In Brazil, EMV 3-D Secure went from an issuer-by-issuer option to an industry standard
4 oct 2026 · @Jose
Latin America processed more than US$500 billion in e-commerce in 2023 and is approaching US$770 billion in 2025. Over the same period, EMV 3-D Secure went from an issuer-by-issuer option to an industry standard in Brazil. Yet the region still has no public figure for how many payments are authenticated, and the phone channel barely shows up in the statistics.
This article brings together the public data available for 2023–2025 on market size, fraud, 3DS adoption and regulation across the region’s six largest markets. It separates what has been measured from what is merely assumed, and explains why phone payments (MOTO) are now the main blind spot for authentication in Latin America.
The key figures, one line each:
- R$1.1 trillion in card-not-present purchases in Brazil in 2025, up 18.3% on 2024 (ABECS).
- August 2024: ABECS publishes Normativo 31, setting 3DS authentication thresholds by merchant category; enforced from February 2025.
- 5.1 million fraud claims linked to online commerce in Mexico in 2023, totalling MXN 7.9 billion (CONDUSEF).
- Zero public time series on 3DS penetration by country, and zero regional figures on MOTO volume.
A remote market growing at double digits
Latin American e-commerce will double between 2023 and 2027, according to Payments and Commerce Market Intelligence (PCMI): from US$507 billion in 2023 to more than US$1 trillion in 2027, with US$769 billion forecast for 2025. Brazil accounts for around 55% of the region’s online sales.
| Market | E-commerce 2024 (PCMI) | Forecast annual growth 2024–2027 |
|---|---|---|
| Brazil | US$346 billion | 19% |
| Mexico | US$97 billion | 24% |
| Argentina | US$33 billion | 14% |
PCMI’s figures include travel and digital goods; retail-only estimates put the region at around US$190–195 billion. For merchants the conclusion is the same: remote payments are growing far faster than in-store payments.
Brazil’s industry statistics confirm the trend with actual transaction data. Card-not-present purchases (online, in-app and digital wallets) reached roughly R$830.9 billion in 2023, R$979.4 billion in 2024 and R$1.1 trillion in 2025. Out of R$4.5 trillion spent on cards in 2025, almost one in every four reais was already spent remotely.
Cards, however, are losing share within online commerce. Credit cards accounted for 56% of Latin American e-commerce in 2019 and 42% in 2024. In Brazil, Pix reached 40% of online purchases in 2024, against 44% for credit cards, and PCMI expects it to overtake them by 2027.
That competition is the underlying reason 3DS matters: every unnecessary challenge and every false decline pushes the shopper towards an alternative payment method.
Fraud has moved to remote channels
The migration to chip cards in the early 2000s cut in-store fraud across the region and pushed fraudsters towards card-not-present transactions. Mexico documents this best, because its financial consumer protection agency, CONDUSEF, publishes complaints to banks broken down by channel.
| Mexico indicator (CONDUSEF) | Value |
|---|---|
| Total claims for possible fraud, 2023 | 8.1 million, totalling MXN 28.5 billion |
| Share of cyber fraud in total claims | 59% in 2018 → 71% in 2023 |
| Growth in cyber fraud complaints, 2023 vs. 2022 | +20.1% |
| Online commerce, 2023 | 5.1 million claims, MXN 7.9 billion |
| Share of claimed cyber fraud amount refunded, 2023 | 29.3% |
| Online card purchases authorised, 2023 | 7 out of 10 requests |
There are two takeaways for merchants. First, e-commerce accounts for most claims, and CONDUSEF has for years linked that volume to the lack of cardholder authentication. Second, three in ten online purchase attempts are declined, and some of those declines are legitimate customers.
Brazil offers another angle. According to merchants represented by the Merchant Risk Council (MRC), the country’s chargeback rate stood between 0.8% and 1% in 2024, against card scheme thresholds of 1.5% to 2%. That is high by international standards, though lower than the figures commonly cited for the region in the past.
For the other countries there are no comparable public series. Fraud figures published by payment providers describe their own portfolios and should not be read as national rates.
From 3DS 1.0 to EMV 3DS 2.2: why this time is different
The first version of 3-D Secure was poorly received in Latin America: redirects, static passwords and decline rates that often exceeded 30%. According to Mastercard, more than 85% of its 3DS 1.0 transactions in the region came from just three markets: Mexico, Brazil and Costa Rica.
EMV 3DS changes the logic. The merchant sends the issuer more than 100 data points about the device, the shopper and the transaction, compared with around 15 in the previous version. With that information the issuer can authenticate low-risk transactions silently and reserve the challenge (OTP, banking app notification or biometrics) for the doubtful ones.
The version timeline closed during the period under review:
| Date | Change |
|---|---|
| September 2024 | Visa and Mastercard stop accepting EMV 3DS 2.1; 2.2 becomes the minimum |
| August 2024 | Visa requires a minimum data set in every authentication request (IP address, email, name and phone number) |
| 2023 | EMVCo publishes version 2.3, with support for WebAuthn and passkeys |
| October 2022 | Mastercard retires 3DS 1.0; Visa follows |
Measured results point in the same direction, although they almost always come from a single issuer or merchant:
| Measurement | Result |
|---|---|
| Visa, global average across clients using authentication | +4% authorisation and −7 basis points of fraud |
| Peruvian issuer using Visa Consumer Authentication Service | −30 points in challenge rate and +6% in authentication success |
| Banco Inter (Brazil), Aug 2022 to Aug 2023 | +11 points in authorisation of authenticated purchases |
| Mastercard, Brazilian market, Feb–Aug 2022 | 86% approval with 3DS vs. 80% without |
| Microsoft in Brazil, 2022 | 83.4% vs. 63.4% |
The less flattering side is documented too. In 2024, Brazilian merchants reported to the MRC that issuers were failing more than half of authentications. 3DS only improves conversion when the issuer’s risk engine is well calibrated.
Brazil: from 50% voluntary to an industry standard
Brazil is the only market in the region with a measurable 3DS trajectory and a rule that standardises it. In September 2023, at an ABECS seminar, the industry estimate was that “practically 50%” of online purchases were authenticated with 3DS, compared with an approval rate of around 90% often cited for France, where it has been mandatory since 2005.
On 21 August 2024, ABECS (the association that brings together issuers, acquirers and card schemes) published Normativo 31/2024. It is industry self-regulation, not law, but its members are bound by it. Its main elements:
- Scope. Merchants selling remotely through Brazilian acquirers must support EMV 3DS 2.0 or higher and authenticate above an amount threshold set for each merchant category group (MCC).
- Timeline. It came into force on publication and has been effectively enforced since 17 February 2025.
- Issuer targets. Successful authentication conversion of 85% in 2024 and 90% from 2025; frictionless authentication of 30% and 40% respectively.
- Exceptions. Recurring payments, card-on-file, keyed-in transactions and lists agreed between issuer and merchant can request exceptional treatment from the ABECS Fraud Security and Prevention Forum (Fórum de Segurança e Prevenção a Fraudes).
In 2025 ABECS published a second edition of the rule that adds an “Authentication Framework” based on each merchant’s fraud rate and on verified tokens. Authentication thus no longer depends only on the amount but also on the merchant’s risk.
The rule was not uncontroversial. The MRC published a position paper criticising it for its lack of metrics, the absence of merchant consultation and poorly defined exemptions. It also estimated that fewer than 40% of merchants supported 3DS and that one of the four largest issuers had no 3DS2 capability. No merchant consulted by the MRC considered the February 2025 deadline achievable.
What is missing is the outcome. The 90% and 40% targets are programme goals, not measurements. In the public sources reviewed, ABECS has not yet published the actual rates issuers achieved in 2025.
Mexico and the rest of the region: liability without a mandate
Outside Brazil, no major Latin American market requires 3DS. What drives adoption is who pays for fraud when there is no authentication.
Mexico is the clearest case. Since Banco de México (Banxico) amended its card rules (Circular 13/2018), issuers must refund within two business days any disputed charge that was not authenticated with two factors. If a merchant chooses to accept a payment without strong authentication, the cost of the chargeback falls on whoever processed the transaction and, ultimately, on the merchant. The rule does not require 3DS, but it makes not authenticating very expensive. There is, however, no public series measuring how much 3DS has grown in Mexico between 2023 and 2025.
| Country | Framework | Adoption signal 2023–2025 |
|---|---|---|
| Mexico | Banxico rules: unauthenticated charges are refunded by the issuer and passed back to whoever did not authenticate | Local PSPs offer selective or full 3DS2; no national figure |
| Chile | Law 21.234 (2020): limits cardholder liability and requires issuers, operators and merchants to adopt security measures | Tokenisation and 3DS on the rise according to providers; no figure |
| Argentina | No mandate | Banks enable 3DS in their apps, especially for purchases from foreign merchants |
| Colombia | No mandate | Available through regional PSPs; no published rate |
| Peru | No mandate | Public case of an issuer that cut its challenge rate by 30 points |
A regional digitalisation indicator sometimes confused with 3DS is tokenisation: Visa announced in 2025 that it had reached one billion tokens in Latin America and the Caribbean. It is a different technology, which protects the credential but does not authenticate the cardholder, and it should not be added to 3DS adoption figures.
The phone channel: authentication’s blind spot
EMV 3DS was designed to authenticate purchases on a website or in an app. When a customer reads out their card details to an agent or keys them into an IVR, there is no browser or SDK to collect device data, and the payment is classified as MOTO (Mail Order / Telephone Order). Protecting card capture and authenticating the cardholder are therefore two separate controls: the first reduces PCI DSS scope; the second is what shifts fraud liability.
In Europe, the European Banking Authority considers MOTO payments to fall outside the scope of PSD2 strong customer authentication. That position does not carry over to Latin America. In Brazil, the annex to Normativo 31 includes a merchant group identified as MOTO, with telemarketing MCCs and its own amount threshold, while also allowing keyed-in or merchant-initiated transactions to request an exception. There is, therefore, neither a universal obligation nor a universal exemption: each flow depends on its MCC, its channel indicator and what the acquirer, issuer and card scheme accept.
In Mexico the consequence is more direct. A phone payment that the cardholder disputes and that was not authenticated with two factors is refunded, and the cost goes back to the merchant.
How big is the channel? There is no public figure on MOTO volume for any Latin American country in 2023–2025. ABECS’s remote purchase statistics combine online, in-app and wallet payments and do not isolate phone sales, so their growth cannot be used as a proxy for MOTO. The only official series that separates out the phone is CONDUSEF’s in Mexico, and the latest public breakdowns found predate the period:
| CONDUSEF data on “phone commerce” | Value |
|---|---|
| Origin of claims for possible card fraud, Jan–Sep 2017 | 11% phone (49% e-commerce, 34% POS, 3% ATMs) |
| Phone share of traditional fraud, H1 2018 | 30% of 1.44 million claims |
These figures are old, but they show two things. The phone was a significant and measurable fraud channel when the regulator broke it out. And if CONDUSEF still classifies it, a current figure exists, even if no published version could be found.
As e-commerce becomes increasingly authenticated, the economics are simple: fraud seeks out the remote channel with the fewest controls. Today, that channel is the phone call.
From MOTO to ATO: closing the phone channel gap
In markets where cyber fraud claims are growing by 20% a year, as in Mexico, and where e-commerce is increasingly authenticated, phone payments cannot keep working the way they did twenty years ago. Any contact center that takes card payments at meaningful volume concentrates significant risk: a single breach can expose thousands of cards. The channel needs the same standard as the web: card data protected under PCI DSS and, where the risk justifies it, cardholder authentication.
Protecting card data without turning it into a capital project
Until recently, PCI DSS certification for a contact center meant clean rooms, dedicated hardware, network segmentation and an annual assessment by a Qualified Security Assessor (QSA). It is a significant capital cost that recurs every year, and many high-volume operations put it off precisely because of its price.
The model has changed. Cloud-based PCIaaS (Compliance as a Service) platforms now exist: the customer enters their card on the phone keypad, the tones are masked and the card number never reaches the agent, the call recording or the contact center’s systems. Certification scope is reduced to a minimum, custody of the data and responsibility for it move to the certified provider, and capital expenditure (CAPEX) becomes an operating cost (OPEX) priced per transaction, integrated via API with the PSP, contact center platform or BPO the client already uses. This is the approach taken by Pay by Call SL, whose PaybyCall platform, certified to PCI DSS Level 1 and ENS High, runs natively on Google Cloud Platform: resilient, scalable to any country, operating in any language and currency, and live in production in Spain, Mexico and Argentina, among other markets.
Authenticating the payer without breaking the call
Protecting the data is not enough when the amount or the risk profile of a transaction calls for confirming that the payer is the cardholder. Payment links and QR codes work well when the customer is not on the phone. But when the payment arises in the middle of a conversation, taking it out of the channel adds friction at the very moment of closing the sale.
The alternative is to bring EMV 3DS into the call itself. Solutions such as PBC 3DS, Pay by Call’s native authentication method (patent pending), authenticate the payer without leaving the voice channel, whether with a human agent or an AI agent. PBC 3DS is designed to operate within the authentication frameworks set by the card schemes, in a brand-agnostic way for Visa and Mastercard. Its goal is for a phone payment to offer the same identity assurances, for liability shift purposes, as an authenticated online purchase.
PCIaaS protects card data in the contact center and PBC 3DS authenticates the cardholder. Together, they create ATO (Authenticated Telephone Order), turning traditional, insecure MOTO into a secure telephone order.
ATO = PCIaaS + PBC 3DS
What to do now
- Measure by channel. Separate phone payments from web and app payments using the correct channel indicator, and link authentication, authorisation, confirmed fraud and chargebacks for each. Without that breakdown there is no way to know whether the phone channel is absorbing the fraud pushed out of e-commerce.
- Take the card out of the contact center. Assess whether the annual cost of maintaining PCI DSS on in-house systems still makes sense compared with a pay-per-transaction PCIaaS model.
- Authenticate by risk. Define which calls require cardholder authentication (by amount, MCC or risk profile) and confirm with the acquirer the liability treatment they will receive.
- In Brazil, review MCCs and exceptions. Check which group in the Normativo 31 annex the operation falls under, which threshold applies and whether the acquirer has requested any exception from ABECS.
- Demand data from the industry. Networks, acquirers and associations should publish indicators with a clear denominator: eligible payments sent to 3DS, challenge and abandonment rates, issuer approval and fraud by channel and country.
The urgency grows as AI agents arrive in the contact center. When a voice assistant can resolve a query and close a sale in the same call, the payment has to happen right there, without links or QR codes, with the data protected and the cardholder authenticated. That combination of PCIaaS and native voice authentication lays the foundations for Secure Agentic Voice Commerce, which in Latin America is no longer a future scenario but a present need.
Frequently asked questions
Is 3D Secure mandatory in Latin America? Not as a general rule. Brazil is the exception: ABECS’s Normativo 31, an industry self-regulation rule, has required EMV 3DS 2.0 or higher above amount thresholds by merchant category since 17 February 2025. In Mexico, Chile, Colombia, Argentina and Peru there is no mandate; adoption is driven by who bears the fraud when a payment is not authenticated.
What is the difference between PCI DSS and 3D Secure? PCI DSS protects card data: how it is captured, transmitted and stored. 3D Secure authenticates the cardholder: it checks that the person paying owns the card. They are complementary controls and neither replaces the other.
Can a phone payment be authenticated with EMV 3DS? EMV 3DS was designed for web and app purchases. Native voice solutions such as PBC 3DS carry out authentication within the call itself, without links or QR codes. How each transaction is treated depends on the rules of the card scheme, the acquirer and the issuer.
What is ATO (Authenticated Telephone Order)? It is the evolution of traditional MOTO towards a secure phone payment. PCIaaS protects card data in the contact center and PBC 3DS authenticates the cardholder: ATO = PCIaaS + PBC 3DS.
What is PCIaaS and how does it change the cost of compliance? PCIaaS (Compliance as a Service) moves PCI DSS compliance to a certified cloud platform. The contact center no longer invests in clean rooms or dedicated hardware, reduces its certification scope to a minimum and pays per transaction: CAPEX becomes OPEX.
Does it work with AI agents? Yes. Secure capture and native voice authentication work with human agents, IVRs and conversational AI agents alike. This is the foundation of Secure Agentic Voice Commerce.
Is there public data on MOTO payment volumes in Latin America? Not for 2023–2025. The only official series that separates out the phone channel is CONDUSEF’s in Mexico, and its latest public breakdowns found date from 2017 and 2018.
Sources
Figures from providers and industry seminars describe specific portfolios and are not national rates. The absence of a public series does not mean private data does not exist.
- ABECS – 2025 results: R$4.5 trillion on cards and R$1.1 trillion remote
- ABECS – 2025 sector report (PDF)
- ABECS – 3DS 2.0 and Normativo 31/2024
- ABECS – Normativo 31 text (PDF)
- ABECS – 2025 review (2nd edition of Normativo 31)
- Panorama ABECS – 2023 3DS seminar
- Panorama ABECS – 2022 3DS seminar
- Merchant Risk Council – Position paper on Normativo 31
- CONDUSEF – Cyber and traditional fraud, Q4 2023 (PDF)
- CONDUSEF – E-commerce, H1 2024
- CONDUSEF – Card fraud claims, 2017
- CONDUSEF – Financial fraud portal, 2018
- Banco de México – Card transaction rules, 2018 consultation
- BCN – Law 21.234 (Chile)
- Visa – 3D Secure and Peruvian issuer case
- Mastercard – End of EMV 3DS 2.1
- Entersekt – The state of 3D Secure in Latin America
- PCMI – Latin America E-Commerce Blueprint
- PCMI – Payment methods in Latin America
- PCMI – Brazil e-commerce market
- PCMI – Mexico e-commerce market
- Pomelo – Digital payments in Latin America (Argentina and Chile)