EMV

Also known as: Chip card

The global chip-card standard that reduces counterfeit fraud for in-person payments.

EMV (named for Europay, Mastercard, and Visa) is the standard behind chip cards, which generate a unique code per transaction to prevent cloning. Since the EMV 'liability shift', whichever party (merchant or issuer) is least chip-capable bears fraud losses on in-person transactions.

How it works

October 2015 is the date that still costs merchants money in the US. That is when the liability shift landed, and a counterfeit card used at a terminal that cannot read chips became the merchant's loss rather than the issuer's. An old swipe-only reader converts someone else's problem into yours, one chargeback at a time. Any terminal sold today reads chip and contactless as standard, so the exposure is usually legacy hardware nobody replaced.

Dipping a card starts a short conversation between the chip and the terminal. The terminal picks the card's payment application, runs its risk checks, then asks the chip for a cryptogram: a one-time code computed from the amount, a transaction counter, and a key only the issuer can verify. That cryptogram rides up with the authorization request. Because it never repeats, data copied off the card is worthless for the next sale.

EMV is narrower than merchants assume. The chip stops counterfeit cards at the counter and does nothing at all for online fraud, which is exactly where card fraud moved after the shift. Fallback transactions are the other thing to watch. When a chip will not read and staff swipe instead, the sale is flagged as a fallback and carries non-chip liability. Your processor can usually report your fallback count, and a rising one normally means a dirty or failing reader.

Worked example

The same $600 laptop, the same cloned card, two different readers. The clone was made from stolen stripe data, so it has no working chip to dip: at your chip terminal the sale fails or the issuer declines it. On a swipe-only reader it sails through. Then the real cardholder disputes the charge, and you are out the laptop and the $600, plus a chargeback fee commonly between $15 and $40.

Frequently asked questions

Do I still need a chip reader if most customers tap?
You do, and in practice the same terminal does both, because contactless is EMV carried over NFC. Some cards have no contactless antenna, and some issuers ask for a dip on a first use or a high-value sale. A reader that only takes taps will turn away a share of in-person customers, so check the spec covers chip, tap and swipe.
What should staff do when a chip will not read?
Tap first. If the chip still will not read, let the terminal prompt a fallback swipe, and keep in mind that a fallback sale carries the fraud liability of a non-chip transaction. Some acquirers monitor or block them. Repeat failures are a hardware fault, not bad luck, so clean or replace the reader. Keying the card in works as a last resort, though it prices as card-not-present.
Does EMV do anything for my online sales?
Chip hardware and the in-store liability shift do nothing for an online order. EMVCo also publishes EMV 3-D Secure, which is the current version of 3D Secure and does apply online, but that is a separate integration from your terminal. E-commerce needs its own controls: AVS and CVV checks, velocity limits, 3D Secure where you want liability moved to the issuer.

Related terms