Network Programs Reference
This page is the numbers for VAMP, ECM, HECM and EFM: the thresholds, what breaching costs, and how to get out. Looking for what the email means or remediation plans?
The network on the letterhead narrows it fast: VAMP is Visa's, and ECM, HECM and EFM are all Mastercard's.
- Visa VAMP: 1.5% merchant excessive since 1 April 2026 (2.2% in CEMEA only), on a minimum of 1,500 fraud reports and disputes combined. Fraud and disputes land in the same number
- Mastercard ECM: 100-299 chargebacks AND a 1.50%-2.99% ratio. HECM is 300+ AND 3.00%+. You have to breach the count and the ratio together. One on its own does nothing
- The two networks divide differently. Mastercard puts this month's chargebacks over last month's transactions. Visa uses the same calendar month for both. Growing fast? The Mastercard number runs hotter
- Mastercard SMMP: live since 24 July 2026. Refunds plus chargebacks over 5% can start a 72-hour acquirer investigation. Only in your first six months, though, and only at 500+ transactions. No fines, no ratio you can look up
- MATCH: a 5-year listing. It isn't a legal ban. But ordinary acquirers won't board you while you're on it, and the ones that will want 5-10% and a fat reserve
- Safe zone: under 0.9% on Visa, under 100 chargebacks and under 1.5% on Mastercard. Getting out takes three consecutive months under the line plus a remediation plan
Processor just named a program at you? Sitting at 0.9% and want to know where the lines fall? This is the cheat sheet. One thing first. Neither network publishes these numbers. Every figure here, ours included, reached the public through an acquirer.
For the deep version, see Dispute Monitoring Programs.
Visa VAMP (Visa's chargeback and fraud monitoring program)
Live since April 2025. It folded the old VDMP and VFMP together, so fraud reports and disputes now land in one ratio instead of two.
Visa retired four programs into VAMP on 1 April 2025, not two. VDMP, VFMP, DGMFM and VFMP-3DS.
VFMP-3DS was the US-only track that measured fraud on your Visa Secure traffic on its own. The penalty was the sharp part: while you were in it, you lost the 3DS liability shift. You'd done the authentication and still carried the fraud.
It's dead. Fraud on authenticated transactions now just lands in the single VAMP ratio like everything else. Reported thresholds while it ran were 0.5% and $5,000 of fraud for early warning, 0.75% and $7,500 for the standard program. Those come from vendor write-ups, and the vendors don't agree with each other on whether fines ever applied. Visa published none of it. REPORTED
Why it's worth knowing: a fraud vendor quoting VFMP-3DS at you is selling against a program that closed over a year ago.
Current Thresholds
Last verified: 1 August 2026.
| Threshold | Ratio | Volume Minimum |
|---|---|---|
| Merchant Non-Compliant | 0.5% | 5 |
| Merchant Excessive | 1.5% since 1 April 2026 (2.2% in CEMEA only) | 1,500 combined fraud reports + disputes. CEMEA is 150 events and US$75,000 in value |
| Acquirer Above Standard | 0.5% (portfolio level), since 1 June 2025 | Same as merchant excessive: 1,500 combined fraud reports + disputes, or 150 and US$75,000 in CEMEA |
| Acquirer Excessive | 0.7% (portfolio level), since 1 June 2025 | Same as above standard |
| Enumeration | 20% | 300,000 |
The CEMEA row has two tests, not one. A CEMEA merchant needs 150 combined fraud reports and disputes. And US$75,000 of value in them. Only then does the 2.2% ratio do anything. The count alone isn't enough. Most summaries drop the dollar half.
A threshold and a fee are two different events. Both acquirer lines, 0.5% and 0.7%, have run since 1 June 2025. That's off Visa's own VAMP overview. The US$4 charge at the above-standard tier didn't start until 1 January 2026. Plenty of summaries print 1 January 2026 as the date the 0.5% threshold appeared. It isn't. The threshold was already seven months old.
0.5% is the line you'll cross first. Watch it. It isn't automatically a fee event, though. Visa applies the merchant thresholds only when your acquirer isn't already in Above Standard or Excessive. And the $8 per-dispute charge at 0.5% lands when your acquirer's whole portfolio has breached Excessive. Stripe's wording catches the difference. Visa may assess at non-compliant. It assesses at excessive. So 0.5% puts you on your acquirer's watch list. 0.9% is where most processors act for their own reasons. 1.5% is the number that gets you named.
Visa doesn't publish VAMP thresholds publicly. Visa Core Rules 10.4.3.1 defers entirely to the VAMP Guide. That guide goes to acquirers, not merchants. Section 12.5.4 of the public rules, "Dispute Monitoring Fees and Non-Compliance Assessments", is a printed heading with nothing under it.
So every VAMP figure you find online, this page included, comes from acquirer-facing summaries. Not from a citable Visa document. The figures above match Stripe's published documentation. They hold up across several independent acquirer sources too. That's the strongest evidence available. It still isn't a primary source.
Mastercard is only slightly better. "ECM" appears four times in the 503 pages of the public Mastercard Rules (2 June 2026 edition). Only one of those is an operative rule: section 5.11.4, on address verification at automated fuel dispensers. The rest point at a Connect-only manual. "HECM" doesn't appear at all. Neither acronym is ever attached to a number.
What to do about it: ask your acquirer for your current ratio, the thresholds they apply to you, and which transactions land in the denominator. Their internal threshold is usually stricter than the network's. And theirs is the one that gets you offboarded.
What Counts in VAMP
| Component | Counts? | Notes |
|---|---|---|
| TC40 (fraud reports) | Yes | Counts even if no chargeback |
| TC15 (chargebacks) | Yes | Standard disputes |
| Fraud + chargeback same transaction | Effectively 2x | Double impact |
| RDR-resolved disputes | TC15 excluded | TC40 may still count |
| CE 3.0 qualified | Both excluded | Best protection |
Fee Structure
Last verified: 1 August 2026.
| Level | Per-Dispute Fee |
|---|---|
| Merchant Excessive | US$8 per CNP dispute, passed through by your acquirer |
| Acquirer Above Standard (0.5% portfolio) | US$4 per dispute, from 1 January 2026 |
| Acquirer Excessive (0.7% portfolio), on disputes at merchants whose own ratio is 0.5% or higher | US$8 per dispute |
These are flat amounts, not the ranges most summary pages circulate. And the $8 doesn't hit every dispute in an excessive acquirer's book. Only the ones at merchants sitting at 0.5% or above themselves. REPORTED
The fees come from Checkout.com's acquirer notice dated 12 June 2026, corroborated by Antom. They do not come from Visa. Visa's own VAMP fact sheet is a single page, created 14 May 2026. It carries the ratios and count minimums above. It carries no fee figure of any kind. Neither does the public rulebook. Watch which fact sheet you open. Visa hosts two at near-identical URLs, both stamped 2025 on their faces, and the earlier one still prints 220 bps and a 1,000 count. Several vendor pages link to the stale one, Stripe's included. If you see these amounts attributed to a Visa document, ask which one. NOT PUBLISHED
Your acquirer decides how much of its portfolio fee to pass down. Nothing in the rules stops it passing down more than it pays. Ask what your per-dispute pass-through is before you're in a program, not after.
Timeline and Remediation
| Event | Deadline |
|---|---|
| Identification notice | Month after breach. That month is program month 1 |
| Remediation plan required | 15 days from notice |
| Grace period | Program months 1, 2 and 3. First identification in a rolling 12 months only |
| First fee | Program month 4 |
| Exit criteria | Below threshold 3 consecutive months |
Count in program months, not calendar months. The breach happens in one calendar month and the notice lands in the next, so the two counters sit a month apart. That gap is where most published VAMP timelines go wrong. Grace runs program months 1 to 3. The first fee lands in program month 4.
Visa MERP (Merchant Elevated Risk Program)
Asia Pacific only. Effective 9 April 2026. Selling into AP through an AP acquirer? This one can reach you. Everywhere else, skip it.
MERP isn't a ratio program. Visa identifies a merchant showing "unusual activity" and can then require the acquirer, or you, to deploy remediation tools or technologies. There's no published number to stay under, because the criteria sit in the Merchant Elevated Risk Program Guide. That guide goes to acquirers. Same pattern as VAMP.
| Event | Assessment on your acquirer |
|---|---|
| First identification | USD 25,000 |
| Repeat identification, same acquirer | USD 50,000 |
| Continued non-compliance after that | Monthly assessments, then risk reduction requirements |
Those amounts are unusual: they're published, in Visa's public rulebook, at Table 12-6. The thresholds that trigger them aren't. So Visa will tell you what it costs and not what sets it off.
The assessment lands on the acquirer, not on you. That doesn't help much. An acquirer facing USD 25,000 has a cheaper option than paying it, and the cheaper option is offboarding you.
Source: Visa, Visa Core Rules and Visa Product and Service Rules, 18 April 2026, sections 10.4.4.4 and 12.5.8.1.
Mastercard ECM (Mastercard's chargeback monitoring program)
Two tiers, and you have to breach the count AND the ratio. One on its own doesn't put you in anything.
First, the umbrella name nobody uses
ECM, HECM and EFM aren't three loose programs. They all sit inside the Acquirer Chargeback Monitoring Program (ACMP). That's the name Mastercard's own rules use. Its Transaction Processing Rules (9 December 2025, section 5.4.1) refer to a merchant "identified for four months or more in the Acquirer Chargeback Monitoring Program (ACMP) as an Excessive Chargeback Merchant (ECM), a High Excessive Chargeback Merchant (HECM) and/or an Excessive Fraud Merchant (EFM)".
ACMP has no threshold of its own. No ACMP ratio, no ACMP fine. The ECM, HECM and EFM numbers below are the ACMP numbers. The acronym is worth knowing for one reason: your acquirer will use it in an email and expect you to follow.
One consequence is real and specific. It's also narrower than most summaries claim. Four of Mastercard's five subscription standards already bind every recurring merchant, in or out of any program. Disclose the terms up front and capture acceptance. Confirm the order electronically. Provide an online cancellation method, or clear cancel instructions. Send an advance reminder before any bill six months or more apart. Only the fifth is a recommendation: the receipt after each individual charge. Get identified in ACMP for four months or more in one audit period, as ECM, HECM or EFM, and that fifth one becomes a requirement too. Category A assessments then land on your acquirer for each month of noncompliance, on top of whatever ECM or HECM already costs. Not-for-profit and charity recurring merchants start with the whole list as recommendations. The same four-month trigger makes all five mandatory.
ECM Thresholds
You have to hit both:
| Level | Chargeback Count | Chargeback Ratio |
|---|---|---|
| ECM | 100-299 | 1.5% - 2.99% |
| HECM | 300+ | 3.0%+ |
Ratio Calculation
Mastercard Ratio = (First Presentment Chargebacks in Month N) / (Transactions in Month N-1) × 100
The denominator is last month's transactions, not this month's. Visa uses the same calendar month for both. That's why the same merchant can show two different ratios in one week. Growing fast? The Mastercard number runs hotter, because the denominator is a smaller month. This is the most commonly botched fact in the field. Check which month your acquirer is actually using. See Chargeback Metrics for the arithmetic.
The result is a percentage. Compare it against 1.5% (ECM) and 3.0% (HECM) directly.
ECM Fine Escalation
| Month in Program | Monthly Assessment |
|---|---|
| 1 | $0 (warning) |
| 2 | $1,000 |
| 3 | $1,000 |
| 4-6 | $5,000 |
| 7-11 | $25,000 |
| 12-18 | $50,000 |
| 19+ | $100,000 |
ECM carries no issuer recovery charge. That one belongs to HECM.
HECM Fine Escalation
| Month in Program | Monthly Assessment | Issuer Recovery Assessment |
|---|---|---|
| 1 | $0 (warning) | No |
| 2 | $1,000 | No |
| 3 | $2,000 | No |
| 4-6 | $10,000 | Yes |
| 7-11 | $50,000 | Yes |
| 12-18 | $100,000 | Yes |
| 19+ | $200,000 | Yes |
The Issuer Recovery Assessment is the HECM column, and only from program month 4. It isn't an ECM charge, whatever a summary page tells you. Mastercard collects it from your acquirer and pays it out to the issuers that ate the chargebacks. An issuer needs at least USD 20 owed to get anything. If nobody clears USD 20, the issuer carrying the most takes the whole pot. Two tied, and they split it. Source: Mastercard, Security Rules and Procedures - Merchant Edition, 3 February 2026, section 8.3.3.
So an issuer recovery line on your statement is a tier signal. It means HECM. Ask your acquirer which program you're actually in, because the fine ladder doubles between the two.
Exit Criteria
- Below ECM thresholds (< 100 chargebacks AND < 1.5% ratio) for 3 consecutive months
- Extension option: Suspends fines for 6 months during remediation
- If below thresholds at end: accrued fines forgiven
- If still above: all accrued fines become due
Mastercard EFM (Excessive Fraud Merchant)
A separate program on the fraud side, with its own thresholds and its own ladder. It runs alongside ECM, not instead of it. You can be in both at once.
EFM Enrollment Criteria
You have to hit all four:
| Criterion | Threshold |
|---|---|
| Monthly transactions | 1,000+ |
| Fraud claims amount | $50,000+ |
| Fraud-to-sales ratio | 0.50%+ |
| 3DS usage | < 50% in regulated markets, < 10% in non-regulated |
EFM Fine Escalation
| Month in Program | Monthly Assessment |
|---|---|
| 1 | $0 (warning) |
| 2 | $500 |
| 3 | $1,000 |
| 4-6 | $5,000 |
| 7-11 | $25,000 |
| 12-18 | $50,000 |
| 19+ | $100,000 |
EFM and ECM don't stack. A MID in both is assessed under EFM, and its ECM assessments are suspended. After 12 months in either, the higher of the two applies.
Exit Criteria
Below all thresholds for 3 consecutive months.
Mastercard SMMP (Scam Merchant Monitoring)
Live since 24 July 2026, on card-not-present merchants. SMMP isn't part of ACMP. It isn't a ratio program either. It's an obligation on your acquirer to open an investigation within 72 hours of a trigger. The only outcome is that Mastercard and Maestro acceptance stops. No fines, no ladder, no grace period.
| Trigger | Applies to | Detail |
|---|---|---|
| Authorization rate collapse | All in-scope merchants | 25+ purchase transactions in 72 hours, and approvals drop 50 points or fall below 30% |
| Refunds + chargebacks over 5% | First six months only | Rolling 30 days, and only at 500+ purchase transactions |
| Two issuers file fraud code 56 | First six months only | Code 56 is "Manipulation of Cardholder", filed by the issuer where you can't see it |
| GRIP letter, or an alert from a Merchant Monitoring Service Provider (MMSP) | All in-scope merchants | Comes from Mastercard or an approved monitoring vendor, not from your own numbers |
Refunds and chargebacks get added together. So refunding hard to hold your chargeback ratio down feeds the number this program watches. And that 5% trigger only applies in your first six months on Mastercard. Almost every summary drops that part.
→ Full detail: Scam Merchant Monitoring (SMMP)
The Global Merchant Audit Program has been suspended since 15 October 2020. Mastercard's current rules say so in one sentence. A vendor page or a sales call may tell you GMAP thresholds apply today, or that reason code 4849 is "the GMAP chargeback". Wrong on both counts. See Mastercard GMAP: Suspended Since 2020. It also covers the reported 2027 relaunch and why we can't confirm it.
MATCH List (Terminated Merchant File)
The industry blacklist. A 5-year listing. It isn't a legal ban on accepting cards. But ordinary acquirers won't board you while you're on it, and the high-risk shops that will want 5-10% and a heavy reserve.
MATCH Reason Codes
Eleven codes, not the fourteen most pages still print. Codes 02, 07 and 11 were removed in the 11 February 2025 edition. Code 06 read "Reserved for Future Use" until that same edition.
| Code | Reason | Trigger |
|---|---|---|
| 01 | Account Data Compromise | Cardholder data breach, including Common Point of Purchase |
| 03 | Transaction Laundering | Processing for someone else, against the merchant agreement |
| 04 | Excessive Chargebacks | Mastercard chargebacks over the previous three months above 1.5% of Mastercard sales transactions, and USD 5,000 or more in chargebacks. Amex-acquired merchants: whatever Amex decides, no published number |
| 05 | Excessive Fraud | Fraud-to-sales dollar volume 8% or greater over the previous three months, and 10 or more fraudulent transactions, and USD 5,000 or more |
| 06 | Coercion | Forced transactions |
| 08 | Mastercard Questionable Merchant Audit Program | Merchant audit violation |
| 09 | Liquidation/Insolvency | Insolvency |
| 10 | Violation of Standards | Network rules violation. No published number |
| 12 | PCI Data Security Standard Noncompliance | PCI DSS failure |
| 13 | Illegal Transactions | Illegal activity |
| 14 | Identity Theft | Merchant was identity theft victim |
Source: Mastercard, Security Rules and Procedures - Merchant Edition, 3 February 2026, section 11.14.1, Table 11.4, p.155. Codes 04 and 05 need every condition met, not any one of them.
The ratio isn't a trigger on its own. Termination is. Section 11.5 makes the listing mandatory within five calendar days once your acquirer terminates you while a code applies. Section 11.4 item 8 penalizes an acquirer who lists you under code 04 when you're under the floor.
MATCH Consequences
| Impact | Duration |
|---|---|
| Listing duration | 5 years, then automatic purge (11.10) |
| New merchant accounts | Nearly impossible in practice, though Mastercard states twice that an acquirer may still board a listed merchant |
| High-risk processors | May accept at 5-10%+ rates, 20%+ reserves |
| Removal | The merchant can request it (11.5.1), no lawyer required. The acquirer owes a response in 30 calendar days. Code 12 has a direct route to Mastercard |
Avoiding MATCH
- Respond to processor warnings immediately
- Submit and execute remediation plans
- Show month-over-month improvement
- If termination is inevitable, negotiate "voluntary exit" (no MATCH)
Prevention Tool Impact
How alerts and prevention tools affect program ratios:
| Tool | VAMP Impact | ECM Impact | Best For |
|---|---|---|---|
| RDR | Excludes TC15, TC40 may count | N/A (Visa only) | Ratio protection |
| CDRN | Excludes TC15 if refunded | N/A | Manual control |
| Ethoca | Prevents chargeback | Prevents chargeback | Mastercard focus |
| CE 3.0 | Can exclude both TC40 and TC15 | N/A | Best VAMP protection |
| Order Insight | Prevents dispute from filing | N/A | Upstream prevention |
| Consumer Clarity | Prevents dispute from filing | Prevents dispute | Upstream prevention |
Quick Reference: Safe Zones
Stay Safe
| Metric | Safe Threshold |
|---|---|
| Visa dispute ratio | < 0.9% (processor threshold) |
| Mastercard chargebacks | < 100/mo AND < 1.5% |
| Mastercard fraud ratio | < 0.50% |
0.9% isn't a Visa number. It's where most processors act for their own reasons. It's also the one that ends relationships. Visa's own first line is 0.5% non-compliant. 1.5% is the one that gets you named.
Danger Zone (Act Now)
| Metric | Danger Threshold |
|---|---|
| Visa dispute ratio | 0.9% - 1.5% (VAMP merchant excessive; 2.2% in CEMEA) |
| Mastercard chargebacks | Approaching 100 OR approaching 1.5% |
| Mastercard fraud ratio | Approaching 0.50% |
Breach (Crisis Mode)
| Metric | Breach Threshold |
|---|---|
| Visa VAMP ratio | > 1.5% (2.2% in CEMEA) |
| Mastercard ECM | 100-299 chargebacks AND 1.50%-2.99% |
| Mastercard HECM | 300+ chargebacks AND 3.00%+ |
Timeline: How Fast Things Escalate
Visa VAMP Timeline
Calendar month 1: You breach
Calendar month 2: Identification notice. Program month 1 starts
Remediation plan due 15 days later
Program months 1-3: Grace period, first identification only
Program month 4: Fees begin
Program month 7+: Termination risk climbs
Grace is three program months, not four, and it only applies to a first identification in a rolling 12 months. Breach again inside that window and there's no grace at all.
Mastercard ECM Timeline
Month 1: First month above threshold
Month 2: Identified as ECM. Program month 1, no assessment
Month 3: Program month 2, $1,000
Month 4: Program month 3, $1,000
Month 5+: Program month 4 and up, $5,000/month and climbing
Month 13+: Program month 12 and up, $50,000/month, termination likely
Only the first month in the program is free. The "warning period" a lot of summaries describe as months two and three is $1,000 a month.
Analyst Layer: Metrics to Track
Ratio alone tells you where you are. Distance-to-threshold tells you how much room is left. That's the number that decides whether you act this week or next quarter.
Distance Metrics
| Metric | Your Value | Threshold | Distance | Status |
|---|---|---|---|---|
| Visa dispute ratio | 0.72% | 0.90% (processor line, not VAMP's) | 0.18% | ⚠️ Watch |
| Mastercard CB ratio | 1.1% | 1.50% | 0.40% | ✓ Safe |
| Mastercard CB count | 65 | 100 | 35 | ⚠️ Watch |
| Mastercard fraud ratio | 0.25% | 0.50% | 0.25% | ✓ Safe |
Distance Alert Thresholds
| Distance to Threshold | Action |
|---|---|
| > 50% buffer | Monitor monthly |
| 25-50% buffer | Monitor weekly |
| 10-25% buffer | Monitor daily, prepare plan |
| < 10% buffer | Emergency mode, implement plan |
Calculating Distance
Distance % = (Threshold - Current) / Threshold × 100
Example:
- Current ratio: 0.72%
- Threshold: 0.90%
- Distance: (0.90 - 0.72) / 0.90 = 20%
At 20% distance you're in the 10-25% band. That means daily monitoring and a plan already drafted, not a weekly check-in.
Trend Projection
Track your trajectory:
| Week | Ratio | Week-over-Week Change | Projected at Trend |
|---|---|---|---|
| 1 | 0.60% | - | - |
| 2 | 0.65% | +0.05% | - |
| 3 | 0.72% | +0.07% | Breach in ~3 weeks |
| 4 | 0.71% | -0.01% | Stable |
If your trend shows breach within 4 weeks, act now.
Dashboard Requirements
Build a real-time dashboard showing:
- Current ratios vs thresholds (visual gauge)
- Distance to each threshold (percentage)
- Trend line (past 8 weeks)
- Projection (at current trend)
- Alert status (green/yellow/red)
Alert rules:
- Yellow: < 25% distance OR upward trend
- Red: < 10% distance OR projected breach < 4 weeks
Next Steps
Approaching threshold limits?
- Zero Point Nine Panic - Emergency response playbook
- Chargeback Alerts - Deploy RDR, Ethoca, CDRN fast
- Reduce Chargebacks Fast - Tactical intervention guide
Building monitoring dashboards?
- Monitoring Thresholds - Threshold detail by network
- Chargeback Metrics - Set up ratio tracking
- Dispute Monitoring Programs - Detailed program requirements
Been told a program applies to you and want to check?
- Scam Merchant Monitoring (SMMP) - Live since 24 July 2026, and refunds count
- Mastercard GMAP - Suspended since 2020, plus the reported 2027 version
- MATCH and the TMF - The listing that actually ends an account
Preventing program enrollment?
- Chargeback Prevention - Prevention hierarchy
- Winning Evidence - CE 3.0 for ratio protection
- 3D Secure - Fraud liability shift
Related Pages
- Dispute Monitoring Programs - Detailed VAMP, ECM coverage
- Scam Merchant Monitoring (SMMP) - The 72-hour acquirer investigation program
- Mastercard GMAP - Suspended since 2020, and the reported 2027 relaunch
- Monitoring Thresholds - Threshold detail
- Zero Point Nine Panic - Crisis playbook
- Chargeback Alerts - RDR, Ethoca, CDRN
- Winning Evidence - CE 3.0 requirements
- Reduce Chargebacks Fast - Emergency playbook
- Chargeback Prevention - Prevention hierarchy
- Chargeback Metrics - Ratio tracking
- 3D Secure - Fraud liability shift
- Processor Management - Acquirer relationships
- Holds and Reserves - Program consequences
- Chargeback Lifecycle - Full dispute flow