SardineCon SF/2026

Learn More

What is Liability shift?

SUBSCRIBE

Liability shift is the rule that decides who absorbs a fraud loss based on authentication and compliance. It changes who is on the hook for a chargeback, sometimes without changing the fraud itself, which makes it a key lever when a team tunes its controls.

What is liability shift, in plain English?

Liability shift is a set of card-network rules that answer a single question: when a fraudulent transaction happens, who pays for it? The answer is not fixed. It depends on how the payment was authenticated and how compliant each party was with the network's security standards. Do the right thing and the loss moves off you; skip a control and it lands on you.

Two common examples show the pattern. Under chip rules, the least chip-compliant party absorbs a counterfeit loss, which is why merchants rushed to upgrade to EMV terminals. Under 3-D Secure, when an online payment is authenticated, the issuer generally eats the resulting fraud rather than the merchant.

The crucial idea is that liability shift changes who pays, not whether fraud occurs. The transaction can be just as fraudulent either way. All the rule decides is which party in the chain, the merchant, the acquirer, or the issuer, ends up carrying the cost of the chargeback.

Where liability lands

Scenario

Without the control

With the control

In-store counterfeit

Merchant on a stripe-only terminal often pays

Chip-compliant merchant pushes loss to the least-compliant party

Online payment

Merchant typically owns the chargeback

3DS authentication shifts fraud loss to the issuer

Who decides

Default network rules by transaction type

Authentication and compliance status of each party

Effect on fraud

Fraud still happens

Fraud still happens, only the payer changes

What it looks like in practice

In practice

An online retailer is taking heavy chargebacks on high-value orders. The fraud team routes those risky transactions through 3-D Secure, which adds an authentication step handled by the customer's bank. The fraud attempts do not stop; the same criminals keep trying.

What changes is the bill. On the authenticated transactions that still turn out to be fraud, the liability shifts to the issuer, so the retailer's chargeback losses on that segment fall sharply. The team did not prevent the fraud outright, they moved the exposure by satisfying the authentication rule, and they watch carefully for the exemptions where the shift does not apply.

Why it matters to operators

Liability shift is a strategic tool, not just a piece of trivia. Routing payments through 3DS or upgrading to chip terminals can move real chargeback exposure off your books, so teams weigh it directly when they tune controls and decide where to add authentication friction. Used well, it lets you manage loss without necessarily lowering fraud volume.

Used carelessly, it bites back. Misreading the rules leads to surprise losses, where a team assumed the shift protected them and discovers, in a contested representment, that a missed compliance step left the liability on their side. Knowing exactly when the shift applies, and when an exemption breaks it, is the difference between a control that pays for itself and one that quietly costs you.

What to watch in the data

  • Unexpected chargebacks. Fraud losses landing on your side when you assumed authentication protected you signal a misread of the rules.
  • Compliance gaps. Stripe-only terminals or un-authenticated flows quietly keep liability where you did not want it.
  • Exemption leakage. Transactions that skipped 3DS under an exemption may not carry the shift, so the loss stays with the merchant.
  • Representment reversals. Contested cases you expected to win but lose often trace to a broken liability assumption.
  • Channel mix shifts. A move toward channels without a shift can raise your effective exposure even if fraud is flat.

Quick questions

Does liability shift reduce fraud?

No. It only changes which party absorbs the loss. The fraudulent transaction still occurs; the rule decides whether the merchant, acquirer, or issuer pays for it.

How does the EMV liability shift work?

For in-person counterfeit fraud, the loss falls on whichever party is least chip-compliant. A merchant still using a stripe-only terminal against a chip card typically absorbs the chargeback.

How does 3DS shift liability?

When an online transaction is authenticated through 3-D Secure, resulting fraud generally becomes the issuer's responsibility rather than the merchant's, which is a major reason merchants route risky orders through it.

Can exemptions undo the shift?

Yes. If a transaction skips authentication under an exemption, the liability protection may not apply, and the merchant can remain on the hook. That is why exemption use needs careful monitoring.

Why do teams get surprised by liability?

Usually because they misread when the shift applies or missed a compliance step. The gap only surfaces later, in a chargeback or a lost representment, when the loss lands where they did not expect.

Is liability shift the same across all networks?

The core concept is shared, but the specific rules, thresholds, and reason codes vary by card network and region. Teams need to know the exact terms of the networks they operate on.

Go deeper

What to know alongside Liability shift