The PSR (PSD3) for compliance teams
The PSR is a regulation. It will apply without transposition 21 months after it enters into force, and PSD2 is repealed on the same date. Every ASPSP offering a payment account accessible online will have to run a dedicated interface with no fallback mechanism, and the only way out will be the Article 39 derogation, granted by the competent authority. The obstacles the EBA described in its opinion of 4 June 2020 become the list in Article 44. The authority must have them removed, including when a TPP reports them, and national law must provide for companies a maximum fine of at least 10% of annual turnover.
To map the text against current rules, each entry has an Origin field that says whether the rule comes from PSD2, from RTS 2018/389 or from the 2020 opinion, or whether it is new. The consent dashboard in Article 43 is entirely new, and no EBA mandate covers it. Articles are cited in the provisional numbering of the April 2026 compromise.
By Tancrède Simonin, October 4, 2026
Where to start
The five obligations that change the most for this role.
- OB-IF-001PSR 35(1)Covered
At least one dedicated interface per ASPSP
Every ASPSP offering a payment account accessible online must have at least one dedicated interface for exchanging data with AISPs and PISPs.
STET 1.6.3 STET 1.6.3 specifies a dedicated interface for the AISP, PISP and CBPII roles.
- OB-IF-014PSR 39(1)Out of spec
Derogation from the dedicated interface
At the ASPSP's request, the competent authority may exempt it from the dedicated interface and allow it either to open its customer interface, if that interface offers equivalent functions with widely accepted, interoperable standards, or to offer no interface at all where justified.
STET 1.6.3 The derogation is a decision of the competent authority, outside the specification's scope.
- OB-ENF-001PSR 48(1)Out of spec
The authority has obstacles removed
The competent authority ensures ongoing compliance with Articles 35(1) and 38, has any identified Article 44 obstacle removed immediately, including on a TPP's report, and takes the necessary measures and sanctions without undue delay.
STET 1.6.3 The obligation lies with the authority, not with the interface.
- OB-ENF-005PSR 97Out of spec
Maximum fine of at least 10% of turnover
For a breach of the open banking chapter or of Articles 85 to 87 on SCA, national law provides for a fine whose maximum is at least 10% of annual turnover for a legal person and at least EUR 3 million for a natural person.
STET 1.6.3 Sanctions are a matter for national law and the authority.
- OB-DB-001PSR 43(1)Out of spec
Consent dashboard at the ASPSP
The ASPSP builds into its user interface a dashboard where the user monitors and manages AIS consents and PIS consents covering multiple or recurring payments.
STET 1.6.3 The dashboard is a bank screen. Its content depends on the exchanges described in OB-DB-007 and OB-DB-008.
Every obligation for this role
33 obligations in the register concern this role. Obligations checked on October 4, 2026.
Dedicated interface(12)
- CoveredOB-IF-001PSR 35(1)T + 21 months
At least one dedicated interface per ASPSP
ASPSP
- Out of specOB-IF-002PSR 35(2)T + 21 months
Interface live within three months of authorisation
ASPSP
- CoveredOB-IF-003PSR 35(3)T + 21 months
Recognised communication standards
ASPSP
- Out of specOB-IF-004PSR 35(3)T + 21 months
Free technical documentation and public summary
ASPSP
- Out of specOB-IF-005PSR 35(4)T + 21 months
Two months' notice before any change
ASPSP
- Out of specOB-IF-006PSR 35(5)T + 21 months
Quarterly statistics published
ASPSP
- Out of specOB-IF-010PSR 37(1)T + 21 months
Parity with the customer interface
ASPSP
- Out of specOB-IF-011PSR 38(1)T + 21 months
Unavailability presumed after five failed requests
ASPSP
- Out of specOB-IF-014PSR 39(1)T + 21 months
Derogation from the dedicated interface
ASPSP · National authority
- Out of specOB-IF-015PSR 45(1)T + 21 months
TPP access through the dedicated interface only
AISP · PISP
- Out of specOB-IF-016PSR 45(2)T + 21 months
TPP duties on the customer interface
AISP · PISP
- Out of specOB-IF-018PSR 40(c)T + 21 months
TPP requests treated like the customer's own
ASPSP
Account information(3)
Payment initiation(2)
Consent dashboard(3)
Prohibited obstacles(4)
- To reviewOB-OBS-003PSR 44(1)(c)T + 21 months
Checking the consent given to the TPP
ASPSP
- To reviewOB-OBS-004PSR 44(1)(d)T + 21 months
Requiring additional registrations
ASPSP
- To reviewOB-OBS-005PSR 44(1)(e)T + 21 months
Requiring contact details to be pre-registered
ASPSP
- Out of specOB-OBS-013PSR 34T + 21 months
No contract required for the baseline
ASPSP · AISP · PISP
Strong customer authentication(2)
Authorities and sanctions(7)
- Out of specOB-ENF-001PSR 48(1)T + 21 months
The authority has obstacles removed
National authority
- Out of specOB-ENF-002PSR 48(6)T + 21 months
Dedicated staff and ASPSP-TPP meetings
National authority
- Out of specOB-ENF-003PSR 48(7)T + 21 months
TPP access data reported to the authority
ASPSP · AISP · PISP · National authority · EBA
- Out of specOB-ENF-004PSR 42(1)T + 21 months
Denying a TPP access over fraud
ASPSP · National authority
- Out of specOB-ENF-005PSR 97T + 21 months
Maximum fine of at least 10% of turnover
National authority
- Out of specOB-ENF-006PSR 98T + 21 months
Daily penalty payments for up to six months
National authority
- Out of specOB-ENF-007PSD3 18(7)T + 21 months
Machine-readable central list of AISPs and PISPs
EBA
STET 1.6.3 handbook pages to read
The pages these obligations cite, most cited first.
- 3. Prerequisites and technical detailsCited by OB-IF-003, OB-OBS-004, OB-OBS-005, OB-ENF-007
- PUT /consentsCited by OB-AIS-006, OB-OBS-003
- AISP endpointsCited by OB-IF-001
- PISP endpointsCited by OB-IF-001
- CBPII endpointsCited by OB-IF-001
- GET /accountsCited by OB-AIS-001
- AccountResourceCited by OB-AIS-001
- GET /accounts/{accountResourceId}/ownersCited by OB-AIS-006
- POST /payment-requestsCited by OB-PIS-013
- POST /registerCited by OB-OBS-004