Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› What are the signs that PSD2 is creating…
Governance, Ownership & Risk

What are the signs that PSD2 is creating more risk than protection?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 26, 2026 Domain: Governance, Ownership & Risk

Warning signs include rising abandonment during checkout, a spike in chargebacks, and fraud concentrating in exempt or out-of-scope transactions. If authentication is being added without a matching reduction in fraud losses, the control is not doing enough. Teams should watch whether good customers are being blocked while fraudsters still find gaps in the payment flow.

What the warning signs look like in a PSD2 rollout

PSD2 is only helping if strong customer authentication reduces fraud without breaking too much legitimate flow. The practical warning signs are operational: more customers abandoning at checkout, more transactions falling into chargeback or dispute paths, and more fraud moving into exemptions, fallback routes, or transactions that sit outside the strongest controls. That pattern usually means the control is adding friction faster than it is removing risk.

A second signal is when authentication volume rises but loss metrics do not improve. If teams add more challenges, redirects, or step-up checks and still see the same fraud pattern, the control may be protecting the wrong part of the flow, or attackers may be adapting faster than the protection does.

For payment teams, the important question is not whether authentication is present, but whether it is changing outcomes at the points where abuse occurs. A control that blocks good customers while leaving loss-making paths open is a sign of poor calibration, not stronger protection.

Why these signs matter operationally

PSD2 can create false confidence when organisations measure compliance activity instead of business and security outcomes. A payment journey can look more controlled because more users are challenged, yet the real effect may be higher abandonment, weaker conversion, and fraud concentration in the flows that remain easiest to abuse.

That is why the balance between protection and friction matters. If authentication is introduced without a matching reduction in fraud losses, the control is not achieving its purpose. In practice, that often means exemptions are overused, risk scoring is too blunt, or the fraud team is not seeing how attackers adapt around the strongest step in the journey.

The cleanest read is comparative: if the protected flow is materially safer than the unprotected one, the control is probably working. If the protected flow is simply more expensive for customers to complete, while fraud shifts elsewhere, the organisation has probably moved risk rather than reduced it.

What to inspect before calling PSD2 effective

Start by separating customer friction from fraud effect. Look at abandonment, conversion, chargebacks, fraud rates, and exemption usage together, because any one metric on its own can be misleading. Then compare outcomes by payment path: authenticated, exempt, out-of-scope, fallback, and failed-authentication flows often behave very differently.

It also helps to check whether fraud is concentrating in the paths least touched by the control. If losses are clustering in exemptions or other bypass routes, the programme may need tighter policy, better risk scoring, or narrower use of exceptions rather than more authentication everywhere.

Finally, verify whether good customers are being blocked at a rate that is operationally unacceptable. A protection layer that disproportionately stops low-risk buyers usually needs tuning, because the business cost can exceed the security value it creates.

Risk and Threat Considerations

The main risk is control displacement: attackers and fraudsters often move toward the easiest remaining payment path when stronger checks are added to the main flow. That can leave the organisation with higher friction, lower conversion, and little or no improvement in loss prevention.

Failure mechanism: Authentication is applied unevenly or too broadly, so legitimate users are interrupted while fraud is redirected into exemptions, fallback routes, or other weaker branches of the payment journey.

Impact: The business pays more in customer drop-off and support burden, while fraud losses stay flat or become more concentrated in the paths that were least protected.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP API Security Top 10 addresses the attack and risk surface, while NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5IA-2 — Identification and Authentication (Organizational Users)PSD2 checkout friction is an authentication outcome problem.
AC-7 — Unsuccessful Logon AttemptsRepeated auth failure patterns can indicate poor customer experience or abuse.
Recommendation — Tune step-up authentication to reduce fraud without overblocking legitimate customers. Monitor repeated authentication failures to detect friction and attack pressure.
OWASP API Security Top 10API2 — Broken AuthenticationPayment flows often rely on authentication strength and failure handling.
Recommendation — Review payment authentication flows for weak or bypassable challenge handling.
NIST CSF 2.0PR.AA-01 — Identities and credentials are issued, managed, verified, revoked, and audited for authorized users, devices, and servicesPSD2 effectiveness depends on managed authentication and exception handling.
Recommendation — Audit payment credentials and auth paths to ensure controls reduce loss, not just add steps.

Practitioner Guidance

What to measure: Track abandonment, chargebacks, fraud loss rate, exemption rate, and approval rate together, then review them by payment path rather than only as a whole-programme average. The most useful signal is whether stronger authentication correlates with lower net loss in the same flow.

Decision rule: If fraud losses are not falling in the protected journey, do not add more authentication by default. First tighten exemption policy, review risk scoring, and identify where attackers are still reaching payment success.

Practitioner takeaway: PSD2 is creating more risk than protection when it improves formal compliance but worsens the combined outcome of loss, friction, and bypass behaviour.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 26, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org