---
title: Why PSD2 gives merchants the upper hand around Strong Customer Authentication
date: 2018-11-19T11:49:00+00:00
author: Martin Sweeney
canonical_url: "https://www.ravelin.com/blog/why-psd2-gives-merchants-the-upper-hand-around-strong-customer-authentication"
section: Blog
---
Blog /[3DS &amp; SCA](/resources?search=&category%5B0%5D=134550#resourceContainer "Go to 3DS & SCA")

# Why PSD2 gives merchants the upper hand around Strong Customer Authentication

Merchants with low fraud rates will be able to shop around for Acquirers who can offer authentication exemptions under PSD2. The balance of power will be permanently shifted.

![Why PSD2 gives merchants the upper hand around Strong Customer Authentication](https://storage.googleapis.com/ravelin-website-assets-production/assets/images/_blogSmall/2052/Screenshot-2018-06-01-10.11.42.webp)

*This article was originally published in* [*Payments Card and Mobile*](https://www.paymentscardsandmobile.com/psd2-giving-merchants-and-strong-customer-authentication/)*.*

The Second Payment Services Directive ([PSD2](https://www.ravelin.com/insights/ultimate-guide-psd2-strong-customer-authentication)) certainly covers a lot of ground, but one important and largely overlooked aspect is the requirement that:

> *"strong customer authentication \[…\] should be applied each time a payer \[…\] initiates an electronic payment transaction"*

Prima facie, this means that all online card payments initiated by European Customers in Europe now need to use 3D Secure - a technology so notoriously poor for conversion that most sophisticated merchants today deploy it selectively for only the riskiest of transactions.

When this requirement was first floated by the European Banking Association (EBA), they got more than they bargained for when the Payments Industry [strenuously objected](https://www.eba.europa.eu/regulation-and-policy/payment-services-and-electronic-money/regulatory-technical-standards-on-strong-customer-authentication-and-secure-communication-under-psd2/-/regulatory-activity/consultation-paper/1548180#responses_1548180) to this regressive and unnecessary stance.

The outcry prompted a concession from the regulators: **Exemptions**.

## Exemptions from Strong Customer Authentication (SCA)

There are three primary exemptions from SCA relevant to online card payments: Low Value Transactions, Merchant Initiated Transactions and, most importantly "Low Risk Transactions".

If you're able to determine that a transaction is Low Risk by using Transaction Risk Analysis (TRA), and your aggregate fraud rate is low, you may request an exemption from SCA.

That headline requirement should now read:

*"strong customer authentication should be applied each time a payer **directly** initiates a \[…\] **non-low value** electronic payment transaction \[…\] **unless you're very good at Fraud Detection**"*

## Regulated Entities

Under [PSD2](https://www.ravelin.com/blog/psd2-what-online-merchants-and-their-customers-need-to-know), transaction fraud liability resides with the entity that triggers the exemption. For our purposes, the entities here are '*regulated payment service providers*' which in online card payments means Issuing and Acquiring Banks.

Since it's the Issuing Bank performing the SCA, it's usually the Acquiring Bank that will request the exemptions from SCA and assume liability for any resulting fraud.

## What this means for Acquirers

Only Acquirers with low fraud rates across their entire portfolio, and compliant transaction risk monitoring technology, are eligible to use Transaction Risk Analysis (TRA) exemptions from SCA.

The ability to use these exemptions will become a key differentiator between Acquirers, with merchants moving their volumes away from players who force them to use 3D Secure.

Acquirers will have to work hard to attract and retain low risk merchants in their portfolio, and may even contemplate splitting their entity into two cohorts; low and high risk; with all the legal and operational burden that that entails, in order to remain competitive and attractive to demanding merchants.

Put another way; Acquirers who operate a high risk portfolio or are unable to perform Transaction Risk Analysis will only able to compete on price. This might suit some Acquirers but not those with an eye on margin, profit and longevity.

## What this means for Merchants

A key part of any online payment strategy is optimising for high payment acceptance and conversion, where a smooth user experience is at the core of both. Since blanket use of 3D Secure is so unappealing to sophisticated merchants, the ability to avoid it wherever possible is a key requirement for any Acquirer the merchant may choose to use.

Merchants with historically low and well managed fraud rates and high or growing volumes will be in increasingly high demand by Acquirers seeking to maintain the low risk portfolio they'll need to offer SCA exemptions to their merchants.

All this gives the upper hand to merchants in contract and relationship negotiations in this brave new world.

**Make sure to also read about the upcoming PSD3**

![Ravelin Logo](https://storage.googleapis.com/ravelin-website-assets-production/assets/images/ravelin-symbol-logo-transparent.webp)

## Stay up to speed

Get the latest reports, analysis and advice on fraud, payments and growing securely online in your inbox.

Subscribe 

  

## Author

![Martin Sweeney](https://storage.googleapis.com/ravelin-website-assets-production/assets/images/_avatarSmall/201892/Martin_Sweeney-1.webp)

Martin SweeneyCo-Founder and CEO

With a background in software and physics, Martin Sweeney believes in harnessing the power of technology to solve real-world problems. He co-founded…

[More from this author](https://www.ravelin.com/author/martin-sweeney)

## Related content

[Blog / Payments &amp; payment fraud

### Card payment liability shift – everything you need to know to reduce chargeback burden

The knowledge you need to make the most of liability shifts and reap the benefits for your company – including saving money on chargebacks.

![Freddie burgess](https://storage.googleapis.com/ravelin-website-assets-production/assets/images/_33x33_crop_center-center_none_ns/281707/freddie-burgess.webp)Freddie Burgess,Senior Product Support Analyst](https://www.ravelin.com/blog/card-payment-liability-shift-for-chargebacks)

[Blog / Fraud analytics

### Refund abuse KPIs: How to measure and reduce refund fraud rates

What you need to know to assess and quantify refund abuse – as well as to measure whether your refund abuse solution and strategy are delivering results.

![Can](https://storage.googleapis.com/ravelin-website-assets-production/assets/images/_33x33_crop_center-center_none_ns/280078/can.webp)Can Colak,Senior Product Manager](https://www.ravelin.com/blog/how-to-measure-refund-abuse-kpis)

[Blog / Press release

### Driven by AI, customers now rival criminals for ecommerce fraud, say merchants

Global ecommerce fraud enters a new phase as losses continue to climb. Merchants now view criminals and their own customers as presenting a comparable risk, and there's a gap in AI adoption.

![Ravelin Symbol Blue 1](https://storage.googleapis.com/ravelin-website-assets-production/assets/images/_33x33_crop_center-center_none_ns/187712/Ravelin-Symbol-Blue-1.webp)Ravelin Technology](https://www.ravelin.com/blog/ravelin-fraud-survey-2026-press-release)
