Why there are so many programs (and why they don't replace each other)

Every major card network runs at least one merchant monitoring program. The programs all exist for the same fundamental reason: card networks pass risk through to acquirers, and acquirers need a structured way to know which merchants threaten the chain. But each network measures slightly different things, on different cadences, with different volume floors, and with different enforcement consequences. A merchant breaching one program is often breaching others at the same time, but the timeline and the remediation playbook differ per network.

For subscription apps specifically, the relevant programs are: Visa VAMP, Mastercard ECM/ECP, Mastercard EFM, American Express CMP, and Discover's chargeback monitoring program. Above all of them sits the MATCH list — the nuclear outcome that bars the merchant principal from acquiring relationships across networks for five years.

On top of the network programs, every acquirer (Stripe, Adyen, Braintree, Checkout.com, PayPal) runs an internal risk-management layer that typically activates at lower thresholds than the network programs. That internal layer is often the first thing a merchant actually notices — a Stripe risk team email, a sudden reserve hold, a payout delay — well before any Visa or Mastercard notification reaches the merchant directly.

Visa VAMP — the consolidated Visa program

The Visa Acquirer Monitoring Program (VAMP) took effect June 1, 2025 (with enforcement from October 1, 2025), consolidating the previously separate VDMP (dispute monitoring) and VFMP (fraud monitoring) — both retired March 31, 2025 — into a single combined ratio. At merchant level there is one tier only: Excessive, and on April 1, 2026 Visa reduced that threshold from 2.2% to 1.5% in AP, Canada, EU, and the US (CEMEA stays at 2.2%). The merchant ratio only applies at 1,500 or more combined fraud and dispute transactions per month, per Visa's own VAMP fact sheet.

VAMP levelTierCombined ratioWhat happens
MerchantExcessive (only merchant tier)≥ 1.5% since Apr 1, 2026 (CEMEA: 2.2%), at ≥ 1,500 fraud + disputes/monthPer-dispute assessments + offboarding risk
AcquirerAbove Standard≥ 0.5%Acquirer-level monitoring — acquirers pass the pressure down to merchants
AcquirerExcessive≥ 0.7%Acquirer-level enforcement

The combined ratio formula: count of TC40 fraud reports + TC15 disputes ÷ count of settled transactions (TC05) — card-not-present VisaNet transactions only, count-based (not dollar-based), measured per calendar month. Disputes resolved through pre-dispute tools (RDR/CDRN) and TC40s qualified under Compelling Evidence 3.0 are excluded from the numerator. Merchant-level thresholds apply only when the merchant's acquirer is itself below the 0.5% Above-Standard line. For context on how typical merchant dispute rates compare to these thresholds, see the chargeback statistics reference.

The full operator guide for VAMP — including the structural moves that drive a successful exit and how VAMP compares directly to Mastercard ECM — is available at /vamp-guide.

Mastercard ECP — the ECM and HECM tiers

The Excessive Chargeback Program (ECP) is Mastercard's chargeback monitoring program — ECP is the program name, not a tier. It has two tiers: Excessive Chargeback Merchant (ECM) and High Excessive Chargeback Merchant (HECM). Both require an absolute chargeback count AND a chargeback rate, calculated as the current month's chargeback count divided by the preceding month's captured transaction count (per Stripe's monitoring-programs documentation).

TierChargeback countChargeback rateFines
Below ECP< 100/monthor < 1.5%No enforcement
ECM100–299/month1.5%–2.99%Mo 2–3: $1,000 · Mo 4–6: $5,000 · Mo 7–11: $25,000 · Mo 12–18: $50,000 · Mo 19+: $100,000
HECM≥ 300/month≥ 3.0%Mo 2: $1,000 · Mo 3: $2,000 · Mo 4–6: $10,000 · Mo 7–11: $50,000 · Mo 12–18: $100,000 · Mo 19+: $200,000

From the fourth month in the program, Mastercard also applies an Issuer Recovery Assessment of USD 5 per chargeback above 300 in a month, in both tiers. The 100-chargeback floor matters more than it looks: a small merchant with 50 chargebacks per month at a 3% chargeback rate stays out of ECP entirely despite a rate that would alarm any acquirer, while a merchant clearing both the count and rate conditions is enrolled regardless of how "moderate" either number looks in isolation.

Full operator guide for ECM exit: /ecm-guide. Side-by-side comparison with VAMP: /ecm-vs-vamp.

Mastercard EFM — the fraud track

The Excessive Fraud Merchant (EFM) program is Mastercard's separate fraud monitoring track, distinct from chargeback-focused ECM. EFM uses a fraud-to-sales dollar ratio rather than a transaction count ratio, which has subtle implications for subscription apps. A subscription app with many low-dollar fraud transactions can stay under the EFM dollar floor even at elevated fraud counts — the program is structured to catch high-dollar fraud concentration, not high-frequency low-dollar fraud.

TierFraud-to-salesDollar/volume floorWhat happens
Below< 0.50%anyNo enforcement
EFM≥ 0.50%≥ $50K monthly fraud and ≥ 1,000 transactionsAcquirer enforcement + fines

For most subscription apps, EFM is less likely to be the first triggered program than VAMP — the dollar floor protects low-ARR merchants, and the fraud-only measurement excludes the non-fraud "friendly fraud" disputes that drive most subscription chargebacks.

American Express CMP

American Express runs the Chargeback Monitoring Program (CMP), but Amex's program is structured differently from Visa or Mastercard's. Amex operates a closed loop — both acquirer and issuer roles are performed by Amex itself — which means enforcement is direct and bilateral. There is no acquirer between Amex and the merchant.

Amex's CMP thresholds are less publicly documented than Visa or Mastercard programs. The commonly cited entry threshold is approximately 1.00% chargeback ratio, but specific values are typically disclosed to merchants during direct enforcement contact rather than published in operating guides accessible to merchants. Amex can also place merchants under direct review at very low transaction volume — there's no meaningful volume floor.

For most subscription apps, Amex transaction share is small enough (typically 5-15% of total volume) that Amex enforcement comes later than Visa or Mastercard. But Amex's review process is faster and more direct once triggered.

Discover's program

Discover runs an Excessive Chargeback Merchant Program functionally similar to Mastercard ECM — chargeback ratio with an absolute count component, but with US-centric enforcement and smaller volume reach. For subscription apps with significant US Discover volume, the program operates at approximately a 1.00% standard threshold and 1.50% excessive threshold, though the specifics are less publicly documented than Visa or Mastercard.

Practical reality for subscription apps: Discover's transaction share is usually small enough that Discover enforcement rarely binds. If it does, the remediation playbook overlaps almost entirely with Mastercard ECM exit work.

MATCH list — the nuclear outcome

The Member Alert to Control High-risk merchants (MATCH) list is Mastercard's cross-network risk-merchant registry. It's the worst outcome in payment compliance for a merchant principal.

AttributeDetail
OwnerMastercard maintains; Visa and others query during onboarding
Duration5 years from placement
EffectEffective industry ban — most major acquirers refuse to onboard MATCH-listed merchants
TriggersExcessive chargebacks, fraud convictions, identity theft, money laundering, bankruptcy/insolvency, illegal merchant activity
Reason codes13 numeric reason codes; for subscription apps, most common are 12 (excessive chargebacks) and 04 (excessive fraud)
ExitNot removable on demand; serves full 5-year term unless successfully challenged
Avoiding MATCH. A merchant in active ECM/EFM with cooperative remediation rarely lands on MATCH. The list is generally reserved for merchants who failed to remediate, abandoned the account during enforcement, or operated unlawfully. Diligent program-exit work is the primary preventive control.

Processor-internal thresholds (the layer most teams miss)

The single most important thing about payment compliance for subscription apps in 2026 is that the processor's internal risk thresholds usually trigger before any card network program. Stripe, Adyen, Braintree, Checkout.com, and other major acquirers all run internal risk-monitoring that activates at lower thresholds than VAMP, ECM, or any network-level program.

Common processor-internal triggers I've observed across engagements:

Trigger typeApproximate thresholdTypical processor response
Combined fraud-plus-dispute ratio0.40-0.50%Enhanced review by processor risk team
Sudden ratio spike (week-over-week)2x prior 4-week averageReserve increase + payout delay
Dispute reason concentration40%+ of disputes in one reason codeSpecific remediation request (e.g., billing descriptor fix)
Card-testing fingerprint detectedPattern-based, not ratio-basedVelocity throttling on the merchant's account

The implication: monitoring only the public Visa and Mastercard thresholds gives a false sense of safety. The processor's risk team often acts on internal triggers that no public threshold publishes. The first time most subscription operators learn their processor was watching is when a payout gets delayed.

PayPal and alternative payment networks

For subscription apps with significant PayPal volume, PayPal's Seller Protection program operates as a parallel compliance layer. PayPal monitors a Seller Performance metric (combining dispute rate, refund rate, and customer claim frequency) and can place merchants under enhanced reserves, processing limits, or account holds independently of card network programs.

PayPal's specific threshold values are less publicly documented than Visa or Mastercard. The commonly observed entry threshold is approximately 1.0-1.5% Item Not Received plus Significantly Not As Described dispute rate, but PayPal's enforcement is often pattern-based rather than ratio-based — a sudden dispute spike or unusual customer-complaint pattern can trigger review at much lower ratios.

For other alternative payment methods (Apple Pay, Google Pay, Klarna, Afterpay, etc.) the underlying risk attribution flows back to the card network or BNPL provider's own monitoring. There is no separate Apple Pay or Google Pay merchant monitoring program — those payment methods inherit the card network rules.

The typical order of escalation for subscription apps

From observed pattern across engagements, the typical order in which a subscription app experiencing chargeback growth gets formally notified, in approximate sequence:

  1. Processor-internal review (Stripe risk team email, payout delay, reserve increase) — usually triggered between 0.40-0.50% combined ratio.
  2. Acquirer pressure from VAMP — your acquirer manages its own 0.5% Above-Standard / 0.7% Excessive acquirer-level thresholds and leans on high-ratio merchants well before merchant-level enforcement.
  3. Mastercard ECM enrollment — triggered at 100–299 chargebacks AND a 1.5%–2.99% chargeback rate (prior-month denominator).
  4. Visa VAMP Excessive — triggered at a 1.5% combined ratio (CEMEA: 2.2%) with at least 1,500 fraud + dispute transactions in the month.
  5. Mastercard HECM — triggered at 300+ chargebacks AND a 3.0%+ chargeback rate; fines escalate to $100,000/month at months 12–18 and $200,000/month from month 19.
  6. Amex CMP direct contact — depends on Amex transaction share; usually after Visa/Mastercard thresholds breach.
  7. Processor offboarding warning — depends on processor's contractual thresholds; often around the same time as VAMP Excessive or Mastercard ECM.
  8. MATCH placement — only if account is offboarded under unfavorable conditions and remediation was not undertaken.

What to actually monitor, monthly

The minimum monitoring set for any subscription app processing meaningful card volume:

  • VAMP combined ratio — calculate monthly using TC40 fraud + TC15 disputes ÷ settled transactions. Use the calculator for current-month estimates.
  • Mastercard chargeback ratio — chargebacks ÷ transactions, with absolute chargeback count tracked separately.
  • Fraud-to-sales dollar ratio — fraud dollar volume ÷ total sales dollar volume, for Mastercard EFM monitoring.
  • Dispute reason code distribution — concentration in any single reason code is a structural signal of a fixable root cause (e.g., billing descriptor confusion driving "unrecognized charge" disputes).
  • Processor-internal signals — payout cadence, reserve levels, any communication from the risk team. These are leading indicators that arrive before any network program triggers.

Quarterly review of the threshold tracker page to confirm no network has updated values since last review.

Compliance work is structural, not cosmetic. Better customer support emails won't move any of these ratios materially. The work is structural: tighter Stripe Radar rules, dynamic 3DS gating, Ethoca and Verifi dispute interception, billing descriptor and renewal-notification fixes, and formal compliance documentation submitted to processors in the format they expect. The 90-day rescue program walks through that structural work end to end.

Read next

Georges Rayess
About the author

Georges Rayess drove the chargeback rate at a privacy-focused subscription mobile app from 13% to below 1% and exited Mastercard ECM with compliance documents accepted by the processor on first submission. Connect on LinkedIn.

Approaching a program threshold?

Get a structured exit plan

First call covers diagnosis — which program will trip first for your business, and what the exit window looks like.

Book an Intro Call → See the Rescue Program
Watch · walkthrough

Every Card-Network Monitoring Program Subscription Apps Need to Know (2026)

A complete operator's walkthrough of the payment-compliance programs that decide whether a subscription app keeps taking card payments - Visa VAMP, Mastercar...
Video transcript

Operator's Reference · 2026 Every monitoring program The full landscape of card-network compliance programs — and the exact order they hit a subscription app. Every network runs its own program Visa VAMP Mastercard ECM · ECP · EFM Amex CMP Discover Chargeback program ☠ Above them all: the MATCH list Visa VAMP [thresholds updated since recording: one merchant tier — Excessive ≥ 1.5% since April 1, 2026 (CEMEA 2.2%), applying at 1,500+ fraud + disputes/month; acquirer-level 0.5% / 0.7%] Per-dispute assessments + offboarding risk Mastercard · ECP tiers ECM 100–299 chargebacks + 1.5–2.99% HECM 300+ chargebacks + 3.0%+ Escalating monthly fines + enrollment Both tiers need a chargeback-count floor Smaller apps stay below ECM longer. They overlap. Breach one and you're usually breaching others — but the timeline and the playbook differ for every network. The worst outcome 0 -year ban ⛔ The MATCH list Mastercard-maintained · queried by Visa at onboarding Cooperative remediation rarely lands you here. Diligent exit work is the control. The layer most teams miss 01 Your processor's internal thresholds trip before any network program. 02 Stripe, Adyen, Braintree — internal review around 0.40–0.50%. Reserve increases, payout delays, velocity throttling. 03 You usually find out when a payout gets delayed. Monitor the right things. VAMP combined ratio · Mastercard ratio + count · processor signals. Payouts and reserves are your leading indicators. georgesrayess.com/fraud/payment-monitoring-programs

Continue learning

ECM vs VAMP

Decide which program you are actually approaching first — Mastercard or Visa.

Read →

Ethoca vs Verifi

The two dispute-interception networks every app approaching VAMP or ECM needs.

Read →

Stripe Radar vs Sift

When to outgrow Radar — and when Sift is the wrong jump.

Read →