Card Not Present Fraud: Prevention Guide for IIBF Bankers
Card not present fraud is now one of the most common ways criminals target Indian bank customers, because it needs no stolen plastic — only a card number, an expiry date, a CVV and, increasingly, a compromised one-time password. For candidates studying the IIBF Prevention of Cyber Crime and Fraud Management paper, card not present fraud sits right at the intersection of technology, banking operations and RBI regulation, which is exactly why it turns up so often in case-study questions. This article explains how card not present fraud works, which controls banks rely on to stop it, what RBI expects of banks and customers, and how to spot it quickly in an exam scenario.
💳 What Is Card Not Present Fraud
Card not present (CNP) fraud happens when a transaction is completed using card details — number, expiry date and CVV — without the physical card being swiped, dipped or tapped at a terminal. Typical examples include e-commerce checkouts, phone or mail orders, and recurring billing set up on a stolen card. Because the merchant never sees or physically handles the card, standard chip-and-PIN protection is irrelevant; the fraud lives entirely in the data layer.
This is a deliberate distinction from card-present fraud such as skimming or counterfeit-card cloning, where a criminal needs a physical copy of the card to transact. The IIBF syllabus treats card fraud as one connected topic, and the Electronic Card Frauds chapter is the right place to compare CNP fraud against skimming, cloning and lost-or-stolen-card misuse side by side. Once a candidate can separate "was the card physically present" from "was the transaction authenticated," most exam questions on this topic become straightforward.
🛒 Common Ways Card Not Present Fraud Happens
Fraudsters rarely guess a valid card number and CVV combination by chance; they buy or harvest it first. Large-scale data breaches at merchants or payment aggregators leak card numbers in bulk, which are then sold on dark-web marketplaces. Phishing emails and fake shopping or lottery websites trick cardholders into typing their own card details directly into a criminal's form — a technique closely linked to the broader problem covered in computer insecurity threats in banking.
A second, more automated route is "card testing": bots run thousands of small transactions against a payment gateway using guessed or stolen card numbers to find which ones are still active, before the fraudster moves to a larger purchase. Compromised merchant checkout pages, malware-infected browsers, and unsecured Wi-Fi during online payments round out the common attack surface. Understanding these entry points is covered in more depth in the Cyber Crime Methods chapter, which maps each technique to the stage of a fraud lifecycle it belongs to.
⚠️ Common Mistake: Candidates often assume EMV chip cards eliminate card fraud entirely. Chip-and-PIN stops most card-present cloning, but it does nothing to stop card not present fraud, since the chip is never read in an online or phone transaction.

🔐 Authentication Controls Banks Use Against It
Because card not present fraud cannot be stopped at the point of physical card verification, banks push authentication into the transaction data itself. CVV entry confirms the customer is holding the physical card at least once. Address Verification Service (AVS) checks the billing address against bank records. Additional Factor of Authentication (AFA) — typically an OTP sent to the registered mobile number — is mandatory for most domestic online card transactions under RBI's payment security framework.
Card tokenisation, which RBI has pushed banks and merchants to adopt, replaces the actual card number stored on a merchant's server with a unique token, so a data breach at the merchant no longer exposes usable card data. 3D Secure protocols (the OTP or app-based approval screen a cardholder sees before an online payment completes) add a bank-side checkpoint that a stolen card number alone cannot pass. Velocity checks — flagging multiple transactions in quick succession or from unusual locations — catch card-testing bots even when every individual transaction looks valid. These layered controls are exactly what the Computer Fraud Protection chapter groups together as technical countermeasures. RBI's public guidance on these requirements is available on the Reserve Bank of India website under its payment and settlement systems directions.
💡 Exam Tip: If a question describes a fraud where the card was never physically used and an OTP or CVV was the point of compromise, classify it as card not present fraud, not skimming — examiners frequently test this distinction with a case study rather than a direct definition question.
| Fraud Type | Physical Card Needed | How the Data Is Used | Primary Bank Control |
|---|---|---|---|
| Card not present (CNP) fraud | ❌ No | Card number, expiry, CVV, OTP entered online or by phone | 3D Secure / AFA + velocity checks |
| Skimming / card cloning | ✅ Yes | Magnetic stripe copied at an ATM or POS device | EMV chip and PIN |
| Lost or stolen physical card | Yes | Card used directly at a merchant terminal | Instant card blocking, SMS transaction alerts |
| Account takeover after number hijack | No | New card or OTP redirected after mobile number compromise | OTP delivery monitoring, device binding |

⚖️ RBI Rules, Liability and the Legal Angle
When a card not present fraud does slip through, the customer's financial liability depends heavily on how quickly it is reported. RBI's framework on limiting customer liability in unauthorised electronic transactions sets out reduced or zero liability where the customer reports promptly and the fraud did not result from their own negligence, with liability rising the longer the delay in reporting. The full mechanics of this framework, including the reporting-time bands, are covered separately in customer liability in unauthorised transactions, which is worth reading alongside this article since exam questions often combine both topics.
Once a bank confirms a CNP fraud case, it triggers an internal incident-response process — isolating the compromised channel, blocking further transactions on affected cards, and filing the required regulatory reporting. The structured approach banks are expected to follow is detailed in the Incident Management chapter, and it pairs directly with the legal backing that treats such fraud as a punishable offence under India's cyber law framework. For candidates, the key exam takeaway is that CNP fraud is not just a technology failure — it is also a regulatory and legal event with defined bank obligations.
📌 Remember: Zero customer liability under RBI's framework generally requires that the loss did not arise from the customer's own negligence AND that the transaction was reported within the bank-specified window — both conditions matter, not just the reporting speed.

🛡️ A Prevention Checklist for Bank Staff and Customers
Practical prevention works best when the bank and the customer close different gaps. On the customer side: enable SMS and email alerts for every transaction, set a low default limit for online and international CNP transactions through the mobile banking app, and disable international usage entirely if it is never needed. Never enter card details or OTPs on a site reached through an SMS or WhatsApp link rather than typing the merchant's URL directly — a discipline that also protects against the fraud pattern covered in QR code and payment link fraud.
On the bank side: enforce merchant-level due diligence before onboarding e-commerce partners, monitor for card-testing patterns in real time, and keep tokenisation and 3D Secure enabled by default rather than opt-in. Staff handling customer complaints should be trained to recognise CNP fraud symptoms quickly — a sudden series of small transactions, a purchase from an unfamiliar merchant category, or a transaction location inconsistent with the customer's recent activity. For readers also revising Treasury Investment and Risk Management, the same discipline of separating "what changed" from "what stayed the same" in a transaction pattern is a useful parallel to how clean price and dirty price of bonds separates accrued interest from the quoted market price — both require isolating one variable to see the real picture. More articles on this subject are collected on the Prevention of Cyber Crime blog tag.
🧠 Practice MCQs: Card Not Present Fraud
Q1. Which of the following best describes card not present fraud? (a) Card cloned using a skimming device at an ATM (b) Transaction completed using card number, expiry and CVV without the physical card (c) Cash withdrawn using a stolen PIN (d) Counterfeit card manufactured from stolen data
Answer: (b) — CNP fraud is defined by the absence of the physical card at the point of transaction, not by how the data was originally obtained.
Q2. Why does an EMV chip not prevent card not present fraud? (a) Chips are only used for ATM withdrawals (b) The chip is read only in physical card-present transactions (c) Chips do not work for international transactions (d) EMV chips have been discontinued in India
Answer: (b) — Chip-and-PIN protection applies only when the card is physically dipped or tapped at a terminal, which never happens in a CNP transaction.
Q3. What is the purpose of card tokenisation? (a) To speed up transaction processing (b) To replace the stored card number with a merchant-specific token so a breach does not expose usable card data (c) To waive the need for CVV entry (d) To allow unlimited international transactions
Answer: (b) — Tokenisation removes the real card number from merchant systems, so even if a merchant is breached, the stolen token cannot be reused elsewhere.
Q4. Under RBI's customer liability framework, what typically affects the extent of a customer's liability in a card not present fraud? (a) The customer's account balance (b) The type of card issued (c) How promptly the fraud is reported and whether negligence is involved (d) The merchant's location
Answer: (c) — Liability generally reduces where the customer reports promptly and negligence is absent; delay in reporting increases the customer's exposure.
Q5. "Card testing" by fraudsters most closely resembles which pattern? (a) A single large transaction from a known merchant (b) Multiple small transactions run in quick succession to check which stolen card numbers are still active (c) A cash withdrawal using a duplicate card (d) A merchant refund processed twice
Answer: (b) — Card testing uses automated small transactions to validate stolen card data before a larger fraudulent purchase is attempted.
Want chapter-wise mock tests with 100+ MCQs? Start practising free →
Frequently Asked Questions
Is card not present fraud the same as online fraud?
Not exactly. Card not present fraud is a specific category of online (and phone-order) fraud that involves misuse of card details without the physical card. Online fraud is a broader term that also covers non-card channels like net banking credential theft.
Can a customer stop card not present fraud completely by using a strong PIN?
No. A card PIN is not used in CNP transactions at all — the relevant protections are CVV, OTP/AFA, and transaction alerts, not the ATM PIN.
Does disabling international transactions prevent all card not present fraud?
It removes one significant risk channel but not all of it — domestic CNP fraud through phishing, breached merchant data, or compromised OTPs can still occur even with international usage disabled.
Who bears the loss if a bank's OTP system itself is compromised?
Where the fraud results from a deficiency on the bank's side rather than customer negligence, RBI's liability framework generally places the loss on the bank, provided the customer reports the transaction promptly.
Card not present fraud will keep growing as more banking moves online, which is exactly why IIBF weighs it heavily in the Prevention of Cyber Crime and Fraud Management paper. Revise the authentication controls, the liability framework, and the difference between CNP and card-present fraud until you can classify any case study in seconds. Put that understanding to the test with a full chapter-wise mock at iibf.store/tests.
Practice this topic
Take a free mock test, download chapter PDFs, or watch a video class — all included on iibf.store.