Fraud Protection
for Issuers

Apple actively partners with issuers to combat fraud collaboratively across the Apple Pay token lifecycle.

Smart provisioning

Issuers can leverage signals provided by Apple’s on‑device intelligence and other insights about observed risk levels to make decisions on token requests safely. This information, along with their own first‑party data, allows issuers to retain control and make more informed decisions regarding card provisioning and transaction approval decisions.

Tailored verification

During provisioning, Apple sends issuers via their network risk signals and data about the cardholder’s Apple account and device. These recommendations and additional data help issuers decide whether to approve, step‑up authenticate, or decline a cardholder’s request to provision. Issuers can choose their preferred cardholder authentication method from Apple’s wide array of options, including In‑App Verification, SMS OTP, Email OTP, Call Center, and Website or App Clip.

Informed protection

During checkout, Apple only processes the details necessary to facilitate the transactions for the cardholder — without retaining personal financial data linked to the cardholder. When a fraudulent transaction occurs on Apple Pay, Apple may receive and use real-time feedback from the issuer to improve risk recommendations and fraud detection capabilities as the fraud ecosystem evolves, flagging the involved devices to help deter future fraud.

$1 Billion+

in fraud losses prevented for our partners to date.

Frequently asked questions

How does Apple help protect issuers from fraud?

Issuers will always be in control of approving or rejecting card provisioning requests and transactions made with provisioned cards. Apple supports that responsibility throughout the Apple Pay lifecycle by providing real‑time risk signals and ecosystem insights. This data helps issuers confidently decide whether to approve, decline, or require extra verification (like SMS or In‑App Verification) when a card provision is submitted by a cardholder.

Apple also leverages feedback from issuers about fraudulent provisions to flag risky devices and continuously improve fraud detection, all while maintaining strict cardholder privacy.

Issuers also benefit from Apple Pay’s Fraud Protection for Merchants, which helps combat fraud at multiple stages of the transaction process.

What data elements and reason codes does Apple recommend issuers use?

Apple recommends that issuers ingest all the available Apple risk signals provided via the payment network operators (PNOs). This allows issuers to have all available data elements, including subtle indicators, that can be used to help detect and prevent fraud. Due to the complex nature of global payment processing, and the many different parties or service providers along the way, we suggest you verify you are receiving all data provided by Apple.

Who is liable for transactions that used Apple Pay as a payment method but are flagged as fraudulent?

Liability for fraud is determined by the policy of the payment network operator (PNO).

Does Apple retain purchase information from Apple Pay transactions?

Apple processes cardholder data to connect customers with their issuer. Apple does not retain personal financial data linked to the cardholder.

If a cardholder’s provisioning request for Apple Pay is denied, what further steps should issuers take?

Issuers should review the Issuer Functional Requirements (IFR) for best practices.

How should issuers use Apple Pay risk data?

Issuers that have enabled Apple Pay will receive recommendations from Apple based on a variety of risk data for consideration, including overall recommendations, data elements, and reason codes. Issuers should confirm with their payment network operator or service provider which data elements, values, and formats to expect.

In making provisioning request decisions, issuers must:

  • Consider the provisioning data sent by Apple,
  • Compare it against their data in the cardholder profile,
  • Complete their own risk assessment of the provisioning request, then
  • Respond with an appropriate fraud mitigation decision.
What makes Apple Pay secure?

Apple Pay combines issuer‑controlled verification methods, industry‑standard tokenization, and cardholder authentication through biometrics or passcode. This is designed to help prevent unauthorized users from making transactions with a cardholder’s card using Apple Pay.

More resources

Apple Pay Demo

Test and debug your integration
in an interactive playground.
Learn more

Apple Developer

Get the resources to design and
build apps for Apple platforms.
Learn more

Apple Business

Manage your company’s digital
presence across Apple apps.
Learn more
  1. In the US, Apple Pay is a service provided by Apple Payments Services LLC, a subsidiary of Apple Inc. Neither Apple Inc. nor Apple Payments Services LLC is a bank. Any card used in Apple Pay is offered by the card issuer.

  2. Apple Pay is not available in all markets. View Apple Pay countries and regions.

  3. Features are subject to change. Some features, applications, and services may not be available in all regions or all languages and may require specific hardware and software.