Announcing our New Developer Hub
Announcing our New Developer Hub
Announcing our New Developer Hub
Announcing our New Developer Hub
Jul 13, 2026

Liability Shift: A 2026 Guide to Fraud Responsibility in Card Payments

This is a h2 title that comes out of the rich text automatically.

Chargebacks?
No longer your problem.

Recover 4x more chargebacks and prevent up to 90% of incoming ones, powered by AI and a global network of 20,000 merchants.

600+ reviews
No credit card needed.
TL;DR:

The liability shift moved fraud responsibility from issuers to merchants who skip secure authentication like EMV chips or 3D Secure. It cut counterfeit fraud in stores but pushed more fraud online. Even after a successful shift, merchants can still face disputes, since risk simply relocates rather than disappearing.

Key Takeaways:
  • The EMV liability shift assigns fraud losses to whichever party, merchant or issuer, used the weaker authentication method, not to whoever approved the transaction.
  • Card-present fraud dropped after EMV adoption; card-not-present fraud rose because online transactions don't benefit from chip verification.
  • Online liability shift runs through 3D Secure instead of EMV, and only applies when authentication completes successfully.
  • Liability shift fails when merchants fall back to magnetic stripe, skip available chip technology, or don't trigger 3DS when required.
  • Even after a successful liability shift, the transaction can still be disputed. The issuer's evaluation of the evidence decides who absorbs the loss.

The EMV liability shift assigns fraud losses to whichever party used the weaker authentication method. If a merchant can't process an EMV chip transaction, the merchant pays. If both sides support EMV and the transaction still turns fraudulent, the issuer typically pays. Online, the same logic runs through 3D Secure instead of EMV: authenticate correctly and liability moves to the issuer, skip it and the merchant absorbs the chargeback.

Fraud didn’t disappear after EMV. It moved, making card-present fraud harder and card-not-present fraud easier. The liability shift didn’t reduce fraud. It changed where it shows up and who pays for it. For merchants, that shift changed more than fraud patterns. It changed who absorbs the loss.

Not Sure Who is Liable for a Disputed Card Transaction?

Chargeflow reviews how each transaction was authenticated (EMV chip or 3D Secure) and builds the evidence needed to prove liability sits with the issuer, not you.

Start for Free

What Is the EMV Liability Shift?

Liability shifts based on how a transaction is authenticated, not whether it is approved. 

The EMV liability rule determines which party is financially responsible when a transaction turns out to be fraudulent.

This is often referred to as a fraud liability shift, where responsibility moves based on how the transaction is authenticated. In practice, it determines which party is financially responsible when a transaction turns out to be fraudulent.

Before the adoption of EMV, issuers typically absorbed fraud losses. After the shift, liability moved to the party using less secure technology.

In practice:

  • If a merchant does not support EMV chip transactions, merchant is liable
  • If both sides support EMV, issuer is typically liable

This is what people mean by a credit card liability shift, card payment liability shift, or payment liability shift. 

The goal was simple: force the adoption of more secure payment methods. 

So what does a successful liability shift mean? It means the transaction was authenticated using the required method, and the issuer, not the merchant, is responsible for fraud-related losses.

RuleApplies ToLiability Shifts to Issuer WhenMerchant Stays Liable When
EMV ChipIn-store, card-presentBoth parties support EMV and the transaction is chip-authenticatedMerchant can't process a chip transaction and falls back to swipe or manual entry
3D Secure (3DS)Online, card-not-presentThe cardholder is verified through 3DS and authentication completes successfully3DS is skipped, fails, or isn't triggered when required

How the Liability Shift Changed Payment Fraud Responsibility   

In practice, a merchant's Payment Service Provider is often the one applying these liability rules at the point of sale, translating card network policy into what happens at checkout.

The liability shift didn’t just change who pays for fraud. It changed how risk is distributed across the transaction lifecycle.

Before the shift, issuers often absorbed fraud losses, and transactions could be approved without the merchant carrying the full risk.

After the shift, that changed: if a transaction isn’t authenticated using the expected method, the loss moves downstream to the merchant, even if the payment was approved. That creates a gap between system approval and dispute reality. 

From the system’s perspective, the transaction is valid and authorized. From the issuer’s perspective, the situation is simpler: the cardholder denies the charge. Liability is determined by how clearly the merchant can connect the customer to the transaction, not whether the payment was approved.

In practice, the liability shift determines which party is financially responsible for a fraudulent transaction when proper authentication isn’t used, shifting responsibility to the party with weaker security controls. 

Card-present fraud declined after EMV adoption, while online fraud increased as attackers moved to environments without chip-based verification. Today, card-not-present fraud accounts for the majority of payment fraud losses, even though it represents a smaller share of total transactions. 

The shift didn’t make fraud easier or harder. It made merchants accountable for what happens after approval, which is why many losses show up later, when a completed transaction turns into a dispute. 

Card-Present vs. Card-Not-Present Fraud After the Liability Shift

Distinguishing genuine card-not-present fraud from friendly fraud earlier is exactly what a broader Ecommerce Fraud Prevention strategy is built for.

Liability shifts based on how a transaction is authenticated, not whether it is approved.

The biggest impact of the EMV liability shift was where fraud happens. In physical stores, chip cards reduced counterfeit fraud and made skimming less effective, while shifting liability to merchants still using outdated systems. As a result, card-present fraud declined.

Online, the opposite happened. Transactions don’t benefit from chip verification and rely on weaker authentication signals, which made them easier to exploit and increased fraud rates.

This is where most liability gaps exist today. Online transactions carry more exposure, which is why unauthorized transaction disputes remain common even when payments are successfully approved.

Skipped 3D Secure? Do not Absorb the Chargeback Alone

When 3DS authentication fails or gets skipped, Chargeflow automates the evidence submission needed to fight the resulting dispute instead of writing off the loss.

Start for Free

Liability Shift in Online Payments (3D Secure)

In online transactions, liability shift works differently. Instead of EMV, it depends on authentication methods like 3D Secure (3DS). When applied correctly, the cardholder is verified during checkout, and liability can shift from the merchant to the issuer. But this only applies under specific conditions. 

Liability shift typically applies when authentication is successful and fully completed. If the transaction bypasses 3DS, fails authentication, or isn’t triggered when required, the merchant may still be liable. 

Even when liability shifts, gaps remain. The transaction can still be disputed, and the outcome depends on the issuer’s evaluation. 3D Secure reduces risk. It doesn’t remove it. Like EMV, it protects the transaction at a specific moment. It does not address what happens after authentication, including account takeover or post-purchase disputes.

How the Liability Shift Affects Merchants and Payment Processors

For Visa transactions, liability shift outcomes can still factor into a merchant's standing under the Visa Acquirer Monitoring Program, independent of who bears liability for any single dispute.

Mastercard runs its own separate monitoring too, and merchants who cross its thresholds can be enrolled in the mastercard chargeback monitoring program regardless of liability shift outcomes.

For merchants, the liability shift is not just about compliance. It’s about exposure.  Even when transactions look legitimate, the account may be compromised, the payment method may be valid, and the authorization may pass. But if the cardholder disputes the charge, the merchant may still be liable

This is where chargeback liability shift expectations break down. Authorization does not equal protection, because approval only confirms the transaction, not the customer behind it.

Processors handle the transaction. They facilitate authentication and routing, but they don’t determine liability in a dispute. That decision rests with the issuer, based on how the transaction was authenticated. Issuers evaluate the dispute, and merchants absorb the loss if the proof is insufficient. Liability shift changes who pays for fraud. It doesn’t prevent the dispute from happening. 

How EMV Technology Helps Prevent Fraudulent Transactions

EMV technology reduces fraud by making transactions harder to replicate. It uses dynamic authentication codes and chip-based verification and reduces reliance on static card data.

This measure makes counterfeit fraud significantly harder in physical environments. But EMV has limits. It does not protect online transactions or prevent account takeover and friendly fraud. It secures the card, not the account.

When Liability Shift Fails

Liability shift only applies under the right conditions. In practice, it often fails. Common reasons include fallback to magnetic stripe transactions, missing or skipped authentication, incomplete transaction data, and issuer-side decisions during dispute review.

When the transaction is completed, liability moves back to the merchant. This situation is where many losses occur, not because the transaction was obviously fraudulent, but because the required conditions for liability shift weren’t met.

ScenarioOutcome
Transaction uses the required authentication (EMV or 3DS) and completes successfullyLiability shifts to the issuer
Merchant falls back to magnetic stripe or skips available chip technologyMerchant stays liable
Authentication is skipped, incomplete, or not triggered when requiredMerchant stays liable
Issuer reviews the dispute and finds authentication requirements weren't metLiability moves back to the merchant
Transaction is approved but the customer disputes it after authenticationMerchant must prove the customer authorized the charge, regardless of the liability shift

For the network-specific version of this rule, see Visa's reason code 10.2.

Best Practices for Merchants After the Liability Shift

Merchants building out these practices at scale often turn to a dedicated chargeback management company rather than managing liability shift disputes case by case.

The liability shift changed responsibility. It didn’t eliminate risk.

Most fraud today doesn’t fail at authentication. It fails after access is granted. That’s why merchants need to focus beyond payment approval and control what happens across the full transaction lifecycle.

Don’t rely on authorization alone. Approved transactions can still become disputes, especially in account takeover and friendly fraud scenarios where the payment itself looks legitimate.

Use authentication selectively. Apply EMV and 3D Secure where risk justifies it. Overusing authentication adds friction, while underusing it increases exposure without actually reducing disputes.

Strengthen post-login monitoring. Most fraud now happens after the customer is authenticated, when the session is trusted and actions inherit that trust.

Track behavior, not just transactions. Fraud rarely appears as a single event. It shows up as a sequence, where actions connect over time.

Prepare for disputes, not just fraud prevention. Even when liability shifts, disputes still happen. What matters is whether you can connect the customer to the transaction in a way the issuer accepts.

The goal isn’t to stop every risky transaction. It’s to reduce the number of valid transactions that turn into disputes later.

The Bottom Line

It is also worth watching how AI agent chargeback liability develops, since liability shift rules will need to adapt as more disputed purchases originate from automated agents rather than the cardholder.

The liability shift didn’t remove fraud. It changed where risk sits and how losses surface. For in-store payments, EMV reduced counterfeit fraud. For online transactions, risk increased and shifted toward merchants.

A successful liability shift depends on using the right authentication at the right time. But most losses today don’t come from failed authentication. They come from trusted sessions that lead to disputes later. Understanding where liability sits matters. Controlling what happens before the chargeback is what actually reduces loss.

Win EMV Liability Shift Disputes Automatically

You can prove liability doesn't fall on you when a card wasn't dipped or tapped, instead of untangling liability shift rules case by case. Chargeflow automates evidence collection and submission, backed by a 4X ROI guarantee.

Start for Free

Frequently Asked Questions

What is the EMV liability shift?

The EMV liability shift is a card network rule that assigns fraud losses to whichever party, merchant or issuer, used the weaker authentication method. If a merchant can't process an EMV chip transaction, the merchant is liable. If both sides support EMV, liability typically falls to the issuer.

Does the EMV liability shift apply to online purchases?

Not directly. EMV liability shift covers card-present transactions. Online purchases run through 3D Secure instead: liability can shift to the issuer when the cardholder is verified through 3DS and authentication completes successfully.

What happens when the EMV liability shift fails?

If a transaction falls back to magnetic stripe, skips available chip technology, or authentication isn't triggered when required, liability stays with the merchant, even if the transaction was approved.

Who is liable for a chargeback after a successful liability shift?

A successful liability shift moves the fraud loss to the issuer, but it doesn't block a dispute from being filed. The transaction can still be challenged, and the outcome depends on whether the merchant can prove the customer authorized the charge.

What's the difference between EMV and 3D Secure liability shift?

EMV liability shift applies to card-present, in-store chip transactions. 3D Secure liability shift applies to card-not-present, online transactions. Both work the same way: liability shifts to whichever party used the weaker authentication method.

SHARE THIS ARTICLE

Chargebacks?
No longer your problem.

Recover 4x more chargebacks and prevent up to 90% of incoming ones, powered by AI and a global network of 20,000 merchants.

600+ reviews
No credit card needed.
subscribe

The latest chargebacks, fraud, and ecommerce content, in your inbox. Every week.

Sign up now and never miss out the latest trends!
By providing your email you're agreeing to our Terms of Service and Privacy Notice
Diagram with dashed and curved lines forming segmented arcs highlighted by three blue diamond markers on the left side.Abstract circular grid design with blue diamond markers on a half-black, half-white background.