SCA exemptions under the PSD2 RTS — thresholds, fraud rates and how the TRA exemption is lost
Every SCA exemption in the PSD2 RTS is conditional on monitoring you have to run whether or not you use the exemption — and the transaction-risk-analysis exemption withdraws itself automatically after two bad quarters. Commission Delegated Regulation (EU) 2018/389 sets out eight exemptions from strong customer authentication, each with its own trigger, and one common obligation: quarterly fraud-rate measurement broken down by exemption. This walks through what each exemption actually permits, how the fraud-rate arithmetic works, and what happens operationally when a threshold is breached.
1. The instrument, and what it does not cover
The regulatory technical standards on strong customer authentication and common and secure open standards of communication are Commission Delegated Regulation (EU) 2018/389 of 27 November 2017, made under Directive (EU) 2015/2366. Under Article 38 it applies from 14 September 2019, with Article 30(3) and (5) having applied from 14 March 2019.
Two framing points. First, an exemption is a permission, not an instruction: each of Articles 10 to 18 says payment service providers “shall be allowed not to apply” strong customer authentication. The decision, and the fraud liability that follows it, sits with the provider. Second, the exemptions are drafted “subject to compliance with the requirements laid down in Article 2” — the transaction-monitoring mechanisms — so a firm cannot claim an exemption while running no monitoring. The exemption and the monitoring are a package.
2. The eight exemptions, and their actual triggers
| Article | Exemption | Conditions |
|---|---|---|
| 10 | Account information access | Limited to defined information; SCA required if accessed for the first time, or if more than 90 days have elapsed since SCA was last applied to that access |
| 11 | Contactless at point of sale | Individual amount ≤ EUR 50, and cumulative since last SCA ≤ EUR 150, or no more than five consecutive transactions since last SCA |
| 12 | Unattended terminals | Transport fares and parking fees only |
| 13 | Trusted beneficiaries | SCA is required to create or amend the list; subsequent payments to a listed payee may be exempt |
| 14 | Recurring transactions | SCA required on creation, amendment or first initiation of a series with the same amount and same payee; subsequent ones may be exempt |
| 15 | Credit transfers between own accounts | Payer and payee the same person and both accounts at the same account servicing provider |
| 16 | Low-value remote transactions | Amount ≤ EUR 30, and cumulative since last SCA ≤ EUR 100, or no more than five consecutive remote transactions since last SCA |
| 17 | Secure corporate processes | Legal persons only, dedicated processes or protocols unavailable to consumers, competent authority satisfied they give at least equivalent security |
| 18 | Transaction risk analysis | Fraud rate at or below the Annex reference rate, amount at or below the exemption threshold value, and no negative signal from real-time analysis |
The counters in Articles 11 and 16 are where implementations most often diverge from the text. Both are drafted as an amount condition and either a cumulative-value condition or a consecutive-count condition. Reading them as three independent tests, or as a single value ceiling, produces either over-authentication or exemptions applied outside their terms.
3. Transaction risk analysis: the conditional exemption
Article 18 is the commercially valuable one and the only one that can be lost. It permits exemption where a remote electronic payment transaction is identified as posing a low level of risk, and it defines low risk by three cumulative conditions.
First, the fraud rate for that type of transaction, calculated under Article 19, must be at or below the reference rate in the Annex. Second, the amount must not exceed the relevant exemption threshold value. Third, real-time risk analysis must not have identified any of six listed signals: abnormal spending or behavioural pattern of the payer; unusual information about the payer’s device or software access; malware infection in any session of the authentication procedure; a known fraud scenario; abnormal location of the payer; or high-risk location of the payee.
The Annex pairs each threshold with a fraud rate, and the two payment types are treated differently:
| Exemption threshold value | Remote electronic card-based payments | Remote electronic credit transfers |
|---|---|---|
| EUR 500 | 0.01% | 0.005% |
| EUR 250 | 0.06% | 0.01% |
| EUR 100 | 0.13% | 0.015% |
Article 18(3) then requires providers intending to use the exemption to take into account, as a minimum, four risk-based factors — the user’s previous spending patterns, the payment transaction history of each of the provider’s users, the location of payer and payee where the access device or software is provided by the provider, and identification of abnormal payment patterns relative to the user’s history — and to combine all of those factors into a risk scoring for each individual transaction.
4. How the fraud rate is actually calculated
Article 19 defines it precisely, and two elements of the definition are routinely got wrong. The overall fraud rate is the total value of unauthorised or fraudulent remote transactions, whether the funds have been recovered or not, divided by the total value of all remote transactions of the same type, on a rolling quarterly basis (90 days).
The first trap is recovery: recovered funds stay in the numerator. A chargeback that is won does not remove the transaction from the fraud figure. The second is population: the denominator and numerator cover transactions authenticated through SCA as well as those executed under any of the exemptions in Articles 13 to 18. The rate is not the fraud rate on exempted traffic — it is the fraud rate on all remote traffic of that type, which means fraud on authenticated transactions consumes the same headroom.
Article 19(2) puts the calculation inside the audit review referred to in Article 3(2), which must ensure the figures are complete and accurate; Article 19(3) requires the methodology and any model to be documented and made fully available to competent authorities and to the EBA on request, with prior notification to the relevant authority.
Facts: a provider operating at the EUR 250 threshold for remote card payments measures fraud only on the traffic it exempted, gets 0.04%, and treats itself as comfortably inside the 0.06% reference rate.
What the rule says: Article 19(1) requires the overall rate across both authenticated and exempted transactions of that type. Adding the authenticated population — which is where the higher-value, higher-risk traffic usually sits — can move the true figure above the reference rate.
What the practitioner does: rebuilds the metric on the full remote population for the transaction type, on a rolling 90-day basis with recovered fraud included, and re-runs the prior four quarters before deciding whether the exemption was ever validly available at that threshold.
5. Losing the exemption, and getting it back
Article 20 makes the consequence mechanical. Where a monitored fraud rate exceeds the applicable reference rate for any transaction type in the Annex, the provider must immediately report to the competent authority and provide a description of the measures it intends to adopt to restore compliance.
Then the automatic part. Under Article 20(2), providers must immediately cease using the Article 18 exemption for that transaction type in that specific exemption threshold range where the monitored fraud rate exceeds the reference rate for two consecutive quarters. Article 20(3) prevents re-use until the calculated fraud rate is at or below the reference rate for that type and threshold range for one quarter. Article 20(4) requires notification to the competent authority in a reasonable timeframe and evidence of restored compliance before the exemption is used again.
The threshold ranges are severable, which is the practical escape route: a rate that breaches at EUR 500 does not necessarily breach at EUR 250 or EUR 100.
Facts: a provider breaches the EUR 500 reference rate in Q1 and again in Q2, and its product team asks whether the exemption can simply be re-enabled once the next month looks better.
What the rule says: use must cease immediately for that type in that threshold range, cannot resume until a full quarter at or below the reference rate, and requires prior notification with evidence. A good month is not a quarter.
What the practitioner does: steps down to the next threshold range where the rate still complies rather than switching SCA fully on, and sets the exemption engine to enforce cessation automatically at the second consecutive breach instead of leaving it to a manual review that will run late.
6. The monitoring obligation that applies to everyone
Article 21 is easy to miss because it sits after the exemptions rather than before them. To make use of any of the exemptions in Articles 10 to 18, providers must record and monitor the following data for each type of payment transaction, with a breakdown for remote and non-remote transactions, at least quarterly: the total value of unauthorised or fraudulent transactions in accordance with Article 64(2) of PSD2, the total value of all payment transactions and the resulting fraud rate, including a breakdown of transactions initiated through SCA and under each of the exemptions; the average transaction value with the same breakdown; and the number of transactions where each exemption was applied, and their percentage of the total number of transactions. Article 21(2) requires the results to be made available to competent authorities and the EBA on request.
That is a per-exemption data model. A firm using the low-value exemption at Article 16 and nothing else still owes the same breakdown, and the reporting cannot be produced retrospectively from a system that never tagged which exemption was applied to which transaction.
Alongside this sits Article 5 on dynamic linking, which governs the authenticated path: the authentication code must be specific to the amount and the payee, any change to either must invalidate the code, and for a batch of remote transactions the code must be specific to the total amount and the specified payees. Fraud reporting to the supervisor runs separately, through the EBA guidelines applied nationally — for Luxembourg, the six-monthly return described in our note on CSSF legal reporting.
7. FAQ
What are the SCA exemption thresholds?
Contactless at point of sale: EUR 50 per transaction, EUR 150 cumulative or five consecutive since the last SCA. Low-value remote: EUR 30 per transaction, EUR 100 cumulative or five consecutive. Transaction risk analysis: EUR 500, EUR 250 or EUR 100 depending on the fraud rate achieved.
What fraud rate do I need for the TRA exemption?
For remote card-based payments: 0.01% at EUR 500, 0.06% at EUR 250, 0.13% at EUR 100. For remote credit transfers: 0.005%, 0.01% and 0.015% respectively.
Is the fraud rate measured only on exempted transactions?
No. Article 19(1) requires the overall rate across both transactions authenticated with SCA and those executed under any exemption in Articles 13 to 18, on a rolling 90-day basis, with fraudulent transactions counted whether or not funds were recovered.
What happens if we breach the reference fraud rate?
Immediate report to the competent authority with remediation measures. If the breach persists for two consecutive quarters, use of the Article 18 exemption must cease immediately for that transaction type in that threshold range, and cannot resume until one quarter at or below the rate, with prior notification and evidence.
Do we need monitoring if we only use one simple exemption?
Yes. Article 21 applies to any use of Articles 10 to 18 and requires quarterly data per transaction type, split remote and non-remote, broken down by SCA and by each individual exemption.
Does the trusted-beneficiaries exemption avoid SCA entirely?
No. Article 13(1) requires strong customer authentication when the payer creates or amends the list. Only payments to an already-listed payee may be exempt.
8. What to do, today
- Data model first: confirm every transaction is tagged with the exemption applied, or with “SCA”. Article 21’s quarterly breakdown cannot be reconstructed later from untagged data.
- Recompute the fraud rate on the full remote population for each transaction type, rolling 90 days, recovered fraud included. If your current metric excludes authenticated traffic, it has been flattering you.
- Automate cessation: encode the two-consecutive-quarters rule and the one-clean-quarter re-entry rule in the exemption engine, per threshold range, rather than in a policy document.
- Check the counters: verify Articles 11 and 16 are implemented as amount and (cumulative or count), and that the counters reset only on an actual application of SCA.
- Enrolment paths: confirm SCA fires on creating or amending a trusted-beneficiary list and on setting up a recurring series — the exemption covers the repeat, not the setup.
- Documentation: keep the fraud-rate methodology and any model documented and ready to hand to the competent authority or the EBA, and make sure it is inside the Article 3(2) audit review.
Related: Sanctions screening in instant payments · Major ICT incident reporting under PSD2 and DORA · Verification of Payee under the IPR · PSD2 fraud reporting under Article 96(6) · Payment Accounts Directive — fees and switching


