The fraud rate is measured as a ratio between fraudulent and successful transactions. It compares the total amount of fraudulent transactions to the total amount of successful transactions in USD over a specific time period.
The way to calculate the fraud rate depends on the payment system and how it gathers data, by descriptors, merchant account IDs, or legal entities.
Download the checklist and protect your business from fraud and chargebacks.
Screen card payments before authorization with lists and rules, and choose whether to pass, reject, force 3DS, or review each payment. Antifraud rules.
Calculate fraud rate
Fraud rate can be measured using the aggregated or cohort method:
USD in current month / sale amount USD in current month
Account-level metrics:
- Numerator: The total amount in
USDof fraud notifications received in the current month. - Denominator: The total amount in
USDof revenue for the current month.
The settlement date determines the sale date, not the authorization date. Only Visa and Mastercard transactions count, since these brands provide fraud alerts. Only acquiring banks that fully transmit fraud notifications count. Fraud alerts can arrive for orders up to 180 days after the original transaction date. Alerts received in the current month can relate to orders from prior months.
USD on cohort / sale amount USD of cohort
Cohort is a group of orders created in a specific calendar month.
- Numerator: The total fraud amount in
USDreported against orders within that cohort, tracked over the full alert window (up to 180 days). - Denominator: The total sale amount in
USDof successful orders in that same cohort.
The cohort method evaluates the impact of risk rule changes and compares fraud performance across payment methods or traffic segments. It eliminates the cross-cohort mixing effect inherent in the aggregated method.
Track fraud alerts
Card schemes report fraudulent transactions after the payment, often weeks later. Use fraud alerts to find affected orders and respond before they turn into chargebacks.
-
card fraud alerts API v1 report helps merchants identify and respond to fraudulent transactions. Each alert includes the order ID, fraud amount in the transaction currency, and the date and time the fraud was reported.
-
received fraud alert Webhook v1 or fraud alert received Webhook v2 notifies of fraudulent activities reported by card schemes and enables rapid response.
Analysis of fraud causes
- Friendly fraud: Unclear terms can lead customers to commit fraud without realizing it.
solution Ensure clarity of terms and ease of subscription management. - Product issues: The received product does not meet expectations or is of poor quality.
solution Analyze customer reviews and improve quality. - Misleading descriptions: Discrepancies between descriptions and the actual goods/services.
solution Standardize descriptions to reflect the content of the purchase accurately.
- Card verification fraud: Attempts to verify card validity through microtransactions.
solution Set limits on the number of payment attempts from a single customer or IP address. - Account takeover: Illegal account acquisition through phishing, brute force, and more.
solution Apply multifactor authentication and monitor for abnormal customer behavior. - Affiliate fraud: Manipulation of traffic or payments to gain undue benefits.
solution Work closely with affiliate networks and audit traffic sources.
Card network fraud monitoring
Visa uses descriptors to group and calculate fraud rates. This links transaction activity and results to specific merchants, goods, or services. Under Visa’s Acquirer Monitoring Program
VAMP is designed to monitor and manage risk among Visa acquirers and their merchants, aiming to protect the integrity of the Visa payment system by preventing fraud and excessive chargebacks.
(VAMP),
Visa reviews monthly processing data to identify merchants exceeding fraud or dispute thresholds. VAMP includes metrics such as the VAMP Ratio and Enumeration Ratio to enhance fraud detection and prevention. Enrolled businesses must submit remediation plans and might face penalties. To exit the program, businesses must meet thresholds for at least one month.
Mastercard uses Merchant ID (MID) to group transactions and assess fraud levels. The formula divides the number of chargebacks per month by the total number of successful transactions from the previous month. Mastercard counts only the first 35 chargebacks from the same card. Mastercard’s Excessive Chargeback Merchant
The ECM categorizes merchants into tiers based on their chargeback rates, enforcing measures to maintain transaction integrity.
(ECM)
and Excessive Fraud Merchant Compliance Program
The EFM targets e-commerce fraud by setting strict thresholds for fraud-related chargebacks, enhancing merchant accountability and transaction security.
(EFM)
are key programs for managing chargebacks and fraud.
Solidgate uses TC40 (Visa’s fraud reporting code) and SAFE (Mastercard’s fraud reporting system) data to monitor card fraud. These reports contain cardholder fraud claims along with detailed transaction information.
A TC40 or SAFE report indicates a claim of a fraudulent charge and requires an immediate review. Not every TC40 report results in a chargeback.
Other card networks like American Express, Discover, Diners, and JCB identify merchants by their account ID. These networks calculate fraud rate as either the number of chargebacks or the fraud amount in a month, divided by total successful transactions or sales for the same month.
Each card network sets its own thresholds for its monitoring program.