Strong Customer Authentication for card payments

When you buy something online, your bank may ask you to approve the payment with an app, a text code or a phone call. This is Strong Customer Authentication, a legal requirement across the UK. Here is how the checks work, when they apply, what to do if you have no mobile, and how to spot the scams that copy them.

Strong Customer Authentication for card payments

Strong Customer Authentication, usually shortened to SCA, is the set of extra checks your bank or card issuer must carry out when you shop or bank online. In practice it means that when you press "pay" at an online checkout, or log in to your account, you may be asked to confirm it is really you, using your banking app, a code sent by text, an automated phone call or a card reader. The rules were introduced to help further reduce fraud and protect customers when purchasing online1, and by law all banks need to have this extra layer of security for their customers2.

The checks are now a routine part of online life. In the Financial Conduct Authority's 2024 survey, 75% of UK adults recalled Strong Customer Authentication the last time they made an online card payment3. For you, it means more protection when you are shopping and banking online, with extra checks to prove it is really you and help keep you safer from online fraud2. The legal definition comes from the Payment Services Regulations 2017: authentication based on the use of two or more elements that are independent, in that the breach of one element does not compromise the reliability of any other element4.

What Strong Customer Authentication is and why banks use it

Strong Customer Authentication has been introduced across all banks in the UK5. It is not a marketing feature or an optional extra that your bank has chosen to add: it is a legal requirement, and every provider of payment services in the UK must apply it in the situations the rules set out. The purpose is straightforward. Online card fraud works when a criminal has enough of your details to pretend to be you, and SCA is designed to make that much harder by demanding proof from two separate categories of evidence before money moves.

The reason banks ask more often than they used to is that the law changed. Because of the new banking regulations, banks ask you to confirm your identity and approve transactions more often8. The rules were phased in over a long period: the original enforcement date was March 2021, but the FCA allowed an extension to 14 September 2021, with a gradual ramp up from 1 February 2021 and all journeys starting on 1 June 20211. Since then, the checks have been a permanent part of online shopping and banking.

For a consumer, the practical effect is that an online purchase now often has a second step. You enter your card details as before, and then, depending on your bank, a screen appears asking you to open your banking app, or a text arrives with a code to type in. Some purchases will be exempt from authentication, decided by analysis of the level of risk involved9, which is why you are not asked every single time. The system behind the screen may be branded Visa Secure (formerly known as Verified by Visa) or Mastercard Identity Check, but the underlying requirement is the same legal one.

Two of three: something you know, have or are

The core of SCA is a simple idea. There are three ways you can verify yourself: "something you know", "something you have" and "something you are"5. You need to provide two of these three ways to verify it is you, which is called two-factor authentication5. The same three-part structure appears across the industry: Halifax describes the categories as a piece of secret information only you know, like your password, alongside something you have and something you are10.

CategoryWhat it meansExamples given by providers
Something you knowInformation only you knowA password, PIN or security number11
Something you haveAn object only you holdYour card or phone12
Something you areA physical characteristic unique to youFingerprint, facial recognition, voice pattern13

The legal wording matters because it explains why two factors are needed rather than one. The regulations define strong customer authentication as authentication based on the use of two or more elements that are independent, in that the breach of one element does not compromise the reliability of any other element14. A password alone is "something you know", but if a criminal steals it, nothing else stands in their way. Pair the password with a code sent to your phone, and the criminal needs both the secret and the physical object. NS&I describes the same principle for its customers: two-factor authentication uses at least two of three different types of identification information, or factors13.

The pairing does not have to be the same for everyone. One person might approve a payment with a fingerprint in an app, combining "something you are" with the phone they hold. Another might type a password and then a texted passcode, combining "something you know" with "something you have". What the rules demand is that the two elements come from different categories and that beating one does not help a criminal beat the other14.

A banking app asking the customer to approve an online purchase before it goes through.

When you will be asked to verify a payment

The law sets out exactly when your provider must apply the checks. A payment service provider must apply strong customer authentication where a payment service user accesses their payment account online, initiates an electronic payment transaction, or carries out any action through a remote channel which may imply a risk of payment fraud or other abuses15. In everyday terms, that covers three situations: logging in to online banking, making an electronic payment, and doing anything else online that could open the door to fraud, such as changing your details or adding a new payee.

Not every payment triggers a visible check. Your issuer assesses the risk of each transaction and may apply an exemption for low-value or low-risk payments1. This is why some online purchases go through with no prompt at all, while others stop and ask. The pattern also reflects your own behaviour: Visa Secure works in the background to automatically verify your card details at participating retailers, and may ask for a one-time passcode only if the purchase seems unusual or outside your normal spending pattern16.

There is an important protection built into the rule. Where the regulations require strong customer authentication but your provider does not apply it, you are not liable for the resulting unauthorised payment, except where you acted fraudulently7. In other words, the duty to run the checks sits with the bank, and the bank bears the consequences of skipping them. If money leaves your account in a situation where SCA should have been applied and was not, challenge any suggestion that the loss is yours. The dedicated page on credit card fraud and unauthorised payments explains how to do that.

Ways to approve a payment: app, text, call or card reader

Providers offer several ways to complete the checks, and most offer more than one, so a customer without a mobile phone is not shut out of online shopping. Lloyds lists three: use the app to verify your purchase, receive a text passcode to your mobile phone which you then enter, or take a call2. Its fuller guidance adds a fourth option: an automated call to your landline or mobile, and the option to use the app on a tablet device to verify a payment if you cannot receive a text or a phone call17.

MethodHow it worksWho it suits
Banking appConfirm with Face ID, Touch ID, a fingerprint or your app passcode18Customers who use their bank's app regularly
Text messageA one-time passcode is texted to your registered mobile number19Customers with a mobile phone
Automated callA passcode is read out in a voice message to your mobile or UK landline17Customers without a mobile, including landline-only households
Card readerWhere the bank issues one, it is used with the card to generate a codeCustomers of banks that provide readers

The app route is what most banks point to first. TSB asks customers to confirm payments in its mobile banking app if they regularly use the app, or by a one-time password sent to a mobile or UK landline18. Bank of Ireland UK tells customers the easiest way to approve an online purchase will be using its banking app, and to make sure notifications are enabled so the prompt reaches you20. Ulster Bank says that if you have the app, you will need to use face ID, fingerprint or your app passcode to confirm the transaction, and for customers without the app or without a mobile phone, one-time passcodes can come by text message or email, or you can call to approve the transaction8.

If you have no mobile phone at all, the key step is to make sure your bank has another way to reach you. Passcodes are sent to the contact details your bank holds, so they only work if those details are up to date8. Register a landline number, ask about email delivery, or ask your bank what its alternative process is. Some banks also let you update your details in branch16. For customers in particularly difficult circumstances, such as those fleeing economic abuse who need to open a new bank account safely, guidance exists on arranging banking access, including how a trusted device arrangement works: if one device is registered as the trusted device, any other device used to attempt access will still need verification21.

One-time passcodes: how long they last and how to use them

A one-time passcode, or OTP, is a unique number sent by text message or automated voice message to verify your identity22. NS&I describes the format its customers receive: a unique 6-digit number which, for added security, will only work for a short amount of time13. Cumberland Building Society is more specific about its own Visa Secure codes: each code expires after 5 minutes16. Expiry times are set by each provider, so treat any code as something to use immediately rather than save.

Using a passcode safely is mostly a matter of treating it like your PIN. Take Five, the national anti-fraud campaign, is direct about this: protect your one-time passcodes, treat them as carefully as you would your PIN, and read any messages in full to check what you are approving23. The reason for reading the whole message is that the text often names the shop and the amount, so a quick glance tells you whether the code is for the purchase you are actually making or for something else entirely.

A few practical points recur across providers' guidance:

  • Keep your registered mobile number up to date, since it is important you do so to make sure you receive OTPs22.
  • A registered mobile number is needed for some services: without one, you may not be able to make online purchases using Visa Secure16.
  • Codes are single use. A one-time passcode is a unique number for one verification, not a standing password22.
  • Never share it. The same campaign guidance applies to every provider: treat the code as carefully as your PIN24.

If a code does not arrive, check your signal and your inbox first, then check that your bank holds the right number for you. If you enter a wrong passcode repeatedly, expect a lock: one building society locks the account after three incorrect entries of a password, memorable word or passcode, until identity is verified by phone or in branch25. That lock is a security measure protecting your money, and your bank will unlock access once it has confirmed it is you.

Where SCA does not apply: low-value, low-risk and merchant-initiated payments

Not every payment needs the full checks. The law and the industry guidance both carve out categories, and knowing roughly where the boundaries sit explains why your experience differs from purchase to purchase. Some purchases will be exempt from authentication, decided by analysis on the level of risk involved9. Importantly, merchants cannot apply SCA exemptions in their own right: exemptions are applied by the payer's own payment provider1. So the shop does not decide to skip the check on your payment, your bank does.

The main categories outside the requirement are:

  • Merchant-initiated transactions. Payee or card-based merchant-initiated transactions are out of scope of the requirement for SCA and do not need to rely on an exemption1. These are payments the shop triggers itself under an agreement you gave earlier, such as a subscription renewal, rather than one you approve at a checkout each time.
  • Direct debits. Direct debits of fixed or variable amount that are initiated by the payee only, without any direct intervention from the payer, are out of scope, although creating an e-mandate for the direct debit does require SCA1.
  • Card-present payments. Card present transactions, such as chip and PIN in a shop, do not require dynamic linking1. You have already authenticated yourself with your PIN.
  • Low-risk analysis. Your issuer may assess a transaction as low risk and let it through without a prompt1.

For recurring card payments, your consent matters too. FCA guidance says your consent should be clear, specific and informed for it to be valid, with enough information about the amount and frequency of the payments26. That sits alongside the SCA rules: the first payment you approve at a checkout may need full authentication, while later payments taken by the merchant under that consent fall outside the requirement.

One point worth knowing about how the checks bind a payment to its details. For remote payments, the authentication code generated must be specific to the amount of the payment transaction and the payee1. This is dynamic linking, and it is why the text or app prompt shows you the amount and the shop before you approve. If the amount decreases after authentication, current FCA guidance confirms this will not invalidate the authentication code1. The page on recurring card payments and the wider guide to how credit cards work cover the protections that apply to the payments themselves.

Scam warning signs: never share a passcode

The security checks work so well that criminals now try to hijack them rather than bypass them. Which? reported on fraudsters exploiting the new online security checks with phishing attacks, expecting more to surface during the phased implementation of SCA27. The pattern is simple: a criminal contacts you, claims to be your bank or a retailer, and asks you to read out the passcode that has just arrived on your phone. The criminal then uses that code to approve a payment from your account, and because the code is genuine and the payment is "authenticated", it can look legitimate from the bank's side.

The rule that defeats this is absolute: never share a passcode. Take Five's card fraud guidance warns that criminals will try to trick you into sharing your one-time passcode, and says to treat it as carefully as you would your PIN28. A genuine bank or organisation will never contact you out of the blue to ask for your PIN, full password or to move money to another account29. Receiving sign-in codes when you were not trying to sign in is itself a warning sign: HMRC's guidance notes that if you receive sign-in codes when you are not trying to sign in, it may mean someone has your sign in details, and changing your password would be sensible30.

A passcode text, showing the details to check before entering the code: who sent it, what it is for, and the amount.

The warning signs to act on:

  • A passcode you did not request. One-time passcodes you did not request are a warning sign of digital wallet fraud24.
  • An unexpected call, text or email asking for codes or details. Never give away your financial information over the phone31, and never give out personal information, which can be used to steal your identity and access accounts32.
  • Pressure and urgency. Always question uninvited approaches, and never automatically click a link in an unexpected email or text29.
  • Weak account hygiene. Do not use the same password for more than one account, and never use banking passwords on other websites33.

If a code arrives for a purchase you did not make, do not enter it anywhere and do not read it to anyone. Check your account for payments you do not recognise. You are not liable for any unauthorised payments taken after you tell the bank that your card has been stolen or that someone else has got hold of your security details34. The guides to scams and fraud and chargeback set out the full routes to getting money back.

The rules behind SCA: PSD2 and the Payment Services Regulations

The legal foundation is the Payment Services Regulations 2017, the UK's implementation of the second Payment Services Directive, known as PSD2. The revised directive took effect in the UK in January 201835, and the regulations require stronger customer authentication to reduce the risk of fraud36. The regulations define strong customer authentication as authentication based on the use of two or more elements that are independent, in that the breach of one element does not compromise the reliability of any other element, drawn from the categories of knowledge, possession and inherence14. The FCA's own handbook guidance for banks points firms towards the adoption of strong customer authentication as defined in the Payment Services Regulations37.

The rules also changed what happens when things go wrong. Since January 2018, when people complain about payment services, businesses need to give their final response within 15 days, rather than the eight weeks they had previously35. Complaints that the business cannot resolve can go to the Financial Ombudsman Service, and the page on complaining about a credit card provider explains that route.

Two consumer-facing rules arrived alongside the authentication requirements. From 13 January 2018, shops are not allowed to charge their customers extra if they pay using certain payment methods6, a ban explained in full on the page about the surcharge ban. And the directive itself excludes certain payments from its scope, such as cash-only transactions, cheques and drafts6, which is why the security checks belong to the world of cards and electronic payments rather than every way of paying.

Sources39 cited
  1. Strong Customer Authentication frequently asked questions UK Finance, 2026
  2. Security checks Lloyds Bank, 2026-09-27
  3. Financial Lives 2024: payments survey Financial Conduct Authority, 2024-05
  4. The Payment Services Regulations 2017 legislation.gov.uk, 2017-07-18
  5. Security checks FAQs Bank of Scotland, 2026-09-27
  6. The IFR and consumers Payment Systems Regulator, 2018-01-13
  7. Regulation 77 of the Payment Services Regulations 2017 legislation.gov.uk, 2026
  8. Strong Customer Authentication Ulster Bank, 2026-09-25
  9. Frequently asked questions NBK London, 2026
  10. Security checks Halifax, 2026-09-27
  11. Strong Customer Authentication RBS International, 2026-09-25
  12. Strong Customer Authentication Santander, 2026
  13. Improved security NS&I, 2024-05-21
  14. The Payment Services Regulations 2017, PDF legislation.gov.uk, 2017-07-18
  15. The Payment Services Regulations 2017, Part 7 legislation.gov.uk, 2017
  16. Visa Secure Cumberland Building Society, 2026
  17. Extra security explained Lloyds Bank, 2026-09-27
  18. Strong Customer Authentication TSB, 2026
  19. Visa Secure Cynergy Bank, 2026-09-25
  20. Strong Customer Authentication Bank of Ireland UK, 2026-09-25
  21. Opening a new bank account safely Surviving Economic Abuse, 2023-11
  22. One-time passcodes Cumberland Building Society, 2026
  23. Type don't tap Take Five to Stop Fraud, 2026-09-26
  24. Digital wallet fraud Take Five to Stop Fraud, 2026-09-26
  25. Staying safe online Cambridge Building Society, 2026-09-26
  26. Recurring card payments Financial Conduct Authority, 2025-06-23
  27. Scam alert: fraudsters exploit new online security checks with phishing attacks Which?, 2019-09-03
  28. Card fraud protection Take Five to Stop Fraud, 2026-09-26
  29. Thomas Cook refund calls and messages: is it a scam or the real deal? Which?, 2019-09-25
  30. Keeping your HMRC login details safe GOV.UK, 2022-10-28
  31. 5 phone scams to know about right now Which?, 2025-07-16
  32. Protecting yourself from scams nidirect, 2021-07-02
  33. Identity theft Finance and Leasing Association, 2026-09-25
  34. Dealing with fraud Business Debtline, 2026-09-26
  35. Full review 2018 Financial Ombudsman Service, 2018
  36. Payment Services Regulations 2017 Which?, 2025-06-18
  37. BCOBS 5 FCA Handbook, 2018
  38. Confirm my purchase AIB (NI), 2026
  39. I want to return something bought online Which?, 2026-03-10

Related guides

Section 75: credit card purchase protection
Section 75 ProtectionExplains how Section 75 makes the card provider jointly liable for faulty goods or services and firms that fail.
The ban on credit card surcharges
Card Surcharge BanExplains the rules banning extra charges for paying by consumer card and the exceptions.

Frequently asked questions

Can I opt out of Strong Customer Authentication?

No. There is no way to opt out of SCA, because it is a legal requirement that applies to all banks in the UK. The checks exist to reduce fraud when you shop or bank online, and your card issuer must apply them when the rules require. If the checks are causing you difficulty, for example because you have no mobile phone, your bank has alternative ways to verify you, such as an automated call to a landline, so contact it to arrange a method that works for you.

What should I do if my one-time passcode does not arrive?

First check that your bank has your current mobile number, since passcodes are sent to the number registered to your account, and keeping it up to date is what makes sure the codes reach you. Poor signal or a full message inbox can also stop a code arriving. If it still does not come, some banks can send a passcode by email or let you approve the payment by an automated phone call instead. If you cannot receive texts at all, contact your bank to set up an alternative.

What happens if I enter the wrong passcode three times?

It depends on your provider, but a common outcome is that the account is locked after three incorrect entries of a password, memorable word or passcode, and stays locked until the provider has verified your identity by phone or in branch. This is a security measure, not a penalty. If it happens to you, call your bank using the number on the back of your card, and it will take you through the steps to unlock access.

Can an additional cardholder approve online payments?

The security checks are tied to the account holder's registered details, such as their mobile number and their banking app, so an additional cardholder may not be able to complete verification themselves. Each provider handles this differently, so check with the card issuer. If two people need to make online payments independently, the account holder may need to register the additional cardholder's details with the bank or the additional cardholder may need their own card account.

What does trusting a device mean for security checks?

Some banks let you mark a device, such as your own laptop, as trusted, which means they will not need to run the extra security checks the next time you log in from it. Only trust devices that are secure and used only by people you know, because anyone using that device afterwards may get easier access to your account. If another device is used to try to access the account, verification will still be needed. Clearing your browser data usually undoes the trust, and you will be asked to trust the device again.

Why did I get a passcode for a purchase I did not make?

A passcode you did not request is a warning sign that someone may be trying to use your card details or your account. Do not share the code with anyone. Check your account for payments you do not recognise, and if you find any, tell your bank straight away. Once you have told your bank that your card has been stolen or that someone has got hold of your security details, you are not liable for any unauthorised payments taken after that. Receiving sign-in codes you did not request can also mean someone has your login details, so changing your password is sensible.

Do shops charge extra for paying by card?

No. Since 13 January 2018 shops have not been allowed to charge customers extra for paying with certain payment methods, including cards. This ban came in alongside the wider payment services rules. If a retailer tries to add a surcharge for card payment, that is not permitted, and you can challenge it. The cost of the security checks is met by banks and card schemes, not by an extra charge at the till.