> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://ixopay.ferndocs.com/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://ixopay.ferndocs.com/_mcp/server.

# Available Risk Rules

The following section lists all the risk rules available in the IXOPAY platform.

## General Checks

\_\_**Total Transaction count**

Total count of Transactions of \[Connector, Merchant] in \[last x hours, last x days] \[\< >] \[x]

Threshold check for the total count of Transactions

* for a defined period (hours/ days)
* for a defined reference source (Connector or Merchant of the current Transaction)

\_\_**Total amount**

Total amount for \[Connector, Merchant] in \[last x hours, last x days] \[\< >] \[x]

Threshold check for the total volume of Transactions

* for a defined period (hours/ days)
* for a defined reference source (Connector or Merchant of the current Transaction)
* volume is defined by preauthorize & debit Transactions amounts

\_\_**Total payout amount**

Total payout amount for \[Connector, Merchant] in \[last x hours, last x days] \[\< >] \[x]

Threshold check for the total volume of payout Transactions

* for a defined period (hours/ days), measured as a rolling window from the current time, not a calendar-aligned day/week/month, up to a maximum of 50 days
* for a defined reference source (Connector or Merchant of the current Transaction)
* volume is defined by payout Transaction amounts only
* the payout that would cross the configured limit is the one that is blocked, not the next one after it
* the threshold amount can be compared in a specific currency (only payouts in that exact currency count), or in the tenant's Base Currency (other currencies are converted before being added to the total); if no conversion rate is available, the check errors instead of silently counting as zero
* refund Transactions are not included in this threshold

\_\_**Total amount of customer**

Total Transaction amount of this customer for \[Connector, Merchant] in \[last x hours] \[\< >] \[x]

Threshold check for the total volume of Transactions of the same customer

* for a defined period (hours/ days)
* for a defined reference source (Connector or Merchant of the current Transaction)
* customer is defined by Identification and email address
* volume is defined by preauthorize & debit Transactions amounts

\_\_**Total Transaction count of customer**

Total count of Transaction of this customer for \[Connector, Merchant] in \[last x hours] \[\< >] \[x]

Threshold check for the total count of Transactions of the same customer

* for a defined period (hours/ days)
* for a defined reference source (Connector or Merchant of the current Transaction)
* customer is defined by Identification and email address

\_\_**Count of Transactions of same device**

Count of Transactions of same device (browser fingerprint) of \[Connector, Merchant] in last \[x] hours \[\< >] \[x].

Threshold check for the count of Transactions performed on the same device

* for a defined period (hours/ days)
* for a defined reference source (Connector or Merchant of the current Transaction)
* device is defined by the fingerprint generated through the payment page or payment.js

\_\_**Total amount of same device**

Total amount of same device (browser fingerprint) of \[Connector, Merchant] in last \[x] hours \[\< >] \[x]

Threshold check for the total Transaction volume performed on the same device

* for a defined period (hours/ days)
* for a defined reference source (Connector or Merchant of the current Transaction)
* device is defined by the fingerprint generated through the payment page or payment.js
* volume is defined by preauthorize & debit Transactions amounts

\_\_**Transaction Indicator Check**

Checks for a specific transaction indicator

\_\_**Registration Flag Check**

Checks whether the transaction has been flagged *withRegister*

Optionally Register transactions can be considered as well

\_\_**Count of different countries**

Count of different countries based on \[billing address, shipping address, ip address] of \[Connector, Merchant] in \[last x hours] \[\< >] \[x]

Compares the count of different country values used within all Transactions

* for a defined period (hours/ days)
* for a defined reference source (Connector or Merchant of the current Transaction)

\_\_**Difference of this Transaction amount vs. average Transaction amount**

Difference of this Transaction amount vs. average Transaction amount of \[Connector, Merchant] in \[last x hours] \[\< >] \[x %]

Evaluates the difference of the average Transaction amount of the sliding window versus the current Transaction amount

* for a defined period (hours/ days)
* for a defined reference source (Connector or Merchant of the current Transaction)

\_\_**Average amount comparison**

Difference of average Transaction amount of \[Connector, Merchant] in \[last x hours] vs. average Transaction amount of \[Connector, Merchant] in \[last y hours] \[\< >] \[x %]

Evaluates the difference of the average Transaction amount of the two sliding windows

* for a defined period (hours/ days)
* for a defined reference source (Connector or Merchant of the current Transaction)

\_\_**Difference of Transaction count**

Difference of Transaction count of \[Connector, Merchant] in \[last x hours] vs. Transaction count of \[Connector, Merchant] in \[last y hours] \[\< >] \[x %]

Evaluates the difference of the count of Transactions of the two sliding windows (up to now)

* for a defined period (hours/ days)
* for a defined reference source (Connector or Merchant of the current Transaction)

\_\_**Count of different payment instruments**

Count of different payment methods (over all customers) at \[Connector, Merchant] in \[last x hours] \[\< >] \[x]

Threshold check for the total count of all payment instruments on the given reference source (Connector, Merchant)

* payment instrument is a particular card, IBAN or wallet

\_\_**Blocklist**

Is anything on Blocklist.

Evaluates all available (and chosen) Transaction/ customer values against the Blocklist

\_\_**Allowlist**

Is anything on Allowlist.

Evaluates all available (and chosen) Transaction/ customer values against the Allowlist

\_\_**Transaction amount evaluation**

This Transaction amount is \[\<>=] \[x]

Evaluates the current Transaction amount (limit check)

\_\_**Total amount of customer country**

Total amount of customer country based on \[ip country, billing country, shipping country] of \[Connector, Merchant] in last \[x] \[hours, days] \[\<>] \[x] \[currency]

Threshold check for the total Transaction volume of all Transactions made from customers in the chosen country

* for a defined period (hours/ days)

\_\_**Payment instrument usage count**

Count of Transactions using same payment instrument

Threshold check for the total count of Transactions with the same payment instrument

* for a defined period (hours/ days)
* for a defined reference source (Connector or Merchant of the current Transaction)
* payment instrument is a particular card, IBAN or wallet

## Customer Checks

\_\_**Total amount of customer**

Total transaction amount of this customer for \[connector, merchant] in \[last x hours] \[\< >] \[x]

\_\_**Total transaction count of customer**

Total count of transaction of this customer for \[connector, merchant] in \[last x hours] \[\< >] \[x]

\_\_**Advanced Country Check**

Country of \[type x] is \[in/ not in] \[list of countries] of \[only successful, all] Transactions of \[Connector, Merchant] in \[last x hours] - but pass the first \[x] Transactions

Velocity check to allow only a certain count of Transaction from a particular country within the chosen time period

\_\_**Count of Customers with same Credit card**

Count of customers (email or customerIdentification) with same Credit Card (Credit Card fingerprint) of \[Connector, Merchant] in last \[x] hours \[\< >] \[x]

Threshold check for the count of customers using the same card

* for a defined period (hours/ days)
* for a defined reference source (Connector or Merchant of the current Transaction)
* customer is defined by Identification and email address

\_\_**Count of Customers of same device**

Count of Customers (email or customerIdentification) of same device (browser fingerprint) of \[Connector, Merchant] in last \[x] hours \[\< >] \[x] of \[all, only successful] Transactions

Threshold check for the count of different customers performed Transaction on the same device

* for a defined period (hours/ days)
* for a defined reference source (Connector or Merchant of the current Transaction)
* device is defined by the fingerprint generated through the payment page or payment.js
* customer is defined by Identification and email address

\_\_**Count of customers with same IBAN**

Count of customers (email or customerIdentification) with same IBAN of \[Connector, Merchant] in last \[x] hours \[\< >] \[x]

Threshold check for the count of customers using the same IBAN

* for a defined period (hours/ days)
* for a defined reference source (Connector or Merchant of the current Transaction)
* customer is defined by Identification and email address

\_\_**Customer's data comparison**

Customer Data Analysis Check

Compares the chosen customer data values against the defined values

Comparison with equals, not equals, contains, not contains

\_\_**Customer's IP address**

Customer's IP address is \[in, not in] \[ip address range in CIDR notation]

Checks if the customer's IP address is within the defined range

\_\_**Customer's IP address country**

Customer's IP address country is \[in, not in] \[list of countries]

Checks if the customer's IP address belongs to the chosen countries

\_\_**Count of different payment instruments of customer**

Count of different payment methods of customer at \[Connector, Merchant] in \[last x hours] \[\< >] \[x]

Threshold check for the different payment instruments used by a customer

* customer is defined by Identification and email address
* payment instrument is a particular card, IBAN or wallet

\_\_**Country compare to address**

Customer's \[ip address, shipping address, billing address] country \[= !=] \[ip address, shipping address, billing address] country

Checks if two defined country values match or not

\_\_**Total amount of customer country**

Total amount of customer country based on \[ip country, billing country, shipping country] of \[connector, merchant] in last \[x] \[hours, days] \[\<>] \[x] \[currency]

\_\_**Transaction Indicator and Reference Scheme ID Check**

Checks for a specific transaction indicator and additionally checks whether a reference scheme transaction ID is given

## IP Address Checks

> **Info**
>
> See Customer Checks.

## Credit Card Checks

> **Note**
>
> The Credit card checks do not take into account tokens (ApplePay, GooglePay, Network Tokens) created for credit cards. This can lead to over- or undercounting of specific payment instrument counts.

\_\_**\_Deprecated : \_Level of Credit Card (BIN)**

BIN level of Credit Card is \[in, not in] \[list of levels]

Checks the level of the used card (Standard, Gold, Business etc.)

\_\_**Segment of Credit Card (BIN)**

BIN segment of Credit Card is \[in, not in] \[list of segments]

Checks the segment of the used card (Consumer, Business, Commercial, Government or Unknown)

\_\_**Credit Card PAN Check**

Check first 6 digits and last 4 digits of Credit Card number

Checks the currently used card against the defined card number (first 6 and last 4 digits)

\_\_**Transaction Count of same Credit Card (first 6 and last 4 digits)**

Count of Transactions of \[Connector, Merchant] where same first 6 digits (and opt. last 4 digits) are used in last x hours

Velocity check to evaluate the number of Transaction performed with the same Credit Card

\_\_**Count of different Credit Cards of same device**

Count of different Credit Cards (Credit Card fingerprint) of same device (browser fingerprint) of \[Connector, Merchant] in last \[x] hours \[\< >] \[x].

Threshold check for the count of different cards used by the same device

* for a defined period (hours/ days)
* for a defined reference source (Connector or Merchant of the current Transaction)
* device is defined by the fingerprint generated through the payment page or payment.js

\_\_**Total count of Transactions with certain bin range**

Credit Card matches defined BIN range and total count of Transaction of the defined BIN range for \[Connector, Merchant] in \[last x hours] \[\< >] \[x].

Velocity check to evaluate the number of Transactions performed with cards originating in the chosen BIN Range

* for a defined period (hours/ days)
* for a defined reference source (Connector or Merchant of the current Transaction)

\_\_**Prepaid Credit Card (BIN)**

Credit Card \[is, is not] prepaid

Checks if the current credit card is a prepaid card or not.

\_\_**Reloadable Credit Card (BIN)**

Credit Card \[is, is not] reloadable

Checks if the current credit card is a reloadable card or not.

\_\_**Brand of Credit Card (BIN)**

BIN brand of Credit Card is \[in, not in] \[list of brands]

Checks the brand of the used card (Visa, Mastercard, Amex, etc.)

\_\_**BIN Country**

BIN country of Credit Card is \[in, not in] \[list of countries]

Checks if the issuing country of the used card is within the chosen list of countries

\_\_**Type of Credit Card (BIN)**

BIN type of Credit Card is \[in, not in] \[list of types]

Checks the type of the used card (Debit, Credit)

## IBAN Checks

> **Info**
>
> See Customer Checks.

## External Risk Checks

\_\_**\_Legacy : \_Kount - External Risk Check**

Use Kount Risk Check Analysis. (External Risk Check)

Integrates Kount as external Risk Check service

Not available for new clients. See [Kount — External Risk Check](https://documentation.ixopay.com/manual/docs/risk-management/risk-profiles/create-risk-rules#kount--external-risk-check).

\_\_**Notolytix - External Risk Check**

Use Notolytix Risk Check Analysis. (External Risk Check)

Integrates Notolytix as external Risk Check service

\_\_**Maxmind - External Risk Check**

Use Maxmind Risk Check Analysis. (External Risk Check)

Integrates Maxmind as external Risk Check service

\_\_**Forter - External Risk Check**

Use Forter Risk Check Analysis. (External Risk Check)

Integrates Forter as external Risk Check service

\_\_**FraudNet - External Risk Check**

Use FraudNet Risk Check Analysis. (External Risk Check)

Integrates FraudNet as external Risk Check service

\_\_**Riskified - External Risk Check**

Use Riskified Risk Check Analysis. (External Risk Check)

Integrates Riskified as external Risk Check service

## Other Checks

\_\_**Randomly hit check**

Triggers randomly by the configured chance (e.g. to generate random samples)

\_\_**Extra Data Check**

Checks the passed extra data against the configured values

\_\_**Count of A with same B**

Count of \[A] with same \[B] of \[Connector, Merchant] in last \[x] hours \[\< >] \[x] of \[all, only successful] Transactions

Threshold check for the number of Transactions performed with different Credit Cards from different IP addresses.

* for a defined period (hours/ days)
* for a defined reference source (Connector or Merchant of the current Transaction)

\_\_**Count or Volume of Chargebacks**

Total Chargeback \[count, volume] for \[Connector, Merchant] in \[last x hours, last x days] \[\< >] \[x]

Threshold check for the volume of Chargebacks used by a customer

* customer is defined by Identification and email address
* payment instrument is a particular card, IBAN or wallet

\_\_**Last Transaction is longer ago then**

Last Transaction (debit & preauth) of \[Connector, Merchant] \[is, is not] longer ago then \[x days]

Triggers if the last Transaction of the chosen reference source is longer ago then the defined days

\_\_**First Transaction check**

Transaction \[is, is not] first Transaction on \[Connector, Merchant]

Triggers if the current Transaction is the first one on the chosen reference source (Connector, Merchant)

\_\_**Includes another Risk Profile**

Includes another defined Risk Profile