GR-6.3.15

Past version: Effective from 01 Apr 2019 to 30 Jun 2021
To view other versions open the versions tab on the right

Conventional retail bank licensees, AISPs and PISPs must ensure that the elements referred to in Paragraph GR-6.3.14 are independent, so that the breach of one does not compromise the reliability of the others, in particular, when any of these elements are used through a multi-purpose device, i.e. a device such as a tablet or a mobile phone which can be used for both giving the instruction to make the payment and for being used in the authentication process. The CBB will consider exempting from a 3 factor authentication on a case to case basis.

Added: April 2019