3D Secure Liability Shift
A liability shift happens when certain types of fraudulent or disputed transactions occur and the responsibility is moved from one party in the payment flow (you, merchant, etc.) to another (the card issuer).
When the liability shift applies, the issuer becomes responsible for fraud chargebacks. When it does not apply, the merchant remains liable for the disputed funds.
Prepaid cards do not receive a liability shift.
Mastercard
Mastercard 4837: No Cardholder Authorization
A liability shift applies, which prevents issuers from opening chargebacks with reason code 4837 for transactions properly authenticated and identified through 3DS.
The liability shift applies to the following Electronic Commerce Indicator (ECI) values:
- ECI 01: Attempted
- ECI 02: Authenticated
The Mastercard fraud chargeback liability shift does not apply if the ECI is 00.
Visa
Visa 10.4: Other Fraud – Card-Absent Environment
The liability shift applies to the following ECI values (provided that the transaction does not meet any of the criteria for exclusions listed in the table below):
- ECI 05: Authenticated
- ECI 06: Attempted
The Visa fraud chargeback liability shift provided with 3DS does NOT apply under the following conditions:
ECI 06 Alone Does Not Guarantee Liability ShiftECI 06 indicates attempted authentication, and is subject to additional exclusions that can disqualify a transaction from liability shift protection. Common disqualifiers include:
- Missing CAVV in the authorization message (reclassified to ECI 07)
- Non-reloadable prepaid cards (reclassified to ECI 07)
- Merchant participation in the Visa Fraud Monitoring Program , or 3-D Secure Fraud Monitoring Program
- Restricted Merchant Category Codes
Discover
Discover ProtectBuy is the Discover® Global Network implementation of the EMV® 3-D Secure (3DS) protocol. It is designed to mitigate fraud for Card-Not-Present (CNP) transactions by verifying the cardholder’s identity in real-time during the checkout process.
When a merchant successfully authenticates a transaction using Discover ProtectBuy, the financial liability for fraud-related chargebacks shifts from the merchant to the card issuer. This protection applies even if the issuer is not participating in the program, provided the merchant attempted the authentication.
The liability shift applies to the following dispute reason codes:
Fraud (Reason Code UA): Such as UA02 (Fraud – Card Not Present).
Does Not Recognize (Reason Code AA): When a cardholder does not recognize a transaction on their statement.
To qualify for the liability shift, the transaction must result in one of the following Electronic Commerce Indicators (ECI), which must be passed in the authorization request:
| ECI Value | Description | Liability Shift Status |
|---|---|---|
| 05 | Fully authenticated transaction | Shifted to Issuer |
| 06 | Authentication attempted (but could not be completed) | Shifted to Issuer |
| 07 | Not authenticated / Failed | Merchant Remains Liable |
The liability shift is not universal. Merchants remain liable for fraud in the following scenarios:
- The shift only applies to fraud. Merchants remain fully liable for service disputes, such as "Merchandise Not Received" or "Not as Described".
- High risk MCCs are excluded from the general ProtectBuy liability shift protections (for both AA and UA02):
- 4829: Money Transfer – Non-Financial Institution (e.g., wire transfers)
- 5967: Direct Marketing-Inbound Teleservices
- 6051: Quasi Cash – Non-Financial Institution (e.g., money orders, foreign currency)
- 6540: Non-Financial Institutions (stored value card purchase/load)
- 7801: Government Licensed On-Line Casinos
- 7802: Government Licensed Horse/Dog Racing
- 7995: Betting (sportsbooks, fantasy gaming, etc.)
- The liability shift is void if the merchant fails to include the required evidence (such as the valid CAVV cryptogram) in the Authorization Request.
- Support for JCB cards within the Discover ProtectBuy (EMV 3DS) product was officially launched in June 2025. However, transactions using cards issued within the IIN ranges assigned to JCB or UnionPay are not eligible for liability shift protection through Discover ProtectBuy, even if authenticated.
Merchant Requirements for Participation
All merchants must utilize EMV 3DS protocol 2.2 or higher (including v2.3.1.1) to maintain eligibility for the program.
The Cardholder Authentication Verification Value (CAVV) generated during authentication is valid for 90 days. For recurring or merchant-initiated transactions (3RI), merchants must ensure they request a CAVV refresh or use the proper indicators to maintain protection.
Updated 11 days ago