• Skip to primary navigation
  • Skip to main content
  • Skip to footer
The Evolution of ESG RegulationThe Evolution of ESG RegulationThe Evolution of ESG Regulation

CUBE global

  • Products
        • RegPlatform product overviewOur enterprise product, providing regulatory intelligence for large, global financial institutions looking to tackle complex compliance.
        • RegAssure product overviewOur highly intuitive, seamless compliance product, that grows with your small or medium sized business.
        • CUBE's technology
  • Solutions
        • PrivacyGlobal governance for data privacy regulations, the world over
        • RecordsHolistic oversight of ever-growing regulations for records
        • CybersecurityAutomated workflows for up to date, relevant data on cyber
        • Technology riskEffective policies and controls to mitigate technology risk
        • Financial crime and AMLWatertight audit trails to show risk-based rationale
        • View all solutions
  • Resources
        • Resource hubLifting the lid on financial services, compliance, and regulation
        • Read

        • Case Studies
        • Blog posts
        • Reports
        • RegNews
        • Brochures
        • Find

        • Compliance Corner
        • Compliance Confessions
        • ESG Conference
        • CUBE’s regulation game
        • Listen

        • Videos
        • Webinars
        • Podcasts
  • Partners
        • Advisory and consulting partnersEnhance your regulatory compliance offering with the entire suite of CUBE regulatory data.
        • Integration partnersCompliance is complex enough without over-complicated integration procedures.
        • Technology partnersAdd value to existing customer applications with a unified window into regulatory intelligence.
        • Partners overview
  • About us
        • About usThe story of who we are, how we got here and why we’re exceptionally proud of what we do
        • TeamThe visionaries and leaders powering CUBE’s success
        • NewsThe latest news from CUBE
        • CareersOur movement to transform regulatory data into regulatory intelligence
        • ContactWant to know more? Get in touch
  • Request a demo
Customer login
Home » Resources » What regulations are there for the payment services industry?

June 23, 2023

Estimated reading time: 4 minutes

What regulations are there for the payment services industry?

With new payment methods emerging all the time, accompanying regulations are also coming in thick and fast. But regulations don’t need to feel restrictive. Leading card providers like Mastercard and Visa leverage their compliance to gain a competitive advantage over other providers and upgrade their customer experiences. 

Here are some of the biggest payment services regulations: 

  1. Payment Services Directive 2
  2. Strong Customer Authentication
  3. Anti-Money Laundering Directives
  4. Suspicious Transaction and Order Reports

Payment Services Directive 2

The version of the Payment Services Directive, released in the mid-2010s, was the second iteration of the regulation. It’s an EU framework that aims to hold payment providers accountable and make the industry fairer for customers. 

Here are some of the key takeaways from the PSD2:

  • It eliminates surcharges on payment instruments by payment service providers for consumer protection.
  • It makes T&Cs more visible so that customers are more informed about what they’re signing up for.
  • It allows for the creation of APIs for third-party providers to increase access to open banking and reduce friction for customers.

The second payment services directive was well-received, as it provided a clear way for European payment institutions to take advantage of the disruptive embedded finance industry. Moreover, a call for feedback in 2018 for the payment services regulation found that the EBA’s requirements were effective in enhancing competition, facilitating innovation and protecting consumers. 

Strong Customer Authentication

Strong Customer Authentication (SCA) is one arm of the PSD2. It is, therefore, also driven by the European Commission under the main payment regulation framework released in the last decade.

SCA focuses on customer-led payments such as contactless transactions in a shop, compared to direct debits or subscriptions which are typically merchant-led. 

The SCA has two main points of focus: 

  • 2-Factor Authentication (2FA)
  • 3DSecure2 Protocol (3DSP)

2-Factor Authentication

2FA is a payment validation tool which aims to verify the identity of the payment maker. This decreases the risk of fraud, as online money and payment channels become more secure against third parties. 

Under the payment services regulation, 2FA requires at least two of the following three information categories before a payment can be made: 

  1. Knowledge (such as a password)
  2. Possession (such as a code sent to your mobile phone)
  3. Inherence (such as fingerprint or facial ID)

3D Secure Protocol

3D Secure Protocol is a security protocol to facilitate online card transactions. Dynamic linking technology is used to track customer payments while protecting their identities by keeping the data anonymous. 

3DSP was first adopted by leading payment brand Visa to increase the security of their online payments, without the intrusiveness of previous protocols. 

Overall, SCA works to reduce the risk of fraud because it requires such specific validation for payments. This also increases confidence in risk management practices, even as less-established payment channels increase in popularity. 

AMLD5 and AMLD6

Anti-money laundering directives AMLD5 and AMLD6 are both recent regulations that touch on payment services. As we move into the digital age, money laundering checks should focus on moving with the technology, including online payments. 

AMLD5 became effective in 2020, and focused on four major areas: 

  • Online identification (including the SCA mentioned above).
  • Better due diligence – including the purpose and background of each transaction.
  • Ultimate Beneficial Ownership changes – including better verification methods and a new private register that’s specific for banks.
  • Better due diligence for politically exposed persons.

It applies to all member states, including EU countries and the US, but not the UK. It clarified 22 separate offences with regard to illicit finance or money laundering. Many of these involve the internet or modern technologies, such as online piracy and cybercrime. 

The regulation also places more emphasis on the penalties and punishments of those convicted of these types of crimes. This aims to deter potential criminals. Finally, 6AMLD6 also encourages member-state cooperation as regulators recognise the need for a collaborative approach to payment services and preventing fraud. 

Suspicious Transaction and Order Reports (STORs)

Finally, STORs are required by any company which facilitates trading or investments, which could be considered a payment services regulation. They are reports which must be filed for investigation if one of seven key suspicious behaviours are noticed. 

STORs were introduced under the EU system to prevent market abuse and help payment firms and financial services companies to monitor each payment transaction and their payment systems more closely. 

Compliance made easy

For payment services companies, it can feel overwhelming to create new compliance strategies as more payment regulations are launched. Additionally, there is constant work to remain up to date with changes to existing legislation. 

No matter your jurisdiction, CUBE can do the heavy lifting. We use horizon-scanning technology to help businesses stay ahead of the regulatory curve and eliminate the need for manual trawling of regulatory body sites, so that compliance officers can focus on what matters most. 

Demo CUBE to find out more. 

Keep ahead of emerging regulations by speaking to CUBE.


Speak to CUBE

Related resources
View all articles
Blogs

The crackdown on crypto continues 

Recent US and UK crypto regulation developments
Blogs

Taming the crypto wild west: the US and UK strengthen regulation

SEC cracks down on fraudulent crypto activity
Blogs

The SEC’s crackdown on fraudulent crypto activity

cryptocurrency and global financial inclusion
Blogs

How will embracing cryptocurrency bring global financial inclusion?


Want CUBE updates and latest industry news sent straight to your inbox?

Footer

Add CUBE logo here

  • Products
    • Partners
    • Solutions
  • Resource hub
    • Blogs
    • Reports
    • Brochures
    • Compliance Corner
    • Webinars
    • Podcasts
    • Videos
  • Behind CUBE
    • About us
    • Meet the team
    • Careers
    • News
    • Contact us
  • The legal bits
    • Privacy policy
    • Cookie policy
    • Terms of use
    • Accessibility
Follow us:
  • LinkedIn
  • Twitter
  • YouTube

© 2023 CUBE Content Governance Global Limited

  • English
  • US

envelope

Want CUBE updates and latest industry news sent straight to your inbox?

Sign up to our Newsletter here