# PSD2: Merchants Must Regain Checkout Control Through Delegated Authentication
Author:  Pal Sinha, Barnali 
Author URL: https://financedigest.com/author/pal-sinha-barnali
Published: 2021-10-28
Category: BUSINESS
Category URL: https://financedigest.com/category/business
Meta Title: PSD2 Impact: Optimising eCommerce Checkout for Consumers
Meta Description: Learn how merchants can improve the seamless checkout experience for consumers by leveraging exemptions and optimising payment solutions under PSD2 regulations.
URL: https://financedigest.com/psd2-merchants-must-regain-checkout-control-through-delegated-authenticationhtml

![undefined](https://prod.superblogcdn.com/site_cuid_cm5qst7v3003gwirgwqtxn8i8/images/close-up-on-the-hands-of-man-shopping-online-using-laptop-and-credit-card-shopping-onl-sbi-304221014-1736837500641-compressed.jpg)

_By_ **_Galit Michel,_** _VP of Payments,_ [_Forter_](https://www.forter.com/)

For the past ten years, globalisation and digitalisation have changed the way companies connect with consumers around the world, enabling consumers to shop across borders seamlessly. The COVID-19 pandemic accelerated this change as consumers steadily turned away from bricks-and-mortar shops and towards online brands.

This has forced merchants to change the way they operate.

Today, merchants stay up to date on [eCommerce trends](https://www.financedigest.com/ecommerce-trends.html "eCommerce trends"), both from the payment and consumer perspective, optimising the checkout process to meet the needs and expectations of their consumers. They [personalise every part of the shopping experience](https://www.financedigest.com/psd2-and-personalising-customer-experience.html "PSD2 and Personalising Customer Experience") from onboarding to conversion, which brings increased liability.

However, they still do not have full control when it comes to deciding what type of [authentication is best suited for their customers](https://www.financedigest.com/consumers-in-the-covid-era-can-learn-to-embrace-strong-customer-authentication.html "Consumers in the COVID era can learn to embrace strong customer authentication").

[PSD2 and its impact](https://www.financedigest.com/the-real-impact-of-psd2.html "The Real Impact of PSD2 ") on conversions and revenue generation have forced merchants to re-examine the control they have over authentication and increased the urgency to prepare for delegated authentication.

**The struggle for a seamless checkout experience**

Merchants operating within the European Union (EU) and European Economic Area (EEA) must comply with PSD2 and execute a higher standard of [Strong Customer Authentication](https://www.financedigest.com/how-strong-customer-authentication-can-prevent-cart-abandonment.html "How Strong Customer Authentication can Prevent Cart Abandonment") (SCA). This includes requiring their consumers to undergo multi-factor authentication, most frequently executed through 3D-secure (3DS).

The problem with 3DS is two-fold:

- For consumers, 3DS adds friction to the checkout process, increasing abandonment and negatively impacting the [customer experience](https://www.financedigest.com/the-new-client-adviser-experience-in-the-age-of-the-customer.html "The New Client-Adviser Experience in the Age of the Customer").
- Within the [payment ecosystem](https://www.financedigest.com/the-future-of-payments-biometrics-within-the-financial-ecosystem.html "The Future of Payments: Biometrics Within the Financial Ecosystem"), 3DS adds an additional verification step, complicating the authorisation journey and increasing the chances of a legitimate transaction being declined.

The result is a direct negative impact on revenue generation, profitability, and customer satisfaction.

To reduce the impact of PSD2, and particularly 3DS, on their operations, many merchants have optimised their payment solution suite and integrated payment optimisation products to [increase authorisation rates](https://www.financedigest.com/how-to-increase-repeat-purchase-rates-in-ecommerce.html "How to increase repeat purchase rates in eCommerce") and provide consumers with a better checkout experience. Such products enable [merchants to reduce the impact](https://www.financedigest.com/how-does-the-fca-deadline-extension-impact-uk-merchants.html "How Does the FCA Deadline Extension Impact UK Merchants?") of SCA on their consumers by creating a seamless checkout experience that is still PSD2 compliant. This is most often done through exemptions.

If a merchant has an exemption engine in place, they can leverage it to override SCA requirements and continue providing their consumers with the seamless checkout experience they have become accustomed to.

The most common type of exemption, Transaction [Risk Analysis](https://www.financedigest.com/trendrating-1-3-delivers-faster-data-analysis-and-enhanced-risk-control-tools.html "Trendrating 1.3 delivers faster data analysis and enhanced risk control tools") (TRA) is based on the transaction’s risk. This is calculated by considering the [consumer’s behavioural](https://www.financedigest.com/gumgum-powers-into-europe-as-new-research-shows-consumers-reject-behavioural-ads.html "GumGum Powers into Europe as New Research Shows Consumers Reject Behavioural Ads") patterns, the transaction amount, and the merchant fraud ratio.

However, not every transaction is eligible for an exemption.

When a merchant has non-exemption eligible transactions, consumers must still undergo full SCA verification, increasing the friction they encounter, negatively impacting customer experience, and increasing decline rates. This is because the payment ecosystem looks at each transaction individually, while the merchant can consider behavioural factors, such as whether or not the customer is a repeat customer, strengthening their confidence in the legitimacy of the transaction as well as their desire to make the checkout process as seamless as possible for their consumer.

**What will delegated authentication do for merchants?**

Issuers recognise that merchants want to provide their consumers with a seamless checkout experience, even if the transaction is not eligible for an exemption. That is why many card networks, such as Visa and MasterCard, have launched Delegated Authentication programs.

Delegated authentication programs, which are PSD2 compliant, provide issuers the ability to ‘delegate authority’ to a third-party, such as the merchant or someone acting on their behalf, and let the third party manage SCA. This provides merchants with the ability to continue offering a seamless checkout experience to consumers since they would no longer be redirected to complete a 3DS challenge through the issuers’ network, all while ensuring the transaction [meets regulatory requirements](https://www.financedigest.com/lack-of-collaboration-and-skills-shortage-is-limiting-organisations-ability-to-meet-ifrs-9-requirements.html "Lack of collaboration and skills shortage is limiting organisations’ ability to meet IFRS 9 requirements").

PSD2 requires all transactions to undergo SCA authentication; a responsibility that falls on the issuer. If delegated authentication is enabled, the merchant, or the party acting on their behalf, would be able to determine what type of authentication to use based on their unique knowledge of the consumer, their behavioural habits, and more. For example, merchants could choose to authenticate transactions for [consumers who are logged in to their account](https://www.financedigest.com/what-successful-accounting-looks-like-in-the-age-of-the-consumer.html "What successful accounting looks like in the age of the consumer") and have already performed a type of authentication. This would create a frictionless checkout process that does not rely on 3DS, thereby increasing conversion and optimising [customer experience](https://www.financedigest.com/allianz-benelux-taps-into-modern-data-management-to-combat-fraud-and-foster-a-positive-customer-experience.html "Allianz Benelux Taps into Modern Data Management to Combat Fraud and Foster a Positive Customer Experience"), all while ensuring PSD2 compliance.

It is important to note that when merchants assume responsibility for authenticating transactions, the chargeback liability shifts to them. As a result, it is critical for merchants to ensure they only request delegated authentication for transactions they are confident about, otherwise they risk suffering from increased chargebacks.

That is why merchants that want to be eligible for delegated authentication, must do two things:

1) [Ensure their payment ecosystem supports](https://www.financedigest.com/strategic-budgeting-ensures-success-of-community-support-programs.html "Strategic Budgeting Ensures Success of Community Support Programs") the latest version of 3DS, namely 3DS2.2

2) Have a strong [fraud protection](https://www.financedigest.com/protect-your-organisation-from-fraud.html "Protect your organisation from fraud") solution in place.

**The different versions of 3DS and what they mean for** **merchants**

The 3D-Secure (3DS) protocol has undergone significant changes since its development. The original version of 3DS, also known as 3DS1, was created in 1999 by Visa when the only way to complete [digital transactions](https://www.financedigest.com/igtb-launch-digital-transaction-banking-available-as-saas.html "iGTB launch Digital Transaction Banking available as SaaS") was via a personal computer. 3DS1 is extremely unfriendly towards users, is not mobile-friendly, and is the least desired version of 3DS. 3DS1 also does not support exemptions.

3DS2, on the other hand, is the latest version of 3DS that was designed to reduce customer [friction and meet PSD2 SCA compliance](https://www.financedigest.com/fintechs-must-remove-security-and-compliance-friction-to-unlock-new-growth.html "Fintechs Must Remove Security and Compliance Friction to Unlock New Growth") requirements. The way 3DS optimises [customer experience is by sending more data to the issuing bank](https://www.financedigest.com/christmas-debt-hangovers-how-banks-can-help-customers.html "CHRISTMAS DEBT HANGOVERS: HOW BANKS CAN HELP CUSTOMERS"). This enables dynamic 3DS and reduces the friction consumers undergo.

In the upcoming months, issuers are expected to roll out the new version of 3DS2, also known as 3DS2.2. The new iteration will enable merchants to request exemptions via the 3DS rails, getting a direct response from the issuer in the event of exemption approval. It will also enable merchants to open the 3DS challenge if a transaction is not approved. This will [increase the ability to leverage TRA exemptions to their benefit](https://www.financedigest.com/benefits-of-increasing-blog-traffic-with-guest-blogging-and-posting-service.html "Benefits of Increasing Blog Traffic With Guest Blogging and Posting Service") as well as to establish themselves as a trusted merchant.

Another key difference between 3DS2.1 and 3DS2.2 is the ability to support delegated authentication. Under 3DS2.2, issuers can enable delegated authentication and shift authentication to merchants or selected third parties.

[Merchants that want delegated authentication to be part of their PSD2 SCA](https://www.financedigest.com/is-compliance-to-psd2s-sca-a-bridge-too-far-for-b2b-merchants.html "Is compliance to PSD2’s SCA a bridge too far for B2B merchants?") strategy need to ensure that their payment ecosystem is prepared to support 3DS2.2 when it goes into effect.

**The importance of fraud protection with delegated authentication**

If merchants want to take transaction authentication upon themselves or delegate it to a third-party of their choice, they must realise that in doing so, they, or the third party acting on their behalf, will assume full chargeback liability. This in turn will increase a merchant’s risk exposure.

To mitigate that risk, [merchants need to ensure they have a strong fraud](https://www.financedigest.com/three-online-fraud-trends-beauty-and-cosmetics-merchants-should-watch-out-for.html "Three Online Fraud Trends Beauty and Cosmetics Merchants Should Watch Out For") protection solution in place. This is particularly crucial when dealing with transactions that are not low value or low risk. If a merchant wants to process high-value transactions, the authentication they need to use must match the risk level of the transaction, and as a result, their need for a powerful [fraud prevention](https://www.financedigest.com/payroll-fraud-and-how-to-prevent-it.html "Payroll fraud and how to prevent it") solution will increase.

Having a strong fraud solution will enable merchants to effectively ensure that they take authentication liability upon themselves for transactions that do not pose a [financial risk](https://www.financedigest.com/financial-risks-of-climate-change-overplayed-senior-hsbc-banker-says.html "Financial risks of climate change overplayed, senior HSBC banker says").

A strong fraud protection solution is also crucial for exemption requests, and as a result, should be part of a merchant’s payment optimisation suite.

Fraud prevention solutions will enable merchants to analyse each transaction in real-time and determine the best course of action per consumer. This will automatically direct each consumer to a checkout experience best suited for them [reducing risk](https://www.financedigest.com/how-can-you-reduce-the-risk-of-fraud-in-b2b-payments.html "How can you reduce the risk of fraud in B2B payments?") and liability exposure.

Many fraud prevention solutions will even be prepared to take liability upon themselves, making it a true win-win for merchants who want to leverage exemptions, reduce risk and utilise delegated authentication.

**The power is in the hands of the merchants**

In the past, merchants focused predominantly on customers’ onboarding experience, investing heavily in retargeting, personalised campaigns, email marketing, UI/UX, etc.

Over the years, merchants have taken a more significant role in the checkout and payment process, recognising that revenue generation and profitability may suffer without optimised checkout.

The ability to delegate authentication to merchants is part of this ongoing [trend that increases merchants’ role in the payment](https://www.financedigest.com/top-5-payment-trends-for-2016.html "TOP 5 PAYMENT TRENDS FOR 2016") experience and gives them back control of the customer experience throughout the checkout journey. The independence delegated authentication provides merchants is in line with PSD2 and issuers’ role. As a result, it is a great strategy for merchants who put their [customer needs and payment](https://www.financedigest.com/2019-year-customers-take-control-payments.html "2019: The year customers take control of payments") expectations as a priority.

To ensure they are ready to take upon themselves authentication responsibility when delegated authentication is feasible, the entire payment ecosystem must shift, and issuers must release 3DS2.2 to merchants. Merchants that have low-risk levels, strong fraud [protection and advanced](https://www.financedigest.com/the-protective-cultures-market-to-see-through-explicit-advancements.html "The Protective Cultures Market To See Through Explicit Advancements") payment infrastructures should be in touch with their PSP or 3DS provider and ensure they are notified when 3DS2.2 is released, if their payment ecosystem supports it, and if they will be able to take advantage of delegated authentication.

Merchants that want to continue providing their customers with a user-friendly seamless checkout experience must argue for delegated authentication from their issuers.


---
This blog is powered by Superblog. Visit https://superblog.ai to know more.
---

