Does a card payment prove that the cardholder made it?¶
No. A card payment links activity to a card account or token, not automatically to the named cardholder.
Avoid this assumption: Possession or registration of the card proves personal use.
A family member, employee or associate may use the card with permission. An offender may use stolen card details, a copied card, a compromised account or an existing mobile-wallet token.
Card-not-present payments can occur without the physical card. Recurring transactions may be initiated by the merchant under an earlier authority.
Even card-present transactions need careful interpretation. CCTV, terminal location and authentication method may help, but the record alone may not identify the person.
Successful PIN use shows that the correct PIN was entered. It does not prove who knew or entered it.
Contactless use may require no fresh authentication for an individual low-value transaction.
A mobile-wallet payment may show that a tokenised card was used from a registered device. It does not automatically identify the person holding the device.
To assess attribution, obtain issuer records, card-allocation information, authentication data, device-token details, merchant records, CCTV, receipts and order or delivery information.
Look at what happened before and after the payment. Card freezes, wallet provisioning, password changes, disputed transactions and repeated attempts may be relevant.
Do not accept a denial or an attribution solely because of the cardholder name. Test the explanation against the evidence.
When reporting, state that the transaction was made using the card account, card number or token unless the wider evidence identifies the user.
Operational takeaway¶
Attribute the payment first to the card or token and only to the cardholder where merchant, device, authentication and contextual evidence supports it.