Strong Customer Authentication, usually shortened to SCA, is the set of extra checks your bank or card issuer must carry out when you shop or bank online. In practice it means that when you press "pay" at an online checkout, or log in to your account, you may be asked to confirm it is really you, using your banking app, a code sent by text, an automated phone call or a card reader. The rules were introduced to help further reduce fraud and protect customers when purchasing online1, and by law all banks need to have this extra layer of security for their customers2.
The checks are now a routine part of online life. In the Financial Conduct Authority's 2024 survey, 75% of UK adults recalled Strong Customer Authentication the last time they made an online card payment3. For you, it means more protection when you are shopping and banking online, with extra checks to prove it is really you and help keep you safer from online fraud2. The legal definition comes from the Payment Services Regulations 2017: authentication based on the use of two or more elements that are independent, in that the breach of one element does not compromise the reliability of any other element4.
What Strong Customer Authentication is and why banks use it
Strong Customer Authentication has been introduced across all banks in the UK5. It is not a marketing feature or an optional extra that your bank has chosen to add: it is a legal requirement, and every provider of payment services in the UK must apply it in the situations the rules set out. The purpose is straightforward. Online card fraud works when a criminal has enough of your details to pretend to be you, and SCA is designed to make that much harder by demanding proof from two separate categories of evidence before money moves.
The reason banks ask more often than they used to is that the law changed. Because of the new banking regulations, banks ask you to confirm your identity and approve transactions more often8. The rules were phased in over a long period: the original enforcement date was March 2021, but the FCA allowed an extension to 14 September 2021, with a gradual ramp up from 1 February 2021 and all journeys starting on 1 June 20211. Since then, the checks have been a permanent part of online shopping and banking.
For a consumer, the practical effect is that an online purchase now often has a second step. You enter your card details as before, and then, depending on your bank, a screen appears asking you to open your banking app, or a text arrives with a code to type in. Some purchases will be exempt from authentication, decided by analysis of the level of risk involved9, which is why you are not asked every single time. The system behind the screen may be branded Visa Secure (formerly known as Verified by Visa) or Mastercard Identity Check, but the underlying requirement is the same legal one.
Two of three: something you know, have or are
The core of SCA is a simple idea. There are three ways you can verify yourself: "something you know", "something you have" and "something you are"5. You need to provide two of these three ways to verify it is you, which is called two-factor authentication5. The same three-part structure appears across the industry: Halifax describes the categories as a piece of secret information only you know, like your password, alongside something you have and something you are10.
| Category | What it means | Examples given by providers |
|---|---|---|
| Something you know | Information only you know | A password, PIN or security number11 |
| Something you have | An object only you hold | Your card or phone12 |
| Something you are | A physical characteristic unique to you | Fingerprint, facial recognition, voice pattern13 |
The legal wording matters because it explains why two factors are needed rather than one. The regulations define strong customer authentication as authentication based on the use of two or more elements that are independent, in that the breach of one element does not compromise the reliability of any other element14. A password alone is "something you know", but if a criminal steals it, nothing else stands in their way. Pair the password with a code sent to your phone, and the criminal needs both the secret and the physical object. NS&I describes the same principle for its customers: two-factor authentication uses at least two of three different types of identification information, or factors13.
The pairing does not have to be the same for everyone. One person might approve a payment with a fingerprint in an app, combining "something you are" with the phone they hold. Another might type a password and then a texted passcode, combining "something you know" with "something you have". What the rules demand is that the two elements come from different categories and that beating one does not help a criminal beat the other14.
When you will be asked to verify a payment
The law sets out exactly when your provider must apply the checks. A payment service provider must apply strong customer authentication where a payment service user accesses their payment account online, initiates an electronic payment transaction, or carries out any action through a remote channel which may imply a risk of payment fraud or other abuses15. In everyday terms, that covers three situations: logging in to online banking, making an electronic payment, and doing anything else online that could open the door to fraud, such as changing your details or adding a new payee.
Not every payment triggers a visible check. Your issuer assesses the risk of each transaction and may apply an exemption for low-value or low-risk payments1. This is why some online purchases go through with no prompt at all, while others stop and ask. The pattern also reflects your own behaviour: Visa Secure works in the background to automatically verify your card details at participating retailers, and may ask for a one-time passcode only if the purchase seems unusual or outside your normal spending pattern16.
There is an important protection built into the rule. Where the regulations require strong customer authentication but your provider does not apply it, you are not liable for the resulting unauthorised payment, except where you acted fraudulently7. In other words, the duty to run the checks sits with the bank, and the bank bears the consequences of skipping them. If money leaves your account in a situation where SCA should have been applied and was not, challenge any suggestion that the loss is yours. The dedicated page on credit card fraud and unauthorised payments explains how to do that.
Ways to approve a payment: app, text, call or card reader
Providers offer several ways to complete the checks, and most offer more than one, so a customer without a mobile phone is not shut out of online shopping. Lloyds lists three: use the app to verify your purchase, receive a text passcode to your mobile phone which you then enter, or take a call2. Its fuller guidance adds a fourth option: an automated call to your landline or mobile, and the option to use the app on a tablet device to verify a payment if you cannot receive a text or a phone call17.
| Method | How it works | Who it suits |
|---|---|---|
| Banking app | Confirm with Face ID, Touch ID, a fingerprint or your app passcode18 | Customers who use their bank's app regularly |
| Text message | A one-time passcode is texted to your registered mobile number19 | Customers with a mobile phone |
| Automated call | A passcode is read out in a voice message to your mobile or UK landline17 | Customers without a mobile, including landline-only households |
| Card reader | Where the bank issues one, it is used with the card to generate a code | Customers of banks that provide readers |
The app route is what most banks point to first. TSB asks customers to confirm payments in its mobile banking app if they regularly use the app, or by a one-time password sent to a mobile or UK landline18. Bank of Ireland UK tells customers the easiest way to approve an online purchase will be using its banking app, and to make sure notifications are enabled so the prompt reaches you20. Ulster Bank says that if you have the app, you will need to use face ID, fingerprint or your app passcode to confirm the transaction, and for customers without the app or without a mobile phone, one-time passcodes can come by text message or email, or you can call to approve the transaction8.
If you have no mobile phone at all, the key step is to make sure your bank has another way to reach you. Passcodes are sent to the contact details your bank holds, so they only work if those details are up to date8. Register a landline number, ask about email delivery, or ask your bank what its alternative process is. Some banks also let you update your details in branch16. For customers in particularly difficult circumstances, such as those fleeing economic abuse who need to open a new bank account safely, guidance exists on arranging banking access, including how a trusted device arrangement works: if one device is registered as the trusted device, any other device used to attempt access will still need verification21.
One-time passcodes: how long they last and how to use them
A one-time passcode, or OTP, is a unique number sent by text message or automated voice message to verify your identity22. NS&I describes the format its customers receive: a unique 6-digit number which, for added security, will only work for a short amount of time13. Cumberland Building Society is more specific about its own Visa Secure codes: each code expires after 5 minutes16. Expiry times are set by each provider, so treat any code as something to use immediately rather than save.
Using a passcode safely is mostly a matter of treating it like your PIN. Take Five, the national anti-fraud campaign, is direct about this: protect your one-time passcodes, treat them as carefully as you would your PIN, and read any messages in full to check what you are approving23. The reason for reading the whole message is that the text often names the shop and the amount, so a quick glance tells you whether the code is for the purchase you are actually making or for something else entirely.
A few practical points recur across providers' guidance:
- Keep your registered mobile number up to date, since it is important you do so to make sure you receive OTPs22.
- A registered mobile number is needed for some services: without one, you may not be able to make online purchases using Visa Secure16.
- Codes are single use. A one-time passcode is a unique number for one verification, not a standing password22.
- Never share it. The same campaign guidance applies to every provider: treat the code as carefully as your PIN24.
If a code does not arrive, check your signal and your inbox first, then check that your bank holds the right number for you. If you enter a wrong passcode repeatedly, expect a lock: one building society locks the account after three incorrect entries of a password, memorable word or passcode, until identity is verified by phone or in branch25. That lock is a security measure protecting your money, and your bank will unlock access once it has confirmed it is you.
Where SCA does not apply: low-value, low-risk and merchant-initiated payments
Not every payment needs the full checks. The law and the industry guidance both carve out categories, and knowing roughly where the boundaries sit explains why your experience differs from purchase to purchase. Some purchases will be exempt from authentication, decided by analysis on the level of risk involved9. Importantly, merchants cannot apply SCA exemptions in their own right: exemptions are applied by the payer's own payment provider1. So the shop does not decide to skip the check on your payment, your bank does.
The main categories outside the requirement are:
- Merchant-initiated transactions. Payee or card-based merchant-initiated transactions are out of scope of the requirement for SCA and do not need to rely on an exemption1. These are payments the shop triggers itself under an agreement you gave earlier, such as a subscription renewal, rather than one you approve at a checkout each time.
- Direct debits. Direct debits of fixed or variable amount that are initiated by the payee only, without any direct intervention from the payer, are out of scope, although creating an e-mandate for the direct debit does require SCA1.
- Card-present payments. Card present transactions, such as chip and PIN in a shop, do not require dynamic linking1. You have already authenticated yourself with your PIN.
- Low-risk analysis. Your issuer may assess a transaction as low risk and let it through without a prompt1.
For recurring card payments, your consent matters too. FCA guidance says your consent should be clear, specific and informed for it to be valid, with enough information about the amount and frequency of the payments26. That sits alongside the SCA rules: the first payment you approve at a checkout may need full authentication, while later payments taken by the merchant under that consent fall outside the requirement.
One point worth knowing about how the checks bind a payment to its details. For remote payments, the authentication code generated must be specific to the amount of the payment transaction and the payee1. This is dynamic linking, and it is why the text or app prompt shows you the amount and the shop before you approve. If the amount decreases after authentication, current FCA guidance confirms this will not invalidate the authentication code1. The page on recurring card payments and the wider guide to how credit cards work cover the protections that apply to the payments themselves.
Scam warning signs: never share a passcode
The security checks work so well that criminals now try to hijack them rather than bypass them. Which? reported on fraudsters exploiting the new online security checks with phishing attacks, expecting more to surface during the phased implementation of SCA27. The pattern is simple: a criminal contacts you, claims to be your bank or a retailer, and asks you to read out the passcode that has just arrived on your phone. The criminal then uses that code to approve a payment from your account, and because the code is genuine and the payment is "authenticated", it can look legitimate from the bank's side.
The rule that defeats this is absolute: never share a passcode. Take Five's card fraud guidance warns that criminals will try to trick you into sharing your one-time passcode, and says to treat it as carefully as you would your PIN28. A genuine bank or organisation will never contact you out of the blue to ask for your PIN, full password or to move money to another account29. Receiving sign-in codes when you were not trying to sign in is itself a warning sign: HMRC's guidance notes that if you receive sign-in codes when you are not trying to sign in, it may mean someone has your sign in details, and changing your password would be sensible30.
The warning signs to act on:
- A passcode you did not request. One-time passcodes you did not request are a warning sign of digital wallet fraud24.
- An unexpected call, text or email asking for codes or details. Never give away your financial information over the phone31, and never give out personal information, which can be used to steal your identity and access accounts32.
- Pressure and urgency. Always question uninvited approaches, and never automatically click a link in an unexpected email or text29.
- Weak account hygiene. Do not use the same password for more than one account, and never use banking passwords on other websites33.
If a code arrives for a purchase you did not make, do not enter it anywhere and do not read it to anyone. Check your account for payments you do not recognise. You are not liable for any unauthorised payments taken after you tell the bank that your card has been stolen or that someone else has got hold of your security details34. The guides to scams and fraud and chargeback set out the full routes to getting money back.
The rules behind SCA: PSD2 and the Payment Services Regulations
The legal foundation is the Payment Services Regulations 2017, the UK's implementation of the second Payment Services Directive, known as PSD2. The revised directive took effect in the UK in January 201835, and the regulations require stronger customer authentication to reduce the risk of fraud36. The regulations define strong customer authentication as authentication based on the use of two or more elements that are independent, in that the breach of one element does not compromise the reliability of any other element, drawn from the categories of knowledge, possession and inherence14. The FCA's own handbook guidance for banks points firms towards the adoption of strong customer authentication as defined in the Payment Services Regulations37.
The rules also changed what happens when things go wrong. Since January 2018, when people complain about payment services, businesses need to give their final response within 15 days, rather than the eight weeks they had previously35. Complaints that the business cannot resolve can go to the Financial Ombudsman Service, and the page on complaining about a credit card provider explains that route.
Two consumer-facing rules arrived alongside the authentication requirements. From 13 January 2018, shops are not allowed to charge their customers extra if they pay using certain payment methods6, a ban explained in full on the page about the surcharge ban. And the directive itself excludes certain payments from its scope, such as cash-only transactions, cheques and drafts6, which is why the security checks belong to the world of cards and electronic payments rather than every way of paying.
Sources39 cited
- Strong Customer Authentication frequently asked questions UK Finance, 2026
- Security checks Lloyds Bank, 2026-09-27
- Financial Lives 2024: payments survey Financial Conduct Authority, 2024-05
- The Payment Services Regulations 2017 legislation.gov.uk, 2017-07-18
- Security checks FAQs Bank of Scotland, 2026-09-27
- The IFR and consumers Payment Systems Regulator, 2018-01-13
- Regulation 77 of the Payment Services Regulations 2017 legislation.gov.uk, 2026
- Strong Customer Authentication Ulster Bank, 2026-09-25
- Frequently asked questions NBK London, 2026
- Security checks Halifax, 2026-09-27
- Strong Customer Authentication RBS International, 2026-09-25
- Strong Customer Authentication Santander, 2026
- Improved security NS&I, 2024-05-21
- The Payment Services Regulations 2017, PDF legislation.gov.uk, 2017-07-18
- The Payment Services Regulations 2017, Part 7 legislation.gov.uk, 2017
- Visa Secure Cumberland Building Society, 2026
- Extra security explained Lloyds Bank, 2026-09-27
- Strong Customer Authentication TSB, 2026
- Visa Secure Cynergy Bank, 2026-09-25
- Strong Customer Authentication Bank of Ireland UK, 2026-09-25
- Opening a new bank account safely Surviving Economic Abuse, 2023-11
- One-time passcodes Cumberland Building Society, 2026
- Type don't tap Take Five to Stop Fraud, 2026-09-26
- Digital wallet fraud Take Five to Stop Fraud, 2026-09-26
- Staying safe online Cambridge Building Society, 2026-09-26
- Recurring card payments Financial Conduct Authority, 2025-06-23
- Scam alert: fraudsters exploit new online security checks with phishing attacks Which?, 2019-09-03
- Card fraud protection Take Five to Stop Fraud, 2026-09-26
- Thomas Cook refund calls and messages: is it a scam or the real deal? Which?, 2019-09-25
- Keeping your HMRC login details safe GOV.UK, 2022-10-28
- 5 phone scams to know about right now Which?, 2025-07-16
- Protecting yourself from scams nidirect, 2021-07-02
- Identity theft Finance and Leasing Association, 2026-09-25
- Dealing with fraud Business Debtline, 2026-09-26
- Full review 2018 Financial Ombudsman Service, 2018
- Payment Services Regulations 2017 Which?, 2025-06-18
- BCOBS 5 FCA Handbook, 2018
- Confirm my purchase AIB (NI), 2026
- I want to return something bought online Which?, 2026-03-10







MoneyHelperFree, impartial money and pensions guidance, set up by government
StepChangeFree debt advice and solutions from a charity
National DebtlineFree debt advice by phone, webchat and online
Financial Ombudsman ServiceFree, independent help when a complaint about a firm is not put right
Citizens AdviceFree advice on money, consumer and legal problems in England and Wales