Reference⚖️ Disputes & chargebacksIntermediate⏱ 15 min read

🛡️ Fraud prevention and tooling

Friendly fraud, rules vs. machine learning scoring, Verifi and Ethoca alerts, 3DS strategy, proactive refunds, and the KPIs to manage by

Friendly fraud: enemy number one

Friendly fraud (first-party misuse in Visa’s terminology) is a chargeback filed by the legitimate cardholder. The purchase really happened, but the cardholder disputes it as fraudulent or not received. Industry estimates (Visa, Datos Insights) converge on 60% to 80% of e-commerce chargebacks. That share changes what anti-fraud work is about. Most of the “fraud” an online merchant sees comes from its own customers’ behavior, not from third parties using stolen cards.

≈ 75 %
of e-commerce chargebacks are friendly fraud
Datos Insights / Visa
60-80 %
range generally cited, depending on the industry
×2–3
repeat behavior: a cardholder who won a dispute files another one
🛒
Cyber-shoplifting
A deliberate dispute to keep both the product and the money. It targets digital goods and products that are hard to trace.
👨‍👩‍👧
Family fraud
A child’s in-app purchase, a subscription taken out by a spouse. The account holder disputes, in good faith, a real household purchase.
❓
Descriptor confusion
An unreadable billing descriptor (SARL WEBCO 75). The cardholder doesn’t recognize their own transaction and checks “fraud.”
😤
Bypassing customer service
The cardholder sees a chargeback as faster than asking for a refund, a sign that the refund process is too slow or hidden.
🔑
The number one fix is free: the descriptor
A clear billing descriptor (well-known brand + city or URL, with dynamic per-product descriptors for marketplaces) eliminates a substantial share of “I don’t recognize this” disputes. The descriptor should match between the checkout page and the statement. Reminder emails sent before each subscription renewal round out the approach, and Visa and Mastercard rules on recurring payments now require them explicitly.

Scoring: rules vs. machine learning

Fraud scoring assigns every transaction a risk score before or during authorization, and that score determines the outcome: approve, decline, 3DS challenge, or manual review. Two approaches coexist and complement each other. Expert rules are readable and take effect immediately. Machine learning models capture correlations humans can’t see (entity graphs, typing speed, device reuse), at the cost of less explainability.

Authorization messageISO 8583 on the network, JSON on the PSP API sideIdentifiersPAN/DPAN · expiration · CVVMerchant contextMID · MCC · descriptor · currencyCardholder contextemail · IP · device · addressesAuthenticationECI · CAVV · TAVVScheme: routing + scoreVisa Advanced Authorization · MC Decision IntelligenceIssuer: rules + modelapproved · declined · soft decline (SCA required)network score addedThe decision hinges on CONSISTENCY across data familiesgeography: BIN · IP · currencyidentity: name · email · cardflagging: ECI ↔ CAVV ↔ MITAn empty field is data too: issuer models treat absence as a risk factor.
CriterionRules engineMachine learning
ImplementationImmediate, by the fraud teamTraining data + iterations
ExplainabilityFull (audit, compliance)Partial (scores, approximate reasons)
New patternsBlind until someone writes the ruleEarly detection if the data network is large
False positivesHigh if rules are too broadGenerally lower at equal detection
Response to attacksExcellent (a rule in 5 minutes)Depends on how often the model is retrained
Best used forGuardrails, regulatory cases, immediate responseBaseline score on 100% of traffic
Rules vs. machine learning
⚡
Stripe Radar
ML trained on the Stripe network and built natively into authorization. Radar for Fraud Teams adds custom rules and manual review.
🧠
Adyen (RevenueProtect)
Scoring built into the platform, rules + ML, fine-grained control of SCA exemptions and 3DS friction.
🕸️
Forter / Riskified
Fully automated decisions with a chargeback guarantee. The provider reimburses the fraud it approved, so risk becomes a contractual cost (roughly 0.4% to 1% of revenue).
✅
Signifyd
Same guarantee model, strong in North American retail. Depending on the contract, it also covers “item not received” friendly fraud.
Excerpt from a rules engine (pseudo-configuration)
# Rules act as fast guardrails around the ML score.
rules:
  - id: card-velocity
    condition: distinct_cards_per_device_24h >= 3
    action: decline
    comment: testing stolen cards (card testing / enumeration)

  - id: geo-mismatch
    condition: ip_country != bin_country AND amount > 150
    action: challenge_3ds
    comment: targeted friction instead of a hard decline

  - id: loyal-customer
    condition: account_age > 180d AND delivered_orders >= 5 AND ml_score < 20
    action: request_tra_exemption
    comment: acquirer TRA exemption if the fraud rate is below the EBA thresholds

  - id: gray-zone
    condition: ml_score between 60 and 85
    action: manual_review
    queue: priority_if_amount > 300
    comment: human review absorbs the model's zone of uncertainty
⚠️
A score is only as good as its feedback loop
Without feeding back actual outcomes (chargebacks received, TC40/SAFE reports, alerts, representments won), any model drifts within a few months. The behavior it was trained on stops matching the behavior it sees. The fix is automated reconciliation that links each transaction to the dispute it generated, and then to the final outcome. This feedback chain determines whether scoring can learn from its own mistakes.

Alerts and deflection: stopping the dispute before the chargeback

Deflection means resolving the cardholder’s dispute before it becomes a formal chargeback. Between the two, there is a 24- to 72-hour window to settle the matter. The Verifi (a Visa subsidiary) and Ethoca (a Mastercard subsidiary) alert networks cover this ground, connected directly to participating issuers. A deflected dispute does not count as a chargeback in monitoring program ratios, with one exception described below. It costs a fraction of what a chargeback costs.

Upstreamclear descriptor, support, reminderOrder InsightConsumer ClarityCDRN / Ethoca24 to 72 h to refundRDRrules-based refundnot closed≈ €0≈ €0alert + amountamount, no feesno dispute createdno dispute createdcounted as a refundnot counted as a disputedeflection failsFormal chargebackimmediate debit + €15 to €50 + scheme countTC40 / SAFE fraud reportissued as soon as the dispute is raised; still counts in the VAMP ratiocloses the dispute and the feescloses the dispute, not the fraudpoint of no return
FrameworkNetworkMechanismIndicative costEffect on ratios
Verifi CDRNVisa (and other networks, depending on the issuer)Alert sent to the merchant, which refunds within 72 hours to avoid the chargeback$20–40 per alertDispute not counted as a chargeback
Verifi Order InsightVisaOrder data sent in real time to the issuer or banking app when the cardholder has doubtsPer request / subscriptionDeflects “I don’t recognize this” disputes before they are filed
Verifi RDRVisaPreset decision rules: automatic refund at the pre-dispute stage, based on amount/MCC/reason code$12–40 per caseNot a chargeback; drops out of the VAMP ratio, except fraud already reported (TC40)
Ethoca AlertsMastercard (and Visa, depending on the issuer)CDRN equivalent: fraud/dispute alert, refund within 72 hours$20–40 per alertDispute not counted as a chargeback
Ethoca Consumer ClarityMastercardOrder Insight equivalent: order details in the banking appPer request / subscriptionUpstream deflection
Overview of deflection tools
How RDR resolves a dispute
Cardholder
Disputes the charge with their bank
issuer participating in the Verifi network
Issuer
Routes the case to Verifi before any chargeback
pre-dispute stage
Verifi
Applies the merchant’s decision rules
e.g., refund if the amount is under €50 and the reason code is fraud
PSP / merchant
Automatic refund issued
no formal chargeback raised
⚠️
You pay for alerts even on winnable disputes
CDRN and Ethoca charge for every alert. That includes disputes the merchant would have won through representment (3DS-authenticated), as well as duplicates where a chargeback is raised anyway after the alert. Under VAMP, a dispute resolved through RDR drops out of the Visa ratio, but the fraud report (TC40) on the same transaction stays in, so an automatic refund does not remove a fraud case from the ratio. RDR rules should therefore target segments that are lost from the start (small amounts without 3DS) rather than provide blanket coverage.

3DS: across the board or targeted?

In the EEA, strong customer authentication (SCA) is mandatory. The merchant’s choice is therefore not “with or without 3DS” but who requests exemptions, and which ones. An authenticated 3DS transaction shifts fraud liability to the issuer (liability shift). A TRA (transaction risk analysis) exemption keeps checkout smooth but leaves liability with whoever requested the exemption. Fine-tuning this setting has a direct impact on conversion.

Browserdevice data (~130 fields)3DS Servermerchant / PSP sideDSscheme directory serverACSissuing bankcollectionAReqAReqFrictionless≈ 90–95% of transactionsChallengeOTP, banking app, biometricsARes = Y (low risk)ARes = CCReq / CResThe customer authenticatesthrough their bankAuthentication successfulliability shift → the issuer bears the fraudRich, consistent data= more frictionless
StrategyFraudConversionWhen to choose it
Across-the-board 3DS (frequent challenges)Minimal, maximum liability shiftLoss of 1 to 5 points, depending on the checkout flow and issuersHigh-fraud industries (digital goods, travel), merchants in a monitoring program, large baskets
Frictionless-first 3DS (rich data, rare challenges)Low, liability shift retainedNearly neutralRecommended default: send as much data as possible in the AReq so the ACS can decide without a challenge
Managed TRA/low-value exemptionsMerchant/acquirer liable for exempted transactionsBest (no redirect at all)Low-risk repeat customers, if the acquirer’s fraud rate stays below the EBA thresholds
3DS strategies compared
  • EBA thresholds for TRA: exemption possible up to €100 if the requesting PSP’s fraud rate is ≤ 13 basis points, €250 if ≤ 6 bps, and €500 if ≤ 1 bp. What counts is the PSP’s rate, not the merchant’s.
  • Low value: exemption under €30, with cumulative counters (5 transactions or €100 in a row) managed by the issuer, which explains “surprise” challenges on small baskets.
  • Measured impact: in France, the rollout of SCA came with a lasting drop in the fraud rate on remote payments, from about 0.27% in the early 2010s to ~0.16% in 2023 (OSMP).
🔑
The liability shift isn’t free
Switching 100% of traffic to 3DS challenges to “never pay for fraud again” costs lost conversions and abandoned carts. That cost often exceeds the fraud it prevents. The optimum is fraud avoided plus chargebacks avoided, minus revenue lost to friction and ACS declines. For most European merchants, it lies in maximizing frictionless flows and challenging only high-risk scores.

Proactive refunds

A proactive refund returns the funds to the customer before their dispute turns into a chargeback. The point is the cost gap between the two outcomes. A refund costs only the amount, while a lost chargeback costs the amount + €15–50 in fees + the hit to the ratio. A proactive refund policy sets out in advance when the merchant refunds without investigating the case.

  • Alert received (CDRN/Ethoca) on a losing case: always refund within 72 hours, since that is what the alert is for.
  • Customer complaint before a dispute (“I’m going to my bank”) on a small amount: refund if fighting it costs more than what is at stake, even if you doubt the customer’s good faith.
  • Confirmed merchant error (duplicate charge, credit note never issued, parcel lost with no proof of delivery): refund immediately. Any representment would be lost, with fees.
  • Anti-abuse limit: cap per customer (cumulative amount, number of goodwill gestures) and track repeat recipients. Proactive refunds must not become a reward for repeat friendly fraud.
ℹ️
Watch out for double refunds
A refund issued after a chargeback has already been raised pays the customer twice, and the amount taken back through the chargeback is not returned. Before any refund on a sensitive case, check the dispute status with the PSP. If a dispute is already open, respond through representment, with proof of the refund where relevant, never with a parallel refund.

The fraud KPIs to track

Managing a fraud prevention setup is an economic trade-off: every euro of fraud avoided has a measurable cost. That cost takes two forms. One is false positives, legitimate sales declined because they could not be told apart from fraud. The other is the cost of the tools that make the distinction. A minimum dashboard therefore tracks four families of metrics: fraud losses, disputes, false positives, and total cost.

The same traffic split across four actions: the goal isn't zero fraud, it's the lowest total cost.rising risk score →low scoremoderatehighcriticalTRA exemptionno frictionfraud: merchantmaximum conversion3DS2 frictionlessdata, 0 customer stepsfraud: issuer3DS cost, 0 frictionForced challengerequired customer stepfraud: issuerchallenge drop-offsDeclineno attemptno fraudlost saleSum to minimizeaccepted fraud + false declines + friction = total costAccepted fraudchargeback + fees + goodsAdded frictioncart abandonmentFalse declinemargin and customer lostFeedback loop: TC40/SAFE + actual dispute outcomewithout it, the model drifts within a few monthsretrains the scoreapproved without frictionfriction addeddeclined, or fraud absorbed
KPIOptionIndicative targetMeasurement trap
Fraud rate (by value)Confirmed fraud amount / volume processedUnder 0.10% (France card-not-present average: ~0.16%)Count TC40/SAFE reports, not just chargebacks
Chargeback rate (by count)Number of chargebacks / number of transactions in the monthUnder 0.65% comfortable; warning at 0.9%, below the 1.5% VAMP/ECM thresholdsReplicate each scheme’s exact calculation (Mastercard uses a one-month lag)
Fraud decline rateTransactions declined by fraud screening / attempts1% to 5%, depending on the industryA low rate is good only if fraud doesn’t rise
False positive rateLegitimate customers declined / fraud declinesUnder 30% of declines (measured by sampling/review)Invisible without test campaigns: a declined customer doesn’t come back to complain
Representment win rateRepresentments won / filed≥ 40% with structured evidenceCross-check with the recovery rate by value
Total cost of fraud(Net losses + dispute fees + tools + team) / revenueUnder 0.3% of revenueInclude estimated revenue lost to over-declining
Benchmark KPIs, formulas, and indicative targets (European e-commerce)
0,053 %
overall card fraud rate in France in 2023, the national benchmark
OSMP
~0,16 %
fraud rate on remote payments (vs. 0.269% in 2013)
OSMP
€175.3B
e-commerce sales in France in 2024: the base that makes every basis point count
FEVAD
🔑
Optimize for profit, not for fraud
You can get a zero fraud rate by declining every transaction, which shows that fraud avoided is not a goal in itself. The metric that matters is net profit after fraud: the margin actually earned, minus fraud losses. Approving a transaction with a 2% probability of fraud still pays if the margin is 30%, because the expected margin on the good transactions exceeds the expected loss on the fraudulent ones. The best fraud teams report their KPI in euros of margin protected rather than as a percentage of fraud avoided. That framing aligns risk with the business.