Checked 31 July 2026

Payment security and fraud: what UK small businesses need to know

Most guidance on this subject is written for businesses with a risk department. This one is written for the owner who takes payments between jobs and wants to know three things: what am I actually liable for, what does it cost me when something goes wrong, and what should I do differently on Monday morning.

The short version

Taking payment in person with chip and PIN is by a wide margin the safest thing you can do — the card and the cardholder are both verified, which makes a later "I didn't authorise this" claim very hard to sustain. Online and over-the-phone payments carry the real risk.

For online payments, 3D Secure is not optional in the UK — it is how businesses meet the regulatory requirement for Strong Customer Authentication. It also shifts fraud liability to the customer's bank.

But 3D Secure protects you against one category of dispute only: fraud. It does nothing for "the item never arrived" or "it wasn't as described" — and for most small businesses, those are the disputes that actually turn up.

Where the risk actually sits

Card-present vs card-not-present

Before any of the technology matters, this is the distinction that determines most of your exposure. "Card-not-present" means the physical card wasn't verified at the point of sale — online, over the phone, or manually keyed into a terminal.

How you took paymentFraud riskWho is liable for fraud disputesTypical cost
Chip and PIN, in personLowestGenerally the card issuer, not youStandard rate
Contactless / mobile walletLowGenerally the card issuer, not youStandard rate
Online with 3D SecureModerateShifts to the issuer for fraud codes onlyStandard online rate
Online without 3D SecureHighYouStandard online rate
Keyed in manually / over the phoneHighestYouUsually a higher rate

This is also why most providers charge more for manually keyed transactions than for chip and PIN — the price difference is a risk premium, not an arbitrary markup. If you regularly key in card details over the phone, that is the single riskiest habit in your payment process.

The legal requirement

Strong Customer Authentication (SCA)

SCA is a UK regulatory requirement enforced by the Financial Conduct Authority. It requires that most remote electronic payments verify the customer using at least two of three independent factors:

Something they know

A password, a PIN, or an answer to a security question.

Something they have

Their phone, a banking app, or a card reader device.

Something they are

A fingerprint, face scan or other biometric.

In practice, for card payments online, this is delivered through 3D Secure 2 — the step where your customer approves the payment in their banking app or via a one-time code. If you sell online through a mainstream provider (Stripe, PayPal, Square, Shopify and so on), this is already built into their checkout and you do not need to implement anything yourself. The obligation sits with your payment provider, but the commercial consequence sits with you.

Worth knowing: the FCA has been consulting on moving toward a more risk-based authentication model, which could change how prescriptively SCA is applied in future. Nothing about your current obligations changes today, but it is worth a periodic check with your provider rather than assuming the rules are fixed forever.
The most misunderstood point on this page

What 3D Secure does and doesn't cover

When a payment is successfully authenticated with 3D Secure, a liability shift applies: if the cardholder later claims the transaction was fraudulent, their bank carries the loss rather than you. That is genuinely valuable protection and a good reason never to disable 3D Secure to reduce checkout friction.

The limit is what most business owners miss. The liability shift applies to fraud reason codes only. Disputes raised on any other grounds remain entirely your problem:

Covered by the liability shift

"I did not make this transaction." "My card was used without my permission." Genuine third-party card fraud, where the authentication succeeded.

NOT covered — still your liability

"The goods never arrived." "It wasn't as described." "I cancelled this subscription." "I was charged twice." "I was charged the wrong amount."

For a typical small business selling real goods and services, that second column is where nearly all disputes come from. 3D Secure will not help you with any of them — good records will.

How disputes actually work

Chargebacks, and the clock you're on

A chargeback is not a refund. A refund is you choosing to return money. A chargeback is the customer's bank forcibly reversing the payment, usually without asking you first — the money leaves your account and you then have to argue to get it back.

The timings are asymmetric, and this asymmetry is the practical danger:

StageVisaMastercard
Customer's window to raise a disputeAround 120 days for most reason codesAround 120 days for most reason codes
When that window starts for online goodsUsually the expected delivery date, not the payment date
Your window to respond30 days per dispute phase45 days
The real risk isn't losing the argument — it's missing the email. Miss your response deadline and the dispute is forfeited automatically, no matter how good your evidence was. Make sure dispute notifications from your payment provider go to an address somebody actually reads daily, and are not sitting in a spam folder or an old inbox from when you set the account up.

Because the customer's clock often starts at the expected delivery date, a dispute can land four or five months after you were paid and had long since counted the money as yours. Chargebacks are governed by Visa and Mastercard scheme rules rather than UK law, so the exact windows vary by scheme and reason code — your provider's dispute documentation is the authority for your specific case.

The true cost

What one chargeback actually costs you

Business owners tend to think of a chargeback as costing the value of the sale. It is usually considerably worse than that. On a £200 disputed order:

The disputed amount, reversed−£200.00
The goods, if already shipped and not returned−your cost
The original processing fee — usually not refunded even if you win−£3–4
A chargeback/dispute fee, charged by most (not all) providers−varies
Your time assembling evidence−unbilled

Dispute fees differ meaningfully between providers, and this is a genuine point of comparison that rarely appears on a headline rate card. Square publishes that it does not charge a dispute fee at all and covers the cost of every dispute its merchants challenge. Most other providers do charge a per-dispute fee, and some do not refund it even when you win.

We have deliberately not published a comparison table of dispute fees. The per-dispute figures circulating on comparison sites mostly trace back to third-party aggregators rather than providers' own published rate cards, and we could not verify them against official UK pricing pages at the time of writing. Ask your provider directly for two numbers: what is the per-dispute fee, and do you refund it if I win. If you process meaningful volume, the answer is worth real money each year.
The risk nobody warns you about

Too many chargebacks can cost you your merchant account

This is the part that turns an irritation into an existential problem. Visa and Mastercard both monitor the ratio of disputes to transactions at merchant level, and businesses that breach the thresholds face fines, mandatory remediation programmes, and ultimately the loss of their ability to accept card payments at all.

Visa tightened its Acquirer Monitoring Programme thresholds on 1 April 2026, lowering the "excessive" ratio to 1.5% and combining fraud reports and disputes into a single measure. Mastercard's excessive chargeback programme similarly operates around a 1.5% ratio alongside a minimum monthly chargeback count.

Context before you panic: these programmes apply a ratio and a minimum monthly volume of disputed items together, and those volume floors are high enough that a typical small business will not come close. The reason to understand them is directional — it tells you that the card schemes treat a sustained dispute rate above roughly 1% as a serious problem, so that is a sensible internal warning line to watch long before anyone else raises it with you. Exact thresholds vary by region and by acquirer, so treat these as indicative and confirm with your provider if you are anywhere near them.
Know the patterns

Fraud types that actually hit small businesses

First-party ("friendly") fraud

The customer genuinely made the purchase, then disputes it anyway — sometimes dishonestly, often because they didn't recognise the payment on their statement. It is the most common dispute type for small businesses, and the cheapest to prevent: make sure your billing descriptor is the name customers know you by, not a dormant limited company name they've never seen.

Card testing

Fraudsters run stolen card numbers through your checkout in bulk with tiny amounts to find which still work. Signs are a sudden spike of small transactions, many declines, and repeated attempts from the same IP. It inflates your fraud ratio even when the amounts are trivial. Rate limiting and your provider's fraud tools stop it.

The overpayment scam

A "customer" pays too much, then asks you to refund the difference by bank transfer. The original payment is later reversed as fraudulent, and your refund is gone for good. Never refund to a different payment method than the one used to pay — refund to the original card only.

Phone and email payment requests

Someone urgently needs to pay by phone, or a "supplier" emails asking you to update their bank details. Both are common. Verify any change of bank details by calling a number you already had on file, never one supplied in the message itself.

Do these things

A practical checklist

1. Fix your billing descriptor

The cheapest single fix on this page. If the name on the customer's statement isn't the name on your shopfront or invoice, you are manufacturing disputes.

2. Make dispute alerts reach a human

Check which email address your provider sends dispute notifications to, and confirm it is monitored. A 30-day deadline is generous until nobody reads the message.

3. Keep proof of delivery and agreement

Signed job sheets, delivery confirmations, booking confirmations, before-and-after photos, message threads. For "not received" and "not as described" disputes — the ones 3D Secure won't help with — this evidence is the entire case.

4. Put your refund policy in writing

Visible at the point of sale and on invoices. A clear, reasonable policy you can evidence gives you a much stronger position, and encourages customers to come to you rather than their bank.

5. Never disable 3D Secure to smooth checkout

The conversion gain is small, the liability transfer you give up is not. 3DS2 is also far less intrusive than the original version people remember.

6. Take payment in person where you can

For trades and mobile businesses especially, tapping a card at the end of the job is both faster to get paid and materially lower risk than invoicing and taking card details over the phone.

7. Refund to the original card only

No exceptions, however plausible the reason. This single rule defeats the overpayment scam entirely.

8. Answer disputes even when you'll lose

Not always worth it on a small amount — but a pattern of unanswered disputes is what pushes ratios up. Track your dispute rate as a percentage, not just as a count.

Compliance

PCI DSS: what you actually have to do

PCI DSS is the card industry's security standard for handling card data. It is not UK law — but it is a contractual requirement imposed on you through your payment provider's terms, so in practice it applies to virtually every business that takes cards.

The good news for most small businesses: if you use a standard card reader, or a hosted checkout where card details go directly from your customer's browser to the provider, card data never touches your systems. That puts you in the simplest compliance category, SAQ A — an annual self-assessment questionnaire that is generally free and achievable in an afternoon.

You move into far more demanding territory if you store card numbers yourself, write them down, or take details into your own systems. The practical advice is simple: never write a card number down, and never store one anywhere. Let the provider handle it and you stay in the easy category.

Frequently asked questions

Does 3D Secure protect me from all chargebacks?

No. It shifts liability for fraud disputes to the customer's bank. Disputes for goods not received, goods not as described, duplicate charges or cancelled subscriptions remain your liability.

How long does a customer have to raise a chargeback?

Around 120 days for most reason codes — and for online goods that window usually starts at the expected delivery date, not the payment date.

How long do I have to respond?

Around 30 days with Visa and 45 with Mastercard. Miss it and you forfeit automatically.

Is in-person payment safer than online?

Yes, substantially. Chip and PIN verifies both the card and the cardholder, which makes an unauthorised-transaction claim very hard to sustain.

Do I need to be PCI compliant?

Effectively yes — it is contractual rather than statutory. Most small businesses qualify for SAQ A, a free annual self-assessment, provided card data never touches their own systems.

Can I be dropped by my payment provider?

Yes, if your dispute ratio stays high. The card schemes monitor disputes as a percentage of transactions and both operate programmes with fines and remediation above roughly 1.5%.

Comparing providers?

Dispute handling and fees are worth weighing alongside the headline rate.

Compare card readers

Methodology and sources: Strong Customer Authentication requirements per the FCA's UK implementation of PSD2-equivalent rules. 3D Secure liability-shift behaviour, including its limitation to fraud reason codes, per Stripe's official dispute and 3D Secure documentation, checked 31 July 2026. Chargeback response windows (Visa 30 days, Mastercard 45 days) and the approximately 120-day cardholder window reflect Visa and Mastercard scheme rules as reported by multiple payment-industry sources; exact windows vary by reason code and your provider's documentation is authoritative for your case. Square's no-dispute-fee position per Square's official UK support pages, checked 31 July 2026. Visa Acquirer Monitoring Programme threshold change effective 1 April 2026 per multiple payment-industry sources; Visa's own programme documentation is not fully public, so treat the figures as indicative and confirm with your acquirer. We have deliberately omitted per-provider dispute fee amounts we could not verify against official UK rate cards. This guide is general information about how card payments work, not legal, regulatory or financial advice. See our Editorial Policy.