Skip to content
Insights

Skipping SCA puts your fraud rate under supervision.

Transaction risk analysis buys a skipped authentication, and the price is a fraud rate the regulator computes with you and can switch you off for.

  • Ihor Yurko
  • Industry
  • Jul 19, 2026

Transaction risk analysis lets a payment service provider skip strong customer authentication on a remote payment worth up to EUR 500. Nothing is asked of the payer. The check moves to a number.

That number is the PSP's own fraud rate, calculated by a formula the regulation fixes, measured every quarter, audited every year, and capable of switching the exemption off. The rules here are the current RTS on SCA, Delegated Regulation 2018/389. The Payment Services Regulation will replace them with new EBA standards, and it is not in force yet.

When a transaction qualifies

Three conditions have to hold at once, and failing any of them means SCA, unless some other exemption applies.

  • The amount sits inside a band: EUR 100, EUR 250 or EUR 500.
  • The PSP's fraud rate for that type of transaction is at or below the reference rate for that band.
  • Real-time risk analysis finds no risk signals. The RTS names six: abnormal spending or behavior, unusual device or software access, malware, a known fraud scenario, an abnormal payer location, and a high-risk payee location.

The reference rates sit in the Annex to the regulation, and they run the opposite way to the bands.

  • EUR 100: 0.13 percent on remote card payments, 0.015 percent on remote credit transfers.
  • EUR 250: 0.06 and 0.01.
  • EUR 500: 0.01 and 0.005.

Exempting up to EUR 500 on cards asks for a fraud rate thirteen times lower than exempting up to EUR 100. The widest band is the one the fewest firms can hold.

The rate counts transactions you did not exempt

The formula is the value of fraudulent remote transactions divided by the value of all remote transactions of the same type. The denominator is wider than TRA, and so is the numerator.

  • It takes in transactions that were authenticated with SCA, and every exemption under Articles 13 to 18. Fraud on a low-value or a recurring payment raises the rate that governs TRA.
  • It is calculated once per calendar quarter, and separately for cards and for credit transfers.
  • Fraud is booked to the quarter the transaction happened in. A fraud reported later reopens a quarter that had already been calculated.
  • Each PSP works from its own rate. The issuer is always liable to the payer where a transaction went through without SCA, and where the acquirer applied TRA, the acquirer is liable to the issuer.

Two of those have teeth. The cheap exemptions you shipped first feed the number that decides whether you keep the expensive one. And a quarterly figure that gets written down once is wrong by construction, because fraud arrives after the quarter it belongs to.

Two quarters and it stops

  • A threshold breach is reported to the regulator immediately.
  • After two consecutive quarters above the threshold, TRA stops in that band, at once.
  • It resumes after one quarter back under the threshold, and the regulator is told in advance.

Stopping at once is a product requirement long before it is a compliance one. A band that can only be turned off by shipping code is a band you cannot turn off on the day the second quarter closes.

What that means to build

  • Real-time risk scoring on every transaction.
  • A fraud-rate pipeline that implements the regulation's formula and can recalculate a closed quarter.
  • Quarterly monitoring data covering all the exemptions, not only TRA.
  • A runtime switch per band.
  • Documentation of the methodology, the model and the rates, written for a regulator.
  • An annual audit, external in the first year and at least every three years after that.

The first step sits outside the build. Calculate last quarter's fraud rate with the regulation's formula on the data already sitting in the warehouse. That answer says which bands are available before a line of it is built.