Warning signs include rising abandonment during checkout, a spike in chargebacks, and fraud concentrating in exempt or out-of-scope transactions. If authentication is being added without a matching reduction in fraud losses, the control is not doing enough. Teams should watch whether good customers are being blocked while fraudsters still find gaps in the payment flow.
What the warning signs look like in a PSD2 rollout
PSD2 is only helping if strong customer authentication reduces fraud without breaking too much legitimate flow. The practical warning signs are operational: more customers abandoning at checkout, more transactions falling into chargeback or dispute paths, and more fraud moving into exemptions, fallback routes, or transactions that sit outside the strongest controls. That pattern usually means the control is adding friction faster than it is removing risk.
A second signal is when authentication volume rises but loss metrics do not improve. If teams add more challenges, redirects, or step-up checks and still see the same fraud pattern, the control may be protecting the wrong part of the flow, or attackers may be adapting faster than the protection does.
For payment teams, the important question is not whether authentication is present, but whether it is changing outcomes at the points where abuse occurs. A control that blocks good customers while leaving loss-making paths open is a sign of poor calibration, not stronger protection.
Why these signs matter operationally
PSD2 can create false confidence when organisations measure compliance activity instead of business and security outcomes. A payment journey can look more controlled because more users are challenged, yet the real effect may be higher abandonment, weaker conversion, and fraud concentration in the flows that remain easiest to abuse.
That is why the balance between protection and friction matters. If authentication is introduced without a matching reduction in fraud losses, the control is not achieving its purpose. In practice, that often means exemptions are overused, risk scoring is too blunt, or the fraud team is not seeing how attackers adapt around the strongest step in the journey.
The cleanest read is comparative: if the protected flow is materially safer than the unprotected one, the control is probably working. If the protected flow is simply more expensive for customers to complete, while fraud shifts elsewhere, the organisation has probably moved risk rather than reduced it.
What to inspect before calling PSD2 effective
Start by separating customer friction from fraud effect. Look at abandonment, conversion, chargebacks, fraud rates, and exemption usage together, because any one metric on its own can be misleading. Then compare outcomes by payment path: authenticated, exempt, out-of-scope, fallback, and failed-authentication flows often behave very differently.
It also helps to check whether fraud is concentrating in the paths least touched by the control. If losses are clustering in exemptions or other bypass routes, the programme may need tighter policy, better risk scoring, or narrower use of exceptions rather than more authentication everywhere.
Finally, verify whether good customers are being blocked at a rate that is operationally unacceptable. A protection layer that disproportionately stops low-risk buyers usually needs tuning, because the business cost can exceed the security value it creates.
Risk and Threat Considerations
The main risk is control displacement: attackers and fraudsters often move toward the easiest remaining payment path when stronger checks are added to the main flow. That can leave the organisation with higher friction, lower conversion, and little or no improvement in loss prevention.
Failure mechanism: Authentication is applied unevenly or too broadly, so legitimate users are interrupted while fraud is redirected into exemptions, fallback routes, or other weaker branches of the payment journey.
Impact: The business pays more in customer drop-off and support burden, while fraud losses stay flat or become more concentrated in the paths that were least protected.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP API Security Top 10 addresses the attack and risk surface, while NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | IA-2 — Identification and Authentication (Organizational Users) | PSD2 checkout friction is an authentication outcome problem. |
| AC-7 — Unsuccessful Logon Attempts | Repeated auth failure patterns can indicate poor customer experience or abuse. | |
| Recommendation — Tune step-up authentication to reduce fraud without overblocking legitimate customers. Monitor repeated authentication failures to detect friction and attack pressure. | ||
| OWASP API Security Top 10 | API2 — Broken Authentication | Payment flows often rely on authentication strength and failure handling. |
| Recommendation — Review payment authentication flows for weak or bypassable challenge handling. | ||
| NIST CSF 2.0 | PR.AA-01 — Identities and credentials are issued, managed, verified, revoked, and audited for authorized users, devices, and services | PSD2 effectiveness depends on managed authentication and exception handling. |
| Recommendation — Audit payment credentials and auth paths to ensure controls reduce loss, not just add steps. | ||
Practitioner Guidance
What to measure: Track abandonment, chargebacks, fraud loss rate, exemption rate, and approval rate together, then review them by payment path rather than only as a whole-programme average. The most useful signal is whether stronger authentication correlates with lower net loss in the same flow.
Decision rule: If fraud losses are not falling in the protected journey, do not add more authentication by default. First tighten exemption policy, review risk scoring, and identify where attackers are still reaching payment success.
Practitioner takeaway: PSD2 is creating more risk than protection when it improves formal compliance but worsens the combined outcome of loss, friction, and bypass behaviour.