Glossary
Strong customer authentication (SCA) is a regulatory requirement under the EU’s PSD2 that mandates multi-factor authentication for electronic payments and account access, using at least two of three independent factors: knowledge, possession, and inherence. It’s a legal mandate, not just a best practice, and it reshaped how European banks and merchants authenticate customers.
SCA exists to cut payment fraud by ensuring that sensitive actions are protected by independent factors, with additional rules to bind the authentication to the specific transaction.
SCA allows exemptions to avoid friction on low-risk transactions: small amounts, recurring payments, trusted beneficiaries, and, importantly, transactions the provider’s risk analysis deems low-risk (transaction risk analysis, or TRA). These exemptions are where risk-based authentication meets compliance: a strong fraud engine lets a provider safely apply exemptions, reducing checkout friction while staying within the rules.
For banks and merchants serving European customers, SCA compliance is mandatory, and getting it wrong means declined transactions and lost sales as well as regulatory exposure. The practical challenge is satisfying the mandate without tanking conversion, which is exactly where risk-based orchestration earns its keep, applying strong authentication when required and leaning on exemptions (backed by solid risk analysis) when allowed. SCA is also a preview of where regulators elsewhere are heading, so its principles matter beyond Europe.
SCA’s exemptions are where compliance and conversion meet, and using them well is a real competitive advantage. The rules allow authentication to be skipped for low-risk cases: small-value payments, recurring transactions of the same amount, payments to trusted beneficiaries the customer has whitelisted, and (most importantly) transactions a provider’s own risk analysis deems low-risk under transaction risk analysis (TRA). Each exemption avoided friction is a checkout not abandoned.
The catch is that TRA exemptions depend on having a strong fraud engine and keeping fraud rates below defined thresholds. A provider with accurate, real-time risk analysis can safely claim more exemptions, waving through more good customers without a challenge, while staying compliant. A provider with weak fraud detection must challenge more transactions to stay safe, paying for it in abandonment. This is why SCA turned risk-based authentication from a nice-to-have into a commercial lever in Europe: better fraud detection literally translates into smoother checkout within the rules. It’s a concrete example of security capability driving revenue, not just protecting it.
What does SCA stand for?
Strong customer authentication.
What regulation requires SCA?
The EU’s PSD2 (Payment Services Directive 2).
What is dynamic linking?
A requirement that payment authentication be tied to the specific amount and payee.
Can SCA be skipped for some transactions?
Yes, exemptions exist for low-risk cases, including transaction risk analysis, which relies on a strong fraud engine.
How does SCA affect conversion?
Well-applied exemptions (backed by strong fraud detection) let low-risk payments through without a challenge, reducing checkout friction while staying compliant.
Does SCA apply outside the EU?
SCA is a PSD2 (EU) requirement, but its principles are influencing payment-security regulation elsewhere, so they matter beyond Europe.
Related: PSD2 · Multi-Factor Authentication (MFA) · Risk-Based Authentication · Open Banking · Two-Factor Authentication (2FA)