Join our Newsletter — 33% off our NHI Course
Home FAQ Identity Beyond IAM Why does PSD3 place more pressure on transaction…
Identity Beyond IAM

Why does PSD3 place more pressure on transaction authentication and fraud controls than PSD2?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 17, 2026 Domain: Identity Beyond IAM

PSD3 tightens the regulatory focus on payments, data, and security because fraud tactics keep evolving and cross-border payment environments are more complex. It expands Strong Customer Authentication expectations, pushes technology-neutral verification methods, and strengthens operational resilience. The practical result is that PSPs need controls that adapt quickly, support different transaction types, and reduce fraud without weakening customer trust.

Why PSD3 Puts More Weight on Authentication Than PSD2

PSD3 treats payment authentication as a moving control problem, not a one-time compliance checkbox. That matters because fraud patterns change quickly, payment journeys are more fragmented, and trust decisions now have to hold across channels, devices, and borders. The result is higher pressure on strong verification, adaptive fraud detection, and evidence that controls actually reduce loss.

PSD2 established the baseline for Strong Customer Authentication, but PSD3 raises the practical burden on payment service providers by expecting more resilience against evolving fraud methods and more flexibility in how authentication is applied. In practice, that shifts attention from merely meeting a rule to proving that the authentication flow remains effective under real transaction conditions.

What Changes Operationally for PSPs

PSPs now need controls that can distinguish low-risk from high-risk activity without creating avoidable customer friction. That means authentication policies must work across card, account-to-account, and cross-border flows, and fraud models need to support step-up decisions rather than relying on static thresholds alone. A rigid design is easier to audit, but it is also easier for attackers to route around.

This is where the pressure on fraud controls becomes visible. If authentication is too weak, the payment stack becomes an easy target for account takeover, social engineering, token abuse, and mule-enabled laundering patterns. If it is too strict, legitimate payments fail, conversion drops, and customers abandon trust in the service. PSD3 pushes organisations to manage that trade-off explicitly instead of hiding it inside legacy rules.

For teams trying to modernise their control set, the broader NHI and secrets lifecycle lessons in Ultimate Guide to NHIs are useful because payment fraud often succeeds where credentials, tokens, or automated access paths are overexposed. The same logic behind 52 NHI Breaches Analysis applies here: weak control over identity-bearing material expands attack surface and makes incident response slower.

Risk and Threat Considerations

PSD3 raises the cost of weak verification because fraud is no longer just a customer dispute problem, it is a control failure that can cascade into reimbursement pressure, operational churn, and regulatory scrutiny. The biggest risk is assuming that a compliant authentication flow is automatically a resilient one, especially when fraud actors adapt faster than policy updates.

Failure mechanism: Attackers exploit gaps between authentication strength, fraud scoring, and transaction context, then target the easiest path, such as bypassed step-up controls, compromised credentials, or payment journeys that are hard to score consistently across regions or channels.

Impact: Losses rise, false approvals increase, and the provider absorbs more operational and reputational damage because the control stack cannot prove it is reducing fraud without blocking legitimate activity.

That threat pattern is consistent with real-world account compromise and MFA-bypass behaviour seen in cases such as Microsoft Midnight Blizzard breach and Uber Breach, where trust in the authentication layer was the attacker’s entry point, not the end of the attack.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10 address the attack and risk surface, while NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AC — Access ControlPSD3 pressure centers on verifying transaction access before authorisation is granted.
DE.CM — Continuous MonitoringFraud controls must detect evolving abuse patterns across payment channels.
Recommendation — Align payment access decisions with least-privilege and step-up verification controls. Monitor transaction telemetry continuously for anomalous authentication and fraud signals.
CIS Controls v85 — Account ManagementPayment authentication depends on disciplined account and credential control.
6 — Access Control ManagementPSD3 increases pressure to restrict payment actions by risk and context.
8 — Audit Log ManagementFraud detection and challenge decisions require auditable transaction evidence.
Recommendation — Tighten account lifecycle controls for payment identities and recovery paths. Enforce context-aware access rules for high-risk payment actions. Log authentication outcomes and fraud decisions for review and tuning.
OWASP Agentic AI Top 10A1 — Prompt Injection and Tool MisuseAutomated payment and fraud workflows can be abused through trusted action paths.
Recommendation — Constrain automated decision paths so fraud logic cannot be manipulated or misused.

Practitioner Guidance

What to verify: Test whether your fraud controls can make different decisions for different transaction types, not just different users. A PSP should be able to show how step-up authentication, velocity rules, device signals, and anomaly scoring interact during a live payment, because that is where PSD3 pressure becomes measurable.

Decision rule: If the control only works when transaction patterns stay “normal,” treat it as brittle. Prioritise adaptive verification, control evidence, and monitoring over static policy tuning, because PSD3 is effectively asking whether your authentication model still works when fraud tactics and payment routes change.

Practitioner takeaway: Under PSD3, authentication is not valuable because it exists, it is valuable only if it remains proportionate, adaptable, and demonstrably effective against modern fraud paths.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 17, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org