The life of a chargeback
Every chargeback starts with a cardholder contacting their bank. What happens next is a fixed sequence with deadlines at each step, and the deadlines are where most merchants lose.
- The dispute. The cardholder tells their issuing bank they do not recognize a charge, did not receive what they paid for, or were charged incorrectly. The issuer assigns a reason code that describes the complaint in the network's vocabulary. Some issuers first send a retrieval request (a request for a copy of the sales record) or route the case through an alert network, but increasingly the first thing a merchant sees is the chargeback itself.
- The chargeback. The issuer debits the acquirer for the transaction amount, the acquirer debits the merchant account, and the merchant is notified, usually by the processor's dispute portal or by email. At this point the money is gone and a chargeback fee has been charged, regardless of what happens next.
- Representment. The merchant can accept the chargeback or fight it by submitting evidence through the acquirer. This is called representment, or on Mastercard a second presentment. The evidence goes back to the issuer, which decides whether to reverse the chargeback.
- Pre-arbitration. If the issuer rejects the representment, or the cardholder disputes again, the case can go to pre-arbitration, where the two banks try to settle it between themselves. The merchant may be asked for more evidence.
- Arbitration. The network itself rules. Filing fees run to several hundred dollars and are paid by the losing side, so arbitration is rare below a few thousand dollars.
Two facts shape everything else. The cardholder has a long window to dispute, typically 120 days from the transaction, or from the date goods or services were expected. The merchant has a short window to respond, measured in weeks. And the burden of proof sits with the merchant: the issuer's default is to believe its customer.
What a chargeback actually costs
The debited sale is the visible cost. The others add up to more.
| Cost | Typical amount | Notes |
|---|---|---|
| The transaction amount | The full sale | Debited when the chargeback is filed, before you can respond. Refunded only if you win representment. |
| Chargeback fee | $15 to $25 per case; up to $100 for high-risk accounts | Charged by the acquirer on every chargeback, won or lost. |
| Goods or services already delivered | Cost of goods | Rarely recovered. |
| Staff time | 30 to 90 minutes per contested case | Gathering evidence, writing the response, following up. |
| Network monitoring program fees | Hundreds to thousands of dollars per month | Only once your dispute ratio crosses the network thresholds (next section). |
| Account termination | The business | Persistent excessive ratios end in a closed merchant account and a listing on the industry blacklist (the MATCH list), which makes getting a new one very hard. |
Industry estimates put the total cost of a chargeback at two to three times the transaction amount for a typical card-not-present merchant. The arithmetic is why alerts that let you refund before a chargeback is filed can be worth paying for even though you still lose the sale.
Dispute ratios and the monitoring programs
Both networks run programs that identify merchants with too many disputes and charge them escalating fees until the ratio comes down or the account is closed. The thresholds are published and worth knowing precisely, because the calculations differ.
| Program | Ratio calculation | Standard threshold | Excessive / high threshold |
|---|---|---|---|
| Visa Dispute Monitoring Program (VDMP) | Disputes received this month divided by transactions this month | 0.9% and at least 100 disputes | 1.8% and at least 1,000 disputes |
| Visa Fraud Monitoring Program (VFMP) | Fraud-reported dollars this month divided by sales dollars this month | 0.9% and at least $75,000 in fraud | 1.8% and at least $250,000 |
| Mastercard Excessive Chargeback Program (ECP) | Chargebacks this month divided by transactions the previous month | 1.5% and at least 100 chargebacks | 3.0% and at least 300 chargebacks |
Thresholds as published at the time of writing; both networks revise their programs periodically. Fraud and non-fraud counts are tracked separately by Visa.
Three details matter in practice:
- Visa counts disputes, Mastercard counts chargebacks. Under Visa, a dispute counts toward the ratio when it is filed, whether or not you later win it. Winning representment recovers the money but does not lower the ratio.
- Cases resolved through the alert networks do not count. A refund issued in response to an Ethoca or CDRN alert prevents the chargeback from being filed, and a dispute resolved through Visa's RDR is treated as a pre-dispute resolution. Neither appears in the ratio. This is the main financial argument for alerts.
- The count thresholds protect small merchants. A business with 40 transactions a month and two disputes has a 5 percent ratio but is below the minimum count for every program. The ratio still matters to your acquirer's risk team, which has its own, usually stricter, view.
Reason codes: Visa
Visa groups disputes into four categories under its Visa Claims Resolution framework. The category decides the workflow. Fraud and Authorization disputes go through the allocation workflow: Visa's system assigns liability automatically from the transaction data, and the merchant's response options are narrow. Processing Error and Consumer disputes go through the collaboration workflow, which is the traditional representment process.
| Code | Name | What the cardholder is saying | What usually wins |
|---|---|---|---|
| 10.1 | EMV liability shift, counterfeit fraud | A counterfeit chip card was accepted at a terminal that did not use the chip | Proof the chip was read. If the terminal is not chip-enabled, this is almost never winnable. |
| 10.2 | EMV liability shift, non-counterfeit fraud | A lost or stolen chip card was used at a terminal that did not read the chip or verify the PIN | Chip and PIN data from the terminal. |
| 10.3 | Other fraud, card-present | The cardholder did not authorize an in-person transaction | Signed receipt, chip data, ID verification, CCTV if available. |
| 10.4 | Other fraud, card-absent | The cardholder did not authorize an online, phone or mail transaction. The most common code for e-commerce and invoicing. | 3-D Secure authentication (the liability is already the issuer's), or Compelling Evidence 3.0 (see below), or proof of delivery to the cardholder plus AVS and CVV matches. |
| 10.5 | Visa Fraud Monitoring Program | Visa flagged the transaction under a fraud program | Little; the transaction is presumed fraudulent under the program. |
| 11.1 | Card recovery bulletin | The card was listed as recovered and the merchant did not check | Rare outside card-present. |
| 11.2 | Declined authorization | The transaction was completed after an authorization was declined | Proof of an approved authorization. Usually indicates a forced or retried sale; often unwinnable. |
| 11.3 | No authorization | No authorization was obtained, or it was obtained after the fact or for a lower amount | The approved authorization record matching the amount and date. |
| 12.1 | Late presentment | The transaction was submitted for settlement too long after the authorization | Proof of timely settlement. Settle batches daily. |
| 12.2 | Incorrect transaction code | A sale was processed as a credit or vice versa | Corrected transaction record. |
| 12.3 | Incorrect currency | The cardholder was charged in a currency they did not agree to | The receipt showing the agreed currency. |
| 12.4 | Incorrect account number | The wrong card was charged | The authorization for the number used. |
| 12.5 | Incorrect amount | The amount charged differs from what was agreed | The signed or accepted order at that amount. |
| 12.6 | Duplicate processing / paid by other means | The cardholder was charged twice, or paid another way as well | Proof the two transactions were for different purchases, or a refund of the duplicate. |
| 12.7 | Invalid data | Authorization data was wrong | Corrected authorization data. |
| 13.1 | Merchandise or services not received | The order never arrived or the service was not provided | Proof of delivery to the cardholder's address, or of the service being performed, with dates. |
| 13.2 | Cancelled recurring transaction | The cardholder cancelled a subscription and was billed again | Proof of the cancellation policy, that it was disclosed, and that no cancellation was received before the billing date. |
| 13.3 | Not as described or defective merchandise | The goods or service differed from the description | The original description, photographs, correspondence, proof the cardholder did not attempt to return or resolve. |
| 13.4 | Counterfeit merchandise | The goods were counterfeit | Proof of authenticity and sourcing. |
| 13.5 | Misrepresentation | The terms were misrepresented | The terms as presented at the time of sale. |
| 13.6 | Credit not processed | A promised refund never arrived | Proof the credit was issued, or that the refund policy did not apply. |
| 13.7 | Cancelled merchandise or services | The order was cancelled and still charged, or the goods were returned | Proof no cancellation was received, or that the return was refused under a disclosed policy. |
| 13.8 | Original credit transaction not accepted | A credit was refused by the cardholder | Rare; usually a processing issue. |
| 13.9 | Non-receipt of cash | ATM or cash disbursement not received | Not applicable to merchants. |
Visa Claims Resolution dispute conditions. The four categories are 10 Fraud, 11 Authorization, 12 Processing Errors and 13 Consumer Disputes.
Compelling Evidence 3.0
For 10.4 card-absent fraud disputes, Visa allows a merchant to shift liability back to the issuer by proving the cardholder has a history with the business. The rule, in force since 2023, requires two prior undisputed transactions on the same card, between 120 days and 365 days old at the time of the dispute, that share at least two data elements with the disputed transaction from this list: IP address, device ID or fingerprint, account login, and shipping address. One of the two matching elements must be the IP address or the device ID. Merchants that store these fields with every transaction win a category of dispute that was previously close to unwinnable, which is a strong reason to capture them.
Reason codes: Mastercard, and the others
Mastercard consolidated most of its consumer reason codes into a single code in 2018, so its list is shorter. The specifics of the complaint are carried in a message text rather than the code.
| Code | Name | Covers |
|---|---|---|
| 4837 | No cardholder authorization | Fraud: the cardholder denies making the transaction. The card-absent equivalent of Visa 10.4. |
| 4853 | Cardholder dispute | All consumer disputes: goods not received, not as described, cancelled recurring, credit not processed, counterfeit, and so on. The older codes 4841, 4855, 4859, 4860 and others were folded into this one. |
| 4834 | Point-of-interaction error | Processing errors: duplicate charges, incorrect amounts, late presentment, paid by other means, currency errors. |
| 4808 | Authorization-related chargeback | No authorization, declined authorization, expired authorization, or authorization for a lower amount. |
| 4870 | Chip liability shift | Counterfeit fraud at a non-chip terminal. |
| 4871 | Chip and PIN liability shift | Lost, stolen or never-received card at a terminal without chip and PIN. |
| 4849 | Questionable merchant activity | Transactions at a merchant listed under a Mastercard fraud program. |
Mastercard chargeback reason codes. Mastercard's merchant response is a "second presentment" and its equivalent of pre-arbitration is called pre-arbitration as well.
American Express and Discover act as both network and issuer for most of their cards and use their own codes. Amex codes are letter-number pairs: F29 for card-not-present fraud, C08 for goods or services not received, C18 for a cancelled recurring charge, P08 for a duplicate charge. Discover uses short alpha codes: UA02 for card-not-present fraud, RG for non-receipt of goods, AP for a cancelled recurring payment, DP for duplicate processing. The evidence that wins is the same as for the equivalent Visa code.
The deadlines
Missing a response deadline is an automatic loss. The windows below run from the date the chargeback is issued, and your processor usually gives itself several days inside that window to forward your response, so the practical deadline is shorter than the network's.
| Stage | Visa | Mastercard | Notes |
|---|---|---|---|
| Cardholder files a dispute | Up to 120 days from the transaction date, or from the date goods or services were expected, for most codes | Up to 120 days, with the same exceptions | Some codes allow longer, and delivery-based disputes can be filed up to 540 days after the transaction in specific cases. |
| Merchant responds (representment / second presentment) | 30 days | 45 days | Your processor may allow less to leave itself time to submit. |
| Issuer decides on the response | Within 30 days | Within 45 days | Silence is a win for the merchant. |
| Pre-arbitration | 30 days for each side to respond | 45 days | The merchant may be asked for further evidence. |
| Arbitration | Filed within 10 days of the pre-arbitration outcome | Within 45 days | Filing fees of several hundred dollars, paid by the losing party. |
Deadlines as published at the time of writing; processors and acquirers often impose shorter internal deadlines.
Fighting a chargeback: what evidence wins
Representment succeeds when the evidence answers the specific reason code, arrives before the deadline, and is easy for a bank analyst to read in a few minutes. Merchants that fight every chargeback with the same generic packet win perhaps one in five. Merchants that match evidence to the code and skip the unwinnable cases win closer to half.
Decide whether to fight
- Fight: consumer disputes where you can show delivery, performance or the disclosed policy; processing errors where you have the correct record; card-absent fraud where you have 3-D Secure, matching prior history for Compelling Evidence 3.0, or delivery to the cardholder's verified address.
- Accept: fraud disputes with no authentication and no delivery proof; disputes where you did make an error; small amounts where the time costs more than the recovery. Accepting quickly does not affect the ratio; the dispute already counted.
- Refund instead: if a dispute arrives and you would have refunded anyway, refunding does not undo the chargeback. Never refund a transaction that has already been charged back; you will pay twice.
Build the packet
A representment packet is a cover letter and attachments. The letter states the reason code, summarizes the transaction in three sentences, and lists the attached evidence with one line on what each proves. The attachments depend on the code:
| Dispute type | Evidence to include |
|---|---|
| Fraud, card-absent (10.4, 4837) | 3-D Secure authentication result if any; AVS and CVV match results; IP address, device ID and login history with two prior undisputed transactions (Compelling Evidence 3.0); delivery confirmation to the billing address with signature; any correspondence with the cardholder after the sale; evidence the cardholder used the product or service. |
| Not received (13.1, 4853) | Carrier tracking with delivery date and address matching the order; signature on delivery; for services, timestamps of access, logins, appointment records, or a signed completion form. |
| Cancelled recurring (13.2, 4853) | The subscription terms as shown at signup with the checkbox or signature; the cancellation policy; the date of the last successful renewal notification; records showing no cancellation request before the billing date, or that the cancellation came after it; proof of usage after the claimed cancellation. |
| Not as described (13.3, 4853) | The product listing or estimate as presented; photographs; the return policy and any refusal by the cardholder to return; correspondence. |
| Credit not processed (13.6, 4853) | The refund transaction record with date and amount, or the disclosed policy that excludes the refund and proof the cardholder accepted it. |
| Duplicate / paid by other means (12.6, 4834) | Two separate receipts or orders with different items or dates; or proof the other payment was for a different purchase. |
| Amount or currency (12.3, 12.5, 4834) | The signed estimate, invoice or checkout page showing the agreed amount and currency. |
| Authorization (11.x, 4808) | The authorization approval code, date and amount matching the settlement. |
Keep the packet short. Ten pages of screenshots with the relevant line circled beats a fifty-page export. Never include full card numbers or anything not requested.
Friendly fraud, and why the word "fraud" is misleading
Most industry estimates attribute well over half of card-not-present chargebacks to friendly fraud: a real cardholder disputing a legitimate charge. Some of it is deliberate. Much of it is confusion: an unrecognized merchant name on the statement, a family member's purchase, a subscription the customer forgot, a refund that was slow to post, or a bank app that makes "dispute this charge" easier than "call the merchant".
The reason this matters for prevention is that the fixes are not fraud tools. They are clarity tools:
- A descriptor the customer recognizes. The name that appears on the statement should be the name on the invoice or the storefront, with a phone number. "ECS*PAYSVC 8005551234" generates disputes; "NORTHWIND PLUMBING 302-555-0142" generates phone calls.
- Receipts and confirmations by email and text at the moment of payment, with the amount, the descriptor and how to reach you.
- Reminders before recurring charges. Both networks now require merchants to notify cardholders before a trial converts or a subscription renews at a changed amount, and to make cancellation as easy as signup. Beyond compliance, a reminder a few days before billing converts disputes into cancellations, which cost far less.
- Fast, visible refunds. A refund that takes ten days to post produces a dispute on day six. Confirm refunds by email with the expected posting time.
- Answer the phone. The dispute button in the banking app is the customer's second choice. Make the first one easy.
The alert networks: Ethoca, Verifi CDRN and Visa RDR compared
The alert networks exist because both the issuer and the merchant would rather resolve a dispute before it becomes a chargeback. When a cardholder calls their bank, a participating issuer sends the case to the network, which forwards it to the merchant, who can refund immediately. The cardholder gets their money, the issuer avoids the paperwork, and the merchant avoids the fee and the ratio hit. The merchant still loses the sale and pays a per-alert fee, so alerts make sense for disputes you would have lost anyway, which for card-absent fraud is most of them.
| Ethoca Alerts | Verifi CDRN | Visa RDR | |
|---|---|---|---|
| Owned by | Mastercard | Visa | Visa (operated through Verifi) |
| Cards covered | All brands, from issuers that participate in Ethoca | All brands, from issuers that participate in CDRN | Visa cards only, from participating issuers |
| How it works | The issuer sends the merchant a notice of a confirmed fraud or dispute claim; the merchant refunds (or stops fulfillment) and reports the outcome back | The dispute is routed to the merchant as a case; the merchant has 72 hours to resolve it by refunding, and the outcome is reported to the issuer | Rules-based and automatic: the merchant sets rules (amount ranges, reason codes, transaction types) and Visa resolves qualifying disputes with a refund before they are filed, with no manual step |
| Merchant action | Manual or automated via API, ideally within 24 hours | Manual or automated via API within 72 hours | None per case; rules are set once |
| Types of disputes | Fraud and non-fraud, depending on issuer | Fraud and non-fraud | Fraud and non-fraud; most useful for low-value, high-frequency disputes where fighting is not worthwhile |
| Effect on ratios | Chargeback prevented, so not counted | Chargeback prevented, so not counted | Treated as pre-dispute resolution; not counted in VDMP |
| Typical cost | A fee per alert, commonly in the tens of dollars | A fee per case, commonly in the tens of dollars | A fee per resolved dispute, commonly in the tens of dollars |
| Best for | Broad coverage across brands; stopping fulfillment on fraud orders before shipping | Broad coverage across brands; cases needing a human decision | Visa volume with predictable dispute patterns; removing manual work |
Per-alert fees vary by provider, volume and contract. Coverage depends on which issuers participate in each network; none covers every card.
Two related services address disputes one step earlier, before the cardholder even files: Verifi Order Insight and Ethoca Consumer Clarity push merchant and order details into the issuer's app or call center, so a customer who does not recognize a charge sees the store name, the items and the delivery address and often stops there. They require an integration that answers lookups in real time.
Running alerts well
- Enroll all three if you can. Coverage is by issuer, and the networks overlap only partially. A merchant on one network still sees chargebacks from issuers on the others.
- Match every alert to the original transaction before acting. Alerts carry the card details, amount and date, not your order number. Automate the match.
- Refund the full amount unless the alert is for a partial dispute. A partial refund often results in a chargeback for the remainder.
- Stop fulfillment when a fraud alert arrives before shipping. This is the one case where an alert saves the goods as well as the fee.
- Report outcomes back to the network. Unreported alerts are billed anyway, and issuers use response rates to decide how much of their volume to route to alerts.
- Watch for duplicate alerts for the same transaction from two networks, and for an alert followed by a chargeback anyway. Both happen, and both need a rule.
- Review the economics quarterly. If most alerts are for disputes you would have won, the alert fee is buying nothing. If most are fraud on shipped goods, it is buying a great deal.
A prevention checklist
- Statement descriptor: business name as customers know it, plus a phone number, on every processor account.
- Receipts by email or text at the time of payment, including the descriptor.
- AVS and CVV required on every card-not-present transaction; decline mismatches or review them.
- 3-D Secure on higher-value or higher-risk card-absent transactions, for the liability shift on fraud disputes.
- Capture and store IP address, device ID, login and shipping address with every transaction, so Compelling Evidence 3.0 is available later.
- Delivery confirmation with signature for goods above a threshold; timestamps and completion records for services.
- Clear, visible refund and cancellation policies, accepted at checkout, and reminders before recurring charges.
- Refunds processed the same day and confirmed to the customer.
- Alerts from Ethoca, CDRN and RDR, matched to transactions automatically, acted on within 24 hours, outcomes reported.
- A dispute log: reason code, amount, fought or accepted, outcome, root cause. Review it monthly; one or two causes usually explain most of the volume.
Where FloPay fits
FloPay's chargeback prevention pulls Ethoca, Verifi CDRN and Visa RDR alerts every hour, matches each one to the original payment across every connected gateway, refunds automatically according to your rules, and reports the outcome back to the network. The pieces that stop friendly fraud earlier are on the same platform: receipts and reminders by text and email, subscriptions with pre-billing notifications, hosted checkout with 3-D Secure, and tokenized cards so a refund can be issued against the original payment months later without card data on hand.
Stop chargebacks before they count
FloPay pulls Ethoca, CDRN and RDR alerts hourly, matches them to the payment on any gateway, refunds by your rules and reports back to the network. Ask us what your current dispute mix would look like with alerts.
See Chargeback Prevention