Notification and response deadlines
The merchant learns of a chargeback through a notification from its acquirer or PSP. It arrives as a webhook (charge.dispute.created at Stripe, or a Mastercom/VROL notice relayed by the acquirer), a line in the back office, or a letter from a traditional acquirer. By then, the funds have already been debited. The representment clock starts on the chargeback’s clearing date, not when someone reads the notification. Any delay in passing it on eats into the merchant’s response window.
| Network | Interbank deadline | Typical merchant deadline set by the PSP |
|---|---|---|
| Visa | 30 days (dispute response) | 10–20 days |
| Mastercard | 45 days (second presentment) | 15–25 days |
| Cartes Bancaires (CB) | Similar (about 30 days, depending on the reason) | 10–20 days |
Building the representment package
The representment package gathers the evidence the merchant puts forward to rebut the issuer’s reason code. Keep it short, focused on the reason code, and factual: issuer analysts handle dozens of cases an hour. A one-page summary (transaction, reason code, main argument) followed by numbered exhibits beats a raw 40-page log export every time. Volume proves nothing on its own. What matters is how directly each exhibit answers the reason the issuer cited.
| Card type | Decisive evidence | Supporting evidence |
|---|---|---|
| CNP fraud (10.4 / 4837) | 3DS result: ECI 05/02, CAVV. The liability shift makes the chargeback invalid | AVS/CVV match, device fingerprint, IP consistent with the address, history of undisputed orders (CE 3.0) |
| Not received (13.1 / 4853) | Proof of delivery: signature, geotagged photo, pickup-point collection with ID | Full tracking, delivery address = verified address, post-delivery customer messages |
| Not as described (13.3 / 4853) | Exact product description at the time of purchase (timestamped screenshot) | Customer service messages, return offer declined, photos of the item shipped |
| Canceled recurring (13.2 / 4853) | Logs showing no cancellation, or a cancellation date after the billing date | Terms accepted (timestamped checkbox), reminder emails before billing, use of the service after the alleged cancellation |
| Credit not processed (13.6) | Proof the credit was issued (refund ARN) | Refund policy accepted |
| Duplicate processing (12.6.x) | Two separate orders: different contents, timestamps and addresses | Cart logs, order IDs |
- Login and device logs: IP, user agent, device fingerprint, signed-in customer account. They are decisive in showing that the “fraudster” is a regular customer.
- Terms and checkout flow: timestamped checkbox, archived version of the terms, confirmation screen. They are essential for 13.5 disputes (misrepresentation) and subscriptions.
- Customer history: earlier orders shipped to the same address and never disputed. This is the core of Visa’s Compelling Evidence 3.0 (two transactions 120 to 365 days old, with matching identifiers).
- Customer correspondence: any message in which the customer acknowledges the purchase or delivery ends the dispute.
# Response to a 10.4 dispute: submit structured evidence.
# Stripe maps the "evidence" fields to the VROL/Mastercom format.
curl https://api.stripe.com/v1/disputes/dp_1NXWPnCZ6qsJgndP \
-u sk_live_xxx: \
-d "evidence[customer_name]=John Smith" \
-d "evidence[customer_email_address]=john.smith@example.com" \
-d "evidence[customer_purchase_ip]=82.64.113.27" \
-d "evidence[shipping_carrier]=Colissimo" \
-d "evidence[shipping_tracking_number]=6A12345678901" \
-d "evidence[shipping_documentation]=file_1NXWPnCZ6qsJgndP" \
-d "evidence[access_activity_log]=Account created 2024-03-02, 12 orders delivered to the same address, no disputes" \
-d "evidence[uncategorized_text]=3DS-authenticated transaction: ECI 05, valid CAVV. Issuer liability shift applies." \
-d "submit=true"Win rates: what to expect
The win rate is the share of representments that end with the funds returned to the merchant. It depends first on the type of dispute and the quality of the evidence. Writing skill comes a distant second. The ranges below come from well-tooled European e-commerce portfolios; a merchant without structured evidence will get markedly lower rates.
| Case | Typical win rate | Deciding factor |
|---|---|---|
| Alleged fraud, 3DS-authenticated transaction | 70-90 % | ECI/CAVV passed correctly |
| Alleged fraud, CE 3.0-eligible | 40-65 % | Quality of the historical device/IP match |
| Alleged fraud, no 3DS and no history | 10-25 % | Almost impossible to defend: prevent it up front |
| Not received, with signed proof of delivery | 50-70 % | Signature or verified pickup vs. a bare “delivered” status |
| Not as described | 25-40 % | Exact description archived, customer service contacts documented |
| Canceled subscription (13.2) | 20-35 % | Cancellation logs, reminders before billing |
| Processing error, wrongly disputed | 60-80 % | Clean accounting reconciliation |
A high win rate can reflect case selection rather than a strong defense. A merchant that contests only its best 10% of cases will post an 80% win rate while recovering very little money. The recovery rate corrects for that bias. It divides the amount recovered by the total amount cardholders disputed, and should be read alongside the handling cost of getting it back.
The full cost of a chargeback
The full cost of a chargeback is the refunded amount plus every related loss it triggers. A lost chargeback on a shipped order means the lost goods, fixed fees, handling costs, and a worse score on the monitoring ratios. LexisNexis research (True Cost of Fraud) puts that full cost at 3 to 4 times the face value of the fraud for retailers.
| Item | Amount | Notes |
|---|---|---|
| Amount refunded | 100 € | Clawed back with the first chargeback |
| Goods | ≈ 60 € | Cost of goods, lost in a fraud case |
| Outbound shipping (+ return, if any) | 6-12 € | Not recoverable |
| Acquirer/PSP chargeback fees | 15-50 € | Not refunded in most cases |
| Handling cost | 25-40 € | Gathering evidence, drafting, follow-up |
| Program fees, if any | 0-100 $ | If the merchant is in VAMP/ECM |
| Total | ≈ 210-290 € | 2.1 to 2.9 × the face value |
Scheme monitoring programs
Beyond per-case fees, the schemes track each merchant’s ratios. Crossing a threshold triggers mandatory remediation plans, escalating monthly fines and, as a last resort, termination of the merchant agreement. Until VAMP replaced them in 2025, Visa ran two separate programs. VDMP covered disputes: the standard threshold was 0.9% of transactions and 100 disputes a month, the excessive threshold 1.8% and 1,000 disputes. VFMP covered fraud: $75,000 in TC40 fraud and a 0.9% ratio at the standard threshold, $250,000 and 1.8% at the excessive threshold.
| Program | Metric | “Standard” threshold | “Excessive” threshold | Status in 2026 |
|---|---|---|---|---|
| VDMP (legacy) | Disputes / transactions in the month | 0.9% and ≥ 100 disputes | 1.8% and ≥ 1,000 disputes | Replaced by VAMP (April 2025) |
| VFMP (legacy) | TC40 fraud / volume | 0.9% and ≥ $75,000 | 1.8% and ≥ $250,000 | Replaced by VAMP (April 2025) |
| VAMP merchant | (TC40 fraud + all TC15 disputes) / settled card-not-present transactions | – | 2.2% at launch, 1.5% since April 2026 (US, EU, Canada, Asia-Pacific) | Active; per-dispute penalties above the threshold |
| VAMP enumeration | Share of card-testing attacks (enumeration) | – | 20 % | Targets card testing |
| Program | Entry criteria (monthly) | Penalties |
|---|---|---|
| ECM (Excessive Chargeback Merchant) | ≥ 100 chargebacks and a ratio ≥ 1.5% (this month’s chargebacks / last month’s transactions) | Escalating fines from the 2nd consecutive month, roughly $1,000 to $100,000+ a month, plus recovery of issuer costs |
| HECM (High Excessive Chargeback Merchant) | ≥ 300 chargebacks and a ratio ≥ 3% | Much higher fines, direct pressure on the acquirer |
| EFM (Excessive Fraud Merchant) | ≥ 1,000 e-commerce transactions, ≥ $50,000 in fraud, fraud ratio ≥ 0.50%, insufficient 3DS usage | Monthly fraud-specific fines |
One point of method on how these ratios are calculated. Scheme ratios are based on counts, disputes divided by transactions, sometimes with a one-month lag. Mastercard, for example, divides chargebacks in month M by sales in month M-1. A month of strong growth therefore lowers the ratio mechanically, and a month of decline pushes it up. A reliable dashboard replicates each scheme’s exact formula rather than an in-house ratio that compares both figures in the same month.
MATCH: the blacklist of terminated merchants
MATCH (Member Alert to Control High-risk Merchants) is Mastercard’s database of merchants whose agreements were terminated for cause. Nearly every acquirer worldwide checks it before onboarding a merchant. A listing stays for 5 years and makes it very hard to open a new merchant account; often only “high-risk” acquirers charging premium rates will take the business. Mastercard now runs it as MATCH Pro, queried through an API, and the principle of a searchable list remains.
| Code | Reason | Example |
|---|---|---|
| 01 | Account data compromise | Breach of PANs stored in clear text |
| 02 | Common point of purchase (CPP) | Terminal or site identified as a source of fraud |
| 03 | Laundering | Processing payments for an undisclosed third party |
| 04 | Excessive chargebacks | Exit from ECM/HECM without remediation |
| 05 | Excessive fraud | Fraud ratio persistently over the limits |
| 07 | Fraud conviction | Convicted executive |
| 09 | Bankruptcy / liquidation | Closed with unpaid debts |
| 10 | Violation of scheme rules | Sale of prohibited products, transaction laundering |
| 12 | PCI DSS non-compliance | Refused to remediate after a compromise |