The launch implementation of PSD2 has seen its fair share of bumps along the way. Although many merchants and PSPs found this journey to be quite confusing, there are techniques and innovations that are picking up traction, like passwordless technology.

Discover how cutting edge technology can provide a seamless and secure experience for both merchants and customers, removing the complications many of us now face on a daily basis after the introduction of PSD2.

In this webinar, you’ll learn:

  • The current landscape of payments in Europe
  • The challenges posed since PSD2 directive came into force
  • How passwordless technology can help merchants and PSPs to overcome these challenges

Watch the On-Demand Webinar

Close

Thanks for submitting!

close

Video Transcript

0:14
Hi everyone. Good afternoon or good morning if you’re joining us from the
0:18
Americas. Welcome to today’s webinar. Uh we’ve got a very hot topic to do with
0:24
PSD2 and pain. So, uh, I can see that there’s, uh, a lot of excitement
0:29
building about it. So, let’s just give it a few minutes and then we’ll get
0:33
cracking with the, uh, the topic. Welcome to the webinar, everyone. We’re
0:53
just going to give it a couple more minutes to let everyone join who’s uh
0:58
trying to get online right now. Uh number of participants is going up
1:02
quickly, so that’s a good sign. Good afternoon everyone. Good morning if
1:31
you’re joining from the US or elsewhere in the Americas. Welcome to the webinar.
1:36
Uh we’re just going to wait another minute or so to let everyone get online.
1:41
So uh please bear with us and we’ll be starting shortly.
2:01
Okay. Well, let’s get started. Um, it’s a great pleasure to have you all today
2:07
on the webinar. Uh, topic is a very um, exciting one, let’s say. how
2:14
passwordless technology can help you overcome PSD2 pain. Not that there’s any
2:19
pain attached with PSD2, but anyway, my name is Alan M. I’m managing director of
2:24
Western Europe for New Payment Technology. We’re a leading supplier of
2:28
payment devices from Empi management systems. as we’ve all seen
2:37
cashless payments uh on the increase which is great news as part of the the
2:41
broader retail recovery and certainly most of the acquirers PSPs and processes
2:47
that we speak to are looking to deploy very comprehensive or versatile
2:52
solutions uh that help merchants drive sales in store as well as online. So the
2:58
whole payment experience is very much in demand. Now today’s session is organized
3:03
by merchant payments ecosystem the forum that’s been bringing us together over
3:08
these past couple years of of corona virus and in fact for a decade or so
3:13
before then as well. Uh we have a big event coming up in Berlin this July from
3:18
the 5th to the 7th. So if you’re not on your summer holidays uh or planning to
3:23
take holidays then please sign up and join us.
3:27
We’ve got around 200 people in fact slightly over registered for today’s
3:31
session. Um and a number of questions which we’ll get to after the
3:36
presentation. Now just to introduce the topic and I’m
3:40
I’m sure in some ways it doesn’t need introduction but anyway if if if you
3:44
think back um to before Corona virus before the pandemic started uh in the
3:50
heady days of autumn 2019 there was a lot of noise about PSD2 introduction and
3:56
the famous SCA compliance cutoff uh which I think was initially set for
4:02
September the 14th. It was one of those cliff edge moments uh where half the
4:08
world certainly in payments expected e-commerce to come to a grinding halt.
4:13
Now there were a number of delays and I think the the last of those in terms of
4:17
implementation which has been in the UK uh was finally um come into effect or
4:23
finally the the implementation came into effect last month. So even the US now in
4:28
the even the UA the UK now sorry has implemented SCA and apparently there
4:34
hasn’t been a huge drop off in traffic but we can hear more about that later I
4:39
think just to come back to the PSD2 um or revised payment services directive
4:46
um the focus was very much on security securing digital payments expanding the
4:51
financial ecosystem uh bringing in strong customer authentication for all
4:56
payer initiated transactions requiring official licensing of payment providers
5:02
as well as opening up bank data to new fintech players. Now clearly the
5:06
introduction of SEA was designed to reduce fraud um and online payment fraud
5:11
had actually reached almost 80% of total card payment fraud uh back in 2018 uh
5:18
with an increase per year of approximately 18% according to the ECB.
5:24
So clearly something did need to be done about it. Now since the original SCA
5:29
implementation deadline, e-commerce has had a big boost from COVID. Um and
5:35
figures I’ve seen from last year were approximately 20% of global sales um in
5:41
retail. Um last year were done through e-commerce with a total value of $4.9
5:49
trillion. As we know, fraud is also on the
5:52
increase. we have more knowledgeable, more active fraudsters uh as well as a
5:57
general increase in e-commerce traffic. So according to a recent report from
6:01
MRC, payment fraud losses accounted for over 3% of total e-commerce revenue last
6:07
year. So definitely attacking or addressing fraud uh does require
6:13
sophisticated measures to be put in place as well as complying with mandates
6:18
like SCA. Some would say that the use of passwords and clunky authentication
6:23
processes has become part of the new normal post PSD2 with a heavy impact on
6:29
user experience. So the key question is how can technology help us provide a
6:34
seamless and secure experience for both merchants and consumers whilst removing
6:39
some of this unwanted friction. Today’s session is sponsored by Syft, a
6:45
company that’s focused on securing business at scale with solutions that
6:49
proactively stop account takeover, payment fraud, and prevent scam content
6:53
from destroying brand integrity. Their digital trust and safety suite claims to
6:58
be every fraudster’s nightmare. Now, it’s a great pleasure to welcome back
7:03
Kevin Lee, uh, a veteran of these webinars and and VP of trust and safety
7:08
at SIFT. Kevin focuses on helping customers implement strategies to align
7:13
risk and revenue programs in a crossf functional way. Uh before joining Syft,
7:19
he spent over 14 years leading risk charge back chargeback, spam, scam,
7:24
trust, and safety organizations at organizations like Facebook, Square, and
7:29
Google. I’d also like to welcome Corey Hinton who’s product marketing manager
7:34
at Sift and specializes in risk trust and safety operations providing insights
7:39
for managing Ford. Before joining SIFT, he held a number of marketing and
7:44
technical positions at Honeywell focusing on problem solving using sensor
7:48
and IoT technology. So at this point I’m going to hand over to Kevin to get us
7:54
started with a presentation. Kevin. Kevin,
8:11
did Kevin drop off? Corey, you’re still there.
8:16
>> Yes, I’m still here.
8:17
>> We seem to have lost Kevin. Uh, would you like to start with the intro to
8:22
Swift?
8:24
>> Sure, no problem at all. We’ll give Kevin a second to join, but
8:28
if if you can start at least with the presentation, I think that would help.
8:32
>> Sure, no problem. So, um, Syft is a, um, global provider of, uh, fraud prevention
8:41
solutions. Uh, we’re a trust and safety company that helps businesses protect,
8:46
um, every step of the user journey. Um, we help businesses protect themselves
8:52
from and their users from various forms of abuse and help them grow. Everyday
8:57
fraudsters oftentimes collaborate when it comes to taking advantage of
9:01
collective systems and communities. And SIFT was created to help level the
9:05
playing field uh so that illegitimate actors aren’t the only ones that should
9:11
be able to collaborate, share tools and best practices.
9:16
So with that, if you go to the next slide,
9:22
we have our agenda here. Um, what we’ll talk about today is a history of PSD2,
9:32
uh, strategies for today and then what’s next. And I see Kevin’s joined, so I’ll
9:36
hand over the
9:37
>> Looks like Kevin is back. Welcome back, Kevin. You see,
9:40
>> apologies for the technical delay there. I uh I could not find my unmute button
9:45
for some reason. Corey, thank you for taking the intro there. Um, thank you
9:48
everybody. Great to uh see everybody in the uh the uh the webinar today. Um I
9:54
think Corey mentioned gave a brief background on SIFT. I could definitely
9:57
hear all that information. So, thank you for that. Um and then really today want
10:01
to focus on I think people know what PSC2 is now. So, we’ll spend a brief
10:05
time on like a history here. uh and then really talk about strategies for what
10:09
companies are doing today with regards to PSD2 and then really the bulk of the
10:13
time on uh what’s next in terms of the new area
10:20
and let’s see all right so let’s chat about just a
10:27
brief overview of kind of what we’re dealing with here so as Allan mentioned
10:30
at the beginning of the webinar PSD2 kind of launched uh in September of 2019
10:36
19 and the mission or the the the goal uh was to create a more open and secure
10:41
online payment ecosystem um and encourage innovation and I know today’s
10:45
webinar we’re going to talk a lot about from the merchant perspective um and I
10:50
think we’ll some of the maybe pain points there um however I think in
10:54
general PSC2 one of the I’d say bright lights here has come from more open
10:59
banking applications and I think from a consumer standpoint we all stand to gain
11:03
uh quite heavily in that regard uh when it comes to being able to um kind of
11:08
connect our finances a little bit more easily. Um and it essentially creates a
11:12
lot more convenience for us. Um we’ll certainly talk about the online impacts
11:17
um across the uh European economic area and then we we mentioned about SCA a
11:23
little bit. Um and we’ve certainly had our I’d say hiccups along the way with
11:27
with COVID but also just I’d say general preparedness or readiness. Um there have
11:32
been a series of delays. Uh and now finally as of I think March 14th I think
11:37
the UK was kind of like the last big puzzle piece uh to roll in here.
11:43
So um in terms of SCA um certainly there are incope transactions and out of scope
11:50
transactions. The ones that are out of scope here um tend to be the one leg out
11:55
transaction. So for example, if the issuer and the acquirer are in the same
11:59
uh region um very likely um can qualify for SCA. I say qualify uh somewhat
12:06
begrudgingly but they can they maybe must go through SCA. Then of course
12:10
there’s mail order and telephone order transactions that can uh be uh exempt.
12:16
And then I’d say merchant initiated. So in this case think subscription billing.
12:20
So if you are billing the same amount every month um to a particular consumer
12:26
um you would not necessarily be subject to any um SCA requirements.
12:32
Um and then there are some uh exemptions here. So um I think folks are familiar
12:37
with the sub30uro transactions. There’s kind of some fine print in terms of uh
12:42
how many 30 transactions or um less you can qualify here. corporate payments.
12:48
We’ll spend a little bit less time on here just because um this is was
12:52
primarily designed for the travel industry and this really depends on the
12:55
issuer because they’re the ones that know if they’re corporate cards or not.
12:58
Um in terms of working through those, we’ll probably spend the both the bulk
13:02
of the time here on what we call lowrisk transactions. So, um, if you have what
13:07
we call transaction risk analysis in place, um, and you’re able to identify
13:11
these lowest transactions, um, you can work with your PSP or your acquire to
13:16
really bump up the exemption rate here. Um, in the US, it is tax season and, um,
13:24
I’m reminded of the term tax avoidance versus tax evasion. So, in the US, tax
13:30
evasion or global anyways, tax evasion is illegal. Like, you don’t want to do
13:33
that. However, tax avoidance is completely illegal and essentially
13:38
working through the system to make sure that you’re able to uh exempt yourself
13:43
from paying uh tax that you don’t need to pay. And here where I see some
13:48
correlation is when we talk about lowrisk transactions, there are many
13:52
lowrisisk transactions that can qualify for these exemptions. We just need to
13:56
know how and when to uh apply for them or or kick them off. And the last
14:01
section here is around trusted beneficiaries. This is more so on the
14:05
consumer side where if they work with a trusted merchant, they can golden list
14:11
them or shield them um from going through this process. But that’s very
14:14
much so in the consumer’s hands. And so there might be some enablement or some
14:18
education that merchants can do there. But that’s primarily I’d say less in the
14:23
merchants control. But we’ll spend most of the time here talking about the
14:27
lowrisk transactions and how to essentially qualify for the most.
14:31
Um, so with regards to uh PSPs, uh, merchants can request exemptions um, if
14:38
they attain low fraud rates. And I’d say of course, I mean, being in this
14:42
business for a long time, of course, everybody wants to reduce fraud.
14:45
However, now we have some specific targets to hit. And yes, we will reduce
14:51
fraud. However, the upshot here or the the plus side on the growth end is that
14:56
if let’s say I as a business can expand to €100 or €250 or even 500 euros based
15:03
on my fraud rates, then that allows a more seamless experience for more
15:07
transactions to get that exemption. And so really that’s the name of the game
15:10
here when we’re talking about hey how do we apply and qualify for as many
15:16
exemptions as possible given low risk of course and we’ll talk about kind of the
15:22
a lot of the pains here that merchants we’ve heard from merchants uh that they
15:25
face um just because not everybody knows how to get the most exentures or really
15:32
I’d say from a merchant perspective how much leverage you may have with your
15:35
PSPs or with your acquirers in this uh specific specific regard.
15:41
So with that said, we have our kind of precoid or pre uh kind of PSD times. You
15:47
might look at this as your typical order flow where the order is placed. There’s
15:51
some O, there’s a capture and and off you go. PSD2 introduced an
15:55
authentication measure here where in that space there were essentially three
16:00
items that could qualify for uh this sea or you need two out of these three where
16:05
one you have passwords something you know something you have for for example
16:10
a device and then something you are in terms of a biometric and so really I’d
16:14
say the vast majority of SCA in practicality when it’s done today is
16:20
factoring in password plus device Um, it can be a little bit clunky at times. I
16:25
know we’re in I think uh 2.2 at this point in terms of PSD2. Um, but in terms
16:31
of usage, I’d say majority of users are going through the password plus um the
16:37
device like kind of flipping over to the app and then flipping back.
16:42
So, with that said, I’ll pass it back to Corey to chat a little bit about more
16:46
about kind of as we as we’ve done research for this particular talk, what
16:50
we’ve heard from various merchants. Corey,
16:52
>> thanks Kevin. So if you can step ahead.
16:57
So um ready or not uh as this slide says and as Kevin mentioned previously the
17:04
final kind of hold out in so far as sea enforcement uh was you know set into
17:11
place on March 14th in the UK and this really set the stage for uh what
17:16
merchants would need to expect when it comes to say full implication or the
17:22
full implications of PSD2 in I’ll say the European economic area plus uh so uh
17:29
if you can click ahead once uh you can see that just before that March 14th
17:34
deadline uh earlier in 2021 there was some imple implementation of say testing
17:40
of PST2 and SCA specifically and if you read through the screenshots here um we
17:46
won’t bel them uh but it wasn’t exactly an easy process uh you can see that uh
17:52
this Twitter um poster you know listed her interaction actions via her mobile
17:58
phone where she had to say authenticate through her mobile device uh via her uh
18:04
banking app and uh biometrics were introduced and um she can she says at
18:10
the end that it wasn’t exactly an easy process. Uh so you can see that it’s
18:14
it’s not exactly uh what everyone hoped it would be when the when the uh
18:20
regulation was introduced back in 2018 uh and set to be enforced in in 2019.
18:25
And if you can click ahead. So here are some of the things that
18:30
we’ve been hearing from merchants and and the in the wild. Um things like you
18:36
know challenge rates of 65 and 70% across Europe and and for a basis line
18:42
uh most merchants like to see challenge rates of around 20% or at least uh pre
18:48
PSD2 that was the case. Um here in the middle you can see in the world of SCA
18:53
uh merchants have found that customers are more likely to abandon their baskets
18:57
if they have a checkout process that has friction in it. Um they’re focused on
19:02
optimizing what transactions they can request exemptions for. Um, and when it
19:08
comes to say omni channel retailers or or traditional retailers that have some
19:12
online presence that traditionally didn’t see uh large fraud implications
19:18
because of card present transactions, uh they can see that for the card not
19:22
present transactions, they’re forced to put their most loyal customers uh with
19:27
their biggest baskets through an uncomfortable process when it comes to
19:30
the friction that’s added because of SCA. and um they’re they’re seeing
19:35
things as you know it’s not reducing fraud substantially but it is heavily
19:39
impacting conversion rates. Uh so these are some of the the quotes that we were
19:43
seeing uh from merchants when it comes to the implementation of sea throughout
19:49
Europe and it it paints a fairly you know uh challenge laden picture
19:55
>> and just a few things to kind of add there. One of the things that popped out
19:58
is around certainly the challenge rate and Corey’s going to cover that a little
20:02
little bit more, but one thing that particularly I heard in terms of
20:07
frustration was with the challenge rate so so high. I think in general we
20:12
recognize that fraud is out there and the spirit of the the the regulation
20:17
coming out is to reduce that that fraud and I think by and large it has but for
20:22
example when it comes to a lot of retailers let’s say they have
20:27
brickandmortar and and online sales as well their chargeback rates or their
20:32
fraud rates were pretty low I’m talking like singledigit basis points here and
20:37
so they with SCA rolling out they have seen a a drop in that um that fraud
20:42
rate. But let’s say this business goes from seven or eight basis points of
20:46
fraud to uh six or seven basis points of fraud. So yes, it is going down. Um
20:51
however, on the flip side, when we talk about conversion rates, uh some of these
20:56
businesses are seeing 3 to 4% decline. So let’s say three or 400 basis points
21:01
in terms of conversion rate there. And so I think what we found as to be a
21:05
challenge for many merchants was yes we see lower fraud but fraud really at
21:10
least for us because we had fraud systems in place and things like that
21:13
fraud rates weren’t too significant in terms of the the overall business. What
21:18
is a lot more painful and what is a lot more noticeable for the business is
21:22
around that conversion rate. Um and a lot of it is due to these high challenge
21:26
rates. Now we also have seen and heard that consumers are trying. So, it’s not
21:31
like they’re necessarily doing a one and done. Like, we see the activity where
21:34
they’re trying three or four uh or more times to get through. Um, but in our
21:40
perspective, we see that as essentially a customer insult where why are we
21:44
asking 65 or 70% of our consumers to to go through this process when we know
21:50
that let’s say sub 1% of the population is actively trying to do something bad.
21:58
So let’s talk a little bit more about uh acceptance rates. So Corey, back to you.
22:02
>> Thanks Kevin. Uh so one of the best ways to see how the implications of the
22:09
regulation um as it rolled out over you know
22:12
several countries in Europe played out is to take a look at the challenge rates
22:16
over time. So, so we’re going to, you know, zoom out and take a look at uh
22:20
several countries in the European economic area. And um you can see uh
22:25
from the early days of imp implementation of PST2, challenge rates
22:30
remained uh fairly low. But as you continued on, the common trend amongst
22:35
all these countries is the fact that the challenge rate was increasing and
22:38
sometimes uh significantly increasing. Um this this was a result of you know a
22:44
lot of confusion between say acquirer and issuer uh when it comes to what
22:50
exemptions mean, how you uh file those exemptions, whether or not the issuer
22:54
should accept it. And um the the overall story turned into, you know, issuers
23:00
were uh uh challenging um transactions more often than not. And uh of course
23:07
it’s not a onetoone correlation between um uh conversion rate but as the
23:14
challenge rate continue to increase uh conversion uh decrease uh significantly.
23:20
And then one thing we also noticed, it wasn’t mentioned on the previous side,
23:23
but was around consumer confusion where oftentimes, let’s say an order was
23:29
declined, they would contact the merchants and then uh the merchant might
23:33
say, “Well, you have to contact the your your your card uh your your uh issuing
23:37
bank here.” And then customer service, not everybody was enabled that same
23:41
rate, let’s say. And so that also caused some more kind of turn and and thrash
23:46
when uh card holders would then call the their issuers and ask kind of what’s
23:50
going on and then the issuer might say, “Oh, I think it’s something with the
23:53
merchant. We’re not seeing anything here.” And so that also caused a bit of
23:56
frustration from a a consumer perspective.
24:00
>> Exactly. So in uh zooming out to the ecosystem overall, what does PST2 mean
24:07
for the ecosystem? Uh so the intent we’ll say in this this first bullet
24:11
point at the top left is better security for consumers. Um users online payments
24:16
are of course more secure with the implementation of SCA. But as Kevin
24:21
mentioned uh that also led to a bit of confusion when it comes to you know the
24:26
the uh where to go and and how to work through the system when it comes to uh
24:31
when I’m challenged what do I do? Um in the case of uh merchants, it can lead to
24:37
abandoned transactions and c due to customer friction. So the things like
24:42
two-factor authentication and multiple steps in the payment journey being added
24:46
as Kevin mentioned previously, those can cause friction and confusion for
24:50
consumers and it can often result in higher instances of abandoned
24:54
transactions and failed payments. um for for fraudsters if we were to you know
24:59
think of the fraud economy’s impact on the payment ecosystem there are new tax
25:03
avenues uh so the siloed steps of the authentication process and um the
25:08
expanded number of uh you know scope of transactions and exemptions things of
25:14
that nature uh essentially expands the number of attack vectors that cyber
25:19
criminals are able to exploit and as users are becoming accustomed to things
25:23
like uh you know being promp prompted for credentials for these new scenarios
25:28
of SCA the opportunity for fishing attacks and things like that broadens as
25:32
well. Uh there are compliance risks. So if you think of the um the issuers uh
25:40
banks around Europe are going to face challenges and and have been facing
25:44
challenges implementing PSD2 and um its associated regulatory technical
25:48
standards while also trying to conform to GDPR requirements. So these financial
25:54
organizations need to ensure that whatever solutions they use for PSD2
25:59
need to comply with with both of these strict regulatory requirements
26:03
and then um for developers at you know PSPs merchants acquirers alike uh it can
26:09
lead to complex integrations um sea being a new authentication capability
26:15
and trying to add that into the identity stack that’s that’s already existing can
26:19
be a frustrating and timeconuming process that differs widely from
26:23
business to business. So, um that can be a really huge frustration and concern
26:29
there. And then of course increased costs uh with two-factor authentication.
26:34
Uh but depending on the method that you use, it can be expensive. And what I
26:38
mean by that, you know, password resets can be costly as well as sending SMS’s
26:43
for saying one-time password every time a customer process a processes a payment
26:48
is also very very costly. you can move ahead. And uh when it comes
26:54
to merchants specifically, you know, there’s there’s two main goals. I I even
26:58
heard a quote from one merchant said that at the end of the day, you know, we
27:02
we want to make sales and um I’m sure the the rest of the payment ecosystem
27:06
would agree, but when it comes to PSD2, uh the goal to minimize risk, so using
27:12
that real-time risk analysis to stop fraud proactively and keep those fraud
27:16
rates low. uh but also while doing that maximizing conversion and that involves
27:20
balancing exemptions in SCA to keep the friction low for consumers.
27:28
All right. So in terms of strategies like what are merchants doing today now
27:33
that PSC2 is is out and about and uh kind of consumers are going through that
27:38
flow really the most common theme we found was u around this concept of
27:44
dynamic friction and um maybe I’m aging myself a bit where if you do recognize
27:48
what these books are um these are the choose your own adventures uh books and
27:52
if you’re not familiar with them essentially it’s where you as the reader
27:57
here doesn’t h like not all readers have the same ending or the same choices uh
28:02
when it comes to um how the book and the story progresses. And so in the uh the
28:08
way that these series work is that you as a reader as the book goes along you
28:12
can make choices whether to let’s say fight the boss or or leave or stay in a
28:17
town or not or talk to a person or not. Um and so how does this apply to the
28:23
payment space? Well, when it comes to adaptive friction or dynamic friction,
28:27
we’ve seen this play out where now that and again the name of the game here and
28:34
I’m trying to get trying to gify this scenario where merchants essentially are
28:38
trying to create as many exemptions as possible. And now in this particular
28:44
case like let’s say you have a particular order that is in that must go
28:49
through SCA let’s say so it’s not under €30 or it’s not kind of a onelegout
28:54
transaction scenario but we do have that lowrisk transaction um uh scenario or
29:00
transaction to potentially qualify for. And so this is where it’s really
29:04
important for merchants to have proper fraud screening in place or they talk to
29:08
their PSPs to make sure I not even to make sure and this is where the
29:13
conversation shifts a bit where if you as a merchant have a very low fraud rate
29:18
you should be having some pretty real discussions I’ll I’ll call it with
29:22
regards to how does the exemption process work with a particular PSP how
29:27
is my business being affected by it and what can we do to maximize our
29:32
exemption. status when it comes to particular transactions flowing through
29:36
the system. One key component to that is that uh transaction risk analysis and
29:41
what systems um do you have in place to create better experiences for consumers.
29:46
And so for example uh listening to one merchant they essentially uh been able
29:52
to change the um payment flow where if uh there let’s say the user is coming
29:58
from an iPhone they can prompt Apple Pay as one of the main payment types um to
30:03
hopefully qualify for an easier uh SCA process and then move through that route
30:09
as opposed to let’s say just entering in your your credit card number.
30:14
So when it comes to transaction risk analysis like ideally you have a
30:18
particular flow where let’s say you know the user maybe they’re not subscription
30:22
based but you’ve seen them come back to your your business before or based on
30:26
the activity that a user has or behavior that user has done on a particular
30:31
system you know that they’re relatively low risk and that’s really where um even
30:36
if it’s above €30 or €100 you really want to apply for that exemption and
30:41
then if you have the proper tools in place from a risk betting scenario then
30:44
you can be confident that the probability that this is going to turn
30:48
out fraudulent will be very very low. And so this is kind of the ideal flow
30:53
and the areas that you can start collecting information from your users.
30:56
And that’s for your best users. And of course when it comes to u stopping
31:01
fraud, um one of the tactics that we’ve seen uh in from merchants is moving the
31:08
actions closer and closer to let’s say account creation. So in this particular
31:13
flow time starts let’s say when the order is placed you have your
31:16
authentication piece authorization and capture that’s I’d say old school or
31:22
this is how like uh some companies play it out where it’s the least efficient um
31:28
but we see more savvy merchants out there begin to look at okay we are
31:33
already collecting so much data on our particular um consumers why don’t we
31:38
start taking action a little bit sooner in the chain here so not necessarily ly
31:42
at the authorization where there are costs and things associated with that.
31:46
Can we do it at create order or let’s say when the item is added to the cart
31:50
or if you really understand that this we’re dealing with a fraudulent user
31:53
because we’ve seen this particular device or behavior before even at the
31:57
account creation stage um merchants can start taking action sooner up the
32:02
funnel. So with regards to where we go from now
32:06
I’ll uh pass it back to G.
32:08
>> Yes. Let’s take a look at where we go from here. So uh looking at the history
32:14
of authentication it’s evolved to include various methods that you know
32:17
could potentially fulfill SCA some of which we’ve mentioned prior to this like
32:22
passwords uh pens hard tokens and soft tokens and these provide a moderate and
32:29
varying moderate level of security and varying degrees of usability. So when
32:32
you think of uh say a password that that’s something that you know provides
32:37
a level of security but you can also forget your password and need to reset
32:41
it or uh for a hard token or soft token. Hard tokens can be lost and uh soft
32:47
tokens uh I I always have the issue of remembering which soft token I need for
32:52
which application. So it can be a little confusing. Um, so,
32:57
uh, however, I’ll say, uh, biometrics provide an opportunity, if you’ll click
33:03
ahead, Kevin, biometrics provide an opportunity,
33:07
uh, for payment providers to become leaders in providing frictionless
33:12
authentication experiences while doubling down on security and
33:15
compliance. And we’ll we’ll talk about what that looks like. So, if you’ll
33:18
click ahead. So, uh, how can, uh, biometrics help turn SEA into an
33:23
advantage? Well, in in lots of ways. It number one simplifies security in that
33:28
you know built-in 2FA helps to eliminate fraud uh fishing and credential reuse
33:34
and lot in a lot of use cases where customers are using uh sea to
33:38
authenticate. Um el eliminating customer friction. So the authentication fatigue
33:44
that can come with SEA if not properly taken care of can lead to card
33:49
abandonment and um you can avoid that by applying industryleading techniques uh
33:55
an enhanced user experience. So when the authentication process is carried out
34:00
over several devices uh you want to provide a seamless authentication
34:03
experience for any user on device from anywhere uh and dramatically reducing
34:08
costs. So some of those costs that we discussed before uh things like SMSs um
34:13
you know enrollment costs for multi-device use cases uh when passwords
34:17
are forgotten you can dramatically reduce those costs. So if you’ll jump to
34:22
the next slide so let’s talk about the biometrics that exist uh out in the wild
34:28
today. Um, everyone’s familiar with say Touch ID or Face ID and um, there are
34:36
several benefits to this. You know, it was a new technology that, you know, was
34:40
introduced by Apple. And if you recall from the um the the Twitter uh feed that
34:47
I showed where the user was, you know, being prompted for SCA, she actually
34:51
was, you know, offered Face ID, but there was a there was a note there that
34:56
we’ll talk about in just a second, uh that said, “Be careful. Anyone who is
35:00
registered to use the Face ID on this phone can authenticate for your your
35:04
transactions.” Um so there are drawbacks. Um and to take a look at the
35:10
drawbacks uh when it comes to you know um end user coverage um smartphones
35:18
worldwide uh may or may not have a fingerprint sensor. So Touch ID may not
35:24
be the the best use depending on what type of phone uh the end user has. Uh
35:29
when it comes to opting out um you know Apple users sometimes are reluctant to
35:34
enable Face ID for payments for security reasons. Uh when it comes to an
35:39
inconsistent experience for security um device native biometrics mean that you
35:46
know you have an inconsistent user experience and security measures for end
35:49
users. So for iOS for example, you might use Face ID, but Android users may have
35:55
a fingerprint that they use or an older iOS device might use Touch ID. So um
36:01
with each of these different methods, you have varying levels of security. And
36:06
then when it comes to you know multiple devices uh similarly with device made of
36:11
biometrics uh you have users having separate biometric templates across each
36:16
device and that means that they can’t necessarily recover their biometrics and
36:20
you know have to repeat the onboarding process when it comes to you know
36:24
setting up new devices and and that can be costly for a business. And um lastly
36:30
like I mentioned before low assurance. So if anyone can use or if anyone’s
36:35
registered to use Face ID to access your phone, um this this is a drawback for
36:40
device native biometrics because uh there’s no way for financial
36:43
institutions to guarantee that the biometric templates are in fact the the
36:47
registered user. Uh so the the person that’s actually authenticating for the
36:52
transaction may not be the person that you know went through the onboarding and
36:56
KYC process for that banking app. So if you’ll click ahead when it comes to
37:02
nonnative biometrics uh when we’re looking at you know the future of
37:07
biometrics there are a lot of pluses. So uh
37:11
software only biometrics tend to be an exciting alternative to you know what we
37:16
talked about with device native biometrics and that they’re independent
37:19
from hardware devices and operating systems. So that makes them an ideal um
37:25
usage for uh providing universal authentication experiences. And the fact
37:31
that you know technology can be progressed such that you know for GDPR
37:37
for instance no biometric data is stored or processed it it makes it a much
37:42
better passwordless uh uh use case. So if you’ll click ahead,
37:48
let’s talk about how uh this can play into uh PSD2 compliant SCA in one single
37:54
action. So you can see in the picture that the user can actually authenticate
37:59
via SCA by you know a single look into the the device they’re working with. And
38:04
um how this accomplishes SCA we we talked about you know you have to have
38:08
something that you know something that you uh are and something that you have.
38:13
uh for the something that you have the ownership um on any device a user you
38:19
can click ahead Kevin for ownership um on any device that a user may have uh
38:24
with an onboard camera they can you know authenticate with with just a look and
38:30
any any um device native uh information that can be drawn from those devices is
38:36
used you know to fulfill the ownership requirements of sea and then in the case
38:40
of inherent something that you are uh the actual face and biometric signature
38:45
of that user as well as uh uh behavioral biometrics, you know, like swiping or
38:51
the way that the the person interacts with the phone as well as maybe even a
38:55
touch sensitive biometric is also accomplishing that inherent portion of
39:00
SCA. So you get the two-factor authentication required for sea uh with
39:05
you know a simple look into the phone. if you’ll click ahead. So, uh how does
39:12
passwordless um benefit you know businesses when it
39:16
comes to to authentication? Uh number one, it’s accessible on any enduser
39:22
device. Um hardware and operating system uh don’t matter. meaning that you can
39:29
have any uh device and um any operating system for full user coverage and uh
39:36
your your end user can authenticate from any of those devices. It’s uh built-in
39:40
user identification meaning that uh you don’t have those assurance issues that
39:45
may come with Face ID with more person more than one person being enrolled. Uh
39:49
you can ensure that the customer who’s authenticating is who they say they are.
39:54
Uh you can enroll once and use everywhere. So, uh, self-service, uh,
39:59
multi-device capabilities are are, you know, one of the benefits of this type
40:04
of technology. Um, there’s no enrollment required. And when it comes to backup
40:08
and recovery, uh, you know, you don’t have to reset a password, but users can
40:13
recover their ident identity in case of a lost or stolen device because it’s not
40:18
stored, their biometric signature isn’t stored on that device. So if you click
40:22
ahead.
40:25
>> So with regards to uh where where should I be now or where should a merchant be
40:30
now? Uh number one is certainly continuing that conversation with your
40:34
PSPs. So I think merchants are in a pretty unique scenario right now where
40:39
let’s say I’m a large e-commerce merchant and I have a low fraud rate.
40:46
Certainly the low fraud rate is good for me in terms of like okay I have low
40:49
losses but from a I’d say negotiation standpoint or from a leverage standpoint
40:55
now where the essentially game has changed is if you have a low fraud rate
41:00
that can be used in discussions with your PSP or with your acquirer in terms
41:05
of like hey look I know that I have a low uh fraud rate um therefore I would
41:10
like or I want um to qualify for more exemptions. So in addition to that what
41:15
makes it let’s say beneficial for the acquirer the PSP here they are also they
41:21
also have a portfolio right and they look at their overall fraud rates and so
41:25
if you have a low um fraud rate or chargeback rate overall you become even
41:30
more attractive to them as a customer in this case um because of that low fraud
41:35
rate and that can be used when it comes to let’s say renewals or things like
41:39
that um and this is really where the conversation goes from the I just use a
41:45
PSP or I’m just using acquire to where you as a merchant have or potentially
41:50
have a lot more say here um in this in this conversation. And so hopefully
41:54
those conversations continue. Um of course we want to aim to maximize those
42:00
exemptions. And so uh I mentioned earlier the tax avoidance versus tax
42:04
evasion. We definitely want to avoid uh having to go through SDA if we can given
42:10
those high uh challenge rates and and like I said earlier, many of these
42:14
businesses already have low fraud chargeback rates. And so yes, they will
42:20
continue to to decrease, but that decrease isn’t necessarily worth the the
42:25
hit on a on the overall conversion rate. Um certainly we’ve got to continue to
42:30
protect ourselves from fraud and that’s where having a fraud system in place
42:34
that can in real time look and identify uh different fraud patterns hitting your
42:39
system is extremely important. Um and the last one we haven’t really talked a
42:44
lot about has a lot of seam in the last couple years is around alternative forms
42:49
of payment. So I mentioned Apple Pay earlier where some merchants are if they
42:53
identify the user or the customer is coming from an Apple device prompting
42:57
that form of payment sooner. Um but we didn’t even talk about things like buy
43:02
now pay later or other forms of payment that have become um quite popular uh in
43:08
kind of the last year or so. And so I know many merchants are certainly
43:12
investigating these but also um already have adopted these different forms of
43:15
payment um through their checkout flow. And this is yet another reason why to
43:21
potentially prompt users to go through one flow versus another if it means that
43:26
either one the exempt exemption can happen or two it can be essentially out
43:31
of scope uh does not need to go through that uh particular type of challenge.
43:39
>> So where should we be in the future? So you
43:44
should always be you know thinking about differentiating for the next stage. uh
43:48
PSC2 has had a slow roll out as we’ve talked about through this entire
43:52
discussion today. Uh rightfully so. You know, there were major concerns with the
43:56
pandemic as well as you know, major concerns around testing and practical uh
44:02
aspects of implementation and the extensions that were set into place uh
44:08
made sure that you know everyone was on a level playing field uh for
44:12
implementation. And as you could see from the quotes we’ve talked about
44:15
previously, uh there was there were still some challenges. Uh so looking
44:19
forward um using PSD2 and the tools available, the technology available uh
44:25
from vendors will help you differentiate uh for the next stage uh with things
44:30
like low friction and privacy preservation. So compliance can be
44:35
complex as I mentioned before uh adhering to PSD2 uh which you know 3DS2
44:41
is supposed to provide a lower friction method of strong customer authentication
44:46
uh but you know there are some challenges with it with you know
44:50
customers still being met with that friction and and abandoning carts uh but
44:54
also as you’re implementing PSD2 uh being concerned with privacy uh
44:59
especially if you ought to use biometrics
45:03
um GDPR can come into play. So having a solution that addresses both of those is
45:09
definitely something to look into as you move forward into the future. And then
45:14
uh at the end of the day, you definitely want to be looking into passwordless
45:17
authentication when it comes to reducing that uh friction at the SCA stage. Um
45:22
because you know the three requirements of SCA uh something you know, something
45:26
you have and something you are uh those are addressed. There’s nothing to
45:31
remember. there’s nothing to steal and you are the key. Uh so with that, we’d
45:36
like to take any questions from the audience
45:40
>> and there haven’t been any questions coming in amazingly enough because we
45:44
normally have loads of questions um on anything related to PSD2 and SCA. But
45:49
anyway, we’ll give everyone a time to get some questions out there. Um and
45:55
certainly Kevin Corey uh for me that that was very interesting session. I I
46:01
have to say on my own side I I was normally against biometrics until I
46:05
realized it made life a heck of a lot easier for my online banking espec
46:11
especially trying to put in passcodes in a mobile phone which was a real pain in
46:14
the neck. So uh certainly facial recognition and biometrics have helped
46:19
with all that. Um but but coming back to where we started which was this whole
46:24
thing of PSD2 SCA deadlines hype noise trouble you know it’s I I would say it’s
46:31
kind of been and gone and was it that painful for everyone I mean was there
46:36
was there really so much disruption have you seen a lot of disruption in in in
46:41
the market generally or with the customers that you speak to?
46:45
Yeah, that’s that’s a good question and I’m I’m happy to chime in and Kevin, you
46:49
can you can add if you’d like. Um, since the original rollout date back in 2019,
46:57
uh, coming to this point, uh, the the challenges when it comes to testing, the
47:02
challenges when it comes to practical implication and readiness all over the
47:06
payment ecosystem, um, that has led to a lot of, you know, concerns, I’ll say.
47:14
Um, there was a lot of hype around, you know, PSD2 making things easier with the
47:19
introduction of EMV 3DS as, you know, an option for strong customer
47:22
authentication. And at least from what I’ve been hearing out in the wild, uh,
47:28
throughout this, you know, two two and a half year period, it it there has been,
47:32
you know, quite a bit of disruption. I think if you look at it from the uh ESP,
47:38
the the payment service providers perspective, uh they tend to be more
47:42
optimistic in that, you know, things will calm down, the regulation will set
47:46
in, consumers will learn and uh things will get better. Uh from a merchant
47:51
perspective, and maybe we can throw the consumer in there as well, um they tend
47:55
to be a little less optimistic. Uh it it’s friction. Um, if I’m trying to book
48:01
travel for, you know, uh, visiting family or or going on vacation and I
48:06
have to authenticate and it’s clunky and I’m not quite sure who I reach out to
48:10
when I have problems, uh, that that can be a big issue. And then on the merchant
48:14
side, this person that had all these problems where, you know, I’m trying to
48:18
tell them to visit their issuer to help solve the problem, the issuer saying go
48:22
to the acquirer, the PSP or back to the merchant. It it can lead to abandoned
48:26
carts and that that’s a real frustration for merchants.
48:29
So, I mean, if if we just look at the EU and, you know, kind of global
48:35
implementation status, um, what what would you say? We pretty close to a full
48:40
implementation. Have we got everyone ready for things like uh 3D Secure 2.0
48:46
or, uh, or is that all still to come?
48:49
>> I I think it’s still to come. uh there is no definitive resource on you know
48:55
total readiness of all countries in the EU but the resources that I have been
48:59
you know perusing over the the past few days certainly and as well as you know
49:04
all the time that I’ve been studying PSD2
49:07
um there are varying levels of usage when it comes to uh 3DS so uh 3D if if
49:14
you choose 3DS as your option for SCA which which there are other options out
49:18
there just to just to point that out um 3DS S1 is say still very popular for
49:24
usage by issuers in Spain. Uh whereas in Norway uh 3DS2 is is much more popular.
49:31
So um we’re we’re getting there. I I don’t know that I could put a deadline
49:35
on, you know, when we see full implementation, but uh country by
49:40
country, I think, you know, there’s a lot of of thought and effort being put
49:44
behind uh readying for PSD2. For sure.
49:47
>> That’s a good point. And you know I like your example of Nordics versus Spain in
49:52
terms of 3D secure. But in in terms of PSD2 scope is is this handled
49:58
differently across the countries then? Is is this something which is you know
50:03
is it just people are doing things in different ways or or or does PST2 enable
50:08
this kind of variable scope um across the board?
50:14
I think if you look at the implementation of PSD2, there was a lot
50:19
of variability. You know, the global pandemic came in and and disrupted
50:23
everything uh globally. Um but varying levels of uh readiness were also the uh
50:31
reasonings behind some of the exemptions, I’m sorry, extensions rather
50:34
that you saw uh in the early days of of PSC2. So, uh, a country may have a
50:41
certain dollar value, uh, attached to a deadline, um, before
50:45
they go to full SCA enforcement. Um, so I’m just just going to make up numbers.
50:50
It may be, you know, uh, items below 500 euros uh, are exempt from SCA um, up to
51:01
March of 2021 and then say March of 2022, you have full implementation of
51:06
SCA. uh so in so ter so far as the rollout is concerned you did see lots of
51:10
variations but um the scope of the regulation and the implementation of SCA
51:17
uh as a as a regulation as a requirement it it didn’t so much vary over the
51:22
various countries
51:24
>> right now now coming into SEA itself and you know 3D secure um very specific
51:32
question on on on how is that triggered I mean how how do we get into the you
51:37
know now you have to do sea is there a a kind of process that uh that that that’s
51:44
followed through the transaction can you can you give us a bit of uh granularity
51:48
on that
51:49
>> sure sure I’ll I’ll walk you through uh my understanding of the the flow process
51:54
again there are lots of resources out there um that we’re happy to point you
51:57
to but it it all starts with the risk evaluation so and and all aspects of the
52:03
payment ecosystem are involved in this from the consumer to the merchant to the
52:06
acquirer PSP and and issuer. Uh but it starts with a risk evaluation. So before
52:12
requesting authorization, the merchant is required to provide data on the card
52:16
issuer. Um and the card issuer then goes through this process of riskbased
52:23
authentication where uh the merchant data is verified alongside the the
52:28
issuers’s data and a score is determined. And that score then lets the
52:34
issuer know if uh an additional step is required to complete the transaction.
52:38
And that additional step of course would be sea. Um so in the this authentication
52:43
stage uh you know a step up requirement is sent to the consumer’s bank and a
52:49
push notification on the mobile device of the consumer like we saw with that
52:53
that face ID prompting uh in the earlier slide is uh is sent to the consumer. So
52:59
then the consumer is required to strongly authenticate to their mobile
53:03
banking app. It’s typically a mobile banking app and um through that
53:07
two-factor method for SEA um and then if they are able to successfully
53:13
authenticate that’s when the authorization is set through and the
53:16
bank replies to the merchant with a confirmation that the card holder
53:20
authentication was successful. So that that’s kind of the SCA uh flow in a
53:26
nutshell. Okay. The the the other thing that you
53:29
mentioned which I thought was interesting was the the kind of the
53:33
reference fraud rate um and exemption. So you know depending on your reference
53:39
fraud rate um you know you can put in an exemption request. So the kind of the
53:46
question around that I guess then is is how are you managing or how are you
53:50
handling those reference fraud rates? who who who is kind of cataloging that
53:54
and and what are their criteria?
53:57
>> Sure. So so the fraud rate itself is calculated based on you know the total
54:04
number of fraudulent transactions which you can maybe capture based on
54:08
chargebacks that are are received uh over the total number of transactions.
54:14
And um there was a slide that um Kevin presented previously where you had you
54:19
know the the fraud rates um and then dollar values or I’m sorry euro values
54:23
that are associated with uh the various fraud rates. So, if you keep your fraud
54:27
rate below um a certain level, you’re able to uh request exemptions. And um in
54:36
the case of a PSP, uh as Kevin mentioned previously or an
54:41
acquirer fits into this this realm as well, um you want to have merchants who
54:46
have lower fraud rates because it’s an aggregate fraud rate that actually
54:51
allows you to, you know, go through that low risk transaction process. Um so
54:56
number one uh having that um that uh TRA in place the transaction risk analysis
55:03
through some sort of a fraud vendor or uh rules basic whatever you whatever you
55:08
might have in place that uh meets the requirements of PST2. Um that’s your
55:14
first step to ensuring that you you keep your fraud rate low. And um once you
55:19
have the calculation as an acquirer or a PSP uh you can then work on behalf of
55:24
your merchants to request exemptions up to the dollar value of the the uh
55:28
requirements for PSD2. Um and then the issuer of course would need to have the
55:33
fornowledge to deal with those exemption requests and properly properly route
55:38
them.
55:40
>> Right. Okay. Um we’re going to get on to some of the questions that have now
55:44
started to uh to to buzz in. So first one here, this is coming from Brett
55:49
Dyson. Um, and it is for split payments at the checkout where the CC details are
55:55
passed to a third party. Is there a requirement to have a second
56:00
authentication check for PSD2? So Corey um, or Kevin, I don’t know if
56:05
either of you two is able to kind of address that one.
56:09
>> I’m sorry, I I missed the question. My internet dropped for probably
56:13
>> Oh, we lost you from that. Okay. So, it’s it’s split payments at the
56:17
checkout. That’s the scenario. Okay. And the CC details are passed to a third
56:22
party. Is there a requirement to have a second authentication check to comply
56:27
with PSD2?
56:30
>> That’s a great question. Um, I’m assuming that both payments are via
56:36
credit card. um and if they fall within the scope of PST2 and they’re not below
56:44
say €30 a piece or something like that um I believe the transactions would be
56:49
treated differently since you know they would have a different pre-authorization
56:53
path but uh Kevin I’ll let you jump in on that as well.
56:57
>> I think that sounds correct. So it sounds like this particular transaction
56:59
it’s not like a subscription so it’s like it’s not annual or monthly like
57:03
that. So, in terms of split payment, I believe it would have to go through that
57:06
Etsier check again.
57:09
>> Okay, cool. Good answer, guys. I’m impressed. Good thinking on your feet
57:14
there. Um, now another one from anonymous this time is coming back to
57:19
biometrics. So, with regards to face-based biometric authentication, who
57:24
is the controller of the stored biometric data? So, I guess this is
57:28
touching on GDPR, isn’t it? And how can you reenroll in case the biometric
57:33
database is breached? Interesting.
57:36
>> That’s a that’s a great question. So there are different
57:41
technologies behind doing biometric authentication
57:45
uh and different vendors will provide different levels. So you can have the uh
57:50
data stored on the device itself in the case of like face ID. Uh you can have
57:55
the biometric data stored in say a server. uh but you know in both of those
58:00
cases it acts as kind of a honeypot for uh hackers to come and you know access
58:05
that biometric data which you know that that definitely has GDPR implications.
58:09
Um, now the passwordless authentication technology uh that I was referring to
58:14
throughout the presentation actually uses a technology that I it’s it’s
58:20
complicated to explain but it breaks up the biometric data and distributes it in
58:24
such a way that no one can reassemble that biometric data uh except for the
58:30
end user themselves. So whoever you know the biometric data is associated with
58:35
they can then through the authentication process reassemble that biometric data
58:39
and um and uh authenticate into you know whatever login or uh transaction they
58:45
need to authenticate. So uh the GDPR implications are actually met in the
58:50
fact that there’s no stored data and there’s no um uh processing of the
58:56
biometric data. So great great question. Okay, so last one because we’re we’re
59:03
fast running out of time and and this is very direct from Ambriela Ukqua. I hope
59:08
I pronounced that right. Um but but she’s asking what are the penalties for
59:12
not implementing SCA. Don’t know if you guys get involved in
59:17
uh you know what you have to pay if you don’t follow SCA.
59:22
>> That’s a very good question uh and and maybe something that I would need to
59:26
take offline. Um my understanding is that the European Banking Authority is
59:32
kind of like your your last stop when it comes to as well as you know incountry
59:36
banking authorities but uh they’re kind of the last stop when it comes to
59:40
enforcement of the the regulation. Um in my reading of the RTS I didn’t
59:47
necessarily see say fines or anything of that nature uh for the uh the
59:53
regulation. Um but again I’d like to take that question offline and and
59:57
answer it thoroughly uh with some of my my colleagues who might be more expert
1:00:02
in the regulation than I am. But that’s that’s a great question
1:00:06
>> and that’s a good answer. So anyway, thank thank you for that Corey very
1:00:11
impressive that you managed to to field a lot of those unexpected questions. Uh
1:00:16
we’re actually out of time so I would like to thank Sift uh as the sponsors of
1:00:22
today’s webinar. Very big thanks to Corey and also to Kevin. Um, also big
1:00:28
thanks to MPE, to Patricia and the rest of the team. And just a reminder that we
1:00:33
will have the presentation available in PDF from tomorrow. So if you’re
1:00:37
registered, you’ll be able to download it. Uh, and you should get a
1:00:40
notification of that. So lastly, thank you all for joining and wish you all a
1:00:46
great rest of the day and uh, great rest of the week. Thanks very much. Bye for
1:00:51
now.