Glossary
3DS · 3-D Secure
A card-scheme authentication protocol that inserts a verification step - such as a one-time password or in-app approval - between the cardholder and their bank during an online payment, to confirm the transaction is authorised by the genuine account holder.
What it means
3-D Secure (3DS) is a technical standard developed under the umbrella of major card schemes - including Visa (where it is branded Verified by Visa) and Mastercard (SecureCode) - to reduce fraud on card-not-present transactions. The "3 domains" refer to the acquiring bank (the merchant's bank), the issuing bank (the cardholder's bank), and the card scheme's infrastructure that connects them. When a transaction is flagged for authentication, the cardholder is redirected or prompted to verify their identity before payment is approved.\n\nThe current generation of the protocol, version 2.x (commonly called 3DS2), replaced the original version and introduced risk-based authentication. Under 3DS2, the issuing bank assesses data points - device fingerprint, transaction history, location - and may approve low-risk transactions silently (a "frictionless flow") without asking the cardholder to do anything. Higher-risk transactions trigger a "challenge flow," which is where the OTP or biometric prompt appears.\n\nLiability for fraud shifts under 3DS: when a transaction is authenticated through the protocol, the financial liability for a subsequent chargeback generally moves from the merchant to the card issuer. This is why merchants in the GCC are increasingly required by their acquiring banks to enable 3DS on their payment gateways.
Why it matters for Gulf-based readers
For expats holding UAE, Saudi, Qatari, Bahraini, Kuwaiti, or Omani-issued debit and credit cards, 3DS authentication is a regulatory expectation, not just a bank preference. The Central Bank of the UAE, SAMA, QCB, CBB, CBK, and CBO have each issued guidance or mandates requiring strong customer authentication on electronic payments. In practice, this means almost every online purchase on a locally issued card will trigger an OTP sent to your registered mobile number. Keeping your registered mobile number current with your bank is essential - an outdated number will block legitimate transactions.\n\nExpats who travel frequently or use VoIP numbers as their primary contact can find OTP delivery unreliable. If you are transacting across borders - for example, paying a foreign merchant while physically outside the GCC - check with your card issuer whether your number is registered for international SMS delivery. Some GCC issuers also support authenticator-app or push-notification approval as an alternative to SMS OTP; see your bank's official mobile banking documentation for what options are available on your specific card.
Related terms
Related guides
This glossary entry is general information for English-speaking expats in the Gulf. It is not personal financial, tax, or legal advice.