Home  /  News  /  Payments & Risk
Payments & RiskSeptember 22, 2024

3-D Secure in iGaming: What Regulators and Banks Expect

Practical guide for iGaming operators on 3-D Secure adoption, covering regulator requirements, banking partner expectations, and implementation priorities.

3-D Secure in iGaming: What Regulators and Banks Expect

3-D Secure has moved from an optional friction-reducer to a baseline expectation across regulated iGaming markets. Operators who treat it as a checkbox risk losing acquiring relationships and facing regulatory scrutiny, while those who implement it thoughtfully gain measurable reductions in chargebacks and stronger positions with banking partners.

Why 3-D Secure Is No Longer Optional

The revised Payment Services Directive (PSD2) mandated Strong Customer Authentication (SCA) across the European Economic Area, and 3-D Secure 2 (3DS2) is the primary mechanism that card schemes and acquirers use to satisfy that requirement. For iGaming operators, the stakes are higher than in most verticals. Banking partners and payment facilitators routinely audit SCA coverage rates, and low adoption figures flag an operator as a chargeback and fraud risk. Acquirers serving the gambling vertical are already operating on thin margins and restricted network agreements; any preventable fraud exposure is grounds for rate increases or termination of the merchant relationship.

Regulators in markets such as the United Kingdom, Malta, Sweden, and the Netherlands have signalled that payment integrity forms part of the broader responsible gambling and anti-money laundering framework. An operator that cannot demonstrate robust authentication controls may find that issue raised during licence renewal reviews, even if the direct trigger was a consumer protection complaint rather than a payment audit.

What Banking Partners Look for in Practice

Acquirers and sponsor banks assess 3DS2 implementations across several dimensions that go beyond simple on/off activation:

  • Authentication coverage rate: The percentage of card transactions routed through 3DS2 rather than exemptions. Partners typically want to see coverage above 80 percent for non-exempted transaction types.
  • Frictionless versus challenge ratio: A mature implementation uses the richer data signals in 3DS2 to qualify the majority of low-risk transactions for frictionless approval, reserving the challenge flow for genuinely anomalous activity. An operator running full challenge rates above 30 percent suggests poor data sharing with the directory server.
  • Exemption strategy documentation: Banks expect operators to articulate which SCA exemptions they apply, such as low-value, trusted beneficiary, or transaction risk analysis, and to demonstrate that those choices are supported by actual fraud data rather than convenience.
  • Chargeback and dispute ratios: 3DS2 shifts liability to the issuer for authenticated transactions. Operators whose dispute ratios remain elevated despite claimed 3DS2 deployment raise immediate questions about implementation quality.

Regulator Expectations Beyond the Technical Layer

Compliance officers should note that regulators increasingly view payment authentication as part of the identity and verification fabric, not just a fraud tool. The UK Gambling Commission has reinforced the principle that operators must know who is transacting, not merely verify a card. That means 3DS2 data should feed into player risk profiles and be cross-referenced against KYC records. A transaction authenticated under a device fingerprint that does not match the registered account holder's usual environment should trigger a review rather than silent approval.

In the Netherlands, the Kansspelautoriteit has emphasised source-of-funds controls that touch deposit authentication. An operator collecting rich 3DS2 device and behavioural data but siloing it away from AML workflows is missing a significant compliance opportunity.

Practical Implementation Priorities for Operators

The following steps represent the minimum viable posture that banking partners and regulators expect to see documented:

  • Configure your payment gateway to pass all available device, browser, and behavioural data elements in the 3DS2 authentication request. Incomplete data fields are the single most common cause of unnecessary challenge flows and abandonment.
  • Establish a documented exemption policy that is reviewed quarterly and calibrated against your actual fraud and chargeback data.
  • Integrate 3DS2 authentication outcomes into your player risk engine so that failed or degraded authentications generate alerts rather than silent declines.
  • Conduct at minimum a bi-annual reconciliation between 3DS2 coverage reports from your acquirer and your internal transaction logs to identify gaps.
  • Retain authentication records in a format that can be produced quickly during a regulatory audit or a chargeback representment process.

The Operator Advantage of Getting This Right

Operators who treat 3-D Secure as infrastructure rather than compliance overhead consistently report lower interchange costs, better acquiring terms, and faster resolution of chargeback disputes.

Banking partners reward operators whose data shows that 3DS2 is actively reducing fraud rather than merely existing on paper. That translates into negotiating leverage on processing fees and, in some cases, access to acquiring relationships in markets where marginal operators simply cannot get a merchant account. For operators building towards new licence applications or jurisdiction expansions, a clean 3DS2 track record is a concrete asset to present to prospective banking partners before the first conversation even begins.

FAQ

Frequently asked questions

Is 3-D Secure 2 mandatory for iGaming operators in Europe?

Under PSD2, Strong Customer Authentication is legally required for electronic payments in the European Economic Area, and 3-D Secure 2 is the standard mechanism card schemes use to satisfy that requirement. iGaming operators accepting card deposits from EEA cardholders must apply SCA unless a valid exemption applies and is properly documented. Failure to comply can result in declined transactions, acquirer penalties, and regulatory findings during licence reviews.

What chargeback benefit does 3-D Secure 2 provide for operators?

When a transaction is successfully authenticated through 3-D Secure 2, liability for fraudulent chargebacks shifts from the merchant to the card issuer. This means a player cannot dispute a charge as unauthorised if they completed a 3DS2 authentication step, which significantly reduces the operator's chargeback exposure. Operators must maintain authentication records to exercise this liability shift during representment proceedings.

What do acquirers mean by a frictionless authentication rate?

Frictionless authentication occurs when the 3DS2 directory server has enough device, behavioural, and account data to approve a transaction as low-risk without presenting a challenge to the cardholder. Acquirers measure the ratio of frictionless to challenged authentications as an indicator of implementation quality. A low frictionless rate suggests the operator is not passing sufficient data fields, which increases customer abandonment and signals weak fraud controls to the banking partner.

How should 3-D Secure data be used in AML compliance workflows?

3-D Secure 2 captures device fingerprints, IP addresses, geolocation signals, and behavioural patterns that are directly relevant to AML risk assessment. Operators should feed authentication outcomes and anomalies into their player risk profiles and cross-reference them with KYC records. A transaction authenticated from an unrecognised device or location inconsistent with a player's history should trigger an enhanced due diligence review rather than be processed silently, aligning authentication controls with broader source-of-funds obligations.

Keep reading

Related articles

Show us one brand.
We will find the leaks.

Book a 30-minute teardown. We walk through one of your brands and show you exactly where revenue, retention or compliance is slipping, no obligation.