A smarter payment authentication flow starts with the right acquirer & processor

A customer reaches the end of checkout. They enter their card details. The payment fails. They don't try again.

1 minutes read

For most merchants, this happens more often than it should, and the cause is rarely the customer. It's the payment authentication flow. 
Strong Customer Authentication (SCA) is a legal requirement across Europe. But how it's implemented makes all the difference between a seamless checkout and an abandoned cart. The merchant who gets this right has a significant advantage over one who doesn't, and the key is working with the right payment partner. 
We've already covered what a merchant acquirer is and how it works. This time, we go deeper into one of the most impactful things an acquirer and processor can do for your business: managing the payment authentication flow to recover declined transactions and protect your conversion rate. 

What does it mean to work with a Payment Service Provider (PSP) that is also an acquirer and processor? 

To understand why this matters, it helps to start with 3D Secure 2 (3DS2) — the current industry standard for authenticating online card payments, used by card schemes like Visa and Mastercard to verify the identity of cardholders during online transactions. 
3DS2 is more user-friendly than its predecessor — but it still introduces friction at checkout. Based on MultiSafepay platform data, the conversion rate for 3DS transactions currently stands at around 70%, meaning roughly one in three payments still fails at the authentication stage. 
The challenge for merchants is that not every transaction needs the same level of authentication. Some are low-risk. Some qualify for SCA exemptions. And routing every payment through the same flow — regardless of risk level — means unnecessarily high drop-off rates. 
This is where an acquirer & processor has a decisive advantage. As both the financial and technical counterpart in the payment chain, an acquirer & processor can assess each transaction in real time, determine the most appropriate authentication path, and act on it, all within milliseconds. 

 

At MultiSafepay, we do this through our risk assessment engine, which evaluates each transaction and routes it towards either an SCA authentication flow or an exemption flow, whichever has the highest probability of success with the least friction for the customer. 

Two paths are possible: 

  • 3D Secure frictionless flow: We provide the issuing bank with all relevant transaction data — such as order value and customer behavioral history — to help it determine whether a full 3DS challenge is needed or whether a frictionless authentication is possible. The richer the data we provide, the higher the chance of a frictionless outcome. 
  • Exemption flow: Some transactions qualify for SCA exemptions ecommerce rules allow, for example, low-value payments, low-risk transactions identified by our risk assessment engine, or payments initiated outside the EU. The issuer always has the final say on whether to accept an exemption, but an acquirer and processor is instrumental in making that case. 

A note on liability: when an SCA exemption applies and a transaction turns out to be fraudulent, liability for the chargeback shifts to the merchant. At MultiSafepay, our risk tools are designed to minimize that exposure — but no system provides total immunity. What we do provide is a robust additional layer of security, and the ability to use exemptions to their full potential while keeping risk under control. 

6 real transaction scenarios 

The best way to understand the role of an acquirer and processor in streamlining payment authentication is to see it in action. Here are six scenarios that cover the most common authentication paths, and what happens at each step. 

<h6>1. Frictionless 3DS</h6>

The ideal outcome: the customer pays, and nothing interrupts them. 

  1. The customer initiates the payment. We detect that the card is enrolled in 3D Secure. 
  2. We provide the issuer with all relevant transaction data and assess it as low risk. 
  3. The issuer agrees with our assessment and approves the transaction as frictionless 3DS. 
  4. The issuer sends the authorization response to us. 
  5. The transaction is approved and the merchant is notified immediately. The customer never sees a challenge screen. 

<h6>2. 3DS Authentication </h6>

When the issuer requires identity verification before authorizing the payment. 

  1. The customer initiates the payment. We detect 3DS enrollment and send transaction data to the issuer. 
  2. The issuer requests additional authentication to verify the cardholder's identity. 
  3. The customer is redirected to an authentication page and completes the verification — for example, via biometrics or a one-time code. 
  4. Once authenticated, the issuer moves the transaction to authorization and approves it. 
  5. We receive the confirmation and notify the merchant. The order is finalized. 

<h6>3. Recurring payments </h6>

For subscriptions and merchant-initiated transactions, 3DS is only needed once. 

  1. When a customer signs up for a recurring subscription, the first payment requires full 3DS authentication to verify their identity and register their card. 
  2. The customer completes authentication. Their card is registered as a card-on-file and tokenized for future use. 
  3. For all subsequent payments, we charge the card automatically using a recurring authorization request — no further 3DS challenge required. The issuer approves each renewal without interrupting the customer. 

<h6>4. Transaction Risk Analysis (TRA) exemption</h6>

When our risk assessment engine identifies a transaction as low risk and the issuer agrees. 

  1. The customer initiates the payment. Our fraud filter scans the transaction data in real time. 
  2. Based on multiple risk parameters, we determine the transaction qualifies for a TRA exemption and forward this assessment to the issuer. 
  3. The issuer agrees with our low-risk assessment and authorizes the transaction — no authentication required, no friction for the customer. 

<h6>5. Transaction Risk Analysis (TRA) soft-decline </h6>

When the issuer disagrees with our exemption request, and what happens next. 

  1. The customer initiates the payment. Our risk engine assesses the transaction as low risk and we request a TRA exemption. 
  2. The issuer disagrees and requests 3DS authentication instead — returning a soft decline. 
  3. Rather than letting the transaction fail, we immediately reroute it to the 3DS authentication flow. 
  4. The customer is prompted to verify their identity and completes the authentication. 
  5. The transaction is approved. The customer experiences minimal disruption — and the payment is recovered. 

This is one of the clearest cases of what acquirer and processor authentication means in practice. A provider without this capability would receive a declined transaction and stop there. We keep the payment moving. 

<h6>6. Low Value Payment (LVP) exemption </h6>

For smaller transactions, a faster path with built-in safeguards. 

  1. The customer initiates a payment below €30. Our fraud filter scans the transaction data. 
  2. We determine it qualifies for a Low Value Payment exemption and submit it to the issuer. 
  3. The issuer detects this is the fifth consecutive LVP exemption on this card — or that the cumulative amount since the last authentication has exceeded €100 — and returns a soft decline, requesting authentication. 
  4. We receive the soft decline and immediately reroute to 3DS authentication. 
  5. The customer verifies their identity. The payment is authorized and completed. 

LVP exemptions allow to speed up transactions for smaller amounts. However, every fifth transaction, or when the cumulative amount since the last authentication is more than €100, the issuer requires a 3DS authentication. Thanks to our status as an acquirer & processor, we can handle this return as a soft-decline, quickly moving to 3DS authentication, without the customer noticing it. 
Once again, the intervention of the acquirer & processor is aimed at reducing the impact on the consumer. 

What this means for your business 

Every declined transaction is a lost sale. Every unnecessary authentication challenge is a potential abandoned cart. And every layer between you and your payments is a layer where things can go wrong. 
Working with an acquirer and processor like MultiSafepay removes those layers. We sit directly between you and the card schemes — assessing risk, managing SCA exemptions, recovering soft declines, and handling compliance — so you don't have to. 

The result: 

  • Higher conversion rates: Fewer customers drop off at authentication 
  • Fewer failed payments: Soft declines are recovered, not lost 
  • Stronger fraud protection: Without adding unnecessary friction 
  • Full compliance with SCA requirements: Handled on your behalf 
  • A simpler operation: One partner, one integration, full visibility. 

Ready to see what this looks like for your business?
Find out how we can streamline your payment authentication flow and help you improve approval rates, reduce friction, and grow with confidence. 
 

Boost your credit card payments  

Frequently Asked Questions

<h6>What is a payment authentication flow?</h6>

The payment authentication flow is the process that verifies a cardholder's identity before a transaction is authorized. It determines whether a payment goes through a full 3D Secure challenge, a frictionless authentication, or qualifies for an SCA exemption — and it has a direct impact on your conversion rate. 

<h6>What role does an acquirer and processor play in the authentication flow?</h6>

An acquirer and processor sits directly between the merchant and the card schemes, assessing each transaction in real time and routing it towards the most appropriate authentication path. This means fewer unnecessary 3DS challenges, smarter use of SCA exemptions, and the ability to recover soft declines that a standard PSP would simply log as failed payments — all with a direct impact on your conversion rate.

<h6>What is the difference between a frictionless flow and a 3DS challenge?</h6>

In a frictionless flow, the issuer authenticates the transaction in the background without interrupting the customer. In a 3DS challenge, the customer is asked to actively verify their identity — for example, via a one-time code or biometric check. The goal of a well-optimized authentication flow is to maximize frictionless outcomes while maintaining security.

<h6>What is a soft decline in payments?</h6>

A soft decline occurs when an issuer rejects an exemption request and asks for 3DS authentication instead. Unlike a hard decline, a soft decline doesn't mean the transaction is lost — an acquirer and processor can intercept it and reroute it to the appropriate authentication flow, recovering the payment without the customer noticing.

<h6>What is a TRA exemption?</h6>

A Transaction Risk Analysis (TRA) exemption allows certain low-risk transactions to bypass the standard SCA authentication process. The exemption is assessed by the acquirer and processor based on multiple risk parameters and submitted to the issuer, who has the final say on whether to accept it.

<h6>What is a Low Value Payment exemption?</h6>

A Low Value Payment (LVP) exemption applies to transactions below €30. It allows eligible payments to skip SCA authentication, speeding up the checkout experience. However, every fifth consecutive LVP exemption — or when the cumulative amount since the last authentication exceeds €100 — the issuer will require a full 3DS authentication.

Want to stay updated on the latest news?