How Visa Compelling Evidence 3.0 works for Shopify orders


TL;DR
CE 3.0 turned representment into a matching exercise: show two earlier orders from the same customer whose data elements line up with the disputed one.
Most representment is persuasion. You gather delivery records and support emails and hope a reviewer reads them the way you do.
Visa's Compelling Evidence 3.0 rule works differently. It turns one specific dispute type into a matching exercise with defined inputs, and either your data satisfies the criteria or it does not.
What CE 3.0 changes about a 10.4 dispute
Visa's Compelling Evidence 3.0 merchant readiness document is dated March 2023, and it is still the only public merchant-facing PDF Visa has published on the rule. It describes CE 3.0 as an update to dispute condition 10.4, fraud in the card-absent environment, effective April 15, 2023. That is the code you get when a cardholder says they did not authorise an ecommerce purchase.
Checked July 22, 2026, that PDF shows its age. A Visa Business News bulletin (AI15461, July 24, 2025) rolled out automatic CE 3.0 qualification through Visa Secure and Visa Data Only globally, effective October 17, 2025, adding a second path alongside the manual one below. Trade reporting also has Visa attaching a fee to successful qualifications from April 17, 2026, though no Visa document we found publishes the amount. Confirm both with your acquirer; neither is in the March 2023 PDF.
The mechanism itself is still a historical footprint. Visa's document says that when merchants furnish data establishing that footprint and meet the CE 3.0 criteria, the rule "provides a remedy on behalf of the merchant and liability will shift back to Issuers and ultimately the responsible party."
In practice that means you are no longer arguing that this particular order looks legitimate. You are demonstrating that this customer has an established relationship with your store, using data elements Visa has specified in advance.
Visa also allows the same required information to be delivered before the dispute is created, in real time within Visa Resolve Online, or afterwards during the pre-arbitration response through your acquirer.
The criteria, as Visa states them
Visa's merchant readiness document sets out what qualifies. The merchant shares two previous transactions meeting criteria including:
- The transactions must be at least 120 days old but no older than 365 days, calculated from the dispute date.
- The transaction must have no active fraud report.
- The transaction must have no active fraud dispute. Visa notes that fraud reported under codes C and D is not classed as a fraud dispute.
- At least two of the core data elements (User ID, IP Address, Shipping Address, Device ID or Fingerprint) match between the prior transactions and the disputed transaction, and one of the two must be either the IP address or the Device ID or Fingerprint.
- The transactions must be from the same merchant.
Visa adds that the 120 calendar day floor does not apply where the other undisputed transactions were original credit transactions.
Two operational notes from the same document deserve more attention than they get. Visa applies merchant matching logic to identify two transactions mapping to the same merchant, and calls merchant identifiers, meaning your descriptors, critical to that matching. Visa also says each transaction must have a unique ARN.
Stripe's current documentation, checked July 22, 2026, confirms this test itself has not moved since March 2023. What changed is qualification mechanics, covered above.
The other networks don't have this rule
Search for compelling evidence 3.0 without the word Visa, and the real question is whether Mastercard, Amex, or Discover run something similar. They do not, not under this name. CE 3.0 is scoped to Visa's own reason code 10.4; the other networks run separate dispute frameworks with no equivalent named rule.
That does not make prior-transaction history worthless elsewhere. A Mastercard fraud dispute under reason code 4837 still accepts records of prior undisputed purchases as supporting evidence, the same signal CE 3.0 formalizes, just without a named threshold forcing a reviewer's hand.
Where a Shopify store actually holds these signals
Three of Visa's four core elements are already in your Shopify data. One usually is not, and that is the part nobody writes about.
| Visa core element | Where a Shopify store holds it | Reliability for matching |
|---|---|---|
| Shipping address | On every order | Present, but weakest; cannot be one of your two alone |
| IP address | Recorded against the order | Present, but mobile IPs shift; treat a match as a bonus |
| User ID | Only if the customer has an account | Zero on guest-checkout stores |
| Device ID or fingerprint | From the processor or a fraud tool, not the admin | Often the deciding element; check retention covers 120-365 days |
Visa requires two elements to match, and one of the two must be the IP address or the Device ID/fingerprint.
Shipping address. On every order, and the easiest element to match. It is also the weakest on its own, since Visa requires one of your two matches to be IP or device.
IP address. Shopify records the browser IP against the order, and Shopify's documentation lists customer IP among the data it collects automatically for a Shopify Payments chargeback response. Customers on mobile networks change IPs constantly, so treat a match here as a bonus rather than a plan.
User ID. This exists only if the customer has an account. A store running mostly guest checkout has effectively zero User ID matches, which is a real and rarely mentioned cost of not pushing customer accounts.
Device ID or fingerprint. Shopify does not hand you a device fingerprint in the admin. It comes from your payment processor or a fraud tool sitting in front of checkout. Since Visa requires one of your two matches to be IP or device, and IP is unreliable, device fingerprinting is frequently what decides whether a dispute qualifies at all. Find out today whether your processor generates one and whether it is retained long enough to cover a 120 to 365 day lookback.
Your processor submits this, not you
CE 3.0 evidence does not go in as a PDF. It goes in as structured fields, through your acquirer or payment service provider, which is why merchant experience of it varies so much by processor.
Stripe's documentation, checked July 22, 2026, is the clearest illustration. Stripe exposes an enhanced_eligibility status that tells you whether a dispute qualifies, and its element list is broader than Visa's original four, split into two tiers:
| Tier | Elements | Rule to qualify |
|---|---|---|
| Main | Customer purchase IP, device fingerprint or device ID | Two main elements alone are enough |
| Secondary | Shipping address, email address, customer account ID | One main plus one secondary also qualifies |
Two secondary elements alone do not qualify. Stripe also requires product descriptions for the disputed charge and each prior transaction.
Note that Stripe describes its window as roughly 120 to 364 days before the disputed transaction itself, while Visa's original document calculates the window from the dispute date. That gap is exactly the kind of detail worth confirming with your own processor rather than inferring.
The practical question for a Shopify merchant is short: does my processor support CE 3.0 submission, and does it tell me when a dispute qualifies? If the answer is no, the rule exists but you cannot reach it.
Where a dispute does qualify, the work is finding the two prior orders and lining up the elements before the deadline. Reclaim does that against the store's own order history. It is free to run: no install fee, no success fee, and the merchant keeps 100% of what is recovered.
The honest limits
CE 3.0 covers one dispute condition. It does nothing for product not received, subscription cancelled, or product unacceptable claims, which for many stores are the larger problem. For those, the evidence work is the ordinary kind, mapped to the specific allegation in the reason code.
The 120 day floor structurally excludes your newest customers. A dispute from someone whose first order was three months ago cannot qualify, no matter how obviously legitimate the purchase was.
The criteria are also unforgiving in a way persuasive evidence is not. Two matching elements where one is IP or device is a threshold, not a spectrum. Almost qualifying is the same as not qualifying.
Here is the point that matters most for anyone whose acquirer is watching them.
Note
A dispute counts toward your Visa monitoring ratio whether CE 3.0 wins it or not. The remedy shifts liability for the money. It does not remove the dispute from the count.That is why win rate and ratio move independently.
What to check first
Pull your 10.4 disputes from the last quarter. For each one, ask whether that customer had two orders between roughly four months and a year before the dispute date, and whether any element beyond shipping address matched.
If most of them fail on the device and IP requirement rather than on order history, your gap is not evidence. It is that nobody is retaining a device signal, and that is a conversation with your processor, not a new tool.
Frequently asked questions
What is Visa Compelling Evidence 3.0?
A Visa rule, effective April 15, 2023, that turns fraud dispute condition 10.4 into a matching exercise. You furnish two of the customer's prior undisputed transactions and show that defined data elements line up with the disputed order. If the criteria are met, liability shifts back to the issuer. Since October 17, 2025, Visa also auto-qualifies some transactions through Visa Secure and Visa Data Only, on top of this manual path.
What are the CE 3.0 criteria?
Two prior transactions from the same merchant, each roughly 120 to 365 days before the dispute, with no active fraud report or dispute, and at least two core data elements matching the disputed order (User ID, IP, shipping address, or device ID/fingerprint), one of which must be IP or device. Confirm the current criteria with Visa and your acquirer before building a workflow.
Does compelling evidence 3.0 apply outside Visa?
No, not under this name. CE 3.0 is a Visa mechanism scoped to Visa's own reason code 10.4. Mastercard, Amex, and Discover run separate dispute frameworks with no equivalent named rule, though prior-transaction history still helps as supporting evidence in their fraud reviews. Within Visa, it also does nothing for not-received, subscription-cancelled, or not-as-described claims.
Does winning with CE 3.0 lower my dispute ratio?
No. CE 3.0 shifts liability for the money back to the issuer, but a dispute counts toward your Visa monitoring ratio whether or not it is won. Only resolving a dispute before it is filed keeps it off the count.