What Is Visa VAMP?

The Visa Acquirer Monitoring Program (VAMP) is Visa's compliance enforcement framework for identifying acquirers and their merchants whose combined fraud and dispute activity exceeds defined thresholds. VAMP counts a merchant's fraud transactions (TC40) plus disputes (TC15) against settled card-not-present transactions (TC05) each month, expressed as a single combined ratio (per Visa's VAMP fact sheet). When that ratio crosses the threshold, the acquirer is required to escalate monitoring, request a remediation plan, and — if the breach persists — apply further enforcement measures.

For subscription mobile apps and SaaS businesses, VAMP matters disproportionately. Subscription billing produces a steady stream of low-value recurring transactions that, when paired with even a moderate friendly-fraud rate, can push a merchant above the VAMP combined threshold faster than the same merchant ever crossed the legacy VDMP or VFMP thresholds individually. Many founders who comfortably operated under the prior split-program regime have found themselves placed under VAMP monitoring for the first time.

How VAMP Replaced VDMP and VFMP

Until they were retired on March 31, 2025, Visa ran two separate compliance programs. The Visa Dispute Monitoring Program (VDMP) tracked merchants by their non-fraud chargeback ratio. The Visa Fraud Monitoring Program (VFMP) tracked merchants by their fraud ratio. A merchant could be in one program, both, or neither. Each had its own thresholds — vendor documentation of the retired programs puts the Standard tier of each at a 0.9% ratio — its own remediation expectations, and its own fee schedules. VAMP took effect on June 1, 2025, with an advisory period through September 30, 2025 and enforcement from October 1, 2025.

VAMP consolidated both programs into a single framework with a single combined ratio. The structural argument from Visa was that the legacy split-program regime under-monitored merchants whose risk straddled the two categories — a subscription app with a moderate fraud rate and a moderate dispute rate could pass each program individually while presenting meaningful aggregate risk. The combined ratio closes that gap.

Key takeaway: VAMP is not a stricter version of VDMP or VFMP. It is a different measurement. A merchant's VAMP ratio can be above the threshold even when both legacy fraud and legacy dispute ratios were comfortably below their old individual thresholds.

The VAMP Ratio Formula in Plain Language

VAMP uses one ratio. The numerator is the count of two transaction types reported to Visa during the calendar month: fraud transactions reported via TC40 messages and disputes reported via TC15 messages (the standard chargeback transaction code). The denominator is the count of the merchant's settled transactions (TC05) for the same month. Per Visa's fact sheet, the ratio covers card-not-present VisaNet transactions only, is count-based (not dollar-based), and is measured monthly.

Stated simply: (TC40 fraud count + TC15 dispute count) ÷ settled TC05 count, expressed as a percentage. A merchant with 500 fraud reports plus 1,200 chargebacks against 600,000 settled CNP transactions in a given month produces a VAMP ratio of (500 + 1,200) ÷ 600,000 = 0.28% — well below the 1.5% Excessive threshold, though the 1,700 combined items clear the 1,500-count minimum for the ratio to apply.

Three implementation details matter for accurate self-measurement. First, disputes resolved through pre-dispute tools (Rapid Dispute Resolution and CDRN) and TC40s qualified under Compelling Evidence 3.0 are excluded from the numerator — so interception tooling directly improves the measured ratio. Second, fraud reports (TC40) are typically filed by issuing banks 1 to 30 days after the cardholder reports the fraud, so the fraud number for a given month continues to grow for several weeks after the month closes — a current-month VAMP ratio is always a moving estimate. Third, the ratio only applies to merchants with at least 1,500 combined fraud and dispute transactions in the month (CEMEA: at least 150 and USD 75,000).

Key takeaway: Track the VAMP ratio internally as a 30-day rolling estimate. Both numerator components keep growing for weeks after the month closes, so reading the ratio at month-end almost always understates the final value.

Merchant Threshold (1.5%) vs Acquirer Thresholds (0.5% / 0.7%)

VAMP defines one merchant tier — Excessive — plus two tiers that apply at the acquirer level, per Visa's VAMP fact sheet. "Above Standard" exists only at the acquirer level; there is no merchant warning tier.

Visa VAMP thresholds as of April 1, 2026: the single merchant tier, the minimum activity floor, and the two acquirer-level tiers (source: Visa VAMP fact sheet)
LevelTierThreshold
MerchantExcessive (the only merchant tier)≥1.5% combined ratio (CEMEA: 2.2%)
MerchantMinimum activity for ratio to apply≥1,500 fraud+dispute transactions/month (CEMEA: ≥150 and ≥USD 75,000)
AcquirerAbove Standard≥0.5% portfolio ratio
AcquirerExcessive≥0.7% portfolio ratio

Merchant Excessive tier — 1.5% combined ratio (CEMEA: 2.2%)

The merchant Excessive threshold is a combined VAMP ratio of 1.5%, in force since April 1, 2026 in AP, Canada, Europe, and the US (LAC was already 1.5%; CEMEA remains 2.2%). Crossing it triggers enforcement: mandatory remediation programs, the acquirer's heightened risk of being held responsible by Visa for the merchant's continued non-compliance, and — according to acquirer and processor advisories (not Visa's own fact sheet) — per-transaction assessments of roughly USD 8 per fraud or dispute transaction, with a 3-month grace period on first identification in a rolling 12 months. Merchants in the Excessive tier are at real risk of acquirer offboarding if the ratio does not recover.

Acquirer tiers — 0.5% Above Standard, 0.7% Excessive (acquirer-level only)

The 0.5% and 0.7% thresholds apply to an acquirer's entire portfolio ratio, not to any individual merchant. They matter to merchants for one structural reason: merchant-level VAMP thresholds apply only when the merchant's acquirer is itself below Above Standard (under 0.5%). An acquirer drifting toward its own thresholds will tighten merchant-level enforcement well before Visa requires it to.

Exit criteria

VAMP identification is monthly. Visa's fact sheet describes month-by-month identification of entities that exceed the thresholds and publishes no formal multi-month exit window — a merchant is out of identification in any month where the combined ratio (net of RDR/CDRN and CE3.0 exclusions) is back below the threshold, or where the 1,500 fraud-and-dispute count minimum is not met. In practice, plan for sustained recovery rather than a single clean month: acquirers run their own remediation programs on top of VAMP and typically stand down only once the downward trend holds.

What Changed on April 1, 2026

On April 1, 2026, Visa reduced the merchant Excessive threshold from 2.2% to 1.5% in AP, Canada, Europe, and the US, per Visa's VAMP fact sheet. LAC was already at 1.5% from launch, and CEMEA is unchanged at 2.2%. The practical consequence: a merchant that ran a comfortable 1.8% combined ratio through 2025 is now above threshold with no change in its own behaviour.

VAMP also includes a separate enumeration (card-testing) monitoring criterion: an enumeration ratio of ≥20% together with ≥300,000 enumerated authorization attempts (approved plus declined). Per Stripe's monitoring-programs documentation, no fines are assessed for enumeration monitoring — it drives remediation requirements rather than financial penalties. The per-transaction assessments tied to the Excessive tier (~USD 8, USD 4 at acquirer Above Standard) appear in acquirer and processor advisories rather than Visa's published fact sheet, so treat the exact amounts as processor-reported.

How VAMP Differs from Mastercard ECM

VAMP and Mastercard's Excessive Chargeback Merchant (ECM) program both monitor merchant payment risk, but they measure different things and have different enforcement profiles. The two are not redundant; a subscription business in trouble on Visa is often in trouble on Mastercard too, and the playbooks for exit overlap but are not identical.

AttributeVisa VAMPMastercard ECM
MeasurementCombined fraud + dispute ratio (CNP, count-based)Chargeback ratio only
Merchant tier(s)Excessive: 1.5% combined (CEMEA 2.2%) — single tierECM: 100–299 CBs + 1.5%–2.99%; HECM: 300+ CBs + 3.0%+
Volume floor1,500+ fraud+dispute transactions/monthRequires 100+ chargebacks in a month
Exit criteriaReassessed monthly — no published multi-month windowBelow thresholds for 3 consecutive months
EffectiveJune 1, 2025 (replaced VDMP and VFMP); 1.5% threshold from April 1, 2026Long-standing program
Nuclear outcomeAcquirer offboarding; VAMP disqualificationMATCH list (5-year ban)

The most important practical difference is the shape of the volume floor. Mastercard ECM requires both a percentage breach and 100 absolute chargebacks in a month. VAMP's floor is higher in absolute terms — at least 1,500 combined fraud and dispute transactions per month before the ratio applies — but the numerator counts fraud reports and disputes together on card-not-present volume, so a subscription merchant at meaningful scale can clear the count floor on TC40s alone before its chargeback count would ever trigger ECM.

If you want the full ECM playbook, the complete guide to exiting Mastercard's ECM program covers thresholds, escalation timeline, the 90-day exit playbook, and the five most common chargeback root causes for subscription apps.

Common Ways Subscription Apps Trigger VAMP

The structural reasons subscription apps disproportionately end up under VAMP fall into four categories. Each is fixable; each is also commonly missed because the failure mode looks like normal operating noise until the combined ratio crosses 1.5%.

1. Card testing on low-cost trials

Subscription apps that offer $0.99 or $4.99 weekly trials are attractive testing targets for stolen-card fraudsters. A single card-testing session can produce 50 to 200 successful sign-ups before fraud filters react. Even when those transactions are flagged and refunded, they often appear in TC40 fraud reports filed by issuers when the legitimate cardholder later reports the unrecognised charge. Each TC40 lands in the VAMP numerator regardless of whether the merchant already refunded the transaction.

2. Friendly fraud on subscription renewals

Friendly fraud — where the cardholder authorised the original transaction but later disputes it as unrecognised — is the dominant failure mode for subscription billing (see the chargeback statistics reference for the sourced industry numbers). Common patterns include subscription amnesia (the user forgot they signed up), shared-card disputes (a family member subscribed and the primary cardholder did not recognise it), and trial-to-paid surprise (the user did not realise the trial would convert). Each of these produces TC15 disputes that count in the VAMP numerator.

3. Aggressive paywall changes without communication

Mid-trial price changes, removal of grandfathered tiers, or shortened trial windows reliably produce a chargeback cluster within days of the change. The cluster is concentrated, so it shows up in a single month's VAMP ratio and can push a previously-stable merchant across the 1.5% Excessive threshold in one cycle.

4. Stripe Link and other one-tap flows bypassing CVC/AVS

Convenience-focused checkout features — Stripe Link, Apple Pay autofill in some configurations, browser-stored card profiles — can bypass CVC and AVS verification for the sake of conversion rate. The conversion gain is real; the cost is a higher rate of card-testing success and friendly fraud, both of which feed the VAMP numerator. Subscription merchants on Stripe should explicitly review which of their flows skip CVC/AVS and ensure that bypass is intentional, not a default.

Exiting VAMP — the Structural Moves That Work

VAMP identification is reassessed monthly, so exit is mechanical: get the combined ratio back below the threshold and keep it there. The structural moves below are the same playbook that drives a successful exit from Mastercard ECM, with VAMP-specific notes where the combined ratio changes the priority order.

1. Tighten fraud filters and 3DS gating

Stripe Radar (or the equivalent on other processors) typically ships with conservative defaults that under-block subscription-app fraud vectors. The first move is a Radar rule rebuild — adding velocity checks, IP and BIN blocklists for known testing patterns, and dynamic 3DS gating on high-risk regions and card BINs. 3DS shifts liability for fraud disputes back to the issuer, which removes them from the merchant's TC40 count and improves the VAMP ratio directly.

2. Integrate Ethoca and Verifi for dispute interception

Ethoca (Mastercard-owned) and Verifi/CDRN (Visa-owned) are dispute interception networks. When an issuer alerts that a cardholder has initiated a dispute, the merchant receives the alert before the chargeback formally posts. The merchant can issue a proactive refund, which prevents the dispute from progressing into a TC15 chargeback and removes it from the VAMP numerator entirely. For subscription apps with a meaningful friendly-fraud rate, dispute interception can lower the VAMP ratio by a structural 10 to 30% within a single month.

3. Redesign the cancellation flow

The single most under-used VAMP exit lever is the cancellation flow. Subscription apps that make cancellation harder than sign-up convert a meaningful share of cancellation intent into chargebacks instead. The fix is a self-serve cancellation flow that completes in two clicks, prompts for a refund of the most recent charge if the user is within a defined window, and acknowledges the cancellation in writing. Implemented well, this single change can reduce friendly-fraud disputes by 20 to 40% over 60 days.

4. Submit compliance documentation to the acquirer

Acquirers operating under VAMP are required to document their merchant remediation; merchants are required to participate. Submit a structured remediation plan to the acquirer covering the fraud-filter changes, the dispute interception integrations, the cancellation-flow redesign, and the timeline for ratio recovery. Acquirers move faster on merchants who arrive with a written plan than on merchants the acquirer has to chase.

Key takeaway: The VAMP exit playbook is the same structural work as the ECM exit playbook — fraud filters, dispute interception, cancellation flow, compliance documentation — but the combined-ratio framework means dispute interception (which lowers TC15 counts) and 3DS gating (which lowers TC40 counts) both contribute to ratio recovery, so prioritise both rather than choosing.

Above 1.5% — or heading there?

My 90-day Chargeback Rescue program covers the full VAMP exit playbook: Stripe Radar rule rebuilds, Ethoca/Verifi interception, 3DS gating, cancellation flow redesign, and the compliance documentation acquirers actually accept.

See the 90-Day Chargeback Rescue program →

or book a free call

When to Escalate vs When DIY Is Enough

VAMP is recoverable in-house in some scenarios and demands outside help in others. The honest assessment depends on which tier you are in, the trajectory of the ratio, and what cross-functional moves the team can land in time.

SituationDIY-suitableEscalate
VAMP positionApproaching the threshold (below 1.5%)In the Excessive tier (≥ 1.5%; CEMEA ≥ 2.2%)
TrajectoryRatio falling month over monthRatio flat or rising for 2+ months
Root causeSingle, identifiable trigger (e.g. a recent paywall change)Multi-cause: fraud + friendly fraud + cancellation friction
Acquirer relationshipAcquirer is responsive and constructiveAcquirer is escalating, threatening offboarding, or non-responsive
Internal capacityEngineering and ops can land Radar + cancellation changes inside 30 daysCross-functional coordination is the bottleneck; multiple teams can't align
Other compliance pressureOnly on VisaAlso on Mastercard (ECM/ECP) or Stripe Radar review

The pattern across engagements is consistent: merchants approaching the threshold with a clear single-cause trigger and responsive internal teams handle VAMP recovery in-house most of the time. Merchants already in the Excessive tier, with rising trajectory, multiple root causes, or strained acquirer relationships benefit substantially from outside help — both because the diagnosis is harder and because the cost of being wrong (acquirer offboarding) is no longer recoverable.

Frequently Asked Questions

What is VAMP?

VAMP is the Visa Acquirer Monitoring Program — Visa's compliance enforcement framework for tracking acquirers and merchants whose combined fraud and dispute activity exceeds defined thresholds. Effective June 1, 2025, VAMP consolidated and replaced VDMP (Visa Dispute Monitoring Program) and VFMP (Visa Fraud Monitoring Program), both retired March 31, 2025. VAMP measures fraud (TC40) and disputes (TC15) against settled card-not-present transactions using a single combined, count-based ratio.

When did VAMP start?

VAMP became effective June 1, 2025, after VDMP and VFMP were retired on March 31, 2025. An advisory (non-enforcement) period ran through September 30, 2025, with enforcement beginning October 1, 2025. On April 1, 2026, Visa reduced the merchant Excessive threshold from 2.2% to 1.5% in AP, Canada, Europe, and the US (LAC was already 1.5%; CEMEA remains 2.2%).

What is the VAMP ratio?

The VAMP ratio is the count of a merchant's fraud transactions (TC40) plus disputes (TC15 chargebacks) in a calendar month, divided by the count of settled transactions (TC05) in that month — card-not-present VisaNet transactions only, count-based rather than dollar-based. Disputes resolved through pre-dispute tools (RDR/CDRN) and TC40s qualified under Compelling Evidence 3.0 are excluded from the numerator.

What is the VAMP threshold for merchants?

There is one merchant tier: Excessive, at a combined ratio of 1.5% or higher, effective April 1, 2026 in AP, Canada, Europe, and the US (reduced from 2.2%; CEMEA remains 2.2%). The ratio only applies to merchants with at least 1,500 combined fraud and dispute transactions in the month (CEMEA: at least 150 and USD 75,000). Merchant-level thresholds apply only when the merchant's acquirer is itself below the acquirer Above Standard line of 0.5%. Source: Visa's VAMP fact sheet.

How do you exit VAMP?

VAMP identification is reassessed monthly: you are out in any month where the combined ratio (after RDR/CDRN and CE3.0 exclusions) is back below the Excessive threshold (1.5% in most regions; 2.2% in CEMEA), or where the 1,500-count minimum is not met — Visa publishes no formal multi-month exit window. The structural moves: tighten fraud filters and add 3DS gating on high-risk BINs and regions, integrate dispute interception via Ethoca and Verifi/RDR (which also removes those items from the VAMP numerator), redesign the cancellation flow to prevent friendly-fraud disputes, and submit formal compliance documentation to the acquirer.

How is the VAMP ratio calculated?

The VAMP ratio is calculated monthly as the count of (fraud transactions reported via TC40 + disputes via TC15) ÷ the count of settled transactions (TC05), card-not-present only, expressed as a percentage. RDR/CDRN-resolved disputes and Compelling Evidence 3.0-qualified TC40s are excluded. The result is compared to the merchant Excessive threshold of 1.5% (CEMEA 2.2%), which only applies at 1,500+ combined fraud and dispute transactions per month. Example: 1,500 combined fraud-and-dispute items on 100,000 settled CNP transactions is a 1.5% ratio — exactly the Excessive line.

What were VDMP and VFMP?

VDMP (Visa Dispute Monitoring Program) and VFMP (Visa Fraud Monitoring Program) were Visa's two separate legacy programs: VDMP tracked a merchant's dispute and chargeback ratio, and VFMP tracked the fraud-to-sales ratio. According to vendor documentation of the retired programs, each had a Standard tier at a 0.9% ratio. Visa retired both on March 31, 2025 and replaced them with a single program — VAMP, effective June 1, 2025 — which measures fraud and disputes together as one combined ratio. If you're looking for VDMP or VFMP thresholds today, VAMP is the program that now applies.

Is VAMP worse than ECM?

VAMP and Mastercard ECM measure different things. ECM is triggered by 100–299 chargebacks plus a 1.5%–2.99% chargeback ratio in a month (HECM at 300+ and 3.0%+). VAMP's merchant Excessive threshold is also 1.5%, but it is a combined fraud-plus-dispute ratio on card-not-present transactions, and it only applies at 1,500+ combined fraud and dispute transactions per month. Neither is "worse"; they monitor different things, and a merchant in trouble on one is often in trouble on both.