Payment service providers must apply Strong Customer Authentication when a payer accesses a payment account online, initiates an electronic payment transaction, or carries out an action through a remote channel that may imply a risk of payment fraud.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.