Fraud Filters: Build Rules Around Chargeback Outcomes and False-Positive Cost

Contracargos?
Ya no es problema tuyo.
Recupera cuatro veces más Contracargos y prevención , hasta un 90 % de las entradas, gracias a IA y a una red global de 20 000 comercios.
En resumen:
- A fraud filter only proves its worth once you trace what happened to the orders it approved and declined, not how suspicious they looked at checkout.
- Stolen-card fraud needs tighter rules, while friendly fraud needs better evidence retention, and treating both as the same problem stalls filter tuning.
- Successfully authenticated 3D Secure transactions generally shift fraud-dispute liability from merchant to card issuer under Visa and Mastercard network rules.
- Consumers reported $15.9 billion in fraud losses to the FTC's Consumer Sentinel Network in 2025, up from just over $12 billion in 2024.
- Every filter should be retired, tightened, or left alone based on its dispute and false-positive outcomes, not its checkout-time logic.
A fraud filter is a rule that evaluates a transaction against one or more risk signals, such as location, device, or order value, and routes it to approve, decline, or manual review. A filter only proves its worth once you can trace what happened to the orders it touched: how many became confirmed fraud, how many became chargebacks, and how many were legitimate sales it blocked by mistake.
Most fraud filter programs stop at the first half of that sentence. Rules get written to stop suspicious-looking orders at checkout, then nobody connects the rule back to what the order actually turned out to be 30, 60, or 120 days later. Building filters around chargeback outcomes, not just checkout-time suspicion, is what closes that gap.
What a Fraud Filter Actually Does
A fraud filter analyzes signals available at the moment of purchase, such as transaction amount, geolocation, device fingerprint, address and card verification results, and order velocity, and compares them against thresholds or patterns associated with known fraud. The most common filter types are:
- Velocity limits: caps on transaction amount or frequency within a time window.
- Geolocation and IP checks: comparing a customer's IP location against their billing and shipping address.
- Device fingerprinting: identifying returning devices by IP, browser, and hardware attributes.
- Proxy and VPN detection: flagging traffic routed through anonymizing networks.
- AVS and CVV checks: verifying that the billing address and card security code match the issuer's records.
- 3D Secure authentication: an additional verification step at checkout, described below.
- Custom rules and blacklists: thresholds and blocklists built from a merchant's own historical fraud data.
- Real-time risk scoring: a composite score built from the signals above, covered in more depth in fraud scoring.
Trace the Attack Path From Checkout to Dispute
A fraud filter sits at one point in a longer path: account creation or checkout, fulfillment, and, for the transactions that go wrong, a dispute. A filter tuned only to stop bad orders at checkout has no visibility into what happens after the package ships, which is exactly where the chargeback outcome gets decided. Mapping that path for your own store, order by order, shows where a filter is actually earning its keep versus where it is just adding friction with no dispute-rate improvement to show for it.
Separate True Third-Party Fraud From First-Party Misuse
Not every chargeback a filter is meant to prevent comes from a stolen card. A meaningful share comes from friendly fraud, where the actual cardholder made the purchase and later disputes it anyway. Filters built around stolen-card signals, such as address mismatches and device anomalies, do little to stop this pattern, since the legitimate cardholder passes every one of those checks. Treating both patterns as the same problem is a common reason filter tuning stalls: the fix for third-party fraud is a tighter rule, while the fix for first-party misuse is better evidence retention and a clearer post-purchase communication trail, not a tighter rule.
Map Signals to Controls, False-Positive Risk, and Liability
Every filter type carries a different false-positive profile and a different liability outcome if it lets fraud through. The table below maps the most common ones.
| Rule Type | What It Targets | False-Positive Risk | If the Rule Is Wrong |
|---|---|---|---|
| Velocity Limits | Card testing, bulk fraud attempts | Medium: penalizes legitimate repeat buyers | Merchant absorbs the fraud loss and any resulting chargeback |
| Geolocation and IP Checks | Cross-border stolen-card fraud | High: penalizes travelers and VPN users | Merchant absorbs the fraud loss and any resulting chargeback |
| AVS and CVV Checks | Stolen card numbers without physical card access | Medium: penalizes recent movers and data-entry errors | Merchant absorbs the fraud loss and any resulting chargeback |
| 3D Secure Authentication | Stolen-card fraud at checkout | Low to medium: adds a checkout step | Liability for a resulting fraud dispute generally shifts to the card issuer under Visa and Mastercard network rules, when the transaction is successfully authenticated |
| Custom Rules and Blacklists | Repeat offenders and store-specific patterns | Variable: depends entirely on rule quality | Merchant absorbs the fraud loss and any resulting chargeback |
The 3D Secure row is the one exception on this table: it is the rare control where getting it right shifts financial liability for the resulting fraud dispute off the merchant entirely, rather than simply lowering the odds of fraud happening. That makes it worth the checkout friction for higher-risk order segments even when it measurably lowers approval rate.
Specify the Evidence to Retain Before and After Fulfillment
A filter that approves an order should also decide what evidence gets logged in case that order later becomes a dispute: device ID and IP address at checkout, the AVS and CVV match result, the 3D Secure authentication value if used, and, after fulfillment, tracking and delivery confirmation. Merchants who only start gathering this evidence after a dispute notice arrives are working from memory instead of records, which is the single biggest reason winnable disputes get lost. Building this into your chargeback fraud prevention workflow up front turns every approved order into a ready-made evidence file instead of a scramble.
Emerging checkout patterns need the same discipline. As autonomous shopping agents start placing orders on a cardholder's behalf, standard device and behavioral signals stop working the way they were designed to, since the buyer at checkout is software, not a person. Understanding Agentic commerce chargebacks and AI agent chargeback liability now, before this volume becomes material, means the evidence a filter should retain for an agent-initiated order gets specified ahead of the dispute wave instead of during it.
Close the Loop Using Dispute Results and Reason Codes
Every filter should be retired, tightened, or left alone based on one input: what happened to the orders it decided on, not how suspicious those orders looked at the time. When a dispute resolves, feed the reason code and the rule that approved or declined the original order back to whoever owns that rule. A filter generating more false-positive cost than chargeback fraud it prevents should be loosened or replaced with a manual review step, using the same fraud analytics discipline you would apply to any other rule.
The stakes for getting this loop right keep rising. Consumers reported $15.9 billion in fraud losses to the FTC's Consumer Sentinel Network in 2025, up from just over $12 billion the year before, according to the FTC's March 2026 testimony to the Joint Economic Committee. A filter set built once and left alone is measuring against a threat that has grown by double digits since the rule was written.
A Fraud Filter Is a Hypothesis Until a Dispute Confirms It
Every rule in a filter set is a bet that a given signal predicts fraud better than it predicts a legitimate order. Chargeback and false-positive outcomes are the only evidence that settles the bet. Build filters around that evidence, retain what you need to fight the disputes that still get through, and route every result back to the rule that produced it as part of your broader ecommerce fraud prevention program.
Fraud Filters FAQ
What are fraud filters?
Fraud filters are rules that evaluate a transaction against risk signals, such as location, device, order value, and card verification results, and route the transaction to approve, decline, or manual review based on whether it matches known fraud patterns.
What is the difference between fraud filters and fraud scoring?
Fraud filters apply discrete pass or fail rules to individual signals, such as blocking any order above a set velocity threshold. Fraud scoring combines multiple signals into a single weighted score and routes the transaction based on which risk band that score falls into. Many programs use both together.
What causes fraud filters to create false positives?
False positives happen when a rule built to catch a fraud pattern also matches normal customer behavior, such as a customer traveling internationally, using a VPN, placing a first-time high-value order, or recently changing their billing address.
How often should fraud filter rules be reviewed?
Review high-volume rules monthly against fresh dispute and confirmed-fraud data, and review the full rule set at least quarterly, since fraud patterns and legitimate customer behavior both shift faster than an annual review cycle can catch.
Does 3D Secure replace the need for other fraud filters?
No. 3D Secure authenticates the cardholder and can shift fraud-dispute liability to the issuer, but it does not evaluate order economics, shipping risk, or first-party misuse, all of which still need their own filters and review process.
See how Chargeflow Prevent connects pre-transaction fraud controls to dispute recovery, so a filter decision and its chargeback outcome are managed in the same place.

Contracargos?
Ya no es problema tuyo.
Recupera cuatro veces más Contracargos y prevención , hasta un 90 % de las entradas, gracias a IA y a una red global de 20 000 comercios.













.png)
.webp)

.webp)