Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› How should merchants balance PSD2 compliance with reducing…
Governance, Ownership & Risk

How should merchants balance PSD2 compliance with reducing checkout friction?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 26, 2026 Domain: Governance, Ownership & Risk

Merchants should treat PSD2 as a security requirement, not a reason to accept avoidable abandonment. The practical approach is to map where Strong Customer Authentication applies, use exemptions selectively, and coordinate closely with payment service providers. The goal is to preserve a smooth customer journey while keeping fraud controls strong enough to block risky transactions before they create chargebacks or churn.

Where PSD2 compliance and checkout friction actually collide

PSD2 is not just a regulatory box to tick, it changes how merchants design checkout, risk scoring, and payment routing. The tension appears when Strong Customer Authentication is applied too broadly, too late, or without exemptions strategy. The right balance is to preserve compliance while limiting unnecessary step-up prompts for low-risk, low-friction transactions.

In practice, merchants should separate the compliance question from the conversion question. Some transactions must be challenged, but many can be handled through exemption logic, fraud controls, and payment service provider configuration that reduces avoidable interruption.

How to reduce friction without weakening authentication

The most effective approach is to identify where SCA is mandatory, where exemptions are available, and where the payment flow can be structured to maximise successful authentication. That usually means relying on the payment service provider’s support for exemption signalling, 3-D Secure behaviour, and transaction risk assessment rather than forcing every customer through the same path.

Merchants should also look at the transaction mix. Low-value, repeat, trusted, or low-risk payments can often be treated differently from first-time, high-value, or anomalous orders. Friction is reduced not by removing controls, but by applying the strongest control only where the risk profile justifies it.

A useful practical test is whether the checkout experience changes because of the transaction, or because of a default integration choice. If the merchant has not tuned exemption use, authentication routing, and fallback behaviour, checkout friction often reflects implementation laziness rather than regulatory necessity.

What good payment authentication design looks like

Good design keeps the authentication burden proportional to risk. It uses the payment provider’s capabilities to support exemption requests, preserves clear fallback paths when authentication fails, and monitors approval rates, abandonment, and fraud outcomes together rather than treating them as competing silos.

It also means treating checkout performance as an operational control, not only a UX metric. If a payment method or authentication path increases abandonment without reducing fraud meaningfully, the merchant should revisit exemption policy, customer segmentation, and transaction routing. That review should include whether recurring customers, tokenised payments, or lower-risk baskets can be handled with less interruption.

Risk and Threat Considerations

Overly aggressive friction can create business risk by increasing abandonment, while overly permissive treatment can increase fraud, chargebacks, and issuer disputes. The challenge is not only compliance, but avoiding a checkout design that either blocks good customers or lets risky transactions through unchecked.

Failure mechanism: Merchants either challenge transactions that could have been exempted, or they weaken risk controls to preserve conversion. In both cases, the payment flow becomes misaligned with the actual fraud profile, issuer expectations, or provider configuration.

Impact: The result can be lower conversion, higher cart abandonment, more false declines, more chargebacks, and a checkout experience that trains customers to disengage at the final step.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5, NIST SP 800-63 and NIST CSF 2.0 set the technical controls, while PCI DSS v4.0 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
PCI DSS v4.0Req. 7 — Restrict Access by Business Need to KnowPSD2 checkout controls must stay proportionate to transaction risk and access needs.
Req. 8 — Identify Users and Authenticate Access to System ComponentsCheckout authentication design must ensure strong customer and account authentication where required.
Recommendation — Limit payment-flow privileges and approvals to the minimum needed for each transaction path. Enforce strong authentication for payment actions and step-up paths.
NIST SP 800-53 Rev 5AC-6 — Least PrivilegeCheckout and payment controls should restrict elevated handling to risky cases only.
Recommendation — Apply least privilege to payment and fraud-review functions.
NIST SP 800-63Digital Identity GuidelinesPSD2 balancing often depends on how authentication strength and step-up are implemented.
Recommendation — Use assurance-oriented authentication choices that match transaction risk.
NIST CSF 2.0PR.AA-05 — Managed Access ControlThe question is about tuning access and authentication controls without harming customer flow.
Recommendation — Tune access and authentication controls to the transaction's risk level.

Practitioner Guidance

What to prioritise: Start with transaction segmentation, not blanket checkout rules. Identify which payment paths are truly high-risk, which qualify for exemptions, and which are already safe enough to minimise interruption.

What to verify: Confirm that your payment service provider is configured for the exemption and authentication behaviours you expect, and that failed authentications still route cleanly to a retry or fallback path without duplicating charges or confusing the customer.

What to measure: Track approval rate, abandonment at the authentication step, chargeback rate, and fraud rate together. A healthy control reduces loss without creating a disproportionate drop in completed orders.

Practitioner takeaway: The right balance is usually not “more friction” or “less friction”, it is better risk targeting. Apply strong authentication where it changes fraud exposure, and remove friction everywhere else that the control is not buying meaningful security.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 26, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org