Merchants should use risk-based authentication to reserve the strongest checks for higher-risk transactions and keep lower-risk customers moving through checkout. The goal is to reduce fraud without forcing every buyer into the same friction level. That balance depends on accurate risk signals, sound authorization strategy, and ongoing monitoring of approval rates, abandonment, and legitimate customer loss.
Why This Matters for Security Teams
When EMV 3D Secure is mandatory, the real question is not whether to use it, but how to tune it so fraud reduction does not create avoidable checkout friction. For ecommerce teams, that means balancing issuer challenge rates, false declines, customer abandonment, and chargeback exposure in one operating model. NIST’s NIST SP 800-53 Rev 5 Security and Privacy Controls is useful here because it frames authentication, monitoring, and risk treatment as controls rather than one-off product settings.
Merchants often get this wrong by treating 3D Secure as a binary compliance step instead of a layered decision point. The practical issue is that every extra challenge introduces a conversion risk, but every weak exemption path increases fraud exposure. Security teams have to work with payments, product, and fraud operations to define which transactions deserve step-up checks, which can flow through friction-light paths, and what telemetry proves the policy is working. In practice, many security teams encounter the cost of poor challenge strategy only after abandonment and good-customer loss have already risen, rather than through intentional fraud tuning.
How It Works in Practice
The strongest approach is risk-based authentication. EMV 3D Secure supports transaction data sharing that can help issuers approve low-risk transactions without challenge and reserve step-up authentication for cases that need more assurance. That is where fraud teams, payment engineers, and identity controls intersect: the merchant is not only defending against card fraud, but also shaping the customer’s authentication path.
Operationally, merchants should align checkout policy with measurable signals such as device reputation, account age, shipping mismatch, velocity, prior dispute history, and unusual purchase behaviour. Best practice is evolving, but the common pattern is to combine these inputs into rules or scores that decide whether to:
- send a friction-light transaction with strong data quality and exemption support
- apply challenge only when risk is elevated
- hold, review, or decline transactions that show clear abuse indicators
Authentication design also needs close attention to issuer response quality and soft decline handling. If the merchant supplies poor transaction context, issuers may challenge more often, which hurts conversion. If the merchant overuses exemptions or low-friction flows, fraud rises and authorization quality can degrade over time. The operational goal is to improve the probability that legitimate customers are approved on the first attempt while keeping enough scrutiny to suppress abuse.
Merchant teams should also monitor approval rate, challenge completion rate, abandonment, post-auth fraud, and chargeback trends as a single control loop. That makes it possible to identify whether a policy change is reducing fraud by design or merely shifting loss elsewhere in the funnel. Current guidance suggests that checkout tuning works best when fraud strategy, authentication policy, and acquiring performance are reviewed together, not in separate silos. These controls tend to break down when transaction data quality is inconsistent across markets or when issuer behaviour varies widely by region because the same risk signal can produce very different challenge outcomes.
Common Variations and Edge Cases
Tighter authentication often increases checkout friction, so organisations have to balance fraud reduction against conversion loss and customer trust. That tradeoff becomes more pronounced in subscription commerce, high-volume marketplaces, and cross-border sales where legitimate patterns are diverse and issuer expectations vary.
There is no universal standard for how aggressive challenge thresholds should be, and current guidance suggests merchants should segment by risk and customer context rather than apply one policy across all transactions. For example, a returning customer with stable behaviour may justify a smoother path than a first-time buyer placing an unusually large order. High-risk verticals may accept more step-up activity, while low-margin businesses may prioritise friction reduction more heavily.
It is also important to distinguish fraud controls from identity assurance. EMV 3D Secure can support authentication decisions, but it does not replace broader account security, bot mitigation, or post-auth transaction monitoring. For merchants with recurring payments, strong payment authentication should be paired with access governance and credential protection to reduce account takeover risk. Where the merchant also operates digital identity verification or saved-payment ecosystems, the relevant baseline extends to NIST SP 800-63 Digital Identity Guidelines and the transaction-risk controls described in CISA Zero Trust Maturity Model.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0, NIST SP 800-63 and NIST AI RMF set the technical controls, while PCI DSS v4.0 and EU AI Act define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AA | Authentication tuning must support secure access without excessive friction. |
| PCI DSS v4.0 | 8 | Checkout authentication and fraud controls affect cardholder data and access safeguards. |
| NIST SP 800-63 | AAL | Assurance level concepts help separate low-risk from step-up authentication cases. |
| NIST AI RMF | GOVERN | Fraud scoring and risk decisions need accountable governance and monitoring. |
| EU AI Act | If AI models drive fraud decisions, governance and traceability become important. |
Map payment authentication to access assurance outcomes and monitor whether controls improve or harm trust.
Related resources from NHI Mgmt Group
- How should travel merchants balance fraud prevention with checkout conversion?
- How do merchants balance convenience with stronger fraud controls?
- How can regulated gaming teams balance fraud prevention with conversion?
- How should payment teams balance compliance and fraud controls in APAC P2P systems?