Home › KYC providers & costs › iGaming Chargeback Fraud Prevention: CE3.0 & KYC Evidence

iGaming Chargeback Fraud Prevention: CE3.0 & KYC Evidence

IE By iGaming Expert Hub Editorial· Updated 2026-10-08·10 min read

Key takeaways

iGaming chargeback fraud prevention rests on three things: taking deposits in ways that create scheme-recognised evidence (3-D Secure, consistent descriptors, device ID and IP captured on every deposit), keeping KYC records that tie the player to the card, and using Visa Compelling Evidence 3.0 so that a repeat customer's "I never made this deposit" dispute can be returned to the issuer.

This guide is written for operators' payments, fraud and compliance leads. It explains the chargeback types you will actually see, sets out the Visa Compelling Evidence 3.0 criteria as Visa's own merchant FAQ (March 2023) describes them, maps each criterion to the data a cashier and KYC stack already hold, and shows where regulators and the Financial Ombudsman Service draw the line. It is not legal advice and contains nothing that helps a player file a false dispute. Online gambling is for adults only: 19+ in Ontario, 18+ in most other regulated markets. Please play responsibly.

What iGaming chargeback fraud prevention has to cover

A chargeback is the issuing bank reversing a card payment after the cardholder disputes it. For a casino or sportsbook the money has usually already been wagered, so a lost dispute costs the deposit, any winnings already paid out and a scheme fee. The first step in iGaming chargeback fraud prevention is to stop treating "chargebacks" as one problem: there are at least four kinds, and each needs different controls.

True fraud, first-party misuse and processing errors

True fraud is a stolen or compromised card used by someone who is not the account holder. First-party misuse (often called friendly fraud) is the real cardholder, or a household member, disputing a deposit they did make, sometimes because they regret the losses and sometimes because they do not recognise the descriptor. Processing errors are duplicated or wrongly amounted captures. A fourth category, the "cancelled recurring" dispute, arises when a player believes a stored-card or subscription-style debit continued after they asked for it to stop; Visa's FAQ notes that such cases are often classed under Cancelled Recurring rather than fraud, so the fraud-evidence route does not apply to them.

TypeTypical triggerPreventionEvidence to keep
True fraud (third party)Stolen card details used to fund a new account3-D Secure on first deposits, name-on-card vs KYC name match, velocity limits on new cardsAuthentication result, KYC profile, card BIN and country, device fingerprinting record
First-party misuseCardholder disputes a deposit they made, citing non-recognition or regretClear descriptor, deposit confirmation email, login and device capture on every depositLogin ID, device ID, IP address, gameplay and withdrawal history, prior undisputed deposits
Processing errorDuplicate capture or wrong amountIdempotent capture logic, reconciliation before settlementTransaction log with unique Acquirer Reference Number per capture
Cancelled recurringStored-card debit after a player asked to stopHonour stop requests immediately; record the requestConsent record and cancellation timestamp (not a 10.4 case)

Why MCC 7995 merchants feel it more

Every gambling transaction carries merchant category code MCC 7995, and the code applies uniformly to licensed and unlicensed operators. A PXP-commissioned Piran Consulting whitepaper (undated), built on 62 stakeholder interviews, reports that regulated UK gambling merchants run a chargeback rate of about 0.01 percent against a UK average of around 0.6 percent, with fraud below two basis points, yet their card authorisation rates sit at roughly 92 to 95 percent compared with 97 to 99 percent through Apple Pay at the same merchants. Those are the whitepaper's figures, not ours, but they describe the operator's position well: low actual loss, high issuer suspicion. Because both declines and disputes turn on how the issuer reads an MCC 7995 transaction, the evidence attached to each deposit matters more than it would for a retailer.

Visa Compelling Evidence 3.0: the criteria from Visa's own FAQ

Visa Compelling Evidence 3.0 (CE3.0) is Visa's updated rule for fighting disputes filed under fraud condition code 10.4, the card-absent fraud code. Visa's Evolution of Compelling Evidence merchant FAQ (March 2023) explains that when a merchant can show the cardholder has a history of undisputed transactions on the same account, the dispute is invalidated and liability moves to the issuer. The rule took effect in April 2023 (for pre-arbitration attempts processed on or after 15 April 2023), and it applies to all VisaNet merchant category codes, so MCC 7995 deposits are eligible. If you are deciding which vendor should hold the identity and device records this depends on, compare KYC providers on evidence export and retention before you commit.

The 2-of-4 match and the 120-365 day window

In the FAQ's terms, a qualifying CE3.0 response needs an item description for the disputed transaction plus at least two of four data elements that are identical across the disputed transaction and two earlier undisputed transactions: the customer account or login ID, the delivery address, the device ID or device fingerprint, and the IP address. One of the two matching elements must be the device ID/fingerprint or the IP address. The two prior transactions must have been processed between 120 and 365 days before the dispute processing date. Prior transactions that had a non-fraud dispute still count; transactions previously reported as fraud do not. Recurring merchant-initiated transactions are eligible, and Visa notes one exception: for a disputed account-funding transaction, the associated original credit transactions may be 0 to 365 days old.

Pre-dispute (Order Insight) vs post-dispute (VROL)

Operators can use CE3.0 in two places. Pre-dispute, the issuer queries Verifi's Order Insight service before the chargeback is raised; according to Chargeback Gurus (21 May 2026), Visa pre-selects up to five prior undisputed transactions more than 120 days old and the merchant's system must return its evidence automatically within about two seconds, which rules out manual lookups. Post-dispute, the merchant's acquirer submits the same evidence as a pre-arbitration attempt through Visa Resolve Online. The second route is slower but open to any operator whose acquirer supports it.

What does not qualify

CE3.0 does not touch non-fraud reason codes, so a "services not provided" or Cancelled Recurring dispute needs ordinary representment evidence. It does not help a brand-new player with no history, which is why first-deposit controls stay separate. And it is weakened by sloppy data: the FAQ's descriptor guidance (Q10) asks merchants to keep the leftmost characters of the merchant descriptor consistent across transactions and to assign a unique Acquirer Reference Number to each one, because a prior transaction under a different name or a reused reference may not be matched. Mastercard runs its own dispute and compelling-evidence rules; they are outside this guide and should be checked with your acquirer.

Capturing the evidence at deposit, login and withdrawal

None of the CE3.0 elements is exotic. Most operators already collect them for KYC, anti-money-laundering and bonus-abuse work; the gap is that they sit in different systems and cannot be pulled per transaction. The table maps each element to where it is usually captured and who should own retention.

CE3.0 elementWhere the operator captures itRetention / owner
Customer account or login IDPlayer account system at registration and at every login that precedes a depositAccount ID stored on each deposit record; platform team
Delivery addressKYC profile (proof-of-address document) and billing address entered at cashierVerified address version-stamped per deposit; KYC/compliance team
Device ID or device fingerprintDevice fingerprinting SDK in the app or site, written to the deposit eventHash plus raw attributes for at least 13 months (covers the 365-day window); fraud team
IP addressCashier gateway request, logged with the authorisationStored with timestamp and geolocation lookup; payments team
Item descriptionCashier builds "Account deposit, wallet credit" plus internal referenceIncluded in acquirer submission; payments team
Authentication result3-D Secure outcome from the PSPKept with the auth record; payments team

Three practical rules follow. First, write the device ID and IP address to the deposit record itself, not only to a session log that is purged after 90 days, because CE3.0 needs transactions up to 365 days old. Second, make the KYC ID verification documents you collect searchable by card and account, so the proof-of-address on file can be matched to the billing address on the disputed transaction. Third, send the same leftmost descriptor on every deposit, with a unique reference per capture, so the issuer can match history. The same device and account data also powers multi-accounting detection; the bonus abuse prevention guide covers that side. Withdrawals complete the picture: a payout to a bank account in the KYC-verified name, after the disputed deposit, is strong evidence that the person who deposited is the person who was identified.

Regulatory and consumer-side boundaries

Evidence rules only help if the deposit was taken lawfully in the first place. A regulator's ban and one ombudsman decision mark the boundaries operators most often misjudge.

UK: no credit-card gambling since April 2020

The UK Gambling Commission announced on 14 January 2020 that gambling with credit cards would be banned from 14 April 2020, covering all online and offline gambling except non-remote lotteries. The regulator cited figures that about 800,000 UK consumers used credit cards to gamble in 2018 and that 22 percent of online gamblers using credit cards were classed as problem gamblers; it also required all online operators to join the GAMSTOP self-exclusion scheme by 31 March 2020. For a UK-facing operator this is a BIN-level acceptance rule: a credit-card deposit should never reach the point of dispute because it should never be authorised. Ontario operators also work under Alcohol and Gaming Commission of Ontario standards, which they should read alongside this guide.

When a bank is told to raise a chargeback anyway

The Financial Ombudsman Service's final decision DRN-4443965 (November 2023), against National Westminster Bank Plc, shows the consumer side of MCC coding. The complainant said he had a gambling block on his account. An online casino took 54 card payments between August and October 2021 under other merchant names with incorrect merchant category codes, which he said let the payments get past the block. When he disputed them on 19 October 2021, within the 75-day limit under Visa dispute condition 12.7, the bank did not raise chargebacks. The ombudsman found that the bank had mis-characterised the dispute and should have considered raising chargebacks; the complaint was upheld and the bank was told to refund 70 percent of the disputed value, calculated at GBP 3,916.96 as a loss of chance, plus 8 percent simple interest. This is one published decision, not a general rule, but the lesson for operators is direct: honest MCC 7995 coding and consistent descriptors are both a scheme-rule obligation and a chargeback-exposure issue. Deposits taken under a different merchant name or code can be charged back even though the cardholder authorised them, and no CE3.0 history will rescue them.

A representment workflow that respects players

Winning disputes is not the goal; keeping honest customers and a low chargeback ratio is. A workflow that treats every dispute as fraud alienates players who simply did not recognise a descriptor. The sequence below applies the evidence standards above while leaving room for refunds where they are right.

Treat chargeback data as a safer-gambling signal as well. A cluster of disputes from one player after large losses can indicate harm rather than fraud, and the responsible route is to intervene with limits and support information, not only to fight the case. Gambling should remain entertainment: it is for adults only (19+ in Ontario, 18+ elsewhere), and players who are struggling should use the self-exclusion and support tools every licensed operator provides. A KYC stack that stores device and login evidence per transaction is the practical foundation for everything above; compare providers on that capability before you commit.

Frequently asked questions

What is friendly fraud in online gambling?

Friendly fraud, or first-party misuse, is when the genuine cardholder disputes a casino or sportsbook deposit they actually made, often after losing or because they did not recognise the merchant descriptor. Consistent descriptors and login, device and IP capture on every deposit are the main defences.

Does Visa Compelling Evidence 3.0 apply to casino deposits?

Yes. Visa's merchant FAQ (March 2023) states that CE3.0 applies to all VisaNet merchant category codes, so MCC 7995 gambling deposits are eligible, but only for disputes filed under fraud condition code 10.4.

How many prior transactions does CE3.0 need?

Two undisputed transactions on the same account, processed between 120 and 365 days before the dispute processing date, that share at least two of four data elements with the disputed transaction (account/login ID, delivery address, device ID or fingerprint, IP address), one of which must be the device or IP.

Can UK players use credit cards to gamble?

No. The UK Gambling Commission banned gambling with credit cards from 14 April 2020 for all online and offline gambling except non-remote lotteries. Operators should block credit BINs at the cashier rather than rely on disputes later.

Do KYC documents count as chargeback evidence?

They support it. A verified identity and proof-of-address that match the cardholder name and billing address, together with login, device and IP data on the deposit, form the evidence bundle; the KYC record alone does not meet the CE3.0 data-element test.

Authoritative referenceBeGambleAware — responsible gambling ↗

Compare independently vetted sites.

See reviews

18+ only. Gambling can be addictive — please play responsibly and only bet what you can afford to lose. If gambling is affecting you or someone you know, contact a local support service. This content is informational and never a guarantee of winnings.

Written and reviewed by the iGaming Expert Hub editorial team. Facts checked against primary sources; see the reference above.

← All articles