Why do I need 2FA to both log in and authorise payments in Calmony?
This stems from Strong Customer Authentication (SCA) requirements under the UK's Payment Services Regulations 2017 (implementing PSD2).
SCA mandates two or more independent authentication factors whenever a customer:
- Accesses their payment account online (login)
- Initiates an electronic payment transaction (payment authorisation)
SCA treats logging in and authorising a payment as two separate moments requiring their own verification - so entering your password to log in doesn't also authorise a payment. The logic is that compromising login credentials shouldn't automatically grant payment authority.
The FCA enforces this in the UK post-Brexit, maintaining alignment with the EU framework. Calmony and Griffin are subject to regulatory action for non-compliance, which is why we're rigorous about applying 2FA at both stages.