Visa VAMP chargeback thresholds tighten as Mastercard adds scam monitoring
Visa and Mastercard rules are raising pressure on merchants as global chargebacks are forecast to reach 324 million by 2028.
By Rafael Ortiz · Fintech Correspondent
· 3 min read
VAMP chargeback thresholds have become a sharper operating risk for merchants after Visa tightened its monitoring framework in April 2026 and Mastercard’s Scam Merchant Monitoring program took effect on July 24, 2026. Mastercard has forecast global chargeback volume will rise 24% to 324 million transactions in 2028, with nearly half classified as fraudulent.
Oleg Stefanet, chief risk officer at payabl., wrote on Finextra that friendly fraud is increasing as more consumers use chargeback rights as a substitute for conventional refunds or, in some cases, to obtain goods without paying. He said lower fraud, dispute and refund thresholds at the card networks make chargeback control a more direct constraint on revenue growth.
What are the new VAMP chargeback thresholds?
Visa’s Acquirer Monitoring Program, known as VAMP, is a unified compliance framework that measures both fraud reports and customer disputes. According to Stefanet, it replaced Visa’s earlier Visa Dispute Monitoring Program and Visa Fraud Monitoring Program after coming into force in April 2025.
The VAMP ratio is calculated by dividing a merchant’s combined reported fraud cases and dispute chargebacks by total settled transactions. Stefanet said a merchant is considered “excessive” if that monthly ratio is above 0.9%, exposing the merchant to fines per event. He added that acquirers often apply lower internal limits and that merchants commonly aim for 0.5% as a practical ceiling.
The framework can count one transaction twice if a bank files a TC40 fraud alert and the customer later files a TC15 dispute, Stefanet said. That double count means a merchant can approach the 0.9% ratio with fewer underlying chargeback transactions than under previous monitoring systems.
VAMP also tracks card-testing activity by measuring enumerated transactions, including approvals and declines, against total authorised transactions that settle. Stefanet said a merchant is treated as excessive if that enumeration ratio reaches 2,000 basis points, equal to a 20% enumeration transaction rate. He also said a 20% authorisation failure rate over 24 hours can trigger surcharges on failed attempts during an attack.
How does Mastercard’s scam monitoring work?
Mastercard’s Scam Merchant Monitoring program requires acquirers to investigate possible scam merchants within 72 hours once defined criteria are met, according to Stefanet. If the acquirer confirms scam activity, it must prevent that merchant from submitting Mastercard transactions.
The program extends Mastercard controls already in place, including the Business Risk Assessment and Mitigation program and the Merchant Monitoring Program, which monitor prohibited activity. Stefanet said the new regime lowers excessive fraud, dispute and refund thresholds for merchants in many regions.
What can merchants change?
Stefanet argued that chargeback ratios can rise at legitimate merchants when the customer experience creates confusion or friction. Examples he cited include difficult cancellation paths and trial-to-paid conversion terms shown in very small text.
His recommendations include clearer billing descriptors, reminders before higher-value rebills and cancellation flows that allow customers to pause a service. He said merchants should review user experience monthly and keep cancellation to no more than two clicks.
Stefanet also pointed to payment mix and geography. He described Visa as a key volume channel with higher monitoring risk under VAMP, Mastercard as a moderate-risk alternative with an Excessive Chargeback Merchant threshold of 1.5%, and American Express as more descriptor-focused with limited acceptance and relevance for higher average order values.
For operational controls, he cited daily tracking of TC40 and TC15 activity, Visa’s Rapid Dispute Resolution service powered by Verifi, Mastercard Collaboration tools that provide transaction details to issuers and cardholders, and velocity-checking systems to address card enumeration attacks.
This story draws on original reporting from Finextra Research.