Fraud Risk
Keeping dispute rates low: a control view of chargebacks
A chargeback rate is a lagging indicator of decisions made two to three months earlier. By the time the number moves, the transactions that caused it are long settled, the customers are long gone, and whatever was wrong with the checkout flow or the fraud rules has been wrong for a quarter.
That lag is why dispute management so often becomes a fire-fighting function. The team responds to the rate rather than to the causes, and the levers it reaches for — fight more cases, tighten authorisation — are the two that do least.
Three problems wearing one number
Almost every underperforming dispute programme has the same root defect: it treats the chargeback rate as a single quantity. It is not. It is three unrelated failure modes added together, and they have almost nothing in common.
True third-party fraud. Someone used a card they were not entitled to use. The cardholder is telling the truth. This is a fraud-prevention problem and the fix sits upstream in authentication and screening.
Service and merchant failure. The goods never arrived, the description was wrong, the subscription was not cancelled when the customer asked, the refund was promised and never processed. The cardholder is also telling the truth. This is an operations problem and no amount of fraud tooling will touch it.
Cardholder misuse — the thing the industry unhelpfully calls "friendly fraud". The cardholder made the purchase and disputed it anyway, whether through confusion, buyer's remorse, a family member's transaction they did not recognise, or deliberate abuse. This is partly a clarity problem and partly a fraud problem, and it is usually the largest of the three.
Each requires a different owner, a different fix, and a different measure. Reported as one percentage, they cancel each other out: fraud tooling improves, service quality slips, the rate holds flat, and the dashboard shows nothing happened.
If you cannot split your dispute rate three ways, you cannot manage it. You can only react to it.
The thresholds have moved, and the maths changed
Scheme monitoring is no longer a distant concern for merchants running a modest rate. Visa's Acquirer Monitoring Program tightened its "excessive" threshold to a 1.50% VAMP ratio with effect from 1 April 2026, down from 2.20%, with the count condition set at 1,500 fraud-and-dispute items in a calendar month for a US merchant. Both conditions must be met. Mastercard's Excessive Chargeback Merchant programme sits at 100 chargebacks and a 1.50% ratio, again requiring both.
The structural detail that matters more than the numbers: the VAMP ratio counts fraud reports (TC40) plus disputes (TC15) over settled card-not-present transactions. A single fraudulent transaction that is both reported as fraud and disputed can therefore contribute twice to the numerator.
The practical consequence is that a firm's internal chargeback rate and its VAMP ratio are different measures, and a programme monitoring only the former can be genuinely surprised. Reconcile the two deliberately rather than assuming one proxies the other.
What actually reduces disputes
In rough order of return, from a control perspective:
- Billing descriptor clarity. The single cheapest fix in the whole field. A descriptor showing a legal entity name the customer has never heard of generates disputes from people who simply do not recognise the charge. Descriptors should carry the trading name the customer transacted with, plus contact detail where the field allows.
- Refund before dispute. A refund costs the refund. A dispute costs the refund plus a fee plus a ratio point plus staff time. Any policy that makes a refund harder to obtain than a chargeback is, in effect, a policy that converts service failures into scheme statistics.
- Cancellation that works. For anything recurring, the cancellation path should be no harder than the sign-up path. Subscription disputes are overwhelmingly a design problem rather than a fraud problem, and they are also increasingly a regulatory one.
- Delivery and consumption evidence, captured at the time. Not retrieved painfully at representment. If the system does not record delivery confirmation, IP and device, authentication result, and terms acceptance as the transaction happens, the evidence usually does not exist when it is needed.
- Selective step-up authentication. Blanket 3-D Secure moves fraud liability but costs conversion, and abandoned checkouts are a real business cost. Applied to a risk-scored slice rather than the whole book, it is one of the few interventions that reduces both fraud and cardholder-initiated disputes — because the customer remembers the authentication step.
- Pre-dispute alerts. Resolving a case before it becomes a chargeback keeps it out of the ratio entirely. Worth the per-alert cost in most books; run the arithmetic rather than assuming.
Representment: fight selectively, not proudly
Teams tend to over-invest here because it feels like the active response. It is the narrowest lever available.
Fighting a dispute costs analyst time and wins only where the evidence genuinely contradicts the reason code. A true-fraud dispute where the cardholder did not transact is not winnable and should not be contested. A service-failure dispute where the goods were not delivered is not winnable either — and contesting it is arguably worse than losing, because it converts a resolvable service complaint into a formal fight.
Where representment does earn its cost is cardholder misuse with good evidence: matched device and IP, delivery confirmation, prior undisputed purchases from the same customer, authentication records.
Track win rate by reason code and by evidence type. Most programmes cannot say which cases they win, which means they cannot say which are worth fighting, which means they fight roughly everything at roughly break-even.
One thing worth stating plainly: winning a representment does not remove the chargeback from your ratio. Scheme monitoring counts the dispute, not the outcome. Representment protects revenue; it does not protect your standing in the programme. Only prevention does that.
Measure it where the decision was made
An aggregate monthly rate tells you almost nothing. Three refinements make it useful:
- Cohort by transaction date, not dispute date. A dispute arriving in June belongs to March's decisions. Reporting it in June's rate systematically misattributes cause and makes it impossible to tell whether a change worked.
- Segment by product, channel, geography and acquiring MID. Trouble is almost always concentrated. A flat book-wide rate hides the one product line carrying the problem.
- Watch leading indicators. Refund rate, customer-service contact volume by reason, failed-cancellation complaints, and inbound "what is this charge" queries all move weeks before the dispute rate does. They are the early warning the chargeback number cannot give you.
The ownership problem
Disputes sit across payments, customer service and fraud, which in many firms means they are owned by none of them. Payments treats the rate as a fraud metric. Fraud treats service-failure disputes as somebody else's noise. Customer service resolves individual cases without ever seeing the aggregate.
The organisational fix is unglamorous: one named owner for the rate, with authority to raise findings against the product and service failures that generate it, and a standing report that shows the three-way split rather than the single number.
Without that, every improvement is temporary. The rate gets pushed down by whoever is under pressure this quarter, the underlying causes stay exactly where they were, and it climbs back within two.
Sources
- Visa — Visa Acquirer Monitoring Program fact sheet (Visa Inc., 2025)
- Merchant Risk Council — Stricter VAMP ratio thresholds are now in effect (2026)
- Visa VAMP & Mastercard thresholds 2026 (GivePayments, 2026)
Scheme thresholds and programme definitions change. Confirm current figures against the card networks' own published rules before relying on them operationally.