Back to blog
Payment Processing7 min read

Visa's Compelling Evidence 3.0 Changes on 24 October. The Prior Purchases Can Come From Other Merchants, and in Pre-Arbitration Only From Ones Your Acquirer Processed.

From 24 October 2026, Visa lets a merchant defend a 10.4 card-absent fraud dispute with a cardholder's earlier undisputed purchases at other merchants, not only its own, and in pre-arbitration the acquirer may submit only transaction data it processed itself. What CE3.0 requires today, what changes, and what an acquirer or ISO should check first.

Kyle Hall

Kyle Hall

Founder

Visa's Compelling Evidence 3.0 Changes on 24 October. The Prior Purchases Can Come From Other Merchants, and in Pre-Arbitration Only From Ones Your Acquirer Processed.

Most friendly-fraud disputes on Visa arrive under Dispute Condition 10.4, Other Fraud – Card-Absent Environment: the cardholder says they did not authorise or take part in an online or phone purchase. Since April 2023, Visa has given merchants a way to answer that claim with data rather than argument, a rule the industry calls Compelling Evidence 3.0, or CE3.0. On 24 October 2026 the rule changes in a way that moves part of the work from the merchant to the acquirer.

The headline is that the two earlier purchases a merchant uses as proof no longer have to be its own. They can come from other merchants. The detail most summaries leave out is where those purchases may come from: the April 2026 edition of the Visa Rules says an acquirer may only submit transaction data it accepted and processed itself. Everything below is taken from that edition, the Visa Core Rules and Visa Product and Service Rules dated 18 April 2026, unless noted.

What CE3.0 Does Today

A 10.4 dispute starts with the issuer. It must report the fraud to Visa before it can dispute, and it has 120 calendar days from the transaction processing date to do so. CE3.0 lets the merchant's side show that the same cardholder has bought the same way before without complaint, which Visa treats as grounds to refuse the fraud claim rather than as one more piece of evidence to weigh.

Under the rule in force through 23 October 2026, the merchant needs two earlier transactions on the same payment credential, such as the account number or a token, that meet these conditions:

  • The issuer did not report either of them to Visa as fraud.
  • Both were processed more than 120 calendar days before the dispute, and no more than 365 days before its processing date. The 120-day floor does not apply if the earlier transactions were Original Credit Transactions.
  • A detailed description of what was bought is supplied for the disputed transaction and both earlier ones. In the pre-dispute version of the rule, for e-commerce transactions processed through Visa Secure with ECI 7 and a CAVV, which includes Visa Data Only transactions, a purchase order number can stand in for the description.
  • The device ID or device fingerprint, or the IP address, matches between the earlier transactions and the disputed one, plus at least one more data element from the list below.

The rules are specific about what counts as each data element, and these specifications are where most submissions will succeed or fail:

  • Customer account or login ID: the unique identifier the cardholder used to sign in at the time of the purchase, in clear text, not hashed, and a value the cardholder would recognise.
  • Full delivery address: street, city, state or province, postal code and country, in clear text. Visa's client FAQ says a billing address cannot be substituted when nothing was shipped.
  • Device ID: an identifier the cardholder can verify, such as an IMEI, at least 15 characters, in clear text.
  • Device fingerprint: derived from at least two software or hardware properties of the device, at least 20 characters, and the only element that may be hashed.
  • IP address: the cardholder's public IP address, in clear text, in IPv4 or IPv6 format.

Device ID and device fingerprint count as one element, not two. The pre-arbitration rule already says so, and from 24 October the pre-dispute rule says it as well. A merchant that supplies both has to pick another element to reach two.

The Two Ways In

The same criteria can be met at two points. Before a dispute is filed, a merchant that shares order data through Verifi's Order Insight service can have the dispute blocked outright: the Visa Rules list a transaction meeting the CE3.0 criteria as an invalid dispute. Visa's client FAQ says disputes rejected this way do not add to dispute counts or ratios.

After a dispute is filed, the acquirer can use the criteria in a pre-arbitration attempt through Visa Resolve Online. The acquirer has 30 calendar days from the dispute processing date to make the attempt, and the issuer has 30 days from the attempt to accept liability or decline it, after which the acquirer may file for arbitration.

Either way, Visa's FAQ says the fraud report (the TC40) attached to a CE3.0-qualified transaction is removed. That matters for the Visa Acquirer Monitoring Program: Visa's VAMP fact sheet says TC40 fraud qualified for CE3.0 is excluded from the VAMP ratio, contingent on the timing of the data extract. A case resolved after the monthly extract does not help that month's number.

What Changes on 24 October 2026

The April 2026 Summary of Changes describes the update as expanding the availability and application of the remedy rule and letting the CE3.0 framework support multi-merchant transactions as evidence. The revised text for disputes processed on or after 24 October makes four substantive changes.

  • The earlier transactions may be at one or more merchants. The new text says the same card, or a payment credential associated with that card such as a token, was used at one or more merchants in two previous undisputed transactions.
  • Card and token are tied together. The old wording required the same payment credential; the new wording accepts the same card or a credential associated with it. Visa's 2022 FAQ had already said it uses the underlying account number to pair merchant and cardholder.
  • The purchase-order-number alternative widens. In the pre-dispute rule it now covers ECI 7 e-commerce transactions carrying a valid CAVV from Visa Secure, a valid TAVV from Visa Token Service, or a valid Match Key from Visa's Intelligent Data Exchange API, where before it was tied to Visa Secure.
  • Login IDs from an agentic payment provider count. The account or login ID element now expressly includes login IDs for an agentic payment provider as well as for the merchant's own site or app.

The limit sits in a footnote to the pre-arbitration table. For disputes processed on or after 24 October, an acquirer must only submit transaction data accepted and processed by that acquirer. In pre-arbitration, then, the multi-merchant history is a portfolio asset rather than a network-wide one: a merchant can lean on a cardholder's clean purchases at other merchants only where its own acquirer processed them and can produce the matching data. The pre-dispute version of the rule carries no equivalent footnote, and the public rules do not say how evidence from other merchants would be assembled at that stage, so treat that route as unsettled until Visa or your acquirer says otherwise.

This is a real reversal of the original position. Visa's October 2022 FAQ said a merchant operating several business lines generally could not supply evidence across them. From 24 October, the question is less whether the purchases were at the same merchant and more whether the acquirer holds usable records of them.

The Guard Rail

The rules also say what happens to merchants who fabricate a history. Under the Visa Fraud Dispute Monitoring Program, Visa monitors the data submitted to meet the criteria. If it finds a merchant falsifying data to gain protection, it notifies the acquirer, merchant or service provider, and the merchant can no longer use the CE3.0 pre-arbitration remedy for the payment credentials concerned until the acquirer, merchant or service provider confirms in writing that the activity is corrected. Visa's FAQ adds that it runs algorithms to look for anomalous data.

With multi-merchant evidence, that exposure widens. A submission can now rest on data captured by a merchant other than the one defending the dispute, and the acquirer is the party presenting it.

What Does Not Change

  • CE3.0 applies only to Dispute Condition 10.4. It does not help with a consumer dispute such as goods not received or not as described.
  • It still does not work for a first purchase. Two qualifying earlier transactions are required, so a new cardholder has no history to point to.
  • Visa's FAQ says Rapid Dispute Resolution and 3-D Secure rules are unaffected. A fraud dispute that passes Visa's edits still runs through RDR if the merchant participates.
  • Recurring merchant-initiated transactions can qualify, using the data elements from the initial setup, according to the FAQ.
  • It is a Visa rule. Nothing here changes Mastercard's dispute process.

What an Acquirer or ISO Should Check Before 24 October

  • Whether the gateway captures the data elements for every card-absent merchant, not only the large ones, and keeps them in the formats the rules require: public IP in clear text, a login ID the cardholder would recognise, a full delivery address, a device ID of at least 15 characters or a fingerprint of at least 20.
  • How long that data is kept. An earlier transaction can be up to 365 days older than the dispute, and the acquirer then has up to 30 days to attempt pre-arbitration, so a retention period shorter than about 13 months throws away usable history.
  • Whether transaction data can be searched across merchants in the portfolio by card and by token. Multi-merchant evidence is only as good as the acquirer's ability to find the cardholder's other purchases.
  • Whether merchant agreements and privacy notices allow one merchant's customer data to be used in another merchant's dispute. The Visa Rules permit the evidence; they do not settle the contract or privacy question, and that is one for counsel.
  • Whether submissions are checked before they go out. A pre-arbitration that pairs a device ID with a device fingerprint as two elements does not meet the rule, and a pattern of weak or doubtful submissions invites monitoring under the Fraud Dispute Monitoring Program.
  • Whether the disputes team knows the VAMP timing. A CE3.0 case closed after the monthly extract does not reduce that month's ratio.

None of this is a new product. It is a data-retention decision, a portfolio search and a submission checklist. Since April 2023, CE3.0 has rewarded merchants with good records of their own customers. From 24 October it also rewards acquirers who keep good records across the portfolio.

Tags

About the author

Kyle Hall

Kyle Hall

Founder

Kyle Hall is a fintech entrepreneur, software engineer, and marketing strategist with over a decade of experience in high-risk payment processing and SaaS development. He is the CEO of PayKings, a leader in high-risk merchant services, and the founder of PulseCRM, a purpose-built CRM platform for the payments industry. Kyle specializes in building custom payment processing systems and growth strategies that empower merchant services providers to scale and succeed in the digital marketplace.

Now onboarding software partners

Turn your software into a payments business.

We sell it, board it, underwrite it, and run it. You add a revenue line to your platform without adding headcount.

Built for vertical SaaS platforms ready to monetize payments.

PCI DSS compliantSOC 2 Type II99.9% uptimeMulti-processor