Mastering the Interplay of Tokenization and 3-D Secure
The session also covers practical ways to reduce false declines, improve approval rates, and deliver lower-friction digital payment experiences. If you're focused on strengthening card-not-present (CNP) fraud controls while protecting customer experience, this recording offers a useful view of where secure commerce is headed.
Highlights
- Why tokenization and 3DS work best as a layered approach to credential and identity protection
- How better data quality improves issuer decisioning, approval rates, and fraud outcomes
- What merchants and issuers can do to reduce false declines and unnecessary checkout friction
- How data-only strategies can support smarter authentication and authorization decisions
- Why these trends matter as digital commerce evolves toward wallet-first and agentic experiences
Want to dive deeper? Download the companion white paper for a closer look at the convergence of tokenization and 3-D Secure.
Show full transcript
Hello, everyone. Thank you for joining us today. exciting conversation ahead, I think, about tokenization and 3DS. an interesting one, a forward-looking one. for sure. And for those on the other side, again, kind of a carry on from what we had sent out in, a white paper that Glenbrook and Intersect recently did on this topic. Just to level set on what we're getting into today. So again, I think, just for everybody who is attending, we wanna get into kinda three kinda core topics, and then we'll finish with that Q&A.
The first topic, we really wanna talk about the convergence of tokenization and 3DS. We'll unpack that a little bit, what that looks like, how we're starting to see some of those silos break down. I think it's kind of the second big group, and again, we'll, we'll unpack this a lot more, is that... Hey, Chris welcome back. shifting data foundations and the impact to RBA and authentication, so we'll get into that. And then topic three we'll get into is kind of the impact on authorization and kind of that customer experience.
So Chris, welcome. Dewald, appreciate you both being here. Always good to catch up and talk with you two. do you wanna do quick intros and then, and then we'll kinda jump into it? Sure. Sure, yeah. Chris, you wanna start with- Yeah, sure. Well, hi, everybody. I'm Chris Riardi. I'm a partner at Glenbrook Partners. we're a payment strategy consulting firm, that's been doing this for about twenty-five years or so. I focus, really working throughout the full payments value chain, working closely with merchants, with banks, with service providers, with a lot of my focus on fraud and risk management.
Dewald, I'll send it over to you. Great. Yeah, thanks. Hey, everyone, name's Dewald Naude co-founder and chief, and chief strategy officer for Intersect. we're a business that focuses on payment authentication and then securing transactions in flight. And, started the business pretty much from, twenty-- in, twenty ten in South Africa. and, we've expanded over the years into Europe and to the US, and today. we're a global business. And so, have a pretty good idea across both merchants and issuers, when it comes to transactions.
So a, a good view of the total, transaction flow there. Looking forward to the conversation today. Thanks, Dewald. Thanks, Chris. Appreciate you both. okay, jumping in. So kinda alluded to this before, but really want to unpack this concept and this topic of the convergence of tokenization and 3DS, right? I think we see and hear it more and more, and it's, it's pretty rapidly accelerating. and they're really no longer independent silos, right? As they start to come together, we're starting to see a little bit more of a unified layer across some of the data integrity and the risk management and how that's starting to look and how we're approaching that.
And so as we kinda think about this and see that, Chris, I wanna start with you and just kinda get some of your thoughts of of this convergence and what you're seeing and hearing. Yeah. So let me first say, first of all, thank you for, having me. Let me first say that, you know, this is a topic that not a lot of people are talking about right now. It's, it's kind of niche, but at the same time, it is something that is really go-- impacting today, merchants and issuers.
And i-it-- we will see this have a bigger impact on merchants and issuers in the future, all these themes that we're talking about. So I think it's really important that we get ahead of this. I think maybe a good way to start is to just talk a little bit about kinda the state of tokenization and where we stand here. if you look at the messaging that's coming from Mastercard and Visa, tokenization is really important to their strategy. You just have to listen to their quarterly earnings calls, and out of all the issues that Mastercard and Visa deal with, they take five minutes out of almost every earning call just to talk about tokenization, V-Visa especially these days.
That shows how important it is. And the messaging that we're hearing from them is incredible growth continues from tokenization almost now at the point that it's, it's almost fifty to a hundred percent year over year in regard to network tokens that, that are issued through both networks. so they very much see a future where the future on their network is comprised of tokenization everywhere either card on file tokens that are kept at at a merchant, tokens that are kept in a wallet like an Apple Pay or Google Pay wallet, or tokens that might be authenticated at the time of transaction, like like click to pay.
and I think all of this kind of leads us to, this continued use of tokenization very often leads to this misbelief that, tokenization in all cases equals full credential security and tokenization always equates to identity security. And that's not always the case, and especially in the case of identity right? We do have this concept of authenticated tokens. We have this concept of unauthenticated tokens, but the issue is there's weakness in both of those models.
Unauthenticated tokens can essentially be requested by anybody. Any merchant can, request a token. There's no authentication required. And the key thing to note about authenticated tokens is that they only address identity validation at the time of provisioning. They don't address identity, integrity or validation through the subsequent life cycle of that token. So I think that's really important to note. And all of this is gonna be more important in the future as Visa and Mastercard have signaled that by twenty-thirty, they wanna get rid of, the input of PANs in the clear by consumers.
So that by default leads us to wallet-driven models, click to pay, card on file tokens, where tokenization is really the foundation here. So we really just wanna stress the theme today I think, that tokenization is focused on protecting the credential. Three DS Secure is really focused on validating the customer, but they have to work together in a layered approach in order to-- for us to get sort of a holistic, risk management view here. So it's, it's a really complex interplay for sure.
Yeah. Thanks, Chris. And I think, such a good point too on just like the acceleration of it and how focused everybody is. And it's interesting the point you made there is we're seeing more on the consumer and the experience side of those rises in the wallets and the click to pay, right? It's almost like we're, we're being forced on the front end to, to kinda get there and keep up with this. So- Yeah, absolutely. Appreciate that. So Dewald, I think just kinda shifting over here to, I'm interested to get your thoughts.
I know sometimes when you and I have talked about this in the past you kindly and wonderfully have both kind of that strategic but also tactical standpoint to things. so when we think about this maybe from a little bit more tactical level what are, what are your thoughts here? Sure. And I think the you know, just to kind of reiterate that very important point that Chris made, that you know, the tokenization kind of, you know, the, the protocol, the action around it's all about kind of securing the credential right?
You when you, when you have a s-- a, let's say a a card, right, and you've got-- you can have multiple tokens that are actually tied to that card, right? So I know sometimes the, you know, the issuers or the networks will kind of let's say, refer to that master you know, card or PAN where all these tokens kinda hang from as the FPAN right, or the, which is that master kind of account. And you can then kind of you know, issue num-- a number of different tokens against it, whether it be one-time use tokens or, you know, maybe tokens that are specifically let's say, scoped for a specific merchant, specific amount.
That really kinda helps you to kind of secure the credential and, and kind of limit the scope of the credential which is a great advantage, right, in terms of you know, securing that credential. But as Chris mentioned the ongoing authentication and, and making sure that those tokens are used in the intended way by the intended person or the intended you know, IoT device or agent, right, even, that's the part where, sometimes there's a, I guess a little bit of a, a lack of, of realizing that the token in and of itself doesn't mean you're now, you know, completely secure.
You still have to do that identification. You still have to make sure on an ongoing continuous basis that the transaction that is performed by that token is in fact, you know, legitimate and you know, performed in a, in a, in a way that's consistent with the mandate or the intent of the cardholder, right? And so I think one of the points that I perhaps wanna highlight around that is there's a almost a little bit of a temptation as you, as you start to kinda think about this tokenized world where, you know there's many times, this perception that, okay so if we're gonna have these secure credentials, we only have to, you know secure the issuing of of the token.
If you issued the token securely after that everything's fine. You don't have to continuously authenticate. And so what then happens is, most of the times, if you look at just some of the discussions that I've had, the initial approach to something like tokenization is that we should only do something like strong customer or strong cardholder authentication at the point of issuing a token into a wallet or something like that, and not then actually do ongoing authentication.
And what happens essentially in that case, we've seen a couple of studies kind of, around just what happens in that case, because what essentially happens when you do that is you're only sending high-risk transactions kind of via this rail, you know, for authentication, which means the models on the issuer side only sees high risk or bad transactions. And so it never really gets to see what good looks like. And the the challenge with that is, that it almost becomes like, you know, this this, let's say scenario of, of kind of trying to get insurance for something that happened already, right?
in the sense that you, you can't go back, once something's happened and then say, " yeah, now now I want protection for it." There's kind of like a learning period, right, that's kinda required to see, this is what good looks like over time, you know, in the same way that you would have to have a policy for some time before it will actually you know, protect you, from an insurance perspective. And so I think that's something that perhaps, when we think about this and when we start to design for this tokenized world that we-- that I think it's gonna be very important to kinda keep in the back of your mind is that there is you know, a requirement still to secure the transaction and to, and to on an ongoing basis actually use the tools for data sharing between a merchant and an issuer to be able to train the models in the correct way so that when the bad transactions do come, those models are equipped to make the right decision.
and so that's something that I think is gonna be very important from a tactical perspective when it comes to how we actually, you know, deploy these things. And of course, three secure when it comes to e-commerce is a very powerful tool, and an existing tool to do that, to actually share that data, you know, from merchant to issuer, and to enable them to actually then, you know, build the models and properly secure those transactions on a continuum base-- continuous basis.
Thank, thanks so much. I appreciate the, you know, you can't go back. but I wanna use, I wanna use that too, right, in terms of like the concept of the use cases and how we're getting into it 'cause again, starting to look at kind of the next, you know, part of the conversation we're seeing those shi- shifting kinda data foundations and really the impact across RBA and how it's, it's starting to change visibility and the quality of the data available.
And so-With that, you know, again y-to your point, like, there feels like there's almost a little bit of a, you know, maybe recalibration or like how do we look at some of the models that we currently have employed. and so Dull, I kinda wanna start with you there. As like we think about this foundational shift in RBA what are the key things that kinda stand out for you? Yeah. I think it's it's, w-we're, we're, we're blessed at the moment with a lot of data, the ability to share a lot of data in, in real time, right?
if you look at at, you know, some of the protocols, something like Three Secure as an example, has 150 data elements, right? That it actually sends across. And, I think if you really look at evaluating and the richness of that data that actually a-allows you to make a good decision around that we s- we start to get into a world where we probably need to kind of, you know, get rid of the hangover Three Secure one in the sense that Three Secure one was very much like a way for you to kind of challenge a cardholder, right?
So it was kind of almost like a, let's say like a, a security checkbox, so to speak, right? Like, hey you know, like if there's risk you know, let's, let's, let's use Three Secure so that we can actually challenge someone. So that's why in in a lot of cases, because of the, the limited kind of data sharing elements and capabilities that that protocol had, you would see that it was mostly used for challenges. And of course when there's a challenge always kind of, approached to something like that merchants would try to kind of avoid that a little bit just to make sure that, hey, okay you know, only the ones that we want challenged, we would send via this rail.
I think what we're starting to see now with the, you know, the, let's say, the new version of these protocols is that with these rich data elements and with the schemes and things like tokenization actually starting to to, provide much more high quality data in that message that actually comes through to the issuer that tool that used to be a compliance tick box now becomes something that's actually an authorization you know, optimization tool, in the sense that you have a lot of data elements that you can actually you know, look at, and you can evaluate that without the time pressures that you typically see on the authorization, stream at that stage, because this is authentication that happens prior to authorization.
And what that means is you... With that rich data that you can look at, you can frictionlessly approve a lot of that. And so it actually becomes a way for, you know, issuers and merchants to, prior to the transaction kinda happening, already kinda getting that green light from the issuer that, "Hey, yeah, I'm happy with this. When you submit it, everything's gonna be great." And we're starting to see some of the, you know, some of the organizations that really have have made that shift from a compliance tick box kind of approach towards a authorization optimization strategy using this much more to kind of, you know, really kind of mark transactions for good versus just trying to, to see the bad ones for authentication.
Seeing some really good results where your authorization uplift is quite significant and measurable, right? And so definitely something that I think is gonna be key and is a key way of thinking about it, going forward because you now have the data. and I think that kind of also becomes more important as we go into some of these new, you know, trends that are kind of in the, in the industry. You know, tokenization and, you know, these rich data share journeys become all the more important as we, as we start to kind of enter into the world of agentic commerce, right?
Agentic commerce you know, something that's obviously very topical at the moment. But if you look at it, the frameworks that are being de- kind of developed by the schemes around how agentic commerce will kinda play out is very much rooted in things like tokenization cardholder mandates that, you know, are sent with that. And so you're getting things like proof from the c- the cardholder, proof that they've already, authenticated and given a mandate to an agent to execute within.
And that proof is sent together with the agent transaction kind of over these rails, which means by the time that something like a ACS on the Three Secure side, an issuer gets that they've got all the data to prove that the cardholder has looked at this cardhold- cardholder has approved it, and you know, this is a registered agent, for example, right? There's things like know your agent now registration protocols kind of as part of that, framework as well.
And so what that means is this same tool that you kind of used, you know, with your normal, commerce now has the ability to kinda look at these additional fields, these additional data fields, and frictionlessly approve much more of these transactions. And then by the time that they hit your authorization stream, you've already got that green tick box there to say, "Hey, we've already looked at this. We're happy with this. Nothing to see here. Let's go." And that really then is kind of the opportunity here, you know, to kind of reuse, some of these capabilities, that's, that are already implemented in a, in a more, you know, let's just say like a more constructive way versus a compliant way.
Awesome. Thank, thanks a lot. I was wondering too if you're gonna touch on the agentic thing. so I'm glad you did. I feel like we could take a whole separate conversation if everybody- Right... wants to come back for the second version of this live discussion, we'll, we'll do it on agentic commerce. But, thanks. So Chris, again kinda keeping this topic here with you. I think you obviously, Glen- Glenbrook, super close with, you know, FIs and merchants in the market in those conversations.
And so how are you kinda seeing some of, you know, those those different audiences and segments really lean into like the value of this shift? Is there- Yeah... some early indicators? How are they kind of approaching it? Yeah. So I maybe want to emphasize or put a finer point on some of the points that, Dewald raised earlier. first thing is I think we have historically had this notion of, Dewald used the term of three DS secure being a compliance checkbox right?
And I think what you mean by that, Dewald, is that we know in some major geographies like the UK and Europe, for example we have requirements under PSD two and the forthcoming PSD three that says you have to do some type of strong customer authentication. Very often, three DS secure is the way that that is accomplished right? But m- merchants very often are not really putting the effort into kind of the, the next step of executing a three DS secure authentication, which is ensuring that the data is robust, the data is consistent, and the data is good.
They're just sort of executing it, you know to, to check the box, if you will, from a compliance perspective, and that has been a problem for a long time. But this is a little bit of a chicken and egg situation, right? Because you've had this historical issue of merchants saying "Well, you know, I don't maybe put a lot of trust in three DS secure decisioning because I'm not getting good decisions coming back from issuers." And then issuers saying, "Well, I can't really come back with quality responses because the data I'm getting is pretty poor." So, you know, that's a historical problem, right, where low quality data leads to sort of low issuer confidence, which leads to poor three DS performance or more friction, at the consumer level.
So I think that's a historical problem. I think the smart merchants, however, have been taking advantage of the expanded data set capabilities that we've been talking about really focusing on enriching the data stream and also taking it to the next level and understanding which issuers are better at actually using that data, than others and being adaptive in how they approach their requests to issuers. So I do know a number of you know, major merchants that put a lot of effort into doing issuer and BIN, even within an issuer BIN-level profiling, on those issuers to understand how they adjust their authentication strategy as a result, their tokenization and their authentication strategy.
and we should note that everything that I've just talked about regarding three DS authentication there's kind of a parallel to that with tokenization as well. Merchants see various performance profiles from issuers. they see various perf- performance profiles on sets of bins from issuers. And, the smartest of merchants sometimes will say "I'm not even going to send a token down the line to this issuer. I'm going to revert back to PAN." Or they'll say, "I'm going to go with a token to start with and I'm going to fall back to PAN if I get a decline." So we have this really fragmented environment now both on the three DS end and the tokenization end that's making this very challenging for merchants.
But the bottom line is better data equals better approvals, and we want to get to a point, going back to kind of what Dewald was talking about earlier, where three DS, the presence of three DS is not looked at as a risk signal. It's looked at as a trust signal, right? And in this scenario where merchants are saying, particularly in unregulated geographies "Hey, I'm only going to send the riskiest of transactions to an issuer," that makes three DS a risk signal and not a trust signal.
But if a merchant starts building good data sets, consistently sending it down the line, using data only rails and such, which we'll talk about in a second, that starts to, to shift the balance from risk to trust and allows the issuers to make much better informed decisions on the merchant's behalf. Yeah. Thank, thanks, Chris. And on John notes, I think that's such a key thing, the trust signal, right, and the better data driving kind of better decisions and how we all leverage that.
I'll, I'll go on record with a quick controversial statement too. Everyone heard it here. I think egg egg came first, right? It was definitely the egg. okay. So thank you both. A- again, I think we're, we're really stressing and covering across the, again, the data really is only as good as the outcome it produces and how we kind of leverage that and what the actual impact is across some of these use cases, and particularly when we think about, right like authorization rates and what that looks like.
And so kind of, kind of segue into, Chris, what you hit on there too is we look at this, right, and as kind of, you know w- the impact of tokenization three DS on that authorization and that customer experience, the balance, the approval you know, all of those things that come into it. How do, how do you kinda look at that, and what are your thoughts? Yeah. It is a balance, and you know, I think we all agree that false declines are probably the biggest driver of a poor user payments experience.
There's nothing more frustrating than that because often the path to resolution, fr- from a, from a customer perspective is, it's tough, right? Is sometimes they have to fall back to another cr-Payment type or credential. Other times they actually get-- have to get to the point where they pick up the phone, and they have to speak to a bank right? That's a terrible customer experience that we want to avoid. we know, however, that tokenization does really help improve the user experience.
we have various statistics, around this. you know, we talked to a number of merchants that have seen sort of, negligible but positive, improvements when tokenization is present, all the way up to those who are seeing five, six percent uplift sometimes even more if it's a subscription and recurring merchant when tokenization is used. Visa, MasterCard, their position on this depends on which side of the bed they get up every morning-- on the morning.
The story change-- seems to change every quarter. But I would say, you know, their line has been somewhere between like three to five percent uplift across the network fro-from a tokenization perspective. So tokenization, a lot of that benefit from tokenization, that authorization uplift benefit is really coming from the lifecycle management aspect of tokens, where we know that as the underlying credential, the underlying PAN, if it changes, if it's been lost or stolen, if it expires et cetera, most importantly, the token doesn't change.
So just by their very nature tokens, the lifecycle management feature of tokens helps enable better authorization rates, right? But, but again, this is very credential focused, right? Three DS in parallel is more identity focused and more focused on the individual right? And we know that as we've been saying, is three DS helps improve issuer decisioning, particularly when the data is very good there. So I think that the message here that we have to, continue to stress, we're talking about consumer experience, is the two of these have to work together in this layered approach.
You need to make sure that you're using tokenization in the right way to manage your, your lifecycle. If you're doing that efficiently, effectively, that's going to help your consumers. you have to ensure that you've got good three DS data pipeline, that you're, you know, thinking beyond just, you know, executing three DS, using good data doing a bit of issuer profiling, BIN profiling, things along those lines. And those two together are going to lead to higher approval rates and lower friction for the consumer.
Awesome. Thanks Chris. and Dwelle, I want to keep this here, just get your thoughts as well. So when we again think about the impact authorization kind of areas for improvement what's your take? So this is, this is a, you know, a very important kind of distinction, Chris, that you, that you highlight here, right? In terms of the, the credential and the impact of a credential. Yes, you know, you mentioned like a three to five percent or six percent in some cases kind of uplift, when you look at the credential.
I'll, I'll, I'll take whereas something like fully secure provides the data that actually allows you to, you know, evaluate the identity piece, tie the identity piece to that credential. And why that's important, let me let me use a practical example, because we recently worked with a, you know, with a very frustrated merchant, in one of our territories with a, you know, where I think something like, eighty percent of their transactions were being challenged, right?
and they were getting you know, a, a lot of abandonment around that. And so we were kind of looking into, okay, how can we help? You know what's, what can we do to actually im-im-improve the situation? And what it came down to was, you know, the data that the merchant was sending through was actually very very poor. And because of that, the issuer was making you know, looking at the data and going like "Hey, this doesn't look good let's challenge." And so by working with that merchant to actually capture the right data elements and send it over to the issuer, we made that eighty percent of their transactions are frictionless, which was a massive uplift on the success of their transactions, right?
And so I think that's the point is that data and good quality data when it comes to risk-based deci-decisioning and, you know, in terms of authorization, optimization plays such a crucial role because it really kind of helps you to to make good decisions quickly. If you see all the right stuff, that's a very quick yes, and that's what everyone wants. And so I think you mentioned earlier, Chris, that, you know, some of the, the smart merchants are really kind of investing in in data quality heavily.
And I cannot kind of agree more in terms of where we've seen the highest like double dig-digit kind of authorization uplifts have been where data quality was addressed, you know, via these rails. And so I certainly think that is-- that's kind of where the key of all, all of this kind of, you know, how these two things kind of work together, work, quite well. If you think about tokenization as a capability why that helps, again, you have the ability to make the risk that is around that credential.
You can reduce the risk around the credential. You can limit the scope of it. "Hey, this token is only, you know, usable at this merchant, only up to this amount." So you can actually reduce the risk associated with a specific credential. So that in and of itself already helps with the decision that the issuer is making. And then at the same time if you layer the identity information, the correct you know, data that says, yeah, and, if you look at the spending patterns and you look at the behavior of this, of this, consumer that's actually initiating this transaction, this is consistent with everything that we've seen.That's put together- Yeah...
then actually that's your slam dunk. Yeah. And that really, then gets you that, that home run slam dunk kind of, you know scenario that we're all kind of after here. And so that would be kind of the thing that I think is, is really key here, of how these two worlds kind of play together. And then, you know, Chris, you kinda mentioned earlier you know, initiatives like data-only. And I don't know whether we wanna quickly talk about that, but that certainly is one of the mechanisms that kinda helps with that specific, you know area of concern, right, where, data-only kind of, is a, is a three secure transaction type that enables a merchant to share these data elements without the risk that the issuer is actually going to challenge.
So- Yeah... where many merchants were kind of let's say very kind of, let's say just nervous about sending something via three secure due to how an issuer might, you know, implement their challenge strategy something like data-only kind of guarantees that the issuer will not do that, but still gives you the benefit of actually sharing that data with the issuer and then getting the issuer to be able to consider that as part of their authentication and authorization strategy.
And that I think is the almost that golden midway that then really kinda can help us to get to a place where we move away from this as an authentication or strong customer authentication, you know, tick box towards more of an au- authorization optimization tool, that this becomes. Agreed. Yep, for sure. Yep. We d- and it's a-and again, it is really amazing and all of us in it, you know, folks on the other side live and breathe in it every day, the shift to the impact and importance of data in this whole ecosystem, right?
And how we're leveraging and how we're using it is just, it's, it's changing so rapidly and so quickly, in a lot of ways. So glad we're digging in a little bit more. okay, thank you both. I wanna, I wanna kinda shift again and get into Q&A. a little bit. So for folks on the other side feel free to start to drop in some... I saw a couple come in. Don't mind me squinting as I'm trying to read the other screen here. A couple come in we'll hit in a second. as those are coming in, I guess, Duvall, Chris, just kinda wanna close with final thoughts, right?
As we're moving towards more token, you know, centric, I don't wanna say necessarily token first 'cause I think a lot of this stuff kinda works in tandem, right? But ecosystem, what are some kind of, you know, immediate thoughts and takeaways for the folks on the other side? Chris, let's start with you. Yeah. So I'll jump in here, and just look at this maybe more from the issuer perspective, is I think we have historically had a lot of issues with d-decisioning system and deci-decisioning model fragmentation at a lot of issuers, particularly mid-size and large issuers.
you know, we did some studies now going back three years ago, but, you know, it still tells a really interesting story where, you know, we've, we've seen some large issuers that had three, four, five, in one instance and a large issuer that had twenty-seven different ACS systems and different fragmentations and models, making decisions behind the scenes there. So I think historically we've had this challenge of decisioning model fragmentation just in the three DS.
world, and, now you introduce tokenization into this, and very often, you know, that. is, perhaps handled by the risk model that's attached to the authorization engine for example, and not actually as part of the three DS, the ACS or the three DS decisioning engine. so this perhaps, it introduces even more fragmentation in modeling and decisioning. So you know, our advice to issuers is always, you know, you should be on a path to working toward consolidated, decisioning models, risk models as best as possible.
We talked about it mostly within the context of three DS, three, four, five, six years ago. Now we're talking about it in the context of three DS plus typical authentication, decisions plus tokenization in that. as well. So, you know, fragmentation of these decision decisioning systems that we've been talking about doesn't help any of these issues that we've identified earlier. Hmm. Thanks. Thanks, Chris. if I'm waiting for our marketing team after when you dropped that line of the, one issuer having twenty-seven different- Yeah.
Yeah. Yeah... I don't know if you both Duvall and I, our eyebrows went straight up. That's, that's wild. Yeah. That's a lot. No, it's crazy, right? We' see this as a meme with all our eyebrows raised. Yeah. Duvall any closing thoughts? Yeah, no, first of all, wow, you know I, I guess to Chris' point, that issuer, you know, it's like one of the ACS for every day of the month almost, right? It's, that's really interesting. But no I think I think it's, it's-- if you look at kind of where things are going you know, closing thoughts would be, I think we need to, to modernize our approach a little bit, you know, when it comes to this.
As tokens, are, you know, there there are a lot of these new tools available and, investing in making sure that we actually use those tools in the correct way is something that I think is gonna be very important here, right? How do you how do you issue tokens in a in a, in a, you know, in the correct way that, you know, you benefit from it on the, you know, on the authorization side? How do you you know, process data signals and identity signals, together with these signals in a, in a way that actually enables you to make faster decisions?
So I think a long way of saying, you know really thinking about using the new capabilities of the tool, so upgrading your approach to it. I think we seeA lot of the market kind of being stuck in the, in the past, right? And, and in terms of kind of using the new tools in the old way. And I think that's perhaps the shift that we kinda need to make is to kind of use the new capabilities that are at our disposal. That's probably the biggest shift that we need to do, because the tools are there, but I just don't think we're using them in the right way just yet.
Mm-hmm. Mm-hmm. Agreed. Agreed. okay. Just let's roll into Q&A a little bit. It looks like, Catherine, I think, Chris, you touched on, you answered one of the questions right in your your final closing there. So it sounds like Catherine, that question on fragmentation got answered. That's awesome. Thank you. A couple others that rolled in here. So there's one about kind of piloting data or like how-- what's the recommendations of rolling out a data-only kind of approach?
Is it specific merchant categories or is there a better way to approach across all merchants? I don't know. Dewald, do you maybe wanna take that one in terms of... Sure. And, yeah, I mean, I'd love to also kinda hear from Jessica. I know Chris is, also very, from a merchant perspective, very well, informed. But I, I, think in general, it's, it's probably, it's probably good to to, from a, from a data-only perspective, right? If you're gonna start to kinda use a tool like that which is, and just to kind of quickly re, you know, re-resummarize that' or restate that.
You've got-- with something like data-only, you've got the ability as a merchant to send the data elements like you would for three secure but the issuer is not able to challenge, right? So. there's no risk that the issuer will challenge but they get the data and are-- they're able to actually, you know, process that, and, and make sure that they then actually, you know, use that as part of their authorization decisioning, right? Because that you'll get, something like a cryptogram back in the same way that you can kind of submit to signal to the authorization side that, you know, this has this has kind of been seen before.
Now, i-in terms of the approach around that I mean, you know, you could probably, if you wanted to just test that, you could probably limit it to... There's a couple of approaches, limit it to a specific BIN range, to a specific issuer. Yeah. You know, kind of test that to see to see... I would probably recommend, if you, if you really wanna test it you know, if you're coming from, the side of a merchant you know, pick one of your issuers that you partner with well and kind of work with them to say, "Right, okay, listen, hey, we're gonna send this to you, and let's, let's kind of collaborate on this." I think that's the thing with payments is payments has two sides.
And if we kind of you know... There's a collaboration there that's required. And so I would, I would kind of recommend if you wanna pilot it, you know, choose one of your issuer partners and, you know, put it to the test and, and prove the outcome. And then, you know, once you've kind of ironed out the kinks go wider. De-Dewald you, you hit on with that point exactly what I was gonna say is I guess the broader point here is data-only is only as good as what the issuer does with it on the receiving end right?
Correct. So if you are kind of just blindly creating some sort of AB test or so-something along those lines and you don't have full visibility to how the issuer is actually u-using that data, then it's tough to really make a judgment as to how effective the-- how the impact is there. You don't see the full picture. So if you, as Dewald said, is if you do have a friendly issuer that you could work with on this, that's gonna get you more of the visibility to try to figure out h-how it's improving overall performance or where your data needs to be enhanced or things along those lines.
Right on. Thank you, gentlemen. there's two other questions here, but any thoughts any thoughts on how well orchestrators or PSPs are handling these nuances with tokenization and three DS? Yeah, I could, I could jump on that. So, you know, the term orchestrator right there there's really a broad set of capabilities amongst orchestration platforms today, whether they be independent orchestration platforms that exist along the lines of like a Spreedly or a Gravy or something along those lines, or orchestration capabilities that exist within your PSP.
And that is a model that is continuing to become sort of more and more prevalent in use these days. But the capabilities, in each of those tends to vary greatly. Some of the orchestrators ha-have fairly limited capabilities, you know, just maybe being able to specify a simple workflow. Others start to get very advanced in regards to performance monitoring, cost monitoring, et cetera that can be used as an input to your orchestration de-decision. most orchestrators now are at-- the, especially the standalone orchestrators are incorporating to- both tokenization and three DS into the capability logic, some of them a little better than others.
So if you're evaluating orchestration capabilities those are two areas you really wanna focus, on, like does the orchestrator actually take issuer level tokenization and three DS performance into account in making the orchestration decision would be a good question to ask. So I guess short answer is we're seeing a variety of different approaches to this. It's continuing to mature. But in general, we're seeing most of these platforms take tokenization and three DS secure into consideration within their feature set.
Awesome. Thanks, Chris. one more that just came in, and then there's a couple others. The others are a little bit more technical and specific to some some I think individuals and accounts, so we'll, we'll follow up with those folks off. But, throw this one out. can you talk about intermediary services such as MDES or VTS and how they can be leveraged in a data-only pilot? That adds some complexity in some cases. Yeah. I'm not really sure. I don't know, Dewaldt, if you have any insight into this, how they're sort of, playing this.
Yeah. And certainly I guess when it comes to, to those two services you know, that, those, MDES is obviously Mastercard's kind of tokenization service and VTS kind of being Visa's, tokenization service. and so I think it'll be interesting to kinda see, exactly what complexity, there can be. But at the end of the day, when it comes to sending some of the the data a-a-across it shouldn't necessarily be that it's, that it's more complex. From a three secure perspective, if you're using a token, what would happen is that you know, a PAN or the, or a token in this case, right, that you're sending kind of in that three secure message, or that data-only message over to, the issuer you know, that would be in the middle by, Mastercard or Visa.
They would kind of like, you know, swap that out with the actual kind of PAN before it goes to the issuer side. And so when the issuer kinda sees that, they'll kind of, you know, be able to translate it back to the actual card that sits, that F-PAN kind of that I mentioned earlier, right, that sits behind that token. And so there there shouldn't necessarily be, you know, any, let's say, kinks in, in that process, but I know obviously sometimes it's, it might be a bit more complex than that.
So Catherine, I'm not exactly sure whether there's- We'll have to dig in on there from a- Yes. That's definitely a question for your Mastercard and Visa rep, but I guess, Dewaldt, what we can say is we know that both Mastercard and Visa are paying a lot of attention this year, twenty twenty-six into twenty twenty-seven, into data only right? So I'm, I, you know, I would suspect that they are thinking through these issues here. and it's-- and I-I-I would also suspect they'd be very happy to speak to any issuer or any merchant who wants to talk to them about using data-only rails.
They they would pick up the phone in a minute a-on this topic. Absolutely. Dewaldt, Chris, thank you so much. enjoyed the conversation today. To everyone on the other side, thank you. Just a couple quick closing things too. Again, if, y'all haven't caught the white paper, that will go out. And I believe, Chris, Dewaldt, we have kind of a third part of this, maybe later in April where there's a conversation with Stripe coming up on some of these similar topics- Yeah...
and narratives. So, - Yeah... keep an eye out everyone for that. Looking forward to it. Yeah. For sure. Yep. so that'll be coming down the pipe as well. And, thank you. Thank you both. Appreciate it. Great. Thanks, Max. Thank you. Thanks, everyone. Thanks, all. Thanks, everyone. Have a wonderful weekend.