "title": "Authentication started by the TPP, protected session",
      "level1": "The interface lets the TPP ask the ASPSP to start authentication based on the user's consent, keeps the session between the parties open throughout authentication, and protects the integrity and confidentiality of credentials and authentication codes.",
      "level2": {
        "mandate": "PSR 89(1)(e)",
        "instrument": "rts",
        "deadline": "T+12",
        "link": "named"
      },
      "origin": [
        {
          "act": "rts-2018-389",
          "articles": "30(2)"
        }
      ],
      "stet": {
        "1.6.3": {
          "status": "present",
          "note": "In redirect or decoupled mode, the TPP triggers authentication at the bank, through the OAuth2 authorisation for the AISP and through the payment request for the PISP, over a mutually authenticated TLS connection.",
          "pages": [
            "https://openfinanceguide.com/en/stet/1.6.3/framework/3-prerequisites-and-technical-details",
            "https://openfinanceguide.com/en/stet/1.6.3/flows/6-1-psu-context-retrieval",
            "https://openfinanceguide.com/en/stet/1.6.3/endpoints/pisp/payment-requests-post"
          ]
        }
      },
      "verification": null,
      "sources": [
        {
          "document": "8221/26",
          "page": 242,
          "url": "https://data.consilium.europa.eu/doc/document/ST-8221-2026-INIT/en/pdf#page=242"
        },
        {
          "document": "8221/26",
          "page": 243,
          "url": "https://data.consilium.europa.eu/doc/document/ST-8221-2026-INIT/en/pdf#page=243"
        }
      ],
      "verifiedAt": "2026-10-04"
    },
    {
      "id": "OB-IF-010",
      "url": "https://openfinanceguide.com/en/dsp3/obligations/ob-if-010",
      "article": "PSR 37(1)",
      "alsoIn": [
        "PSR 36(1)(c)",
        "PSR 38(2b)"
      ],
      "articleFinal": null,
      "actors": [
        "aspsp"
      ],
      "roles": [
        "infra",
        "compliance"
      ],
      "appliesAt": "T+21",
      "title": "Parity with the customer interface",
      "level1": "The dedicated interface offers at all times at least the same availability and performance as the customer interface, technical support included, and does not respond more slowly than it.",
      "level2": null,
      "origin": [
        {
          "act": "rts-2018-389",
          "articles": "32(1)"
        }
      ],
      "stet": {
        "1.6.3": {
          "status": "out-of-scope",
          "note": "A specification cannot guarantee a service level. The comparison is made on the Article 35(5) statistics.",
          "pages": []
        }
      },
      "verification": null,
      "sources": [
        {
          "document": "8221/26",
          "page": 247,
          "url": "https://data.consilium.europa.eu/doc/document/ST-8221-2026-INIT/en/pdf#page=247"
        },
        {
          "document": "8221/26",
          "page": 242,
          "url": "https://data.consilium.europa.eu/doc/document/ST-8221-2026-INIT/en/pdf#page=242"
        },
        {
          "document": "8221/26",
          "page": 249,
          "url": "https://data.consilium.europa.eu/doc/document/ST-8221-2026-INIT/en/pdf#page=249"
        }
      ],
      "verifiedAt": "2026-10-04"
    },
    {
      "id": "OB-IF-011",
      "url": "https://openfinanceguide.com/en/dsp3/obligations/ob-if-011",
      "article": "PSR 38(1)",
      "alsoIn": [],
      "articleFinal": null,
      "actors": [
        "aspsp"
      ],
      "roles": [
        "infra",
        "compliance"
      ],
      "appliesAt": "T+21",
      "title": "Unavailability presumed after five failed requests",
      "level1": "The ASPSP keeps planned unavailability to what is strictly necessary and works to prevent the rest, and the interface is presumed unavailable when five consecutive requests get a server error or no response within 30 seconds.",
      "level2": null,
      "origin": [
        {
          "act": "rts-2018-389",
          "articles": "33(1)"
        }
      ],
      "stet": {
        "1.6.3": {
          "status": "out-of-scope",
          "note": "The rule is monitored on the operations side. STET defines no timeout and no error threshold.",
          "pages": []
        }
      },
      "verification": null,
      "sources": [
        {
          "document": "8221/26",
          "page": 248,
          "url": "https://data.consilium.europa.eu/doc/document/ST-8221-2026-INIT/en/pdf#page=248"
        }
      ],
      "verifiedAt": "2026-10-04"
    },
    {
      "id": "OB-IF-012",
      "url": "https://openfinanceguide.com/en/dsp3/obligations/ob-if-012",
      "article": "PSR 38(2)",
      "alsoIn": [],
      "articleFinal": null,
      "actors": [
        "aspsp"
      ],
      "roles": [
        "infra",
        "product"
      ],
      "appliesAt": "T+21",
      "title": "Maintenance announced a month ahead, from 00:00 to 06:00",
      "level1": "Except for emergency changes, the ASPSP announces each planned unavailability and its duration to TPPs at least one month ahead, and it normally takes place between 00:00 and 06:00, in the ASPSP's local time according to recital 57.",
      "level2": null,
      "origin": [],
      "stet": {
        "1.6.3": {
          "status": "out-of-scope",
          "note": "STET has no status endpoint and no maintenance calendar. The announcement goes through the bank's developer portal.",
          "pages": []
        }
      },
      "verification": null,
      "sources": [
        {
          "document": "8221/26",
          "page": 248,
          "url": "https://data.consilium.europa.eu/doc/document/ST-8221-2026-INIT/en/pdf#page=248"
        },
        {
          "document": "8221/26",
          "page": 46,
          "url": "https://data.consilium.europa.eu/doc/document/ST-8221-2026-INIT/en/pdf#page=46"
        }
      ],
      "verifiedAt": "2026-10-04"
    },
    {
      "id": "OB-IF-013",
      "url": "https://openfinanceguide.com/en/dsp3/obligations/ob-if-013",
      "article": "PSR 38(2a)",
      "alsoIn": [],
      "articleFinal": null,
      "actors": [
        "aspsp"
      ],
      "roles": [
        "infra"
      ],
      "appliesAt": "T+21",
      "title": "TPPs kept informed during an outage",
      "level1": "During unplanned unavailability, the ASPSP promptly tells TPPs what it is doing to restore the interface and how long it expects the fix to take, and ensures an optimal recovery time.",
      "level2": {
        "mandate": "PSR 38(5)",
        "instrument": "rts",
        "deadline": "T+9",
        "link": "named"
      },
      "origin": [
        {
          "act": "rts-2018-389",
          "articles": "33(2)"
        }
      ],
      "stet": {
        "1.6.3": {
          "status": "out-of-scope",
          "note": "STET has nothing for signalling an outage to TPPs. The recovery time will be set by the Article 38(5) RTS.",
          "pages": []
        }
      },
      "verification": null,
      "sources": [
        {
          "document": "8221/26",
          "page": 249,
          "url": "https://data.consilium.europa.eu/doc/document/ST-8221-2026-INIT/en/pdf#page=249"
        }
      ],
      "verifiedAt": "2026-10-04"
    },
    {
      "id": "OB-IF-014",
      "url": "https://openfinanceguide.com/en/dsp3/obligations/ob-if-014",
      "article": "PSR 39(1)",
      "alsoIn": [],
      "articleFinal": null,
      "actors": [
        "aspsp",
        "nca"
      ],
      "roles": [
        "compliance"
      ],
      "appliesAt": "T+21",
      "title": "Derogation from the dedicated interface",
      "level1": "At the ASPSP's request, the competent authority may exempt it from the dedicated interface and allow it either to open its customer interface, if that interface offers equivalent functions with widely accepted, interoperable standards, or to offer no interface at all where justified.",
      "level2": {
        "mandate": "PSR 39(2)",
        "instrument": "rts",
        "deadline": "T+12",
        "link": "named"
      },
      "origin": [
        {
          "act": "rts-2018-389",
          "articles": "31, 33(6)"
        }
      ],
      "stet": {
        "1.6.3": {
          "status": "out-of-scope",
          "note": "The derogation is a decision of the competent authority, outside the specification's scope.",
          "pages": []
        }
      },
      "verification": null,
      "sources": [
        {
          "document": "8221/26",
          "page": 251,
          "url": "https://data.consilium.europa.eu/doc/document/ST-8221-2026-INIT/en/pdf#page=251"
        }
      ],
      "verifiedAt": "2026-10-04"
    },
    {
      "id": "OB-IF-015",
      "url": "https://openfinanceguide.com/en/dsp3/obligations/ob-if-015",
      "article": "PSR 45(1)",
      "alsoIn": [],
      "articleFinal": null,
      "actors": [
        "aisp",
        "pisp"
      ],
      "roles": [
        "compliance",
        "api"
      ],
      "appliesAt": "T+21",
      "title": "TPP access through the dedicated interface only",
      "level1": "AISPs and PISPs access payment account data only through the dedicated interface, except under an Article 39 derogation or, exceptionally, through another safe and efficient interface.",
      "level2": null,
      "origin": [
        {
          "act": "rts-2018-389",
          "articles": "33(4)"
        }
      ],
      "stet": {
        "1.6.3": {
          "status": "out-of-scope",
          "note": "The obligation is about the channel the TPP chooses. A TPP connected to the bank's STET API meets it.",
          "pages": []
        }
      },
      "verification": null,
      "sources": [
        {
          "document": "8221/26",
          "page": 265,
          "url": "https://data.consilium.europa.eu/doc/document/ST-8221-2026-INIT/en/pdf#page=265"
        },
        {
          "document": "8221/26",
          "page": 60,
          "url": "https://data.consilium.europa.eu/doc/document/ST-8221-2026-INIT/en/pdf#page=60"
        }
      ],
      "verifiedAt": "2026-10-04"
    },
    {
      "id": "OB-IF-016",
      "url": "https://openfinanceguide.com/en/dsp3/obligations/ob-if-016",
      "article": "PSR 45(2)",
      "alsoIn": [],
      "articleFinal": null,
      "actors": [
        "aisp",
        "pisp"
      ],
      "roles": [
        "compliance",
        "infra"
      ],
      "appliesAt": "T+21",
      "title": "TPP duties on the customer interface",
      "level1": "When only the Article 39 interface is available, the TPP identifies itself, sends the dashboard information, relies on the ASPSP's authentication, processes data only for the service requested and logs the data accessed, with logs deleted after three years.",
      "level2": null,
      "origin": [
        {
          "act": "rts-2018-389",
          "articles": "33(5)"
        }
      ],
      "stet": {
        "1.6.3": {
          "status": "out-of-scope",
          "note": "This case assumes there is no dedicated API.",
          "pages": []
        }
      },
      "verification": null,
      "sources": [
        {
          "document": "8221/26",
          "page": 265,
          "url": "https://data.consilium.europa.eu/doc/document/ST-8221-2026-INIT/en/pdf#page=265"
        },
        {
          "document": "8221/26",
          "page": 266,
          "url": "https://data.consilium.europa.eu/doc/document/ST-8221-2026-INIT/en/pdf#page=266"
        }
      ],
      "verifiedAt": "2026-10-04"
    },
    {
      "id": "OB-IF-017",
      "url": "https://openfinanceguide.com/en/dsp3/obligations/ob-if-017",
      "article": "PSR 36(2)(a)",
      "alsoIn": [
        "PSR 46(1)(f)",
        "PSR 47(1)(c)"
      ],
      "articleFinal": null,
      "actors": [
        "aspsp",
        "aisp",
        "pisp"
      ],
      "roles": [
        "api",
        "infra",
        "pentest"
      ],
      "appliesAt": "T+21",
      "title": "TPP identification towards the ASPSP",
      "level1": "The interface lets AISPs and PISPs identify themselves towards the ASPSP, and they do so at every payment initiation for the PISP and at every session for the AISP.",
      "level2": {
        "mandate": "PSR 89(1)(e)",
        "instrument": "rts",
        "deadline": "T+12",
        "link": "named"
      },
      "origin": [
        {
          "act": "rts-2018-389",
          "articles": "30(1)(a), 34"
        },
        {
          "act": "psd2",
          "articles": "66(3)(d), 67(2)(c)"
        }
      ],
      "stet": {
        "1.6.3": {
          "status": "present",
          "note": "STET identifies the TPP with an eIDAS QWAC over mTLS and checks that the `client_id` matches the authorisation number in the certificate. The PSR does not say how the TPP identifies itself.",
          "pages": [
            "https://openfinanceguide.com/en/stet/1.6.3/framework/3-prerequisites-and-technical-details"
          ]
        }
      },
      "verification": null,
      "sources": [
        {
          "document": "8221/26",
          "page": 243,
          "url": "https://data.consilium.europa.eu/doc/document/ST-8221-2026-INIT/en/pdf#page=243"
        },
        {
          "document": "8221/26",
          "page": 268,
          "url": "https://data.consilium.europa.eu/doc/document/ST-8221-2026-INIT/en/pdf#page=268"
        },
        {
          "document": "8221/26",
          "page": 269,
          "url": "https://data.consilium.europa.eu/doc/document/ST-8221-2026-INIT/en/pdf#page=269"
        }
      ],
      "verifiedAt": "2026-10-04"
    },
    {
      "id": "OB-IF-018",
      "url": "https://openfinanceguide.com/en/dsp3/obligations/ob-if-018",
      "article": "PSR 40(c)",
      "alsoIn": [
        "PSR 41(1)(b)"
      ],
      "articleFinal": null,
      "actors": [
        "aspsp"
      ],
      "roles": [
        "infra",
        "compliance"
      ],
      "appliesAt": "T+21",
      "title": "TPP requests treated like the customer's own",
      "level1": "The ASPSP treats a payment order sent through a PISP like one placed directly by the payer, in particular as to timing, priority and charges, and an AISP's data request like the user's own request in the customer interface.",
      "level2": null,
      "origin": [
        {
          "act": "psd2",
          "articles": "66(4)(c), 67(3)(b)"
        }
      ],
      "stet": {
        "1.6.3": {
          "status": "out-of-scope",
          "note": "This is about how the bank processes requests, which the specification does not settle.",
          "pages": []
        }
      },
      "verification": null,
      "sources": [
        {
          "document": "8221/26",
          "page": 254,
          "url": "https://data.consilium.europa.eu/doc/document/ST-8221-2026-INIT/en/pdf#page=254"
        },
        {
          "document": "8221/26",
          "page": 255,
          "url": "https://data.consilium.europa.eu/doc/document/ST-8221-2026-INIT/en/pdf#page=255"
        }
      ],
      "verifiedAt": "2026-10-04"
    },
    {
      "id": "OB-AIS-001",
      "url": "https://openfinanceguide.com/en/dsp3/obligations/ob-ais-001",
      "article": "PSR 33(2)",
      "alsoIn": [
        "PSR 33(1)"
      ],
      "articleFinal": null,
      "actors": [
        "aspsp"
      ],
      "roles": [
        "compliance",
        "product"
      ],
      "appliesAt": "T+21",
      "title": "All payment accounts accessible online",
      "level1": "No payment service provider may prevent the user from using an AISP or a PISP, and the right covers all of the user's payment accounts accessible online.",
      "level2": null,
      "origin": [
        {
          "act": "psd2",
          "articles": "66(1), 67(1)"
        }
      ],
      "stet": {
        "1.6.3": {
          "status": "present",
          "note": "`AccountResource` models current accounts (`CACC`) as well as card accounts (`CARD`).",
          "pages": [
            "https://openfinanceguide.com/en/stet/1.6.3/endpoints/aisp/accounts-get",
            "https://openfinanceguide.com/en/stet/1.6.3/resources/account-resource"
          ]
        }
      },
      "verification": null,
      "sources": [
        {
          "document": "8221/26",
          "page": 236,
          "url": "https://data.consilium.europa.eu/doc/document/ST-8221-2026-INIT/en/pdf#page=236"
        }
      ],
      "verifiedAt": "2026-10-04"
    },
    {
      "id": "OB-AIS-002",
      "url": "https://openfinanceguide.com/en/dsp3/obligations/ob-ais-002",
      "article": "PSR 36(3)",
      "alsoIn": [],
      "articleFinal": null,
      "actors": [
        "aspsp"
      ],
      "roles": [
        "api",
        "product"
      ],
      "appliesAt": "T+21",
      "title": "Minimum data for the AISP",
      "level1": "The AISP receives at least the account identifier, the account holder's name, the currencies, the balance, and payment-instrument transactions not yet charged to the account if the customer interface shows them.",
      "level2": null,
      "origin": [],
      "stet": {
        "1.6.3": {
          "status": "present",
          "note": "STET carries the IBAN and currency in `accountId`, the holders in `GET /accounts/{id}/owners` since 1.5.0, the balances, and pending transactions with status `PDNG`. The `accountId` field is still optional in the schema, while the text makes the identifier mandatory.",
          "pages": [
            "https://openfinanceguide.com/en/stet/1.6.3/endpoints/aisp/accounts-get",
            "https://openfinanceguide.com/en/stet/1.6.3/endpoints/aisp/accounts-owners-get",
            "https://openfinanceguide.com/en/stet/1.6.3/endpoints/aisp/accounts-balances-get",
            "https://openfinanceguide.com/en/stet/1.6.3/endpoints/aisp/accounts-transactions-get"
          ]
        }
      },
      "verification": null,
      "sources": [
        {
          "document": "8221/26",
          "page": 244,
          "url": "https://data.consilium.europa.eu/doc/document/ST-8221-2026-INIT/en/pdf#page=244"
        }
      ],
      "verifiedAt": "2026-10-04"
    },
    {
      "id": "OB-AIS-003",
      "url": "https://openfinanceguide.com/en/dsp3/obligations/ob-ais-003",
      "article": "PSR 37(2)",
      "alsoIn": [],
      "articleFinal": null,
      "actors": [
        "aspsp"
      ],
      "roles": [
        "api",
        "product"
      ],
      "appliesAt": "T+21",
      "title": "Data parity with the customer interface",
      "level1": "The ASPSP gives the AISP at least the information on designated accounts and their transactions that the user sees when consulting directly, excluding sensitive payment data.",
      "level2": null,
      "origin": [
        {
          "act": "rts-2018-389",
          "articles": "36(1)(a)"
        }
      ],
      "stet": {
        "1.6.3": {
          "status": "partial",
          "note": "The STET data model is closed. Information the customer interface shows and that no STET resource carries does not reach the AISP.",
          "pages": [
            "https://openfinanceguide.com/en/stet/1.6.3/endpoints/aisp"
          ]
        }
      },
      "verification": null,
      "sources": [
        {
          "document": "8221/26",
          "page": 247,
          "url": "https://data.consilium.europa.eu/doc/document/ST-8221-2026-INIT/en/pdf#page=247"
        }
      ],
      "verifiedAt": "2026-10-04"
    },
    {
      "id": "OB-AIS-004",
      "url": "https://openfinanceguide.com/en/dsp3/obligations/ob-ais-004",
      "article": "PSR 41(2)",
      "alsoIn": [],
      "articleFinal": null,
      "actors": [
        "aspsp"
      ],
      "roles": [
        "api",
        "infra",
        "product"
      ],
      "appliesAt": "T+21",
      "title": "AIS access with or without the user",
      "level1": "The ASPSP lets the AISP access the designated accounts whether or not the user is actively requesting the information, and the text does not carry over the 2018 RTS limit of four accesses per 24 hours.",
      "level2": null,
      "origin": [
        {
          "act": "rts-2018-389",
          "articles": "36(5)"
        }
      ],
      "stet": {
        "1.6.3": {
          "status": "review",
          "note": "The Framework has an `ACCESS_EXCEEDED` code (429) for exceeding the daily number of accesses, and `PSU-*` headers as proof that the user is connected. A daily quota built on the four-access rule no longer has any footing in the text.",
          "pages": [
            "https://openfinanceguide.com/en/stet/1.6.3/framework/3-prerequisites-and-technical-details"
          ]
        }
      },
      "verification": null,
      "sources": [
        {
          "document": "8221/26",
          "page": 255,
          "url": "https://data.consilium.europa.eu/doc/document/ST-8221-2026-INIT/en/pdf#page=255"
        }
      ],
      "verifiedAt": "2026-10-04"
    },
    {
      "id": "OB-AIS-005",
      "url": "https://openfinanceguide.com/en/dsp3/obligations/ob-ais-005",
      "article": "PSR 41(2a)",
      "alsoIn": [],
      "articleFinal": null,
      "actors": [
        "aisp"
      ],
      "roles": [
        "product",
        "compliance"
      ],
      "appliesAt": "T+21",
      "title": "User told about background access",
      "level1": "Before accessing accounts without the user actively requesting it, the AISP makes sure the user is duly aware of it, which recital 65a says can be done in the framework contract.",
      "level2": null,
      "origin": [],
      "stet": {
        "1.6.3": {
          "status": "out-of-scope",
          "note": "Informing the user happens in the AISP's own journey, before any call to the bank.",
          "pages": []
        }
      },
      "verification": null,
      "sources": [
        {
          "document": "8221/26",
          "page": 255,
          "url": "https://data.consilium.europa.eu/doc/document/ST-8221-2026-INIT/en/pdf#page=255"
        },
        {
          "document": "8221/26",
          "page": 56,
          "url": "https://data.consilium.europa.eu/doc/document/ST-8221-2026-INIT/en/pdf#page=56"
        }
      ],
      "verifiedAt": "2026-10-04"
    },
    {
      "id": "OB-AIS-006",
      "url": "https://openfinanceguide.com/en/dsp3/obligations/ob-ais-006",
      "article": "PSR 36(5a)",
      "alsoIn": [],
      "articleFinal": null,
      "actors": [
        "aspsp",
        "aisp",
        "pisp"
      ],
      "roles": [
        "compliance",
        "api"
      ],
      "appliesAt": "T+21",
      "title": "Holder name and identifier are not sensitive",
      "level1": "For AISPs and PISPs, the account owner's name and the account's unique identifier are not sensitive payment data.",
      "level2": null,
      "origin": [],
      "stet": {
        "1.6.3": {
          "status": "out-of-scope",
          "note": "The text classifies the data and describes no exchange. In STET, holder names depend on the `owners` access sent with `PUT /consents`.",
          "pages": [
            "https://openfinanceguide.com/en/stet/1.6.3/endpoints/aisp/consents-put",
            "https://openfinanceguide.com/en/stet/1.6.3/endpoints/aisp/accounts-owners-get"
          ]
        }
      },
      "verification": null,
      "sources": [
        {
          "document": "8221/26",
          "page": 247,
          "url": "https://data.consilium.europa.eu/doc/document/ST-8221-2026-INIT/en/pdf#page=247"
        }
      ],
      "verifiedAt": "2026-10-04"
    },
    {
      "id": "OB-AIS-007",
      "url": "https://openfinanceguide.com/en/dsp3/obligations/ob-ais-007",
      "article": "PSR 47(1)(d)",
      "alsoIn": [
        "PSR 47(1)(e)"
      ],
      "articleFinal": null,
      "actors": [
        "aisp"
      ],
      "roles": [
        "api",
        "pentest"
      ],
      "appliesAt": "T+21",
      "title": "The AISP accesses designated accounts only",
      "level1": "The AISP accesses only information from designated accounts and their transactions, with mechanisms that prevent any other access, in line with the user's consent.",
      "level2": null,
      "origin": [
        {
          "act": "psd2",
          "articles": "67(2)(d)"
        },
        {
          "act": "rts-2018-389",
          "articles": "36(3)"
        }
      ],
      "stet": {
        "1.6.3": {
          "status": "present",
          "note": "`PUT /consents` lists, for each data type, the accounts the user designated, and the bank uses it to limit access.",
          "pages": [
            "https://openfinanceguide.com/en/stet/1.6.3/endpoints/aisp/consents-put",
            "https://openfinanceguide.com/en/stet/1.6.3/flows/6-2-consent-forwarding"
          ]
        }
      },
      "verification": null,
      "sources": [
        {
          "document": "8221/26",
          "page": 269,
          "url": "https://data.consilium.europa.eu/doc/document/ST-8221-2026-INIT/en/pdf#page=269"
        }
      ],
      "verifiedAt": "2026-10-04"
    },
    {
      "id": "OB-PIS-001",
      "url": "https://openfinanceguide.com/en/dsp3/obligations/ob-pis-001",
      "article": "PSR 36(4)(a)",
      "alsoIn": [],
      "articleFinal": null,
      "actors": [
        "aspsp"
      ],
      "roles": [
        "api",
        "product"
      ],
      "appliesAt": "T+21",
      "title": "Standing order, set-up and revocation",
      "level1": "The interface lets the PISP place and revoke a standing order.",
      "level2": null,
      "origin": [],
      "stet": {
        "1.6.3": {
          "status": "present",
          "note": "`standingOrderCharacteristics` describes the schedule and `PUT /payment-requests/{id}` handles cancellation. The text makes it mandatory, while support varies from bank to bank today.",
          "pages": [
            "https://openfinanceguide.com/en/stet/1.6.3/flows/8-3-standing-orders-request",
            "https://openfinanceguide.com/en/stet/1.6.3/endpoints/pisp/payment-request-put",
            "https://openfinanceguide.com/en/stet/1.6.3/resources/standing-order-characteristics"
          ]
        }
      },
      "verification": null,
      "sources": [
        {
          "document": "8221/26",
          "page": 244,
          "url": "https://data.consilium.europa.eu/doc/document/ST-8221-2026-INIT/en/pdf#page=244"
        }
      ],
      "verifiedAt": "2026-10-04"
    },
    {
      "id": "OB-PIS-002",
      "url": "https://openfinanceguide.com/en/dsp3/obligations/ob-pis-002",
      "article": "PSR 36(4)(b)",
      "alsoIn": [],
      "articleFinal": null,
      "actors": [
        "aspsp"
      ],
      "roles": [
        "api"
      ],
      "appliesAt": "T+21",
      "title": "Single payment",
      "level1": "The interface lets the PISP initiate a single payment.",
      "level2": null,
      "origin": [
        {
          "act": "psd2",
          "articles": "66(1)"
        }
      ],
      "stet": {
        "1.6.3": {
          "status": "present",
          "note": "The PISP sends `POST /payment-requests` with a single instruction, which the user confirms by authenticating at the bank.",
          "pages": [
            "https://openfinanceguide.com/en/stet/1.6.3/endpoints/pisp/payment-requests-post"
          ]
        }
      },
      "verification": null,
      "sources": [
        {
          "document": "8221/26",
          "page": 244,
          "url": "https://data.consilium.europa.eu/doc/document/ST-8221-2026-INIT/en/pdf#page=244"
        }
      ],
      "verifiedAt": "2026-10-04"
    },
    {
      "id": "OB-PIS-003",
      "url": "https://openfinanceguide.com/en/dsp3/obligations/ob-pis-003",
      "article": "PSR 36(4)(c)",
      "alsoIn": [],
      "articleFinal": null,
      "actors": [
        "aspsp"
      ],
      "roles": [
        "api",
        "product"
      ],
      "appliesAt": "T+21",
      "title": "Future-dated payment, initiation and revocation",
      "level1": "The interface lets the PISP initiate and revoke a future-dated payment.",
      "level2": null,
      "origin": [],
      "stet": {
        "1.6.3": {
          "status": "present",
          "note": "The date goes in `requestedExecutionDate`, the cancellation deadline in `cancellableTill`, and cancellation goes through `PUT /payment-requests/{id}`.",
          "pages": [
            "https://openfinanceguide.com/en/stet/1.6.3/flows/8-1-payment-request-with-multiple-instructions-having-different",
            "https://openfinanceguide.com/en/stet/1.6.3/endpoints/pisp/payment-request-put"
          ]
        }
      },
      "verification": null,
      "sources": [
        {
          "document": "8221/26",
          "page": 244,
          "url": "https://data.consilium.europa.eu/doc/document/ST-8221-2026-INIT/en/pdf#page=244"
        }
      ],
      "verifiedAt": "2026-10-04"
    },
    {
      "id": "OB-PIS-004",
      "url": "https://openfinanceguide.com/en/dsp3/obligations/ob-pis-004",
      "article": "PSR 36(4)(d)",
      "alsoIn": [],
      "articleFinal": null,
      "actors": [
        "aspsp"
      ],
      "roles": [
        "api",
        "product"
      ],
      "appliesAt": "T+21",
      "title": "Payments to multiple beneficiaries",
      "level1": "The interface lets the PISP initiate payments to multiple beneficiaries.",
      "level2": null,
      "origin": [],
      "stet": {
        "1.6.3": {
          "status": "present",
          "note": "A payment request can carry several instructions to different beneficiaries, up to the limit each bank sets for `numberOfTransactions`. The text does not define a payment to multiple beneficiaries.",
          "pages": [
            "https://openfinanceguide.com/en/stet/1.6.3/flows/8-2-payment-request-with-multiple-instructions-having-different-beneficiaries",
            "https://openfinanceguide.com/en/stet/1.6.3/endpoints/pisp/payment-requests-post"
          ]
        }
      },
      "verification": null,
      "sources": [
        {
          "document": "8221/26",
          "page": 244,
          "url": "https://data.consilium.europa.eu/doc/document/ST-8221-2026-INIT/en/pdf#page=244"
        }
      ],
      "verifiedAt": "2026-10-04"
    },
    {
      "id": "OB-PIS-005",
      "url": "https://openfinanceguide.com/en/dsp3/obligations/ob-pis-005",
      "article": "PSR 36(4)(e)",
      "alsoIn": [],
      "articleFinal": null,
      "actors": [
        "aspsp"
      ],
      "roles": [
        "api",
        "product"
      ],
      "appliesAt": "T+21",
      "title": "Payee outside the payer's beneficiary list",
      "level1": "The PISP can initiate a payment whether or not the payee is on the payer's beneficiary list, unless the user cannot make that payment in the customer interface.",
      "level2": null,
      "origin": [],
      "stet": {
        "1.6.3": {
          "status": "present",
          "note": "The payee is carried in the request itself, and the `isTrusted` flag marks a trusted beneficiary without requiring one.",
          "pages": [
            "https://openfinanceguide.com/en/stet/1.6.3/endpoints/pisp/payment-requests-post",
            "https://openfinanceguide.com/en/stet/1.6.3/resources/beneficiary"
          ]
        }
      },
      "verification": null,
      "sources": [
        {
          "document": "8221/26",
          "page": 244,
          "url": "https://data.consilium.europa.eu/doc/document/ST-8221-2026-INIT/en/pdf#page=244"
        }
      ],
      "verifiedAt": "2026-10-04"
    },
    {
      "id": "OB-PIS-006",
      "url": "https://openfinanceguide.com/en/dsp3/obligations/ob-pis-006",
      "article": "PSR 37(3)",
      "alsoIn": [
        "PSR 36(4)(f)",
        "PSR 40(b)"
      ],
      "articleFinal": null,
      "actors": [
        "aspsp"
      ],
      "roles": [
        "api",
        "product"
      ],
      "appliesAt": "T+21",
      "title": "Execution information and status until the end",
      "level1": "As soon as it receives the order, the ASPSP gives the PISP at least the initiation and execution information the payer would see, then every update, status included, until the payment is executed or rejected.",
      "level2": null,
      "origin": [
        {
          "act": "rts-2018-389",
          "articles": "36(1)(b)"
        },
        {
          "act": "psd2",
          "articles": "66(4)(b)"
        }
      ],
      "stet": {
        "1.6.3": {
          "status": "partial",
          "note": "The PISP polls `GET /payment-requests/{id}`, with `nextStatusRequestHint` as a pacing hint. Nothing is pushed to the PISP apart from the redirect callback.",
          "pages": [
            "https://openfinanceguide.com/en/stet/1.6.3/endpoints/pisp/payment-requests-get",
            "https://openfinanceguide.com/en/stet/1.6.3/endpoints/pisp/payment-request-transactions-get"
          ]
        }
      },
      "verification": null,
      "sources": [
        {
          "document": "8221/26",
          "page": 248,
          "url": "https://data.consilium.europa.eu/doc/document/ST-8221-2026-INIT/en/pdf#page=248"
        },
        {
          "document": "8221/26",
          "page": 245,
          "url": "https://data.consilium.europa.eu/doc/document/ST-8221-2026-INIT/en/pdf#page=245"
        },
        {
          "document": "8221/26",
          "page": 253,
          "url": "https://data.consilium.europa.eu/doc/document/ST-8221-2026-INIT/en/pdf#page=253"
        }
      ],
      "verifiedAt": "2026-10-04"
    },
    {
      "id": "OB-PIS-007",
      "url": "https://openfinanceguide.com/en/dsp3/obligations/ob-pis-007",
      "article": "PSR 36(4)(g)",
      "alsoIn": [],
      "articleFinal": null,
      "actors": [
        "aspsp"
      ],
      "roles": [
        "api",
        "product"
      ],
      "appliesAt": "T+21",
      "title": "Account holder name check before initiation",
      "level1": "The PISP can check the account holder's name before initiating the payment, whether or not that name is available in the direct interface.",
      "level2": null,
      "origin": [],
      "stet": {
        "1.6.3": {
          "status": "absent",
          "note": "The PISP role has no account operation in STET 1.6.3.",
          "pages": [
            "https://openfinanceguide.com/en/stet/1.6.3/endpoints/pisp"
          ]
        }
      },
      "verification": null,
      "sources": [
        {
          "document": "8221/26",
          "page": 245,
          "url": "https://data.consilium.europa.eu/doc/document/ST-8221-2026-INIT/en/pdf#page=245"
        }
      ],
      "verifiedAt": "2026-10-04"
    },
    {
      "id": "OB-PIS-008",
      "url": "https://openfinanceguide.com/en/dsp3/obligations/ob-pis-008",
      "article": "PSR 36(4)(ha)",
      "alsoIn": [],
      "articleFinal": null,
      "actors": [
        "aspsp"
      ],
      "roles": [
        "api",
        "product"
      ],
      "appliesAt": "T+21",
      "title": "The PISP chooses the authentication procedure",
      "level1": "Where the ASPSP offers several authentication procedures, the PISP chooses which one is presented to the payer.",
      "level2": null,
      "origin": [],
      "stet": {
        "1.6.3": {
          "status": "partial",
          "note": "The PISP lists the approaches it accepts in `acceptedAuthenticationApproach` and the bank picks the one it applies in `appliedAuthenticationApproach`. The text gives the choice to the PISP.",
          "pages": [
            "https://openfinanceguide.com/en/stet/1.6.3/endpoints/pisp/payment-requests-post",
            "https://openfinanceguide.com/en/stet/1.6.3/resources/supplementary-data"
          ]
        }
      },
      "verification": null,
      "sources": [
        {
          "document": "8221/26",
          "page": 245,
          "url": "https://data.consilium.europa.eu/doc/document/ST-8221-2026-INIT/en/pdf#page=245"
        }
      ],
      "verifiedAt": "2026-10-04"
    },
    {
      "id": "OB-PIS-009",
      "url": "https://openfinanceguide.com/en/dsp3/obligations/ob-pis-009",
      "article": "PSR 36(4)(hc)",
      "alsoIn": [],
      "articleFinal": null,
      "actors": [
        "aspsp"
      ],
      "roles": [
        "api",
        "product"
      ],
      "appliesAt": "T+21",
      "title": "Account, holders and currencies visible before initiation",
      "level1": "Before initiation, the PISP sees the account identifier, the holders' names and the currencies, where the user has access to them.",
      "level2": null,
      "origin": [],
      "stet": {
        "1.6.3": {
          "status": "absent",
          "note": "The PISP can only propose a `debtorAccount` in its request. It reads nothing about the account before initiation.",
          "pages": [
            "https://openfinanceguide.com/en/stet/1.6.3/endpoints/pisp/payment-requests-post"
          ]
        }
      },
      "verification": null,
      "sources": [
        {
          "document": "8221/26",
          "page": 245,
          "url": "https://data.consilium.europa.eu/doc/document/ST-8221-2026-INIT/en/pdf#page=245"
        }
      ],
      "verifiedAt": "2026-10-04"
    },
    {
      "id": "OB-PIS-010",
      "url": "https://openfinanceguide.com/en/dsp3/obligations/ob-pis-010",
      "article": "PSR 36(5)(a)",
      "alsoIn": [],
      "articleFinal": null,
      "actors": [
        "aspsp"
      ],
      "roles": [
        "api"
      ],
      "appliesAt": "T+21",
      "title": "Yes or no answer on funds",
      "level1": "On request, the ASPSP immediately confirms to the PISP, as a simple yes or no, whether the amount needed for the payment is available on the payer's account.",
      "level2": null,
      "origin": [
        {
          "act": "rts-2018-389",
          "articles": "36(1)(c)"
        }
      ],
      "stet": {
        "1.6.3": {
          "status": "partial",
          "note": "`fundsAvailability` is only returned when the bank could not book the payment straight away, and `POST /funds-confirmations` is reserved for the CBPII role, which the PSR removes.",
          "pages": [
            "https://openfinanceguide.com/en/stet/1.6.3/endpoints/pisp/payment-requests-get",
            "https://openfinanceguide.com/en/stet/1.6.3/resources/funds-availability-information",
            "https://openfinanceguide.com/en/stet/1.6.3/endpoints/cbpii/funds-confirmations-post"
          ]
        }
      },
      "verification": null,
      "sources": [
        {
          "document": "8221/26",
          "page": 246,
          "url": "https://data.consilium.europa.eu/doc/document/ST-8221-2026-INIT/en/pdf#page=246"
        }
      ],
      "verifiedAt": "2026-10-04"
    },
    {
      "id": "OB-PIS-011",
      "url": "https://openfinanceguide.com/en/dsp3/obligations/ob-pis-011",
      "article": "PSR 36(5)(b)",
      "alsoIn": [],
      "articleFinal": null,
      "actors": [
        "aspsp"
      ],
      "roles": [
        "api",
        "product"
      ],
      "appliesAt": "T+21",
      "title": "Confirmation that the payment will be executed",
      "level1": "The ASPSP confirms to the PISP as soon as possible that the payment has been or will be executed, taking pending orders into account, without sharing those orders with it.",
      "level2": null,
      "origin": [],
      "stet": {
        "1.6.3": {
          "status": "partial",
          "note": "The PISP reads ISO 20022 statuses (`ACSP`, `ACSC`, `RJCT`…) by polling, and the specification, which predates the text, does not say which one counts as confirmation of execution.",
          "pages": [
            "https://openfinanceguide.com/en/stet/1.6.3/endpoints/pisp/payment-requests-get",
            "https://openfinanceguide.com/en/stet/1.6.3/resources/payment-information-status-code"
          ]
        }
      },
      "verification": null,
      "sources": [
        {
          "document": "8221/26",
          "page": 246,
          "url": "https://data.consilium.europa.eu/doc/document/ST-8221-2026-INIT/en/pdf#page=246"
        }
      ],
      "verifiedAt": "2026-10-04"
    },
    {
      "id": "OB-PIS-012",
      "url": "https://openfinanceguide.com/en/dsp3/obligations/ob-pis-012",
      "article": "PSR 65(1)",
      "alsoIn": [],
      "articleFinal": null,
      "actors": [
        "aspsp"
      ],
      "roles": [
        "api",
        "product"
      ],
      "appliesAt": "T+21",
      "title": "Refusal over suspected fraud, reasons to the PISP",
      "level1": "When the payer's PSP refuses an order after the suspected-fraud assessment of Article 65(-1a), it makes the refusal, its specific reasons and, where applicable, the procedure for correcting the decision available to the PISP, within 10 seconds for an instant credit transfer.",
      "level2": null,
      "origin": [
        {
          "act": "psd2",
          "articles": "79(1)"
        }
      ],
      "stet": {
        "1.6.3": {
          "status": "partial",
          "note": "The refusal shows up as status `RJCT` with a `statusReasonInformation` code, `FRAD` for fraud or `AM04` for insufficient funds. No time limit is set.",
          "pages": [
            "https://openfinanceguide.com/en/stet/1.6.3/endpoints/pisp/payment-requests-get",
            "https://openfinanceguide.com/en/stet/1.6.3/resources/status-reason-information"
          ]
        }
      },
      "verification": null,
      "sources": [
        {
          "document": "8221/26",
          "page": 313,
          "url": "https://data.consilium.europa.eu/doc/document/ST-8221-2026-INIT/en/pdf#page=313"
        },
        {
          "document": "8221/26",
          "page": 314,
          "url": "https://data.consilium.europa.eu/doc/document/ST-8221-2026-INIT/en/pdf#page=314"
        }
      ],
      "verifiedAt": "2026-10-04"
    },
    {
      "id": "OB-PIS-013",
      "url": "https://openfinanceguide.com/en/dsp3/obligations/ob-pis-013",
      "article": "PSR 57",
      "alsoIn": [
        "PSR 50"
      ],
      "articleFinal": null,
      "actors": [
        "pisp",
        "aspsp"
      ],
      "roles": [
        "compliance",
        "product"
      ],
      "appliesAt": "T+27",
      "title": "Payee verification, PISP liability",
      "level1": "The payee name verification of the SEPA Regulation extends to all credit transfers, and when a verification failure comes from the PISP, the PISP compensates the payer's PSP, which refunds the payer first.",
      "level2": null,
      "origin": [],
      "stet": {
        "1.6.3": {
          "status": "review",
          "note": "The payment resource carries no payee verification result, and STET 1.6.3 does not say who shows it to the payer in a PISP journey.",
          "pages": [
            "https://openfinanceguide.com/en/stet/1.6.3/endpoints/pisp/payment-requests-post"
          ]
        }
      },
      "verification": null,
      "sources": [
        {
          "document": "8221/26",
          "page": 291,
          "url": "https://data.consilium.europa.eu/doc/document/ST-8221-2026-INIT/en/pdf#page=291"
        },
        {
          "document": "8221/26",
          "page": 277,
          "url": "https://data.consilium.europa.eu/doc/document/ST-8221-2026-INIT/en/pdf#page=277"
        }
      ],
      "verifiedAt": "2026-10-04"
    },
    {
      "id": "OB-PIS-014",
      "url": "https://openfinanceguide.com/en/dsp3/obligations/ob-pis-014",
      "article": "PSR 46(1)(fa)",
      "alsoIn": [],
      "articleFinal": null,
      "actors": [
        "pisp"
      ],
      "roles": [
        "compliance",
        "product"
      ],
      "appliesAt": "T+21",
      "title": "The PISP may refuse to initiate",
      "level1": "The PISP must be able to refuse to initiate a transaction for objectively justified reasons.",
      "level2": null,
      "origin": [],
      "stet": {
        "1.6.3": {
          "status": "out-of-scope",
          "note": "The refusal is decided at the PISP, before any call to the bank.",
          "pages": []
        }
      },
      "verification": null,
      "sources": [
        {
          "document": "8221/26",
          "page": 268,
          "url": "https://data.consilium.europa.eu/doc/document/ST-8221-2026-INIT/en/pdf#page=268"
        }
      ],
      "verifiedAt": "2026-10-04"
    },
    {
      "id": "OB-DB-001",
      "url": "https://openfinanceguide.com/en/dsp3/obligations/ob-db-001",
      "article": "PSR 43(1)",
      "alsoIn": [],
      "articleFinal": null,
      "actors": [
        "aspsp"
      ],
      "roles": [
        "product",
        "compliance"
      ],
      "appliesAt": "T+21",
      "title": "Consent dashboard at the ASPSP",
      "level1": "The ASPSP builds into its user interface a dashboard where the user monitors and manages AIS consents and PIS consents covering multiple or recurring payments.",
      "level2": null,
      "origin": [],
      "stet": {
        "1.6.3": {
          "status": "out-of-scope",
          "note": "The dashboard is a bank screen. Its content depends on the exchanges described in OB-DB-007 and OB-DB-008.",
          "pages": []
        }
      },
      "verification": null,
      "sources": [
        {
          "document": "8221/26",
          "page": 257,
          "url": "https://data.consilium.europa.eu/doc/document/ST-8221-2026-INIT/en/pdf#page=257"
        }
      ],
      "verifiedAt": "2026-10-04"
    },
    {
      "id": "OB-DB-002",
      "url": "https://openfinanceguide.com/en/dsp3/obligations/ob-db-002",
      "article": "PSR 43(2)(a)",
      "alsoIn": [],
      "articleFinal": null,
      "actors": [
        "aspsp"
      ],
      "roles": [
        "product",
        "api"
      ],
      "appliesAt": "T+21",
      "title": "What the dashboard shows",
      "level1": "For each ongoing consent, the dashboard shows the TPP, the account, the purpose, the validity period with the date of consent, the categories of data shared and the dates the data was accessed.",
      "level2": null,
      "origin": [],
      "stet": {
        "1.6.3": {
          "status": "partial",
          "note": "The bank knows the TPP, the accounts, the data types sent with `PUT /consents` and the access dates. It receives no purpose, validity or consent date.",
          "pages": [
            "https://openfinanceguide.com/en/stet/1.6.3/endpoints/aisp/consents-put",
            "https://openfinanceguide.com/en/stet/1.6.3/resources/access"
          ]
        }
      },
      "verification": null,
      "sources": [
        {
          "document": "8221/26",
          "page": 257,
          "url": "https://data.consilium.europa.eu/doc/document/ST-8221-2026-INIT/en/pdf#page=257"
        },
        {
          "document": "8221/26",
          "page": 258,
          "url": "https://data.consilium.europa.eu/doc/document/ST-8221-2026-INIT/en/pdf#page=258"
        }
      ],
      "verifiedAt": "2026-10-04"
    },
    {
      "id": "OB-DB-003",
      "url": "https://openfinanceguide.com/en/dsp3/obligations/ob-db-003",
      "article": "PSR 43(2)(b)",
      "alsoIn": [],
      "articleFinal": null,
      "actors": [
        "aspsp"
      ],
      "roles": [
        "product"
      ],
      "appliesAt": "T+21",
      "title": "Withdrawal at any time, free of charge",
      "level1": "The user can withdraw access for a given TPP or for all TPPs, at any time and free of charge.",
      "level2": null,
      "origin": [],
      "stet": {
        "1.6.3": {
          "status": "out-of-scope",
          "note": "Withdrawal happens in the bank's screen. The Framework already has the bank revoke the AISP's refresh token at the user's request.",
          "pages": [
            "https://openfinanceguide.com/en/stet/1.6.3/framework/3-prerequisites-and-technical-details"
          ]
        }
      },
      "verification": null,
      "sources": [
        {
          "document": "8221/26",
          "page": 258,
          "url": "https://data.consilium.europa.eu/doc/document/ST-8221-2026-INIT/en/pdf#page=258"
        }
      ],
      "verifiedAt": "2026-10-04"
    },
    {
      "id": "OB-DB-004",
      "url": "https://openfinanceguide.com/en/dsp3/obligations/ob-db-004",
      "article": "PSR 43(2)(c)",
      "alsoIn": [],
      "articleFinal": null,
      "actors": [
        "aspsp"
      ],
      "roles": [
        "product",
        "api"
      ],
      "appliesAt": "T+21",
      "title": "Re-establishment possible for 48 hours",
      "level1": "Within 48 hours of withdrawing a consent, the user can re-establish the access withdrawn.",
      "level2": null,
      "origin": [],
      "stet": {
        "1.6.3": {
          "status": "absent",
          "note": "A revoked refresh token does not come back, and the STET consent resource has no state. Restoring access takes a new authorisation journey.",
          "pages": [
            "https://openfinanceguide.com/en/stet/1.6.3/endpoints/aisp/consents-put",
            "https://openfinanceguide.com/en/stet/1.6.3/framework/3-prerequisites-and-technical-details"
          ]
        }
      },
      "verification": null,
      "sources": [
        {
          "document": "8221/26",
          "page": 258,
          "url": "https://data.consilium.europa.eu/doc/document/ST-8221-2026-INIT/en/pdf#page=258"
        }
      ],
      "verifiedAt": "2026-10-04"
    },
    {
      "id": "OB-DB-005",
      "url": "https://openfinanceguide.com/en/dsp3/obligations/ob-db-005",
      "article": "PSR 43(2)(d)",
      "alsoIn": [],
      "articleFinal": null,
      "actors": [
        "aspsp"
      ],
      "roles": [
        "product",
        "infra"
      ],
      "appliesAt": "T+21",
      "title": "Two-year history",
      "level1": "The dashboard keeps a record of withdrawn or expired consents for two years.",
      "level2": null,
      "origin": [],
      "stet": {
        "1.6.3": {
          "status": "out-of-scope",
          "note": "Retention is handled on the bank's side.",
          "pages": []
        }
      },
      "verification": null,
      "sources": [
        {
          "document": "8221/26",
          "page": 258,
          "url": "https://data.consilium.europa.eu/doc/document/ST-8221-2026-INIT/en/pdf#page=258"
        }
      ],
      "verifiedAt": "2026-10-04"
    },
    {
      "id": "OB-DB-006",
      "url": "https://openfinanceguide.com/en/dsp3/obligations/ob-db-006",
      "article": "PSR 43(2b)",
      "alsoIn": [],
      "articleFinal": null,
      "actors": [
        "aisp",
        "pisp"
      ],
      "roles": [
        "product",
        "compliance",
        "infra",
        "pentest"
      ],
      "appliesAt": "T+21",
      "title": "After withdrawal, the TPP stops and deletes",
      "level1": "After a withdrawal, the TPP stops accessing and using the data, then deletes it without undue delay but not before 48 hours, unless the user explicitly chooses to let it keep the data.",
      "level2": null,
      "origin": [],
      "stet": {
        "1.6.3": {
          "status": "out-of-scope",
          "note": "The TPP can only apply this rule if it learns of the withdrawal, which STET only tells it indirectly (OB-DB-008).",
          "pages": []
        }
      },
      "verification": null,
      "sources": [
        {
          "document": "8221/26",
          "page": 259,
          "url": "https://data.consilium.europa.eu/doc/document/ST-8221-2026-INIT/en/pdf#page=259"
        }
      ],
      "verifiedAt": "2026-10-04"
    },
    {
      "id": "OB-DB-007",
      "url": "https://openfinanceguide.com/en/dsp3/obligations/ob-db-007",
      "article": "PSR 43(3b)",
      "alsoIn": [
        "PSR 43(4)"
      ],
      "articleFinal": null,
      "actors": [
        "aisp",
        "pisp",
        "aspsp"
      ],
      "roles": [
        "api",
        "product"
      ],
      "appliesAt": "T+21",
      "title": "The TPP sends each consent to the ASPSP",
      "level1": "The TPP tells the ASPSP without undue delay about each new consent, with its name, the account, the purpose, the validity and the data categories, and the ASPSP shows only what the TPP sent it.",
      "level2": {
        "mandate": "PSR 89(1)(e)",
        "instrument": "rts",
        "deadline": "T+12",
        "link": "reading"
      },
      "origin": [],
      "stet": {
        "1.6.3": {
          "status": "partial",
          "note": "`PUT /consents` sends the accounts and data types, with no purpose, validity or date. Nothing exists for recurring PIS consents.",
          "pages": [
            "https://openfinanceguide.com/en/stet/1.6.3/endpoints/aisp/consents-put",
            "https://openfinanceguide.com/en/stet/1.6.3/flows/6-2-consent-forwarding"
          ]
        }
      },
      "verification": null,
      "sources": [
        {
          "document": "8221/26",
          "page": 260,
          "url": "https://data.consilium.europa.eu/doc/document/ST-8221-2026-INIT/en/pdf#page=260"
        }
      ],
      "verifiedAt": "2026-10-04"
    },
    {
      "id": "OB-DB-008",
      "url": "https://openfinanceguide.com/en/dsp3/obligations/ob-db-008",
      "article": "PSR 43(4)",
      "alsoIn": [],
      "articleFinal": null,
      "actors": [
        "aspsp"
      ],
      "roles": [
        "api"
      ],
      "appliesAt": "T+21",
      "title": "The ASPSP tells the TPP about every change",
      "level1": "The ASPSP tells the TPP without undue delay about any change the user makes in the dashboard, withdrawal included.",
      "level2": {
        "mandate": "PSR 89(1)(e)",
        "instrument": "rts",
        "deadline": "T+12",
        "link": "reading"
      },
      "origin": [],
      "stet": {
        "1.6.3": {
          "status": "partial",
          "note": "STET has neither a consent status to query nor a notification. A withdrawal revokes the refresh token, and the AISP only finds out from the `invalid_grant` error on its next refresh.",
          "pages": [
            "https://openfinanceguide.com/en/stet/1.6.3/framework/3-prerequisites-and-technical-details",
            "https://openfinanceguide.com/en/stet/1.6.3/endpoints/aisp/consents-put"
          ]
        }
      },
      "verification": null,
      "sources": [
        {
          "document": "8221/26",
          "page": 260,
          "url": "https://data.consilium.europa.eu/doc/document/ST-8221-2026-INIT/en/pdf#page=260"
        }
      ],
      "verifiedAt": "2026-10-04"
    },
    {
      "id": "OB-DB-009",
      "url": "https://openfinanceguide.com/en/dsp3/obligations/ob-db-009",
      "article": "PSR 43(3)",
      "alsoIn": [],
      "articleFinal": null,
      "actors": [
        "aspsp"
      ],
      "roles": [
        "product",
        "compliance"
      ],
      "appliesAt": "T+21",
      "title": "Neutral dashboard, no deceptive design",
      "level1": "The dashboard is easy to find, its content is clear and neutral, and the ASPSP neither prompts the user to withdraw nor designs the screen to steer the user's choices.",
      "level2": null,
      "origin": [],
      "stet": {
        "1.6.3": {
          "status": "out-of-scope",
          "note": "The requirement concerns the bank's screen, not the API.",
          "pages": []
        }
      },
      "verification": null,
      "sources": [
        {
          "document": "8221/26",
          "page": 259,
          "url": "https://data.consilium.europa.eu/doc/document/ST-8221-2026-INIT/en/pdf#page=259"
        }
      ],
      "verifiedAt": "2026-10-04"
    },
    {
      "id": "OB-OBS-001",
      "url": "https://openfinanceguide.com/en/dsp3/obligations/ob-obs-001",
      "article": "PSR 44(1)(a)",
      "alsoIn": [],
      "articleFinal": null,
      "actors": [
        "aspsp"
      ],
      "roles": [
        "api",
        "product",
        "pentest"
      ],
      "appliesAt": "T+21",
      "title": "Blocking the use of the bank's credentials",
      "level1": "The ASPSP may not prevent TPPs from using the personalised security credentials it issued to its customers.",
      "level2": null,
      "origin": [
        {
          "act": "rts-2018-389",
          "articles": "32(3)"
        },
        {
          "act": "eba-opinion-2020"
        }
      ],
      "stet": {
        "1.6.3": {
          "status": "present",
          "note": "The TPP relies on the bank's authentication in redirect, decoupled or one-factor embedded mode (`EMBEDDED-1-FACTOR`).",
          "pages": [
            "https://openfinanceguide.com/en/stet/1.6.3/framework/3-prerequisites-and-technical-details",
            "https://openfinanceguide.com/en/stet/1.6.3/resources/authentication-approach"
          ]
        }
      },
      "verification": null,
      "sources": [
        {
          "document": "8221/26",
          "page": 261,
          "url": "https://data.consilium.europa.eu/doc/document/ST-8221-2026-INIT/en/pdf#page=261"
        }
      ],
      "verifiedAt": "2026-10-04"
    },
    {
      "id": "OB-OBS-002",
      "url": "https://openfinanceguide.com/en/dsp3/obligations/ob-obs-002",
      "article": "PSR 44(1)(b)",
      "alsoIn": [],
      "articleFinal": null,
      "actors": [
        "aspsp"
      ],
      "roles": [
        "product",
        "api",
        "pentest"
      ],
      "appliesAt": "T+21",
      "title": "Making the user type the account identifier at the bank",
      "level1": "The ASPSP may not require the user to type their account identifier by hand on the ASPSP's domain to use an AIS or PIS service.",
      "level2": null,
      "origin": [
        {
          "act": "rts-2018-389",
          "articles": "32(3)"
        },
        {
          "act": "eba-opinion-2020"
        }
      ],
      "stet": {
        "1.6.3": {
          "status": "present",
          "note": "`debtorAccount` is optional in the payment request, which lets the bank have the user pick the account during authentication.",
          "pages": [
            "https://openfinanceguide.com/en/stet/1.6.3/endpoints/pisp/payment-requests-post",
            "https://openfinanceguide.com/en/stet/1.6.3/resources/payment-request-resource"
          ]
        }
      },
      "verification": null,
      "sources": [
        {
          "document": "8221/26",
          "page": 261,
          "url": "https://data.consilium.europa.eu/doc/document/ST-8221-2026-INIT/en/pdf#page=261"
        }
      ],
      "verifiedAt": "2026-10-04"
    },
    {
      "id": "OB-OBS-003",
      "url": "https://openfinanceguide.com/en/dsp3/obligations/ob-obs-003",
      "article": "PSR 44(1)(c)",
      "alsoIn": [
        "PSR 49(4)"
      ],
      "articleFinal": null,
      "actors": [
        "aspsp"
      ],
      "roles": [
        "api",
        "product",
        "compliance"
      ],
      "appliesAt": "T+21",
      "title": "Checking the consent given to the TPP",
      "level1": "The ASPSP may neither require checks of the consent the user gave the TPP nor verify that consent itself.",
      "level2": null,
      "origin": [
        {
          "act": "rts-2018-389",
          "articles": "32(3)"
        },
        {
          "act": "eba-opinion-2020"
        }
      ],
      "stet": {
        "1.6.3": {
          "status": "review",
          "note": "`PUT /consents` passes the consent's scope to the bank, which Article 43(3b) also requires. The bank may use it to limit access, not to verify the consent.",
          "pages": [
            "https://openfinanceguide.com/en/stet/1.6.3/endpoints/aisp/consents-put"
          ]
        }
      },
      "verification": null,
      "sources": [
        {
          "document": "8221/26",
          "page": 261,
          "url": "https://data.consilium.europa.eu/doc/document/ST-8221-2026-INIT/en/pdf#page=261"
        },
        {
          "document": "8221/26",
          "page": 276,
          "url": "https://data.consilium.europa.eu/doc/document/ST-8221-2026-INIT/en/pdf#page=276"
        }
      ],
      "verifiedAt": "2026-10-04"
    },
    {
      "id": "OB-OBS-004",
      "url": "https://openfinanceguide.com/en/dsp3/obligations/ob-obs-004",
      "article": "PSR 44(1)(d)",
      "alsoIn": [],
      "articleFinal": null,
      "actors": [
        "aspsp"
      ],
      "roles": [
        "api",
        "compliance"
      ],
      "appliesAt": "T+21",
      "title": "Requiring additional registrations",
      "level1": "The ASPSP may not require additional registrations from TPPs to access the account or the dedicated interface.",
      "level2": null,
      "origin": [
        {
          "act": "rts-2018-389",
          "articles": "32(3)"
        },
        {
          "act": "eba-opinion-2020"
        }
      ],
      "stet": {
        "1.6.3": {
          "status": "review",
          "note": "STET provides for an OAuth2 technical setup with each bank when the bank cannot accept the TPP on the fly, possibly automated through the Registration API. The text does not say whether that setup counts as an additional registration.",
          "pages": [
            "https://openfinanceguide.com/en/stet/1.6.3/framework/3-prerequisites-and-technical-details",
            "https://openfinanceguide.com/en/stet/1.6.3/endpoints/registration/registration-post"
          ]
        }
      },
      "verification": null,
      "sources": [
        {
          "document": "8221/26",
          "page": 262,
          "url": "https://data.consilium.europa.eu/doc/document/ST-8221-2026-INIT/en/pdf#page=262"
        }
      ],
      "verifiedAt": "2026-10-04"
    },
    {
      "id": "OB-OBS-005",
      "url": "https://openfinanceguide.com/en/dsp3/obligations/ob-obs-005",
      "article": "PSR 44(1)(e)",
      "alsoIn": [],
      "articleFinal": null,
      "actors": [
        "aspsp"
      ],
      "roles": [
        "api",
        "compliance"
      ],
      "appliesAt": "T+21",
      "title": "Requiring contact details to be pre-registered",
      "level1": "The ASPSP may not require the TPP to pre-register its contact details, unless this is needed for their exchanges, in particular to keep the dashboard up to date.",
      "level2": null,
      "origin": [
        {
          "act": "rts-2018-389",
          "articles": "32(3)"
        },
        {
          "act": "eba-opinion-2020"
        }
      ],
      "stet": {
        "1.6.3": {
          "status": "review",
          "note": "STET's technical setup is also used to exchange logos, phone numbers and email addresses. The text allows this where it is needed for exchanges related to the dashboard.",
          "pages": [
            "https://openfinanceguide.com/en/stet/1.6.3/framework/3-prerequisites-and-technical-details"
          ]
        }
      },
      "verification": null,
      "sources": [
        {
          "document": "8221/26",
          "page": 262,
          "url": "https://data.consilium.europa.eu/doc/document/ST-8221-2026-INIT/en/pdf#page=262"
        }
      ],
      "verifiedAt": "2026-10-04"
    },
    {
      "id": "OB-OBS-006",
      "url": "https://openfinanceguide.com/en/dsp3/obligations/ob-obs-006",
      "article": "PSR 44(1)(f)",
      "alsoIn": [],
      "articleFinal": null,
      "actors": [
        "aspsp"
      ],
      "roles": [
        "product",
        "api"
      ],
      "appliesAt": "T+21",
      "title": "Limiting payments to the payer's beneficiary list",
      "level1": "The ASPSP may not limit initiation through a PISP to payees on the payer's beneficiary list, unless the customer interface has the same limit.",
      "level2": null,
      "origin": [
        {
          "act": "rts-2018-389",
          "articles": "32(3)"
        },
        {
          "act": "eba-opinion-2020"
        }
      ],
      "stet": {
        "1.6.3": {
          "status": "present",
          "note": "Nothing in the specification limits the payee to the trusted list. See also OB-PIS-005.",
          "pages": [
            "https://openfinanceguide.com/en/stet/1.6.3/endpoints/pisp/payment-requests-post",
            "https://openfinanceguide.com/en/stet/1.6.3/resources/beneficiary"
          ]
        }
      },
      "verification": null,
      "sources": [
        {
          "document": "8221/26",
          "page": 262,
          "url": "https://data.consilium.europa.eu/doc/document/ST-8221-2026-INIT/en/pdf#page=262"
        }
      ],
      "verifiedAt": "2026-10-04"
    },
    {
      "id": "OB-OBS-007",
      "url": "https://openfinanceguide.com/en/dsp3/obligations/ob-obs-007",
      "article": "PSR 44(1)(g)",
      "alsoIn": [],
      "articleFinal": null,
      "actors": [
        "aspsp"
      ],
      "roles": [
        "api",
        "product"
      ],
      "appliesAt": "T+21",
      "title": "Limiting to domestic account identifiers",
      "level1": "The ASPSP may not limit initiated payments to or from domestic account identifiers only.",
      "level2": null,
      "origin": [
        {
          "act": "rts-2018-389",
          "articles": "32(3)"
        },
        {
          "act": "eba-opinion-2020"
        }
      ],
      "stet": {
        "1.6.3": {
          "status": "present",
          "note": "Accounts are identified by IBAN or by an `other` identifier, with no country restriction in the specification.",
          "pages": [
            "https://openfinanceguide.com/en/stet/1.6.3/resources/account-identification",
            "https://openfinanceguide.com/en/stet/1.6.3/endpoints/pisp/payment-requests-post"
          ]
        }
      },
      "verification": null,
      "sources": [
        {
          "document": "8221/26",
          "page": 262,
          "url": "https://data.consilium.europa.eu/doc/document/ST-8221-2026-INIT/en/pdf#page=262"
        }
      ],
      "verifiedAt": "2026-10-04"
    },
    {
      "id": "OB-OBS-008",
      "url": "https://openfinanceguide.com/en/dsp3/obligations/ob-obs-008",
      "article": "PSR 44(1)(h)",
      "alsoIn": [],
      "articleFinal": null,
      "actors": [
        "aspsp"
      ],
      "roles": [
        "product",
        "api",
        "pentest"
      ],
      "appliesAt": "T+21",
      "title": "More SCA than in the direct channel",
      "level1": "The ASPSP may not require strong customer authentication more often than when the user accesses the account or pays directly with it.",
      "level2": null,
      "origin": [
        {
          "act": "rts-2018-389",
          "articles": "32(3)"
        },
        {
          "act": "eba-opinion-2020"
        }
      ],
      "stet": {
        "1.6.3": {
          "status": "review",
          "note": "The specification does not count SCAs. Token and consent lifetimes, set by each bank, decide how often the user authenticates.",
          "pages": [
            "https://openfinanceguide.com/en/stet/1.6.3/framework/3-prerequisites-and-technical-details"
          ]
        }
      },
      "verification": null,
      "sources": [
        {
          "document": "8221/26",
          "page": 262,
          "url": "https://data.consilium.europa.eu/doc/document/ST-8221-2026-INIT/en/pdf#page=262"
        }
      ],
      "verifiedAt": "2026-10-04"
    },
    {
      "id": "OB-OBS-009",
      "url": "https://openfinanceguide.com/en/dsp3/obligations/ob-obs-009",
      "article": "PSR 44(1)(i)",
      "alsoIn": [],
      "articleFinal": null,
      "actors": [
        "aspsp"
      ],
      "roles": [
        "api",
        "product",
        "pentest"
      ],
      "appliesAt": "T+21",
      "title": "Not supporting every authentication procedure",
      "level1": "The dedicated interface must support every authentication procedure the ASPSP offers its customers.",
      "level2": null,
      "origin": [
        {
          "act": "rts-2018-389",
          "articles": "32(3)"
        },
        {
          "act": "eba-opinion-2020"
        }
      ],
      "stet": {
        "1.6.3": {
          "status": "present",
          "note": "The specification provides redirect, decoupled and one-factor embedded, and each bank states which ones it supports.",
          "pages": [
            "https://openfinanceguide.com/en/stet/1.6.3/framework/3-prerequisites-and-technical-details",
            "https://openfinanceguide.com/en/stet/1.6.3/resources/authentication-approach"
          ]
        }
      },
      "verification": null,
      "sources": [
        {
          "document": "8221/26",
          "page": 263,
          "url": "https://data.consilium.europa.eu/doc/document/ST-8221-2026-INIT/en/pdf#page=263"
        }
      ],
      "verifiedAt": "2026-10-04"
    },
    {
      "id": "OB-OBS-010",
      "url": "https://openfinanceguide.com/en/dsp3/obligations/ob-obs-010",
      "article": "PSR 44(1)(j)",
      "alsoIn": [],
      "articleFinal": null,
      "actors": [
        "aspsp"
      ],
      "roles": [
        "product",
        "pentest"
      ],
      "appliesAt": "T+21",
      "title": "Adding steps to the journey",
      "level1": "In a redirect or decoupled journey, authentication at the ASPSP may not add steps or actions compared with the equivalent procedure in the direct channel.",
      "level2": null,
      "origin": [
        {
          "act": "rts-2018-389",
          "articles": "32(3)"
        },
        {
          "act": "eba-opinion-2020"
        }
      ],
      "stet": {
        "1.6.3": {
          "status": "out-of-scope",
          "note": "The number of screens depends on each bank's implementation, not on the specification.",
          "pages": []
        }
      },
      "verification": null,
      "sources": [
        {
          "document": "8221/26",
          "page": 263,
          "url": "https://data.consilium.europa.eu/doc/document/ST-8221-2026-INIT/en/pdf#page=263"
        }
      ],
      "verifiedAt": "2026-10-04"
    },
    {
      "id": "OB-OBS-011",
      "url": "https://openfinanceguide.com/en/dsp3/obligations/ob-obs-011",
      "article": "PSR 44(1)(k)",
      "alsoIn": [],
      "articleFinal": null,
      "actors": [
        "aspsp"
      ],
      "roles": [
        "product",
        "api",
        "pentest"
      ],
      "appliesAt": "T+21",
      "title": "Forcing a redirect to the bank's website",
      "level1": "The ASPSP may not impose an automatic redirect to its web page at authentication when the dedicated interface does not support all its authentication procedures.",
      "level2": null,
      "origin": [
        {
          "act": "rts-2018-389",
          "articles": "32(3)"
        },
        {
          "act": "eba-opinion-2020"
        }
      ],
      "stet": {
        "1.6.3": {
          "status": "review",
          "note": "STET redirection sends the user to a URL the bank provides, the OAuth2 authorisation endpoint for the AISP and the `consentApproval` link for the PISP. The specification does not describe handing over to the mobile app, which depends on each bank.",
          "pages": [
            "https://openfinanceguide.com/en/stet/1.6.3/framework/3-prerequisites-and-technical-details"
          ]
        }
      },
      "verification": null,
      "sources": [
        {
          "document": "8221/26",
          "page": 263,
          "url": "https://data.consilium.europa.eu/doc/document/ST-8221-2026-INIT/en/pdf#page=263"
        }
      ],
      "verifiedAt": "2026-10-04"
    },
    {
      "id": "OB-OBS-012",
      "url": "https://openfinanceguide.com/en/dsp3/obligations/ob-obs-012",
      "article": "PSR 44(1)(l)",
      "alsoIn": [],
      "articleFinal": null,
      "actors": [
        "aspsp"
      ],
      "roles": [
        "product",
        "api",
        "pentest"
      ],
      "appliesAt": "T+21",
      "title": "Two SCAs in a payment-initiation-only journey",
      "level1": "When the PISP sends all the information needed, the ASPSP may not require one SCA for the funds confirmation and a second one for the initiation.",
      "level2": null,
      "origin": [
        {
          "act": "rts-2018-389",
          "articles": "32(3)"
        },
        {
          "act": "eba-opinion-2020"
        }
      ],
      "stet": {
        "1.6.3": {
          "status": "present",
          "note": "A payment request is confirmed with a single authentication, and the PISP has no separate funds confirmation call.",
          "pages": [
            "https://openfinanceguide.com/en/stet/1.6.3/endpoints/pisp/payment-request-confirmation-post",
            "https://openfinanceguide.com/en/stet/1.6.3/flows/8-2-payment-request-with-multiple-instructions-having-different-beneficiaries"
          ]
        }
      },
      "verification": null,
      "sources": [
        {
          "document": "8221/26",
          "page": 264,
          "url": "https://data.consilium.europa.eu/doc/document/ST-8221-2026-INIT/en/pdf#page=264"
        }
      ],
      "verifiedAt": "2026-10-04"
    },
    {
      "id": "OB-OBS-013",
      "url": "https://openfinanceguide.com/en/dsp3/obligations/ob-obs-013",
      "article": "PSR 34",
      "alsoIn": [],
      "articleFinal": null,
      "actors": [
        "aspsp",
        "aisp",
        "pisp"
      ],
      "roles": [
        "compliance",
        "product"
      ],
      "appliesAt": "T+21",
      "title": "No contract required for the baseline",
      "level1": "No one may make AIS and PIS conditional on a contract with the ASPSP, and a multilateral scheme may not be the only way to reach the data the Regulation covers.",
      "level2": null,
      "origin": [
        {
          "act": "psd2",
          "articles": "66(5), 67(4)"
        }
      ],
      "stet": {
        "1.6.3": {
          "status": "out-of-scope",
          "note": "This is a contractual matter. Recitals 55 and 56 allow paid premium APIs beyond the baseline.",
          "pages": []
        }
      },
      "verification": null,
      "sources": [
        {
          "document": "8221/26",
          "page": 237,
          "url": "https://data.consilium.europa.eu/doc/document/ST-8221-2026-INIT/en/pdf#page=237"
        },
        {
          "document": "8221/26",
          "page": 44,
          "url": "https://data.consilium.europa.eu/doc/document/ST-8221-2026-INIT/en/pdf#page=44"
        },
        {
          "document": "8221/26",
          "page": 45,
          "url": "https://data.consilium.europa.eu/doc/document/ST-8221-2026-INIT/en/pdf#page=45"
        }
      ],
      "verifiedAt": "2026-10-04"
    },
    {
      "id": "OB-SCA-001",
      "url": "https://openfinanceguide.com/en/dsp3/obligations/ob-sca-001",
      "article": "PSR 86(2)",
      "alsoIn": [],
      "articleFinal": null,
      "actors": [
        "aspsp"
      ],
      "roles": [
        "api"
      ],
      "appliesAt": "T+21",
      "title": "TPPs rely on the ASPSP's authentication",
      "level1": "The ASPSP lets PISPs and AISPs rely on the authentication procedures it provides to its customers.",
      "level2": {
        "mandate": "PSR 89(1)(a)",
        "instrument": "rts",
        "deadline": "T+12",
        "link": "reading"
      },
      "origin": [
        {
          "act": "psd2",
          "articles": "97(5)"
        }
      ],
      "stet": {
        "1.6.3": {
          "status": "present",
          "note": "STET's three approaches, redirect, decoupled and one-factor embedded, all rely on the bank's authentication.",
          "pages": [
            "https://openfinanceguide.com/en/stet/1.6.3/framework/3-prerequisites-and-technical-details"
          ]
        }
      },
      "verification": null,
      "sources": [
        {
          "document": "8221/26",
          "page": 362,
          "url": "https://data.consilium.europa.eu/doc/document/ST-8221-2026-INIT/en/pdf#page=362"
        }
      ],
      "verifiedAt": "2026-10-04"
    },
    {
      "id": "OB-SCA-002",
      "url": "https://openfinanceguide.com/en/dsp3/obligations/ob-sca-002",
      "article": "PSR 86(3)",
      "alsoIn": [],
      "articleFinal": null,
      "actors": [
        "aspsp"
      ],
      "roles": [
        "api",
        "product",
        "pentest"
      ],
      "appliesAt": "T+21",
      "title": "ASPSP SCA on the AISP's first access only",
      "level1": "For a given AISP, the ASPSP applies SCA only on the first access to the account data and not afterwards, unless it has reasonable grounds to suspect fraud.",
      "level2": {
        "mandate": "PSR 89(1)(a)",
        "instrument": "rts",
        "deadline": "T+12",
        "link": "reading"
      },
      "origin": [
        {
          "act": "rts-2018-389",
          "articles": "10"
        }
      ],
      "stet": {
        "1.6.3": {
          "status": "review",
          "note": "The Framework has the AISP's refresh token revoked when the regulatory delay between two SCAs expires, which sends the user back to an SCA at the bank. After the first access the bank can no longer impose it, and renewing SCA is the AISP's job (OB-SCA-003).",
          "pages": [
            "https://openfinanceguide.com/en/stet/1.6.3/framework/3-prerequisites-and-technical-details",
            "https://openfinanceguide.com/en/stet/1.6.3/flows/6-1-psu-context-retrieval"
          ]
        }
      },
      "verification": null,
      "sources": [
        {
          "document": "8221/26",
          "page": 363,
          "url": "https://data.consilium.europa.eu/doc/document/ST-8221-2026-INIT/en/pdf#page=363"
        }
      ],
      "verifiedAt": "2026-10-04"
    },
    {
      "id": "OB-SCA-003",
      "url": "https://openfinanceguide.com/en/dsp3/obligations/ob-sca-003",
      "article": "PSR 86(4)",
      "alsoIn": [],
      "articleFinal": null,
      "actors": [
        "aisp"
      ],
      "roles": [
        "product",
        "api",
        "pentest"
      ],
      "appliesAt": "T+21",
      "title": "AISP SCA every 180 days",
      "level1": "The AISP applies SCA when the user accesses their data through it at least 180 days after the last one, using its own SCA or the ASPSP's.",
      "level2": {
        "mandate": "PSR 89(1)(a)",
        "instrument": "rts",
        "deadline": "T+12",
        "link": "reading"
      },
      "origin": [
        {
          "act": "rts-2018-389",
          "articles": "10"
        }
      ],
      "stet": {
        "1.6.3": {
          "status": "review",
          "note": "Using the bank's SCA, the AISP runs a full OAuth2 authorisation journey again. STET does not provide for the AISP telling the bank about an SCA it performed itself.",
          "pages": [
            "https://openfinanceguide.com/en/stet/1.6.3/flows/6-1-psu-context-retrieval",
            "https://openfinanceguide.com/en/stet/1.6.3/framework/3-prerequisites-and-technical-details"
          ]
        }
      },
      "verification": null,
      "sources": [
        {
          "document": "8221/26",
          "page": 363,
          "url": "https://data.consilium.europa.eu/doc/document/ST-8221-2026-INIT/en/pdf#page=363"
        }
      ],
      "verifiedAt": "2026-10-04"
    },
    {
      "id": "OB-SCA-004",
      "url": "https://openfinanceguide.com/en/dsp3/obligations/ob-sca-004",
      "article": "PSR 85a",
      "alsoIn": [],
      "articleFinal": null,
      "actors": [
        "aspsp"
      ],
      "roles": [
        "product",
        "compliance"
      ],
      "appliesAt": "T",
      "title": "Recurring credit transfers without SCA each time",
      "level1": "Recurring credit transfers initiated by the payer's PSP at the payee's request, under an agreement that sets frequency and amounts and whose set-up was subject to SCA, need no SCA for each transfer.",
      "level2": null,
      "origin": [],
      "stet": {
        "1.6.3": {
          "status": "out-of-scope",
          "note": "These transfers are initiated by the payer's PSP, with no PISP involved. The text does not say how recurring payments initiated by a PISP fit with this article.",
          "pages": []
        }
      },
      "verification": null,
      "sources": [
        {
          "document": "8221/26",
          "page": 361,
          "url": "https://data.consilium.europa.eu/doc/document/ST-8221-2026-INIT/en/pdf#page=361"
        }
      ],
      "verifiedAt": "2026-10-04"
    },
    {
      "id": "OB-SCA-005",
      "url": "https://openfinanceguide.com/en/dsp3/obligations/ob-sca-005",
      "article": "PSR 89(1)(e)",
      "alsoIn": [
        "PSR 89(1)(f)"
      ],
      "articleFinal": null,
      "actors": [
        "eba"
      ],
      "roles": [
        "compliance",
        "api"
      ],
      "appliesAt": "T",
      "title": "RTS on open communication standards",
      "level1": "The EBA drafts, for submission one year after entry into force, the technical standards on common and secure open standards of communication between ASPSPs, PISPs, AISPs and other providers for identification, authentication, notification and information, with supplementary provisions on dedicated interfaces.",
      "level2": {
        "mandate": "PSR 89(1)(e)",
        "instrument": "rts",
        "deadline": "T+12",
        "link": "named"
      },
      "origin": [
        {
          "act": "psd2",
          "articles": "98(1)(d)"
        }
      ],
      "stet": {
        "1.6.3": {
          "status": "out-of-scope",
          "note": "This RTS will say what a specification such as STET must carry. The EBA had published nothing as of 30 September 2026.",
          "pages": []
        }
      },
      "verification": null,
      "sources": [
        {
          "document": "8221/26",
          "page": 368,
          "url": "https://data.consilium.europa.eu/doc/document/ST-8221-2026-INIT/en/pdf#page=368"
        },
        {
          "document": "8221/26",
          "page": 371,
          "url": "https://data.consilium.europa.eu/doc/document/ST-8221-2026-INIT/en/pdf#page=371"
        }
      ],
      "verifiedAt": "2026-10-04"
    },
    {
      "id": "OB-ENF-001",
      "url": "https://openfinanceguide.com/en/dsp3/obligations/ob-enf-001",
      "article": "PSR 48(1)",
      "alsoIn": [
        "PSR 48(2)"
      ],
      "articleFinal": null,
      "actors": [
        "nca"
      ],
      "roles": [
        "compliance"
      ],
      "appliesAt": "T+21",
      "title": "The authority has obstacles removed",
      "level1": "The competent authority ensures ongoing compliance with Articles 35(1) and 38, has any identified Article 44 obstacle removed immediately, including on a TPP's report, and takes the necessary measures and sanctions without undue delay.",
      "level2": null,
      "origin": [
        {
          "act": "rts-2018-389",
          "articles": "30(6)"
        }
      ],
      "stet": {
        "1.6.3": {
          "status": "out-of-scope",
          "note": "The obligation lies with the authority, not with the interface.",
          "pages": []
        }
      },
      "verification": null,
      "sources": [
        {
          "document": "8221/26",
          "page": 271,
          "url": "https://data.consilium.europa.eu/doc/document/ST-8221-2026-INIT/en/pdf#page=271"
        }
      ],
      "verifiedAt": "2026-10-04"
    },
    {
      "id": "OB-ENF-002",
      "url": "https://openfinanceguide.com/en/dsp3/obligations/ob-enf-002",
      "article": "PSR 48(6)",
      "alsoIn": [
        "PSR 48(4)",
        "PSR 48(6a)"
      ],
      "articleFinal": null,
      "actors": [
        "nca"
      ],
      "roles": [
        "compliance"
      ],
      "appliesAt": "T+21",
      "title": "Dedicated staff and ASPSP-TPP meetings",
      "level1": "The competent authority has dedicated staff, holds joint meetings of ASPSPs and TPPs on its own initiative, and does its best to get interface access problems solved quickly and durably.",
      "level2": null,
      "origin": [],
      "stet": {
        "1.6.3": {
          "status": "out-of-scope",
          "note": "The obligation lies with the authority, not with the interface.",
          "pages": []
        }
      },
      "verification": null,
      "sources": [
        {
          "document": "8221/26",
          "page": 272,
          "url": "https://data.consilium.europa.eu/doc/document/ST-8221-2026-INIT/en/pdf#page=272"
        }
      ],
      "verifiedAt": "2026-10-04"
    },
    {
      "id": "OB-ENF-003",
      "url": "https://openfinanceguide.com/en/dsp3/obligations/ob-enf-003",
      "article": "PSR 48(7)",
      "alsoIn": [],
      "articleFinal": null,
      "actors": [
        "aspsp",
        "aisp",
        "pisp",
        "nca",
        "eba"
      ],
      "roles": [
        "compliance",
        "infra"
      ],
      "appliesAt": "T+21",
      "title": "TPP access data reported to the authority",
      "level1": "ASPSPs report data on AISP and PISP access to the accounts they service, the authority may ask TPPs for their data, and the EBA coordinates the monitoring and reports to the Commission every two years.",
      "level2": {
        "mandate": "PSR 48(8)",
        "instrument": "rts",
        "deadline": "T+18",
        "link": "named"
      },
      "origin": [],
      "stet": {
        "1.6.3": {
          "status": "out-of-scope",
          "note": "The content, method and frequency of this data will come from the Article 48(8) RTS.",
          "pages": []
        }
      },
      "verification": null,
      "sources": [
        {
          "document": "8221/26",
          "page": 273,
          "url": "https://data.consilium.europa.eu/doc/document/ST-8221-2026-INIT/en/pdf#page=273"
        },
        {
          "document": "8221/26",
          "page": 274,
          "url": "https://data.consilium.europa.eu/doc/document/ST-8221-2026-INIT/en/pdf#page=274"
        }
      ],
      "verifiedAt": "2026-10-04"
    },
    {
      "id": "OB-ENF-004",
      "url": "https://openfinanceguide.com/en/dsp3/obligations/ob-enf-004",
      "article": "PSR 42(1)",
      "alsoIn": [
        "PSR 42(2)"
      ],
      "articleFinal": null,
      "actors": [
        "aspsp",
        "nca"
      ],
      "roles": [
        "compliance",
        "product"
      ],
      "appliesAt": "T+21",
      "title": "Denying a TPP access over fraud",
      "level1": "The ASPSP may deny an AISP or PISP access for objectively justified and duly evidenced reasons of unauthorised or fraudulent access, tells the user before or at the latest immediately after, and reports it immediately to the authority.",
      "level2": null,
      "origin": [
        {
          "act": "psd2",
          "articles": "68(5), 68(6)"
        }
      ],
      "stet": {
        "1.6.3": {
          "status": "out-of-scope",
          "note": "The decision and the report happen outside the API.",
          "pages": []
        }
      },
      "verification": null,
      "sources": [
        {
          "document": "8221/26",
          "page": 256,
          "url": "https://data.consilium.europa.eu/doc/document/ST-8221-2026-INIT/en/pdf#page=256"
        }
      ],
      "verifiedAt": "2026-10-04"
    },
    {
      "id": "OB-ENF-005",
      "url": "https://openfinanceguide.com/en/dsp3/obligations/ob-enf-005",
      "article": "PSR 97",
      "alsoIn": [],
      "articleFinal": null,
      "actors": [
        "nca"
      ],
      "roles": [
        "compliance"
      ],
      "appliesAt": "T+21",
      "title": "Maximum fine of at least 10% of turnover",
      "level1": "For a breach of the open banking chapter or of Articles 85 to 87 on SCA, national law provides for a fine whose maximum is at least 10% of annual turnover for a legal person and at least EUR 3 million for a natural person.",
      "level2": null,
      "origin": [
        {
          "act": "psd2",
          "articles": "103"
        }
      ],
      "stet": {
        "1.6.3": {
          "status": "out-of-scope",
          "note": "Sanctions are a matter for national law and the authority.",
          "pages": []
        }
      },
      "verification": null,
      "sources": [
        {
          "document": "8221/26",
          "page": 393,
          "url": "https://data.consilium.europa.eu/doc/document/ST-8221-2026-INIT/en/pdf#page=393"
        },
        {
          "document": "8221/26",
          "page": 394,
          "url": "https://data.consilium.europa.eu/doc/document/ST-8221-2026-INIT/en/pdf#page=394"
        }
      ],
      "verifiedAt": "2026-10-04"
    },
    {
      "id": "OB-ENF-006",
      "url": "https://openfinanceguide.com/en/dsp3/obligations/ob-enf-006",
      "article": "PSR 98",
      "alsoIn": [],
      "articleFinal": null,
      "actors": [
        "nca"
      ],
      "roles": [
        "compliance"
      ],
      "appliesAt": "T+21",
      "title": "Daily penalty payments for up to six months",
      "level1": "The authority may impose daily penalty payments for an ongoing breach, for up to six months, with a maximum of at least 3% of average daily turnover for a legal person and at least EUR 30,000 for a natural person.",
      "level2": null,
      "origin": [],
      "stet": {
        "1.6.3": {
          "status": "out-of-scope",
          "note": "Sanctions are a matter for national law and the authority.",
          "pages": []
        }
      },
      "verification": null,
      "sources": [
        {
          "document": "8221/26",
          "page": 396,
          "url": "https://data.consilium.europa.eu/doc/document/ST-8221-2026-INIT/en/pdf#page=396"
        }
      ],
      "verifiedAt": "2026-10-04"
    },
    {
      "id": "OB-ENF-007",
      "url": "https://openfinanceguide.com/en/dsp3/obligations/ob-enf-007",
      "article": "PSD3 18(7)",
      "alsoIn": [],
      "articleFinal": null,
      "actors": [
        "eba"
      ],
      "roles": [
        "api",
        "compliance"
      ],
      "appliesAt": "T+21",
      "title": "Machine-readable central list of AISPs and PISPs",
      "level1": "The EBA keeps a central, machine-readable list of the providers offering payment initiation and account information services, with their name, identifier and authorisation status.",
      "level2": null,
      "origin": [],
      "stet": {
        "1.6.3": {
          "status": "out-of-scope",
          "note": "Today the bank checks the authorisation number carried by the TPP's eIDAS certificate. This list will give it another source for the authorisation status.",
          "pages": [
            "https://openfinanceguide.com/en/stet/1.6.3/framework/3-prerequisites-and-technical-details"
          ]
        }
      },
      "verification": null,
      "sources": [
        {
          "document": "8222/26",
          "page": 109,
          "url": "https://data.consilium.europa.eu/doc/document/ST-8222-2026-INIT/en/pdf#page=109"
        }
      ],
      "verifiedAt": "2026-10-04"
    }
  ]
}
