Fraud detection metrics are the numbers that show whether a fraud tool works on your own transactions. Track six: fraud rate, chargeback rate, false positive rate, approval rate, manual review rate and step-up conversion. Write the definitions into your vendor contract, log every decision against one order ID, review the numbers weekly and send each alert to a named owner.
Analyst and peer-review listings, such as the online fraud detection category on Gartner Peer Insights, are a good way to build a vendor shortlist. They say little about what a specific vendor will do to your approval rate, your chargeback exposure or your customer experience once it is live on your own transaction mix.
Few vendors offer to show you, in your own numbers, whether a lift in approval rate still holds ninety days after signature. You can get that answer yourself with a measurement plan you own, independent of any vendor dashboard. That plan has three parts: shared metric definitions, end-to-end instrumentation, and a fixed reporting cadence with alert thresholds.
Six metrics tell the full story of a fraud program. Agree on the definitions before you sign, and put them in the vendor contract as well as your internal wiki. A vendor who resists a shared definition is telling you something.
| Metric | Definition | Formula |
|---|---|---|
| Fraud rate | Share of transaction value confirmed as fraudulent | Confirmed fraud $ ÷ total transaction $ |
| Chargeback rate | Share of transactions disputed by a cardholder | Chargebacks ÷ total transactions (by count and by $) |
| False positive rate | Share of legitimate orders that were declined | Legitimate orders declined ÷ all legitimate orders attempted |
| Approval rate | Share of attempted transactions cleared for payment | Approved transactions ÷ attempted transactions |
| Manual review rate | Share of orders sent to a human reviewer | Orders routed to review ÷ total orders |
| Step-up conversion | Share of customers completing added verification | Completed step-up challenges ÷ challenges presented |
A false positive, also called a false decline, is a legitimate order your system declines. The false positive rate measures how many of your good customers you turn away, so its denominator is all legitimate orders, not all declines.
Some teams also track the share of declines that turned out to be legitimate (legitimate declines ÷ total declines). That number is a useful check on decision quality, but it is a different metric. Label it separately so the two are never compared as if they were the same thing.
You will rarely know for certain that a declined order was legitimate. Estimate it from evidence you can collect: a customer who retries and succeeds with the same card, complaints to customer service, and periodic manual sampling of declined orders.
Your internal chargeback rate is one input. Visa monitors card-not-present merchants with its own measure, the VAMP ratio, which counts fraud reports (TC40) plus disputes (TC15) and divides by the count of settled transactions. Because fraud reports are included, the VAMP ratio can run higher than your chargeback rate alone. Track both, and reconcile them each month against your processor's reports. For the current thresholds and how they apply, see our guide to Visa VAMP thresholds.
A fraud score on its own tells you very little. Log the fraud decision, the review outcome and the final chargeback outcome against the same order ID so you can trace one transaction from end to end. Capture a timestamp at each stage: authorization, review assignment, review resolution and chargeback filing. Tag every declined order with a specific reason code. Without this discipline, a fraud problem and a friction problem look identical in your reporting.
Good instrumentation also helps you spot attacks early. A sudden spike in small authorization attempts and declines from the same cards or BINs is a classic sign of card testing, and it will distort every metric above if you don't isolate it.
Review all six metrics every week. Fraud patterns move faster than a quarterly business review. Set an alert threshold for each metric, route each alert to a named owner instead of a shared inbox, and report the same six numbers to leadership every month in the same format. That way a change in performance shows up right away instead of at contract renewal.
The triggers below are starting points. Tune them to your own baseline and volume after the first 90 days of data.
| Metric | Cadence | Alert trigger | Owner |
|---|---|---|---|
| Fraud rate | Weekly | Rises more than 15% above the trailing 90-day average | Risk or fraud lead |
| Chargeback rate and VAMP ratio | Weekly | VAMP ratio moves toward 1.5%, Visa's merchant "Excessive" threshold in the U.S. since April 1, 2026 (set your internal trigger well below it) | Risk or fraud lead |
| False positive rate | Weekly | Rises more than 20% above the trailing 90-day average | Risk lead and CX owner |
| Approval rate | Weekly | Drops more than 3 percentage points week over week | Finance lead |
| Manual review rate | Weekly | Exceeds 10% of order volume for two straight weeks | Operations lead |
| Step-up conversion | Monthly | Drops below 80% | Product or UX lead |
Report all six metrics to the board or leadership team monthly, in the same format each time, with a trend line covering the trailing twelve months.
pmtbox underwrites e-commerce and retail merchants up front, so the terms are clear before you process. With Fraud Ownership, pmtbox covers fraud on the transactions it approves, which puts the cost of a missed fraud decision on pmtbox instead of on you. Chargeback Automation handles representment, and you pay one fee.
That model makes the plan above more useful. You can watch approval rate and false positive rate to confirm good customers are getting through, and use fraud rate and chargeback data to see the coverage working in your own numbers.
Talk to the pmtbox team about how your current metrics would look under Fraud Ownership.
There is no single benchmark, because it depends on your product, price points and customer base. Measure your own baseline first, then hold any vendor to improving it. Make sure every comparison uses the same formula: legitimate orders declined divided by all legitimate orders.
Fraud rate measures the share of transaction value confirmed as fraudulent. Chargeback rate measures how often cardholders dispute transactions, which includes non-fraud disputes such as "item not received." A merchant can have a low fraud rate and still have a chargeback problem, so track both.
Visa uses the VAMP ratio: the count of fraud reports (TC40) plus disputes (TC15), divided by the count of settled card-not-present transactions. From April 1, 2026, the merchant "Excessive" threshold in the U.S., Canada, the EU and Asia Pacific is 1.5%, with a minimum of 1,500 fraud reports and disputes in a month.
Yes. Writing the six definitions into the contract means you and the vendor report the same numbers the same way. It also gives you a clear basis for reviewing performance at renewal.
Review the metrics weekly and the alert thresholds themselves at least quarterly. Revisit thresholds sooner after a major change, such as a new product line, a new market or a card network rule update.