Join our Newsletter — 33% off our NHI Course

When should merchants use step-up authentication instead of a straight approval flow?

Step-up authentication should be used when a transaction is borderline and the merchant or issuer needs more proof before approval. It is most useful where the added challenge can resolve uncertainty without creating excessive friction. For routine low-risk transactions, it is usually better to preserve speed and avoid unnecessary customer drop-off.

When step-up authentication is the right control

Step-up authentication belongs in the approval path when the decision is not clearly low risk and the merchant needs more confidence before completing the transaction. It works best as a targeted challenge, not a blanket requirement, because its value comes from resolving uncertainty while preserving a smooth flow for routine approvals.

A good way to think about it is as a risk-sensitive branch in the customer journey. If the transaction has enough risk signals that a straight approval would be hard to defend, but not so much risk that it should be blocked outright, step-up can add an extra proof point at the exact moment it is needed. That is why merchants often pair it with fraud scoring, behavioral signals, device reputation, or unusual purchase patterns.

The control is most effective when the added challenge changes the decision outcome in a meaningful way. If the challenge would only delay a transaction that would be approved anyway, it adds friction without much security value. If the transaction is already clearly malicious or clearly safe, step-up is usually the wrong tool because it either underreacts or creates unnecessary customer friction.

What merchants should look for before triggering step-up

Merchants should reserve step-up for borderline cases where the available evidence is incomplete or mixed. Typical triggers include a new device, an unusual location, a mismatch between historical behavior and current activity, or a purchase that is larger or riskier than the customer’s normal pattern. The point is to challenge the transaction only when additional proof can materially improve the approval decision.

For customer-facing commerce, the best step-up logic is usually selective and adaptive. A merchant may let low-risk transactions pass with no interruption, while asking for additional verification only when the transaction sits near the approval threshold. That approach preserves conversion for good customers and concentrates friction where it is most defensible.

Step-up also needs to fit the customer journey. If the challenge is too hard, too slow, or too frequent, customers abandon the flow and the control becomes self-defeating. If it is too weak, attackers can satisfy it easily and the step adds little beyond cosmetic friction.

How step-up differs from a straight approval flow

A straight approval flow assumes the available signals are sufficient to make a decision immediately. That is appropriate for routine transactions where the risk is low and the user experience matters more than extra verification. Step-up changes the model by inserting an additional check only when the transaction needs more scrutiny to reach a confident decision.

For merchants, the practical distinction is not just security, but decision quality. Straight approval is efficient when confidence is already high. Step-up is useful when the merchant wants to avoid both overblocking legitimate customers and underchallenging suspicious activity. In that sense, it is a precision control, not a default control.

Used well, step-up can also support issuer confidence and internal fraud operations. It creates an opportunity to confirm that the person initiating the purchase is the legitimate account holder, which can reduce false approvals in cases where the initial signal set is ambiguous. Used poorly, it becomes a random hurdle that customers resent and fraudsters learn to anticipate.

Risk and Threat Considerations

Borderline approvals are exactly where merchants are most exposed to fraud, account takeover, and false decline pressure. If the transaction is not challenged when it should be, the merchant may approve activity that does not belong to the real customer. If it is challenged too aggressively, legitimate users are pushed out of the flow and the business absorbs avoidable abandonment.

Failure mechanism: Attackers exploit weak or static approval rules by blending in with normal activity, while merchants that overuse step-up create friction that can depress conversion and teach users to expect interruptions even for low-risk transactions.

Impact: The merchant either accepts more fraudulent transactions than intended or introduces so much friction that good customers leave before completion. The control only pays off when the added challenge changes the decision on cases that are genuinely uncertain.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-63, NIST SP 800-53 Rev 5, OWASP ASVS and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

Framework Control / Reference Relevance
NIST SP 800-63 Digital Identity Guidelines Defines assurance levels and phishing-resistant authentication choices for step-up decisions.
Recommendation — Use assurance levels to trigger stronger verification only when transaction risk justifies it.
NIST SP 800-53 Rev 5 IA-5 — Authenticator Management Step-up often depends on stronger or additional authenticators at risk points.
IA-2 — Identification and Authentication (Organizational Users) Supports authentication logic where user proof is needed before allowing a sensitive action.
Recommendation — Require stronger authenticators when a transaction needs higher confidence. Apply stronger authentication before approving sensitive access or actions.
ISO/IEC 27001:2022 A.5.15 — Access control Step-up is an access-control decision that limits approval under uncertainty.
Recommendation — Define when higher assurance is required before granting transaction approval.
OWASP ASVS V6 — Authentication Step-up is an authentication design choice that affects verification strength and user flow.
Recommendation — Specify when the application must request additional authentication before proceeding.
CIS Controls v8 CIS-6 — Access Control Management Adaptive approval and escalation are access-control decisions tied to risk.
Recommendation — Enforce conditional access checks for higher-risk transactions.

Practitioner Guidance

What to prioritise: Use step-up only when your signals show uncertainty, not as a substitute for poor risk scoring. If the transaction is clearly low risk, let it pass; if it is clearly malicious, block or review it rather than asking the customer to solve the problem.

What to verify: Measure whether step-up actually improves approval quality on the transactions that trigger it. A useful test is whether the challenged cohort has a meaningfully different fraud or chargeback profile than the unchallenged cohort.

What good looks like: Low-risk customers move through without interruption, while borderline transactions are challenged only when the extra check can reasonably change the outcome. That is the balance point where security and conversion both improve.

Practitioner takeaway: Step-up authentication should be treated as a selective decision-control, not a routine gate, and its success depends on using it only where extra proof materially improves confidence.