PSD2
Revised Payment Services Directive. EU regulation requiring Strong Customer Authentication for electronic payments and enabling open banking. SCA mandates two-factor authentication with specific dynamic linking requirements.
PSD2 is the reason European checkout flows look the way they do, and dynamic linking is the requirement most often implemented poorly: the authentication has to be bound to the specific amount and payee, shown to the user, so an approval cannot be replayed against a different transaction. That constraint is why generic push approvals do not satisfy it.
See also: SCA, FAPI, step-up auth, identity regulations
Related on Start with Identity
- GlossaryPCI DSS
Payment Card Industry Data Security Standard. Required of any organization that stores, processes, or transmits cardholder data. The current major version (4.0)
- GlossaryAML
Anti-Money Laundering. The set of regulations and processes used to detect and report suspicious financial activity. AML programs sit on top of KYC and include
- GuideCustomer Identity Verification Guide: KYC, Document Verification, and Fraud Prevention
Implement customer identity verification with KYC processes, document verification, liveness detection, progressive profiling, and fraud prevention strategies.
- GlossaryFedRAMP
Federal Risk and Authorization Management Program. The US government cloud services authorization framework. Levels: Low, Moderate, High. Required for SaaS used
- GuideGDPR for identity systems: what the regulation actually requires
GDPR confers user rights (access, rectification, erasure, portability, object). Identity systems are usually where those requests are routed because they hold t
- GuideIAM Audit Preparation Guide: SOX, SOC 2, and HIPAA Readiness
Prepare for identity and access management audits with complete evidence collection, access review documentation, and compliance frameworks for SOX, SOC 2, and