top of page

The Frictionless Paradox: 3DS Success Is Rising. Smooth Checkouts Aren't.

Sep 24
9 min read

Meta title: Authentication and Payment Success Rate: The Frictionless Paradox | Quantum Payments Meta description: 3DS success rates are rising but frictionless checkouts are falling in 28 of 37 countries. Learn how authentication routing, exemption strategy and richer issuer data lift payment success rate. Suggested slug:frictionless-paradox-authentication-payment-success-rate Suggested URL:https://www.quantumpayments.io/post/frictionless-paradox-authentication-payment-success-rate Primary keyword: payment success rate Secondary keywords: AI payment routing,payment authentication,3D Secure,authentication orchestration,frictionless authentication,AI payments,payments foundation model,agentic payments,SCA exemptions,issuer approval

Executive summary

3DS is working better in one sense and creating more friction in another.

Ravelin’s Global Payments Report 2026 shows that overall 3DS success rates have increased slightly,driven partly by a 47% improvement in the US average. Yet frictionless authentication has declined globally,in the US and in Europe. Of the 37 countries tracked,28 recorded declining or plateauing frictionless rates.

The problem is not that merchants need to choose between stronger fraud controls and better conversion. It is that authentication is still too often treated as a compliance checkpoint rather than a performance layer.

Adyen’s 22 September 2026 upgrade to Authenticate makes the strategic shift clear. Its machine-learning models decide whether authentication is needed,which method is most likely to succeed and which transaction data should be sent to the issuer. That turns authentication into a conversion channel and a routing decision.

For merchants,the next priority is to measure authentication as part of the payment success rate: by issuer,country,device,channel,payment method and shopper context.

The data exposes a frictionless paradox

Ravelin’s results are easy to misread. A higher 3DS success rate sounds like a smoother customer journey. It is not necessarily so.

The report found that challenge success rates remained broadly stable. In other words,when shoppers were asked to complete a challenge,they succeeded at similar rates to the previous year. The more important movement was elsewhere: fewer transactions were being authenticated without a challenge.

The pattern appeared across global,US and European results. Frictionless rates declined in 76% of countries,with 28 of 37 markets either falling or plateauing. Country performance also varies sharply. The UK recorded a 95% average 3DS success rate,compared with 87% in Australia,88% in the US,82% in Canada,72% in India and 36% in Brazil.

This is a measurement and data-quality problem before it is a fraud-model failure.

If challenge success is stable and overall 3DS success is rising,falling frictionless performance suggests that issuers are demanding stronger evidence before allowing a transaction to pass silently. Merchants may be sending incomplete,poorly structured or insufficiently relevant context. They may also be requesting exemptions that do not fit the issuer’s risk tolerance.

That is consistent with the report’s finding that 78% of merchants now use SCA exemptions,up year on year,while issuers are declining weak exemption requests more often.

Abstract neon waveforms contrasting rising authentication success and falling frictionless checkout

Adyen’s upgrade makes authentication a conversion decision

Adyen’s upgraded Authenticate product,part of its Uplift optimisation suite,responds to this gap with three machine-learning decisions on every transaction:

  1. Whether authentication is needed.

  2. Which authentication method is most likely to perform well.

  3. Which data should be shared to maximise issuer approval.

For 3DS,Authenticate evaluates more than 150 data fields. It can remove the authentication step where appropriate,complete it silently or trigger a challenge when additional customer verification is necessary.

The important architectural advantage is that Adyen operates as both the authentication provider and acquirer. Its models can learn from final authorisation outcomes rather than authentication results alone. Adyen says its models are trained on trillions of interactions and that,for a retail merchant on the platform,there is more than a 90% chance it has seen the shopper before.

That downstream visibility matters. A frictionless authentication result is not the same as an approved payment. The real commercial outcome is whether the transaction is authorised,settled and completed without fraud or unacceptable cost.

Early results reported by Adyen include a 12% increase in payment conversion on eligible traffic for Just Eat Takeaway.com and an 11% relative increase for Too Good To Go. Authenticate is live globally for 3DS and issuer optimisation,and supports Google Secure Payment Authentication,Mastercard Payment Passkeys and Visa Payment Passkeys. Live transactions using newer methods are already enabled in the UK,with broader expansion planned through 2027.

As Renan Renner,Group Product Manager for Adyen Uplift,put it: “Authentication is evolving from a regulatory checkpoint into a trust layer for digital commerce.”

That is the right framing. The future is not one authentication protocol. It is context-aware selection between 3DS,data-only flows,passkeys and other methods.

Why requesting the biggest exemption is not a strategy

Under SCA,the main exemption mechanisms include:

  1. Low-value payments under EUR 30,subject to a cumulative EUR 100 or five consecutive transactions.

  2. Transaction Risk Analysis for payments up to EUR 100,EUR 250 or EUR 500 where the acquirer’s fraud rate remains below 0.13%,0.06% or 0.01% respectively.

  3. A trusted beneficiary arrangement where the cardholder has approved a merchant with the issuing bank.

The issuing bank always makes the final decision. A merchant or acquirer can request an exemption,but the issuer may reject it and require step-up authentication.

That makes a static “always request the highest available exemption” policy suboptimal. Issuers do not share identical risk tolerances. A strategy that performs well for one issuer,country or customer segment can underperform badly for another.

The better approach is adaptive. Authentication decisions should consider issuer,country,currency,device,shopper history,channel,payment method,transaction value,acceptance cost and the likely impact of a challenge on conversion.

This is also why authentication and routing decisions are converging into one decision layer. The system should not first choose an acquirer,then separately decide whether to authenticate. It should evaluate both decisions together.

For merchants building this capability,the lesson from the $231 billion approval problem is relevant: fraud prevention and revenue optimisation cannot be managed as separate systems when every false decline has a commercial cost.

The operating layer merchants need

Authentication-linked declines are often operational rather than purely financial-crime decisions. Common triggers include delayed SMS one-time passwords during cross-border or roaming transactions,outdated banking apps,unregistered devices,unsupported issuer protocols,customer confusion,session timeouts and soft declines that are not retried with a 3DS challenge.

A fully authenticated 3DS payment generally shifts liability for unauthorised fraud chargebacks from the merchant to the card issuer. It does not cover every dispute type,but it remains an important protection. The objective is therefore not to remove authentication. It is to place the right authentication experience in the right transaction.

EMV 3DS 2.3 introduces additional fields that can provide issuers with more context. Adoption remains uneven,so merchants should prepare their data and integration layers now rather than waiting for a universal transition.

The same trust layer will become more important as agentic commerce grows. Agent payment rails are already live across more than 30 European banks under the PSD3/PSR framework. In July 2026,an ING,Worldline and Visa transaction in Germany used Visa Payment Passkeys. Mastercard has enabled more than 1,000 merchants to accept passkey payments,and Visa is expanding payment passkeys across Asia Pacific and Europe.

An authorised AI agent should not look like an unauthorised bot. Payment passkeys,data-only flows and rich transaction context will help distinguish legitimate automated purchase intent from malicious automation. Our analysis of agentic payment liability in Australia and the payment stack required for AI agents explores why this trust distinction is becoming foundational.

PSD3 and the Payment Services Regulation are expected to retain SCA and the 3DS liability mechanism,with refinements to exemptions. Authentication strategy is therefore a multi-year operating commitment,not a 2026 compliance project.

A practical authentication checklist

  1. Make frictionless rate,challenge success rate and exemption approval rate board-visible metrics.

  2. Segment authentication and decline performance by issuer,country,channel,device and payment method.

  3. Quantify the revenue attached to challenged,failed and abandoned checkouts.

  4. Review exemption strategy by issuer instead of applying one static rule set.

  5. Enrich authorisation data with device,behavioural and customer-history signals,and prepare for EMV 3DS 2.3 fields.

  6. Retry soft declines with a step-up challenge instead of showing the shopper a generic error.

  7. Offer an alternative payment rail at the point of failure where it is faster or cheaper.

  8. Align authentication and payment routing decisions in one decision layer.

  9. Treat agent-initiated traffic as a legitimate customer class with passkey-based verification.

  10. Review contracts with authentication providers and acquirers covering data sharing,model feedback and access to final authorisation outcomes.

Real-time account-to-account payments already rank among the top three payment types in Germany and the Netherlands. That matters because consumers moving to bank-based rails will change where authentication effort sits. The winning checkout will not simply ask whether a transaction is secure. It will decide where trust can be established with the least commercial friction.

Quantum Payments’ unified payments platform is designed around this broader operating model: flexible payment orchestration,online and in-person acceptance,embedded payments and business intelligence working together rather than as disconnected layers.

Authentication is no longer a gate at the edge of the payment stack. It is part of the stack’s decision-making core.

Frequently asked questions

Why are 3DS success rates rising while frictionless authentication is falling?

Overall 3DS success can rise because challenged transactions are completing more successfully,while fewer transactions qualify for or receive frictionless treatment. Ravelin’s data indicates that issuer risk assessments are becoming stricter and that merchants need to provide richer,more relevant transaction data.

Does frictionless authentication mean no authentication occurred?

No. A frictionless 3DS flow authenticates the transaction in the background without requiring the shopper to complete an active challenge. It still depends on issuer risk assessment and the quality of data provided.

Who decides whether an SCA exemption is accepted?

The issuing bank makes the final decision. A merchant or acquirer can request an exemption,but the issuer can reject it and require step-up authentication.

Does 3DS protect merchants from all chargebacks?

No. When a payment is fully authenticated with 3DS,liability for unauthorised fraud chargebacks generally shifts to the card issuer. Other dispute categories may remain the merchant’s responsibility.

What should merchants measure to improve payment success rate?

At minimum,track frictionless rate,challenge success rate,exemption approval rate,authentication-attributable declines and payment success rate by issuer and market. Add device,channel,payment method and shopper-history segmentation to identify operational failure points.

Why do agentic payments increase the importance of authentication?

An authorised AI agent needs to be distinguished from malicious bot traffic. Passkeys,delegated trust and rich transaction context can verify that an automated payment falls within a customer’s approved intent.

Authoritative sources

Daily handover to Sonny

Blog title: The Frictionless Paradox: 3DS Success Is Rising. Smooth Checkouts Aren't.

Wix slug:frictionless-paradox-authentication-payment-success-rate

Publishing instruction: Schedule in Wix for Thursday 24 September 2026 at 7:30am AEST. Confirm the scheduled post and assets no later than 6:30am AEST,at least one hour before go-live.

Primary angle: Authentication has become a conversion and routing decision. Ravelin’s data shows 3DS success rates rising while frictionless rates decline in 28 of 37 countries. Adyen’s Authenticate upgrade shows why merchants need adaptive authentication orchestration,richer issuer data and final authorisation feedback.

Relevant tags: 3D Secure,authentication orchestration,payment success rate,AI payment routing,SCA exemptions,issuer approval,frictionless authentication,authorisation,agentic payments,payment passkeys,EMV 3DS 2.3

Recommended organisation tags: Quantum Payments,Adyen,Ravelin,European Payments Initiative,Visa,Mastercard,Google Payments

LinkedIn post 1, 8:08am AEST

Angle: Data-led strategic hook. The frictionless paradox and the shift from authentication checkpoint to conversion channel.

Exact copy:

3DS success rates are rising. Smooth checkouts are not.

Ravelin’s Global Payments Report 2026 found that:

  1. Average 3DS success improved,driven partly by a 47% increase in the US.

  2. Frictionless authentication declined globally,in the US and in Europe.

  3. 28 of 37 tracked countries recorded declining or plateauing frictionless rates.

  4. 78% of merchants now use SCA exemptions,while issuers are denying weak requests more often.

The signal is clear: authentication is no longer a compliance checkpoint sitting at the edge of checkout.

It is a conversion channel and a routing decision.

Adyen’s upgraded Authenticate product makes three machine-learning decisions for each transaction:

  1. Whether authentication is needed.

  2. Which method is most likely to succeed.

  3. Which data should be shared with the issuer.

The strategic advantage comes from connecting those decisions to final authorisation outcomes,not measuring authentication in isolation.

Merchants should be tracking frictionless rate,challenge success rate,exemption approval rate,authentication-attributable declines and payment success rate by issuer and market.

Relevant tags: @Quantum Payments @Adyen @Ravelin @Visa @Mastercard

First comment:

The next generation of authentication will not be defined by choosing one protocol. It will be defined by choosing the right trust mechanism for each transaction,including 3DS,data-only flows and payment passkeys.

LinkedIn post 2, 3:23pm AEST

Angle: Merchant-operational checklist. Practical actions and metrics for improving payment success rate.

Exact copy:

Is your authentication programme improving payment success rate,or only proving compliance?

A merchant operating checklist:

  1. Put frictionless rate,challenge success rate and exemption approval rate on the board dashboard.

  2. Segment declines by issuer,country,channel,device and payment method.

  3. Quantify the revenue attached to challenged and abandoned checkouts.

  4. Review exemption rules per issuer instead of requesting the highest available exemption every time.

  5. Enrich authorisation data with device,behavioural and customer-history signals.

  6. Prepare your integration for EMV 3DS 2.3 data fields.

  7. Retry soft declines with a step-up challenge instead of displaying a generic checkout error.

  8. Offer an alternative payment rail at the point of failure.

  9. Align authentication and routing decisions in one decision layer.

  10. Treat agent-initiated traffic as a legitimate class and verify it with passkey-based trust.

  11. Confirm that your authentication provider and acquirer share final authorisation outcomes for model feedback.

The operational goal is not “more 3DS” or “less 3DS”.

It is the highest-confidence payment path for each shopper,issuer and market.

Relevant tags: @Quantum Payments @Adyen @Ravelin @Visa @Mastercard

First comment:

A useful starting point is to build one weekly view combining authentication outcomes,authorisation results and abandonment. If those metrics live in separate systems,the revenue impact of friction will remain invisible.

 
 
bottom of page