May 2, 2026

Visa/Mastercard Card Dispute Mechanics

Payments · Consumer Protection · Vietnam vs Singapore 2026-05-02
Visa · Mastercard · Reg Z · Reg E · SBV Circular 18/2024 · FIDReC

Visa/Mastercard Dispute Mechanics: Why Credit Differs From Debit

Same swipe, but in the US a credit card is protected by Reg Z + the Fair Credit Billing Act - a $50 liability cap, plus a legal right to dispute goods/services with the merchant; a debit card only has Reg E, with a tiered liability of $0/$50/$500/unlimited depending on when you report it. Singapore has no dedicated statute - only an ABS guideline plus FIDReC mediating for free up to S$150,000. Vietnam has Circular 18/2024/TT-NHNN, which gives a 60-day window to file and 30 business days to resolve - but OTP-authenticated transactions are a gray zone where courts tend to side with the bank. The Visa/Mastercard card mechanism is identical across all three; the law layered on top - and which card type you use - is where the cardholder's rights are actually decided.

USA · Reg Z + Reg E
$50
credit card cap at all times (FCBA); debit card tiers by report timing (Reg E)
SG · ABS + FIDReC
14 days
to file a dispute from the statement date; FIDReC mediates for free up to S$150k
VN · SBV Circular 18/2024
60 days
to file from the transaction date; 30-day resolution for domestic BINs, negotiated for international ones; effective 1 July 2024

This piece is split into seven parts. Part I covers what the dispute mechanism is and who pays whom. Part II is the difference between credit cards and debit cards - same Visa/Mastercard logo, but different legal rights, a fact rarely stated plainly in Vietnam. Part III lists the cases eligible for dispute under network rules. Part IV compares the legal frameworks across three countries - the US, Singapore, Vietnam - same payment network, different outcomes. Parts V and VI cover the reality on the ground in SG and VN, checking the license against actual life. Part VII is a six-step playbook for anyone who has just spotted a strange transaction.

Scope and terminology

DisputeRefund. A refund is the seller agreeing to give the money back (fast, simple, through the merchant). A chargeback is the buyer asking the issuing bank to reverse the transaction under network rules (Visa Claims Resolution / Mastercom) - forcing the seller to prove otherwise. This article uses "dispute" in the broad sense (including non-fraud complaints like non-delivery), and "chargeback" in the narrow sense (a reversal via scheme rules).

Scope: Visa and Mastercard only, in the consumer (B2C) space. American Express (a closed-loop network), JCB, UnionPay, and domestic NAPAS are not covered. The article focuses on three regions: the US (the benchmark legal framework), Singapore (a soft-law model with a strong regulator), and Vietnam (the new SBV framework under Circular 18/2024). Legal figures are current as of April 2026; specific bank policies can change - re-read your card's terms before acting.

I. The Dispute Mechanism - Four Parties, One Money Loop, Three Layers Of Rules

Every card transaction has four parties in the payment chain (the four-party model): the cardholder, the issuing bank (issuer), the card network (Visa/Mastercard), the bank that settles with the merchant (acquirer), and the merchant. Money flows one way - from the cardholder through the issuer, through the scheme, through the acquirer, to the merchant. When a dispute arises, the money flow reverses along that exact same path. That is a chargeback.

1. Cardholder The person holding the card. Spots a strange transaction on the app/statement, calls the issuer.
2. Issuer The bank that issued the card. Opens a chargeback under a reason code, issues temporary credit to the customer.
3. Network Visa/Mastercard. Defines reason codes, time limits, and evidence rules (VCR / Mastercom).
4. Acquirer The bank that collects on the merchant's behalf. Forwards the chargeback down to the merchant along with an evidence request.
5. Merchant The seller. Submits evidence (representment) within 20–45 days, or accepts the loss.

The card network's role here is not "final arbiter" - the network sets the rules (Visa Dispute Management Guidelines 2024; Mastercard Chargeback Guide May 2025) and settles disputes between two banks. The cardholder never speaks directly with Visa or Mastercard. Everything goes through your issuer. This is the first point where the mechanism becomes asymmetric: the bargaining power sits with the issuing bank, not the cardholder.

1.1 - Visa Claims Resolution (VCR): four reason-code groups

Since April 2018, Visa has standardized all reason codes into four categories numbered 10/11/12/13:

  • 10 · Fraud - a fraudulent transaction not carried out by the cardholder. Examples: a skimmed card, card-not-present (CNP) fraud, a counterfeit card. Runs through the Allocation workflow: Visa automatically assigns liability to whichever party is at fault (usually the acquirer/merchant if there's no 3DS/EMV).
  • 11 · Authorization - a transaction that wasn't validly authorized (e.g., an expired card, a blocked card, or a limit exceeded but processed anyway).
  • 12 · Processing Errors - technical errors. Includes duplicates (the same transaction recorded twice), wrong amount, wrong currency, an unprocessed refund.
  • 13 · Consumer Disputes - civil disputes. Goods not delivered, goods differing from description, damaged goods, service not rendered, a subscription cancellation that didn't take effect. Runs through the Collaboration workflow: Visa does not auto-assign liability - both sides get a chance to respond before it's formalized.

Visa's standard time limit: the cardholder has 120 days from the transaction date (or the expected delivery date) to file a chargeback. The merchant has 30 days for representment (submitting counter-evidence) after being notified (ChargePay 2024).

1.2 - Mastercard MasterCom: four categories with longer time limits

Mastercard splits similarly into four groups: Authorization, Cardholder Disputes, Fraud, Point-of-Interaction Errors (Visa calls this differently: "Processing Errors"). The main difference: the window is usually 90–120 days, with some reason codes running as long as 540 days (long-running transactions such as subscriptions and installment plans). Merchants get 45 days for representment (Chargebacks911 Mastercard 2026).

Category Visa code Mastercard code Cardholder filing limit Merchant response
Fraud (CNP/3DS/EMV)10.x4837, 4870, 4871120 days30 / 45 days
Authorization11.x4808120 days30 / 45 days
Processing Error12.x4834, 4842, 4846120 days30 / 45 days
Consumer / Cardholder Dispute13.x4853, 4854, 4855120 days (some up to 540)30 / 45 days

1.3 - Pre-arbitration and Arbitration: the final round

If the two sides still disagree after representment, the dispute moves to pre-arbitration - the issuer can refile with additional evidence. The final step is formal arbitration at Visa/Mastercard, costing $500–900 and potentially adding another 10–45 days (Chargebacks911). The arbitration decision is final and binds the two banks - it is not a court ruling, and the consumer is never a party to arbitration. The issuing bank decides whether to escalate to arbitration on the customer's behalf. If they don't, the customer has nowhere left to go within the scheme system.

A truth rarely stated plainly

The dispute mechanism is designed to settle disputes between banks, not between a consumer and their own bank. When your issuer refuses to open a chargeback, closes the case early, or fails to file representment when the merchant objects, the scheme has no mechanism for you to appeal directly. Your rights stop at your issuer's door. Everything then depends on two things: which type of card you use (credit or debit - Part II) and the national law binding what your issuer must do for you (Part IV).

II. Credit Card vs Debit Card - Same Visa Logo, Different Protections

Most Vietnamese cardholders carrying a Visa/Mastercard don't know a structural fact: a credit card and a debit card - even under the same Visa logo, issued by the same bank - do not carry the same dispute rights. This gap isn't because Vietnamese banks apply the rules poorly; it originates in the US's own legal design, spreads through scheme rules, and gets printed into the T&Cs of every bank in the world. Three core differences:

Credit Card

The bank's money is moving

US law that appliesTILA → Reg Z (12 CFR 1026), FCBA
Unauthorized liability cap$50 at all times
Goods/services dispute with merchantLegal right (billing error)
Holder-in-due-course defenseYes (≥$50, within 100 miles)
When money is lostIt's the bank's money, not your account
Provisional creditMandatory, immediate (Reg Z)
Impact on daily lifeSalary, rent NOT frozen
VS
Debit Card

Your money has already evaporated

US law that appliesEFTA → Reg E (12 CFR 1005)
Unauthorized liability cap$50 / $500 / unlimited (by timing)
Goods/services dispute with merchantNo legal right - scheme only
Holder-in-due-course defenseNone
When money is lostYour account empties instantly
Provisional creditMandatory if investigation takes >10 business days
Impact on daily lifeBills, salary, rent can trigger overdraft

2.1 - Why the US splits credit and debit into two different laws

The US is the only country that draws this sharp a line, via two separate statutes. Consumer Compliance Outlook (Federal Reserve, 2016) explains: "Consumer protections for credit and debit cards derive from different federal laws - the Truth in Lending Act (TILA) for credit cards and the Electronic Fund Transfer Act (EFTA) for debit cards."

  • TILA 1968 → Regulation Z → Fair Credit Billing Act 1974 - applies to credit cards. It sets (a) a hard $50 liability cap, no tiers; (b) a legal right to dispute goods/services with the merchant via a "billing error" (12 CFR §1026.13); (c) a holder-in-due-course defense - if the merchant breaches the contract, the cardholder can refuse to pay the bank, for amounts ≥$50 within the same state or within 100 miles.
  • EFTA 1978 → Regulation E - applies to debit cards. It sets a liability tier of $50 (reported within 2 business days) / $500 (reported 2–60 days from the statement) / unlimited (after 60 days). Important: Reg E does not define a merchant dispute as an "error" - only a pure EFT (a wrong amount transferred, a wrong account, or goods charged but never received are not Reg E errors).

This asymmetry isn't a legislative oversight - it's deliberate. The logic: a credit card is a temporary loan from the bank (the bank bears the money risk); a debit card is a direct withdrawal (the customer bears the money risk). When credit fraud happens, it's the bank's loss - they have an incentive to investigate thoroughly and recover. When debit fraud happens, the money has already left the customer's account - the bank only investigates when forced to, and Reg E's tiered liability is designed to pressure users into checking their statements regularly.

2.2 - Visa Zero Liability - an extra layer, but with gaps

On top of the legal framework sits the voluntary Visa Zero Liability Policy - applying to both credit and debit, pushing most unauthorized cases down to $0. Mastercard has an equivalent policy. Regardless of national law, these two schemes create a shared layer of protection. But there are three points users easily get wrong:

  • Applies only to unauthorized transactions - not to merchant disputes. Goods not delivered, damaged goods, an uncancelled subscription - none of this falls under Zero Liability. It has to go through the chargeback process, whose scope is voluntary, not a hard legal right.
  • Doesn't apply to commercial cards or anonymous prepaid cards. Business cards and internal prepaid cards typically sit outside Zero Liability.
  • Can be revoked if "negligence" is inferred. The bank can declare the customer "negligent" - especially when an OTP was entered - and withdraw Zero Liability protection. This is the biggest gray zone in SG and VN.

2.3 - Singapore and Vietnam: the law doesn't draw a clear line, but daily life does

Neither Singapore nor Vietnam splits its legal framework by card type the way the US does. Singapore: the ABS guideline uses a single "card transaction disputes" category - no credit/debit split. Vietnam: Circular 18/2024, Article 19, applies uniformly to "bank cards" - covering debit, credit, and prepaid cards alike. On paper, both card types get the same right to file, the same 60-day deadline, the same 30-business-day processing window.

But the economic reality differs. SingSaver puts it bluntly: "transaction disputes might be easier to manage in credit cards as compared to debit cards... fraudulent charges in debit card transactions will deduct money straight from your account. Debit card users should be aware that protections might not be as robust as those for credit cards." The reason isn't in the scheme rules or the law - it's in the cash flow:

  • When credit fraud happens: the bank has not yet demanded payment from you (the statement cycle can run up to 30 days). You have time to dispute before facing payment pressure. If you don't pay the disputed portion, there's no immediate financial consequence for you personally.
  • When debit fraud happens: the money is already gone from your account. Auto-debits for rent, electricity, or an incoming paycheck deposit can fail due to insufficient balance. You need the bank to issue provisional credit as soon as possible - and Circular 18/2024 doesn't mandate immediate provisional credit (only compensation after the investigation concludes).
A point almost never stated plainly in Vietnam

Most Vietnamese users consider an ATM/debit card "safe because you can see the money in the account" and a credit card "risky because you don't see real money." That's everyday-life logic. Dispute logic runs the opposite way: a credit card gives you more legal rights and has a smaller cash-flow impact when it's compromised. The US structure formalized this back in 1974; Vietnam's structure hasn't - but the economic consequences still play out under the same rules. When fraud hits a debit card, the money has already flowed out - you wait for the bank's investigation while short on cash to live on. When fraud hits a credit card, you wait for the investigation while still spending your salary normally.

2.4 - A practical recommendation: credit for online, debit only for familiar POS + ATM

A lesson found across every US financial-safety guide - and increasingly agreed on by the VN/SG fintech community - boils down to one simple rule:

  • Online purchases, travel abroad, long-running subscriptions, high-value goodscredit card. Stronger legal rights (FCBA billing error), smaller cash-flow impact if fraud occurs, and if there's a dispute, the bank investigates while its own money is on the line - meaning the bank has a real incentive to close the case.
  • POS at merchants you know well, ATM withdrawals at your own bankdebit card. Low fees, no accumulating balance, no interest if paid late. Fraud risk is lower in a familiar environment.
  • Set a low debit limit; set a high credit limit. If one card is compromised, the maximum loss shrinks. You can hold two debit cards: one for salary (low limit), one for spending (top up as needed).
  • For online payments: use a virtual / one-time card if available (Privacy.com in the US; Timo, Cake, TPBank Evo in VN offer virtual cards). If it's compromised, you just lock it - no impact on your main card.

This recommendation doesn't depend on national law - it holds true in the US, SG, VN, Indonesia, Thailand. The cash-flow structure is universal; what differs between countries is only the strength of the legal framework behind you once things have already gone wrong.

III. Which Cases Are Eligible For Dispute - What Most Users Don't Know

Network rules allow chargebacks across the four groups above. Applied to daily life, eight specific situations account for nearly all real-world disputes. Note: the "merchant dispute" situations (non-delivery, defective goods, cancel a subscription) are a hard legal right only for US credit cards via the FCBA - for a debit card, or a card issued in SG/VN, this is a voluntary right under scheme rules. The bank can refuse:

Fraud · Visa 10.4 / MC 4837
A CNP (online) transaction you didn't make

Card-not-present fraud accounts for the majority of fraud disputes. The issuer opens a chargeback, issues provisional credit, and investigates. If the transaction didn't use 3DS/OTP, liability usually falls to the merchant (chip liability shift).

Time limit: 120 days · Evidence: the card is still in your possession, IP/geography doesn't match
Fraud · Visa 10.5 / MC 4870–4871
Card lost/stolen, with a transaction afterward

The physical card was lost/stolen; a transaction occurred before or after it was reported. Liability shift follows chip/EMV rules: if the merchant fails to read the chip and falls back to a magstripe swipe, the merchant is liable.

Time limit: 120 days · Evidence: a police report (recommended), the time the loss was reported
Processing Error · Visa 12.5 / MC 4834
Charged twice (duplicate)

The same transaction recorded twice on the statement. A POS error, a gateway error, a staff processing error. This is the easiest dispute to win - the merchant has almost no evidence to fight it with.

Time limit: 120 days · Evidence: two line items for the same amount
Processing Error · Visa 12.6 / MC 4842
Wrong amount charged

An auto-added tip, a wrong currency conversion (a DCC trap), an 18% tip billed as 80%, a refund processed as a new charge (a Tinhte case in 2024 - a $5,400 USD refund got double-charged FX, costing roughly VND 8 million). This falls under a partial dispute - chargeback only the difference.

Time limit: 120 days · Evidence: receipt vs. statement
Consumer Dispute · Visa 13.1 / MC 4855
Goods/services never delivered

Ordered online, never arrived by the due date. You need evidence you contacted the merchant and it wasn't resolved. Singapore's ABS specifically requires "documentary proof of agreed delivery timeline" plus "merchant correspondence regarding non-delivery".

Time limit: 120 days from the expected delivery date, not the transaction date
Consumer Dispute · Visa 13.3 / MC 4853
Goods not as described / defective / damaged

Wrong color shirt, wrong size, counterfeit goods, used goods sold as new. You have to try the merchant first - the bank requires evidence you contacted the seller and weren't refunded. Harder to win than fraud because it's subjective.

Time limit: 120 days · Evidence: photos, chat logs, emails
Consumer Dispute · Visa 13.7 / MC 4853
Cancelled subscription/service still being charged

Gym, streaming, SaaS. Cancelled, but charges keep coming. Evidence: cancellation confirmation plus a statement showing a charge after the cancel date. Some MC reason codes allow up to 540 days - because it's recurring by nature.

Time limit: up to 540 days (Mastercard) for recurring charges · Evidence: cancellation email
Consumer Dispute · MC 4850
An installment payment plan (IPP) when the merchant goes bankrupt

A deposit for a course, a trip, a gym membership paid in installments; the merchant closes down. Some SG banks allow cancelling the remaining installments; but per the ABS guideline, "cardholders remain liable for instalments unless merchant refunds the bank".

Time limit: per installment · Evidence: bankruptcy notice, IPP contract

Note what cannot be disputed (under standard network rules): a transaction you later decide "wasn't worth the money" after receiving exactly what was described; a tip with no receipt; gambling losses; a penalty fee already written into the terms. And most importantly: a transaction successfully authenticated with OTP/3DS - this is the gray zone, and also where national law splits into four different directions.

Same Visa/Mastercard network, same rulebook, but each country's law adds its own layer - deciding when you get your money back, who has to prove what, and what happens if the bank refuses. This is the part that separates an American from a Vietnamese cardholder.

USA · Statute

Reg Z/FCBA (credit) + Reg E (debit)

Credit liability$50 cap at all times
Debit reported ≤2 daysMax $50
Debit reported 2–60 daysMax $500
Debit reported >60 daysUnlimited
Merchant disputeCredit yes (FCBA), debit no
Bank investigation10 business days
Visa/MC zero liabilityAdditional layer
SG · Soft law

ABS Guideline + FIDReC

RightBank policy + MAS oversight
File a dispute form14 days from statement
Bank processing4 weeks simple, 12 weeks complex
Provisional credit5 business days (DBS)
OTP-authenticatedBank can refuse
EscalateFIDReC, ≤S$150k
FIDReC feeMediate $0; adjudicate S$50
VN · Regulatory

SBV Circular 18/2024 (1 July 2024)

BasisSBV regulation, not a statute
File a claim from≥60 days from the transaction
Domestic BIN processing≤30 business days
International BIN processingPer contract agreement
Card lock after report5 days (domestic) / 10 days (international)
Compensation after ruling5 business days
OTP-authenticatedCourts usually say "customer's fault"

4.1 - The US: two different laws for two card types - and that's a feature, not a bug

The US has the most complete card-payment protection framework - not because Americans are smarter, but because the law drew a sharp line between credit and debit as far back as 1968 (TILA) and 1978 (EFTA). The two card types fall under two different statutes, two different sets of regulations, two different liability caps - all detailed in Part II. To summarize here:

  • Credit card · Reg Z + FCBA: a maximum liability of $50 for any unauthorized transaction, with no timing tier. The issuer must acknowledge the dispute within 30 days and finish investigating within two billing cycles or 90 days. There's a right to dispute goods/services with the merchant (billing error plus holder-in-due-course defense).
  • Debit card · Reg E: a tiered liability of $0/$50/$500/unlimited depending on when it's reported. The bank must issue provisional credit if the investigation runs >10 business days. Reg E does not cover merchant disputes - only pure EFT (electronic fund transfer) issues. A merchant dispute on debit only goes through Visa/MC's voluntary chargeback process.
  • On top of that, Visa/Mastercard's voluntary "zero liability policy" pushes most unauthorized cases down to $0 - as long as the user "used reasonable care".

This is a structural difference from every East Asian country: the US has a statutory floor that a bank isn't allowed to override in its T&Cs. Americans may not love the $50 cap, but they always have that $50 cap - even if the bank wants to pressure them into voluntarily accepting more liability. The VN/SG framework has no such floor.

4.2 - Singapore: no statute, but there is FIDReC

Singapore has no statute equivalent to Reg E / Reg Z for card disputes. The dispute process sits entirely within bank policy - overseen by MAS through the ABS guideline. The practical framework:

  • File a dispute resolution form within 14 days of the card statement date (at most banks).
  • Bank processing takes 4 weeks for simple cases, 12 weeks for complex ones.
  • DBS/OCBC/UOB give provisional credit within 5 business days; investigations can run up to 60 days.
  • OCBC: only 7 days from receiving the SMS alert about a strange transaction - far stricter than the 14-day statement window.

When the bank refuses, the user can escalate to FIDReC (Financial Industry Disputes Resolution Centre) - an intermediary body backed by MAS. Mediation is free; adjudication (a formal ruling) has a nominal fee of S$50. The claim ceiling is S$150,000 (since 1 July 2024, up from S$100k). It must be filed within 6 months of the bank's "final reply".

This structure has two important properties. First, there is no statutory floor for zero liability - a bank is free to write into its T&Cs that "an OTP-authenticated transaction = customer liability". Second, FIDReC is not a court - an adjudication decision binds the bank if the customer accepts it, but there's no power to compel the bank to fix a systemic pattern. Singaporeans compensate for this with an unusually fast process and a MAS that's very strict about internal reporting - not with strong statute.

4.3 - Vietnam: Circular 18/2024 - a new regulation, but OTP remains a gray zone

Vietnam belongs to the regulatory group - no statute on the level of Reg E / Reg Z, but Circular 18/2024/TT-NHNN (effective 1 July 2024, replacing Circular 19/2016) sets out fairly detailed rules. One point worth flagging immediately: Circular 18/2024 does not clearly distinguish between credit cards and debit cards in the claims/complaints section - Article 19 applies uniformly. The real-world consequence still differs because of the cash-flow structure (debit money leaves instantly) - discussed in Parts II and VI.

Article 19 sets a clear timeline:

  • The cardholder gets a minimum of 60 days from the transaction date to file a claim/complaint.
  • Processing within ≤30 business days for cards on an SBV-issued domestic BIN; for an international BIN (Visa/MC), it's set by contract but must be reasonable.
  • After receiving a suspected-fraud report, the bank must lock the card and process it within 5 business days (domestic BIN) or 10 days (international BIN).
  • Compensation within ≤5 business days after notifying the outcome, provided it's "not the cardholder's fault" and not force majeure.
  • If the deadline passes without determining fault, there's 15 business days to negotiate; failing that, it's "resolved under the law" - meaning a civil lawsuit.
  • The bank must offer at least 2 complaint channels: a 24/7 recorded hotline plus a branch; a paper form plus an electronic form. From 1 January 2025, it must also offer online complaint-status lookup.

Anyone reading this far might think "not much worse than Singapore." The paperwork structure is actually good. The problem sits in the last three words of Article 19: "not the cardholder's fault". This is the gray zone that Vietnamese courts, in major 2023–2024 cases, have repeatedly interpreted in the bank's favor - the subject of Part V.

An easy point to miss - the US uses "hard law," VN and SG use "soft law"

Reg E and the FCBA in the US are hard law - a bank can be sued in court for violating them, and has been, repeatedly, and lost (CFPB enforcement, class actions). In SG and VN, dispute rules are administrative regulations or guidelines: violating them triggers MAS/SBV sanctions, but an individual consumer rarely gets to sue directly. The consequence: in the US, the bank pays first and investigates after; in VN/SG, the bank investigates first and only then decides whether to pay. Same process, opposite logic about who carries the burden of proof.

V. Singapore In Practice - The OTP Gray Zone, With FIDReC As The Last Shield

Singapore has the second-best theory after the US. Real life tells a different story - not a bad one, but one that pulls users into a very wide gray zone around OTPs.

Case · Mothership.SG · 6/2021

DBS, S$10,150 lost over 7 transactions - customer says she never received the OTP

A Singaporean woman lost S$10,150 across 7 consecutive transactions to a foreign money-transfer service. DBS insisted every transaction was OTP-authenticated; the customer countered that she had never received a single OTP SMS. The bank's investigation dragged on with no immediate temporary credit. The technical question at the heart of this case: SS7 vulnerability - the ability to hijack SMS through the telecom network. The bank had no way to verify, at the user's end, whether the message was actually received.

Source: Mothership.SG, 6/2021

Case · The Online Citizen · 2/2023

UOB - froze the fraud victim's account, demanded the victim pay

A UOB customer spotted a strange transaction on their credit card and immediately reported it to the bank. Instead of investigating, UOB froze the account and demanded the customer pay the disputed transaction - because an OTP had been used in it. The community reacted strongly on All Singapore Stuff and TOC, calling the "fraud protection terrible".

Source: TOC 2/2023 · All Singapore Stuff

These two cases, along with a string of threads on HardwareZone and r/singaporefi, paint the same pattern: whenever merchant evidence shows "an OTP was used," Singaporean banks default to pushing liability onto the customer. The bank's logic: an OTP is a second authentication factor (2FA); if it was used, either the customer did it themselves, or the customer was socially engineered - either way, not the bank's fault. This is written explicitly into the card contract's T&Cs.

This is exactly where FIDReC becomes important. When DBS/UOB refuses a refund, the user files with FIDReC; a case manager will mediate - meaning they don't rule right or wrong but push both sides toward a compromise. In many cases, the bank agrees to refund 50–80% to avoid adjudication (fearing it would set a precedent). If no agreement is reached, the customer pays S$50 to escalate to adjudication, where an adjudicator rules based on "facts and merits". Adjudication binds the bank - but not the customer: the customer can reject the outcome and go to civil court instead (very rare).

Why FIDReC works

FIDReC has no power to compel a bank. But MAS tracks each bank's case volume at FIDReC very closely, and adjudication outcomes are published. Banks know: losing at FIDReC repeatedly is a bad signal when MAS reviews their license. Combined with a S$150k protection ceiling that covers most consumer disputes, this system has replaced hard regulation with reputational pressure in a high-density market - a very Singaporean approach: replace the law with an incentive structure.

VI. Vietnam In Practice - When The Bank Says "The OTP Was Entered, No Grounds For A Claim"

Vietnam has Circular 18/2024, with its 30-day, 60-day, 5-day-compensation framework - on paper, not bad at all. But there's another truth that anyone who has ever had to dispute a card transaction in Vietnam knows: whenever a transaction shows successful OTP/3DS authentication, the bank's default answer is "no grounds for a claim". This isn't the fault of any one bank; it's how Circular 18/2024 gets interpreted whenever the "cardholder's fault" clause runs into an authentication log.

A typical pattern · cafef.vn 1/2020

"Strange transactions" on Vietcombank Visa cards - many customers charged by unrecognized foreign sites

In early 2020, a wave of Vietcombank customers reported being charged for Visa transactions on foreign websites they had never visited. One specific customer: a Vietcombank Visa debit card was charged across four transactions totaling roughly VND 22 million, which the cardholder insisted she never made. Vietcombank investigated and found multiple fraudulent transactions on the same foreign payment site - classic CNP fraud (card-not-present, no 3DS).

This case sits in the plausible zone for a dispute - since the international transaction had no 3DS, scheme rules shift liability to the acquirer/merchant. But most of the coverage never reported the final outcome - after the initial disclosure, banks usually resolve these quietly case by case, without publishing success-vs-denial rates. Individual users have no aggregate data to know the actual odds.

Source: cafef.vn 1/2020 · VietnamNet - bank warnings on card info theft

Pattern · tinhte.vn 2024 · A two-way currency-conversion trap

Refund-instead-of-cancel: $5,400 USD comes back as ~VND 127 million, a ~VND 8 million loss

A Vietnamese user paid $5,400 USD with an international credit card while in Vietnam. The merchant entered the wrong amount, and instead of cancelling the transaction (no FX involved), processed a refund (FX applied twice). Result: the cardholder was charged FX both on the way out and the way back - the refund returned only about VND 127 million against an original transaction that should have been roughly VND 135 million. A loss of about VND 8 million from the refund-vs-cancel trap.

This is a plausible dispute under Visa code 12.6 (wrong amount) or a form of processing error; banks usually support it because the merchant's error is clear. But many people don't know this right exists and simply accept the loss.

Source: Tinhte 2024

Vietnam Law Magazine sums up the general trend: "in most cases, banks blame the customer's carelessness, while claiming their payment systems are secure because they've invested in advanced security technology." This pattern isn't limited to card disputes - it applies to nearly every dispute between a bank and a customer where an authentication trail exists.

This is a logic very familiar across East Asia: the OTP was entered = the cardholder's will = not the bank's fault. This logic makes sense in a case where a user voluntarily shares an OTP with a friend; it becomes absurd in a case of sophisticated social engineering (fake bank-support agents, fake delivery notices, fake government officials). But the law doesn't distinguish motive - only fact: where the OTP was, who entered it, on which device. Circular 18/2024 doesn't clearly define "cardholder's fault" in this context, leaving room for case-by-case interpretation that defaults toward whichever side holds the documentation - which is the bank.

A comparison that matters

A 2023 IMF report on consumer financial protection in emerging markets found: in countries where consumer-protection law is framed as soft regulation rather than hard statute, the consumer fraud-refund rate tends to run 30–50% lower than in countries with a statutory framework. The reason isn't that courts are hostile to consumers - it's that the burden of proof isn't clearly allocated by law. When a court has to divide the burden of proof itself, it defaults to placing it on whoever is making the accusation - the consumer. Compare: in the US, Reg E states plainly that "the issuer must demonstrate that the transfer was authorized" - the burden runs the other way, the bank must prove the customer did authorize it, not the other way around.

A rhetorical question: if you were someone whose phone was taken over by malware, how would you prove that the OTP wasn't entered by you?

6.1 - What's actually plausible: foreign transactions, non-delivery, duplicates

The picture isn't entirely bleak. Within the same Circular 18/2024 framework, some dispute types are genuinely plausible and usually win:

  • CNP fraud with no 3DS (an international transaction where the merchant didn't require an OTP) - Visa/MC scheme rules shift liability to the acquirer. Vietnamese banks open the chargeback and almost certainly win, since the merchant has no evidence to fight it with.
  • Duplicate / wrong amount - a refund-instead-of-cancel resulting in double FX charges (the Tinhte 2024 case: a $5,400 USD refund cost about VND 8 million in two-way FX). Banks usually support this because the merchant's error is clear.
  • Non-delivery / goods not as described with clear evidence - chats, photos, emails - banks still open a chargeback under VCR/Mastercom.
  • An uncancelled subscription - Netflix, Spotify, global software - Vietnamese banks open a chargeback if there's cancellation evidence.

What's not plausible: a domestic transaction with an OTP already used, phone-based fraud, or any case where the bank can point to a successful authentication record. The system defaults to one answer: "the OTP was entered, no grounds for a claim."

6.2 - A structural shift worth watching: passkeys, biometrics, in-app authentication

Regulators have seen the problem. Since 1 July 2024, the SBV has required biometric authentication for transactions above VND 10 million/transaction or VND 20 million/day. This is a shift from OTP-via-SMS to device-bound 2FA - much harder for social engineering, since the attacker doesn't have physical access to the real device. The legal significance may matter even more than the technical one: if a transaction lacks biometric verification, the bank will find it harder to argue "customer's fault" as before; if it has biometric verification, that path to a dispute is almost entirely closed off.

An open question: as biometrics become standard, will the definition of "cardholder's fault" narrow along with it? The answer will shape Vietnamese financial consumers' rights over the next five years - and it doesn't sit in scheme rules, but in how Vietnamese courts interpret Article 19 of Circular 18/2024.

VII. A Six-Step Playbook - When You've Just Spotted A Strange Transaction

Compiled from ABS Singapore, the SBV, and the US CFPB - six steps that apply across all three regions, ordered by priority:

  1. Report to the issuer within 24 hours - through every channel available

    Call the 24/7 hotline (the number on the back of the card), send a message via the app, note the reference number. US: within 2 days = $50 cap. SG: within 7 days (OCBC) or 14 days (most banks). VN: ≥60 days is the legal minimum, but sooner is always better - the bank can verify the timestamp more easily while the event is fresh. Request that the card be locked immediately.

  2. Request temporary credit and a reference number in writing

    US: Reg E mandates provisional credit within 10 business days. SG: 5 days (DBS). VN: Circular 18/2024 doesn't mandate provisional credit - you must specifically request it and get it documented. Get the ticket/reference number via email - not over the phone. Reference that number in every subsequent call.

  3. File the official dispute form (paper or digital) within the window

    Each bank has its own form. SG: within 14 days of the statement. VN: VCB Digibank online; Techcombank/ACB via app + branch. The more specific the form is about the reason code, the better: state clearly "unauthorized CNP", "duplicate charge", "non-delivery of service ABC ordered on XYZ" - this helps the issuer file it under the correct VCR/Mastercom category.

  4. Document everything - chats, emails, photos, tracking, screenshots

    The issuer needs evidence to open a chargeback. The default question: "have you contacted the merchant yet?" You need evidence you tried the merchant first. For fraud: the SMS alert, IP/location if available, transaction history before/after. For non-delivery: a tracking number, a photo showing "not received," a record of the merchant not responding.

  5. When the bank refuses - escalate to the right place for your country

    US: file a CFPB complaint (consumerfinance.gov/complaint) - the bank must respond within 15 days. SG: FIDReC - mediate $0, adjudicate S$50, ceiling S$150k, within 6 months of the bank's "final reply". VN: the SBV has supervisory authority; the Competition and Consumer Protection Authority (Ministry of Industry and Trade) handles B2C matters; civil court is the last resort - expensive and slow.

  6. Understand the real limits - OTP-authenticated transactions are very hard to win in VN/SG

    This is the part rarely said out loud. If a transaction was successfully authenticated by OTP/biometric, banks in VN/SG default to saying "no fault on our end," and courts usually agree. Filing a VCR Fraud (10.x) chargeback in these cases has a <20% chance of success. Focus on the two genuinely plausible avenues instead: (a) a merchant-side issue (non-delivery/defective), (b) a processing error (duplicate/wrong amount). Avoid betting on "proving malware was involved" - the burden of proof is heavy and the outcome uncertain.

Friendly fraud - don't do this

Visa says roughly 3 out of every 4 chargebacks issuing banks handle are cases of "friendly fraud" - the customer genuinely received the goods/service but disputed the charge anyway to get the money back. The consequence: merchants raise prices to compensate; banks scrutinize genuine cases more; a repeat-offending cardholder can get blacklisted by merchants or have their card revoked by the bank. In the same pool, one fake dispute makes life harder for ten real ones. This is why banks interview fairly thoroughly - on top of scheme rules requiring evidence of "best efforts to resolve with merchant".

VIII. Four Closing Lessons

Lesson 1

The card mechanism is identical everywhere; the law behind it and the card type in your wallet decide your rights

Visa Claims Resolution and Mastercard Mastercom are technical rules between banks - identical in Singapore, the US, or Vietnam. The difference sits in two layers: national law sets the minimum obligation on the issuing bank, and card type (credit or debit) decides which legal layer you fall under. When judging the safety of a transaction, don't just look at the Visa logo - ask: is this card credit or debit, and what dispute law does the issuing country apply?

Lesson 2

Burden of proof is everything

US: the bank must prove the customer authorized it. Vietnam and Singapore: in practice, the customer must prove they didn't - the burden reverses because of soft law plus OTP. Result: same scam, same network, but an American usually gets the money back while a Vietnamese usually doesn't. Before choosing a card for a large transaction, ask: "if this is lost, who has to prove what?"

Lesson 3

An OTP isn't a shield - it's a double-edged lock

An OTP protects you from a thief who doesn't have your phone. It doesn't protect you from a thief who convinces you to hand the OTP over. Worse: in the card contract's terms and in a court's thinking, an entered OTP is treated as almost synonymous with "the customer consented." When in doubt, never enter an OTP for anyone who calls you - even someone claiming to be police, customs, your bank, or your company's boss.

Lesson 4

Know your rights before you need to use them

Most cardholders in VN don't know Circular 18/2024 exists; most in SG don't know FIDReC takes cases up to S$150k for free; most debit users in the US don't know Reg E gives them a $0/$50/$500/unlimited tier depending on report timing. Rights don't enforce themselves. When talking to a bank, citing the specific legal provision (Article 19 of Circular 18/2024; 12 CFR §1005.6 Reg E; 12 CFR §1026.13 Reg Z) changes the tone of the call very quickly - because the person on the other end now knows exactly which legal framework you're operating in.

Appendix - A quick checklist before you call the bank hotline

Have ready: the card number + last 4 digits, the transaction date, the amount, the merchant name on the statement (the raw descriptor, not the brand name - e.g. "PADDLE.NET* SUPERCHARGED" instead of "Notion"), a reference number if you've called before, screenshot/email evidence.

Questions to ask the bank right away: "Which reason code will this be filed under?" (10.4 fraud / 12.5 duplicate / 13.1 non-delivery...). "Is there temporary credit, and within how many days?" "Is the dispute form paper or digital, and what's the deadline?" "After the bank concludes, what's the escalation channel?"

Don't: cancel the card right away (it destroys the audit trail; just lock it instead); agree to anything with the bank over the phone without it being documented; wait for the statement to arrive before acting (the shortest window is 7 days at OCBC - you'd miss it before the statement even arrives).

Appendix - Why doesn't MAS have hard law like Reg E?

Singapore organizes consumer protection on a regulator-led, soft-law-first principle. MAS replaces hard statute with (a) an ABS guideline that member banks are required to follow, (b) FIDReC as a dispute intermediary, (c) the Banking Act plus the Payment Services Act, which set a broad licensing framework letting MAS penalize a violating bank. The underlying philosophy: Singapore's financial market is dominated by around 5 major banks - few enough for the regulator to grip tightly, professional enough to largely self-enforce. The US has thousands of community banks - it has to use hard statute to protect users when it can't watch every single bank.

The consequence: SG works well when banks are voluntarily good, but has fewer hard legal tools when a bank pushes back. SG users can end up either very satisfied (most small cases resolve fast) or quite powerless (the OTP gray-zone cases) - depending entirely on how cooperative the issuing bank chooses to be.

Appendix - VN: when does going to court actually make sense?

After the SBV/Consumer Protection Authority fails to resolve a case, going to court is the last resort. In practice: a case only becomes worthwhile above roughly VND 500 million, given court fees, lawyers, and 1–3 years of time. A typical card dispute's loss (a few million to a few tens of millions VND) is almost never worth suing over - which is exactly why a specialized mediator structure like FIDReC would be a far more efficient way for customers to get their money back than an ordinary court.

The odds of winning are higher in cases where: (a) the bank failed to follow the process in Circular 18/2024 (didn't lock the card within 5 days, didn't respond within 30 days, didn't provide evidence), (b) the transaction was not validly authenticated (e.g. an OTP bypass), (c) the merchant issued a chargeback but the bank didn't act on it. Conversely, an "OTP was entered" case has a very difficult precedent to overcome.

A trend worth watching: with mandatory biometric authentication since 7/2024, if fraud occurs without biometric verification, the definition of "cardholder's fault" will have to narrow. This could shift precedent over 2026–2028.

"Every consumer financial-protection mechanism boils down to one simple question: when a loss occurs, who has to prove what? That answer doesn't live in the logo on the card - it lives in the law of the country that issued it." - Synthesized from Reg Z/Reg E, ABS Singapore, SBV Circular 18/2024

Read next

More from the shelf

Jul 8, 2026Open USD Launches: Why Stablecoins Settle Faster Than Traditional BanksJul 19, 2026Vietnam's Fiscal Room, FX Reserves and the Exchange RateMay 25, 2026How To Survive A Debt And Liquidity CrisisMay 18, 2026Extend and Pretend - When Banks Pretend Bad Debt Doesn't Exist

Pass it on

If it found you, share it kindly

XEmail

03 Discussion

Leave a note

A considered space for questions, counterpoints, and useful additions. Civil, on-topic, signed.

Reader notes

...

Loading notes...