Coreal.
Book a working session →
·Compliance · PSD2

PSD2 compliance for telco fintech.

Revised Payment Services Directive (Directive (EU) 2015/2366). Enforced from 2018-01-13 (SCA technical standards from 2019-09-14). Supervised by EBA + national competent authorities. Coreal generates the evidence pack automatically on every Minctrl build — see /security-compliance for the full posture.

Enforced
2018-01-13
Authority
EBA…
Penalties
Member-state specific (typically up to €5M or 10% of turnover)
Vertical
TELCO

What this regulation covers.

Authorisation of Payment Institutions and Payment Initiation / Account Information Service Providers; Strong Customer Authentication; open banking.

For a telco fintech, the salient angles are: BSS write-path protection (regulator must see read-only on event bus); Subscriber consent for fintech data sharing under GDPR; Group-level vs partner-bank capital allocation. Primary licence: Partner-bank EMI passport (or own EMI for tier-1).

● RELEVANT ARTICLES
  • Art. 4 — Definitions of PSP types
  • Art. 11 — Authorisation criteria
  • Art. 66–67 — PIS and AIS access rights
  • Art. 97 — Strong Customer Authentication
● EVIDENCE PACK COREAL GENERATES

What lands in the regulator file.

E01PI / PSP authorisation file
E02SCA flow design (3DS2 + biometric + device binding)
E03Open banking consent log (per-customer, time-bound)
E04Liability matrix for unauthorised transactions

All items journaled, replayable, 7-year retention.

● READ NEXT
·Questions we hear

Which PSD2 articles apply to a telco?

Primarily: Art. 4 — Definitions of PSP types; Art. 11 — Authorisation criteria; Art. 66–67 — PIS and AIS access rights. The full mapping is in the Coreal compliance posture document — see /security-compliance.

What evidence does Coreal generate per audit?

PI / PSP authorisation file; SCA flow design (3DS2 + biometric + device binding); Open banking consent log (per-customer, time-bound). The Minctrl pipeline produces this artefact set automatically on every build — see /company §05 'How we ship'.

What are the penalties for non-compliance?

Member-state specific (typically up to €5M or 10% of turnover); FCA fines have exceeded £100M for major breaches.

·Working session

Bring the perimeter,
leave with a brief.

Book a working session →Read field notes →
Not ready to book 4 hours?

Read the Wave-1 runbook first.

The full 90-day launch sequence — phases, partner-bank gates, who signs off when. No form to read it.

Read the runbook →

INDICATIVE DATA · Numbers and timelines reflect public regulator filings, vendor documentation and our own delivery experience. Per-engagement values vary with operator profile, BSS vintage and regulatory perimeter. Engage early for a fitted estimate under NDA.