🎓 CoursesMarkets & internationalAdvanced⏱ 60 min

Managing fraud internationally. 6 chapters and a final quiz.

A handbook for risk managers who operate across several markets. Build a rule matrix by rail and liability regime, calibrate a threshold on the cost of false positives and false negatives, and run a UK claims desk for authorized push payment (APP) fraud within its five-business-day deadline. Then tune the controls that actually work on instant payments, decide when to turn on 3-D Secure in a market without mandatory strong authentication, and read a decline rate without getting the denominator wrong.

Chapter 1. Mapping each market before tuning the rules.

A fraud setup is tuned by combination, not by country. The rail that carries the payment, the regime that allocates the loss, and the threshold that penalizes the operator are three separate axes, and they do not line up. The UK and the euro area both run an instant payment rail, under two opposite reimbursement regimes. Neither the US nor Australia requires strong authentication, yet they fall under different monitoring programs. The unit that matters is the combination, not the border.

Four questions to answer before launching in a market

  • Is the dominant payment method pull or push? A pull instrument leaves a way to dispute after the fact; a push instrument closes the window at settlement
  • Is there a reimbursement regime, and who funds it? Three possible answers: nobody, the PSP, or a fund recovery process organized by the regulator
  • Which threshold can penalize me, and how is it calculated? A network program on the card side; data published by the regulator on the transfer side
  • Which local data feeds my rules? Card issuing country, the age of a proxy identifier, the result of a payee verification check
  • Who answers the customer, and under what binding deadline? The claims desk belongs to the fraud setup, not to customer service
MarketPriority railMandatory authenticationReimbursement regimeWhat the rule must target first
European Economic AreaCard-not-present, then SCT InstYes, SCA by default (PSD2)No regime dedicated to payer manipulationSegmentation by issuing country: outside the EEA, the fraud rate is 17 times the domestic rate (EBA / ECB, 2024 data)
UKFaster Payments Service and CHAPSNot required by law for transfersMandatory since October 7, 2024, split 50/50, capped at £85,000Desk quality: five business days to decide and give reasons (PSR, PS25/5)
United StatesCard, then Zelle, the RTP network, and FedNow ServiceNo strong authentication requirementRegulation E, for unauthorized transactions only (12 CFR 1005)The 3-D Secure challenge policy, decided transaction by transaction
BrazilPixNot required by the regulator on this railFund recovery through the Mecanismo Especial de DevoluçãoReporting speed: the refund is executed within 6 hours (Guia MED, Banco Central do Brasil)
IndiaUnified Payments Interface (UPI) and AePSUPI PIN entered by the payer, no SCA equivalentNo general reimbursement regimeRamp-up limits and due diligence on AePS service points (RBI/2025-26/63)
Market launch matrix: what to know before writing the first rule
One rule set per market, versioned and reviewed by the risk committee
# rules/gb.yaml
market: gb
priority_rail: faster-payments           # push
reimbursement_regime: psr-mandatory      # 50/50, cap 85000 GBP
decision_clock_business_days: 5
controls:
  payee_verification: mandatory          # Confirmation of Payee
  new_payee_delay_h: 4
  first_transfer_cap_gbp: 500
monitored_metric: published_reimbursement_rate

---
# rules/us.yaml
market: us
priority_rail: card                      # pull
reimbursement_regime: none               # Regulation E: unauthorized only
strong_authentication: optional
controls:
  challenge_3ds_if: "amount > 300 USD or unknown device"
  avs_and_cvv: required
monitored_metric: vamp_ratio             # merchant threshold 1.5% from 2026-04-01
🔑
A global rule is a rule calibrated on your largest market
A single threshold applied across 10 countries is not neutral. It reproduces the behavior of the market that dominates the training history, with its own carts, customer journeys, and fraud patterns. The other markets inherit a setting they did not produce, and the damage shows up in conversion, not in fraud. So version a rule file per market, with a review date and an owner. A parameter without a named owner never gets fixed.
🎯 Quick question
You are launching in Brazil, where Pix carries most retail payments. What should your fraud rule target first?