Card issuing fraud controls
This guide is written for programs building card issuing: charge cards, revolving credit cards, and business or consumer banking with debit cards.
Any card program opens the door to fraudulent behavior and losses. But you can reduce your exposure with planning. This guide details the fraud controls Increase applies to every authorization, the customized controls platforms commonly add to their real-time decisioning, and the product patterns that keep those controls from hurting cardholders.
Your control options
- Increase’s built-in fraud controls are always on. They cover the most common fraud. You can launch your program with only these controls and add customized ones later.
- Add customized fraud controls as you see fit. You can enforce them on your own server through Real-Time Decisions, or declare them on the card itself. Add as many as you want and remove them at any time.
- Engage a fraud vendor. Sardine and Unit21 both offer card issuing fraud management rules. We typically recommend this only for later stage programs with a dedicated risk team.
For platforms launching a new card issuing program, we recommend starting with the built-in controls and adding customized ones as you learn more about your specific needs.
Built-in fraud controls
We screen every authorization request received and we automatically decline if any of the following rules are triggered.
| Control | Rule |
|---|---|
| High risk industries | Decline authorizations from merchants with a high risk Merchant Category Code (MCC):4829 Money transfers.6051 Quasi-cash, money orders.7801 Government-licensed casinos.7802 Government-licensed horse and dog racing.7995 Betting and casino gambling.9754 Gambling: horse racing, dog racing, non-sports intrastate internet gambling.If your program needs to accept transactions at high risk industry merchants, contact support@increase.com. |
| High risk countries | Decline authorizations from merchants in sanctioned countries:CU Cuba.IR Iran.KP North Korea.RU Russia.SY Syria.VE Venezuela. |
| Bank Identification Number (BIN) enumeration | Decline authorizations from a merchant once it exhibits behavior that looks like a BIN enumeration attack, in which a fraudster guesses card numbers within a BIN range by running a high volume of small authorizations through a single merchant. Once a merchant submits more than a threshold count of authorization requests within a time window, we decline its subsequent authorization requests. |
Commonly-added customized fraud controls
These are the real-time decision rules we most often see platforms implement to tighten their fraud risk posture.
| Control | Rule |
|---|---|
| Expanded industry list | Decline authorizations from merchants in an expanded range of industries. If your cards are issued for a narrow spend use case, such as fuel cards or software subscriptions, block a longer list of industries than we do by default. MCCs commonly exploited by fraudsters include:5732 Electronics stores.5817 Digital goods.5968 Direct marketing.5310, 5311 Discount stores and department stores, which can be used to buy gift cards. |
| Expanded country list | Decline authorizations from merchants in an expanded range of countries. If you offer a charge card for US pizza restaurants, it’s unlikely those cardholders spend at European merchants. Declining outside a short list of expected countries removes a large class of fraud. |
| New instrument velocity | Decline authorizations on a recently issued card when it is used too frequently. A fraudster who has obtained stolen credentials and issued a new card will often try to quickly maximize spending. What counts as normal is industry specific, but declining after more than a handful of transactions within 48 hours of issuance or delivery catches much of this. |
| Unusual purchase location or merchant | Decline authorizations where the merchant doesn’t match the card’s intended spend use case. In a bill pay scenario, where a unique virtual card is issued to pay a specific vendor, limit the card to a single MCC or Merchant Acceptor ID. For general purpose cards, track the historical geographies, MCCs, and Merchant Acceptor IDs a cardholder uses and decline authorizations that deviate significantly. |
| Visa network risk score | Decline authorizations with an elevated Visa network risk score. Visa produces an overall risk score that Increase passes through on each card authorization as network_risk_score. Scores above roughly 50 correlate with significantly higher risk of fraud. You can decline these automatically or use step-up authentication to verify them. |
If Merchant Category Codes (MCCs) are too broad for your use case, ask us about transaction enrichment. This applies more granular categories to authorization requests.
Where to enforce them
You can enforce customized controls in either of two places, and most programs use both:
- Real-Time Decisions. Increase sends your server the full authorization request — amount, merchant descriptor, MCC, merchant country, Merchant Acceptor ID, network risk score, and Address Verification System results — and waits for your approval or decline. Use this for anything that depends on state your server holds, such as velocity across a cardholder’s other cards or a deviation from their historical spend.
- Card authorization controls. Declare the rule on the card itself and Increase enforces it at authorization time with no round trip to your server.
Implementation best practices
If you add customized fraud controls, there are behaviors you can build into your product that further mitigate fraud while keeping a good cardholder experience.
- Make it easy for cardholders to disable a card.
- Apply step-up authentication with 3D Secure to authorizations that might be risky. If you aren’t sure whether to approve an authentication request, respond to the
card_authentication_requestedreal-time decision withchallenge. The cardholder receives a one-time code that you deliver by text message or email and they enter it on the merchant’s site. - Monitor for inactive cards and either automatically deactivate them or prompt the cardholder to accept deactivation.
- Control which of your users can create new cards and modify card limits.
- Temporarily block new card creation and card limit changes for 24 hours after a user changes their login information.
Whichever controls you choose, keep false positives in mind. They hurt the cardholder experience and can cost you transactions. Monitor your false positive rate. When you do decline a legitimate transaction, help the cardholder recover quickly. Use step-up authentication, or send them the declined authorization so they can confirm it was them and retry.
Learn more
If you have questions, reach out to support@increase.com.