In our previous blog, Understanding Chargeback Fraud: Insights and Prevention Strategies, we covered chargeback fraud and its impact on your business, including authentication indicators like the Electronic Commerce Indicator (ECI) and Universal Cardholder Authentication Field (UCAF), and the role of advanced risk systems in mitigating fraud. This blog goes deeper on fraud reporting itself.
TL;DR
Fraud reporting is a critical process for maintaining financial integrity and combating fraudulent activity. When a consumer reports a suspicious transaction to their issuer, it alerts the bank to potential fraud and can flag the transaction for investigation. In this case the charge is not reversed and the merchant keeps the funds, because the fraud liability sits with the issuer. That does not make reporting optional, and the rest of this guide explains why.
Fraud reporting matters because it protects a business even when no money is clawed back on the individual charge. It surfaces fraudulent activity early, ensures it is investigated and addressed, and stops a platform from being misused at scale. Just as importantly, it keeps an organisation compliant with legal and regulatory standards, which avoids penalties and protects credibility. Left unreported, fraud compounds into higher loss rates, network penalties, and reputational damage that far outweigh any single transaction.
The fraud reporting cycle runs from the cardholder's report through the issuer, the card networks, and back to the merchant's PSP, with the networks monitoring the merchant's fraud levels throughout. At its centre is the risk engine.
The job of a risk engine is to block as many fraudulent transactions as possible while minimising the impact on genuine ones. That means balancing fraud detection against false positives, where a legitimate transaction is wrongly flagged. False positives inconvenience customers and can damage business relationships, so keeping them low is essential to trust and satisfaction.
The reporting process itself moves through four stages:
Visa and Mastercard each run their own fraud monitoring and reporting frameworks, and merchants are expected to work within them.
Visa. Visa operates a fraud prevention system called Visa Advanced Authorization, which monitors transactions in real time for suspicious activity. It encourages merchants and financial institutions to report fraud through the Visa Fraud Monitoring Program (VFMP), which tracks fraud trends and provides insights to improve prevention.
Mastercard. Mastercard's framework includes the Mastercard Fraud Alert Management (FAM) system, which lets issuers report fraudulent activity and receive alerts about potential threats. Mastercard also uses ECI and UCAF values to indicate the level of authentication and fraud prevention applied to a transaction.
ECI and UCAF values signal how much authentication and security was applied to an online transaction, which in turn determines eligibility for liability protection and how fraud reports are raised.
ECI 5 and 6 for Visa. An ECI value of 5 indicates a fully authenticated transaction, giving the merchant liability protection. An ECI value of 6 indicates an attempted authentication, which may still offer some liability-shift protection. Transactions under these ECIs are typically raised as fraud reports when fraud is detected.
UCAF 1 and 2 for Mastercard. UCAF values indicate whether the merchant supports UCAF data collection. A value of 1 means the merchant supports UCAF but the data was not present in the authorisation message; a value of 2 means UCAF data was collected and present. These values help determine the level of fraud protection and reporting requirements.
American Express and Discover run their own authentication and fraud-reporting tools alongside Visa and Mastercard.
American Express. Amex emphasises prevention through its SafeKey technology, which adds a layer of security to online transactions. Its Fraud Protection Guarantee ensures cardholders are not held responsible for unauthorised charges, and it operates a dedicated fraud reporting hotline for immediate assistance.
Discover. Discover offers several fraud prevention and reporting tools, including Discover ProtectBuy, which helps authenticate online purchases. It also runs a fraud monitoring system and encourages cardholders to report suspicious activity immediately through customer service.
A good payment service provider (PSP) mitigates fraud by combining real-time detection, tailored risk models, and chargeback handling, so merchants are protected from losses without turning away genuine customers. Here is how a strong PSP helps across the fraud lifecycle:
Taken together, these strategies let a merchant focus on growth while the PSP maintains financial security.
A robust fraud reporting system is vital for safeguarding your business. Clear reporting channels, thorough documentation, and collaboration with authorities let businesses combat fraud and protect their assets, and regular training, advanced technology, and a culture of integrity make those programs more effective.
At PayGlocal, we work to help merchants navigate fraud effectively. We currently maintain a false positive rate of less than ~0.1%, meaning that out of every 1,000 transactions, only about one legitimate transaction might be incorrectly flagged as fraudulent, which reflects our focus on both security and customer experience. PayGlocal is authorised by the Reserve Bank of India as a Payment Aggregator - Cross Border - Inward & Outward (PA-CB-I&O) and as an Online Payment Aggregator (PA-O), and is part of the ICICI Bank Group.
TL;DR
- Fraud reporting flags suspicious transactions to issuers and card networks. Even when a charge is not reversed, it protects merchants from escalating losses, penalties, and deactivation.
- Card networks track a merchant's fraud-to-sales ratio; breach the threshold and you get a warning, then penalties, then possible deactivation if it stays high.
- A strong payment service provider (PSP) lowers this risk with pattern analysis, real-time detection, machine-learning models, risk scoring, and chargeback management, while keeping false positives low.
Fraud reporting is a critical process for maintaining financial integrity and combating fraudulent activity. When a consumer reports a suspicious transaction to their issuer, it alerts the bank to potential fraud and can flag the transaction for investigation. In this case the charge is not reversed and the merchant keeps the funds, because the fraud liability sits with the issuer. That does not make reporting optional, and the rest of this guide explains why.
Why does fraud reporting matter?
Fraud reporting matters because it protects a business even when no money is clawed back on the individual charge. It surfaces fraudulent activity early, ensures it is investigated and addressed, and stops a platform from being misused at scale. Just as importantly, it keeps an organisation compliant with legal and regulatory standards, which avoids penalties and protects credibility. Left unreported, fraud compounds into higher loss rates, network penalties, and reputational damage that far outweigh any single transaction.
How does the fraud reporting cycle work?
The fraud reporting cycle runs from the cardholder's report through the issuer, the card networks, and back to the merchant's PSP, with the networks monitoring the merchant's fraud levels throughout. At its centre is the risk engine.
The job of a risk engine is to block as many fraudulent transactions as possible while minimising the impact on genuine ones. That means balancing fraud detection against false positives, where a legitimate transaction is wrongly flagged. False positives inconvenience customers and can damage business relationships, so keeping them low is essential to trust and satisfaction.
The reporting process itself moves through four stages:
- Cardholder notification. When a transaction occurs, the cardholder is notified. If it is fraudulent, they report it to their issuer.
- Issuer action. The issuer records the fraud report and shares the data with the card networks (Visa and Mastercard) at predefined intervals.
- Network analysis. The networks analyse the data and pass it to the acquirer, who sends it to the aggregator and their technology service provider. This is both a heads-up about fraud and a prompt to optimise risk engines.
- Tracking and monitoring. Networks track the fraud-to-sales ratio on a merchant's platform. If it breaches a threshold, early warning signals are issued and the merchant gets three months to optimise. If the threshold is still breached, penalties follow, and continued high ratios can lead to merchant deactivation.
How do the major card networks handle fraud reporting?
Visa and Mastercard each run their own fraud monitoring and reporting frameworks, and merchants are expected to work within them.
Visa. Visa operates a fraud prevention system called Visa Advanced Authorization, which monitors transactions in real time for suspicious activity. It encourages merchants and financial institutions to report fraud through the Visa Fraud Monitoring Program (VFMP), which tracks fraud trends and provides insights to improve prevention.
Mastercard. Mastercard's framework includes the Mastercard Fraud Alert Management (FAM) system, which lets issuers report fraudulent activity and receive alerts about potential threats. Mastercard also uses ECI and UCAF values to indicate the level of authentication and fraud prevention applied to a transaction.
What role do ECI and UCAF play in fraud reporting?
ECI and UCAF values signal how much authentication and security was applied to an online transaction, which in turn determines eligibility for liability protection and how fraud reports are raised.
ECI 5 and 6 for Visa. An ECI value of 5 indicates a fully authenticated transaction, giving the merchant liability protection. An ECI value of 6 indicates an attempted authentication, which may still offer some liability-shift protection. Transactions under these ECIs are typically raised as fraud reports when fraud is detected.
UCAF 1 and 2 for Mastercard. UCAF values indicate whether the merchant supports UCAF data collection. A value of 1 means the merchant supports UCAF but the data was not present in the authorisation message; a value of 2 means UCAF data was collected and present. These values help determine the level of fraud protection and reporting requirements.
How do Amex SafeKey and Discover ProtectBuy fit in?
American Express and Discover run their own authentication and fraud-reporting tools alongside Visa and Mastercard.
American Express. Amex emphasises prevention through its SafeKey technology, which adds a layer of security to online transactions. Its Fraud Protection Guarantee ensures cardholders are not held responsible for unauthorised charges, and it operates a dedicated fraud reporting hotline for immediate assistance.
Discover. Discover offers several fraud prevention and reporting tools, including Discover ProtectBuy, which helps authenticate online purchases. It also runs a fraud monitoring system and encourages cardholders to report suspicious activity immediately through customer service.
How does a PSP help merchants mitigate fraud?
A good payment service provider (PSP) mitigates fraud by combining real-time detection, tailored risk models, and chargeback handling, so merchants are protected from losses without turning away genuine customers. Here is how a strong PSP helps across the fraud lifecycle:
- Pattern analysis. When fraud reporting data comes in, the PSP analyses it for patterns and blocks the offending credentials to prevent repeat misuse.
- Focus on high-risk areas. The PSP works with internal teams to apply stricter measures to high-risk sectors such as resalable goods, quick delivery, foodtech, and online travel agencies (OTAs).
- Advanced fraud detection tools. Real-time tools counter strategies like BIN attacks, distributed attempts with differentiated device fingerprints, and account takeover, using behavioural analysis to identify and terminate fraudulent accounts.
- Machine learning models. State-of-the-art models continuously refine detection and adapt to evolving fraud patterns, with specific AI models and rules tuned to each business type (food delivery, quick delivery, restaurant booking, and so on).
- Fraud vector identification. A screening system provides features for specific businesses, for example protecting against enumeration attacks in food delivery and first-party fraud in quick delivery, by tailoring the risk engine to each distinct vector.
- Customised risk profiles. The PSP builds profiles around transaction volume, customer location, and payment method to assess each transaction's risk accurately.
- Risk scoring. Transaction risk scores drive automated accept-or-decline decisions, improving efficiency and reducing fraud.
- Chargeback management. The PSP supplies insights and data for dispute resolution, integrates fraud reporting into the risk engine, and ensures fraudulent accounts are reported and blocked quickly.
Taken together, these strategies let a merchant focus on growth while the PSP maintains financial security.
In a nutshell
A robust fraud reporting system is vital for safeguarding your business. Clear reporting channels, thorough documentation, and collaboration with authorities let businesses combat fraud and protect their assets, and regular training, advanced technology, and a culture of integrity make those programs more effective.
At PayGlocal, we work to help merchants navigate fraud effectively. We currently maintain a false positive rate of less than ~0.1%, meaning that out of every 1,000 transactions, only about one legitimate transaction might be incorrectly flagged as fraudulent, which reflects our focus on both security and customer experience. PayGlocal is authorised by the Reserve Bank of India as a Payment Aggregator - Cross Border - Inward & Outward (PA-CB-I&O) and as an Online Payment Aggregator (PA-O), and is part of the ICICI Bank Group.

