Operate fraud detection + Transaction Risk Analysis + rate limiting + sandbox per scheme requirements. Fraud Detection and Transaction Risk Analysis must (a) implement real-time fraud detection at authorisation + initiation + completion + (b) consider device + behavioural + geographic + transaction pattern signals + (c) integrate with TRA for SCA exemption decisions where applicable + (d) maintain false positive + false negative metrics + tuning. API Rate Limiting and Throttling Controls must (a) implement rate limiting per TPP + per customer + per scope + (b) prevent abuse + DoS + scraping + (c) align with scheme-defined limits + (d) provide back-off signals + retry-after guidance. Sandbox Parity and Testing Facilities must (a) maintain sandbox environment with production-grade API behaviour + (b) provide TPP testing capability + (c) maintain documentation + sample data + onboarding support + (d) coordinate sandbox releases with production releases. Penetration Testing and Vulnerability Management must (a) conduct regular pen testing per scheme requirement + (b) maintain vulnerability disclosure programme + (c) consume scheme + national CERT advisories + (d) coordinate vulnerability response with TPPs.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.