Firms get what they measure, and for years, payment security technology has been measured by how much fraud it stops.
Untold billions of dollars have been invested in risk models, authentication technologies and compliance frameworks designed to stop fraudsters before they can exploit the financial system. But a growing number of payments executives are beginning to focus on a different question: How much legitimate revenue is being blocked in the process?
“The amount of transactions that are falsely declined vastly outweighs the actual fraud,” Dewald Nolte, co-founder and chief strategy officer at Entersekt, told PYMNTS. “Ironically, we’re declining a lot more good transactions than we’re actually stopping fraud.”
Fraud losses are visible, measurable and routinely reported. False-decline costs, by contrast, are distributed across customer experience, merchant performance and long-term revenue outcomes. As a result, they often remain hidden within broader business metrics.
But as margins tighten across financial services and competition for customer loyalty intensifies, institutions are searching for ways to improve approval rates without increasing fraud exposure. Richer transaction intelligence offers one potential path forward, and this reality is already positioning the next evolution of 3D Secure, EMV 3DS 2.x, as a mechanism for improving authorization rates, reducing false declines and strengthening customer relationships.
“If you look at the enhancements that version two of the protocol has brought into play, 3D Secure becomes almost like a high-speed data pipeline,” Nolte said.
The Data Pipeline Behind 3D Secure’s New Authorization Optimization Engine
The future of 3D Secure may ultimately be defined not by the fraud it prevents, but by the legitimate revenue it helps recover. While issuers continue investing heavily in fraud prevention, overly cautious risk models can reject legitimate customers, creating a hidden form of revenue leakage that receives far less attention than fraud losses.
“The industry still sees [3D Secure] as a lock on the door,” Nolte said, emphasizing the need to move beyond prior perceptions of both SD Secure and fraud defense as a practice to track other relevant metrics such as authorization uplift and false-decline reduction.
“Let’s see whether we are measuring how many false declines that we typically would’ve seen are now removed,” he said. “Let’s measure the authorization uplift.”
A key aspect of Nolte’s argument is that issuers should stop treating authentication and authorization as isolated processes. Authentication occurs before a transaction enters the highly constrained authorization environment, giving issuers time to gather context, analyze risk and, when necessary, challenge the cardholder. Because the transaction has not yet entered the authorization rail, issuers can perform more sophisticated analysis without facing authorization-time constraints.
“The industry has split the authentication and authorization into two parts,” Nolte said. “We are doing all of the heavy lifting before we actually submit the transaction for authorization.”
By bringing the two processes together, once authentication is complete, the transaction arrives with cryptographic proof that the cardholder has already been validated. The downstream effect is a faster, more confident authorization process that requires fewer conservative declines.
“There’s a cryptogram, there’s proof of the fact that you’ve already authenticated this transaction,” Nolte said, noting that this approach rests on one of the most important advances introduced by EMV 3DS 2.x: the ability to transmit extensive contextual information before an authorization decision is made.
“When you’re declining good transactions, you break the trust with your customer,” he added. “You lose the lifetime value of them. You lose your top-of-wallet status when you falsely decline a customer.”
Viewed through that lens, authorization optimization becomes a growth initiative rather than merely a fraud-management exercise.
Firms Need Better Data to Build Trust Through Behavioral Context
Rather than simply verifying identity, EMV 3DS 2.x enables the exchange of more than 150 data elements before an authorization decision is made. By continuously observing device signals, merchant relationships, geographic patterns and purchasing behavior, issuers can better distinguish normal customer activity from genuine anomalies.
Nolte compared the difference to moving from “looking at a transaction through a keyhole” to seeing “the full picture.”
He illustrated the concept with a hypothetical example: one cardholder makes a small purchase at a craft store, while another makes a larger transaction at an online gambling merchant. Traditional risk scoring might automatically favor the craft-store transaction and scrutinize the gambling transaction. But behavioral context tells a different story.
“Online gambling is very normal for this customer. There’s nothing to see here,” Nolte said, noting that the seemingly harmless craft-store purchase may represent an unusual deviation from the customer’s established spending patterns.
“The goal that we want to do here is to weaponize trust,” he added.
The objective is not simply to identify risky merchants but to understand customer-specific behavior well enough to approve legitimate transactions confidently.
Watch the full PYMNTS exclusive interview with Entersekt Co-Founder and Chief Strategy Officer Dewald Nolte to hear more about:
- Why 3D Secure should be viewed as an authorization optimization engine, not just a fraud tool.
- How reducing false declines can unlock greater value than fraud prevention alone.
- How behavioral intelligence and trust-based decisioning can improve both customer experience and performance.