iGaming Chargeback Fraud Prevention: CE3.0 & KYC Evidence
Key takeaways
- Prevention has three pillars: evidence-creating deposits (3-D Secure, consistent descriptors, device ID and IP on every deposit), KYC records tied to the card, and Visa Compelling Evidence 3.0 for repeat customers.
- CE3.0 covers fraud code 10.4 only: item description plus two of four matching elements (account ID, address, device ID, IP; one must be device or IP) across two undisputed transactions 120-365 days old, per Visa's March 2023 merchant FAQ.
- Store device ID and IP on the deposit record itself for at least 13 months; session logs purged at 90 days cannot support a CE3.0 response.
- The UK Gambling Commission banned credit-card gambling from 14 April 2020; block credit BINs at the cashier.
- FOS decision DRN-4443965 (Nov 2023) shows miscoded gambling payments can be charged back even when authorised: keep MCC 7995 and descriptors honest.
iGaming chargeback fraud prevention rests on three things: taking deposits in ways that create scheme-recognised evidence (3-D Secure, consistent descriptors, device ID and IP captured on every deposit), keeping KYC records that tie the player to the card, and using Visa Compelling Evidence 3.0 so that a repeat customer's "I never made this deposit" dispute can be returned to the issuer.
This guide is written for operators' payments, fraud and compliance leads. It explains the chargeback types you will actually see, sets out the Visa Compelling Evidence 3.0 criteria as Visa's own merchant FAQ (March 2023) describes them, maps each criterion to the data a cashier and KYC stack already hold, and shows where regulators and the Financial Ombudsman Service draw the line. It is not legal advice and contains nothing that helps a player file a false dispute. Online gambling is for adults only: 19+ in Ontario, 18+ in most other regulated markets. Please play responsibly.
What iGaming chargeback fraud prevention has to cover
A chargeback is the issuing bank reversing a card payment after the cardholder disputes it. For a casino or sportsbook the money has usually already been wagered, so a lost dispute costs the deposit, any winnings already paid out and a scheme fee. The first step in iGaming chargeback fraud prevention is to stop treating "chargebacks" as one problem: there are at least four kinds, and each needs different controls.
True fraud, first-party misuse and processing errors
True fraud is a stolen or compromised card used by someone who is not the account holder. First-party misuse (often called friendly fraud) is the real cardholder, or a household member, disputing a deposit they did make, sometimes because they regret the losses and sometimes because they do not recognise the descriptor. Processing errors are duplicated or wrongly amounted captures. A fourth category, the "cancelled recurring" dispute, arises when a player believes a stored-card or subscription-style debit continued after they asked for it to stop; Visa's FAQ notes that such cases are often classed under Cancelled Recurring rather than fraud, so the fraud-evidence route does not apply to them.
| Type | Typical trigger | Prevention | Evidence to keep |
|---|---|---|---|
| True fraud (third party) | Stolen card details used to fund a new account | 3-D Secure on first deposits, name-on-card vs KYC name match, velocity limits on new cards | Authentication result, KYC profile, card BIN and country, device fingerprinting record |
| First-party misuse | Cardholder disputes a deposit they made, citing non-recognition or regret | Clear descriptor, deposit confirmation email, login and device capture on every deposit | Login ID, device ID, IP address, gameplay and withdrawal history, prior undisputed deposits |
| Processing error | Duplicate capture or wrong amount | Idempotent capture logic, reconciliation before settlement | Transaction log with unique Acquirer Reference Number per capture |
| Cancelled recurring | Stored-card debit after a player asked to stop | Honour stop requests immediately; record the request | Consent record and cancellation timestamp (not a 10.4 case) |
Why MCC 7995 merchants feel it more
Every gambling transaction carries merchant category code MCC 7995, and the code applies uniformly to licensed and unlicensed operators. A PXP-commissioned Piran Consulting whitepaper (undated), built on 62 stakeholder interviews, reports that regulated UK gambling merchants run a chargeback rate of about 0.01 percent against a UK average of around 0.6 percent, with fraud below two basis points, yet their card authorisation rates sit at roughly 92 to 95 percent compared with 97 to 99 percent through Apple Pay at the same merchants. Those are the whitepaper's figures, not ours, but they describe the operator's position well: low actual loss, high issuer suspicion. Because both declines and disputes turn on how the issuer reads an MCC 7995 transaction, the evidence attached to each deposit matters more than it would for a retailer.
Visa Compelling Evidence 3.0: the criteria from Visa's own FAQ
Visa Compelling Evidence 3.0 (CE3.0) is Visa's updated rule for fighting disputes filed under fraud condition code 10.4, the card-absent fraud code. Visa's Evolution of Compelling Evidence merchant FAQ (March 2023) explains that when a merchant can show the cardholder has a history of undisputed transactions on the same account, the dispute is invalidated and liability moves to the issuer. The rule took effect in April 2023 (for pre-arbitration attempts processed on or after 15 April 2023), and it applies to all VisaNet merchant category codes, so MCC 7995 deposits are eligible. If you are deciding which vendor should hold the identity and device records this depends on, compare KYC providers on evidence export and retention before you commit.
The 2-of-4 match and the 120-365 day window
In the FAQ's terms, a qualifying CE3.0 response needs an item description for the disputed transaction plus at least two of four data elements that are identical across the disputed transaction and two earlier undisputed transactions: the customer account or login ID, the delivery address, the device ID or device fingerprint, and the IP address. One of the two matching elements must be the device ID/fingerprint or the IP address. The two prior transactions must have been processed between 120 and 365 days before the dispute processing date. Prior transactions that had a non-fraud dispute still count; transactions previously reported as fraud do not. Recurring merchant-initiated transactions are eligible, and Visa notes one exception: for a disputed account-funding transaction, the associated original credit transactions may be 0 to 365 days old.
Pre-dispute (Order Insight) vs post-dispute (VROL)
Operators can use CE3.0 in two places. Pre-dispute, the issuer queries Verifi's Order Insight service before the chargeback is raised; according to Chargeback Gurus (21 May 2026), Visa pre-selects up to five prior undisputed transactions more than 120 days old and the merchant's system must return its evidence automatically within about two seconds, which rules out manual lookups. Post-dispute, the merchant's acquirer submits the same evidence as a pre-arbitration attempt through Visa Resolve Online. The second route is slower but open to any operator whose acquirer supports it.
What does not qualify
CE3.0 does not touch non-fraud reason codes, so a "services not provided" or Cancelled Recurring dispute needs ordinary representment evidence. It does not help a brand-new player with no history, which is why first-deposit controls stay separate. And it is weakened by sloppy data: the FAQ's descriptor guidance (Q10) asks merchants to keep the leftmost characters of the merchant descriptor consistent across transactions and to assign a unique Acquirer Reference Number to each one, because a prior transaction under a different name or a reused reference may not be matched. Mastercard runs its own dispute and compelling-evidence rules; they are outside this guide and should be checked with your acquirer.
Capturing the evidence at deposit, login and withdrawal
None of the CE3.0 elements is exotic. Most operators already collect them for KYC, anti-money-laundering and bonus-abuse work; the gap is that they sit in different systems and cannot be pulled per transaction. The table maps each element to where it is usually captured and who should own retention.
| CE3.0 element | Where the operator captures it | Retention / owner |
|---|---|---|
| Customer account or login ID | Player account system at registration and at every login that precedes a deposit | Account ID stored on each deposit record; platform team |
| Delivery address | KYC profile (proof-of-address document) and billing address entered at cashier | Verified address version-stamped per deposit; KYC/compliance team |
| Device ID or device fingerprint | Device fingerprinting SDK in the app or site, written to the deposit event | Hash plus raw attributes for at least 13 months (covers the 365-day window); fraud team |
| IP address | Cashier gateway request, logged with the authorisation | Stored with timestamp and geolocation lookup; payments team |
| Item description | Cashier builds "Account deposit, wallet credit" plus internal reference | Included in acquirer submission; payments team |
| Authentication result | 3-D Secure outcome from the PSP | Kept with the auth record; payments team |
Three practical rules follow. First, write the device ID and IP address to the deposit record itself, not only to a session log that is purged after 90 days, because CE3.0 needs transactions up to 365 days old. Second, make the KYC ID verification documents you collect searchable by card and account, so the proof-of-address on file can be matched to the billing address on the disputed transaction. Third, send the same leftmost descriptor on every deposit, with a unique reference per capture, so the issuer can match history. The same device and account data also powers multi-accounting detection; the bonus abuse prevention guide covers that side. Withdrawals complete the picture: a payout to a bank account in the KYC-verified name, after the disputed deposit, is strong evidence that the person who deposited is the person who was identified.
Regulatory and consumer-side boundaries
Evidence rules only help if the deposit was taken lawfully in the first place. A regulator's ban and one ombudsman decision mark the boundaries operators most often misjudge.
UK: no credit-card gambling since April 2020
The UK Gambling Commission announced on 14 January 2020 that gambling with credit cards would be banned from 14 April 2020, covering all online and offline gambling except non-remote lotteries. The regulator cited figures that about 800,000 UK consumers used credit cards to gamble in 2018 and that 22 percent of online gamblers using credit cards were classed as problem gamblers; it also required all online operators to join the GAMSTOP self-exclusion scheme by 31 March 2020. For a UK-facing operator this is a BIN-level acceptance rule: a credit-card deposit should never reach the point of dispute because it should never be authorised. Ontario operators also work under Alcohol and Gaming Commission of Ontario standards, which they should read alongside this guide.
When a bank is told to raise a chargeback anyway
The Financial Ombudsman Service's final decision DRN-4443965 (November 2023), against National Westminster Bank Plc, shows the consumer side of MCC coding. The complainant said he had a gambling block on his account. An online casino took 54 card payments between August and October 2021 under other merchant names with incorrect merchant category codes, which he said let the payments get past the block. When he disputed them on 19 October 2021, within the 75-day limit under Visa dispute condition 12.7, the bank did not raise chargebacks. The ombudsman found that the bank had mis-characterised the dispute and should have considered raising chargebacks; the complaint was upheld and the bank was told to refund 70 percent of the disputed value, calculated at GBP 3,916.96 as a loss of chance, plus 8 percent simple interest. This is one published decision, not a general rule, but the lesson for operators is direct: honest MCC 7995 coding and consistent descriptors are both a scheme-rule obligation and a chargeback-exposure issue. Deposits taken under a different merchant name or code can be charged back even though the cardholder authorised them, and no CE3.0 history will rescue them.
A representment workflow that respects players
Winning disputes is not the goal; keeping honest customers and a low chargeback ratio is. A workflow that treats every dispute as fraud alienates players who simply did not recognise a descriptor. The sequence below applies the evidence standards above while leaving room for refunds where they are right.
- Classify by reason code first. Only reason code 10.4 (card-absent fraud) disputes go down the CE3.0 path; processing errors are refunded on sight, Cancelled Recurring cases are checked against the player's stop request.
- Pull the KYC and deposit bundle automatically. Account ID, device ID, IP address, 3-D Secure result, verified address and the two best prior undisputed deposits in the 120-365 day window should assemble without a human copying from four screens.
- Check the player's safer-gambling history. If the account has a self-exclusion, deposit limit or block that the operator breached, the dispute is a compliance incident, not a representment opportunity; the FOS decision above is the warning.
- Respond through the right channel. Order Insight if your PSP connects to it, otherwise pre-arbitration through the acquirer and Visa Resolve Online within the scheme's time limit. Keep Mastercard disputes in a separate queue with that scheme's requirements.
- Record the outcome against the account. A player whose dispute was invalidated by CE3.0 evidence may be restricted from card deposits; a player whose dispute was accepted should not be flagged as a fraudster.
- Review descriptors and MCC quarterly. Any new processor, brand or wallet must present the same leftmost descriptor and MCC 7995; this is the single cheapest way to prevent the next wave of first-party misuse.
Treat chargeback data as a safer-gambling signal as well. A cluster of disputes from one player after large losses can indicate harm rather than fraud, and the responsible route is to intervene with limits and support information, not only to fight the case. Gambling should remain entertainment: it is for adults only (19+ in Ontario, 18+ elsewhere), and players who are struggling should use the self-exclusion and support tools every licensed operator provides. A KYC stack that stores device and login evidence per transaction is the practical foundation for everything above; compare providers on that capability before you commit.
Frequently asked questions
What is friendly fraud in online gambling?
Friendly fraud, or first-party misuse, is when the genuine cardholder disputes a casino or sportsbook deposit they actually made, often after losing or because they did not recognise the merchant descriptor. Consistent descriptors and login, device and IP capture on every deposit are the main defences.
Does Visa Compelling Evidence 3.0 apply to casino deposits?
Yes. Visa's merchant FAQ (March 2023) states that CE3.0 applies to all VisaNet merchant category codes, so MCC 7995 gambling deposits are eligible, but only for disputes filed under fraud condition code 10.4.
How many prior transactions does CE3.0 need?
Two undisputed transactions on the same account, processed between 120 and 365 days before the dispute processing date, that share at least two of four data elements with the disputed transaction (account/login ID, delivery address, device ID or fingerprint, IP address), one of which must be the device or IP.
Can UK players use credit cards to gamble?
No. The UK Gambling Commission banned gambling with credit cards from 14 April 2020 for all online and offline gambling except non-remote lotteries. Operators should block credit BINs at the cashier rather than rely on disputes later.
Do KYC documents count as chargeback evidence?
They support it. A verified identity and proof-of-address that match the cardholder name and billing address, together with login, device and IP data on the deposit, form the evidence bundle; the KYC record alone does not meet the CE3.0 data-element test.
Compare independently vetted sites.
See reviews18+ only. Gambling can be addictive — please play responsibly and only bet what you can afford to lose. If gambling is affecting you or someone you know, contact a local support service. This content is informational and never a guarantee of winnings.
Written and reviewed by the iGaming Expert Hub editorial team. Facts checked against primary sources; see the reference above.