Join our Newsletter — 33% off our NHI Course
Home FAQ Identity Beyond IAM How should merchants use 3D Secure to reduce…
Identity Beyond IAM

How should merchants use 3D Secure to reduce true fraud chargebacks without adding too much checkout friction?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 17, 2026 Domain: Identity Beyond IAM

Merchants should apply 3D Secure selectively, not universally. The strongest use case is high-risk transactions where extra verification can stop stolen card use before authorization. For low-risk traffic, friction should be minimized because extra prompts can increase abandonment. The best approach is to combine risk scoring, issuer authentication, and checkout design so fraud controls protect revenue without damaging conversion rates.

Use 3D Secure Where It Changes the Fraud Profile

3D Secure works best as a targeted control, not a blanket checkout step. Merchants get the most value when they apply it to transactions with higher fraud likelihood, such as unusual purchase patterns, risky geographies, repeat attempts, or signals that the cardholder may not be the person placing the order. That is where extra issuer authentication can interrupt stolen-card use before authorization.

The practical trade-off is that 3D Secure is not free. Every challenge introduces the possibility of abandonment, failed authentication, or added latency, so forcing it on low-risk traffic can reduce conversion without meaningfully reducing chargebacks. For that reason, the control should be treated as part of a broader fraud decision path, not as a universal checkout gate.

Fraud teams usually get better outcomes when 3D Secure is combined with order-level risk scoring, device and behavioral signals, and clear exemption logic. The point is to route only the transactions that need stronger proofing into the extra step, while letting low-risk customers move through with less friction.

Design the Checkout Experience So Verification Helps Rather Than Hurts

checkout friction matters because legitimate buyers often have limited patience, especially on mobile and repeat purchases. A good 3D Secure strategy therefore depends on timing and presentation as much as on policy. If the challenge appears at the wrong moment or too often, even a sound fraud rule can create avoidable revenue loss through abandonment.

Merchants should watch for signs that the experience is too aggressive: a drop in completed checkouts, higher cart abandonment after authentication starts, or a mismatch between the transactions challenged and the actual fraud saved. If those signals appear, tighten the risk thresholds, revisit exemption rules, and make sure the authentication flow is performing as intended across devices and issuers.

Where possible, favour the least disruptive route that still gives issuers enough confidence to approve the transaction. That usually means using 3D Secure selectively for riskier sessions and relying on cleaner checkout design, rather than assuming more prompts will automatically produce better fraud outcomes.

Risk and Threat Considerations

3D Secure reduces exposure to true fraud chargebacks, but only when it is applied to the right transactions. Overuse shifts the problem from fraud loss to customer friction, while underuse leaves stolen credentials and card-not-present abuse insufficiently challenged.

Failure mechanism: The control fails when merchants either challenge too broadly, causing legitimate customers to abandon checkout, or challenge too narrowly, allowing high-risk payments to pass without meaningful verification.

Impact: Too much friction reduces conversion and can erase the value of the fraud reduction; too little verification leaves merchants with chargeback exposure, higher fraud losses, and more pressure on dispute operations.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
CIS Controls v86 — Access Control ManagementSupports limiting stronger verification to higher-risk transactions.
Recommendation — Apply Access Control Management principles to restrict extra verification to transactions that warrant it.
NIST CSF 2.0PR.AC — Identity Management, Authentication and Access Control3D Secure is an authentication decision that should be risk-based and least-friction.
ID.RA — Risk AssessmentSelective 3D Secure depends on scoring fraud likelihood before adding friction.
Recommendation — Use PR.AC to align authentication strength with transaction risk. Use ID.RA to drive challenge decisions from transaction risk signals.

Practitioner Guidance

What to prioritise: Put the strongest 3D Secure treatment behind transactions that are both high risk and economically meaningful. Low-value or repeat-customer flows often benefit more from friction reduction than from extra challenge rates.

What to verify: Measure post-challenge conversion, issuer authentication success, and the share of prevented fraud chargebacks, then compare those figures by risk segment. If the challenged population is mostly legitimate, the policy is too broad.

Decision rule: If a transaction has a credible fraud signal, challenge it; if the risk is low and the customer experience cost is likely to outweigh the fraud benefit, use a lighter path or an exemption. The right balance is the one that protects margin without making good customers pay the price for bad ones.

Practitioner takeaway: 3D Secure should be tuned as a risk decision, not deployed as a default obstacle, because the best fraud control is the one that removes true fraud while preserving the checkout flow for everyone else.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 17, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org