The customer filled the basket, entered the card, then received an SMS code they failed to enter in time. The sale is lost, and the merchant concludes that authentication is costing them turnover. That is true, and yet removing it would cost more: authentication does not primarily protect the customer, it moves onto their bank the liability for a fraud that would otherwise stay with you.

The essentials in five points
- Authenticating means proving the cardholder is genuinely present at the moment they cannot physically present the card.
- The real stake is liability: on an authenticated operation, fraud is in principle borne by the cardholder’s bank.
- An unauthenticated operation leaves you alone facing the dispute, with no evidence you can rely on.
- Abandonment is real but workable: it owes more to surprise and slowness than to the principle itself.
- It concerns distance selling only: in store, the card and the PIN already perform this role.
1. What authentication proves, and to whom
An in-store payment rests on two things the merchant witnesses: the card is physically there and the holder knows the PIN. At a distance both guarantees vanish at once. Authentication rebuilds them by another route.
- What the customer has: The card itself, whose number they enter, and increasingly the phone registered with their bank.
- What the customer knows: A password, or a one-time code received on that phone and valid for a few minutes.
- What the customer is: A fingerprint or face recognition, where validation runs through the banking app.
- Who validates, in the end: The cardholder’s bank, never you. You see only the result: the operation is authenticated or it is not.
That last point is often misunderstood: you verify nothing yourself and receive no secret data from the customer. You receive an answer, and it is that answer which carries weight in a dispute.
2. The liability shift, which is the real subject
Many merchants see authentication as a constraint imposed on the customer. It is in fact insurance taken out on themselves, and comparing the two situations shows it immediately.
| Situation | Who bears the fraud | ||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| I | n | – | s | t | o | r | e | s | a | l | e | , | c | a | r | d | a | n | d | P | I | N | |||||||||||||||
| T | h | e | b | a | n | k | , | a | b | s | e | n | t | f | a | u | l | t | b | y | t | h | e | m | e | r | c | h | a | n | t |
Translated into practice: accepting a remote order without authentication means insuring the fraud risk on that sale yourself. On a high average basket, a single fraudulent operation wipes out several days of margin.
It is also why an authenticated operation is far easier to defend in a dispute, a mechanism set out in our guide to disputed card payments.
3. Cutting abandonment without giving up protection
Abandonment at the code step is a real problem, but it rarely comes from authentication itself: it comes from the customer not expecting it, or from a checkout that lost them along the way.
- Announce the step before it arrives, in one sentence, on the payment page.
- Check that your page works on a phone: the customer has to leave your site to read an SMS and come back.
- Do not make the customer rebuild the basket after a failure: keep it and offer to try again.
- Make sure the customer’s phone number is current with their bank, by naming it as a likely cause of failure.
- Offer a defined fallback, such as a payment link sent afterwards, rather than leaving the order dead.
A customer who fails authentication is not a lost customer: they wanted to buy. Calling them or resending a link recovers a meaningful share of these baskets.
Turning off authentication to sell more is bad arithmetic
The temptation appears when abandonment rises. But on an unauthenticated operation, card-number fraud is debited to you with no useful recourse: you have neither the card, nor a signature, nor proof the holder was present. The gain on recovered baskets is almost always smaller than the cost of the first fraud.
4. Where it concerns you, and where it does not
Strong authentication concerns remote payments: an online shop, a payment link, a telephone order processed on a virtual terminal. In store, the inserted card and the entered PIN already perform this function, and nothing further is asked of you.
BelloPOS works offline and processes no payments: it records the sale and its payment method without ever touching card data. Authentication happens entirely between the customer, their bank and your online payment provider. That is good news for liability: no sensitive data passes through your till or sits on your machine.
Mistakes to avoid
- Treating a failure as a cancelled order — The customer wanted to buy. A payment link resent the same day recovers a good share of these sales.
- Never testing your own checkout on a phone — Most payments happen on mobile, and that is exactly where the jump to the SMS breaks most often.
- Keeping card numbers “for convenience” — No commercial reason justifies storing that data. Use the mechanisms your provider offers.
- Believing it protects the merchant from the customer — Authentication proves the holder was present, not their intention. A dispute for services not rendered remains possible.
Frequently asked questions
Can I choose not to authenticate certain operations?
It depends on your provider and the applicable rules, but the question to ask is a different one: on those operations, you bear the fraud. The flexibility has an identifiable price.
Does the customer need to install an app?
Not necessarily. Depending on their bank, validation runs through an SMS code or the banking app. That choice belongs to their bank, not to you.
Does authentication slow down in-store payment?
No, it does not apply there: the inserted card and entered PIN already constitute authentication. The subject belongs to distance selling.
Does this eliminate fraud?
No, it moves the liability. Fraud remains possible, but you no longer bear it on the same terms.
What to take away
Strong authentication is not a formality imposed on the customer but insurance taken out on your own account: without it, remote fraud is debited to you. Keep it, announce it in the checkout, test it on a phone, and follow up failed baskets instead of writing them off.
Sources
The figures and rules quoted above come from these pages, read on the date given in the article.
A till that handles no card data at all
BelloPOS works offline and records the sale and its payment method without ever storing a card number.
Read next
Other practical guides on the same subject: