Exemptions make sense when they reduce friction without materially weakening fraud controls, especially for low-value, repeat, or whitelisted transactions. They should be prioritised only as part of a monitored strategy, because fraudsters often target the easier paths. Organisations need to balance conversion, liability exposure, and fraud risk rather than assuming any exemption is automatically safe.
When exemptions are the better control choice
PSD2 exemptions are most defensible when they preserve enough security while removing avoidable friction from a transaction flow. That means low-risk scenarios, repeat customers, whitelisted payees, low-value payments, or behaviour that your fraud model already understands. The question is not whether step-up authentication is “stronger”, but whether it adds measurable protection for the specific transaction profile.
A useful way to think about the decision is whether the exemption shifts risk in a controlled way or simply transfers it to a weaker path. When the answer is the latter, more authentication is usually justified. When the exemption is backed by monitoring, fraud signals, and clear liability rules, it can be the more practical control because it avoids unnecessary abandonment while keeping attack surface bounded.
Organisations should also distinguish between customer convenience and security architecture. Exemptions work best when they are part of a deliberate access and transaction policy, not a default shortcut that gets applied because users dislike prompts. For payment teams, the real test is whether the business can explain, measure, and defend why a transaction was allowed without extra verification.
Where more authentication becomes the safer option
Additional authentication steps become more important when the transaction is unusual, high-value, high-risk, or outside established behavioural patterns. The same is true when fraud monitoring is weak, whitelisting is immature, or the organisation cannot reliably detect account takeover, mule activity, or replayed sessions. In those cases, the exemption may look efficient but can leave too much trust in the wrong place.
This is especially important because fraudsters naturally seek the easiest route through a payment journey. If an exemption is applied broadly, attackers will adapt to the relaxed path rather than the protected one. Organisations therefore need to treat exemptions as selective controls, not a blanket alternative to authentication.
There is also a governance angle. If an exemption cannot be linked to a defined risk appetite, fraud threshold, and review process, it becomes hard to justify after an incident. The strongest programmes make sure the business, fraud, and security functions agree on when a low-friction path is acceptable and when authentication should be stepped up.
How to decide without overdoing either control
The best decision rule is simple: use the exemption when it lowers friction without materially increasing fraud exposure, and use more authentication when the transaction’s risk profile is uncertain or elevated. That usually means weighting transaction amount, payee familiarity, customer history, device and behavioural signals, and the quality of monitoring behind the exemption.
- Prioritise the exemption when the transaction is genuinely low-risk and the organisation can monitor for abnormal patterns in near real time.
- Prioritise more authentication when the payment is novel, large, cross-channel, or tied to a customer profile that has weak historical trust.
- Review the control when fraud losses, false approvals, or customer abandonment begin to trend upward in the same segment.
For teams implementing PSD2 policy, the operational question is not “Can we exempt this flow?” but “Can we explain why the exemption is safe, and can we detect quickly if that assumption stops being true?” That is the difference between a friction-reduction tactic and a control failure.
Risk and Threat Considerations
Exemptions can create a predictable easier path that attackers target, especially when they are applied broadly or without strong transaction monitoring. The main exposure is not the exemption itself, but the combination of reduced user friction, weak anomaly detection, and limited review of whether the exempted population is still behaving like low risk.
Failure mechanism: Fraudsters exploit relaxed verification paths by steering stolen credentials, social engineering, or replayed payment attempts into flows where extra authentication is skipped, then move quickly before monitoring or liability review catches the abuse.
Impact: Organisations can see higher fraud losses, increased chargeback or reimbursement exposure, and a false sense of security because the control looks efficient while quietly broadening the attack surface.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5, CIS Controls v8 and NIST CSF 2.0 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | PSD2 exemption decisions hinge on control of authentication strength and lifecycle. |
| AC-6 — Least Privilege | Exemptions should limit access to the minimum needed for low-risk payment flows. | |
| Recommendation — Use IA-5 to govern when authentication can be reduced and ensure compensating controls remain enforced. Apply AC-6 to keep exempted transaction paths tightly bounded and narrowly authorised. | ||
| CIS Controls v8 | CIS-6 — Access Control Management | Payment exemptions are an access decision that should be reviewed and constrained. |
| Recommendation — Use CIS-6 to define, review, and revoke payment-path exceptions when risk changes. | ||
| NIST CSF 2.0 | PR.AA-05 — Protective Technology | Exemptions belong in a broader protective control strategy that still limits fraud exposure. |
| Recommendation — Align exemption decisions with PR.AA-05 so protective controls remain proportionate and monitored. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access control | Exempting step-up authentication is an access-control choice that needs governance. |
| Recommendation — Use A.5.15 to define approval and review rules for reduced-authentication payment paths. | ||
Practitioner Guidance
What to verify: Before expanding exemptions, confirm that each exempted segment has clear approval criteria, a measurable fraud threshold, and enough telemetry to spot drift in risk. If you cannot explain why a flow remains low risk, it is not a good exemption candidate.
Decision rule: If the control is protecting a repeat or whitelisted flow with stable behaviour, favour exemption only when monitoring and response can catch abuse quickly. If the flow is novel, high-value, or materially atypical, use stronger authentication even if it adds friction.
Practitioner takeaway: The best PSD2 strategy is selective, monitored friction removal, not the broad pursuit of fewer prompts; exemptions should be granted only where the organisation can prove the risk stayed contained.
Related resources from NHI Mgmt Group
- When should organisations prioritise cleanup of unused access over adding more approval steps?
- When should organisations prioritise transaction risk analysis exemptions over forcing more step-up authentication at checkout?
- Should organisations prioritise external exposure or internal credential governance first?
- When should organisations prioritise OAuth over simpler authentication for MCP?