3-D Secure (3DS) has moved well beyond a simple fraud-prevention tool. For iGaming operators processing card payments in 2024, it sits at the intersection of regulatory obligation, risk management, and player experience, and getting it wrong carries consequences that range from chargeback liability to licence scrutiny.
What 3-D Secure Actually Does
3-D Secure is an authentication protocol developed by EMVCo that adds a verification step between a cardholder and their issuing bank at the point of a card transaction. Version 2 (3DS2), which has largely replaced the original protocol, exchanges rich contextual data, device fingerprints, behavioural signals, and transaction history, between the merchant, the card network, and the issuer. This allows the issuer to authenticate the cardholder silently in most cases, stepping up to a one-time password or biometric check only when the risk score warrants it.
For operators, this matters because 3DS2 is the technical mechanism through which Strong Customer Authentication (SCA), mandated under PSD2 in the European Economic Area and mirrored in UK FCA guidance, is implemented for card payments. Without it, operators accepting EEA-issued cards are not SCA-compliant, regardless of what their acquiring bank may have told them.
Regulatory Obligations Operators Cannot Ignore
PSD2 SCA applies to online card payments where both the issuer and the acquirer are located within the EEA. The obligation sits with the payment service provider, but regulators increasingly hold operators accountable for their payment stack choices. Key compliance points include:
- Liability shift: When a transaction is authenticated via 3DS2, chargeback liability shifts from the operator to the issuing bank in the event of fraud. Without 3DS2, the operator bears that cost.
- Exemptions must be managed deliberately: SCA permits certain exemptions, low-value transactions, merchant-initiated transactions, and transaction risk analysis (TRA) for qualifying acquirers. Operators should document which exemptions their payment service provider applies and why, because regulators can request this audit trail.
- Gambling-specific scrutiny: Gambling licence conditions in jurisdictions such as Malta, Gibraltar, and the UK require operators to demonstrate responsible payment practices. Persistent chargeback rates or fraud spikes can trigger compliance reviews, and the absence of 3DS2 is a visible contributing factor.
Practical Implementation Considerations
Choosing the Right Integration Model
Operators can implement 3DS2 through their payment gateway or via a dedicated 3DS server provider. Gateway-led integration is faster to deploy but gives the operator less visibility into authentication data. A standalone 3DS server provides granular access to authentication results, reason codes, and issuer responses, data that feeds directly into AML transaction monitoring and responsible gambling checks.
Balancing Friction Against Conversion
A common objection to 3DS2 is player drop-off at the authentication step. The counter-argument is that 3DS2 was specifically designed to reduce friction compared with its predecessor. When issuers receive sufficient context data, frictionless authentication rates above 80 percent are achievable for established players on known devices. Operators can improve these rates by ensuring their payment page collects and transmits all optional 3DS2 data fields, including billing address, device channel, and account age indicators.
Connecting 3DS2 Data to AML Workflows
Authentication outcomes are an underused signal in AML monitoring. A sudden increase in step-up challenges on a player account, or repeated authentication failures followed by a successful transaction, can indicate account takeover or card testing activity. Operators should configure their transaction monitoring rules to ingest 3DS2 response codes alongside payment data, not treat them as a separate stream.
Treating 3DS2 as a compliance checkbox rather than an operational data source is a missed opportunity. Authentication signals, when routed correctly, materially improve the precision of AML alerts and reduce false positives on legitimate high-value depositors.
What Operators Should Audit Right Now
If you have not reviewed your 3DS2 configuration recently, a focused audit should cover the following areas:
- Confirm your acquirer applies SCA exemptions in line with your documented risk appetite, not simply to maximise approval rates.
- Verify that authentication result codes are being stored at transaction level and are accessible for regulatory reporting.
- Check that your 3DS2 setup handles recurring transaction flows correctly, specifically the distinction between initial cardholder-initiated transactions and subsequent merchant-initiated transactions, which have different SCA requirements.
- Review your chargeback data by payment method to identify whether card fraud chargebacks are concentrated in transaction cohorts that bypassed 3DS2.
The OnlineShine Perspective
Operators in competitive markets often deprioritise payment compliance configuration because the consequences are diffuse and slow to materialise. Chargebacks accumulate, card scheme monitoring programmes flag the merchant ID, and regulators eventually ask questions. Addressing 3DS2 properly, both technically and as a documented compliance control, is one of the more straightforward ways to reduce tail risk in a payments operation.



