Skip to content

Oh no! How do I audit SCA and CSC under PSD2?

Published on:

NOREA, the Dutch Payments Association and the Dutch Banking Association offer practical guidance for IT audits of strong customer authentication (SCA) and common and secure communication (CSC) under PSD2.

Man reviewing a document while sitting behind a laptop.

The Payments Knowledge Group of NOREA (the professional association of IT auditors in the Netherlands (in Dutch) ), the Dutch Payments Association and the Dutch Banking Association (NVB (in Dutch) ) have published guidance on an audit approach (in Dutch) for SCA (Strong Customer Authentication) and CSC (Common & Secure Communication) under PSD2 (Revised Payment Services Directive).

This guidance is an initial minimum viable product: practical advice developed in the summer of 2019 following consultation with IT auditors and stakeholders. It helps auditors follow a widely agreed, harmonised and workable audit approach that is aligned with legal requirements. The recommendations in the guidance are endorsed by the financial institutions consulted and can also be used by other organisations that must comply with PSD2. It supports a flexible approach that reuses previous audit work and can be adapted easily if the requirements change.

Read the full guidance from NOREA, the Dutch Payments Association and the Dutch Banking Association (in Dutch)…

Related articles