Join our Newsletter — 33% off our NHI Course
Home FAQ Identity Beyond IAM Why do no knowledge, item not received, and…
Identity Beyond IAM

Why do no knowledge, item not received, and significantly not as described disputes create such a difficult chargeback environment for merchants?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 18, 2026 Domain: Identity Beyond IAM

These dispute types are difficult because each one contains uncertainty that merchants cannot always prove away. No knowledge claims stem from customer confusion, item not received depends on delivery evidence and shipping variables, and significantly not as described often becomes a subjective judgment about expectation versus reality. That combination makes investigation slow, costly, and often inconclusive.

Why these disputes are hard to resolve cleanly

No knowledge, item not received, and significantly not as described disputes each fail in a different way, but they share the same merchant problem: the evidence is rarely absolute. A cardholder can genuinely forget a purchase, a shipment can be delayed or misdelivered without the merchant controlling the carrier, and product expectations can diverge from what was actually delivered. That makes the dispute environment less like a binary fraud check and more like an evidence contest.

The practical difficulty is that the merchant is often asked to prove a negative, or to prove a condition the merchant did not directly observe. A transaction may have strong order logs yet still look ambiguous to an issuer if the delivery chain, product condition, or customer intent is unclear. In that sense, the dispute is not only about the order itself, but about whether the merchant can assemble a complete and credible record across payment, fulfilment, and customer communication.

Why each dispute type behaves differently

No knowledge disputes usually hinge on recognition, household use, or cardholder memory. A merchant can present descriptors, receipts, or prior transaction history, but those signals do not always settle whether the purchase was authorised or simply unrecognised by the cardholder. The most useful evidence is often contextual, not just transactional, because the issue is frequently about recall and account sharing rather than a straightforward system error.

Item not received disputes depend heavily on delivery evidence and process integrity. Tracking scans, proof of delivery, delivery address validation, signature capture, and carrier exception handling can all matter, but gaps in any one link weaken the case. If the order was shipped correctly yet the parcel was lost, stolen after delivery, or delivered with poor chain-of-custody evidence, the merchant may still face an uphill battle.

Significantly not as described disputes are the most subjective of the three. Even when the merchant delivered exactly what was ordered, the chargeback can still turn on whether the product condition, appearance, features, sizing, or quality met the buyer’s expectation. That subjectivity makes product pages, images, specifications, customer support notes, return policies, and pre-dispute communications unusually important, because they help define what the customer was actually promised.

What merchants can control, and what they cannot

Merchants tend to win more often when they reduce ambiguity before the dispute happens. Clear product descriptions, consistent fulfilment records, accurate shipping confirmations, and responsive post-purchase support all narrow the room for disagreement. The challenge is that even strong process controls do not eliminate uncertainty when the disputed fact sits outside the merchant’s direct observation, such as household recognition, third-party shipping failure, or the buyer’s subjective interpretation of product quality.

For that reason, the best dispute strategy is usually evidentiary discipline rather than overreliance on one proof point. If the case rests only on a tracking number, only on a receipt, or only on a product photo, the record is fragile. A stronger file connects the order to the customer journey end to end, so the merchant can show not just that something was sold, but that the transaction, delivery, and description were all handled in a way a reviewer can trust. Merchants that keep delivery and fulfilment data coherent are better positioned to defend borderline claims, especially when shipment issues overlap with customer confusion or expectation gaps. Internal analysis of credential and access risks also shows how quickly weak controls become systemic: NHI Mgmt Group reports that only 5.7% of organisations have full visibility into their service accounts, a useful reminder that incomplete operational visibility tends to undermine defensibility across many workflows.

Risk and Threat Considerations

These dispute types create exposure because they reward ambiguity, and ambiguity scales poorly. A merchant that cannot consistently prove shipment, description, or customer intent faces higher loss rates, more manual review, and more time spent on disputes that may still be lost despite being legitimate sales.

Failure mechanism: weak evidence collection, inconsistent shipping telemetry, poor product documentation, and incomplete customer communication records leave too much room for interpretation at the issuer or network review stage.

Impact: merchants absorb direct chargeback cost, operational overhead, and reputational friction, while repeat ambiguity can make a business look higher risk even when the underlying problem is process quality rather than fraud.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV.OV-02 — Cybersecurity Risk Management StrategyChargeback dispute handling is a measurable operational risk to business continuity and loss rates.
Recommendation — Track dispute patterns as an operational risk signal and align prevention controls to the highest-loss dispute types.
CIS Controls v812 — Network Infrastructure ManagementConsistent logging and evidence capture support traceability across fulfilment and delivery workflows.
8 — Audit Log ManagementDefensible disputes depend on tamper-resistant records of order, fulfilment, and support events.
5 — Account ManagementMerchant-side access control reduces the chance of internal record tampering or inconsistent case handling.
Recommendation — Centralise and retain the logs and records needed to reconstruct order, shipment, and customer timelines. Preserve audit-quality records for order creation, shipping, delivery exceptions, and customer correspondence. Restrict who can alter order, shipping, and refund records to preserve evidence integrity.

Practitioner Guidance

What to prioritise: Build dispute files around evidence that survives reviewer scrutiny, not just evidence that proves the order existed. Delivery proof, product expectation proof, and customer-contact history should be easy to retrieve together, because these disputes are often lost on missing context rather than missing transactions.

What to verify: Check whether the evidence you retain would answer the exact question being disputed. For no knowledge, that means order context and authorisation signals; for item not received, that means shipment and delivery integrity; for significantly not as described, that means the merchant’s description versus the buyer’s reasonable expectation.

Practitioner takeaway: The merchants that do best are usually the ones that treat chargebacks as an evidence-quality problem, not a customer-support afterthought, because these disputes are won by reducing uncertainty before it becomes a reviewer’s judgment call.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 18, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org