Card-Not-Present Liability: How E-commerce Merchants Assume Fraud Risk Under Card Network Rules
In card-not-present transactions, liability for fraudulent purchases defaults to the merchant rather than the card issuer. E-commerce businesses must balance the friction of 3D Secure authentication against the financial exposure of chargebacks.
- Payment Processors
- Advocate for layered fraud prevention tools beyond basic network protocols.
- Merchant Advocates
- Focus on the trade-off between fraud prevention friction and checkout conversion rates.
- Card Networks
- Design the liability rules to incentivize secure authentication at checkout.
Perspectives this story doesn't cover
- Consumer Rights Advocates
- Small Business Owners
Start with the binding constraint. For a payment to be guaranteed by the bank that issued the card, the physical plastic must interact with a terminal. That condition does not hold in e-commerce. When a customer types a 16-digit primary account number into a checkout page, the transaction is classified as "card-not-present" (CNP). Because the merchant cannot physically verify the card or the cardholder's identity, the major card networks dictate that the merchant, not the issuing bank, assumes the financial risk if the transaction turns out to be fraudulent.[2][3]
The stakes of this default liability are substantial. In a card-present transaction, if a stolen card is dipped into an EMV chip reader, the issuer absorbs the loss. In a CNP environment, the merchant loses the shipped merchandise, forfeits the transaction revenue, and pays an administrative chargeback fee that typically ranges from $15 to $100 per dispute. By making e-commerce merchants liable for fraud rather than the issuer, the networks force the merchant to bear sole responsibility for resolving fraudulent orders.[2][5]
This structural vulnerability has made e-commerce the primary target for organized fraud. As physical point-of-sale security hardened with the global rollout of EMV chips, criminals migrated online, exploiting the gap where digital data replaces physical verification. By 2020, retail e-commerce sales in the United States grew by 36 percent, while CNP fraud losses increased by 31 percent, establishing a trend that has only accelerated. Today, CNP fraud accounts for the vast majority of global card fraud losses, representing the single biggest threat in e-commerce fraud prevention and costing the industry billions annually.[5]
The mechanics of a CNP transaction explain this persistent exposure. During an online checkout, the cardholder provides their primary account number, expiration date, and CVV electronically. The payment gateway encrypts this data and transmits an authorization request to the acquiring bank, which then forwards it to the card network and the issuing bank. The issuer runs preliminary risk checks, such as Address Verification Service (AVS) and internal fraud scoring algorithms, before approving or declining the request. Because the merchant never sees the physical card, they rely entirely on these digital signals to determine whether the buyer is legitimate.[5]
However, standard AVS and CVV checks do not shift liability away from the merchant. They function as basic filters that confirm the buyer possesses the card details, but they cannot definitively prove the buyer is the authorized cardholder. If a fraudster uses stolen credentials to successfully pass these checks, the merchant remains fully liable when the legitimate cardholder eventually notices the unauthorized charge and files a dispute. These basic checks stop unsophisticated attacks but miss coordinated fraud rings entirely, leaving the merchant exposed to the resulting chargebacks.[5]
However, standard AVS and CVV checks do not shift liability away from the merchant.
The primary mechanism that alters this default rule is the liability shift triggered by 3D Secure (3DS) authentication. Originally developed to secure online payments, 3DS adds an interactive verification layer to the checkout process. It redirects the buyer to their issuing bank to confirm their identity before the transaction is authorized. This verification often occurs via a one-time password sent via SMS, a biometric check on a mobile banking app, or through passive risk signals evaluated in the background. By forcing this extra step, the protocol ensures the issuer actively participates in the authentication.[1][4]
When a transaction successfully passes this 3DS authentication, the liability for any subsequent fraud-related chargeback definitively shifts from the merchant back to the card issuer. Because the issuer has explicitly vouched for the buyer's identity during the checkout flow, the issuer is forced to take the financial loss if their assessment was wrong. This protocol is specifically designed to protect businesses and customers from fraudulent activities and disputes in scenarios where the physical card is not presented, providing merchants with a powerful defense mechanism against organized fraud.[1][3]
Despite this robust protection, merchants face a difficult strategic trade-off. Historically, the added friction of 3DS authentication caused a significant number of legitimate customers to abandon their shopping carts out of frustration. To preserve high conversion rates, many e-commerce businesses deliberately chose to disable 3DS entirely. By doing so, they willingly absorbed the cost of fraud as a standard operating expense, calculating that the revenue saved by offering a seamless checkout experience outweighed the financial penalty of occasional chargebacks and lost merchandise.[4][6]
The introduction of 3D Secure 2.0 (3DS2) attempted to resolve this tension between security and user experience. 3DS2 enables merchants to share extensive background data with issuers—such as device fingerprints, IP addresses, and behavioral signals—allowing for sophisticated risk-based authentication. Under this updated protocol, low-risk transactions proceed without any visible friction to the user, while only high-risk orders trigger an active challenge. This allows merchants to secure the liability shift on the majority of their orders without sacrificing their checkout conversion rates.[1][6]
Even with the widespread adoption of 3DS2, the liability shift is not absolute. The protection only covers unauthorized-use fraud, meaning it does not protect merchants against friendly fraud. Friendly fraud occurs when the actual cardholder makes a legitimate purchase and later falsely claims the item never arrived or was defective. In those specific cases, the merchant must still compile compelling evidence—such as delivery receipts, customer communications, and IP logs—to fight the chargeback through the card network's rigorous dispute resolution process.[5][6]
Key points
- Card-not-present (CNP) transactions occur when payment details are entered electronically without physical card verification.
- Liability for fraudulent CNP purchases defaults to the merchant, who loses the merchandise, the revenue, and pays a chargeback fee.
- Address Verification Service (AVS) and CVV checks do not shift fraud liability away from the merchant.
- Implementing 3D Secure (3DS) authentication shifts the liability for unauthorized-use fraud from the merchant to the card issuer.
- 3D Secure does not protect merchants against friendly fraud, where legitimate buyers falsely dispute a charge.
Key terms
- Card-Not-Present (CNP)
- A payment transaction where the cardholder does not physically present the card to a merchant terminal, typical of e-commerce and phone orders.
- Chargeback
- A forced payment reversal where the issuing bank pulls the transaction amount back from the merchant's acquirer after a customer dispute.
- 3D Secure (3DS)
- An authentication protocol that requires the buyer to verify their identity with their issuing bank during an online checkout.
- Liability Shift
- The transfer of financial responsibility for a fraudulent transaction from the merchant to the card issuer, typically triggered by successful 3DS authentication.
- Friendly Fraud
- When a legitimate cardholder makes a purchase but later files a false chargeback claim, such as stating the item never arrived.
Frequently asked
Why are merchants liable for online credit card fraud?
Because the merchant cannot physically inspect the card or verify the buyer's identity through a terminal, card networks assign the risk of accepting the digital transaction to the merchant.
Does requiring the CVV code protect the merchant from liability?
No. While checking the CVV reduces the chance of accepting a stolen card number, it does not trigger a liability shift. The merchant remains fully responsible if the charge is disputed.
How does 3D Secure change who pays for fraud?
When a transaction successfully passes 3D Secure authentication, the issuing bank vouches for the buyer's identity. If the transaction turns out to be fraudulent, the issuer absorbs the loss instead of the merchant.
Does 3D Secure protect against all chargebacks?
No. It only shifts liability for unauthorized-use fraud. Merchants are still liable for disputes related to product quality, delivery failures, or friendly fraud.
Sources
[1]GPaymentsCard NetworksWhat the 3D Secure Liability Shift Means for US Businesses
Read on GPayments →
[2]Verifi IncMerchant AdvocatesWhy are e-Commerce Merchants Liable for Fraud?
Read on Verifi Inc →
[3]PXPCard NetworksFraud Liability Shift: Definition, How It Works
Read on PXP →
[4]PAAYMerchant AdvocatesHow Liability Shift Works — and Why It's Your Most Powerful Fraud Defense
Read on PAAY →
[5]ChargeflowPayment ProcessorsCard Not Present Fraud: The Ultimate Guide for Merchants
Read on Chargeflow →
[6]Factlen Editorial TeamCard NetworksSynthesis by Factlen editorial team
Read on Factlen Editorial Team →
Comments
More in Business
See all →African Markets
Dangote Refinery IPO Aims to Raise $1.5 Billion in Landmark African Market Listing
4 sources
Resource-Based View
How Valuable, Rare, Inimitable, and Organized Resources Determine Sustained Competitive Advantage
7 sources
Corporate Accounting
Cash Basis vs. Accrual Basis: How Timing Revenue Recognition Shifts Tax Liability and Financial Reporting
7 sources
Hiring Science
The 0.51 Validity Coefficient: How General Mental Ability Tests Predict Job Performance
9 sources
Every angle. Every day.
Get Business stories with full source coverage and perspective breakdowns delivered to your inbox.




