Skip to main content Skip to main content

Guide · 6 min read

EMV, the liability shift, and why it protects you.

The chip is not a convenience feature. It is a liability instrument, and understanding which way it points is worth real money the first time a counterfeit card lands in your store.

What EMV is

EMV is the global standard for chip cards, named after the original consortium of Europay, Mastercard and Visa. The distinction from the magnetic stripe is not incremental.

A magnetic stripe holds static data. Every transaction transmits the same numbers, so anyone who captures them once can reproduce the card indefinitely. A chip generates a unique cryptogram for each transaction, a one-time code that authenticates that specific card, in that specific moment. Capturing it tells an attacker nothing useful about the next transaction.

This is why counterfeit card fraud collapsed at chip-accepting merchants and concentrated at the ones still swiping.

The liability shift

Before EMV, the issuing bank absorbed counterfeit fraud losses. The liability shift changed the default: whichever party is less EMV-capable now bears the loss.

In practice this means if you accept a chip card by chip, correctly, and it turns out to be counterfeit, the loss sits with the issuing bank. If you swipe a card that had a chip you could have read, the loss sits with you.

That is the entire commercial argument for chip acceptance, and it is a stronger one than most merchants realize.

Chip, contactless, and mobile wallets

Chip dip

The card is inserted and the chip generates its cryptogram. Full EMV protection.

Contactless tap

A tapped card uses the same EMV cryptographic process over NFC rather than through contacts. Same protection, faster.

Apple Pay and Google Pay

Also EMV underneath, with an additional layer: the merchant receives a device-specific token rather than the real card number. From a fraud standpoint these are the strongest transactions you can take.

Magnetic stripe

Static data, no cryptogram, and liability generally sits with you if the card had a chip available.

Technical fallback

Sometimes a chip genuinely cannot be read, a damaged chip, a dirty reader, and the terminal falls back to the stripe. This is legitimate and occasionally unavoidable.

It is also a known fraud technique. Deliberately damaging the chip on a counterfeit card forces fallback to the stripe, where the counterfeit works. A sudden rise in fallback transactions at one location is a recognized fraud pattern, and it is worth monitoring rather than ignoring. If fallback is happening regularly at one terminal, the likeliest explanations are a reader that needs cleaning or replacing, or something you want to know about.

What EMV does not protect

Worth being precise here, because it is widely misunderstood. EMV protects against counterfeit cards in card-present transactions. That is its entire job.

It does nothing for card-not-present fraud, where the physical card is never involved. It does nothing about a genuine card that was physically stolen and used before it was reported. And it does nothing about friendly fraud, where the real cardholder makes a purchase and disputes it later. Those need address verification, security codes, clear billing descriptors, and good records, different tools for different problems.

What to check on your own setup

Confirm every terminal you run is EMV certified and that chip and contactless are both actually enabled, since contactless is sometimes shipped switched off. Train staff that dipping or tapping is the default and swiping is the exception, not a matter of preference. Watch your fallback rate. And keep readers clean, because a large share of fallback transactions are simply dirty contacts.

236.6B

US noncash payments in 2024, over three quarters by card

Source: Federal Reserve Payments Study

$1.57

US average fees per $100 of card volume, 2024

Source: The Nilson Report

Common questions

What does the chip on a card actually do?+

A chip generates a unique one-time code for each transaction, so capturing one tells a thief nothing about the next. A magnetic stripe holds static data that can be copied and reused. That difference is why counterfeit fraud collapsed at chip-accepting merchants.

What is the EMV liability shift?+

Since EMV, whichever party is less chip-capable bears counterfeit fraud losses. If you accept a chip card by chip and it turns out counterfeit, the issuing bank absorbs it. If you swipe a card whose chip you could have read, that loss is yours.

Are tap to pay and Apple Pay as secure as inserting the chip?+

Yes, and often more. Contactless taps use the same EMV cryptography over NFC. Apple Pay and Google Pay add a device-specific token instead of your real card number, which makes them the strongest transactions you can take.

What is EMV fallback and why should I watch it?+

When a chip cannot be read, the terminal falls back to the stripe. That is sometimes legitimate, a damaged chip or dirty reader, but it is also a known fraud trick. A sudden rise in fallback at one terminal is worth investigating, not ignoring.

What does EMV not protect against?+

Counterfeit cards in person only. It does nothing for card-not-present fraud, a genuine card physically stolen and used before it is reported, or friendly fraud where the real cardholder disputes a purchase. Those need AVS, security codes, clear descriptors, and good records.

Every terminal we ship is EMV certified.

Chip, contactless, and mobile wallets enabled out of the box, so the liability shift works in your favor from day one.

Get a Savings Analysis (615) 943-9373

More on merchant services and credit card processing, or read the payments glossary.