Confidential by defaultEstablished 201072 Jurisdictions
Explainers

EMV 3-D Secure for US Remittance Merchants

How 3DS works, how to obtain and implement it in the United States, and how successful authentication

Format
PDF
Size
122.9 KB
Filed under
Explainers
Access
Open download
Download

The file downloads straight away. No email required.

"EMV 3-D Secure for US Remittance Merchants" (FK-C002, Faisal Khan LLC, 20 March 2026, companion to FK-C001) explains how 3DS works, how to implement it in the United States, and how successful authentication moves fraud chargeback liability from the merchant to the issuer. For a remittance business paying out irrevocably abroad while accepting revocable card funding at origin, the guide calls that single rule change worth more than any fraud-scoring model.

3DS is an EMVCo protocol running across the acquirer, the network's Directory Server, and the issuer's Access Control Server. On a successfully authenticated transaction (ECI 05 for Visa, 02 for Mastercard), the issuer loses the right to charge back under fraud reason codes — Visa 10.4 and its equivalents — because the issuer authenticated its own cardholder. The guide details four limits on that protection: non-fraud disputes like "services not provided" are untouched; merchant category exclusions apply, with money transfer typically sitting under MCC 4829; US debit can route over unaffiliated networks under the Durbin Amendment, bypassing 3DS entirely; and Visa can restrict liability-shift benefits from merchants with disproportionate fraud on authenticated traffic.

What the guide covers:

  • The three domains and the three artefacts — ECI code, CAVV/AAV cryptogram, and 3DS Transaction ID — that must be captured and stored for every authenticated transaction
  • Why frictionless authentication now handles the large majority of US 3DS2 traffic, unlike the password-popup 3DS1 era retired by the networks in 2022
  • The dispute flow change: a contested chargeback battle becomes a single-exhibit representment
  • Where to obtain 3DS — through a PSP or gateway, a standalone 3DS Server, or an orchestration platform — at a typical per-authentication cost in the low cents
  • Since the US has no 3DS mandate, where to deliberately aim it: new customers, new devices or phone numbers, amount escalations, and new beneficiaries above a threshold
  • Why the liability shift works specifically against first-party fraud, since the issuer holds both the loss and the authentication proof

Click here to download the document and view in full.

← All downloads

Page Last Updated: 22/SEPT/2026 (1300033)