EU merchants should treat PSD2 as a conversion and risk-management trade-off, not just a compliance exercise. Strong Customer Authentication can reduce fraud, but it also adds friction at checkout and can increase abandonment. The practical goal is to apply the stronger control where required, then use exemption pathways and risk-based review to preserve approval rates and customer experience.
Why PSD2 Friction Becomes a Checkout Design Problem
PSD2 changes checkout from a pure payment-processing step into a control decision. strong customer authentication is meant to reduce card-not-present fraud, but the merchant still has to preserve conversion. That means the right question is not whether to authenticate every buyer the same way, but where to use SCA, where to qualify for exemptions, and how to keep authentication from becoming the dominant source of abandonment.
For EU merchants, the practical balance is usually to route low-risk and low-value payments through exemption paths where allowed, while reserving step-up authentication for transactions that genuinely need it. That approach works best when fraud controls are tuned to the transaction, not imposed as a flat rule across the entire funnel.
Risk-based decisioning is the key design principle here. If the checkout flow cannot distinguish between routine repeat customers, high-risk orders, unusual devices, and suspicious payment patterns, it will over-challenge good customers and under-challenge risky ones. The outcome is either unnecessary friction or preventable fraud loss, both of which hurt revenue.
How Merchants Can Reduce Abandonment Without Weakening Fraud Controls
Merchants generally get the best result when they treat authentication as part of the payment journey rather than a separate security event. The goal is to make SCA feel targeted and expected, not arbitrary. That means placing the challenge only where the issuer, acquirer, or merchant risk engine has enough signal to justify it, and ensuring the fallback path is clear when an exemption is available or a retry is needed.
A useful operating pattern is to align the checkout experience with the fraud profile of the order. Low-risk returning customers should see the least disruption possible, while higher-risk activity should absorb more friction. This is where payment orchestration, issuer behaviour, transaction history, and device or behavioural signals matter more than a blanket “authenticate everyone” policy.
Merchants also need to think about user experience details that influence completion rates. Clear error messaging, fast redirects, minimal re-entry of payment data, and mobile-friendly authentication screens can materially reduce abandonment even when SCA is triggered. If the authentication step feels broken, slow, or surprising, customers often abandon before the fraud-control benefit is realised.
Well-run programmes usually measure both fraud loss and checkout completion together. If fraud goes down but abandonment rises sharply, the control may be too blunt. If abandonment stays low but chargebacks or fraud attempts rise, the exemption policy or step-up threshold may be too permissive. The right balance is observable in payment approval quality, not in compliance status alone.
What Good PSD2 Balance Looks Like in Practice
The strongest implementations separate policy, risk signal, and checkout presentation. Policy defines when SCA is required, risk signal determines when an exemption is defensible, and presentation determines whether the customer can complete the flow without confusion. When those three layers are aligned, merchants can reduce fraud without making the checkout feel hostile.
For teams working on the control design, a good benchmark is whether the merchant can explain why a given customer was challenged, exempted, or routed to a retry path. That traceability matters because it shows the payment control is being applied consistently rather than as an ad hoc UX compromise. It also helps support operations when issuers, acquirers, or customers dispute the outcome.
Merchants should also assume that the balance is dynamic. Fraud patterns change, issuer behaviour changes, and customer tolerance for friction changes. A flow that is well tuned today can become too strict or too lenient if the approval mix shifts, so the checkout policy needs periodic review rather than one-time configuration.
Risk and Threat Considerations
Overly aggressive SCA can create avoidable cart abandonment, but overly generous exemption use can create an opening for card testing, account takeover-driven purchases, and first-party or third-party fraud. The risk is not only financial loss, it is also degraded customer trust when legitimate buyers are interrupted or when bad payments are allowed through.
Failure mechanism: Merchants either challenge too many low-risk transactions, which increases checkout drop-off, or they suppress challenges too broadly and give attackers a smoother path through payment authorisation and dispute-generating fraud.
Impact: Conversion falls when good customers are blocked, while fraud and chargeback exposure rise when exemptions are applied without enough risk discipline. At scale, both failures distort revenue, issuer relationships, and the merchant’s ability to tune future decisioning.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 and OWASP ASVS set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | IA-2 — Identification and Authentication (Organizational Users) | Strong customer authentication is an authentication control decision at checkout. |
| IA-5 — Authenticator Management | PSD2 checkout balance depends on handling authenticators and their lifecycle safely. | |
| Recommendation — Apply IA-2 to require step-up authentication only when the risk justifies it. Use IA-5 to manage authentication factors and recovery paths without adding unnecessary friction. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access control | PSD2 SCA is a control-choice problem about when access to payment completion is granted. |
| A.8.5 — Secure authentication | SCA is directly about secure authentication at the payment step. | |
| Recommendation — Set access rules that challenge high-risk payments and streamline low-risk ones. Implement secure authentication flows that preserve checkout completion where allowed. | ||
| OWASP ASVS | V6 — Authentication | Checkout authentication quality affects conversion, abandonment, and fraud outcomes. |
| V7 — Session Management | Smooth checkout often depends on preserving session state across authentication redirects. | |
| Recommendation — Validate authentication paths so step-up checks remain usable and resilient under load. Protect session continuity so authentication does not break the purchase flow. | ||
Practitioner Guidance
What to prioritise: Treat exemption strategy and step-up rules as part of conversion management, not a separate compliance exercise. The merchant should know which transaction segments are worth challenging and which should be allowed through with the least friction.
What to verify: Check that SCA is being applied consistently across channels, that exemption outcomes are reviewable, and that the checkout journey still completes cleanly on mobile and desktop when authentication is triggered. If completion rates drop, verify whether the problem is the control itself or the way the flow is presented.
Common mistake: Do not use a single blanket policy for all customers and all baskets. That usually creates either unnecessary abandonment or a false sense of security.
Practitioner takeaway: The best PSD2 programme is the one that challenges only the transactions that benefit from it, while keeping legitimate customers moving through checkout with as little surprise as possible.
Related resources from NHI Mgmt Group
- How can merchants balance fraud prevention with customer experience?
- How do merchants balance convenience with stronger fraud controls?
- How should merchants respond when account takeover and post-purchase fraud are driving customer abandonment?
- How should merchants balance fraud prevention with customer-friendly returns policies during peak holiday shopping periods?