What is SCA and how can open banking help?

null
Jack Wilson, VP Policy & Research
18 Jun 2021
Abstract brand shapes with SCA in the centre

Strong Customer Authentication (SCA), one of the requirements under the Revised Payment Service Directive (PSD2), has been gradually coming into force across different payment types since 2018. The last payment type to be affected is cards. It means any person making card payments online will need to confirm their identity by providing two separate identification factors – a big change from just entering long card details. 

While European merchants have been struggling with SCA requirements for cards since 31 December last year, issuing banks in the UK have lobbied for delays, and the Financial Conduct Authority (FCA) has moved the UK enforcement date to 14 March 2022.

One of the most significant concerns for businesses and card issuers is that SCA will negatively impact conversion rates. Some studies suggest it could reduce conversion for online card payments by 30%, and businesses could stand to lose billions in online sales.

The implementation of SCA for cards remains new and unproven. Most examples today show it adds significant friction to the online checkout experience.

In contrast, open banking payment providers have been required to include SCA since 2018. UK and EU banks have been warned by regulators to ensure SCA journeys for open banking are as frictionless as possible.

This headstart, and steers from regulators, means SCA works well in open banking payments. So, there’s huge potential for it to help merchants mitigate the impact of SCA on card payment conversion.

In this blog, we'll cover what SCA looks like in practice, the impact it’s having on merchants and how open banking can help.


Navigating SCA: how can open banking help? Watch on demand this digital masterclass and listen to the panel discussion with Merchant Payment Ecosystem.


What is SCA and why is it needed?

Essentially, it means consumers need to take extra steps to pay online in order to prove that they are who they say they are (and not a fraudster using the payment instrument without authorisation).

Strong customer authentication is not new. You’ll be familiar with it if you’ve used your card in a shop and had to enter your pin. This is using two factors for identification:

  1. the physical payment card in your hand (which identifies you as the cardholder)

  2. the knowledge that only you have of your PIN number

In 2015, EU rules were created to extend this to payments made online, including card payments (previously customers could pay online using only the numbers printed on their bank card).

These rules created a new set of authentication factors for online and point of sale payments:

  • Knowledge: Something they “know,” like a password or PIN

  • Possession: Something they “own,” like a phone or payment card

  • Inherence: Something they “are,” referring to biometrics like fingerprint or facial recognition

The ultimate goal of SCA is to reduce fraud and to make online payments more secure. This is long overdue. There were over 2 million cases of card fraud in the UK in 2020, valued at ÂŁ574m (according to UK Finance). Resolving these unauthorised payments is a huge worry for consumers and a burden on merchants.

null

What does SCA look like in practice?

Card issuers in the EU and UK are now being required to align with other payment types (including open banking) by introducing multi-factor authentication.

This has meant the rollout of new technology (such as 3D Secure 2 – “3DS2”) by card issuers and schemes.

But the implementation of SCA for online card payments remains inconsistent and unproven. Most examples today, show that it adds significant friction to the online commerce experience.

We’ve analysed a number of SCA payment flows (like this one from NatWest) – and found that payers typically have to go through 10+ steps to complete a purchase.

null

What’s the impact for merchants?

One of the most significant concerns for merchants is that SCA will impact conversion and abandonment rates. And since card payments still dominate ecommerce checkouts, European businesses could stand to lose €108 billion in one year.

The concern has been so great that The EuroCommerce and Ecommerce Europe associations wrote to the European Banking Authority in April this year to outline the problems that European retailers are facing with increasing failure rates, as well as new-SCA related fees from card providers.

According to these bodies there are structural problems with SCA compliance for cards including:

  • Consumer 3DS enrolment with issuers

  • Issues with the availability, usability, or mis-interpretation of the available exemptions – notably those based on transaction risks analysis

  • Access control server providers (which facilitate 3DS messages and authentication) are failing to address issues

  • Timing and latency issues between the issuer’s 3DS page and the final payment confirmation page

How can open banking payments help?

By adding open banking payments to the checkout, merchants can boost overall conversion rates and reduce abandonment caused by poor SCA flows.

Open banking payments have been designed to comply with PSD2 and SCA from day 1 (since 2018). They’re inherently secure and the user flows have been refined over the last two years to make it easy for customers to pay this way.

  • In the UK, the largest banks were required to follow guidelines which has led to much more consistent payment journeys

  • As a result, open banking payments typically involve 5-7 steps (compared to 10+ for SCA card journeys)

  • Merchants offering open banking payments through TrueLayer find it achieves 30% share of checkout on average within a few months. They also report that customers who pay this way mostly don’t go back to paying by card.

Consumer protections for open banking

Open banking payments are safe by design, but no online purchase is 100% risk-free. In the event that something goes wrong, consumers have legal protections – as with other types of electronic payment. For more information, read our guide to consumer protections with open banking.


Navigating SCA: how can open banking help? Watch ondemand this digital masterclass and listen to the panel discussion with Merchant Payment Ecosystem.

Latest
Pay by bank phone
12 Jun 2025

Pay by Bank protections: a modern approach

15 million users milestone
10 Jun 2025

TrueLayer hits new industry milestone, surpassing 15 million consumers

Hey, I'm Andy from TrueLayer, and I'm going to try and tell you everything you need to know about Pay by Bank—in just ninety seconds.  Let’s start the clock.  Let’s keep it simple. What is Pay by Bank? It’s a payment method that lets you pay directly from your bank account via your banking app—with zero need for card networks.  That could mean buying pizza, paying for flights, or just about anything in between. And it’s actually pretty easy—and very quick.  It looks a bit like this: start by tapping the Pay by Bank button, then choose your bank from the list.  If you’ve used it before, we can even preselect your preferred bank. You then review the payment, and you’re seamlessly redirected to your bank app to approve it using secure biometrics.  That’s Face ID or a fingerprint, to you and me. And that’s it—success. But no time to relax—we're on the clock!  Now, this might be the first time you’re hearing about it, but every month in the UK, 27 million payments are made using Pay by Bank. And most people who haven’t tried it yet say they’d be happy to—if given the option. On the merchant side, nine out of ten businesses are already planning to adopt it in one way or another.  So what’s in it for businesses?  Number one: more potential sales. No cards means no long card numbers, no clunky 3DS2—just a smoother experience from start to finish. And it converts.  Number two: because payment details are pre-populated and verified with biometrics, things like card-not-present fraud, chargebacks, and authorized push payment fraud are virtually eliminated.  Number three: lower costs. Without all the intermediaries and manual admin, the total cost of Pay by Bank is typically lower than card payments.  I'm running out of time—one last benefit: instant refunds. And trust me, shoppers love instant refunds.  And breathe. That was a lot to cram into ninety seconds.  If you’d like to take your time and learn more about Pay by Bank—and why brands like Just Eat Takeaway, lastminute.com, Ryanair, and Papa John’s already offer it at checkout—you can read our in-depth guide. There should be a link on screen now.  And that’s it. Thanks for watching.
9 Jun 2025

Pay by Bank explained in 90 seconds

Categories to explore