• January 5, 2026 |
  • |

Fraud Reduction vs. Customer Friction: A Comparative Analysis of PSD2 Strong Customer Authentication and US Passkey Adoption

By:
SHARE
ABSTRACT
The global digital payments ecosystem faces the persistent challenge of balancing robust fraud prevention with a frictionless customer experience. This paper presents a comparative analysis of two divergent approaches to this challenge: the European Union’s regulatory-mandated Payment Services Directive 2 (PSD2) and its Strong Customer Authentication (SCA) requirements, versus the market-driven adoption of passkey technology in the United States. Adopting a multi-stakeholder perspective, this analysis synthesizes findings from industry reports and regulatory guidance to evaluate each model against key quantitative and qualitative metrics, including fraud reduction rates, transaction abandonment, implementation complexity, and user experience. The findings indicate that while PSD2 SCA has been highly effective in reducing payment fraud, it has imposed significant customer friction, leading to high initial transaction failure rates. Conversely, US-based implementations of passkeys demonstrate a capacity to reduce fraud substantially while simultaneously improving user login success and convenience. The primary barrier to leveraging passkeys within the EU is regulatory ambiguity surrounding their compliance with PSD2’s prescriptive, factor-based framework. This study concludes that an evolution toward more flexible, outcome-based security regulations is necessary to foster innovation and reconcile the critical objectives of security and usability in digital payments.

The proliferation of digital commerce has magnified the tension between securing online transactions and providing a seamless user experience. For merchants, payment fraud represents a substantial financial threat, costing e-commerce businesses an average of 3.6% of their total revenues in 2022, with cumulative losses projected to reach USD 206 billion between 2021 and 2025.1 In response, regulatory bodies and technology providers have developed distinct models for authenticating users and authorizing payments. In the European Union, the revised Payment Services Directive (PSD2) established a top-down, regulatory mandate for Strong Customer Authentication (SCA), enforcing a multifactor approach to security.2 In contrast, the United States has largely pursued a market-driven path, characterized by industry-led innovation and the voluntary adoption of new technologies like passkeys, which are based on the FIDO2 standard.3

While both approaches aim to reduce fraud, their methodologies and resulting impacts on the digital ecosystem differ profoundly. The EU’s prescriptive framework has demonstrated success in curbing fraudulent activities but has been criticized for introducing significant friction into the payment process, leading to increased cart abandonment and lost revenue for merchants. Conversely, passkeys promise a future of phishing-resistant security combined with a simplified, often single-gesture, user experience. However, their integration into Europe’s rigid regulatory landscape faces considerable challenges.

This paper aims to provide a comparative analysis of these two models from a multi-stakeholder perspective, encompassing merchants, financial institutions, technology providers, regulators, and consumers. By examining both quantitative metrics (e.g., fraud rates, transaction success) and qualitative factors (e.g., user experience, implementation complexity), this study seeks to illuminate the trade-offs inherent in each approach and provide insights into the future of digital payment authentication.

Literature review

The academic and industry literature reveals a clear divergence between the regulatory-push model of the EU and the market-pull dynamics of the US in payment authentication. PSD2 mandates SCA for electronic payments within the European Economic Area, requiring authentication using at least two of three independent factors: knowledge (something only the user knows), possession (something only the user possesses), and inherence (something the user is).2 An opinion from the European Banking Authority (EBA) further clarified that these two elements must belong to different categories, effectively upgrading the requirement to true two-factor authentication (2FA).4

This regulatory intervention has yielded significant results in fraud prevention. A report from the EBA showed that the average fraud rate in Europe was halved to 0.06% between June 2020 and June 2021.5 Similarly, France reported a 37% decrease in online card fraud between 2019 and 2021 following SCA implementation.6 However, this security gain came at a considerable cost to user experience and merchant revenue. The initial rollout of SCA caused some European merchants to lose nearly 40% of transactions due to user confusion and cart abandonment.7 Other research found that merchants in France, Germany, Italy, and Spain lost between 26% and 39% of transactions where 3-D Secure (3DS), a primary mechanism for SCA, was applied.8 A 2016 PayPal study noted an average 40% transaction abandonment rate following the introduction of 3DS, and an econometric analysis found that a significant increase in secure payments was associated with a reduction in overall card turnover.9

In contrast, the US market, characterized by voluntary industry initiatives, has fostered the growth of passkey technology.3 Passkeys, built on the FIDO2 standard, inherently satisfy two of the three SCA elements (possession via the user’s device and either inherence via biometrics or knowledge via a PIN) and are designed to be phishing-resistant.10 Large-scale deployments in the US have demonstrated the potential to achieve superior outcomes on both security and usability fronts. For example, PayPal reported that its implementation of passkeys resulted in a 70% reduction in Account Takeover (ATO) rates and a more than 10% increase in login success rates compared to passwords.6 Further data suggests passkeys can lead to a 4x higher login success rate and a 60-90% reduction in authentication support costs for banking institutions.11 The primary gap this paper addresses is the direct comparison of these two models, with a focus on the regulatory ambiguity in the EU that hinders the adoption of technologically superior, user-friendly solutions like passkeys.6

Methodology

This study utilizes a comparative analysis framework to evaluate the EU’s PSD2 SCA regulations against the US market-driven adoption of passkeys. The research synthesizes evidence from a curated selection of sources, including academic studies, industry white papers, reports from regulatory bodies like the European Banking Authority, and technical documentation from technology providers. This approach allows for a comprehensive assessment that incorporates both theoretical underpinnings and real-world performance data.

To ensure a balanced evaluation, the analysis is structured from a multi-stakeholder perspective, considering the distinct priorities and concerns of merchants (conversion, implementation costs), financial institutions (risk, compliance), technology providers (innovation, market share), regulators (consumer protection, market stability), and end-consumers (experience, security). The comparison is based on a balanced scorecard of quantitative and qualitative metrics. Quantitative indicators include fraud reduction rates, transaction approval rates, false decline rates, and cart abandonment rates. Qualitative factors include user experience (UX) and sentiment, perceived security, implementation complexity, and the long-term viability of the respective ecosystems.

By juxtaposing these metrics across the two models, this paper aims to provide a nuanced understanding of the trade-offs between mandated security and market-led innovation in the digital payments landscape.

Findings and analysis

The analysis of the two authentication models reveals a stark contrast in outcomes related to security, commerce, and technological adoption. The findings are organized into quantitative and qualitative comparisons to highlight the inherent trade-offs.

Quantitative analysis: fraud reduction vs. transaction success

On the primary objective of fraud reduction, PSD2 SCA has been an unambiguous success. Data shows that the regulation helped halve the average fraud rate in Europe to just 0.06% and contributed to a 37% drop in online card fraud in France.5,6 This stands in sharp contrast to the US, where one source placed the card-not-present fraud level at 4%.5 However, this success was achieved at the expense of commercial efficiency. The friction introduced by SCA led to significant transaction failures, with reports of merchants initially losing up to 40% of transactions and sustained losses of 26-39% in transactions where 3DS was applied.7,8 Earlier studies also pointed to a 40% transaction abandonment rate with 3DS.9

The US passkey model presents a different narrative. Data from PayPal’s large-scale deployment shows it is possible to achieve dual objectives: a 70% reduction in account takeover fraud was accompanied by a 10% increase in login success rates.6 Further evidence suggests passkeys can deliver a 4x higher login success rate than passwords and dramatically reduce authentication-related support costs.11 This quantitative data suggests that market-driven technological innovation has produced a solution that is superior in balancing security and user experience, whereas the regulatory approach forced a direct trade-off between the two.

Qualitative analysis: implementation complexity and regulatory ambiguity

From a qualitative perspective, the implementation of SCA in Europe has been complex and fragmented. A study of the DACH region revealed that while most issuers offered an app-based authentication procedure, 83% of these were separate, non-integrated apps, creating a disjointed user journey.12 For merchants, a key technical challenge is implementing ‘dynamic linking,’ a cornerstone of PSD2 that requires each transaction to be authenticated with a code specific to the payment amount and payee.10

The primary hurdle for passkey adoption in the EU is regulatory ambiguity. The EBA has not provided clear guidance on whether a passkey (possession) unlocked by a biometric (inherence) on the same device constitutes two sufficiently independent factors.6 This uncertainty causes banks and Payment Service Providers (PSPs) to avoid relying on passkeys for SCA compliance.6 Further complexity arises from the distinction between ‘synced passkeys’ (cloud-based) and ‘device-bound passkeys.’ While the latter are PSD2 compliant, the former, which offer a better user experience, are not, forcing a trade-off between compliance and convenience.13 In contrast, the US ecosystem fosters competing architectural models for passkey integration—Issuer-Centric, Merchant-Centric, Network-Centric, and PSP-Centric—driving innovation as players like Visa and Mastercard launch proprietary passkey services.14,15

Discussion

The findings illuminate a fundamental divergence in philosophy and outcome between regulatory-prescribed security and market-driven innovation. PSD2’s SCA mandate successfully established a high, uniform floor for payment security across the EU, drastically reducing fraud. However, its rigid, factor-based framework has inadvertently become a barrier to adopting newer, more user-friendly, and potentially more secure technologies like passkeys. The initial high rates of transaction abandonment demonstrate the significant economic cost of prioritizing security compliance over user experience. While systems like Mastercard’s Identity Check aim to make 90–95% of authentications frictionless through risk-based analysis, the underlying friction of a challenge remains a threat to conversion.16

The US passkey adoption model, led by major technology and payment players, demonstrates that the goals of fraud reduction and customer convenience are not mutually exclusive. PayPal’s results—simultaneously decreasing fraud and increasing login success—underscore the power of an outcome-focused approach.6 The urgency for such an approach is amplified by the evolving threat landscape; the rise of AI-driven phishing attacks, which saw a 1,265% increase in malicious emails after the launch of ChatGPT, renders traditional phishable factors like SMS OTPs increasingly obsolete.6 Passkeys, being inherently phishing-resistant, are better suited to this modern reality.

However, the European regulatory landscape is not static. The proposed PSD3/PSR framework introduces new rules for Delegated Authentication (DA), where a merchant or third party performs SCA. By classifying DA as ‘outsourcing,’ the framework imposes significant compliance burdens, including liability for fraud, on the authenticating party.17 This move could complicate merchant-centric passkey models, and industry players like Mastercard are actively lobbying against such a broad classification, arguing it could stifle innovation.18 This ongoing debate highlights the struggle to fit modern, distributed identity models into traditional, centralized regulatory frameworks.

Conclusion

This comparative analysis reveals that while the EU’s regulatory-driven PSD2 SCA framework has been highly effective in reducing payment fraud, it has done so at the cost of significant customer friction and has been slow to adapt to superior authentication technologies. In contrast, the market-driven adoption of passkeys in the US demonstrates a powerful alternative, achieving substantial fraud reduction while simultaneously enhancing the user experience. The primary barrier to harmonizing these outcomes is the regulatory ambiguity within the EU, which penalizes innovation by adhering to a prescriptive, factor-based definition of security rather than focusing on the outcome of phishing resistance.

For the digital payments ecosystem to advance, regulatory frameworks must evolve to become technology-neutral and outcome-oriented. Instead of dictating the ‘how’ of authentication, future regulations should define the ‘what’—resilience against modern threats like account takeover and phishing. Future research should focus on the real-world impact of the finalized PSD3/PSR on Delegated Authentication models, conduct longitudinal studies on the economic and security effects of scaled passkey adoption in the US, and perform qualitative analyses of consumer trust and preference between SCA and passkey-based systems.

REFERENCES AND NOTES

  1. Worldline. (2022). Fraud prevention in eCommerce report 2022–2023. https://worldline.com/content/dam/worldline/global/documents/reports/fraud-prevention-in-ecommerce-report-2022-2023.pdf
  2. Ford, C. D. (2020). PSD2 and CMA: What European “open banking” laws mean for U.S. financial institutions and industry innovators. Ballard Spahr. https://www.ballardspahr.com/-/media/files/articles/psd2-and-cma-what-european-open-banking-laws-mean-for-us-financial-institutions-and-industry-innovat.pdf?la=en&hash=60E3490149668F45EEBE24A8E8B901BD
  3. Child, S. (2025, July 9). Market first, regulation later? The American open banking journey. Open Banking Excellence. https://www.openbankingexcellence.org/blog/american-open-banking-market-vs-regulation/
  4. Delitz, V. (2024, April 15). Analysis of PSD2 & SCA requirements (SCA & Passkeys II). https://www.corbado.com/blog/psd2-sca-requirements
  5. Vasaasen, E. (2021, December 8). Will a PSD2 come to the US? https://okaythis.com/blog/will-a-psd2-come-to-the-us
  6. Delitz, V. (2025, May 1). Outcome-based strong customer authentication with passkeys. https://www.corbado.com/blog/outcome-based-sca-passkeys
  7. Max. (2025, August 13). Mandating MFA & moving toward passkeys: Best practices. Corbado. https://www.corbado.com/blog/mandating-mfa
  8. Forter Team. (2022, March 10). One year on from enforcement, has PSD2 reduced fraud? https://www.forter.com/blog/one-year-on-from-enforcement-has-psd2-reduced-fraud/
  9. Ardizzi, G. (2017, November 30–December 1). Innovation in customer authentication methods, card-based internet payments and user experience: Empirical evidence from Italy. European Central Bank. https://www.ecb.europa.eu/press/conferences/shared/pdf/20171130_ECB_BdI_conference/payments_conference_2017_academic_paper_ardizzi.pdf
  10. Soong, J. (2025, May 13). Passkeys and PSD2 SCA: Streamlining compliance. https://www.authsignal.com/blog/articles/navigating-passkeys-within-sca-psd2
  11. Corbado. (n.d.). Passkeys for banking: Secure & frictionless logins. https://www.corbado.com/passkeys-for-banking
  12. von Hake, B., Siebert, D., Steinbrecher, J., & Gieske, T. (2021, January). Weak customer authentication: An opportunity for banks. CORE SE. https://core.se/sites/default/files/2021-07/2021_CORE_Whitepaper_Weak_customer_authentication_EN_v1.0_3.pdf
  13. Faheem, A. (2024, September 2). Breaking free from passwords: Passkeys and the future of digital services. Thales Group. https://cpl.thalesgroup.com/blog/access-management/passkeys-future-digital-services
  14. Delitz, V. (2025, June 23). Payment passkey landscape: Four core integration models. https://www.corbado.com/blog/payment-passkeys-landscape-overview
  15. Corbado. (n.d.). Passkeys for financial services: Secure authentication. https://www.corbado.com/passkeys-for-financial-services
  16. Max. (2025, May 7). Mastercard Identity Check: Everything issuers & merchants need to know. Corbado. https://www.corbado.com/blog/mastercard-identity-check
  17. Delitz, V. (2025, May 6). Delegated authentication & passkeys under PSD3 / PSR. https://www.corbado.com/blog/delegated-sca-psd3-passkeys

Latest Research

Home » Fraud Reduction vs. Customer Friction: A Comparative Analysis of PSD2 Strong Customer Authentication and US Passkey Adoption
© Hampton Global 2026.
Join our newsletter
Stay up to date on latest stories