"EMV 3-D Secure for US Remittance Merchants" (FK-C002, Faisal Khan LLC, 20 March 2026, companion to FK-C001) explains how 3DS works, how to implement it in the United States, and how successful authentication moves fraud chargeback liability from the merchant to the issuer. For a remittance business paying out irrevocably abroad while accepting revocable card funding at origin, the guide calls that single rule change worth more than any fraud-scoring model.
3DS is an EMVCo protocol running across the acquirer, the network's Directory Server, and the issuer's Access Control Server. On a successfully authenticated transaction (ECI 05 for Visa, 02 for Mastercard), the issuer loses the right to charge back under fraud reason codes — Visa 10.4 and its equivalents — because the issuer authenticated its own cardholder. The guide details four limits on that protection: non-fraud disputes like "services not provided" are untouched; merchant category exclusions apply, with money transfer typically sitting under MCC 4829; US debit can route over unaffiliated networks under the Durbin Amendment, bypassing 3DS entirely; and Visa can restrict liability-shift benefits from merchants with disproportionate fraud on authenticated traffic.
What the guide covers:
- The three domains and the three artefacts — ECI code, CAVV/AAV cryptogram, and 3DS Transaction ID — that must be captured and stored for every authenticated transaction
- Why frictionless authentication now handles the large majority of US 3DS2 traffic, unlike the password-popup 3DS1 era retired by the networks in 2022
- The dispute flow change: a contested chargeback battle becomes a single-exhibit representment
- Where to obtain 3DS — through a PSP or gateway, a standalone 3DS Server, or an orchestration platform — at a typical per-authentication cost in the low cents
- Since the US has no 3DS mandate, where to deliberately aim it: new customers, new devices or phone numbers, amount escalations, and new beneficiaries above a threshold
- Why the liability shift works specifically against first-party fraud, since the issuer holds both the loss and the authentication proof
