Compaytence · Payment Risk Client-facing · 23 September 2026

Mastercard Monitoring
The Merchant Guide

Mastercard monitors merchant risk via three models: ECM and EFM use threshold math with scaling fines, while the new SMMP threatens immediate account blocks. Here is a breakdown of all three programs, MATCH Pro, and their core formulas.

For
Merchants processing Mastercard
Updated
23 September 2026
Covers
SMMP, ECM, EFM and MATCH Pro
Book a Call Mastercard
01

The Three Programs

Chargebacks, fraud, and scams are monitored separately, each with its own math and its own consequences. A merchant can be clean on two of the three and still lose processing on the third.

ProgramWhat it watchesThe lineWhat happens
SMMP · Scam Merchant MonitoringScam signals: authorization collapse, issuer scam reports, refund-heavy new merchantsTrigger-based, not monthly math72-hour investigation; immediate block if confirmed
ECM · Excessive Chargeback MerchantChargeback count and ratio, per merchant account100+ and 1.5%+Fine ladder to $100,000+; remediation plans
EFM · Excessive Fraud MerchantCard-not-present fraud volume, rate, and 3-D Secure share$50k + 0.50% + low 3DSFine ladder to $100,000
MATCH Pro · the listMerchants terminated for cause, listed by acquirersReason-coded listingUnderwriting failure at nearly every provider

Mastercard Security Rules and Procedures, Merchant Edition (4 August 2026) for SMMP and MATCH Pro; Mastercard Data Integrity thresholds as documented by Stripe and acquirer notices for ECM and EFM.

The three ratios
EFM · fraud chargebacks against last month’s transactions0.50%
ECM entry · all chargebacks (3.0% and up is the HECM high tier)1.5%
SMMP · refunds + chargebacks, first six months only, rolling 30 days5%

Mastercard Security Rules and Procedures, Merchant Edition (4 August 2026); ECM and EFM lines as documented by Stripe and acquirer notices. Checked 2 September 2026.

Each is a percentage of your transactions, but they do not count the same events: EFM counts fraud chargebacks, ECM and HECM count all chargebacks, and SMMP counts refunds and chargebacks together. Three separate measurements, not one number you can compare across programs. Note that 1.5% does double duty: it is both the ECM entry ratio and the MATCH Pro reason code 04 threshold.

02

The Programs in Detail

Three programs, three different kinds of math. Each tab carries one program’s formula, its thresholds, and the fine ladder or the block that follows.

ECM · Excessive Chargebacks

All chargeback reason codes

The Excessive Chargeback Merchant program is Mastercard’s long-standing chargeback initiative, and its thresholds are unchanged through 2026. Both a count and a ratio must be breached in the same month.

Note the lag: this month’s chargebacks are divided by last month’s transaction count. A sudden jump in sales volume mathematically spikes your ratio even when your dispute count feels flat, which is exactly how growing merchants stumble into the program.

TierMonthly chargebacksCTR
ECM · Excessive Chargeback Merchant100–2991.5%–2.99%
HECM · High Excessive Chargeback Merchant300+3.0%+

Chargebacks count regardless of outcome: winning the representment later does not remove the chargeback from the month it landed in, and neither does refunding after the fact. The fines escalate by how many months the account has been over the line:

Months over thresholdECM fineHECM fine
Month 1$0$0
Months 2–3$1,000$1,000–$2,000
Months 4–6$5,000$10,000 + IR
Months 7–11$25,000$50,000 + IR
Months 12–18$50,000$100,000 + IR
Month 19 and on$100,000$200,000 + IR

IR is issuer recovery: from month 4, an additional $5 per chargeback above 300 in the month, paid to reimburse issuers. Worked example, month 4 with 400 chargebacks: $5,000 + (100 × $5) = $5,500 for the month. Exit requires three consecutive months below threshold, and after six months in the program (consecutive or not) Mastercard can impose an action plan and a customer risk review at the acquirer’s expense.

Bottom line

Make sure you have alert coverage.

EFM · Excessive Fraud

Reason codes 4837 · 4863

The Excessive Fraud Merchant program measures fraud performance separately from chargebacks. A merchant with healthy overall disputes can still be flagged here, because EFM counts fraud chargebacks and low 3-D Secure use rather than your total dispute volume. All four conditions are measured in the same month, and together.

Note the lag: this month’s fraud chargebacks are divided by last month’s transaction count. A sudden jump in sales volume mathematically spikes your ratio even when your disputes feel flat.

All four means EFM
  • 1,000 or more Mastercard eCommerce transactions.
  • Net fraud chargeback volume above $50,000.
  • A fraud chargeback rate above 0.50%, on the same lagged math as ECM.
  • 3-D Secure on 10% or less of Mastercard volume (50% or less where SCA regulation applies).

Two things to know about how the program behaves:

  • 3DS gives you the most power over EFM: it is the condition merchants control most directly, and authenticating a meaningful share of volume takes you out of EFM territory even when fraud is high.
  • EFM takes precedence, but ECM keeps counting: when a merchant qualifies for both in the same month, EFM takes precedence for that month’s assessment, but the ECM month counter keeps running underneath.
Months over thresholdEFM fine
Month 1$0
Month 2$500
Month 3$1,000
Months 4–6$5,000
Months 7–11$25,000
Months 12–18$50,000
Month 19 and on$100,000

The program does not apply in Germany, India, or Switzerland. Australia runs lower entry lines: $15,000 fraud volume and a 0.20% rate. A merchant account in either ECM or EFM for 12 months pays the higher of the two assessments.

Bottom line

Front end fraud tools minimize the threat of EFM.

SMMP · The Scam Program

Fraud type 56

The Scam Merchant Monitoring Program (SMMP) launched on July 24, 2026. SMMP focuses on deceptive business practices, where the customer believes the marketing misled them. SMMP is especially sensitive to fraud type 56.

Triggers

Extra rules in your first six months

Merchants with six months or less of Mastercard history carry additional triggers. Any one is enough on its own:

  • Two issuers reporting scam fraud: two different issuers each reporting at least one transaction as scam-type fraud (fraud type 56, “Manipulation of Cardholder”, in Mastercard’s Fraud and Loss Database).
  • Two issuers citing scams in a chargeback: two or more issuers filing chargebacks, fraud or non-fraud, whose supporting documentation refers to scams or manipulation.
The new-merchant refund trigger
Combined rate: refunds + chargebacks over purchase transactions5%
Rolling window: any 30-day period, not the calendar month30 days
Minimum volume: purchase transactions inside that window500
Who it covers: Mastercard acceptance history at or under six months6 months

Mastercard Security Rules and Procedures, Merchant Edition (4 August 2026), §7.2.1.

Refunds count:

Preemptive refunds create hidden exposure under SMMP. By explicitly including transactions subject to “refunds or chargebacks or both,” the rule counts pre-dispute refunds toward the 5% threshold. This directly opposes the Visa VAMP model, where RDR refunds insulate your metrics.

Your approval rate falls off a cliff

An authorization rate collapse triggers a Mastercard SMMP investigation because Mastercard’s network-level monitoring treats a sudden wave of issuer declines as the behavior of deceptive or fraudulent scam operations. If your approval rate drops below 30%, you’re automatically added to SMMP.

Mastercard’s worked example: a 95% approval rate falling to 45% across 72 hours. APPROVAL RATE Seven-day baseline 95% After the drop 45% 30% floor Either condition fires it on its own. BIN attacks and processor outages are excluded.
  • The average approval rate drops 50 percentage points against your preceding seven-day baseline. Mastercard’s own example is 95% to 45%.
  • It falls below 30% outright.

BIN attacks and processor outages are excluded, so this trigger reads as issuers collectively declining you.

A monitoring provider flags you

An MMSP alert is a flag triggered when an automated merchant monitoring service provider detects that a merchant is potentially engaging in deceptive business models, scams, or illicit payment routing.

The automated scanners look for structural patterns of fraud, including:

  • Transaction laundering: hiding unauthorized or illegal transactions behind a seemingly harmless approved website.
  • Merchant Category Code (MCC) misalignment: intentionally misclassifying a business type to skirt risk rules, such as hiding a high-risk adult or gambling site under a retail profile.
  • Deceptive content and redirects: using stealth domain redirects or hidden checkouts to obscure the true nature of what is being sold.
argus-mm.com/alerts
AArgus Merchant MonitoringMMSP · automated scan

CriticalAlert classification

Potential scam merchant · suspected illegal activity

Vitaglow Labs Ltd vitaglow-shop.com

Transaction launderingpayment page not on file

MCC misalignment5499 vs 7995

Deceptive redirectscloaked to the scanner

Investigation openedOne alert is the whole threshold.

One alert opens the investigation

  1. A machine made the call. A crawler read the site and filed this on its own. No customer complained first.
  2. Chargebacks don’t trigger this. It reads how the business is wired: where the money lands, what the MCC claims, which page the buyer actually sees.
  3. One alert opens the file. There is no safe number to stay under.
Fictional monitoring vendor, merchant and domains.

One MMSP alert identifying the account as a potential scam merchant, or as suspected illegal activity, opens the investigation.

What actually gets merchants flagged
  • Subscription enrollment buried in checkout fine print, or pre-checked.
  • Billing descriptors that do not match the brand the customer bought from.
  • Cancellation that requires a phone call, or cannot be found at all.
  • A volume spike tied to a new ad campaign or affiliate push.
  • Affiliates and lead generators running claims you never approved.
  • A new merchant account carrying high CNP volume with no history behind it.
What deceptive marketing looks like
A composite of deceptive patterns. No real brand, person or publication appears here. WHAT GETS READ AS DECEPTIVE NORTHLANE PRO “I made €4,200 in my first week. Life-changing.” Dr. A. Vance · Verified buyer ★★★★★ AS SEEN IN NEWS 4 FINANCE DAILY THE LEDGER OFFER ENDS IN 04:59 €19.90/mo was €79 1 2 3 4 1 Earnings claim A specific figure with no basis a reader could check. 2 Borrowed authority A title, and a badge the seller issued to itself. 3 Invented press Publication marks for outlets the brand was never featured in. 4 Manufactured urgency A timer that resets, beside a price that never applied. Any one of these invites the question. Together they are the pattern SMMP was written for.

Remember that the SMMP results in an immediate block, and you might not even know it’s coming.

SMMP extends accountability to your entire acquisition chain. A merchant can have strong sales and a clean technical chargeback rate and still trigger a scam investigation if the business model, the ads, or the checkout appear designed to confuse the customer.

Bottom line

Audit your checkout, billing descriptors and cancellation flow before an investigator does.

03

MATCH Pro

MATCH Pro is Mastercard’s risk database. Acquiring banks and payment processors use it to screen high-risk businesses.

All three monitoring programs can end here. A MATCH Pro listing follows a termination for cause, and ECM, EFM and SMMP can each end in one: chargebacks that never come down, fraud that stays above the line, or a confirmed scam block.

Removal plans rarely succeed

MATCH Pro listings typically stick for five years, with removal restricted to acquirer reporting errors, identity theft, or resolved PCI non-compliance. Only the listing bank can initiate removal. The ECM and EFM fine ladders exist to give merchants months of advance warning before account termination becomes the cheaper option for the acquirer.

04

The Ripple Effect

Mastercard pressures acquirers and payment facilitators, who then pressure you. When a processor “gets difficult,” it is usually one of these programs working as designed.

Acquirers answer to Mastercard for their portfolios, and payment facilitators can have their whole book audited when a cluster of bad accounts draws network attention. That is why:

What the pressure looks like from your side
Mastercard pressures your acquirer; your acquirer pressures you. Here is what that looks like from your side. WHILE THE ACCOUNT IS OPEN Mandatory tooling Alert and deflection products, enrolled as a condition of keeping the account. Rolling reserve One appearing, or an existing one growing, as a ratio grows. Settlement delays Payouts held while the review window runs. AFTER IT CLOSES Termination Once the fines and the risk outweigh your processing revenue. MATCH Pro listing Reason-coded, around five years, checked in underwriting on any network.
05

Staying Off the Lists

Three actions you can take to stay off the lists.

Pull 90 days of your own data

Don’t assume you’ll see GRIP letters and MMSP alerts. They arrive with your acquirer, and you’ll rarely see them.

Four things to lay out side by side
  • Approval rate by day.
  • Refund count and rate.
  • Chargebacks by reason code.
  • Fraud reports.
Watch the combined rate weekly
Three numbers, every week
  • Chargeback ratio.
  • Fraud rate.
  • For new merchants, the combined refund-and-chargeback rate against 5% on a rolling 30 days.
Bottom line

Your own numbers show the data-based triggers before they fire, so read them weekly.

Audit billing, cancellation and claims

Check your:

  • Checkout, including how a subscription is disclosed.
  • Billing descriptors, against the brand the customer bought from.
  • Transparent checkout, easy cancellation.
  • Claims your ads and affiliates are running.
Your trial ends in 7 days — €19.90 on 25 Sep
NNorthlanebilling@northlane.app

Hi Alex — here is exactly what happens next, so nothing on your statement is a surprise.

First charge25 Sep 2026

Amount€19.90

Then€19.90 monthly, until cancelled

Statement lineNORTHLANE PRO

Keep Northlane ProCancel my trial

Remind them before the money moves

  1. Seven days before the first charge. Early enough that cancelling still costs the customer nothing.
  2. It works even unopened. Amount and date in the subject line. Sender is the brand they know.
  3. Amount, date and descriptor in one block. Four lines, no prose to parse.
  4. Cancel sits next to keep. One click. A hidden cancel button just sends them to their bank.
Scheme notice requirements differ by network and trial length. Confirm before publishing.

Every SMMP flag is something a customer experienced before Mastercard measured it.

Bottom line

Fix what the customer sees, because that is what an investigator reads.

Get alert coverage

Mastercard and Visa license pre-dispute products to alert providers like Chargeblast, Disputifier, and Chargemont, who layer more on top:

What providers layer on top
  • Refund logic
  • Representment
  • Reporting
  • Multi-network coverage
  • Pre-dispute deflection
  • Evidence capture

Providers we work with

An alert resolved before the chargeback posts helps with ECM and EFM. Under SMMP the same refund still counts toward the new-merchant 5%, so pair the alerts with root-cause fixes rather than leaning on them alone.

Bottom line

Alerts buy headroom on ECM and EFM.

06

Glossary

The programs, codes and tools this guide leans on, in plain terms.

SMMP

The Scam Merchant Monitoring Program, effective July 24, 2026. Trigger conditions open a mandatory 72-hour acquirer investigation; confirmed scam activity means an immediate Mastercard and Maestro block.

GRIP

The Global Rules Investigation Program. A GRIP letter is a formal Mastercard notice to an acquirer that an account is connected to suspected scam activity, and is itself an SMMP trigger.

MMSP

A Merchant Monitoring Service Provider: a third party that watches merchant behavior for acquirers. One MMSP scam alert is enough to open the 72-hour investigation.

Fraud type 56

“Manipulation of Cardholder” in Mastercard’s Fraud and Loss Database: the issuer’s code for a scam report, as distinct from stolen-card fraud. Two issuers filing it against a new merchant is an SMMP trigger.

ECM / HECM

Excessive Chargeback Merchant and its high tier. Entry at 100+ chargebacks and a 1.5%+ ratio in the same month; HECM at 300+ and 3%+.

CTR

The chargeback-to-transaction ratio: this month’s chargebacks divided by last month’s Mastercard transactions. The lag means falling sales raise the ratio on their own.

EFM

Excessive Fraud Merchant. Four conditions measured together: 1,000+ eCommerce transactions, $50,000+ net fraud chargebacks, a 0.50%+ fraud rate, and a low 3-D Secure share.

3-D Secure (3DS)

The authentication layer (Mastercard Identity Check) that shifts fraud liability to the issuer. Its share of your volume is a formal EFM condition.

MATCH Pro

The Mastercard Alert to Control High-risk Merchants: the reason-coded list of terminated merchants, checked by underwriters across the industry. Formerly MATCH.

Ethoca

Mastercard’s alert network. Issuer alerts arrive before a chargeback posts, leaving a window to refund or resolve. Under the SMMP new-merchant trigger, that refund still counts toward the 5%.

07

How Compaytence Helps

Compaytence is a global payments and compliance consultancy working across a network of 30+ top-tier providers. Mastercard’s programs are squarely inside the work: keeping merchants out of them, and managing the relationship when an account is already under review.

Operational Audit
  1. 1Authorization Rate Analysis
  2. 2Risk & Chargeback Mitigation
  3. 3Bank Policy Examination
  4. 4Website UX & UI Review
  5. 5Licensing & Compliance Audit
  6. 6Assessment of Documentation

Having questions about Mastercard & your compliance? Compaytence takes the guesswork out. Book a call now!

Email
marketing@compaytence.com
Web
www.compaytence.com

Sources

Figures verified 2 September 2026 against the Mastercard Security Rules and Procedures, Merchant Edition (4 August 2026 edition, §7.2.1 for SMMP), Stripe and acquirer documentation of the Data Integrity fine schedules, and trade-press coverage of the July 2026 launch. Thresholds change; confirm the current tables before relying on a figure in an underwriting or remediation context. Mastercard, Maestro and the interlocking-circles mark belong to Mastercard International; this guide is independent merchant education and is not endorsed by Mastercard.