Glossary
Liability Shift

Liability Shift

Liability Shift is the transfer of responsibility for certain types of fraud losses from one party to another, for example from merchant to issuer after successful 3D Secure authentication.

GLOSSARY
What is a
Liability Shift

Liability shift reallocates responsibility for certain fraud-related chargeback losses from the merchant to the card issuer, and it typically happens when a transaction has been successfully authenticated using a protocol like 3D Secure. In plain terms: if the issuer confirms it verified the cardholder at the time of purchase, the issuer generally takes on the fraud risk for that transaction rather than leaving it with the merchant.

That reallocation matters a great deal in practice, because without it, merchants accepting card-not-present transactions carry most of the fraud risk on unauthorised purchases by default. Liability shift exists specifically to change that default, rewarding merchants who use stronger authentication with reduced exposure, while placing responsibility with whichever party actually made the authentication decision.

How The Shift Actually Gets Triggered

The shift generally applies when a payment is successfully authenticated through 3D Secure for a supported card scheme, which today includes most major networks. Technically, this shows up as a specific electronic commerce indicator (ECI) value attached to the transaction, such as an ECI of 05 for Visa or 02 for Mastercard at the time of writing, confirming that full authentication took place - scheme-specific values and rules are subject to change Without that indicator present, the shift generally doesn't apply, regardless of whether the merchant attempted authentication.

Where Liability Shift Rules Differ By Card Scheme

Not every card scheme handles this identically. If a card isn't enrolled in 3D Secure and a merchant attempts authentication anyway, some schemes, including Visa, still extend liability protection to the merchant for the attempt itself. Others, including Mastercard, generally leave liability with the merchant if the card wasn't enrolled, even when authentication was correctly attempted. That distinction is easy to overlook but matters a lot for merchants operating across multiple card schemes.

What Liability Shift Actually Covers

The protection is specifically aimed at fraud-related chargeback claims, particularly those coded as unauthorised use or fraud in a card-not-present environment. It generally doesn't extend to friendly fraud, where a legitimate cardholder disputes a charge they actually authorised, nor does it typically apply to recurring transactions processed after an initial authenticated payment, since those later charges usually aren't separately authenticated.

Why Issuers Accept The Risk They Do

From the card issuer's perspective, taking on liability makes sense specifically because a successful 3D Secure authentication represents the issuer's own verified claim that the cardholder was genuinely present at the time of purchase. Having made that determination itself, using its own authentication tools and its own relationship with the cardholder, The issuer is generally considered the party best placed to bear responsibility if that determination turns out to be wrong. Liability shift rules vary by card network and are updated periodically; merchants should confirm current rules with their acquirer or the relevant card scheme.

How This Fits Into The Broader Authentication And Authorisation Flow

Liability shift sits specifically at the authentication step, distinct from payment authorisation, which is the separate decision about whether a transaction can proceed based on funds and account status. A transaction can be authenticated, triggering liability shift, and still be declined at the authorisation stage for unrelated reasons, or approved at authorisation without ever having gone through authentication at all, in which case liability shift simply never enters the picture.

Practical Implications For Merchants

Merchants weighing whether to route transactions through 3D Secure generally need to balance the fraud protection liability shift provides against the additional friction authentication can introduce at checkout, since a challenge flow that interrupts the customer experience can sometimes cost more in abandoned purchases than it saves in prevented fraud. Many businesses lean on risk-based authentication specifically to apply that friction selectively, reserving it for transactions that genuinely look higher risk rather than applying it universally.

Fitting Liability Shift Into A Smarter 3DS Strategy

Chasing liability shift on every single transaction isn't necessarily the right goal, since the friction that comes with universal authentication can cost a merchant more in abandoned purchases than it saves in avoided fraud losses. finera.'s piece on smart 3D Secure and reducing payment declines covers this trade-off directly, making the case for applying authentication selectively based on genuine risk signals rather than treating liability shift as something to maximise unconditionally across every single transaction a merchant processes.

Table of contents

Frequently Asked Questions

How does liability shift actually work with 3D Secure?

When a transaction is successfully authenticated through 3D Secure, responsibility for certain fraud-related chargebacks generally shifts from the merchant to the card issuer, since the issuer verified the cardholder at checkout.

Does liability shift work the same way for Visa and Mastercard?

Not entirely. If a card isn't enrolled in 3D Secure, Visa generally still protects merchants who attempted authentication, while Mastercard typically leaves liability with the merchant in that scenario.

Does liability shift protect against all types of chargebacks?

No. It generally covers fraud-related chargebacks in card-not-present transactions, but doesn't typically extend to friendly fraud or to recurring charges processed after an initial authenticated payment.

Why does the issuer accept liability after authentication?

Because a successful 3D Secure authentication represents the issuer's own verified claim that the cardholder was present, the issuer is generally considered best placed to bear responsibility if that verification turns out to be wrong.

Is liability shift the same thing as payment authorisation?

No. Liability shift relates to authentication, while authorisation is the separate decision about whether a transaction can proceed based on funds and account status. A transaction can involve one without the other.

Still Have Questions?

Let’s Find the Right Solution for You

Share this article
Glossary

Stay Connected with Us!

Follow us on social media to stay up to date with the latest news, updates, and exclusive insights!