Visa 11.1 - Card Recovery Bulletin
TL;DR
- You processed a card that was on the Card Recovery Bulletin, the hot card list. Liability moved to you
- Mostly card-present. Your terminal should have returned "pick up card" (04, 07, 41 or 43) and you should have declined
- Dispute window is 120 days from the transaction date
- Representment options are thin. You need proof the card wasn't listed when you ran it
- Prevention is a terminal that checks the CRB and staff who don't override a decline
Transaction processed on a card that was on the Card Recovery Bulletin (CRB), also known as the "hot card list."
Overview
Issuers put lost, stolen and fraudulent cards on the CRB. Your terminal is supposed to check that list before it approves a card-present sale. Run the card anyway and the loss is yours, not the issuer's.
When This Code Applies
- The card was on the CRB when you ran it
- Your terminal skipped the check or ignored it
- You completed the sale even though the card was listed
- Almost always card-present, rarely e-commerce
Conditions for Valid Dispute
Issuer Must Verify
- The card was on the CRB at sale time
- The cardholder says they didn't make the purchase
- The card was already blocked or cancelled
Transaction Requirements
- The sale was card-present
- Your terminal should have returned "pick up card" or similar
- The sale fell inside the CRB publication window
Time Frames
| Scenario | Dispute Window |
|---|---|
| Standard | 120 days from transaction date |
CRB Process
How CRB Works
- The cardholder reports the card lost, stolen or fraudulent
- The issuer adds it to the Card Recovery Bulletin
- The bulletin goes out to acquirers and terminals
- Your terminal should decline, and staff retain the card if it's safe
Terminal Response Codes
| Code | Meaning | Merchant Action |
|---|---|---|
| 04 | Pick up card | Decline, retain if safe |
| 07 | Pick up card (special) | Decline, retain if safe |
| 41 | Lost card | Decline |
| 43 | Stolen card | Decline |
Representment Options
Your options are thin. You're either proving the card wasn't listed when you ran it, or proving you got a clean approval back.
1. Card Not on CRB at Transaction Time
Evidence required:
- Timestamp of transaction
- CRB publication records
- Proof card added to CRB after transaction
2. Authorization Obtained
Evidence required:
- Auth approval code
- Auth request/response logs
- No "pick up card" response received
3. Timing Dispute
Evidence required:
- Transaction timestamp
- CRB addition timestamp
- Proof of real-time auth check
Prevention Strategies
Terminal Configuration
- Real-time auth - every sale goes online for authorization
- CRB checking on - never skip the hot card list
- Response code handling - the terminal acts on the code
Staff Training
- Decline codes - your staff knows what 04, 41 and 43 mean
- Card retention - retain the card only when it's safe
- Never override - nobody pushes a CRB decline through
System Requirements
- Online terminals - turn off store-and-forward and offline auth
- Fresh CRB data - download on schedule if you batch
- Response logging - store every auth response you get
Win Rate Expectations
| Defense Type | Expected Win Rate |
|---|---|
| Card added to CRB after transaction | 80-90% |
| Auth approved (no CRB match) | 70-85% |
| Card was on CRB at transaction | Under 10% |
Common Mistakes
- Offline processing - you can't check the CRB offline
- Ignoring decline codes - selling after a "pick up" response
- Stale CRB data - the terminal checks last week's list
- No auth logging - you can't prove the auth was clean
Related Codes
- 11.2 - Declined Authorization
- 11.3 - No Authorization
- 10.1 - EMV Counterfeit
Next Steps
Got this chargeback?
- Check if card was on CRB at transaction time → Very hard to defend
- Verify you had valid authorization → Pull auth logs
- If card was on CRB → Accept the chargeback (limited defense)
Prevent future 11.1 chargebacks:
- Process transactions online (real-time CRB check)
- Update terminal CRB data regularly if offline capable
- Never override "pick up card" decline responses
- Review authorization basics