US Issuers Treat 3DS Requests Differently Than Their European Counterparts

Strong Customer Authentication (SCA) has been mandatory for European electronic transactions for four years, driving widespread adoption of 3D Secure (3DS) authentication for online card payments. The regulation has proven effective, preventing approximately €900 million in fraud annually across Europe. However, as Stripe's analysis of US transactions reveals, the authentication strategies that work in regulated markets do not simply translate to other regions.

When US businesses on Stripe began requesting 3DS authentication—despite no SCA requirement—the outcomes diverged sharply from European patterns. US issuers appeared to interpret the 3DS request itself as a signal of elevated fraud risk, often declining such transactions outright rather than guiding customers through an unfamiliar two-factor authentication challenge.

Frictionless Flows Dominate US Issuer Behavior

Among the top 10 US banks analyzed, frictionless authentication rates were strikingly high. One major bank sent 100% of transactions through the frictionless pathway, never challenging a transaction with two-factor authentication. This contrasts with EU and UK issuers, where Stripe data shows only a minority of SCA-eligible transactions that don't qualify for exemptions pass through frictionless authentication.

The frictionless pathway bypasses the second authentication layer entirely, making it a potential fraud enabler. European banks reserve this route for transactions they are confident are legitimate. In the US, however, issuers deploy it widely—even for higher-risk transactions.

Requesting 3DS Reduced Authorization Rates

This data represents the authorization rates for a small group of businesses over a limited time frame and is not reflective of, or a guarantee of, any future performance or Stripe’s overall performance.

Stripe's data indicates US issuers may view a 3DS request as a fraud indicator, reasoning that businesses request authentication because they already know transactions carry elevated risk and hope to shift liability to the issuer. A controlled experiment supports this theory: businesses that added 3DS to their US entities saw their average authorization rate drop from 87% to 82% on the frictionless pathway, while transactions that successfully completed a two-factor challenge maintained the 87% rate.

The decline occurred despite all other customer and card factors remaining constant, suggesting the mere act of requesting authentication made issuers more cautious. They frequently declined what they perceived as riskier transactions rather than challenging them.

Inverse Relationship Between Authentication and Authorization in the US

Expanding beyond the two-week experiment, Stripe examined the broader correlation between authentication and authorization outcomes. In the EU and UK, authentication success rates and authorization rates move in tandem: higher authentication success—whether through challenges or frictionless flows—correlates with higher authorization. Their risk models have adapted to regulatory requirements, granting frictionless pathways primarily to low-risk transactions.

The US shows the opposite pattern. As authentication rates climbed, particularly via frictionless pathways, authorization rates declined. This inverse relationship again points to US issuers declining riskier transactions without subjecting them to a challenge.

Authentication Strategies Require Market-Specific Tuning

These findings underscore that fraud prevention approaches cannot be lifted and shifted between markets. Businesses must calibrate their authentication strategies not only to their products and customer base but also to the regulatory and issuer landscape of each region.

For EU and UK operations, Stripe's SCA optimization engine and delegated authentication handle regulatory compliance while minimizing checkout friction, using built-in machine learning adaptations that request authentication only when necessary. For US businesses, Stripe continues working with ecosystem partners to evolve issuer perspectives on authentication, including testing new machine learning models that optimize over 600 factors per transaction—3DS usage among them—and collaborating with card networks on potential future passkey-based biometric authentication expansions.

The broader lesson: digital wallets and other payment methods that offer built-in security with a streamlined user experience may serve US businesses better than attempting to replicate European 3DS patterns. There is no universal authentication formula, only strategies fine-tuned to their environment.