Direct answer
A billing interruption is not automatically fraud, platform error, or chargeback grounds. Synthesis/inference (PR-P09, PR-P18, RS-S07, RS-S08): preserve billing state, verify authority, and reconcile platform, bank/card, delivery, agency, attribution, analytics, and settled ledgers. Branch into legitimate balance, payment/issuer decline, suspected unauthorized activity, agency mismatch, or credit/refund. Keep disputed and undisputed amounts separate; use evidence-supported, authorized routes.
Who this is for
Fit: Finance, media, agency, incident leads running high-spend Meta, Google Ads, or TikTok programs.
Not a fit: anyone seeking payment-lock bypass, identity rotation, replacement accounts, evasion, or unauthorized disputes. This is operational—not legal, tax, insurance, banking, or platform-policy advice. AdsInfra is separate from providers; it promises no support, credit, refund, reinstatement, delivery, or recovery timing.
Decision model
Treat visible labels as states and causes as hypotheses. Google documents payment, chargeback, suspicious-activity, and verification states; TikTok documents transaction-related restrictions with account- and scenario-dependent eligibility. Google requires transaction/authorization reconciliation before dispute and warns legitimate-balance chargebacks can create suspension risk. [PR-P11][PR-P15][DRS-A07] Meta, TikTok, and issuer/bank routes are mutable; verify current account/region scope.
Use four control categories:
| Category | Meaning in reconciliation | Owner and proof |
|---|---|---|
| Controlled | Authority, contract, approved spend, ledger, export, or decision. | Finance/asset owner; approval and source export. |
| Observed | Platform label, bank status, report, invoice, or symptom. | Recorder preserves timestamp, source, and scope; not causal proof. |
| Provider-dependent | Platform, issuer, appeal, review, credit, or refund decision. | Authorized liaison uses current route; no promised result/time. |
| Unknown | Missing authority, mapping, match, settlement, or data scope. | Assign owner and verification; do not fill gaps with confidence. |
Synthesis/inference (PR-P09, PR-P18, RS-S07, RS-S08): Keep platform-billed, bank/card, served-delivery, agency/reseller, attribution, analytics, and backend-settlement ledgers separate. Match entity, account, scope, currency, time zone, period, and settlement—not amount alone. Operating method; not provider proof.
Diagnostic or control sequence
-
Open the incident record. Evidence/input: exact label/error, IDs, transaction reference, currency, first-seen UTC, region, entity, and last-good export. Owner: recorder/finance owner. Action: preserve export and screenshot without secrets. Stop/branch: uncertain source or storage becomes a logged verification gap.
-
Confirm authority. Evidence/input: entity, approval chain, authorized users, billing/payment owners, contracts, and manager/portfolio links. Owner: finance and asset owners. Action: name who may pause spend, contact platform/issuer, approve dispute, accept remedy, and close. Stop/branch: unclear authority means no nonessential financial action.
-
Capture platform billing state. Evidence/input: invoice/balance export, transaction ID, status, profile ID, amount, currency, timestamp, notice, and case ID. Owner: finance owner/authorized liaison. Action: save URL, access date, and protected original. Stop/branch: preserve changed states; do not call one a correction without provider evidence. [RS-S03][RS-S15]
-
Match the external payment record safely. Evidence/input: issuer/bank merchant, amount, currency, date, status, and reference. Owner: finance owner. Action: map to the approved finance/payment system; use only a permitted redacted token or last four digits as a worksheet pointer. Stop/branch: pending, reversed, duplicated, or absent is not proof of fraud. Synthesis/inference (RS-S03, PR-P12): Do not copy full PAN, bank-account numbers, CVV, PIN, passwords, cookies, or MFA codes into the incident worksheet or send them inbound; standard payment/authentication hygiene.
-
Reconcile served delivery. Evidence/input: account/campaign/ad export, cost, range, currency, time zone, budget, and change ledger. Owner: media operations, reviewed by finance. Action: compare served and billed periods; record variance or “unresolved.” Stop/branch: stale reports pause conclusions; delivery alone does not prove an unauthorized charge. Synthesis/inference (PR-P09, PR-P18, RS-S07, RS-S08): reporting and serving remain separate signals until matched.
-
Choose the billing branch. Evidence/input: matched records, authorization/change logs, delivery export, and agency invoice. Owner: finance owner. Action: for a Google Ads legitimate-balance disagreement, reconcile transaction and authorization before the current Google dispute/billing route; a legitimate-balance chargeback can create suspension risk. [DRS-A07][PR-P11] For payment lock/issuer decline, keep tracks separate. For suspected unauthorized activity, Synthesis/inference (PR-P11, PR-P12, PR-P15, RS-S03): preserve, contain within authority, and verify current platform and issuer/bank routes for the account, region, and provider. For agency mismatch, Synthesis/inference (RS-S03, RS-S09): separate platform and contract disputes; use finance, procurement, or counsel.
-
Classify each amount. Evidence/input: worksheet row, authority, platform response, issuer status, contract, and settlement. Owner: finance owner. Action: label
undisputed-authorized,disputed-amount,suspected-unauthorized,pending, each refund state, each credit state, orunmatched-residual; record approver/date. Stop/branch: do not dispute authorized spend merely because delivery, attribution, or revenue disappointed. -
Handle credits and refunds as provider-dependent. Evidence/input: current provider response/offer, transaction, amount, currency, reason, scope, contract, and issuer posting. Owner: finance owner, with procurement/counsel as needed. Action: reconcile to the original row; count cash only for
refund-settledin the issuer/bank record, and reportcredit-posted/credit-appliedas non-cash value. Stop/branch: Synthesis/inference: refund, credit, and service-credit terms are provider- and contract-dependent; verify current terms in-account before recording cash or non-cash value. Do not invent a remedy or timeline. -
Separate attribution from revenue. Evidence/input: attribution export, event definition/window/version, cohort, consent/matching notes, analytics, backend IDs, refunds, cancellations, qualification, and settlement. Owner: measurement and finance. Action: freeze cohort, time zone, definition, and cutoff. Stop/branch: modeled, delayed, duplicated, unmatched, refunded, or unsettled events are not recovered revenue, fraud, or causal lift. Synthesis/inference (PR-P18, RS-S07, RS-S08): settled revenue requires the business record.
-
Use official routes. Evidence/input: branch, sanitized evidence index, account/region route, and authorized case owner. Owner: platform liaison; finance for issuer/bank; procurement/counsel for agency rights. Action: submit one chronology and retain case IDs. Stop/branch: stop on requests for credentials, codes, cookies, full payment data, remote access, or scripts. Synthesis/inference (RS-S03, PR-P11, PR-P12, PR-P15): routing is conditional guidance, not cross-platform policy or an outcome claim.
-
Apply financial acceptance criteria. Evidence/input: reconciled worksheet, access/change review, platform/issuer responses, settled refund or posted/applied credit, delivery baseline, attribution/settlement cohort, and residual list. Owner: finance signs finance scope; asset owner and incident lead sign operations. Action: match every row, evidence dispute/refund/credit, or assign residual owner/date. Stop/branch: login, dashboard, active campaign, or account credit alone is not recovered cash. Synthesis/inference (RS-S03, RS-S09, RS-S10, RS-S15): closure requires evidence and residual ownership.
-
Run a limited monitored restart. Evidence/input: signed criteria, ceiling, payment state, clean access, campaign diff, event test, and stop condition. Owner: asset owner approves; executor records read-back; finance monitors. Action: test the smallest authorized scope. Stop/branch: stop on unexpected charge, access change, delivery mismatch, event failure, or out-of-bound ledger movement. Synthesis/inference (RS-S03, RS-S09): this is an operating control, not a provider promise.
-
Close and test the control. Evidence/input: UTC chronology, decisions, mitigations, missing-data log, residuals, and owners/dates. Owner: incident lead with finance, measurement, and asset-owner acknowledgement. Action: record and later exercise authority, export, invoice, dispute, and credit/refund controls. Stop/branch: an untested action is a hypothesis. Synthesis/inference (RS-S10, RS-S15): retain unresolved items with owners/dates.
Reconciliation worksheet fields
| Field group | Required fields; safe handling boundary |
|---|---|
| Identity and authority | Legal entity; platform; region; account/payment-profile ID; finance owner; asset owner; authorized approver; agency/reseller; authority source and date. |
| Platform billed | Invoice/statement ID; transaction ID; amount; currency; billing period; event/posting timestamp and time zone; balance or payment label; source URL/export; case ID. |
| External payment | Issuer/bank; merchant; amount/currency; pending/posted/reversed status; date/reference; approved-system pointer; permitted redacted token/last four. Synthesis/inference (RS-S03, PR-P12): full PAN, bank numbers, CVV, PIN, passwords, cookies, or MFA codes stay out of this worksheet; standard payment/authentication hygiene. |
| Served delivery | Account/campaign/ad scope; date range and time zone; served cost; delivery export version; budget/change references; known reporting incident or freshness note. |
| Agency/reseller | Contract/insertion-order ID; invoiced entity; account scope; service period; media amount; fees/markup/tax fields as applicable; invoice status; dispute owner. |
| Attribution and revenue | Event definition/window; reporting version; cohort/cutoff; platform/analytics values; backend IDs; qualified/settled/refunded/cancelled status. |
| Decision state | Branch; line status; disputed/undisputed/unauthorized amounts; refund state; credit state; authority decision; next action; owner/date; residual. |
Evidence to preserve
- Exact billing label/error, invoice or balance export, transaction/profile IDs, currency, timestamp, and case ID.
- Redacted bank/card evidence showing merchant, amount, currency, status, date, and reference; keep the source in the approved finance/payment system. Do not copy full payment credentials or authentication data into this worksheet or send them inbound. Synthesis/inference (RS-S03, PR-P12): standard payment/authentication hygiene.
- Authorized-user, admin, partner, payment-method, budget, and automation changes with actor and UTC time.
- Served-delivery export with scope, freshness, attribution window, event definition, and version.
- Agency/reseller contract, insertion order, invoice, entity mapping, period, and correspondence.
- Analytics and backend records showing qualification, order, cancellation, refund, or settlement.
- Evidence index: collector, source, timestamp, file/version, permissions, retention decision, and unavailable-data reason.
What not to do
- Do not charge back because ads stopped, a dashboard is late, attribution failed, or revenue missed target.
- Do not casually reverse an authorized Google Ads balance. Reconcile first; Google warns a legitimate-balance chargeback can create suspension risk. [DRS-A07][PR-P11] Verify separate Meta, TikTok, and issuer routes.
- Keep agency/reseller contract disputes separate from platform transactions.
- Do not call attribution settled revenue or variance fraud without the business settlement record.
- Do not send full payment data, passwords, MFA codes, cookies, IDs, remote access, or scripts to inbound “recovery” contacts.
- Do not forge evidence, rotate identities/payment methods, rent accounts, create bypass accounts, or spam appeals. Meta describes action against deceptive advertisers and “un-ban” services. [PR-P07]
When to escalate
Self-service requires one authorized owner, matched records, a clear branch, and no compromise or contract question. Escalate disputed authority, linked entities/accounts, suspected unauthorized activity, issuer/platform conflict, contract remedy, data exposure, or material amount to finance, fraud, procurement, legal, privacy, or security.
Use current account-/region-specific first-party routes for billing, payment, verification, or appeal; verify availability and eligibility. Synthesis/inference (RS-S03, PR-P11, PR-P12, PR-P15): authorized finance handles issuer/bank fraud/dispute; preserve issuer, contract, insurer, or legal deadlines. Promise no privileged access, faster review, reimbursement, credit, or favorable outcome; close only when criteria pass or residuals have owners/dates.
FAQ
Is a failed payment proof that the platform charged fraudulently?
No. It is an observed payment state. Synthesis/inference (PR-P09, PR-P18, RS-S07, RS-S08): compare platform, issuer, authorization, delivery, and agency records before classifying the charge.
Should I charge back an ad-platform transaction when campaigns did not deliver?
Not by default. Synthesis/inference (PR-P09, PR-P18, RS-S07, RS-S08): delivery and billing remain separate until matched. For Google Ads, reconcile transaction/authorization before the current route; a legitimate-balance chargeback can create suspension risk. [DRS-A07][PR-P11] Meta, TikTok, and issuer routes require current verification; dissatisfaction alone is not evidence.
What if the agency invoice and platform invoice do not match?
Synthesis/inference (RS-S03, RS-S09): Keep them separate. Match entity, account, period, media, fees, and contract; route contract-rights questions to finance, procurement, or counsel, not a platform dispute form.
Can platform-attributed conversions be used as revenue in the reconciliation?
Synthesis/inference (PR-P18, RS-S07, RS-S08): Report platform attribution separately. Revenue requires the business backend record, including qualification, cancellation, refund, or payment status; no platform report alone proves revenue or causal lift.
Are credits and refunds guaranteed after a billing interruption?
No. Eligibility and terms are provider- and contract-dependent. A refund and platform credit are different: record refund request, approval, and issuer settlement; record credit request, approval, posting, and application as non-cash value. Record only terms evidenced in the current account or contract; do not infer a remedy or timeline.
What is enough to close the billing incident?
Synthesis/inference (RS-S03, RS-S09, RS-S10, RS-S15): Match each amount, dispute it with authority, evidence a settled refund or posted/applied credit, or assign residual owner/date. A credit is not cash. Access, payment, delivery, attribution, settlement, and monitoring checks must pass.
Source appendix
All sources were accessed 2026-07-19.
| Key | Source title; author/publisher; publication date | URL | Supports and boundary |
|---|---|---|---|
| DRS-A07 | “How to dispute a Google Ads charge”; Google Ads Help; current/undated. | https://support.google.com/google-ads/answer/10560092 | Google-specific reconcile-before-dispute; suspension-risk warning; no outcome. |
| PR-P07 | “Meta Takes Legal Action Against Scam Advertisers”; Meta Newsroom; Meta; 2026-02-26. | https://about.fb.com/news/2026/02/meta-takes-legal-action-against-scam-advertisers/ | Anti-evasion posture; not an individual finding. |
| PR-P09 | “History | Google Ads Status Dashboard”; Google; live/undated. | https://ads.google.com/status/publisher/summary | Live status signal; not account-level proof. |
| PR-P11 | “Billing and payment suspensions”; Google Ads Help; current/undated. | https://support.google.com/adspolicy/answer/13704200?hl=en | Google payment states/suspension risk; no remedy promise. |
| PR-P12 | “Secure your Google Ads account: Introduction”; Google Ads Help; current/undated. | https://support.google.com/google-ads/answer/2375456 | Google security route; not retention/compromise proof. |
| PR-P15 | “About transaction-related appeals”; TikTok for Business; updated July 2026. | https://ads.tiktok.com/help/article/about-transaction-related-appeals | TikTok transaction states; eligibility varies; no timing. |
| PR-P18 | “Google Ads Experiencing Outage Impacting Key Features [Updated]”; Matt G. Southern, Search Engine Journal; 2024-08-01, updated 2024-09-19. | https://www.searchenginejournal.com/google-ads-experiencing-outage-impacting-key-features/523624/ | Specific 2024 secondary incident; not universal billing/revenue proof. |
| RS-S03 | “Cybersecurity Incident & Vulnerability Response Playbooks”; CISA; 2021 (PDF served from 2024 path). | https://www.cisa.gov/sites/default/files/2024-08/Federal_Government_Cybersecurity_Incident_and_Vulnerability_Response_Playbooks_508C.pdf | Roles/evidence/recovery; federal thresholds do not transfer. |
| RS-S07 | “Monitoring Distributed Systems”; Rob Ewaschuk, editor Betsy Beyer, Google SRE; 2017. | https://sre.google/sre-book/monitoring-distributed-systems/ | Monitoring/symptom-cause; metrics are proxies. |
| RS-S08 | “Service Level Objectives”; Chris Jones, John Wilkes, Niall Murphy, Cody Smith, Google SRE; 2017. | https://sre.google/sre-book/service-level-objectives/ | Internal objectives; no platform/revenue SLA. |
| RS-S09 | “Managing Incidents”; Andrew Stribblehill, Google SRE; 2017. | https://sre.google/sre-book/managing-incidents/ | Incident roles/controlled changes; no AdsInfra staffing. |
| RS-S10 | “Postmortem Culture: Learning from Failure”; John Lunney and Sue Lueder, Google SRE; 2017. | https://sre.google/sre-book/postmortem-culture/ | Postmortems/tested follow-up; no ad benchmark. |
| RS-S15 | “How Good is Your Data? Investigating the Quality of Data Generated During Security Incident Response Investigations”; George Grispos, William Bradley Glisson, Tim Storer; arXiv; 2019-01-11. | https://arxiv.org/abs/1901.03723 | Incident data-quality limits; not ad prevalence. |
Before-acting scope checks
| Route or issue | Public boundary |
|---|---|
| Meta billing, failed-payment, and unauthorized-activity routes | Before acting, an authorized owner should check the current first-party route for the affected account, entity, and region; labels and eligibility vary. |
| Google billing, charge-dispute, compromised-account, manager-access, and related-account routes | Before acting, an authorized owner should check the current first-party route for the affected account and region; requirements vary by issue. |
| TikTok transaction appeals, Account Health, and eligibility | Before acting, an authorized owner should check the current first-party route for the affected market, account type, and region; appeal eligibility varies. |
| Issuer/bank fraud and dispute route | Authorized finance should follow the issuer-specific process for the affected entity, currency, and transaction. |
| Refund, credit, and service-credit terms | Finance or procurement should verify current terms in the affected account and contract; no remedy or timeline is inferred. |
| Payment evidence handling | Keep full payment and authentication data out of worksheets and inbound contacts; use approved finance/payment systems. |
| Direct historical status objects | Verify the product-specific UTC scope and source directly before relying on a status observation. |
Related resources
- Google Ads Account Suspended for Billing — Fix GuideYour Google Ads account has been suspended due to a billing issue — failed payment, suspected fraud, or expired card. Here's how to identify the exact issue and get your account back.
- Facebook Business Account Hacked — Recovery GuideYour Facebook Business account has been hacked. Unauthorized campaigns are running, your budget is being drained, and your pages may have been transferred. Here's how to regain control immediately.
- TikTok Ads Not Delivering? Diagnose Zero ImpressionsTikTok ads approved but not delivering or spending? Check delivery status, billing, schedule, audience, bid, budget, and creative before making changes.
- Meta Pixel Not Firing — Troubleshooting GuideYour Meta Pixel is not firing or firing inconsistently. Here's how to diagnose the issue, fix broken tracking, and restore your conversion data and retargeting audiences.
Contact AdsInfra
Send a message about this resource before making a high-impact change.