PaymentsJournal
No Result
View All Result
SIGN UP
  • Commercial
  • Credit
  • Debit
  • Digital Assets & Crypto
  • Digital Banking
  • Emerging Payments
  • Fraud & Security
  • Merchant
  • Prepaid
PaymentsJournal
  • Commercial
  • Credit
  • Debit
  • Digital Assets & Crypto
  • Digital Banking
  • Emerging Payments
  • Fraud & Security
  • Merchant
  • Prepaid
No Result
View All Result
PaymentsJournal
No Result
View All Result

Another Delay of PSD2 SCA Mandate Reflects the Complexities of Ecommerce Authentication

By Tim Sloane
May 26, 2021
in Analysts Coverage, Authentication, Credit, Debit, E-commerce, Emerging Payments, Merchant
0
0
SHARES
0
VIEWS
Share on LinkedIn
Another Delay of PSD2 SCA Mandate Reflects the Complexities of Ecommerce Authentication, PSD2 honeymoon period

Another Delay of PSD2 SCA Mandate Reflects the Complexities of Ecommerce Authentication

Strong Customer Authentication (SCA) was introduced to strengthen online payment security, but its rollout has also created new challenges for merchants and consumers alike. By requiring additional identity verification for many online transactions, SCA aims to reduce fraud across digital commerce. However, inconsistent authentication methods, evolving regulatory guidance, and varying implementation across financial institutions have introduced significant friction into the checkout experience. As businesses continue adapting to these requirements, balancing security with a seamless customer journey remains one of the industry’s biggest challenges.

The complexity extends beyond compliance. Merchants must understand exemption rules, liability shifts, and authentication workflows, while consumers increasingly face multiple verification methods that vary from one institution to another. Without greater standardization and improved user experiences, the additional friction created by SCA risks driving higher cart abandonment rates and reducing customer satisfaction, even as it strengthens payment security.

Strong Customer Authentication (SCA) deployment keeps getting more complex for both merchants and card holders. As a result the UK Financial Conduct Authority issued another six month delay. This article, which is worth a read, looks at SCA primarily from the merchant’s perspective but also identifies how banks add more complexity. 

As a user, my complaint is the lack of a standard user interface for challenges. I’ve felt the increase in challenges and the lack of consistency is frustrating. Once I enter my user ID and (strong) password I increasingly get one of the following challenges (listed from the most frustrating to the least):

  • My bank calls my mobile and a drunken sounding women reads off 6 numbers I enter in my browser.
  • My company’s customer management solution uses an authenticator app on my phone that gives me six numbers I enter in my browser.
  • One Time Passwords jam my email and mobile SMS which I enter in my browser (and this isn’t even a secure method).
  • CVS pharmacy app challenges me with my mobile phone’s biometric.
  • Some sites send me an SMS messages that I only need to tap.

I often abandoned transactions because the transaction isn’t worth the effort; but I still get angry at the inconvenience. If this insanity doesn’t coalesce around one type of challenge I expect the current 14% of browser and 25% app-based abandonment rates identified in this article will increase and none of the participants will be unhappy.  This article provides a concise review of where we are today in the rollout of SCA:

“On one hand, Strong Customer Authentication requirements are projected to help defend consumers throughout the EU against more than one billion euros in annual losses resulting from online fraud. At the same time, preliminary data finds that the requirements may cause a substantial uptick in friction.

As outlined in a new whitepaper published by Fi911, SCA standards could be used to verify only 76% of browser-based transactions, and just 48% of app-based ones. Requirements also prompted 14% of browser-based shoppers to abandon a purchase; for app-based shoppers, the figure rose to one-quarter of shoppers.

Other concerns about SCA adoption persist as well. For example, there will be some confusion, at least at first, regarding liability and applicability in different regions. The same goes for different transaction types and product verticals, some of which will be exempt from SCA rules.

Finally, we should also keep in mind that not all fraud is a form of payment fraud. SCA requirements have no effect on tactics like friendly fraud, return fraud, and triangulation fraud.”

Strong Customer Authentication represents an important step toward reducing online payment fraud, but its long-term success depends on making security as intuitive as it is effective. While stronger authentication can help protect consumers and merchants from account compromise and payment fraud, inconsistent challenge methods and complex implementation continue to create unnecessary friction throughout the purchasing process.

As regulators, banks, merchants, and payment providers continue refining SCA deployment, greater consistency in authentication experiences will be essential. Standardized user interfaces, wider use of low-friction authentication methods such as biometrics, and thoughtful application of exemptions can help preserve security while minimizing abandoned transactions. The organizations that strike the right balance between fraud prevention and customer experience will be best positioned to succeed in an increasingly digital payments environment.

Overview by Tim Sloane, VP, Payments Innovation at Mercator Advisory Group

0
SHARES
0
VIEWS
Share on LinkedIn
Tags: AuthenticationE-commercePSD2SCAStrong Customer Authentication

    Get the Latest News and Insights Delivered Daily

    Subscribe to the PaymentsJournal Newsletter for exclusive insight and data from Javelin Strategy & Research analysts and industry professionals.

    Must Reads

    agentic commerce

    Biometrics Are Here. Agentic Payments Aren’t—Yet.

    September 4, 2026
    swift cross-border

    P2P Payments Have Changed How Consumers Move Money. What’s Next?

    September 3, 2026
    holiday prepaid

    The Holiday Gift Card Outlook: Why Repeat Buyers Matter Most

    September 2, 2026
    co-branded debit cards

    A New Generation of Consumers Is Changing the Role of Debit Cards

    September 1, 2026
    BNPL for credit unions

    How BNPL Is Helping Credit Unions Strengthen Member Relationships

    August 31, 2026
    cross-border tokenized deposits

    Project Agorá Is Showing Banks Why Tokenized Deposits Matter

    August 28, 2026
    prepaid speed

    How Jumpstarting Gift Card Redemption Can Mitigate Breakage

    August 27, 2026
    ISO and ISV partnerships

    Building a Successful Payments Strategy: How ISOs and ISVs Can Drive Scalable Growth Together

    August 26, 2026

    Linkedin-in X-twitter
    • Commercial
    • Credit
    • Debit
    • Digital Assets & Crypto
    • Digital Banking
    • Commercial
    • Credit
    • Debit
    • Digital Assets & Crypto
    • Digital Banking
    • Emerging Payments
    • Fraud & Security
    • Merchant
    • Prepaid
    • Emerging Payments
    • Fraud & Security
    • Merchant
    • Prepaid
    • About Us
    • Advertise With Us
    • Sign Up for Our Newsletter
    • About Us
    • Advertise With Us
    • Sign Up for Our Newsletter

    ©2026 PaymentsJournal.com |  Terms of Use | Privacy Policy

    • Commercial Payments
    • Credit
    • Debit
    • Digital Assets & Crypto
    • Emerging Payments
    • Fraud & Security
    • Merchant
    • Prepaid
    No Result
    View All Result