Skip to main content

Visa 10.4 - Card Absent Environment (Fraud)

This is the Visa code for a customer denying an online or phone order: 10.4. Looking for Mastercard 4837, Amex F29 or Discover UA02?

Read the code off your notice: four digits and no dot is Mastercard, one letter and two digits is Amex, two letters at the front is Discover. Get that right first, because the response deadline runs from 20 days on Amex to 45 on Mastercard.

TL;DR
  • A cardholder told their bank they didn't make an online order. It's the fraud code you'll see most
  • Ran 3DS and got ECI 05? The issuer eats it. That's the whole ballgame
  • No 3DS? Compelling Evidence 3.0 is next best. It needs two prior clean orders from that customer
  • They get 120 days. You get 30 to answer

Someone says they didn't make the online purchase you shipped. That's 10.4, Visa's main fraud code for card-not-present.

When This Code Applies

  • Cardholder denies making an online purchase
  • Card credentials used without authorization
  • Account takeover leading to CNP fraud
  • Stolen card used for an online purchase
  • Friendly fraud, where the cardholder says it wasn't them

Conditions for Valid Dispute

The issuer has to confirm two things. The cardholder didn't authorize the charge, and got no benefit from it. It also has to be card-absent, and filed inside the window.

Card-absent means e-commerce, MOTO, or recurring billing without proper authentication.

When the Dispute Isn't Valid At All

Visa lists conditions that make a 10.4 invalid before anyone argues about evidence. One of them is worth knowing by heart, because it's the serial-disputer rule and almost nobody cites it:

A Transaction on an Account Number for which the Issuer has initiated more than 35 Disputes within the previous 120 calendar days.

That's Visa Core Rules section 11.7.5.3, Table 11-28, in the 18 April 2026 edition. Thirty-five disputes on one account inside four months, counted across every merchant, not just yours. Past that, a further 10.4 on that account isn't a weak dispute. It's an invalid one.

You can't see the other 34. Only the issuer can. So this isn't something you check before responding, it's something you raise when a customer's behaviour smells like a pattern: several disputes from the same person, or a customer whose story keeps changing. Put it in the representment narrative and make the issuer look:

"We believe this dispute may be invalid under Visa Core Rules 11.7.5.3. Please confirm whether more than 35 disputes have been initiated on this account number in the previous 120 calendar days."

Two honest caveats. It only covers 10.4, not every fraud code. And the rule carries two footnotes in Visa's text that we haven't read, so check the current edition before you quote it in a formal filing.

Time Frames

ScenarioDispute Window
Standard120 days from transaction date
With delivery120 days from delivery date (or expected delivery)
Digital goods120 days from transaction date

Liability Shift with 3D Secure

Full Liability Shift (Issuer Liable)

When transaction is fully authenticated:

  • Visa Secure (3DS 2.0) - Challenge flow completed
  • ECI = 05 (fully authenticated)
  • Cryptogram present and valid

Partial/No Liability Shift (Merchant Liable)

ScenarioECIMerchant Liability
Authentication attempted, issuer unavailable06Reduced
Authentication failed07Full
No authentication attempted07Full
3DS not supportedN/AFull

Compelling Evidence 3.0 (CE 3.0)

Visa's enhanced compelling evidence program for repeat customers.

CE 3.0 Requirements

To qualify for CE 3.0 representment:

  1. Two prior undisputed transactions with same payment credentials
  2. At least 120 days before disputed transaction
  3. Matching data elements - at least two of the four below, and one of them must be IP address or Device ID.
    • IP address
    • Device ID/fingerprint
    • Shipping address
    • User account ID

CE 3.0 Process

CE 3.0 Benefits

  • Pre-arbitration liability protection
  • Higher win rates
  • Faster resolution

Standard Representment Options

1. Transaction Was Authorized

Evidence required:

  • Cardholder correspondence acknowledging purchase
  • Order confirmation sent to cardholder email
  • IP/device match to prior purchases
  • Signed delivery confirmation

2. 3D Secure Authentication

Evidence required:

  • ECI value showing authentication
  • Cryptogram/CAVV
  • Authentication timestamp
  • 3DS transaction ID

3. AVS/CVV Verification

Evidence required:

  • AVS match (full or partial)
  • CVV2 match
  • Delivery to verified address

4. Delivery Confirmation

Evidence required:

  • Carrier tracking showing delivered
  • Signature confirmation
  • Delivery address matches billing
  • Photo proof of delivery (if available)

5. Digital Goods Access

Evidence required:

  • IP address at time of download/access
  • Access logs showing usage
  • Account login after purchase
  • Download confirmation

6. Prior Transaction History

Evidence required:

  • Previous undisputed purchases
  • Same email/phone/device
  • Established customer relationship

Representment Time Frames

StageWindow
Initial response30 days from chargeback
Pre-arbitration30 days from representment
Arbitration45 days from pre-arb

Win Rate Expectations

Defense TypeExpected Win Rate
3DS authenticated (ECI 05)80-95%
CE 3.0 qualifying70-85%
AVS match + delivery proof40-60%
Standard evidence25-40%
No evidenceUnder 15%

Where This Breaks

Most merchants who lose 10.4 never ran 3DS. Without it you get no liability shift. So you argue evidence instead of pointing at a rule.

Records are next. Log IP, device fingerprint and timestamps on every order. You can't build a CE 3.0 case without them, and you can't backfill them later.

Delivery proof is the other hole. "Delivered" beats "shipped." A signature beats both.

Then there's the clock. You get 30 days. Teams miss it because the notice lands in an inbox nobody reads. Route dispute alerts somewhere a human looks daily.

Thin evidence loses. One order confirmation email isn't a case, and you rarely get a second submission.

  • 10.3 - Other Fraud Card Present
  • 10.5 - VFMP

Next Steps

Got this chargeback?

  1. Check if 3DS was used → If ECI 05, you have strong defense
  2. Check CE 3.0 eligibility → Prior undisputed transactions from same customer?
  3. Gather evidence → Representment Workflow
  4. Respond within 30 days

Prevent future 10.4 chargebacks:

  1. Implement 3D Secure for liability shift
  2. Set up dispute alerts to refund before chargeback

See Also