Future of Commerce: A Training Program
for AFI Member Institutions
Kuala Lumpur, Malaysia
4-5 July 2019
Nicholas D LeeVP & Head of AP Digital Product
Commercialization
Securing Digital Commerce
©2019 Visa. All rights reserved. 3 | 2019 Security Summit Visa Public
The number of connected devices will be
more than 3x theglobal populationby 2022
Source:: Cisco Visual Networking Index: Forecast and Trends, 2017–2022 White Paper
https://www.cisco.com/c/en/us/solutions/collateral/service-provider/visual-networking-index-
vni/white-paper-c11-741490.html
3 | 2019 Security Summit ©2019 Visa. All rights reservedVisa Public
©2019 Visa. All rights reserved. 4 | 2019 Security Summit Visa Public
63% of all eCommerce payments take place on a mobile in AP
Source: eMarketer, “Worldwide Retail and Ecommerce Sales: eMarketer’s Updated Forecast and
New Mcommerce Estimates for 2016—2021,” Jan 29, 2018
4 | 2019 Security Summit ©2019 Visa. All rights reservedVisa Public
©2019 Visa. All rights reserved. 5 | 2019 Security Summit Visa Public
75% of all eCommerce payments are abandoned globally
Source : Statista 2017 Worldwide, Q4; 500 global brands
5 | 2019 Security Summit ©2019 Visa. All rights reservedVisa Public
©2019 Visa. All rights reserved. 6 | 2019 Security Summit Visa Public
$4.9$6.3
$2.1
$4.3
2018 2023 forecast
Card Present
eCommerce
15%CAGR$7T+
$10T+
5%CAGR
Ecommerce payment
volume is growing
3x faster than in store payments
2018 Actuals based only on Settled Payment Volume processed directly over Visa or certain Visa-Affiliated Networks. CNP defined as ECI codes 2, 5-9; CP defined as all other codes, which is a proxy for ecommerce and may not completely categorize ecommerce volume correctly due to regional differences in reporting. 2023 forecast growth for ecommerce is based off Visa’s 2012-2017 CAGR, averaged with eMarketer’s Worldwide Retail & Ecommerce Sales 2016-2021 forecast of growth. CP 2023 forecast based solely off Visa’s 2012-2017 historical growth. Forward-looking estimates are not guarantees of future performance and should be used for educational purposes only.
©2019 Visa. All rights reserved. 7 | 2019 Security Summit Visa Public
Manual PAN key entry is ~50% of ecommerce
4234 5678 9010 0000
Source: 2018 Visa global card not present data 7 | 2019 Security Summit
Credit Card Number
Expiration Date
05/2022
CVV
***
©2019 Visa. All rights reservedVisa Public
©2019 Visa. All rights reserved. 8 | 2019 Security Summit Visa Public
99%Globally, authorisation rates are lower than in store
Visa authorizations, 2017 Q4, Visa branded cards on Visa Networks, including Interlink
In-Store eCommerce
86%
©2019 Visa. All rights reserved. 9 | 2019 Security Summit Visa Public
Sources: 1) 2018 Visa net data comparing CNP to COF2) Experian, State of Online Shopping Fraud 2019, https://www.experian.com/blogs/ask-experian/the-state-of-online-shopping-fraud
In-Store eCommerce
1x 5xFraud rates higher than in store & growing ~2x faster
©2019 Visa. All rights reserved. 10 | 2019 Security Summit Visa Public
Responsible innovation
Security has to keep moving
at the speed of innovationResponsible innovation
10 | 2019 Security Summit ©2019 Visa. All rights reservedVisa Public
©2019 Visa. All rights reserved. 11 | 2019 Security Summit Visa Public
Visa is focusing on 5 key pillars to Securing Digital Commerce
Visa
Tokenisation
Visa Digital
Commerce Program
Secure Remote
Commerce
Cloud Token
Framework Card on File
Tokenisation
3DS 2.0
11 | 2019 Security Summit ©2019 Visa. All rights reservedVisa Public
©2019 Visa. All rights reserved. 12 | 2019 Security Summit Visa Public
Visa Digital Commerce Program key features provide
Enhanced security
Eliminate PAN entry and storage
Domain restricted network tokens
Device binding and consumer authentication
Utilises increased device data for contextual
risk management
Card art enhances consumer trust
Simplification of digital payments
Stay signed-in for known customer
Future proof across new channels
and devices
Optimal, consistent UX within merchant’s
existing checkout environments
Standards-based implementations
Improved authorisation rates, reduced
abandonment
©2019 Visa. All rights reserved. 13 | 2019 Security Summit Visa Public
Visa Tokenisation
13 | 2019 Security Summit ©2019 Visa. All rights reservedVisa Public
©2019 Visa. All rights reserved. 14 | 2019 Security Summit Visa Public
Visa tokens enhance digital commerce
Card
Art
Device
Binding
Lifecycle
Management
Domain
Controls
Cryptogram
Remove
PAN
©2019 Visa. All rights reserved. 15 | 2019 Security Summit Visa Public
Visa Token journey since its inception
Wearables
Secure
Remote
Checkout
IoT &
Future
Use Cases
P2P
Consumer
& Merchant
QRCard
on File
2014 2015 2016 2017 2018 2019 2020+
Pays &
Wallets
All brand names and logos are the property of their respective owners, are used for identification purposes only, and do not imply product endorsement or affiliation with Visa
©2019 Visa. All rights reserved. 16 | 2019 Security Summit Visa Public
Authorisation rate lift1
3.2%Average
Visa Token performance is clear
1. Authorization approval rate lift for Card Not Present transactions processed as a Token vs. as Non-Tokenized credential. 3.2% average lift (3.2 percentage point increase) across sample of top U.S. merchants accepting Token transactions. Lift calculated by averaging auth rate improvement seen across samples of top merchants
accepting Token transactions via third party Token Requestors with lifts seen by merchants acting as own Token Requestor. (In total, sample included 22 merchants across 6 different Token Requestors.) Source: VisaNet, Jan-March 2019, Brand: Visa. US-Issued Cards at US Merchants. Transactions deduped and controlled to credentials
linked to a provisioned Token and Token auth attempted. Auths excluding Condition Code 51. Auth rate defined as approved count of unique transaction authorizations, divided by total unique transaction auths attempts. Auth rate includes first attempt, as well as subsequent retries on same credential type.
2. Fraud Rate Reduction: Source: VisaNet, Jan-Dec’18, U.S. Issued Cards at all U.S. merchants, Gross Fraud only. Fraud reduction for Card Not Present transactions processed via Token vs. PAN. Fraud reduction calculated across all Token Requestors. Weights for PV($) and Tran Count(#) for TRs was adjusted in accordance with Visa’s data
confidentiality obligations by reducing weight of any TR contributing to more than 50% weight (if any) to 50% and then distributing remaining weight (50%) into other TRs based on their original relative weights.
Note - Authorization and Fraud rate improvement can vary from merchant to merchant due to a variety of factors (including merchant’s existing performance, merchant’s usage of other tools etc.), which could result in a merchant’s auth or fraud benefit being higher or lower than average from this sample.
Fraud count reduction2
67%Average
16 | 2019 Security Summit ©2019 Visa. All rights reservedVisa Public
©2019 Visa. All rights reserved. 17 | 2019 Security Summit Visa Public17 | 2019 Security Summit
Secure Remote Commerce
©2019 Visa. All rights reservedVisa Public
©2019 Visa. All rights reserved. 18 | 2019 Security Summit Visa Public
Three areas of standardisation for the digital world
This document is intended for illustrative purposes only. It contains depictions of a product currently in the process of deployment, and should be understood as a representation of the potential
features of the fully-deployed product. The final version of this product may not contain all of the features described in this presentation. This slide depicts programs, concepts and details under
continuing development by Visa. Any Visa features, functionality, implementation, branding, and schedules may be amended, updated or canceled at Visa’s discretion.
Secure Remote Commerce (SRC)
18 | 2019 Security Summit
Common UX and
acceptance mark
…to enable digital POS
Cardholder
verification methods
Password-free experiences
Common data played
Token Data protection
and management
321
©2019 Visa. All rights reserved
Visa Public
©2019 Visa. All rights reserved. 19 | 2019 Security Summit Visa Public
MultipleIntegrations
and buttons
We’re moving from this…..
Up to
23 steps to checkout
©2019 Visa. All rights reserved. 20 | 2019 Security Summit Visa Public
Cart Page Payment Method
SelectionOrder Review Confirmation Page
illustrative design and SRC Mark
Note: UX/UI shown (including CVM) is a potential extension of EMV SRC specification.
All brand names, logos and/or trademarks are the property of their respective owners, are used for
identification purposes only, and do not necessarily imply product endorsement or affiliation with Visa.
To a simple and secure experience
WE ACCEPT
©2019 Visa. All rights reserved. 21 | 2019 Security Summit Visa Public21 | 2019 Security Summit
Cloud Token Framework
©2019 Visa. All rights reservedVisa Public
©2019 Visa. All rights reserved. 22 | 2019 Security Summit Visa Public
Digital Marketplaces accessed from multiple accounts
A cloud token enables a single experience across devices within an operating system
Music Exercise Food Delivery
Ride Hailing
Video Streaming
Social Utilities Seller Marketplace
©2019 Visa. All rights reserved. 23 | 2019 Security Summit Visa Public
Device Binding
Visa Cloud Token Framework
Issuer Step-Up Capabilities
Consumer Authentication
Enriched Data
End-to-End Secure Scalable Framework for E-commerce Tokenization
23 | 2019 Security Summit ©2019 Visa. All rights reservedVisa Public
©2019 Visa. All rights reserved. 24 | 2019 Security Summit Visa Public24 | 2019 Security Summit
Card on File Tokenisation
©2019 Visa. All rights reservedVisa Public
©2019 Visa. All rights reserved. 25 | 2019 Security Summit Visa Public
Card on File Tokenisation
Recurring / subscription
Transactions
Consumer Initiated
Transactions
Merchant Initiated
Transactions
~ 6% approval rates
~ 2% approval rates~ +8% approval rates
©2019 Visa. All rights reserved. 26 | 2019 Security Summit Visa Public26 | 2019 Security Summit
3DS 2.0
©2019 Visa. All rights reservedVisa Public
©2019 Visa. All rights reserved. Visa confidential27 | 2019 Security Summit
Digital commerce fraud mitigation requires a multi-layered approach
Authentication Tools
• Transaction based
authentication
• Password-less
• Advanced verification
(ie. Biometrics)
• Issuer Authentication
• Stay signed in
• Password-less
• Advanced verification
(ie. Biometrics)
• Issuer Authentication
• Device data
• Secured credentials
• Device binding
• Issuer Authentication
TokenPAN
©2019 Visa. All rights reserved. Visa confidential
©2019 Visa. All rights reserved. 28 | 2019 Security Summit Visa Public
Digital Security Roadmap
ActivityQ2 2019
Apr May Jun
Q3 2019 Q4 2019 Q1 2020 Q2 2020
Subject to Change
Jul Aug Sep Oct Nov Dec Jan Feb Mar Apr May Jun
Card on File
ReadinessOngoing VTS/TR integraton, issuer provisioning and authorisation optimisation
Cloud Token
FrameworkVisa Tech Letter Issuer integration begins
EMVCo common mark
& specifications
Visa Checkout migration begins
SRC
Scale SRC via third party enablers
3DS 2.0AP 3DS 2.0 Activation
Future of Commerce: A Training Program
for AFI Member Institutions
Thank you