Chargebacks 101
TC40 Fraud Reports vs TC15 Disputes
Understand the difference between Visa TC40 fraud reports and TC15 disputes, how both affect VAMP monitoring, and why merchants need visibility into each signal.
- Primary topic
- Fraud Reports
- Guide level
- Advanced
What Is a TC40 Fraud Report?
A TC40 is a fraud report inside the Visa system. When a cardholder tells their issuing bank that a transaction was fraudulent, the issuer files a fraud record — carried in Visa's transaction-code format as a TC40 — reporting the fraud event to Visa. The record identifies the transaction, the merchant, and the nature of the fraud claim, and it flows into Visa's fraud-reporting data.
The critical point: a TC40 record is a fraud report, not a chargeback. Filing a TC40 does not move money, does not open a dispute case, and does not require any merchant response. Money may never move at all — an issuer can report fraud and simply write off the transaction, or the fraud claim may later arrive separately as a dispute.
TC40 activity is nonetheless consequential, because Visa's monitoring programs count fraud reports. A merchant can accumulate significant TC40 volume — and significant monitoring exposure — while its chargeback dashboard shows nothing unusual.
What Is a TC15 Dispute?
A TC15 record represents dispute activity in VisaNet — the transaction-code family that carries dispute (chargeback) financial messages between issuers and acquirers. When an issuer files a dispute on a transaction, the resulting dispute activity is recorded through TC15 messaging: funds are pulled back, a reason code is attached, and the merchant is expected to accept or respond.
Where a TC40 is information, a TC15 is action: dispute activity that affects settlement and triggers the response process described in how chargebacks work. TC15 dispute activity is what merchants recognize as chargebacks in their processor portal — though, as covered below, the processor's presentation and Visa's counting are not always the same view.
TC40 vs TC15 at a Glance
| Record Type | What It Represents | Who Creates It | Is It a Chargeback? | How Merchants Use It |
|---|---|---|---|---|
| TC40 | A fraud report on a transaction | The issuing bank, after a cardholder fraud claim | No — a report only; no funds move and no response is required | Early fraud-trend warning; input to VAMP monitoring; signal to tighten screening |
| TC15 | Dispute (chargeback) activity on a transaction | The issuing bank, filing a dispute through VisaNet | Yes — it reflects dispute activity that reverses funds | Case management: accept or represent; input to VAMP monitoring; dispute-ratio tracking |
Both records can exist on the same transaction, and both feed Visa's monitoring math — which is why merchants need visibility into each.
Does a TC40 Report Mean a Chargeback Was Filed?
No. A TC40 fraud report and a chargeback are separate events, and one does not imply the other:
- An issuer can file a TC40 and never dispute the transaction — absorbing the loss or resolving it otherwise. The merchant keeps the funds and may never know the fraud report exists.
- An issuer can file a TC40 and then also file a dispute on the same transaction, producing both a fraud record and a chargeback.
- A dispute can arrive with a non-fraud reason code and involve no TC40 at all.
Equally important, a TC40 fraud report does not necessarily stop or replace a later dispute. Merchants sometimes assume that a fraud report which never became a chargeback is a closed matter; the dispute can still arrive within the cardholder's dispute window. TC40 data is a signal to investigate and act — not a resolution.
Can a Transaction Have Both Fraud and Dispute Activity?
Yes, and for monitoring purposes this matters. A single fraudulent transaction commonly generates a TC40 fraud report when the cardholder reports the fraud, and TC15 dispute activity when the issuer recovers the funds through a chargeback.
Visa's VAMP methodology counts fraud and dispute records under its program rules — and Visa's published materials describe counting rules and exclusions that determine how records are treated, including how pre-dispute resolutions are handled depending on timing. Merchants should not try to hand-calculate deduplication; the practical takeaway is that fraud-coded activity can be counted through channels a chargeback dashboard never shows, and the authoritative count lives with Visa and the acquirer.
How TC40 and TC15 Activity Affects VAMP
The Visa Acquirer Monitoring Program (VAMP) is where these two record types converge. The current VAMP ratio is count-based: TC40 fraud reports plus TC15 disputes, divided by settled TC05 card-not-present transactions, subject to Visa's program rules and exclusions.
Two implications follow. First, fraud reports count even when they never become chargebacks — a merchant with heavy TC40 volume and modest chargebacks can still breach VAMP thresholds. Second, because the ratio is count-based, many small fraud events hurt as much as a few large ones; transaction size does not dilute the numerator. The full program mechanics, current thresholds, and exclusions are covered in our VAMP guide.
What Merchants Can Learn From TC40 Data
TC40 data is one of the earliest fraud signals available to a merchant, and it rewards analysis:
- Fraud pressure by channel — spikes tied to a traffic source, campaign, or affiliate often indicate card-testing or stolen-credential abuse arriving through that channel.
- Product and SKU patterns — fraud concentrating on resellable or instantly-delivered items tells you where to tighten screening.
- Descriptor confusion vs true fraud — fraud reports on transactions with strong identity signals (matched AVS, established accounts) suggest first-party misuse or unrecognized descriptors rather than stolen cards; see friendly fraud and first-party misuse.
- Monitoring exposure — TC40 counts are half of the VAMP numerator, so tracking them is tracking the ratio.
One caveat: visibility into TC40 data depends on the merchant's acquirer, processor, provider, and reporting access. Not every merchant receives fraud-report data by default — asking for it is a worthwhile conversation with your acquirer.
What Merchants Can Learn From TC15 Data
TC15 dispute activity is the operational record of chargebacks, and it drives day-to-day dispute management:
- Reason-code distribution — which claims dominate (fraud, non-receipt, canceled recurring) tells you which prevention fixes will pay off; the Reason Codes directory explains the code families.
- Win-rate tracking — outcomes by reason code show which representments are worth fighting.
- Ratio management — dispute counts against transaction counts, measured per MID, are what acquirers and networks evaluate.
- Alert coverage measurement — comparing disputes that arrived as chargebacks against cases intercepted by pre-dispute alerts shows how much of your dispute flow alerts actually cover.
Where TC40 data tells you where fraud pressure is building, TC15 data tells you what it is costing and how well your defenses are working.
Why Processor Chargeback Reports May Not Show the Full Picture
A processor dashboard shows the disputes the processor handled — which is not the same as the activity Visa counts:
- Fraud reports are usually absent. TC40 records that never became disputes typically do not appear in chargeback reporting at all.
- Counting methods differ. A processor's internal chargeback ratio may use different numerators, denominators, or timing than Visa's count-based VAMP math.
- Multiple MIDs and processors fragment the view. Networks evaluate activity per merchant account; a merchant spread across gateways sees only fragments in each portal.
- Pre-dispute resolutions sit outside chargeback counts. Alert-resolved cases and their exclusions live in program rules, not processor dashboards.
The merchant who relies on a processor dashboard alone can be genuinely surprised by an acquirer's VAMP conversation. The activity Visa counts was real the whole time — it just was not on the screen the merchant was watching.
What Merchants Should Monitor
A complete monitoring picture combines both record types and their context:
- Fraud-report volume and trend — monthly TC40-type counts, by MID, channel, and product, to the extent your acquirer or providers expose them.
- Dispute volume and trend — chargeback counts and reason-code mix, per MID and consolidated.
- The combined count against settled transactions — the VAMP-relevant ratio, tracked with headroom targets well below Visa's thresholds.
- Alert outcomes — cases resolved pre-dispute, with reconciliation against refunds.
- Leading indicators — decline spikes, card-testing patterns, and complaint volume that precede fraud reports.
Set internal alarm thresholds meaningfully below the network's, so remediation starts while options are still cheap. And confirm with your acquirer or processor what fraud and dispute reporting you can access — visibility varies, and the merchants with the fewest surprises are the ones who asked.
How Fraud Signal™ and Threshold Defense™ Help
Payment Defender closes the visibility gap between the two record types. Fraud Signal™ monitors fraud-report activity available through the merchant's acquirer, processors, and connected providers, surfacing fraud trends that never reach a chargeback dashboard. Threshold Defense™ tracks combined fraud and dispute counts against settled transaction volume across every connected MID and gateway, measuring VAMP-relevant exposure continuously instead of quarterly. Chargeback Shield™ manages the TC15 side — the dispute cases themselves — so responses go out complete and on time.
Fraud reports and disputes are two halves of the same risk picture. Contact Payment Defender to see both halves in one view.
