Card Not Present
46.0 What this chapter gives you#
- You will be able to explain why a chip transaction cannot be replayed while an online one is nothing but replayable facts, and why that single difference decides the rest of the chapter.
- You will be able to say what “card not present” actually means — a combination of indicators in an authorisation message, not a fact about where the customer was standing.
- You will be able to describe exactly what the address verification service compares, and why a criminal holding a delivery label defeats it without ever knowing the street name.
- You will be able to read the address verification response codes and explain why
G,U,SandRmean the merchant learned nothing, and what a decline-on-mismatch rule costs in conversion. - You will be able to explain why the shop rather than the bank carries an online fraud loss by default, and why the acquirer is the party of last resort behind it.
- You will be able to state the effect of regulation 77(4)(d) of the Payment Services Regulations 2017 and say why a United Kingdom consumer’s exposure to unauthorised online card fraud is zero rather than £35.
- You will be able to explain why quoting £328.4 million of 2008 card-not-present fraud without the £41.2 billion of online spending behind it is campaigning rather than reporting.
- You will be able to map the three e-commerce indicator outcomes to their liability positions, and name the three limits that cause most disappointment about the liability shift.
- You will be able to say why first-party misuse is invisible at the message layer, and what Compelling Evidence 3.0 does instead of arguing about it.
- You will be able to explain why a billing descriptor that does not resemble the trading name is a fraud problem the merchant manufactured itself, and the cheapest one on the list to fix.
The plain version#
Imagine a members’ club with a very good doorman.
When you arrive in person you hand him your membership card. The card has a small computer inside it. The doorman’s reader asks the card a question, the card does a sum using a secret number that only it and the club’s office know, and hands back an answer. The answer is different every single time. If somebody photographed everything about your card and turned up tomorrow with a perfect copy of the picture, they would still be stuck at the door, because the doorman would ask his question and a picture cannot do a sum.
Now imagine the same club takes bookings by post. You write a letter containing your membership number, the date your membership runs out, and the three-digit code on the back of your card. The club opens it, checks all three against its file, and books you a table.
Everything about that letter is copyable. The membership number does not change. The expiry date does not change. The three-digit code does not change. Anybody who has seen your card, or received one of your letters, or broken into a filing cabinet full of other people’s letters, can write out an identical letter and send it in. The club will read it and it will agree with itself, because all the club can do is check the writing on the page against the writing in its file.
That is the whole problem of buying things on the internet. In a shop the chip does a fresh sum every time. Online there is no chip, no reader, no sum. There is only a page of facts about a card, and facts can be copied.
Nadia buys a pair of running shoes for £48.99 from a British website. The checkout page asks her for five things: the sixteen digits on the front of her card, the expiry date, the three-digit code on the back, her name, and her billing address, which is Flat 4, 27 Bramble Road, Leeds, LS6 2QD.
The shop sends all of that to its bank, which sends it to Nadia’s bank, which does three checks and answers all three in the same breath. Is there £48.99 available and is the card in good standing? Yes. Does the three-digit code match the one we generated? Yes. Does the address match the one we hold on file?
That third check is much weaker than it sounds. The bank does not compare the words. It does not know or care that the street is Bramble Road or the town is Leeds. It pulls out the numbers, the house number and the digits of the postcode, compares them with the digits it holds, and reports whether both agree, one does, or neither does.
So a criminal who has stolen Nadia’s card details does not need to know she lives on Bramble Road. He needs a house number and a postcode, the two least secret things about anybody. They are printed on delivery labels, typed into hundreds of websites, and usually stolen in the same breath as the card number, because the same shopping basket that took the card number also took the address to send the shoes to.
Now the part that decides everything else: who loses the money.
Suppose the transaction was not Nadia. Somebody in another country bought £48.99 of shoes with her card. She sees the line on her statement, does not recognise it, and rings her bank, which puts the £48.99 back into her account. That is not a favour; in the United Kingdom it is the law, and it has to happen quickly. Her bank then tells the shop’s bank it wants the money back. The shop’s bank takes the £48.99 out of the shop’s account and charges the shop a fee for the trouble on top. So the shop has lost the shoes, the £48.99, the postage and the fee. The bank has lost nothing. Nadia has lost nothing.
That asymmetry is the single most important fact in this chapter. In a shop, when the chip does its sum properly, the bank carries the fraud. Online, by default, the shop carries it. Which means everything a merchant does about online fraud, every awkward extra screen, every declined order, every “please confirm this purchase in your banking app”, is a merchant spending its own money to protect its own money.
For decades the easiest way to steal with a card in Britain was to copy the magnetic stripe and make a fake card, or to steal a real card and forge a signature. Then, over 2004, 2005 and 2006, the country replaced signatures with chips and PINs. It worked: between 2004 and 2008 the value of counterfeit card fraud committed in the United Kingdom fell by sixty-eight per cent. The criminals did not retire. They moved. Over the same stretch card-not-present fraud on British cards rose from £72.9 million in 2000 to £328.4 million in 2008, and by 2008 total losses on British cards hit £609.9 million, the highest since 1998, of which fifty-four per cent was card-not-present and only twenty-eight per cent counterfeit.
Squeeze a balloon at one end and the air goes to the other. Security measures rarely destroy fraud. They relocate it, towards whichever door is now cheapest to open.
Finally, there is a kind of card-not-present loss with no criminal in it, and it is the one merchants find hardest to talk about. Sometimes the person who says “I did not buy that” really did buy it. Sometimes a twelve-year-old bought it on a parent’s card. Sometimes a subscription renewed and the customer had forgotten signing up. Sometimes the statement line reads “SP*ORD9931” and the customer genuinely does not recognise their own purchase. And sometimes somebody has worked out that saying “I did not buy that” is a quick way to get free shoes.
At the level of the message that arrives at the shop, every one of those looks identical. They arrive as the same dispute, with the same code, saying the same thing. The industry calls this friendly fraud, or first-party misuse, and nothing in the payment system separates it from the real thing. That is the awkward part.
Where the plain version stops being true#
“Card not present” is not a description of the shopper. It is a set of codes in a message. Whether a card is present is not a physical fact about the room. It is an assertion the acquiring side puts into the authorisation, and the issuer prices, risk-scores and disputes the transaction on the basis of that assertion rather than on reality. A customer can stand at a counter with the card in their hand and still generate a card-not-present transaction, because the shop typed the number into a virtual terminal or the chip reader was broken. Conversely, a subscription renewal at three in the morning with no human near it is card-not-present in the same category as a live checkout, yet treated differently again because it carries an indicator saying the merchant initiated it. The question is never “was the card there?” It is always “what did the message claim, and does the issuer believe it?”
Address verification does not verify an address, and often does not run at all. Two things are hidden. The first is that the check is numeric and partial, so it is defeated by knowing two facts that are barely secret. The second, and more practically important, is coverage: it depends on the issuer supporting it and on the acquiring chain passing the data through. British and American issuers generally do; a great many issuers elsewhere do not, and return a code meaning “not checked” or “not supported”. A merchant selling internationally gets a real answer on some of its traffic and a shrug on the rest, so a rule that declines on mismatch will refuse many honest foreign customers and almost no informed criminals. There is also the mundane failure mode: a cardholder who moved house and never told their bank fails the check on every purchase for years, while being entirely genuine.
The liability shift did not move money. It moved a right to argue, and it did not move it to a bank. What the shift changes is who carries the risk of one category of dispute, under scheme rules that are private contracts, not law. The party carrying the merchant’s risk in practice is the acquirer, because the acquirer is the one the scheme takes the money from. If a merchant with a large fraud problem goes out of business, the chargebacks keep arriving for months and the acquirer pays them from its own capital. That single fact explains behaviour that looks arbitrary from the merchant’s side: rolling reserves, delayed settlement for new merchants, onboarding refusals for high-risk sectors, and the acquirer’s intense interest in a dispute ratio. The acquirer is not being difficult. It is the party of last resort.
“Friendly fraud” is a commercial term, not a legal one, and a meaningful share of it is the merchant’s own fault. No regulation anywhere contains the phrase. In United Kingdom law the customer’s claim is simply that a transaction was unauthorised, and the burden of proving otherwise sits by statute on the payment service provider. The law goes further than most merchants realise: the fact that the instrument was used, as recorded by the bank’s own systems, is expressly stated not to be sufficient in itself to prove the customer authorised it. The merchant who says “the transaction went through, so obviously they authorised it” is making an argument the legislation has already anticipated and rejected. Separately, an unglamorous share of these disputes are caused by the merchant: a descriptor that does not resemble the trading name, a free trial that converts silently, a delivery date that slipped. That is not fraud in any direction. It is bad merchandising producing a fraud-shaped message.
One caution applies to every number below. Published fraud figures are not comparable with each other and often not with themselves. Some count cards or accounts rather than people; some count issuer reports of suspected fraud, which are not confirmed loss; and year-on-year percentages are routinely computed against restated prior-year figures. Every figure below therefore carries its source and its date.
The technical version#
What the message actually says#
A card-not-present transaction is not a distinct protocol. It is an ordinary authorisation request carrying a particular combination of indicators, and everything downstream, from the interchange rate to the dispute rights, keys off them.
The primary indicator is the point-of-service entry mode, carried in ISO 8583 data element 22. The values that matter here are those asserting the card details were not read from the card: manually keyed entry, and electronic commerce. Acquirer specifications commonly assign 01 to manual key entry, 05 to chip, 07 to contactless chip and 81 to electronic commerce, but this is precisely the area where, as Chapter 24 set out, the standard fixes the box number and the parties negotiate the contents. An integrator must read the specification in front of them rather than a table on the internet.
Alongside it sit several other assertions, each changing the commercial and legal treatment:
| Assertion | What it claims | What it changes |
|---|---|---|
| Entry mode | How the card data reached the terminal | Interchange, fraud scoring, dispute rights |
| E-commerce indicator (ECI) | Whether the cardholder was authenticated, and to what degree | Whether fraud liability sits with issuer or merchant |
| MOTO indicator | The order was taken by mail or telephone | Excludes most authentication routes entirely |
| CIT/MIT flag | Whether the cardholder or the merchant initiated this specific transaction | Whether authentication was required at all |
| Recurring/instalment indicator | Part of an agreed series | Availability of an authentication exemption |
A merchant’s fraud position is therefore decided partly by the accuracy of its own integration. One that flags genuine cardholder-initiated e-commerce as merchant-initiated, or sends recurring transactions without the series indicator, will find a liability shift it believed it had does not exist when a dispute arrives. That is among the most common and least discussed causes of lost disputes.
What the merchant can check, and what each check is actually worth#
The Luhn check on the primary account number, described in Chapter 42, involves no network at all: it proves only that the digits are internally consistent, and catches typing errors. The expiry date is likewise static and printed on the card. The issuer identification number is more useful, because it names the issuing institution, country and product, and the mix of card types in an order stream is stable for a real business and unstable for an attacked one.
The card verification code printed on the signature panel, called CVV2 by Visa and CVC2 by Mastercard, is the one static check with real teeth, and the reason is archival rather than cryptographic. The code is not in the magnetic stripe and not in the chip, and PCI DSS prohibits merchants and processors from retaining it after authorisation. A criminal who obtained card data from a merchant’s stored records should therefore not have it; one who copied the physical card, or persuaded the cardholder to read it out, will. The code does not distinguish honest from dishonest. It distinguishes one class of data theft from another, and it is worth exactly that much.
Everything beyond address verification, treated below, is inference rather than verification: network address, device, email address, shipping address, time, basket composition, the velocity of orders sharing any of those, and how it all compares with the merchant’s own history. That is the domain of Chapter 51.
Address verification and its limits#
The address verification service is an issuer-side check invoked as part of authorisation. The acquiring side sends the billing address supplied at checkout; the issuer compares it with the address on the account and returns a single-character result code alongside the authorisation response.
The comparison is not textual. It compares the numeric portion of the street address and the numeric portion of the postcode or ZIP code. Street, town and county names play no part. That was a deliberate decision from an era of noisy address data, where “27 Bramble Rd” and “Flat 4, 27 Bramble Road” had to be treated as the same place, and it has never been revisited.
Each scheme publishes its own code set and they do not agree. The following are the codes a British merchant will meet most often, as published by the schemes and by acquirers at the time of writing in August 2026:
| Code | Meaning |
|---|---|
Y |
Address and postcode both match (five-digit ZIP in the United States) |
A |
Address matches, postcode does not |
Z |
Postcode matches, address does not |
N |
Neither matches |
F |
Visa only: address and postcode both match, United Kingdom domestic |
G |
Non-participating issuer outside the United States; not verified |
U |
Issuer holds no data or the service is unavailable |
S |
Issuer does not support address verification |
R |
System unavailable, retry |
Four properties of this list matter more than the list itself.
First, most of the codes are not answers. G, U, S and R all mean the merchant learned nothing. A rule expressed as “decline on anything other than a full match” therefore declines a large fraction of legitimate international orders, and merchants who write that rule discover it in their conversion figures rather than their fraud figures.
Second, the result arrives with, or after, the authorisation decision, not before it. The issuer may approve a transaction whose address check failed completely, because the two decisions are separate: approval is about funds and card status, the address code is advice. A merchant that rejects on the strength of the code must then reverse or void the authorisation, and if it does not it leaves a hold on a genuine customer’s balance for days. Failing to reverse abandoned authorisations is among the most common defects in a young integration, and it generates complaints that look like fraud disputes and are not.
Third, the check is defeated by the same breach that supplies the card number, because retail data theft almost always yields the billing address in the same record. It is not a defence against an attacker holding a full record; it is a defence against one holding a partial record, which is a real and common situation.
Fourth, it does nothing for digital goods, where there is no shipping address, and is easily neutralised for physical goods by shipping somewhere other than the billing address, which honest customers do constantly. The correct use is therefore not as a gate but as one weighted input, where a mismatch on a high-value first order from an unrecognised device is worth a great deal and a mismatch on a small repeat order from a two-year customer is worth almost nothing.
Who bears the loss, in law and in practice#
In the United Kingdom, the statutory position for consumer card payments is set by the Payment Services Regulations 2017 (S.I. 2017/752), and it is far more favourable to the cardholder than most people working in payments assume. What follows describes the regulations as in force at the time of writing in August 2026; legislation.gov.uk recorded regulation 77 as up to date to 14 August 2026.
Regulation 76(1) requires the payment service provider to refund the amount of an unauthorised transaction and restore the account. Regulation 76(2) requires that refund “as soon as practicable, and in any event no later than the end of the business day following the day on which it becomes aware of the unauthorised transaction”, with a single exception in 76(3) where the provider suspects fraud by its own customer and reports it in writing under the Proceeds of Crime Act 2002.
Regulation 77(1) allows the provider to hold the payer liable for up to £35 of losses arising from a lost, stolen or misappropriated instrument, and 77(3) removes all protection where the payer has acted fraudulently or has failed, with intent or gross negligence, to keep credentials safe.
Then comes regulation 77(4), where card-not-present becomes a special case. Except where the payer has acted fraudulently, the payer is not liable for any losses at all in four situations. Two concern notification. The third is where strong customer authentication was required but the payer’s own provider did not apply it. The fourth, at regulation 77(4)(d), is where “the payment instrument has been used in connection with a distance contract”, subject to narrow exceptions.
An ordinary online purchase is a distance contract. The practical effect is that for a consumer card used to buy something online in the United Kingdom, the £35 excess does not apply at all. The cardholder’s exposure to unauthorised online card fraud is, absent their own fraud, zero. Regulation 77(6) completes the circuit: where strong customer authentication was required but the payee or the payee’s provider did not accept it, that party must compensate the payer’s provider for what it paid out.
Two evidential provisions finish the picture. Under regulation 75(1) the burden of proof is on the payment service provider to show the transaction was authenticated, accurately recorded and unaffected by technical failure. Under 75(3) the use of the instrument as recorded by the provider “is not in itself necessarily sufficient to prove” either that the payer authorised it or that the payer was fraudulent or grossly negligent, and under 75(4) a provider alleging either must give the payer supporting evidence.
Read together, these provisions leave the issuer under a next-business-day refund obligation with a burden of proof it usually cannot discharge cheaply, and therefore with one economically rational response: refund the customer and push the loss down the chain by raising a chargeback. The scheme rules then determine whether the acquirer, and through it the merchant, can push it back. That is how a consumer protection statute becomes a merchant cost line, and it is why the merchant’s true cost of a single fraudulent order is never the order value alone. It is the order value, plus goods and shipping already dispatched, plus the chargeback fee, plus the labour of responding, plus that dispute’s contribution to the ratios described next, plus, over time, the controls bought to prevent it and the revenue lost to honest customers those controls turned away.
The price of the channel#
Card-not-present acceptance is also more expensive to run before any fraud occurs, and the clearest recent United Kingdom illustration is a matter of public regulatory record. Following the United Kingdom’s withdrawal from the European Union, Mastercard and Visa increased interchange fees for card-not-present transactions between the United Kingdom and the European Economic Area on consumer cards, from 0.2 per cent to 1.15 per cent for debit and from 0.3 per cent to 1.5 per cent for credit. The Payment Systems Regulator opened a market review, and its final report concluded that the two schemes were not subject to effective competitive constraint, that the increases were made without regard to the effect on businesses, that no justification for them was identified, and that they were costing United Kingdom businesses an additional £150 million to £200 million a year.
The state of that remedy at the time of writing is worth recording precisely, because it will not stay true. As of the regulator’s page last updated in October 2025, it had decided not to proceed with the interim cap it had consulted on, citing litigation about its powers, and had instead launched a consultation on the methodology for a longer-term cap. No cap was in force. Separately, in March 2025 the government announced its intention to abolish the Payment Systems Regulator and consolidate its functions primarily into the Financial Conduct Authority, with a Treasury consultation closing in October 2025 and legislation expected when parliamentary time allows. Any reader in a later year must check both.
The principle underneath survives regulatory change: card-not-present interchange is higher than card-present interchange, in every scheme and region, because the issuer carries a higher expected fraud cost and prices accordingly. Anything that reduces that cost, above all authentication, tends to be rewarded with a lower rate.
Scheme monitoring: the thresholds that actually discipline a merchant#
Statutory liability determines who pays for a given transaction. Scheme monitoring programmes determine whether a merchant may keep trading at all, and they shape day-to-day behaviour in a fraud team. Visa consolidated its previous Visa Dispute Monitoring Program and Visa Fraud Monitoring Program into a single Visa Acquirer Monitoring Program, VAMP, effective 1 April 2025. It combines fraud reports and disputes into one ratio rather than tracking them separately, and applies at both acquirer portfolio and individual merchant level.
The thresholds below are as reported by acquirers, processors and the Merchant Risk Council at the time of writing in August 2026, and are marked as such deliberately: the Visa Rules are a private document distributed to participants and not published, so no figure here can be cited to a primary public source, and the thresholds have already changed twice since launch.
| Level | Ratio threshold | Minimum volume to enter the programme |
|---|---|---|
| Acquirer, above standard | 0.5 per cent | 1,500 combined fraud and dispute events per month |
| Acquirer, excessive | 0.7 per cent | 1,500 combined fraud and dispute events per month |
| Merchant, excessive (from 1 April 2026) | 1.5 per cent, reduced from 2.2 per cent | 1,500 combined fraud and dispute events per month |
The design consequence is worth stating plainly. Because fraud reports and disputes are combined into one ratio, a merchant with almost no fraud but many “goods not received” disputes can be caught by a fraud programme, and a single large merchant can drag an entire acquirer’s portfolio over a threshold. That is why acquirers monitor individual merchants far more closely than their dispute volumes would seem to justify, and why a merchant that quietly refunds every complaint to keep its ratio down may be acting rationally even while being taken advantage of.
Alongside this, PCI DSS v4.0.1, published in June 2024 and the active version of the standard at the time of writing, brought two requirements out of their future-dated grace period on 31 March 2025. Requirement 6.4.3 requires every script executing on a payment page to be authorised, integrity-assured and inventoried. Requirement 11.6.1 requires a mechanism alerting staff to unauthorised changes to payment page scripts and HTTP headers, evaluated at least weekly. Both exist because the modern route to bulk card data theft is not the merchant’s database but the shopper’s browser, and the control is inventory and integrity rather than detection after the fact, precisely because the merchant’s own server never sees the theft happen. Chapter 48 covers the standard in full.
Displacement: why the internet got worse as the shop got better#
The British chip and PIN migration is the cleanest natural experiment in payment security, because it happened quickly, in one country, with published statistics either side. The figures given in the plain version come from the Office for National Statistics, drawing on data from the UK Cards Association. Of the £609.9 million lost on United Kingdom-issued cards in 2008, £379.7 million was incurred domestically and £230.1 million abroad; the composition was fifty-four per cent card-not-present, twenty-eight per cent counterfeit, nine per cent lost and stolen, eight per cent card identity theft and two per cent mail non-receipt.
Two refinements stop this being a simple morality tale.
The first is that displacement also happened geographically. Counterfeit fraud accounted for fifty-eight per cent of losses incurred abroad on British cards in 2008, because criminals took cloned British magnetic stripes to countries that had not yet migrated to chip. The stripe stayed on the card for years after the chip arrived, precisely so British cards would work abroad, and that compatibility was the vulnerability. Displacement follows the gradient of the weakest reader anywhere in the world that will accept your card.
The second is arithmetic honesty. Card-not-present fraud rose about three hundred and fifty per cent between 2000 and 2008, while the value of online shopping in the United Kingdom rose from £3.5 billion to £41.2 billion, more than tenfold. The fraud rate per pound spent therefore fell substantially while the absolute loss more than tripled. Both statements are true and only one is usually quoted. A book that reports the £328.4 million without the £41.2 billion is not reporting; it is campaigning.
The same pattern is visible today at European scale. The joint European Banking Authority and European Central Bank report on payment fraud published on 15 December 2025, covering data from 2022 to 2024, found card payment fraud seventeen times higher when the payee was outside the European Economic Area, where strong customer authentication is not legally required and frequently is not applied. Total reported payment fraud across the Area rose from €3.4 billion in 2022 to €4.2 billion in 2024, of which fraud on cards issued in the European Union and Economic Area was €1.329 billion, a twenty-nine per cent increase. The report concluded that strong customer authentication remains effective against the fraud types it was designed to defeat, while new types, chiefly the manipulation of legitimate payers into authenticating fraudulent transactions themselves, are rising.
That is confirmed on the British side. UK Finance’s Annual Fraud Report 2026, published on 15 June 2026 and covering 2025, reported remote purchase card fraud losses of £423.5 million on 3.2 million cases, up three per cent by value and thirteen per cent by case count, and explicitly identified criminals compromising one-time passcodes in order to authenticate fraudulent transactions or to enrol stolen card credentials into digital wallets. The preceding edition, published on 28 May 2025, reported 2024 losses up eleven per cent to just under £400 million across nearly 2.6 million cases, and made the same observation. The two do not reconcile arithmetically, because figures are restated between editions, which is routine and legitimate and is exactly why this chapter dates every number. The 2025 edition is consistently reported, in the professional summaries written of it by firms such as TLT and circulated through Lexology, as having found that seventy-five per cent of United Kingdom e-commerce card-not-present fraud occurred at merchants acquired outside the United Kingdom, alongside £154.2 million of card fraud incurred abroad. UK Finance places the full report behind registration rather than publishing it openly, so that particular figure cannot be checked against the primary text, and it is given here on the authority of those summaries rather than of the report itself.
The mechanism to carry away does not date. Authentication closed the route that consisted of replaying stolen static credentials. It did not close the route that consists of persuading the legitimate human to complete the authentication. The defence against the second is not a stronger credential; it is behavioural detection at the issuer, out-of-band confirmation for high-risk actions such as wallet enrolment, and consumer messaging that treats a one-time passcode as something never to be repeated to another person under any circumstances, including to somebody claiming to be the bank.
Liability shift, and what it did to merchant behaviour#
There are two distinct liability shifts in cards and they are routinely confused. The first is the chip liability shift, in the card-present world: where a counterfeit card is used at a terminal that could not read a chip, the party that failed to support the technology bears the fraud. That is the shift that drove terminal replacement.
The second is the authentication liability shift, which applies in the card-not-present world and is the one that matters here. Where a merchant submits a transaction successfully authenticated through 3-D Secure, fraud liability moves from the merchant to the issuer, and the issuer loses the right to raise a chargeback under the fraud reason codes. The mechanism is the e-commerce indicator carried in the authorisation, together with the cryptographic authentication value the authentication produced. The mapping, as documented by acquirers including Worldpay at the time of writing in August 2026, is:
| Visa ECI | Mastercard ECI | Meaning | Liability |
|---|---|---|---|
05 |
02 |
Cardholder fully authenticated | Shifts to issuer |
06 |
01 |
Authentication attempted; card not enrolled or issuer unavailable | Generally shifts, subject to scheme rules |
07 |
00 |
Authentication not performed | Remains with merchant |
Three limits on this shift are load-bearing and are the source of most disappointment.
It covers fraud disputes only. It does not cover “goods not received”, “goods not as described”, “credit not processed” or any other non-fraud condition. A merchant that authenticates every transaction still receives chargebacks, and for many merchants those are the majority.
It does not apply to data-only authentication, where risk data is passed to the issuer to improve approval rates without a full authentication taking place. That is a conversion optimisation, not a liability instrument, and is regularly mis-sold as both.
It does not apply where the merchant, or its acquirer, requested an exemption. If you asked not to authenticate, you cannot claim the protection authenticating would have given you. That is the central trade-off of the modern checkout, and it is a commercial decision made per transaction, at speed, by software.
The behavioural effect over two decades was what an economist would predict. Merchants who could adopt authentication cheaply did so and stopped caring about fraud disputes; merchants who could not, because they took orders by telephone or sold digital goods into markets with poor coverage, stayed exposed and built fraud teams instead. The shift did not reduce fraud by itself. It reallocated the cost of preventing it onto whichever party could prevent it most cheaply, which is what a well-designed liability rule is supposed to do.
Strong customer authentication changed the calculus again by making authentication a legal requirement rather than a competitive option. The rules, set in the Payment Services Regulations 2017 and the associated technical standards, applied from 14 September 2019, but the Financial Conduct Authority granted successive forbearance for card-not-present e-commerce: an industry plan to deliver by 14 March 2021, a six-month extension for the coronavirus crisis, and a further six months announced in 2021 taking the final date to 14 March 2022, which the Authority described as the latest at which it expected full compliance.
Once authentication became compulsory, competition moved to the exemptions, which Chapter 47 treats in full. One belongs here because it prices the whole channel. Under Article 18 of the technical standards, a provider may skip authentication on a remote transaction it identifies as low risk, provided the amount is below an exemption threshold value and its own fraud rate for that transaction type sits at or below a reference rate tied to that threshold. The Annex to Commission Delegated Regulation (EU) 2018/389 sets those out as follows:
| Exemption threshold value | Reference fraud rate, remote card payments | Reference fraud rate, remote credit transfers |
|---|---|---|
| €500 | 0.01 per cent | 0.005 per cent |
| €250 | 0.06 per cent | 0.01 per cent |
| €100 | 0.13 per cent | 0.015 per cent |
The United Kingdom version restates the same three-tier structure in sterling. Article 18 as it stands in the Financial Conduct Authority’s Handbook points to a table set out in an Appendix, and that table, reproduced in the Authority’s own Policy Statement PS19/26 of October 2019, gives exemption threshold values of £440, £220 and £85 against reference fraud rates of 0.01, 0.06 and 0.13 per cent for remote card payments and 0.005, 0.01 and 0.015 per cent for remote credit transfers. The sterling figures look untidy because they are the euro ones converted at the Bank of England’s spot rate on exit day and rounded down to the nearest five pounds, the same method that turned the €30 low-value exemption into £25.
Article 19 computes that fraud rate as the total value of unauthorised or fraudulent remote transactions over the total value of all remote transactions of that type, on a rolling ninety-day basis, covering authenticated and exempted transactions alike. Article 20 requires the exemption to cease if the rate exceeds the reference rate for two consecutive quarters. That is the discipline: a provider using transaction risk analysis aggressively to remove friction is buying conversion with a fraud budget it must account for quarterly.
One dating caution is unavoidable. The retained version of Commission Delegated Regulation (EU) 2018/389 carries, on the United Kingdom statute book at the time of writing, a recorded future effect: revocation by Schedule 1, Part 3 of the Financial Services and Markets Act 2023, as part of the programme replacing assimilated European Union financial services law with rules made by the regulators. The substance is expected to be restated in the Financial Conduct Authority’s own rulebook. Any reader after 2026 must confirm the current instrument before quoting an article number.
First-party misuse: the category the system cannot see#
The industry’s terms are friendly fraud, first-party misuse, first-party fraud and chargeback abuse. Visa’s own documentation uses “friendly fraud or first party misuse” interchangeably; Mastercard’s programme is called First-Party Trust. There is no agreed definition, and no regulatory definition at all.
The reason it is structurally hard rather than merely annoying is that it is invisible at the message layer. A dispute raised because a stranger stole a card and a dispute raised because a customer changed their mind arrive under the same reason code: Visa dispute condition 10.4, “Fraud — Card-Absent Environment”, and Mastercard message reason code 4837, “No Cardholder Authorization”. Nothing in the message distinguishes them, and nothing can, because the distinguishing fact is a state of mind.
The economics finish the job. The issuer is under a next-business-day refund obligation, carries the burden of proof, and is told by regulation 75(3) that its own record of the instrument’s use does not by itself discharge it. Investigating a £48.99 dispute properly costs more than £48.99. So it refunds and charges back, and the merchant, the only party with evidence about what actually happened, is the party furthest from the decision.
Both major schemes have responded with the same architectural idea: replace argument with a deterministic data match.
Visa’s Compelling Evidence 3.0, which took effect on 15 April 2023 as an update to dispute condition 10.4, lets a merchant establish a historical footprint by supplying two prior transactions on the same credential. Per Visa’s merchant readiness documentation of March 2023, those transactions must be at least 120 calendar days old and no more than 365 days old measured from the dispute date, must carry no active fraud report and no active fraud dispute, and must be from the same merchant. At least two of four core data elements must match across all three: user identifier, network address, shipping address, and device identifier or fingerprint; at least one of the two matches must be the network address or the device identifier. Where the criteria are met, liability shifts back away from the merchant. Merchants may respond before a dispute exists, through Verifi’s Order Insight service, or afterwards through their acquirer as a pre-arbitration submission in Visa Resolve Online; the submission may be attempted only once, and the response window is thirty days. Mastercard’s First-Party Trust programme applies the same principle, requiring a match of one element from each of three categories.
Two consequences deserve naming. The first is that it works, because it removes human judgement: a merchant meeting the criteria wins automatically, while one that does not falls back to ordinary representment where the issuer weighs the evidence and the outcome is uncertain. That difference in expected value has turned qualification into a product requirement rather than a dispute-team concern.
The second is that it quietly converts device fingerprinting and client-side network address capture from optional analytics into commercial necessities, because those are the two elements a merchant cannot reconstruct after the event and one must be present to qualify. A server-side log of the address that received the checkout request often records a load balancer or content delivery network edge rather than the customer. The privacy consequence is real and rarely discussed: a scheme dispute rule has, in effect, mandated persistent device identification across the retail internet.
The scale is not precisely measurable, for the definitional reasons given, but the direction is not in doubt. The Merchant Risk Council’s 2026 Global eCommerce Payments and Fraud Report, released on 18 March 2026 and drawn from 1,278 merchant professionals in 37 countries, found sixty-four per cent of merchants reporting increasing rates of first-party misuse, a quarter of those reporting increases of twenty-five per cent or more, while the average number of distinct fraud attack types fell from 4.2 to 3.7. More attacks of one kind, fewer kinds of attack: the profile of a maturing threat.
And it must be said, because merchants rarely say it, that a substantial share of first-party misuse is manufactured by the merchant. A billing descriptor that does not match the trading name produces disputes from customers who genuinely do not recognise the charge, and descriptor drift between the initial charge and the renewal also breaks the scheme’s own merchant-matching logic and disqualifies the merchant from the remedy. A free trial that converts without a reminder produces disputes. A dispatch date that slips produces disputes filed under fraud codes, because that is what the banking app offers first. None of that is fraud. It is a merchandising problem wearing a fraud problem’s clothes, and it is the cheapest thing on this list to fix.
What a competent card-not-present programme actually looks like#
The working model is a constrained optimisation rather than a defence. The merchant minimises fraud losses plus dispute handling cost plus revenue lost to declined honest customers, subject to keeping its combined fraud and dispute ratio below the scheme threshold and its fraud rate low enough that its acquirer can keep claiming risk-based exemptions on its behalf. Every control buys one of those terms at the price of another.
Velocity limits and per-issuer throttling belong in that stack for a reason worth naming: a decline is not a neutral outcome. It is an answer, and an endpoint that answers quickly and often is itself a source of information to somebody testing stolen numbers in bulk, which is why scheme monitoring now treats that testing traffic as a category of its own.
None of these controls is optional in a serious operation and none is sufficient. The internet remains the hard case not because any single defence is weak, but because the underlying credential, sixteen digits and an expiry date, is a static secret that must be shared with every party the cardholder transacts with, and a secret shared with thousands of parties is not a secret. Everything in this chapter is a compensating control for that one architectural fact. The two developments that attack the fact itself are network tokenisation, which replaces the shared number with a merchant-specific or device-specific one, and authentication, which adds a dynamic element to a static exchange. Chapter 45 covered the first. Chapter 47 covers the second.
46.98 Common wrong ideas#
Wrong: “Card not present” describes a shopper who was not in the shop. Right: It is an assertion the acquiring side puts into the authorisation message, so a customer standing at the counter can generate one when the chip reader is broken and the number is typed into a virtual terminal.
Wrong: Address verification verifies the address. Right: It compares only the numeric portion of the street address and the numeric portion of the postcode, so street, town and county names play no part and two barely secret facts defeat it.
Wrong: A full address match is a meaningful gate, so decline everything else. Right: Most of the code set means the check did not run, and a rule expressed that way declines a large fraction of legitimate international orders while stopping almost no informed criminal.
Wrong: The address result arrives in time to prevent the authorisation. Right: It arrives with or after the authorisation decision, so a merchant rejecting on it must reverse or void the hold, and failing to do so generates complaints that look like fraud disputes and are not.
Wrong: The liability shift moves the loss to a bank. Right: It moves a right to argue under private scheme rules, and the party actually carrying the merchant’s risk is the acquirer, which is why rolling reserves, delayed settlement and onboarding refusals exist.
Wrong: “Friendly fraud” is a recognised legal category. Right: No regulation anywhere contains the phrase; in United Kingdom law the claim is simply that a transaction was unauthorised, and the burden of proving otherwise sits by statute on the payment service provider.
Wrong: The transaction went through, so obviously the customer authorised it. Right: Regulation 75(3) expressly states that use of the instrument as recorded by the provider is not in itself necessarily sufficient to prove authorisation, so that argument has already been anticipated and rejected.
Wrong: Authenticating every transaction ends chargebacks. Right: The authentication liability shift covers fraud disputes only, and for many merchants “goods not received”, “not as described” and “credit not processed” are the majority.
Wrong: Data-only authentication buys the liability shift more cheaply. Right: Passing risk data to the issuer to improve approval rates is a conversion optimisation, not a liability instrument, and it is regularly mis-sold as both.
Wrong: Published fraud figures can be compared year on year straight out of the report. Right: Some count cards rather than people, some count suspected rather than confirmed fraud, and percentages are routinely computed against restated prior-year figures, which is why every number in this chapter carries its date.
46.99 Chapter summary in 20 lines#
- In a shop the chip does a fresh sum every time; online there is no chip, no reader and no sum, only a page of facts about a card, and facts can be copied.
- Every element the checkout asks for — number, expiry, code, name, billing address — is static, and a criminal who has any complete record has all of them.
- “Card not present” is not a physical condition but a set of indicators in the authorisation, chiefly the point-of-service entry mode in ISO 8583 data element 22.
- Entry mode, the e-commerce indicator, the mail-order flag, the cardholder-or-merchant-initiated flag and the recurring indicator each alter interchange, fraud scoring and dispute rights.
- A merchant that mis-flags its own traffic discovers a liability shift it believed it had does not exist when the dispute arrives, which is among the commonest causes of lost disputes.
- The address verification service compares numbers only, so a house number and a postcode — the two least secret things about anybody — are enough to pass it.
- Most of its response codes are not answers at all, and the ones that are get defeated by the same breach that supplied the card number in the first place.
- The card verification code has real teeth for an archival reason: PCI DSS forbids its retention, so a thief working from stored records should not have it while one working from the physical card will.
- In the United Kingdom regulation 76 requires the issuer to refund an unauthorised transaction by the end of the business day following the day it becomes aware of it.
- Regulation 77(4)(d) removes even the £35 excess where the instrument was used in connection with a distance contract, so consumer exposure to unauthorised online card fraud is zero.
- Regulation 75 puts the burden of proof on the provider and denies that its own record of use discharges it, which leaves the issuer one economically rational move: refund and charge back.
- The loss therefore lands on the merchant through the acquirer, and the acquirer is the party of last resort when a failed merchant’s chargebacks keep arriving.
- The merchant’s true cost of one fraudulent order is the order, the goods, the shipping, the fee, the labour, the ratio, the controls bought afterwards and the honest customers those controls turn away.
- The channel is dearer before any fraud occurs, and the United Kingdom to European interchange increases were found to cost businesses an additional £150 million to £200 million a year.
- Scheme monitoring, consolidated into the Visa Acquirer Monitoring Program from 1 April 2025, combines fraud reports and disputes into one ratio, so a merchant with no fraud can be caught by a fraud programme.
- The British chip and PIN migration is the cleanest natural experiment available: counterfeit fraud fell sixty-eight per cent between 2004 and 2008 while card-not-present fraud rose to £328.4 million.
- Displacement was geographic as well as channel-wise, following the gradient of the weakest reader anywhere in the world that will accept the card.
- Arithmetic honesty requires the £41.2 billion of online spending alongside the £328.4 million, because the rate per pound fell while the absolute loss more than tripled.
- Authentication closed the route that replays stolen static credentials and not the route that persuades the legitimate human to authenticate, which is why passcode compromise and wallet enrolment now drive the numbers.
- Every control in the chapter is a compensating measure for one architectural fact — a static secret shared with thousands of parties is not a secret — and only tokenisation and authentication attack that fact itself.
Chapter sources: Payment Services Regulations 2017 (S.I. 2017/752), regulations 75 to 77 on legislation.gov.uk, current to August 2026; Commission Delegated Regulation (EU) 2018/389, Articles 16 and 18 to 20 and the Annex, with the FCA Handbook Technical Standards on Strong Customer Authentication, Chapter 3, last updated 19 March 2026; the FCA’s Strong Customer Authentication page, its Dear CEO letter of 20 August 2019, and its statement extending the e-commerce deadline to 14 March 2022; UK Finance Annual Fraud Report press releases of 15 June 2026 and 28 May 2025; the joint EBA and ECB payment fraud reports of 15 December 2025 and 1 August 2024; ONS Social Trends, sourced to the UK Cards Association, for the 2000 to 2008 card fraud series; the Payment Systems Regulator’s cross-border interchange market review, page last updated October 2025; HM Treasury’s March 2025 announcement on consolidating the PSR into the FCA; Visa’s Compelling Evidence 3.0 Merchant Readiness document of March 2023; Mastercard Developers documentation for First-Party Trust; PCI Security Standards Council material on PCI DSS v4.0.1 and Requirements 6.4.3 and 11.6.1; the Merchant Risk Council press release of 18 March 2026; and acquirer documentation from Adyen, Worldpay and Stripe for address verification codes and e-commerce indicator mappings.