Mastercard monitors merchant risk via three models: ECM and EFM use threshold math with scaling fines, while the new SMMP threatens immediate account blocks. Here is a breakdown of all three programs, MATCH Pro, and their core formulas.
Chargebacks, fraud, and scams are monitored separately, each with its own math and its own consequences. A merchant can be clean on two of the three and still lose processing on the third.
| Program | What it watches | The line | What happens |
|---|---|---|---|
| SMMP · Scam Merchant Monitoring | Scam signals: authorization collapse, issuer scam reports, refund-heavy new merchants | Trigger-based, not monthly math | 72-hour investigation; immediate block if confirmed |
| ECM · Excessive Chargeback Merchant | Chargeback count and ratio, per merchant account | 100+ and 1.5%+ | Fine ladder to $100,000+; remediation plans |
| EFM · Excessive Fraud Merchant | Card-not-present fraud volume, rate, and 3-D Secure share | $50k + 0.50% + low 3DS | Fine ladder to $100,000 |
| MATCH Pro · the list | Merchants terminated for cause, listed by acquirers | Reason-coded listing | Underwriting failure at nearly every provider |
Mastercard Security Rules and Procedures, Merchant Edition (4 August 2026) for SMMP and MATCH Pro; Mastercard Data Integrity thresholds as documented by Stripe and acquirer notices for ECM and EFM.
Mastercard Security Rules and Procedures, Merchant Edition (4 August 2026); ECM and EFM lines as documented by Stripe and acquirer notices. Checked 2 September 2026.
Each is a percentage of your transactions, but they do not count the same events: EFM counts fraud chargebacks, ECM and HECM count all chargebacks, and SMMP counts refunds and chargebacks together. Three separate measurements, not one number you can compare across programs. Note that 1.5% does double duty: it is both the ECM entry ratio and the MATCH Pro reason code 04 threshold.
Three programs, three different kinds of math. Each tab carries one program’s formula, its thresholds, and the fine ladder or the block that follows.
All chargeback reason codes
The Excessive Chargeback Merchant program is Mastercard’s long-standing chargeback initiative, and its thresholds are unchanged through 2026. Both a count and a ratio must be breached in the same month.
The chargeback-to-transaction ratio (CTR)
Chargebacks received this month
Mastercard transactions last month
Note the lag: this month’s chargebacks are divided by last month’s transaction count. A sudden jump in sales volume mathematically spikes your ratio even when your dispute count feels flat, which is exactly how growing merchants stumble into the program.
| Tier | Monthly chargebacks | CTR |
|---|---|---|
| ECM · Excessive Chargeback Merchant | 100–299 | 1.5%–2.99% |
| HECM · High Excessive Chargeback Merchant | 300+ | 3.0%+ |
Chargebacks count regardless of outcome: winning the representment later does not remove the chargeback from the month it landed in, and neither does refunding after the fact. The fines escalate by how many months the account has been over the line:
| Months over threshold | ECM fine | HECM fine |
|---|---|---|
| Month 1 | $0 | $0 |
| Months 2–3 | $1,000 | $1,000–$2,000 |
| Months 4–6 | $5,000 | $10,000 + IR |
| Months 7–11 | $25,000 | $50,000 + IR |
| Months 12–18 | $50,000 | $100,000 + IR |
| Month 19 and on | $100,000 | $200,000 + IR |
IR is issuer recovery: from month 4, an additional $5 per chargeback above 300 in the month, paid to reimburse issuers. Worked example, month 4 with 400 chargebacks: $5,000 + (100 × $5) = $5,500 for the month. Exit requires three consecutive months below threshold, and after six months in the program (consecutive or not) Mastercard can impose an action plan and a customer risk review at the acquirer’s expense.
Make sure you have alert coverage.
Reason codes 4837 · 4863
The Excessive Fraud Merchant program measures fraud performance separately from chargebacks. A merchant with healthy overall disputes can still be flagged here, because EFM counts fraud chargebacks and low 3-D Secure use rather than your total dispute volume. All four conditions are measured in the same month, and together.
The fraud chargeback rate
Fraud chargebacks received this month
Mastercard transactions last month
Note the lag: this month’s fraud chargebacks are divided by last month’s transaction count. A sudden jump in sales volume mathematically spikes your ratio even when your disputes feel flat.
Two things to know about how the program behaves:
| Months over threshold | EFM fine |
|---|---|
| Month 1 | $0 |
| Month 2 | $500 |
| Month 3 | $1,000 |
| Months 4–6 | $5,000 |
| Months 7–11 | $25,000 |
| Months 12–18 | $50,000 |
| Month 19 and on | $100,000 |
The program does not apply in Germany, India, or Switzerland. Australia runs lower entry lines: $15,000 fraud volume and a 0.20% rate. A merchant account in either ECM or EFM for 12 months pays the higher of the two assessments.
Front end fraud tools minimize the threat of EFM.
Fraud type 56
The Scam Merchant Monitoring Program (SMMP) launched on July 24, 2026. SMMP focuses on deceptive business practices, where the customer believes the marketing misled them. SMMP is especially sensitive to fraud type 56.
Merchants with six months or less of Mastercard history carry additional triggers. Any one is enough on its own:
Mastercard Security Rules and Procedures, Merchant Edition (4 August 2026), §7.2.1.
Preemptive refunds create hidden exposure under SMMP. By explicitly including transactions subject to “refunds or chargebacks or both,” the rule counts pre-dispute refunds toward the 5% threshold. This directly opposes the Visa VAMP model, where RDR refunds insulate your metrics.
An authorization rate collapse triggers a Mastercard SMMP investigation because Mastercard’s network-level monitoring treats a sudden wave of issuer declines as the behavior of deceptive or fraudulent scam operations. If your approval rate drops below 30%, you’re automatically added to SMMP.
BIN attacks and processor outages are excluded, so this trigger reads as issuers collectively declining you.
An MMSP alert is a flag triggered when an automated merchant monitoring service provider detects that a merchant is potentially engaging in deceptive business models, scams, or illicit payment routing.
The automated scanners look for structural patterns of fraud, including:
CriticalAlert classification
Potential scam merchant · suspected illegal activity
Vitaglow Labs Ltd vitaglow-shop.com
Transaction launderingpayment page not on file
MCC misalignment5499 vs 7995
Deceptive redirectscloaked to the scanner
Investigation openedOne alert is the whole threshold.
One alert opens the investigation
One MMSP alert identifying the account as a potential scam merchant, or as suspected illegal activity, opens the investigation.
SMMP extends accountability to your entire acquisition chain. A merchant can have strong sales and a clean technical chargeback rate and still trigger a scam investigation if the business model, the ads, or the checkout appear designed to confuse the customer.
Audit your checkout, billing descriptors and cancellation flow before an investigator does.
MATCH Pro is Mastercard’s risk database. Acquiring banks and payment processors use it to screen high-risk businesses.
All three monitoring programs can end here. A MATCH Pro listing follows a termination for cause, and ECM, EFM and SMMP can each end in one: chargebacks that never come down, fraud that stays above the line, or a confirmed scam block.
MATCH Pro listings typically stick for five years, with removal restricted to acquirer reporting errors, identity theft, or resolved PCI non-compliance. Only the listing bank can initiate removal. The ECM and EFM fine ladders exist to give merchants months of advance warning before account termination becomes the cheaper option for the acquirer.
Mastercard pressures acquirers and payment facilitators, who then pressure you. When a processor “gets difficult,” it is usually one of these programs working as designed.
Acquirers answer to Mastercard for their portfolios, and payment facilitators can have their whole book audited when a cluster of bad accounts draws network attention. That is why:
Three actions you can take to stay off the lists.
Don’t assume you’ll see GRIP letters and MMSP alerts. They arrive with your acquirer, and you’ll rarely see them.
Your own numbers show the data-based triggers before they fire, so read them weekly.
Check your:
Hi Alex — here is exactly what happens next, so nothing on your statement is a surprise.
First charge25 Sep 2026
Amount€19.90
Then€19.90 monthly, until cancelled
Statement lineNORTHLANE PRO
Remind them before the money moves
Every SMMP flag is something a customer experienced before Mastercard measured it.
Fix what the customer sees, because that is what an investigator reads.
Mastercard and Visa license pre-dispute products to alert providers like Chargeblast, Disputifier, and Chargemont, who layer more on top:
White-label platform with quick setup. Handles chargeback alerts and front-end fraud prevention in one dashboard, validating device fingerprints, purchase regions, and buyer behavior at the point of sale.
Learn more →Real-time chargeback alert platform. Intercepts disputes before they hit your processor’s formal count and integrates with major gateways for automated resolution.
Learn more →Full-service chargeback management. Provides dispute intelligence, alert routing, and prevention analytics for subscription-heavy merchant portfolios.
Learn more →Chargeback alerts and dispute prevention that intercept disputes before they register with your processor.
Learn more →An alert resolved before the chargeback posts helps with ECM and EFM. Under SMMP the same refund still counts toward the new-merchant 5%, so pair the alerts with root-cause fixes rather than leaning on them alone.
Alerts buy headroom on ECM and EFM.
The programs, codes and tools this guide leans on, in plain terms.
The Scam Merchant Monitoring Program, effective July 24, 2026. Trigger conditions open a mandatory 72-hour acquirer investigation; confirmed scam activity means an immediate Mastercard and Maestro block.
The Global Rules Investigation Program. A GRIP letter is a formal Mastercard notice to an acquirer that an account is connected to suspected scam activity, and is itself an SMMP trigger.
A Merchant Monitoring Service Provider: a third party that watches merchant behavior for acquirers. One MMSP scam alert is enough to open the 72-hour investigation.
“Manipulation of Cardholder” in Mastercard’s Fraud and Loss Database: the issuer’s code for a scam report, as distinct from stolen-card fraud. Two issuers filing it against a new merchant is an SMMP trigger.
Excessive Chargeback Merchant and its high tier. Entry at 100+ chargebacks and a 1.5%+ ratio in the same month; HECM at 300+ and 3%+.
The chargeback-to-transaction ratio: this month’s chargebacks divided by last month’s Mastercard transactions. The lag means falling sales raise the ratio on their own.
Excessive Fraud Merchant. Four conditions measured together: 1,000+ eCommerce transactions, $50,000+ net fraud chargebacks, a 0.50%+ fraud rate, and a low 3-D Secure share.
The authentication layer (Mastercard Identity Check) that shifts fraud liability to the issuer. Its share of your volume is a formal EFM condition.
The Mastercard Alert to Control High-risk Merchants: the reason-coded list of terminated merchants, checked by underwriters across the industry. Formerly MATCH.
Mastercard’s alert network. Issuer alerts arrive before a chargeback posts, leaving a window to refund or resolve. Under the SMMP new-merchant trigger, that refund still counts toward the 5%.
Compaytence is a global payments and compliance consultancy working across a network of 30+ top-tier providers. Mastercard’s programs are squarely inside the work: keeping merchants out of them, and managing the relationship when an account is already under review.
Having questions about Mastercard & your compliance? Compaytence takes the guesswork out. Book a call now!
Sources
Figures verified 2 September 2026 against the Mastercard Security Rules and Procedures, Merchant Edition (4 August 2026 edition, §7.2.1 for SMMP), Stripe and acquirer documentation of the Data Integrity fine schedules, and trade-press coverage of the July 2026 launch. Thresholds change; confirm the current tables before relying on a figure in an underwriting or remediation context. Mastercard, Maestro and the interlocking-circles mark belong to Mastercard International; this guide is independent merchant education and is not endorsed by Mastercard.