Authentication has been one of the more successful pieces of payments regulation of the past decade. Remote card fraud is harder to commit, approval rates have recovered from the early friction that followed full enforcement in March 2022, and liability for an unauthorised transaction passes to the issuer whenever a payment has been authenticated to the standard. Merchants who invested properly can point to a clear return.
The useful question now is what to do about everything the mechanism does not cover. A customer who received the goods, watched the film, played the game or took the flight, and then asked the bank for the money back, has not been stopped by a one-time passcode or a biometric prompt. The authentication was valid, the cardholder was genuine, and the chargeback still lands on the merchant.
Treating that as a separate discipline is where the margin is. The businesses making progress have stopped filing every dispute under the heading of fraud and started managing two distinct problems with two distinct sets of tools. What follows is how they are doing it.
Start with the split
Any improvement starts with separating fraud reason codes from the rest, because the two categories behave nothing alike. Liability transfer under 3D Secure applies to claims of unauthorised use and to nothing else. A dispute raised because an item never arrived, a service was not delivered as described, a subscription renewed unexpectedly, or a descriptor on a statement went unrecognised, sits wholly outside it.
A month of dispute data split along that line usually produces the first surprise. Merchants who assumed authentication had solved the problem typically find the fraud codes are the smaller pile, and that the larger one has been growing without anyone owning it. Assigning a name to each category, and a different owner, turns an undifferentiated loss line into two manageable workstreams.
Follow the exposure
Exposure is not spread evenly across a catalogue, and knowing where it sits allows resource to follow it. Merchant Risk Council and LexisNexis data puts first-party misuse at between 60% and 75% of total disputes in streaming, gaming, digital downloads and travel. Intangible goods and recurring billing carry the heaviest weight, because the evidence a merchant can produce is thinner than a signed delivery receipt.
Consumer behaviour explains the concentration. Banking apps have reduced raising a dispute to a two-tap exercise, and a meaningful proportion of cardholders use it as a quicker route than a refund request. The intent is rarely criminal, which is exactly why fraud controls do not catch it, and why clearer billing descriptors, sharper renewal notifications and faster refunds remove a measurable slice of volume before it reaches the bank.
Price the full claim
Building a business case for any of this work requires the full cost of a dispute, and the disputed amount is only part of it. LexisNexis put the all-in figure at $5.13 for every $1 lost in its 2026 True Cost of Fraud study for retail and ecommerce in North America, the first time the multiplier has passed $5, with the Canadian equivalent at $5.23. Scheme fees, lost goods, shipping, payment processing and the staff hours spent assembling evidence all sit inside it.
Recovery economics sharpen the case further. Contesting a dispute consumes analyst time whether or not the merchant prevails, and the net sum recovered after second presentments and administration is a fraction of the headline win rate. Prevention and transferred liability are worth considerably more per pound than argument after the fact, which is the number that usually unlocks the budget.
Build for the volume
Capacity planning works better against a published forecast than against last year’s total. Global dispute cases are expected to rise 24% between 2025 and 2028, from 261 million to 324 million, on figures from Mastercard with Datos Insights. Card-not-present payments now account for 63% of merchant transactions, and dispute volume is tracking that expansion closely.
The financial curve follows the same line, with worldwide chargeback losses projected to climb from $33.79bn in 2025 to $41.69bn by 2028. A merchant scaling international digital revenue should therefore model dispute cost as a function of growth, not as a fixed overhead. Doing so makes the decision to automate or underwrite a growth question with a clear trigger point.
Underwrite what remains
Once prevention has taken out what it can, the residual exposure can be moved off the balance sheet. Chargeback protection covering eligible non-fraud disputes underwrites item not received, subscription and service claims alongside fraud, converting a variable and unpredictable loss into a fixed and forecastable cost. Guaranteed outcomes allow a finance function to budget for disputes with the same confidence it budgets for card acceptance.
The data behind the guarantee is what makes it work at scale. Signifyd assesses claims against its Commerce Network, a pooled dataset drawn from purchasing behaviour across thousands of merchants, which allows a repeat disputer at one retailer to be recognised at the next. Merchants pairing authentication with cover for the non-fraud side are protecting the complete picture for the first time.
Put the recovered hours to work
The final step is deciding what the released capacity does next, because the labour saving is often larger than the loss saving. Manual evidence gathering absorbs experienced analysts who understand customer behaviour better than anyone else in the business. Freed from compiling delivery confirmations, they are well placed to work on approval rates, checkout friction and the review rules that turn declined good orders into revenue.
That redeployment is where authentication and dispute protection start compounding. One secures the transaction, the other secures the outcome, and together they let a payments team spend its attention on conversion. The merchants treating chargebacks as a design problem rather than a cost of trading online are the ones pulling ahead.
