Liability Shift: What It Means for Chip Cards, 3-D Secure and Chargebacks

A liability shift decides who pays for a fraudulent card sale: the merchant or the card issuer. This guide covers the EMV chip shift at the counter, Visa dispute conditions 10.1 and 10.2, Mastercard reason codes 4870 and 4871, the 3-D Secure shift for online orders, Apple Pay and the "successful liability shift for enrolled card is required" message.

Illustration of a retail checkout with a payment terminal, shopping bag and receipt.

A liability shift is a card network rule that moves the cost of a fraudulent sale to whichever party used the weaker security. In stores, the EMV chip liability shift, in effect in the US since October 2015, makes the merchant pay for counterfeit-card fraud when its terminal couldn't read the chip. Online, 3-D Secure authentication (Visa Secure, Mastercard Identity Check) can move fraud chargebacks from the merchant to the card issuer.

What Does Liability Shift Mean?

Before the shift, the U.S. Payments Forum says, liability for card-present fraud generally sat with card issuers. The networks changed their rules to place fraud liability on the party that had not moved to chip technology. Visa's chip dispute conditions apply only when a transaction "qualifies for the EMV liability shift."

A US merchant meets two separate shifts:

Swipe to see all columns
Chip (EMV) liability shift3-D Secure liability shift
WhereIn person, at the terminalOnline orders
What it coversCounterfeit cards, and for some networks lost or stolen cardsFraud the cardholder says they didn't make
How you keep liability off your booksRead the chipAuthenticate the shopper with 3-D Secure
Visa dispute condition10.1 and 10.210.4
Mastercard reason code4870 and 48714837

Neither shift covers every chargeback. A shopper who says the goods never arrived files a different dispute, and the shift doesn't apply. For how disputes move through the system, see what is a chargeback.

The EMV Liability Shift for Chip Cards

The U.S. Payments Forum, a cross-industry group, says most US payment networks put their EMV fraud liability shifts into effect in October 2015 for point-of-sale transactions. The rule is about a specific fraud: a criminal copies the magnetic stripe data from a real chip card onto a counterfeit card, then swipes it somewhere the chip can't be checked.

Who pays for counterfeit chip-card fraud in the US: a magstripe-only card at any terminal, the issuer; a counterfeit of a chip card at a terminal that can't read chips, the merchant; the same counterfeit at a chip-enabled terminal, the issuer; a properly flagged fallback the issuer approved, the issuer

The Forum's summary table for the networks it lists, Visa and Mastercard included:

Swipe to see all columns
CardTerminalWho pays for counterfeit fraud
Magnetic stripe onlyAny terminalIssuer
Chip cardChip-enabledIssuer
Counterfeit stripe copied from a chip cardCan't read chipsAcquirer and merchant
Counterfeit stripe copied from a chip cardChip-enabledIssuer

What about fallback swipes?

When the chip won't read and the terminal falls back to the stripe, Visa's rules say the fallback sale is the issuer's liability if the issuer approved it, the authorization message identified it as fallback, and correct acceptance procedures were followed. Key-entering the card number is different. The Forum warns that a merchant who keys in a card at the counter is liable for fraudulent transactions.

Fuel pumps came later

Automated fuel dispensers got extra time. In an April 2020 notice, Visa moved its US fuel-pump liability shift from October 1, 2020 to April 17, 2021. Mastercard's Chargeback Guide lists April 16, 2021 for US domestic fuel transactions (MCC 5542) under its lost-or-stolen chip shift.

EMV fraud liability shift: counterfeit vs lost or stolen

The counterfeit shift is the one every major network has. The lost-or-stolen shift is where the networks differ. Per the Forum's 2019 paper, American Express, Discover, Mastercard and PULSE can hold the merchant liable when a stolen PIN-preferring chip card is used at a terminal that can't read the chip or can't take a PIN. Visa's US rules don't: the Forum says there is never any lost-and-stolen liability for a Visa merchant on electronically read face-to-face transactions, whether or not the merchant has EMV.

Visa Liability Shift: Dispute Conditions 10.1 and 10.2

Visa's current rules (18 April 2026 edition) list the US Region's EMV liability shift as covering "all domestic and interregional counterfeit POS and ATM Transactions." That's dispute condition 10.1. Condition 10.2 exists for the lost-or-stolen shift in other regions.

Visa 10.1: EMV Liability Shift Counterfeit Fraud

An issuer can file 10.1 when all of these are true:

  • A counterfeit card was used in a card-present sale, and the cardholder denies making it.
  • The real card is a chip card.
  • The sale didn't happen at a chip-reading device, or the chip was read but the acquirer didn't send the full chip data to Visa.

The dispute is invalid for, among other things, a chip-initiated transaction, a fallback transaction, and (everywhere except Europe) a transaction that contained a token. The issuer has 120 calendar days from the transaction processing date to file.

Visa 10.2: EMV Liability Shift Non-Counterfeit Fraud

10.2 covers a lost, stolen or never-received PIN-preferring chip card used in person at a terminal that couldn't read the chip or wasn't EMV PIN-compliant. Contactless transactions and sales correctly processed at an EMV PIN-compliant device are invalid for 10.2. Given the US Region's counterfeit-only entry in Visa's table, a US merchant mostly meets 10.1.

Chip Liability Shift Chargebacks at Mastercard (4870 and 4871)

Mastercard's Chargeback Guide (Merchant Edition, 13 May 2025) has two chip codes:

  • 4870, Chip Liability Shift. Counterfeit fraud on an EMV chip card, either at a terminal that isn't a hybrid (chip and stripe) terminal, or at a hybrid terminal where the chip data (DE 55) wasn't in the authorization. The issuer has 120 calendar days from the central site business date in most cases.
  • 4871, Chip Liability Shift: Lost/Stolen/Never Received Issue (NRI) Fraud. A PIN-preferring chip card that wasn't in the cardholder's possession, used at a stripe-only terminal, or at a chip terminal without a working PIN pad that can check the PIN. Mastercard's table gives October 1, 2015 as the US domestic start date outside fuel pumps.

Mastercard says 4870 can't be used for a valid chip transaction with chip data sent, a properly identified technical fallback, a mail, phone or e-commerce order, or a properly identified and authorized contactless transaction. 4871 can't be used when online PIN data was sent, or for a contactless sale where the phone verified the shopper (CDCVM).

Worked example: a counterfeit chargeback on a swiped chip card

Maple Street Outfitters is a fictional clothing shop still using an old magnetic-stripe-only terminal. On Monday, March 2, 2026, a shopper buys $1,240 of jackets and boots with a Visa card. The card is a counterfeit: its stripe carries data copied from a real customer's chip card. The sale is approved and its transaction processing date is Tuesday, March 3.

Swipe to see all columns
DateWhat happensRule
March 3, 2026Transaction processedDay 0
April 20, 2026The real cardholder reports the charge; the issuer files dispute 10.1Must be within 120 calendar days, by July 1, 2026
May 20, 2026Last day for the acquirer's pre-arbitration attempt30 calendar days from the dispute processing date

The shop has no defense. The card was a chip card, the terminal wasn't a chip-reading device, and none of Visa's invalid-dispute reasons apply. Maple Street loses the $1,240 sale and the merchandise is gone. Had the same counterfeit been run on a chip-enabled terminal, the Forum's table puts the loss on the issuer. Your processor handles the response with the network, so answer its notice the day it arrives.

A chip-enabled merchant terminal is the defense here.

The 3-D Secure Liability Shift for Online Orders

Chip rules don't protect online orders. Our guide to card-not-present transactions covers the basics of 3-D Secure. This section covers what Visa's rules say about the shift.

What a "successful liability shift" means

Visa ties the shift to the Electronic Commerce Indicator (ECI) value in the authorization request. Acquirers may only use ECI 5 or 6 when the authorization included the Cardholder Authentication Verification Value (CAVV), a code produced by Visa Secure authentication.

Visa Secure and dispute 10.4: ECI 5, authenticated with CAVV sent, a 10.4 dispute is invalid; ECI 6, attempted with CAVV sent, also invalid except on non-reloadable prepaid cards; no 3-D Secure, a 10.4 fraud dispute can apply

Under dispute condition 10.4 (Other Fraud, Card-Absent Environment), Visa lists as invalid:

  • ECI 5, authenticated. The issuer answered with an authentication confirmation using Visa Secure with EMV 3-D Secure, and the CAVV was in the authorization request.
  • ECI 6, attempted. The issuer, or Visa on its behalf, sent an attempt response, meaning the issuer or cardholder wasn't participating in Visa Secure, and the CAVV was included. This doesn't apply to non-reloadable prepaid cards.
  • ECI 5 with a token. A sale using an authenticated payment credential with the token cryptogram (TAVV), where the issuer or token requestor approved a cardholder verification.

Exclusions you can't authenticate around

For US domestic e-commerce, Visa says 10.4 applies "regardless of the Electronic Commerce Indicator value" for merchants with MCC 4829 (wire transfers and money orders), 5967 (adult content), 6051 (non-financial institutions selling foreign currency, cryptocurrency and similar), 6540 (stored-value card purchase or load), 7801 and 7802 (licensed online gambling and racing) and 7995 (betting). Stripe's documentation adds that successful authentication "doesn't guarantee" the shift, and that accounts in a fraud monitoring program may lose it.

Mastercard Identity Check

Mastercard's guide bars reason code 4837 (No Cardholder Authorization) on properly authenticated transactions carrying security level indicator values 211, 212, 215, 217 or 242, naming Identity Check as an example. Ask your payment gateway which values it sends.

Worked example: four online orders, two outcomes

Harbor Candle Co. is a hypothetical online store. In one month, four of its Visa orders come back as 10.4 fraud disputes:

Swipe to see all columns
Order3-D Secure resultAmountOutcome under Visa's rules
AECI 5, authenticated, CAVV sent$420Dispute invalid
BECI 6, attempt, CAVV sent, regular credit card$260Dispute invalid
CECI 6, attempt, non-reloadable prepaid gift card$180Not protected
DNo 3-D Secure$350Not protected

Orders A and B are protected: $420 + $260 = $680. Orders C and D, $180 + $350 = $530, fall to the store unless it wins with evidence, such as the compelling-evidence rules in how to win a chargeback.

"Successful Liability Shift for Enrolled Card Is Required": What It Means

Shoppers see this message when a checkout refuses their card. We checked the 3-D Secure documentation of PayPal, Braintree, Stripe, Checkout.com and Nuvei and didn't find this exact wording in any of them, so we can't tell you which system shows it.

The terms do match 3-D Secure results. In PayPal's documentation, an enrollment status of Y means the card is ready for 3-D Secure, and a LiabilityShift result of NO means "Liability is with the merchant. Do not continue with authorization." A merchant that requires a successful shift on every enrolled card will stop the sale when authentication fails.

If you're the shopper: finish your bank's verification prompt if one appears, or use a different card. Visa's rules don't extend the "attempted" protection to non-reloadable prepaid cards, so a merchant that insists on protection may not get it from one. That doesn't tell you why any particular site refused your card.

Does Apple Pay Shift Liability?

In the store. Visa's rules make a 10.1 counterfeit dispute invalid for a transaction that contained a token, and make 10.2 invalid for contactless transactions. Mastercard bars 4870 on properly identified contactless sales and 4871 on contactless sales verified on the device. The Forum's 2019 paper, which names Apple Pay as a certified app, says a Visa merchant enabled for contact EMV is protected against counterfeit liability regardless of interface. See our tap-to-pay guide.

Online. Stripe's Apple Pay documentation says Apple Pay supports liability shift globally for all the major networks, but for Visa only on devices running iOS 16.2 and above (below that, only for cards issued in Europe). Adyen's documentation says the same about iOS 16.2.

How to Keep the Shift on Your Side

  1. Dip or tap every chip card. Swipe only when the chip fails, and let the terminal flag it as fallback.
  2. Don't key in cards at the counter.
  3. Make sure your acquirer sends full chip data. Visa 10.1 can apply to a chip-read sale when it doesn't.
  4. Turn on 3-D Secure for online orders, and check that your gateway sends the CAVV with ECI 5 or 6.
  5. Decide what to do with unauthenticated orders. Ship, review or decline, knowing the fraud risk stays with you.
  6. Keep records. Save authentication results and delivery proof. More tactics are in our fraud prevention guide, and terms are in the glossary.

This is general information, not legal advice. Card network rules change, and your processing agreement may add its own requirements.

If you're not sure whether your terminals read chips or your gateway runs 3-D Secure, send us a recent statement for a free statement review.

Sources

Frequently Asked Questions

What does liability shift mean?

It's a card network rule that moves the cost of a fraudulent card sale to the party with the weaker security. In stores, a merchant whose terminal can't read chips pays for counterfeit-card fraud. Online, a sale authenticated with 3-D Secure can move fraud chargebacks from the merchant to the card issuer.

When did the EMV liability shift start in the US?

Most US payment networks put their EMV fraud liability shifts into effect in October 2015 for point-of-sale transactions, according to the U.S. Payments Forum. Fuel pumps came later: Visa moved its US fuel-pump date to April 17, 2021, and Mastercard lists April 16, 2021.

What is Visa dispute condition 10.1?

Visa 10.1, EMV Liability Shift Counterfeit Fraud, lets an issuer dispute an in-person sale made with a counterfeit of a chip card when the sale didn't happen at a chip-reading device or full chip data wasn't sent. It is invalid for chip-initiated and fallback transactions, and the issuer has 120 calendar days from the processing date to file.

Does 3-D Secure always protect me from fraud chargebacks?

No. Under Visa's rules, a card-absent fraud dispute (10.4) is invalid for an ECI 5 authenticated sale or an ECI 6 attempted sale with the CAVV sent, but the attempt protection doesn't cover non-reloadable prepaid cards, and some US merchant categories stay exposed whatever the ECI value.

Does Apple Pay shift liability to the issuer?

In stores, Visa's rules make counterfeit disputes invalid for tokenized transactions, and Mastercard bars its chip codes on properly identified contactless sales. Online, Stripe and Adyen say Apple Pay supports liability shift for the major networks, with Visa limited to devices on iOS 16.2 or later.

liability shiftemv liability shift3-D Securechargebackschip cards

About Payment USAโ€™s Founder

Published by Payment USA, a merchant services provider. Our guides and comparisons reflect that commercial perspective.

Chase James

Chase James

CEO, Payment USA

Chase James is the founder and CEO of Payment USA, a merchant services company built on transparency and fair pricing. With over 15 years in the payments industry, Chase has helped thousands of businesses uncover hidden processing fees and switch to honest, interchange-plus pricing.

Contact Chase โ†’

Ready to See What You're Really Paying?

Upload your processing statement and we'll show you โ€” line by line โ€” where markup is hiding and what you could save.

Get My Free Statement Review โ†’
Get Free Savings Review