Skip to main content
Category: Chargebacks and Disputes

TC40 Fraud Report

Also known as: TC40, TC40 Data, TC40 Fraud Record, TC40 Fraud Data
Simply put

A TC40 is a fraud report created by a card issuer in the Visa network when a cardholder claims that a charge was made without their permission. Issuers use it to report those fraud claims to Visa and to share the information with acquiring banks so merchants and processors can monitor fraud activity. It is one of the data sources payment teams use to track fraud and manage chargeback risk.

Formal definition

TC40 is an issuer-generated fraud record within Visa's network, associated with Visa's Risk Identification Service, that captures cardholder fraud claims where the cardholder disputes a transaction as unauthorized. Issuers submit TC40 records to Visa to report fraud and share fraud data with acquiring banks; the data reflects reported fraud claims rather than adjudicated or confirmed fraud, and a TC40 record does not by itself constitute a chargeback or dispute. Per the evidence, TC40 data is used as an input in calculating a merchant's VAMP ratio and in broader fraud-monitoring and chargeback-risk workflows. Note that a TC40 record is a fraud-reporting artifact and is distinct from a formal Visa dispute or chargeback, which are governed separately by Visa network rules; the analogous fraud-reporting mechanism in the Mastercard network is SAFE. Exact reporting thresholds, monitoring-program parameters, and network rules are governed by Visa and are subject to change and regional variation, so readers should confirm current program definitions against Visa's published rules.

Why it matters

A TC40 record is one of the earliest signals a payment team can receive that a cardholder has reported a transaction as unauthorized. Because issuers generate these records when a cardholder claims a charge was made without permission, TC40 data can surface fraud activity before it escalates into a formal Visa dispute or chargeback. This early visibility helps merchants, acquirers, and processors monitor fraud trends and take action to manage chargeback risk. It is important to understand, however, that a TC40 reflects a reported fraud claim rather than adjudicated or confirmed fraud, so the presence of a TC40 record does not on its own establish that fraud occurred.

Who it's relevant to

Fraud Analysts
Fraud analysts use TC40 data as one input among several to identify fraud patterns and track reported unauthorized transactions. Because the data reflects reported claims rather than confirmed fraud, analysts should treat it as a signal to investigate rather than as adjudicated proof, and should weigh it alongside other fraud-monitoring sources.
Merchant Risk Teams
Merchant risk teams monitor TC40 records to understand fraud activity tied to their transactions and to manage chargeback risk before disputes formalize. Since TC40 data can contribute to a merchant's VAMP ratio, these teams have a direct interest in reviewing the reported activity and understanding how it may affect Visa monitoring programs, whose parameters can change and vary by region.
Acquirers and Payment Processors
Acquiring banks receive TC40 fraud data shared through Visa's network and pass relevant information to their merchants and processors. Acquirers and processors rely on this data to help clients monitor fraud and manage chargeback exposure, while recognizing that a TC40 record is not itself a chargeback or formal dispute.
Compliance Officers
Compliance officers should distinguish TC40 fraud reporting from formal Visa dispute and chargeback processes, which are governed separately under Visa network rules. Because reporting thresholds and monitoring-program parameters are set by Visa and subject to change and regional variation, compliance teams should confirm current definitions against Visa's published rules.

Inside TC40

Issuer-Reported Fraud Data
A TC40 record is generated by an issuer when a cardholder or the issuer reports a transaction as fraudulent. It reflects fraud claims associated with an account, not confirmed or adjudicated losses in every case.
Fraud Type Classification
Records typically categorize the reported fraud by a type code, which may distinguish scenarios such as card-not-present fraud, card-present fraud, lost or stolen cards, or account misuse. Specific code sets and definitions are governed by card brand and network rules and vary by network and region.
Transaction Reference Information
Data elements that allow the reported fraud to be tied back to a specific transaction and merchant, such as identifiers for the transaction, the acquiring entity, and the merchant. Exact field layouts depend on the network's specification, which readers should confirm against current network documentation.
Merchant and Acquirer Attribution
The report attributes reported fraud to the merchant and acquirer involved, which supports network fraud-monitoring programs and merchant risk assessment. Attribution does not by itself assign chargeback liability, which is determined separately under network dispute rules.
Network-Specific Format
TC40 is a Visa-associated fraud reporting construct; other networks operate their own analogous fraud-reporting mechanisms. Field names, formats, and delivery differ by network, so the term should not be treated as a single cross-network standard.

Common questions

Answers to the questions practitioners most commonly ask about TC40.

Does a TC40 report represent a confirmed chargeback or financial loss?
No. A TC40 is a fraud notification submitted through a card brand's fraud reporting system (Visa's fraud reporting is often referenced by the TC40 record type), not a chargeback or settled financial loss. It reflects that a transaction was reported as fraudulent, typically by or on behalf of the issuer. A related chargeback may or may not follow, and the two are governed by separate network processes. Treat TC40 data as an indicator of reported fraud rather than proof of a completed dispute or loss amount.
Is TC40 the same thing across all card brands, and does one report cover every network?
No. TC40 is a specific record format associated with Visa's fraud reporting, while other networks use their own fraud reporting mechanisms and formats (for example, Mastercard's fraud reporting differs). A TC40 record does not cover activity on other brands' rails, and the fields, timing, and submission processes vary by network and can change under each brand's rules. Confirm the applicable format and process against the relevant card brand's current documentation rather than assuming a single universal report.
How do acquirers and merchants typically receive TC40 data?
TC40-derived fraud data is generally made available to acquirers through the card brand's reporting channels, and acquirers or their processors may pass relevant information to merchants, often through fraud monitoring or reporting portals. Availability, granularity, and cadence depend on the acquirer, processor, and applicable network rules, so confirm what your specific processor provides and in what format.
How should a merchant use TC40 data operationally without over-relying on it?
TC40 data can help identify patterns of reported fraud, inform rule tuning, and flag potentially compromised accounts or problematic transaction segments. Because it reflects reported rather than adjudicated fraud, it is best used alongside chargeback data, internal fraud signals, and manual review. Relying on it alone may introduce false positives or miss fraud that was never reported, so treat it as one input into a broader fraud strategy.
Does receiving TC40 records affect participation in card brand fraud or dispute monitoring programs?
Card brands operate monitoring programs that consider reported fraud levels, and fraud reporting data can contribute to how an account is evaluated under those programs. Thresholds, program names, and consequences are defined by each brand's rules, vary by region, and change over time. Confirm current program criteria and how reported fraud is counted directly with the applicable card brand and your acquirer.
Can TC40 data be reconciled directly against chargebacks on a one-to-one basis?
Not reliably. Because TC40 reflects reported fraud and chargebacks follow a separate dispute process, they may not map one-to-one; a reported transaction might never become a chargeback, and timing between the two can differ. Reconciliation is possible for analysis but should account for these process differences and the specific matching keys available in your data, rather than assuming every TC40 record has a corresponding chargeback or vice versa.

Common misconceptions

A TC40 record means a chargeback has occurred or that the merchant is liable for the loss.
A TC40 reflects issuer-reported fraud and is distinct from a chargeback or dispute. Chargeback and liability outcomes are governed separately by card brand and network dispute rules, which vary by region and change over time. A fraud report may exist without a corresponding chargeback, and vice versa.
TC40 data is a definitive, confirmed record of fraud losses.
TC40 records represent fraud as reported by issuers and cardholders and can include claims that are later disputed, reclassified, or found to be first-party or friendly fraud. It should be treated as a fraud signal for monitoring rather than an adjudicated ledger of confirmed losses.
TC40 is a universal fraud reporting standard used identically across all card networks.
TC40 is associated with the Visa ecosystem; other networks maintain their own fraud-reporting formats and programs. Definitions, fraud type codes, and field structures differ by network and region, and should be confirmed against the relevant network's current published specification.

Best practices

Treat TC40 data as one fraud signal among several, correlating it with your own chargeback, authorization, and dispute data rather than relying on it as a standalone measure of loss.
Confirm current field layouts, fraud type codes, and delivery mechanisms against the relevant network's published specification, since these vary by network and region and change over time.
Reconcile TC40 fraud reports against chargebacks and dispute outcomes to identify discrepancies, including reported fraud that never becomes a chargeback and first-party or friendly fraud that may be misclassified.
Monitor TC40-derived fraud ratios against the thresholds defined in applicable network fraud-monitoring programs, and verify those thresholds directly with current network rules rather than assuming fixed values.
Handle any cardholder data or transaction identifiers within fraud reports under your defined PCI DSS data-protection controls, and ensure sensitive authentication data is never stored after authorization.
Use TC40 trends to tune card-not-present fraud controls such as 3-D Secure and risk scoring, while accounting for false-positive and false-negative trade-offs rather than treating any single control as eliminating fraud.