Introduction
Strong Customer Authentication (SCA) is a European payments-security requirement: two independent checks, not one, before specified payments or account logins go through. It comes from the EU's second Payment Services Directive (PSD2), implemented through Regulatory Technical Standards that applied from 14 September 2019. This review did not find an African regulator that has copied that framework wholesale.
That does not mean African banks and fintechs can ignore its logic. South Africa mandated a narrower 3-D Secure requirement for local e-commerce merchants years before PSD2 existed. Nigeria's central bank issued its own narrower directive in December 2025. And African institutions processing international card payments can face authentication obligations through Visa and Mastercard's own scheme rules, regardless of domestic law.
This guide explains what SCA actually requires, and where Africa's own rules already overlap with it. It also covers where the exposure sits for banks and fintechs that assume none of this applies to them.
What Is Strong Customer Authentication?
Under PSD2, payment service providers must generally apply SCA in three scenarios. These are when a payer accesses a payment account online, initiates an electronic payment, or carries out a remote action that could involve payment fraud. Exemptions can apply. SCA itself means using at least two of three independent authentication factors. The three factor categories are knowledge, possession, and inherence. Knowledge is something only the customer knows, like a PIN or password. Possession is something only the customer has, like a phone that receives a one-time code. Inherence is something the customer is, like a fingerprint or face. Youverify's own guide to multi-factor authentication covers how these factors work in practice across different implementation methods.
The elements must be independent: compromising one must not compromise the reliability of the others. A password stolen alongside its recovery email, for instance, does not satisfy SCA, since both live in the same knowledge category. The Regulatory Technical Standards behind PSD2's SCA rule, Commission Delegated Regulation (EU) 2018/389, applied from 14 September 2019. They also set out exemptions, including for low-value payments, trusted beneficiaries, recurring transactions, contactless payments, and transaction-risk analysis.
South Africa: PASA's 3D Secure Mandate
The Payments Association of South Africa (PASA) decided in February 2013 to require local e-commerce merchants to enrol in and activate 3-D Secure. This applied to card-not-present transactions.
The compliance deadline was 28 February 2014, more than five years before PSD2's SCA requirement applied in the EU. Mobile and app-based transactions got a six-month extension. 3-D Secure adds issuer-controlled authentication and risk assessment to card-not-present payments. Depending on the transaction, that authentication can be frictionless, or it can require a customer challenge such as an OTP, password, biometric, or app approval.
It is narrower than full PSD2 SCA: it addresses card-not-present payments specifically, not account access, other electronic payments, or PSD2's own exemption and monitoring requirements.
Nigeria: CBN's December 2025 Multi-Factor Authentication Circular
Nigeria's Central Bank issued a circular on 18 December 2025 directing banks and non-bank acquirers to implement multi-factor authentication for foreign-issued card transactions. As reported, it covers withdrawals and online transactions exceeding $200 per day, $500 per week, or $1,000 per month, or their naira equivalents.
It does not specify which authentication methods satisfy the requirement. It is also narrower than South Africa's rule: it targets foreign-card spending above set thresholds, not all card-not-present transactions. Nigerian news coverage reports the circular also addresses fraud-pattern monitoring, exchange-rate transparency, and chargeback documentation, alongside the authentication requirement.
Why This Matters Even Without a Formal SCA Law
Two things apply pressure regardless of domestic law. Card scheme rules and cross-border commercial arrangements are the first. Visa and Mastercard operate scheme rules and authentication programmes that can make 3-D Secure important for card-not-present payments, liability allocation, and cross-border acceptance.
The exact obligation depends on the transaction, the region, and the parties involved. It can still bind a Nigerian or Kenyan fintech processing international card payments, through its issuer, acquirer, or processor relationships. Connectivity is the second pressure, and it cuts the other way.
The World Bank's ID4D program notes that authentication method selection needs to account for connectivity and digital-literacy constraints. SMS-based one-time codes are the most common possession factor in African markets. They depend on network reliability that is not guaranteed everywhere SCA-style rules would apply.
Building SCA-Ready Authentication Without Waiting for a Mandate
Three moves position a bank or fintech ahead of whatever comes next, without waiting for a formal mandate. Layering an inherence factor onto onboarding is the first move. Verifying who a customer is at account opening, with a genuine biometric check rather than a document photo alone, does this. It gives every later authentication step a trustworthy identity to build on. Adding risk-based triggers is the second move. Not every transaction needs a full SCA challenge, and PSD2 itself allows risk-based exemptions for low-risk payments.
A fraud-risk score can decide when to step up authentication, rather than applying it uniformly. Documenting the approach is the third move. CBN's December 2025 circular and South Africa's PASA mandate both expect an auditable process, not just a working feature. The authentication logic and its exceptions need to be written down before a regulator or a card scheme asks for it.
How Youverify Supports the Identity Layer Behind Strong Customer Authentication
Youverify's biometric verification can help establish and verify a customer's identity at onboarding. It uses facial liveness detection and document matching to confirm a real, present person rather than a photo alone.
Our fraud insights solution scores device, behavioral, and network signals in real time. Those signals may support a bank's broader fraud-risk and authentication decisioning.
To get started, book a free demo today.
Conclusion
Strong Customer Authentication is not a European rule African banks and fintechs can treat as irrelevant. South Africa mandated a narrower 3-D Secure version years before PSD2 existed. Nigeria's central bank issued its own narrower directive in December 2025.
Card-scheme rules, acquirer requirements, and cross-border commercial arrangements can impose authentication obligations on top of whatever domestic law requires. Connectivity constraints also mean the SMS-based factor most African implementations lean on cannot be assumed reliable everywhere.
The practical response is not waiting for a comprehensive SCA law to arrive. It is layering a genuine identity check into onboarding, and using risk signals to decide when to step up authentication. That logic needs documenting before a regulator or a card scheme asks for it.
About the Author
Victoria Okere is a compliance content writer at Youverify, specializing in AML compliance, financial crime risk, regulatory technology, and emerging trends in financial services.