OB-ENF-004PSR 42(1)Authorities and sanctions

Denying a TPP access over fraud

What the text fixes

The ASPSP may deny an AISP or PISP access for objectively justified and duly evidenced reasons of unauthorised or fraudulent access, tells the user before or at the latest immediately after, and reports it immediately to the authority.

Article
PSR 42(1) · See also PSR 42(2)Provisional numbering of the April 2026 compromise (Council doc. 8221/26). The final numbering will be added when the Official Journal publishes the text, without changing the id.
Who is bound
ASPSP, National authority
Who it is for
Compliance, Product
Application
21 months after entry into force, the general application date (Article 112).
Level 2
No EBA mandate covers this obligation.
Origin
PSD2, Art. 68(5), 68(6)

STET 1.6.3

Out of spec

The decision and the report happen outside the API.

Sources

Checked on October 4, 2026

The entry as JSON
{
  "id": "OB-ENF-004",
  "article": "PSR 42(1)",
  "alsoIn": [
    "PSR 42(2)"
  ],
  "articleFinal": null,
  "actors": [
    "aspsp",
    "nca"
  ],
  "roles": [
    "compliance",
    "product"
  ],
  "appliesAt": "T+21",
  "title": {
    "fr": "Refus d'accès à un TPP pour fraude",
    "en": "Denying a TPP access over fraud",
    "es": "Denegación de acceso a un TPP por fraude",
    "pt-br": "Recusa de acesso a um TPP por fraude"
  },
  "level1": {
    "fr": "L'ASPSP peut refuser l'accès à un AISP ou à un PISP pour des raisons objectivement justifiées et documentées d'accès non autorisé ou frauduleux, en informe l'utilisateur avant ou au plus tard juste après, et le signale immédiatement à l'autorité.",
    "en": "The ASPSP may deny an AISP or PISP access for objectively justified and duly evidenced reasons of unauthorised or fraudulent access, tells the user before or at the latest immediately after, and reports it immediately to the authority.",
    "es": "El ASPSP puede denegar el acceso a un AISP o a un PISP por razones objetivamente justificadas y documentadas de acceso no autorizado o fraudulento, lo comunica al usuario antes o, a más tardar, justo después, y lo notifica de inmediato a la autoridad.",
    "pt-br": "O ASPSP pode recusar o acesso a um AISP ou a um PISP por razões objetivamente justificadas e documentadas de acesso não autorizado ou fraudulento, informa o usuário antes ou, no máximo, logo depois, e comunica imediatamente à autoridade."
  },
  "level2": null,
  "origin": [
    {
      "act": "psd2",
      "articles": "68(5), 68(6)"
    }
  ],
  "stet": {
    "1.6.3": {
      "status": "out-of-scope",
      "note": {
        "fr": "La décision et le signalement se font hors de l'API.",
        "en": "The decision and the report happen outside the API.",
        "es": "La decisión y la notificación se producen fuera de la API.",
        "pt-br": "A decisão e a comunicação acontecem fora da API."
      },
      "pages": []
    }
  },
  "verification": null,
  "sources": [
    {
      "document": "8221/26",
      "page": 256
    }
  ],
  "verifiedAt": "2026-10-04"
}