Compliance & onboarding

Strong Customer Authentication (SCA)

Strong Customer Authentication (SCA) is a rule requiring two independent factors to confirm a payer — cutting fraud on European online payments.

Strong Customer Authentication, or SCA, is a regulatory requirement — under Europe’s PSD2 — that many online payments be confirmed with at least two independent factors before they go through.

How it works

  • The two factors come from different categories: something you know (a password), something you have (a phone), something you are (a fingerprint).
  • In card payments it usually shows up as a 3-D Secure step — a bank prompt or app approval mid-checkout.
  • Some payments are exempt — low-value, recurring, or low-risk transactions — so the rule bites selectively rather than on every tap.

Unlike KYC, which verifies identity at onboarding, SCA authenticates the payer at the moment of paying.

Why it matters

SCA meaningfully cuts fraud, but each extra step is also a place a genuine customer abandons the payment. For a platform, that trade-off is real revenue: too little authentication invites chargebacks, too much clumsy friction and baskets are dropped at the last screen. Applying the exemptions correctly is how you stay compliant without taxing every checkout.

How Fynex does it

Fynex is PCI DSS Level 1 and an FCA-authorised e-money institution, and handles SCA within its payment flows so platforms meet the requirement without wiring it up themselves. See Marketplaces & Platforms.

Book a demo