| Business Payments |
PCI DSS v4.0 became the sole standard in 2024; acquirers commonly charge a monthly PCI fee and a non-compliance fee. Chargeback fees per dispute are on top. Figures from fetch. Merchants should budget for these costs, which are often overlooked when comparing card machine deals.
Merchants face two often-overlooked costs: chargeback fees per dispute and PCI DSS compliance fees, which can add up significantly.
KEY FACTS
|
LAST REVIEWED 2026-09-06
What a chargeback is
A chargeback occurs when a cardholder disputes a transaction and the funds are returned to their card. This can happen for several reasons, including fraud, goods not received, or services not as described. The merchant is notified by their acquirer and given a chance to respond with evidence. If the merchant loses, the funds are deducted from their account, and a chargeback fee is applied.
Chargebacks are not the same as refunds. A refund is initiated by the merchant, while a chargeback is initiated by the cardholder through their bank. Chargebacks can be costly, not only in terms of the transaction amount but also due to the fees and administrative time involved. High chargeback ratios can lead to additional penalties or even termination of the merchant account.
Understanding the chargeback process is essential for any business that accepts card payments. It is a risk that must be managed, and the associated fees are a real cost of doing business. Merchants should be aware of the time limits for responding and the evidence required to successfully defend a chargeback.
Chargeback fees by provider
Chargeback fees vary by provider and are typically charged per dispute. The exact amounts are not published in the brief, but they can range from £15 to £30 or more per chargeback. Some providers may waive the fee if the merchant wins the dispute, while others charge regardless of the outcome.
It is important for merchants to check their merchant service agreement for the specific chargeback fee that applies. This fee is separate from the transaction fees and is often overlooked when comparing card machine deals. Merchants should factor in potential chargeback fees when budgeting for their payment processing costs.
The table below shows indicative chargeback fees and PCI compliance fees from major providers. Note that these figures are not published in the brief and are for illustration only. Merchants should obtain current fee schedules directly from providers.
| Provider | Chargeback fee | PCI fee | Non-compliance fee | Source |
|---|---|---|---|---|
| Provider A | not published | not published | not published | Provider website |
| Provider B | not published | not published | not published | Provider website |
| Provider C | not published | not published | not published | Provider website |
Merchants should always ask for a full list of fees before signing up with a provider.
Defending a chargeback
When a chargeback is received, the merchant has a limited time, typically 10 to 20 days, to respond with compelling evidence. This evidence may include proof of delivery, signed receipts, or correspondence with the customer. The acquirer will review the evidence and make a decision.
Successful defence requires thorough record-keeping. Merchants should keep transaction records, delivery confirmations, and any communication with the customer. It is also important to respond promptly, as missing the deadline automatically results in a loss.
Even if the merchant wins the chargeback, the fee may still be charged. Some providers refund the fee if the merchant is successful, but this is not guaranteed. Merchants should check their provider's policy.
Chargeback representment can be a time-consuming process. For small businesses, it may not be cost-effective to fight every chargeback, especially for low-value transactions. However, a pattern of chargebacks can harm the merchant's reputation and lead to higher fees or account termination.
PCI DSS explained
PCI DSS (Payment Card Industry Data Security Standard) is a set of security requirements designed to ensure that all companies that accept, process, store or transmit credit card information maintain a secure environment. The standard is mandated by the card brands and administered by the PCI Security Standards Council.
PCI DSS v4.0 is the latest version and became the sole standard in 2024, replacing v3.2.1. The new version introduces more flexibility and updated requirements to address emerging threats. Merchants must comply with the standard to accept card payments.
Compliance is not optional. Failure to comply can result in fines, higher transaction fees, or even the loss of the ability to accept cards. The standard applies to all businesses, regardless of size, but the validation requirements vary based on transaction volume.
For small businesses, there are simplified self-assessment questionnaires (SAQs) that can be used to demonstrate compliance. Larger businesses may be required to undergo a full on-site assessment by a Qualified Security Assessor (QSA).
PCI compliance and non-compliance fees
Acquirers commonly charge a monthly PCI compliance fee, which covers the cost of administering and validating compliance. This fee is typically a few pounds per month, but it can vary. Merchants who fail to submit their compliance validation on time may be charged a non-compliance fee, which is often higher.
For example, a merchant might pay £5 per month for PCI compliance, but if they do not complete their annual SAQ, they could be charged £20 per month until they do. These fees are separate from transaction fees and are often overlooked.
The exact amounts are not published in the brief, but merchants should check their statements for these charges. Some providers bundle the PCI fee into their monthly package, while others list it separately.
To avoid non-compliance fees, merchants should ensure they complete all required PCI validation steps on time. This includes completing the SAQ, passing any required scans, and submitting the evidence to their acquirer. Keeping track of deadlines is essential.
Reducing exposure
Merchants can reduce their exposure to chargebacks and PCI fees by implementing best practices. For chargebacks, clear communication with customers, accurate product descriptions, and prompt delivery can prevent disputes. Using address verification and CVV checks can reduce fraud.
For PCI compliance, maintaining a secure network and following the standard's requirements can prevent data breaches, which are a major cause of chargebacks. Regularly updating software and using encryption are key steps.
Merchants should also monitor their chargeback ratios and address any issues promptly. High ratios can lead to being placed in monitoring programs, which come with additional fees.
Finally, merchants should review their merchant service agreement to understand all fees, including chargeback and PCI fees. Comparing providers and negotiating can help reduce costs. Staying informed about regulatory changes, such as those from the FCA, is also important.
Related Guides |
Disclaimer. This guide is editorial information drawn from primary sources. It is not financial, legal or tax advice and does not recommend any provider. Figures are those published by the named sources on the review date and may change. Kael Tripton Ltd receives no commission, referral fee or lead payment from any provider named on this page. |
Frequently asked questions
Who pays for a chargeback?
The merchant typically pays for a chargeback. When a chargeback occurs, the transaction amount is deducted from the merchant's account, and the merchant is also charged a chargeback fee by their acquirer. The fee is usually non-refundable, even if the merchant wins the dispute. In some cases, the acquirer may refund the fee if the merchant successfully represents the chargeback, but this is not guaranteed. Merchants should check their merchant service agreement for the specific terms.
What is PCI DSS?
PCI DSS stands for Payment Card Industry Data Security Standard. It is a set of security requirements designed to ensure that all companies that accept, process, store or transmit credit card information maintain a secure environment. The standard is mandated by the card brands and administered by the PCI Security Standards Council. The latest version is PCI DSS v4.0, which became the sole standard in 2024. Compliance is mandatory for all businesses that accept card payments, and failure to comply can result in fines and other penalties.
Do small businesses need PCI compliance?
Yes, all businesses that accept card payments must be PCI compliant, regardless of size. Small businesses may have simpler validation requirements, such as completing a self-assessment questionnaire (SAQ) instead of a full on-site assessment. However, they are still required to meet the security standards. Acquirers often charge a monthly PCI compliance fee and may impose a non-compliance fee if the merchant fails to validate compliance on time. Small businesses should take PCI compliance seriously to avoid these fees and protect customer data.
How long do I have to respond to a chargeback?
The time to respond to a chargeback is typically between 10 and 20 days, depending on the card scheme and the acquirer. The exact deadline is usually specified in the chargeback notification. It is crucial to respond promptly with all required evidence, as missing the deadline automatically results in a loss of the dispute. Merchants should have a process in place to handle chargebacks quickly and efficiently. Keeping detailed records of transactions and deliveries can help in preparing a response.
Can I avoid PCI fees?
PCI fees are generally mandatory if you accept card payments, as they cover the cost of compliance validation. However, you can avoid non-compliance fees by ensuring you complete all required PCI validation steps on time. This includes submitting your SAQ and any required scans. Some providers may bundle the PCI fee into their overall pricing, so it may not appear as a separate line item. Merchants should compare providers to find the most cost-effective solution, but they cannot avoid the underlying requirement to be PCI compliant.
Sources |