EMV Liability Shift: How It Works and Who Pays

The EMV liability shift is a payment network rule that assigns responsibility for counterfeit card fraud to whichever party in an in-person transaction does not support chip technology. If a merchant’s terminal cannot read a chip and the bank issued a chip card, the merchant pays. If the merchant has a working chip terminal and the bank sent out a card with no chip, the issuer pays. Before the shift took effect in October 2015, card issuers absorbed almost all counterfeit fraud losses by default. The rule now puts the loss on the weaker link.1U.S. Payments Forum. EMV Fraud Liability Shift

How the Rule Assigns the Loss

The mechanism is a security gap. A chip card generates a unique cryptographic code for every transaction, so cloning it is effectively useless. Magnetic stripe data is static and can be copied onto a blank card in seconds. The liability shift punishes whoever forced the transaction to rely on the weaker technology.2Mastercard. EMV/Chip Frequently Asked Questions for Merchants

Three scenarios cover almost every dispute:

  • Chip card swiped at a magnetic-stripe-only terminal: the merchant absorbs the counterfeit fraud loss.
  • Non-chip card processed at a chip terminal: the issuer absorbs the loss.
  • Chip card processed correctly at a chip terminal: full cryptographic protection applies, and counterfeit fraud liability stays with the issuer under the traditional chargeback framework.1U.S. Payments Forum. EMV Fraud Liability Shift

The financial hit is larger than the stolen merchandise. A merchant who loses an EMV chargeback typically pays the full transaction amount plus an administrative fee, which runs roughly $15 to $50 depending on the payment processor. Across hundreds of daily transactions on outdated equipment, those fees compound quickly.

What Kinds of Fraud the Shift Covers

Counterfeit Card Fraud

Every major U.S. payment network applies the liability shift to counterfeit card fraud at the point of sale. This is the core case the rule was written for. A criminal copies stolen card data onto a blank card and uses it in a store; if the merchant’s terminal cannot read the chip on a chip-enabled account, the merchant pays.2Mastercard. EMV/Chip Frequently Asked Questions for Merchants

Lost and Stolen Card Fraud

Coverage for lost and stolen cards is narrower and depends on PIN. Visa shifts liability for lost, stolen, or “card not received as issued” fraud when a PIN-preferring chip card is used at a terminal that either lacks chip capability or does not support PIN verification.3Visa. Dispute Management Guidelines for Visa Merchants Mastercard, American Express, and Discover follow a similar approach: since October 2015, they shift lost-or-stolen fraud liability to the merchant when a PIN-preferring chip card is processed on a magnetic-stripe-only terminal or on a chip terminal that does not support PIN entry. If the stolen card does not prefer PIN as its verification method, or the terminal properly supports PIN, the issuer generally keeps the loss.1U.S. Payments Forum. EMV Fraud Liability Shift

Online and Phone Orders Are Outside the Rule

Card-not-present transactions fall outside the EMV hardware framework entirely. No chip reader is involved, so the in-store liability rules do not apply. Online fraud is handled by separate protocols; 3D Secure, used by Visa, Mastercard, and other networks, can shift fraud liability to the issuer when the cardholder completes an extra verification step during checkout. A merchant relying only on the EMV shift for protection against online fraud has none.

Contactless and Mobile Wallets

Tap-to-pay cards and mobile wallets like Apple Pay and Google Pay are covered by the same liability rules as chip-insert transactions. They use tokenization and dynamic cryptograms that provide at least the same security as a chip in a terminal.4U.S. Payments Forum. Understanding Fraud Liability for EMV Contact and Contactless A merchant who is not enabled for contactless and forces a contactless-capable card through a magnetic swipe faces the same liability exposure as one without a chip reader.

One quiet trap: payment networks no longer allow deployment of contactless terminals that use the older Contactless Magnetic Stripe Data (MSD) technology. Merchants with legacy contactless readers must upgrade to contactless EMV, which requires additional certification testing.5U.S. Payments Forum. Payment Network Host and Level 3 Requirements A merchant may think they accept contactless when the hardware actually runs on a deprecated standard that gives no liability protection.

Fallback Transactions

A fallback happens when a chip card is inserted at a chip terminal but the chip cannot be read, so the transaction drops to a magnetic swipe. This is common with damaged chips or malfunctioning readers. Liability for approved fallback transactions generally stays with the issuer, provided the merchant’s system correctly flags the transaction as a fallback in the authorization message.6U.S. Payments Forum. EMV Implementation Guidance – Fallback Transactions

Two limits apply. If the clerk manually keys in the card number after both the chip and stripe fail, the merchant takes on the liability.1U.S. Payments Forum. EMV Fraud Liability Shift And payment networks track fallback rates; merchants with abnormally high volumes may face compliance scrutiny or additional fees. A terminal that constantly fails to read chips is not a functioning chip terminal in the network’s eyes, whatever hardware is installed.

Owning a Chip Terminal Is Not the Same as Chip Protection

Buying a chip-capable terminal is only the first step. The equipment must pass a three-level certification process before it delivers liability protection.

  • Level 1 tests whether the physical chip reader meets EMVCo’s contact and contactless specifications for electrical performance and communication.
  • Level 2 tests whether the terminal’s software kernel correctly processes chip data, handles card authentication, and communicates with the payment application.7EMVCo. What Are EMV Level 1 and Level 2 Testing
  • Level 3 tests the complete transaction path from card through terminal to payment network. This is the acquirer’s responsibility and verifies the whole system works end to end.5U.S. Payments Forum. Payment Network Host and Level 3 Requirements

Level 3 testing is required whenever new hardware, a new payment kernel, or significant software changes are introduced, including when adding contactless EMV to a terminal that previously only handled chip-insert transactions. Merchants adding contactless must also run regression testing on their existing contact chip functionality to confirm nothing broke.5U.S. Payments Forum. Payment Network Host and Level 3 Requirements

A terminal that physically reads a chip but has not completed all three levels can still leave the merchant holding the fraud loss. The network will examine whether chip data was properly transmitted in the authorization and clearing messages. If the terminal garbled the data or omitted required fields, the merchant has chip hardware but not chip protection.

Fighting an EMV Chargeback

When an issuer files an EMV liability shift chargeback, the merchant still has options. The dispute process, called representment, lets the merchant prove the transaction was handled correctly.

For Mastercard, the acquiring bank can challenge the chargeback by showing that the required chip data (specifically the DE 55 data element) was included in the original clearing record, that the transaction did not require online authorization, or that a refund was already processed. Procedural defenses also apply: duplicate chargebacks, missed filing deadlines, or mismatched account and reference data.8Mastercard. Chargeback Guide Merchant Edition

For Visa, the merchant needs to show the transaction took place at a chip-reading device (identified by a terminal entry capability code of 5) and that full chip data was transmitted in the authorization request.3Visa. Dispute Management Guidelines for Visa Merchants Keep transaction logs that capture terminal capability codes and chip data transmission records. Without that documentation, winning a representment is essentially impossible.

Timing is unforgiving. Mastercard requires supporting documentation within eight calendar days of generating a chargeback that needs it, and insufficient detail can result in an automatic loss regardless of the merits.8Mastercard. Chargeback Guide Merchant Edition Most merchants lose winnable disputes not because the terminal failed, but because no one pulled the processing logs in time.