What card-payment records should investigators request?¶
A card statement entry is only the starting point for a card-payment enquiry.
Avoid this assumption: One request to the card issuer will produce every relevant record.
From the issuer, consider requesting the cardholder relationship, card status, card or token identifier, authorisation request and response, transaction reference, authentication method, fraud alerts, device-wallet provisioning, declines, reversals, refunds and disputes.
From the merchant, request order records, account details, billing and delivery information, receipts, communications, staff records and CCTV where relevant.
From the processor or acquiring side, request merchant ID, terminal ID, gateway records, entry mode, card-present indicator, authorisation code, settlement information and linked processor references.
For online payments, obtain IP addresses, device or browser data, checkout sessions and account-login records.
For mobile-wallet activity, seek token and provisioning records.
For card-present activity, preserve terminal and location information and obtain CCTV quickly where retention may be short.
Specify the transaction amount, currency, date, time, merchant descriptor, masked card details and every known reference.
Ask providers to explain unfamiliar fields and identify the stage represented by each timestamp.
Do not request records without a clear investigative purpose. Separate questions about movement, merchant activity, authentication and personal attribution.
Where several organisations hold parts of the chain, obtain records from each relevant holder. Preserve original exports and field definitions where possible so that records can be reconciled accurately.
A declined, reversed or refunded payment may still require the original authorisation and processing records.
Operational takeaway¶
Request issuer, merchant, processor and acquiring records according to the question being investigated rather than relying on the statement entry alone.