
A liability shift is a card network rule that moves the cost of a fraudulent sale to whichever party used the weaker security. In stores, the EMV chip liability shift, in effect in the US since October 2015, makes the merchant pay for counterfeit-card fraud when its terminal couldn't read the chip. Online, 3-D Secure authentication (Visa Secure, Mastercard Identity Check) can move fraud chargebacks from the merchant to the card issuer.
What Does Liability Shift Mean?
Before the shift, the U.S. Payments Forum says, liability for card-present fraud generally sat with card issuers. The networks changed their rules to place fraud liability on the party that had not moved to chip technology. Visa's chip dispute conditions apply only when a transaction "qualifies for the EMV liability shift."
A US merchant meets two separate shifts:
| Chip (EMV) liability shift | 3-D Secure liability shift | |
| Where | In person, at the terminal | Online orders |
| What it covers | Counterfeit cards, and for some networks lost or stolen cards | Fraud the cardholder says they didn't make |
| How you keep liability off your books | Read the chip | Authenticate the shopper with 3-D Secure |
| Visa dispute condition | 10.1 and 10.2 | 10.4 |
| Mastercard reason code | 4870 and 4871 | 4837 |
Neither shift covers every chargeback. A shopper who says the goods never arrived files a different dispute, and the shift doesn't apply. For how disputes move through the system, see what is a chargeback.
The EMV Liability Shift for Chip Cards
The U.S. Payments Forum, a cross-industry group, says most US payment networks put their EMV fraud liability shifts into effect in October 2015 for point-of-sale transactions. The rule is about a specific fraud: a criminal copies the magnetic stripe data from a real chip card onto a counterfeit card, then swipes it somewhere the chip can't be checked.
The Forum's summary table for the networks it lists, Visa and Mastercard included:
| Card | Terminal | Who pays for counterfeit fraud |
| Magnetic stripe only | Any terminal | Issuer |
| Chip card | Chip-enabled | Issuer |
| Counterfeit stripe copied from a chip card | Can't read chips | Acquirer and merchant |
| Counterfeit stripe copied from a chip card | Chip-enabled | Issuer |
What about fallback swipes?
When the chip won't read and the terminal falls back to the stripe, Visa's rules say the fallback sale is the issuer's liability if the issuer approved it, the authorization message identified it as fallback, and correct acceptance procedures were followed. Key-entering the card number is different. The Forum warns that a merchant who keys in a card at the counter is liable for fraudulent transactions.
Fuel pumps came later
Automated fuel dispensers got extra time. In an April 2020 notice, Visa moved its US fuel-pump liability shift from October 1, 2020 to April 17, 2021. Mastercard's Chargeback Guide lists April 16, 2021 for US domestic fuel transactions (MCC 5542) under its lost-or-stolen chip shift.
EMV fraud liability shift: counterfeit vs lost or stolen
The counterfeit shift is the one every major network has. The lost-or-stolen shift is where the networks differ. Per the Forum's 2019 paper, American Express, Discover, Mastercard and PULSE can hold the merchant liable when a stolen PIN-preferring chip card is used at a terminal that can't read the chip or can't take a PIN. Visa's US rules don't: the Forum says there is never any lost-and-stolen liability for a Visa merchant on electronically read face-to-face transactions, whether or not the merchant has EMV.
Visa Liability Shift: Dispute Conditions 10.1 and 10.2
Visa's current rules (18 April 2026 edition) list the US Region's EMV liability shift as covering "all domestic and interregional counterfeit POS and ATM Transactions." That's dispute condition 10.1. Condition 10.2 exists for the lost-or-stolen shift in other regions.
Visa 10.1: EMV Liability Shift Counterfeit Fraud
An issuer can file 10.1 when all of these are true:
- A counterfeit card was used in a card-present sale, and the cardholder denies making it.
- The real card is a chip card.
- The sale didn't happen at a chip-reading device, or the chip was read but the acquirer didn't send the full chip data to Visa.
The dispute is invalid for, among other things, a chip-initiated transaction, a fallback transaction, and (everywhere except Europe) a transaction that contained a token. The issuer has 120 calendar days from the transaction processing date to file.
Visa 10.2: EMV Liability Shift Non-Counterfeit Fraud
10.2 covers a lost, stolen or never-received PIN-preferring chip card used in person at a terminal that couldn't read the chip or wasn't EMV PIN-compliant. Contactless transactions and sales correctly processed at an EMV PIN-compliant device are invalid for 10.2. Given the US Region's counterfeit-only entry in Visa's table, a US merchant mostly meets 10.1.
Chip Liability Shift Chargebacks at Mastercard (4870 and 4871)
Mastercard's Chargeback Guide (Merchant Edition, 13 May 2025) has two chip codes:
- 4870, Chip Liability Shift. Counterfeit fraud on an EMV chip card, either at a terminal that isn't a hybrid (chip and stripe) terminal, or at a hybrid terminal where the chip data (DE 55) wasn't in the authorization. The issuer has 120 calendar days from the central site business date in most cases.
- 4871, Chip Liability Shift: Lost/Stolen/Never Received Issue (NRI) Fraud. A PIN-preferring chip card that wasn't in the cardholder's possession, used at a stripe-only terminal, or at a chip terminal without a working PIN pad that can check the PIN. Mastercard's table gives October 1, 2015 as the US domestic start date outside fuel pumps.
Mastercard says 4870 can't be used for a valid chip transaction with chip data sent, a properly identified technical fallback, a mail, phone or e-commerce order, or a properly identified and authorized contactless transaction. 4871 can't be used when online PIN data was sent, or for a contactless sale where the phone verified the shopper (CDCVM).
Worked example: a counterfeit chargeback on a swiped chip card
Maple Street Outfitters is a fictional clothing shop still using an old magnetic-stripe-only terminal. On Monday, March 2, 2026, a shopper buys $1,240 of jackets and boots with a Visa card. The card is a counterfeit: its stripe carries data copied from a real customer's chip card. The sale is approved and its transaction processing date is Tuesday, March 3.
| Date | What happens | Rule |
| March 3, 2026 | Transaction processed | Day 0 |
| April 20, 2026 | The real cardholder reports the charge; the issuer files dispute 10.1 | Must be within 120 calendar days, by July 1, 2026 |
| May 20, 2026 | Last day for the acquirer's pre-arbitration attempt | 30 calendar days from the dispute processing date |
The shop has no defense. The card was a chip card, the terminal wasn't a chip-reading device, and none of Visa's invalid-dispute reasons apply. Maple Street loses the $1,240 sale and the merchandise is gone. Had the same counterfeit been run on a chip-enabled terminal, the Forum's table puts the loss on the issuer. Your processor handles the response with the network, so answer its notice the day it arrives.
A chip-enabled merchant terminal is the defense here.
The 3-D Secure Liability Shift for Online Orders
Chip rules don't protect online orders. Our guide to card-not-present transactions covers the basics of 3-D Secure. This section covers what Visa's rules say about the shift.
What a "successful liability shift" means
Visa ties the shift to the Electronic Commerce Indicator (ECI) value in the authorization request. Acquirers may only use ECI 5 or 6 when the authorization included the Cardholder Authentication Verification Value (CAVV), a code produced by Visa Secure authentication.
Under dispute condition 10.4 (Other Fraud, Card-Absent Environment), Visa lists as invalid:
- ECI 5, authenticated. The issuer answered with an authentication confirmation using Visa Secure with EMV 3-D Secure, and the CAVV was in the authorization request.
- ECI 6, attempted. The issuer, or Visa on its behalf, sent an attempt response, meaning the issuer or cardholder wasn't participating in Visa Secure, and the CAVV was included. This doesn't apply to non-reloadable prepaid cards.
- ECI 5 with a token. A sale using an authenticated payment credential with the token cryptogram (TAVV), where the issuer or token requestor approved a cardholder verification.
Exclusions you can't authenticate around
For US domestic e-commerce, Visa says 10.4 applies "regardless of the Electronic Commerce Indicator value" for merchants with MCC 4829 (wire transfers and money orders), 5967 (adult content), 6051 (non-financial institutions selling foreign currency, cryptocurrency and similar), 6540 (stored-value card purchase or load), 7801 and 7802 (licensed online gambling and racing) and 7995 (betting). Stripe's documentation adds that successful authentication "doesn't guarantee" the shift, and that accounts in a fraud monitoring program may lose it.
Mastercard Identity Check
Mastercard's guide bars reason code 4837 (No Cardholder Authorization) on properly authenticated transactions carrying security level indicator values 211, 212, 215, 217 or 242, naming Identity Check as an example. Ask your payment gateway which values it sends.
Worked example: four online orders, two outcomes
Harbor Candle Co. is a hypothetical online store. In one month, four of its Visa orders come back as 10.4 fraud disputes:
| Order | 3-D Secure result | Amount | Outcome under Visa's rules |
| A | ECI 5, authenticated, CAVV sent | $420 | Dispute invalid |
| B | ECI 6, attempt, CAVV sent, regular credit card | $260 | Dispute invalid |
| C | ECI 6, attempt, non-reloadable prepaid gift card | $180 | Not protected |
| D | No 3-D Secure | $350 | Not protected |
Orders A and B are protected: $420 + $260 = $680. Orders C and D, $180 + $350 = $530, fall to the store unless it wins with evidence, such as the compelling-evidence rules in how to win a chargeback.
"Successful Liability Shift for Enrolled Card Is Required": What It Means
Shoppers see this message when a checkout refuses their card. We checked the 3-D Secure documentation of PayPal, Braintree, Stripe, Checkout.com and Nuvei and didn't find this exact wording in any of them, so we can't tell you which system shows it.
The terms do match 3-D Secure results. In PayPal's documentation, an enrollment status of Y means the card is ready for 3-D Secure, and a LiabilityShift result of NO means "Liability is with the merchant. Do not continue with authorization." A merchant that requires a successful shift on every enrolled card will stop the sale when authentication fails.
If you're the shopper: finish your bank's verification prompt if one appears, or use a different card. Visa's rules don't extend the "attempted" protection to non-reloadable prepaid cards, so a merchant that insists on protection may not get it from one. That doesn't tell you why any particular site refused your card.
Does Apple Pay Shift Liability?
In the store. Visa's rules make a 10.1 counterfeit dispute invalid for a transaction that contained a token, and make 10.2 invalid for contactless transactions. Mastercard bars 4870 on properly identified contactless sales and 4871 on contactless sales verified on the device. The Forum's 2019 paper, which names Apple Pay as a certified app, says a Visa merchant enabled for contact EMV is protected against counterfeit liability regardless of interface. See our tap-to-pay guide.
Online. Stripe's Apple Pay documentation says Apple Pay supports liability shift globally for all the major networks, but for Visa only on devices running iOS 16.2 and above (below that, only for cards issued in Europe). Adyen's documentation says the same about iOS 16.2.
How to Keep the Shift on Your Side
- Dip or tap every chip card. Swipe only when the chip fails, and let the terminal flag it as fallback.
- Don't key in cards at the counter.
- Make sure your acquirer sends full chip data. Visa 10.1 can apply to a chip-read sale when it doesn't.
- Turn on 3-D Secure for online orders, and check that your gateway sends the CAVV with ECI 5 or 6.
- Decide what to do with unauthenticated orders. Ship, review or decline, knowing the fraud risk stays with you.
- Keep records. Save authentication results and delivery proof. More tactics are in our fraud prevention guide, and terms are in the glossary.
This is general information, not legal advice. Card network rules change, and your processing agreement may add its own requirements.
If you're not sure whether your terminals read chips or your gateway runs 3-D Secure, send us a recent statement for a free statement review.
Sources
- Visa, "Visa Core Rules and Visa Product and Service Rules," 18 April 2026 edition (sections 1.10.1.2, 4.1.17.47, 5.8.4.4, 11.2.2, 11.7.2, 11.7.3 and 11.7.5; Attempt Response glossary entry), observed October 2026.
- Visa, "Visa's Operational Business Response to COVID-19: U.S. Automated Fuel Dispenser EMV Liability Shift Delayed to 2021," Visa Business News, 30 April 2020 (copy hosted by a fuel retailers' association), observed October 2026.
- Mastercard, "Chargeback Guide, Merchant Edition," 13 May 2025 (reason codes 4837, 4870 and 4871), observed October 2026.
- U.S. Payments Forum, "Understanding Fraud Liability for EMV Contact and Contactless Transactions in the U.S.," version 3.0, February 2019, observed October 2026.
- PayPal Developer, "3D Secure response parameters", observed October 2026.
- Stripe, "Authenticate with 3D Secure", observed October 2026.
- Stripe, "Apple Pay liability shift, disputes, and refunds", observed October 2026.
- Adyen, "Apple Pay", observed October 2026.
Frequently Asked Questions
What does liability shift mean?
It's a card network rule that moves the cost of a fraudulent card sale to the party with the weaker security. In stores, a merchant whose terminal can't read chips pays for counterfeit-card fraud. Online, a sale authenticated with 3-D Secure can move fraud chargebacks from the merchant to the card issuer.
When did the EMV liability shift start in the US?
Most US payment networks put their EMV fraud liability shifts into effect in October 2015 for point-of-sale transactions, according to the U.S. Payments Forum. Fuel pumps came later: Visa moved its US fuel-pump date to April 17, 2021, and Mastercard lists April 16, 2021.
What is Visa dispute condition 10.1?
Visa 10.1, EMV Liability Shift Counterfeit Fraud, lets an issuer dispute an in-person sale made with a counterfeit of a chip card when the sale didn't happen at a chip-reading device or full chip data wasn't sent. It is invalid for chip-initiated and fallback transactions, and the issuer has 120 calendar days from the processing date to file.
Does 3-D Secure always protect me from fraud chargebacks?
No. Under Visa's rules, a card-absent fraud dispute (10.4) is invalid for an ECI 5 authenticated sale or an ECI 6 attempted sale with the CAVV sent, but the attempt protection doesn't cover non-reloadable prepaid cards, and some US merchant categories stay exposed whatever the ECI value.
Does Apple Pay shift liability to the issuer?
In stores, Visa's rules make counterfeit disputes invalid for tokenized transactions, and Mastercard bars its chip codes on properly identified contactless sales. Online, Stripe and Adyen say Apple Pay supports liability shift for the major networks, with Visa limited to devices on iOS 16.2 or later.
About Payment USAโs Founder
Published by Payment USA, a merchant services provider. Our guides and comparisons reflect that commercial perspective.

Chase James
CEO, Payment USA
Chase James is the founder and CEO of Payment USA, a merchant services company built on transparency and fair pricing. With over 15 years in the payments industry, Chase has helped thousands of businesses uncover hidden processing fees and switch to honest, interchange-plus pricing.
Contact Chase โ