In Person and Online Are Two Different Businesses
In Person and Online Are Two Different Businesses
The same customer, the same card, the same $180. Bought in your shop it costs less to accept, is more likely to be approved, and if it turns out to be fraud you probably don't bear the loss. Bought on your website it costs more, is more likely to be declined, and the fraud loss is yours. These aren't variations on one activity — they're two operations with different economics, different failure modes, and different rules. Most merchants running both look at one blended set of numbers, which describes neither, and manage them with one set of settings, which is wrong for both.
What you'll learn
What actually differs
| In person | Remote | |
|---|---|---|
| Card verified by | The chip | Data anyone with the number could supply |
| Acceptance cost | Lower | Meaningfully higher |
| Approval rate | Higher | Lower |
| Fraud rate | Low | Substantially higher |
| Counterfeit fraud loss | Generally the issuer's | Generally yours |
| Dispute defence rests on | The terminal record | Delivery and verification evidence |
| Customer identity | Physically present | Inferred |
Every row traces to one fact: in person, the card proves itself; remotely, it doesn't. Everything else — the pricing, the scrutiny, the liability allocation — is the system's response to that single difference.
Which means a merchant who understands that one fact can predict the rest without memorizing any of it. The chip performs a verification that a card number simply cannot, and every downstream difference prices or allocates the gap.
The cost gap and what closes it
Remote transactions clear at more expensive interchange categories, and the difference is built into the pass-through cost rather than added by your processor — the structure in our interchange analysis.
What you can and can't control:
Can't: that a remote transaction is remote, or the base category difference.
Can: a meaningful part of the gap, through data quality. The downgrade causes in our effective rate guide hit remote transactions hardest:
- Pass complete address verification data. The single largest controllable factor, and it's a checkout configuration rather than a commercial decision.
- Settle within a day of authorization.
- Pass all available cardholder data fields.
- Use authentication where available, which can improve the category and shift liability simultaneously — per our authentication guide.
- Ensure settled amounts match authorized amounts.
A related case worth separating: a keyed transaction in a physical location is treated as remote. Typing a card number at a counter — because the chip failed, or over the phone — loses the terminal verification and gets priced and treated accordingly. Staff who key rather than persist with a difficult chip read are silently moving transactions into the expensive channel, and it's worth telling them so.
Approval rates
Issuers scrutinize remote transactions more heavily, so the same customer and amount is more likely to be declined online — a real revenue cost that most merchants never quantify.
What drives remote declines:
- Missing or mismatched address data. Frequently the largest single factor and entirely fixable.
- Shipping address differing from billing address, which raises the issuer's fraud probability.
- Unfamiliar device or location.
- Amounts unusual for the cardholder.
- Merchant category and history, since issuers observe fraud rates by merchant.
The point worth acting on: the same fixes that lower cost also raise approval. Complete verification data reduces downgrade probability and reduces decline probability at once, which makes checkout data quality unusually high-return — it's the rare change with two independent payoffs.
And the framing from our declines guide applies directly: a decline is a lost sale, and the customer frequently doesn't retry. A merchant tracking cost per transaction while ignoring approval rate is optimizing the smaller number.
Who bears fraud loss
The difference with the largest financial consequence, and the one that should drive how much screening each channel gets.
In person, with a chip-capable terminal: counterfeit fraud loss generally falls on the issuer. A merchant who accepted a fraudulent card properly through a chip read typically isn't out the money.
In person, without using available technology: the merchant frequently bears it. A terminal that isn't chip-capable, or a chip bypassed by swiping, moves the loss.
Remotely: the merchant generally bears it — the full transaction amount, the goods, and a dispute fee.
Which produces the calculation that matters:
| In person, chip read | Remote | |
|---|---|---|
| Fraudulent $180 sale costs you | Frequently nothing | $180 + goods + fee |
| Value of catching it | Low | High |
| Right screening intensity | Light | Substantially heavier |
Authentication changes the remote picture materially, because it can shift liability to the issuer on transactions that pass. That's the strongest argument for it — not the fraud it prevents, but the losses it reallocates.
Why screening should differ
Given the liability table, one threshold across both channels is wrong in both directions at once — the same simultaneous error our fraud analysis identifies with uniform rules.
Apply that report's threshold rule per channel:
Tighten only while: fraud prevented × fraud cost > additional false declines × false decline cost
In person, fraud cost is low because you frequently don't bear it. The threshold is easily exceeded, so heavy in-person screening declines good customers to prevent losses that weren't going to be yours — and an in-person false decline is especially costly, since the customer is standing in front of you.
Remotely, fraud cost is the full amount plus goods plus fee. The threshold is much harder to exceed, so meaningful screening is justified.
What to configure separately:
- Score thresholds, materially tighter remotely.
- Velocity rules, which matter far more remotely.
- Address mismatch handling, which is only available remotely.
- Value bands, since a large remote transaction warrants review that a large in-person one doesn't.
- Step-up authentication, remote only — and it converts a decline into friction, which is the cheaper outcome.
- Manual review triggers, remote only in most cases.
Defending disputes in each channel
Different evidence wins, and preparing the wrong kind means losing defensible cases.
In person: the terminal record is usually decisive. A chip-read transaction with an authorization record is difficult to dispute as fraud, which is why the liability sits with the issuer. What you need is the transaction record and, where taken, a signature or receipt.
Remotely: the terminal record doesn't exist, so the defence rests on evidence that the legitimate cardholder received what they bought:
- Delivery confirmation to the billing address, ideally signed.
- Verification results captured at the time.
- Device and session data — IP, device fingerprint, timestamps.
- Customer communication before and after.
- Prior order history from the same customer.
- Authentication results where used.
The operational point from our chargeback guide: this evidence must be captured at the time of sale, because it can't be reconstructed when a dispute arrives months later. A merchant who doesn't retain device and verification data has forfeited most remote disputes before receiving any.
Why blended reporting misleads
A merchant running both channels and reading one set of numbers is reading an average of two different distributions.
What blending hides:
- Which channel is actually profitable after acceptance cost and fraud loss.
- Whether a rate change was repricing or mix shift — a merchant moving volume online sees rising costs with nobody having repriced anything.
- Where declines are concentrated, and therefore where lost revenue is.
- Whether a fraud spike is channel-specific, which determines the response entirely.
- Which channel's disputes you're losing.
What to split, minimum: effective rate, approval rate, fraud rate, dispute rate, dispute win rate, and average ticket — each by channel, monthly. The cohort logic in our payment data guide applies here as it does everywhere: a blended figure can move because performance changed or because mix changed, and you cannot tell which from the blend.
Managing a shifting mix
Most merchants' mix is moving, usually toward remote, and the consequences arrive without any decision being made:
- Acceptance cost rises as remote share grows. Forecast this rather than discovering it — and per our pricing analysis, a rising acceptance cost absorbed rather than passed through is a margin cut nobody decided to make.
- Fraud exposure rises, since the channel bearing the loss is growing.
- Dispute volume rises disproportionately.
- Approval rate falls, so revenue leaks at checkout.
- Working capital changes, since settlement and reserve treatment can differ — per our settlement timing analysis.
The habit worth building: track channel mix as a metric alongside revenue, and re-run your cost and fraud parameters whenever it moves materially. A business that grew its online share from 20% to 55% is a different business on every dimension in this guide, and none of it announced itself.
Two channels, two sets of numbers
HL Hunt Pay reports effective rate, approval rate, fraud, and disputes split by channel, with separate screening configuration for in-person and remote — so each is managed on its own economics rather than on an average of both.
Frequently asked questions
The chip verifies the card physically; remotely you're relying on data anyone with the number could supply. Higher fraud rates are reflected in the interchange categories, which is pass-through cost rather than processor markup.
For chip-read in-person transactions, counterfeit loss generally falls on the issuer. Remotely, or where available technology wasn't used, the merchant typically bears it.
Issuers scrutinize unverified transactions more, and remote ones often arrive with less data. Passing complete verification data improves approval and cost simultaneously.
Yes — the cost of an undetected fraudulent transaction differs enormously. One threshold across both screens too hard in person and too lightly online at the same time.
Key takeaways
- Every difference between the channels traces to one fact: in person the chip proves the card, remotely nothing does.
- Complete address and verification data lowers cost and raises approval at once, which makes checkout data quality unusually high-return.
- A keyed transaction at a physical counter is treated as remote, so staff bypassing a difficult chip read are moving revenue into the expensive channel.
- Counterfeit fraud loss generally sits with the issuer in person and with you remotely, which should drive screening intensity per channel.
- Remote dispute defence needs delivery, device, and verification evidence captured at the time of sale — it can't be reconstructed later.
- Track mix as a metric; a business that moved from 20% to 55% online is different on every dimension and nothing announced it.
One integration, channel-level visibility
Sign up for HL Hunt Pay for in-person, online, and invoiced acceptance through a single integration with per-channel reporting and rules — so a shifting mix shows up as a number you can act on.
This guide is educational and does not constitute financial or legal advice. Interchange categories, liability allocation rules, and dispute procedures are set by card networks and change periodically; specific outcomes depend on the network, the transaction, and your agreements. Confirm current rules with your processor.