The Great De-Risking: How Visa’s Rulebook Is Closing Online Merchant Accounts

Milena Sokolova

Author: Milena Sokolova

International Banking Consultant
The Great De-Risking: How Visa’s Rulebook Is Closing Online Merchant Accounts
Table of Contents:

An investigation into VAMP, VIRP, and the compliance squeeze that has kept card acquiring “in a storm” since 2025 — plus a practical playbook for surviving it.

For more than a year, the market for online card acceptance has been running through a slow-motion crisis. Merchants wake up to termination notices with 30 days’ warning and no stated cause. Payment service providers quietly tighten onboarding until whole categories of legitimate business can no longer get a merchant account. Acquiring banks — the institutions that connect a merchant to Visa and Mastercard — are shrinking their high-risk books rather than risk the fines waiting on the other side of a threshold.

The trigger is not a new law or a regulator. It is Visa’s own rulebook, rewritten across 2023–2026 into two programs that together changed the economics of who gets to accept a card online: the Visa Integrity Risk Program (VIRP) and the Visa Acquirer Monitoring Program (VAMP). Mastercard has moved in near-lockstep with its own monitoring regime. The stated goals are unimpeachable — less fraud, fewer disputes, no illegal transactions on the network. The practical effect has been a wave of de-risking that catches good businesses alongside bad ones.

This piece breaks down exactly what changed, with the real numbers, and then turns to what merchants and acquirers can actually do about it.

A note on sourcing. Where a figure comes from Visa’s or Mastercard’s own documents, it is labeled as such. Where a figure is reported by acquirers, processors, or chargeback-mitigation vendors — some of whom sell fear — it is flagged. Dollar penalty amounts in particular are frequently not published by the networks themselves and reach the market through acquirer advisories. Several widely repeated statistics turned out to be superseded or unsourced; those are called out rather than repeated.

Part 1 — What actually changed

VAMP: Visa merged fraud and disputes into a single ratio

Before April 2025, Visa policed merchant risk with two separate programs: the Visa Dispute Monitoring Program (VDMP), which tracked chargebacks, and the Visa Fraud Monitoring Program (VFMP), which tracked fraud. A merchant could be in trouble on one axis or the other.

On 1 April 2025, Visa folded that structure into a single framework — the Visa Acquirer Monitoring Program (VAMP) — launching it with a six-month advisory period; the updated program thresholds then took effect on 1 June 2025. In Visa’s own words from its VAMP fact sheet, the change was about “consolidating the existing VAMP, Visa Fraud Monitoring Program, and Visa Dispute Monitoring Program into a single global program,” streamlining what Visa describes as dozens of separate remediation processes into one. (Visa, Introducing VAMP; Visa VAMP Fact Sheet 2025)

The structural heart of VAMP — and the reason it caused so much turbulence — is a single combined ratio:

VAMP Ratio = ( Fraud reports [TC40] + Disputes [TC15] ) ÷ Settled card-not-present transactions [TC05]

It is count-based, not dollar-based, and it applies to card-not-present (online) VisaNet transactions only. (Visa VAMP Fact Sheet 2025)

That looks innocuous until you notice the double-counting problem. A single fraudulent transaction can hit the numerator twice — once as a TC40 fraud report and again, when the cardholder disputes it, as a TC15 dispute. (Ravelin; Riskified) Merchants who were comfortably inside the old separate limits suddenly found themselves measured against a metric that adds their fraud and their disputes together.

The thresholds (current, per Visa’s fact sheet):

Level Tier Threshold Enforced from
Acquirer (portfolio) Above Standard ≥ 0.50% (50 bps) 1 Jan 2026
Acquirer (portfolio) Excessive ≥ 0.70% (70 bps) 1 Oct 2025
Merchant (AP, Canada, EU, US) Excessive ≥ 2.20% (220 bps) → 1.50% from 1 Apr 2026 1 Oct 2025
Merchant (LAC) Excessive ≥ 1.50% (150 bps) 1 Oct 2025
Merchant (CEMEA) Excessive ≥ 2.20% (220 bps) 1 Oct 2025
Enumeration (card-testing) — ≥ 20% ratio and ≥ 300,000 enumerated auth attempts/month —

There is no “above standard” tier for merchants — only “excessive.” A merchant enters the program only after clearing a floor of ≥ 1,500 combined fraud + dispute events in a month (in CEMEA, ≥ 150 events and ≥ USD 75,000). (Visa VAMP Fact Sheet 2025)

Note the regional split that matters for European operators: Western Europe (the “EU” bucket) is on the tightening path to 1.5%, but CEMEA — Central Europe, Middle East and Africa — stays at 2.2% with a much lower event floor. Intra-Europe, the same business can face a different standard depending on where its acquirer books it. Latin America has been at 1.5% since launch; Brazil, Chile and India were carved out for a later, separate rollout.

The enforcement calendar is the part that turned a rule change into a market event:

  • 1 Apr 2025 — VAMP goes live; a no-penalty advisory period begins.
  • 1 Jun 2025 — updated thresholds take effect.
  • 30 Sep 2025 — advisory period ends.
  • 1 Oct 2025 — enforcement begins for the Excessive tier (fees now assessed).
  • 1 Jan 2026 — acquirer “Above Standard” enforcement begins.
  • 1 Apr 2026 — merchant Excessive threshold tightens from 2.2% to 1.5% in AP/Canada/EU/US — a roughly one-third cut in tolerated dispute volume, effective overnight.

(Visa VAMP Fact Sheet 2025; Merchant Risk Council; Chargebacks911)

Two important corrections to the record, because both circulate widely and both are wrong:

  1. Enforcement was originally set for 1 July 2025, then pushed to 1 October after the Merchant Risk Council relayed industry pushback in March 2025 (the advisory window was extended from three months to six). Any source citing a July 2025 enforcement date is stale. (Chargeback Gurus)
  2. The current thresholds are milder than Visa’s early drafts. Visa revised the program upward in May 2025 after industry feedback, so lower figures that still circulate — notably a 0.9% merchant ratio — reflect a superseded draft, not the current rule (merchant Excessive is 2.2%, tightening to 1.5% in April 2026). (Chargeback Gurus)

The fines. Visa’s public fact sheet defines ratios and thresholds but does not print per-transaction penalty amounts. Those reach the market through acquirer and processor advisories, which currently converge on:

  • Acquirer, Above Standard: ~US$4 per fraud/disputed transaction
  • Acquirer, Excessive: ~US$8 per transaction
  • Merchant, Excessive: ~US$8 per transaction

These were reportedly revised down from an original $5/$10 schedule before enforcement began. Fines are levied on the acquirer, which then decides how much to pass through to the merchant. First-time offenders get roughly a three-month grace window; acquirers must file a remediation plan within 15 days of a breach. (Ravelin; Chargebacks911) Treat the exact dollar figures as vendor-reported rather than Visa-published.

The RDR trap: why “just auto-refund it” is not a complete fix

VAMP’s ratio excludes disputes resolved through pre-dispute solutions — tools like Rapid Dispute Resolution (RDR), Order Insight, CDRN and Ethoca that refund or deflect a case before it becomes a chargeback. This is why the entire prevention industry exists: kill the dispute before it posts, and it never enters your numerator. (Visa VAMP Fact Sheet 2025)

But there is a catch that trips up a lot of merchants: RDR and CDRN only remove the non-fraud dispute (the TC15). They do not erase the underlying TC40 fraud report. If a transaction was flagged as fraud, auto-refunding it stops the chargeback but the fraud signal still counts against your ratio. The only mechanism that suppresses the TC40 is Compelling Evidence 3.0, submitted through Order Insight and accepted by the issuer in the same month. Visa even retracted an earlier proposal to exclude Verifi-resolved fraud pre-disputes in March 2025. (Corgi Labs; Solidgate) In other words: prevention tooling controls your dispute problem, not your fraud problem.

VIRP: the program that decides whether your category is even allowed

VAMP governs how well you process. VIRP — the Visa Integrity Risk Program — governs whether you’re allowed to process at all.

VIRP took effect on 1 May 2023, replacing the older Global Brand Protection Program (GBPP). (LegitScript; PaymentCloud) Its purpose, per Visa’s Ecosystem Risk Programs Guide, is “to deter, detect, and remediate illegal activity” on the network — with particular attention to “certain business types that are at a higher risk of processing unlawful transactions.”

VIRP sorts high-integrity-risk merchants into three tiers, each mapped to specific merchant category codes (MCCs):

  • Tier 1 (highest risk — activity that can harm health or safety): adult-content merchants (MCC 5967), dating services (MCC 7273), gambling (MCC 7995), pharmacies (MCC 5122/5912).
  • Tier 2 (financial or economic harm): crypto (6051/6012 under special condition code 7), cyberlockers/file-sharing (4816), card-absent games of skill (5816).
  • Tier 3 (deceptive marketing): card-absent financial trading — forex, CFDs, binary options (6211); outbound telemarketing (5966); subscription / negative-option billing (5968); cross-border tobacco (5993).

(LegitScript; PaymentCloud)

To board a merchant in any of these categories, the acquirer must register it with Visa and carry ongoing obligations: control assessments (annually for Tier 1), self-assessments, and an annual High-Integrity-Risk attestation to Visa that its merchants remain compliant. (Visa, Protecting the Integrity of the Visa Network)

The costs stack up fast:

  • Merchant registration fee: raised from US$500 to US$950 on 1 April 2024, per provider, per acquirer, billed annually. (Corepay)
  • Acquirer-level program registration: reported at US$100,000 initial + US$100,000 annual for Tiers 1 and 2, and US$25,000 + US$25,000 for Tier 3. (Green Sheet; one source lists the Tier 1 renewal at $50,000 — figures vary by source.)
  • A per-transaction Integrity Risk Fee on select Tier 1 categories (adult, dating, gambling): US$0.10 per transaction + 10 basis points of processed volume. (Corepay; Green Sheet)

And the penalties are where VIRP becomes an existential risk for an acquirer’s whole book. Straight from Visa’s Core Rules (§12.5.5.1):

Visa may impose a non-compliance assessment of USD 100,000 for Tier 1 and Tier 2 Merchants, or USD 25,000 for Tier 3 Merchants, to the Acquirer per calendar month of non-compliance, plus a non-compliance assessment of USD 2,000 per High-Integrity Risk Merchant … per calendar month of non-compliance.

(Visa Core Rules and Product & Service Rules)

Try to dodge the rules by altering a merchant’s name, data or transaction performance and Visa’s Core Rules (§12.5.3.2) authorize US$25,000 per merchant per month plus permanent disqualification of the merchant and its principals. For processing outright illegal transactions, Visa’s confidential VIRP Guide — as reported by compliance vendors — sets non-compliance assessments of US$50,000 per merchant or URL, up to a US$150,000 maximum, with materially larger assessments — reported at up to US$400,000 — reserved for the most serious illegal-content violations, which carry a 24-hour remediation deadline. (Austreme; LegitScript) Crucially, and unlike Mastercard, Visa offers no fine-mitigation program — there is no path to a partial refund of a VIRP assessment. (LegitScript)

Stack it up from the acquirer’s chair: six-figure monthly exposure per non-compliant merchant, no mitigation, plus registration costs, control assessments and annual attestation. For many banks the math is simple — it is cheaper to exit the category than to bank it.

Part 2 — The downstream crackdown

Why acquirers close accounts before you breach

Here is the mechanism that turned Visa’s rulebook into merchant terminations. The networks fine the acquirer, not the merchant directly. Under VAMP, the acquirer’s entire portfolio now carries its own ratio and its own “Above Standard” (0.5%) and “Excessive” (0.7%) thresholds. One bad merchant doesn’t just fine itself — it drags the acquirer’s book toward a portfolio-level penalty. (Merchant Risk Council)

Because the acquirer bears the cost, the rational move is to set internal limits stricter than Visa’s and to cut merchants who are merely approaching a threshold, not just those who breach it. This is the chilling effect: a merchant running at 1.2% under a 1.5% rule is not “compliant” in the acquirer’s eyes — it’s a liability trending the wrong way. High-risk merchant agreements routinely allow termination on 30 days’ notice with no cause, and settlement funds can be held for 90–180 days afterward. (Boxchrge)

Much of the offboarding is category-level, not performance-level. A merchant with clean numbers can lose its account simply because its bank decided to exit the vertical — a decision driven by VIRP’s compliance load and VAMP’s portfolio math, not by anything that specific merchant did. (This “whole-category de-risking” narrative is well-established in industry commentary; the vivid termination-count figures attached to it are not — see the caution below.)

MATCH: the five-year scarlet letter

When an acquirer terminates a merchant for cause, it is generally required to add that merchant to MATCH — the Mastercard Alert to Control High-risk Merchants, the industry blacklist historically called the Terminated Merchant File (TMF). Any acquirer screening a new application checks MATCH, so a listing is, in practice, close to disqualifying — new applications are usually declined, though specialist high-risk acquirers will sometimes board a listed merchant at premium pricing and heavy reserves. (Stripe — MATCH documentation)

Key facts merchants get wrong:

  • The reason code for excessive chargebacks is 04, not 12. (Code 12 is PCI-DSS non-compliance.) Code 04 is triggered when a merchant’s monthly Mastercard chargebacks exceed 1% of sales and total US$5,000 or more. (Stripe)
  • A listing lasts five years and is purged automatically — there is no early “appeal” except by the acquirer that listed you, and only if the listing was an error (or, for a PCI-compliance listing under code 12, once compliance is restored). (Stripe)
  • You are not notified. Most merchants discover they’re on MATCH only when their next application is declined. (Stripe)

There is no public figure for how many merchants sit on MATCH or are terminated each year — Mastercard doesn’t disclose it. Any specific “X million merchants terminated” number circulating online is unsourced.

The verticals in the blast radius

The businesses most exposed are the ones that sit at the intersection of high dispute rates and VIRP categories: subscription and negative-option billing, nutraceuticals and supplements, CBD/hemp/vape, online gambling, adult, crypto, forex/CFD/binary options, pharma, travel and ticketing, and dropshipping. (CatalystPay; LegitScript)

Subscription businesses deserve a special mention because two forces hit them at once. a Mastercard-cited 2020 merchant survey found that 75% of disputes for subscriptions and digital goods are first-party misuse — customers disputing rather than cancelling. (Mastercard Newsroom) At the same time, negative-option billing sits under intensifying regulatory scrutiny — the federal ROSCA statute, a wave of state “click-to-cancel” laws, and the FTC’s on-again negative-option rulemaking (its 2024 “click-to-cancel” rule was vacated by a federal court in 2025). So a subscription merchant faces elevated disputes and elevated regulatory scrutiny and a VIRP Tier-3 classification — a triple bind.

Part 3 — Is this actually a “storm”? What the data says

It is easy to overstate a crisis, and the high-risk-processing industry has a commercial incentive to do so. So here is what the credible, primary data actually shows — and which scary numbers to distrust.

Disputes are genuinely rising. Mastercard’s 2025 Global Chargebacks Outlook (built on Datos Insights research) projects 261 million chargebacks globally in 2025, rising to 324 million by 2028, with the total cost climbing from US$33.8 billion to US$41.7 billion. Growth is fastest outside North America — Europe is projected at 27% growth through 2028, Asia-Pacific 35%, the Middle East and Africa 59%. (Mastercard / Ethoca, 2025 State of Chargebacks)

Correction to a stat you’ll see everywhere: the widely quoted “337 million chargebacks by 2026” is a 2023 Datos Insights projection, published by Mastercard and since superseded by the 261M→324M trajectory above. Quoting “337M by 2026” in 2026 is quoting a stale forecast.

First-party (“friendly”) fraud is a real driver — but smaller than vendors claim. Visa states that friendly fraud is roughly 20% of all fraudulent disputes globally, and up to 30% for high-volume online merchants. (Visa) Datos/Mastercard’s measured breakdown puts first-party misuse at about 21% of merchant chargebacks. (Mastercard / Ethoca, 2025)

Distrust the “70–75% friendly fraud” figure. It appears in vendor content attributed vaguely to “Visa and Mastercard reports” with no traceable citation. The measured number is ~21%. Likewise, the “$132 billion” and “250,000 merchants terminated by year-end” figures that circulate are unsourced vendor or broker projections — not card-network data.

Chargebacks are expensive out of proportion to their size. The fully-loaded cost of a chargeback — fees, penalties, lost goods, operations — can run to more than twice the transaction value (a figure highlighted on Mastercard’s site, citing Forter), and LexisNexis’s 2025 True Cost of Fraud study puts it at US$4.61 for every US$1 of fraud loss for US retail and e-commerce merchants. (Mastercard Newsroom; LexisNexis Risk Solutions)

So: the storm is real in its mechanism and its direction, but the most alarming numbers attached to it are the least sourced. Visa’s rationale — that combining fraud and disputes, raising the cost of laxity, and forcing prevention tooling will pull dispute volume down — is a coherent response to a genuine trend. The collateral damage is that a compliance regime calibrated for the worst actors also reshapes the economics for everyone else.

Part 4 — Mastercard is doing the same thing, differently

A “Visa storm” narrative is incomplete, because a merchant accepts both brands and can be caught by either. But the two networks are built differently, and the contrast is the single most useful thing to understand.

Mastercard keeps fraud and disputes in separate programs:

  • Excessive Chargeback Program (ECP) — measures chargebacks only, via a chargeback-to-transaction ratio (CTR):
  • ECM (Excessive Chargeback Merchant): ≥ 100 chargebacks/month and CTR 1.50%–2.99%.
  • HECM (High Excessive): ≥ 300 chargebacks/month and CTR ≥ 3.00%.
  • Fines escalate by consecutive month — $0 in month 1, $1,000 in month 2, up to $100,000–$200,000 per month at 19+ months, plus a $5-per-chargeback issuer-recovery assessment above 300 chargebacks. Exit requires three consecutive clean months. (JPMorgan Merchant Services — Mastercard ECM Guide; Braintree/PayPal)
  • Excessive Fraud Merchant (EFM) — measures e-commerce fraud only, triggering when a merchant clears all four thresholds in a month: ≥ 1,000 e-commerce transactions, ≥ US$50,000 in fraud chargebacks, a fraud ratio ≥ 0.50%, and 3-D Secure usage below 50% (regulated markets) or 10% (non-regulated). (Braintree/PayPal)

This is the key contrast: Mastercard still separates fraud from disputes; Visa’s VAMP is the outlier that merged them into one ratio. Notably, Visa looked like Mastercard does today until June 2025 — it was VAMP’s consolidation of VDMP and VFMP that made Visa the structural exception. And while Mastercard’s 1.5% ECM ratio and Visa’s post-April-2026 1.5% VAMP ratio look identical, they are not comparable: Mastercard’s 1.5% counts chargebacks only, Visa’s counts fraud + disputes combined.

On the compliance side, Mastercard’s counterpart to VIRP is its Business Risk Assessment and Mitigation (BRAM) program (now branded the Merchant Monitoring program), which LegitScript describes as carrying “fines as high as six figures per transaction” — larger per-instance than Visa’s — but, unlike Visa, Mastercard offers a fine-mitigation program that can rebate 75–100% of an assessment when the acquirer engages an approved monitoring provider. (LegitScript)

Bottom line on scheme-vs-scheme: VAMP’s combined ratio and its 2025–2026 enforcement calendar are Visa-specific. MATCH, the rising-dispute trend, first-party fraud, and the underlying de-risking pressure are scheme-wide. When people say “the Visa storm,” what they usually mean is the whole weather system — both networks tightening at once.

Part 5 — The survival playbook

The regime is not survivable by hoping. It is survivable by driving your ratio down and building redundancy before you need it. Here is what actually works.

1. Know your real number — and watch the right one

Your VAMP ratio is fraud (TC40) + disputes (TC15) over settled CNP transactions, count-based, measured monthly. Ask your acquirer for your current VAMP standing and the trend, not just a pass/fail. Remember the merchant floor (1,500 events) and that the Excessive line dropped to 1.5% on 1 April 2026 in AP/Canada/EU/US — if you were sitting comfortably at 1.8% under the old 2.2% rule, you are now over the line. Track fraud and disputes separately too, because they have different fixes.

2. Deploy the pre-dispute stack — but understand what each tool actually removes

Disputes resolved before they post are excluded from the VAMP ratio. The tools, mapped to the network that owns them:

Tool Network What it does What it removes
RDR (Rapid Dispute Resolution) Visa (Verifi) Rules-based automatic refund before chargeback; ~97% of Visa cards The TC15 dispute — not the TC40 fraud
CDRN Visa (Verifi) Pre-dispute alert; ~72 hrs to refund manually The TC15 dispute
Order Insight Visa (Verifi) Real-time transaction-detail sharing; deflects a large share of inquiries (vendors report ~40–65%) The dispute; carries CE3.0, which can remove the TC40
Ethoca Alerts Mastercard Pre-dispute alert; 24–72 hrs to refund manually; ~95% of Mastercard The chargeback

Coverage and deflection percentages in this table are vendor-reported and vary by source — treat them as indicative, not card-network-audited figures.

(Visa VAMP Fact Sheet; Chargeback.io; ChargebackGurus) The mnemonic: Verifi = Visa, Ethoca = Mastercard. Alert pricing runs roughly $15–$40 per alert depending on reseller — a cost worth paying only if the refund is cheaper than the ratio damage.

The critical nuance again: RDR and CDRN clear the dispute but leave the fraud record. For fraud-driven ratio problems, the tool that matters is Compelling Evidence 3.0 via Order Insight (issuer-accepted, same month) — that is the only thing that suppresses the TC40.

3. Authenticate to shift fraud liability

EMV 3-D Secure 2 moves liability for fraud chargebacks to the issuer when the transaction is successfully authenticated — covering the networks’ fraud dispute categories (Visa reason codes 10.1–10.5 and Mastercard’s fraud-related codes), but not non-fraud/consumer disputes. (Adyen; gPayments) It does double duty: it lowers your fraud numerator and keeps you out of Mastercard’s EFM program, where low 3DS usage is itself a trigger.

4. Fix the boring things that cause disputes

  • Billing descriptors that match your checkout brand and say what was bought. Opaque DBAs generate “I don’t recognize this charge” disputes. (Checkout.com)
  • Delivery and service confirmation — tracking numbers, delivery confirmation, signature on high-value orders. It’s the strongest evidence against “item not received.”
  • Subscription hygiene — clear and conspicuous terms before billing, express informed consent before charging, renewal reminders, and a simple cancellation mechanism (ROSCA’s baseline requirement; several state laws now demand cancellation be as easy as sign-up). This attacks the first-party-misuse problem at its root and reduces regulatory exposure at the same time. (FTC Negative Option Rule)

5. Diversify acquiring before you’re forced to

Single-acquirer dependence is now an existential risk, not just an operational one. Multiple MIDs across multiple acquirers, with intelligent routing/load-balancing, does three things: it keeps you processing if one MID is restricted, it prevents any single MID’s ratio from spiking, and it gives you leverage. (Kount — Load Balancing; SecureGlobalPay) A word of caution: deliberately fragmenting a business across MIDs to disguise its category or dodge VIRP/VAMP is exactly the “circumvention” that Visa’s Core Rules punish with $25,000/merchant/month and permanent disqualification. Diversify for resilience, not for evasion.

6. Stay off MATCH

Getting listed is far more expensive than any single month of fines, because it locks you out of the market for five years. Practically: keep your Mastercard chargeback ratio below the 1% / $5,000 code-04 line; if an acquirer signals it intends to terminate, negotiate a voluntary, no-MATCH offboarding and settle disputes before they post; and if you are listed in error, only the acquirer that listed you can remove you — so document everything.

The uncomfortable synthesis

Visa did not set out to close good businesses. Combining fraud and disputes into one metric, raising the price of laxity, and pushing prevention tooling are defensible answers to a dispute problem that is genuinely growing and genuinely costly. First-party fraud is real; illegal transactions on the network are real; brand risk is real.

But a compliance regime is a blunt instrument. When you fine the acquirer for the merchant’s behavior, you hand the acquirer a reason to cut anything that looks risky. When you make VIRP registration a six-figure, no-mitigation liability, you make whole legal categories uneconomic to bank. When you drop the merchant threshold by a third overnight, you reclassify yesterday’s compliant merchant as today’s problem. The result is a market where the surviving edge belongs to whoever keeps their ratio lowest, diversifies earliest, and treats dispute prevention as core infrastructure rather than an afterthought.

The storm is not a glitch. It is the system working as designed — and the businesses that make it through will be the ones that stopped waiting for it to pass and started building for the climate.

Sources

Visa (primary):
– Visa — Introducing the Visa Acquirer Monitoring Program. https://corporate.visa.com/en/sites/visa-perspectives/security-trust/introducing-visa-acquirer-monitoring-program.html
– Visa — VAMP Fact Sheet 2025 (PDF). https://corporate.visa.com/content/dam/VCOM/corporate/visa-perspectives/security-and-trust/documents/visa-acquirer-monitoring-program-fact-sheet-2025.pdf
– Visa — Core Rules and Visa Product & Service Rules (PDF; VIRP non-compliance assessments §12.5.3.2, §12.5.5.1). https://usa.visa.com/dam/VCOM/download/about-visa/visa-rules-public.pdf
– Visa — Protecting the Integrity of the Visa Network (PDF). https://corporate.visa.com/content/dam/VCOM/corporate/visa-perspectives/documents/protecting-the-integrity-of-the-visa-network.pdf
– Visa — Friendly fraud insights. https://corporate.visa.com/en/solutions/visa-protect/insights/friendly-fraud.html

Mastercard (primary):
– Mastercard / Ethoca — 2025 Global Chargebacks Outlook. https://www.mastercard.com/us/en/news-and-trends/Insights/2025/2025-global-chargebacks-outlook.html
– Mastercard Newsroom — Sellers beware: getting to the bottom of first-party fraud (2024). https://newsroom.mastercard.com/news/perspectives/2024/sellers-beware-getting-to-the-bottom-of-first-party-fraud/
– JPMorgan Merchant Services — Mastercard Excessive Chargeback Program Guide (PDF). https://www.jpmorgan.com/content/dam/jpm/merchant-services/payment-network-updates/documents/mastercard-excessive-chargeback-program-guide.pdf
– Braintree / PayPal Developer — Mastercard monitoring programs (ECP, EFM). https://developer.paypal.com/braintree/articles/risk-and-security/card-brand-monitoring-programs/mastercard-programs/excessive-chargeback-program

Compliance & industry:
– LegitScript — BRAM and VIRP Basics (PDF) and VIRP overview. https://www.legitscript.com/regulatory-and-card-brand-compliance/visa-integrity-risk-program/
– Merchant Risk Council — Stricter VAMP ratio thresholds are now in effect. https://merchantriskcouncil.org/learning/resource-center/member-news/blog/2026/stricter-vamp-ratio-thresholds-are-now-in-effect-heres-how-to-stay-compliant
– Green Sheet (Ken Musante) — VIRP fees. https://greensheet.com/emagazine.php?article_id=7334
– Austreme — Visa Integrity Risk Program pricing (Oct 2023). https://www.austreme.com/en/visa-integrity-risk-program-october-2023/
– Corepay — Visa Integrity Risk Program. https://corepay.net/articles/visa-integrity-risk-program/
– PaymentCloud — VIRP high-risk merchants guide. https://paymentcloudinc.com/blog/visa-integrity-risk-program-high-risk-merchants-guide/
– Ravelin — New VAMP for 2025. https://www.ravelin.com/blog/visa-vamp-changes-chargeback-disputes
– Riskified — Visa VAMP updates. https://www.riskified.com/blog/visa-vamp-updates/
– Corgi Labs — VAMP 2026 merchant compliance. https://www.corgilabs.ai/insights/vamp-2026-merchant-compliance
– Solidgate — Visa’s new VAMP rules. https://solidgate.com/blog/visa-announces-new-change-to-vamp-rules/
– Checkout.com — VAMP explained and billing descriptors. https://www.checkout.com/blog/visa-acquirer-monitoring-program-explained
– Chargebacks911 — VAMP enforcement and MATCH list. https://chargebacks911.com/visa-acquirer-monitoring-program/
– Chargeback Gurus — Visa extends advisory period and even more VAMP changes. https://www.chargebackgurus.com/blog/visa-announces-even-more-vamp-changes
– Stripe — MATCH documentation. https://docs.stripe.com/disputes/match
– Chargeback.io / ChargebackGurus — RDR vs CDRN vs Ethoca. https://www.chargeback.io/blog/rdr-vs-cdrn-vs-ethoca
– Adyen — 3-D Secure liability shift. https://help.adyen.com/en_US/knowledge/risk/dynamic-3d-secure/what-is-the-3d-secure-liability-shift/what-is-the-3d-secure-liability-shift
– LexisNexis Risk Solutions — True Cost of Fraud 2025. https://risk.lexisnexis.com/about-us/press-room/press-release/20250402-tcof-ecommerce-and-retail
– FTC — Negative Option Rule. https://www.ftc.gov/system/files/ftc_gov/pdf/p064202_negative_option_rule.pdf

Reporting note: per-transaction VAMP fine amounts, VIRP acquirer registration fees, and the illegal-transaction assessment figures are reported by acquirers and compliance vendors rather than published in Visa’s public fact sheet; they are labeled accordingly in the text. Statistics attributed to “Datos Insights” underlie most of the chargeback-volume and first-party-fraud figures published by both networks.

Milena Sokolova
Written by
International Banking Consultant · Unity Consulting

Milena Sokolova helps non-resident founders open and keep business bank and EMI accounts. She knows what compliance teams look for and how to prepare an application that actually gets approved.

Leave your review

Your opinion is important to us. Share your impressions of the article - this will help other readers make the right choice.

Rate the article*