United Kingdom flagIndependent UK business banking research
UK Business Banking Research · BanksGB
Business typesCards & expensesCash flowSecurityDigital bankingMerchant servicesFX & tradeInsightsAll topics
BanksGB · Security

Refund fraud controls: stop legitimate sales money being redirected to the wrong person

A practical UK merchant guide to refund fraud covering original-payment-method rules, employee permissions, fake returns, account takeover, refund limits and reconciliation.

Refunds move money out of the business and can be abused by customers, employees or attackers. Strong controls make sure the refund relates to a real original payment, goes back through an approved route and is released only by staff with the correct authority.

Refund to the original payment method where practical

Returning money to the original card or account reduces the risk that a fraudster uses a genuine sale to redirect cash to an unrelated bank account.

If the original method cannot be used, apply enhanced verification and document why an alternative route was necessary.

Require proof of the original transaction

Staff should confirm order number, payment status, amount and customer identity before approving a refund. A screenshot of an email asking for money back is not enough.

For goods, link the refund to return or cancellation evidence under the merchant's policy.

Limit who can issue and approve refunds

Frontline staff can have authority for low-value refunds while higher amounts require a supervisor or finance approval.

Separate refund creation from changing payout or bank-account settings. One compromised support login should not be able to redirect merchant funds freely.

Monitor unusual refund patterns

Look for employees issuing refunds near shift end, customers receiving repeated credits, refunds without matching sales and several refunds to the same destination.

Use value and frequency thresholds. One £5,000 refund can deserve more scrutiny than fifty routine £5 refunds.

Account takeover can turn a customer profile into a refund route

If an attacker gains access to a customer account, they can change contact or payment details and request refunds. Re-authenticate sensitive account changes and large refunds.

Do not rely only on the fact that the request came from the customer's logged-in session.

Reconcile refund batches to original sales and bank payouts

Processors can net refunds against merchant settlements. Finance should still record the gross refund against the original customer transaction.

Track refund reason, approver and amount. A rising refund rate can indicate product problems, policy abuse or internal fraud.

Worked example: a customer buys a £1,200 laptop by card and later asks support to refund £1,200 to a new bank account because the card is "closed". Finance should not comply automatically. It verifies the original transaction, uses the processor's card-refund route where possible and escalates any alternative payment request.

Set employee-level refund analytics. A staff member issuing three times the normal refund rate can be innocent, poorly trained or fraudulent, but the pattern deserves review.

Keep refund reasons structured rather than free text only. Categories such as duplicate, cancellation, damaged goods, goodwill and fraud let management see which business process is driving the cash outflow.

Worked example: a support agent has authority to refund up to £200, while anything above that requires a supervisor. A fraudster compromises the agent's account and tries five £190 refunds to the same bank-linked customer profile. Per-transaction limits alone would not stop the pattern, so velocity and recipient-level monitoring should complement staff permissions.

Use refund reason codes to identify internal control problems. A spike in "duplicate charge" refunds can mean checkout is submitting orders twice; a spike in "goodwill" can indicate staff using the wrong category or exceeding commercial authority.

For high-value manual bank refunds, require the same beneficiary-verification process used for supplier changes. A customer asking for money to a new corporate account should not receive weaker controls merely because the transaction is called a refund.

Reconcile refunds to tax and revenue adjustments. Finance should reverse the appropriate sale, VAT or deferred-revenue amount rather than booking every refund to one generic expense account.

Set daily or weekly aggregate refund limits by employee or team, not only per transaction. An attacker who controls one support account can stay below a single-refund threshold while draining substantial cash through many smaller credits.

Keep management approval for refunds to directors, employees or related parties. Those transactions can be legitimate, but the relationship creates a higher conflict-of-interest risk and deserves independent review.

Review refund destination data in chargeback cases. Fraudsters can sometimes obtain both a merchant refund and an issuer chargeback, creating double loss. Finance should connect refund status to dispute handling before accepting or contesting the case.

Review refund rights after staff departures and temporary assignments. Seasonal customer-service workers can legitimately need refund access for a short period, but those permissions should expire automatically when the campaign or contract ends.

Keep refund audit data after the customer receives money. Later chargebacks, complaints or internal investigations can depend on who approved the refund and why the original sale was reversed.

Use stronger review for refunds that exceed the original captured amount through goodwill or compensation. Extra compensation can be legitimate, but it should be authorised as a separate commercial payment rather than disguised inside a refund.

Editorial Verdict

Refunds are outgoing payments and deserve the same control mindset as supplier transfers.

Return money to the original method where possible, restrict staff permissions and monitor patterns. A refund policy should protect genuine customers without creating a simple path for cash to be redirected.

Sources

Keep the banking structure tied to the business model

Use the provider directory, comparisons and practical guides to narrow the questions before choosing products.

Start comparison