Risk-Based Authentication
What Is Risk-Based Authentication? Definition and How It Works
Definition
Risk-based authentication (RBA) is an approach to transaction and account authentication that dynamically adjusts the level of verification required based on the assessed risk of the specific transaction or access request. Low-risk interactions proceed with minimal friction; higher-risk interactions trigger additional authentication steps. In payments, RBA underpins the SCA exemption framework under PSD2 and the frictionless flow in 3DS2.
How it works
Risk-based authentication evaluates a set of signals at the time of a transaction or login to produce a risk score. The signals include: device recognition (is this a known, trusted device for this user?), geolocation (is the request coming from a location consistent with the user's usual pattern?), transaction amount (is this within the normal range for this cardholder?), velocity (how many transactions has this cardholder or device made recently?), and behavioural biometrics (does the interaction pattern match the user's historical behaviour?).
Based on the risk score, the authentication system applies one of several responses. Low-risk transactions receive a frictionless approval: the transaction proceeds without any additional authentication step visible to the user. Medium-risk transactions may trigger a passive step-up: a soft authentication that the user completes without significant friction, such as a biometric confirmation or a push notification. High-risk transactions trigger active step-up authentication: an SMS OTP, a 3DS challenge screen, or a full re-authentication flow.
In the 3DS2 framework, risk-based authentication is built into the protocol. The 3DS requestor (the merchant's payment provider) sends a rich data set to the card network's Access Control Server (ACS), which applies the issuer's RBA model to decide whether to grant a frictionless flow or issue a challenge. Issuers using sophisticated RBA models can apply frictionless flow to the majority of transactions while challenging only the highest-risk subset.
Under PSD2's SCA exemptions, Transaction Risk Analysis (TRA) is a formal exemption category: acquirers or issuers with fraud rates below defined thresholds can apply TRA to exempt eligible transactions from SCA, based on a real-time risk assessment meeting the EBA's technical requirements.
Why it matters
Risk-based authentication resolves the fundamental tension between security and conversion in payment authentication. Universal SCA (requiring strong authentication for every transaction) dramatically reduces fraud but also reduces conversion: customers who are asked to authenticate for every purchase abandon at higher rates. Applying authentication friction selectively, only where risk warrants it, preserves conversion on the majority of legitimate low-risk transactions while focusing security scrutiny on the minority of genuinely elevated-risk transactions.
The commercial impact is significant. Across a large e-commerce merchant, the difference between 100% challenged 3DS and optimised RBA-driven frictionless flow can be a 2 to 5 percentage point improvement in checkout conversion. On significant revenue volumes, this improvement is material.
Regulatory expectations for RBA quality are high. Under PSD2, exemptions from SCA are available to issuers and acquirers who meet defined fraud rate thresholds, and those thresholds must be maintained continuously. An issuer whose fraud rate exceeds the threshold loses the right to apply TRA exemptions until it falls back within limits, which creates strong incentives to invest in accurate risk models.
With PXP
PXP's adaptive 3DS evaluates each transaction and applies authentication or exemptions based on risk and regulation. Talk to our team about how PXP can support your risk-based authentication.
Frequently asked questions
What is the difference between risk-based authentication and two-factor authentication?
Two-factor authentication (2FA) requires two verification factors for every authentication, regardless of the assessed risk level. It provides consistent security but applies uniform friction to all users and transactions. Risk-based authentication dynamically adjusts the required factors based on the transaction's risk score: low-risk transactions may require only one factor or proceed frictionlessly, while high-risk transactions trigger the full two-factor flow. RBA is more conversion-friendly; 2FA is simpler to implement and reason about.
What is Transaction Risk Analysis (TRA) under PSD2?
TRA is a PSD2 exemption from SCA that allows acquirers or issuers to process transactions without step-up authentication when a real-time risk assessment determines the transaction is low-risk. The exemption is conditional on the applying institution maintaining a fraud rate below specified thresholds: 0.13% fraud rate for transactions up to EUR 100, 0.06% for up to EUR 250, and 0.01% for up to EUR 500. Institutions exceeding these thresholds lose the right to apply TRA for the relevant amount band until their fraud rate returns within limits.
How does RBA affect the customer experience?
In a well-implemented RBA system, the majority of legitimate customers experience no authentication friction at all: their transactions are assessed as low-risk and proceed frictionlessly. Only a small proportion of transactions, those scoring above the risk threshold, encounter a visible authentication step. For customers, this means seamless checkout on routine purchases and authentication prompts only when their behaviour genuinely warrants additional verification, such as a large purchase on a new device or in an unfamiliar location.
Revolutionize your business with PXP
Take complete control of your commerce and payments with one platform.
Get Started