Skip to main content
Commerce Security logo, "All 12 PCI DSS Requirements in Plain English," "Get it now for free," "Complete Survival Guide" and a button toclick to get it
Acquirer Liability Won't Tank Your Auth RatesRegulations and Standards
4 min readFor Fintech Risk and Compliance Teams

Acquirer Liability Won't Tank Your Auth Rates

There's a belief that PSD3's acquirer liability shift will devastate authorization rates. The idea is that acquirers, now bearing fraud risk, will decline more transactions. Payment Service Providers (PSPs) will become cautious, and merchants will see conversion rates drop as they wait for regulatory clarity in late 2027 or early 2028.

This narrative is neat but misses key points.

Why the Narrative is Incomplete

The liability shift doesn't mean acquirers will decline more transactions. It means they need to make smarter decisions about which transactions to decline.

Acquirers will indeed carry fraud liability under PSD3, but they already faced reputational risk, chargeback costs, and network penalties under PSD2. The new framework changes the incentives around existing risk management, not the risk itself.

What's crucial is not just that acquirers become liable, but whether they have the data and systems to manage that liability well. An acquirer with strong pre-authorization fraud signals can keep high auth rates while managing fraud exposure. Those relying on outdated methods like transaction value thresholds or static rules will likely decline more transactions defensively.

The real issue isn't the liability shift itself. It's the gap between what liability demands and what current fraud prevention systems provide.

The Evidence

PSD3 changes several things. Strong Customer Authentication (SCA) alone no longer proves a transaction was authorized. This doesn't make SCA useless; it raises the standards for post-authorization evidence. You need transaction-level signals like behavioral data, device intelligence, and network patterns, which also enhance pre-authorization decisions.

Transaction Risk Analysis (TRA) exemptions are becoming stricter. PSPs must now show the fraud prevention measures behind their low fraud rates, not just report the rates. The European Banking Authority will publish Regulatory Technical Standards by late 2026 or early 2027.

Practically, if your PSP can't show robust fraud measures, they might default to 100% SCA. But with strong measures, exemptions are still possible. The regulation doesn't remove TRA exemptions; it raises the bar for qualifying.

The regulatory text also clarifies merchant-initiated transactions. SCA is required only at mandate setup, with subsequent charges exempt. Customers can only claim refunds on recurring payments if the amount differs from what they agreed to pay, reducing first-party fraud risk for subscription merchants.

These changes don't aim to kill conversion. They reward sophisticated fraud prevention.

What to Do Instead

Don't view the liability shift as an authorization issue. Treat it as a data challenge.

Build your fraud prevention system to generate the evidence PSD3 requires. Capture behavioral signals in your checkout flow, not just payment credentials. Use device fingerprinting, session replay for disputed transactions, and network graph analysis showing relationships between accounts, devices, and payment methods.

Many merchants already collect this data for fraud prevention. The shift is about making it available to your PSP pre-authorization, not just reviewing it post-authorization. If your acquirer can see the same risk signals you do before making the auth decision, they can authorize confidently.

Engage with your PSPs about their PSD3 preparation. Ask specific questions: What fraud prevention measures will they use to qualify for TRA exemptions? How will they structure pre-authorization data sharing? What evidence standards will they require for chargeback defense? PSPs with clear answers are investing in systems to maintain auth rates under the new framework.

Consider a multi-PSP strategy, not as a hedge against declining auth rates, but to compare how different PSPs are preparing. One processor becoming conservative doesn't mean the entire market will. Working with multiple PSPs gives you insight into which ones are building sophisticated fraud systems versus those defaulting to blunt controls.

For Merchant-Initiated Transactions (MIT) and Mail Order/Telephone Order flows, the regulation now provides explicit definitions and exemptions previously only in EBA guidance. Document your mandate setup processes. Ensure your subscription renewal flows clearly distinguish between merchant-initiated charges (exempt) and customer-initiated changes (not exempt). This isn't new friction; it's regulatory clarity that protects your processes.

When the Conventional Wisdom is Right

The liability shift will hurt authorization rates in specific scenarios, and you should know if you're in one.

If you're working with a single PSP lacking sophisticated fraud prevention systems, you'll likely see more declines. If that PSP can't demonstrate robust fraud measures to qualify for TRA exemptions, they'll push more transactions through SCA challenges, affecting your conversion.

If you're a multi-sided marketplace relying on the Commercial Agent Exemption, the PSR closes that loophole. You'll need a payment institution license or restructure so a licensed PSP handles fund flows. This isn't about authorization rates; it's about whether you can continue processing payments at all.

If you're not capturing transaction-level fraud signals beyond SCA, you'll struggle to defend chargebacks under the new evidence standards. Without that defense capability, your PSP may treat your transactions as higher risk, leading to more declines.

The conventional wisdom is right in identifying acquirer risk aversion as a threat. Where it's wrong is assuming that risk aversion automatically means lower auth rates. Risk aversion means declining transactions you can't defend. Build the systems that let you defend them.

The EU Council's texts are undergoing final checks, expected to be published in September 2026. You have time to enhance your fraud prevention systems before enforcement begins. The question isn't whether the liability shift will hurt your auth rates. It's whether you'll use the next year to ensure it doesn't.

Promotional banner for the Penetration Report Template Kit

You Might Also Like