Fraud Prevention for Online Orders
Fraud prevention should combine payment-provider controls, secure staff access, proportionate order review and a documented response to suspicious activity. It should not rely on stereotypes, ask staff to collect card…

Fraud prevention should combine payment-provider controls, secure staff access, proportionate order review and a documented response to suspicious activity. It should not rely on stereotypes, ask staff to collect card secrets or block legitimate customers with unexplained rules.
Map the fraud scenarios
| Scenario | Operational signal | Control |
|---|---|---|
| Stolen payment card | Provider risk signal, unusual basket or rapid attempts | Gateway authentication, velocity control and review |
| Account takeover | New device, changed address, loyalty use or password reset | Secure recovery, MFA for staff and customer alerts where appropriate |
| Promotion abuse | Repeated accounts, addresses or codes | Bounded promotion and fair review process |
| Refund fraud | Repeated unsupported claims or duplicate remedy | Order evidence, marketplace reconciliation and authority controls |
| Staff or supplier misuse | Unusual refunds, codes or account changes | Separate accounts, permissions, audit and review |
| Phishing and payment diversion | Unexpected credential or bank-detail request | Independent verification and incident reporting |
Use the payment provider properly
Enable supported authentication, CVV and address checks according to the provider's current documentation and the business risk profile. Do not invent universal reject rules. A partial address mismatch can have innocent causes, while a successful authorisation does not guarantee the order is genuine.
Create a proportionate manual-review policy
Define objective triggers such as repeated rapid attempts, unusual value relative to the operation, post-payment address change or inconsistent contact. Give staff a safe procedure that does not request a full card number, PIN, one-time banking code or unnecessary identity document.

Where the outcome remains uncertain, the business may decline or refund before preparation under its documented process. Record the reason and avoid discriminatory assumptions based on name, neighbourhood or accent.
Secure administration
- Unique staff accounts and least privilege
- Multi-factor authentication for payment, ordering and email administration
- Approval and audit for refunds, promotion creation and bank-detail changes
- Prompt offboarding of staff and agencies
- Device updates, backups and phishing training
- Supplier incident contacts and evidence retention
Handle a suspected incident
- Protect active orders and accounts; do not destroy evidence.
- Contact the payment provider or bank through a verified route.
- Reset compromised access and check connected systems.
- Identify affected orders, refunds, customer data and settlements.
- Assess reporting obligations and customer communication.
- Report fraud through the correct UK route where appropriate.
- Review the root cause and update controls.
Measure false positives and outcomes
Track fraud loss, chargebacks, prevented attempts, legitimate orders blocked, manual-review time and customer complaints. A control that rejects many genuine households can cost more than the fraud it prevents.
Practical next step: write a one-page suspicious-order procedure with three review triggers, prohibited questions, approval authority and provider contact. Test it with staff using a harmless scenario.
Review supplier configuration regularly
Payment authentication, risk rules and device controls can change after a provider release. Schedule a periodic review with sample transactions and documented approval. Check that alerts reach a monitored address and that staff know the verified support route.
Keep fraud controls separate from customer-service judgement. A suspicious order may be declined, but a later complaint or data request still requires a fair and documented response.
Related guides
- Payments — the main guide for the wider topic.
- Payment Security and Compliance — the broader guide that frames this implementation.
- Data Protection for Payment Information — a closely related operational control to review alongside this page.
- PCI DSS Compliance for Restaurants — a closely related operational control to review alongside this page.
Sources and date checked
Guidance checked: 24 July 2026. Recheck official guidance and supplier documentation before changing a live system.
Operational, legal and platform requirements can change. Recheck official guidance and supplier documentation before altering a live service.
Related practical guides
PaymentsHandling Refunds for Online OrdersA refund process should be fast enough to treat the customer fairly and controlled enough to prevent duplicates, fraud and accounting gaps. The r…Read guide →
PaymentsData Protection for Payment InformationA payment transaction can involve more personal data than a card number. Names, delivery addresses, phone numbers, email addresses, order history…Read guide →
PaymentsComparing Profitability Across ChannelsA fair channel comparison uses the same sales basis, time period and cost definitions. It also recognises that a marketplace, app, website and te…Read guide →
PaymentsChoosing a Payment Gateway for Online OrdersThe cheapest quoted transaction rate is not necessarily the cheapest gateway for a takeaway. A payment service that creates duplicate charges, de…Read guide →
PaymentsChargeback Management for RestaurantsA chargeback is not the same as a customer asking the restaurant for a refund. It is a card-scheme dispute raised through the customer’s card iss…Read guide →
PaymentsHow to Reconcile Online Orders, Payments and RefundsReconciliation is the process of proving that the orders fulfilled by the takeaway agree with the payments taken, refunds issued, provider statem…Read guide →Connect customer ordering with operations and profit
Use the wider guide library to check the menu, kitchen, fulfilment, payment and financial implications of each decision.
Browse all practical guides