3D Secure Liability Shift

A liability shift happens when certain types of fraudulent or disputed transactions occur and the responsibility is moved from one party in the payment flow (you, merchant, etc.) to another (the card issuer).

When the liability shift applies, the issuer becomes responsible for fraud chargebacks. When it does not apply, the merchant remains liable for the disputed funds.

⚠️

Prepaid cards do not receive a liability shift.

Mastercard

Mastercard 4837: No Cardholder Authorization

A liability shift applies, which prevents issuers from opening chargebacks with reason code 4837 for transactions properly authenticated and identified through 3DS.

The liability shift applies to the following Electronic Commerce Indicator (ECI) values:

  • ECI 01: Attempted
  • ECI 02: Authenticated

The Mastercard fraud chargeback liability shift does not apply if the ECI is 00.

Visa

Visa 10.4: Other Fraud – Card-Absent Environment

The liability shift applies to the following ECI values (provided that the transaction does not meet any of the criteria for exclusions listed in the table below):

  • ECI 05: Authenticated
  • ECI 06: Attempted

The Visa fraud chargeback liability shift provided with 3DS does NOT apply under the following conditions:

⚠️

ECI 06 Alone Does Not Guarantee Liability Shift

ECI 06 indicates attempted authentication, and is subject to additional exclusions that can disqualify a transaction from liability shift protection. Common disqualifiers include:

ScopeRestrictionECIDescription
Global07Liability shift does not apply
GlobalAnyAn Electronic Commerce Transaction in which the Issuer responded to an Authentication Request with either:
  • Unable-to-Authenticate Response
  • Authentication Denial
Global

CAVV Missing

05 or 06

Merchants will receive a CAVV for authenticated and attempted authentication transactions which they must provide in the authorization message.

For ECI 05 or ECI 06 transactions where a CAVV was not received in authorization, the ECI will be reclassified to ECI 07.

Global

Non-Reloadable Prepaid

06Non-reloadable Visa prepaid cards are not required to participate in the Visa Secure program, but issuers may elect to participate. In terms of liability:
  • Authentication: If a non-reloadable Visa prepaid card is authenticated during Visa Secure program (ECI 05), the merchant is protected against specific Dispute reason codes.
  • Attempted Authentication: If authentication is attempted on a non-reloadable Visa prepaid card (ECI 06), the merchant does not receive liability protection on e-commerce fraud-related Disputes. ECI is reclassified to 07.
Global

Visa Fraud Monitoring Program

05 or 06Merchants are not protected if they have been identified in the program.
U.S.

Visa 3-D Secure Fraud Monitoring Program

05 or 06Merchants are not protected if they have been identified in the program.
U.S

Merchant Restricted Merchant Category Codes (MCCs)

05 or 06Merchants are not protected if their MCC is one of the following:
  • MCC 4829: Wire Transfer/Money Order
  • MCC 5967: Direct Marketing-Inbound Teleservices
  • MCC 6051: Non-Financial Institution-Foreign Currency, Money Order (not Wire Transfer), Travelers’ Cheques
  • MCC 7995: Betting, including Lottery Tickets, Casino Gaming Chips, Off-Track Betting and Wagers at Race Tracks
  • MCC 6540: Non-Financial Institutions: Stored Value Card Purchase / Load
  • MCC 7801: Government Licensed On-Line Casinos (On-Line Gambling)
  • MCC 7802: Government-Licensed Horse/Dog Racing

Discover

Discover ProtectBuy is the Discover® Global Network implementation of the EMV® 3-D Secure (3DS) protocol. It is designed to mitigate fraud for Card-Not-Present (CNP) transactions by verifying the cardholder’s identity in real-time during the checkout process.

When a merchant successfully authenticates a transaction using Discover ProtectBuy, the financial liability for fraud-related chargebacks shifts from the merchant to the card issuer. This protection applies even if the issuer is not participating in the program, provided the merchant attempted the authentication.

The liability shift applies to the following dispute reason codes:

Fraud (Reason Code UA): Such as UA02 (Fraud – Card Not Present).

Does Not Recognize (Reason Code AA): When a cardholder does not recognize a transaction on their statement.

To qualify for the liability shift, the transaction must result in one of the following Electronic Commerce Indicators (ECI), which must be passed in the authorization request:


ECI ValueDescriptionLiability Shift Status
05Fully authenticated transactionShifted to Issuer
06Authentication attempted (but could not be completed)Shifted to Issuer
07Not authenticated / FailedMerchant Remains Liable

The liability shift is not universal. Merchants remain liable for fraud in the following scenarios:

  • The shift only applies to fraud. Merchants remain fully liable for service disputes, such as "Merchandise Not Received" or "Not as Described".
  • High risk MCCs are excluded from the general ProtectBuy liability shift protections (for both AA and UA02):
    • 4829: Money Transfer – Non-Financial Institution (e.g., wire transfers)
    • 5967: Direct Marketing-Inbound Teleservices
    • 6051: Quasi Cash – Non-Financial Institution (e.g., money orders, foreign currency)
    • 6540: Non-Financial Institutions (stored value card purchase/load)
    • 7801: Government Licensed On-Line Casinos
    • 7802: Government Licensed Horse/Dog Racing
    • 7995: Betting (sportsbooks, fantasy gaming, etc.)
  • The liability shift is void if the merchant fails to include the required evidence (such as the valid CAVV cryptogram) in the Authorization Request.
  • Support for JCB cards within the Discover ProtectBuy (EMV 3DS) product was officially launched in June 2025. However, transactions using cards issued within the IIN ranges assigned to JCB or UnionPay are not eligible for liability shift protection through Discover ProtectBuy, even if authenticated.

Merchant Requirements for Participation

All merchants must utilize EMV 3DS protocol 2.2 or higher (including v2.3.1.1) to maintain eligibility for the program.

The Cardholder Authentication Verification Value (CAVV) generated during authentication is valid for 90 days. For recurring or merchant-initiated transactions (3RI), merchants must ensure they request a CAVV refresh or use the proper indicators to maintain protection.


Did this page help you?