Home  /  News  /  Compliance & AML
Compliance & AMLAugust 13, 2024

3-D Secure Adoption in iGaming: A Compliance Perspective

How iGaming operators can use 3-D Secure to meet PSD2 SCA requirements, reduce chargebacks, and satisfy regulators in 2024.

3-D Secure Adoption in iGaming: A Compliance Perspective

3-D Secure (3DS) has moved well beyond a simple fraud-prevention tool. For iGaming operators processing card payments in 2024, it sits at the intersection of regulatory obligation, risk management, and player experience, and getting it wrong carries consequences that range from chargeback liability to licence scrutiny.

What 3-D Secure Actually Does

3-D Secure is an authentication protocol developed by EMVCo that adds a verification step between a cardholder and their issuing bank at the point of a card transaction. Version 2 (3DS2), which has largely replaced the original protocol, exchanges rich contextual data, device fingerprints, behavioural signals, and transaction history, between the merchant, the card network, and the issuer. This allows the issuer to authenticate the cardholder silently in most cases, stepping up to a one-time password or biometric check only when the risk score warrants it.

For operators, this matters because 3DS2 is the technical mechanism through which Strong Customer Authentication (SCA), mandated under PSD2 in the European Economic Area and mirrored in UK FCA guidance, is implemented for card payments. Without it, operators accepting EEA-issued cards are not SCA-compliant, regardless of what their acquiring bank may have told them.

Regulatory Obligations Operators Cannot Ignore

PSD2 SCA applies to online card payments where both the issuer and the acquirer are located within the EEA. The obligation sits with the payment service provider, but regulators increasingly hold operators accountable for their payment stack choices. Key compliance points include:

  • Liability shift: When a transaction is authenticated via 3DS2, chargeback liability shifts from the operator to the issuing bank in the event of fraud. Without 3DS2, the operator bears that cost.
  • Exemptions must be managed deliberately: SCA permits certain exemptions, low-value transactions, merchant-initiated transactions, and transaction risk analysis (TRA) for qualifying acquirers. Operators should document which exemptions their payment service provider applies and why, because regulators can request this audit trail.
  • Gambling-specific scrutiny: Gambling licence conditions in jurisdictions such as Malta, Gibraltar, and the UK require operators to demonstrate responsible payment practices. Persistent chargeback rates or fraud spikes can trigger compliance reviews, and the absence of 3DS2 is a visible contributing factor.

Practical Implementation Considerations

Choosing the Right Integration Model

Operators can implement 3DS2 through their payment gateway or via a dedicated 3DS server provider. Gateway-led integration is faster to deploy but gives the operator less visibility into authentication data. A standalone 3DS server provides granular access to authentication results, reason codes, and issuer responses, data that feeds directly into AML transaction monitoring and responsible gambling checks.

Balancing Friction Against Conversion

A common objection to 3DS2 is player drop-off at the authentication step. The counter-argument is that 3DS2 was specifically designed to reduce friction compared with its predecessor. When issuers receive sufficient context data, frictionless authentication rates above 80 percent are achievable for established players on known devices. Operators can improve these rates by ensuring their payment page collects and transmits all optional 3DS2 data fields, including billing address, device channel, and account age indicators.

Connecting 3DS2 Data to AML Workflows

Authentication outcomes are an underused signal in AML monitoring. A sudden increase in step-up challenges on a player account, or repeated authentication failures followed by a successful transaction, can indicate account takeover or card testing activity. Operators should configure their transaction monitoring rules to ingest 3DS2 response codes alongside payment data, not treat them as a separate stream.

Treating 3DS2 as a compliance checkbox rather than an operational data source is a missed opportunity. Authentication signals, when routed correctly, materially improve the precision of AML alerts and reduce false positives on legitimate high-value depositors.

What Operators Should Audit Right Now

If you have not reviewed your 3DS2 configuration recently, a focused audit should cover the following areas:

  • Confirm your acquirer applies SCA exemptions in line with your documented risk appetite, not simply to maximise approval rates.
  • Verify that authentication result codes are being stored at transaction level and are accessible for regulatory reporting.
  • Check that your 3DS2 setup handles recurring transaction flows correctly, specifically the distinction between initial cardholder-initiated transactions and subsequent merchant-initiated transactions, which have different SCA requirements.
  • Review your chargeback data by payment method to identify whether card fraud chargebacks are concentrated in transaction cohorts that bypassed 3DS2.

The OnlineShine Perspective

Operators in competitive markets often deprioritise payment compliance configuration because the consequences are diffuse and slow to materialise. Chargebacks accumulate, card scheme monitoring programmes flag the merchant ID, and regulators eventually ask questions. Addressing 3DS2 properly, both technically and as a documented compliance control, is one of the more straightforward ways to reduce tail risk in a payments operation.

FAQ

Frequently asked questions

Is 3-D Secure 2 mandatory for iGaming operators accepting card payments in the EEA?

Yes, for card payments where both the issuing bank and the acquiring bank are located within the European Economic Area, PSD2 requires Strong Customer Authentication, which is technically implemented through 3DS2. Operators that process EEA-issued card deposits without SCA are non-compliant unless a documented exemption applies. The liability for fraudulent chargebacks also remains with the operator when 3DS2 is not used.

What SCA exemptions are available to iGaming operators and how should they be managed?

PSD2 SCA exemptions relevant to iGaming include low-value transactions below 30 euros, merchant-initiated transactions for recurring billing arrangements, and transaction risk analysis exemptions available to acquirers with sufficiently low fraud rates. Operators should obtain written confirmation from their payment service provider of which exemptions are being applied, under what conditions, and how those decisions are logged, because regulators and licence bodies can request this documentation.

How does 3DS2 authentication data support AML compliance in online casinos?

3DS2 generates authentication outcome codes and metadata for every card transaction, including whether the transaction passed frictionless authentication or required a step-up challenge. When these signals are fed into AML transaction monitoring systems, they help identify patterns consistent with account takeover, card testing, or identity fraud. For example, repeated authentication failures followed by a successful deposit, or sudden step-up challenges on a previously frictionless account, are behavioural anomalies that warrant review.

Can requiring 3-D Secure significantly harm player conversion rates in iGaming?

3DS2 is designed to minimise friction compared with the original 3DS protocol by using passive data exchange to authenticate most transactions without player interaction. Operators that supply all available optional data fields to the 3DS2 server, such as device fingerprint, billing address, and account history, typically achieve frictionless authentication rates above 80 percent for returning players. Conversion impact is most pronounced when operators rely on gateway defaults without optimising the data sent to issuers.

Keep reading

Related articles

Show us one brand.
We will find the leaks.

Book a 30-minute teardown. We walk through one of your brands and show you exactly where revenue, retention or compliance is slipping, no obligation.