FAQ Section
Card Payments

Card-Present vs Card-Not-Present Transactions

 

Learn the difference between card-present and card-not-present transactions and how it affects fraud risk, chargeback liability and processing fees.

Card payments are split into two broad categories. A card-present (CP) transaction happens when the physical card and the cardholder are at the point of sale, for example a tap or chip-and-PIN payment at a card machine. A card-not-present (CNP) transaction happens when the card details are provided remotely, for example on a website, in an app, via a payment link or over the phone.

The distinction matters because it changes how the cardholder is verified, how much fraud risk the transaction carries, who is liable if the transaction turns out to be fraudulent, and often what the transaction costs to process.

What Counts as Card-Present?

A transaction is card-present when the card interacts directly with a payment terminal:

  • Inserting a card and entering a PIN (EMV chip-and-PIN)
  • Tapping a contactless card
  • Tapping a phone or watch using a digital wallet such as Apple Pay or Google Pay
  • Paying on a SoftPOS-enabled smartphone acting as a card machine

In each case the chip in the card (or the secure token in the device) generates a unique cryptogram for the transaction, which the issuer can verify. This makes counterfeiting extremely difficult. See Chip, Contactless and SoftPOS Payments.

What Counts as Card-Not-Present?

A transaction is card-not-present when the card details are captured without the physical card being read:

  • E-commerce checkouts and in-app payments
  • Payment links sent by email, SMS or WhatsApp
  • Card-on-file and recurring subscription charges
  • Mail order and telephone order (MOTO) payments
  • Manually keyed transactions on a terminal

Because anyone who knows the card number, expiry date and CVV could attempt a CNP payment, additional controls are used, most importantly 3D Secure, which is standard on South African e-commerce. See What Is 3D Secure?.

How Do CP and CNP Compare?

AspectCard-presentCard-not-present
Card verified byEMV chip cryptogram at the terminalCard number, expiry and CVV entered remotely
Cardholder verified byPIN (or device biometrics for wallets)3D Secure (OTP or banking app approval)
Fraud riskLowHigher
Typical fraud liabilityUsually the issuer for chip transactionsUsually the merchant, unless 3D Secure shifts liability to the issuer
Common chargeback reasonsRare; mostly disputes about goods or servicesFraud, "transaction not recognised", non-delivery
Typical cost to processGenerally lowerGenerally higher, reflecting the higher risk

Why Does Liability Differ?

Card scheme rules broadly place fraud liability on the party that failed to use the strongest available security:

  • In a card-present chip transaction, the chip and PIN prove the genuine card and cardholder were there, so fraud losses generally sit with the issuer.
  • In a card-not-present transaction without authentication, the merchant carries the fraud risk and will usually lose a fraud chargeback.
  • When a CNP transaction is successfully authenticated with 3D Secure, liability for fraud chargebacks generally shifts from the merchant to the issuing bank.

This is why South African acquirers and gateways require or strongly encourage 3D Secure on e-commerce transactions. For what happens when a cardholder disputes a payment, see Card Chargebacks.

Which Should a Merchant Use?

Most businesses need both. A retail store, restaurant or delivery business takes card-present payments on a terminal or SoftPOS device, while an online store, subscription service or invoicing business takes card-not-present payments through a checkout or payment links. The practical rule is simple: whenever the physical card can be read, let it be read, because the transaction will be more secure and cheaper to process.

Copyright © 2026 Kwik Payments