Facciata a griglia di un edificio per uffici

Directive (EU) 2019/882 · Annex I, section IV

Consumer banking is named in the directive, and the statement has to show it

Most service providers have to work out whether they are in scope. Banks, payment institutions and consumer credit providers do not: consumer banking services appear by name in the directive, together with identification methods, electronic signatures and security. That makes the statement easier to write and much harder to bluff.

Directive (EU) 2019/882Annex I, section IV

What the directive names for banking

Consumer banking services are covered, and the accessibility requirements apply to more than the marketing site. They reach identification methods, electronic signatures, security features and payment services, which is exactly where the customer journey actually happens. Self-service terminals used to provide the service are covered as products, with their own annex.

In practice this pulls four things into scope that a generic audit leaves out: onboarding with identity verification, strong customer authentication, the documents you send, and the terminals your customers touch.

Identification is where most fintech fails the test

Video identity checks, liveness detection, document scanning and one-time codes are the hardest part of a banking journey to make accessible, and they are the part nobody tests. Common failures, each one fatal to an onboarding:

  • A liveness step that requires seeing your own face on screen, with no alternative route for a blind customer.
  • A code entry field with a countdown too short for someone using a screen reader, and no way to extend it.
  • An error message shown as a coloured border with no announced text, so the customer does not know what failed.

Article 4 lets you offer an alternative accessible means where a requirement cannot be met, but the alternative has to exist, be documented and be reachable without arguing with support. A branch phone number buried in a PDF is not an alternative.

Facciata a griglia di un edificio per uffici
Facciata a griglia di un edificio per uffici
Una mano firma un documento
Una mano firma un documento

Documents count as part of the service

Statements, contracts, pre-contractual information and security notices are part of a banking service. If they go out as scanned PDFs with no text layer, a screen reader user cannot read their own contract. The directive expects the information to be available in accessible formats, and this is one of the few areas where the fix is cheap and the failure is obvious.

Two regulators, one journey

Accessibility sits next to rules you already live with. Strong customer authentication comes from payment law, identity checks from anti-money-laundering rules, and both constrain what you can change. Nothing in the accessibility regime lets you drop an authentication factor, and nothing in payment law excuses an unusable factor. The work is in finding the combination that satisfies both, and documenting why the combination was chosen.

Terminals, branches and the products annex

If your customers use ATMs, payment terminals or check-in kiosks that you provide, those are products under the directive, not services. They come with technical documentation under Annex IV rather than a published statement, and the assessment covers hardware, interface and the instructions that ship with them. Leasing the hardware does not move the duty if the service delivered through it is yours.

In practice this matters for two groups: retail banks with a terminal estate, and fintech providers whose card product is dispensed or activated through a machine they branded.

Facciata a griglia di un edificio per uffici
Facciata a griglia di un edificio per uffici
Facciata a griglia di un edificio per uffici
Facciata a griglia di un edificio per uffici

Where a banking audit usually finds the worst barriers

Not on the home page. The failures that stop a customer sit inside the product: a transfer confirmation that appears as a visual overlay the screen reader never announces, a card-freeze toggle with no accessible name, a statement download that opens a viewer with no keyboard support, a chat widget that traps focus so the keyboard user cannot get back to the page.

Each of those is invisible to an automatic scan of the marketing site, and each one is the kind of thing a customer writes to the regulator about, because it happened with their own money.

What you get at the end

An Annex V statement written from the result and ready to publish, a developer report with every barrier, its criterion, where it sits and how to verify the fix, a signed record with a public code, a hosted feedback page, and a retest every month that tells you the day a release breaks something. Where you want the barriers closed rather than only documented, we quote the corrections separately on the real work.

Procurement will ask before the regulator does

If you sell to corporates or to the public sector, the accessibility report is already a line in the questionnaire, often alongside a VPAT or an EN 301 549 report. Providers who have one answer in a day; the others lose weeks assembling something after the bid has closed.

How we work with a regulated provider

We test with a real account on the journeys that matter: opening, identification, authentication, transfer, card controls, support. We work inside your rules, with test credentials and a sandbox where you have one. The output is a statement written from the result, a developer report with each barrier and its criterion, and a record signed by Europe Services SE with a public code anyone can verify. See also how this looks for a SaaS provider and what the audit covers.

Questions we get before buying

Are all banking services covered?

Consumer banking services are named in the directive. Purely business-facing services are outside it, though buyers increasingly ask anyway.

Does this apply to payment institutions and e-money firms?

Where they provide consumer banking or payment services in the Union, yes. The label on the licence does not change the analysis.

What about our ATMs and self-service terminals?

Terminals used to provide the service are covered as products, with technical documentation under Annex IV rather than only a statement.

Can we keep video identity verification?

Yes, provided a customer using assistive technology has a documented alternative route that works without special pleading.

Do our PDFs really matter?

Yes. Contracts and statements are part of the service, and a scanned PDF with no text layer is unreadable to a screen reader.

Does strong customer authentication conflict with accessibility?

No factor has to be dropped. The requirement is that the chosen factors are usable, with alternatives where a barrier is unavoidable.

Who signs the statement?

You publish it. We test, document and sign the record behind it through Europe Services SE, established in Prague.

How long does a banking journey test take?

Five business days from your scope answers for a standard set of journeys. Onboarding with identity checks is quoted separately.

Do you need production access?

A test account is enough in most cases. We work in a sandbox where you have one.

Will this satisfy a procurement questionnaire?

It gives you the conformance report, criterion by criterion, with a date and a verifiable code, which is what those questionnaires ask for.

Test the journey your customers actually use

Onboarding, authentication, documents and support, tested with assistive technology and signed with a public code.

See pricing