Skip to main content

Dispute & Fraud Monitoring Programs

This page covers the monitoring programs plus the obligations they trigger: what a remediation plan has to contain, and the high-risk registrations. Looking for the threshold table?

The fine ladders are the same on both pages. The reference table is for looking a number up; this one is for when you have to write something back.

TL;DR
  • Early warning is not enforcement. Plenty of guides say "stay under 0.65%." That's a good internal target. It just isn't where the fines start; the numbers below are.
  • Visa VAMP (live April 2025): one ratio for fraud and disputes. Merchant excessive is 1.5% since 1 April 2026. CEMEA keeps 2.2%, and non-compliant sits at 0.5%. Acquirers are reported at 0.5% above-standard and 0.7% excessive.
  • Mastercard ECM: enforcement starts at 100-299 chargebacks AND a 1.50-2.99% ratio. HECM starts at 300+ chargebacks and 3.00%+.
  • Mastercard EFM: the fraud-only program. You need 0.50%+ fraud-to-sales, $50K+ in fraud claims, and thin 3DS coverage.
  • Consequences: monthly fines that climb into six figures. A remediation plan due in 15 days. A MATCH listing that follows you five years.
  • Prevention tools (Ethoca, Verifi RDR/CDRN) can keep resolved disputes out of the ratio.

Both networks fine you when disputes or fraud stay high. These are the lines where that starts.

Want the short version?

See Network Programs Reference for thresholds, fees and safe zones. This page carries the full context.

Visa Acquirer Monitoring Program (VAMP)

Background and Consolidation

VAMP replaced two programs on 1 April 2025. VDMP covered disputes and VFMP covered fraud. Now it's one ratio, and fraud and non-fraud disputes both count.

Key Dates:

  • 1 April 2025: VAMP goes live and the advisory period begins.
  • 1 June 2025: Visa revises the program after industry pushback. Fraud disputes join the numerator. Thresholds move up to compensate. The count minimum goes from 1,000 to 1,500. The step-down date slips from January to April 2026. Most stale pages predate this revision.
  • 1 October 2025: the advisory period ends and fees begin, at the excessive level only.
  • 1 January 2026: the acquirer above-standard tier starts being charged, at US$4 per dispute.
  • 1 April 2026: merchant excessive drops from 2.2% to 1.5% in AP, Canada, the EU and the US. CEMEA keeps 2.2%.

VAMP Ratio Calculation

Visa combines issuer fraud reports (TC40) and dispute events (TC15) into one ratio. The denominator is card-not-present volume.

Components:

  • TC40: issuer-reported fraud notifications
  • TC15: chargeback transaction codes, dispute conditions 10, 11, 12 and 13. Condition 10 is the fraud group. It joined the numerator in the June 2025 revision. Anything saying VAMP counts non-fraud disputes only predates that change
  • Denominator: settled CNP transactions

Fraud disputes count twice. Once when the issuer files the TC40. Again if a TC15 chargeback follows.

Minimum volume: about 1,500 applicable disputes before the program picks you up.

Denominator Varies by Reporting View

Formulas and denominators vary by acquirer reporting system. Use your acquirer's definition when you build a dashboard. Don't assume one universal formula.

Threshold Overview (2025-2026)

Since 1 April 2026 merchant excessive is 1.5%. The 2.2% figure still circulating applies to CEMEA only. Both acquirer portfolio lines, 0.5% and 0.7%, have run since 1 June 2025.

WhoThresholdNotes
Merchant - non-compliant0.5%The line you cross first. Early warning, not an automatic fee
Merchant - excessive1.5%Since 1 April 2026. 2.2% retained in CEMEA only
Acquirer - above standard0.5%Portfolio level, since 1 June 2025. The US$4 fee at this tier didn't start until 1 January 2026
Acquirer - excessive0.7%Portfolio level, since 1 June 2025. It was 0.5% when VAMP went live in April 2025

Don't merge those two dates. A threshold and a fee are separate events. Visa's own VAMP overview puts the acquirer lines at 50 bps above standard and 70 bps excessive, effective 1 June 2025. The 1 January 2026 date belongs only to the US$4 per-dispute charge at the above-standard tier. That charge came in seven months after the threshold it attaches to, and most summaries run the two together.

The merchant thresholds are gated on your acquirer. Visa's own framing is conditional, and the merchant lines apply where the acquirer isn't already sitting in Above Standard or Excessive. The per-dispute charge at 0.5% only lands once the acquirer's portfolio has breached Excessive. Stripe's docs put the difference in one word: Visa may assess at non-compliant, and assesses at excessive.

That doesn't make 0.5% safe to ignore. It's where your acquirer starts watching you. Their internal limit is usually tighter than Visa's anyway. Crossing 0.5% just isn't an automatic bill. Don't let anyone sell you a service on the claim that it is.

Verify Current Thresholds

Threshold numbers change, so confirm yours against Visa Core Rules or your acquirer's compliance docs. Regions differ, and LAC runs its own timeline.

Enumeration Ratio

VAMP also monitors card testing/BIN attacks through the enumeration ratio.

Formula:

Enumeration Ratio = Enumerated Authorizations / All Authorizations

Both halves count approvals and declines. That matters. A card-testing attack is mostly declines. A denominator built from settled transactions would never get near the threshold.

Threshold: 20%, over a minimum of 300,000 enumerated authorizations. Detection runs on Visa's Account Attack Intelligence (VAAI) Score.

Exclusions and Prevention Tool Impact

RDR and CDRN can keep disputes out of VAMP ratios. Issuer fraud reports (TC40) often still count anyway, even on a resolved dispute. CE 3.0 can exclude some TC40/TC15 pairs from Visa's program metrics. Treatment depends on how the transaction qualifies.

Check Current Visa Guidance

How prevention tools hit VAMP keeps moving. Visa clarified TC40 treatment in March 2025. Verify the current exclusion rules before you rely on them.

VAMP Fee Structure

Fees run per dispute or fraud event, once you're over the line.

LevelPer-Dispute Fee
Acquirer Above Standard (0.5% portfolio)US$4, from 1 January 2026
Acquirer Excessive (0.7% portfolio), on disputes at merchants whose own ratio is 0.5% or higherUS$8
Merchant ExcessiveUS$8 per CNP dispute, passed through by the acquirer

These are flat amounts, not the vague ranges that usually get published. They come from Checkout.com's acquirer notice dated 12 June 2026, corroborated by Antom. Visa does not publish them. Visa's own one-page VAMP fact sheet gives the ratios and the count minimums and no fee figure at all. Core Rules 12.5.4 is headed "Dispute Monitoring Fees and Non-Compliance Assessments" and has nothing under it. Treat the amounts as reported, and confirm your own pass-through with your acquirer.

Key Program Features:

  • Grace covers program months 1, 2 and 3. Fees start in program month 4.
  • Grace applies once per rolling 12 months, on a first identification.
  • Program months and calendar months aren't the same. You breach in one calendar month and the notice lands in the next, which is program month 1.
  • Fines compound monthly until you're compliant.
  • Fee amounts sit in Visa Core Rules and change.

Remediation Requirements

  • Submit a remediation plan within 15 days of notification, then report progress monthly.
  • Exit criteria: below the excessive threshold for three straight months.

Mastercard Excessive Chargeback Program (ECP)

Program Structure (as of 2025)

Two tiers. Both the count and the ratio have to be met.

LevelChargeback CountChargeback Ratio
ECM (Excessive Chargeback Merchant)100-2991.5%-2.99% (150-299 bps)
HECM (High Excessive Chargeback Merchant)300+3.0%+ (300+ bps)

Ratio Calculation

Basis Points = (First Presentment Chargebacks in Month N) / (Transactions in Month N-1) × 10,000

Note: Mastercard divides by the prior month's transactions. Visa uses the same month for both.

ECM Fine Structure

Month in ProgramMonthly Assessment
1$0 (warning)
2$1,000
3$1,000
4-6$5,000
7-11$25,000
12-18$50,000
19+$100,000

ECM carries no issuer recovery charge. That belongs to HECM, and it's in the next table.

Fine Amounts Change

Mastercard sets these amounts and updates them. Confirm current assessments with your acquirer.

HECM Fine Structure

Month in ProgramMonthly AssessmentIssuer Recovery Assessment
1$0 (warning)No
2$1,000No
3$2,000No
4-6$10,000Yes
7-11$50,000Yes
12-18$100,000Yes
19+$200,000Yes

HECM escalates far faster than ECM. That's the point of the tier.

The Issuer Recovery Assessment is a HECM charge, and only from program month 4. It doesn't apply to ECM. Mastercard collects it from your acquirer and remits it to the issuers that took the chargebacks. An issuer needs USD 20 owed before it sees a payment. Below that, the issuer with the biggest burden takes the whole amount, and a tie gets split evenly (Mastercard, Security Rules and Procedures - Merchant Edition, 3 February 2026, section 8.3.3).

If your acquirer bills you an issuer recovery line, that tells you which tier you're in. It's HECM. Ask them to confirm.

Exit Criteria

  • Below ECM thresholds for three straight months. That means under 100 chargebacks AND under a 1.5% ratio.
  • Extension available: fines pause for six months while you remediate.
  • Come in under the thresholds by the end and the accrued fines are forgiven.
  • Stay above them and the whole accrued balance falls due.

Mastercard Excessive Fraud Merchant (EFM)

Enrollment Criteria (as of 2025)

You have to hit all four.

  • 1,000+ Mastercard transactions in the prior month
  • $50,000+ in fraud claims
  • 0.50%+ fraud-to-sales ratio
  • Under 50% 3DS usage in regulated markets, or 10% in non-regulated

EFM Fine Structure

The fine structure took effect 1 March 2020. It runs on the same month counter as ECM.

Month in ProgramMonthly Assessment
1$0 (warning)
2$500
3$1,000
4-6$5,000
7-11$25,000
12-18$50,000
19+$100,000

Exit: below all thresholds for three straight months.

3DS Requirement

Mastercard treats 3DS as the main EFM defense. Regulated countries need 50%+ coverage. Non-regulated need 10%+, and data-only 3DS counts toward the threshold.

MATCH List (Terminated Merchant File)

What is MATCH?

MATCH is Mastercard's database of terminated merchants. Acquirers have to check it before they onboard anyone. The full name is Member Alert to Control High-risk Merchants. In practice it's the industry blacklist.

Key Characteristics:

  • Entries sit for 5 years, then purge automatically (section 11.10).
  • You can ask the listing acquirer to remove you. Mastercard says no lawyer is required (11.5.1).
  • Most acquirers won't touch a listed merchant, though the rules do permit it.
  • It hits every card brand, not just Mastercard.

MATCH Reason Codes

Eleven codes. Codes 02, 07 and 11 came out in the 11 February 2025 edition. Code 06 read "Reserved for Future Use" until then. Anything showing 14 codes is quoting an expired rulebook.

CodeReasonDescription
01Account Data CompromiseCardholder data exposed, including Common Point of Purchase
03Transaction LaunderingProcessing for another party, against the merchant agreement
04Excessive ChargebacksMastercard chargebacks over the previous three months above 1.5% of Mastercard sales transactions, and USD 5,000 or more in chargebacks
05Excessive FraudFraud-to-sales dollar volume of 8% or more over the previous three months, and 10 or more fraudulent transactions, and USD 5,000 or more
06CoercionForced transactions
08Mastercard Questionable Merchant Audit ProgramQMAP violation
09Liquidation/InsolvencyMerchant insolvent
10Violation of StandardsNetwork rules violation. No published number
12PCI Data Security Standard NoncomplianceFailed to maintain PCI compliance
13Illegal TransactionsProcessed illegal activity
14Identity TheftMerchant was identity theft victim

Source: Mastercard, Security Rules and Procedures - Merchant Edition, 3 February 2026, section 11.14.1, Table 11.4, p.155. For codes 04 and 05, every condition has to be met. Not any one of them. When an American Express acquirer reports you, code 04 carries no number at all and the call is entirely Amex's.

Meeting the ratio doesn't list you. Termination does. Once the acquirer terminates while a code applies, the listing is mandatory within five calendar days (11.5). List a merchant sitting under the code 04 floor and the acquirer risks a noncompliance assessment (11.4, item 8).

MATCH Consequences

  • Most acquirers won't onboard a MATCH-listed merchant.
  • High-risk processors might, at higher fees and with a reserve.
  • The listing hits all card brands, not just Mastercard.
  • You start the removal request with the listing acquirer. They have 30 calendar days to respond (11.4, item 1). They also have to hand over the listing ICA and reason code on request (item 10). Code 12 listings can go straight to Mastercard when the acquirer won't file (11.13).

Visa Merchant Screening Service (VMSS)

VMSS is Visa's shared screening database. That's the real counterpart to MATCH. Visa's TMF is something else. Under Core Rules 10.10.1.1 the Terminated Merchant File is a file the acquirer keeps on you: merchant agreement, deposit history, correspondence.

  • Acquirers have to query VMSS before onboarding.
  • Terminated merchants go in by close of business the day after notice of intent to terminate. That's tighter than Mastercard's five calendar days.
  • Visa publishes no numeric listing standard. Its stated reasons are qualitative, "excessive Counterfeit Transactions" and "an excessive number of Disputes due to the Merchant's business practices or procedures". Any page giving you a numeric TMF threshold invented it.
  • Visa's public rules don't state a retention period the way Mastercard's do. Ask your acquirer if you need one.

High-Risk Merchant Programs

VIRP (Visa Integrity Risk Program)

VIRP replaced the Global Brand Protection Program in May 2023. It sorts high-risk merchants into three tiers.

Tier Structure:

  • Tier 1: adult content, dating and escort, gambling, pharmaceuticals
  • Tier 2: cryptocurrency, cyberlockers, file sharing
  • Tier 3: other high-risk MCCs

Costs (as of 2024 Visa bulletins):

  • Registration: on the order of $1,000 per acquirer
  • Transactions: a few basis points, plus per-transaction fees on MCCs 5967, 7273 and 7995
  • Non-compliance: monthly assessments that get large if you stay unregistered
Fee Amounts Subject to Change

Visa updates VIRP pricing by bulletin. Check current fees with your acquirer.

BRAM (Mastercard Business Risk Assessment and Mitigation)

BRAM protects against illegal or brand-damaging transactions.

Prohibited Categories Include:

  • Synthetic drugs
  • Illegal pharmaceuticals
  • Counterfeit goods
  • Unlicensed gambling
  • Child exploitation material
  • Piracy and IP theft

Requirements:

  • Acquirers register with the Merchant Monitoring Program (MMP)
  • Reporting is monthly
  • Fine mitigation of 75-100% if you use a registered Merchant Monitoring Service Provider

Remediation Strategies

Immediate Actions

  1. Find the root cause. True fraud, friendly fraud, or an operational mess.
  2. Turn on prevention alerts. Ethoca and Verifi (RDR/CDRN).
  3. Look at your worst products. Some of them are worth dropping.
  4. Audit support and refunds. Easy refunds prevent disputes.

Prevention Tools Impact (as of 2025)

ToolVAMP ImpactECM Impact
RDR (Visa)Can exclude associated TC15 disputes; TC40 usually still countedN/A
CDRN (Visa)Can exclude associated TC15 if resolvedN/A
CE 3.0 (Visa)Can exclude both TC40 and TC15 for qualifying transactionsN/A
Ethoca AlertsPrevents chargeback if refunded before TC40 filedPrevents if refunded
Order InsightReduces disputes by providing transaction details to issuersReduces disputes
Confirm Tool Behavior

How tools affect program ratios keeps changing. Confirm the current behavior with your acquirer.

Remediation Plan Components

  1. What you do and where you stand. The business, the current ratios.
  2. Root cause. Why the chargebacks or fraud are elevated.
  3. Specific actions with dates. What you'll change and when.
  4. Timeline. Where you expect the ratio to land.
  5. Backup plan. For when the first one doesn't work.
  6. Reporting. How you'll keep them updated.

Issuer Considerations

TC40 Filing Requirements

  • Issuers file a TC40 on every fraud claim, however small.
  • The TC40 still gets filed when an alert resolves the dispute, for VAMP purposes.
  • Skipping the filing creates its own compliance problem.

Visa Issuer Monitoring Program (VIMP)

  • Watches issuer-side fraud and dispute rates on CNP
  • Metrics are dispute-to-transaction and fraud-to-sales
  • Minimum volume thresholds vary by region

Consumer Clarity / Order Insight

  • Enrolled issuers show cardholders the transaction detail
  • That kills a lot of "I don't recognize this" disputes
  • Verifi runs it for Visa, Ethoca for Mastercard

Last verified: 1 August 2026

These thresholds move, and VAMP has already changed twice since April 2025. Neither Visa nor Mastercard publishes the numbers in a document you can read. Verify yours with your acquirer before you decide anything on them.

Next Steps

Understanding your risk?

  1. Review chargeback metrics - Calculate your current ratios
  2. Check compliance metrics - Build monitoring dashboards

Implementing prevention?

  1. Set up chargeback alerts - Ethoca, Verifi RDR/CDRN
  2. Enable 3D Secure - Liability shift and fraud reduction
  3. Evaluate vendors - Prevention tool options

Already in a program?

  1. Reduce chargebacks fast - Emergency response playbook
  2. Work with your processor - Remediation plan support
  3. Understand holds and reserves - Program consequences

See Also