Access Control Server
An Access Control Server (ACS) is the issuer-side system that authenticates the cardholder in a 3-D Secure flow.
Read full definitionShouldEye Trust Intelligence Glossary
3-D Secure, SCA, AVS, CVV checks, liability shift, and risk-based authentication.
Educational information only. ShouldEye does not provide legal, banking, or individualized financial advice. Dispute rights, deadlines, and outcomes depend on your payment method, card network, issuer, processor, jurisdiction, and the facts of your case. Legal Disclaimers
37 published definitions in this topic.
An Access Control Server (ACS) is the issuer-side system that authenticates the cardholder in a 3-D Secure flow.
Read full definitionAddress Verification Service (AVS) compares billing address elements to issuer records during authorization.
Read full definitionAn Authentication Request (AReq) is the 3-D Secure message that starts issuer authentication for a transaction.
Read full definitionAn Authentication Response (ARes) is the ACS reply indicating authentication outcome or that a challenge is required.
Read full definitionAn AVS match means the billing address data supplied at checkout aligned with the issuer’s address records.
Read full definitionBehavioral biometrics analyzes how a user types, moves, or interacts to detect bots and account takeover.
Read full definitionBiometric authentication verifies a person using inherence factors such as fingerprint or face recognition.
Read full definitionA card verification charge is a small temporary authorization used to confirm a card works—often refunded or released after setup.
Read full definitionCard Verification Value (CVV/CVV2/CVC/CID) is the short security code printed on a card used to help prove possession in card-not-present payments.
Read full definitionA Cardholder Authentication Verification Value (CAVV) is a cryptographic result evidencing 3-D Secure authentication.
Read full definitionCardholder Verification Method (CVM) is how the cardholder proves presence at a card-present acceptance device—PIN, signature, biometrics, or no CVM.
Read full definitionChallenge authentication is a 3-D Secure step-up that requires the cardholder to actively verify (OTP, app push, biometrics, etc.).
Read full definitionA Challenge Request (CReq) starts the cardholder challenge step in a 3-D Secure challenge flow.
Read full definitionA Challenge Response (CRes) returns the result of a 3-D Secure cardholder challenge.
Read full definitionA CVV mismatch means the card security code entered at checkout did not validate with the issuer.
Read full definitionDecoupled authentication verifies the cardholder outside the merchant checkout UI on a separate device or channel.
Read full definitionDevice fingerprinting collects device and browser attributes to recognize returning devices and score risk.
Read full definitionA Directory Server routes 3-D Secure authentication messages between the 3DS Server and the issuer ACS.
Read full definitionAn Electronic Commerce Indicator (ECI) is a value describing the e-commerce authentication/security results on a card transaction.
Read full definitionFrictionless authentication verifies the cardholder in 3-D Secure without showing a challenge UI.
Read full definitionLiability shift moves certain fraud-chargeback financial responsibility between merchant and issuer when authentication rules are met.
Read full definitionThe low-value exemption allows omitting SCA for remote payments below defined amount and cumulative limits.
Read full definitionMulti-factor authentication (MFA) uses two or more independent factors to verify a user.
Read full definitionNo CVM means the transaction proceeds without PIN, signature, or biometric cardholder verification at the terminal.
Read full definitionA one-time password (OTP) is a single-use code used as an authentication factor.
Read full definitionOut-of-band authentication uses a channel separate from the checkout session—such as a banking app push—to verify the payer.
Read full definitionAn SCA exemption is a permitted case where Strong Customer Authentication may not be applied under applicable rules.
Read full definitionThe secure corporate payment exemption can omit SCA for certain payments made through dedicated secure corporate processes.
Read full definitionStep-up authentication adds a stronger verification step when baseline checks are insufficient.
Read full definitionStrong Customer Authentication (SCA) is a regulatory standard requiring multi-factor authentication for many electronic payments.
Read full definitionThree-D Secure (3-D Secure / 3DS) is an EMVCo cardholder authentication protocol for e-commerce card payments.
Read full definitionThree-D Secure 2 (3DS2) is the EMV 3-D Secure version designed for richer data and mobile-friendly flows.
Read full definitionA Three-DS SDK is software embedded in mobile or in-app checkout to support EMV 3-D Secure device data and challenges.
Read full definitionA Three-DS Server (3DS Server) is the merchant- or provider-side component that initiates and orchestrates 3-D Secure messages.
Read full definitionThe transaction risk analysis (TRA) exemption allows skipping SCA when fraud risk is within regulated thresholds.
Read full definitionThe trusted beneficiary exemption allows omitting SCA for payees the payer has whitelisted with their ASPSP.
Read full definitionTwo-factor authentication (2FA) verifies a user with two different authentication factor types.
Read full definition