SCA Is a Given. Cross-Border Fraud Is Still Adapting.
Aug 11, 2026
•
6 min read

Strong Customer Authentication has become an established part of the European payment environment. Now, Europe's developing regulatory framework reflects a wider shift: authentication remains important, but it is not expected to address every form of payment fraud on its own.
The EU's proposed Payment Services Regulation (PSR) and Third Payment Services Directive (PSD3) moved forward in 2026. The PSR is intended to create more consistent rules governing how payment services are provided across EU Member States, while PSD3 focuses primarily on the authorisation and supervision of payment institutions. The final compromise texts were confirmed at Council level in April, followed by approval by the European Parliament's Economic and Monetary Affairs Committee (ECON) in May. Formal adoption and publication are still required before the legislation takes effect.
The agreed texts extend beyond authentication. They include measures relating to fraud prevention, fraud-related information sharing, transparency and consumer protection. While the precise obligations and implementation timetable will depend on the final legislation, merchants should already be aware of the areas the proposed framework is expected to address.
The real question is no longer simply whether SCA is being applied. It's how authentication fits within a wider approach to payment risk, customer experience and commercial performance.
SCA remains important, but it is only one layer
The most recent joint fraud report from the European Banking Authority and European Central Bank found that transactions authenticated using SCA were generally less susceptible to fraud than transactions without it, particularly for card payments.
The report, published in December 2025 using consolidated industry data through 2024, also warned that fraud methods were adapting. The EBA and ECB specifically identified growth in fraud involving the manipulation of payers.
In these cases, a customer may be deceived into initiating or approving a payment. Authentication may confirm that the legitimate customer completed the required steps, but it cannot by itself determine whether the customer was acting under false pretences created by a fraudster.
Why the regulatory conversation is becoming broader
The proposed rules also address fraud methods such as spoofing, where a fraudster impersonates a trusted organisation or payment provider. These developments recognise that payment fraud may involve technology, behaviour and communication across several participants in the payment journey.
For merchants, this broader regulatory direction matters even where a particular obligation falls primarily on a payment service provider. Changes to fraud controls, authentication, information requirements and liability can affect payment journeys and the way incidents are investigated.
As the legislation is not yet in force, its provisions should not be treated as current legal requirements.
Cross-border growth can change the transaction context
When a merchant enters a new market, its payment profile may change. Transactions may involve different issuers, customer behaviours, currencies and authentication outcomes. Patterns considered typical in one market may not be typical in another.
The appropriate response will depend on the merchant's business model, products, customer base and risk profile. A fixed set of rules may not respond equally well to every market or transaction type.
Merchants may therefore need to review payment and risk performance as their geographic mix develops. Relevant indicators could include authentication outcomes, suspected fraud, chargebacks, declines and completed transactions, assessed in the context of the individual business.
The objective is not to remove friction in every case or approve the maximum possible number of transactions. Nor is it necessarily to apply the most restrictive controls to every payment. It is to make informed decisions about where authentication and other controls may be appropriate.
Fraud and payment performance should be considered together
Risk decisions can have commercial consequences. A transaction blocked because it appears suspicious may represent prevented fraud, but it may also be a legitimate customer whose payment has been declined. Looking only at one metric can provide an incomplete view.
This is why merchants may benefit from considering fraud, chargebacks, authentication and payment performance together.
It can help them ask more useful questions, such as:
- Are particular markets, transaction types or customer journeys producing different outcomes?
- How is 3DS being applied within the payment flow?
- Can risk controls respond to transaction context?
- How are suspicious patterns investigated?
- Can payment performance be reviewed by market, currency or other relevant factors?
- What happens when an established pattern changes?
The answers will depend on the technology, data, processes and responsibilities across the merchant and its payment partners.
The payment provider's role extends beyond enabling SCA
For merchants, compliance with applicable authentication requirements is essential. The choice of payment provider may also affect how authentication interacts with the wider payment operation.
When assessing a payment provider's fraud and risk capabilities, areas to examine should include 3DS capabilities, fraud and risk controls, tokenisation, transaction routing, monitoring and the support available when an issue needs investigation. These elements perform different functions, but they may need to work as part of a connected payment strategy.
Merchants should also understand the division of responsibility. A payment provider may supply technology, transaction data and risk-management capabilities, while the merchant and its payment partners each retain responsibility for the decisions and obligations applicable to their respective roles.
The appropriate setup will vary. What matters is that the merchant understands how the individual components work and how they support its particular risk and commercial objectives.
From authentication compliance to adaptive payment risk
Current regulatory developments show that the response to payment fraud is becoming broader. For merchants, this means considering how authentication, transaction context and other risk controls work together.
Griner combines global payments capabilities with a boutique approach. Businesses can access secure tokenisation, 3DS-compliant payment capabilities, adaptive fraud and risk management, and dedicated compliance support, together with access to a team that understands their setup.
Bottom line: Effective payment risk management is not only about meeting an authentication requirement. It is about applying appropriate controls within a payment strategy that can respond as markets, customer behaviour and fraud patterns change.
This article is for general information only and does not constitute legal or regulatory advice. PSD3 and PSR had not been formally adopted at the time of writing, and the final requirements and implementation dates may change.
Looking to strengthen your payment strategy?
Talk to Griner: support@griner.io

