Join our Newsletter — 33% off our NHI Course

Why do overly strict PSD2 authentication flows reduce merchant profitability?

Overly strict flows add friction at checkout, and that friction can push legitimate buyers to abandon the purchase or buy elsewhere. Merchants then lose the sale, the customer’s lifetime value, and the marketing cost already spent to acquire that customer. The result is not just a lower conversion rate, but a direct hit to revenue efficiency across the funnel.

Why strict PSD2 checks can hurt the checkout funnel

PSD2 authentication is meant to reduce payment fraud, but the merchant only sees the commercial side effect: extra steps, extra latency, and more drop-off at the point where intent is most fragile. If the flow feels heavy, inconsistent, or repetitive, even legitimate buyers will abandon before authorisation completes. That makes the control economically expensive when applied too rigidly.

There is a practical distinction between fraud reduction and conversion optimisation. A stricter challenge can improve approval quality, but only up to the point where friction starts to outweigh the value of the extra risk reduction. Merchants therefore need to judge the cost of each failed or delayed checkout against the fraud losses the flow is actually preventing.

When the customer experience breaks down, the merchant loses more than the immediate order. The abandonment also wastes acquisition spend, weakens repeat purchase behaviour, and can reduce trust in the payment journey itself. That is why profitability falls faster than the conversion-rate metric alone suggests.

Where profitability is lost in practice

The main leak is not always the final authentication challenge itself, but the cumulative effect of friction across the funnel. Extra redirects, timeouts, device handoffs, weak mobile usability, and repeated re-authentication all increase the chance that a legitimate shopper will quit or choose a competitor with a smoother flow.

  • Higher abandonment at checkout when the challenge interrupts purchase momentum.
  • Lower approval completion on mobile, where context switching is especially costly.
  • More customer support contacts when shoppers do not understand why they were challenged.
  • Reduced lifetime value when a poor payment experience depresses repeat buying.

Merchant profitability is therefore a margin problem as much as a security problem. A control that blocks fraud but suppresses too many legitimate transactions can still reduce net revenue efficiency, especially in businesses with thin margins or high customer-acquisition costs.

For teams assessing the broader security and access implications of this trade-off, NHI Management Group’s Ultimate Guide to NHIs is useful background on lifecycle, governance, and access boundaries. For payment-sector control expectations, the PCI DSS v4.0 document library is the most relevant external reference among the supplied sources.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 set the technical controls, while PCI DSS v4.0 define the regulatory obligations.

Framework Control / Reference Relevance
PCI DSS v4.0 8.6 — System and application accounts with interactive login PSD2 checkout risk is shaped by how interactive payment flows handle authentication burden.
7 — Restrict access by business need and least privilege Least-privilege principles support targeted challenge logic instead of blanket friction.
Recommendation — Limit interactive authentication steps to what the transaction genuinely requires. Apply least-privilege access logic to challenge only the transactions that need it.
NIST CSF 2.0 PR.AA — Identity Management, Authentication and Access Control Authentication strength and user friction are directly tied to the protection objective here.
Recommendation — Balance authentication strength with user experience to preserve legitimate transaction completion.

Practitioner Guidance

What to prioritise: Treat PSD2 friction as a revenue-control issue, not just a compliance implementation detail. The right question is whether each added challenge step removes enough fraud to justify the conversion loss it creates.

What to verify: Measure abandonment by device, geography, issuer response pattern, and step in the challenge flow. If drop-off clusters around a specific authentication stage, that is usually where the profit leak is being created.

Decision rule: If a stricter flow materially increases failed or abandoned checkout on low-risk traffic, prefer a more targeted authentication policy rather than applying the same burden to every transaction.

What practitioners underestimate: The commercial damage is often delayed and cumulative. A buyer who abandons today may not return tomorrow, so the true cost includes lost repeat revenue, not only the missed basket value.

Practitioner takeaway: The goal is not to remove authentication friction entirely, but to place it only where it earns back more fraud reduction than it costs in lost conversion and customer value.