Managing fraud internationally. 6 chapters and a final quiz.
A handbook for risk managers who operate across several markets. Build a rule matrix by rail and liability regime, calibrate a threshold on the cost of false positives and false negatives, and run a UK claims desk for authorized push payment (APP) fraud within its five-business-day deadline. Then tune the controls that actually work on instant payments, decide when to turn on 3-D Secure in a market without mandatory strong authentication, and read a decline rate without getting the denominator wrong.
Segment a multi-country portfolio by dominant rail and liability regime, then produce a versioned rule matrix for each market
Calibrate a decision threshold on the measured cost of a false decline and of missed fraud, within the limits set by monitoring programs
Investigate a UK APP fraud claim in line with the mandatory regime’s deadlines, grounds for refusal, and cost sharing
Set the controls on an instant payment rail: payee verification, delays, ramp-up limits, and the recovery window
Chapter 1. Mapping each market before tuning the rules.
A fraud setup is tuned by combination, not by country. The rail that carries the payment, the regime that allocates the loss, and the threshold that penalizes the operator are three separate axes, and they do not line up. The UK and the euro area both run an instant payment rail, under two opposite reimbursement regimes. Neither the US nor Australia requires strong authentication, yet they fall under different monitoring programs. The unit that matters is the combination, not the border.
Four questions to answer before launching in a market
Is the dominant payment method pull or push? A pull instrument leaves a way to dispute after the fact; a push instrument closes the window at settlement
Is there a reimbursement regime, and who funds it? Three possible answers: nobody, the PSP, or a fund recovery process organized by the regulator
Which threshold can penalize me, and how is it calculated? A network program on the card side; data published by the regulator on the transfer side
Which local data feeds my rules? Card issuing country, the age of a proxy identifier, the result of a payee verification check
Who answers the customer, and under what binding deadline? The claims desk belongs to the fraud setup, not to customer service
Market
Priority rail
Mandatory authentication
Reimbursement regime
What the rule must target first
European Economic Area
Card-not-present, then SCT Inst
Yes, SCA by default (PSD2)
No regime dedicated to payer manipulation
Segmentation by issuing country: outside the EEA, the fraud rate is 17 times the domestic rate (EBA / ECB, 2024 data)
UK
Faster Payments Service and CHAPS
Not required by law for transfers
Mandatory since October 7, 2024, split 50/50, capped at £85,000
Desk quality: five business days to decide and give reasons (PSR, PS25/5)
United States
Card, then Zelle, the RTP network, and FedNow Service
No strong authentication requirement
Regulation E, for unauthorized transactions only (12 CFR 1005)
The 3-D Secure challenge policy, decided transaction by transaction
Brazil
Pix
Not required by the regulator on this rail
Fund recovery through the Mecanismo Especial de Devolução
Reporting speed: the refund is executed within 6 hours (Guia MED, Banco Central do Brasil)
India
Unified Payments Interface (UPI) and AePS
UPI PIN entered by the payer, no SCA equivalent
No general reimbursement regime
Ramp-up limits and due diligence on AePS service points (RBI/2025-26/63)
Market launch matrix: what to know before writing the first rule
One rule set per market, versioned and reviewed by the risk committee
A global rule is a rule calibrated on your largest market
A single threshold applied across 10 countries is not neutral. It reproduces the behavior of the market that dominates the training history, with its own carts, customer journeys, and fraud patterns. The other markets inherit a setting they did not produce, and the damage shows up in conversion, not in fraud. So version a rule file per market, with a review date and an owner. A parameter without a named owner never gets fixed.
🎯 Quick question
You are launching in Brazil, where Pix carries most retail payments. What should your fraud rule target first?
Chapter 2. Calibrating a threshold on the cost of both errors.
A decision threshold produces two kinds of error, and they do not cost the same. A false decline destroys a margin and sometimes a customer, while missed fraud costs the order, adds dispute fees, and erodes a monitoring ratio. Calibrating means finding the score at which the marginal costs of the two are equal. That point moves from one market to the next, because unit margin, the administrative cost of a dispute, and the customer’s propensity to retry move with it. A threshold inherited from another country arrives calibrated on three quantities it no longer measures. It is wrong from day one.
A threshold is calculated, not decreed
# calibrate_threshold.py — one threshold per market, recalculated monthly
# on the market's RESOLVED history, never on aggregated history
def total_cost(threshold, history):
false_declines = [t for t in history if t.score >= threshold and not t.fraud]
missed_fraud = [t for t in history if t.score < threshold and t.fraud]
conversion_loss = sum(t.margin * t.p_no_return for t in false_declines)
fraud_loss = sum(t.amount + t.cost_of_goods + DISPUTE_FEE
for t in missed_fraud)
return conversion_loss + fraud_loss
chosen_threshold = min(CANDIDATE_SCORES, key=lambda s: total_cost(s, history_gb))
# Constraint: the network monitoring ratio bounds the result.
# If the optimal threshold breaches the program threshold, it is rejected.
Six parameters to collect, market by market
Unit margin after cost of goods, in local currency: a false decline on a low-margin order costs little
Probability of not returning after a decline, measured on a cohort rather than estimated: it varies widely depending on whether an alternative payment method is available
Administrative cost of a dispute at the local acquirer, network fees included
Recovery rate on funds: high where a refund mechanism exists, zero on a rail with no recourse
Distance to the monitoring threshold in force in the market, which caps the fraud you can tolerate
Case resolution time: an unresolved history overstates the performance of any rule
Program or framework
Scope
Trigger
Effect on calibration
Visa VAMP
Merchants accepting Visa
Ratio of (TC40 fraud + TC15 disputes) to TC05 settled transactions, set at 1.5% from April 1, 2026, in Europe, the US, Canada, and Asia-Pacific; 2.2% maintained in CEMEA
The program threshold becomes the hard cap on the score threshold, whatever the economic optimum
Mastercard ECM
Merchants accepting Mastercard
At least 100 chargebacks in the month and a ratio of at least 1.5%
The dual criterion protects low volumes: below 100 cases, the ratio triggers nothing
Mastercard HECM
Same scope
At least 300 chargebacks and a ratio of at least 3%
A tier of heavier fines: at this stage, calibration is no longer a choice but a constraint
Australian Payments Network
Australian merchants
More than A$50,000 in losses and a 0.2% fraud rate over two consecutive quarters
Two cumulative criteria and a long window: track the limit as a quarterly trend
Payment Systems Regulator
UK PSPs
Publication of APP fraud performance by PSP
The limit triggers a public comparison with peers, not a fine
Binding limits that cap a calibration
$33.4B
global payment card fraud losses in 2024, down 1.2%
Nilson Report, January 2026
0,091 %
card fraud rate for remote sales in the EEA, vs. 0.007% in person
EBA / ECB, 2025 Report on Payment Fraud, 2024 data
1,5 %
“Excessive” merchant threshold in the Visa VAMP program since April 1, 2026, outside CEMEA
Visa, VAMP program, thresholds in effect April 1, 2026
⚠️
The network threshold is a cap, not a target
A dispute ratio of 1.4% does not signal comfortable compliance. It signals 10 basis points of headroom before remediation, fees, and acquirer pressure. The programs are measured over a rolling month, and fraud reporting can lag by more than 30 days. So manage to the projected ratio, not the observed one. A promotion launched on the 20th of the month shows up in the next month’s ratio, when fixing it is already expensive.
🎯 Quick question
In one market, the score threshold that minimizes total cost would push the dispute ratio from 1.2% to 1.7%. What do you decide?
Chapter 3. Running a UK APP claims desk.
The UK reimbursement regime turns authorized push payment fraud into an industrial process. A customer reports, one PSP decides, another pays half, and everything hinges on a short clock and an exhaustive list of grounds for refusal. The regime covers payments executed on the Faster Payments Service and CHAPS since October 7, 2024. A team entering this market first builds a desk that can triage, investigate, and give reasons within the window, and only then builds detection models. The reverse order produces late decisions.
J0
The customer reports the fraud
The claim is eligible up to 13 months after the last payment in the case. The desk timestamps it, identifies the rail, and checks that it falls within scope.
Day 0 + 2 hours
Receiving PSPs notified
Rule 4.1 of the Faster Payments reimbursement rules. The deadline runs in hours, not business days, which requires an automated chain rather than overnight batch processing.
Business days 1 to 5
Investigation and reasoned decision
The sending PSP investigates alone, gathers evidence from the receiving PSP, then reimburses or refuses in writing. The clock can stop while missing information is obtained.
Business day 35 at the latest
Hard deadline
No extension beyond that. A case not decided by then is lost, however strong its merits.
After the decision
Receiving PSP’s contribution
50% of the amount reimbursed, within the deadline set by the scheme rules. Receiving funds therefore commits a budget, not just an account.
Item
Why it determines the outcome
Where it is captured
Timestamp of the report
Starts the five-business-day clock and sets the 13-month time limit
Customer service, channel by channel, including phone calls
Payee verification result
A no-match result ignored by the payer feeds into the gross negligence assessment
Confirmation of Payee service log, kept with the response displayed
Warnings displayed and path followed
The PSP must show what the customer saw, not what the product was designed to show
Timestamped application log, with the screen version served
Vulnerability assessment
Gross negligence cannot be invoked against vulnerable customers
Customer file, with the date and author of the assessment
Evidence from the receiving PSP
The basis for the 50% contribution and for action on the recipient account
Interbank notification channel, opened within two hours
Written reasons for the decision
A refusal without reasons turns into an ombudsman complaint
Versioned letter template, reviewed by compliance
What the case file must contain to withstand a regulatory review
£576.4M
APP fraud losses in the UK in 2025, up 19%
UK Finance, Annual Fraud Report 2026
97 %
reimbursement rate on in-scope claims in the first year
Frontier Economics for the Payment Systems Regulator, July 1, 2026
54 % → 65 %
reimbursement rate across all claims, before and after the regime took effect
Frontier Economics for the Payment Systems Regulator, July 1, 2026
≈ £73M
estimated annual reduction in APP losses attributed to the reimbursement policy
Frontier Economics for the Payment Systems Regulator, July 1, 2026
The gap between these two reimbursement rates is where the work lies. In-scope claims are reimbursed 97% of the time. Across all claims, the rate is 65%. The difference does not reflect resistance from PSPs; it measures out-of-scope cases: cards, international payments, and commercial disputes with a genuine seller. An effective desk therefore checks scope before investigating the merits, and tells the customer the result of that triage at first contact.
🔑
Receiving payments in the UK puts the receiving side on the hook
The 50/50 split makes the PSP that receives the funds a co-payer of the reimbursement. The consequence is budgetary. It can be modeled as a provision per account opened, indexed to onboarding quality and to the history of recorded claims. Track the number of notifications received per recipient account, not just the amount received, because an account that piles up notifications within two hours is a mule account before it is a customer.
🎯 Quick question
A UK customer asks for a refund of a Faster Payments transfer to a seller who did exist but never delivered. How does the desk classify the case?
Chapter 4. Push rails: the controls that actually work.
On a push rail, the victims authenticate the transaction themselves. Biometrics, a PIN, a notification approved in the app: everything works exactly as the product intended. Stronger authentication therefore does not reduce this fraud by a single cent, while the money spent on it shows up in the income statement and never in losses avoided. The controls that work act elsewhere, at three distinct moments. Before the instruction, by checking where the money is going. During the instruction, by slowing down anything newly created. After the instruction, by chasing the funds while they are still somewhere.
Control chain for an outgoing transfer
Adding a payee
Name check before the payee is saved
Confirmation of Payee in the UK; Verification of Payee mandatory on all credit transfers in the euro area since October 9, 2025 (Regulation (EU) 2024/886)
➜
Ramp-up window
Low limit for the first few hours
India’s model: ₹5,000 during the first 24 hours of a UPI ID or a newly linked account (NPCI)
➜
Amount entry
Delay on the first transfer to a new payee
The delay does not prevent the fraud: it breaks the script of an ongoing call, in which the victim is kept from hanging up
➜
Confirmation screen
Context-specific warning, not a generic one
The wording names the risk pattern detected; it is logged with its version because it will serve as evidence if a claim is filed
➜
Execution
Anomalous session detection
Unknown device, active screen sharing, dictated input: behavioral signals, independent of authentication
➜
After settlement
Race to recover the funds
Notify the receiving PSPs, freeze the funds as a precaution, then return whatever is still there
Market
Mechanism
Clock to meet
What falls outside the system
Brazil
Mecanismo Especial de Devolução, mandatory for all Pix participants
Dispute within 80 days, analysis in 7 days, refund request in 72 hours, execution in 6 hours (Guia MED, Banco Central do Brasil)
Funds already moved out of the receiving account; MED 2.0 has extended the freeze to the chain of accounts since February 2026
UK
Mandatory reimbursement regime and interbank notification
Receiving PSPs notified within 2 hours, decision in 5 business days, 35 at most
Cards, international payments, commercial disputes
Euro area
Payee verification before sending; prevention, with no organized refund process
The control applies before the instruction; no harmonized recovery clock afterward
Anything executed despite a no-match warning
United States
No federal mechanism dedicated to manipulation fraud
Credit-push fraud monitoring required by Nacha from March 20, then June 19, 2026
Transactions the customer authorized: Regulation E covers only unauthorized ones
Four markets, four recovery clocks for a fraudulent transfer
Delay rather than block: a block leads to a support call and a new attempt, while a delay breaks the script of a fraudster who keeps the victim on the phone
Cap the ramp-up: the first hours of a payee, a device, or a proxy identifier concentrate the risk, and a limit there costs little in conversion
Log what the customer saw, with the screen version: it is the only usable evidence when a claim is investigated
Monitor the receiving side: incoming notifications per account, how fast the account is drained, onward transfers to a second account within seconds
Put a cost on friction before adding it: a blanket delay on every transfer is paid for in abandoned payments and targets nothing
⚠️
Never promise reversibility the rail does not offer
A checkout paid by instant payment carries no chargeback. Promising a “money-back guarantee” in the checkout flow therefore creates an expectation that is legally false, followed by a claim that cannot be met. The exact wording on screen binds the operator, and the regulator reads it during an inspection. Have that wording approved by local compliance, market by market. Copy translated from a chargeback market imports promises the local rail does not honor.
🎯 Quick question
Your app adds a four-hour delay to the first transfer to a new payee. Which fraud mechanism does this control target?
Chapter 5. Deciding when to authenticate in the US.
No strong authentication requirement applies in the US. There is no exemption to document and no fraud rate to maintain in order to keep the right not to authenticate. 3-D Secure becomes a commercial tool, turned on transaction by transaction. A team coming from the European Economic Area arrives with exactly the wrong reflex: it tries to avoid the challenge. The local question is when a challenge earns more than it costs. The answer is calculated segment by segment, from the liability shift gained and the conversion lost in return.
Transaction segment
Expected gain from a challenge
Expected cost
Default decision
High-value order, unknown device, new shipping address
Liability shift on a transaction where the loss would be heavy
A legitimate customer in a hurry may abandon
Challenger
Repeat customer, known device, clean history
Low: fraud is rare there, and the score already knows it
Direct friction on the most profitable customers
Do not challenge
Card issued outside the US
Real: the cross-border fraud rate is far above the domestic rate
Authentication can fail on the foreign issuer’s side
Challenge above a set amount, monitoring the success rate by issuing country
Digital good delivered instantly, low amount
Modest in value, but the loss is immediate and unrecoverable
High sensitivity to friction for this type of purchase
Do not challenge; control through velocity checks and identifier reputation
Account top-up, transfer to a wallet
High: the classic entry point for cashing out stolen cards
Customers often tolerate an extra step
Challenger
Turning 3-D Secure on or off in a market with no requirement: the decision grid
Signals available here that do not exist everywhere
AVS (Address Verification Service): checks the street number and postal code; usable for US, Canadian, and UK addresses and useless elsewhere, it is often overlooked by European teams
CVV check: decline on a mismatch, a choice to make explicitly rather than inherit from the PSP’s default setting
Network tokens: automatic credential updates and a higher authorization rate, unrelated to cardholder authentication
Regulation Z and Regulation E: they allocate losses between the cardholder and their bank, never to the merchant; no protection extends that far
Network rules: the only ground on which the merchant can defend itself, using whatever proof of delivery and authentication it has kept
$20.877B
losses reported to the FBI's IC3 in 2025, from 1,008,597 complaints
FBI, 2025 Internet Crime Report
$3.047B
business email compromise (BEC) losses in 2025, from 24,768 complaints
FBI, 2025 Internet Crime Report
50 $ / 500 $
cardholder liability for an unauthorized transaction: reported within two business days, then later
Regulation E, 12 CFR 1005
⚠️
On US push credits, the burden shifts to the receiving side
With no federal law on payer manipulation, scheme rules are moving ahead on their own. Nacha is phasing in credit-push fraud monitoring in two waves: March 20, 2026, for originating institutions and large originators, and June 19, 2026, for all receiving institutions, regardless of volume. An operator that collects through ACH in this market therefore becomes accountable for what it receives. The UK adopted the same mechanism through a different legal route.
🎯 Quick question
A US merchant is considering turning on 3-D Secure for all its domestic traffic. What is the strongest objection?
Chapter 6. Comparing decline rates and trading off fraud against conversion.
How you read a decline rate depends on where the payment was rejected. There are four successive rejection points, each controlled by a different party: first the merchant’s filter, then authentication, then the issuer’s authorization, and finally the retry after a decline. The same overall rate of 12% can reflect opposite situations: a filter set too tight in one case, abandoned challenges in another, a wary foreign issuer in a third. The denominator adds its own ambiguity, depending on whether it counts attempts submitted to the network or every cart that reached the payment page. Comparing two markets without this breakdown leads to the wrong conclusion and an expensive decision.
Rejection point
Who decides
What to measure
Lever
Merchant fraud filter
The merchant
Share of attempts stopped before reaching the network, and the fraud rate on accepted ones
The score threshold, calibrated per market on the cost of both errors
Authentication
The issuer, reached through 3-D Secure
Challenge rate, challenge abandonment rate, success rate by issuing country
Exemption policy and quality of the data sent with the request
Authorization
The issuer
Response code distribution, separating hard and soft declines
Recovery rate by response code, within the retry limits set by the networks
Retry a soft decline, never a hard decline
The four rejection points, and the lever that acts on each
A soft decline is not a decline
When an issuer wants authentication on a transaction that has none, it responds with 65 on Mastercard and 1A on Visa and CB. These codes decline nothing. They tell you to resubmit the transaction with 3-D Secure, so a system that does not handle this step-up records as declines what were actually sales. Conversely, retrying a hard decline exposes you to penalties: Visa caps retries at 15 per card over 30 days, with fees beyond that. Retry rules are therefore set by response code, never in bulk.
Segment by issuing country, not by merchant country: in the EEA, a payment whose counterpart is outside the region shows 17 times the domestic fraud rate (EBA / ECB, 2024 data)
Separate volume from value: the ratio between the two varies widely from one instrument to another, and a rate calculated by value cannot be compared with one calculated by count
Date the measurement: fraud reports arrive several weeks late, so a recent ratio always understates the final figure
Distinguish a blocked attempt from a net loss: three figures circulate for the same event, and they do not add up
Measure fraud against the channel, not total revenue: in the EEA, remote sales carry 83% of card fraud but only 28% of value (EBA / ECB, 2024 data)
40 %
share of electronic card payments in the EEA covered by strong authentication, by number of transactions
EBA / ECB, 2025 Report on Payment Fraud, 2024 data
29% and 22%
share of transaction risk analysis and merchant-initiated transactions among remote payments without strong authentication
EBA / ECB, 2024 data
100 / 250 / 500 €
caps on the transaction risk analysis exemption, depending on whether the requesting PSP’s fraud rate is ≤ 0.13%, ≤ 0.06%, or ≤ 0.01%
PSD2 RTS, Delegated Regulation (EU) 2018/389
🔑
The metric to manage by is net margin per attempt
A fraud rate on its own is minimized by declining everything, while a payment success rate on its own is maximized by stopping nothing. The only metric that balances the two divides the margin retained, net of fraud losses and dispute fees, by the number of payment attempts. It is calculated by market, by channel, and by issuing country. A risk committee that tracks this figure stops refereeing between two departments, because fraud and conversion become two terms of the same subtraction.
🎯 Quick question
Your payment success rate drops three points in one market after a score threshold is tightened. What should you look at first?