Payment security and fraud: what UK small businesses need to know
Most guidance on this subject is written for businesses with a risk department. This one is written for the owner who takes payments between jobs and wants to know three things: what am I actually liable for, what does it cost me when something goes wrong, and what should I do differently on Monday morning.
The short version
Taking payment in person with chip and PIN is by a wide margin the safest thing you can do — the card and the cardholder are both verified, which makes a later "I didn't authorise this" claim very hard to sustain. Online and over-the-phone payments carry the real risk.
For online payments, 3D Secure is not optional in the UK — it is how businesses meet the regulatory requirement for Strong Customer Authentication. It also shifts fraud liability to the customer's bank.
But 3D Secure protects you against one category of dispute only: fraud. It does nothing for "the item never arrived" or "it wasn't as described" — and for most small businesses, those are the disputes that actually turn up.
Card-present vs card-not-present
Before any of the technology matters, this is the distinction that determines most of your exposure. "Card-not-present" means the physical card wasn't verified at the point of sale — online, over the phone, or manually keyed into a terminal.
| How you took payment | Fraud risk | Who is liable for fraud disputes | Typical cost |
|---|---|---|---|
| Chip and PIN, in person | Lowest | Generally the card issuer, not you | Standard rate |
| Contactless / mobile wallet | Low | Generally the card issuer, not you | Standard rate |
| Online with 3D Secure | Moderate | Shifts to the issuer for fraud codes only | Standard online rate |
| Online without 3D Secure | High | You | Standard online rate |
| Keyed in manually / over the phone | Highest | You | Usually a higher rate |
This is also why most providers charge more for manually keyed transactions than for chip and PIN — the price difference is a risk premium, not an arbitrary markup. If you regularly key in card details over the phone, that is the single riskiest habit in your payment process.
Strong Customer Authentication (SCA)
SCA is a UK regulatory requirement enforced by the Financial Conduct Authority. It requires that most remote electronic payments verify the customer using at least two of three independent factors:
Something they know
A password, a PIN, or an answer to a security question.
Something they have
Their phone, a banking app, or a card reader device.
Something they are
A fingerprint, face scan or other biometric.
In practice, for card payments online, this is delivered through 3D Secure 2 — the step where your customer approves the payment in their banking app or via a one-time code. If you sell online through a mainstream provider (Stripe, PayPal, Square, Shopify and so on), this is already built into their checkout and you do not need to implement anything yourself. The obligation sits with your payment provider, but the commercial consequence sits with you.
What 3D Secure does and doesn't cover
When a payment is successfully authenticated with 3D Secure, a liability shift applies: if the cardholder later claims the transaction was fraudulent, their bank carries the loss rather than you. That is genuinely valuable protection and a good reason never to disable 3D Secure to reduce checkout friction.
The limit is what most business owners miss. The liability shift applies to fraud reason codes only. Disputes raised on any other grounds remain entirely your problem:
Covered by the liability shift
"I did not make this transaction." "My card was used without my permission." Genuine third-party card fraud, where the authentication succeeded.
NOT covered — still your liability
"The goods never arrived." "It wasn't as described." "I cancelled this subscription." "I was charged twice." "I was charged the wrong amount."
For a typical small business selling real goods and services, that second column is where nearly all disputes come from. 3D Secure will not help you with any of them — good records will.
Chargebacks, and the clock you're on
A chargeback is not a refund. A refund is you choosing to return money. A chargeback is the customer's bank forcibly reversing the payment, usually without asking you first — the money leaves your account and you then have to argue to get it back.
The timings are asymmetric, and this asymmetry is the practical danger:
| Stage | Visa | Mastercard |
|---|---|---|
| Customer's window to raise a dispute | Around 120 days for most reason codes | Around 120 days for most reason codes |
| When that window starts for online goods | Usually the expected delivery date, not the payment date | |
| Your window to respond | 30 days per dispute phase | 45 days |
Because the customer's clock often starts at the expected delivery date, a dispute can land four or five months after you were paid and had long since counted the money as yours. Chargebacks are governed by Visa and Mastercard scheme rules rather than UK law, so the exact windows vary by scheme and reason code — your provider's dispute documentation is the authority for your specific case.
What one chargeback actually costs you
Business owners tend to think of a chargeback as costing the value of the sale. It is usually considerably worse than that. On a £200 disputed order:
| The disputed amount, reversed | −£200.00 |
| The goods, if already shipped and not returned | −your cost |
| The original processing fee — usually not refunded even if you win | −£3–4 |
| A chargeback/dispute fee, charged by most (not all) providers | −varies |
| Your time assembling evidence | −unbilled |
Dispute fees differ meaningfully between providers, and this is a genuine point of comparison that rarely appears on a headline rate card. Square publishes that it does not charge a dispute fee at all and covers the cost of every dispute its merchants challenge. Most other providers do charge a per-dispute fee, and some do not refund it even when you win.
Too many chargebacks can cost you your merchant account
This is the part that turns an irritation into an existential problem. Visa and Mastercard both monitor the ratio of disputes to transactions at merchant level, and businesses that breach the thresholds face fines, mandatory remediation programmes, and ultimately the loss of their ability to accept card payments at all.
Visa tightened its Acquirer Monitoring Programme thresholds on 1 April 2026, lowering the "excessive" ratio to 1.5% and combining fraud reports and disputes into a single measure. Mastercard's excessive chargeback programme similarly operates around a 1.5% ratio alongside a minimum monthly chargeback count.
Fraud types that actually hit small businesses
First-party ("friendly") fraud
The customer genuinely made the purchase, then disputes it anyway — sometimes dishonestly, often because they didn't recognise the payment on their statement. It is the most common dispute type for small businesses, and the cheapest to prevent: make sure your billing descriptor is the name customers know you by, not a dormant limited company name they've never seen.
Card testing
Fraudsters run stolen card numbers through your checkout in bulk with tiny amounts to find which still work. Signs are a sudden spike of small transactions, many declines, and repeated attempts from the same IP. It inflates your fraud ratio even when the amounts are trivial. Rate limiting and your provider's fraud tools stop it.
The overpayment scam
A "customer" pays too much, then asks you to refund the difference by bank transfer. The original payment is later reversed as fraudulent, and your refund is gone for good. Never refund to a different payment method than the one used to pay — refund to the original card only.
Phone and email payment requests
Someone urgently needs to pay by phone, or a "supplier" emails asking you to update their bank details. Both are common. Verify any change of bank details by calling a number you already had on file, never one supplied in the message itself.
A practical checklist
1. Fix your billing descriptor
The cheapest single fix on this page. If the name on the customer's statement isn't the name on your shopfront or invoice, you are manufacturing disputes.
2. Make dispute alerts reach a human
Check which email address your provider sends dispute notifications to, and confirm it is monitored. A 30-day deadline is generous until nobody reads the message.
3. Keep proof of delivery and agreement
Signed job sheets, delivery confirmations, booking confirmations, before-and-after photos, message threads. For "not received" and "not as described" disputes — the ones 3D Secure won't help with — this evidence is the entire case.
4. Put your refund policy in writing
Visible at the point of sale and on invoices. A clear, reasonable policy you can evidence gives you a much stronger position, and encourages customers to come to you rather than their bank.
5. Never disable 3D Secure to smooth checkout
The conversion gain is small, the liability transfer you give up is not. 3DS2 is also far less intrusive than the original version people remember.
6. Take payment in person where you can
For trades and mobile businesses especially, tapping a card at the end of the job is both faster to get paid and materially lower risk than invoicing and taking card details over the phone.
7. Refund to the original card only
No exceptions, however plausible the reason. This single rule defeats the overpayment scam entirely.
8. Answer disputes even when you'll lose
Not always worth it on a small amount — but a pattern of unanswered disputes is what pushes ratios up. Track your dispute rate as a percentage, not just as a count.
PCI DSS: what you actually have to do
PCI DSS is the card industry's security standard for handling card data. It is not UK law — but it is a contractual requirement imposed on you through your payment provider's terms, so in practice it applies to virtually every business that takes cards.
The good news for most small businesses: if you use a standard card reader, or a hosted checkout where card details go directly from your customer's browser to the provider, card data never touches your systems. That puts you in the simplest compliance category, SAQ A — an annual self-assessment questionnaire that is generally free and achievable in an afternoon.
You move into far more demanding territory if you store card numbers yourself, write them down, or take details into your own systems. The practical advice is simple: never write a card number down, and never store one anywhere. Let the provider handle it and you stay in the easy category.
Frequently asked questions
Does 3D Secure protect me from all chargebacks?
No. It shifts liability for fraud disputes to the customer's bank. Disputes for goods not received, goods not as described, duplicate charges or cancelled subscriptions remain your liability.
How long does a customer have to raise a chargeback?
Around 120 days for most reason codes — and for online goods that window usually starts at the expected delivery date, not the payment date.
How long do I have to respond?
Around 30 days with Visa and 45 with Mastercard. Miss it and you forfeit automatically.
Is in-person payment safer than online?
Yes, substantially. Chip and PIN verifies both the card and the cardholder, which makes an unauthorised-transaction claim very hard to sustain.
Do I need to be PCI compliant?
Effectively yes — it is contractual rather than statutory. Most small businesses qualify for SAQ A, a free annual self-assessment, provided card data never touches their own systems.
Can I be dropped by my payment provider?
Yes, if your dispute ratio stays high. The card schemes monitor disputes as a percentage of transactions and both operate programmes with fines and remediation above roughly 1.5%.
Comparing providers?
Dispute handling and fees are worth weighing alongside the headline rate.
Methodology and sources: Strong Customer Authentication requirements per the FCA's UK implementation of PSD2-equivalent rules. 3D Secure liability-shift behaviour, including its limitation to fraud reason codes, per Stripe's official dispute and 3D Secure documentation, checked 31 July 2026. Chargeback response windows (Visa 30 days, Mastercard 45 days) and the approximately 120-day cardholder window reflect Visa and Mastercard scheme rules as reported by multiple payment-industry sources; exact windows vary by reason code and your provider's documentation is authoritative for your case. Square's no-dispute-fee position per Square's official UK support pages, checked 31 July 2026. Visa Acquirer Monitoring Programme threshold change effective 1 April 2026 per multiple payment-industry sources; Visa's own programme documentation is not fully public, so treat the figures as indicative and confirm with your acquirer. We have deliberately omitted per-provider dispute fee amounts we could not verify against official UK rate cards. This guide is general information about how card payments work, not legal, regulatory or financial advice. See our Editorial Policy.
