Fraud, Risk, and Disputes
Fraud, Risk, and Disputes
Green Dot operates a regulated banking environment with transaction monitoring and BSA/AML
controls built in. But because you control the logic that decides who gets paid, you are on the
front line of fraud prevention for your program.
Payouts are an attractive target precisely because they are fast. A debit push payout that reaches
a card cannot be pulled back the way a card purchase can be reversed. Design for that.
Controls you are responsible for
Requirements vary by program type, volume, and risk profile. Green Dot may require — or strongly
recommend — one or more of the following. Your specific requirements are confirmed during
onboarding.
Identity verification
Verify the identity of recipients before they can receive a payout. Depending on your program,
this may include document verification or KYC checks through a Green Dot-approved provider.
The right moment for this is before the first payout, not after a problem. Verifying identity when
a recipient is added is materially cheaper than investigating a fraudulent payout later.
Device and behavioral signals
Use a fraud intelligence platform to assess the risk of each payout request before initiating.
Green Dot may require integration with a specific platform depending on your program type and
volume; requirements are confirmed during onboarding.
Where the recipient initiated the request in your application, pass device context through in the
payout request:
| Field | What it carries |
|---|---|
deviceDetails.deviceType | The kind of device used |
deviceDetails.ipAddress | The IP address the request came from |
deviceDetails.iovationDeviceToken | A device fingerprint token |
fraudData | Additional key/value signals from your own risk stack |
These improve the quality of Green Dot's own monitoring. Populating them is cheap and worth doing.
Card validation
Green Dot validates the recipient's debit card before executing a Debit Push payout, including
card type eligibility, and returns an error for ineligible cards. You are responsible for acting on
those errors and not retrying against ineligible cards.
Repeated attempts against cards that keep failing is itself a fraud signal, both to Green Dot and
to the card networks. Build your retry logic so it stops.
Velocity controls
Implement your own limits on payout frequency, amount, and recipient patterns. Green Dot's program
limits are a backstop, not a fraud control — they are set for your whole program, and a fraudster
operating below them will not trip them.
Patterns worth watching in your own systems:
- Many payouts to the same card across different recipient records
- A recipient's linked card changing shortly before a large payout
- Payout volume that spikes outside your program's normal rhythm
- New recipients receiving large first payouts
Monitoring and reporting
Monitor payout patterns within your own systems and report suspected fraud to Green Dot promptly.
Speed matters: a report made while a payout is still pending has options that a report made a week
later does not.
Protecting card data
Card data handling is a compliance obligation, not a preference.
- Card numbers are never sent to Green Dot in plain text.
- Use Green Dot's hosted PCI widget unless you already hold PCI DSS certification and have a
specific reason to collect card data yourself. - Never log card numbers, security codes, access tokens, or unencrypted payloads — including in
error handling. - Never send production card data to a non-production environment.
See Encrypting sensitive data.
Disputes
A dispute arises when a recipient challenges a payout they did not authorize or did not receive.
If a recipient reports an unauthorized transaction, the dispute is handled through the card
network's standard dispute and chargeback process. Green Dot's compliance team manages the
network-level workflow. You are responsible for providing transaction records and evidence on
request.
To reduce dispute exposure:
- Verify recipient identity before issuing payouts.
- Keep accurate records of every authorized payout, including the
transferIdentifier, the
request identifier, and the business event that triggered it. - Populate
partnerReferenceDataso payouts can be traced back to your records quickly. - Notify Green Dot promptly of any suspected unauthorized payout.
You are responsible for maintaining accurate transaction records and cooperating with Green Dot's
compliance team in any dispute investigation. Procedures specific to your program are confirmed
during onboarding.
Getting your requirements confirmed
Fraud prevention requirements are set per program. Contact your Green Dot program manager to
confirm which controls apply to yours before you go live — not after your first incident.
Updated about 23 hours ago
