Card-Present vs Card-Not-Present
A liability shift determines whether the merchant or the card-issuing bank is financially responsible for fraudulent transactions and subsequent chargebacks. The core principle relies on technological adoption: the party supporting the less secure payment method bears the financial loss.
CP - Card-Present transactions occur when the physical payment card is scanned, dipped, or tapped at a physical terminal.
CP - Card-Not-Presenttransactions cover e-commerce, phone orders, mail orders, and mobile apps where the card is not physically handled by a merchant terminal.
Liability Shift: CP vs CNP Transactions
In face-to-face environments, the liability shift is governed by EMV (Europay, Mastercard, and Visa) chip technology. This framework protects merchants who use physical security measures at the point of sale.
The Security Standard
The standard requires reading the embedded EMV chip or accepting contactless payments (NFC) rather than relying on the legacy magnetic stripe, which is easily cloned.
Liability Allocation Rules - Liability Shift in Merchant Services
- Merchant Liable: If a customer presents a chip card, but the merchant forces a fallback swipe on a non-EMV terminal or outdated POS hardware, the merchant is 100% liable for fraudulent chargebacks.
- Issuer Liable: If the merchant operates a certified EMV terminal, but the issuing bank has only provided a legacy magnetic stripe card (or the chip fails due to bank error), the card issuer assumes all liability.
Card-Not-Present (CNP) Transactions: The 3D Secure (3DS) Shift
In e-commerce, mobile apps, and phone orders, physical cards cannot be inspected. Consequently, the baseline liability inherently rests on the merchant unless specific software protocols are deployed.
The Security Standard
The standard protocol for shifting CNP liability is 3D Secure (3DS), implemented via versions like 3DS 2.0. This authenticated protocol runs real-time risk analysis and may prompt the buyer for biometric authentication or a one-time passcode.
Liability Allocation Rules
- Merchant Liable: If a merchant processes a standard online checkout without 3DS verification, they are strictly liable for any fraud chargebacks, losing both the sales revenue and the physical inventory.
- Issuer Liable: If the merchant routes the transaction through the 3DS protocol, the liability shifts to the card issuer. This applies even if the issuer waives the authentication step or if a fraudulent charge manages to slip through.
Critical Differences Summary: CP vs. CNP
Hardware vs. Software Enforcement
CP liability shifts are bound entirely to physical POS hardware capabilities. CNP liability shifts depend completely on digital payment gateway software integrations.
Baseline Liability Default
In CP environments, a merchant who upgrades their physical terminal is heavily insulated from fraud by default. In CNP environments, the merchant remains default-liable for every transaction unless they actively pass authentication data via protocols like 3DS for that specific session.
Important Exclusions to the Liability Shift
A liability shift only protects against chargebacks categorized as unauthorized fraud (stolen card numbers or counterfeits). It provides no protection against:
- Service Disputes: Claims regarding items not received, damaged goods, or services not as described.
- Processing Errors: Double charges, incorrect entry amounts, or expired card errors.
Powered by: Joxall Marketing Group - www.jxlmkt.com
