Mastercard Scam Merchant Monitoring (SMMP)
- Live since 24 July 2026, on card-not-present merchants. It's enforceable now, not a proposal.
- It's an acquirer obligation, not a merchant ratio. Your acquirer or payfac has to open an investigation within 72 hours of a trigger. You get no notice, no portal and no published appeal.
- Refunds count. The 5% trigger adds refunds and chargebacks together. Refund hard to protect your chargeback ratio and you build the exact number this program watches.
- That 5% trigger only applies in your first six months on Mastercard. And only if you did at least 500 purchase transactions in the 30-day window.
- No fines, no ladder, no grace period. The only outcome is that Mastercard and Maestro acceptance stops. So the goal is being easy to clear in 72 hours, not staying under a number.
- Every figure here is reported, not published. "SMMP" appears zero times in Mastercard's four current public rulebooks.
You just heard "SMMP" from your processor or a forum thread. You want to know if you're in trouble. For most established merchants, no. This is a screening program built for fake shops, subscription traps and investment fronts. Only one number in it could catch an ordinary business, and that one expires after your first six months on the network.
On this page
- What SMMP actually is
- The triggers, and the numbers attached to them
- Refunds count toward SMMP, and toward nothing else
- The 72-hour window, and what your acquirer actually pulls
- What actually happens to a merchant
- Fraud code 56, and why one scam complaint counts three times
- How SMMP differs from ECM, HECM, EFM and VAMP
- Where these numbers come from
- Scale Callout
- Test to Run
- Where This Breaks
- Sources
- Next Steps
- See Also
The monthly ratio programs do apply to you forever. See Network Programs Reference.
SMMP carries no fine, no assessment ladder and no monthly ratio. Six months or more on Mastercard? The 5% combined refund-and-chargeback trigger doesn't touch you at all.
One trigger can still fire on your own numbers: an authorization approval rate collapse. Collapse means a 50 percentage point drop, or falling below 30% outright. That's a broken gateway or a fraud rule set to the wrong value. It isn't a bad week of trading. BIN attacks and processor outages are reported to be carved out entirely. Most legitimate small merchants run a combined refund-and-chargeback rate in the low single digits. They never come close.
What SMMP actually is
Mastercard's revision document is reportedly titled "Potential Scam Merchant Monitoring". The acronym SMMP comes from the trade press and from PSP blogs, not from Mastercard. Mastercard's own newsroom described the identical 72-hour duty on 19 May 2026. It used the umbrella brand "Merchant Trust Services" and never used the acronym once. Ask your acquirer about "SMMP" and you may get a blank look. Try "the new scam merchant rules" instead.
The mechanism is a screening and investigation duty on acquirers and payment facilitators. Certain signals oblige them to open a file on you and act fast. It isn't a ratio program. There's no scoreboard you can log in and check.
What changed is narrower than the headlines suggest. Mastercard's public Security Rules and Procedures already required acquirers to alert on "an authorization approval rate that falls below a threshold set by the Acquirer for that Merchant" (section 6.2.2.2, 3 February 2026 edition). Your acquirer picked the number. The scam rules swap that discretion for a network number and a hard clock.
The clock is the real story. Under the existing Merchant Monitoring Program, a monitoring provider reports an identification within 5 business days. The acquirer then investigates within 15 calendar days (section 8.9.1). For scam signals that becomes 72 hours. Roughly a five-fold compression. It's why onboarding got tighter across the industry this year.
The triggers, and the numbers attached to them
Every figure in this section is REPORTED. Nobody outside an acquirer login can read the source document. Sources and dates are in the Sources table.
If you've been on Mastercard more than six months
| Trigger | The number | What it really catches |
|---|---|---|
| Authorization approval rate collapse | At least 25 purchase transactions in a 72-hour window, and the approval rate either drops by 50 percentage points or more (the worked example in circulation is 95% falling to 45%) or falls below 30% outright | A gateway or 3DS misconfiguration, or a fraud rule set to the wrong value. BIN attacks and processor outages are reported to be excluded |
| GRIP letter | No threshold. Receipt of the letter is the trigger | A Mastercard compliance investigation already reached your acquirer |
| Monitoring provider alert | No threshold | A Mastercard-approved monitoring vendor flagged your website |
That's the full list for an established merchant. There's no refund test, no chargeback test and no dollar amount.
If you've been on Mastercard six months or less
Any one of these three is enough:
| Trigger | The number |
|---|---|
| Two issuers report fraud type 56 | Two different card issuers file transactions under code 56, Manipulation of Cardholder |
| Two issuers cite scam language | At least two issuers file chargebacks, fraud or non-fraud, where the supporting documentation mentions scams, manipulation or similar |
| Combined refund and chargeback rate above 5% | Refunds plus chargebacks above 5% of purchase transactions in any rolling 30-day period, provided you did at least 500 purchase transactions in that window |
A fourth item shows up in two sources only. Asking your acquirer for multiple Merchant IDs without a clear business reason. Treat that as reported, not established. It's cheap to avoid anyway. Document the reason before you ask.
The 500-transaction floor on the 5% trigger is the better supported of the two. Every write-up we found carries it, Justt included. So does the one source that cites Mastercard's document reference. The 25-transaction floor on the approval rate trigger is carried by every source except Justt. Justt gives the ratio with no minimum attached. That reads like an omission rather than a denial. You can't verify either way, because none of us can read the document.
The scope of the 5% trigger is the genuine disagreement. Every source but one scopes it to merchants with six months or less of Mastercard acceptance history. That again includes the one citing the document reference. Justt lists it as a general merchant trigger applying to everyone. We follow the majority. This page would be badly wrong if the dissenter turns out to be right.
What to do about it: ask your acquirer which version they apply to you. Their answer governs your account, whatever the network document says.
Refunds count toward SMMP, and toward nothing else
Every other network program on this site counts chargebacks. ECM and HECM divide chargebacks by the prior month's transactions. EFM looks only at fraud chargebacks, reason codes 4837 and 4863. Visa's VAMP combines fraud reports and disputes. Refunds appear in none of them.
So the standard advice when your ratio climbs is simple. Refund faster. Refund on request. Refund pre-emptively through alerts. That advice is right for ECM and right for VAMP. Every chargeback vendor, every processor risk email and most of this site will tell you so.
SMMP adds the two together. In your first six months, the refunds you issue to protect your chargeback ratio land in the same numerator as the chargebacks you avoid.
Take a merchant doing 800 purchase transactions in a 30-day window, four months into their Mastercard history:
| Scenario | Transactions | Chargebacks | Refunds | Chargeback rate | Combined rate |
|---|---|---|---|---|---|
| Baseline | 800 | 10 | 28 | 1.25% | 4.75% |
| Alert deflection: 6 disputes refunded before they land | 800 | 4 | 34 | 0.50% | 4.75% |
| Plus a no-questions refund policy adding 12 goodwill refunds | 800 | 4 | 46 | 0.50% | 6.25% |
The first two rows have the same combined rate. The third doesn't.
Deflection is neutral. Turning a dispute into a refund moves one unit from the chargeback column to the refund column. The combined number doesn't move. RDR, Ethoca and CDRN don't hurt you here. They don't help you here either. A vendor who says their alert product protects you from scam monitoring is selling.
Net new refunds aren't neutral. The third row is the trap. A 0.50% chargeback ratio is excellent. It clears every threshold on this site with room to spare. It's the number you'd put in a processor email to prove you fixed the problem. And that merchant just crossed the SMMP line. Twelve goodwill refunds they'd never have issued are twelve units of net new numerator.
Refunds are the half of that number you fully control. So they're the half you can accidentally blow up. Nobody accidentally issues 12 extra chargebacks.
The timing makes it worse. The 5% trigger only lives in your first six months. That's exactly when a new merchant discovers their ratio, panics, and starts refunding everything that moves. The tactic that saves you from ECM starts a 72-hour clock under SMMP.
Who genuinely runs a high combined rate
For most businesses, 5% combined is a long way off. The verticals that sit near it in normal operation:
- Free-trial and trial-to-paid subscriptions. Cancellation refunds and first-bill disputes stack in the same window.
- Apparel, footwear and anything with sizing. Return-driven refund rates of 10% to 30% are ordinary retail, and they're all refunds.
- Ticketing and events. One cancelled event refunds an entire month of sales at once.
- Digital goods and app subscriptions. Low friction to buy, low friction to regret.
- Anything with a 30-day money-back guarantee you actually honour.
In one of those and under six months old? Watch this number weekly, not quarterly. A high refund rate isn't evidence you're doing anything wrong. It isn't something to stop doing. It just means the trigger sits closer to you than to a hardware store. Be ready to explain your refund pattern in one sentence when your acquirer calls.
The 72-hour window, and what your acquirer actually pulls
Once a trigger fires, your acquirer or payfac has to begin investigating within 72 hours. Not resolve it. Begin it.
Reported scope of that review: your onboarding file, transaction records, refund behaviour, chargeback documentation, issuer reports against you, website content, billing descriptors and your emails with the acquirer. Acquirers also reportedly check Mastercard's Fraud and Loss Database daily for newly listed scam merchants.
If the investigation confirms scam activity, Mastercard and Maestro authorization and clearing get blocked immediately.
The obligation sits on your acquirer. The consequence lands on you. Mastercard doesn't notify you. There's no merchant-facing portal. There's no documented appeal. You find out when your acquirer emails asking for records, and by then the clock has been running.
So every bit of preparation has to happen in advance. Seventy-two hours won't cover assembling a fulfilment archive, rewriting a terms page and pulling customer service logs out of a helpdesk you left last year.
What actually happens to a merchant
| Outcome | Does SMMP do this? |
|---|---|
| Monthly fine | No. No source reports any assessment |
| Escalating ladder | No |
| Warning tier before enforcement | No. Reported to have no separate warning stage |
| Remediation plan with a deadline | No published process |
| Documented appeal | None found |
| Loss of Mastercard and Maestro acceptance | Yes, if the investigation confirms scam activity |
That's the trade. No bill, no negotiation, and no runway either. As one write-up put it, ECM and EFM give you time to fix things and this doesn't.
The MATCH question
You'll see claims that SMMP puts you on the MATCH list. One source asserts it. No source documents it. Mastercard's published MATCH reason code table has no scam-specific code.
The honest version: a termination for cause after a confirmed scam investigation would land under an existing code. Most plausibly 10 Violation of Standards, 13 Illegal Transactions or 03 Transaction Laundering. That's reasoning about how MATCH works, not a rule anyone has published. Don't let a vendor sell you protection against a listing mechanism nobody can point to.
Fraud code 56, and why one scam complaint counts three times
Code 56 is Manipulation of Cardholder. In merchant language: the cardholder really did make the payment, and somebody tricked them into it.
The issuer files it into Mastercard's Fraud and Loss Database. It never appears on your statement. You can't see it and you can't dispute it. Mastercard's Chargeback Guide (19 May 2026) says it "encourages" issuers to report scam-related disputes this way. Doing so doesn't invalidate the chargeback itself.
"Encourages" matters. Reporting is discretionary. So the two-issuer trigger depends entirely on which banks bother to file. Two banks that do can start a clock on you. Two that don't, can't. It isn't a measure of how bad you are.
Now the part that catches people. A scam victim did authorise the payment. Mastercard's cardholder dispute chargeback requires that the cardholder engaged in the transaction. So scam complaints arrive as 4853 Cardholder Dispute chargebacks, not as fraud codes. One complaint lands in three different places:
| Program | Does this scam complaint count? |
|---|---|
| ECM and HECM | Yes. They take any reason code, so a 4853 counts like any other chargeback |
| SMMP and QMAP | Yes, separately, through the code 56 entry the issuer files into the Fraud and Loss Database |
| EFM | No. EFM is limited to reason codes 4837 and 4863 |
That's why a merchant can run a clean fraud ratio, pass EFM comfortably, and still be the subject of a scam investigation. The two systems read different data.
How SMMP differs from ECM, HECM, EFM and VAMP
| Program | What it measures | What it costs | Who acts, and how fast |
|---|---|---|---|
| SMMP | Scam signals: refunds plus chargebacks, approval rate collapse, issuer scam reports | No fine. Acceptance switched off if confirmed | Your acquirer, within 72 hours |
| ECM / HECM | Chargeback count and ratio, any reason code | $1,000 to $200,000 a month | Mastercard, monthly |
| EFM | Fraud chargebacks only (4837, 4863) plus 3DS penetration | Escalating assessments | Mastercard, monthly |
| Visa VAMP | Fraud reports plus disputes combined | Per-dispute fees | Visa, monthly |
| QMAP | Fraud-to-sales ratio, three of four conditions met | Audit, and MATCH code 08 | Mastercard |
One structural point worth having straight. ECM, HECM and EFM all sit inside the Acquirer Chargeback Monitoring Program, or ACMP. SMMP isn't part of ACMP. It lives in the merchant screening and monitoring rules. Different mechanism, different consequence. It runs in parallel and it replaces nothing.
Its closest live relative isn't ECM at all. It's QMAP, the Questionable Merchant Audit Program. QMAP is fraud-driven and identified from the same Fraud and Loss Database. One of its four conditions is literally that the merchant has been submitting transactions for fewer than six months. Same six-month concept, same database, same instinct.
Where these numbers come from
"SMMP" appears zero times across the four current public Mastercard manuals: the Security Rules and Procedures Merchant Edition (3 February 2026), Mastercard Rules (2 June 2026), Transaction Processing Rules (9 December 2025) and the Chargeback Guide (19 May 2026). "GRIP" appears zero times too.
All four editions predate 24 July 2026, so that absence refutes nothing. It does mean no document exists that you can read to check any figure on this page. The only reference anywhere is a document number, GLB 12772, cited by exactly one source. No announcement number. No bulletin. No Mastercard-hosted page.
Same situation as ECM, HECM, EFM and VAMP. The real thresholds live in acquirer-login manuals and every number in circulation is a relay. SMMP has only been relayed for a few months rather than a few years. So the relays haven't been corrected as often.
What to do about it: email your acquirer and ask three things. "Do the new Mastercard scam monitoring rules apply to my account?" "Which triggers do you apply to me, and with what minimums?" "If one fires, will you contact me before you act?" Whatever they answer is your operative rule. Their internal thresholds are usually stricter than the network's, and theirs are the ones that end your account.
One part of the story is corroborated outside vendor marketing: the effective date. Payments Dive reported on Monday 27 July 2026 that the rules "went into effect Friday". That's a trade publication with a named editor and no product to sell. That Friday was 24 July 2026. Mastercard's own newsroom confirmed the 72-hour investigation duty on 19 May 2026. Everything else on this page is vendor relay.
Confidence tiers used here: VENDOR read in Mastercard's own published rules, REPORTED published by a named third party with its date and type stated, NOT FOUND where we looked and failed. How the tier system works.
Scale Callout
| Volume | Focus |
|---|---|
| Under $100k/mo | If you're under 500 purchase transactions in any 30-day window, the 5% trigger can't fire on you even in month one. Your realistic exposure is an approval rate collapse from a misconfigured gateway. Fix your billing descriptor, keep fulfilment records somewhere you can export them, and stop worrying about this |
| $100k-$1M/mo | You're past 500 transactions, so tenure is what decides your exposure. Under six months on Mastercard, track refunds and chargebacks as one combined number weekly and keep it under 5%. Over six months, switch your attention to approval rate monitoring and tell your acquirer before any flash sale, pricing change or gateway migration |
| Over $1M/mo | Approval rate is the trigger that matters, and at your volume a BIN attack or a bad 3DS rule can drop you 50 points in an afternoon. Alert on approval rate hourly, not daily. Keep a standing evidence pack you can send inside a working day, and give your acquirer a named contact who answers the phone |
Test to Run
An hour of work that tells you exactly where you stand.
- Pull 30 days of counts. Purchase transactions, refunds issued, chargebacks received. Calculate
(refunds + chargebacks) / purchase transactions. That single number is your SMMP exposure. Almost nobody tracks it, because no other program asks for it. - Check your tenure. Find the date of your first Mastercard transaction on your current MID. Less than six months ago? The number from step 1 has a 5% ceiling on it. More than that, and it doesn't.
- Find your worst 72 hours. Chart daily authorization approval rate for the last 90 days. Look for any 72-hour window with a 50 point drop or a sub-30% reading. Find one and you know what an investigation trigger looks like on your own data.
- Read your own descriptor. Pull a real statement line for a real order. If it doesn't obviously say who you are, some of your "I was tricked" complaints are just people not recognising the charge. Fix that first. It's the cheapest item on this list.
- Build the 72-hour pack now. Fulfilment and delivery records, terms and refund policy as they appeared on the day of sale, customer service logs, and a one-paragraph explanation of your refund pattern. Put it in one folder. If your acquirer calls, you're forwarding a link, not starting a project.
- Make the call. Ask: "Do the new Mastercard scam monitoring rules apply to my account, and which triggers do you apply?" Then: "If one fires, do you contact me before you act?"
Where This Breaks
-
The scope of the 5% trigger is genuinely disputed. Every source but one scopes it to merchants under six months old. Justt applies it to everyone. If your acquirer takes the broader reading, that governs your account. The reassurance on this page won't apply to you.
-
Nobody can read the source. Every number here is a relay of a document behind an acquirer login. Relays get transcribed wrong. This one has only been in circulation since February 2026.
-
"Refunds" isn't a clean count. Partial refunds, order adjustments, refunds issued to resolve an alert, and refunds of already-disputed transactions could each count as one, as a fraction, or not at all. No public source defines the counting rule. Ask your acquirer how they count a partial.
-
"Six months of Mastercard acceptance history" is undefined. Per MID, per legal entity, or per acquirer relationship? It matters. A new MID after a processor switch could restart your clock while your business is three years old. Nobody has published the answer.
-
GRIP's own name is unresolved. Four SMMP-era sources expand it as Global Rules Investigation Program. A PSP's own documentation, written before any of this, expands it as Global Risk Investigation Program. If you get one of these letters, the process is what matters. You respond within 5 business days, either confirming compliance or supplying an action plan. Assessments for ignoring it are set case by case.
-
Your acquirer's rules are stricter than the network's. They always are. A processor that decides scam exposure isn't worth the revenue will offboard you long before Mastercard notices you exist.
Sources
| Source | What it gave us | Kind | Date |
|---|---|---|---|
| Mastercard Security Rules and Procedures, Merchant Edition | The pre-existing acquirer-set approval rate alert (6.2.2.2), the 5-business-day and 15-calendar-day monitoring timetable (8.9.1), QMAP's conditions (8.4), the MATCH reason code table (11.14.1), and a verified zero hits for "SMMP" and "GRIP" | Primary, Mastercard's own published rules | Edition dated 3 February 2026, accessed 2026-08-02 |
| Mastercard Chargeback Guide, Merchant Edition | The verbatim code 56 language, that reporting is "encouraged" rather than required, and that a cardholder dispute chargeback requires the cardholder to have engaged in the transaction | Primary, Mastercard's own published rules | Edition dated 19 May 2026, accessed 2026-08-02 |
| Payments Dive | The effective date. Reported Monday 27 July 2026 that the rules "went into effect Friday" | Trade publication with a named editor and no product to sell | 27 July 2026 |
| Mastercard newsroom | Confirmation of the 72-hour acquirer investigation duty, under the umbrella name "Merchant Trust Services" | Primary, vendor announcement | 19 May 2026 |
| Austreme | The trigger detail and both transaction minimums, plus the only document reference in existence (GLB 12772) and the BIN attack and outage exclusions. A Mastercard-approved merchant monitoring vendor, so it sells into this program | Approved vendor blog | 20 February 2026 |
| Global Payments Consultants | Independent corroboration of the 24 July date and the 5% combined trigger, plus the absence of any warning tier | Consultancy, not a chargeback vendor | 14 July 2026 |
| Solidgate, Chargeback Gurus, Chargeflow, cside, merchanto, Fraudbeat | The six-month scoping of the 5% trigger, the 500 and 25 transaction minimums, and the scope of the acquirer's review. All sell chargeback or payment services | Vendor blogs | May to July 2026 |
| Justt | The 50 point / 30% approval rate figures, and the dissenting unscoped reading of the 5% trigger. Sells chargeback services | Vendor blog | 20 May 2026 |
| Nuvei PSP documentation | The GRIP process, the 5-business-day response window, and the alternative expansion of the acronym. Written before SMMP existed, so uncontaminated by it | Vendor documentation | October 2025 |
Last verified: 2 August 2026.
Next Steps
Just heard the term and want to know if you're exposed?
- Test to Run - the one-hour version, above
- Refund Strategy - when refunding is right and when it's expensive
- Descriptors and Communication - the cheapest fix on the list
Under six months old on Mastercard?
- Underwriting - what your acquirer already knows about you
- Recurring Billing Compliance - free trials, cancellations and the rules around them
- SMB Prevention Priorities - what to do first with limited time
Already in a ratio program?
- Network Programs Reference - VAMP, ECM, HECM, EFM thresholds
- Zero Point Nine Panic - the crisis playbook
- Processor Warnings - how to answer the email you just got
See Also
- Network Programs Reference - the ratio programs and their fines
- Dispute Monitoring Programs - deeper VAMP and ECM coverage
- MATCH List and TMF - the blacklist and its reason codes
- Refund Strategy - refund versus fight, by ticket size
- Refund Policy Design - writing a policy that holds up as evidence
- 4853 Cardholder Dispute - the code scam complaints arrive under
- Chargeback Alerts - RDR, Ethoca and CDRN, and what they don't cover
- Chargeback Metrics - tracking ratios that actually matter
- Processor Management - running the acquirer relationship
- Holds and Reserves - what happens to your money when risk gets nervous
- Refund Fraud - when the refunds aren't yours to control
- Mastercard Network Reference - rules, codes and program overview