TC40 Fraud Reports: What They Are and How to See Yours

A TC40 fraud report is filed by the cardholder's bank, counted by Visa, and acted on by your acquirer, all without you being told. Here is how the record works, how to obtain your own counts, and which controls actually reduce issuance instead of just shifting cost.

A TC40 report is a fraud-notification record. The cardholder's issuing bank files it with Visa when a customer claims a transaction was fraudulent. It moves no money. It triggers no alert to the merchant. It can exist without any chargeback ever being filed. Since June 2025, every TC40 counts directly in the ratio of the Visa Acquirer Monitoring Program (VAMP).

That combination makes the TC40 unique among payments records. A bank you never talk to writes it. A network you have no portal into holds it. Your acquirer, the bank that controls your card processing, acts on it. Acquirers have used TC40 reports for decades to monitor issuer-reported fraud at merchant locations. Then Visa folded the count into the Visa Acquirer Monitoring Program. Since then, the file has priced itself directly into your processing relationship. This guide treats the TC40 as what it is: a data artefact. It covers who writes it, what it contains, how late it runs, how to obtain your own counts, and which controls reduce it.

What is a TC40 report and who actually files it?

The cardholder's issuing bank files the TC40, not the merchant and not the acquirer. The moment a customer tells their bank a charge was fraudulent, the issuer generates the record. The issuer then submits it into Visa's Risk Identification Service. The merchant is not a party to the filing. No one tells the merchant it happened.

Verifi, a Visa company, states the mechanics plainly. The issuing bank generates the TC40 data claim the moment a customer makes a fraud claim. Visa distributes the claim to the acquirer, other issuing banks, and the card brands. No one notifies the merchant. Whether you ever see it depends entirely on what your acquirer chooses to pass along. Issuers file on nearly every claim rather than screening them, because Visa enforces the obligation. Issuers must resubmit rejected fraud records and clear a 90% acceptance floor. An issuer that repeatedly fails to report loses its fraud dispute rights for 90 days. At the third occurrence, it faces a minimum USD 25,000 assessment.

  • Merchant identifiers: business name, MID, and merchant category code
  • Transaction details: date, time, amount, and a card-not-present indicator
  • Truncated card and cardholder data
  • Issuing and acquiring bank identifiers
  • Authorization and authentication indicators, plus a fraud reason

How does a TC40 differ from a chargeback, a TC15, and a TC05 record?

A chargeback moves money: it debits your account and announces itself. A TC40 moves nothing. It is a data record. In Visa's clearing taxonomy, TC05 marks a settled sale. TC06 marks a refund. TC15 marks a disputed sale. TC40 marks a sale reported as fraud. The four codes record different fates of the same underlying transaction.

The TC40 is not a loose synonym for "fraud report." It is a transaction code in Visa's file structure. It sits alongside TC05 (the settled sale), TC06 (the refund), and TC15 (the dispute). Visa counts the codes independently, and that produces two mechanics that surprise merchants. First, a fraud-coded dispute generates both a TC40 and a TC15. That is two events in the VAMP numerator from a single transaction. Second, a refund adds a TC06 but does not delete a TC40 the issuer already filed. Refunding your way out of a fraud claim changes the cash outcome, not the count.

RecordWhat it marksMoney moves?Note
TC05A settled saleYes, to youThe VAMP denominator
TC06A refundYes, back outDoes not erase a filed TC40
TC15A disputed sale (chargeback)Yes, clawed backAnnounces itself via a debit
TC40A sale reported as fraudNoCounted in VAMP, invisible to you

One transaction can accumulate several codes over its life; each is counted independently.

How does a TC40 compare to a Mastercard SAFE report?

Mastercard's equivalent is SAFE, the System to Avoid Fraud Effectively. Mastercard formally renamed it the Fraud and Loss Database (FLD). Issuers must submit every transaction they consider fraudulent, even when the account stays open. The two networks differ in one decisive way. Visa counts TC40s directly in its VAMP ratio. Mastercard calculates its Excessive Fraud Merchant (EFM) program from fraud chargebacks, not SAFE records.

The lag profiles differ too. Mastercard issuers can wait up to 60 days after a chargeback to submit a SAFE report. Many file in weekly or monthly batches. The data a merchant finally obtains can describe fraud about two months old. Reporting access runs through issuer-side infrastructure (Mastercard Connect). No merchant channel exists anywhere in the rails. EFM enrolls a MID based on fraud chargebacks (reason codes 4837/4863). The criteria include 1,000+ e-commerce transactions, USD/EUR 50,000+ in monthly fraud chargebacks, and a fraud chargeback ratio of 50+ basis points (bps). Monthly assessments escalate and reach $100,000 after 19 consecutive months. Both regimes sit inside the same card scheme compliance stack. The TC40 is the record that can hurt you with no dispute attached.

Why does a TC40 hurt you when no money has left your account?

A TC40 matters because Visa counts it. The VAMP ratio is the count of TC40 fraud reports plus TC15 disputes, divided by settled TC05 transactions, on card-not-present volume. A TC40 raises your numerator even when no chargeback follows, no one issues a refund, and no money ever leaves your account.

The formula comes straight from Visa's VAMP fact sheet. Visa divides the count of fraud (TC40) plus disputes (TC15) by settled transactions (TC05), on card-not-present VisaNet volume. The formula took effect on 1 June 2025. The ratio is count-based, so an $8 fraudulent rebill counts the same as an $800 one. The merchant Excessive threshold is now 150bps in Asia-Pacific (AP), Canada, the EU, and the US. Visa tightened it from 220bps on 1 April 2026, as the Merchant Risk Council confirms. A merchant enters the program only at a minimum monthly count of 1,500 combined fraud and disputes. Our VAMP thresholds guide breaks down every tier and region.

Acquirer-level thresholds create the sharper pressure. An acquirer's portfolio goes Above Standard at 50bps and Excessive at 70bps. Acquirers therefore lean on merchants far below the published merchant line. Since enforcement began, some set private merchant thresholds at 1.0% or lower to protect their own ratio. Enforcement is live. VAMP's advisory period ended 30 September 2025. Visa assesses identified merchants $8 per fraudulent or disputed transaction. The terminal escalation for unmonitored fraud counts is acquirer termination plus a listing on MATCH, a shared blacklist of terminated merchants, under Reason Code 05. The VAMP monitoring hub tracks the current state of the program.

How can you see your own TC40 counts when your acquirer won't share them?

No merchant-facing TC40 portal exists at Visa or Mastercard. You have four routes. You can request the data from your acquirer, who may refuse. You can enroll in Verifi's INFORM program for a direct feed. You can use a payment service provider (PSP) that resurfaces issuer fraud reports natively. Or you can reconstruct a proxy series from signals you already own.

Route one is a structured request to your acquirer. What acquirers hand over varies wildly. Some send per-report detail with date, amount, and fraud code. Others send only a monthly count. So ask precisely. Request your full MID list, a calendar-month date range, per-report fields (transaction date, amount, fraud reason code), a machine-readable format, and a recurring monthly delivery. A practical opener is to pull the last 90 days of TC40 and TC15 data, then escalate if the acquirer refuses. Acquirers are not obligated to comply. VAMP has pushed most to share more readily since 2025.

Route two is direct. Verifi's INFORM program delivers all Visa confirmed fraud notifications from a single source, by API, batch, or portal, in CSV format. Authorized partners can deliver it independently of your PSP or acquirer. An uncooperative acquirer is not a hard block. Route three is your PSP's own surface, often under a different name. Stripe exposes issuer fraud reports as Early Fraud Warnings via dashboard and API. Stripe explicitly notes that Visa counts these warnings toward VAMP identification. Checkout.com delivers a Reported Fraudulent Transactions report built from TC40 and SAFE data hourly. It covers fraud reported in the last 183 days. Qualpay surfaces the records under Dispute History filtered to "Fraud Alert". Segpay tags them as Event Code Z.

  • Pre-dispute alert volume: Verifi and Ethoca alerts deliver issuer fraud and dispute signals within hours, the fastest available proxy for claims being made
  • Fraud-coded chargebacks: every fraud chargeback has a TC40 or SAFE record behind it, so your fraud-dispute count is a hard floor on the true report count
  • The silent-share adjustment: 20 to 40% of fraud reports never become disputes, so scale that floor upward accordingly
  • EFW and PSP fraud-report counts on whatever share of volume runs through platforms that expose them

What is the reporting lag between the cardholder call and the TC40?

The timeline runs shorter than most merchants assume on the network side, and longer on yours. The issuer typically generates the TC40 claim within days of the cardholder's fraud report. Visa's rules give issuers a hard outer bound for filing. The delay merchants actually experience, often weeks to months, happens in distribution, not filing.

The rules set the bounds. Visa's public rulebook requires issuers to report fraud immediately upon detection. It sets a hard limit: no later than 60 calendar days from the transaction date. If the cardholder's notification arrives outside that window, the issuer gets 30 calendar days from receipt. Verifi puts typical practice at within days. Distribution is where the time goes. Many issuers batch submissions weekly or monthly. The data often reaches merchants weeks after the event, sometimes after the related chargeback or refund has already cleared. Europe-region rules even codify lateness. Issuers must report only 65% of payment-credential fraud within 60 days of the transaction. They can take up to 90 days on the remaining 35%.

Two sequencing facts matter for monitoring. First, the TC40 always precedes or accompanies the fraud chargeback. Visa's dispute conditions require the fraud report to sit in its system before Visa processes the dispute. Second, the cardholder's own clock is long. Cardholders can raise disputes up to 120 days after payment. An April rebill claimed in August lands in August's VAMP ratio, against August's denominator. TC40 data is therefore a lagging damage record. It is decisive for network scoring but useless as a real-time prevention feed. Alerts arrive within hours and serve as the fast channel.

What makes TC40 volume spike for subscription and rebill merchants?

Forgotten rebills drive the volume, not stolen cards. The first recurring charge is the single highest-risk billing event. Customers forget they signed up, or they feel misled when the charge lands. Subscription disputes then cluster 60 to 90 days after renewal, in batches, when the charge finally surfaces on a statement.

Most of that volume is not criminal fraud. Up to 75% of chargebacks at subscription merchants stem from legitimate customers disputing valid charges. Visa pegs first-party misuse at about 20% of fraudulent disputes globally, and up to 30% for high-volume online merchants. Small price points make it worse. Issuers write off small-dollar claims instead of disputing them. Issuers refunded about 43% of fraud claims under $8 without those claims ever becoming chargebacks. Each one still counts as a TC40 against the merchant. The counting mechanics then stack the damage. One subscriber disputing three months of rebills at once creates three VAMP events in a single month. A fraud-coded rebill can produce both a TC40 and a TC15. VAMP's monthly snapshot captures whichever month the delayed claims cluster in.

  • The first rebill after a trial, when customers forget they signed up or feel misled
  • Renewal charges noticed on a statement 60 to 90 days later and disputed in batches
  • Descriptor mismatch between the checkout brand and the billing line on renewals
  • Small tickets in the issuer write-off zone, generating TC40s with no dispute attached
  • Card testing at checkout: enumeration traffic that converts into fraud reports downstream

Which controls reduce TC40 issuance rather than just the downstream cost?

Split every control into two ledgers: controls that stop the issuer from filing the TC40, and controls that only reduce cost after it exists. Descriptor clarity, renewal notifications, pre-authorization screening, and refunds the customer accepts before calling their bank all prevent issuance. Refunds after the claim and dispute alerts do not. Neither does the liability shift from 3-D Secure (3DS), the card networks' authentication step.

The split became rule when Visa reversed course effective 1 April 2025. TC40 fraud alerts resolved through Rapid Dispute Resolution (RDR) and the Cardholder Dispute Resolution Network (CDRN) now count toward the VAMP ratio. The auto-refund kills the chargeback, not the fraud report. Ordinary refunds behave the same way. A refund prevents a TC40 only if the customer accepts it before contacting their bank. Issued after the claim, it changes nothing on the count. The 3DS liability shift is also a cost control, not an issuance control. Fraud that passes authentication still generates a counted TC40, even though the issuer absorbs the loss. One carve-out survives. Visa still excludes non-fraud TC15 disputes resolved via RDR, so pre-dispute tools fully neutralize the non-fraud side of the ratio.

Issuance-side controls act earlier. Visa's own friendly-fraud guidance names the levers that stop the customer from making the claim at all: recognizable billing descriptors, purchase and renewal notifications, and easy-to-find cancellation and refund policies. Pre-authorization screening and 3DS challenges that block a fraudulent attempt prevent the TC40 outright, since an unauthorized transaction never settles. 3DS-authenticated e-commerce runs about 45% lower fraud rates (11bps versus 20bps). Visa reports tokenized credentials cut fraud by up to 60%. After filing, Compelling Evidence 3.0 (CE 3.0) is the only sanctioned removal. A won CE 3.0 representment on a 10.4 dispute reverses the chargeback and deletes the linked TC40 from the fraud count. Since 18 April 2026, merchants can apply CE 3.0 criteria to standalone TC40s that never became chargebacks. Recurring billing naturally produces the 120-to-365-day prior-transaction history CE 3.0 requires. But inconsistent descriptors across billing cycles break the match. Descriptor hygiene is therefore both an issuance control and a remediation prerequisite.

What to monitor weekly

Run the ratio yourself, per MID, every week. Treat recent weeks as provisional: cardholders can dispute up to 120 days after payment, so the trailing window restates as late claims land. Reconcile Visa's two carve-outs, pre-dispute-resolved disputes and CE 3.0-qualified TC40s, inside the same month. Both exclusions depend on the timing of the data extract. Benchmark against your acquirer's private line, not just Visa's published one. Some acquirers sit at 1.0% or lower. Remember that fraud counts travel with approval health. A MID accumulating TC40s is usually a MID whose approval rates and health metrics are drifting for the same upstream reasons.

  • Pull TC40 and TC15 counts weekly from every acquirer, PSP fraud report, and EFW feed; open with a 90-day historical request and escalate if refused
  • Compute (TC40 + TC15) divided by settled TC05 per MID, tracked against 150bps, your acquirer's private threshold, and the 1,500 monthly count floor
  • Watch pre-dispute alert volume daily: it moves within hours of claims, weeks before TC40 data arrives
  • Cohort first-rebill disputes and the 60-to-90-day renewal window separately from the blended dispute rate
  • Audit descriptor consistency across billing cycles so CE 3.0 matches do not break
  • Reconcile CE 3.0 removals and RDR-resolved non-fraud exclusions before the month's extract timing locks the count
  • Monitor enumeration attempts at authorization: card testing today is TC40 volume next month
ControlTC40 outcomeWhat it changes
Clear descriptorsPreventedThe claim is never made
Renewal noticesPreventedThe charge is recognized
3DS block at authorizationPreventedNo settled fraud to report
Refund before the bank callPreventedThe customer is intercepted
Refund after the claimStill countsCost only
RDR / CDRN alertsStill countsKills the TC15 only
3DS liability shiftStill countsThe issuer absorbs the loss
CE 3.0 winRemovedThe only post-filing erasure

Everything below the Prevented rows manages cost, not the count.

Frequently Asked Questions

What is TC40 data?

TC40 data is the set of fraud reports issuing banks file with Visa when cardholders claim transactions were fraudulent. Each record carries merchant identifiers (name, MID, MCC), bank details for both sides, and transaction date, time, and amount, giving the network enough detail to pattern-match fraud to a specific merchant.

Can merchants view their own TC40 data?

Not natively. Neither Visa nor Mastercard operates a merchant-facing portal, and acquirers are under no obligation to share the reports even when asked. Merchants gain access by requesting data from their acquirer or processor, enrolling in Verifi's INFORM program, or using a PSP that resurfaces it, such as Stripe's Early Fraud Warnings.

Is a TC40 report the same as a chargeback?

No. A chargeback debits the merchant's account and invites a response; a TC40 is an informational fraud record that moves no money and arrives with no notification. Filing a TC40 does not stop a chargeback from also being filed later, and the two are counted as separate events under VAMP.

Do all TC40 reports result in chargebacks?

No. Only about 63.7% of TC40-reported transactions ever advance to a chargeback. Issuers frequently reimburse small-ticket claims directly because it is cheaper than disputing: roughly 43% of fraud claims under $8 were refunded without escalating. Those silent reports still count in the merchant's VAMP numerator.

What is the difference between a TC40 and a Mastercard SAFE report?

They are the two networks' versions of the same record. A TC40 is Visa's issuer-filed fraud report; SAFE, now renamed the Fraud and Loss Database, is Mastercard's. The consequences differ: Visa counts TC40s directly in the VAMP ratio, while Mastercard's EFM program runs on fraud chargebacks, so a report with no dispute mainly hurts you on Visa.

Can a TC40 affect a merchant's ability to process card-not-present payments?

Yes. A high TC40 count alone can place a merchant in a card-scheme fraud monitoring program with added scrutiny and fees, even with zero chargebacks on the books. Acquirers acting on the data can impose processing restrictions, reserves, or fines, and the terminal escalation is account termination plus a MATCH listing under Reason Code 05.

Related articles

What Tools Track Payment Profitability Across Processors?

Subscription analytics tools measure revenue. Payment orchestration routes transactions. Neither one models what a payment actually costs. Here is the honest category map, what each tool genuinely measures, and how to test whether your stack can compute profit after fees, refunds and chargebacks.

AI Agent Chargeback Liability: Who Pays When Bots Buy?

AI agents are starting to buy on customers' cards, and when those purchases get disputed, the merchant eats the loss by default. Here is who pays, what the card networks actually say, and the consent evidence subscription merchants should start capturing today.

VAMP Thresholds Explained: Visa Acquirer Monitoring Program

The current VAMP thresholds after the 1 April 2026 tightening: the Excessive Merchant line is now 1.50% (150 bps) across the US, Canada, EU, APAC, and LATAM, with CEMEA the lone holdout at 2.20%. Includes the ratio calculation, the RDR carve-out, remediation timeline, and how to stay under the line.