Back to the library
Fraud & Risk
2026-08-09 11 min read

Fraud Screening Tools: Build In House or Buy One?

Detection rates are the wrong axis. The question is whether your setup can still produce dispute evidence in clear text six months later.

GM

By Gray Merchants Team

fraud screening tools comparisonCompelling Evidence 3.0chargeback evidence3-D Securefraud prevention
Fraud Screening Tools: Build In House or Buy One?
Key takeaways
  • Blocking fraud and winning disputes are different jobs running on different data. Visa's VAMP ratio combines both into one measure, so better detection only addresses half of it.
  • The decision should turn on data retention, not detection rates. Visa's Compelling Evidence 3.0 requires identifiers in clear text and explicitly not hashed, including a device ID of at least 15 characters and a login ID the cardholder recognises.
  • Hashing identifiers is normal, sensible engineering, and many third-party services deliberately minimise retained personal data. Both instincts can leave you unable to produce qualifying dispute evidence.
  • The useful vendor question is whether you can export device ID, device fingerprint, IP address, login ID and delivery address for a specific past transaction, in a submittable form, and for how long it is retained. CE3.0 relies on transactions more than 120 days old.
  • Most sensible setups buy detection for the cross-merchant pattern data you cannot reproduce alone, while keeping an independent record of the identifiers Visa names. That combination only happens if someone plans it.
  • False positives are the cost nobody models. A declined good customer never appears in fraud reporting, so over-tuned screening looks like success while quietly buying a lower fraud rate with a lower approval rate.

Choosing between in-house fraud screening and a third-party tool like Sift or Kount usually gets argued on detection rates. That's the wrong axis. The question that decides it is whether your setup can still produce the evidence you need to win a dispute six months later, and most teams find out the answer too late.

We're not going to compare vendor feature lists. We can't verify those claims, and they change. What we can do is set out the rules both options have to satisfy.

Blocking Fraud and Winning Disputes Are Different Jobs

A fraud tool decides whether to accept a transaction. A dispute decides whether you keep the money months afterwards. Those run on different data, and a system optimised only for the first can quietly ruin the second.

Under Visa's Acquirer Monitoring Program the ratio that matters combines fraud and disputes into one count-based measure over card-absent volume (Visa). Blocking more transactions lowers the fraud half. It does nothing for the dispute half, and if your screening is aggressive enough to annoy real customers it can raise it.

Our guide to calculating your true chargeback ratio covers how that measure actually works.

The Requirement That Should Drive the Decision

Visa's Compelling Evidence 3.0 remedy lets you defeat a friendly fraud dispute by showing the same card made two previous undisputed purchases from you more than 120 calendar days earlier, matched by device or network identifiers.

The rules are unusually specific about the form that evidence takes (Visa Core Rules, 18 April 2026). A customer account or login ID "must be a unique identifier that the Cardholder uses to authenticate on the Merchant's e-commerce site or application at the time of the Transaction, and must be a value that the Cardholder recognizes in clear text and not hashed." A device ID "must be at least 15 characters, in clear text, and not hashed." A full delivery address must carry street, city, state or province, postal code and country, also in clear text.

Clear text and not hashed, stated three times.

Now hold that against how fraud systems normally work. Hashing identifiers is standard, sensible engineering. Many third-party services are designed to minimise the personal data they retain, which is good privacy practice and often a contractual commitment. Both instincts can leave you unable to produce qualifying evidence.

So the real build-versus-buy question is: who holds the raw identifiers, in clear text, for at least the retention window a dispute needs? Ask that before you ask about detection rates.

What Each Option Is Actually Good At

In-house screening gives you the data. You keep the raw identifiers, you decide retention, and you can assemble a CE3.0 file without asking permission. You also own the whole burden: rule writing, tuning, keeping up with attack patterns, and the PCI scope that comes with handling more data yourself. Our PCI DSS guide covers what that scope means.

Third-party tools give you pattern data across many merchants, which is genuinely something you cannot reproduce alone. A network that has seen a card testing campaign at other merchants can stop it at yours on first contact. What you give up is control over what's stored and in what form, and sometimes the ability to export it in a usable state.

Most sensible setups are both. Buy the detection, keep your own record of the identifiers Visa names. Those aren't in conflict, but it only happens if someone decides it deliberately.

Questions to Ask a Vendor

Five that get past the demo:

  1. Which identifiers do you store in clear text rather than hashed?
  2. Can I export device ID, device fingerprint, IP address, login ID and delivery address for a specific past transaction, in a form I can submit as dispute evidence?
  3. How long is that retained? Disputes arrive months after the sale, and CE3.0 depends on transactions more than 120 days old.
  4. Do you support Visa Secure with ECI 7 and CAVV, since that route allows a purchase order number instead of a full description?
  5. What happens to my data if I leave?

Question two is the one that separates a fraud product from a dispute-capable one.

What Actually Moves the Ratio

Whichever way you go, the same controls do the work, and several aren't fraud tools at all.

3-D Secure shifts fraud liability on qualifying card-absent transactions and produces the ECI and CAVV values that matter later.

Address and card verification checks are cheap and remain the baseline for card-absent sales.

Velocity limits catch card testing, which targets low-priced items precisely because small charges attract less attention.

A recognisable billing descriptor prevents disputes outright. Visa requires the merchant name to be used consistently across receipts, authorizations, clearing records and dispute records, and it prevents more disputes per dollar than any screening rule.

Pre-dispute alerts let you refund before a chargeback is recorded, which keeps the event out of the ratio rather than merely winning it later.

The layered approach is in ecommerce fraud prevention.

The Cost Nobody Models

False positives don't appear on any dashboard as a loss, which is why over-tuned screening survives so long.

A declined good customer costs you the margin on that sale, quite possibly the customer, and nothing in your fraud reporting records it. Meanwhile the fraud number looks excellent, so the system appears to be working.

If you're in a category where approval rates are already under pressure, that trade is worse than it looks. High risk merchants usually cannot afford to buy a lower fraud rate with a lower approval rate.

Frequently Asked Questions

Should I build fraud screening in-house or buy a tool?

Most businesses should buy detection and keep their own record of the identifiers Visa names for dispute evidence. The two aren't alternatives, but combining them only happens if you plan for it.

Why does hashing my data matter?

Because Visa's Compelling Evidence 3.0 requires identifiers in clear text and explicitly not hashed, including a device ID of at least 15 characters and a login ID the cardholder recognises. Hashed values can't qualify, so the storage decision decides whether you can fight those disputes at all.

Do fraud tools lower my chargeback ratio?

Partly. Visa's VAMP ratio combines fraud and disputes, so blocking fraud addresses one half. Disputes from real customers need descriptors, support, and easy cancellation instead.

What should I ask a fraud vendor?

Whether you can export device ID, device fingerprint, IP address, login ID and delivery address for a past transaction in clear text, and for how long it's retained. Disputes surface months later and CE3.0 relies on transactions over 120 days old.

Is 3-D Secure worth the friction?

Usually, for card-absent volume. It shifts fraud liability on qualifying transactions and generates the ECI and CAVV values that open an easier evidence route later.

What's the most underrated fraud control?

Your billing descriptor. Visa requires consistent merchant naming across receipts, authorizations, clearing and dispute records, and an unrecognised descriptor manufactures disputes no screening rule can catch.

How do I know if my screening is too aggressive?

Look at declines rather than fraud. A falling fraud rate alongside falling approvals means you're buying one number with another, and the lost customers never appear in fraud reporting.

Getting declined transactions and lost disputes at the same time? Apply free for an account with dispute handling included, or talk to a specialist about what your current stack can actually prove.

GM

Gray Merchants Team

Gray Merchants is a payment ISO that places merchant accounts across every risk level, from low-risk retail and e-commerce to 67+ high-risk verticals. The editorial team writes on high-risk merchant accounts, chargeback defense, MATCH/TMF remediation, and ACH processing, whether you are new, scaling, switching processors, or rebuilding after a decline.

Talk to a specialist

Tell us about your business

Share a few details and a specialist reviews your industry, volume, and processing history, then comes back with the right path. No obligation.

  • Underwriting decision in 24 to 48 hours
  • $0 setup fee, dedicated MID
  • Specialist replies within 4 business hours
  • Every term disclosed in writing before you sign

Request a call from a specialist

Are you currently processing?

No obligation. A specialist replies within 4 business hours, Mon to Fri, 9:00 to 18:00 EST.

Fraud Screening Tools: Build In House or Buy One? | Gray Merchants