# OB-ENF-004 — Denying a TPP access over fraud

> The ASPSP may deny an AISP or PISP access for objectively justified and duly evidenced reasons of unauthorised or fraudulent access, tells the user before or at the latest immediately after, and reports it immediately to the authority.

- Article: PSR 42(1) (See also PSR 42(2))
- Who is bound: ASPSP, National authority
- Who it is for: Compliance, Product
- Application: 21 months after entry into force, the general application date (Article 112).
- Level 2: No EBA mandate covers this obligation.
- Origin: PSD2, Art. 68(5), 68(6)

Provisional numbering of the April 2026 compromise (Council doc. 8221/26). The final numbering will be added when the Official Journal publishes the text, without changing the id.

## STET 1.6.3: Out of spec

The decision and the report happen outside the API.


## Sources

- [Council doc. 8221/26, page 256](https://data.consilium.europa.eu/doc/document/ST-8221-2026-INIT/en/pdf#page=256)

Checked on 2026-10-04. https://openfinanceguide.com/en/dsp3/obligations/ob-enf-004
