The PSR (PSD3) for compliance teams

By Tancrède Simonin, October 4, 2026

The five obligations that change the most for this role.

  • OB-IF-001PSR 35(1)Covered

    At least one dedicated interface per ASPSP

    Every ASPSP offering a payment account accessible online must have at least one dedicated interface for exchanging data with AISPs and PISPs.

    STET 1.6.3 STET 1.6.3 specifies a dedicated interface for the AISP, PISP and CBPII roles.

  • OB-IF-014PSR 39(1)Out of spec

    Derogation from the dedicated interface

    At the ASPSP's request, the competent authority may exempt it from the dedicated interface and allow it either to open its customer interface, if that interface offers equivalent functions with widely accepted, interoperable standards, or to offer no interface at all where justified.

    STET 1.6.3 The derogation is a decision of the competent authority, outside the specification's scope.

  • OB-ENF-001PSR 48(1)Out of spec

    The authority has obstacles removed

    The competent authority ensures ongoing compliance with Articles 35(1) and 38, has any identified Article 44 obstacle removed immediately, including on a TPP's report, and takes the necessary measures and sanctions without undue delay.

    STET 1.6.3 The obligation lies with the authority, not with the interface.

  • OB-ENF-005PSR 97Out of spec

    Maximum fine of at least 10% of turnover

    For a breach of the open banking chapter or of Articles 85 to 87 on SCA, national law provides for a fine whose maximum is at least 10% of annual turnover for a legal person and at least EUR 3 million for a natural person.

    STET 1.6.3 Sanctions are a matter for national law and the authority.

  • OB-DB-001PSR 43(1)Out of spec

    Consent dashboard at the ASPSP

    The ASPSP builds into its user interface a dashboard where the user monitors and manages AIS consents and PIS consents covering multiple or recurring payments.

    STET 1.6.3 The dashboard is a bank screen. Its content depends on the exchanges described in OB-DB-007 and OB-DB-008.

Every obligation for this role

33 obligations in the register concern this role. Obligations checked on October 4, 2026.

Open this view in the register
33 of 33

Dedicated interface(12)

Account information(3)

Payment initiation(2)

Consent dashboard(3)

Prohibited obstacles(4)

Strong customer authentication(2)

Authorities and sanctions(7)

STET 1.6.3 handbook pages to read

The pages these obligations cite, most cited first.

Glossary cards