Visa/Mastercard Dispute Mechanics: Why Credit Differs From Debit
Same swipe, but in the US a credit card is protected by Reg Z + the Fair Credit Billing Act - a $50 liability cap, plus a legal right to dispute goods/services with the merchant; a debit card only has Reg E, with a tiered liability of $0/$50/$500/unlimited depending on when you report it. Singapore has no dedicated statute - only an ABS guideline plus FIDReC mediating for free up to S$150,000. Vietnam has Circular 18/2024/TT-NHNN, which gives a 60-day window to file and 30 business days to resolve - but OTP-authenticated transactions are a gray zone where courts tend to side with the bank. The Visa/Mastercard card mechanism is identical across all three; the law layered on top - and which card type you use - is where the cardholder's rights are actually decided.
This piece is split into seven parts. Part I covers what the dispute mechanism is and who pays whom. Part II is the difference between credit cards and debit cards - same Visa/Mastercard logo, but different legal rights, a fact rarely stated plainly in Vietnam. Part III lists the cases eligible for dispute under network rules. Part IV compares the legal frameworks across three countries - the US, Singapore, Vietnam - same payment network, different outcomes. Parts V and VI cover the reality on the ground in SG and VN, checking the license against actual life. Part VII is a six-step playbook for anyone who has just spotted a strange transaction.
Dispute ≠ Refund. A refund is the seller agreeing to give the money back (fast, simple, through the merchant). A chargeback is the buyer asking the issuing bank to reverse the transaction under network rules (Visa Claims Resolution / Mastercom) - forcing the seller to prove otherwise. This article uses "dispute" in the broad sense (including non-fraud complaints like non-delivery), and "chargeback" in the narrow sense (a reversal via scheme rules).
Scope: Visa and Mastercard only, in the consumer (B2C) space. American Express (a closed-loop network), JCB, UnionPay, and domestic NAPAS are not covered. The article focuses on three regions: the US (the benchmark legal framework), Singapore (a soft-law model with a strong regulator), and Vietnam (the new SBV framework under Circular 18/2024). Legal figures are current as of April 2026; specific bank policies can change - re-read your card's terms before acting.
I. The Dispute Mechanism - Four Parties, One Money Loop, Three Layers Of Rules
Every card transaction has four parties in the payment chain (the four-party model): the cardholder, the issuing bank (issuer), the card network (Visa/Mastercard), the bank that settles with the merchant (acquirer), and the merchant. Money flows one way - from the cardholder through the issuer, through the scheme, through the acquirer, to the merchant. When a dispute arises, the money flow reverses along that exact same path. That is a chargeback.
The card network's role here is not "final arbiter" - the network sets the rules (Visa Dispute Management Guidelines 2024; Mastercard Chargeback Guide May 2025) and settles disputes between two banks. The cardholder never speaks directly with Visa or Mastercard. Everything goes through your issuer. This is the first point where the mechanism becomes asymmetric: the bargaining power sits with the issuing bank, not the cardholder.
1.1 - Visa Claims Resolution (VCR): four reason-code groups
Since April 2018, Visa has standardized all reason codes into four categories numbered 10/11/12/13:
- 10 · Fraud - a fraudulent transaction not carried out by the cardholder. Examples: a skimmed card, card-not-present (CNP) fraud, a counterfeit card. Runs through the Allocation workflow: Visa automatically assigns liability to whichever party is at fault (usually the acquirer/merchant if there's no 3DS/EMV).
- 11 · Authorization - a transaction that wasn't validly authorized (e.g., an expired card, a blocked card, or a limit exceeded but processed anyway).
- 12 · Processing Errors - technical errors. Includes duplicates (the same transaction recorded twice), wrong amount, wrong currency, an unprocessed refund.
- 13 · Consumer Disputes - civil disputes. Goods not delivered, goods differing from description, damaged goods, service not rendered, a subscription cancellation that didn't take effect. Runs through the Collaboration workflow: Visa does not auto-assign liability - both sides get a chance to respond before it's formalized.
Visa's standard time limit: the cardholder has 120 days from the transaction date (or the expected delivery date) to file a chargeback. The merchant has 30 days for representment (submitting counter-evidence) after being notified (ChargePay 2024).
1.2 - Mastercard MasterCom: four categories with longer time limits
Mastercard splits similarly into four groups: Authorization, Cardholder Disputes, Fraud, Point-of-Interaction Errors (Visa calls this differently: "Processing Errors"). The main difference: the window is usually 90–120 days, with some reason codes running as long as 540 days (long-running transactions such as subscriptions and installment plans). Merchants get 45 days for representment (Chargebacks911 Mastercard 2026).
| Category | Visa code | Mastercard code | Cardholder filing limit | Merchant response |
|---|---|---|---|---|
| Fraud (CNP/3DS/EMV) | 10.x | 4837, 4870, 4871 | 120 days | 30 / 45 days |
| Authorization | 11.x | 4808 | 120 days | 30 / 45 days |
| Processing Error | 12.x | 4834, 4842, 4846 | 120 days | 30 / 45 days |
| Consumer / Cardholder Dispute | 13.x | 4853, 4854, 4855 | 120 days (some up to 540) | 30 / 45 days |
1.3 - Pre-arbitration and Arbitration: the final round
If the two sides still disagree after representment, the dispute moves to pre-arbitration - the issuer can refile with additional evidence. The final step is formal arbitration at Visa/Mastercard, costing $500–900 and potentially adding another 10–45 days (Chargebacks911). The arbitration decision is final and binds the two banks - it is not a court ruling, and the consumer is never a party to arbitration. The issuing bank decides whether to escalate to arbitration on the customer's behalf. If they don't, the customer has nowhere left to go within the scheme system.
The dispute mechanism is designed to settle disputes between banks, not between a consumer and their own bank. When your issuer refuses to open a chargeback, closes the case early, or fails to file representment when the merchant objects, the scheme has no mechanism for you to appeal directly. Your rights stop at your issuer's door. Everything then depends on two things: which type of card you use (credit or debit - Part II) and the national law binding what your issuer must do for you (Part IV).
II. Credit Card vs Debit Card - Same Visa Logo, Different Protections
Most Vietnamese cardholders carrying a Visa/Mastercard don't know a structural fact: a credit card and a debit card - even under the same Visa logo, issued by the same bank - do not carry the same dispute rights. This gap isn't because Vietnamese banks apply the rules poorly; it originates in the US's own legal design, spreads through scheme rules, and gets printed into the T&Cs of every bank in the world. Three core differences:
The bank's money is moving
Your money has already evaporated
2.1 - Why the US splits credit and debit into two different laws
The US is the only country that draws this sharp a line, via two separate statutes. Consumer Compliance Outlook (Federal Reserve, 2016) explains: "Consumer protections for credit and debit cards derive from different federal laws - the Truth in Lending Act (TILA) for credit cards and the Electronic Fund Transfer Act (EFTA) for debit cards."
- TILA 1968 → Regulation Z → Fair Credit Billing Act 1974 - applies to credit cards. It sets (a) a hard $50 liability cap, no tiers; (b) a legal right to dispute goods/services with the merchant via a "billing error" (12 CFR §1026.13); (c) a holder-in-due-course defense - if the merchant breaches the contract, the cardholder can refuse to pay the bank, for amounts ≥$50 within the same state or within 100 miles.
- EFTA 1978 → Regulation E - applies to debit cards. It sets a liability tier of $50 (reported within 2 business days) / $500 (reported 2–60 days from the statement) / unlimited (after 60 days). Important: Reg E does not define a merchant dispute as an "error" - only a pure EFT (a wrong amount transferred, a wrong account, or goods charged but never received are not Reg E errors).
This asymmetry isn't a legislative oversight - it's deliberate. The logic: a credit card is a temporary loan from the bank (the bank bears the money risk); a debit card is a direct withdrawal (the customer bears the money risk). When credit fraud happens, it's the bank's loss - they have an incentive to investigate thoroughly and recover. When debit fraud happens, the money has already left the customer's account - the bank only investigates when forced to, and Reg E's tiered liability is designed to pressure users into checking their statements regularly.
2.2 - Visa Zero Liability - an extra layer, but with gaps
On top of the legal framework sits the voluntary Visa Zero Liability Policy - applying to both credit and debit, pushing most unauthorized cases down to $0. Mastercard has an equivalent policy. Regardless of national law, these two schemes create a shared layer of protection. But there are three points users easily get wrong:
- Applies only to unauthorized transactions - not to merchant disputes. Goods not delivered, damaged goods, an uncancelled subscription - none of this falls under Zero Liability. It has to go through the chargeback process, whose scope is voluntary, not a hard legal right.
- Doesn't apply to commercial cards or anonymous prepaid cards. Business cards and internal prepaid cards typically sit outside Zero Liability.
- Can be revoked if "negligence" is inferred. The bank can declare the customer "negligent" - especially when an OTP was entered - and withdraw Zero Liability protection. This is the biggest gray zone in SG and VN.
2.3 - Singapore and Vietnam: the law doesn't draw a clear line, but daily life does
Neither Singapore nor Vietnam splits its legal framework by card type the way the US does. Singapore: the ABS guideline uses a single "card transaction disputes" category - no credit/debit split. Vietnam: Circular 18/2024, Article 19, applies uniformly to "bank cards" - covering debit, credit, and prepaid cards alike. On paper, both card types get the same right to file, the same 60-day deadline, the same 30-business-day processing window.
But the economic reality differs. SingSaver puts it bluntly: "transaction disputes might be easier to manage in credit cards as compared to debit cards... fraudulent charges in debit card transactions will deduct money straight from your account. Debit card users should be aware that protections might not be as robust as those for credit cards." The reason isn't in the scheme rules or the law - it's in the cash flow:
- When credit fraud happens: the bank has not yet demanded payment from you (the statement cycle can run up to 30 days). You have time to dispute before facing payment pressure. If you don't pay the disputed portion, there's no immediate financial consequence for you personally.
- When debit fraud happens: the money is already gone from your account. Auto-debits for rent, electricity, or an incoming paycheck deposit can fail due to insufficient balance. You need the bank to issue provisional credit as soon as possible - and Circular 18/2024 doesn't mandate immediate provisional credit (only compensation after the investigation concludes).
Most Vietnamese users consider an ATM/debit card "safe because you can see the money in the account" and a credit card "risky because you don't see real money." That's everyday-life logic. Dispute logic runs the opposite way: a credit card gives you more legal rights and has a smaller cash-flow impact when it's compromised. The US structure formalized this back in 1974; Vietnam's structure hasn't - but the economic consequences still play out under the same rules. When fraud hits a debit card, the money has already flowed out - you wait for the bank's investigation while short on cash to live on. When fraud hits a credit card, you wait for the investigation while still spending your salary normally.
2.4 - A practical recommendation: credit for online, debit only for familiar POS + ATM
A lesson found across every US financial-safety guide - and increasingly agreed on by the VN/SG fintech community - boils down to one simple rule:
- Online purchases, travel abroad, long-running subscriptions, high-value goods → credit card. Stronger legal rights (FCBA billing error), smaller cash-flow impact if fraud occurs, and if there's a dispute, the bank investigates while its own money is on the line - meaning the bank has a real incentive to close the case.
- POS at merchants you know well, ATM withdrawals at your own bank → debit card. Low fees, no accumulating balance, no interest if paid late. Fraud risk is lower in a familiar environment.
- Set a low debit limit; set a high credit limit. If one card is compromised, the maximum loss shrinks. You can hold two debit cards: one for salary (low limit), one for spending (top up as needed).
- For online payments: use a virtual / one-time card if available (Privacy.com in the US; Timo, Cake, TPBank Evo in VN offer virtual cards). If it's compromised, you just lock it - no impact on your main card.
This recommendation doesn't depend on national law - it holds true in the US, SG, VN, Indonesia, Thailand. The cash-flow structure is universal; what differs between countries is only the strength of the legal framework behind you once things have already gone wrong.
III. Which Cases Are Eligible For Dispute - What Most Users Don't Know
Network rules allow chargebacks across the four groups above. Applied to daily life, eight specific situations account for nearly all real-world disputes. Note: the "merchant dispute" situations (non-delivery, defective goods, cancel a subscription) are a hard legal right only for US credit cards via the FCBA - for a debit card, or a card issued in SG/VN, this is a voluntary right under scheme rules. The bank can refuse:
A CNP (online) transaction you didn't make
Card-not-present fraud accounts for the majority of fraud disputes. The issuer opens a chargeback, issues provisional credit, and investigates. If the transaction didn't use 3DS/OTP, liability usually falls to the merchant (chip liability shift).
Card lost/stolen, with a transaction afterward
The physical card was lost/stolen; a transaction occurred before or after it was reported. Liability shift follows chip/EMV rules: if the merchant fails to read the chip and falls back to a magstripe swipe, the merchant is liable.
Charged twice (duplicate)
The same transaction recorded twice on the statement. A POS error, a gateway error, a staff processing error. This is the easiest dispute to win - the merchant has almost no evidence to fight it with.
Wrong amount charged
An auto-added tip, a wrong currency conversion (a DCC trap), an 18% tip billed as 80%, a refund processed as a new charge (a Tinhte case in 2024 - a $5,400 USD refund got double-charged FX, costing roughly VND 8 million). This falls under a partial dispute - chargeback only the difference.
Goods/services never delivered
Ordered online, never arrived by the due date. You need evidence you contacted the merchant and it wasn't resolved. Singapore's ABS specifically requires "documentary proof of agreed delivery timeline" plus "merchant correspondence regarding non-delivery".
Goods not as described / defective / damaged
Wrong color shirt, wrong size, counterfeit goods, used goods sold as new. You have to try the merchant first - the bank requires evidence you contacted the seller and weren't refunded. Harder to win than fraud because it's subjective.
Cancelled subscription/service still being charged
Gym, streaming, SaaS. Cancelled, but charges keep coming. Evidence: cancellation confirmation plus a statement showing a charge after the cancel date. Some MC reason codes allow up to 540 days - because it's recurring by nature.
An installment payment plan (IPP) when the merchant goes bankrupt
A deposit for a course, a trip, a gym membership paid in installments; the merchant closes down. Some SG banks allow cancelling the remaining installments; but per the ABS guideline, "cardholders remain liable for instalments unless merchant refunds the bank".
Note what cannot be disputed (under standard network rules): a transaction you later decide "wasn't worth the money" after receiving exactly what was described; a tip with no receipt; gambling losses; a penalty fee already written into the terms. And most importantly: a transaction successfully authenticated with OTP/3DS - this is the gray zone, and also where national law splits into four different directions.
IV. The Legal Frameworks - Three Ways Of Treating The Cardholder
Same Visa/Mastercard network, same rulebook, but each country's law adds its own layer - deciding when you get your money back, who has to prove what, and what happens if the bank refuses. This is the part that separates an American from a Vietnamese cardholder.
Reg Z/FCBA (credit) + Reg E (debit)
ABS Guideline + FIDReC
SBV Circular 18/2024 (1 July 2024)
4.1 - The US: two different laws for two card types - and that's a feature, not a bug
The US has the most complete card-payment protection framework - not because Americans are smarter, but because the law drew a sharp line between credit and debit as far back as 1968 (TILA) and 1978 (EFTA). The two card types fall under two different statutes, two different sets of regulations, two different liability caps - all detailed in Part II. To summarize here:
- Credit card · Reg Z + FCBA: a maximum liability of $50 for any unauthorized transaction, with no timing tier. The issuer must acknowledge the dispute within 30 days and finish investigating within two billing cycles or 90 days. There's a right to dispute goods/services with the merchant (billing error plus holder-in-due-course defense).
- Debit card · Reg E: a tiered liability of $0/$50/$500/unlimited depending on when it's reported. The bank must issue provisional credit if the investigation runs >10 business days. Reg E does not cover merchant disputes - only pure EFT (electronic fund transfer) issues. A merchant dispute on debit only goes through Visa/MC's voluntary chargeback process.
- On top of that, Visa/Mastercard's voluntary "zero liability policy" pushes most unauthorized cases down to $0 - as long as the user "used reasonable care".
This is a structural difference from every East Asian country: the US has a statutory floor that a bank isn't allowed to override in its T&Cs. Americans may not love the $50 cap, but they always have that $50 cap - even if the bank wants to pressure them into voluntarily accepting more liability. The VN/SG framework has no such floor.
4.2 - Singapore: no statute, but there is FIDReC
Singapore has no statute equivalent to Reg E / Reg Z for card disputes. The dispute process sits entirely within bank policy - overseen by MAS through the ABS guideline. The practical framework:
- File a dispute resolution form within 14 days of the card statement date (at most banks).
- Bank processing takes 4 weeks for simple cases, 12 weeks for complex ones.
- DBS/OCBC/UOB give provisional credit within 5 business days; investigations can run up to 60 days.
- OCBC: only 7 days from receiving the SMS alert about a strange transaction - far stricter than the 14-day statement window.
When the bank refuses, the user can escalate to FIDReC (Financial Industry Disputes Resolution Centre) - an intermediary body backed by MAS. Mediation is free; adjudication (a formal ruling) has a nominal fee of S$50. The claim ceiling is S$150,000 (since 1 July 2024, up from S$100k). It must be filed within 6 months of the bank's "final reply".
This structure has two important properties. First, there is no statutory floor for zero liability - a bank is free to write into its T&Cs that "an OTP-authenticated transaction = customer liability". Second, FIDReC is not a court - an adjudication decision binds the bank if the customer accepts it, but there's no power to compel the bank to fix a systemic pattern. Singaporeans compensate for this with an unusually fast process and a MAS that's very strict about internal reporting - not with strong statute.
4.3 - Vietnam: Circular 18/2024 - a new regulation, but OTP remains a gray zone
Vietnam belongs to the regulatory group - no statute on the level of Reg E / Reg Z, but Circular 18/2024/TT-NHNN (effective 1 July 2024, replacing Circular 19/2016) sets out fairly detailed rules. One point worth flagging immediately: Circular 18/2024 does not clearly distinguish between credit cards and debit cards in the claims/complaints section - Article 19 applies uniformly. The real-world consequence still differs because of the cash-flow structure (debit money leaves instantly) - discussed in Parts II and VI.
Article 19 sets a clear timeline:
- The cardholder gets a minimum of 60 days from the transaction date to file a claim/complaint.
- Processing within ≤30 business days for cards on an SBV-issued domestic BIN; for an international BIN (Visa/MC), it's set by contract but must be reasonable.
- After receiving a suspected-fraud report, the bank must lock the card and process it within 5 business days (domestic BIN) or 10 days (international BIN).
- Compensation within ≤5 business days after notifying the outcome, provided it's "not the cardholder's fault" and not force majeure.
- If the deadline passes without determining fault, there's 15 business days to negotiate; failing that, it's "resolved under the law" - meaning a civil lawsuit.
- The bank must offer at least 2 complaint channels: a 24/7 recorded hotline plus a branch; a paper form plus an electronic form. From 1 January 2025, it must also offer online complaint-status lookup.
Anyone reading this far might think "not much worse than Singapore." The paperwork structure is actually good. The problem sits in the last three words of Article 19: "not the cardholder's fault". This is the gray zone that Vietnamese courts, in major 2023–2024 cases, have repeatedly interpreted in the bank's favor - the subject of Part V.
Reg E and the FCBA in the US are hard law - a bank can be sued in court for violating them, and has been, repeatedly, and lost (CFPB enforcement, class actions). In SG and VN, dispute rules are administrative regulations or guidelines: violating them triggers MAS/SBV sanctions, but an individual consumer rarely gets to sue directly. The consequence: in the US, the bank pays first and investigates after; in VN/SG, the bank investigates first and only then decides whether to pay. Same process, opposite logic about who carries the burden of proof.
V. Singapore In Practice - The OTP Gray Zone, With FIDReC As The Last Shield
Singapore has the second-best theory after the US. Real life tells a different story - not a bad one, but one that pulls users into a very wide gray zone around OTPs.
DBS, S$10,150 lost over 7 transactions - customer says she never received the OTP
A Singaporean woman lost S$10,150 across 7 consecutive transactions to a foreign money-transfer service. DBS insisted every transaction was OTP-authenticated; the customer countered that she had never received a single OTP SMS. The bank's investigation dragged on with no immediate temporary credit. The technical question at the heart of this case: SS7 vulnerability - the ability to hijack SMS through the telecom network. The bank had no way to verify, at the user's end, whether the message was actually received.
Source: Mothership.SG, 6/2021
UOB - froze the fraud victim's account, demanded the victim pay
A UOB customer spotted a strange transaction on their credit card and immediately reported it to the bank. Instead of investigating, UOB froze the account and demanded the customer pay the disputed transaction - because an OTP had been used in it. The community reacted strongly on All Singapore Stuff and TOC, calling the "fraud protection terrible".
Source: TOC 2/2023 · All Singapore Stuff
These two cases, along with a string of threads on HardwareZone and r/singaporefi, paint the same pattern: whenever merchant evidence shows "an OTP was used," Singaporean banks default to pushing liability onto the customer. The bank's logic: an OTP is a second authentication factor (2FA); if it was used, either the customer did it themselves, or the customer was socially engineered - either way, not the bank's fault. This is written explicitly into the card contract's T&Cs.
This is exactly where FIDReC becomes important. When DBS/UOB refuses a refund, the user files with FIDReC; a case manager will mediate - meaning they don't rule right or wrong but push both sides toward a compromise. In many cases, the bank agrees to refund 50–80% to avoid adjudication (fearing it would set a precedent). If no agreement is reached, the customer pays S$50 to escalate to adjudication, where an adjudicator rules based on "facts and merits". Adjudication binds the bank - but not the customer: the customer can reject the outcome and go to civil court instead (very rare).
FIDReC has no power to compel a bank. But MAS tracks each bank's case volume at FIDReC very closely, and adjudication outcomes are published. Banks know: losing at FIDReC repeatedly is a bad signal when MAS reviews their license. Combined with a S$150k protection ceiling that covers most consumer disputes, this system has replaced hard regulation with reputational pressure in a high-density market - a very Singaporean approach: replace the law with an incentive structure.
VI. Vietnam In Practice - When The Bank Says "The OTP Was Entered, No Grounds For A Claim"
Vietnam has Circular 18/2024, with its 30-day, 60-day, 5-day-compensation framework - on paper, not bad at all. But there's another truth that anyone who has ever had to dispute a card transaction in Vietnam knows: whenever a transaction shows successful OTP/3DS authentication, the bank's default answer is "no grounds for a claim". This isn't the fault of any one bank; it's how Circular 18/2024 gets interpreted whenever the "cardholder's fault" clause runs into an authentication log.
"Strange transactions" on Vietcombank Visa cards - many customers charged by unrecognized foreign sites
In early 2020, a wave of Vietcombank customers reported being charged for Visa transactions on foreign websites they had never visited. One specific customer: a Vietcombank Visa debit card was charged across four transactions totaling roughly VND 22 million, which the cardholder insisted she never made. Vietcombank investigated and found multiple fraudulent transactions on the same foreign payment site - classic CNP fraud (card-not-present, no 3DS).
This case sits in the plausible zone for a dispute - since the international transaction had no 3DS, scheme rules shift liability to the acquirer/merchant. But most of the coverage never reported the final outcome - after the initial disclosure, banks usually resolve these quietly case by case, without publishing success-vs-denial rates. Individual users have no aggregate data to know the actual odds.
Source: cafef.vn 1/2020 · VietnamNet - bank warnings on card info theft
Refund-instead-of-cancel: $5,400 USD comes back as ~VND 127 million, a ~VND 8 million loss
A Vietnamese user paid $5,400 USD with an international credit card while in Vietnam. The merchant entered the wrong amount, and instead of cancelling the transaction (no FX involved), processed a refund (FX applied twice). Result: the cardholder was charged FX both on the way out and the way back - the refund returned only about VND 127 million against an original transaction that should have been roughly VND 135 million. A loss of about VND 8 million from the refund-vs-cancel trap.
This is a plausible dispute under Visa code 12.6 (wrong amount) or a form of processing error; banks usually support it because the merchant's error is clear. But many people don't know this right exists and simply accept the loss.
Source: Tinhte 2024
Vietnam Law Magazine sums up the general trend: "in most cases, banks blame the customer's carelessness, while claiming their payment systems are secure because they've invested in advanced security technology." This pattern isn't limited to card disputes - it applies to nearly every dispute between a bank and a customer where an authentication trail exists.
This is a logic very familiar across East Asia: the OTP was entered = the cardholder's will = not the bank's fault. This logic makes sense in a case where a user voluntarily shares an OTP with a friend; it becomes absurd in a case of sophisticated social engineering (fake bank-support agents, fake delivery notices, fake government officials). But the law doesn't distinguish motive - only fact: where the OTP was, who entered it, on which device. Circular 18/2024 doesn't clearly define "cardholder's fault" in this context, leaving room for case-by-case interpretation that defaults toward whichever side holds the documentation - which is the bank.
A 2023 IMF report on consumer financial protection in emerging markets found: in countries where consumer-protection law is framed as soft regulation rather than hard statute, the consumer fraud-refund rate tends to run 30–50% lower than in countries with a statutory framework. The reason isn't that courts are hostile to consumers - it's that the burden of proof isn't clearly allocated by law. When a court has to divide the burden of proof itself, it defaults to placing it on whoever is making the accusation - the consumer. Compare: in the US, Reg E states plainly that "the issuer must demonstrate that the transfer was authorized" - the burden runs the other way, the bank must prove the customer did authorize it, not the other way around.
A rhetorical question: if you were someone whose phone was taken over by malware, how would you prove that the OTP wasn't entered by you?
6.1 - What's actually plausible: foreign transactions, non-delivery, duplicates
The picture isn't entirely bleak. Within the same Circular 18/2024 framework, some dispute types are genuinely plausible and usually win:
- CNP fraud with no 3DS (an international transaction where the merchant didn't require an OTP) - Visa/MC scheme rules shift liability to the acquirer. Vietnamese banks open the chargeback and almost certainly win, since the merchant has no evidence to fight it with.
- Duplicate / wrong amount - a refund-instead-of-cancel resulting in double FX charges (the Tinhte 2024 case: a $5,400 USD refund cost about VND 8 million in two-way FX). Banks usually support this because the merchant's error is clear.
- Non-delivery / goods not as described with clear evidence - chats, photos, emails - banks still open a chargeback under VCR/Mastercom.
- An uncancelled subscription - Netflix, Spotify, global software - Vietnamese banks open a chargeback if there's cancellation evidence.
What's not plausible: a domestic transaction with an OTP already used, phone-based fraud, or any case where the bank can point to a successful authentication record. The system defaults to one answer: "the OTP was entered, no grounds for a claim."
6.2 - A structural shift worth watching: passkeys, biometrics, in-app authentication
Regulators have seen the problem. Since 1 July 2024, the SBV has required biometric authentication for transactions above VND 10 million/transaction or VND 20 million/day. This is a shift from OTP-via-SMS to device-bound 2FA - much harder for social engineering, since the attacker doesn't have physical access to the real device. The legal significance may matter even more than the technical one: if a transaction lacks biometric verification, the bank will find it harder to argue "customer's fault" as before; if it has biometric verification, that path to a dispute is almost entirely closed off.
An open question: as biometrics become standard, will the definition of "cardholder's fault" narrow along with it? The answer will shape Vietnamese financial consumers' rights over the next five years - and it doesn't sit in scheme rules, but in how Vietnamese courts interpret Article 19 of Circular 18/2024.
VII. A Six-Step Playbook - When You've Just Spotted A Strange Transaction
Compiled from ABS Singapore, the SBV, and the US CFPB - six steps that apply across all three regions, ordered by priority:
-
Report to the issuer within 24 hours - through every channel available
Call the 24/7 hotline (the number on the back of the card), send a message via the app, note the reference number. US: within 2 days = $50 cap. SG: within 7 days (OCBC) or 14 days (most banks). VN: ≥60 days is the legal minimum, but sooner is always better - the bank can verify the timestamp more easily while the event is fresh. Request that the card be locked immediately.
-
Request temporary credit and a reference number in writing
US: Reg E mandates provisional credit within 10 business days. SG: 5 days (DBS). VN: Circular 18/2024 doesn't mandate provisional credit - you must specifically request it and get it documented. Get the ticket/reference number via email - not over the phone. Reference that number in every subsequent call.
-
File the official dispute form (paper or digital) within the window
Each bank has its own form. SG: within 14 days of the statement. VN: VCB Digibank online; Techcombank/ACB via app + branch. The more specific the form is about the reason code, the better: state clearly "unauthorized CNP", "duplicate charge", "non-delivery of service ABC ordered on XYZ" - this helps the issuer file it under the correct VCR/Mastercom category.
-
Document everything - chats, emails, photos, tracking, screenshots
The issuer needs evidence to open a chargeback. The default question: "have you contacted the merchant yet?" You need evidence you tried the merchant first. For fraud: the SMS alert, IP/location if available, transaction history before/after. For non-delivery: a tracking number, a photo showing "not received," a record of the merchant not responding.
-
When the bank refuses - escalate to the right place for your country
US: file a CFPB complaint (consumerfinance.gov/complaint) - the bank must respond within 15 days. SG: FIDReC - mediate $0, adjudicate S$50, ceiling S$150k, within 6 months of the bank's "final reply". VN: the SBV has supervisory authority; the Competition and Consumer Protection Authority (Ministry of Industry and Trade) handles B2C matters; civil court is the last resort - expensive and slow.
-
Understand the real limits - OTP-authenticated transactions are very hard to win in VN/SG
This is the part rarely said out loud. If a transaction was successfully authenticated by OTP/biometric, banks in VN/SG default to saying "no fault on our end," and courts usually agree. Filing a VCR Fraud (10.x) chargeback in these cases has a <20% chance of success. Focus on the two genuinely plausible avenues instead: (a) a merchant-side issue (non-delivery/defective), (b) a processing error (duplicate/wrong amount). Avoid betting on "proving malware was involved" - the burden of proof is heavy and the outcome uncertain.
Visa says roughly 3 out of every 4 chargebacks issuing banks handle are cases of "friendly fraud" - the customer genuinely received the goods/service but disputed the charge anyway to get the money back. The consequence: merchants raise prices to compensate; banks scrutinize genuine cases more; a repeat-offending cardholder can get blacklisted by merchants or have their card revoked by the bank. In the same pool, one fake dispute makes life harder for ten real ones. This is why banks interview fairly thoroughly - on top of scheme rules requiring evidence of "best efforts to resolve with merchant".
VIII. Four Closing Lessons
The card mechanism is identical everywhere; the law behind it and the card type in your wallet decide your rights
Visa Claims Resolution and Mastercard Mastercom are technical rules between banks - identical in Singapore, the US, or Vietnam. The difference sits in two layers: national law sets the minimum obligation on the issuing bank, and card type (credit or debit) decides which legal layer you fall under. When judging the safety of a transaction, don't just look at the Visa logo - ask: is this card credit or debit, and what dispute law does the issuing country apply?
Burden of proof is everything
US: the bank must prove the customer authorized it. Vietnam and Singapore: in practice, the customer must prove they didn't - the burden reverses because of soft law plus OTP. Result: same scam, same network, but an American usually gets the money back while a Vietnamese usually doesn't. Before choosing a card for a large transaction, ask: "if this is lost, who has to prove what?"
An OTP isn't a shield - it's a double-edged lock
An OTP protects you from a thief who doesn't have your phone. It doesn't protect you from a thief who convinces you to hand the OTP over. Worse: in the card contract's terms and in a court's thinking, an entered OTP is treated as almost synonymous with "the customer consented." When in doubt, never enter an OTP for anyone who calls you - even someone claiming to be police, customs, your bank, or your company's boss.
Know your rights before you need to use them
Most cardholders in VN don't know Circular 18/2024 exists; most in SG don't know FIDReC takes cases up to S$150k for free; most debit users in the US don't know Reg E gives them a $0/$50/$500/unlimited tier depending on report timing. Rights don't enforce themselves. When talking to a bank, citing the specific legal provision (Article 19 of Circular 18/2024; 12 CFR §1005.6 Reg E; 12 CFR §1026.13 Reg Z) changes the tone of the call very quickly - because the person on the other end now knows exactly which legal framework you're operating in.
Appendix - A quick checklist before you call the bank hotline
Have ready: the card number + last 4 digits, the transaction date, the amount, the merchant name on the statement (the raw descriptor, not the brand name - e.g. "PADDLE.NET* SUPERCHARGED" instead of "Notion"), a reference number if you've called before, screenshot/email evidence.
Questions to ask the bank right away: "Which reason code will this be filed under?" (10.4 fraud / 12.5 duplicate / 13.1 non-delivery...). "Is there temporary credit, and within how many days?" "Is the dispute form paper or digital, and what's the deadline?" "After the bank concludes, what's the escalation channel?"
Don't: cancel the card right away (it destroys the audit trail; just lock it instead); agree to anything with the bank over the phone without it being documented; wait for the statement to arrive before acting (the shortest window is 7 days at OCBC - you'd miss it before the statement even arrives).
Appendix - Why doesn't MAS have hard law like Reg E?
Singapore organizes consumer protection on a regulator-led, soft-law-first principle. MAS replaces hard statute with (a) an ABS guideline that member banks are required to follow, (b) FIDReC as a dispute intermediary, (c) the Banking Act plus the Payment Services Act, which set a broad licensing framework letting MAS penalize a violating bank. The underlying philosophy: Singapore's financial market is dominated by around 5 major banks - few enough for the regulator to grip tightly, professional enough to largely self-enforce. The US has thousands of community banks - it has to use hard statute to protect users when it can't watch every single bank.
The consequence: SG works well when banks are voluntarily good, but has fewer hard legal tools when a bank pushes back. SG users can end up either very satisfied (most small cases resolve fast) or quite powerless (the OTP gray-zone cases) - depending entirely on how cooperative the issuing bank chooses to be.
Appendix - VN: when does going to court actually make sense?
After the SBV/Consumer Protection Authority fails to resolve a case, going to court is the last resort. In practice: a case only becomes worthwhile above roughly VND 500 million, given court fees, lawyers, and 1–3 years of time. A typical card dispute's loss (a few million to a few tens of millions VND) is almost never worth suing over - which is exactly why a specialized mediator structure like FIDReC would be a far more efficient way for customers to get their money back than an ordinary court.
The odds of winning are higher in cases where: (a) the bank failed to follow the process in Circular 18/2024 (didn't lock the card within 5 days, didn't respond within 30 days, didn't provide evidence), (b) the transaction was not validly authenticated (e.g. an OTP bypass), (c) the merchant issued a chargeback but the bank didn't act on it. Conversely, an "OTP was entered" case has a very difficult precedent to overcome.
A trend worth watching: with mandatory biometric authentication since 7/2024, if fraud occurs without biometric verification, the definition of "cardholder's fault" will have to narrow. This could shift precedent over 2026–2028.
03 Discussion
Leave a note
A considered space for questions, counterpoints, and useful additions. Civil, on-topic, signed.
Reader notes
...Loading notes...