Overview
ISO 5201:2024 - "Financial services - Code-scanning payment security" is an international standard that defines a risk-based security framework for mobile code-scanning payments (e.g., QR codes, barcodes) where the payer uses a mobile device to initiate or complete a transaction. The standard covers an overview, structured risk assessment, minimum security requirements, and extended security guidelines for two main implementation modes: payer-presented and payee-presented code payments. It explicitly excludes details of payer/payee onboarding and the broader supporting payment infrastructure.
ISO 5201 follows a risk-based approach aligned with ISO 31000 and ISO/IEC 27005 and organizes requirements into baseline controls and mode-specific best practices. Annexes provide implementation examples, a case study, and cryptographic requirements.
Key topics and technical requirements
- Risk assessment framework: Identifies common risks (e.g., unauthorized users, illegitimate or tampered code content, insecure transmission, sensitive data leakage, routing conflicts) and mode-specific risks for payer-presented and payee-presented flows (e.g., stolen code value, code abuse, replay, forged payment notifications).
- Minimum security requirements (baseline): Measures that apply to all code-scanning payment providers, including:
- Payment application security and secure coding
- Payer authentication and verification mechanisms
- Secure communication and security protocols
- Anti-cyber attack controls and server-side protection of sensitive data
- Transaction integrity controls such as unique transaction IDs and payment result notification
- Rejecting illegitimate payment codes and protecting printed code images
- Mode-specific guidelines: Best practices for payer-presented flows (secure code generation, encoding/decoding controls, TTL for prefetched codes, anti-replay) and payee-presented flows (dynamic codes, encryption in the code payload, payer verification, payee code management).
- Cryptography requirements: Annex C defines approved algorithm and mechanism requirements for any cryptographic protections used (no specific algorithms are invented here; implementers must follow Annex C and referenced cryptographic standards).
Practical applications and who uses this standard
ISO 5201 is intended for:
- Payment service providers, fintechs, mobile wallet vendors
- Merchants and acquirers implementing QR/barcode-based checkout
- Security architects, developers, and QA teams designing code-scanning payment apps
- Risk managers, auditors, and regulators assessing security posture of mobile payments
Typical uses:
- Designing secure QR-code payment flows (payer-presented or payee-presented)
- Performing risk assessments and gap analysis against a recognized baseline
- Defining secure code-generation, storage, and presentation practices
- Choosing cryptographic and protocol controls to mitigate replay, tampering, and data leakage
Related standards
Relevant references cited in ISO 5201 include:
- ISO 11568 (Key management - retail)
- ISO 16609 (Message authentication using symmetric techniques)
- ISO 19092 (Biometrics - Security framework)
- ISO 20038 and other payment/crypto-related standards and ISO/IEC 27000-series guidance for information security management
Keywords: ISO 5201, code-scanning payment, mobile payment security, QR code security, payer-presented, payee-presented, risk assessment, payment application security, cryptography.