Digital Payments

Access Control Server (ACS) combined with Risk-Based Authentication (RBA): Increasing E-commerce Security While Reducing Cart Abandonment

The exponential growth of digital commerce has brought two major challenges for issuers and retailers: sophisticated fraud and cart abandonment. To address this critical need, we have developed Access Control Server (ACS) solutions essential for the 3-D Secure protocol integrated with Risk-Based Authentication (RBA). According to Juniper Research, global losses due to online fraud are … Continued

The exponential growth of digital commerce has brought two major challenges for issuers and retailers: sophisticated fraud and cart abandonment. To address this critical need, we have developed Access Control Server (ACS) solutions essential for the 3-D Secure protocol integrated with Risk-Based Authentication (RBA).

According to Juniper Research, global losses due to online fraud are expected to reach nearly $400 billion by 2025. In 2024 alone, Brazil continued to rank among the countries with the highest rates of identity fraud attempts and unauthorized transactions in Latin America.

On the other hand, the fear of fraud cannot become an obstacle for legitimate customers. A recent study by BI Intelligence reveals that the average cart abandonment rate is around 70%, with one of the most crucial reasons being an excessively complex checkout process or one that requires too many manual authentications.

The current challenge is clear: How can we protect every transaction without creating barriers that cause the customer to give up on the purchase? In this tension between security and convenience, HST’s ACS and RBA solutions become indispensable.

What is ACS?

The ACS (Access Control Server) is the solution responsible for authenticating the cardholder during online purchases, whether in e-commerce or mobile apps.

It is part of the EMV® 3-D Secure protocol, a global standard that adds an extra layer of security to digital transactions. In practice, the ACS connects the issuing bank to the moment of payment.

It validates, in seconds, whether the person making the purchase is truly the card owner—balancing fraud protection with a seamless user experience.

Risk Analyzer: Risk-Based Authentication

HST Risk Analyzer is HST’s Risk-Based Authentication (RBA) solution that works alongside the HST ACS to enhance payment security. It analyzes transactions in real time, reducing cart abandonment by recommending frictionless authentication (no password required) or a challenge, thereby improving conversion and decision-making.

Cart abandonment remains one of the biggest challenges in global e-commerce. It is estimated that billions of dollars are lost every year to purchases that are never completed.

In Latin America, this scenario is even more critical. More than 75% of consumers abandon their carts before finalizing the purchase. One of the primary reasons is not price or product, but the payment experience. This is where Risk-Based Authentication (RBA) comes in.

What is Risk-Based Authentication (RBA)?

RBA is an authentication model based on risk analysis. In practice, this means that not every transaction needs to go through the same level of verification. The decision to require additional authentication is based on the data of the transaction itself. In the context of digital payments, RBA operates integrated with the ACS within the EMV 3-D Secure (3DS) protocol.

Based on this analysis, two possibilities are defined:

  • Frictionless Authentication: When the risk is considered low, the transaction is approved without the user needing to take any additional action.
  • Challenge Authentication: When there are signs of risk, the system requests extra validation, such as an SMS code, biometrics, or another verification method.

How RBA Works in Practice

During checkout, various pieces of information are analyzed in real time, including:

  • Customer data
  • Card information
  • Purchase details
  • Device data
  • Browsing behavior

This data is processed by the risk analysis system, which returns a recommendation for the ACS to either approve directly or request additional authentication. All of this happens in milliseconds.


Less Friction, More Conversion

One of the main impacts of RBA is on the conversion rate. By avoiding unnecessary challenges in low-risk transactions, the user experience becomes smoother. This reduces cart abandonment without compromising security. At the same time, suspicious transactions continue to be handled with the appropriate level of protection.


Security with Intelligence, Not Barriers

The traditional authentication model treated all transactions the same way. This generated excessive friction and directly impacted the customer journey. With RBA, the logic changes. Security becomes intelligent, contextual, and adaptive—acting only when necessary.


HST: More Efficiency in Payment Authentication

HST offers the Risk Analyzer, its Risk-Based Authentication solution, integrated with the HST ACS.

In practice, this allows issuers to:

  • Make faster and more accurate decisions.
  • Reduce fraud without harming the experience.
  • Decrease cart abandonment.
  • Increase transaction approval rates.

All of this is achieved with compliance with market standards and simplified integration.

Contact us for more information.

Related posts

AI, Stablecoins, and the Future of Payments: What to Expect in 2026

Learn more

Money Transfer: Instant and Secure International Transfers

Learn more

Reducing Fraud Without Adding Friction to Checkout

Learn more

Demystifying ACS: How Authentication Protects Online Payments

Learn more