Fraud & Risk

Fraud Liability Shift

What Is a Fraud Liability Shift? Definition and How It Works

Definition

A fraud liability shift is a card scheme rule that transfers financial responsibility for fraudulent transactions from the issuing bank to the merchant or acquirer when the party that could have prevented the fraud (by supporting a more secure authentication method) chose not to. The most common liability shift is the EMV chip liability shift (favouring merchants who accept chip over those accepting magnetic stripe) and the 3DS liability shift (favouring merchants who complete 3DS authentication over those who do not).

How it works

Liability shifts operate on a simple principle: responsibility for a fraudulent transaction falls on the party that had access to a stronger security measure and did not use it, or that used a weaker authentication method than was available.

As an example, the EMV chip liability shift took effect in the US in October 2015. Before that date, card issuers bore the financial liability for fraudulent card-present transactions regardless of whether the merchant had chip-capable terminals. After the shift, if a cardholder presents a chip card at a merchant without a chip-capable terminal, and a fraudulent transaction results, the liability transfers to the merchant or acquirer. The issuer is protected because a chip transaction would have been more secure; the merchant bears the fraud cost for not upgrading.

The 3DS authentication liability shift works similarly for card-not-present transactions. If a merchant submits a transaction through 3DS and the issuer authenticates the cardholder (or grants a frictionless flow based on their own risk assessment), the liability for subsequent fraud shifts to the issuer. The merchant has done its part by initiating authentication; the issuer accepted the transaction. If the cardholder later disputes the transaction as fraudulent, the issuer cannot initiate a chargeback against the merchant for fraud reason codes.

Conversely, if a merchant does not use 3DS for an eligible transaction, and the transaction turns out to be fraudulent, the liability remains with the merchant: the merchant cannot benefit from a liability shift it did not trigger by using the available authentication method.

Why it matters

Fraud liability shift rules create direct financial incentives for merchants to adopt more secure authentication methods. Before the EMV liability shift in the US, many merchants had limited financial motivation to invest in chip terminal upgrades because fraud losses fell on the issuer. The liability shift made the cost of inaction (bearing fraud liability on chip card transactions at mag-stripe terminals) exceed the cost of terminal investment for most merchants, accelerating EMV adoption.

For e-commerce merchants, 3DS liability shift is one of the most commercially significant reasons to implement 3DS even beyond regulatory requirements. A merchant that uses 3DS and obtains issuer authentication for a transaction is protected from chargeback liability for fraud reason codes on that transaction. A merchant that skips 3DS and experiences fraud retains full liability, including chargeback fees and the value of disputed transactions.

Liability shift rules also affect risk model design. Merchants protected by 3DS liability shift can accept more borderline transactions that a non-3DS merchant would decline, because the fraud cost is borne by the issuer if authentication succeeds. This changes the optimal fraud policy threshold for 3DS-protected transactions.

With PXP

PXP's 3DS2 authentication secures the issuer liability shift on authenticated transactions. Talk to our team about how PXP can support your authentication and liability protection.

Talk to a payments specialist

Frequently asked questions

Does 3DS liability shift protect merchants from all chargebacks?

No. 3DS liability shift protects merchants from chargebacks filed under fraud reason codes (where the cardholder claims the transaction was unauthorised). It does not protect against chargebacks for other reasons: non-delivery of goods, item significantly not as described, or merchant-specific disputes. Merchants should not expect 3DS to eliminate all chargebacks; it eliminates only the subset attributable to fraudulent use of the payment credential.

What happens to liability if the issuer does not support 3DS?

If the merchant's payment provider attempts 3DS authentication but the issuer's Access Control Server (ACS) does not respond or does not participate in 3DS, the transaction may proceed as a non-authenticated transaction. In this case, the liability shift still applies in most scheme implementations: if the issuer failed to authenticate when given the opportunity, the issuer bears the liability for subsequent fraud. Merchants should confirm with their payment provider how non-participating issuer scenarios are handled.

How does the EMV liability shift affect card-not-present transactions?

The EMV chip liability shift applies specifically to card-present (in-person) transactions where a chip card is presented at a magnetic stripe-only terminal. It has no direct effect on card-not-present (online) transactions, which have their own liability framework through 3DS authentication. Card-not-present fraud liability is governed by 3DS adoption and scheme-specific rules rather than the physical EMV chip standard.