get in touch

3DS ACS

  • Reduce fraud with risk-based authentication
  • Increase approval rates with frictionless flow
  • Get operational transparency & monitoring
Book a Call
3ds Access Control Server

FinOn 3D Secure Access Control Server (ACS)

is a scalable cardholder authentication solution for card issuers and processors, built to secure the payment process across e-commerce transactions and internet banking, and to meet EMV 3DS 2.x protocols.

Transaction initiated

Real-time risk analysis

Adaptive authentication

Approved or declined

Built for

Banks

Move beyond SMS-only OTP and cut fraud without compromising the checkout experience.

  • Risk-based, frictionless authentication
  • Multiple challenge methods (OTP, OOB, biometrics) to push for higher approval rates
  • Rule tuning by segment/channel

Fintech Card Issuers

Go live with issuer authentication as a service fast and stay compliant while scaling.

  • Out-of-band approvals via fintech app push for higher completion rates
  • Adaptive authentication based on real-time risk (RBA)
  • Seamless mobile and web user experience

Card Processors & BaaS

Support multiple issuers/BINs with different policies and branding without ops chaos.

  • Multi-issuer, multi-product architecture
  • Centralized rules for issuing and acquiring services
  • Scalable, API-first integration as a single service

Key Features

Multifunctional authentication

Supports multiple authentication methods, including one-click app (OOB), one-time passcodes (OTP), risk-based authentication (RBA), decoupled and non-payment authentication

Risk-based authentication

Advanced RBA rules dynamically determine the required authentication level based on transaction context. The ACS evaluates amount, user behavior, device fingerprinting, and geolocation to apply the most appropriate challenge method.

Flexible whitelisting

Merchant whitelisting lets trusted merchants bypass the challenge for approved transactions. Issuers can easily manage trusted merchants through the administrative interface.

Advanced risk management

Built-in scoring system for real-time security assessment and challenge-type definition. Can operate stand-alone or integrated with external fraud engines.

EMV® 3DS 2.3.1 compliant

Fully approved by EMVCo and certified by major card schemes, including Visa, Mastercard, AMEX. JCB, UnionPay, and mada, ensuring compliance with the latest security standards and protocols

Intuitive admin interface

User-friendly interface with access to RBA settings, system configuration, user management, and transaction search. Includes comprehensive dashboards, logs, and analytics for full operational visibility and security.

Authentication SDK for Mobile Apps
  • Secure multi-factor authentication inside iOS and Android apps
  • Push, biometrics, and OTP support
  • Reduce SMS fraud and improve user experience

Cost-efficient by design

Transparent pricing with no hidden fees or service charges. Open-source technologies significantly reduce licensing and maintenance costs compared to legacy ACS vendors, lowering total cost of ownership.

Advanced customization

Full control over cardholder-facing authentication flows, branding, languages, and challenge logic, letting issuers tailor the experience to different programs, regions, and customer segments.

Why FinOn 3DS ACS

Simple integration

Built-in APIs provide fast, seamless integration with issuer systems, card management platforms, notification service, and fraud engines in the authorization flow.

Modern 3D Secure built for

Speed
Flexibility
Control

Flexible architecture

Built on a modern, scalable Java-based architecture, FinOn ACS supports cloud, on-premise, and hybrid deployments across Linux and Windows, ensuring a highly available, horizontally scalable solution.

Multi-issuer & multi-program ready

Designed for processors and BIN sponsors, this ACS solution supports multiple issuers, programs, and BINs within a single platform, each with independent configurations, policies, and branding.

Frequently Asked Questions

FinOn 3D Secure ACS evaluates each transaction in real time using contextual data such as amount, device and behavioral signals, geolocation, and issuer-defined rules. Based on this assessment, the ACS solution dynamically applies either a frictionless flow or the appropriate challenge, reducing fraud while minimizing unnecessary customer friction.

Authentication rules, thresholds, and challenge logic in FinOn ACS can be configured through an administrative interface without vendor-side development. This lets issuers and processors to quickly adapt authentication behavior to changing fraud patterns, regulatory updates, or business requirements.

Yes. FinOn ACS is designed for multi-issuer and multi-BIN environments, enabling independent configurations, branding, and authentication policies per issuer or card program, all managed centrally within a single deployment.

By applying adaptive checks, FinOn ACS approves low-risk transactions using frictionless flows, while challenges are triggered only when necessary. This improves the checkout experience versus legacy SMS-only methods and lifts overall approval rates.

Yes. FinOn ACS supports EMVCo out-of-band (OOB) authentication and biometric verification through the Authentication SDK, which runs inside your own mobile app. The SDK combines biometric verification (Face ID, fingerprint, device credentials) with the Access Control Server for EMV 3-D Secure flows, letting issuers, fintech apps and wallet providers deliver Strong Customer Authentication without sending the cardholder to an SMS code.

The SDK supports:

  • a) Biometric authentication (Face ID / Touch ID / fingerprint)
  • b) Device-level secure authentication (PIN / pattern)
  • c) App-based confirmation flows
  • d) Push-based transaction confirmation
  • e) Challenge-response flows
  • f) Step-up authentication triggered by ACS
  • g) All methods are compliant with EMV 3DS requirements for challenge flows.

No. The SDK does not store or transmit biometric data.
Verification is performed by the operating system or banking application, and the SDK only receives a success/failure result, which is cryptographically bound to the authentication session.

FinOn offers support for:

  • a) iOS (native Swift/Objective-C)
  • b) Android (Kotlin/Java)
  • c) React Native bridge
  • d) Flutter bridge

This lets issuers and fintech platforms embed the authentication service across app environments, with a consistent cardholder experience for every payment.

They sit on opposite sides of the same transaction. The 3DS Server sits on the merchant side. It initiates authentication, assembles the transaction data, and sends the request to the card scheme's Directory Server. Acquirers, PSPs, gateways and payment orchestrators buy this component. The Access Control Server sits on the issuer side. It receives the authentication request, evaluates the risk, and decides whether to approve the transaction frictionlessly or challenge the cardholder. Banks, card fintechs, processors and BIN sponsors buy this component. They are separately certified, handle different data, and are usually bought by different organisations. If you issue cards, you need an ACS. If you acquire, process or route payments, you need a 3DS Server. If your institution does both, you need both, and they can be configured to communicate directly for on-us transactions, bypassing the Directory Server where scheme rules permit. FinOn provides both. ACS FINON and 3DSS FINON are both approved for EMV 3DS 2.2.0 and 2.3.1.

FinOn ACS supports one-time passcodes (OTP), out-of-band approval through your own mobile app, biometric verification, risk-based frictionless approval, decoupled authentication and non-payment authentication. Methods are configured per card programme, region and customer segment, so different portfolios can use different approaches within one deployment. Biometric and app-based confirmation run through the Authentication SDK embedded in your iOS or Android application, where verification is performed by the operating system or banking app and the ACS receives only a cryptographically bound result. Which method applies to a given transaction is decided by your risk rules, not fixed by the platform. Low-risk transactions can pass frictionlessly with no cardholder interaction at all, while higher-risk ones step up to the challenge method you have configured for that segment.

Do you have any other question?

Ready to see the Full Picture?

Let’s connect - and walk you through a personalized demo.

Your message has been sent.
We will contact you shortly.

Prefer to skip the form?

BOOK A CALL

Prefer to skip the form?

BOOK A CALL

Ready to see the Full Picture?

Let’s connect - and walk you through a personalized demo.

Your message has been sent.
We will contact you shortly.