The PSR (PSD3) for product teams
The PSR adds a screen on the bank's side, the consent dashboard. For each consent the user sees the TPP, the purpose and the dates of access. They can withdraw access at any time, restore it within 48 hours, and look up withdrawn or expired consents for two years. The twelve obstacles in Article 44 read as journey rules. The bank cannot ask for more SCA than in its own channel or add steps, and it cannot redirect to its website by default if the interface does not offer all of its authentication procedures.
For PISPs, two points come first. The PISP chooses the authentication procedure shown to the payer, and it can check the account holder's name before initiation. STET 1.6.3 covers the first only in part and has nothing for the second.
By Tancrède Simonin, October 4, 2026
Where to start
The five obligations that change the most for this role.
- OB-DB-002PSR 43(2)(a)Partial
What the dashboard shows
For each ongoing consent, the dashboard shows the TPP, the account, the purpose, the validity period with the date of consent, the categories of data shared and the dates the data was accessed.
STET 1.6.3 The bank knows the TPP, the accounts, the data types sent with
PUT /consentsand the access dates. It receives no purpose, validity or consent date. - OB-DB-004PSR 43(2)(c)Missing
Re-establishment possible for 48 hours
Within 48 hours of withdrawing a consent, the user can re-establish the access withdrawn.
STET 1.6.3 A revoked refresh token does not come back, and the STET consent resource has no state. Restoring access takes a new authorisation journey.
- OB-OBS-010PSR 44(1)(j)Out of spec
Adding steps to the journey
In a redirect or decoupled journey, authentication at the ASPSP may not add steps or actions compared with the equivalent procedure in the direct channel.
STET 1.6.3 The number of screens depends on each bank's implementation, not on the specification.
- OB-PIS-008PSR 36(4)(ha)Partial
The PISP chooses the authentication procedure
Where the ASPSP offers several authentication procedures, the PISP chooses which one is presented to the payer.
STET 1.6.3 The PISP lists the approaches it accepts in
acceptedAuthenticationApproachand the bank picks the one it applies inappliedAuthenticationApproach. The text gives the choice to the PISP. - OB-PIS-007PSR 36(4)(g)Missing
Account holder name check before initiation
The PISP can check the account holder's name before initiating the payment, whether or not that name is available in the direct interface.
STET 1.6.3 The PISP role has no account operation in STET 1.6.3.
Every obligation for this role
43 obligations in the register concern this role. Obligations checked on October 4, 2026.
Dedicated interface(3)
Account information(5)
- CoveredOB-AIS-001PSR 33(2)T + 21 months
All payment accounts accessible online
ASPSP
- CoveredOB-AIS-002PSR 36(3)T + 21 months
Minimum data for the AISP
ASPSP
- PartialOB-AIS-003PSR 37(2)T + 21 months
Data parity with the customer interface
ASPSP
- To reviewOB-AIS-004PSR 41(2)T + 21 months
AIS access with or without the user
ASPSP
- Out of specOB-AIS-005PSR 41(2a)T + 21 months
User told about background access
AISP
Payment initiation(12)
- CoveredOB-PIS-001PSR 36(4)(a)T + 21 months
Standing order, set-up and revocation
ASPSP
- CoveredOB-PIS-003PSR 36(4)(c)T + 21 months
Future-dated payment, initiation and revocation
ASPSP
- CoveredOB-PIS-004PSR 36(4)(d)T + 21 months
Payments to multiple beneficiaries
ASPSP
- CoveredOB-PIS-005PSR 36(4)(e)T + 21 months
Payee outside the payer's beneficiary list
ASPSP
- PartialOB-PIS-006PSR 37(3)T + 21 months
Execution information and status until the end
ASPSP
- MissingOB-PIS-007PSR 36(4)(g)T + 21 months
Account holder name check before initiation
ASPSP
- PartialOB-PIS-008PSR 36(4)(ha)T + 21 months
The PISP chooses the authentication procedure
ASPSP
- MissingOB-PIS-009PSR 36(4)(hc)T + 21 months
Account, holders and currencies visible before initiation
ASPSP
- PartialOB-PIS-011PSR 36(5)(b)T + 21 months
Confirmation that the payment will be executed
ASPSP
- PartialOB-PIS-012PSR 65(1)T + 21 months
Refusal over suspected fraud, reasons to the PISP
ASPSP
- To reviewOB-PIS-013PSR 57T + 27 months
Payee verification, PISP liability
PISP · ASPSP
- Out of specOB-PIS-014PSR 46(1)(fa)T + 21 months
The PISP may refuse to initiate
PISP
Consent dashboard(8)
- Out of specOB-DB-001PSR 43(1)T + 21 months
Consent dashboard at the ASPSP
ASPSP
- PartialOB-DB-002PSR 43(2)(a)T + 21 months
What the dashboard shows
ASPSP
- Out of specOB-DB-003PSR 43(2)(b)T + 21 months
Withdrawal at any time, free of charge
ASPSP
- MissingOB-DB-004PSR 43(2)(c)T + 21 months
Re-establishment possible for 48 hours
ASPSP
- Out of specOB-DB-005PSR 43(2)(d)T + 21 months
Two-year history
ASPSP
- Out of specOB-DB-006PSR 43(2b)T + 21 months
After withdrawal, the TPP stops and deletes
AISP · PISP
- PartialOB-DB-007PSR 43(3b)T + 21 months
The TPP sends each consent to the ASPSP
AISP · PISP · ASPSP
- Out of specOB-DB-009PSR 43(3)T + 21 months
Neutral dashboard, no deceptive design
ASPSP
Prohibited obstacles(11)
- CoveredOB-OBS-001PSR 44(1)(a)T + 21 months
Blocking the use of the bank's credentials
ASPSP
- CoveredOB-OBS-002PSR 44(1)(b)T + 21 months
Making the user type the account identifier at the bank
ASPSP
- To reviewOB-OBS-003PSR 44(1)(c)T + 21 months
Checking the consent given to the TPP
ASPSP
- CoveredOB-OBS-006PSR 44(1)(f)T + 21 months
Limiting payments to the payer's beneficiary list
ASPSP
- CoveredOB-OBS-007PSR 44(1)(g)T + 21 months
Limiting to domestic account identifiers
ASPSP
- To reviewOB-OBS-008PSR 44(1)(h)T + 21 months
More SCA than in the direct channel
ASPSP
- CoveredOB-OBS-009PSR 44(1)(i)T + 21 months
Not supporting every authentication procedure
ASPSP
- Out of specOB-OBS-010PSR 44(1)(j)T + 21 months
Adding steps to the journey
ASPSP
- To reviewOB-OBS-011PSR 44(1)(k)T + 21 months
Forcing a redirect to the bank's website
ASPSP
- CoveredOB-OBS-012PSR 44(1)(l)T + 21 months
Two SCAs in a payment-initiation-only journey
ASPSP
- Out of specOB-OBS-013PSR 34T + 21 months
No contract required for the baseline
ASPSP · AISP · PISP
Strong customer authentication(3)
Authorities and sanctions(1)
STET 1.6.3 handbook pages to read
The pages these obligations cite, most cited first.
- 3. Prerequisites and technical detailsCited by OB-AIS-004, OB-DB-003, OB-DB-004, OB-OBS-001, OB-OBS-008, OB-OBS-009, OB-OBS-011, OB-SCA-002, OB-SCA-003
- POST /payment-requestsCited by OB-PIS-004, OB-PIS-005, OB-PIS-008, OB-PIS-009, OB-PIS-013, OB-OBS-002, OB-OBS-006, OB-OBS-007
- PUT /consentsCited by OB-DB-002, OB-DB-004, OB-DB-007, OB-OBS-003
- GET /payment-requests/{paymentRequestResourceId}Cited by OB-PIS-006, OB-PIS-011, OB-PIS-012
- GET /accountsCited by OB-AIS-001, OB-AIS-002
- PUT /payment-requests/{paymentRequestResourceId}Cited by OB-PIS-001, OB-PIS-003
- 8.2. Payment Request with multiple instructions having different beneficiariesCited by OB-PIS-004, OB-OBS-012
- BeneficiaryCited by OB-PIS-005, OB-OBS-006
- AuthenticationApproachCited by OB-OBS-001, OB-OBS-009
- 6.1. PSU Context RetrievalCited by OB-SCA-002, OB-SCA-003
- AccountResourceCited by OB-AIS-001
- GET /accounts/{accountResourceId}/ownersCited by OB-AIS-002
- GET /accounts/{accountResourceId}/balancesCited by OB-AIS-002
- GET /accounts/{accountResourceId}/transactionsCited by OB-AIS-002
- AISP endpointsCited by OB-AIS-003
- 8.3. Standing Orders RequestCited by OB-PIS-001
- StandingOrderCharacteristicsCited by OB-PIS-001
- 8.1. Payment Request with multiple instructions having differentCited by OB-PIS-003
- GET /payment-requests/{paymentRequestResourceId}/transactionsCited by OB-PIS-006
- PISP endpointsCited by OB-PIS-007
- SupplementaryDataCited by OB-PIS-008
- PaymentInformationStatusCodeCited by OB-PIS-011
- StatusReasonInformationCited by OB-PIS-012
- AccessCited by OB-DB-002
- 6.2. Consent ForwardingCited by OB-DB-007
- PaymentRequestResourceCited by OB-OBS-002
- AccountIdentificationCited by OB-OBS-007
- POST /payment-requests/{paymentRequestResourceId}/confirmationCited by OB-OBS-012