Chargeback monitoring in 2026: Visa cut the merchant threshold, and the maths is not what you think
Payment Review Editorial Team
Payment Review Editorial Team

Every processor's underwriting conversation eventually arrives at the same question: how many chargebacks is too many? For years the working answer was "about one percent", repeated so often that it hardened into folklore. It was never quite right, and as of 1 April 2026 it is wrong in a specific and expensive way.
Visa's Acquirer Monitoring Program Overview sets the excessive-merchant threshold for the Visa Acquirer Monitoring Program — VAMP — and a footnote in that document reduced it from 220 basis points to 150 basis points in the AP, Canada, EU and US regions on 1 April 2026. The LAC region was already at 150. CEMEA stays at 220. That is a 32% tightening of the headline number in a single step, and it landed on a ratio that most merchants have never actually calculated correctly.
The most common mistake is to assume VAMP measures chargebacks. It does not. Visa defines the VAMP ratio as the count of fraud reports plus the count of disputes, divided by the count of settled transactions:
That first point is the one that catches businesses out. A merchant whose customers call their bank rather than the merchant can be carrying a fraud count several times its chargeback count, and never know until the acquirer's risk team calls. If you have been benchmarking yourself on the disputes that reached your gateway, you have been measuring the smaller half of the numerator.
Two exclusions cut the other way, and both reward acting early. Visa excludes disputes resolved through pre-dispute solutions, and excludes TC40 fraud that qualified for Compelling Evidence 3.0 — in both cases contingent on the timing of the data extract. Resolving a case before it becomes a dispute does not merely save the chargeback fee; it keeps the item out of the ratio entirely.
There is a structural detail in Visa's fact sheet that almost never gets quoted. An acquirer's portfolio is identified as Above Standard at a VAMP ratio of 50 basis points or more, and as Excessive at 70 or more. The excessive-merchant thresholds are then introduced with a condition: they apply if the acquirer is not itself Above Standard or Excessive.
In practice that means the pressure on your account is a function of the company you keep. An acquirer sitting comfortably below 50 basis points has room to work with a merchant running hot. One that is already identified has every incentive to shed the accounts driving its number, well before those accounts reach 150 basis points on their own. This is why two businesses with identical dispute performance can get very different treatment, and why the identity of the acquiring bank behind your account matters more than the brand on your statement.
It is also the strongest argument for the placement model that specialist high-risk providers run. Easy Pay Direct underwrites each application individually and places merchants across a panel of more than 30 banking partners, and lets established merchants run multiple accounts so one bank's risk appetite does not stop the business. Durango Merchant Services works the same way, matching each merchant to an acquiring bank suited to its risk profile rather than pushing everyone through one relationship. Neither publishes rates, which is its own problem, but the diversification is a real answer to a real rule.
The ratio alone does not enrol anybody. Visa pairs it with a minimum monthly count of combined fraud and disputes: 1,500 in the AP, Canada, EU and US regions. CEMEA uses a lower count of 150 combined with a minimum amount of USD 75,000.
For most small merchants, 1,500 fraud reports and disputes in a single month is a number they will never reach — a business would need roughly 100,000 card-not-present transactions a month to hit 1,500 events at the 150 basis point threshold. That is genuine relief, and it is worth saying plainly: VAMP is an acquirer program that reaches down to large merchants, not a rule that terminates a small e-commerce store over a bad quarter.
What terminates a small store is the acquirer's own contract. Processing agreements routinely set internal chargeback limits far below anything Visa publishes, precisely because a portfolio-level ratio is built from thousands of small accounts. The network threshold is the ceiling; your merchant agreement is the floor, and the floor is where most accounts are actually lost.
Running clean on Visa does not mean running clean on Mastercard, because Mastercard's Excessive Chargeback Program asks a different question. It counts chargebacks only — no issuer fraud reports — and its chargeback-to-transaction ratio divides the chargebacks received in a calendar month by the sales transactions received in the preceding month.
The lagged denominator matters more than it looks. A business with falling sales sees its Mastercard ratio rise even if the absolute number of chargebacks holds steady, because this month's disputes are divided by last month's larger sales count. Seasonal merchants and anyone coming off a promotion should model that explicitly.
Mastercard also runs a separate Excessive Fraud Merchant program aimed at card-not-present fraud, which dispute-management vendors including Solidgate describe as requiring all four of its criteria to be met in the same month: at least 1,000 e-commerce transactions, at least 50,000 dollars in fraud-related chargebacks, a fraud ratio of at least 50 basis points, and 3-D Secure usage at or below 50% in regulated countries or 10% elsewhere. Mastercard does not publish these figures on its public site, so treat them as well-corroborated industry reporting rather than gospel — but note the direction of the last one. Low authentication usage is part of what qualifies you.
Visa does not publish the fees attached to VAMP identification. Chargeback Gurus, writing for the Merchant Risk Council in April 2026, puts the figure at 8 dollars per fraudulent or disputed transaction for enrolled merchants, and describes a three-month grace period for a first violation in a rolling twelve months. Those numbers are consistent across several dispute-management vendors, but they are vendor reporting, not a Visa document.
The published consequences are in the rules, and they are harsher than the fees. The Visa Core Rules let Visa require an acquirer or its merchant to deploy remediation tools or technologies to address activity identified in VAMP, and allow evaluation at either an aggregated merchant level or a sponsored merchant level — which reaches merchants sitting under a payment facilitator.
If it ends in termination, the listing does. An acquirer must add a terminated merchant to the Terminated Merchant File no later than close of business on the day following the date the merchant is notified of the intent to terminate. Visa's own glossary describes that file as the one "currently known as MATCH", maintained by Mastercard. Among the listed grounds are an excessive number of disputes due to the merchant's business practices, and identification by VAMP reports.
Visa requires acquirers to query a common terminated-merchant database before entering into a merchant agreement, to list a merchant terminated for cause for three years, and — effective 18 April 2026 — to verify a possible match and contact the listing member directly to find out why the merchant was added. That last change is quietly good news for anyone wrongly listed: the rule now obliges the reviewing acquirer to ask, rather than simply decline. Mastercard's own MATCH records are generally reported to purge after five years.
Because the VAMP ratio excludes items resolved before they become disputes and fraud reports that qualified for Compelling Evidence 3.0, the highest-leverage work is upstream of the dispute process, not inside it.
Compelling Evidence 3.0 is the remedy for dispute condition 10.4, other fraud in the card-absent environment. As the Visa Core Rules stand for disputes processed through 23 October 2026, it turns on showing that the same payment credential was used in two previous transactions the issuer did not report as fraud, processed more than 120 calendar days earlier and not more than 365 days before the dispute. You must supply a description of what was bought in the disputed and the two prior transactions, and match either the device ID or fingerprint or the IP address, plus at least one of: the customer's account or login ID, the full delivery address, a device ID of at least 15 characters, a device fingerprint of at least 20 characters, or the cardholder's public IP address. Most of those requirements are data-retention decisions made long before any dispute arrives.
From 24 October 2026 Visa is widening the remedy so that the two prior undisputed transactions may have occurred at one or more merchants, rather than only your own — a material expansion for businesses whose customers buy infrequently. The same updated rule text extends the acceptable login identifiers to those used with an agentic payment provider, which is the first time an AI purchasing agent appears in this part of the dispute rules.
One warning attached to it: if Visa determines a merchant is falsifying data to gain this protection, it notifies the acquirer and the merchant of the rules violation and removes access to the remedy for that payment credential until the underlying activities are corrected in writing.
Dispute economics vary more between processors than headline rates do. Square charges nothing for chargebacks and dispute management on its published fee list. Stripe charges 15 dollars per dispute. Both are aggregators, which means your account sits under a shared arrangement and the risk decision can be abrupt.
Among the specialists, eMerchantBroker sells chargeback prevention and management alongside the merchant account itself, which is the right shape for a business that expects disputes — though our review marks it down hard for tiered pricing and 295-to-595-dollar early termination fees. Easy Pay Direct includes chargeback alerts and representment at no surcharge. At the enterprise end, Checkout.com has genuinely strong fraud tooling — device fingerprinting, velocity checks, 3-D Secure management — but our review found dispute and refund resolution to be a recurring complaint outside dedicated enterprise accounts, which is exactly the wrong weakness for this problem.
If you are shopping the high-risk market specifically, our guide to high-risk merchant accounts covers the providers we have reviewed and what each one actually publishes. Ask any of them three questions before you sign: which acquiring bank holds the account, what the contract's internal chargeback limit is, and whether pre-dispute alerts are included or billed per alert. The first tells you whose portfolio ratio you are joining. The second is the number that will actually end your account. The third decides whether the cheapest fix is available to you at all.