A customer finds the right product, adds it to their cart and reaches checkout ready to pay. The card is valid. The account has sufficient funds. The customer is genuine.
❌ Then the transaction fails.
From the customer’s perspective, the reason may be unclear. From the merchant’s perspective, a sale has disappeared. From the issuer’s perspective, the decision may have looked prudent: an unfamiliar merchant, a new device, an unusual location or a transaction that did not contain enough information to establish confidence.
This is the problem of false declines in 3-D Secure. The payment is legitimate, but the available signals make it look risky.
The consequences extend beyond a single failed transaction. False declines reduce revenue, frustrate cardholders and can send customers to competitors. The answer is not to remove security controls. It is to improve the quality of the decision.
That means combining richer transaction data, risk-based authentication and better coordination across the payment ecosystem. When the participants have a clearer view of the transaction, legitimate customers are less likely to be treated like fraudsters.
Fraud decisioning is designed to identify patterns that may indicate misuse. The difficulty is that legitimate customers often create the same signals.
A customer travelling abroad may buy from a new location. Someone replacing a phone may use an unfamiliar device. A high-value purchase may be completely normal during a holiday period. A subscription renewal may look different from the customer’s first purchase. A digital wallet or network token may also change the way a payment credential appears in a transaction.
None of these signals proves fraud on its own. But when an issuer cannot see the surrounding context, several relatively minor signals can combine into a decision that is too cautious.
This is why false declines are often a context problem. In a 3-D Secure flow, a transaction can fail at different points: authentication may be rejected, a customer may abandon or fail a challenge, or the transaction may pass authentication but later be declined during authorization. Understanding where the failure occurs matters because each problem requires a different response.
The underlying issue is often insufficient or inconsistent information. Merchants know about the customer relationship, order and session. Issuers have access to cardholder history, spending patterns and other risk signals. 3-D Secure provides an opportunity to bring more of that context together.
The immediate cost of a false decline is the value of the transaction that did not happen. The wider cost can be much higher.
Research from Checkout.com and Oxford Economics estimated that businesses in the United States, United Kingdom, France and Germany lost $50.7 billion to false declines in 2022. The research also found that 45% of consumers would not retry a payment after one false decline, while 42% said they would not return to the business after a failed payment attempt.
For merchants, payment approval is therefore part of the customer experience, not simply a back-office processing metric. A failed transaction can lead to cart abandonment, customer-support contacts or a customer choosing another business.
Issuers and payment providers face a similar balancing act. A high approval rate achieved by allowing more fraud is not a success, but neither is a low fraud rate achieved by declining too many legitimate customers.
The objective is better precision: fewer fraudulent approvals and fewer legitimate declines.
One of the most direct ways to reduce false declines in 3-D Secure is to improve the information available at the point of decision.
EMV 3-D Secure supports the exchange of transaction, device and payment context between merchants and issuers. This can include information about the customer account, shipping details, browser or device characteristics, transaction history and the relationship between the customer and the merchant.
The data does not guarantee approval. Instead, it gives the issuer a stronger foundation for deciding whether a transaction can proceed frictionlessly, whether a challenge is appropriate or whether the request should be rejected.
Visa’s guidance on high-quality data for Visa Secure with EMV 3-D Secure illustrates the potential impact. In its analysis, merchants that completed the 3-D Secure Method URL at least 95% of the time saw an average 8% lift in authentication success and an 8% lift in approval rate compared with merchants with lower completion rates. Merchants that populated more than half of the priority data elements saw an average 6% approval-rate lift.
The lesson is not simply to send more fields. Data needs to be accurate, complete, timely and relevant to the risk decision.
For merchants and payment providers, that means treating the authentication request as a source of transaction intelligence rather than a compliance message that can be populated minimally. For issuers, it means ensuring that the Access Control Server (ACS) and surrounding risk systems can interpret the available information consistently and use it in decisioning.
EMVCo also describes how device information collected through the 3DS SDK can assist with transaction risk assessment and help determine which authentication experience is appropriate. Reliable device-data collection is therefore an important part of the overall journey, particularly in app-based payments.
Better data is only useful if it leads to better decisions. This is where risk-based authentication becomes important.
Rather than applying the same authentication step to every customer and every payment, a risk-based approach evaluates the available signals and selects an appropriate response. A low-risk transaction may proceed through a frictionless flow. A transaction with meaningful risk indicators may require a step-up challenge. A request with strong evidence of fraud may be declined.
The principle is simple: authentication should respond to risk, not create it indiscriminately.
Effective decisioning considers the transaction, customer, device, location, payment method and previous authentication history together. A new device, for example, may look suspicious in isolation, but becomes less concerning when it belongs to a long-standing customer with a consistent transaction history and a familiar shipping address.
This is where static rules can struggle. Rules remain useful for expressing clear policy boundaries, but they can become blunt when asked to interpret complex and changing customer behavior. Dynamic risk assessment can preserve the protection those rules provide while adding the context needed for more precise decisions.
Issuers sit at the center of the 3-D Secure decision. Their systems determine whether a transaction can proceed frictionlessly, whether the cardholder should be challenged or whether the payment should be declined.
Reducing false declines starts with ensuring that the Access Control Server can use the full range of available information. Transaction, device, behavioral and historical signals should be evaluated in real time rather than relying too heavily on a narrow set of static indicators.
Issuers should also look beyond whether a challenge was issued. A challenge is not automatically a successful authentication. If customers abandon the flow, cannot access their authentication method or do not recognize the experience, a legitimate transaction can still be lost.
Monitoring authentication and authorization outcomes together can help identify whether the problem lies in risk decisioning, challenge completion, technical handling or downstream authorization. Analyzing performance by factors such as merchant, region, device and transaction type can also reveal problems that broad averages hide.
Entersekt’s 3-D Secure ACS is designed around this balance: using real-time, risk-aware decisioning to reduce unnecessary challenges while applying stronger authentication when risk warrants it.
Merchants cannot control an issuer’s risk model, but they can influence the quality of the information that model receives.
Account details, shipping information, transaction history and device data should be captured accurately and passed consistently through the 3-D Secure flow. Missing or contradictory values can make a genuine customer appear less trustworthy than they are.
Merchants and PSPs should also look beyond a single approval metric. Frictionless authentication, challenge completion, authentication declines, authorization declines and abandonment all provide clues about where legitimate customers are being lost.
This is particularly important across different markets. In its analysis of US 3-D Secure transactions, Stripe found that issuer behavior differed from Europe, with some US issuers declining transactions requesting 3-D Secure more aggressively because the flow was less familiar to customers and issuers.
The finding reinforces an important point: authentication performance is shaped by market context. A strategy that performs well in one region may not produce the same result in another.
Payment providers and acquirers sit between merchants, card schemes and issuers, giving them an important role in keeping the payment journey reliable and transparent.
Transaction data should not be lost, transformed incorrectly or inconsistently mapped as it moves between systems. Merchants should also have meaningful visibility into authentication and authorization outcomes rather than receiving a generic decline message that provides no path to improvement.
The broader opportunity is to treat payment authentication as a shared decisioning environment. Merchants have customer and order context. Issuers have account and cardholder context. Payment providers have visibility across payment flows. Better outcomes become possible when those signals are exchanged consistently and interpreted as part of one journey.
If an organization is seeing too many legitimate transactions fail, five questions can help identify where the problem lies:
These questions shift the conversation from “How many transactions did we decline?” to “Why did we decline them, and what evidence could have supported a better decision?”
False declines in 3-D Secure are often described as a trade-off between security and convenience. A more useful way to look at the problem is the trade-off between poor information and informed decisioning.
When an issuer receives limited or unreliable context, declining a transaction may be the safest available response. When that same issuer can evaluate trustworthy device, behavioral, transaction and customer signals, it may be able to approve the payment frictionlessly or ask for a proportionate challenge.
For merchants, that means improving the quality of the data they send. For issuers, it means strengthening risk-based authentication and challenge strategies. For payment providers, it means preserving the integrity of those signals and making performance visible across the journey.
The objective is not to approve everything. It is to give legitimate customers a fairer chance of being recognized as legitimate.
When 3-D Secure is used as a coordinated decisioning capability rather than a disconnected compliance step, it can do more than stop fraud. It can help protect revenue, strengthen cardholder trust and keep good transactions moving.