PSD3European UnionFintech

PSD3 & PSR: Strong Customer Authentication and KYC

PSD3 and the PSR reshape EU payments from 2027: biometric SCA, payee verification, and what they mean for your KYC, fraud controls, and licensing.

PSD3 raises the bar on proving who is behind a payment

EU co-legislators reached a political agreement on 27 November 2025 on the package that replaces PSD2: a third Payment Services Directive (PSD3) plus a directly applicable Payment Services Regulation (PSR). April 2026 saw the agreed texts published. Count roughly 21 months from appearance in the Official Journal before general application — so most duties first bite in the second half of 2027 at the earliest, with a few sliding into 2028.

"2027" sounds distant. It isn't. Two reasons. Authentication patterns most fintechs built for PSD2 are about to fall out of compliance, and re-authorising a licence under PSD3 is a 2026 project, not a last-week scramble.

What PSD3 and the PSR change for authentication, fraud, and the identity checks underneath — and what to do about it now — is what this guide covers.

Two instruments, one rulebook

How the rules reach you depends on the split:

  • PSD3 (a directive) governs the licensing of payment institutions. It folds the old payment-institution and e-money-institution regimes into a single one, and it raises the bar on authorisation — AML and KYC frameworks the applicant must show included.
  • PSR (a regulation) governs conduct: strong customer authentication, fraud, transparency, and access to data. As a regulation it applies directly in every member state; no national transposition, and therefore none of the gold-plating and divergence that split PSD2 apart.

Hold a payment or e-money licence, or apply for one, and both instruments land together. The licence lives in the directive. Day-to-day authentication and fraud duties live in the regulation.

Strong customer authentication gets stricter — and biometric

SCA was already mandatory under PSD2. The PSR rebuilds it around risk and biometrics.

  • Adaptive, risk-based authentication. Authentication must reflect user behaviour, transaction patterns, and current fraud typologies. A fixed two-factor prompt on every action no longer cuts it.
  • Biometrics, both kinds, are explicitly on the table. SCA may be built from physiological biometrics — fingerprint, facial recognition — combined with behavioural biometrics such as typing rhythm and screen-touch patterns. Behavioural signals can serve as an authentication element, not just a fraud score.
  • Accessibility becomes a legal right. At least one SCA method must work for customers without a smartphone, with disabilities, or with low digital skills. That clause breaks the most existing flows: a smartphone-only push-approval setup no longer satisfies the rule on its own.

For most teams, the inherence factor stops being "a selfie at onboarding" and becomes a continuous, accessible, biometric capability. Identity first. Payments second.

Verification of Payee: matching a name to an account

A Verification of Payee (VoP) duty now stretches across the EU under the PSR. Before a transfer is processed, the payer's PSP must check that the payee's name matches the account identifier (the IBAN) and warn the payer of a mismatch. The obligation, and the liability that rides with it, applies 24 months after the regulation enters into force — a longer runway, because both sending and receiving sides have to change systems.

At root, VoP is an identity-data matching problem: a claimed name resolved against the verified holder of an account. Get the matching logic wrong and you either wave fraud through or bury customers in false-positive warnings they learn to ignore.

The fraud-liability shift

The basic rule stays: a payer who authorises a fraudulent payment carries the loss. The PSR then carves out cases where the provider pays instead:

  • Failure to flag a payee-name/identifier mismatch can move liability onto the PSP that skipped the VoP check or ran it badly.
  • Impersonation ("spoofing") fraud, in which a criminal poses as the bank or a public authority, can shift liability to the PSP under the agreed terms.
  • SCA failures can pin liability on scheme operators and technical service providers, not only the customer-facing bank.

Put differently: weak authentication and weak payee verification cease to be the customer's problem. They become a balance-sheet item for you and your vendors.

Where KYC actually fits

PSD3/PSR is a payments rulebook. Identity still sits under it at three points:

  • Licensing. Robust AML and KYC procedures have to be evidenced for a PSD3 authorisation (or re-authorisation). Onboarding due diligence that already satisfies MiCA for crypto and the EU AML package is what a payment-institution applicant must show. Need the fundamentals first? Start with what KYC is.
  • Authentication. Biometric and behavioural SCA is identity verification that runs continuously, not a one-off at sign-up.
  • Fraud and mule accounts. The cheapest place to stop synthetic and mule accounts is strong onboarding identity checks — before downstream fraud rules have to chase them.

PSD3 and eIDAS 2 also intersect: a high-assurance EU Digital Identity Wallet credential can underpin both onboarding and the inherence factor in SCA.

The reality check: your PSD2 setup is already behind

Here is the contrarian read most payments vendors won't lead with: the long timeline is a trap. Three pieces of work cannot wait for 2027.

  • Smartphone-only SCA is already non-compliant in spirit. The accessibility mandate requires a non-smartphone authentication path. That work hits the core auth flow, not a bolt-on.
  • Behavioural biometrics take data and time to train. Behaviour-based authentication cannot be switched on the month the rule applies; the models need history.
  • VoP changes both sides of every transfer. Twenty-four months is the runway because the plumbing runs deep.

Treat PSD3 as a 2027 problem and 2027 is spent firefighting. Teams that win start the authentication and identity rebuild against the 2026 texts.

How Joinble fits

The identity layer the PSR now demands is what Joinble's AI-powered identity platform covers:

  • Physiological biometric verification with certified liveness to serve as the inherence factor in SCA, together with an accessible fallback for customers who cannot use a smartphone flow.
  • Adaptive, risk-based authentication in which Joinble's identity agents weigh behaviour and transaction context and decide when to step up a challenge, instead of prompting on every action.
  • Identity verification and AML screening at payment- and e-money-institution onboarding — the evidence a PSD3 licence application requires.
  • Name-to-identity matching that supports Verification of Payee logic without flooding customers with false positives.

Fintech teams already running KYC on Joinble can extend the same identity stack for SCA and VoP, instead of bolting on a separate authentication vendor.

How to prepare before the deadline

  • Inventory every SCA touchpoint and isolate those that assume a smartphone — an accessible alternative belongs there first.
  • Begin collecting the behavioural data future authentication models will need; it cannot be backfilled.
  • Treat Verification of Payee as a data-matching project on inbound and outbound transfers alike, and budget for false-positive tuning.
  • Put the PSD3 licence re-authorisation, AML/KYC evidence included, on the 2026 roadmap rather than the 2027 one.

FAQ

What is the difference between PSD3 and the PSR?

Licensing of payment and e-money institutions sits in PSD3, a directive that member states must transpose. Conduct — strong customer authentication, fraud, transparency — sits in the PSR, a regulation that applies directly across the EU with no national transposition. Most fintechs feel both at the same time.

When do PSD3 and the PSR apply?

Political agreement came in November 2025; the texts were published in April 2026. Most obligations apply roughly 21 months after publication in the Official Journal, so the earliest window is the second half of 2027, and some duties stretch into 2028. Verification of Payee applies 24 months after the regulation enters into force.

Does the PSR require biometric authentication?

Biometrics are not forced by the PSR. The text does explicitly allow strong customer authentication built from physiological biometrics (fingerprint, facial recognition) and behavioural biometrics (typing and touch patterns). It also requires at least one authentication method that works for customers without a smartphone, with disabilities, or with low digital skills.

What is Verification of Payee under the PSR?

The payer's payment service provider must check that the payee's name matches the account identifier (IBAN) before a transfer, and must warn the payer of any mismatch. Botch that check and fraud liability can shift to the provider. The duty applies 24 months after the regulation enters into force.

How does PSD3 affect KYC obligations?

To obtain or renew authorisation, payment and e-money institutions must evidence robust AML and KYC frameworks under PSD3. Beyond licensing, the PSR's biometric and behavioural SCA is identity verification performed continuously, and strong onboarding identity checks remain the most effective control against the mule and synthetic accounts that drive payment fraud.

Automate your compliance with AI Agents

Joinble's Agentic Identity platform reduces manual KYC reviews by up to 80%. Book a demo to see it in action.

Book a demo