PSD2 SCA Exemption Routing

Route low-risk payments to a frictionless auth and only challenge via 3DS when no exemption holds

PSD2 SCA Exemption Routing Route low-risk payments to a frictionless auth and only challenge via 3DS when no exemption holds 01 / Merchant / Checkout 02 / Exemption Engine EX / Strong Auth Intake Decide Auth Request · card + amount · Merchant / Checkout › Intake Auth Request card + amount Rule Engine · value / TRA / allowlist · Exemption Engine › Intake Rule Engine value / TRA / allowlist Decision · Exemption Engine › Decide · exempt? Decision exempt? Frictionless · SCA exempted · Merchant / Checkout › Decide Frictionless SCA exempted 3-D Secure · issuer step-up · Strong Auth › Decide 3-D Secure issuer step-up no exemption Legend User UI Agent logic Policy Tool action Context / trace

Exemption Types

  • • Low-value (under threshold)
  • • TRA (acquirer fraud band)
  • • Trusted beneficiary (allowlist)
  • • Recurring / MIT

Engineering Notes

  • • Exemption is a request, not a guarantee
  • • Issuer can soft-decline to 3DS
  • • Track exemption rate against fraud