Paystrax company logo

Risk & fraud management

What is a merchant category code (MCC), and how does it affect risk classification?

An MCC is a four-digit code that classifies what type of business a merchant runs, assigned by the card schemes when an account is set up – covering everything from retail to gambling to financial services. Acquirers use it to gauge the typical chargeback rate, regulatory exposure, and fraud pattern for that category, which shapes underwriting decisions and pricing; sectors like iGaming and forex carry MCCs that call for closer monitoring than standard retail.

How long does risk assessment take when onboarding?

Risk assessment of the business is a crucial process before starting the onboarding. Depending on the business and given information, risk assessment can take from few hours to weeks. The more information provided, the sooner the onboarding process can begin.

What happens if a fraud is detected during the transaction?

If fraudulent activity is detected during the payment transaction, the transaction is stopped and manually reviewed by our team members. After checking the transaction, a chargeback may be issued to return money to the client. If it’s detected that the business is taking part in criminal activity, a report is sent to responsible authorities.

What is payment gateway fraud?

Payment gateway fraud is a way of purchasing goods using another person’s funds or personal details without a card present. In these situations, a chargeback is issued.

What business is considered high risk?

Common high-risk merchants are: trading, gambling, gaming, travel agencies, cryptocurrency, telemarketing, e-cigarettes, computer software and similar.

What is AML (Anti-money laundering)?

Money laundering is illegally obtaining a large amount of money from criminal activities and making it look legal through buying or selling assets, business transactions etc. AML is a process that detects such an activity through money transactions. AML includes different regulatory standards, laws, and policies that prevent financial crime.

Security

What is Strong Customer Authentication (SCA), and how does it affect checkout for UK & EU merchants?

SCA is a regulatory requirement under PSD2 that means most online card payments need two-factor verification – typically something the customer has (their phone or card) plus something they know or are (a PIN, fingerprint, or one-time code) – usually delivered through 3D Secure. For UK & EU merchants, this means checkout needs to support that authentication step by default; PAYSTRAX builds SCA compliance into its payment gateway, so merchants meet the requirement without adding friction for genuine customers.

What is 3D Secure (3DS2), and does PAYSTRAX support it?

3D Secure (3DS2) is an authentication step that verifies a cardholder’s identity during checkout – usually via a one-time code, biometric prompt, or bank app approval – reducing fraud and shifting chargeback liability away from the merchant. PAYSTRAX supports 3DS2 as standard across its payment gateway, helping merchants meet Strong Customer Authentication requirements while keeping the checkout flow smooth for genuine customers.

Contact us if you have more questions

Let our support team help you!

Contact us