Skip to main content
Category: Chargebacks and Disputes

Chargeback

Also known as: payment reversal, card transaction dispute reversal
Simply put

A chargeback is a reversal of funds from a debit or credit card purchase, set in motion when a cardholder disputes a charge with their bank. Instead of asking the merchant directly for a refund, the customer contacts their card issuer, which may return the money to the payer. The specific rules and outcomes depend on the card brand and network involved.

Formal definition

A chargeback is a card-network dispute mechanism in which a cardholder's issuing bank reverses the settlement of a debit or credit card transaction after the cardholder disputes the charge. It differs from a merchant-initiated refund in that it is initiated through the issuer and processed under card brand and network dispute rules, which vary by region and change over time. Chargebacks may arise from a range of causes, including genuine unauthorized use, processing errors, and disputes over goods or services, as well as friendly fraud (also called chargeback fraud), an industry term for authorized cardholders who dispute seemingly legitimate charges. The applicable dispute reason codes, evidence requirements, timelines, and any liability allocation are governed by the relevant card network rules rather than by PCI DSS, and this entry does not address the separate technical controls that protect cardholder data.

Why it matters

Chargebacks are a core mechanism of consumer protection in card payments, giving cardholders a route to recover funds through their issuing bank when they dispute a charge rather than resolving the matter directly with the merchant. For merchants, acquirers, and payment processors, chargebacks represent both a financial exposure and an operational burden: disputed transactions can result in reversed settlements, added fees, and administrative work to compile evidence, all governed by card brand and network rules that vary by region and change over time.

Chargebacks also intersect with fraud, but not in a single, uniform way. A dispute may stem from genuine unauthorized use of a card, from processing errors, or from disagreements over goods and services actually received. It may also stem from friendly fraud (also called chargeback fraud), an industry term for authorized cardholders who dispute charges that appear legitimate. Because these causes are handled differently under network dispute rules, teams that treat all chargebacks as identical risk misclassifying disputes and applying the wrong response.

It is important to separate the chargeback process from the technical controls that protect cardholder data. Chargeback reason codes, evidence requirements, timelines, and any allocation of liability are defined by the relevant card network rules, not by PCI DSS. This entry does not address data-protection controls, and readers should confirm current dispute procedures against the applicable card brand and network documentation rather than assuming fixed rules.

Who it's relevant to

Merchants and merchant risk teams
Merchants bear the direct financial and operational impact of chargebacks, including reversed settlements and the effort of compiling evidence to contest disputes. Distinguishing genuine unauthorized use from friendly fraud and from service-related disputes helps teams respond appropriately, though the applicable evidence requirements and timelines are set by card network rules rather than by the merchant.
Acquirers and payment processors
Acquirers and processors sit between merchants and issuers in the dispute flow and must operate within card brand and network dispute rules. They handle the mechanics of reason codes, timelines, and any liability allocation as defined by the relevant network, which vary by region and change over time.
Fraud analysts
Chargeback data is a signal fraud analysts use to distinguish fraud types, such as genuine unauthorized use from friendly or first-party fraud. Analysts should treat chargebacks as one input rather than a definitive fraud label, since disputes can arise from processing errors and disagreements over goods or services as well as from fraud, and any detection approach involves trade-offs between false positives and false negatives.
Compliance officers
Compliance teams should note that chargeback dispute procedures are governed by card brand and network rules, not by PCI DSS. Chargeback handling is separate from the technical controls that protect cardholder data, and the two should not be conflated when assessing obligations.

Inside Chargeback

Dispute initiation
The stage at which a cardholder, or in some cases the issuer on the cardholder's behalf, formally disputes a transaction, which begins the chargeback process according to the applicable card brand and network rules.
Reason code
A code assigned by the card network that categorizes the basis of the dispute, such as fraud, processing error, authorization issues, or goods and services not received or not as described. Specific codes and their meanings are defined by each card brand and can change over time.
Representment
The merchant or acquirer response to a chargeback, in which compelling evidence is submitted to challenge the dispute. What qualifies as acceptable evidence is governed by card brand and network rules, which vary by region and reason code.
Liability allocation
The determination of which party bears the financial loss for a disputed transaction. Liability outcomes, including any liability shift associated with EMV chip acceptance or 3-D Secure, are governed by card brand and network rules that change and vary by region rather than by PCI DSS.
Arbitration and pre-arbitration
Escalation stages available when a dispute remains unresolved after representment, in which the card network may adjudicate the outcome under its published dispute rules.

Common questions

Answers to the questions practitioners most commonly ask about Chargeback.

Is a chargeback the same thing as a refund?
No. A refund is a merchant-initiated return of funds to the cardholder, typically processed directly through the merchant's payment channel. A chargeback is a card-network dispute mechanism initiated by the cardholder through their issuing bank, which forces a reversal of funds through the network rather than through the merchant's own goodwill. The two follow different processes, involve different parties, and carry different implications for the merchant.
Does receiving a chargeback always mean fraud occurred?
No. A chargeback can arise from many causes that are not fraud, including processing errors, non-receipt of goods or services, cancelled recurring billing, or disputes over the quality of what was delivered. Some chargebacks also stem from first-party or friendly fraud, where the cardholder disputes a legitimate transaction. The dispute reason code assigned by the issuer indicates the stated basis, but that basis is a claim to be evaluated, not a confirmed finding of fraud.
What determines whether a merchant can successfully dispute a chargeback?
The ability to represent a chargeback depends on the reason code cited, the compelling evidence permitted for that code, and the timeframes and rules set by the relevant card brand and network. These rules vary by region and change over time, so merchants should confirm the current requirements for the specific network and reason code involved rather than relying on a fixed procedure. Documentation such as proof of delivery, transaction records, and authentication results may support representment depending on the case.
How does 3-D Secure relate to chargeback liability?
3-D Secure is intended to authenticate the cardholder in card-not-present transactions, and in some cases a successful authentication may shift liability for certain fraud-related chargebacks from the merchant toward the issuer. The specifics of any liability shift are governed by card brand and network rules, which vary by region and change over time. 3-D Secure addresses only certain fraud-related dispute categories and does not affect chargebacks arising from processing errors, non-delivery, or service quality disputes.
What operational data should a merchant retain to manage chargebacks?
Merchants generally benefit from retaining transaction authorization records, order and delivery documentation, customer communications, and any authentication results associated with a transaction, so this information is available within the network's dispute timeframes. Any retention must comply with applicable data-handling controls; note that sensitive authentication data must not be stored after authorization even when encrypted, so retained evidence should rely on permissible cardholder data and business records rather than prohibited elements.
How do chargeback monitoring programs affect a merchant?
Card brands and networks operate monitoring programs that track a merchant's chargeback activity against defined thresholds, and merchants exceeding those thresholds may face additional fees, remediation requirements, or other consequences under the applicable program rules. These thresholds, program names, and consequences are set by each network, vary by region, and change over time, so merchants should confirm current program terms with their acquirer rather than assuming fixed criteria.

Common misconceptions

A chargeback and fraud are the same thing.
A chargeback is a dispute and reversal mechanism defined by card brand and network rules. It may result from confirmed fraud, but it can also arise from processing errors, non-receipt of goods, or friendly or first-party fraud where the legitimate cardholder disputes a valid purchase. Distinguishing these fraud types matters because they call for different evidence and controls.
Winning a chargeback or shifting liability prevents future fraud losses.
Chargeback outcomes and liability shifts, such as those tied to EMV chip authentication or 3-D Secure, only allocate financial responsibility for individual transactions under network rules. They are intended to reallocate liability, not to eliminate fraud, and no single control prevents card-present or card-not-present fraud, account takeover, or synthetic identity fraud.
Chargeback rules, reason codes, and liability outcomes are fixed and uniform worldwide.
These are governed by card brand and network rules that change over time and vary by region. Reason codes, evidence requirements, timeframes, and liability determinations should be confirmed against the current network rules applicable to the transaction rather than assumed to be constant.

Best practices

Map each dispute to the correct card network reason code and confirm evidence requirements against the current card brand and network rules for the applicable region before responding.
Retain transaction and delivery records needed for representment while ensuring sensitive authentication data such as full track data, CAV2/CVC2/CVV2/CID, and PINs is not stored after authorization, and that any retained cardholder data is protected under defined controls.
Distinguish among fraud types, such as card-not-present fraud, account takeover, chargeback fraud, and friendly or first-party fraud, so that dispute handling and any preventive controls target the actual driver.
Treat authentication mechanisms such as EMV chip authentication and 3-D Secure as tools that may reduce specific fraud exposure or affect liability allocation under network rules, without assuming any single control eliminates disputes.
Monitor chargeback ratios and reason-code trends over time to identify systemic issues, while recognizing that detection and dispute-management thresholds involve false-positive and false-negative trade-offs.
Periodically review dispute, representment, and liability-shift processes against updated card brand and network rules, since these vary by region and change over time.