Protective measures to confine risk & vulnerability to fraud

A list of simple fraud prevention measures a merchantentered may appear to be of a domain, such as
should observe.mike.sanders@mynigeria .com. In such cases the
1. Billing address entered by a customer should bemerchant needs to verify the authenticity of the
verified and compared with the automated Addressdomain, by pre-fixing with a www ( in the URL of a
Verification System (AVS), which has abrowser and if it is an existing domain, the address
complete profile of a credit card holder including theindicated in the website needs to be compared with
address to which monthly statements are sent,  anthat of the billing/shipping address, for example if the
Address Verification System should be a part &website has a US address and the billing /shipping
parcel of any payment processing equipment oraddress leads to Nigeria, then caution needs to be
software, a merchant should observe this as aobserved.
mandatory exercise.And as an added verification process, if the domain
The AVS was created to shield MOTO (Mail Order /appears to be legitimate with no mismatch of the
Telephone Order) businesses from fraud, but theaddress, a further check in WHOIS will certify the
process is limited to curbing online fraud, the internetgenuineness of the domain; there are many domain
provides a window of opportunity for globalregistration websites where WHOIS checks can be
commerce, however for the moment the AVS isprocessed.
available for US addresses only.5. A merchant should be vary of orders that appear to
The internet has benefited companies that marketbe different, instances where unusually large quantity
software online, it allows customers to buy theof the same product is being ordered or when the
software and instantly download it, the AVScustomer offers to pay an extra charge for expedited
unfortunately does not provide protection to ashipment. These orders can be cleverly spotted for
merchant in this case, the identity thief will havethe unusual ordering pattern, which tend to be different
address particulars of the fraudulently acquired creditfrom the day-to-day legitimate ones.
card and because the transaction has no merchandise6. The other solution to confirm the authenticity of the
to physically deliver, these companies become easyperson placing the order online is to call the customer
victims of fraud on the net.on the telephone, and summarize the order details, this
2. It is therefore very important to ensure that there isverification more or less establishes the genuineness
no mismatch in the shipping address and the billingof the person placing the order.
address. Many merchants do not accept orders which7. It is in the fitness of things to collect as much data
have a billing address that is different from the shippingas possible on the order placed, a verification of the
address, this policy is confined to internationalcustomers address and telephone number, the credit
customers as well as domestic customers.card issuing bank details and the IP address of the
There are instances where a customer has to call ancomputer, are some of the basic checks that will help
online merchant and provide verification details,prevent or even tracking fraud, some of the
because the merchandise ordered was to beverifications need to be done indiscreetly and these
delivered as a birthday gift to another city, and inshould be done by an agency that has all the possible
instances like these the billing address will obviously bedata on fraudulent credit cards in circulation.
different from the shipping address.8. A prominently placed warning on the website stating
3. Another important verification feature for athat fraud detection software is protecting the website,
merchant is to keep a check on orders which have aand fraud will be tracked and prosecution proceedings
free subscription email address. Many fraudulentwill be initiated. This will deter potential fraudsters.
transactions more often have these email addresses,9) The never process (factor) for someone else
because a free sign-up to these email domains doesshould be scrupulously observed, it is a breach of
not require a process in which the antecedents of theagreement that can cost the company dearly.
user can be verified. Additional checks need to be10) Offering real time service to customers will help the
done for customers using these email accounts,online business grow; a professional customer service
although not all of them can be fictitious.pays and wins the appreciation of millions of
4. There are instances in which the email addresscustomers.