Composite, auth-rate × inverse decline × inverse dispute × settlement-on-time. The CFO single-number.
At a glance
A 0, 100 composite that compresses four enterprise payment-health signals (authorisation rate, decline rate, dispute rate, settlement-on-time) into one number a Fortune-500 CFO or VP of Payments can read at a glance. CyberSource is Visa’s enterprise gateway used by airlines, hotels, automotive, and large retailers; this card is calibrated for that volume profile (50k+ transactions per period is normal) and that risk posture (Visa Dispute Monitoring Program 1.0% ceiling sits very close to “merchant account terminated”). The number a board pack opens with.
Calculation
Calculated automatically from your CyberSource data. See the At a glance summary above for what the metric tracks and the worked example below for a typical reading.Worked example
A North American mid-market airline running CyberSource for ticket payments and Magento (Adobe Commerce) for the storefront. The 7-day window covers 06 Apr 26 to 12 Apr 26. Roughly 1.2M passengers booking, mix of one-time tickets and recurring corporate-account billing.
Composite = 0.35 × 94.5 + 0.25 × 75.75 + 0.20 × 67.75 + 0.20 × 92.7 = 33.08 + 18.94 + 13.55 + 18.54 = 84.1
A score of 84 is healthy for an enterprise carrier (above the 70 alert threshold, below the rare 90+ band). What’s worth noticing:
- Dispute rate is the largest drag. At 0.645% the composite component scored only 67.75. The carrier is comfortably under the Visa VDMP 0.9% warning, but a doubling to 1.3% would drop the dispute component to 35 and pull the composite to ~76, AND would land the merchant in VDMP enrolment within 60 days. Open Chargeback Reason Codes to see if reason 4853 (cardholder dispute / fraud) or 4855 (goods/services not received, common on cancelled-flight refund disputes) is driving the mix. Airlines historically over-index on 4855 because of cancellation-policy disputes.
- Decline-rate amplifier is doing its job. A 4.85% decline rate cost 24.25 component points (vs perfect 100). Drilling into Top Decline Reasons: 41% are issuer
do_not_honor(reason 203, low value to fix, retry rarely succeeds), 22% AVS mismatch (corporate cards from outside the US billing-zip system), 18% Decision Manager REVIEW (potentially false-positive, see below), 12% insufficient_funds, 7% expired_card. The Decision Manager REVIEW slice is the actionable one; if fraud-ops can tighten rules without raising chargeback risk, the composite climbs roughly 1.5 points per 1pp of REVIEW reduction. - Decision Manager false-positive rate is suspect. REVIEW outcomes that ops manually approves and ship without a chargeback are by definition false-positives. If the carrier’s ops team manually reviews these and approves >85% (typical when DM rules are over-tuned), tightening the rules is the highest-leverage action. The composite would respond within one full sync cycle.
- Three settlement batches missed T+1. Two were Easter weekend (banking-holiday-driven, expected), one was a routine acquirer-side delay on EUR-denominated batches. Cross-border settlement to non-USD currencies takes T+2 contractually, so the on-time threshold should arguably be applied per-currency, not globally; that’s a manifest tweak, not a CFO concern. See Avg Settlement Time.
- Token Management Service auth uplift is hidden in the blend. This carrier’s TMS-tokenized corporate-account recurring book runs at 97.8% auth rate; fresh-card one-time tickets run at 92.1%. The blended 94.5% includes both. If the recurring book grew (B2B corporate adoption), the composite would climb without any operational change. Watch Stored-Token Health and Recurring Charge Failure Rate.
Sibling cards merchants should reference together
Reconciling against the vendor’s own dashboard
Where to look in CyberSource Business Center (EBC2): CyberSource Business Center does NOT have a single “Payment Health” composite, this card synthesises one from four CyberSource-native metrics. The closest equivalent screens in ebc2.cybersource.com:- Transactions → Search for auth-rate context (filter on Status =
AUTHORIZEDvs total). - Decisions → Decision Manager → Case Management for fraud-rule outcome mix (
ACCEPT/REVIEW/REJECT). - Reports → Standard Reports → Conversion Detail Report for decline-reason breakdown.
- Reports → Chargeback Summary Report for dispute-rate context.
- Reports → Payment Batch Detail Report for settlement-on-time context (batch arrival vs expected window).
Cross-connector reconciliation, what should match what:
Quick rule for support tickets: if a payments-ops lead says “EBC2 shows 95% auth rate, your dashboard shows 93%”, walk through the reconciliation table. The
REVIEW-as-half-decline treatment is the most common cause; the second is the overnight-batch reporting lag.
Known limitations / merchant FAQs
Why is the CyberSource health score lower than the Stripe one for the same brand? Two structural reasons. First, CyberSource is positioned for enterprise volume with harder issuer-base mix: more international cards, more corporate cards, more cross-border, more recurring. All of these have lower baseline auth rates than the SMB-domestic-consumer mix Stripe sees. A 2, 4 point gap is normal. Second, enterprise merchants on CyberSource typically run multi-acquirer routing with CyberSource as the failover for high-risk traffic; the harder traffic ends up on CyberSource by design. My score dropped 6 points overnight, what happened? Open the four component cards in this order: Decline Rate, Auth Rate, Dispute Rate, Avg Settlement Time. Decline rate is amplified ×5 so a 1pp jump is 1.25 score points; this is the most common cause. Then check Top Decline Reasons. If a single decline-reason bucket grew (e.g. AVS mismatch from 22% to 35%), that’s almost always a Decision Manager rule pack that fraud-ops shipped recently. Roll back the rule pack or dial it down. How do I read AVS codes? My fraud-ops lead asks for the breakdown. Address Verification System codes returned by the issuer:Y. Address and 5-digit zip both match. The healthiest signal; auth-rate near 100%.A. Address matches, zip does not. Common on military APO/FPO addresses, hotels, and corporate billing centres. Most enterprise merchants accept; tightening toY-only declines 8, 15% of corporate transactions for very little fraud-prevention upside.Z. Zip matches, address does not. Common on rural / international addresses where USPS standardisation differs. Treat similarly toA.N. Neither matches. Highest-risk signal but still a wide band; some legitimate fresh-card / new-customer transactions land here. Decision Manager should weight this alongside other signals, not auto-decline.- No AVS data returned. Some non-US issuers don’t participate in AVS. Don’t penalise; weight other signals.
do_not_honor and higher insufficient_funds than Stripe for recurring billing?
This is a real pattern. Recurring-billing books on CyberSource (typically B2B, subscription, utility, telecom) see insufficient_funds (reason 204) materially more often than do_not_honor (reason 203) because the issuer responses on recurring-MID flagged transactions skew toward customer-balance reasons rather than issuer-suspicion reasons. The fix is dunning + retry timing: retrying on payday-aligned schedules (1st-of-month, 15th-of-month, 28th-of-month for SSI/pension cohorts) recovers a meaningful share. See Decline Retry Success Rate and Dunning Recovery Rate.
Does Token Management Service really lift auth rates that much?
Yes, materially. Tokenized cards (network tokens specifically, e.g. Visa VTS, Mastercard MDES) flow through the network with stronger metadata and auth rates run 4, 8 percentage points above un-tokenized fresh cards on the same merchant. PAN-based TMS tokens give a smaller uplift (1, 3pp) because the network treats them like any other card. Enterprise merchants with significant recurring revenue should target >80% of the recurring book on network tokens; the composite responds within one full sync cycle.
My multi-currency global merchant, does this score work?
Yes. The components are rates, not amounts, so multi-currency global enterprises (one CS merchant ID processing USD + EUR + GBP + AUD + JPY) get a single, valid composite. Currency-specific health is exposed via Revenue by Currency for the amount lens and Revenue by Country + Decline Rate by Card-Country for the geography lens.
Can I customise the weights?
Not yet, the formula is fixed in the manifest. The default weights (35/25/20/20) reflect what enterprise CFOs and VPs of Payments ask first. If your business needs a different weighting (e.g. settlement-on-time weighted higher because you have very tight cash-flow forecasting), the formula lives in cybersource.yaml and is straightforward to add as a per-merchant override. Open a request.