Exclusive Rates From as Low as 0.26%
Card fraud prevention for UK businesses means combining the right technical tools - such as AVS, CVV checks and 3D Secure - with sound operational procedures and well-trained staff to stop fraudulent transactions before they cost you money. UK Finance reports that unauthorised card fraud losses reached over £609 million in 2023, with remote purchase fraud accounting for the majority of losses, making prevention a genuine commercial priority rather than a compliance afterthought. This guide sets out the practical, prioritised steps that make the biggest difference for both card-not-present and face-to-face businesses.
Key Takeaways
- Card-not-present (CNP) fraud is the dominant threat for UK ecommerce, while lost-or-stolen and card-ID theft fraud are more relevant to face-to-face retailers.
- Strong Customer Authentication (SCA) and 3D Secure 2 are now mandatory for most UK online card payments and significantly reduce liability for fraud losses.
- Address Verification Service (AVS) and CVV checks remain low-cost, high-impact tools that should be enabled by default on every payment gateway.
- Chargeback rates above 1% can trigger monitoring programmes from Visa and Mastercard, so prevention also protects your ability to keep processing cards at all.
- Staff training on social engineering and card-present fraud indicators reduces losses that technology alone cannot catch.
- Fraud scoring and machine-learning tools from providers like Stripe Radar, Worldpay FraudSight and Adyen RevenueProtect can automate much of the decision-making process.
- A layered approach - combining technology, process and people - consistently outperforms any single control used in isolation.
Understanding the Types of Card Fraud Affecting UK Businesses
Before implementing prevention measures, it helps to understand which types of fraud are most relevant to your business model. Card fraud and chargebacks are closely related, and it is worth reading our guides to what is a chargeback and reducing chargebacks alongside this article, since many fraud prevention measures also reduce chargeback volumes.
Card-Not-Present (CNP) Fraud
CNP fraud occurs when a criminal uses stolen card details to make a purchase online, over the phone, or by mail order without the physical card being present. This is by far the largest category of card fraud in the UK, driven by the volume of stolen card data circulating from data breaches and phishing campaigns. Ecommerce businesses, subscription services and phone-order retailers are most exposed.
Lost or Stolen Card Fraud
This occurs when a criminal uses a physically lost or stolen card at a point of sale. Chip-and-PIN has made this harder to execute successfully since 2004, but contactless fraud below the verification threshold remains a residual risk for face-to-face retailers.
Counterfeit and Skimming Fraud
Counterfeit fraud involves cloned cards created from skimmed magnetic stripe data. UK Finance data shows this fraud type has fallen dramatically as chip technology has become near-universal, though it persists in some cross-border and legacy terminal scenarios.
Account Takeover and Application Fraud
Criminals increasingly target merchant accounts and customer accounts directly, using stolen credentials to change delivery addresses or make unauthorised purchases through saved payment methods. This is a growing concern for subscription and marketplace businesses in particular.
Technical Controls Every UK Business Should Implement
The following technical controls form the foundation of fraud prevention and should be considered a baseline for any business accepting card payments, whether online or in person.
3D Secure 2 and Strong Customer Authentication
Since the introduction of SCA under the revised Payment Services Directive (PSD2), most online card transactions in the UK require additional authentication such as a one-time passcode or biometric confirmation. 3D Secure 2 also shifts liability for fraudulent transactions from the merchant to the card issuer in most cases, which materially reduces chargeback exposure. Full details are covered in our guide to 3D Secure and Strong Customer Authentication.
Address Verification Service (AVS) and CVV Checks
AVS checks the billing address provided at checkout against the address held by the card issuer, while CVV checks confirm the three or four-digit security code on the card. Both are free or near-free to implement through virtually every UK payment gateway and should be enabled as standard, with clear rules on how to handle partial matches.
Fraud Scoring and Machine Learning Tools
Most major UK payment providers now offer built-in fraud scoring engines that assess transactions in real time against dozens of risk signals, including device fingerprinting, IP geolocation, velocity checks and behavioural patterns. These tools can automatically block, flag for review, or challenge high-risk transactions without manual intervention.
| Provider | Fraud Tool | Key Features | Typical Cost |
|---|---|---|---|
| Stripe | Radar | Machine learning risk scoring, custom rules, network-wide fraud signals | Included in standard pricing; Radar for Teams from 0.05% per transaction |
| Worldpay | FraudSight | Real-time scoring, configurable rules, chargeback alerts | Typically bundled or charged per transaction, varies by contract |
| Adyen | RevenueProtect | Machine learning, liability shift optimisation, data-driven rules | Included as standard with Adyen processing |
| Checkout.com | Risk engine | Custom rulesets, 3D Secure orchestration, network tokenisation | Included in processing fees |
| SagePay/Opayo | Fraud Screening | AVS/CVV, velocity checking, blacklist management | Included or low monthly add-on |
Tokenisation and Card Data Security
Storing raw card numbers is both a security liability and a PCI DSS compliance burden. Tokenisation replaces card data with a non-sensitive token, meaning that even if your systems are breached, no usable card data is exposed. Most modern UK payment gateways offer tokenisation as standard, and it should be a non-negotiable requirement when selecting a provider.
Operational Procedures That Reduce Fraud Risk
Technology alone is not sufficient. Operational processes determine how well your business responds to warning signs and edge cases that automated systems may miss.
Order Review Thresholds
Set clear internal thresholds for manual review of high-value orders, first-time customers, or transactions flagged by your fraud scoring tool. A common approach is to automatically hold for review any order above a set value combined with a mismatched billing and delivery address.
Velocity and Pattern Monitoring
Monitor for unusual patterns such as multiple transactions from the same card within a short period, repeated failed authentication attempts, or a spike in orders to a single delivery address. These patterns are classic indicators of testing activity, where fraudsters validate stolen card numbers before making larger purchases.
Delivery and Fulfilment Controls
For physical goods, requiring signature on delivery for high-value orders, restricting delivery to the billing address for first-time customers, and avoiding next-day shipping on flagged orders all reduce the window for fraudulent fulfilment. Digital goods and instant-access services carry particular risk because there is no delivery delay to allow fraud checks to complete.
Refund and Chargeback Response Procedures
Having a documented process for responding to chargebacks quickly and with strong evidence packs significantly improves your win rate on disputes. Our step-by-step guide on how to dispute a chargeback in the UK covers the evidence types that scheme rules require and the deadlines you need to meet.
In-Person Fraud Prevention: Chip-and-PIN and Contactless
For businesses taking payments face to face, terminal-based fraud prevention remains highly effective when combined with staff vigilance.
Chip-and-PIN Best Practice
Always insist on chip-and-PIN rather than accepting a swipe or manual key entry unless the terminal specifically prompts for it as a fallback. Manual key entry in particular carries a much higher fraud risk and often shifts liability back to the merchant if the transaction turns out to be fraudulent.
Contactless Limits and Step-Up Authentication
The UK contactless limit is currently £100 per transaction, with card issuers requiring a PIN entry periodically to confirm the cardholder is genuine. Businesses should ensure terminal software is kept up to date so these step-up prompts trigger correctly, as outdated terminal firmware can sometimes fail to enforce them.
Staff Training on Physical Fraud Indicators
Train staff to recognise signs of a stolen or counterfeit card, such as a card that does not match the name given by the customer, visible tampering, or a customer who seems unfamiliar with their own PIN. Staff should also be briefed on distraction techniques used by fraud rings operating in-store.
Building a Fraud Prevention Culture Across Your Business
The most resilient businesses treat fraud prevention as a shared responsibility rather than solely a technical or finance function.
Staff Awareness and Social Engineering
Phone and email-based social engineering attacks, where fraudsters impersonate customers, suppliers or even senior staff to authorise payments, are increasingly common. Regular training on verifying identity before processing refunds, changing payment details, or authorising unusual transactions closes a gap that no software tool can fully cover.
Regular Review of Fraud and Chargeback Data
Review your fraud and chargeback rates monthly, segmented by product line, payment method and customer type where possible. Rising rates in a specific segment often point to a targeted attack or a process weakness that can be addressed before it escalates.
Scheme Monitoring Programmes
Visa and Mastercard both operate monitoring programmes for merchants whose chargeback ratios exceed defined thresholds, typically around 0.65% to 1% of transaction volume depending on the scheme and threshold tier. Exceeding these thresholds can result in additional fees, closer scrutiny from your acquirer, or in severe cases account termination, so proactive fraud prevention directly protects your ability to keep accepting cards.
Choosing a Payment Provider With Strong Fraud Tools
Not all UK payment providers offer the same depth of fraud prevention capability, and this should factor into any decision about switching or selecting a provider.
| Feature | Why It Matters | What to Ask Your Provider |
|---|---|---|
| 3D Secure 2 support | Reduces fraud liability and meets SCA requirements | Is 3DS2 enabled by default and does it support exemptions where appropriate? |
| Custom rule engines | Allows tailored risk rules for your specific business model | Can we set our own thresholds for AVS mismatches, order value and velocity? |
| Chargeback alerts | Gives early warning before a formal chargeback is filed | Do you offer a chargeback alert or pre-dispute notification service? |
| Tokenisation and PCI scope reduction | Reduces both fraud risk and compliance burden | Is card data tokenised by default, and what PCI SAQ level applies to us? |
| Reporting and analytics | Enables ongoing monitoring of fraud and dispute trends | Can we access detailed transaction and dispute reporting in real time? |
Cost of Fraud Prevention Versus Cost of Fraud
Some businesses hesitate to invest in fraud tools because of perceived cost, but the maths generally favours prevention. A single successful chargeback typically costs a merchant the transaction value plus a dispute fee, commonly £15 to £25 per case depending on provider, on top of lost goods and administrative time. Fraud scoring tools, by contrast, are frequently included free or at very low cost within standard payment processing packages from providers such as Stripe, Adyen and Worldpay, making the return on investment strongly positive for almost any UK business processing card payments at meaningful volume.
Practical Action Checklist
For businesses wanting to prioritise action, the following order tends to deliver the fastest risk reduction for the least effort and cost: enable AVS and CVV checks immediately if not already active, confirm 3D Secure 2 is switched on for all eligible transactions, set manual review thresholds for high-value and high-risk orders, train staff on both digital and physical fraud indicators, and review chargeback and fraud data monthly to catch emerging patterns early.
Frequently Asked Questions
What is the biggest fraud risk for UK ecommerce businesses?
Card-not-present fraud is the biggest risk for UK ecommerce businesses, typically arising from stolen card details obtained through data breaches or phishing being used to make unauthorised online purchases. This risk is significantly reduced by combining 3D Secure 2, AVS and CVV checks with fraud scoring tools.
Is 3D Secure mandatory for UK businesses?
Strong Customer Authentication, which is typically delivered through 3D Secure 2, is a regulatory requirement under UK payment services rules for most online card transactions above low-value thresholds. There are limited exemptions, such as for low-risk or low-value transactions, but the default expectation is that authentication will be applied.
How much does fraud prevention software cost for a small UK business?
Many fraud prevention tools, including AVS, CVV checks and basic fraud scoring, are included free within standard payment processing packages from providers like Stripe, Adyen and Opayo. More advanced tools with custom rule engines may carry a small per-transaction fee, often well under 0.1% of transaction value.
Does chip-and-PIN eliminate fraud for in-person businesses?
Chip-and-PIN has dramatically reduced counterfeit card fraud since its introduction but has not eliminated fraud entirely, since lost or stolen cards can still be used until reported, and contactless fraud below verification thresholds remains a residual risk. Staff training and terminal software updates remain important complementary measures.
What happens if my chargeback rate gets too high?
If your chargeback ratio exceeds thresholds set by Visa or Mastercard, typically in the region of 0.65% to 1% of transactions depending on the specific programme, you may be placed into a monitoring programme involving additional fees and scrutiny from your acquirer. In severe or unresolved cases, this can ultimately lead to the withdrawal of card acceptance facilities.
Should I use manual review for all flagged transactions?
Manual review is valuable for genuinely ambiguous cases but should be reserved for transactions that fraud scoring tools cannot confidently classify, since reviewing every flagged order can slow fulfilment and frustrate genuine customers. A well-tuned rule set should aim to automate the majority of low and high-confidence decisions, leaving only borderline cases for human review.
How does fraud prevention relate to chargeback management?
Fraud prevention and chargeback management are closely linked, since reducing fraudulent transactions directly reduces the volume of chargebacks a business receives. However, chargebacks can also arise from non-fraud disputes such as goods not received or dissatisfaction, meaning strong fraud prevention should be paired with clear customer service and dispute response processes for full protection.
How Compare Card Fees Can Help
Compare Card Fees is a free, independent advisory service. We compare rates from leading UK payment providers to find you the best deal available - no fee, no obligation.
Whether you are looking to reduce your card processing costs, switch provider, or understand what you are currently paying, our experts can help. Tell us about your business and we will find the best rates available.


