PSD2: Fraud Win
Turned Revenue Leak
You’ve already approved these customers. Then 3DS loses them at the challenge, and the loss hides as checkout abandonment, not fraud.
The compliance investment was justified.
The revenue leak is the next problem.
PSD2 reduced card fraud. That part worked. European card-not-present (CNP) fraud fell by 12% in 2021 following SCA enforcement (ECB Report on Card Fraud, 2021). Card-not-present (CNP) fraud accounted for 84% of all card fraud value. The regulation was aimed at the right target. The compliance investment was justified.
But the regulation created a second problem that most organisations are still not measuring. When customers you have already identified as trustworthy are sent through a 3DS authentication challenge, a significant proportion never come back. They fail, or they abandon. Across Europe, around one in six of these already-approved customers do not make it through, and in markets like Germany and Austria it climbs to nearly one in four. Because that drop-off occurs before the payment is submitted for authorisation, it never appears as a payments failure in your reporting. It gets logged as checkout abandonment. That looks like a marketing problem, or a UX problem. It is neither.
The merchants who have found that gap and closed it are seeing improvements in completion rates, sustained reduction in chargebacks, and stronger authorisation rates. All at the same time. GetYourGuide increased conversion rates by 1.22% and reduced chargebacks 5x simultaneously. ASOS reduced 3DS challenges by 83% and contained failure and abandonment to 3%. This is not a compliance project. It is a revenue recovery opportunity critical to business growth.
Across European merchants, five distinct levels of authentication maturity have emerged. Most are leaving significant revenue on the table. A small group are not. This report shows you which group you are in, and what closing the gap is worth.
The cost of a failed authentication is not just the transaction. It is the customer. One negative experience in the checkout flow can end a relationship that took years of marketing spend to build.
The Compliance Comfort Zone
How PSD2 reshaped fraud prevention in European ecommerce
PSD2 was built to modernise European payments and open the market to new players. Strong Customer Authentication was its answer to one specific problem: rising card-not-present (CNP) fraud, which had reached €1.87 billion in 2019 (ECB Report on Card Fraud, 2020) and accounted for around 84% of total card fraud value. Something had to change.
By requiring customers to verify identity using two factors, regulators created a meaningful barrier to card-not-present fraud. After a phased rollout, full enforcement landed across most EEA markets by end of 2020, with some countries including Italy, Germany, and Ireland extending into 2021, and the UK following in March 2022. Once in place, it worked. There was a 12% decline in CNP fraud in 2021 (ECB Report on Card Fraud, 2021). By 2024, card fraud was running at ten times the rate for transactions with a counterpart outside the EEA, where SCA is not legally required, compared to within it (EBA/ECB Joint Report on Payment Fraud, 2024).
SCA enforcement did not eliminate fraud. It displaced it. As card payments became harder to exploit, fraudsters moved elsewhere. The EBA and ECB’s 2025 Joint Payment Fraud Report documents a rise in social engineering schemes, impersonation scams, and authorised push payment fraud in the years following SCA enforcement. Forter’s own network data tells a similar story: since PSD2 came into full effect across Europe, ATO attempts across its merchant base have risen 180%, gift card fraud 230%, and refund abuse including false INR claims more than 200%. PSD2 solved the problem it was designed to solve. The fraud landscape it created is a different conversation, and an important one. The problem this report addresses is not the fraud PSD2 pushed elsewhere. It is the revenue it cost merchants at the moment of authentication.
The liability shift
When a transaction completes 3DS, fraud liability shifts from the merchant to the card issuer. That is a genuine benefit. But it created a measurement blind spot: the impact of authentication was measured only in terms of fraud prevention, and did not account for customers lost during the authentication process itself.
And so a reasonable default settled in. Authentication was handled. Card fraud was down. Remaining checkout losses were attributed to the usual suspects. Compliance was ticked. The work felt done.
It was not. Because something else was happening that the standard reporting could not see. It is still happening. This report shows you how far up that ladder your business sits, and what closing the gap is worth.
The merchants operating at the highest levels of authentication maturity today did not wait for the next compliance deadline. They built a capability their competitors had not thought to measure.
The Revenue Leak Revealed
How authentication friction erodes checkout conversion
Every day, genuine customers abandon purchases during authentication. Not because they changed their mind. Not because of fraud. Because the process interrupted them at the worst possible moment and they did not come back.
A customer has spent time on your site. They have made a decision. They have added items to their basket, entered their card details, and clicked pay. They want this purchase. A screen appears from their bank. They need to open a banking app, find a one-time code, or navigate a redirect that looks nothing like your brand experience. On mobile, where over half of your transactions originate, it can be genuinely disruptive.
Sometimes families share cards and the person who gets the authentication request is not the one trying to buy. Sometimes the customer is not near their phone. Sometimes the OTP never arrives because their number is out of date at the bank. There are a dozen other reasons a genuine customer does not complete the challenge. None of them are fraud. You almost certainly never know they were there.
Two types of loss, both hidden in standard reporting
The drop-off comes from two things. A customer who gives up when the challenge appears, or a challenge that breaks before they can finish. Either way the outcome is the same.
The transaction never reaches authorisation, so in most PSP reporting it is filed as checkout abandonment, indistinguishable from a customer who simply decided not to buy (Merchant Risk Council). Retrying rarely helps, because it just runs the same broken flow again. The real cause stays invisible, whether it was an issuer policy, a broken redirect, or a customer who had already left.
The merchants who have closed this gap share one characteristic: they stopped measuring authentication as a fraud metric and started measuring it as a revenue metric. Most of their competitors still have not made that switch.
“Managing fraud is not just about blocking fraudsters. It’s about ensuring your genuine customers aren’t wrongly flagged or inconvenienced.”
The scale of the hidden loss
When SCA was introduced, 451 Research / Stripe projected it would cost European businesses up to €57 billion in lost economic activity in its first year, roughly 10% of the region’s online sales at the time (2019). The revenue leak was there from the very beginning.
The number most teams reach for is a blended 3DS success rate. It is the wrong number. A blended rate mixes the fraudsters you want to fail in with the genuine customers you cannot afford to lose, so a low figure tells you nothing about which is happening. And a fraudster who fails a challenge is a save, not a loss. The figure that actually matters is narrower, and far more uncomfortable: of the customers you have already identified as trustworthy, how many still fail or abandon the challenge?
In Forter’s network, across roughly 723,000 approved-and-challenged transactions in Europe, around 1 in 6 of these known-good customers still fail or abandon the 3DS challenge. Broken down by market, the share runs to roughly 1 in 4 in Germany (24.5%) and Austria (25.5%), about 1 in 5 in Italy (21.8%) and Spain (20.0%), 1 in 6 in France (16.2%), and fewer than 1 in 14 in the UK (6.9%). Every one of those is revenue lost for no fraud benefit whatsoever. Markets have improved since the chaotic early days of SCA rollout. Analysis of regulated markets shows French frictionless authentication rose 40% in H1 2024 as more transactions qualified for exemptions (Stripe, 2024). But improvement is not the same as solved, and the gap between merchants who have invested in authentication infrastructure and those who have not remains large.
None of this friction is inevitable. High authentication rates do not damage conversion. Poor authentication implementation does.
The impact is not evenly distributed across transaction values. Abandonment rates on transactions above €100 are 8–15 percentage points higher than on low-value transactions, across major European issuers in Forter’s network.
The customers most likely to abandon during a 3DS challenge are also the ones making your highest-value purchases.
Complete rate: the number you should be tracking
Successful authorisations divided by transactions submitted for authorisation.
Successful transactions divided by all transaction attempts, including those abandoned or failed during authentication.
This is where the biggest opportunity cost lies, and why over-challenging stays hidden: flood transactions into 3DS and your authorisation rate can still look healthy while your complete rate quietly collapses, because trusted customers abandoned before they ever reached authorisation. Challenge only where it is genuinely needed and the same complete rate climbs. Complete rate is the number that separates a smart authentication strategy from an overdone one. Most merchants track only the first.
Why We Don’t See the Leak
The authentication black box inside the payments ecosystem
If the problem is real and measurable, why do so few merchants know it is happening to them?
Authentication sits across four distinct parties: the merchant, the payment service provider (PSP), the card network, and the issuer. Each plays a role. None has a complete view. The issuer’s Access Control Server makes the actual decision: frictionless flow, challenge, or decline. The merchant cannot see why challenges are triggered for specific customers, why one issuer accepts exemption requests and another systematically rejects them, or what is happening inside an individual bank’s authentication infrastructure.
Soft decline codes are generic. They confirm a transaction was declined for authentication reasons. They do not tell you whether the issuer has a blanket policy against your transaction profile, whether its challenge flow breaks on mobile, whether there is a specific BIN range where your completion rate consistently collapses, or whether the customer themselves dropped out through frustration or confusion despite the technical flow working correctly. Most PSPs do not surface this level of detail in standard reporting, but merchants who ask for it directly can often access more granular breakdowns. The barrier is usually awareness, not availability. What that data will show you is the scale of the problem. What it will not show you is the issuer-level, real-time picture you need to do something about it.
Five questions to ask your payment service provider (PSP) today
Most merchants have never asked their PSP for this level of detail. Start here.
Can you show me my complete rate — successful transactions divided by all transaction attempts, including those abandoned or failed before authorisation?
Can you break down my 3DS authentication failures by type: technical failure versus customer abandonment?
Can you show me my challenge success rate and abandonment rate by individual issuer BIN?
What is my exemption rejection rate — and are those rejections soft declines or hard declines?
Can you show me the difference in authentication success between mobile and desktop traffic?
The answers will either show you a problem you did not know you had, or confirm that your PSP cannot answer these questions. Both are important signals.
Once 3DS was configured with the PSP, nobody wanted to touch it. Nobody was entirely sure what was happening inside it. And so it ran, in the background, unmonitored and unoptimised.
What the PSP is not showing you
PSPs have limited incentive to surface authentication performance problems. They process transactions. They do not own your conversion rate. If customers are dropping off during authentication, those transactions never reach the authorisation layer. They never appear in the metrics the PSP reports to you. The data looks clean. Revenue is leaving and you cannot see why.
PSPs also charge per 3DS authentication attempt regardless of outcome, and have an incentive to maintain low fraud rates for their card network standing. Neither of those things aligns with reducing unnecessary challenges for merchants. This is compounded by the fact that many PSPs both control the 3DS execution and produce the reporting on it. They are marking their own homework. When merchants do push for answers, PSPs can conveniently point to the issuing bank. After all, it is the issuer’s Access Control Server making the final decision. The issuer is inaccessible to the merchant. The PSP has plausible deniability. And in many cases the PSP genuinely lacks the granular data to differentiate between a timeout, a protocol failure, and a customer who simply gave up.
Most teams can quote their fraud loss and chargeback rates to the decimal. Almost none have an equally rigorous view of the good revenue they are turning away. Merchants reject around 6% of all e-commerce orders, and between 2% and 10% of those rejections are legitimate customers turned away, not fraud stopped (MRC Global Payments and Fraud Report, 2024). Research suggests merchants lose roughly 13 times more revenue to false declines and unnecessary friction than to fraud itself (Javelin Strategy & Research). The friction costs more than the fraud.
The tools merchants rely on were designed to stop fraud and process payments. None of them were designed to answer the question that actually drives revenue recovery: given everything known about this customer and this issuer, right now, what is the optimal path through authentication?
Mapping the Leak
Where authentication breaks down across issuers and markets
Many merchants assume issuers behave similarly enough to be treated the same way. A single authentication approach, applied uniformly, feels like the safe and simple choice. It is not. Leading merchants have learned that each issuer is its own problem to solve. Most are still treating them as one. How a bank built its 3DS infrastructure, whether it accepts exemptions or rejects them, whether its challenge flow works on mobile or breaks — all of it determines your conversion rate in that market. The data below shows what that looks like across Europe’s major issuers.
Forter’s network data shows a far more uneven picture than country averages suggest.
Good-customer drop-off by market
The figures below look only at customers Forter had already scored as trustworthy, and show how many still fail or abandon the 3DS challenge. This is pure leak: revenue lost with no fraud benefit. We exclude risky traffic on purpose, because a fraudster failing a challenge is a save, not a loss. Blending the two is exactly why this loss stays invisible.
Figures show Forter-approved (known-good) transactions that were sent to a 3DS challenge and then failed or were abandoned, combining customer abandonment and technical failure. Nearly 1 in 4 trusted customers are lost at the challenge in Germany and Austria; the UK loses fewer than 1 in 14. Source: Forter network data, June 2026. Forter-approved transactions, with non-representative marketplace feeds excluded. n≈723,000 approved challenged transactions.
Even the strongest issuers leak trusted customers
Country averages are only the starting point. The bars below break that same group of Forter-approved, trusted customers down by issuer, on the same drop-off metric as the market chart above, so a high number can’t be blamed on fraud. And not one issuer comes out clean. Even the strongest bank in each market still loses a real share of customers it had already approved. Sabadell loses 17% in Spain, Intesa 20% in Italy, N26 21% in Germany. The weakest, Advanzia, loses a third. That makes it a systemic leak, not a handful of bad banks.
When issuers do differ, it comes down to infrastructure. In Germany, the digital banks N26 (21.5% drop-off) and DZ Bank (22.5%) leak far less than the traditional networks Sparkassen (30.7%) and Advanzia (32.7%), an 11-point gap. That gap is about how each bank built its 3DS flows, not how big it is. Italy and Spain are bunched more tightly, just 4 to 5 points between strongest and weakest, and that tells the same story. The leak reaches every issuer, and it only grows once riskier traffic is added back in.
Drop-off rate by issuer — % of trusted customers who fail or abandon the 3DS challenge (lower is better)
Source: Forter network data, June 2026. Forter-approved (trusted) segment, on the same basis as the market chart above (non-representative marketplace feeds excluded). DZ Bank combines both DZ entities. Drop-off = trusted customers who failed or abandoned the 3DS challenge. Green = under 20%. Blue = 20–30%. Red = 30%+.
The same leak widens on mobile. Across all major issuers in Forter’s network, trusted customers drop off 7–12 percentage points more often on mobile than on web. Crédit Agricole shows the widest gap: 29% drop-off on mobile versus 17% on web. Bank of Scotland runs 24% versus 14%. This is not a customer behaviour problem. It is infrastructure.
Abandonment versus technical failure: two different fixes
The drop-off has two main causes a merchant can fix, and each needs a different response. It helps to see where the failures actually come from. Across Forter’s network, most are issuer-side: exemption rejection (27.8% of failures) and issuer rejection (15.6%), followed by user abandonment (12.6%) and technical failure (11.5%). Abandonment and technical failure are close in size, but they call for completely different fixes, and the traditional German and Italian issuers like Sparkassen, Advanzia and Postepay tend to carry more of both.
Technical failure is mostly a structural problem at traditional German and Italian issuers. Many still run redirect-based 3DS, which pushes the customer out of the merchant’s checkout and onto a bank-hosted page. Those flows were built for desktop browsers, so on mobile, in in-app browsers, or on a weak signal, they break. UK issuers mostly designed this out, investing in SDK-based and app-to-app flows during their longer SCA rollout window.
Abandonment is a different problem. The customer reaches the challenge screen and gives up, because the flow is too slow, too confusing, or too unfamiliar. You fix that with better UX, push-notification flows, and faster challenge completion, not the infrastructure rebuilds that solve technical failure.
Why Existing Approaches Fall Short
Built for fraud. Not built for authentication.
Authentication friction sits in a gap between three systems: fraud prevention tools that operate before authorisation, the 3DS and SCA layer, and the payment authorisation layer that follows. No tool historically owned the optimisation of the middle layer.
Let the PSP decide
Delegate all authentication decisions to the PSP. Simple, compliant, low overhead.
Limitation
No control over when and how 3DS is applied. Authentication is a black box. Optimisation is invisible. It is also disconnected from your fraud decisioning: a borderline transaction carries no risk signal into the authentication step, so it gets declined outright rather than stepped up to 3DS, where authentication could have saved the sale and shifted liability.
3DS everything
Apply 3DS broadly to maximise compliance and shift fraud liability across all transactions.
Limitation
High challenge rates, significant abandonment, reduced conversion. Particularly acute in Germany, Spain, and Italy.
Exempt everything
Apply for exemptions wherever possible to reduce friction and maximise frictionless flow.
Limitation
Issuers do not always soft-decline rejected exemptions. Sometimes they hard-decline outright. That loses a transaction a well-timed authentication would have saved, and it leaves an already-approved customer declined by their own bank, a worse experience than any challenge. It also runs separately from your fraud decisioning, so a borderline transaction that warrants a challenge is waved through on an exemption, or declined, instead of being routed to 3DS, the one path that could both verify the customer and shift liability. A nuanced strategy knows when not to exempt.
Rule-based optimisation
Use TRA and low-value exemptions with static thresholds. Some control, more visibility.
Limitation
Rules are based on historical patterns and cannot adapt to changing issuer behaviour or transaction-level nuance.
Most European merchants sit somewhere in that table. Leaders have moved beyond it entirely. The question is not which of these four approaches to choose. It is how to build the capability that makes the question obsolete.
The scale of exemption rejection is underappreciated. Of all authentication failures in Forter’s network, exemption rejection is the single largest known failure category at 27.8% of failures, larger than technical failure at 11.5% and larger than user abandonment at 12.6%. When issuers reject exemption requests, many are not soft-declining. They are hard-declining outright, losing the transaction entirely. A blanket exemption strategy assumes issuers will play along. The data shows many do not.
A blanket strategy also stumbles on two execution choices most merchants never tune, and both decide whether an exemption is even accepted. The first is the processor. TRA exemption eligibility is not set at the merchant level. It is set at the acquirer level and gated by each PSP’s own fraud rate. Under the RTS, you can exempt up to €100 only while the acquirer’s fraud rate stays below 0.13%, up to €250 below 0.06%, and up to €500 below 0.01% (Commission Delegated Regulation (EU) 2018/389, Annex). So the band you can exempt into depends on your processor’s standing, not your own clean record. And it tightens the moment that processor’s fraud rate drifts up. If you are on a single processor when it does, every transaction above the new ceiling goes to 3DS immediately, however well optimised your strategy is. Merchants with more than one processor can route high-value transactions to whichever currently qualifies for the highest band. In Europe, that multi-processor capability is the difference between controlling your authentication outcomes and being at the mercy of someone else’s risk policy.
The second is how the exemption is requested. An exemption can be sent through the 3DS rails, or sent directly to authorisation with no 3DS message at all (direct-to-authorisation, or DTA). The right choice is market-specific. In some markets, the UK clearest among them, DTA yields higher exemption acceptance and a cleaner, faster flow. In France the opposite is now true and mandatory: since May 2025 the Banque de France has required every exemption on a French-issued card to go through the 3DS rails, and any DTA transaction is systematically soft-declined. Applying one method uniformly across Europe leaves revenue on the table twice over: it under-performs where DTA would have won, and it loses transactions outright in France.
Fraud prevention tools were designed to stop fraud, not reduce unnecessary challenges. Liability protection after authentication does not address friction during authentication. PSP routing tools improve authorisation rates, not authentication success rates. The gap is structural, not a failing of any particular approach. That gap is where the revenue leak lives.
Merchants Who Optimise Authentication
How leading merchants improve conversion without increasing risk
The revenue leak is recoverable. The merchants proving it are not operating at a different scale or with bigger teams. They have made one shift that most of their competitors have not: from treating authentication as a compliance obligation to treating it as a performance discipline. That shift is what separates the leaders from the rest.
ASOS was sending 100% of its EEA digital commerce transactions through 3DS to maintain PSD2 compliance. By building an exemption strategy informed by customer identity and issuer behaviour, ASOS reduced its 3DS challenge rate by 83%. Failure and abandonment was contained to 3%.
“Forter specialises in increasing conversion rates while complying with PSD2 — enabling us to reclaim revenue that would otherwise be lost to abandoned purchase processes.”
Morgan McAlinden-Wall, Fraud Prevention Manager, ASOS
GetYourGuide, a global travel experiences marketplace operating across 170+ countries, partnered with Forter to replace static fraud rules with AI-powered identity intelligence. By combining Fraud Management and Payment Optimisation, Forter gave GetYourGuide the ability to dynamically apply 3DS where needed and exempt trusted customers where it is not, keeping the platform PSD2-compliant without adding checkout friction. The results: a 1.22% increase in conversion rate, a 5x reduction in chargeback rate, and a 72% 3DS exemption recommendation rate, reducing friction for trusted customers without impacting authorisation rates.
“Our goal is to ensure travelers trust our platform and enjoy a seamless experience, end-to-end, while supply partners can grow their businesses on our platform. Forter takes the time to understand the business problems global marketplaces face every day.”
Gianmichele Zappia, Head of Fraud and Risk, GetYourGuide
Priceline’s results challenge the underlying assumption that fraud prevention and conversion are in tension. By moving fraud decisioning to pre-authorisation, implementing Smart 3DS, and sharing richer transaction context with issuer partners, Priceline improved on both dimensions simultaneously. Completion rate up 1%. Bank declines down 3.4%. Chargebacks down 25%. All at the same time.
“If you’re solely focused on preventing fraud without considering the impact on top-line conversion rate, you’re leaving significant value on the table.”
Marc Culver, VP Finance, Priceline
A global travel merchant was running 3DS on 100% of transactions under fraud pressure. By linking fraud management, 3DS recommendation, and 3DS execution through a single decisioning layer, 3DS challenges dropped from 100% to 7% of transactions. Completion rate improved by 7%.
A large luxury retailer had its fraud decisioning running post-bank authorisation. Issuers were treating the merchant’s traffic as higher-risk than it actually was. Moving the fraud decision upstream to pre-authorisation produced a 3.8% increase in completion rate and approximately €460,000 in yearly revenue uplift.
A European apparel merchant whose PSP was achieving only a 2.5% exemption rate moved to an intelligent exemption strategy and reached 93% exemption of PSD2-eligible traffic, with a 1.7% increase in completion rates.
The Authentication Optimisation Framework
Turning authentication from compliance into a performance discipline
The merchants reclaiming the most revenue from authentication share one characteristic: they measure it. Not as a subset of fraud metrics, not buried in general checkout analytics. As a distinct discipline with its own KPIs, its own benchmarks, and clear internal ownership.
The metrics that matter
Of transactions submitted to the issuer for authorisation, what % are approved. The traditional benchmark, but it can look healthy while customers drop off upstream, before authorisation is ever requested.
Successful transactions divided by all transaction attempts. The number that connects authentication directly to revenue, and the one you should be tracking.
Out of all your good transactions, what % you managed to successfully exempt from 3DS. Your most direct lever on the leak: every trusted customer you exempt never reaches a challenge they might have abandoned.
Of all 3DS challenges, what % succeed. Watch it by market and by issuer BIN; a sharp drop in any single one is the signal to investigate, not the blended average.
Of challenges initiated, what % fail on technical errors: timeouts, redirect failures, SDK issues. Track it separately from abandonment, because the fixes are different.
The authentication maturity model
Most European merchants today sit between Level 1 and Level 2, compliance mode or exemption aware, but not yet optimising. The organisations recovering the most revenue operate at Levels 4 and 5. The model reflects organisational maturity as well as technical capability.
Level 4 merchants are optimising the mechanics of authentication. Level 5 merchants have moved upstream: the question is not which authentication path to take, but whether this specific customer, given everything known about them, needs to be challenged at all.
Most merchants who think they are at Level 4 or 5 are operating at Level 2 or 3. The difference is whether your decisions adapt in real time to issuer behaviour, not just customer history. If they do not, you are not as far up the ladder as you think.
How this works in practice
Merchants do not need to become authentication experts. They set their risk tolerance (maximise revenue, manage chargeback liability, or balance both) and the decisioning layer adapts accordingly. The strategy adjusts dynamically to issuer behaviour, transaction context, and customer identity. What changes is not the merchant’s risk appetite. What changes is the precision with which that appetite is applied.
Take the Maturity Assessment
Use the Forter PSD2 Authentication Maturity Assessment to score your current level and calculate your estimated GMV recovery opportunity. It takes three minutes: forter.com/maturity-assessment
Looking Ahead to PSD3
What the next compliance cycle means for merchants who are already optimising
The final texts of PSD3 and the Payment Services Regulation were agreed in April 2026, with most rules expected to apply across 2027–2028. They will introduce clearer SCA requirements, stronger fraud liability rules, and new provisions for mobile wallets and agentic commerce.
For merchants still operating at Level 1 or Level 2, this means another compliance cycle, and another round of conversion losses while they catch up. For merchants who have already built authentication optimisation as a discipline, PSD3 is not a disruption. It is a further advantage. The infrastructure, the issuer relationships, the measurement capability: all of it transfers. The work described in this report is not just about recovering revenue lost to PSD2 friction. It is about building the competency that makes the next regulatory cycle easier to absorb than the last one.
Three steps to take to stay ahead of the curve
Take the PSD2 Authentication Maturity Assessment (3 minutes)
Score your current maturity level, see your estimated GMV recovery opportunity, and get specific guidance on how to advance.
Understand exactly where you are losing revenue
A maturity score tells you where you are. A friction audit tells you why. Request a Payment Friction Audit to get an analyst-led benchmarking of your authentication performance, your complete rate, your issuer-level gaps by market, and a concrete revenue recovery opportunity against real merchant data. This is where the numbers become actionable.
Build the capability for what comes next
PSD3 is coming. The merchants who will adapt fastest are the ones building authentication as a discipline now, not in response to the next compliance deadline. The Payment Optimisation Summer School is a six-week programme on payment optimisation in the era of identity-based decisioning, delivered in partnership with Forter. Register now to secure your place.
Payment Optimisation Summer School
Enter your email to secure your place on the six-week programme.
You’re registered! We’ll be in touch.
Something went wrong. Please try again.