ECM vs VAMP
Decide which program you are actually approaching first — Mastercard or Visa.
Read →Most operators learn about payment compliance programs the hard way — one acquirer email at a time. This guide walks through the full landscape, from VAMP and ECM to lesser-known programs like Mastercard EFM and Amex CMP, and how processors layer their own thresholds on top.
Every major card network runs at least one merchant monitoring program. The programs all exist for the same fundamental reason: card networks pass risk through to acquirers, and acquirers need a structured way to know which merchants threaten the chain. But each network measures slightly different things, on different cadences, with different volume floors, and with different enforcement consequences. A merchant breaching one program is often breaching others at the same time, but the timeline and the remediation playbook differ per network.
For subscription apps specifically, the relevant programs are: Visa VAMP, Mastercard ECM/ECP, Mastercard EFM, American Express CMP, and Discover's chargeback monitoring program. Above all of them sits the MATCH list — the nuclear outcome that bars the merchant principal from acquiring relationships across networks for five years.
On top of the network programs, every acquirer (Stripe, Adyen, Braintree, Checkout.com, PayPal) runs an internal risk-management layer that typically activates at lower thresholds than the network programs. That internal layer is often the first thing a merchant actually notices — a Stripe risk team email, a sudden reserve hold, a payout delay — well before any Visa or Mastercard notification reaches the merchant directly.
The Visa Acquirer Monitoring Program (VAMP) took effect June 1, 2025 (with enforcement from October 1, 2025), consolidating the previously separate VDMP (dispute monitoring) and VFMP (fraud monitoring) — both retired March 31, 2025 — into a single combined ratio. At merchant level there is one tier only: Excessive, and on April 1, 2026 Visa reduced that threshold from 2.2% to 1.5% in AP, Canada, EU, and the US (CEMEA stays at 2.2%). The merchant ratio only applies at 1,500 or more combined fraud and dispute transactions per month, per Visa's own VAMP fact sheet.
| VAMP level | Tier | Combined ratio | What happens |
|---|---|---|---|
| Merchant | Excessive (only merchant tier) | ≥ 1.5% since Apr 1, 2026 (CEMEA: 2.2%), at ≥ 1,500 fraud + disputes/month | Per-dispute assessments + offboarding risk |
| Acquirer | Above Standard | ≥ 0.5% | Acquirer-level monitoring — acquirers pass the pressure down to merchants |
| Acquirer | Excessive | ≥ 0.7% | Acquirer-level enforcement |
The combined ratio formula: count of TC40 fraud reports + TC15 disputes ÷ count of settled transactions (TC05) — card-not-present VisaNet transactions only, count-based (not dollar-based), measured per calendar month. Disputes resolved through pre-dispute tools (RDR/CDRN) and TC40s qualified under Compelling Evidence 3.0 are excluded from the numerator. Merchant-level thresholds apply only when the merchant's acquirer is itself below the 0.5% Above-Standard line. For context on how typical merchant dispute rates compare to these thresholds, see the chargeback statistics reference.
The full operator guide for VAMP — including the structural moves that drive a successful exit and how VAMP compares directly to Mastercard ECM — is available at /vamp-guide.
The Excessive Chargeback Program (ECP) is Mastercard's chargeback monitoring program — ECP is the program name, not a tier. It has two tiers: Excessive Chargeback Merchant (ECM) and High Excessive Chargeback Merchant (HECM). Both require an absolute chargeback count AND a chargeback rate, calculated as the current month's chargeback count divided by the preceding month's captured transaction count (per Stripe's monitoring-programs documentation).
| Tier | Chargeback count | Chargeback rate | Fines |
|---|---|---|---|
| Below ECP | < 100/month | or < 1.5% | No enforcement |
| ECM | 100–299/month | 1.5%–2.99% | Mo 2–3: $1,000 · Mo 4–6: $5,000 · Mo 7–11: $25,000 · Mo 12–18: $50,000 · Mo 19+: $100,000 |
| HECM | ≥ 300/month | ≥ 3.0% | Mo 2: $1,000 · Mo 3: $2,000 · Mo 4–6: $10,000 · Mo 7–11: $50,000 · Mo 12–18: $100,000 · Mo 19+: $200,000 |
From the fourth month in the program, Mastercard also applies an Issuer Recovery Assessment of USD 5 per chargeback above 300 in a month, in both tiers. The 100-chargeback floor matters more than it looks: a small merchant with 50 chargebacks per month at a 3% chargeback rate stays out of ECP entirely despite a rate that would alarm any acquirer, while a merchant clearing both the count and rate conditions is enrolled regardless of how "moderate" either number looks in isolation.
Full operator guide for ECM exit: /ecm-guide. Side-by-side comparison with VAMP: /ecm-vs-vamp.
The Excessive Fraud Merchant (EFM) program is Mastercard's separate fraud monitoring track, distinct from chargeback-focused ECM. EFM uses a fraud-to-sales dollar ratio rather than a transaction count ratio, which has subtle implications for subscription apps. A subscription app with many low-dollar fraud transactions can stay under the EFM dollar floor even at elevated fraud counts — the program is structured to catch high-dollar fraud concentration, not high-frequency low-dollar fraud.
| Tier | Fraud-to-sales | Dollar/volume floor | What happens |
|---|---|---|---|
| Below | < 0.50% | any | No enforcement |
| EFM | ≥ 0.50% | ≥ $50K monthly fraud and ≥ 1,000 transactions | Acquirer enforcement + fines |
For most subscription apps, EFM is less likely to be the first triggered program than VAMP — the dollar floor protects low-ARR merchants, and the fraud-only measurement excludes the non-fraud "friendly fraud" disputes that drive most subscription chargebacks.
American Express runs the Chargeback Monitoring Program (CMP), but Amex's program is structured differently from Visa or Mastercard's. Amex operates a closed loop — both acquirer and issuer roles are performed by Amex itself — which means enforcement is direct and bilateral. There is no acquirer between Amex and the merchant.
Amex's CMP thresholds are less publicly documented than Visa or Mastercard programs. The commonly cited entry threshold is approximately 1.00% chargeback ratio, but specific values are typically disclosed to merchants during direct enforcement contact rather than published in operating guides accessible to merchants. Amex can also place merchants under direct review at very low transaction volume — there's no meaningful volume floor.
For most subscription apps, Amex transaction share is small enough (typically 5-15% of total volume) that Amex enforcement comes later than Visa or Mastercard. But Amex's review process is faster and more direct once triggered.
Discover runs an Excessive Chargeback Merchant Program functionally similar to Mastercard ECM — chargeback ratio with an absolute count component, but with US-centric enforcement and smaller volume reach. For subscription apps with significant US Discover volume, the program operates at approximately a 1.00% standard threshold and 1.50% excessive threshold, though the specifics are less publicly documented than Visa or Mastercard.
Practical reality for subscription apps: Discover's transaction share is usually small enough that Discover enforcement rarely binds. If it does, the remediation playbook overlaps almost entirely with Mastercard ECM exit work.
The Member Alert to Control High-risk merchants (MATCH) list is Mastercard's cross-network risk-merchant registry. It's the worst outcome in payment compliance for a merchant principal.
| Attribute | Detail |
|---|---|
| Owner | Mastercard maintains; Visa and others query during onboarding |
| Duration | 5 years from placement |
| Effect | Effective industry ban — most major acquirers refuse to onboard MATCH-listed merchants |
| Triggers | Excessive chargebacks, fraud convictions, identity theft, money laundering, bankruptcy/insolvency, illegal merchant activity |
| Reason codes | 13 numeric reason codes; for subscription apps, most common are 12 (excessive chargebacks) and 04 (excessive fraud) |
| Exit | Not removable on demand; serves full 5-year term unless successfully challenged |
The single most important thing about payment compliance for subscription apps in 2026 is that the processor's internal risk thresholds usually trigger before any card network program. Stripe, Adyen, Braintree, Checkout.com, and other major acquirers all run internal risk-monitoring that activates at lower thresholds than VAMP, ECM, or any network-level program.
Common processor-internal triggers I've observed across engagements:
| Trigger type | Approximate threshold | Typical processor response |
|---|---|---|
| Combined fraud-plus-dispute ratio | 0.40-0.50% | Enhanced review by processor risk team |
| Sudden ratio spike (week-over-week) | 2x prior 4-week average | Reserve increase + payout delay |
| Dispute reason concentration | 40%+ of disputes in one reason code | Specific remediation request (e.g., billing descriptor fix) |
| Card-testing fingerprint detected | Pattern-based, not ratio-based | Velocity throttling on the merchant's account |
The implication: monitoring only the public Visa and Mastercard thresholds gives a false sense of safety. The processor's risk team often acts on internal triggers that no public threshold publishes. The first time most subscription operators learn their processor was watching is when a payout gets delayed.
For subscription apps with significant PayPal volume, PayPal's Seller Protection program operates as a parallel compliance layer. PayPal monitors a Seller Performance metric (combining dispute rate, refund rate, and customer claim frequency) and can place merchants under enhanced reserves, processing limits, or account holds independently of card network programs.
PayPal's specific threshold values are less publicly documented than Visa or Mastercard. The commonly observed entry threshold is approximately 1.0-1.5% Item Not Received plus Significantly Not As Described dispute rate, but PayPal's enforcement is often pattern-based rather than ratio-based — a sudden dispute spike or unusual customer-complaint pattern can trigger review at much lower ratios.
For other alternative payment methods (Apple Pay, Google Pay, Klarna, Afterpay, etc.) the underlying risk attribution flows back to the card network or BNPL provider's own monitoring. There is no separate Apple Pay or Google Pay merchant monitoring program — those payment methods inherit the card network rules.
From observed pattern across engagements, the typical order in which a subscription app experiencing chargeback growth gets formally notified, in approximate sequence:
The minimum monitoring set for any subscription app processing meaningful card volume:
Quarterly review of the threshold tracker page to confirm no network has updated values since last review.
First call covers diagnosis — which program will trip first for your business, and what the exit window looks like.
Operator's Reference · 2026 Every monitoring program The full landscape of card-network compliance programs — and the exact order they hit a subscription app. Every network runs its own program Visa VAMP Mastercard ECM · ECP · EFM Amex CMP Discover Chargeback program ☠ Above them all: the MATCH list Visa VAMP [thresholds updated since recording: one merchant tier — Excessive ≥ 1.5% since April 1, 2026 (CEMEA 2.2%), applying at 1,500+ fraud + disputes/month; acquirer-level 0.5% / 0.7%] Per-dispute assessments + offboarding risk Mastercard · ECP tiers ECM 100–299 chargebacks + 1.5–2.99% HECM 300+ chargebacks + 3.0%+ Escalating monthly fines + enrollment Both tiers need a chargeback-count floor Smaller apps stay below ECM longer. They overlap. Breach one and you're usually breaching others — but the timeline and the playbook differ for every network. The worst outcome 0 -year ban ⛔ The MATCH list Mastercard-maintained · queried by Visa at onboarding Cooperative remediation rarely lands you here. Diligent exit work is the control. The layer most teams miss 01 Your processor's internal thresholds trip before any network program. 02 Stripe, Adyen, Braintree — internal review around 0.40–0.50%. Reserve increases, payout delays, velocity throttling. 03 You usually find out when a payout gets delayed. Monitor the right things. VAMP combined ratio · Mastercard ratio + count · processor signals. Payouts and reserves are your leading indicators. georgesrayess.com/fraud/payment-monitoring-programs