SCA optimisation
European checkouts require eligible exemptions to be identified before authentication is requested. SCA exemption management assesses basket value, card type and risk criteria, then sets the relevant TRA, low-value or corporate payment flag in the API payload.
- Category
- Security
- Capabilities
- 6
- Available on
- All plans
European payment managers face significant conversion drops when issuers enforce rigid authentication on every digital transaction. Navigating PSD2 and UK FCA requirements demands precise evaluation of basket sizes, corporate cards and payee histories to determine if a purchase legally qualifies for a regulatory carve-out prior to processing.
Cardflo provides infrastructure that evaluates transaction parameters in real time to apply the appropriate regulatory flags. The platform determines whether low value payment exemptions or transaction risk analysis criteria apply, formatting the API payload to request issuer exemption without triggering a visible challenge to the buyer.
PCI scope is minimised through hosted fields and network tokens, and sensitive credentials never touch your servers. Strong Customer Authentication is applied intelligently to keep both regulators and conversion teams happy.
SCA optimisation overview
Merchants operating across European jurisdictions must balance stringent regulatory requirements with the commercial necessity of an uninterrupted checkout flow. While configuring specific authentication data fields falls under 3D Secure optimisation, SCA optimisation focuses entirely on the regulatory exemptions permitted by PSD2 and the UK FCA.
This discipline evaluates live transaction data to assert legal carve-outs before the authentication payload reaches the issuing bank. The Cardflo gateway evaluates the basket amount, the merchant fraud rate and the card type to deploy appropriate flags within the API request.
By systematically identifying low value payment exemptions, corporate secure payments and transaction risk analysis opportunities, payment managers can legally bypass secondary authentication prompts. This technical filtering reduces the volume of traffic subjected to issuer step-up challenges, protecting overall acceptance rates while maintaining full adherence to regional payment service directives.
How SCA optimisation works
Analysing basket values and limits
The gateway evaluates the transaction amount and the customer profile at checkout. For single purchases under thirty euros, the system calculates whether the cardholder has exceeded the cumulative limit of one hundred euros or five consecutive transactions. If the thresholds remain unbreached, Cardflo attaches the low value payment exemption flag to the initial API request.
Deploying transaction risk analysis flags
When transaction values exceed the low value threshold, the system evaluates the current merchant fraud rate against the acquirer partner network thresholds. If the purchase falls within the permitted risk parameters and remains below five hundred euros, the gateway asserts a transaction risk analysis exemption. This signals to the issuer that the transaction poses low risk.
Formatting the exemption payload
Cardflo orchestrates the technical payload to ensure the issuing bank receives clear regulatory indicators. The API request contains specific data fields asserting whether the purchase falls out of scope, such as a merchant-initiated transaction, or qualifies for a direct PSD2 exemption. This structured data prevents the issuer from defaulting to a mandatory step-up challenge.
Why SCA optimisation matters
Preserving checkout conversion rates
Mandatory authentication steps introduce friction that directly causes cart abandonment during checkout. Correctly applying PSD2 SCA exemptions removes these manual verification hurdles for eligible traffic. Payment teams ensure legitimate buyers complete their purchases rapidly, protecting revenue streams without violating stringent European payment regulations or issuer mandates, ultimately raising overall authorisation rates across regulated jurisdictions.
Mitigating technical abandonment
Every secondary challenge relies on issuer infrastructure and user connectivity, both of which introduce latency and potential failure points. Securing low value payment exemptions minimises reliance on external authentication pathways. Merchants retain greater control over the checkout experience, reducing the likelihood of session timeouts or mobile app display errors during the payment sequence.
Regulatory notes for SCA optimisation
Understanding the delegation of TRA exemptions
Under the Payment Services Directive 2, transaction risk analysis exemptions are typically asserted by the acquirer. However, merchants with robust fraud prevention tools can request to calculate and apply these exemptions dynamically.
This requires strict alignment with the acquirer partner network to ensure the overall fraud rate remains below the regulatory thresholds across the portfolio.
If the fraud rate breaches the specified limits, the relevant national competent authority will require the acquirer to revoke the exemption privilege. Finance teams must continuously monitor their chargeback ratios and fraudulent transaction volumes to maintain eligibility.
Precise API flagging ensures that only genuinely low-risk transactions attempt to bypass authentication.
Corporate secure payments and lodged cards
The UK Financial Conduct Authority and European banking authorities recognise that corporate purchasing environments differ significantly from consumer retail.
Payments initiated via secure corporate environments, including lodged cards used by travel management companies or single-use virtual cards for B2B procurement, are exempt from standard authentication mandates.
Properly asserting this exemption requires the gateway payload to identify the payment instrument as a corporate card operating within a secure protocol.
If the API request lacks these specific regulatory indicators, issuing banks will incorrectly treat the business purchase as a consumer transaction, forcing an authentication challenge that a virtual card system cannot complete.
SCA optimisation use cases
LVP exemptions for digital goods
Urban transport operators processing sub-€30 contactless fare payments can request the LVP exemption, but cumulative value and transaction count thresholds still trigger SCA under PSD2. Cardflo configures exemption indicators through its API and helps payment teams monitor issuer outcomes so authentication is requested when the permitted limits are reached.
Lodged corporate card payments
Corporate travel management firms charging centrally lodged cards may qualify for the secure corporate payment exemption when the instrument and process meet PSD2 requirements. Cardflo helps operators pass the appropriate SCA flags and works with its acquirer partners to confirm eligibility, avoiding consumer authentication prompts on approved B2B payment arrangements.
TRA thresholds by basket value
European retailers with low fraud ratios may seek TRA exemptions across eligible basket bands, with permitted thresholds determined by the acquirer partner’s reference fraud rate. Cardflo applies exemption requests according to transaction value and risk rules, then reports issuer acceptance and fraud outcomes so payment managers can adjust exemption policies.
Trusted beneficiary checkout
Account-based merchants may offer customers the option to add a payee to an issuer-managed trusted beneficiary list, reducing SCA prompts on later eligible purchases. Cardflo supports the relevant exemption indicator in the payment request and records authentication and authorisation outcomes for compliance analysis under PSD2 and UK FCA rules.
SCA optimisation by the numbers
This represents the typical percentage of transactions that can bypass manual authentication prompts through strategic exemption management within the European market.
Merchants often observe this range of improvement in successful authorisations when moving from basic 3DS implementation to an optimised SCA strategy.
The additional technical overhead for evaluating exemptions and selecting the optimal 3DS version is generally minimal and does not impact page load times.
Methodology: these figures are illustrative ranges drawn from published industry data and observed merchant cohorts, not guarantees. Actual results depend on your risk profile, card mix, geography and acquiring setup, and are confirmed only in your own pricing and approval terms.
Related terms
Talk to our team about a live rollout across our acquirer partners' rails.
What you get with SCA optimisation
- API flags that apply low value payment exemptions for eligible European transactions under thirty euros.
- Transaction risk analysis exemption parameters that evaluate merchant fraud rates to bypass challenge flows.
- Corporate payment exemptions targeting secure B2B virtual cards and lodged accounts to simplify processing.
- Out-of-scope identification for merchant-initiated transactions and mail order or telephone order payment flows.
- PSD2 exemption monitoring dashboards detailing issuer acceptance rates for specific low-friction authentication requests.
- Dedicated exemption logic for recurring subscription payments to prevent authentication prompts on subsequent billing cycles.
A short scoping call, then a written plan for your MIDs.
Questions about SCA optimisation
How do transaction risk analysis exemptions function under PSD2?
Transaction risk analysis allows merchants to bypass authentication if the transaction is deemed low risk and the acquiring partner maintains a fraud rate below specified thresholds.
The gateway evaluates the transaction amount against three distinct tiers: up to one hundred, two hundred and fifty, or five hundred euros. If the acquirer partner network meets the regulatory fraud rate requirement for that tier, Cardflo attaches the TRA flag to the payment request.
The issuing bank then decides whether to honour the exemption based on its own risk assessment.
Can low value payment exemptions be applied indefinitely?
Low value payment exemptions apply only to transactions under thirty euros, but they are subject to cumulative limits set by the cardholder's issuing bank.
Regulations mandate a step-up challenge once the buyer makes five consecutive low-value purchases or reaches a cumulative total of one hundred euros since their last authenticated transaction.
Cardflo monitors basket values to assert the exemption where possible, but merchants must anticipate that issuers will periodically mandate a challenge to reset the customer's cumulative counter.
Are merchant-initiated transactions classified as an SCA exemption?
Merchant-initiated transactions are not technically an exemption; they are entirely out of scope for Strong Customer Authentication under European directives. Because the cardholder is not present during the transaction sequence, the merchant processes the payment based on a prior mandate.
Cardflo formats the API payload to explicitly flag the transaction as merchant-initiated, preventing the issuer from attempting to trigger a challenge. This requires the initial customer-initiated setup transaction to be fully authenticated and correctly referenced in subsequent billing requests.
Why might an issuing bank decline a valid exemption request?
Issuing banks retain the ultimate authority over transaction approval and can reject any requested exemption to protect the cardholder. If the issuer detects unusual velocity, a suspicious IP address or potential account takeover indicators, they will return a specific response code demanding authentication.
This requires the merchant to resubmit the transaction with a full authentication request. Maintaining clean data formatting and accurately applying exemptions ensures the issuing bank has no technical reason to reject the initial API request outright.
Related features.
Related guides.
See how Cardflo compares.
Ready to improve your payments setup?
Tell us about your business. We'll match you with the right acquiring partners and the right route, typically inside a week.