Before you buy a fraud tool, do the three free things: put a billing descriptor on the statement that matches the name on your website, send tracked delivery with a real tracking number, and answer support messages within a day. A large share of disputes are not fraud at all. They are a confused cardholder who could not work out who charged them and could not reach you, so they phoned their bank instead. Fraud screening is the second job, not the first.

What a chargeback actually costs
Add it up properly once and the number is bigger than people assume. On a reversed USD 80 order with Stripe you lose the 80, you lose the 2.9% + 30¢ you already paid to take the money, you pay a 15 dollar dispute received fee, and if the goods have shipped you have lost the stock and the postage too. That is comfortably over 100 dollars of damage on an 80 dollar sale.
Two details make it worse. Processing fees are not returned when you refund – WooCommerce states this plainly in the WooPayments fee documentation – so even the friendly outcome costs you the margin. And Stripe charges a second fee, equal to the first, when you choose to contest a dispute manually: $15 in the US, £20 in the UK. You get that countered fee back if you win and you do not if you lose.
| Provider and market | Dispute or chargeback fee | Refunded if you win? | Notes |
|---|---|---|---|
| Stripe, United States | $15.00 received | Countered fee refunded on a win | A further $15.00 to contest manually |
| Stripe, United Kingdom | £20.00 received | Countered fee refunded on a win | A further £20.00 to contest manually |
| Stripe Smart Disputes | 30% of the disputed amount | Charged only on wins | The received fee still applies |
| PayPal, USD received | 20.00 USD | Per PayPal’s dispute process | Separate standard dispute fees also published |
| PayPal, GBP received | 14.00 GBP | Per PayPal’s dispute process | Separate standard dispute fees also published |
| PayPal, EUR received | 16.00 EUR | Per PayPal’s dispute process | Separate standard dispute fees also published |
The practical conclusion is uncomfortable but useful. On low-value orders it is often cheaper to refund immediately than to fight, because the countered fee plus your own time exceeds the order value. Save the fighting for orders where the money is worth the paperwork, and for patterns that look like abuse rather than confusion.
The scheme programmes you have to stay out of
Both major schemes run monitoring programmes, and both have thresholds published through acquirer documentation. These matter more than the individual fees, because entering one turns a cost of doing business into a per-item fine and, eventually, a conversation about whether your acquirer still wants you.
Visa consolidated its Dispute Monitoring and Fraud Monitoring programmes into the Acquirer Monitoring Program on 1 April 2025. The ratio is deliberately broad: reported card-not-present fraud plus every opened chargeback, divided by settled transactions in the same month. Per the Braintree documentation, a merchant enters the Excessive level at 1,500 such items in a month combined with a 1.5% ratio, and the fine is $8 per item. There is a separate enumeration test for card testing at 2,000 basis points across at least 300,000 transactions.
Mastercard’s Excessive Chargeback Program works on count and ratio together, which is kinder to small stores. You need 100 to 299 chargebacks in a month and a ratio between 1.50% and 2.99% to be flagged as an Excessive Chargeback Merchant, or 300 and up and 3.00% or more to be a High Excessive Chargeback Merchant. The ratio uses this month’s chargebacks over last month’s sales count.
| Programme | Level | Count trigger | Ratio trigger | Penalty |
|---|---|---|---|---|
| Visa VAMP | Merchant Excessive | 1,500 fraud reports + chargebacks | 1.50% | $8 per item |
| Visa VAMP | Acquirer Excessive | 5 chargebacks at merchant level | 0.70% portfolio | $8 per item |
| Visa VAMP | Acquirer Above Standard | 5 chargebacks at merchant level | 0.50% portfolio | $4 per item |
| Mastercard ECP | Excessive (ECM) | 100-299 chargebacks | 1.50-2.99% | Escalating monthly fine |
| Mastercard ECP | High Excessive (HECM) | 300+ chargebacks | 3.00%+ | Escalating fine plus $5 per chargeback over 300 |
Getting out is slower than getting in. Mastercard requires three consecutive months below the Excessive thresholds before you exit, and may ask for a written remediation plan covering what happened and which fraud tools you have turned on. That is a quarter of trading under scrutiny, which is the real argument for keeping your ratio at a fraction of the limit rather than just under it.

Three fixes that cost nothing
Three changes, none of which need a vendor.
- Fix the billing descriptor. It should be the trading name on your site, not your holding company, and it should include a contact phone number or URL if your processor allows the extra characters.
- Ship tracked, and store the tracking number against the order. Delivery confirmation is the single most useful piece of evidence in an item-not-received dispute, and it has to be retrievable months later.
- Answer support fast and visibly. A reply within a working day converts a would-be chargeback into a refund request, which costs you the order but not the fee, the ratio or the fine.
There is a fourth that costs a little: send a dispatch email with a photo of the packed item and the carrier reference. It reads as reassurance to an honest buyer and as a deterrent to a dishonest one, and it gives you a timestamped record either way.
- Order timestamp, IP address and the email used at checkout.
- Authentication result, including whether 3-D Secure was completed.
- Carrier tracking number and the delivery confirmation event.
- Every support message, with timestamps, in one thread.
- The exact terms and refund policy the customer agreed to, with a version date.
Fraud screening without blocking real buyers
Screening is a balance, and the failure mode people ignore is over-blocking. Baymard Institute’s abandonment data, drawn from 50 studies and averaging a 70.22% cart abandonment rate, finds that 10% of shoppers have abandoned an order because their card was declined. Every rule you add to stop a fraudster also stops some number of real buyers, and you never see those in your dispute log.
Start with what your processor already gives you. Stripe’s Radar Lite, for example, is included at no additional charge for businesses on standard payments pricing, and the machine-learning score it produces is better than any rule set you will hand-write in an afternoon. Add your own rules only where you have seen a pattern: a specific billing-to-shipping mismatch, repeated attempts from one card across different emails, or unusually large first orders in a category where that never happens.
Review queues beat hard blocks for anything borderline. A flagged order that a human looks at within a few hours costs you a little labour; a blocked order costs you the customer and you never find out whether they were genuine. If you sell internationally, this is doubly true – our checklist for selling across borders covers why a foreign billing address is a terrible fraud signal on its own.
The asymmetry at the heart of fraud screeningEvery rule that stops a fraudster also stops some number of real buyers. You see the disputes. You never see the blocked customers.
3-D Secure and who carries the liability
3-D Secure is the step-up challenge your bank shows during checkout. Its commercial point is liability: when a transaction is authenticated, fraud liability generally shifts from you to the card issuer, which takes a whole class of dispute off your books. In the European Economic Area and the UK, strong customer authentication is the default rather than an option, with specific exemptions for low-value and recurring payments.
The trade-off is friction. Every challenge is a chance for someone to abandon, which is why most processors now apply 3-D Secure selectively – automatically on risky orders, exempted on routine ones. If you are choosing a provider, ask how their exemption logic works and who carries the loss when an exemption is wrong. That answer tells you a lot about the product, and it belongs in the same conversation as the one about choosing an ecommerce platform.
Fighting a dispute, and when to just refund
When a dispute arrives you have three choices: accept it, counter it, or try to stop it before it becomes a chargeback. The third option is the best one and the least used. Both schemes run pre-dispute networks – Visa through Verifi, Mastercard through Ethoca – that let you refund an alert before a chargeback is opened, which keeps the item out of your ratio. Braintree’s documentation confirms that non-fraud disputes resolved that way are removed from official chargeback figures.
If you do counter, win it on documents. The argument that works is a timeline: order placed at this time from this IP, authenticated this way, dispatched on this date, delivered and signed for on that date, and here are the three support messages where the customer acknowledged receipt. The argument that loses is an explanation of how careful your business is.
- The order value is below roughly twice the dispute fee.
- You cannot produce delivery confirmation.
- The customer has a legitimate complaint about the goods.
- You are near a scheme threshold and need the ratio down this month.
- The reason code is one you have already lost on three times.

The PCI question nobody asks until the audit
The PCI rules changed in a way that catches small stores by surprise. The PCI Security Standards Council’s revised SAQ A – the shortest self-assessment, intended for merchants who outsource payment entry – added an eligibility criterion that took effect on 1 April 2025. The merchant now has to confirm that their site is not susceptible to scripts that could affect their ecommerce systems.
FAQ 1588 gives you two ways to satisfy that. Either apply techniques of the sort described in PCI DSS requirements 6.4.3 and 11.6.1 to protect the payment page from scripts targeting account data, or obtain confirmation from your PCI DSS compliant payment provider that their embedded page, implemented per their instructions, already includes that protection. The Council also notes the criterion applies to embedded payment pages and forms such as iframes, and not to merchants who redirect the customer away to the processor entirely.
In practice that means two emails: one to your payment provider asking for written confirmation, and one to your acquirer asking which self-assessment questionnaire they expect from you. Do it before your renewal date rather than during it.
A screening setup that fits a small store
For a store doing a few hundred orders a month, this is the whole setup.
- Processor-native screening on its default settings, reviewed monthly rather than tuned weekly.
- A manual review queue for anything scored borderline, checked twice a day.
- 3-D Secure applied selectively, with exemptions handled by the processor.
- Pre-dispute alerts enabled, with a standing rule to refund alerts under a set amount.
- A dispute log with the reason code, the outcome and the evidence you submitted, so you can see which codes you lose.
- A monthly ratio check against both schemes, so you spot a trend before your acquirer does.
That last one is the habit worth building. Nobody is flagged by surprise. The ratio climbs for two or three months first, usually after a product change, a new traffic source or a delivery partner that started missing dates. Watching the number monthly turns a fine into a conversation you have with yourself in time to fix it. Conversion work and fraud work pull in opposite directions here, which is why our notes on boosting conversion rate and this page should be read together rather than separately.
Frequently asked questions
What chargeback ratio should I actually aim for?
Well under the scheme thresholds, which means under about 0.5% of transactions as a working target. Visa’s merchant Excessive level sits at a 1.5% ratio with a count of 1,500 items a month, and Mastercard’s at 1.50% with 100 chargebacks, but you want headroom for a bad month. If you are at 1% and growing, treat it as urgent.
Is it worth contesting a small dispute?
Usually not. Stripe charges a countered fee equal to the received fee – $15 in the US, £20 in the UK – and you only get it back if you win. On a low-value order the fee plus an hour of your time exceeds the order. Refund it, keep the evidence, and spend the time on the pattern that produced it.
Does 3-D Secure hurt conversion?
Every challenge screen costs you some orders, so yes, if you apply it to everything. Applied selectively by your processor’s risk engine, the cost is small and the liability shift on authenticated transactions is worth it. Ask your provider what share of your payments are being challenged; if it is more than a few per cent, something is misconfigured.
Do I need a separate fraud tool, or is my processor enough?
For most small and mid-sized stores the processor’s own screening is enough, and it is often included in standard pricing. A dedicated tool starts to pay for itself when you have enough volume to train rules on your own data, or when you sell something with a high resale value and organised fraud is actually targeting you.
Who is liable when a customer says they never received the parcel?
That depends on your delivery terms and the evidence you can produce, which is why tracked delivery matters so much. Without a delivery confirmation event you will generally lose the dispute. This is a contractual question as much as a payments one, so get your terms reviewed properly rather than copying someone else’s.
If your dispute rate is creeping up and you want somebody to look at the checkout, the screening rules and the evidence you are keeping, we can go through it with you. Get in touch with Eudora Technology to talk about your project.



