The MATCH list: how businesses end up on it, and what actually gets them off
Payment Review Editorial Team
Payment Review Editorial Team

The pattern is always the same. A processor closes an account, sometimes with notice and sometimes not. The business applies somewhere else, gets to the end of the application, and is declined. It applies again, and is declined again, usually within a day and usually with no reason given. At some point somebody in the industry says the word MATCH, and the business owner searches for it for the first time.
MATCH is a screening database Mastercard operates for acquiring banks. When an acquirer terminates a merchant for one of the listed reasons, it is required to add the merchant's details; when an acquirer is underwriting a new application, it is required to query the database first. The rules governing it sit in Mastercard's Security Rules and Procedures, Merchant Edition — a document written for acquirers, not for the businesses whose names go into it, which is a large part of why the process feels so opaque from the outside.
Under Mastercard's rules the acquirer has five calendar days from the earlier of its decision to terminate or its receipt of the merchant's notice of termination to add the record. Visa's parallel obligation is tighter, and it starts earlier than most people assume: in the US region an acquirer must add a terminated merchant to the Terminated Merchant File no later than close of business on the day following the date the merchant is notified of the intent to terminate. The clock runs from the notice, not from the closure. Neither rule requires anybody to tell the merchant it has been listed — the one place Visa does require that is the Europe region, where an acquirer must warn a merchant at the outset that a for-cause termination may be listed, and must tell it in writing if it lists it.
It is also worth being precise about what a listing is not. It is not a credit file, it is not a regulator's finding, and it involves no hearing. It is one bank's report of why it ended a commercial relationship, held in a database every other bank consults.
MATCH records a numeric reason code with every listing, and the code matters enormously — it determines how another acquirer reads your file, and in one case it determines whether removal is even possible. The codes are numbered 01 to 14, with 06 no longer in use. Eleven of them are qualitative judgements about conduct.
Codes 04 and 05 are different in kind. They are arithmetic. No finding of misconduct is required and no intent is relevant — you either crossed the thresholds in a calendar month or you did not.
Code 04, Excessive Chargebacks, is triggered when Mastercard chargebacks in a single month exceed 1% of that month's Mastercard sales transactions and total 5,000 US dollars or more. Both conditions have to be met in the same month. There is no minimum number of chargebacks, which is the detail that surprises people: a small number of large disputes on a modest month's volume is enough.
Code 05, Excessive Fraud, is triggered when the monthly fraud-to-sales dollar volume reaches 8% or more and there are at least ten fraudulent transactions totalling 5,000 dollars or more, all within the same calendar month.
Two consequences follow from the fact that these are month-level measurements. The first is that winning the disputes later changes nothing, because the criteria were satisfied by the transactions processed in that month. The second is that these thresholds are not the same as the card networks' ongoing chargeback monitoring programmes, which are about remediation rather than termination and use different numbers entirely — we cover those separately in our guide to chargeback monitoring programmes in 2026. A business can be inside a monitoring programme and not MATCHed, and it can be MATCHed after a single bad month without ever having been in a monitoring programme.
A MATCH record carries the business legal name and DBA, address, phone number, tax ID and website — and, alongside them, the principal owner's name, address, phone number and tax ID, plus the account opening and termination dates and the reason code. Screening runs against the principals as well as the entity.
This is why the common instinct — dissolve the company, incorporate a new one, apply again — does not work, and why it makes matters worse when it is discovered during underwriting. Applying under a new entity while concealing a listed principal is the sort of thing that turns a five-year problem into a permanent one.
There is no notification requirement on MATCH and no merchant-facing portal. The two practical routes to finding out are to ask the processor that closed the account which code it reported, and — if you do not know which acquirer made the listing — to email Mastercard at matchbusinessowner@mastercard.com. That request has to come from the business owner directly; enquiries sent by an agent or an adviser on the owner's behalf are not answered.
Ask for the reason code specifically, in writing, and keep the reply. Everything you can usefully do next depends on which number it is.
Only the acquirer that created the listing can modify or delete it, and under Mastercard's rules it may do so in two situations. The first is that the merchant was added in error. The second is that the listing was under reason code 12, PCI DSS non-compliance, and the acquirer has verified that the merchant is now fully compliant.
That is the whole list. There is no appeal to Mastercard, no remediation route for code 04, and no discretion for an acquirer to be generous about it — an acquirer can be exposed to claims from a later acquirer over a merchant it should have listed or improperly removed, which is exactly the incentive you would expect that to produce. If the listing is genuinely wrong, the argument you are making is that the acquirer made a factual mistake, and it is worth making it in writing, with the transaction and dispute records that support it, to the acquirer's risk department rather than to the sales contact who sold you the account.
Otherwise, the five-year purge is the answer, and the honest planning assumption is that you will be trading through most of it.
Nothing in the network rules forbids underwriting a listed merchant. Visa's own guidance to acquirers is that they must not refuse to enter into an agreement based solely on information held in its screening database. The listing is information, and the acquirer decides what to do with it.
In practice, the platforms that onboard merchants in minutes are the ones that decline automatically. Stripe's published documentation says plainly that a MATCH listing generally disqualifies a business from processing with it, and that it cannot remove a merchant who met the excessive chargeback criteria even if the dispute problem has since been fixed — see our Stripe review for how that platform underwrites more generally. The same logic applies across the aggregator model: a shared merchant ID that thousands of businesses sit inside cannot absorb a file the sponsor bank would refuse individually.
The realistic route is a provider that underwrites by hand and can place the account with more than one acquiring bank. That is a description of a business model, not a promise about any individual company — every provider makes its own decision, and none of them owe you one. Among the specialists we have reviewed, the following are the kind of shop the description fits:
Expect the terms to reflect the file. A rolling reserve, a higher rate, a monthly volume cap and a shorter leash on disputes are all normal for a business coming off a termination, and a provider that quotes you standard pricing without asking about the closure has probably not underwritten you yet. Our guide to the best high-risk merchant accounts goes through what those terms usually look like and what is negotiable.
Almost everything useful here happens before the account is closed, not after. Two points are worth internalising.
The first is that closing your own account does not protect you. An acquirer must add a qualifying merchant to MATCH even where the merchant gave notice, and even where the qualifying event surfaces after the relationship formally ended. Walking away from a processor mid-argument does not end the argument.
The second is that the exposure is concentrated in single months. Code 04 does not care about your twelve-month average. A product recall, a fulfilment failure, a subscription price change handled badly, or one month of unusually large orders that go wrong can put a business over 1% and 5,000 dollars without anything dishonest happening anywhere. If you can see a bad month developing, that is the moment to talk to your processor's risk team rather than the moment to hope.