Delegated authentication as the answer to SCA-driven checkout drop-off

Strong customer authentication was introduced to reduce fraud, but for many merchants it has simply moved the problem. Instead of losing customers to fraudulent chargebacks, they are losing them at the authentication step itself. The numbers are uncomfortable: roughly one in five payments that enter 3D Secure never complete. That is not a fraud figure, it is a UX failure sitting inside a security mechanism.

The root issue is architectural. SMS OTPs and push notifications to banking apps were layered onto existing checkout flows as compliance tools, not as customer experience tools. The result is a process that interrupts the purchase moment, demands the customer context-switch to another app or device, and assumes they have the right app installed and the right SIM in hand. In practice, none of those assumptions hold reliably across a merchant’s full customer base.

For Dutch and Belgian merchants this matters acutely. Both markets have high smartphone penetration and strong iDEAL and banking-app cultures, which might seem to make push-based authentication natural. But the data suggests otherwise: a significant share of users simply abandon rather than complete a step-up flow they were not expecting. Guest checkout rates rise, loyalty programme sign-ups fall, and average order values drop because registered customers consistently outspend guests.

Delegated authentication shifts control. Under this model, a trusted party, typically a merchant or wallet that already holds verified credentials, takes on the authentication responsibility rather than pushing it back to the issuer at the moment of payment. The merchant gets to design the verification experience; the issuer accepts the outcome if the delegating party meets agreed standards. Friction can be reduced to a passive device signal or a biometric already baked into the device, invisible to the buyer.

The commercial case is straightforward: fewer step-up interruptions mean higher completion rates, more data captured at registration, and a checkout flow that does not penalise mobile users. Merchants evaluating their SCA implementation should ask not just whether it is compliant, but whether it is costing them completions they cannot see in their funnel reports.

Source: internetretailing.net

Related reading