要点
evidence collection、rule lookup、deterministic verification付きcalculation、routing、status monitoring、message draft、reconciliation checkをautomate可能。language modelだけでtransaction選択、不確かなlegal right解釈、fraud断定、未検証amount計算、destination変更、authority外approve、unknown response retry、reconciliation前success宣言をしない。
refund automationが安全に決められる範囲
safe automatic executionはverified requester/transaction、one applicable rule、deterministic amount、permitted action、current authority、supported rail、low-risk signal、conflict/disputeなし、recoverable failureの狭いintersection。「eligibleらしい」だけでは不足。
eligibility
validated legal/contract/policy/goodwill ruleがexact transaction/requestへactionを許すか。
authorization
current actorがaction、amount、currency、entity、exception versionをapprove/execute可能か。
completion
provider/internal record一致、dependent action完了、customer通知、exception ownerあり。
refund money移動前のdecision state
| state | evidence gate | allowed action |
|---|---|---|
| AUTO-ELIGIBLE | exact transaction、one rule、deterministic amount、authority、low risk | validated limit内execute |
| REVIEW | ambiguity、exception、high value、conflict、specialist trigger | human approve/change/reason付きdeny/escalate |
| HOLD | identity、destination、dispute、security、missing/conflicting evidence | money移動なし、保全・investigate |
| EXECUTING | approved version、idempotency、provider request/observed status | monitor、unknown response blind retry禁止 |
| RECONCILED | provider、ledger、tax、entitlement、inventory、notification整合 | closeまたはowned exception/reopen path |
refund request automationの10 rule
各ruleをrelease gateとして扱いrequired evidenceがcurrent、rule version既知、next ownerがfailure recovery可能な時だけ進行。
requester・transaction・authorityを検証
operating rule
eligibility判定前に正確なorder、invoice、charge、payer、account、merchant entity、currency、request channelを解決。requesterがbuyer、authorized representative、administrator、無関係contactかを不要なidentity dataを集めず確認。
evidence to retain
order_id、invoice_id、payment_id、payer/account match、merchant entity、currency、request provenance、representative authority、identity confidence、access restriction。
decision gate
ambiguous identity、multiple matching payment、account takeover indicator、authorityなしthird-party request、customer/payer/refund destination mismatchはHOLD。AIはcandidate提案のみ、都合よいtransactionを暗黙選択しない。
applicable policy・contract・product・jurisdictionをsnapshot
operating rule
現在defaultでなくtransaction/request時点のrule versionを評価。statutory right、contract commitment、goodwill policy、marketplace/subscription term、digital-content condition、product exception、regulator/card-network dutyを分離。
evidence to retain
policy/contract ID/version、effective date、sale channel、適法に分かるcustomer/merchant location、consumer/business classification、product/service type、delivery/performance state、exception evidence。
decision gate
一意でvalidatedなrule pathだけautomatic eligibility。conflicting term、regulated product、cross-border uncertainty、minor、accessibility barrier、classification dispute、legal-right questionはqualified human review。UK/EU例をglobal defaultにしない。
money移動前にrequested actionを分類
operating rule
capture前cancellation、void、full/partial refund、credit note、replacement、service correction、goodwill credit、payout/transfer reversal、chargeback responseのどれかを決定。accounting、inventory、entitlement、tax、provider、customer consequenceが異なる。
evidence to retain
payment lifecycle/capture/settlement state、fulfillment/consumption、return state、dispute state、prior credit、requested outcome、allowed action type、system-of-record owner。
decision gate
one authorized actionとdependencyを指定。顧客がrefundと言っただけで実行せずvoid/correction/replacement/dispute workflowが必要ならfinance/operations ownerへroute。
line-level evidenceからrefundable amountを計算
operating rule
gross amount、eligible line、quantity、fulfilled/consumed portion、discount、coupon、credit、gift value、standard/premium delivery、tax、fee、restocking rule、currency、rounding、prior adjustmentを再構成。formula/source valueを保存しlanguage modelの未検証算術に任せない。
evidence to retain
line item/quantity、price/tax/discount allocation、delivery method、return condition、consumed unit、prior refund/credit、currency/precision、calculation version、expected ledger entry。
decision gate
transaction/applicable ruleへreconcileしindependent arithmetic validation。negative、above-paid、cross-currency、zero/high-value、fee deduction、tax uncertainty、allocation conflictはreview。
state・idempotencyでduplicate executionを防止
operating rule
新action前に全systemのprior refund、credit、cancellation、dispute、manual adjustment、retry、webhookを確認。approved case/action versionからstable idempotency keyを予約しeligible amountをlock、異なるpayload replayを拒否。
evidence to retain
case/action version、idempotency key、prior refund/credit ID、available refundable balance、dispute state、lock owner/expiry、request/response hash、webhook event ID、retry history。
decision gate
one approvalからintended financial actionは最大一つ。timeout/unknown responseはprovider/ledger queryでreconcileしblind retry禁止。amount/destination/policy/approval変更はnew reviewed version。
fraud/security signalをscreenするが自動断罪しない
operating rule
permitted signalでaccount takeover、refund abuse、collusion、stolen instrument、return fraud、unusual velocity、manipulated evidenceを検出。signalはexecution制限/specialist review理由でありwrongdoing証明、customer accusation、unlimited retention許可ではない。
evidence to retain
signal source/time、rule/model version、reason code、confidence/known limitation、permitted device/account context、false-positive path、restricted evidence location、reviewer/expiry。
decision gate
low-riskもvalidated rule下のみ。material fraud/identity/security/discrimination/bias/adverse-actionはtrained human reviewとcontestable route。customer communicationはverified factのみでcontrolを漏らさない。
approval threshold・separation of dutiesを適用
operating rule
amount、cumulative exposure、customer/merchant risk、irreversible action、legal/regulatory trigger、exception type、precedent、available authorityでroute。必要時requester、evidence preparer、approver、executor、reconcilerを分離しself-approval/stale delegationを防止。
evidence to retain
approval matrix/version、amount/cumulative exposure、exception reason、initiator、approver role/delegation、conflict check、decision/rationale/time、expiry、second approval、execution authority。
decision gate
approverがexact version、amount、entity、currency、actionへcurrent authorityを持つ。high-value、novel、regulated、cross-border、manual-destination、policy exception、employee caseはlow-risk auto path不可。
correct payment railで実行しdestination changeを統制
operating rule
verified payment/provider objectへsupported refund operationでapproved amountを送る。必要/対応時original payment railを優先。chatでfull card credentialを求めず、別governed payout processなしにnew bank/wallet/cardへredirectしない。
evidence to retain
provider/account、payment/refund object ID、approved amount/currency、destination rule、API version、idempotency key、execution actor、request/response、provider status、next action、failure data。
decision gate
providerがapproved recordに紐づくone requestをacceptしcredential leakなくresponse保存。unsupported rail、manual bank detail、split-platform liability、connected account、charge dispute、destination change、requires_actionはspecialist procedure。
initiated・pending・completed・failedを正確にcommunicate
operating rule
approved action、amount/currency、安全なdestination description、action time、current provider state、realistic next update、referenceを伝える。API request acceptedだけで「refunded」と言わない。pending/requires_action/failed/canceled/succeeded別message。
evidence to retain
approved response version、amount/currency、safe destination descriptor、provider status/timestamp、non-guaranteed timing basis、delivery state、reference、next update、failure/action instruction。
decision gate
wordingがobserved stateと一致しarrival dateをguaranteeしない。delivery/refund failureはowned follow-up。sensitive provider data redaction、accessibility/language対応、state変更はhistory編集でなくcorrection message。
finance・entitlement・inventory・customer outcomeをreconcile
operating rule
provider success eventだけでbusiness recovery完了ではない。refund/balance transactionをledgerへreconcileしapproved actionが必要とするinvoice、tax、revenue、commission、inventory、entitlement、subscription、fulfillment、vendor payout、analyticsだけを調整。customer delivery確認とreopen condition保全。
evidence to retain
provider final state、balance transaction、GL/subledger entry、credit note/tax record、entitlement/inventory change、commission/vendor effect、customer confirmation、residual balance、exception/reopen owner。
decision gate
provider/internal record一致、dependent action完了、customer通知、orphan exceptionなしでclose。pending、failed、disputed、mismatch、over-refund、unreturned、entitlement conflictはopen。denominator付き集計とfalse approval/denial review。
実例:「full refund」がduplicate recoveryになる
顧客がUSD 1,200 annual subscriptionのfull refundを要求しunauthorized chargeと申告。浅いsystemはinvoice totalを選び即full refund提案するがcontrolled workflowは停止。
- payment解決。 similar invoiceが二つ、payment reference一致は一つ。requesterはauthorized billing administratorだがcardholderではない。
- prior recovery再構成。 matched invoiceにはUSD 300 service creditとopen card dispute。USD 1,200 refundはavailable balance超過またはprovider rule次第でduplicate recovery。
- allegationとactionを分離。 unauthorizedはsecurity/payment specialist reviewをtriggerするがfraud accusation/refund reasonへ自動変換しない。
- valid pathを計算・approve。 financeがcredit、dispute、tax、refundable balanceをreconcile。authorized reviewerがdispute待機、correct residual refund、他permitted remedyを選択。
- observed stateを伝える。 verified invoice reference、current review state、next update、dispute-safe contact routeを伝えfalse completed messageを送らない。
refund automationの運用・test
rule ownership
consumer right、contract、tax、fraud/security、payment provider、finance、entitlement、inventory、customer communication、exception recoveryへowner、effective date/approval limitをversion。
test matrix
full、partial、multi-line、tax-inclusive、discount、mixed-currency、prior credit、disputed、failed、pending、requires_action、destination change、connected account、duplicate、late eventをtest。
outcome review
false approval/denial、amount correction、duplicate attempt、unknown-state recovery、provider failure、ledger mismatch、notification error、reopen rate、time by state、unresolved exceptionをdenominator付き測定。
minimum auditable record
case_id · request_source · requester_authority · order_id · invoice_id · payment_id · merchant_entity · jurisdiction_basis · policy_contract_version · eligibility_path · payment_state · refundable_balance · calculation_inputs · amount_currency · risk_signals · decision_state · owner · approval_version · idempotency_key · provider_request_response · refund_status · ledger_entries · dependent_actions · customer_message · delivery_state · exception · reopen_state · retention_event
OpenMaxによるrefund operation coordination
OpenMaxはcase、CRM、order、billing、payment、policy、risk、approval、communication、ledgerを接続、permitted evidence収集、decision state提案、deterministic calculator/rule service、authorized approval route、approved versionのみexecute、provider event monitor、reconciliation exception作成。least privilege、raw credentialをprompt/logへ入れない。
financial・legal・privacy・customer-harm boundary
- one country refund window、provider status model、internal goodwill ruleをuniversal customer rightにしない。
- tokenized referenceで足りる場合full card credential収集、bank/dispute data開示、sensitive payment evidenceのmodel prompt投入禁止。
- ambiguous right、fraud/security、high value、irreversible/manual destination、cross-border、regulated、employee、precedent、complaintはhuman review。
- deterministic money arithmetic、bounded input、versioned rule、separation of duties、idempotency、state machine、reconciliationを使用。fluent explanationはfinancial controlでない。
- fraud自動断定、right waive、statutory remedy deny、payout destination change、evidence destroy、unresolved refund close禁止。
よくある質問
AIはrefundをauto-approve可能?
exact identity/transaction、one applicable rule、deterministic amount、current authority、supported execution、low risk、idempotency、recoveryのnarrow validated pathのみ。exceptionは人。
provider succeededだけでclose?
いいえ。provider/ledger、tax/entitlement/inventory、customer notification、exceptionをreconcile。
new bank accountへrefund?
ordinary automated path不可。destination changeは別governed identity、fraud、payout、legal、approval control。
AIはpartial refund計算可能?
input assemble/formula説明は可能だがdeterministic decimal/currency logicがsource record/ruleに対し計算・validate。
provider response timeout?
unknown stateを保持、same idempotency/referenceでquery、webhook/ledger eventをreconcileしfresh refundをblind作成しない。
OpenMaxの役割?
evidence、rule、calculator、routing、approval、provider action、status、communication、reconciliationをorchestrateしconsequential financial/legal decisionは人。
情報源、編集方法、制限
OpenMax編集部はUK/EU公式consumer return guidance、one provider implementation例としてStripe refund-state docs、human-AI accountabilityのNIST AI RMFを確認し独自10-rule general-business workflow、state model、control、duplicate-recovery caseを作成。2026年9月3日再確認。legal/tax/accounting/fraud/payment-network/provider adviceではない。
- GOV.UK — Accepting returns and giving refunds
- Your Europe — Consumer shopping rights
- Stripe Docs — Refund object and states
- NIST — AI Risk Management Framework

