August 17, 2026 · 7 min read
Visa VAMP and Mastercard Monitoring Programs: How Enrollment Works and How to Stay Out
What Visa's VAMP and Mastercard's ECM programs actually do once you are enrolled, why VDMP and VFMP no longer exist, and the controls that keep you out.
The notice almost never comes from the network. It comes from your acquirer, in a short email, saying you have been identified under a monitoring program and they need a remediation plan by the end of the week. By then the month that flagged you is already closed, the disputes are already counted, and your options have narrowed to arguing about a number that is no longer moving. Most high-risk merchants meet these programs this way, after the fact, with no idea that enrollment was already three months in the making. Understanding the program mechanics is different from understanding the ratio math. The ratio tells you whether you are over a line. The program tells you what happens for the next six months, who is deciding, and what it costs to get out. This post covers the program side: what VAMP replaced, how enrollment and exit actually work, what Mastercard runs in parallel, and the controls that keep you off the list in the first place.
VDMP and VFMP are gone, and that matters
If you are working from a compliance checklist written before 2025, it probably names two Visa programs. The Visa Dispute Monitoring Program tracked non-fraud chargebacks. The Visa Fraud Monitoring Program tracked fraud-tagged volume through TC40 reports. They ran separately, with separate thresholds, and a merchant could sit comfortably under both while being a mess in aggregate.
Visa consolidated them into the Visa Acquirer Monitoring Program in 2025. VAMP combines fraud reports and non-fraud disputes into one numerator over settled card-not-present transactions. The practical consequence is that the old hedge no longer works. Merchants used to trade one category against the other, absorbing friendly fraud as non-fraud disputes to keep the fraud program clean, or aggressively refunding fraud cases to protect the dispute count. Under VAMP both land in the same number, so there is nothing to trade.
The second consequence is the program name. It is an acquirer monitoring program. Visa's primary counterparty is your processor, not you, and the thresholds that carry the most weight are portfolio-level thresholds measured against the acquirer. The exact figures and the calculation itself are covered in the chargeback ratio guide; what matters here is that your acquirer is being graded on a much tighter line than you are, and their line is the one that decides whether you keep processing.
Enrollment is a monthly snapshot, not a warning system
Networks evaluate on closed calendar months. There is no live counter, no dashboard the network shares with you, and no alert at eighty percent of threshold. You breach in month one, the data settles, and the identification typically reaches your acquirer partway through month two. Your acquirer then decides how to tell you, and some do not tell you at all until they have already decided what to do about it.
This lag is why merchants describe enrollment as sudden when it was not. By the time you can act, you are managing the third month while being judged on the first. It also means that any control you deploy on the day you get the notice, whether that is alerts coverage or a policy change, will not show up in a measured ratio for another full cycle.
Build your own monitor. Compute the ratio yourself, per network, per MID, on a rolling basis, and treat any month above roughly two thirds of the merchant threshold as an internal alarm. That is not conservatism, it is just accounting for the two-month blindfold.
What the program does to you once you are in it
Enrollment triggers a sequence that runs on the network's clock, not yours.
Fees attach per transaction, not per month. Under VAMP, identified merchants are assessed a per-item charge on each disputed or fraud-reported transaction, and under Mastercard's Excessive Chargeback Merchant program the monthly fine escalates with each consecutive month you remain enrolled. The escalation is the part merchants underestimate. Month one is an annoyance, month four is a line item that changes the economics of the offer.
Your acquirer owns the remediation plan. The network asks the acquirer, not you, for a documented plan. The acquirer will push its requirements down to you, and those requirements are usually stricter than anything the network specified, because the acquirer is protecting its own portfolio ratio. Expect mandatory prevention alerts, a forced refund policy, descriptor changes, and often a volume cap. A cap is the one to negotiate hardest, because a shrinking denominator makes the ratio worse before it makes it better.
Reserves get revisited. An enrolled merchant is a merchant the acquirer now models as a loss risk. Rolling reserve percentages frequently go up at this point, or a reserve gets introduced where there was not one.
Termination is discretionary and early. Most high-risk merchants are not terminated by Visa or Mastercard. They are terminated by an acquirer who decided the portfolio math no longer worked, often well below any published merchant threshold. That decision logic is the subject of why processors shut down high-risk accounts, and monitoring enrollment is the single strongest trigger for it.
Termination for excessive chargebacks means a MATCH entry. The listing follows the business and its principals for five years and is visible to every acquirer that runs the check. Operating while listed is possible, but it means offshore acquiring on worse terms, and it is not a position you want to negotiate from.
Exiting takes longer than entering
Entering takes one bad month. Exiting takes consecutive clean months, typically three under Mastercard's program structure, measured after your remediation actually lands in the data.
Stack that against the reporting lag and the real timeline is close to two quarters from the day you fix the underlying problem. Plan the cash accordingly, because fines, elevated reserves, and any volume cap all run for that whole period.
| Visa VAMP | Mastercard ECM / HECM | |
|---|---|---|
| What it counts | Fraud reports and non-fraud disputes combined | Chargebacks only, with a separate fraud program |
| Test structure | Single ratio, above a minimum activity floor | Two-part test: chargeback count and ratio must both trip |
| Primary counterparty | The acquirer, with merchant-level identification | The merchant, via the acquirer |
| Cost shape | Per-item assessment on each counted transaction | Monthly fine that escalates with consecutive months |
| Exit | Sustained performance below threshold | Typically three consecutive clean months |
Treat the specifics as a snapshot. Visa moved its merchant threshold materially in April 2026, and both networks revise these programs on their own schedule. Re-verify the current numbers with your acquirer each quarter rather than trusting a figure you wrote down last year.
The controls that actually keep you out
Staying out is an architecture problem more than a customer service problem.
Prevention alerts, sized to the right program. Alerts stop a dispute before it is filed and are the fastest lever available, but they are not uniformly effective across both networks. Resolving a case through Verifi RDR keeps the dispute out of the count while leaving the underlying fraud report in place, so alerts protect a count-based program better than they protect a combined fraud-and-dispute ratio. The chargeback alerts guide covers the coverage gaps and the per-case economics.
Descriptor and marketing consistency. A meaningful share of disputes are recognition failures rather than dissatisfaction. The billing descriptor, the brand on the checkout page, the sender name on the receipt email, and the name on the support line should all be the same string. This is the cheapest ratio control that exists and it is still the one most commonly skipped.
Refund friction removed on purpose. Every refund is a unit that never enters a numerator, and the revenue you protect by making refunds hard is worth far less than the enrollment it buys. For rebill and trial models this is structural rather than optional, which is why subscription and continuity merchants need cancellation flows that actually work and dunning that stops on the first hard decline.
Per-MID containment. Ratios are computed per MID, so a single processing relationship concentrates every traffic source, every affiliate, and every campaign into one number. Properly underwritten MIDs, each disclosed and each carrying accurate descriptors, keep one bad source from taking down the whole business. The routing rules and per-MID caps are covered in the MID load balancing guide. The line to respect: distributing volume across disclosed, honestly underwritten MIDs is risk management, and opening MIDs to hide history is transaction laundering.
Decline hygiene. Retrying hard declines and letting card testing run against your checkout inflates both fraud reports and enumeration signals. Handle response codes correctly rather than uniformly, using the decline code reference as the map.
Practical takeaway
The path that fails is treating monitoring programs as a compliance topic you read about after the notice arrives. By then the measurement window has closed, your acquirer has already priced you as a risk, and your leverage is gone.
The path that lasts is running the networks' math yourself, monthly, per MID, with an internal alarm well below the published line, and building the controls before you need them: consistent descriptors, alerts sized to the right program, refunds that are easy to get, and enough MID redundancy that one bad traffic source is a contained incident rather than an existential one. None of that is expensive relative to a single enrolled quarter.
If you want a read on where your current setup sits against these programs, and what the containment architecture should look like for your volume, apply for an architecture review.