PSD2 and SCA Compliance in Gambling Payments

Information only. This is not legal advice. The focus is EEA and UK markets.

It is 01:07. A player tries to make a small top‑up on a phone. The screen hangs. A soft decline pops up. A 3‑D Secure challenge comes next. The code does not arrive in time. The player gives up and goes to sleep. The bet never happens.

At the same time, a payments manager watches the dashboard. Challenge rate up. Approval rate down. BIN mix looks normal. Night traffic again. The team tries another acquirer. It helps a bit, then drops again. Rules are clear on paper, but card issuers do not see gambling like retail.

PSD2 and SCA in one page: the bits that matter

PSD2 is an EU law for payment services. It sets rules to make online payments safe. SCA (Strong Customer Authentication) is a key PSD2 rule. It asks for two or more factors: something the user knows, is, or has. Cards need SCA for most online payments in the EEA. The UK has its own rules that match PSD2 in most parts. For a plain‑language intro, see the official PSD2 overview by the European Commission.

The detailed tech rules sit in the EBA’s RTS (Regulatory Technical Standards). These tell banks and PSPs how to do SCA and how to talk to each other in a secure way. Read the source here: RTS on SCA and secure communication.

Jargon decoder (fast)

  • SCA: Strong Customer Authentication (two factors).
  • RTS: Tech rules that support PSD2 and SCA.
  • 3DS2: EMV 3‑D Secure, the main SCA flow for cards.
  • PIS: Payment Initiation Service (Open Banking A2A).
  • TRA: Transaction Risk Analysis (an SCA exemption if fraud is low).
  • MIT: Merchant‑Initiated Transaction (after an earlier SCA).

Three awkward truths in iGaming

First: card payments for gambling live under MCC 7995. This code marks high risk. It leads to more checks and fewer frictionless approvals than retail. Even good players can face a challenge step.

Second: issuers do not act the same. One bank may allow a low‑value exemption. Another bank may still ask for SCA. Your stats will swing by country, bank, hour, and device.

Third: players move. They switch phones. They travel. They use VPNs. This raises false positives. It triggers more step‑ups. For rule nuance and edge cases, the EBA Single Rulebook Q&A on SCA is a solid source.

What actually counts as SCA in real life

Most card payments use EMV 3‑D Secure (3DS2). It can be frictionless (no visible step) if the issuer is happy with the risk data. If the issuer wants more proof, it sends a challenge. A challenge can be a bank app push, a code by SMS, or a biometric check. Learn the base spec at EMV 3‑D Secure.

3DS2.2 supports nicer flows: app‑to‑app hand‑off and trusted beneficiaries. Visa and Mastercard give clear tips for setup and data fields. See Visa Secure merchant guidance and Mastercard Identity Check.

Where SCA applies — and where it does not

Scope in simple terms:

  • In scope: most online card payments in the EEA and UK, and Open Banking PIS (built‑in SCA).
  • Out of scope: mail/telephone orders (MOTO), some corporate cards, and some one‑leg‑out cases.
  • Special cases: MIT and subscriptions (after an initial SCA), low‑value payments, trusted beneficiaries.

The UK rules track PSD2 but sit under the FCA. The best plain guide is here: FCA guidance on SCA. For legal text, read the UK Payment Services Regulations 2017.

Which SCA rules apply to each payment rail (and what you can tune)

Card (3DS2) Yes, in EEA/UK TRA, low‑value, trusted beneficiaries Issuer app hops, SMS code delay, night‑time step‑ups 3DS2.2, rich data, scheme tokens, smart routing Fewer frictionless approvals than retail; expect higher challenge rate
Open Banking PIS (A2A) Yes, built‑in by bank N/A (SCA is part of the flow) Bank hand‑off drop‑off, app switch confusion Clear copy, bank logos, instant receipt, refund SLA No chargebacks; watch coverage and refund ops
Wallets with card funding Usually at top‑up Wallet risk controls; issuer TRA if card on file Extra app loops, forgotten passcodes Device binding, network tokens, clarify who charges Funding source drives SCA; label it well for support
MIT (recurring / merchant‑initiated) Initial SCA, then exempt if flagged right MIT framework, subscription logic Wrong flags → soft declines, “fraud” false hits Correct MIT flags, clear mandate text, retries logic Not ideal for ad‑hoc top‑ups; better for set budgets
MOTO (phone orders) Out of scope for SCA N/A Regulatory limits, compliance risk Use only when rules allow; record calls Rare in regulated iGaming; avoid unless approved

Exemptions that survive contact with gambling traffic

Low‑value (under €30) can pass without a challenge, but issuers track counters. After a few uses, SCA will fire again. Trusted beneficiaries (whitelisting) help repeat players who use one brand often, but take care with consent and clear copy. MIT works when the first payment had SCA and follow‑ups use the right flags and IDs.

TRA is the one teams ask for first. It lets an acquirer apply risk checks and skip SCA if fraud stays below set limits. But the issuer can still step in and ask for SCA. For fraud stats and thresholds, see the EBA’s Guidelines on fraud reporting under PSD2.

Design the player journey so SCA does not kill conversion

Start before the auth. Bind the device. Watch for fast repeat tries. Flag risky patterns early. When a challenge will likely happen, set the player up with clear, short copy. Tell them the bank may switch to the bank app. Tell them how to come back. Keep the bet slip state so the user does not lose context.

Use local cues. Many banks now push a face or thumb ID check in the issuer app. Yours is a hand‑off. Make it smooth: same button text, same tone, progress bar. If the app fails, let the player retry or switch to SMS. If you support passkeys on your side, explain them in plain words. See the FIDO passkeys basics for how users think about this step.

Micro checklist for build teams

  • Show the bank name and logo before hand‑off.
  • Use one clear CTA per step; no tiny grey links.
  • Keep the cart/bet slip alive across the app switch.
  • Log step‑up latency and drop‑off points.
  • Offer fallbacks (push → SMS) with one tap.
  • Explain trusted beneficiaries in simple words.

Issuer diversity and smart routing

Not all acquirers talk to all issuers in the same way. Have at least two acquirers for your top markets. Use network tokens where you can. Keep 3DS2.2 on. Monitor challenge rate, approval rate, and soft decline reasons by issuer BIN and by hour. A good guide for merchant best practice lives at UK Finance SCA resources.

Open Banking as your second rail

Account‑to‑account (A2A) via PIS is strong in the UK and parts of the EEA. SCA is built in by the bank, so you do not manage 3DS here. Players pick the bank, switch to the bank app, confirm, and come back. It can beat cards at night or with banks that hate MCC 7995. For a clear intro, see What is Open Banking.

Pros: no chargebacks, faster funds, and clear balances. Cons: refunds need good ops, some banks have poor UX, and coverage can vary. For key markets, add A2A as a first‑class option, not hidden in “other.” Teach players the flow with two lines of text and bank logos they trust.

Compliance checklist that will not age fast

  • Map your SCA scope by rail and market (EEA vs UK).
  • Upgrade to 3DS2.2; send rich risk data with each auth.
  • Test TRA with acquirers; review fraud KPIs every quarter.
  • Write issuer‑app friendly copy; explain the hand‑off.
  • Tokenise cards when you can; enable multi‑acquirer routing.
  • Add Open Banking PIS; teach the bank hand‑off in plain words.
  • Flag MIT right; store and show clear mandate text.
  • Track challenge rate, soft declines, approvals by BIN/issuer; iterate monthly.
  • Keep a short SCA help page for players; reduce support tickets.

The near future: PSD3/PSR and UK shifts

The EU is moving from PSD2 to PSD3 and a new Payment Services Regulation (PSR). Goals: less fraud, fewer failed auths, better data, and safer access to accounts. Keep an eye on the PSD2 review proposals. In the UK, SCA is now live and stable, but consumer duty pushes clearer UX. Expect more issuer app flows and fewer SMS codes.

Mini case note (anonymised)

A licensed EU operator saw a 28% challenge rate on cards and 74% approval. Night hours were worse. They added a second acquirer, turned on 3DS2.2 data fields, and changed copy to prime the bank app step. They also offered A2A in the deposit modal when 3DS step‑up latency passed 6 seconds.

After eight weeks: challenge rate fell to 19–21% by hour, card approval rose to 83–85%, and A2A took 18% of night deposits with 94% completion. Support tickets on “code did not arrive” dropped by half.

Buyer’s guide: pick PSPs and brands that show their work

Ask PSPs for issuer‑level stats and how they treat MCC 7995. Check their support for 3DS2.2 features (app‑to‑app, trusted beneficiaries) and tokens. For the brands you promote or run, check that player‑facing pages match licence rules and payment claim text. The UK rules live in the Licence Conditions and Codes of Practice (LCCP).

If you want to see how real deposits behave, not just what a promo page says, look at independent test results. We run live checks on deposit and withdrawal UX and publish clear notes. You can compare brands and flows at www.easyplay.vegas.

FAQ

Is SCA required for gambling card deposits in the UK?

Yes. The UK applies SCA to most online card payments. Some exemptions may apply, but the issuer can still ask for a step‑up.

Does SCA apply to withdrawals?

SCA is about paying out of a bank account or card. Withdrawals are payouts to the player. SCA is not the key step there, but KYC and AML checks still apply.

Are recurring top‑ups exempt under MIT?

Only after an initial SCA. You must flag MIT right and keep mandate text clear. The issuer can decline if flags are wrong.

What is TRA in practice?

TRA lets an acquirer skip SCA if its fraud stays below set levels. It is not a right. Issuers can still require a challenge.

How is Open Banking SCA different from card SCA?

With A2A, the bank runs SCA in its own app or site. You do not manage 3DS, and there are no card chargebacks. Refunds use your own process.

Why do SCA challenges spike at night?

Issuers push more checks when risk is higher. Night use, travel, new devices, and VPNs all push risk up.

Is instant A2A the same as SEPA Instant?

Not always. A2A PIS can use standard SEPA or SEPA Instant rails. For the instant scheme details, see the EPC page on SEPA Instant Credit Transfer.

Author: Editorial Team
Reviewed by: Compliance and Payments Editor
Last updated: 27 July 2026