Low fraud rates matter because exemption eligibility depends on trust signals that merchants can sustain over time. When fraud is controlled, merchants are more likely to qualify for lower-friction payment flows and keep more transactions out of step-up authentication. If fraud rises, those exemptions become harder to justify and the checkout experience becomes less predictable for customers.
Why fraud levels shape exemption eligibility
strong customer authentication exemptions are not a blanket convenience, they are a risk decision. Low fraud rates are the clearest evidence that a merchant’s checkout flow, customer base, and fraud controls are stable enough to justify less friction. When that signal weakens, acquirers and schemes are less willing to trust the transaction stream, and more payments are pushed back into step-up authentication.
That is why merchants often treat fraud performance as a core operating metric, not just a loss metric. If the exemption is meant to preserve conversion and reduce abandonment, the merchant has to show that the risk being taken by skipping step-up checks remains controlled over time, not only during a short clean period.
One practical way to think about it is that exemptions are usually earned by demonstrating that the merchant can restrict access by business need and least privilege to the transaction path in a broader control sense, while keeping fraud and abuse at a level the issuer or scheme can tolerate. That logic is easier to sustain when the merchant can also show tight control of payment credentials and customer authentication events.
What changes when fraud starts to rise
When fraud increases, the issue is not only chargeback cost. Higher fraud rates can trigger exemption loss, tighter issuer scrutiny, or more frequent fallback to full authentication. The result is a less predictable customer journey: the same customer may sail through one session and face additional prompts in the next, depending on how the risk signal is interpreted.
That unpredictability matters operationally because checkout teams tend to optimise for conversion, while fraud teams optimise for loss prevention. If fraud is allowed to drift upward, the organisation often ends up paying for it twice, first through direct fraud losses and then through more friction at the point of sale. In practice, low fraud rates are what keep the exemption from becoming a temporary privilege rather than a durable operating mode.
A useful reference point is the payment-sector emphasis on access control and account discipline in PCI DSS v4.0 guidance, which reinforces that stable transaction trust depends on strong control of who and what can initiate or alter payment activity. When that control weakens, exemption confidence weakens with it.
How merchants keep exemption performance credible
Merchants usually need a sustained pattern of clean behaviour, not a one-time improvement. The controls that matter most are the ones that reduce fraudulent activity before it becomes part of the exemption decision: robust transaction monitoring, strong customer verification where needed, and fast response to suspicious patterns. Low fraud rates are therefore the outcome of control quality, not just good luck.
Practitioners should also watch for hidden drivers that can make fraud rates look better than they are in the short term, such as narrow samples, seasonal effects, or a channel mix that temporarily excludes higher-risk traffic. If the underlying risk profile changes, the exemption can deteriorate quickly even when headline fraud numbers initially appear stable.
For broader control design, the NIST Cybersecurity Framework 2.0 is useful because it encourages organisations to treat trust, monitoring, and response as continuous functions rather than one-time checks. That mindset fits exemption management well: keep the fraud signal visible, and treat sudden movement as an operating condition, not just a finance issue.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0 set the technical controls, while PCI DSS v4.0 define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| PCI DSS v4.0 | 7 — Restrict Access by Business Need to Know | Exemption trust depends on controlled payment access and lower abuse risk. |
| 8.6 — System and Application Accounts and Authentication Management | Stable authentication control supports lower fraud and exemption confidence. | |
| Recommendation — Apply least-privilege access to payment systems and transaction approval paths. Manage non-human and application accounts so payment actions remain attributable and controlled. | ||
| NIST CSF 2.0 | GV.RM — Risk Management Strategy | SCA exemptions are a risk decision that depends on sustained fraud performance. |
| DE.CM — Continuous Monitoring | Fraud drift must be detected early or the exemption becomes unreliable. | |
| PR.AC — Access Control | Checkout integrity depends on limiting who can initiate or alter payment activity. | |
| Recommendation — Treat exemption eligibility as a governed risk threshold and review it continuously. Monitor fraud signals continuously and trigger review when risk trends change. Constrain payment-path access to reduce abuse that can invalidate exemption trust. | ||
Practitioner Guidance
What to prioritise: Track fraud rate trends by channel, geography, device pattern, and issuer outcome, not just as a single blended number. The exemption only stays defensible when the risk profile is stable at the slice level that actually drives approval decisions.
What to verify: Confirm that the fraud data used for exemption decisions reflects recent activity, includes abuse patterns that bypass simple chargeback metrics, and is reviewed often enough to catch drift before the merchant loses trust with issuers or schemes.
Common mistake: Treating a low fraud rate as proof that the checkout experience can be left unchanged indefinitely. Exemption eligibility is dynamic, so a merchant that stops measuring control effectiveness usually discovers the problem only after more transactions start being stepped up.
Practitioner takeaway: The real objective is not to “win” an exemption once, but to make low fraud performance credible enough that the exemption remains sustainable under changing traffic and threat conditions.
Related resources from NHI Mgmt Group
- Why do strong customer authentication controls still fail against authorised fraud?
- Why does Strong Customer Authentication matter more for online and contactless payments than standard password checks?
- Why does strong authentication matter so much in NIS2 compliance programmes?
- When does Strong Customer Authentication create more revenue risk than fraud protection value?