Join our Newsletter — 33% off our NHI Course
Home FAQ Identity Beyond IAM Why does strong customer authentication create both fraud…
Identity Beyond IAM

Why does strong customer authentication create both fraud reduction and revenue pressure for online merchants?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 17, 2026 Domain: Identity Beyond IAM

SCA reduces certain fraud paths by requiring stronger proof of identity, but it also adds steps that lengthen checkout and can increase cart abandonment. That creates a direct trade-off between control strength and conversion. Merchants that only focus on compliance can miss the commercial impact, while merchants that optimise the experience can protect revenue and security at the same time.

How SCA changes the fraud equation

strong customer authentication changes the economics of card-not-present fraud by making it harder for an attacker to succeed with stolen card data alone. The extra assurance can block account misuse, reduce false-positive fraud interventions, and lower the downstream cost of chargebacks and manual review. For merchants, that benefit is strongest where fraud loss is high enough to justify added friction.

In practice, SCA is a control-strength decision, not just a compliance checkbox. It shifts the burden from passive checkout acceptance toward stronger proof at the point of transaction, which means fraud teams can rely less on weak signals such as card details alone. That is especially valuable in environments where stolen payment data is cheap but verified customer proof is harder to obtain.

Where merchants have to support high-risk payment flows, payment authentication guidance from PCI DSS v4.0 is useful because it reinforces the need to restrict access and use stronger controls around payment transactions. The practical point is that stronger authentication should be designed to reduce exposure without turning every checkout into an exception path.

Why conversion pressure appears at checkout

The commercial tension comes from the fact that every additional authentication step can increase checkout time, create confusion, or interrupt a smooth purchase flow. Even when the authentication itself is technically sound, a merchant may still lose revenue if legitimate customers abandon baskets before completing payment. So the operational question is not only whether fraud falls, but whether the added friction is tolerable for the customer segment and channel.

That trade-off is why merchants need to look at SCA as part of the whole purchase journey. If challenge rates are too high, the control can be over-applied and undermine conversion. If they are too low, fraud reduction may be weaker than expected. The best outcome usually comes from tuning the authentication path to transaction risk, customer trust, and device or payment context rather than using one fixed experience for every session.

For payment organisations that want a broader control lens, OWASP ASVS is a useful reference for thinking about authentication, session handling, and access control together. Although it is not a payment-only standard, it helps teams see that security controls and user experience have to be designed together if they want fewer abandoned transactions.

How merchants balance protection and revenue in practice

Merchants usually get the best result when they treat SCA as a risk-based control rather than a universal hurdle. Low-risk transactions should be kept as smooth as possible, while higher-risk payments can justify stronger challenge steps. That approach protects revenue by preserving speed where the risk is low and concentrating friction where it has the most security value.

What to prioritise: measure both fraud loss and abandonment at the same time. A reduction in fraud is not a success if it is bought with a larger drop in completed sales. The most useful operating view is the combined effect on net revenue, not a single control metric.

What good looks like: authentication is visible only when it materially changes risk, fallback paths are controlled, and legitimate customers can still complete purchase with minimal friction. In other words, the control should feel selective and purposeful, not like a blanket obstacle.

Practitioner takeaway: the right SCA design is the one that reduces fraud without forcing unnecessary challenge, because the best control is the one that protects both transaction integrity and conversion at the same time.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and OWASP Agentic AI Top 10 address the attack and risk surface, while PCI DSS v4.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
PCI DSS v4.08.6 — System and application accounts with interactive loginInteractive account handling affects checkout authentication flow and merchant fraud exposure.
7 — Restrict access by business need to knowLeast-privilege access reduces payment-system exposure and supports stronger transaction security decisions.
Recommendation — Limit interactive authentication only to the cases that require it and keep payment journeys as friction-light as possible. Apply business-need access restrictions to payment systems and related controls to reduce abuse paths.
OWASP Non-Human Identity Top 10NHI-01 — Secrets and Credential ManagementSCA-adjacent payment systems still depend on protected credentials and authentication material.
Recommendation — Protect authentication material so payment assurance does not depend on exposed secrets or weak credential handling.
OWASP Agentic AI Top 10A2 — Identity and Access AbuseIf automated checkout or fraud tooling is used, access abuse can distort authentication outcomes.
Recommendation — Constrain automation that can alter authentication flows or fraud decisions.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 17, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org