Skip to main content
Category: Chargebacks and Disputes

Compelling Evidence 3.0

Also known as: CE3.0, Visa Compelling Evidence 3.0, CE 3.0
Simply put

Compelling Evidence 3.0 is a Visa initiative that updates the rules for handling certain card-absent fraud disputes, allowing merchants to use a cardholder's prior purchase history to show that a challenged transaction is legitimate. It is intended to help merchants respond to first-party misuse, sometimes called friendly fraud, where a genuine cardholder disputes a purchase they actually made. The updated rules took effect on 15 April 2023.

Formal definition

Compelling Evidence 3.0 (CE3.0) is a Visa initiative title referring to an update to the dispute rules governing Visa reason code 10.4 (Fraud—Card Absent Environment), effective 15 April 2023. Under these rules, a merchant may submit compelling evidence based on a cardholder's established purchase history to demonstrate a prior legitimate transaction relationship, and the process allows the acquirer to remedy the dispute rather than supply the evidence through later dispute stages. CE3.0 is designed to address first-party misuse (friendly fraud) by weighting historical transaction data as evidence of a transaction's legitimacy. Note that these are Visa card brand dispute rules, which vary by region and change over time; merchants and acquirers should confirm current requirements, eligible evidence, and effective dates against Visa's published documentation.

Why it matters

First-party misuse, sometimes called friendly fraud, is a difficult category for merchants because the person disputing the transaction is the genuine cardholder who actually made the purchase. In card-absent environments, disputes filed under Visa reason code 10.4 (Fraud—Card Absent Environment) can be hard to contest, since the merchant may lack the kind of evidence that clearly ties a specific transaction back to the legitimate cardholder. Compelling Evidence 3.0 (CE3.0) is Visa's initiative to update these dispute rules so that a cardholder's established purchase history can be weighted as evidence that a challenged transaction is legitimate.

For merchants operating in card-not-present channels, CE3.0 matters because it provides a defined pathway to respond to certain 10.4 disputes using historical transaction data rather than only transaction-specific proof. This is intended to help distinguish true unauthorized-use fraud from first-party misuse, though it does not eliminate either category of dispute. It is important to understand what CE3.0 does not do: it is a specific Visa dispute rule update tied to reason code 10.4, not a general fraud-prevention control, and it does not address card-present fraud, account takeover, or other dispute reason codes.

Because CE3.0 governs Visa dispute rules, its eligibility criteria, acceptable evidence, and process details are set by Visa and are subject to change and regional variation. Merchants and acquirers should treat the 15 April 2023 effective date and the eligible-evidence requirements as items to confirm against Visa's current published documentation rather than as fixed, permanent conditions.

Who it's relevant to

Card-not-present merchants
Merchants selling in card-absent channels are the primary audience for CE3.0, since it provides a defined way to respond to certain reason code 10.4 disputes using a cardholder's purchase history. These merchants should review Visa's readiness guidance to understand which transactions and evidence qualify, and should confirm current requirements against Visa's published documentation rather than assuming the rules remain static.
Acquirers
Under CE3.0, the updated rules allow the acquirer to remedy the dispute rather than requiring the merchant to supply evidence only through later dispute stages. Acquirers need to understand how this changes their role in the dispute workflow and ensure their processes align with Visa's current rules for reason code 10.4.
Payment processors and platforms
Processors and payment platforms may build support for submitting CE3.0 evidence on behalf of merchants, weighting a cardholder's transaction history in dispute responses. They should track Visa's published rules to keep their implementations aligned with eligible evidence requirements and effective dates.
Dispute and chargeback management teams
Analysts and teams handling chargebacks need to know when a 10.4 dispute may be eligible for a CE3.0 response and what historical transaction evidence can be assembled. Because CE3.0 targets first-party misuse specifically and does not cover all dispute types, these teams should apply it within the scope Visa defines and verify criteria against current documentation.

Inside CE3.0

Prior undisputed transaction evidence
A framework that allows a merchant to rebut a card-not-present fraud dispute by demonstrating a history of prior transactions from the same cardholder that were not disputed, used to establish a pattern of legitimate activity.
Matching data elements
Specific data points that must correspond between the disputed transaction and the prior undisputed transactions, which may include identifiers such as customer account or device information, shipping address, and other transactional attributes, subject to the network's defined requirements.
Qualifying time window
A defined period within which the prior undisputed transactions must have occurred relative to the disputed transaction in order to be eligible as compelling evidence. Confirm the exact window against the current card brand rules.
Dispute reason code applicability
CE3.0 applies to specific card-not-present fraud dispute categories as defined by the card network. It does not apply universally to all chargeback or dispute reason codes.
Liability outcome
When the required evidence criteria are met, the framework is intended to shift or influence liability for the disputed card-not-present transaction according to the network's rules, which govern the process rather than PCI DSS.

Common questions

Answers to the questions practitioners most commonly ask about CE3.0.

Does Compelling Evidence 3.0 guarantee that a merchant will win a dispute if they submit the required data?
No. CE3.0 is a dispute-response framework defined by the card network that establishes what evidence may qualify to remedy or reassign certain card-not-present fraud disputes, typically those alleging that the cardholder did not participate in the transaction. It is intended to help merchants challenge specific dispute categories, but it does not guarantee an outcome. Whether submitted evidence qualifies depends on the network's rules, the specific dispute reason code, regional variations, and the reviewing party's assessment. Merchants should confirm current requirements against the applicable card brand's published rules rather than assume a favorable result.
Is CE3.0 a PCI DSS requirement or something a QSA validates?
No. CE3.0 is not part of PCI DSS or any PCI Security Standards Council standard, and it is not assessed by a QSA. It is a chargeback and dispute-handling framework governed by card brand and network rules, which differ from the PCI standards that address protection of cardholder data and sensitive authentication data. PCI DSS and CE3.0 address different concerns—data protection versus dispute remediation—and should not be conflated. Applicability, evidence criteria, and effective dates for CE3.0 are set by the relevant network and may vary by region and change over time.
What types of data does CE3.0 typically call for to support a dispute response?
Network rules for CE3.0 generally describe transaction-linking data elements intended to show a pattern of prior undisputed activity by the same cardholder, which may include identifiers such as a customer account or login, a device or IP association, a shipping or billing address, or similar attributes across prior transactions. The exact data elements, matching criteria, and number of qualifying prior transactions are defined by the applicable card brand's current rules and can vary by region. Merchants should confirm the precise required elements against the network's published documentation. Note that any handling of this data must still comply with applicable data-protection obligations.
How does CE3.0 differ from providing standard chargeback representment evidence?
Standard representment generally relies on transaction-specific proof such as delivery confirmation or proof of service for the disputed order. CE3.0 is oriented toward demonstrating a history of prior, undisputed transactions tied to the same cardholder through common data elements, which is intended to address disputes that allege the cardholder did not authorize or participate in the transaction. The two approaches are not mutually exclusive, and the qualifying criteria, dispute reason codes, and acceptance of each are defined by network rules that vary by brand and region and change over time.
What operational data should a merchant retain to be able to use CE3.0?
To attempt a CE3.0 response, a merchant typically needs to be able to link the disputed transaction to prior transactions using consistent identifiers, so retaining and being able to query historical transaction attributes over the timeframe the network specifies is generally important. The specific fields and retention window depend on the current network rules and should be confirmed against them. Any such retention should be designed to avoid storing sensitive authentication data after authorization and to align with PCI DSS scope and applicable privacy and data-protection requirements, since CE3.0 does not override those obligations.
Does using CE3.0 reduce a merchant's underlying fraud exposure?
Not directly. CE3.0 is a dispute-response mechanism applied after a transaction is disputed; it may help a merchant contest certain card-not-present disputes but is not a fraud-prevention control. It does not, by itself, reduce the likelihood of fraudulent transactions occurring, and it may have limited applicability to first-party or friendly-fraud scenarios depending on network rules. Fraud exposure is more appropriately addressed through preventive and detective controls such as authentication and risk screening, while CE3.0 addresses a narrower, post-dispute stage governed by card brand rules.

Common misconceptions

CE3.0 is a PCI DSS control or requirement.
CE3.0 is a card brand and network dispute/chargeback rule governing card-not-present fraud disputes. It is not a PCI DSS requirement and is separate from standards such as PCI DSS, PA-DSS, the PCI Software Security Framework, PCI PIN, PCI P2PE, and PCI 3DS. Confirm details against the current card network rules.
Meeting CE3.0 criteria guarantees the merchant wins the dispute.
Submitting qualifying evidence is intended to help the merchant rebut a card-not-present fraud dispute and may influence the liability outcome, but it does not guarantee a win. Eligibility, matching data elements, time windows, and outcomes are governed by network rules that vary by region and change over time.
CE3.0 addresses all fraud and dispute types.
CE3.0 applies to specific card-not-present fraud dispute reason codes as defined by the network. It does not cover card-present fraud, chargeback fraud, or other dispute categories, and it does not itself prevent fraud such as account takeover, friendly/first-party fraud, or synthetic identity fraud.

Best practices

Confirm the current eligibility criteria, required matching data elements, and qualifying time window directly against the card network's published rules rather than assuming fixed values, as these vary by brand and region and change over time.
Verify which specific card-not-present dispute reason codes CE3.0 applies to before relying on it as a representment strategy.
Retain and be able to retrieve the transactional data elements needed to link disputed transactions to prior undisputed ones, while ensuring any stored data is handled under appropriate controls and that sensitive authentication data is never stored after authorization.
Treat CE3.0 as one component of a broader dispute and fraud strategy alongside authentication controls such as 3-D Secure, rather than as a standalone means of eliminating card-not-present fraud.
Track dispute outcomes to understand how often evidence submissions are accepted, recognizing that results depend on network adjudication and may vary.
Coordinate with acquirers and processors to ensure evidence is submitted in the correct format and within required timeframes defined by the network rules.