SCA Demystified: How Bank-Level Security Enables A2A Payments - Full Episode | On The Wire

August 23
21 mins

Episode Description

Most payment security is an attempt to protect a number that has already been copied. The alternative is infrastructure where no reusable credential exists at all.


SCA requires two independent factors from different categories. Knowledge is something only the customer knows. Possession is something only they have. Inherence is something they are. Online card payments fail this by design, because the number, the CVV and the billing address all sit in the knowledge category and all live in databases somebody will eventually breach. Chip-and-PIN passes. A contactless tap under €50 does not, and is permitted anyway.


The flow. A customer starts a €150 payment. Their banking app opens showing merchant, amount, reference and the account to be debited. No money has moved and nothing is authorised, they are looking at a request. The first factor is the app itself, cryptographically bound to that device with credentials provisioned when the customer proved their identity at account setup, which is why merely installing an app is not possession. The second factor is a biometric or PIN. On success the app generates a signature saying: this account holder, on this authorised device, at this timestamp, approved this amount to this merchant. Unique per transaction, not replayable. The bank validates, locks the funds, and settles in under ten seconds.


Against 3D Secure. 3DS adds SCA to card payments and shifts liability to the issuer, which is genuine progress, but it only works online, it interrupts checkout with a redirect, card data is still transmitted and stored so PCI scope remains, and it does not stop the number being stolen and used where 3DS is not enforced. A2A does not add authentication to the payment. Authentication is how the payment starts. Nothing to steal, identical across every channel, and the issuing bank's existing security does the work.


The numbers. A €20 million e-commerce retailer: €80,000 in card fraud, €15,000 in chargeback fees, €40,000 in false declines. €135,000 a year. Add A2A at 25% and A2A fraud comes in at €500, or 0.01% of that volume, chargeback fees drop to €9,000, and false declines fall to €25,000 because card filters can be tightened once there is a fallback that does not decline. €40,500 saved on fraud alone, before processing savings. A payment institution with 200 merchants on €500 million sees A2A fraud at 0.02% against card at 0.40% and disputes down 21% portfolio-wide.


The full case study: a €15 million retailer at €9,300 a month in fraud costs. Month 3 at 8% adoption shows almost nothing. Month 6 at 18% is down 17%. Month 12 at 30% runs €6,370 a month, a 32% cut worth €35,160 a year, plus €31,500 in processing savings. €66,660 total against an €8,000 build. ROI in 44 days.


The honest limits. Phones do get stolen, but the attack needs the device, the unlock, the banking authentication and speed, while banks watch for exactly those patterns. A lost phone is recoverable same-day, faster than a replacement card in the post. Recurring payments run on a mandate authorised with full SCA once, re-authenticated whenever amount or frequency changes, revocable in the banking app rather than by phoning the merchant. And SCA is not inherently slow. Early 3DS was slow, and the failure was the redirect and the forgotten password, not the requirement.


Also covered: why authentication being technology-agnostic lets all seven initiation methods share one security model, and why security living in the banking layer improves automatically as banks upgrade while card-side improvements need network coordination.


The strategic question: how long can card payments justify 2-3% when much of that cost exists to defend static credentials that should not exist.


Full source material and the complete guide: https://go.payware.eu/p-sca-f

Produced by payware - the transaction resolution network for instant A2A payments.

AI-generated from payware's published research and documentation.

See all episodes