Reference⚖️ Disputes & chargebacksIntermediate⏱ 17 min read

🏪 Disputes from the merchant side

Notification, the representment package, win rates, the full cost of a chargeback, Visa and Mastercard monitoring programs, and the MATCH list

Notification and response deadlines

The merchant learns of a chargeback through a notification from its acquirer or PSP. It arrives as a webhook (charge.dispute.created at Stripe, or a Mastercom/VROL notice relayed by the acquirer), a line in the back office, or a letter from a traditional acquirer. By then, the funds have already been debited. The representment clock starts on the chargeback’s clearing date, not when someone reads the notification. Any delay in passing it on eats into the merchant’s response window.

Notification chain
Issuer
Raises the chargeback
VROL (Visa) / Mastercom (Mastercard) / CB network
Scheme
Debits the acquirer at settlement
Day 0 of the response window
Acquirer
Debits the merchant account
amount + fees, sometimes from a reserve
PSP
Notifies the merchant
webhook, email or dashboard, often D+1 to D+3
Merchant
Responds by the PSP deadline
7 to 20 days in practice
NetworkInterbank deadlineTypical merchant deadline set by the PSP
Visa30 days (dispute response)10–20 days
Mastercard45 days (second presentment)15–25 days
Cartes Bancaires (CB)Similar (about 30 days, depending on the reason)10–20 days
Response deadlines: scheme rules vs. PSP practice
⚠️
No response means you accept the loss for good
Once the deadline passes, representment is time-barred, and nothing can reopen it, however strong the evidence. Most teams run on an internal SLA: a response within 5 business days, an alert at D+3 if nothing has happened, and a backup when the disputes lead is out. Cases lost to missed deadlines are the top reason for an artificially low win rate.

Building the representment package

The representment package gathers the evidence the merchant puts forward to rebut the issuer’s reason code. Keep it short, focused on the reason code, and factual: issuer analysts handle dozens of cases an hour. A one-page summary (transaction, reason code, main argument) followed by numbered exhibits beats a raw 40-page log export every time. Volume proves nothing on its own. What matters is how directly each exhibit answers the reason the issuer cited.

Card typeDecisive evidenceSupporting evidence
CNP fraud (10.4 / 4837)3DS result: ECI 05/02, CAVV. The liability shift makes the chargeback invalidAVS/CVV match, device fingerprint, IP consistent with the address, history of undisputed orders (CE 3.0)
Not received (13.1 / 4853)Proof of delivery: signature, geotagged photo, pickup-point collection with IDFull tracking, delivery address = verified address, post-delivery customer messages
Not as described (13.3 / 4853)Exact product description at the time of purchase (timestamped screenshot)Customer service messages, return offer declined, photos of the item shipped
Canceled recurring (13.2 / 4853)Logs showing no cancellation, or a cancellation date after the billing dateTerms accepted (timestamped checkbox), reminder emails before billing, use of the service after the alleged cancellation
Credit not processed (13.6)Proof the credit was issued (refund ARN)Refund policy accepted
Duplicate processing (12.6.x)Two separate orders: different contents, timestamps and addressesCart logs, order IDs
Key evidence by dispute type
  • Login and device logs: IP, user agent, device fingerprint, signed-in customer account. They are decisive in showing that the “fraudster” is a regular customer.
  • Terms and checkout flow: timestamped checkbox, archived version of the terms, confirmation screen. They are essential for 13.5 disputes (misrepresentation) and subscriptions.
  • Customer history: earlier orders shipped to the same address and never disputed. This is the core of Visa’s Compelling Evidence 3.0 (two transactions 120 to 365 days old, with matching identifiers).
  • Customer correspondence: any message in which the customer acknowledges the purchase or delivery ends the dispute.
Submitting the package through the PSP’s API (Stripe example)
# Response to a 10.4 dispute: submit structured evidence.
# Stripe maps the "evidence" fields to the VROL/Mastercom format.

curl https://api.stripe.com/v1/disputes/dp_1NXWPnCZ6qsJgndP \
  -u sk_live_xxx: \
  -d "evidence[customer_name]=John Smith" \
  -d "evidence[customer_email_address]=john.smith@example.com" \
  -d "evidence[customer_purchase_ip]=82.64.113.27" \
  -d "evidence[shipping_carrier]=Colissimo" \
  -d "evidence[shipping_tracking_number]=6A12345678901" \
  -d "evidence[shipping_documentation]=file_1NXWPnCZ6qsJgndP" \
  -d "evidence[access_activity_log]=Account created 2024-03-02, 12 orders delivered to the same address, no disputes" \
  -d "evidence[uncategorized_text]=3DS-authenticated transaction: ECI 05, valid CAVV. Issuer liability shift applies." \
  -d "submit=true"
🔑
Compelling Evidence 3.0: build the case before the dispute
Getting the benefit of CE 3.0 requires collecting data all the time. Device ID, IP, shipping address and account ID must be stored for the long term on every order. The program relies on prior transactions 120 to 365 days old, so the decisive evidence was captured long before the dispute was opened. Merchants that purge their logs after 90 days have no orders left in that window.

Win rates: what to expect

The win rate is the share of representments that end with the funds returned to the merchant. It depends first on the type of dispute and the quality of the evidence. Writing skill comes a distant second. The ranges below come from well-tooled European e-commerce portfolios; a merchant without structured evidence will get markedly lower rates.

CaseTypical win rateDeciding factor
Alleged fraud, 3DS-authenticated transaction70-90 %ECI/CAVV passed correctly
Alleged fraud, CE 3.0-eligible40-65 %Quality of the historical device/IP match
Alleged fraud, no 3DS and no history10-25 %Almost impossible to defend: prevent it up front
Not received, with signed proof of delivery50-70 %Signature or verified pickup vs. a bare “delivered” status
Not as described25-40 %Exact description archived, customer service contacts documented
Canceled subscription (13.2)20-35 %Cancellation logs, reminders before billing
Processing error, wrongly disputed60-80 %Clean accounting reconciliation
Typical net win rate by scenario (representments pursued to the end)
20-45 %
overall net win rate seen across e-commerce portfolios
< 2 %
share of disputes that reach scheme arbitration
43 %
of merchants never fight their chargebacks
industry studies (Chargebacks911, Datos)

A high win rate can reflect case selection rather than a strong defense. A merchant that contests only its best 10% of cases will post an 80% win rate while recovering very little money. The recovery rate corrects for that bias. It divides the amount recovered by the total amount cardholders disputed, and should be read alongside the handling cost of getting it back.

The full cost of a chargeback

The full cost of a chargeback is the refunded amount plus every related loss it triggers. A lost chargeback on a shipped order means the lost goods, fixed fees, handling costs, and a worse score on the monitoring ratios. LexisNexis research (True Cost of Fraud) puts that full cost at 3 to 4 times the face value of the fraud for retailers.

ItemAmountNotes
Amount refunded100 €Clawed back with the first chargeback
Goods≈ 60 €Cost of goods, lost in a fraud case
Outbound shipping (+ return, if any)6-12 €Not recoverable
Acquirer/PSP chargeback fees15-50 €Not refunded in most cases
Handling cost25-40 €Gathering evidence, drafting, follow-up
Program fees, if any0-100 $If the merchant is in VAMP/ECM
Total≈ 210-290 €2.1 to 2.9 × the face value
Cost breakdown of a lost €100 chargeback (shipped physical goods)
⚠️
The hidden cost: lower approval rates
A high dispute ratio also drags down the authorization rate, because issuers score merchants and decline more transactions from those that generate disputes. The revenue lost to these extra declines often exceeds the direct cost of the chargebacks. It shows up in no dispute report, since those only count cases that were actually opened.

Scheme monitoring programs

Beyond per-case fees, the schemes track each merchant’s ratios. Crossing a threshold triggers mandatory remediation plans, escalating monthly fines and, as a last resort, termination of the merchant agreement. Until VAMP replaced them in 2025, Visa ran two separate programs. VDMP covered disputes: the standard threshold was 0.9% of transactions and 100 disputes a month, the excessive threshold 1.8% and 1,000 disputes. VFMP covered fraud: $75,000 in TC40 fraud and a 0.9% ratio at the standard threshold, $250,000 and 1.8% at the excessive threshold.

VAMP programmerchant threshold of 1.5% since April 1, 2026floor of 1,500 events / monthComfort zoneratio below the thresholdsBreach1 month overEnrollmentVAMP · ECM/HECMFines + remediation3 to 6 monthsTermination+ 5 years on MATCHacquirer warning$8 / dispute (VAMP)rising monthly fineonboarding refusedHidden cost: issuers score the merchantover-declining → lost revenue, missing from every dispute reportExit: 3 consecutive months below the thresholdsdeflection and prevention; representment alone won't do itremediationThe fines hit the acquirer, which passes them on and then terminates. MATCH lists the company and its principals.Excluded from the VAMP numerator: disputes resolved at the pre-dispute stage, TC40s that qualify under Compelling Evidence 3.0.
ProgramMetric“Standard” threshold“Excessive” thresholdStatus in 2026
VDMP (legacy)Disputes / transactions in the month0.9% and ≥ 100 disputes1.8% and ≥ 1,000 disputesReplaced by VAMP (April 2025)
VFMP (legacy)TC40 fraud / volume0.9% and ≥ $75,0001.8% and ≥ $250,000Replaced by VAMP (April 2025)
VAMP merchant(TC40 fraud + all TC15 disputes) / settled card-not-present transactions–2.2% at launch, 1.5% since April 2026 (US, EU, Canada, Asia-Pacific)Active; per-dispute penalties above the threshold
VAMP enumerationShare of card-testing attacks (enumeration)–20 %Targets card testing
Visa monitoring: from VDMP/VFMP to VAMP
ProgramEntry criteria (monthly)Penalties
ECM (Excessive Chargeback Merchant)≥ 100 chargebacks and a ratio ≥ 1.5% (this month’s chargebacks / last month’s transactions)Escalating fines from the 2nd consecutive month, roughly $1,000 to $100,000+ a month, plus recovery of issuer costs
HECM (High Excessive Chargeback Merchant)≥ 300 chargebacks and a ratio ≥ 3%Much higher fines, direct pressure on the acquirer
EFM (Excessive Fraud Merchant)≥ 1,000 e-commerce transactions, ≥ $50,000 in fraud, fraud ratio ≥ 0.50%, insufficient 3DS usageMonthly fraud-specific fines
Mastercard monitoring
⚠️
The acquirer takes the penalty, so the acquirer terminates
Scheme fines hit the acquirer, which passes them on to the merchant under the contract and terminates it if the numbers don’t improve within 3 to 6 months. Under VAMP, Visa also monitors the acquirer’s overall portfolio, with its own thresholds. A merchant near the limits can therefore be dropped simply because it drags down its acquirer’s ratio. Effective monitoring relies on internal alert thresholds set below the contractual ones, to leave time to fix the problem.

One point of method on how these ratios are calculated. Scheme ratios are based on counts, disputes divided by transactions, sometimes with a one-month lag. Mastercard, for example, divides chargebacks in month M by sales in month M-1. A month of strong growth therefore lowers the ratio mechanically, and a month of decline pushes it up. A reliable dashboard replicates each scheme’s exact formula rather than an in-house ratio that compares both figures in the same month.

MATCH: the blacklist of terminated merchants

MATCH (Member Alert to Control High-risk Merchants) is Mastercard’s database of merchants whose agreements were terminated for cause. Nearly every acquirer worldwide checks it before onboarding a merchant. A listing stays for 5 years and makes it very hard to open a new merchant account; often only “high-risk” acquirers charging premium rates will take the business. Mastercard now runs it as MATCH Pro, queried through an API, and the principle of a searchable list remains.

CodeReasonExample
01Account data compromiseBreach of PANs stored in clear text
02Common point of purchase (CPP)Terminal or site identified as a source of fraud
03LaunderingProcessing payments for an undisclosed third party
04Excessive chargebacksExit from ECM/HECM without remediation
05Excessive fraudFraud ratio persistently over the limits
07Fraud convictionConvicted executive
09Bankruptcy / liquidationClosed with unpaid debts
10Violation of scheme rulesSale of prohibited products, transaction laundering
12PCI DSS non-complianceRefused to remediate after a compromise
Main MATCH reason codes
⚠️
Executives are listed too
MATCH lists the company and its principal owners or beneficial owners, so setting up a new legal entity does not get anyone off the list. A questionable listing (an error, or a problem since fixed) must be challenged with the acquirer that filed it, the only party that can remove it. Any merchant with a difficult history should therefore check its MATCH status before signing a merchant agreement: a listing discovered during onboarding gets the application rejected on the spot.