Skip to main content

Network Programs Reference

This page is the numbers for VAMP, ECM, HECM and EFM: the thresholds, what breaching costs, and how to get out. Looking for what the email means or remediation plans?

The network on the letterhead narrows it fast: VAMP is Visa's, and ECM, HECM and EFM are all Mastercard's.

TL;DR
  • Visa VAMP: 1.5% merchant excessive since 1 April 2026 (2.2% in CEMEA only), on a minimum of 1,500 fraud reports and disputes combined. Fraud and disputes land in the same number
  • Mastercard ECM: 100-299 chargebacks AND a 1.50%-2.99% ratio. HECM is 300+ AND 3.00%+. You have to breach the count and the ratio together. One on its own does nothing
  • The two networks divide differently. Mastercard puts this month's chargebacks over last month's transactions. Visa uses the same calendar month for both. Growing fast? The Mastercard number runs hotter
  • Mastercard SMMP: live since 24 July 2026. Refunds plus chargebacks over 5% can start a 72-hour acquirer investigation. Only in your first six months, though, and only at 500+ transactions. No fines, no ratio you can look up
  • MATCH: a 5-year listing. It isn't a legal ban. But ordinary acquirers won't board you while you're on it, and the ones that will want 5-10% and a fat reserve
  • Safe zone: under 0.9% on Visa, under 100 chargebacks and under 1.5% on Mastercard. Getting out takes three consecutive months under the line plus a remediation plan

Processor just named a program at you? Sitting at 0.9% and want to know where the lines fall? This is the cheat sheet. One thing first. Neither network publishes these numbers. Every figure here, ours included, reached the public through an acquirer.

For the deep version, see Dispute Monitoring Programs.

Visa VAMP (Visa's chargeback and fraud monitoring program)

Live since April 2025. It folded the old VDMP and VFMP together, so fraud reports and disputes now land in one ratio instead of two.

VFMP-3DS is gone too, and that one matters

Visa retired four programs into VAMP on 1 April 2025, not two. VDMP, VFMP, DGMFM and VFMP-3DS.

VFMP-3DS was the US-only track that measured fraud on your Visa Secure traffic on its own. The penalty was the sharp part: while you were in it, you lost the 3DS liability shift. You'd done the authentication and still carried the fraud.

It's dead. Fraud on authenticated transactions now just lands in the single VAMP ratio like everything else. Reported thresholds while it ran were 0.5% and $5,000 of fraud for early warning, 0.75% and $7,500 for the standard program. Those come from vendor write-ups, and the vendors don't agree with each other on whether fines ever applied. Visa published none of it. REPORTED

Why it's worth knowing: a fraud vendor quoting VFMP-3DS at you is selling against a program that closed over a year ago.

Current Thresholds

Last verified: 1 August 2026.

ThresholdRatioVolume Minimum
Merchant Non-Compliant0.5%5
Merchant Excessive1.5% since 1 April 2026 (2.2% in CEMEA only)1,500 combined fraud reports + disputes. CEMEA is 150 events and US$75,000 in value
Acquirer Above Standard0.5% (portfolio level), since 1 June 2025Same as merchant excessive: 1,500 combined fraud reports + disputes, or 150 and US$75,000 in CEMEA
Acquirer Excessive0.7% (portfolio level), since 1 June 2025Same as above standard
Enumeration20%300,000

The CEMEA row has two tests, not one. A CEMEA merchant needs 150 combined fraud reports and disputes. And US$75,000 of value in them. Only then does the 2.2% ratio do anything. The count alone isn't enough. Most summaries drop the dollar half.

A threshold and a fee are two different events. Both acquirer lines, 0.5% and 0.7%, have run since 1 June 2025. That's off Visa's own VAMP overview. The US$4 charge at the above-standard tier didn't start until 1 January 2026. Plenty of summaries print 1 January 2026 as the date the 0.5% threshold appeared. It isn't. The threshold was already seven months old.

0.5% is the line you'll cross first. Watch it. It isn't automatically a fee event, though. Visa applies the merchant thresholds only when your acquirer isn't already in Above Standard or Excessive. And the $8 per-dispute charge at 0.5% lands when your acquirer's whole portfolio has breached Excessive. Stripe's wording catches the difference. Visa may assess at non-compliant. It assesses at excessive. So 0.5% puts you on your acquirer's watch list. 0.9% is where most processors act for their own reasons. 1.5% is the number that gets you named.

Where these numbers come from, and why you should still ask your acquirer

Visa doesn't publish VAMP thresholds publicly. Visa Core Rules 10.4.3.1 defers entirely to the VAMP Guide. That guide goes to acquirers, not merchants. Section 12.5.4 of the public rules, "Dispute Monitoring Fees and Non-Compliance Assessments", is a printed heading with nothing under it.

So every VAMP figure you find online, this page included, comes from acquirer-facing summaries. Not from a citable Visa document. The figures above match Stripe's published documentation. They hold up across several independent acquirer sources too. That's the strongest evidence available. It still isn't a primary source.

Mastercard is only slightly better. "ECM" appears four times in the 503 pages of the public Mastercard Rules (2 June 2026 edition). Only one of those is an operative rule: section 5.11.4, on address verification at automated fuel dispensers. The rest point at a Connect-only manual. "HECM" doesn't appear at all. Neither acronym is ever attached to a number.

What to do about it: ask your acquirer for your current ratio, the thresholds they apply to you, and which transactions land in the denominator. Their internal threshold is usually stricter than the network's. And theirs is the one that gets you offboarded.

What Counts in VAMP

ComponentCounts?Notes
TC40 (fraud reports)YesCounts even if no chargeback
TC15 (chargebacks)YesStandard disputes
Fraud + chargeback same transactionEffectively 2xDouble impact
RDR-resolved disputesTC15 excludedTC40 may still count
CE 3.0 qualifiedBoth excludedBest protection

Fee Structure

Last verified: 1 August 2026.

LevelPer-Dispute Fee
Merchant ExcessiveUS$8 per CNP dispute, passed through by your acquirer
Acquirer Above Standard (0.5% portfolio)US$4 per dispute, from 1 January 2026
Acquirer Excessive (0.7% portfolio), on disputes at merchants whose own ratio is 0.5% or higherUS$8 per dispute

These are flat amounts, not the ranges most summary pages circulate. And the $8 doesn't hit every dispute in an excessive acquirer's book. Only the ones at merchants sitting at 0.5% or above themselves. REPORTED

The fees come from Checkout.com's acquirer notice dated 12 June 2026, corroborated by Antom. They do not come from Visa. Visa's own VAMP fact sheet is a single page, created 14 May 2026. It carries the ratios and count minimums above. It carries no fee figure of any kind. Neither does the public rulebook. Watch which fact sheet you open. Visa hosts two at near-identical URLs, both stamped 2025 on their faces, and the earlier one still prints 220 bps and a 1,000 count. Several vendor pages link to the stale one, Stripe's included. If you see these amounts attributed to a Visa document, ask which one. NOT PUBLISHED

Your acquirer decides how much of its portfolio fee to pass down. Nothing in the rules stops it passing down more than it pays. Ask what your per-dispute pass-through is before you're in a program, not after.

Timeline and Remediation

EventDeadline
Identification noticeMonth after breach. That month is program month 1
Remediation plan required15 days from notice
Grace periodProgram months 1, 2 and 3. First identification in a rolling 12 months only
First feeProgram month 4
Exit criteriaBelow threshold 3 consecutive months

Count in program months, not calendar months. The breach happens in one calendar month and the notice lands in the next, so the two counters sit a month apart. That gap is where most published VAMP timelines go wrong. Grace runs program months 1 to 3. The first fee lands in program month 4.


Visa MERP (Merchant Elevated Risk Program)

Asia Pacific only. Effective 9 April 2026. Selling into AP through an AP acquirer? This one can reach you. Everywhere else, skip it.

MERP isn't a ratio program. Visa identifies a merchant showing "unusual activity" and can then require the acquirer, or you, to deploy remediation tools or technologies. There's no published number to stay under, because the criteria sit in the Merchant Elevated Risk Program Guide. That guide goes to acquirers. Same pattern as VAMP.

EventAssessment on your acquirer
First identificationUSD 25,000
Repeat identification, same acquirerUSD 50,000
Continued non-compliance after thatMonthly assessments, then risk reduction requirements

Those amounts are unusual: they're published, in Visa's public rulebook, at Table 12-6. The thresholds that trigger them aren't. So Visa will tell you what it costs and not what sets it off.

The assessment lands on the acquirer, not on you. That doesn't help much. An acquirer facing USD 25,000 has a cheaper option than paying it, and the cheaper option is offboarding you.

Source: Visa, Visa Core Rules and Visa Product and Service Rules, 18 April 2026, sections 10.4.4.4 and 12.5.8.1.


Mastercard ECM (Mastercard's chargeback monitoring program)

Two tiers, and you have to breach the count AND the ratio. One on its own doesn't put you in anything.

First, the umbrella name nobody uses

ECM, HECM and EFM aren't three loose programs. They all sit inside the Acquirer Chargeback Monitoring Program (ACMP). That's the name Mastercard's own rules use. Its Transaction Processing Rules (9 December 2025, section 5.4.1) refer to a merchant "identified for four months or more in the Acquirer Chargeback Monitoring Program (ACMP) as an Excessive Chargeback Merchant (ECM), a High Excessive Chargeback Merchant (HECM) and/or an Excessive Fraud Merchant (EFM)".

ACMP has no threshold of its own. No ACMP ratio, no ACMP fine. The ECM, HECM and EFM numbers below are the ACMP numbers. The acronym is worth knowing for one reason: your acquirer will use it in an email and expect you to follow.

One consequence is real and specific. It's also narrower than most summaries claim. Four of Mastercard's five subscription standards already bind every recurring merchant, in or out of any program. Disclose the terms up front and capture acceptance. Confirm the order electronically. Provide an online cancellation method, or clear cancel instructions. Send an advance reminder before any bill six months or more apart. Only the fifth is a recommendation: the receipt after each individual charge. Get identified in ACMP for four months or more in one audit period, as ECM, HECM or EFM, and that fifth one becomes a requirement too. Category A assessments then land on your acquirer for each month of noncompliance, on top of whatever ECM or HECM already costs. Not-for-profit and charity recurring merchants start with the whole list as recommendations. The same four-month trigger makes all five mandatory.

ECM Thresholds

You have to hit both:

LevelChargeback CountChargeback Ratio
ECM100-2991.5% - 2.99%
HECM300+3.0%+

Ratio Calculation

Mastercard Ratio = (First Presentment Chargebacks in Month N) / (Transactions in Month N-1) × 100

The denominator is last month's transactions, not this month's. Visa uses the same calendar month for both. That's why the same merchant can show two different ratios in one week. Growing fast? The Mastercard number runs hotter, because the denominator is a smaller month. This is the most commonly botched fact in the field. Check which month your acquirer is actually using. See Chargeback Metrics for the arithmetic.

The result is a percentage. Compare it against 1.5% (ECM) and 3.0% (HECM) directly.

ECM Fine Escalation

Month in ProgramMonthly Assessment
1$0 (warning)
2$1,000
3$1,000
4-6$5,000
7-11$25,000
12-18$50,000
19+$100,000

ECM carries no issuer recovery charge. That one belongs to HECM.

HECM Fine Escalation

Month in ProgramMonthly AssessmentIssuer Recovery Assessment
1$0 (warning)No
2$1,000No
3$2,000No
4-6$10,000Yes
7-11$50,000Yes
12-18$100,000Yes
19+$200,000Yes

The Issuer Recovery Assessment is the HECM column, and only from program month 4. It isn't an ECM charge, whatever a summary page tells you. Mastercard collects it from your acquirer and pays it out to the issuers that ate the chargebacks. An issuer needs at least USD 20 owed to get anything. If nobody clears USD 20, the issuer carrying the most takes the whole pot. Two tied, and they split it. Source: Mastercard, Security Rules and Procedures - Merchant Edition, 3 February 2026, section 8.3.3.

So an issuer recovery line on your statement is a tier signal. It means HECM. Ask your acquirer which program you're actually in, because the fine ladder doubles between the two.

Exit Criteria

  • Below ECM thresholds (< 100 chargebacks AND < 1.5% ratio) for 3 consecutive months
  • Extension option: Suspends fines for 6 months during remediation
    • If below thresholds at end: accrued fines forgiven
    • If still above: all accrued fines become due

Mastercard EFM (Excessive Fraud Merchant)

A separate program on the fraud side, with its own thresholds and its own ladder. It runs alongside ECM, not instead of it. You can be in both at once.

EFM Enrollment Criteria

You have to hit all four:

CriterionThreshold
Monthly transactions1,000+
Fraud claims amount$50,000+
Fraud-to-sales ratio0.50%+
3DS usage< 50% in regulated markets, < 10% in non-regulated

EFM Fine Escalation

Month in ProgramMonthly Assessment
1$0 (warning)
2$500
3$1,000
4-6$5,000
7-11$25,000
12-18$50,000
19+$100,000

EFM and ECM don't stack. A MID in both is assessed under EFM, and its ECM assessments are suspended. After 12 months in either, the higher of the two applies.

Exit Criteria

Below all thresholds for 3 consecutive months.


Mastercard SMMP (Scam Merchant Monitoring)

Live since 24 July 2026, on card-not-present merchants. SMMP isn't part of ACMP. It isn't a ratio program either. It's an obligation on your acquirer to open an investigation within 72 hours of a trigger. The only outcome is that Mastercard and Maestro acceptance stops. No fines, no ladder, no grace period.

TriggerApplies toDetail
Authorization rate collapseAll in-scope merchants25+ purchase transactions in 72 hours, and approvals drop 50 points or fall below 30%
Refunds + chargebacks over 5%First six months onlyRolling 30 days, and only at 500+ purchase transactions
Two issuers file fraud code 56First six months onlyCode 56 is "Manipulation of Cardholder", filed by the issuer where you can't see it
GRIP letter, or an alert from a Merchant Monitoring Service Provider (MMSP)All in-scope merchantsComes from Mastercard or an approved monitoring vendor, not from your own numbers

Refunds and chargebacks get added together. So refunding hard to hold your chargeback ratio down feeds the number this program watches. And that 5% trigger only applies in your first six months on Mastercard. Almost every summary drops that part.

→ Full detail: Scam Merchant Monitoring (SMMP)

What about GMAP?

The Global Merchant Audit Program has been suspended since 15 October 2020. Mastercard's current rules say so in one sentence. A vendor page or a sales call may tell you GMAP thresholds apply today, or that reason code 4849 is "the GMAP chargeback". Wrong on both counts. See Mastercard GMAP: Suspended Since 2020. It also covers the reported 2027 relaunch and why we can't confirm it.


MATCH List (Terminated Merchant File)

The industry blacklist. A 5-year listing. It isn't a legal ban on accepting cards. But ordinary acquirers won't board you while you're on it, and the high-risk shops that will want 5-10% and a heavy reserve.

MATCH Reason Codes

Eleven codes, not the fourteen most pages still print. Codes 02, 07 and 11 were removed in the 11 February 2025 edition. Code 06 read "Reserved for Future Use" until that same edition.

CodeReasonTrigger
01Account Data CompromiseCardholder data breach, including Common Point of Purchase
03Transaction LaunderingProcessing for someone else, against the merchant agreement
04Excessive ChargebacksMastercard chargebacks over the previous three months above 1.5% of Mastercard sales transactions, and USD 5,000 or more in chargebacks. Amex-acquired merchants: whatever Amex decides, no published number
05Excessive FraudFraud-to-sales dollar volume 8% or greater over the previous three months, and 10 or more fraudulent transactions, and USD 5,000 or more
06CoercionForced transactions
08Mastercard Questionable Merchant Audit ProgramMerchant audit violation
09Liquidation/InsolvencyInsolvency
10Violation of StandardsNetwork rules violation. No published number
12PCI Data Security Standard NoncompliancePCI DSS failure
13Illegal TransactionsIllegal activity
14Identity TheftMerchant was identity theft victim

Source: Mastercard, Security Rules and Procedures - Merchant Edition, 3 February 2026, section 11.14.1, Table 11.4, p.155. Codes 04 and 05 need every condition met, not any one of them.

The ratio isn't a trigger on its own. Termination is. Section 11.5 makes the listing mandatory within five calendar days once your acquirer terminates you while a code applies. Section 11.4 item 8 penalizes an acquirer who lists you under code 04 when you're under the floor.

MATCH Consequences

ImpactDuration
Listing duration5 years, then automatic purge (11.10)
New merchant accountsNearly impossible in practice, though Mastercard states twice that an acquirer may still board a listed merchant
High-risk processorsMay accept at 5-10%+ rates, 20%+ reserves
RemovalThe merchant can request it (11.5.1), no lawyer required. The acquirer owes a response in 30 calendar days. Code 12 has a direct route to Mastercard

Avoiding MATCH

  1. Respond to processor warnings immediately
  2. Submit and execute remediation plans
  3. Show month-over-month improvement
  4. If termination is inevitable, negotiate "voluntary exit" (no MATCH)

Prevention Tool Impact

How alerts and prevention tools affect program ratios:

ToolVAMP ImpactECM ImpactBest For
RDRExcludes TC15, TC40 may countN/A (Visa only)Ratio protection
CDRNExcludes TC15 if refundedN/AManual control
EthocaPrevents chargebackPrevents chargebackMastercard focus
CE 3.0Can exclude both TC40 and TC15N/ABest VAMP protection
Order InsightPrevents dispute from filingN/AUpstream prevention
Consumer ClarityPrevents dispute from filingPrevents disputeUpstream prevention

Quick Reference: Safe Zones

Stay Safe

MetricSafe Threshold
Visa dispute ratio< 0.9% (processor threshold)
Mastercard chargebacks< 100/mo AND < 1.5%
Mastercard fraud ratio< 0.50%

0.9% isn't a Visa number. It's where most processors act for their own reasons. It's also the one that ends relationships. Visa's own first line is 0.5% non-compliant. 1.5% is the one that gets you named.

Danger Zone (Act Now)

MetricDanger Threshold
Visa dispute ratio0.9% - 1.5% (VAMP merchant excessive; 2.2% in CEMEA)
Mastercard chargebacksApproaching 100 OR approaching 1.5%
Mastercard fraud ratioApproaching 0.50%

Breach (Crisis Mode)

MetricBreach Threshold
Visa VAMP ratio> 1.5% (2.2% in CEMEA)
Mastercard ECM100-299 chargebacks AND 1.50%-2.99%
Mastercard HECM300+ chargebacks AND 3.00%+

Timeline: How Fast Things Escalate

Visa VAMP Timeline

Calendar month 1: You breach
Calendar month 2: Identification notice. Program month 1 starts
Remediation plan due 15 days later
Program months 1-3: Grace period, first identification only
Program month 4: Fees begin
Program month 7+: Termination risk climbs

Grace is three program months, not four, and it only applies to a first identification in a rolling 12 months. Breach again inside that window and there's no grace at all.

Mastercard ECM Timeline

Month 1: First month above threshold
Month 2: Identified as ECM. Program month 1, no assessment
Month 3: Program month 2, $1,000
Month 4: Program month 3, $1,000
Month 5+: Program month 4 and up, $5,000/month and climbing
Month 13+: Program month 12 and up, $50,000/month, termination likely

Only the first month in the program is free. The "warning period" a lot of summaries describe as months two and three is $1,000 a month.


Analyst Layer: Metrics to Track

Ratio alone tells you where you are. Distance-to-threshold tells you how much room is left. That's the number that decides whether you act this week or next quarter.

Distance Metrics

MetricYour ValueThresholdDistanceStatus
Visa dispute ratio0.72%0.90% (processor line, not VAMP's)0.18%⚠️ Watch
Mastercard CB ratio1.1%1.50%0.40%✓ Safe
Mastercard CB count6510035⚠️ Watch
Mastercard fraud ratio0.25%0.50%0.25%✓ Safe

Distance Alert Thresholds

Distance to ThresholdAction
> 50% bufferMonitor monthly
25-50% bufferMonitor weekly
10-25% bufferMonitor daily, prepare plan
< 10% bufferEmergency mode, implement plan

Calculating Distance

Distance % = (Threshold - Current) / Threshold × 100

Example:

  • Current ratio: 0.72%
  • Threshold: 0.90%
  • Distance: (0.90 - 0.72) / 0.90 = 20%

At 20% distance you're in the 10-25% band. That means daily monitoring and a plan already drafted, not a weekly check-in.

Trend Projection

Track your trajectory:

WeekRatioWeek-over-Week ChangeProjected at Trend
10.60%--
20.65%+0.05%-
30.72%+0.07%Breach in ~3 weeks
40.71%-0.01%Stable

If your trend shows breach within 4 weeks, act now.

Dashboard Requirements

Build a real-time dashboard showing:

  1. Current ratios vs thresholds (visual gauge)
  2. Distance to each threshold (percentage)
  3. Trend line (past 8 weeks)
  4. Projection (at current trend)
  5. Alert status (green/yellow/red)

Alert rules:

  • Yellow: < 25% distance OR upward trend
  • Red: < 10% distance OR projected breach < 4 weeks

Next Steps

Approaching threshold limits?

  1. Zero Point Nine Panic - Emergency response playbook
  2. Chargeback Alerts - Deploy RDR, Ethoca, CDRN fast
  3. Reduce Chargebacks Fast - Tactical intervention guide

Building monitoring dashboards?

  1. Monitoring Thresholds - Threshold detail by network
  2. Chargeback Metrics - Set up ratio tracking
  3. Dispute Monitoring Programs - Detailed program requirements

Been told a program applies to you and want to check?

  1. Scam Merchant Monitoring (SMMP) - Live since 24 July 2026, and refunds count
  2. Mastercard GMAP - Suspended since 2020, plus the reported 2027 version
  3. MATCH and the TMF - The listing that actually ends an account

Preventing program enrollment?

  1. Chargeback Prevention - Prevention hierarchy
  2. Winning Evidence - CE 3.0 for ratio protection
  3. 3D Secure - Fraud liability shift