03. One Time Password

Checklist ref

2AU.03.15

Area
2AU. Authenticate
Wireframe ref

15

Type
Technical Standard
Requirement level
MUST NOT
Participant
Data Holder
Statement

The delivery mechanism for the One Time Password (OTP) is at the discretion of the data holder but MUST align to existing and preferred channels for the customer and MUST NOT introduce unwarranted friction into the authentication process. In line with CDR Rule 4.24 on restrictions when asking CDR consumers to authorise disclosure of CDR data, unwarranted friction for OTP delivery is considered to include: • the addition of any requirements beyond normal data holder practices for verification code delivery • providing or requesting additional information beyond normal data holder practices for verification code delivery • offering additional or alternative services • reference or inclusion of other documents

Example

Authenticate: Redirect with One Time Password

Version introduced
1.4.0 or earlier
Date introduced

12 August 2020 or earlier

Date modified

25 February 2022

Status
Active