Payment fraud and card-not-present cover do not come under one standard protection. A chargeback can reverse a remote card sale and add an acquirer fee.
You may lose money after dispatching goods or providing a service. The harder question is who carries that loss.
Does your SME actually have CNP loss cover?
Most SMEs do not have one single “CNP cover”; they have separate and sometimes incomplete protections.
Three protections, three different jobs
3D Secure adds a cardholder check. It is often a banking-app approval or a one-time code.
It can support a liability shift for eligible sales. The result depends on card-scheme rules, card type, sale data, exemptions and your acquirer agreement.
For a remote-card loss, ask three questions. Can you defend the chargeback? Will the acquirer debit you? Does the policy insure this exact loss? A “yes” to one question does not answer the others.
Good CNP protection uses layers, not one checkout setting. Use 3D Secure when it fits the sale. Meet PCI DSS requirements and encrypt card data as it moves.
Avoid storing card details unless a compliant provider tokenises them. Tokenisation replaces card data with a safe reference code. Think of it as a cloakroom ticket, not the coat.
AVS and CVV checks can flag mismatches. Fraud tools can compare devices, IP addresses, account age, sale speed and delivery behaviour.
These checks cannot remove every chargeback loss. They can cut fraud chances and give you stronger records for a later dispute.
The error most guides make is treating 3D Secure as insurance. It is evidence and sometimes a liability tool, not a promise of payment.
Which fraud event are you dealing with?
Naming the event correctly is the fastest route to the right recovery action.
What makes a card payment unauthorised?
Card-not-present fraud means someone used a card online, by phone or by post without permission. The card was not shown to you.
Useful evidence can include the authentication result, IP address, device data, AVS or CVV result and fulfilment record. Each item helps tell the payment story.
Authorised push payment fraud, or APP fraud, happens when someone is tricked into sending bank money. Invoice fraud, business email compromise and payment diversion often use this route.
The victim approves the transfer after receiving a convincing false instruction. That makes APP fraud different from a stolen-card sale.
In England, tell your bank at once if APP fraud is suspected. The Payment Services Regulations 2017 and Payment Systems Regulator arrangements may affect recovery.
They do not repay every business transfer automatically. Classify the event first, then check where the loss usually sits.
Friendly fraud, sometimes called chargeback fraud, differs from unauthorised CNP fraud. The real cardholder may have placed the order but later disputes it.
They may not recognise the merchant name. They may forget a renewal, claim non-delivery or regret the purchase.
The merchant may still carry the chargeback loss. Your defence should show contract acceptance, clear billing text, renewal reminders, delivery proof and account use.
Do not rely only on stolen-card signs. A friendly-fraud claim needs different evidence.
Treating every card dispute as criminal misuse can weaken your representment. The next section shows how that distinction affects the likely payer.
Who pays across six remote-sale fraud cases?
The likely payer depends on fulfilment, authentication and contract terms, not just the phrase “stolen card”.
| Sales model | Likely weak point | Best dispute evidence | Insurance issue to check |
|---|
| E-commerce goods | Stolen credentials | 3DS result, delivery proof, device data | Chargeback and trading-loss exclusions |
| MOTO order | Limited authentication | Call record, AVS/CVV, signed delivery | Whether MOTO is included |
| Click-and-collect | Collection by wrong person | ID check, collection signature, CCTV policy | Conditions on identity checks |
| Digital goods | No physical delivery proof | Login, download and usage logs | Intangible-goods exclusions |
| Subscriptions | Cancellation or renewal dispute | Clear consent and renewal notices | Contractual-liability exclusions |
| Marketplace sales | Unclear merchant of record | Platform order and delivery records | Outsourced-provider wording |
E-commerce and MOTO liability differs
MOTO means mail order or telephone order. It usually lacks the customer check used for many online sales.
Do not assume it has the same liability position. A £250 rushed phone order differs from a £250 online order approved through the customer’s bank.
Digital and subscription sale risks
Digital goods need proof that a named account logged in, downloaded, streamed or used the service. A download time alone can be weak evidence.
Link the download to an account or device where possible. A clear use history is usually more persuasive.
Click-and-collect proof changes outcomes
A practical England case involved a Manchester retailer. It received five £180 click-and-collect orders within 20 minutes.
Each order used a different card but the same collection name. Holding collection and checking the signals was safer than relying on later recollection of them.
Use several signals before blocking an unusual order. Approve low-risk orders with matching account, device and delivery histories.
Send orders for manual review when several moderate signs appear. These can include a new account, fast shipping, a high-value basket and different billing details.
Hold or block orders with strong signs. Examples include repeated card failures, many cards on one device, anonymising networks or repeated collection names.
Track approval, chargeback and manual-review rates. Also track review time and false-positive rates by rule.
If genuine customers face repeated declines, relax the weakest rule first. Do not reduce core authentication controls without checking the cause.
Each sales model needs its own proof trail. That matters most during the first 24 hours after suspicion arises.
Suspected fraud: what to do in the first 24 hours
Keep evidence, stop further loss and notify the right people before issuing an emotional refund.
The National Cyber Security Centre advises organisations to contain incidents and keep useful information. Its National Cyber Security Centre guidance helps where phishing or account takeover is suspected.
It also matters if a payment-card breach may have exposed customer data. Fast action protects both your money and your evidence.
Stop losses before evidence disappears
Put suspicious unfulfilled orders on hold. Save confirmations, payment times, AVS or CVV results, 3D Secure results and fraud scores.
Keep IP and device signals, delivery records, customer emails and staff notes. These records may vanish or change later.
If compromise is suspected, end active sessions and change affected passwords. Turn on multi-factor authentication, also called MFA.
MFA checks identity in at least two ways. It might need a password and an authenticator-app code.
It is like needing a house key and a verified phone. One stolen item is then less useful.
🎯Useful for this topic
A FIDO2 security key can protect email and payment-admin accounts. Criminals often target these accounts first.
- It reduces reliance on SMS codes targeted by phishing or SIM-swap attacks.
- It helps protect payment-provider and business-email administrator accounts.
- It gives staff a simple physical check before a sensitive sign-in.
Find on Amazon →
Who to notify, and in which order?
Tell your acquirer or payment provider promptly about suspected card disputes or fraud patterns. Contact your bank immediately for payment diversion, invoice fraud or compromised business banking.
Report criminal activity to Action Fraud where suitable. Keep a record of each report and its time.
Tell your broker or insurer within the policy period. Do this even if the loss seems below the excess.
An excess is the amount your business pays first. Early notice can matter if legal, forensic or breach-response costs appear later.
A fraud event does not always need an ICO report. But a personal-data breach may need ICO notice if it risks people’s rights and freedoms.
UK GDPR may require notice within 72 hours of awareness. Payment card data, customer addresses and login details need careful review.
Quick notice does not decide who pays. It preserves the options needed to pursue recovery or challenge a chargeback well.
How to challenge a chargeback without weakening it
A chargeback defence works best when every document answers the stated dispute reason.
Check your acquirer portal for the reason code, response format and deadline. Card-scheme limits often run up to about 120 days from a relevant event.
The deadline can be shorter and varies by dispute type. Treat your acquirer’s stated date as final.
Which records support representment?
Representment is your formal request to reverse a chargeback. Include the 3D Secure result, AVS or CVV checks, account history and device history.
Also include clear terms and delivery or collection proof. Add customer communications that relate to the reason code.
A refund can support good customer care, but check the dispute first. A refund after a chargeback can create a duplicate loss.
An accusatory email can worsen a genuine complaint. Keep all messages polite and factual.
The key is matching proof to the reason code. Policy wording then decides whether insurance may fill any remaining gap.
How to compare cover beyond “payment fraud”
Match the policy wording to your real loss route, not to a broad product label.
A suitable policy may cover first-party loss from unauthorised remote-card payments. Another policy may only cover privacy claims and recovery costs.
Read the insuring clause before relying on a sales summary. It is the part that says what the insurer agrees to pay.
This is the most useful test for a UK SME. Ask whether your policy clearly covers unauthorised remote-card losses, then check the excess, sub-limit, exclusions and required controls. 3D Secure may help with a card dispute, but it cannot replace insurance wording. If your main risk is MOTO, digital goods or subscriptions, ask whether that model is named or excluded.
Find the insuring clause and definition
Ask if the policy expressly covers first-party financial loss from unauthorised remote-card payments. Check whether it only covers privacy claims and recovery costs.
Check if “computer fraud”, “social engineering” and “payment card loss” have separate definitions. Similar labels can cover very different events.
Check excesses, sub-limits and exclusions
A sub-limit is a smaller cap inside the total policy limit. Think of it as a smaller bucket inside a larger one.
A policy might have a £100,000 total limit. It may allow only £10,000 to £25,000 for social engineering fraud.
Compare that sub-limit with your largest realistic one-day exposure. Also check exclusions for chargebacks, voluntary transfers and trading losses.
Test PCI DSS, MFA and 3D Secure terms
Ask the insurer which controls are cover conditions. Ask which controls are only recommendations.
Check patching rules, MFA for email and remote access, backups and staff training. Confirm 3D Secure use and any PCI compliance declaration.
A missed condition can become a claims argument. These controls may work well in theory, but the schedule and wording decide the actual result.
This guidance is less relevant if you do not accept remote card payments. It cannot confirm that a particular claim will be paid. The policy schedule, wording, merchant agreement, card-scheme rules and incident facts decide the outcome.
Check the wording before renewal or purchase. Then ask your broker to confirm any uncertain point in writing.
What people ask
Does cyber insurance cover card-not-present fraud?
Cyber insurance may cover CNP fraud only when it expressly insures that first-party financial loss. Check the insuring clause, excess, sub-limit and exclusions for chargebacks, voluntary transfers and trading losses.
Does 3D Secure guarantee chargeback protection?
3D Secure does not guarantee every chargeback win or prevent every merchant debit. Liability shifts can depend on scheme rules, sale type, authentication data and your acquirer agreement.
What evidence should I keep for a CNP chargeback?
Keep authentication, AVS or CVV results, order data, delivery or usage proof and customer messages. Save records before cancelling or refunding because acquirer deadlines can be short.
When must an SME report payment fraud to the ICO?
An SME must consider ICO notice when a personal-data breach risks people’s rights and freedoms. UK GDPR may require reporting within 72 hours after awareness, not after every disputed payment.
The essentials:- A chargeback, acquirer safeguard and insurance policy are separate routes with separate conditions.
- Classify the event first, because CNP fraud, friendly fraud and APP fraud need different responses.
- Save authentication, order and fulfilment records before refunds, cancellations or customer accusations.
- Compare definitions, excesses, sub-limits and security conditions against your remote sales model.
Learn more
Here are some additional resources on this subject: