Refund, retrieval request, chargeback: three different events
These three get used interchangeably in merchant conversations, and they are not the same thing. Getting them straight is the precondition for managing any of them.
- A refund is merchant-initiated. The merchant decides to return the money, keeps control of the timing, and the transaction never enters the dispute system or any monitoring program. It is not free: the original transaction's processing costs have generally already been incurred, and depending on the acquirer the percentage fee may not come back.
- A retrieval request — also called a copy request or request for information — is the issuer asking for documentation about a transaction. No money moves. It is a question, not a reversal, and ignoring one is a reliable way to convert it into a chargeback. The networks have diverged on how much they still use them: Visa's dispute redesign largely displaced the traditional retrieval request in favor of pre-dispute inquiry messaging.
- A chargeback is the issuer taking the money back. The merchant is debited, charged a fee by its acquirer, and recorded in the count that feeds the network monitoring programs.
The mistake most merchants make here is refunding a customer after a chargeback has already been filed. That produces a double debit — the chargeback took the money, the refund gives it away again — and it does not withdraw the dispute. Once a dispute is in flight, the only correct responses are to contest it or to accept it. Not both.
How a dispute actually proceeds
The stages are consistent across networks even though the terminology differs.
- The cardholder contacts the issuer — not the merchant. This is the structural problem at the heart of chargebacks: the merchant is the last party to hear about the transaction, and usually hears about it as a debit rather than a question.
- The issuer assigns a reason code and files the dispute. Funds are debited from the merchant through the acquirer, typically with a chargeback fee the merchant pays regardless of outcome.
- The merchant responds — or does not. The response window is short, usually a few weeks, and set by network rules rather than by the acquirer's convenience. Non-response is an automatic loss.
- Representment. The merchant, through its acquirer, resubmits the transaction with evidence that the original charge was valid. This is the merchant's actual chance to win. It is called representment because the transaction is literally being presented to the issuer a second time.
- Pre-arbitration. If the issuer rejects the representment it can escalate. Both major networks have a pre-arbitration stage designed to force the two banks to resolve the case before the network has to.
- Arbitration. The network rules on the case. Arbitration carries a filing fee, and the losing side generally pays both the fee and the transaction — which makes it economically irrational on a low-value sale. Merchants routinely concede small disputes on purpose for exactly that reason.
Visa's framework, introduced under the Visa Claims Resolution program, splits cases into two tracks. Fraud and authorization disputes run through an allocation flow in which the network assigns liability using data it already holds, so the merchant's room to argue is limited and largely mechanical. Processing errors and consumer disputes run through a collaboration flow in which merchant and issuer exchange evidence. Mastercard's framework works on comparable lines. A merchant should know which track a reason code sits in, because it determines whether evidence will even be read.
Reason codes and what they signal
The reason code is the single most useful piece of information on a chargeback: it dictates what evidence is admissible and what the win probability is. Visa organizes disputes into four families — fraud, authorization, processing errors, and consumer disputes. Mastercard uses four-digit codes covering the same territory: cardholder does not recognize the transaction, no cardholder authorization, cardholder dispute over goods or services, goods or services not provided, duplicate processing, and authorization failures. Codes and sub-codes are revised periodically, so confirm specific values against a current network guide. Grouped by what they mean for the merchant:
- True fraud. A stolen card was used. The merchant generally loses unless authentication shifted liability. The correct response is a fraud-prevention project, not a representment strategy.
- First-party misuse — historically called friendly fraud. The cardholder made the purchase and disputed it anyway, often filed under a fraud code because that is the easiest button in a banking app. This is the category where evidence wins, and where the networks have built specific frameworks to let merchants prove a prior relationship.
- Goods or services not received, or not as described. Wins on delivery evidence and on the terms the customer accepted. Loses on a merchant's assertion that the customer is wrong.
- Processing errors. Duplicate charges, wrong amount, wrong currency, credit not processed. Usually the merchant's fault, usually not worth contesting, and always worth fixing upstream because they recur.
- Authorization failures. Charging a declined card, exceeding the authorized amount, settling on an expired authorization. Almost unwinnable, and entirely preventable.
The analytical value of reason codes is in the distribution, not the individual case. A merchant whose disputes are concentrated in "cardholder does not recognize" has a billing descriptor problem. Concentrated in "not received" is a fulfillment or carrier problem. Concentrated in "credit not processed" is a customer service backlog. Each has a fix that is not a dispute-response fix.
What compelling evidence actually wins
Representment is an evidentiary exercise judged by a person at an issuing bank who has minutes to spend on it. Narrative loses. Corroborated, third-party, timestamped records win.
For physical goods sold card-not-present, the strong package is address verification and card security code results from the authorization, carrier proof of delivery to an address matching the one the card verified against, the IP address and device identifier captured at checkout, the order confirmation sent to the customer, and the terms accepted at purchase. Signature on delivery matters disproportionately on higher-value items.
For digital goods, evidence has to substitute for physical delivery: account creation records, login timestamps and IP addresses tied to the same identity as the purchase, usage or download logs, and evidence that the service continued to be used after the disputed date. For subscriptions, the strongest material is the terms displayed at signup, evidence that cancellation was available and how, a receipt showing the charge was recurring, and the history of prior undisputed billings on the same credential.
That last point has become a formal mechanism. Visa's compelling evidence framework for fraud-coded disputes lets a merchant defend a transaction by demonstrating a pattern of earlier undisputed transactions from the same cardholder, matched on identifying data such as device fingerprint, IP address, account identifier or delivery address, subject to a minimum age on the prior transactions. Where the criteria are met, liability can shift back to the issuer and the dispute can be kept out of the merchant's ratio. Merchants that retain this data win a class of dispute they would otherwise lose automatically; merchants that do not cannot use the framework at all. Visa revises the requirements, so build to the current specification rather than a summary.
3-D Secure and the liability shift
3-D Secure is the authentication protocol that lets an issuer verify a cardholder during an online checkout — Visa implements it as Visa Secure, Mastercard as Identity Check. The commercial reason to use it is not security in the abstract. It is that a successfully authenticated transaction generally shifts liability for fraud-related chargebacks from the merchant to the issuing bank.
That shift is genuinely valuable and routinely misunderstood. Four limits matter:
- It covers fraud disputes only. Authentication proves who was at the checkout. It says nothing about whether goods arrived, whether they matched the description, or whether a subscription was properly cancelled. Non-fraud reason codes remain the merchant's problem entirely.
- Full authentication and attempted authentication are treated differently. An authentication attempt where the issuer did not or could not respond does not necessarily carry the same protection as a completed one.
- Treatment varies by region, card product and network rules. The European regime, where strong customer authentication is mandated, is not the US regime, where 3-D Secure is optional and applied selectively.
- It costs conversion. A friction step at checkout loses some proportion of legitimate customers, so the correct use is selective — invoked on high-risk or high-value transactions rather than universally. That is why the routing decision is sold as a product in its own right; Forter, for one, sells 3-D Secure routing and exemption handling alongside its fraud decisioning.
A related option is the chargeback guarantee. Vendors including Forter underwrite fraud chargeback liability on the transactions they approve, converting an unpredictable fraud loss into a contracted vendor cost. That is a real transfer of risk, but it is confined to fraud: a guarantee does not cover non-delivery, not-as-described or cancellation disputes, and merchants sometimes discover that boundary at the worst moment.
Pre-dispute alerts and resolution networks
Between the cardholder complaining and the chargeback being filed, there is a window. Both networks now operate services that exploit it. Mastercard operates Ethoca; Visa operates Verifi, with services covering both order-detail inquiry and rules-based automatic resolution.
The mechanics are simple. When a cardholder queries a transaction with their bank, a participating merchant either receives an alert with a short window to refund before the dispute is filed, or has enriched transaction detail pushed back to the issuer so the cardholder can recognize the charge and drop the query, or has a pre-set rule automatically issue a refund and stop the dispute.
The trade is precise. Resolving through an alert means the merchant loses the sale, pays a per-alert fee and refunds the customer — but avoids the chargeback fee and keeps the case out of the count that drives the monitoring programs. For a merchant in or approaching a program, that ratio effect is the point and the alert cost is cheap. For a merchant with a low dispute rate and defensible transactions, blanket automatic refunding gives away revenue on disputes it would have won. Configure to the merchant's position, not the vendor's default.
The monitoring programs, and what happens inside one
The card networks measure every merchant's disputes as a ratio and act when it gets too high. This is the part of dispute management that turns a cost problem into an existential one.
Visa historically ran two separate merchant-level programs: a dispute monitoring program keyed to chargeback counts and ratios, and a fraud monitoring program keyed to fraud dollars and ratios. Visa has since consolidated monitoring into the Visa Acquirer Monitoring Program, which measures a combined ratio of fraud and non-fraud disputes against settled transactions and is assessed at the acquirer level as well as the merchant level. Visa adjusted thresholds and enforcement timing through the rollout, so read the current numbers from Visa's own program documentation rather than any secondary source.
Mastercard runs its Excessive Chargeback Merchant and High Excessive Chargeback Merchant tiers, keyed to a monthly chargeback-to-transaction ratio, alongside an Excessive Fraud Merchant program aimed specifically at card-not-present merchants and keyed to fraud volume, fraud ratio and the merchant's use of authentication.
Crossing a threshold sets off a predictable sequence:
- The network notifies the acquirer, not the merchant. The merchant hears from its acquirer.
- The acquirer demands a written remediation plan and imposes reporting.
- Monthly assessments begin — typically a per-dispute charge on top of existing chargeback fees, escalating the longer the merchant stays in. These are levied on the acquirer and passed through.
- The acquirer protects itself with a rolling reserve, delayed settlement, or a volume restriction.
- If the ratio does not come down, the acquirer terminates the merchant — because the acquirer, not the merchant, is the party the network is penalizing.
What actually reduces disputes
Dispute management splits into two disciplines that are usually confused. Winning representments recovers revenue; reducing disputes protects the merchant account. The second matters more, because the ratio counts every chargeback filed regardless of who eventually wins it. The interventions that move the number, roughly in order of effort-to-effect:
- Fix the billing descriptor. If the name on the statement is a holding company nobody recognizes, a meaningful share of disputes are simply the customer failing to identify their own purchase. Add a recognizable trading name and a working phone number.
- Make cancellation as easy as signup. Every recurring-billing dispute that starts with a customer unable to cancel is a chargeback the merchant manufactured and will lose.
- Send a pre-billing notification on subscriptions, especially before a renewal after a free trial or an annual term. Surprise renewals are one of the most reliable dispute generators in existence.
- Answer customer service faster than the bank does. A cardholder calls the issuer when the merchant does not respond. Response-time targets are dispute-prevention infrastructure.
- Capture and retain evidence at the time of sale. Device identifier, IP address, authentication results, delivery confirmation, accepted terms. It cannot be reconstructed months later, and the frameworks that let a merchant win fraud disputes depend on data stored before the dispute existed.
- Instrument the ratio. Know the merchant's dispute count and ratio against the thresholds now, not after the acquirer's email arrives. Both networks measure monthly; a merchant should too.
- Assign ownership. The single most common cause of a lost representment is that nobody was responsible for the response and the window closed.
One last structural point. A merchant on a payment facilitator such as Stripe, Square or PayPal is a sub-merchant under someone else's master relationship: the facilitator carries the loss, and its risk team can restrict, reserve or close the account on its own judgment. A merchant with its own merchant account and acquirer has more direct visibility into its monitoring status. Neither structure is inherently safer, but they fail differently, and a business should know which failure mode applies to it before its dispute rate starts climbing.
Frequently asked questions
What is the difference between a chargeback and a refund?
A refund is initiated by the merchant, which keeps control of the timing and the customer relationship, and it never enters the card network dispute system or counts toward any monitoring program. A chargeback is initiated by the cardholder's issuing bank, forcibly debits the funds from the merchant along with a fee, and is counted in the merchant's dispute ratio whether or not the merchant later wins it back. Issuing a refund after a chargeback has already been filed does not withdraw the dispute — it results in the merchant paying twice.
What is representment in a card dispute?
Representment is the stage at which a merchant, through its acquirer, resubmits a disputed transaction to the issuing bank with evidence that the original charge was valid. The name is literal: the transaction is presented a second time. It is the merchant's principal opportunity to recover the funds, it operates on a short response window set by network rules, and failing to respond within that window is an automatic loss.
What counts as compelling evidence in a chargeback?
Corroborated, timestamped, third-party records — address verification and card security code results, carrier proof of delivery to the verified address, IP addresses and device identifiers captured at checkout, login and usage logs for digital services, order confirmations, and the terms the customer accepted. Visa also operates a compelling evidence framework that lets merchants defend fraud-coded disputes by demonstrating a history of earlier undisputed transactions from the same cardholder, matched on identifying data. Merchant narrative and internal screenshots without external corroboration generally lose.
Does 3-D Secure stop chargebacks?
No — it shifts liability for a specific category of them. A successfully authenticated 3-D Secure transaction generally moves fraud chargeback liability from the merchant to the issuing bank, but it provides no protection against non-fraud disputes such as goods not received, goods not as described, duplicate processing, or a subscription the customer says they cancelled. Treatment also differs between full and attempted authentication and varies by region and card product.
What is a retrieval request?
A retrieval request, also called a copy request or request for information, is an issuing bank asking a merchant for documentation about a transaction. No funds are debited and it is not a chargeback. Failing to respond can cause the issuer to escalate the case into a full dispute, so a retrieval request should be treated as an opportunity to prevent a chargeback rather than as paperwork.
What happens if a merchant enters a chargeback monitoring program?
The card network notifies the acquirer, which then requires a written remediation plan from the merchant and passes through monthly assessments that escalate the longer the merchant remains in the program. The acquirer will usually also protect itself with a rolling reserve, delayed settlement or a volume restriction. If the ratio does not come down, the acquirer terminates the merchant — and terminated merchants are typically listed on MATCH, a database acquirers check during underwriting, which makes obtaining a new merchant account substantially harder for years afterward.
What are Ethoca and Verifi alerts?
They are pre-dispute resolution services operated by Mastercard and Visa respectively. When a cardholder queries a transaction with their bank, a participating merchant can receive an alert and refund before a chargeback is filed, have enriched purchase detail shown to the cardholder so they recognize the charge, or have a pre-set rule resolve the case automatically. The merchant loses the sale and pays a per-alert fee, but avoids the chargeback fee and keeps the case out of the ratio that drives network monitoring programs.
How long does a cardholder have to file a chargeback?
It depends on the reason code and the network, but the common window is measured in months from the transaction date or the expected delivery date, and certain scenarios — interrupted services, delayed delivery, or a merchant that ceases trading — extend considerably further. Merchants should confirm the applicable windows against current network dispute rules, and should retain transaction evidence for longer than the longest window that applies to their business.