On this page
- How the shift is triggered
- Card-not-present (ecommerce)
- Card-present
- Digital wallets
- Who the shift applies to
- What the shift does NOT cover
- SCA exemptions and the shift
- Cartes Bancaires scheme nuance
- Practical impact: fraud and authorisation rates
- Regulatory and scheme rule changes (2024–2026)
- Visa VAMP — April 2025
- Mastercard EFM
- 3DS version deprecations
- Regional SCA mandates
- EU/UK regulatory context
- PSD2
- PSD3 / Payment Services Regulation (PSR) (as-of 2026-07-23)
- UK
- Key terms
- Next frontier
Liability Shift
Liability Shift
In card payments, liability shift is the transfer of fraud chargeback responsibility from the merchant (the default carrier of card-not-present fraud losses) to the card-issuing bank, triggered when a transaction is authenticated via a recognised authentication protocol — primarily 3DS2 for online payments or EMV chip for card-present. The shift is scheme-governed and applies only to fraud-coded disputes, not service disputes.
How the shift is triggered
Card-not-present (ecommerce)
Successful authentication via 3DS2 (either frictionless or challenge flow) transfers fraud chargeback liability from the merchant to the issuing bank. (Adyen Help, retrieved 2026; Checkout.com Blog, 2025-01-22)
The Electronic Commerce Indicator (ECI) signals the authentication level to the acquiring bank and card scheme:
| ECI value | Meaning | Liability shift? |
|---|---|---|
| Visa ECI 05 / Mastercard ECI 02 | Fully authenticated | ✅ Shift to issuer |
| Visa ECI 06 | Authentication attempted; issuer did not participate | Partial — scheme-dependent |
| Visa ECI 07 | No 3DS used | ❌ Merchant bears liability |
Merchants must retain the ECI value, CAVV/AAV, and transaction IDs to defend fraud disputes with evidence. (GPayments, 2025-09-24)
Data-Only 3DS (available from 3DS v2.2+) does NOT grant a liability shift — it shares authentication signals with the issuer to improve decisioning but provides no chargeback protection. (GPayments citing Visa Acceptance developer docs, 2025-09-24)
Chargeback protection windows (as-of 2026-07-23):
- Visa: 90 days from transaction date
- Mastercard: 30 days initially; extended to 90 days from 2020 onwards
Card-present
Processing a chip card through a certified EMV terminal shifts liability for counterfeit card fraud to the issuer. Swiping an EMV chip card instead (bypassing chip) reverts liability to the merchant. (Rapyd, 2026-04-15)
Digital wallets
Apple Pay and Google Pay embed cryptographic device authentication (biometric + device-generated token). Card schemes treat this as fully authenticated; liability moves to the issuer automatically. Google Pay in CRYPTOGRAM_3DS mode: issuer acknowledges cardholder authenticated via device and takes fraud liability. Google Pay PAN_ONLY mode may still require separate 3DS for full liability shift. (Rapyd, 2026-04-15; Checkout.com Blog, 2025-01-22)
Who the shift applies to
The shift is scheme-governed and covers the following schemes: Mastercard, Maestro, Visa, American Express, Bancontact, Cartes Bancaires, JCB, and UnionPay. (Adyen Help, retrieved 2026)
Default position: the merchant (or their acquirer) bears liability for fraud chargebacks on CNP transactions. After a successful 3DS authentication, that liability transfers to the issuing bank.
What the shift does NOT cover
- Service disputes: product not received, item not as described, cancelled subscription, billing errors, authorisation errors. The shift is exclusively for fraud-coded chargebacks ("I did not authorise this transaction"). (Adyen Help; GPayments, 2025-09-24; Evervault, 2025-07-16)
- Recurring/MIT charges: the liability shift does not apply to subsequent merchant-initiated transactions, even when the initial customer-initiated transaction (CIT) was authenticated with 3DS. (Adyen Help; Ravelin, 2025-07-24; GPayments, 2025-09-24)
MIT/recurring liability nuance: Adyen Help states flatly that "the 3DS liability shift doesn't apply to recurring transactions." GPayments (2025-09-24) hedges: subsequent recurring/MIT charges "may be ineligible for liability shift, depending on the network and setup." Ravelin (2025-07-24) notes MITs are "out of scope for SCA entirely" — which is consistent with no shift available but framed differently. The nuance: out-of-scope means SCA is not required, but absence of SCA requirement does not automatically confer a shift. All three sources are consistent that subsequent MITs carry merchant-side liability.
- MOTO (Mail Order / Telephone Order): no real-time authentication is available; liability stays with the business. (Stripe Resources, 2025-06-12)
- No-reply chargebacks: failing to respond to a dispute inquiry on a 3DS-authenticated charge can trigger a "no-reply" chargeback that invalidates the liability shift. (Stripe Resources, 2025-06-12)
- Fraud monitoring ratios: a liability shift does not exclude a transaction from scheme fraud monitoring programme calculations. A merchant can be fined under Visa VAMP or Mastercard EFM even on transactions where they bear no direct financial fraud liability. (Evervault, 2025-07-16; PAAY, 2026-02-15)
SCA exemptions and the shift
Under PSD2 and PSD3, merchants and acquirers can request exemptions from Strong Customer Authentication (SCA). The exemption request determines whether the liability shift is retained.
| Exemption type | Who requests it | Liability outcome |
|---|---|---|
| TRA (Transaction Risk Analysis) | Merchant / acquirer | ❌ Shift forfeited — remains with merchant |
| TRA | Issuer (unilateral, without merchant request) | ✅ Shift retained with issuer |
| Low-value (<€30) | Merchant | ❌ Shift forfeited — remains with merchant |
| Trusted beneficiary | Issuer accepts listing | Contested — see contradiction below |
| SCA applied in full | n/a | ✅ Shift to issuer |
(Adyen Docs, retrieved 2026; Primer, retrieved 2026; Ravelin, 2025-07-24)
Trusted beneficiary and liability: Ravelin (2025-07-24) states that if the issuer accepts the trusted listing, liability falls with the issuer. Ravelin also states generally that "use of exemptions will mean that liability sits with the acquirer/merchant." Primer states the trusted beneficiary exemption forfeits the liability shift for the merchant. The outcome appears to depend on whether the merchant or issuer initiates the listing and whether the issuer explicitly accepts it — but sources are inconsistent in their framing. (Ravelin, 2025-07-24 vs. Primer, retrieved 2026)
Transaction Risk Analysis (TRA) thresholds (as-of 2026-07-23, under PSD2):
- Up to €100 if acquirer reference fraud rate (RFR) ≤0.13%
- Up to €250 if RFR ≤0.06%
- Up to €500 if RFR ≤0.01%
- All transactions above €500 require SCA regardless of risk profile (Primer; Ravelin, 2025-07-24)
Low-value exemption (as-of 2026-07-23): after 5 consecutive low-value transactions OR cumulative spend exceeding €100, the issuer may override and demand SCA. (Primer)
American Express exception: in EEA and UK, Amex requires authentication on ALL transactions, even those otherwise qualifying for an exemption category. (Ravelin, 2025-07-24)
Cartes Bancaires scheme nuance
Cartes Bancaires applies a distinct rule: if the merchant signals no authentication preference (challengeInd values 02, 05, 07, or 08) and the flow resolves frictionlessly, no liability shift applies. Only challenge flows — or setting explicit challenge-preference in the authentication request — yield a shift. This directly contradicts the general claim that "frictionless 3DS always shifts liability." (Adyen Docs, retrieved 2026)
Frictionless flow and liability shift: Adyen Help (general rule): the shift applies after "successfully authenticated" transactions, including frictionless. Adyen Docs (Cartes Bancaires-specific): frictionless with no authentication preference = NO liability shift. Evervault (2025-07-16): 3DS2 "delivers a full liability shift to the issuer — even on frictionless flows." These are reconcilable by scheme and region, but the blanket frictionless-equals-shift claim is not universally accurate. (Adyen Help vs. Adyen Docs vs. Evervault, 2025-07-16)
Practical impact: fraud and authorisation rates
Fraud reduction (as-of 2025):
- Visa internal data, VisaNet, US credit cards, Q4 2024: authenticated 3DS transactions show ~45% lower fraud rates — 11 basis points vs. 20 basis points for non-authenticated CNP. (PAAY citing Visa data, 2026-02-15)
- EBA-ECB Joint Report on Payment Fraud 2024: mandatory 3DS under SCA reduced e-commerce card fraud rates by approximately 50% for issuers. (PAAY citing EBA-ECB Joint Report 2024, 2026-02-15)
- Best Buy Canada: 61% reduction in CNP fraud rate within two quarters of implementing Visa Secure. (PAAY citing Visa case study, 2026-02-15)
- EU SCA overall: prevented approximately €900 million of payment fraud per year. (Stripe Blog citing European Commission, 2024-08-05)
Stripe Blog data (August 2024) on EU SCA fraud prevention (€900M figure) and US 3DS authorisation rate split (-5% frictionless). These are the most recent available figures but are not from 2026 primary sources.
Authorisation rate anomaly in the US: Stripe experiment (US merchants, 2024): pre-3DS authorisation rate 87%; post-3DS challenge flow 87% (unchanged); post-3DS frictionless flow 82% (−5%). US issuers appear to treat a merchant-requested 3DS as a fraud signal, increasing decline rates on frictionless-routed transactions — an outcome not observed in EU/UK markets where issuer risk models have adapted to SCA. (Evervault citing Stripe Blog, 2024-08-05)
US frictionless 3DS authorisation rates: Evervault (citing Stripe 2024) reports a 5% decrease in authorisation rates for frictionless 3DS in the US. This contradicts the general claim that frictionless 3DS is conversion-neutral and friction-free. EU/UK data shows no equivalent decline. The finding is US-specific and may not apply to EU/UK merchants. (Evervault, 2025-07-16 citing Stripe, 2024-08-05)
Friendly fraud and 3DS: Friendly fraud (legitimate cardholder disputes own transaction) accounts for up to 75% of all disputes in the US. 3DS authentication creates a verifiable record that complicates friendly fraud claims but does not eliminate them — the dispute reason code can be changed. (PAAY citing Chargebacks911, 2026-02-15)
Scheme monitoring programme interaction: Despite providing liability protection, all chargebacks and TC40 fraud reports on 3DS-authenticated transactions still count toward Visa VAMP and Mastercard EFM ratio calculations. Liability shift protects financial exposure but does not protect against scheme programme enforcement. (Evervault, 2025-07-16)
Regulatory and scheme rule changes (2024–2026)
Visa VAMP — April 2025
Visa launched VAMP (Visa Acquirer Monitoring Program) on 1 April 2025, replacing four legacy programmes (VDMP, VFMP, VFMP 3DS, DGMFM) and 38 remediation processes. (PAAY, 2026-02-15; Evervault, 2025-07-16)
VAMP Ratio = (TC40 Fraud Reports + TC15 Disputes) / Settled CNP Transactions. A single fraudulent and disputed transaction counts twice. TC40 fraud alerts resolved through RDR or CDRN no longer excluded from calculations — only Compelling Evidence 3.0 (CE3.0) can now exclude TC40 reports from the ratio. (Evervault, 2025-07-16; PAAY, 2026-02-15)
VAMP thresholds (as-of 2026-07-23):
- Merchant "Above Standard": ≥0.50% to <0.70%
- Merchant "Excessive": ≥0.70% (global); dropping to ≥1.50% in North America, EU, and APAC from 1 April 2026
- Fine structure: $8 per dispute/fraudulent transaction for merchant excessive violations (from April 2025); additional $4 per dispute for acquirers breaching 0.50% from January 2026. Enforcement began October 2025.
Mastercard EFM
Merchants with >10% of their volume processed through 3DS in non-regulated markets (e.g., US) cannot be placed in the EFM (Excessive Fraud Merchant) programme regardless of fraud numbers — 3DS penetration acts as a binary enrollment guard. EFM threshold: 100 chargebacks/month + 1.5% chargeback-to-transaction ratio. (PAAY citing Mastercard EFM documentation, 2026-02-15; Chargebacks911, 2025)
3DS version deprecations
- July 2024: Mastercard deprecated 3DS 2.1.0; full migration to 2.2.0 required.
- September 2024: Visa deprecated 3DS 2.1.0.
- June 2026: EMVCo published DSB No. 330 draft spec bulletin for 3DS v2.4.0.0 (subscriber access; comment period closed July 2026). (Adyen Docs, retrieved 2026; EMVCo Technology Page, retrieved 2026-07-23)
Regional SCA mandates
- France: From 10 March 2025, French issuers soft-decline all customer-initiated authorisation exemptions except those requested via EMV 3DS. From 14 October 2024, French issuers limit authorisation exemptions to €100 per shopper per day. (Adyen Docs, retrieved 2026)
- Japan: From 1 April 2025, all CNP card payment transactions must use 3DS2. (Adyen Docs, retrieved 2026)
- Australia: SCA required once a merchant exceeds AUD 50,000 in fraud losses AND fraud-to-sales ratio ≥0.2% for two consecutive quarters. (Adyen Docs, retrieved 2026)
EU/UK regulatory context
PSD2
PSD2 Article 74(2): acquiring PSPs are liable for transactions not authenticated using SCA if those transactions are found to be unauthorised. SCA mandate applies to EU/EEA issuers for online card payments, with defined exemptions. (EBA No Action Letter, 2025-06-10)
PSD3 / Payment Services Regulation (PSR) (as-of 2026-07-23)
Key timeline: provisional political agreement November 2025; COREPER endorsement 23 April 2026; EU Parliament plenary vote expected late May/June 2026; publication in EU Official Journal anticipated June–September 2026; PSR applicable ~21 months after publication (estimated Q1–Q4 2028). (GR4VY, 2026-06-23; EPC Fraud Trends Report, 2025-11-19)
PSR key changes affecting liability:
- Directly applicable EU Regulation (not a Directive), eliminating country-by-country variation in SCA implementation.
- Core SCA exemptions retained (LVT, MIT, TRA, Trusted Beneficiary, Secure Corporate Payment).
- Expanded SCA triggers: token creation/replacement, spending limit changes, contact detail amendments.
- Expanded fraud liability: mandatory reimbursement for impersonation fraud victims; technical service providers (wallet providers, payment gateways) now liable for fraud if they fail to apply SCA; issuers liable when spoofing fraud occurs.
- Mandatory IBAN-name verification for all credit transfers, affecting refund flows. (GR4VY, 2026-06-23)
PSD3/PSR analysis sourced from GR4VY (2026-06-23) and EPC Fraud Trends Report (2025-11-19). Final PSR text not yet published in EU Official Journal as of 2026-07-23; all detail based on April 2026 trilogue compromise texts.
UK
UK is not bound by PSD3/PSR. FCA is shifting from prescriptive SCA rules to an outcomes-based framework. UK PSR has consulted on interim CNP fraud rate caps: 0.2% for consumer debit, 0.3% for consumer credit CNP. Final directions pending as of 2026-07-23. (FCA, retrieved 2026; Payments Association, cited in search results 2025)
UK SCA rules remain in force under Payment Services Regulations 2017; FCA policy statement PS21/19 sets out SCA RTS; new Article 10A exemption (March 2022) allows TPP customers to reconfirm account access every 90 days without re-authentication. (FCA SCA page, last updated February 2023)
Key terms
| Term | Meaning |
|---|---|
| ECI (Electronic Commerce Indicator) | Code attached to a CNP transaction signalling the authentication level; determines liability allocation |
| CAVV / AAV | Cardholder Authentication Verification Value / Accountholder Authentication Value — cryptographic proof of successful 3DS |
| TC40 | Visa's fraud reporting mechanism; TC40 alerts count toward VAMP even without a chargeback |
| CE3.0 (Compelling Evidence 3.0) | Visa's dispute resolution tool; the only mechanism that can exclude TC40 reports from VAMP ratio calculations post-April 2025 |
| RFR (Reference Fraud Rate) | Acquirer's fraud rate, used to determine TRA exemption ceiling under PSD2 |
| VAMP | Visa Acquirer Monitoring Program — launched April 2025, measures combined TC40+TC15 fraud ratio |
| EFM | Mastercard Excessive Fraud Merchant program — 3DS penetration above 10% in non-regulated markets exempts merchants from enrollment |
| OOB (Out-of-Band) | Authentication method where the issuer sends a push notification to the cardholder's banking app; used for high-risk or recurring transactions |
| Frictionless flow | 3DS authentication completed without visible customer action; issuer accepts data signals and approves |
| Challenge flow | 3DS authentication requiring customer action (OTP, biometric, etc.) |
Next frontier
- Chargeback — standalone mechanics page missing; referenced throughout
- Identity Resolution — 10+ dangling refs; no page
- Soft Decline — referenced from MIT and SCA pages; no concept page
- Variable Recurring Payments (VRP) — growing UK-specific payment rail; no page
- EUDI Wallet — flagged in EMVCo 2025 white paper as upcoming SCA vector; no page