Reference🏛️ The payments ecosystemIntermediate⏱ 18 min read

⚖️ Payment regulation

From PSD1 to the PSD3/PSR package, by way of the IFR, SCA and the Instant Payments Regulation: the European framework that shapes the entire payments ecosystem.

Who regulates what

European payments are regulated at three institutional levels. The European Union sets the framework through its directives and regulations, and through the EBA's technical standards. National authorities license and supervise payment firms, while central banks oversee infrastructures and payment instruments. France adds an oversight body of its own, the OSMP.

🇪🇺
EBA (European Banking Authority)
Drafts the regulatory technical standards (RTS, including the SCA standards) and the guidelines that spell out how the directives apply. Maintains the central register of European payment institutions.
🏛️
ACPR
France's banking supervisor, attached to the Banque de France. It licenses French credit institutions, payment institutions and e-money institutions, monitors their soundness and compliance (including AML/CFT), and imposes sanctions.
🏦
Banque de France
Holds a statutory mandate to oversee the security of payment methods (Article L141-4 of the French Monetary and Financial Code). It runs the OSMP (Observatoire de la sécurité des moyens de paiement, France's payment security observatory), which publishes the benchmark fraud statistics.
💶
ECB / Eurosystem
Oversees infrastructures (TARGET, clearing systems) and, under the PISA framework, the payment schemes and arrangements operating in the euro area, including wallets and card schemes.
🔐
CNIL and ANSSI
On the periphery, the CNIL protects payment data (GDPR) and ANSSI covers the cybersecurity of critical operators (NIS2). Digital operational resilience in the financial sector falls under DORA, supervised by national financial authorities (the ACPR and AMF in France).
🔑
Directive vs. regulation: how each takes effect
A directive, such as PSD1, PSD2 and the forthcoming PSD3, must be transposed into each member state's national law, which creates differences between countries and delays in application. A regulation, such as the IFR, the Instant Payments Regulation and the forthcoming PSR, is directly applicable across the EU, with no transposition needed. Moving part of the PSD3 package into a regulation (the PSR) reflects a drive for maximum harmonization across member states.

From PSD1 to PSD2: opening up the market

PSD1 (Directive 2007/64/EC, transposed into French law in 2009) laid the foundations of the single market for payments. It created the payment institution license, ending the banks' monopoly on payment services. It also set the legal basis for SEPA, with common rules on execution, timelines and liability. That license opened the way for Europe's first non-bank PSPs.

PSD2 (Directive 2015/2366, in force since January 13, 2018) extended the framework to access to bank accounts themselves. It created two new regulated activities: payment initiation (PISP) and account information (AISP). Banks must serve both through dedicated APIs, and cannot require the third-party provider to sign a contract first. European regulatory open banking grew out of this obligation.

  • Strong customer authentication (SCA) required for account access and electronic payments (covered in the next section).
  • Limits on charges: a ban on surcharging consumer card payments (Art. 62), and SHA (shared) charges by default within the EU.
  • Stronger liability rules: the cardholder's maximum loss cut from €150 to €50, refunds of unauthorized transactions by D+1, and the burden of proof shifted to the PSP.
  • A narrower commercial agent exemption, which sent a regulatory shockwave through marketplaces (see the merchant-acquirer-PSP topic).
  • Stronger passporting and an EBA register: coordinated supervision of pan-European firms.
ℹ️
PSD2 open banking: a mixed record
The APIs mandated by PSD2 gave rise to account aggregation and bank transfer initiation. But their quality varied, and adoption suffered because there was no single technical standard: several competing specifications, such as those of the Berlin Group and STET, coexist. The PSD3/PSR package and the FIDA regulation (open finance) explicitly aim to fix this, with API performance requirements, consent dashboards, and coverage beyond the payment account.

SCA: strong customer authentication

SCA (Strong Customer Authentication) requires at least two independent factors from three categories: knowledge (PIN, password), possession (an enrolled phone, a card) and inherence (biometrics). The EBA's RTS that implement it have applied since September 14, 2019. France completed its e-commerce migration plan in 2021. In practice, French online card payments run on 3-D Secure v2: the cardholder approves in their banking app with biometrics, or with a one-time code combined with a password.

Browserdevice data (~130 fields)3DS Servermerchant / PSP sideDSscheme directory serverACSissuing bankcollectionAReqAReqFrictionless≈ 90–95% of transactionsChallengeOTP, banking app, biometricsARes = Y (low risk)ARes = CCReq / CResThe customer authenticatesthrough their bankAuthentication successfulliability shift → the issuer bears the fraudRich, consistent data= more frictionless
ExemptionConditionsLimitWho bears the fraud loss?
Low-value payment (LVP)€30 or less, with counters: at most 5 transactions or €100 cumulative since the last SCA30 €The issuer (if it grants the exemption)
Transaction risk analysis (TRA)Requesting PSP's fraud rate below the regulatory thresholds€100 (rate ≤ 0.13%), €250 (≤ 0.06%), €500 (≤ 0.01%)The PSP applying the exemption
Trusted beneficiaryMerchant added by the cardholder to an allowlist held by their bankNoneThe issuer
Recurring paymentsFixed amount: SCA on the first transaction onlyNoneDepends on the initial transaction
MITs (merchant-initiated transactions)Out of SCA scope: transactions the merchant initiates without the cardholder (variable-amount subscriptions, for example), backed by an authenticated mandate–The merchant, if the cardholder disputes
MOTO / anonymous cardsMail and telephone orders: out of scope–The merchant
Main SCA exemptions (EBA RTS), requested by the acquirer or the issuer
⚠️
Frictionless ≠ no 3-D Secure
In 3DS2, a transaction can be authenticated without a challenge, a flow known as frictionless. The merchant sends dozens of contextual data points, and the issuer assesses the risk and approves the transaction without prompting the cardholder. The liability shift applies just as it does after a challenge. An exemption requested by the acquirer, for example under acquirer TRA, works differently: the transaction skips 3DS altogether, and fraud liability stays on the acquiring side. How these flows are configured is one of the main levers of the e-commerce payment success rate.
0,053 %
Card fraud rate in France in 2023; SCA drove e-commerce fraud sharply down
OSMP, 2024
≈ -40 %
Drop in the fraud rate on remote card payments since SCA was rolled out (2019–2023)
OSMP
70-80 %
Share of 3DS2 transactions processed frictionless at mature merchants
PSP observations, 2025

From 2023 to 2026, fraud shifted toward manipulating the customer directly. Phone spoofing by fake bank advisers, CEO fraud and fake delivery links all fall into this category, in which the victim personally authenticates the transaction they later dispute. The PSD3/PSR package plans a response: refunds when a fraudster impersonates bank staff, fraud data sharing between PSPs, and obligations for telecom operators and online platforms.

The Interchange Fee Regulation (IFR, 2015)

Regulation (EU) 2015/751 of April 29, 2015 (the Interchange Fee Regulation) directly regulates the price of interchange in the four-party model. Before it, interchange was set collectively and acted as a price floor passed on to merchants. EU lawmakers capped it for consumer cards: 0.2% of the amount for debit cards and 0.3% for credit cards. The caps have applied since December 9, 2015.

0,2 %
Consumer debit interchange cap
IFR, Art. 3
0,3 %
Consumer credit interchange cap
IFR, Art. 4
Dec. 9, 2015
Caps take effect
IFR
Uncapped
Commercial cards and pure three-party schemes
IFR, scope
  • Separation of scheme and processing (Art. 7): schemes must keep brand management and transaction processing separate, in their accounts and their organization, to open processing to competition.
  • Brand choice on co-badged cards (Art. 8): neither the scheme nor the issuer can impose routing; the merchant and the cardholder each have a say. This is the cornerstone that lets Cartes Bancaires (CB), France's domestic card scheme, coexist with Visa and Mastercard.
  • A looser “honor all cards” rule (Art. 10): a merchant can accept a brand's debit cards without having to accept its credit or commercial cards (acceptance remains bundled within each category).
  • Transparency (Arts. 9 and 12): billing itemized by card category (unblending) at the merchant's request, and transaction-level information.
Before the IFR (2014)After the IFR (2016+)
Interchange≈ €0.50 to €1.00, depending on the country€0.30 max
Typical total MSC≈ 0,90-1,20 €≈ 0,50-0,80 €
Who gains from the cut–Merchants (pass-through to consumers is debated)
IFR impact on a €100 transaction (consumer credit card, European orders of magnitude). In France, CB interchange had already been cut to 0.28% in 2011 under pressure from the Autorité de la concurrence, the French competition authority
⚠️
The IFR's blind spots
Three categories of transactions escape the IFR caps, and they are where today's tensions lie. Commercial cards often carry interchange above 1.5%, which leads some issuers to push them. Scheme fees are rising steeply and face no price regulation at all. Inter-regional transactions, where a non-European card is used at a European merchant, fall under separate, higher caps. Those caps come from commitments made to the Commission and stand at 1.15% and 1.50% for card-not-present transactions. The Commission's ongoing IFR review could extend regulation to all three categories.

The Instant Payments Regulation (2024)

Regulation (EU) 2024/886 of March 13, 2024, the Instant Payments Regulation, entered into force on April 8, 2024. It turns instant credit transfers from a commercial option into a legal obligation for every EU PSP that offers standard credit transfers. SCT Inst, the EPC scheme launched in 2017, makes funds available in under 10 seconds, 24/7/365. The regulation tackles two long-standing obstacles: reachability, since not every bank could receive instant transfers, and price, often around €1 per instant transfer in France before the regulation.

DeadlineObligationWho is affected
January 9, 2025Receive instant credit transfers + price no higher than a standard transferEuro-area PSPs
October 9, 2025Send instant credit transfers + Verification of Payee (VoP) on all credit transfers + daily sanctions screening (instead of per transaction)Euro-area PSPs
January 9, 2027Receive + price parityPSPs in member states outside the euro area
July 9, 2027Send + VoPPSPs in member states outside the euro area
Regulation 2024/886 deadlines
🔑
Verification of Payee (VoP): the big 2025 rollout
Since October 2025, Verification of Payee has required the payer's bank, before any credit transfer, to check that the IBAN matches the payee name entered, and to warn the payer if they differ. The measure targets fake-RIB fraud (a RIB is the French bank details document that carries the IBAN) and supplier impersonation fraud. The EPC has published a dedicated VoP scheme with standardized responses: match, close match (the similar name is shown to the payer) and no match. The payer can still go ahead, but having been warned, they take on liability for the transfer.
Simplified VoP exchange (illustration, EPC scheme API format)
POST /verification-of-payee HTTP/1.1
Host: api.payee-bank.example

{
  "iban": "FR7630004000050000123456789",
  "name": "SARL DUPONT ET FILS"          <- name entered by the payer
}

--> 200 OK
{
  "result": "CLOSE_MATCH",               <- near match
  "matched_name": "DUPONT & FILS SARL"   <- actual name, shown to the payer
}
// MATCH      : transfer goes through with no friction
// CLOSE_MATCH: payer confirms, knowing the name differs
// NO_MATCH   : strong warning; if the payer overrides it, their liability grows
< 10 s
Funds available to the payee (SCT Inst)
EPC SCT Inst scheme
≈ 20 %
Instant payments' share of euro-area credit transfers in early 2026, up sharply since January 2025
BCE
0 €
Maximum surcharge allowed over a standard credit transfer
Regulation (EU) 2024/886

The effects of this mandate ripple through the whole ecosystem. Now universal and priced no higher than a standard transfer, the instant credit transfer becomes a payment rail that competes with cards in e-commerce, which is the premise behind Wero. It also underpins payment requests (Request-to-Pay) and is the likely foundation for the digital euro the ECB is preparing. For corporate treasurers, it changes cash management: payroll can be paid as it falls due, and refunds go out instantly.

PSD3/PSR and the 2026–2028 outlook

The Commission presented its package revising PSD2 on June 28, 2023. It centers on a PSD3 directive, refocused on licensing and supervising payment firms, and a directly applicable PSR (Payment Services Regulation) that takes over most conduct rules: SCA, user rights and open banking. The package folds the e-money regime (EMD2) into the payment services framework, and the EMI license is set to be absorbed.

  • Fighting manipulation fraud: refunds, under conditions, for customers deceived by fraudsters impersonating their bank (spoofing); fraud data sharing between PSPs; an extended VoP.
  • Stronger open banking: API performance and availability requirements, a consent dashboard for users, and a ban on unjustified obstacles (frictions). No single technical standard is imposed, but outcomes are mandated.
  • Access for PIs and EMIs to payment systems and central bank accounts: a response to banks de-risking fintechs (with regulated access to infrastructures such as TARGET).
  • SCA fine-tuned: clarifications on exemptions, on outsourcing authentication (delegating it to wallets), and on accessibility for users without a smartphone.
  • In parallel: the FIDA regulation (access to financial data beyond payment accounts, such as savings, insurance and credit), plus DORA (digital operational resilience, applicable since January 2025) and MiCA for crypto-assets, including payment stablecoins, coming into application.
ℹ️
Where things stand in mid-2026
The European Parliament adopted its position in April 2024, and the Council followed in June 2025. The trilogues ended with a provisional political agreement on November 27, 2025, and the final compromise texts were published on April 23, 2026. Formal adoption and publication are expected in the second half of 2026. Application deadlines are long: 21 months after entry into force for the PSR, and the same period for transposing PSD3. The new obligations will therefore not take effect before 2028. Some firms are already tackling the heaviest projects: extended VoP, open banking dashboards and anti-spoofing controls.
2007
DSP1
Directive 2007/64/EC: created the payment institution license and the legal basis for SEPA. Transposed into French law in 2009.
2009
DME2
Directive 2009/110/EC: the e-money regime and the EMI license.
2012-2014
SEPA end-date regulation
Regulation 260/2012: mandatory migration of national credit transfers and direct debits to SCT and SDD, completed on August 1, 2014.
2015
IFR and PSD2 adopted
Interchange caps in force from December 2015; PSD2 applicable from January 13, 2018.
2017
SCT Inst launches
The EPC's instant credit transfer scheme, optional.
2019
SCA RTS
Strong customer authentication applicable from September 14, 2019; e-commerce migration completed in France in 2021.
2023
PSD3/PSR package and FIDA proposed
Commission proposals of June 28, 2023.
2024
Instant Payments Regulation
Regulation (EU) 2024/886, in force since April 8, 2024.
2025
Instant payment deadlines + DORA
Receiving (January), then sending + VoP (October) in the euro area; DORA applicable since January.
2026-2028
PSD3/PSR adoption, then application
Provisional agreement reached in November 2025; formal adoption expected in 2026, with the rules applying from around 2028. A decision on the digital euro is pending.
🔑
Three goals behind every text
Twenty years of European regulation have pursued three constant goals. The first is to open the market to new entrants, through PSD1, PSD2 and open banking. The second is to bring costs down for merchants and the wider economy, through the IFR and price parity for instant payments. The third is to protect users, through SCA, VoP and refund rules. Each new text strikes a fresh balance between these three goals, and their relative weight shifts from one text to the next.

Elsewhere in the world. The same mechanism, elsewhere.

Regulatory caps on interchange

In the US, the Federal Reserve's Regulation II (the Durbin Amendment) caps only debit interchange, and only for issuers with at least $10 billion in assets: $0.21 per transaction plus 0.05% of the amount, plus a $0.01 fraud-prevention adjustment for eligible issuers. Credit card interchange is not regulated.

https://www.federalreserve.gov/paymentsystems/regii-average-interchange-fee.htm

Australia

In Australia, the Reserve Bank of Australia sets the caps. Its March 2026 Conclusions Paper lowers two caps from October 1, 2026: domestic consumer credit cards to 0.30%, and debit and prepaid cards to 8 cents or 0.16% (down from 10 cents or 0.20%). Commercial cards stay at 0.80%, and foreign-issued cards acquired in Australia will be capped at 1.0% from April 1, 2027.

https://www.rba.gov.au/payments-and-infrastructure/review-of-retail-payments-regulation/2026-03/conclusions-paper/interchange-fees.html

Brazil

In Brazil, Resolução BCB nº 246 of September 26, 2022, has capped the interchange fee (tarifa de intercâmbio) at 0.5% of the amount for debit cards and 0.7% for prepaid cards since April 1, 2023. It replaced the earlier regime, which combined a maximum weighted average with a maximum value per transaction, and it aligned the timelines for paying out funds to merchants.

Banco Central do Brasil, Resolução BCB nº 246, September 26, 2022

India

India did not cap interchange; it abolished the merchant fee altogether. Section 10A of the Payment and Settlement Systems Act 2007, inserted by the Finance Act 2019, has banned any charge to the merchant or the payer on UPI payments and RuPay debit cards since January 1, 2020. The result is a zero MDR, funded by a government incentive paid to the banks and payment companies involved.

Payment and Settlement Systems Act 2007, s. 10A (inserted by the Finance Act 2019); Income-tax Act 1961, s. 269SU

Mandatory strong authentication for electronic payments

India

India's equivalent of SCA, the Additional Factor of Authentication (AFA), predates the European rules. The Reserve Bank of India imposed it in 2009 and overhauled it with the Authentication Mechanisms for Digital Payment Transactions Directions, published on September 25, 2025, and applicable from April 1, 2026. The Directions require at least one factor to be generated dynamically for each transaction, and extend AFA to cross-border card-not-present payments when the foreign merchant or acquirer requests it.

https://rbidocs.rbi.org.in/rdocs/PressRelease/PDFs/PR1165D250AB0389BE4D3D9E006CECD26F928E.PDF

The UK kept strong customer authentication after Brexit. It is still required by the Payment Services Regulations 2017 and the UK SCA-RTS, which the FCA has applied since September 14, 2019, with the same set of exemptions, including the contactless point-of-sale exemption in Article 11 of the RTS.

https://www.fca.org.uk/firms/strong-customer-authentication

In the US, no federal rule mandates strong authentication; consumers are protected through liability rules instead. Regulation E (12 CFR 1005.6) caps a consumer's loss at $50 if they report a lost or stolen access device within two business days of discovering the loss, and at $500 after that. The cap disappears for transactions that occur more than 60 days after the statement is sent.

https://www.consumerfinance.gov/rules-policy/regulations/1005/6/

Mandatory instant credit transfers and their pricing

Brazil

In Brazil, the Banco Central made Pix participation mandatory for every authorized institution with more than 500,000 active customer accounts (Resolução BCB nº 1/2020). Resolução BCB nº 19/2020 then barred institutions from charging individuals and sole proprietors any Pix fee for sending or receiving transfers. Free Pix is a regulatory requirement there, not a commercial offer.

Banco Central do Brasil, Resolução BCB nº 1 of August 12, 2020, and Resolução BCB nº 19 of October 1, 2020

India

In India, UPI, operated by the National Payments Corporation of India, runs around the clock, and its zero cost is written into law: since January 1, 2020, Section 10A of the Payment and Settlement Systems Act 2007 has banned any fee charged to the payer or the payee of a UPI payment. The debate over reinstating an MDR for large merchants reopened in 2026.

Payment and Settlement Systems Act 2007, s. 10A (inserted by the Finance Act 2019)

In the US, the Federal Reserve launched FedNow on July 20, 2023, with 35 financial institutions, but participation is voluntary: no law requires a bank to receive or send instant payments, or to price them in line with standard transfers. More than 1,500 institutions were on the service by summer 2025.

https://www.frbservices.org/news/fed360/issues/071625/fednow-service-two-years-growth-innovation