Mastercard Excessive Chargeback Program tiers at a glance (source: Stripe monitoring-programs docs)
TierMonthly chargebacksChargeback rate*
ECM (Excessive Chargeback Merchant)100–2991.5%–2.99%
HECM (High Excessive Chargeback Merchant)≥300≥3.0%

*Rate = current-month chargebacks ÷ the preceding month's captured transactions. Both conditions must be met. Full details in the threshold table below.

What Is the Mastercard ECM Program?

Mastercard's Excessive Chargeback Program (ECP) is a compliance enforcement mechanism that identifies merchants with chargeback rates significantly above industry norms. When a merchant's chargeback rate reaches 1.5% — calculated as the current month's chargeback count divided by the preceding month's captured transactions — and the merchant receives at least 100 chargebacks in that month, Mastercard places them in the ECM (Excessive Chargeback Merchant) tier. This triggers escalating monthly fines, increased scrutiny from payment processors, and — if unresolved — potential termination of the merchant's processing account and placement on the MATCH list.

For subscription mobile apps and SaaS businesses, ECM is an existential threat. Unlike ecommerce merchants who deal primarily with stolen cards and shipping fraud, subscription businesses face unique vectors: card testing on low-cost trials, "subscription amnesia" friendly fraud, and high-volume recurring billing disputes.

Key takeaway: ECM is not just a fine — it's a countdown to losing your ability to process payments entirely. The Excessive Chargeback Program (ECP) has two tiers: ECM (100–299 chargebacks and a 1.5%–2.99% rate) and HECM (≥300 chargebacks and a ≥3.0% rate), with steeper fines at HECM.

ECP Tiers: ECM vs. HECM — Thresholds

Mastercard Excessive Chargeback Program (ECP) tier triggers — both conditions required in the same month (source: Stripe monitoring-programs docs)
TierTrigger — chargeback countTrigger — chargeback rateHow the rate is computed
ECM — Excessive Chargeback Merchant100–299 chargebacks in a month1.5%–2.99%Current-month chargeback count ÷ the preceding month's captured transaction count
HECM — High Excessive Chargeback Merchant≥300 chargebacks in a month≥3.0%
Issuer Recovery Assessment (IRA): on top of fines, Mastercard charges USD 5 per chargeback above 300 from month 4 onward, in both ECM and HECM. Example: a month-4 ECM merchant with 400 disputes owes $5,000 + (400−300)×$5 = $5,500.

How does this compare to Visa? Visa's equivalent is VAMP, which uses a combined fraud-plus-dispute ratio: the merchant Excessive threshold is 1.5% since April 1, 2026 (applying at ≥1,500 fraud + dispute transactions/month), per Visa's VAMP fact sheet.

How Do Merchants Enter ECM?

Most subscription app merchants don't enter ECM because of a single catastrophic fraud event. Instead, it's a gradual accumulation of systemic issues that compound over months. Here are the most common paths:

  • Lax default Stripe Radar settings. Stripe's out-of-the-box risk threshold is calibrated for general ecommerce, not subscription apps. It allows transactions that a subscription-specific rule set would block.
  • No velocity checks on trial sign-ups. Card testers use low-cost trials ($0.99-$2.99) to validate stolen card numbers. Without IP-based, device fingerprint, or BIN velocity checks, thousands of fraudulent trials convert into chargebacks 30-60 days later.
  • Missing dispute interception. Without Ethoca or Verifi/CDRN integration, every cardholder dispute becomes an official chargeback. Interception networks can prevent 30-50% of disputes from becoming chargebacks.
  • Difficult cancellation flows. When legitimate customers can't easily cancel a subscription, they call their bank instead. This creates "friendly fraud" chargebacks that are nearly impossible to win on representment.
  • Stripe Link bypassing CVC/AVS. Stripe Link's stored-credential flow can bypass CVC and AVS verification checks, allowing previously-declined cards to process successfully through a different authentication path.

Key takeaway: ECM entry is almost always the result of 3-5 systemic issues compounding simultaneously, not a single point of failure. Fixing one issue while ignoring others will not bring the ratio below threshold.

What Happens When You're in ECM?

Once Mastercard places a merchant in the ECM program, the consequences escalate on a fixed monthly schedule. Understanding this timeline is critical for prioritizing remediation efforts.

Fine Escalation Schedule — ECM and HECM

Monthly fine schedule per tier (source: Stripe monitoring-programs docs). From month 4, add the $5/chargeback-above-300 Issuer Recovery Assessment in both tiers.
Month in programECM fine / monthHECM fine / month
Month 1$0$0
Month 2$1,000$1,000
Month 3$1,000$2,000
Months 4–6$5,000$10,000
Months 7–11$25,000$50,000
Months 12–18$50,000$100,000
Month 19+$100,000$200,000

Payment processors like Stripe, Adyen, and Braintree often act faster than Mastercard's escalation schedule. Many processors will freeze payouts, require a formal remediation plan, or begin offboarding within 30-60 days of ECM notification — well before the highest fines kick in.

The MATCH list (Member Alert to Control High-risk Merchants) is the nuclear option. Once a merchant is MATCH-listed, they cannot obtain a new merchant account with any Mastercard-accepting processor for five years. This effectively ends the business's ability to accept card payments.

Are you currently in ECM or approaching the 1.5% threshold?

I've helped subscription apps exit ECM in under 90 days with a structured remediation program. Don't wait for escalating fines.

See the 90-Day Chargeback Rescue program →

or book a free call

How to Exit ECM — A 90-Day Playbook

Exiting ECM requires a structured, phased approach. Random fixes applied without a systematic plan typically fail because they address symptoms rather than root causes. The following 90-day playbook is based on real engagements where I've helped subscription apps successfully exit the program.

Phase 1: Hemorrhage Control (Days 1-14)

The first priority is stopping new fraudulent transactions from entering the system. This involves an immediate Stripe Radar rule rebuild or equivalent processor fraud tuning.

  • Audit all existing Radar rules for conflicts and gaps
  • Configure strict velocity checks (IP, BIN, device fingerprint)
  • Deploy dynamic 3D Secure (3DS) gating for high-risk regions and BINs
  • Block Stripe Link for high-risk transaction types
  • Implement real-time card testing detection

Phase 2: Dispute Interception (Days 15-45)

Once new fraud is blocked, the focus shifts to intercepting incoming disputes before they become official chargebacks. This phase typically reduces the effective chargeback ratio by 30-50%.

  • Integrate Ethoca alerts for pre-chargeback dispute notification
  • Set up Verifi/CDRN for Visa dispute interception
  • Configure automated refund rules for intercepted disputes
  • Build a blocked-card database from previous dispute cards

Phase 3: Structural Prevention (Days 46-75)

This phase addresses the root causes of "friendly fraud" and "unrecognized charge" disputes — the category of chargebacks that no amount of fraud-rule tuning will prevent.

  • Audit and update the billing descriptor for clarity
  • Redesign the cancellation flow to prioritize self-serve over bank disputes
  • Review and update terms of service, especially around trial-to-paid conversion
  • Implement pre-renewal email notifications
  • Add proactive refund triggers for high-risk accounts

Phase 4: Compliance Documentation (Days 76-90)

Exiting ECM requires formal documentation proving that systemic issues have been remediated. Payment processors expect specific artifacts that demonstrate sustained improvement.

  • Draft the formal remediation report with before/after metrics
  • Prepare the compliance documentation package for Mastercard
  • Document all Radar rule changes with rationale
  • Compile 3-month trending data showing sustained ratio improvement
  • Submit to the processor's risk team with supporting evidence

Key takeaway: Exiting ECM requires dropping below the threshold for 3 consecutive months. A single month above threshold resets the clock. This is why structural prevention (Phase 3) is as important as fraud blocking (Phase 1).

The 5 Most Common Chargeback Root Causes in Subscription Apps

Based on hands-on work with subscription mobile apps, these five root causes account for the vast majority of chargebacks that push merchants into ECM:

  1. Stripe Link bypassing CVC/AVS checks. Stripe Link's stored-credential flow uses a different authentication path that can bypass the CVC and AVS verification checks configured in Radar rules. Cards that would normally be declined process successfully through Link, creating fraud exposure.
  2. No blocked-card database. When a card generates a dispute, the same card number is not automatically blocked from future transactions. Repeat offenders can dispute multiple charges across different billing cycles.
  3. Default Stripe risk threshold too permissive. Stripe's default risk scoring is calibrated for general ecommerce where false positives are costly. Subscription apps with lower average transaction values can afford stricter thresholds without significant revenue impact.
  4. Unprotected credit bundle purchases. In-app credit purchases (top-ups, coin bundles) are high-value, non-refundable, and attractive to fraudsters. Without separate 3DS gating for these transactions, they become a primary fraud vector.
  5. No chargeback alert integration. Without Ethoca or Verifi, every dispute becomes an official chargeback. Alert networks intercept 30-50% of disputes before they're finalized, directly reducing the chargeback ratio.

Why Generic Fraud Solutions Fail for Subscription Apps

Out-of-the-box machine learning fraud models are designed for ecommerce, where the primary threat is stolen credit cards used to buy physical goods for resale. Subscription apps face fundamentally different fraud vectors that these models don't address.

Ecommerce fraud is about unauthorized transactions — someone stole a card and used it. Subscription fraud includes authorized transactions that are later disputed: a customer signs up for a free trial, forgets about it, sees a charge, and disputes it rather than cancelling. This "subscription amnesia" is technically friendly fraud, and no ML model can predict it because the original transaction was genuinely authorized.

Additionally, subscription apps face card testing at scale. Fraudsters use low-cost trial sign-ups ($0.99-$2.99) to validate stolen card numbers in bulk. A general-purpose fraud model sees each individual $0.99 transaction as low-risk, but the aggregate pattern — hundreds of trials from similar IPs, device fingerprints, or BIN ranges — is the actual signal.

Effective chargeback prevention for subscription apps requires custom rule sets tuned to the specific business model, transaction patterns, and user behavior. This is specialized work that requires deep understanding of both the payment processor's tools (Stripe Radar, Adyen risk engine) and the subscription business model.

When to Hire a Chargeback Consultant

Not every chargeback problem requires external help. Here's a framework for deciding when DIY remediation is sufficient and when you need specialist intervention:

SituationDIYHire a Consultant
Chargeback ratio below 0.5%✓ Basic Radar tuning
Ratio approaching 1.5%✓ Preventive audit
Already in ECM/HECM✓ Structured remediation
Processor requesting remediation plan✓ Compliance documentation
No Ethoca/Verifi integration✓ Integration + rule design
Payout holds or offboarding threat✓ Urgent intervention

I've helped subscription apps reduce chargebacks from 13% to below 1%

My 90-day Chargeback Rescue program covers Stripe Radar rule rebuilds, Ethoca integration, 3DS gating, cancellation flow redesign, and the formal compliance documentation that processors actually accept.

Book a Free Consultation →

View Full Service Details →

Frequently Asked Questions

Mastercard ECM stands for the Excessive Chargeback Merchant program — Mastercard's compliance program for merchants whose chargeback rate runs well above normal. A merchant enters ECM after exceeding both 100 Mastercard chargebacks and a 1.5% chargeback-to-transaction ratio in a single calendar month, which triggers escalating monthly fines and, if unresolved, payment-processor account termination and placement on the MATCH list.

Mastercard's Excessive Chargeback Program (ECP) has two tiers. ECM triggers at 100–299 chargebacks and a 1.5%–2.99% chargeback rate in a month; HECM (High Excessive Chargeback Merchant) triggers at ≥300 chargebacks and a ≥3.0% rate. The rate is the current month's chargeback count divided by the preceding month's captured transaction count, on Mastercard transactions only.

With a structured remediation program, most merchants exit ECM within 60-90 days. The timeline depends on root cause identification, Stripe Radar rule deployment, Ethoca/Verifi integration, and formal compliance documentation. You must remain below threshold for 3 consecutive months to officially exit.

Mastercard ECM triggers at 100 chargebacks and a 1.5% ratio (against the preceding month's transactions) with escalating monthly fines. Visa's VAMP (which replaced VDMP/VFMP) uses a combined fraud-plus-dispute ratio: the merchant Excessive threshold is 1.5% since April 1, 2026, applying at ≥1,500 fraud + dispute transactions/month. Both can result in account termination.

Technically yes, but it requires deep expertise in payment processor fraud tools, dispute interception networks, and compliance documentation. Most subscription app teams lack this specialized knowledge. The cost of failed remediation — potential processor account termination and MATCH listing — far exceeds consulting fees.

Failure to exit ECM results in escalating monthly fines — from $1,000 up to $100,000/month in ECM, and up to $200,000/month from month 19 in HECM — plus the $5-per-chargeback-above-300 Issuer Recovery Assessment from month 4, potential MATCH listing (a 5-year ban from obtaining new merchant accounts), and eventual account termination by your payment processor.

Ethoca is a Mastercard-owned dispute interception network. When a cardholder initiates a dispute, Ethoca alerts the merchant before the chargeback is finalized. The merchant can then issue a proactive refund, preventing the dispute from counting toward the official chargeback ratio. This typically intercepts 30-50% of incoming disputes.