Strong Customer Authentication adds additional verification to many electronic payments and online banking actions. For ecommerce merchants, it is commonly delivered through 3-D Secure. The objective is fraud reduction, but a poorly implemented authentication flow can also create failed payments and customer drop-off.
SCA generally uses at least two independent authentication factors
UK payment rules require strong customer authentication in defined circumstances, including many remote electronic payments. Authentication is based on independent elements drawn from knowledge, possession and inherence, such as a password, registered device or biometric factor.
The merchant usually does not build the bank's authentication itself. The payment gateway, acquirer, card scheme and issuer coordinate the 3-D Secure or equivalent flow. The merchant's job is to provide good transaction data and handle the outcome correctly.
3-D Secure is the main ecommerce mechanism for card authentication
In an online card checkout, 3-D Secure can allow the issuer to authenticate the cardholder through its own app, one-time code or biometric process. Modern versions support risk-based data exchange so some transactions can be approved without a visible challenge.
Test the full journey on mobile and desktop. An authentication window that fails to return the customer to checkout can create abandoned orders even though the fraud rules are being followed correctly. Merchant conversion and compliance need to be measured together.
Not every payment requires a visible SCA challenge
The FCA's technical standards contain exemptions for specified situations, including low-risk transactions, trusted beneficiaries and certain unattended transport and parking payments. From March 2026, the contactless exemption framework was updated so providers can apply it to transactions identified as low risk subject to the technical requirements.
An exemption is not the merchant unilaterally deciding to skip security. Acquirers and issuers apply the regulatory framework and risk analysis. Merchants should send the correct transaction indicators and let their payment provider determine the appropriate authentication route.
Merchant-initiated recurring transactions need the initial consent structured correctly
Subscription businesses should distinguish the customer-initiated setup payment from later merchant-initiated recurring charges. The initial arrangement normally establishes the customer's authority and authentication, while subsequent qualifying merchant-initiated transactions can follow a different SCA treatment.
Store evidence of the subscription terms and cancellation route. If the recurring amount or nature of the service changes materially, check the provider's requirements rather than assuming the original authentication authorises anything the merchant may later charge.
Track authentication failures separately from card declines
A failed online payment can result from insufficient funds, issuer risk rules, an SCA challenge the customer did not complete, technical timeout or incorrect payment data. Do not put every failure into one "declined card" bucket.
Measure challenge rate, challenge success, issuer decline rate and checkout abandonment. If one bank or device type produces abnormal failures, the merchant can investigate with the gateway or acquirer. Better payment data can improve both fraud control and conversion.
Reconcile authenticated payments like any other card settlement
Authentication does not change the need to reconcile gross sales, refunds, chargebacks, fees and settlement. A transaction passing SCA does not guarantee that a later customer dispute or refund will never occur.
Keep the 3-D Secure or provider authentication result with the transaction record where available. That evidence can matter in fraud-dispute handling and in diagnosing why particular payments failed. The merchant's payment stack should connect customer authentication to finance reporting rather than leaving it only inside the gateway.
A useful merchant dashboard separates friction from fraud. Track the percentage of transactions routed to an SCA challenge, the percentage successfully authenticated, the issuer approval rate after authentication and the final checkout conversion rate. If challenges rise sharply without a corresponding fraud benefit, investigate transaction data and gateway configuration with the acquirer rather than assuming customers simply changed behaviour.
Test edge cases before major sales periods: saved cards, subscription renewal, a customer changing device, high-value orders and refunds after an authenticated purchase. The payment team should know which events create a new customer-initiated transaction and which can be treated under a merchant-initiated or other permitted framework. Clear classification reduces both unnecessary challenges and compliance mistakes.
For B2B merchants, test corporate cards and delegated employee purchasing as well as ordinary consumer-card journeys. The cardholder completing authentication may be an employee buying on behalf of a company, while the invoice belongs to the employer. Order records should preserve both the commercial customer and the authenticated payment user so finance can reconcile the transaction without confusing cardholder identity with legal customer identity.
Keep fallback behaviour explicit. If the authentication service or issuer challenge is temporarily unavailable, the checkout should not silently downgrade security in a way the provider has not authorised. Decide whether the order is retried, held for review or offered another payment rail such as bank transfer. A controlled failed sale is usually cheaper than an avoidable fraud loss.
Editorial Verdict
Strong Customer Authentication is now a normal part of UK electronic payments, especially ecommerce. Merchants should focus on accurate transaction data, reliable 3-D Secure integration and clear handling of exemptions and recurring payments.
Do not judge SCA only by fraud reduction or only by checkout conversion. Track both. The strongest payment flow authenticates customers when required, avoids unnecessary friction and leaves finance with a clear record of what happened to every transaction.
Sources
- FCA Handbook, Strong Customer Authentication technical standards: https://handbook.fca.org.uk/technical-standards/s140c1226
- FCA, Strong Customer Authentication: https://www.fca.org.uk/firms/strong-customer-authentication