OB-SCA-002PSR 86(3)Strong customer authentication
ASPSP SCA on the AISP's first access only
What the text fixes
For a given AISP, the ASPSP applies SCA only on the first access to the account data and not afterwards, unless it has reasonable grounds to suspect fraud.
- Article
- PSR 86(3)Provisional numbering of the April 2026 compromise (Council doc. 8221/26). The final numbering will be added when the Official Journal publishes the text, without changing the id.
- Who is bound
- ASPSP
- Who it is for
- API, Product, Audit and pentest
- Application
- 21 months after entry into force, the general application date (Article 112).
- Level 2
- RTS under Article PSR 89(1)(a), draft due at T + 12 months.Link suggested by this site; the text does not say so.
- Origin
- RTS 2018/389, Art. 10
STET 1.6.3
To reviewThe Framework has the AISP's refresh token revoked when the regulatory delay between two SCAs expires, which sends the user back to an SCA at the bank. After the first access the bank can no longer impose it, and renewing SCA is the AISP's job (OB-SCA-003).
Handbook pages
Sources
Checked on October 4, 2026
The entry as JSON
{
"id": "OB-SCA-002",
"article": "PSR 86(3)",
"alsoIn": [],
"articleFinal": null,
"actors": [
"aspsp"
],
"roles": [
"api",
"product",
"pentest"
],
"appliesAt": "T+21",
"title": {
"fr": "SCA de l'ASPSP au premier accès de l'AISP seulement",
"en": "ASPSP SCA on the AISP's first access only",
"es": "SCA del ASPSP solo en el primer acceso del AISP",
"pt-br": "SCA do ASPSP apenas no primeiro acesso do AISP"
},
"level1": {
"fr": "Pour un AISP donné, l'ASPSP n'applique la SCA qu'au premier accès aux données du compte, et plus ensuite, sauf motif raisonnable de soupçonner une fraude.",
"en": "For a given AISP, the ASPSP applies SCA only on the first access to the account data and not afterwards, unless it has reasonable grounds to suspect fraud.",
"es": "Para un AISP concreto, el ASPSP solo aplica la SCA en el primer acceso a los datos de la cuenta y no después, salvo motivos razonables para sospechar fraude.",
"pt-br": "Para um AISP específico, o ASPSP só aplica a SCA no primeiro acesso aos dados da conta e não depois, salvo motivo razoável para suspeitar de fraude."
},
"level2": {
"mandate": "PSR 89(1)(a)",
"instrument": "rts",
"deadline": "T+12",
"link": "reading"
},
"origin": [
{
"act": "rts-2018-389",
"articles": "10"
}
],
"stet": {
"1.6.3": {
"status": "review",
"note": {
"fr": "Le Framework fait révoquer le refresh token de l'AISP quand le délai réglementaire entre deux SCA expire, ce qui renvoie l'utilisateur vers une SCA chez la banque. Après le premier accès, la banque ne peut plus l'imposer, et renouveler la SCA revient à l'AISP (OB-SCA-003).",
"en": "The Framework has the AISP's refresh token revoked when the regulatory delay between two SCAs expires, which sends the user back to an SCA at the bank. After the first access the bank can no longer impose it, and renewing SCA is the AISP's job (OB-SCA-003).",
"es": "El Framework hace revocar el refresh token del AISP cuando vence el plazo reglamentario entre dos SCA, lo que devuelve al usuario a una SCA en el banco. Tras el primer acceso, el banco ya no puede imponerla, y renovar la SCA corresponde al AISP (OB-SCA-003).",
"pt-br": "O Framework faz revogar o refresh token do AISP quando vence o prazo regulamentar entre duas SCAs, o que leva o usuário de volta a uma SCA no banco. Depois do primeiro acesso, o banco não pode mais impô-la, e renovar a SCA cabe ao AISP (OB-SCA-003)."
},
"pages": [
"framework/3-prerequisites-and-technical-details",
"flows/6-1-psu-context-retrieval"
]
}
},
"verification": null,
"sources": [
{
"document": "8221/26",
"page": 363
}
],
"verifiedAt": "2026-10-04"
}