Visa Consumer Authentication Service (VCAS)
Business Requirements Document (BRD)
ISO-639-1 format
Company Name
*
Primary Contact
First Name
*
Last Name
*
Email Address
*
Phone Number
Authentication Method
Is 3DS used today?
*
Yes
No
Select Yes or No
VCAS Screen Languages – Please include the ISO Code(s) and/or dialect(s)
*
Please specifly the languages you wish to display to your cardholders in the VCAS screens.
Risk Based Authentication
VCAS offers multiple authentication solutions.
The Pass/Fail solution leverages the VCAS Rules functionality to pass and fail authentication based on parameters created and maintained by the VCAS client. No system integration is required for this solution. (If selecting this option, please skip the Step-Up Method section.)
The Pass/Fail/Step-Up solution incorporates the rules from the Pass/Fail solution and also includes a step-up flow to obtain an authentication directly from the cardholder. This solution requires a system integration, please see the System Integration section further below.
What is your Risk Based Authentication solution?
*
None
Pass/Fail (Please skip the Step-Up Method Section)
Pass/Fail/Step-Up (Please complete the Step-Up Method Section)
Step-Up Method
In this section you will define your step-up method for your 3DS transactions. The step-up allows you to give your cardholders the chance to authenticate themselves instead of failing the transaction. The System Integration section below will be required to support any step-up option.
One-Time Passcode (OTP)
Who Will Create and Validate the OTP?
VCAS
Issuer/Processor
No Selection
OTP Delivery Method
SMS
Email
SMS & Email
Push Notification
For windows: Hold down the control (ctrl) button to select multiple options. For Mac: Hold down the command button to select multiple options.
OTP Delivery Option
Choice
Single
Concurrent
No Selection
One-Time Passcode (OTP) + Knowledge Based Authentication (KBA) European Economic Area (EEA ONLY)
What type of KBA will be used?
This method is specific to PSD2 SCA compliance. OTP+KBA will leverage the selections in the OTP section above.
How will cardholders enroll for the Knowledge Based Authentication with the Issuer?
Note: This method of authentication is only applicable to API based integrations (Real-Time Data Exchange (RDX)) as the VCAS client will need to perform validation of the Answer in real-time during the transaction. The RDX integration is required to pass the Question & Answer for KBA as VCAS will neither store nor validate the Question or Answer.
Biometric
Biometric Type
Face
Finger
Voice
Iris
Other
For Windows: Hold down the control (ctrl) button to select multiple options. For Mac: Hold down the command button to select multiple options.
Token
Hard or Soft Token?
No Selection
Token Device (Hard Token)
Mobile App (Soft Token)
Out of Band / Other
Out of Band Type
No Selection
Mobile Banking Application
Third Party Application
Online Banking
Other
System Integration
A system integration is necessary if our systems need to share information in order to successfully perform a step-up authentication.
File Processor (FP) - allows you to drop off cardholder information in a specific file format via SFTP (Secure File Transfer Protocol). This data will be used to facilitate authentication with your cardholders.
Real Time Data Exchange (RDX) - is a web service with 4 conditional API calls used to integrate with Cardinal's VCAS system to facilitate communication and share information real-time between our systems. RDX is flexible and allows you to, based on the authentication solution, determine how involved you would like to be in the transaction flow.
Integration Method
*
None
File Processor (FP)
Real Time Data Exchange (RDX)
Data Sharing (Optional)
Additional information may be shared outside of the VCAS Portal. The Authentication Data Exchange (ADX) contains the results of the authentication and is sent in real-time API prior to VCAS sending those results back to the merchant.
Data may also be shared via an SFTP file delivery method via the confirmed marking file and the reports shown further below.
Add the Authentication Data Exchange (ADX) API to my solution
Bulk Confirmed Marking (Upload)
File upload by Client to mark transactions as good or fraud via SFTP file.
Add Bulk Confirmed Marking to my solution
SFTP Reports (Download)
Additional data available via SFTP file delivery.
Add SFTP Reports to my solution
Card Networks
Visa
MasterCard
Amex
Diners/Discover
JCB
UPI
ELO
eftPOS
For Windows: Hold down the control (ctrl) button to select multiple options. For Mac: Hold down the command button to select multiple options.
Card Types
Credit
Debit
Commercial
Prepaid
Combo
Other
For Windows: Hold down the control (ctrl) button to select multiple options. For Mac: Hold down the command button to select multiple options.
Processor
Please provide the name of your processor(s) for the portfolios listed above.
Additional Solution Details
Please add any additional information that may be pertinent to the authentication solution (255 character maximum).