Why Your 3DS Authentication Has Low Approval Rates: 5 Optimisation Tips

Low 3DS approval rates cost online merchants revenue through unnecessary declines and abandoned carts. Learn the most common causes of failed 3DS authentication and five practical steps to fix them, so you can reduce checkout abandonment and drive higher conversions.

August 04, 2025

Low 3DS authentication success rates often come down to incomplete data, a poor mobile experience, or technical errors in how 3DS is implemented.

This guide breaks down the key causes of low approval rates and offers five proven fixes to boost performance and maximise revenue from every transaction.

key-takeaways-icon

Key Takeaways:

  • Low 3DS approval rates are mainly caused by insufficient data, poor mobile UX, and technical misconfigurations
  • Enriching transaction data using 150+ 3DS 2.0 fields significantly boosts issuer trust and approval rates
  • Using native mobile SDKs with biometric or push-based authentication drastically improves mobile conversion
  • Applying strategic challenge indicators and SCA exemptions reduces unnecessary friction for low-risk users
  • Monitoring 3DS performance data and adapting authentication based on real-time insights helps optimize results over time

What a 3DS Approval Rate Measures

A 3D Secure approval rate is the share of 3DS authentication requests that the card issuer approves, either instantly through the frictionless flow or after the customer completes a challenge.

Authentication runs under card scheme programmes such as Visa Secure and Mastercard Identity Check. The merchant's 3DS Server sends transaction and device data to the issuer's Access Control Server (ACS), which scores the risk and decides whether to approve, challenge, or reject the request.

Frictionless Flow vs Challenge Flow

Frictionless flow: the issuer approves on data alone and the customer sees no extra step.

Challenge flow: the customer must confirm their identity with a one-time passcode, a banking-app push notification, or biometrics.

Every challenge adds time and a chance to drop off, so the more transactions an issuer can approve frictionlessly, the higher the overall success rate.

Authentication Rate vs Authorisation Rate

A successful 3DS authentication does not guarantee payment. After authentication, the transaction still goes to the issuer for authorisation, where it can be declined for reasons such as insufficient funds.

Tracking both rates separately shows whether revenue is lost at the authentication step or later in the payment flow.

How 3DS Approval Rates Impact Online Merchants' Revenue

Merchant revenue decreases when 3DS approval rates are low. Customers abandon the checkout process due to unnecessary friction, resulting in lost conversions.

A percentage-point drop can result in millions in lost revenue. European merchants see a 2–3.5% downturn in conversion rate when 3DS authentication is poorly applied; U.S. merchants may experience losses up to 15%.

For merchants selling to European cardholders, skipping 3DS is rarely an option, since Strong Customer Authentication (SCA) under PSD2 requires it for most online card payments unless an exemption applies.

Effective use of 3DS authentication also reduces fraud liability: once a transaction is successfully authenticated, liability for fraud-related chargebacks shifts from the merchant to the card issuer. It also improves user experience and supports higher average order value (AOV).

Common Causes of Low 3DS Approval Rates

Low 3DS success rates usually point to problems in data quality, mobile optimisation, or inconsistent implementation. Identifying these gaps is the first step toward fixing them and improving conversion.

Insufficient Data Provision

Issuers use transaction data to make risk-based decisions. Merchants relying on the original 15 data points from earlier 3DS versions (3DS 1.0) fail to provide critical information.

Missing fields like these cause issuers to default to conservative models, leading to unnecessary challenges and declines:

  • billing/shipping address
  • postal-code match indicator
  • device fingerprinting
  • browser characteristics
  • customer account attributes

Poor Mobile Experience

Over half of transactions occur via mobile, yet merchants continue to use browser-based 3DS authentication. This leads to issues with load times, improper iframe sizing, and redirects from native apps, which cause checkout abandonment.

Native mobile SDKs run the 3DS challenge inside the merchant's own app instead of a browser window. Using them for in-app authentication with biometric authentication and push-based authentication significantly improves approval rates.

Inconsistent Authentication Strategy

Inconsistent 3DS authentication usage disrupts issuer modelling. If transaction volume data is missing or the 3DS Requestor Challenge Indicator (the field where the merchant states its challenge preference to the issuer) does not clearly indicate frictionless authentication versus challenge authentication, issuers lack the input needed to optimise risk decisions, resulting in lower approval rates.

Technical Implementation Issues

Low approval rates can be caused by poor technical setups such as misconfigured parameters, missing required authentication method flags, excessive latency, or compatibility problems.

Average authentication latency exceeding 37 seconds and poor use of 3DS Method URL contribute to customer drop-off and declines. The 3DS Method URL is an issuer-hosted script that the checkout loads in a hidden iframe to collect device data before authentication, so skipping it or calling it late leaves the issuer without that data.

5 Tips To Optimise Your 3DS Approval Rates

These five tips show you where to start and what to fix first to improve 3DS approval rates.

Optimisation Tip #1: Maximise Data Enrichment

Start by using the full range of 150+ data fields supported by 3DS 2.0:

  • Include accurate billing/shipping address details with postal-code match indicator.
  • Invoke the 3DS Method URL early for device fingerprinting and browser characteristics.
  • Share customer account attributes like account age, transaction history, and authentication method flags.

Accurately use the 3DS Requestor Challenge Indicator to signal frictionless authentication or challenge authentication as needed.

Optimisation Tip #2: Implement Strategic Authentication Flows

Select frictionless authentication or challenge authentication based on risk:

"02" (challenge not requested): for low-risk, returning users.

"03" (challenge requested): for high-value or new users.

Apply SCA exemptions when eligible, using transaction risk analysis and whitelisting for qualifying low-risk transactions. Under PSD2:

Exemption
Transaction risk analysis (TRA)
Whitelisting (trusted beneficiaries)
Low-value exemption
When it applies
Lets the acquirer or issuer skip SCA on remote card payments up to €100, €250 or €500, depending on how low its fraud rate is
Lets cardholders exempt merchants they buy from regularly
Payments under €30, within cumulative limits

Optimisation Tip #3: Optimise the Mobile Authentication Experience

Use native mobile SDKs for in-app authentication that supports biometric authentication and push-based authentication. Ensure iframe sizing is optimised for responsive design and supports fallback options.

Target sub-30-second authentication windows to retain users throughout the mobile journey.

Optimisation Tip #4: Monitor and Analyse Performance Data

Track 3DS approval rates by BIN ranges (which identify the issuing bank), transaction sizes, geographies, and customer segments. Identify underperforming segments and test updates with A/B testing.

Use real-time dashboards to analyse performance of data elements, challenge indicators, and SCA exemptions.

Optimisation Tip #5: Implement Advanced Authentication Strategies

Recover soft-declined transactions (authorisations the issuer declines because it requires Strong Customer Authentication, signalled by codes such as 1A on Visa and 65 on Mastercard) through step-up authentication with options like SMS codes, push-based authentication, and biometric authentication.

Use fraud engine risk scores to adjust challenge indicators, apply intelligent transaction routing, and implement machine-learning-driven feedback loops to adapt to issuer behaviour and emerging fraud pattern recognition.

Summary

To improve 3DS authentication success and protect revenue, merchants must go beyond basic implementation. Approval rates suffer when critical data fields are missing, mobile experiences are clunky, or authentication strategies are misaligned.

By enriching data inputs, tailoring authentication flows by risk level, using native mobile SDKs, closely monitoring performance metrics, and applying advanced recovery strategies, payment teams can reduce friction, raise approval rates, and ultimately drive more completed transactions.

Build a Stronger Payment Stack

Talk to DECTA's team about card acceptance, 3DS compliance and fraud management for your online business.

Talk to our team