# OB-SCA-002 — ASPSP SCA on the AISP's first access only

> For a given AISP, the ASPSP applies SCA only on the first access to the account data and not afterwards, unless it has reasonable grounds to suspect fraud.

- Article: PSR 86(3)
- Who is bound: ASPSP
- Who it is for: API, Product, Audit and pentest
- Application: 21 months after entry into force, the general application date (Article 112).
- Level 2: RTS under Article PSR 89(1)(a), draft due at T + 12 months.
- Origin: RTS 2018/389, Art. 10

Provisional numbering of the April 2026 compromise (Council doc. 8221/26). The final numbering will be added when the Official Journal publishes the text, without changing the id.

## STET 1.6.3: To review

The Framework has the AISP's refresh token revoked when the regulatory delay between two SCAs expires, which sends the user back to an SCA at the bank. After the first access the bank can no longer impose it, and renewing SCA is the AISP's job (OB-SCA-003).

- <https://openfinanceguide.com/en/stet/1.6.3/framework/3-prerequisites-and-technical-details>
- <https://openfinanceguide.com/en/stet/1.6.3/flows/6-1-psu-context-retrieval>

## Sources

- [Council doc. 8221/26, page 363](https://data.consilium.europa.eu/doc/document/ST-8221-2026-INIT/en/pdf#page=363)

Checked on 2026-10-04. https://openfinanceguide.com/en/dsp3/obligations/ob-sca-002
