The PSR (PSD3) for product teams

By Tancrède Simonin, October 4, 2026

The five obligations that change the most for this role.

  • OB-DB-002PSR 43(2)(a)Partial

    What the dashboard shows

    For each ongoing consent, the dashboard shows the TPP, the account, the purpose, the validity period with the date of consent, the categories of data shared and the dates the data was accessed.

    STET 1.6.3 The bank knows the TPP, the accounts, the data types sent with PUT /consents and the access dates. It receives no purpose, validity or consent date.

  • OB-DB-004PSR 43(2)(c)Missing

    Re-establishment possible for 48 hours

    Within 48 hours of withdrawing a consent, the user can re-establish the access withdrawn.

    STET 1.6.3 A revoked refresh token does not come back, and the STET consent resource has no state. Restoring access takes a new authorisation journey.

  • OB-OBS-010PSR 44(1)(j)Out of spec

    Adding steps to the journey

    In a redirect or decoupled journey, authentication at the ASPSP may not add steps or actions compared with the equivalent procedure in the direct channel.

    STET 1.6.3 The number of screens depends on each bank's implementation, not on the specification.

  • OB-PIS-008PSR 36(4)(ha)Partial

    The PISP chooses the authentication procedure

    Where the ASPSP offers several authentication procedures, the PISP chooses which one is presented to the payer.

    STET 1.6.3 The PISP lists the approaches it accepts in acceptedAuthenticationApproach and the bank picks the one it applies in appliedAuthenticationApproach. The text gives the choice to the PISP.

  • OB-PIS-007PSR 36(4)(g)Missing

    Account holder name check before initiation

    The PISP can check the account holder's name before initiating the payment, whether or not that name is available in the direct interface.

    STET 1.6.3 The PISP role has no account operation in STET 1.6.3.

Every obligation for this role

43 obligations in the register concern this role. Obligations checked on October 4, 2026.

Open this view in the register
43 of 43

Dedicated interface(3)

Account information(5)

Payment initiation(12)

Consent dashboard(8)

Prohibited obstacles(11)

Strong customer authentication(3)

Authorities and sanctions(1)

STET 1.6.3 handbook pages to read

The pages these obligations cite, most cited first.

Glossary cards