Card Not Present Fraud: Prevention Guide for IIBF Bankers

CYBERCRIME By Ashish Jain · IIBF STORE Editorial · 24 August 2026 · Updated 05 Oct 2026 · 10 min read · 33 views
Card Not Present Fraud: Prevention Guide for IIBF Bankers

Card not present fraud is now one of the most common ways criminals target Indian bank customers, because it needs no stolen plastic — only a card number, an expiry date, a CVV and, increasingly, a compromised one-time password. For candidates studying the IIBF Prevention of Cyber Crime and Fraud Management paper, card not present fraud sits right at the intersection of technology, banking operations and RBI regulation, which is exactly why it turns up so often in case-study questions. This article explains how card not present fraud works, which controls banks rely on to stop it, what RBI expects of banks and customers, and how to spot it quickly in an exam scenario.

💳 What Is Card Not Present Fraud

Card not present (CNP) fraud happens when a transaction is completed using card details — number, expiry date and CVV — without the physical card being swiped, dipped or tapped at a terminal. Typical examples include e-commerce checkouts, phone or mail orders, and recurring billing set up on a stolen card. Because the merchant never sees or physically handles the card, standard chip-and-PIN protection is irrelevant; the fraud lives entirely in the data layer.

This is a deliberate distinction from card-present fraud such as skimming or counterfeit-card cloning, where a criminal needs a physical copy of the card to transact. The IIBF syllabus treats card fraud as one connected topic, and the Electronic Card Frauds chapter is the right place to compare CNP fraud against skimming, cloning and lost-or-stolen-card misuse side by side. Once a candidate can separate "was the card physically present" from "was the transaction authenticated," most exam questions on this topic become straightforward.

🛒 Common Ways Card Not Present Fraud Happens

Fraudsters rarely guess a valid card number and CVV combination by chance; they buy or harvest it first. Large-scale data breaches at merchants or payment aggregators leak card numbers in bulk, which are then sold on dark-web marketplaces. Phishing emails and fake shopping or lottery websites trick cardholders into typing their own card details directly into a criminal's form — a technique closely linked to the broader problem covered in computer insecurity threats in banking.

A second, more automated route is "card testing": bots run thousands of small transactions against a payment gateway using guessed or stolen card numbers to find which ones are still active, before the fraudster moves to a larger purchase. Compromised merchant checkout pages, malware-infected browsers, and unsecured Wi-Fi during online payments round out the common attack surface. Understanding these entry points is covered in more depth in the Cyber Crime Methods chapter, which maps each technique to the stage of a fraud lifecycle it belongs to.

⚠️ Common Mistake: Candidates often assume EMV chip cards eliminate card fraud entirely. Chip-and-PIN stops most card-present cloning, but it does nothing to stop card not present fraud, since the chip is never read in an online or phone transaction.
A customer entering card details for an online payment, the moment card not present fraud targets
A customer entering card details for an online payment, the moment card not present fraud targets

🔐 Authentication Controls Banks Use Against It

Because card not present fraud cannot be stopped at the point of physical card verification, banks push authentication into the transaction data itself. CVV entry confirms the customer is holding the physical card at least once. Address Verification Service (AVS) checks the billing address against bank records. Additional Factor of Authentication (AFA) — typically an OTP sent to the registered mobile number — is mandatory for most domestic online card transactions under RBI's payment security framework.

Card tokenisation, which RBI has pushed banks and merchants to adopt, replaces the actual card number stored on a merchant's server with a unique token, so a data breach at the merchant no longer exposes usable card data. 3D Secure protocols (the OTP or app-based approval screen a cardholder sees before an online payment completes) add a bank-side checkpoint that a stolen card number alone cannot pass. Velocity checks — flagging multiple transactions in quick succession or from unusual locations — catch card-testing bots even when every individual transaction looks valid. These layered controls are exactly what the Computer Fraud Protection chapter groups together as technical countermeasures. RBI's public guidance on these requirements is available on the Reserve Bank of India website under its payment and settlement systems directions.

💡 Exam Tip: If a question describes a fraud where the card was never physically used and an OTP or CVV was the point of compromise, classify it as card not present fraud, not skimming — examiners frequently test this distinction with a case study rather than a direct definition question.
Fraud TypePhysical Card NeededHow the Data Is UsedPrimary Bank Control
Card not present (CNP) fraud❌ NoCard number, expiry, CVV, OTP entered online or by phone3D Secure / AFA + velocity checks
Skimming / card cloning✅ YesMagnetic stripe copied at an ATM or POS deviceEMV chip and PIN
Lost or stolen physical cardYesCard used directly at a merchant terminalInstant card blocking, SMS transaction alerts
Account takeover after number hijackNoNew card or OTP redirected after mobile number compromiseOTP delivery monitoring, device binding
OTP and 3D Secure verification screen used as an authentication control for card transactions
OTP and 3D Secure verification screen used as an authentication control for card transactions

⚖️ RBI Rules, Liability and the Legal Angle

When a card not present fraud does slip through, the customer's financial liability depends heavily on how quickly it is reported. RBI's framework on limiting customer liability in unauthorised electronic transactions sets out reduced or zero liability where the customer reports promptly and the fraud did not result from their own negligence, with liability rising the longer the delay in reporting. The full mechanics of this framework, including the reporting-time bands, are covered separately in customer liability in unauthorised transactions, which is worth reading alongside this article since exam questions often combine both topics.

Once a bank confirms a CNP fraud case, it triggers an internal incident-response process — isolating the compromised channel, blocking further transactions on affected cards, and filing the required regulatory reporting. The structured approach banks are expected to follow is detailed in the Incident Management chapter, and it pairs directly with the legal backing that treats such fraud as a punishable offence under India's cyber law framework. For candidates, the key exam takeaway is that CNP fraud is not just a technology failure — it is also a regulatory and legal event with defined bank obligations.

📌 Remember: Zero customer liability under RBI's framework generally requires that the loss did not arise from the customer's own negligence AND that the transaction was reported within the bank-specified window — both conditions matter, not just the reporting speed.
A bank fraud analyst reviewing flagged card transactions on a monitoring dashboard
A bank fraud analyst reviewing flagged card transactions on a monitoring dashboard

🛡️ A Prevention Checklist for Bank Staff and Customers

Practical prevention works best when the bank and the customer close different gaps. On the customer side: enable SMS and email alerts for every transaction, set a low default limit for online and international CNP transactions through the mobile banking app, and disable international usage entirely if it is never needed. Never enter card details or OTPs on a site reached through an SMS or WhatsApp link rather than typing the merchant's URL directly — a discipline that also protects against the fraud pattern covered in QR code and payment link fraud.

On the bank side: enforce merchant-level due diligence before onboarding e-commerce partners, monitor for card-testing patterns in real time, and keep tokenisation and 3D Secure enabled by default rather than opt-in. Staff handling customer complaints should be trained to recognise CNP fraud symptoms quickly — a sudden series of small transactions, a purchase from an unfamiliar merchant category, or a transaction location inconsistent with the customer's recent activity. For readers also revising Treasury Investment and Risk Management, the same discipline of separating "what changed" from "what stayed the same" in a transaction pattern is a useful parallel to how clean price and dirty price of bonds separates accrued interest from the quoted market price — both require isolating one variable to see the real picture. More articles on this subject are collected on the Prevention of Cyber Crime blog tag.

🧠 Practice MCQs: Card Not Present Fraud

Q1. Which of the following best describes card not present fraud? (a) Card cloned using a skimming device at an ATM (b) Transaction completed using card number, expiry and CVV without the physical card (c) Cash withdrawn using a stolen PIN (d) Counterfeit card manufactured from stolen data

Answer: (b) — CNP fraud is defined by the absence of the physical card at the point of transaction, not by how the data was originally obtained.

Q2. Why does an EMV chip not prevent card not present fraud? (a) Chips are only used for ATM withdrawals (b) The chip is read only in physical card-present transactions (c) Chips do not work for international transactions (d) EMV chips have been discontinued in India

Answer: (b) — Chip-and-PIN protection applies only when the card is physically dipped or tapped at a terminal, which never happens in a CNP transaction.

Q3. What is the purpose of card tokenisation? (a) To speed up transaction processing (b) To replace the stored card number with a merchant-specific token so a breach does not expose usable card data (c) To waive the need for CVV entry (d) To allow unlimited international transactions

Answer: (b) — Tokenisation removes the real card number from merchant systems, so even if a merchant is breached, the stolen token cannot be reused elsewhere.

Q4. Under RBI's customer liability framework, what typically affects the extent of a customer's liability in a card not present fraud? (a) The customer's account balance (b) The type of card issued (c) How promptly the fraud is reported and whether negligence is involved (d) The merchant's location

Answer: (c) — Liability generally reduces where the customer reports promptly and negligence is absent; delay in reporting increases the customer's exposure.

Q5. "Card testing" by fraudsters most closely resembles which pattern? (a) A single large transaction from a known merchant (b) Multiple small transactions run in quick succession to check which stolen card numbers are still active (c) A cash withdrawal using a duplicate card (d) A merchant refund processed twice

Answer: (b) — Card testing uses automated small transactions to validate stolen card data before a larger fraudulent purchase is attempted.

Want chapter-wise mock tests with 100+ MCQs? Start practising free →

Frequently Asked Questions

Is card not present fraud the same as online fraud?

Not exactly. Card not present fraud is a specific category of online (and phone-order) fraud that involves misuse of card details without the physical card. Online fraud is a broader term that also covers non-card channels like net banking credential theft.

Can a customer stop card not present fraud completely by using a strong PIN?

No. A card PIN is not used in CNP transactions at all — the relevant protections are CVV, OTP/AFA, and transaction alerts, not the ATM PIN.

Does disabling international transactions prevent all card not present fraud?

It removes one significant risk channel but not all of it — domestic CNP fraud through phishing, breached merchant data, or compromised OTPs can still occur even with international usage disabled.

Who bears the loss if a bank's OTP system itself is compromised?

Where the fraud results from a deficiency on the bank's side rather than customer negligence, RBI's liability framework generally places the loss on the bank, provided the customer reports the transaction promptly.

Card not present fraud will keep growing as more banking moves online, which is exactly why IIBF weighs it heavily in the Prevention of Cyber Crime and Fraud Management paper. Revise the authentication controls, the liability framework, and the difference between CNP and card-present fraud until you can classify any case study in seconds. Put that understanding to the test with a full chapter-wise mock at iibf.store/tests.

Next step

Practice this topic

Ready to put this into practice?

Take a free mock test, download chapter PDFs, or watch a video class — all included on iibf.store.

Keep reading