Set up TRA (transaction risk analysis) exemption flags for low-risk, low-value card transactions under our PSD2 flow. Sent the exemption indicator on every eligible auth, assumed the issuer would honor it since we were under their fraud rate threshold for the exemption bucket.
About 18% of flagged transactions still came back with a challenge requested anyway.
Turns out the exemption flag is a request, not an instruction. The issuer's ACS makes the final call regardless of what indicator you send, and it can override based on its own risk engine, a mismatch between billing and shipping country, or just a stale risk model that hasn't been retrained since a fraud spike last quarter. Nothing in the response tells you why the exemption was ignored, you just get a challenge flow you didn't build UX for because you assumed frictionless.
Fix was ugly but simple: always render the challenge-capable flow client-side even when requesting an exemption, and log the exemption request vs actual outcome per issuer BIN range so we could see which issuers reliably honor it and which don't bother.
Anyone tracking exemption honor rates by issuer? Curious if this is consistent across regions or if it's mostly an EU-issuer quirk.
Top comments (1)
The useful boundary here is treating the exemption as a requested effect, not as the observed state. I would keep the request, the issuer/ACS decision, and the resulting challenge flow as separate records, then measure the transition by issuer or BIN range without implying that a declined exemption is a failed payment. That preserves the distinction between what the merchant asked for and what the issuer actually authorised, and it keeps the challenge path testable when the “low risk” assumption does not hold.