Visa 10.4 - Card Absent Environment (Fraud)
This is the Visa code for a customer denying an online or phone order: 10.4. Looking for Mastercard 4837, Amex F29 or Discover UA02?
Read the code off your notice: four digits and no dot is Mastercard, one letter and two digits is Amex, two letters at the front is Discover. Get that right first, because the response deadline runs from 20 days on Amex to 45 on Mastercard.
- A cardholder told their bank they didn't make an online order. It's the fraud code you'll see most
- Ran 3DS and got ECI 05? The issuer eats it. That's the whole ballgame
- No 3DS? Compelling Evidence 3.0 is next best. It needs two prior clean orders from that customer
- They get 120 days. You get 30 to answer
Someone says they didn't make the online purchase you shipped. That's 10.4, Visa's main fraud code for card-not-present.
When This Code Applies
- Cardholder denies making an online purchase
- Card credentials used without authorization
- Account takeover leading to CNP fraud
- Stolen card used for an online purchase
- Friendly fraud, where the cardholder says it wasn't them
Conditions for Valid Dispute
The issuer has to confirm two things. The cardholder didn't authorize the charge, and got no benefit from it. It also has to be card-absent, and filed inside the window.
Card-absent means e-commerce, MOTO, or recurring billing without proper authentication.
When the Dispute Isn't Valid At All
Visa lists conditions that make a 10.4 invalid before anyone argues about evidence. One of them is worth knowing by heart, because it's the serial-disputer rule and almost nobody cites it:
A Transaction on an Account Number for which the Issuer has initiated more than 35 Disputes within the previous 120 calendar days.
That's Visa Core Rules section 11.7.5.3, Table 11-28, in the 18 April 2026 edition. Thirty-five disputes on one account inside four months, counted across every merchant, not just yours. Past that, a further 10.4 on that account isn't a weak dispute. It's an invalid one.
You can't see the other 34. Only the issuer can. So this isn't something you check before responding, it's something you raise when a customer's behaviour smells like a pattern: several disputes from the same person, or a customer whose story keeps changing. Put it in the representment narrative and make the issuer look:
"We believe this dispute may be invalid under Visa Core Rules 11.7.5.3. Please confirm whether more than 35 disputes have been initiated on this account number in the previous 120 calendar days."
Two honest caveats. It only covers 10.4, not every fraud code. And the rule carries two footnotes in Visa's text that we haven't read, so check the current edition before you quote it in a formal filing.
Time Frames
| Scenario | Dispute Window |
|---|---|
| Standard | 120 days from transaction date |
| With delivery | 120 days from delivery date (or expected delivery) |
| Digital goods | 120 days from transaction date |
Liability Shift with 3D Secure
Full Liability Shift (Issuer Liable)
When transaction is fully authenticated:
- Visa Secure (3DS 2.0) - Challenge flow completed
- ECI = 05 (fully authenticated)
- Cryptogram present and valid
Partial/No Liability Shift (Merchant Liable)
| Scenario | ECI | Merchant Liability |
|---|---|---|
| Authentication attempted, issuer unavailable | 06 | Reduced |
| Authentication failed | 07 | Full |
| No authentication attempted | 07 | Full |
| 3DS not supported | N/A | Full |
Compelling Evidence 3.0 (CE 3.0)
Visa's enhanced compelling evidence program for repeat customers.
CE 3.0 Requirements
To qualify for CE 3.0 representment:
- Two prior undisputed transactions with same payment credentials
- At least 120 days before disputed transaction
- Matching data elements - at least two of the four below, and one of them must be IP address or Device ID.
- IP address
- Device ID/fingerprint
- Shipping address
- User account ID
CE 3.0 Process
CE 3.0 Benefits
- Pre-arbitration liability protection
- Higher win rates
- Faster resolution
Standard Representment Options
1. Transaction Was Authorized
Evidence required:
- Cardholder correspondence acknowledging purchase
- Order confirmation sent to cardholder email
- IP/device match to prior purchases
- Signed delivery confirmation
2. 3D Secure Authentication
Evidence required:
- ECI value showing authentication
- Cryptogram/CAVV
- Authentication timestamp
- 3DS transaction ID
3. AVS/CVV Verification
Evidence required:
- AVS match (full or partial)
- CVV2 match
- Delivery to verified address
4. Delivery Confirmation
Evidence required:
- Carrier tracking showing delivered
- Signature confirmation
- Delivery address matches billing
- Photo proof of delivery (if available)
5. Digital Goods Access
Evidence required:
- IP address at time of download/access
- Access logs showing usage
- Account login after purchase
- Download confirmation
6. Prior Transaction History
Evidence required:
- Previous undisputed purchases
- Same email/phone/device
- Established customer relationship
Representment Time Frames
| Stage | Window |
|---|---|
| Initial response | 30 days from chargeback |
| Pre-arbitration | 30 days from representment |
| Arbitration | 45 days from pre-arb |
Win Rate Expectations
| Defense Type | Expected Win Rate |
|---|---|
| 3DS authenticated (ECI 05) | 80-95% |
| CE 3.0 qualifying | 70-85% |
| AVS match + delivery proof | 40-60% |
| Standard evidence | 25-40% |
| No evidence | Under 15% |
Where This Breaks
Most merchants who lose 10.4 never ran 3DS. Without it you get no liability shift. So you argue evidence instead of pointing at a rule.
Records are next. Log IP, device fingerprint and timestamps on every order. You can't build a CE 3.0 case without them, and you can't backfill them later.
Delivery proof is the other hole. "Delivered" beats "shipped." A signature beats both.
Then there's the clock. You get 30 days. Teams miss it because the notice lands in an inbox nobody reads. Route dispute alerts somewhere a human looks daily.
Thin evidence loses. One order confirmation email isn't a case, and you rarely get a second submission.
Related Codes
- 10.3 - Other Fraud Card Present
- 10.5 - VFMP
Next Steps
Got this chargeback?
- Check if 3DS was used → If ECI 05, you have strong defense
- Check CE 3.0 eligibility → Prior undisputed transactions from same customer?
- Gather evidence → Representment Workflow
- Respond within 30 days
Prevent future 10.4 chargebacks:
- Implement 3D Secure for liability shift
- Set up dispute alerts to refund before chargeback
See Also
- 3D Secure Implementation - Liability shift protection
- What proof each network accepts - CE 3.0 requirements
- Friendly Fraud - First-party abuse patterns
- Device Fingerprinting - Proving cardholder involvement
- AVS & CVV - Address verification
- Third-Party Fraud - True fraud vs. friendly
- Account Takeover - ATO patterns
- Velocity Rules - Fraud detection
- Risk Scoring - Pre-transaction screening
- Chargeback Alerts - Deflect before filing
- VAMP Fraud Thresholds - Fraud program limits
- Fraud vs. Friendly - Classification