The Conventional Wisdom
Fraud prevention teams often view card network mandates as the main guide for their anti-fraud strategies. When Mastercard and Visa announce new rules, teams update compliance calendars, contact vendors, and fund implementation projects. The logic seems sound: card networks observe fraud patterns across millions of merchants, so their mandates must be effective. Follow the rules, avoid fines, reduce fraud.
This approach assumes that network-level incentives align with merchant-level fraud prevention. They don't.
Why This Approach Falls Short
Card network rules focus on reducing fraud across the network and managing liability. Your fraud challenges are unique. You're dealing with specific attack vectors against your customer base, within your payment flows, and under your risk tolerance and operational constraints.
New rules from Mastercard and Visa encourage more collaboration between merchants and acquiring banks on fraud prevention. While this shift is positive, network mandates set compliance floors, not fraud prevention ceilings. They dictate what you must do to avoid penalties, not what works best for your transactions.
These rules typically address chargeback thresholds, dispute response timelines, and authentication requirements. These are lagging indicators. By the time you're managing chargebacks, the fraud has already occurred, the customer is affected, and you're incurring costs beyond interchange fees.
The core issue: card networks profit from transaction volume, while you lose money on fraud. Your goal is to stop fraud before authorization. Their goal is to process transactions and manage disputes afterward. Network rules won't push you harder than their business model allows.
The Evidence
Consider the fraud types that impact merchants most: account takeover, synthetic identity fraud, return fraud, and promo abuse. Card network rules barely address these because they don't generate chargebacks like CNP fraud or card testing does. The network doesn't feel the pain, so the rules don't cover it.
PCI DSS Requirement 12.8 requires maintaining policies for service providers handling cardholder data. But it doesn't require real-time monitoring of third-party JavaScript on your checkout page. Magecart attacks exploited this gap for years before the industry responded, lagging the threat by at least 18 months.
The same issue arises with authentication mandates. 3-D Secure 2.0 became a requirement, and merchants implemented it. Fraud then shifted to account takeover attacks before checkout. The transaction was "secure" by network standards, but the fraud succeeded because the criminal already controlled the account.
Building your fraud prevention strategy around network compliance means you're always addressing last year's fraud. The rules respond to attacks that have already scaled. By the time a fraud pattern triggers a network mandate, sophisticated fraudsters have moved on.
What to Do Instead
Focus on your actual fraud losses, not just compliance checklists. Conduct a 90-day analysis: What types of fraud are costing you money? Where do they enter your system? What's the financial impact versus the cost to prevent them?
Build your fraud prevention stack in this order:
Instrument your payment flow. You can't prevent what you can't see. Log authorization attempts, failed authentications, velocity patterns, and device fingerprints. Store this data outside your Cardholder Data Environment to avoid expanding PCI DSS scope.
Define your risk thresholds based on your economics, not industry averages. A $50 fraud loss affects a high-margin SaaS company differently than a low-margin retailer. Your friction tolerance varies, and your prevention controls should reflect that.
Test your controls against your actual fraud patterns. If you're seeing account takeovers, add behavioral biometrics or step-up authentication at login. If you're seeing return fraud, scrutinize your returns process as rigorously as your checkout. Don't wait for a network mandate to act.
Use network rules as a baseline, not a target. Meet compliance requirements, then build further. The Visa Compelling Evidence 3.0 framework offers a template for dispute evidence. Use it, but also build monitoring to catch fraud before you need that evidence.
Collaborate with your acquiring bank, but don't outsource your fraud strategy to them. They see patterns across their portfolio; you see patterns in your business. Both perspectives are valuable. Treat new rules pushing merchant-bank collaboration as a communication channel, not just a compliance obligation.
When the Conventional Wisdom Works
Network rules effectively solve specific problems. Chargeback monitoring programs force merchants with systemic fraud to fix their processes or leave the network. EMV liability shift rules drove chip adoption and reduced counterfeit card fraud. Authentication mandates reduced certain types of CNP fraud.
When building a payment system from scratch, network rules provide a reasonable starting framework. They prevent obvious mistakes and establish minimum security baselines.
If your fraud rates are low and stable, compliance-driven fraud prevention might suffice. Not every merchant needs a sophisticated fraud prevention program. If you process 1,000 transactions monthly with minimal fraud, following network rules and letting your processor handle the rest is rational.
The conventional wisdom breaks down when your fraud problem is significant, specific, or evolving faster than network rule cycles. This applies to most mid-size and large merchants, most fintechs, and anyone in a high-fraud vertical.
Card networks will continue issuing rules. Some will help. But your fraud prevention effectiveness depends on understanding your specific risk profile and quickly adapting your controls. Compliance keeps you in the network. Strategy keeps you profitable.



