Insight

Strong customer authentication at checkout: the PSD2 exemptions that reduce friction

Under PSD2, most electronic payments in the European Economic Area need strong customer authentication. For online shops, the difference between a smooth checkout and lost orders often lies in how 3-D Secure is implemented and which exemptions the payment provider requests.

Published by Somnium Digital

A wireframe of the Insight page: headline, supporting sections and a single call to action. Insight Strong customer authentication at… Get in touch 01 What strong customer… 02 Who applies it and wh… 03 Exemptions and out-of…

What strong customer authentication requires

The second Payment Services Directive requires payment service providers to apply strong customer authentication when a payer initiates an electronic payment, subject to exemptions. The detailed rules are set out in the regulatory technical standards adopted as Commission Delegated Regulation (EU) 2018/389.

Strong customer authentication means using at least two independent elements from different categories: knowledge, something only the user knows, such as a PIN; possession, something only the user has, such as a registered phone; and inherence, something the user is, such as a fingerprint. For remote payments, the authentication must also be dynamically linked to the amount and the payee.

For card payments online, strong customer authentication is usually performed through EMV 3-D Secure. The customer confirms the payment in their banking app or with a code and biometric check, and the card issuer decides whether authentication is needed or an exemption can apply.

Who applies it and who decides

The obligation sits with the payer’s payment service provider, which for cards is the issuing bank. Merchants and their payment providers can request exemptions, but the issuer can always insist on authentication. That is why the same checkout can behave differently for customers of different banks.

Strong customer authentication applies where both the payer’s and the payee’s payment service providers are in the European Economic Area. Where one side is outside, such as a card issued outside the EEA, the rules apply on a best-efforts basis. The United Kingdom retained a comparable regime after leaving the EU.

Exemptions and out-of-scope transactions

Some payments are outside the scope of strong customer authentication altogether, while others can use an exemption requested by the merchant’s provider or applied by the issuer. The distinction matters, because an out-of-scope transaction is not counted against exemption limits.

Low-value payments
Remote payments up to 30 euros can be exempt, provided the cumulative amount since the last authentication does not exceed 100 euros or five consecutive transactions.
Transaction risk analysis
Payment providers with low fraud rates can exempt remote card payments up to 100, 250 or 500 euros, depending on how low their reference fraud rate is.
Recurring payments
A series of payments of the same amount to the same payee requires authentication for the first payment, and later ones can be exempt.
Trusted beneficiaries
Customers can add a merchant to a list of trusted beneficiaries held by their bank, where the bank supports it.
Merchant-initiated transactions
Payments initiated by the merchant under an agreement the customer authenticated, such as usage-based billing, are treated as outside the customer-initiated scope.
Mail and telephone orders
Payments taken by mail order or telephone are not electronic payments initiated by the payer and are out of scope.

Why exemptions are not free

When an exemption is applied at the merchant’s request, liability for fraud usually shifts back from the issuer to the merchant’s side under card scheme rules. Authentication shifts liability to the issuer; skipping it keeps the risk. Merchants selling high-value goods or items attractive to fraudsters should decide deliberately where friction is worth the protection.

Issuers also decline exemption requests when their own risk models see something unusual, and some issuers soft-decline, asking for authentication and allowing the payment to be retried. A checkout that does not handle soft declines correctly loses sales that would otherwise have succeeded.

Where checkouts lose payments

The most common problem is an outdated integration. Older 3-D Secure versions relied on redirects and static passwords that customers forgot. Current EMV 3-D Secure sends richer data about the device, the customer and the transaction, which lets issuers approve more payments without a challenge. Incomplete data leads to more challenges and more abandonment.

Mobile flows are the second weak point. Customers are sent to their banking app to confirm and do not return to the shop, or the return path breaks in in-app browsers. Testing the full journey on real devices and banking apps catches problems automated tests miss.

The third is subscriptions and saved cards. If the first payment is not authenticated with the correct flags to establish a mandate, later merchant-initiated charges fail and customers are asked to authenticate repeatedly, causing involuntary churn.

Improving authentication rates

Work with the payment provider’s reporting to see authentication rates, challenge rates, frictionless approvals, soft declines and failures by issuer, country and device. The data shows whether problems are concentrated in a particular bank, browser or step.

Send complete 3-D Secure data, including billing and shipping details and device information. Enable wallets such as Apple Pay and Google Pay, where the device authentication can satisfy strong customer authentication and is familiar to customers. Use exemptions selectively for low-risk, low-value orders, and make sure recurring and stored-credential flows are set up correctly from the first payment.

The EU has proposed revising its payment services rules through a new directive and a Payment Services Regulation, which would also affect authentication. Merchants should check the current status of those rules with their payment provider rather than rely on older guidance. This article is a general overview and not legal advice.

Questions

What is strong customer authentication?

Authentication using at least two independent elements from knowledge, possession and inherence, required for most electronic payments in the EEA under PSD2.

Is there a low-value exemption?

Yes. Remote payments up to 30 euros can be exempt, within cumulative limits of 100 euros or five consecutive transactions since the last authentication.

Who decides whether authentication is required?

The payer’s payment service provider, usually the card issuer. Merchants can request exemptions, but the issuer can still require authentication.

Do subscriptions need authentication every month?

Usually not. The first payment establishing the agreement is authenticated, and later merchant-initiated or recurring payments can proceed without it if set up correctly.

Does using an exemption change fraud liability?

Often yes. Exemptions requested by the merchant side usually keep fraud liability with that side under card scheme rules.

Are telephone orders covered?

Mail and telephone orders are out of scope of strong customer authentication.

Do digital wallets help?

Yes. Wallets such as Apple Pay and Google Pay use device authentication that can meet the requirements with less friction.

Where this sits in what we do

This article covers one decision inside a wider engagement. The solution page sets out how that engagement runs, what it includes and what it costs to find out.

Losing orders at the payment step?

We analyse authentication and decline data, fix 3-D Secure and stored-credential flows, and test checkouts on real devices and banking apps.

Get in touch

Tell us what you are trying to change

Describe the problem rather than the service — the two frequently differ, and working out which is which is the useful part of a first conversation. We reply within one working day, and if it is outside what we do well you will hear that in the reply rather than after a call.

We use what you send to reply to you. Nothing else, and no list.

WhatsApp