{"id":383,"date":"2026-07-06T10:49:20","date_gmt":"2026-07-06T10:49:20","guid":{"rendered":"https:\/\/unitycorporate.com\/?p=383"},"modified":"2026-07-10T20:49:59","modified_gmt":"2026-07-10T20:49:59","slug":"visa-vamp-virp-merchant-crackdown","status":"publish","type":"post","link":"https:\/\/unitycorporate.com\/ua\/blog\/visa-vamp-virp-merchant-crackdown\/","title":{"rendered":"\u0412\u0435\u043b\u0438\u043a\u0438\u0439 \u0434\u0435\u0440\u0438\u0441\u043a\u0456\u043d\u0433: \u044f\u043a \u0437\u0432\u0435\u0434\u0435\u043d\u043d\u044f \u043f\u0440\u0430\u0432\u0438\u043b Visa \u0437\u0430\u043a\u0440\u0438\u0432\u0430\u0454 \u043e\u043d\u043b\u0430\u0439\u043d-\u043c\u0435\u0440\u0447\u0430\u043d\u0442-\u0430\u043a\u0430\u0443\u043d\u0442\u0438"},"content":{"rendered":"<p><em>An investigation into VAMP, VIRP, and the compliance squeeze that has kept card acquiring &#8220;in a storm&#8221; since 2025 \u2014 plus a practical playbook for surviving it.<\/em><\/p>\n<p>For more than a year, the market for online card acceptance has been running through a slow-motion crisis. Merchants wake up to termination notices with 30 days&#8217; warning and no stated cause. Payment service providers quietly tighten onboarding until whole categories of legitimate business can no longer get a merchant account. Acquiring banks \u2014 the institutions that connect a merchant to Visa and Mastercard \u2014 are shrinking their high-risk books rather than risk the fines waiting on the other side of a threshold.<\/p>\n<p>The trigger is not a new law or a regulator. It is Visa&#8217;s own rulebook, rewritten across 2023\u20132026 into two programs that together changed the economics of who gets to accept a card online: the <strong>Visa Integrity Risk Program (VIRP)<\/strong> and the <strong>Visa Acquirer Monitoring Program (VAMP)<\/strong>. Mastercard has moved in near-lockstep with its own monitoring regime. The stated goals are unimpeachable \u2014 less fraud, fewer disputes, no illegal transactions on the network. The practical effect has been a wave of de-risking that catches good businesses alongside bad ones.<\/p>\n<p>This piece breaks down exactly what changed, with the real numbers, and then turns to what merchants and acquirers can actually do about it.<\/p>\n<blockquote style=\"border-left:4px solid #5ad667;background:rgba(237,237,239,.5);margin:1.5em 0;padding:12px 20px;border-radius:0 6px 6px 0;\">\n<p><strong>A note on sourcing.<\/strong> Where a figure comes from Visa&#8217;s or Mastercard&#8217;s own documents, it is labeled as such. Where a figure is reported by acquirers, processors, or chargeback-mitigation vendors \u2014 some of whom sell fear \u2014 it is flagged. Dollar penalty amounts in particular are frequently <em>not<\/em> published by the networks themselves and reach the market through acquirer advisories. Several widely repeated statistics turned out to be superseded or unsourced; those are called out rather than repeated.<\/p>\n<\/blockquote>\n<h2>Part 1 \u2014 What actually changed<\/h2>\n<h3>VAMP: Visa merged fraud and disputes into a single ratio<\/h3>\n<p>Before April 2025, Visa policed merchant risk with two separate programs: the <strong>Visa Dispute Monitoring Program (VDMP)<\/strong>, which tracked chargebacks, and the <strong>Visa Fraud Monitoring Program (VFMP)<\/strong>, which tracked fraud. A merchant could be in trouble on one axis or the other.<\/p>\n<p>On <strong>1 April 2025<\/strong>, Visa folded that structure into a single framework \u2014 the <strong>Visa Acquirer Monitoring Program (VAMP)<\/strong> \u2014 launching it with a six-month advisory period; the updated program thresholds then took effect on <strong>1 June 2025<\/strong>. In Visa&#8217;s own words from its VAMP fact sheet, the change was about <em>&#8220;consolidating the existing VAMP, Visa Fraud Monitoring Program, and Visa Dispute Monitoring Program into a single global program,&#8221;<\/em> streamlining what Visa describes as dozens of separate remediation processes into one. (<a href=\"https:\/\/corporate.visa.com\/en\/sites\/visa-perspectives\/security-trust\/introducing-visa-acquirer-monitoring-program.html\" rel=\"noopener\">Visa, Introducing VAMP<\/a>; <a href=\"https:\/\/corporate.visa.com\/content\/dam\/VCOM\/corporate\/visa-perspectives\/security-and-trust\/documents\/visa-acquirer-monitoring-program-fact-sheet-2025.pdf\" rel=\"noopener\">Visa VAMP Fact Sheet 2025<\/a>)<\/p>\n<p>The structural heart of VAMP \u2014 and the reason it caused so much turbulence \u2014 is a <strong>single combined ratio<\/strong>:<\/p>\n<blockquote style=\"border-left:4px solid #5ad667;background:rgba(237,237,239,.5);margin:1.5em 0;padding:12px 20px;border-radius:0 6px 6px 0;\">\n<p><strong>VAMP Ratio = ( Fraud reports [TC40] + Disputes [TC15] ) \u00f7 Settled card-not-present transactions [TC05]<\/strong><\/p>\n<\/blockquote>\n<p>It is <strong>count-based, not dollar-based<\/strong>, and it applies to <strong>card-not-present<\/strong> (online) VisaNet transactions only. (<a href=\"https:\/\/corporate.visa.com\/content\/dam\/VCOM\/corporate\/visa-perspectives\/security-and-trust\/documents\/visa-acquirer-monitoring-program-fact-sheet-2025.pdf\" rel=\"noopener\">Visa VAMP Fact Sheet 2025<\/a>)<\/p>\n<p>That looks innocuous until you notice the double-counting problem. A single fraudulent transaction can hit the numerator <strong>twice<\/strong> \u2014 once as a TC40 fraud report and again, when the cardholder disputes it, as a TC15 dispute. (<a href=\"https:\/\/www.ravelin.com\/blog\/visa-vamp-changes-chargeback-disputes\" rel=\"noopener\">Ravelin<\/a>; <a href=\"https:\/\/www.riskified.com\/blog\/visa-vamp-updates\/\" rel=\"noopener\">Riskified<\/a>) Merchants who were comfortably inside the old separate limits suddenly found themselves measured against a metric that adds their fraud and their disputes together.<\/p>\n<p><strong>The thresholds (current, per Visa&#8217;s fact sheet):<\/strong><\/p>\n<table>\n<thead>\n<tr>\n<th>Level<\/th>\n<th>Tier<\/th>\n<th>Threshold<\/th>\n<th>Enforced from<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td><strong>Acquirer (portfolio)<\/strong><\/td>\n<td>Above Standard<\/td>\n<td>\u2265 0.50% (50 bps)<\/td>\n<td>1 Jan 2026<\/td>\n<\/tr>\n<tr>\n<td><strong>Acquirer (portfolio)<\/strong><\/td>\n<td>Excessive<\/td>\n<td>\u2265 0.70% (70 bps)<\/td>\n<td>1 Oct 2025<\/td>\n<\/tr>\n<tr>\n<td><strong>Merchant<\/strong> (AP, Canada, EU, US)<\/td>\n<td>Excessive<\/td>\n<td>\u2265 2.20% (220 bps) \u2192 <strong>1.50% from 1 Apr 2026<\/strong><\/td>\n<td>1 Oct 2025<\/td>\n<\/tr>\n<tr>\n<td><strong>Merchant<\/strong> (LAC)<\/td>\n<td>Excessive<\/td>\n<td>\u2265 1.50% (150 bps)<\/td>\n<td>1 Oct 2025<\/td>\n<\/tr>\n<tr>\n<td><strong>Merchant<\/strong> (CEMEA)<\/td>\n<td>Excessive<\/td>\n<td>\u2265 2.20% (220 bps)<\/td>\n<td>1 Oct 2025<\/td>\n<\/tr>\n<tr>\n<td><strong>Enumeration<\/strong> (card-testing)<\/td>\n<td>\u2014<\/td>\n<td>\u2265 20% ratio <strong>and<\/strong> \u2265 300,000 enumerated auth attempts\/month<\/td>\n<td>\u2014<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>There is <strong>no &#8220;above standard&#8221; tier for merchants<\/strong> \u2014 only &#8220;excessive.&#8221; A merchant enters the program only after clearing a floor of <strong>\u2265 1,500 combined fraud + dispute events in a month<\/strong> (in CEMEA, \u2265 150 events <em>and<\/em> \u2265 USD 75,000). (<a href=\"https:\/\/corporate.visa.com\/content\/dam\/VCOM\/corporate\/visa-perspectives\/security-and-trust\/documents\/visa-acquirer-monitoring-program-fact-sheet-2025.pdf\" rel=\"noopener\">Visa VAMP Fact Sheet 2025<\/a>)<\/p>\n<p>Note the regional split that matters for European operators: <strong>Western Europe (the &#8220;EU&#8221; bucket) is on the tightening path to 1.5%, but CEMEA \u2014 Central Europe, Middle East and Africa \u2014 stays at 2.2%<\/strong> with a much lower event floor. Intra-Europe, the same business can face a different standard depending on where its acquirer books it. Latin America has been at 1.5% since launch; Brazil, Chile and India were carved out for a later, separate rollout.<\/p>\n<p><strong>The enforcement calendar<\/strong> is the part that turned a rule change into a market event:<\/p>\n<ul>\n<li><strong>1 Apr 2025<\/strong> \u2014 VAMP goes live; a no-penalty <strong>advisory period<\/strong> begins.<\/li>\n<li><strong>1 Jun 2025<\/strong> \u2014 updated thresholds take effect.<\/li>\n<li><strong>30 Sep 2025<\/strong> \u2014 advisory period ends.<\/li>\n<li><strong>1 Oct 2025<\/strong> \u2014 <strong>enforcement begins<\/strong> for the Excessive tier (fees now assessed).<\/li>\n<li><strong>1 Jan 2026<\/strong> \u2014 acquirer &#8220;Above Standard&#8221; enforcement begins.<\/li>\n<li><strong>1 Apr 2026<\/strong> \u2014 merchant Excessive threshold tightens from <strong>2.2% to 1.5%<\/strong> in AP\/Canada\/EU\/US \u2014 a roughly one-third cut in tolerated dispute volume, effective overnight.<\/li>\n<\/ul>\n<p>(<a href=\"https:\/\/corporate.visa.com\/content\/dam\/VCOM\/corporate\/visa-perspectives\/security-and-trust\/documents\/visa-acquirer-monitoring-program-fact-sheet-2025.pdf\" rel=\"noopener\">Visa VAMP Fact Sheet 2025<\/a>; <a href=\"https:\/\/merchantriskcouncil.org\/learning\/resource-center\/member-news\/blog\/2026\/stricter-vamp-ratio-thresholds-are-now-in-effect-heres-how-to-stay-compliant\" rel=\"noopener\">Merchant Risk Council<\/a>; <a href=\"https:\/\/chargebacks911.com\/visa-acquirer-monitoring-program\/\" rel=\"noopener\">Chargebacks911<\/a>)<\/p>\n<p>Two important corrections to the record, because both circulate widely and both are wrong:<\/p>\n<ol>\n<li><strong>Enforcement was originally set for 1 July 2025<\/strong>, then pushed to 1 October after the Merchant Risk Council relayed industry pushback in March 2025 (the advisory window was extended from three months to six). Any source citing a July 2025 enforcement date is stale. (<a href=\"https:\/\/www.chargebackgurus.com\/blog\/visa-extends-advisory-period-for-vamp\" rel=\"noopener\">Chargeback Gurus<\/a>)<\/li>\n<li><strong>The current thresholds are milder than Visa&#8217;s early drafts.<\/strong> Visa <strong>revised the program upward<\/strong> in May 2025 after industry feedback, so lower figures that still circulate \u2014 notably a <strong>0.9% merchant ratio<\/strong> \u2014 reflect a superseded draft, not the current rule (merchant Excessive is 2.2%, tightening to 1.5% in April 2026). (<a href=\"https:\/\/www.chargebackgurus.com\/blog\/visa-announces-even-more-vamp-changes\" rel=\"noopener\">Chargeback Gurus<\/a>)<\/li>\n<\/ol>\n<p><strong>The fines.<\/strong> Visa&#8217;s public fact sheet defines ratios and thresholds but does <strong>not<\/strong> print per-transaction penalty amounts. Those reach the market through acquirer and processor advisories, which currently converge on:<\/p>\n<ul>\n<li><strong>Acquirer, Above Standard: ~US$4<\/strong> per fraud\/disputed transaction<\/li>\n<li><strong>Acquirer, Excessive: ~US$8<\/strong> per transaction<\/li>\n<li><strong>Merchant, Excessive: ~US$8<\/strong> per transaction<\/li>\n<\/ul>\n<p>These were reportedly revised <em>down<\/em> from an original $5\/$10 schedule before enforcement began. Fines are levied on the <strong>acquirer<\/strong>, which then decides how much to pass through to the merchant. First-time offenders get roughly a three-month grace window; acquirers must file a remediation plan within 15 days of a breach. (<a href=\"https:\/\/www.ravelin.com\/blog\/visa-vamp-changes-chargeback-disputes\" rel=\"noopener\">Ravelin<\/a>; <a href=\"https:\/\/chargebacks911.com\/visa-acquirer-monitoring-program\/\" rel=\"noopener\">Chargebacks911<\/a>) Treat the exact dollar figures as vendor-reported rather than Visa-published.<\/p>\n<h3>The RDR trap: why &#8220;just auto-refund it&#8221; is not a complete fix<\/h3>\n<p>VAMP&#8217;s ratio <strong>excludes disputes resolved through pre-dispute solutions<\/strong> \u2014 tools like Rapid Dispute Resolution (RDR), Order Insight, CDRN and Ethoca that refund or deflect a case before it becomes a chargeback. This is why the entire prevention industry exists: kill the dispute before it posts, and it never enters your numerator. (<a href=\"https:\/\/corporate.visa.com\/content\/dam\/VCOM\/corporate\/visa-perspectives\/security-and-trust\/documents\/visa-acquirer-monitoring-program-fact-sheet-2025.pdf\" rel=\"noopener\">Visa VAMP Fact Sheet 2025<\/a>)<\/p>\n<p>But there is a catch that trips up a lot of merchants: <strong>RDR and CDRN only remove the non-fraud dispute (the TC15). They do not erase the underlying TC40 fraud report.<\/strong> If a transaction was flagged as fraud, auto-refunding it stops the chargeback but the fraud signal still counts against your ratio. The <strong>only<\/strong> mechanism that suppresses the TC40 is <strong>Compelling Evidence 3.0<\/strong>, submitted through Order Insight and accepted by the issuer in the same month. Visa even <em>retracted<\/em> an earlier proposal to exclude Verifi-resolved fraud pre-disputes in March 2025. (<a href=\"https:\/\/www.corgilabs.ai\/insights\/vamp-2026-merchant-compliance\" rel=\"noopener\">Corgi Labs<\/a>; <a href=\"https:\/\/solidgate.com\/blog\/visa-announces-new-change-to-vamp-rules\/\" rel=\"noopener\">Solidgate<\/a>) In other words: prevention tooling controls your <em>dispute<\/em> problem, not your <em>fraud<\/em> problem.<\/p>\n<h3>VIRP: the program that decides whether your category is even allowed<\/h3>\n<p>VAMP governs how <em>well<\/em> you process. <strong>VIRP \u2014 the Visa Integrity Risk Program \u2014 governs whether you&#8217;re allowed to process at all.<\/strong><\/p>\n<p>VIRP took effect on <strong>1 May 2023<\/strong>, replacing the older <strong>Global Brand Protection Program (GBPP)<\/strong>. (<a href=\"https:\/\/www.legitscript.com\/wp-content\/uploads\/2023\/05\/BRAM-and-VIRP-Basics-Info-Sheet.pdf\" rel=\"noopener\">LegitScript<\/a>; <a href=\"https:\/\/paymentcloudinc.com\/blog\/visa-integrity-risk-program-high-risk-merchants-guide\/\" rel=\"noopener\">PaymentCloud<\/a>) Its purpose, per Visa&#8217;s Ecosystem Risk Programs Guide, is <em>&#8220;to deter, detect, and remediate illegal activity&#8221;<\/em> on the network \u2014 with particular attention to <em>&#8220;certain business types that are at a higher risk of processing unlawful transactions.&#8221;<\/em><\/p>\n<p>VIRP sorts high-integrity-risk merchants into <strong>three tiers<\/strong>, each mapped to specific merchant category codes (MCCs):<\/p>\n<ul>\n<li><strong>Tier 1<\/strong> (highest risk \u2014 activity that can harm health or safety): adult-content merchants (MCC 5967), dating services (MCC 7273), gambling (MCC 7995), pharmacies (MCC 5122\/5912).<\/li>\n<li><strong>Tier 2<\/strong> (financial or economic harm): crypto (6051\/6012 under special condition code 7), cyberlockers\/file-sharing (4816), card-absent games of skill (5816).<\/li>\n<li><strong>Tier 3<\/strong> (deceptive marketing): card-absent financial trading \u2014 forex, CFDs, binary options (6211); outbound telemarketing (5966); <strong>subscription \/ negative-option billing (5968)<\/strong>; cross-border tobacco (5993).<\/li>\n<\/ul>\n<p>(<a href=\"https:\/\/www.legitscript.com\/regulatory-and-card-brand-compliance\/visa-integrity-risk-program\/\" rel=\"noopener\">LegitScript<\/a>; <a href=\"https:\/\/paymentcloudinc.com\/blog\/visa-integrity-risk-program-high-risk-merchants-guide\/\" rel=\"noopener\">PaymentCloud<\/a>)<\/p>\n<p>To board a merchant in any of these categories, the acquirer must <strong>register it with Visa<\/strong> and carry ongoing obligations: control assessments (annually for Tier 1), self-assessments, and an <strong>annual High-Integrity-Risk attestation<\/strong> to Visa that its merchants remain compliant. (<a href=\"https:\/\/corporate.visa.com\/content\/dam\/VCOM\/corporate\/visa-perspectives\/documents\/protecting-the-integrity-of-the-visa-network.pdf\" rel=\"noopener\">Visa, Protecting the Integrity of the Visa Network<\/a>)<\/p>\n<p><strong>The costs stack up fast:<\/strong><\/p>\n<ul>\n<li><strong>Merchant registration fee: raised from US$500 to US$950<\/strong> on 1 April 2024, per provider, per acquirer, billed annually. (<a href=\"https:\/\/corepay.net\/articles\/visa-integrity-risk-program\/\" rel=\"noopener\">Corepay<\/a>)<\/li>\n<li><strong>Acquirer-level program registration:<\/strong> reported at <strong>US$100,000 initial + US$100,000 annual<\/strong> for Tiers 1 and 2, and <strong>US$25,000 + US$25,000<\/strong> for Tier 3. (<a href=\"https:\/\/greensheet.com\/emagazine.php?article_id=7334\" rel=\"noopener\">Green Sheet<\/a>; one source lists the Tier 1 renewal at $50,000 \u2014 figures vary by source.)<\/li>\n<li><strong>A per-transaction Integrity Risk Fee<\/strong> on select Tier 1 categories (adult, dating, gambling): <strong>US$0.10 per transaction + 10 basis points<\/strong> of processed volume. (<a href=\"https:\/\/corepay.net\/articles\/visa-integrity-risk-program\/\" rel=\"noopener\">Corepay<\/a>; <a href=\"https:\/\/greensheet.com\/emagazine.php?article_id=7334\" rel=\"noopener\">Green Sheet<\/a>)<\/li>\n<\/ul>\n<p>And the penalties are where VIRP becomes an existential risk for an acquirer&#8217;s whole book. Straight from <strong>Visa&#8217;s Core Rules (\u00a712.5.5.1)<\/strong>:<\/p>\n<blockquote style=\"border-left:4px solid #5ad667;background:rgba(237,237,239,.5);margin:1.5em 0;padding:12px 20px;border-radius:0 6px 6px 0;\">\n<p>Visa may impose a non-compliance assessment of <strong>USD 100,000 for Tier 1 and Tier 2 Merchants, or USD 25,000 for Tier 3 Merchants, to the Acquirer per calendar month of non-compliance<\/strong>, plus a non-compliance assessment of <strong>USD 2,000 per High-Integrity Risk Merchant \u2026 per calendar month of non-compliance.<\/strong><\/p>\n<\/blockquote>\n<p>(<a href=\"https:\/\/usa.visa.com\/dam\/VCOM\/download\/about-visa\/visa-rules-public.pdf\" rel=\"noopener\">Visa Core Rules and Product &amp; Service Rules<\/a>)<\/p>\n<p>Try to dodge the rules by altering a merchant&#8217;s name, data or transaction performance and Visa&#8217;s Core Rules (\u00a712.5.3.2) authorize <strong>US$25,000 per merchant per month plus permanent disqualification<\/strong> of the merchant and its principals. For processing outright illegal transactions, Visa&#8217;s confidential VIRP Guide \u2014 as reported by compliance vendors \u2014 sets non-compliance assessments of <strong>US$50,000 per merchant or URL, up to a US$150,000 maximum<\/strong>, with materially larger assessments \u2014 reported at up to <strong>US$400,000<\/strong> \u2014 reserved for the most serious illegal-content violations, which carry a 24-hour remediation deadline. (<a href=\"https:\/\/www.austreme.com\/en\/visa-integrity-risk-program-october-2023\/\" rel=\"noopener\">Austreme<\/a>; <a href=\"https:\/\/www.legitscript.com\/wp-content\/uploads\/2023\/05\/BRAM-and-VIRP-Basics-Info-Sheet.pdf\" rel=\"noopener\">LegitScript<\/a>) Crucially, and unlike Mastercard, <strong>Visa offers no fine-mitigation program<\/strong> \u2014 there is no path to a partial refund of a VIRP assessment. (<a href=\"https:\/\/www.legitscript.com\/wp-content\/uploads\/2023\/05\/BRAM-and-VIRP-Basics-Info-Sheet.pdf\" rel=\"noopener\">LegitScript<\/a>)<\/p>\n<p>Stack it up from the acquirer&#8217;s chair: six-figure monthly exposure per non-compliant merchant, no mitigation, plus registration costs, control assessments and annual attestation. For many banks the math is simple \u2014 <strong>it is cheaper to exit the category than to bank it.<\/strong><\/p>\n<h2>Part 2 \u2014 The downstream crackdown<\/h2>\n<h3>Why acquirers close accounts <em>before<\/em> you breach<\/h3>\n<p>Here is the mechanism that turned Visa&#8217;s rulebook into merchant terminations. <strong>The networks fine the acquirer, not the merchant directly.<\/strong> Under VAMP, the acquirer&#8217;s entire portfolio now carries its own ratio and its own &#8220;Above Standard&#8221; (0.5%) and &#8220;Excessive&#8221; (0.7%) thresholds. One bad merchant doesn&#8217;t just fine itself \u2014 it drags the acquirer&#8217;s book toward a portfolio-level penalty. (<a href=\"https:\/\/merchantriskcouncil.org\/learning\/resource-center\/member-news\/blog\/2026\/stricter-vamp-ratio-thresholds-are-now-in-effect-heres-how-to-stay-compliant\" rel=\"noopener\">Merchant Risk Council<\/a>)<\/p>\n<p>Because the acquirer bears the cost, the rational move is to set <strong>internal limits stricter than Visa&#8217;s<\/strong> and to cut merchants who are merely <em>approaching<\/em> a threshold, not just those who breach it. This is the chilling effect: a merchant running at 1.2% under a 1.5% rule is not &#8220;compliant&#8221; in the acquirer&#8217;s eyes \u2014 it&#8217;s a liability trending the wrong way. High-risk merchant agreements routinely allow <strong>termination on 30 days&#8217; notice with no cause<\/strong>, and settlement funds can be held for <strong>90\u2013180 days<\/strong> afterward. (<a href=\"https:\/\/boxchrge.com\/why-banks-derisk-high-risk-merchant-accounts\/\" rel=\"noopener\">Boxchrge<\/a>)<\/p>\n<p>Much of the offboarding is <strong>category-level, not performance-level.<\/strong> A merchant with clean numbers can lose its account simply because its bank decided to exit the vertical \u2014 a decision driven by VIRP&#8217;s compliance load and VAMP&#8217;s portfolio math, not by anything that specific merchant did. (This &#8220;whole-category de-risking&#8221; narrative is well-established in industry commentary; the vivid termination-count figures attached to it are not \u2014 see the caution below.)<\/p>\n<h3>MATCH: the five-year scarlet letter<\/h3>\n<p>When an acquirer terminates a merchant for cause, it is generally required to add that merchant to <strong>MATCH \u2014 the Mastercard Alert to Control High-risk Merchants<\/strong>, the industry blacklist historically called the Terminated Merchant File (TMF). Any acquirer screening a new application checks MATCH, so a listing is, in practice, close to disqualifying \u2014 new applications are usually declined, though specialist high-risk acquirers will sometimes board a listed merchant at premium pricing and heavy reserves. (<a href=\"https:\/\/docs.stripe.com\/disputes\/match\" rel=\"noopener\">Stripe \u2014 MATCH documentation<\/a>)<\/p>\n<p>Key facts merchants get wrong:<\/p>\n<ul>\n<li><strong>The reason code for excessive chargebacks is 04, not 12.<\/strong> (Code 12 is PCI-DSS non-compliance.) Code 04 is triggered when a merchant&#8217;s monthly Mastercard chargebacks exceed <strong>1% of sales <em>and<\/em> total US$5,000 or more.<\/strong> (<a href=\"https:\/\/docs.stripe.com\/disputes\/match\" rel=\"noopener\">Stripe<\/a>)<\/li>\n<li><strong>A listing lasts five years<\/strong> and is purged automatically \u2014 there is no early &#8220;appeal&#8221; except by the acquirer that listed you, and only if the listing was an error (or, for a PCI-compliance listing under code 12, once compliance is restored). (<a href=\"https:\/\/docs.stripe.com\/disputes\/match\" rel=\"noopener\">Stripe<\/a>)<\/li>\n<li><strong>You are not notified.<\/strong> Most merchants discover they&#8217;re on MATCH only when their next application is declined. (<a href=\"https:\/\/docs.stripe.com\/disputes\/match\" rel=\"noopener\">Stripe<\/a>)<\/li>\n<\/ul>\n<p>There is <strong>no public figure<\/strong> for how many merchants sit on MATCH or are terminated each year \u2014 Mastercard doesn&#8217;t disclose it. Any specific &#8220;X million merchants terminated&#8221; number circulating online is unsourced.<\/p>\n<h3>The verticals in the blast radius<\/h3>\n<p>The businesses most exposed are the ones that sit at the intersection of high dispute rates and VIRP categories: <strong>subscription and negative-option billing, nutraceuticals and supplements, CBD\/hemp\/vape, online gambling, adult, crypto, forex\/CFD\/binary options, pharma, travel and ticketing, and dropshipping.<\/strong> (<a href=\"https:\/\/catalystpay.com\/resources\/blog\/high-risk-merchant-account-approval\" rel=\"noopener\">CatalystPay<\/a>; <a href=\"https:\/\/www.legitscript.com\/regulatory-and-card-brand-compliance\/virp\/\" rel=\"noopener\">LegitScript<\/a>)<\/p>\n<p>Subscription businesses deserve a special mention because two forces hit them at once. a Mastercard-cited 2020 merchant survey found that <strong>75% of disputes for subscriptions and digital goods are first-party misuse<\/strong> \u2014 customers disputing rather than cancelling. (<a href=\"https:\/\/newsroom.mastercard.com\/news\/perspectives\/2024\/sellers-beware-getting-to-the-bottom-of-first-party-fraud\/\" rel=\"noopener\">Mastercard Newsroom<\/a>) At the same time, negative-option billing sits under intensifying regulatory scrutiny \u2014 the federal ROSCA statute, a wave of state &#8220;click-to-cancel&#8221; laws, and the FTC&#8217;s on-again negative-option rulemaking (its 2024 &#8220;click-to-cancel&#8221; rule was vacated by a federal court in 2025). So a subscription merchant faces elevated disputes <em>and<\/em> elevated regulatory scrutiny <em>and<\/em> a VIRP Tier-3 classification \u2014 a triple bind.<\/p>\n<h2>Part 3 \u2014 Is this actually a &#8220;storm&#8221;? What the data says<\/h2>\n<p>It is easy to overstate a crisis, and the high-risk-processing industry has a commercial incentive to do so. So here is what the <strong>credible, primary<\/strong> data actually shows \u2014 and which scary numbers to distrust.<\/p>\n<p><strong>Disputes are genuinely rising.<\/strong> Mastercard&#8217;s 2025 Global Chargebacks Outlook (built on Datos Insights research) projects <strong>261 million chargebacks globally in 2025, rising to 324 million by 2028<\/strong>, with the total cost climbing from <strong>US$33.8 billion to US$41.7 billion.<\/strong> Growth is fastest outside North America \u2014 Europe is projected at 27% growth through 2028, Asia-Pacific 35%, the Middle East and Africa 59%. (<a href=\"https:\/\/www.mastercard.com\/us\/en\/news-and-trends\/Insights\/2025\/2025-global-chargebacks-outlook.html\" rel=\"noopener\">Mastercard \/ Ethoca, 2025 State of Chargebacks<\/a>)<\/p>\n<blockquote style=\"border-left:4px solid #5ad667;background:rgba(237,237,239,.5);margin:1.5em 0;padding:12px 20px;border-radius:0 6px 6px 0;\">\n<p><strong>Correction to a stat you&#8217;ll see everywhere:<\/strong> the widely quoted <em>&#8220;337 million chargebacks by 2026&#8221;<\/em> is a <em>2023 Datos Insights projection<\/em>, published by Mastercard and <strong>since superseded<\/strong> by the 261M\u2192324M trajectory above. Quoting &#8220;337M by 2026&#8221; in 2026 is quoting a stale forecast.<\/p>\n<\/blockquote>\n<p><strong>First-party (&#8220;friendly&#8221;) fraud is a real driver \u2014 but smaller than vendors claim.<\/strong> Visa states that friendly fraud is roughly <strong>20% of all fraudulent disputes globally, and up to 30% for high-volume online merchants.<\/strong> (<a href=\"https:\/\/corporate.visa.com\/en\/solutions\/visa-protect\/insights\/friendly-fraud.html\" rel=\"noopener\">Visa<\/a>) Datos\/Mastercard&#8217;s measured breakdown puts first-party misuse at about <strong>21% of merchant chargebacks.<\/strong> (<a href=\"https:\/\/www.mastercard.com\/us\/en\/news-and-trends\/Insights\/2025\/2025-global-chargebacks-outlook.html\" rel=\"noopener\">Mastercard \/ Ethoca, 2025<\/a>)<\/p>\n<blockquote style=\"border-left:4px solid #5ad667;background:rgba(237,237,239,.5);margin:1.5em 0;padding:12px 20px;border-radius:0 6px 6px 0;\">\n<p><strong>Distrust the &#8220;70\u201375% friendly fraud&#8221; figure.<\/strong> It appears in vendor content attributed vaguely to &#8220;Visa and Mastercard reports&#8221; with no traceable citation. The measured number is ~21%. Likewise, the &#8220;$132 billion&#8221; and &#8220;250,000 merchants terminated by year-end&#8221; figures that circulate are unsourced vendor or broker projections \u2014 not card-network data.<\/p>\n<\/blockquote>\n<p><strong>Chargebacks are expensive out of proportion to their size.<\/strong> The fully-loaded cost of a chargeback \u2014 fees, penalties, lost goods, operations \u2014 can run to more than <strong>twice the transaction value<\/strong> (a figure highlighted on Mastercard&#8217;s site, citing Forter), and LexisNexis&#8217;s 2025 True Cost of Fraud study puts it at <strong>US$4.61 for every US$1<\/strong> of fraud loss for US retail and e-commerce merchants. (<a href=\"https:\/\/newsroom.mastercard.com\/news\/perspectives\/2024\/sellers-beware-getting-to-the-bottom-of-first-party-fraud\/\" rel=\"noopener\">Mastercard Newsroom<\/a>; <a href=\"https:\/\/risk.lexisnexis.com\/about-us\/press-room\/press-release\/20250402-tcof-ecommerce-and-retail\" rel=\"noopener\">LexisNexis Risk Solutions<\/a>)<\/p>\n<p>So: the storm is real in its mechanism and its direction, but the most alarming numbers attached to it are the least sourced. Visa&#8217;s rationale \u2014 that combining fraud and disputes, raising the cost of laxity, and forcing prevention tooling will pull dispute volume down \u2014 is a coherent response to a genuine trend. The collateral damage is that a compliance regime calibrated for the worst actors also reshapes the economics for everyone else.<\/p>\n<h2>Part 4 \u2014 Mastercard is doing the same thing, differently<\/h2>\n<p>A &#8220;Visa storm&#8221; narrative is incomplete, because a merchant accepts both brands and can be caught by either. But the two networks are built differently, and the contrast is the single most useful thing to understand.<\/p>\n<p><strong>Mastercard keeps fraud and disputes in <em>separate<\/em> programs:<\/strong><\/p>\n<ul>\n<li><strong>Excessive Chargeback Program (ECP)<\/strong> \u2014 measures chargebacks only, via a chargeback-to-transaction ratio (CTR):<\/li>\n<li><strong>ECM (Excessive Chargeback Merchant):<\/strong> \u2265 100 chargebacks\/month <strong>and<\/strong> CTR <strong>1.50%\u20132.99%.<\/strong><\/li>\n<li><strong>HECM (High Excessive):<\/strong> \u2265 300 chargebacks\/month <strong>and<\/strong> CTR <strong>\u2265 3.00%.<\/strong><\/li>\n<li>Fines escalate by consecutive month \u2014 $0 in month 1, $1,000 in month 2, up to <strong>$100,000\u2013$200,000 per month at 19+ months<\/strong>, plus a <strong>$5-per-chargeback<\/strong> issuer-recovery assessment above 300 chargebacks. Exit requires three consecutive clean months. (<a href=\"https:\/\/www.jpmorgan.com\/content\/dam\/jpm\/merchant-services\/payment-network-updates\/documents\/mastercard-excessive-chargeback-program-guide.pdf\" rel=\"noopener\">JPMorgan Merchant Services \u2014 Mastercard ECM Guide<\/a>; <a href=\"https:\/\/developer.paypal.com\/braintree\/articles\/risk-and-security\/card-brand-monitoring-programs\/mastercard-programs\/excessive-chargeback-program\" rel=\"noopener\">Braintree\/PayPal<\/a>)<\/li>\n<li><strong>Excessive Fraud Merchant (EFM)<\/strong> \u2014 measures e-commerce fraud only, triggering when a merchant clears <strong>all four<\/strong> thresholds in a month: \u2265 1,000 e-commerce transactions, \u2265 US$50,000 in fraud chargebacks, a fraud ratio \u2265 0.50%, <strong>and<\/strong> 3-D Secure usage below 50% (regulated markets) or 10% (non-regulated). (<a href=\"https:\/\/developer.paypal.com\/braintree\/articles\/risk-and-security\/card-brand-monitoring-programs\/mastercard-programs\/excessive-fraud-merchant-program\" rel=\"noopener\">Braintree\/PayPal<\/a>)<\/li>\n<\/ul>\n<p><strong>This is the key contrast:<\/strong> Mastercard still separates fraud from disputes; <strong>Visa&#8217;s VAMP is the outlier that merged them into one ratio.<\/strong> Notably, Visa looked <em>like Mastercard does today<\/em> until June 2025 \u2014 it was VAMP&#8217;s consolidation of VDMP and VFMP that made Visa the structural exception. And while Mastercard&#8217;s 1.5% ECM ratio and Visa&#8217;s post-April-2026 1.5% VAMP ratio <em>look<\/em> identical, they are not comparable: Mastercard&#8217;s 1.5% counts <strong>chargebacks only<\/strong>, Visa&#8217;s counts <strong>fraud + disputes combined.<\/strong><\/p>\n<p>On the compliance side, Mastercard&#8217;s counterpart to VIRP is its <strong>Business Risk Assessment and Mitigation (BRAM)<\/strong> program (now branded the Merchant Monitoring program), which LegitScript describes as carrying <em>&#8220;fines as high as six figures per transaction&#8221;<\/em> \u2014 larger per-instance than Visa&#8217;s \u2014 but, unlike Visa, Mastercard offers a <strong>fine-mitigation program<\/strong> that can rebate 75\u2013100% of an assessment when the acquirer engages an approved monitoring provider. (<a href=\"https:\/\/www.legitscript.com\/wp-content\/uploads\/2023\/05\/BRAM-and-VIRP-Basics-Info-Sheet.pdf\" rel=\"noopener\">LegitScript<\/a>)<\/p>\n<p><strong>Bottom line on scheme-vs-scheme:<\/strong> VAMP&#8217;s combined ratio and its 2025\u20132026 enforcement calendar are <strong>Visa-specific<\/strong>. MATCH, the rising-dispute trend, first-party fraud, and the underlying de-risking pressure are <strong>scheme-wide<\/strong>. When people say &#8220;the Visa storm,&#8221; what they usually mean is the whole weather system \u2014 both networks tightening at once.<\/p>\n<h2>Part 5 \u2014 The survival playbook<\/h2>\n<p>The regime is not survivable by hoping. It is survivable by driving your ratio down and building redundancy before you need it. Here is what actually works.<\/p>\n<h3>1. Know your real number \u2014 and watch the right one<\/h3>\n<p>Your VAMP ratio is <strong>fraud (TC40) + disputes (TC15) over settled CNP transactions<\/strong>, count-based, measured monthly. Ask your acquirer for your <strong>current VAMP standing and the trend<\/strong>, not just a pass\/fail. Remember the merchant floor (1,500 events) and that the Excessive line dropped to <strong>1.5% on 1 April 2026<\/strong> in AP\/Canada\/EU\/US \u2014 if you were sitting comfortably at 1.8% under the old 2.2% rule, you are now over the line. Track fraud and disputes <strong>separately<\/strong> too, because they have different fixes.<\/p>\n<h3>2. Deploy the pre-dispute stack \u2014 but understand what each tool actually removes<\/h3>\n<p>Disputes resolved before they post are <strong>excluded from the VAMP ratio.<\/strong> The tools, mapped to the network that owns them:<\/p>\n<table>\n<thead>\n<tr>\n<th>Tool<\/th>\n<th>Network<\/th>\n<th>What it does<\/th>\n<th>What it removes<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td><strong>RDR<\/strong> (Rapid Dispute Resolution)<\/td>\n<td>Visa (Verifi)<\/td>\n<td>Rules-based <strong>automatic<\/strong> refund before chargeback; ~97% of Visa cards<\/td>\n<td>The TC15 dispute \u2014 <strong>not<\/strong> the TC40 fraud<\/td>\n<\/tr>\n<tr>\n<td><strong>CDRN<\/strong><\/td>\n<td>Visa (Verifi)<\/td>\n<td>Pre-dispute <strong>alert<\/strong>; ~72 hrs to refund manually<\/td>\n<td>The TC15 dispute<\/td>\n<\/tr>\n<tr>\n<td><strong>Order Insight<\/strong><\/td>\n<td>Visa (Verifi)<\/td>\n<td>Real-time transaction-detail sharing; deflects a large share of inquiries (vendors report ~40\u201365%)<\/td>\n<td>The dispute; carries <strong>CE3.0<\/strong>, which <em>can<\/em> remove the TC40<\/td>\n<\/tr>\n<tr>\n<td><strong>Ethoca Alerts<\/strong><\/td>\n<td>Mastercard<\/td>\n<td>Pre-dispute <strong>alert<\/strong>; 24\u201372 hrs to refund manually; ~95% of Mastercard<\/td>\n<td>The chargeback<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><em>Coverage and deflection percentages in this table are vendor-reported and vary by source \u2014 treat them as indicative, not card-network-audited figures.<\/em><\/p>\n<p>(<a href=\"https:\/\/corporate.visa.com\/content\/dam\/VCOM\/corporate\/visa-perspectives\/security-and-trust\/documents\/visa-acquirer-monitoring-program-fact-sheet-2025.pdf\" rel=\"noopener\">Visa VAMP Fact Sheet<\/a>; <a href=\"https:\/\/www.chargeback.io\/blog\/rdr-vs-cdrn-vs-ethoca\" rel=\"noopener\">Chargeback.io<\/a>; <a href=\"https:\/\/www.chargebackgurus.com\/blog\/rapid-dispute-resolution\" rel=\"noopener\">ChargebackGurus<\/a>) The mnemonic: <strong>Verifi = Visa, Ethoca = Mastercard.<\/strong> Alert pricing runs roughly <strong>$15\u2013$40 per alert<\/strong> depending on reseller \u2014 a cost worth paying only if the refund is cheaper than the ratio damage.<\/p>\n<p>The critical nuance again: <strong>RDR and CDRN clear the dispute but leave the fraud record.<\/strong> For fraud-driven ratio problems, the tool that matters is <strong>Compelling Evidence 3.0<\/strong> via Order Insight (issuer-accepted, same month) \u2014 that is the only thing that suppresses the TC40.<\/p>\n<h3>3. Authenticate to shift fraud liability<\/h3>\n<p><strong>EMV 3-D Secure 2<\/strong> moves liability for <strong>fraud<\/strong> chargebacks to the issuer when the transaction is successfully authenticated \u2014 covering the networks&#8217; fraud dispute categories (Visa reason codes 10.1\u201310.5 and Mastercard&#8217;s fraud-related codes), but <strong>not<\/strong> non-fraud\/consumer disputes. (<a href=\"https:\/\/help.adyen.com\/en_US\/knowledge\/risk\/dynamic-3d-secure\/what-is-the-3d-secure-liability-shift\/what-is-the-3d-secure-liability-shift\" rel=\"noopener\">Adyen<\/a>; <a href=\"https:\/\/www.gpayments.com\/blog\/article\/3d-secure-liability-shift-in-the-united-states-whats-covered-and-what-isnt\/\" rel=\"noopener\">gPayments<\/a>) It does double duty: it lowers your fraud numerator <em>and<\/em> keeps you out of Mastercard&#8217;s EFM program, where low 3DS usage is itself a trigger.<\/p>\n<h3>4. Fix the boring things that cause disputes<\/h3>\n<ul>\n<li><strong>Billing descriptors<\/strong> that match your checkout brand and say what was bought. Opaque DBAs generate &#8220;I don&#8217;t recognize this charge&#8221; disputes. (<a href=\"https:\/\/www.checkout.com\/blog\/how-to-use-billing-descriptors-to-decrease-chargebacks\" rel=\"noopener\">Checkout.com<\/a>)<\/li>\n<li><strong>Delivery and service confirmation<\/strong> \u2014 tracking numbers, delivery confirmation, signature on high-value orders. It&#8217;s the strongest evidence against &#8220;item not received.&#8221;<\/li>\n<li><strong>Subscription hygiene<\/strong> \u2014 clear and conspicuous terms <em>before<\/em> billing, express informed consent before charging, renewal reminders, and a simple cancellation mechanism (ROSCA&#8217;s baseline requirement; several state laws now demand cancellation be as easy as sign-up). This attacks the first-party-misuse problem at its root and reduces regulatory exposure at the same time. (<a href=\"https:\/\/www.ftc.gov\/system\/files\/ftc_gov\/pdf\/p064202_negative_option_rule.pdf\" rel=\"noopener\">FTC Negative Option Rule<\/a>)<\/li>\n<\/ul>\n<h3>5. Diversify acquiring before you&#8217;re forced to<\/h3>\n<p>Single-acquirer dependence is now an existential risk, not just an operational one. <strong>Multiple MIDs across multiple acquirers,<\/strong> with intelligent routing\/load-balancing, does three things: it keeps you processing if one MID is restricted, it prevents any single MID&#8217;s ratio from spiking, and it gives you leverage. (<a href=\"https:\/\/kount.com\/blog\/what-is-load-balancing-merchant-accounts\" rel=\"noopener\">Kount \u2014 Load Balancing<\/a>; <a href=\"https:\/\/secureglobalpay.net\/gateway-services\/merchant-id-management\/\" rel=\"noopener\">SecureGlobalPay<\/a>) A word of caution: deliberately fragmenting a business across MIDs <em>to disguise its category or dodge VIRP\/VAMP<\/em> is exactly the &#8220;circumvention&#8221; that Visa&#8217;s Core Rules punish with $25,000\/merchant\/month and permanent disqualification. Diversify for resilience, not for evasion.<\/p>\n<h3>6. Stay off MATCH<\/h3>\n<p>Getting listed is far more expensive than any single month of fines, because it locks you out of the market for five years. Practically: keep your Mastercard chargeback ratio below the 1% \/ $5,000 code-04 line; if an acquirer signals it intends to terminate, negotiate a <strong>voluntary, no-MATCH offboarding<\/strong> and settle disputes before they post; and if you <em>are<\/em> listed in error, only the acquirer that listed you can remove you \u2014 so document everything.<\/p>\n<h2>The uncomfortable synthesis<\/h2>\n<p>Visa did not set out to close good businesses. Combining fraud and disputes into one metric, raising the price of laxity, and pushing prevention tooling are defensible answers to a dispute problem that is genuinely growing and genuinely costly. First-party fraud is real; illegal transactions on the network are real; brand risk is real.<\/p>\n<p>But a compliance regime is a blunt instrument. When you fine the acquirer for the merchant&#8217;s behavior, you hand the acquirer a reason to cut anything that looks risky. When you make VIRP registration a six-figure, no-mitigation liability, you make whole legal categories uneconomic to bank. When you drop the merchant threshold by a third overnight, you reclassify yesterday&#8217;s compliant merchant as today&#8217;s problem. The result is a market where the surviving edge belongs to whoever keeps their ratio lowest, diversifies earliest, and treats dispute prevention as core infrastructure rather than an afterthought.<\/p>\n<p>The storm is not a glitch. It is the system working as designed \u2014 and the businesses that make it through will be the ones that stopped waiting for it to pass and started building for the climate.<\/p>\n<h2>Sources<\/h2>\n<p><strong>Visa (primary):<\/strong><br \/>\n&#8211; Visa \u2014 <em>Introducing the Visa Acquirer Monitoring Program.<\/em> https:\/\/corporate.visa.com\/en\/sites\/visa-perspectives\/security-trust\/introducing-visa-acquirer-monitoring-program.html<br \/>\n&#8211; Visa \u2014 <em>VAMP Fact Sheet 2025<\/em> (PDF). https:\/\/corporate.visa.com\/content\/dam\/VCOM\/corporate\/visa-perspectives\/security-and-trust\/documents\/visa-acquirer-monitoring-program-fact-sheet-2025.pdf<br \/>\n&#8211; Visa \u2014 <em>Core Rules and Visa Product &amp; Service Rules<\/em> (PDF; VIRP non-compliance assessments \u00a712.5.3.2, \u00a712.5.5.1). https:\/\/usa.visa.com\/dam\/VCOM\/download\/about-visa\/visa-rules-public.pdf<br \/>\n&#8211; Visa \u2014 <em>Protecting the Integrity of the Visa Network<\/em> (PDF). https:\/\/corporate.visa.com\/content\/dam\/VCOM\/corporate\/visa-perspectives\/documents\/protecting-the-integrity-of-the-visa-network.pdf<br \/>\n&#8211; Visa \u2014 <em>Friendly fraud insights.<\/em> https:\/\/corporate.visa.com\/en\/solutions\/visa-protect\/insights\/friendly-fraud.html<\/p>\n<p><strong>Mastercard (primary):<\/strong><br \/>\n&#8211; Mastercard \/ Ethoca \u2014 <em>2025 Global Chargebacks Outlook.<\/em> https:\/\/www.mastercard.com\/us\/en\/news-and-trends\/Insights\/2025\/2025-global-chargebacks-outlook.html<br \/>\n&#8211; Mastercard Newsroom \u2014 <em>Sellers beware: getting to the bottom of first-party fraud<\/em> (2024). https:\/\/newsroom.mastercard.com\/news\/perspectives\/2024\/sellers-beware-getting-to-the-bottom-of-first-party-fraud\/<br \/>\n&#8211; JPMorgan Merchant Services \u2014 <em>Mastercard Excessive Chargeback Program Guide<\/em> (PDF). https:\/\/www.jpmorgan.com\/content\/dam\/jpm\/merchant-services\/payment-network-updates\/documents\/mastercard-excessive-chargeback-program-guide.pdf<br \/>\n&#8211; Braintree \/ PayPal Developer \u2014 <em>Mastercard monitoring programs (ECP, EFM).<\/em> https:\/\/developer.paypal.com\/braintree\/articles\/risk-and-security\/card-brand-monitoring-programs\/mastercard-programs\/excessive-chargeback-program<\/p>\n<p><strong>Compliance &amp; industry:<\/strong><br \/>\n&#8211; LegitScript \u2014 <em>BRAM and VIRP Basics<\/em> (PDF) and <em>VIRP overview.<\/em> https:\/\/www.legitscript.com\/regulatory-and-card-brand-compliance\/visa-integrity-risk-program\/<br \/>\n&#8211; Merchant Risk Council \u2014 <em>Stricter VAMP ratio thresholds are now in effect.<\/em> https:\/\/merchantriskcouncil.org\/learning\/resource-center\/member-news\/blog\/2026\/stricter-vamp-ratio-thresholds-are-now-in-effect-heres-how-to-stay-compliant<br \/>\n&#8211; Green Sheet (Ken Musante) \u2014 <em>VIRP fees.<\/em> https:\/\/greensheet.com\/emagazine.php?article_id=7334<br \/>\n&#8211; Austreme \u2014 <em>Visa Integrity Risk Program pricing (Oct 2023).<\/em> https:\/\/www.austreme.com\/en\/visa-integrity-risk-program-october-2023\/<br \/>\n&#8211; Corepay \u2014 <em>Visa Integrity Risk Program.<\/em> https:\/\/corepay.net\/articles\/visa-integrity-risk-program\/<br \/>\n&#8211; PaymentCloud \u2014 <em>VIRP high-risk merchants guide.<\/em> https:\/\/paymentcloudinc.com\/blog\/visa-integrity-risk-program-high-risk-merchants-guide\/<br \/>\n&#8211; Ravelin \u2014 <em>New VAMP for 2025.<\/em> https:\/\/www.ravelin.com\/blog\/visa-vamp-changes-chargeback-disputes<br \/>\n&#8211; Riskified \u2014 <em>Visa VAMP updates.<\/em> https:\/\/www.riskified.com\/blog\/visa-vamp-updates\/<br \/>\n&#8211; Corgi Labs \u2014 <em>VAMP 2026 merchant compliance.<\/em> https:\/\/www.corgilabs.ai\/insights\/vamp-2026-merchant-compliance<br \/>\n&#8211; Solidgate \u2014 <em>Visa&#8217;s new VAMP rules.<\/em> https:\/\/solidgate.com\/blog\/visa-announces-new-change-to-vamp-rules\/<br \/>\n&#8211; Checkout.com \u2014 <em>VAMP explained<\/em> and <em>billing descriptors.<\/em> https:\/\/www.checkout.com\/blog\/visa-acquirer-monitoring-program-explained<br \/>\n&#8211; Chargebacks911 \u2014 <em>VAMP enforcement<\/em> and <em>MATCH list.<\/em> https:\/\/chargebacks911.com\/visa-acquirer-monitoring-program\/<br \/>\n&#8211; Chargeback Gurus \u2014 <em>Visa extends advisory period<\/em> and <em>even more VAMP changes.<\/em> https:\/\/www.chargebackgurus.com\/blog\/visa-announces-even-more-vamp-changes<br \/>\n&#8211; Stripe \u2014 <em>MATCH documentation.<\/em> https:\/\/docs.stripe.com\/disputes\/match<br \/>\n&#8211; Chargeback.io \/ ChargebackGurus \u2014 <em>RDR vs CDRN vs Ethoca.<\/em> https:\/\/www.chargeback.io\/blog\/rdr-vs-cdrn-vs-ethoca<br \/>\n&#8211; Adyen \u2014 <em>3-D Secure liability shift.<\/em> https:\/\/help.adyen.com\/en_US\/knowledge\/risk\/dynamic-3d-secure\/what-is-the-3d-secure-liability-shift\/what-is-the-3d-secure-liability-shift<br \/>\n&#8211; LexisNexis Risk Solutions \u2014 <em>True Cost of Fraud 2025.<\/em> https:\/\/risk.lexisnexis.com\/about-us\/press-room\/press-release\/20250402-tcof-ecommerce-and-retail<br \/>\n&#8211; FTC \u2014 <em>Negative Option Rule.<\/em> https:\/\/www.ftc.gov\/system\/files\/ftc_gov\/pdf\/p064202_negative_option_rule.pdf<\/p>\n<p><em>Reporting note: per-transaction VAMP fine amounts, VIRP acquirer registration fees, and the illegal-transaction assessment figures are reported by acquirers and compliance vendors rather than published in Visa&#8217;s public fact sheet; they are labeled accordingly in the text. Statistics attributed to &#8220;Datos Insights&#8221; underlie most of the chargeback-volume and first-party-fraud figures published by both networks.<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u041f\u0440\u043e\u0433\u0440\u0430\u043c\u0438 VAMP \u0442\u0430 VIRP \u0432\u0456\u0434 Visa \u0437 2025 \u0440\u043e\u043a\u0443 \u043f\u0440\u0438\u0437\u0432\u0435\u043b\u0438 \u0434\u043e \u0441\u0442\u0438\u0441\u043d\u0435\u043d\u043d\u044f \u0435\u043a\u0432\u0430\u0439\u0440\u0456\u0432 \u0442\u0430 \u043d\u0435\u043f\u043e\u043c\u0456\u0442\u043d\u043e\u0433\u043e \u0437\u0430\u043a\u0440\u0438\u0442\u0442\u044f \u043e\u043d\u043b\u0430\u0439\u043d-\u043c\u0435\u0440\u0447\u0430\u043d\u0442-\u0440\u0430\u0445\u0443\u043d\u043a\u0456\u0432. \u0420\u043e\u0437\u0441\u043b\u0456\u0434\u0443\u0432\u0430\u043d\u043d\u044f \u0442\u043e\u0433\u043e, \u0449\u043e \u0437\u043c\u0456\u043d\u0438\u043b\u043e\u0441\u044f \u2014 \u0440\u0435\u0430\u043b\u044c\u043d\u0456 \u043f\u043e\u0440\u043e\u0433\u0438, \u0448\u0442\u0440\u0430\u0444\u0438 \u0442\u0430 \u0440\u0438\u0437\u0438\u043a MATCH-\u0441\u043f\u0438\u0441\u043a\u0443 \u2014 \u0430 \u0442\u0430\u043a\u043e\u0436 \u043f\u0440\u0430\u043a\u0442\u0438\u0447\u043d\u0438\u0439 \u043f\u043e\u0441\u0456\u0431\u043d\u0438\u043a \u0437\u0456 \u0437\u0431\u0435\u0440\u0435\u0436\u0435\u043d\u043d\u044f \u0432\u0430\u0448\u043e\u0433\u043e MID.<\/p>","protected":false},"author":4,"featured_media":382,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"rank_math_title":"How Visa's VAMP & VIRP Rules Are Closing Merchant Accounts","rank_math_description":"Visa's VAMP and VIRP rules squeezed acquirers and closed merchant accounts since 2025. The real thresholds, fines, MATCH risk, and a survival playbook.","footnotes":""},"categories":[8,3],"tags":[],"class_list":["post-383","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-banking-payments","category-blog"],"_links":{"self":[{"href":"https:\/\/unitycorporate.com\/ua\/wp-json\/wp\/v2\/posts\/383","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/unitycorporate.com\/ua\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/unitycorporate.com\/ua\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/unitycorporate.com\/ua\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/unitycorporate.com\/ua\/wp-json\/wp\/v2\/comments?post=383"}],"version-history":[{"count":3,"href":"https:\/\/unitycorporate.com\/ua\/wp-json\/wp\/v2\/posts\/383\/revisions"}],"predecessor-version":[{"id":386,"href":"https:\/\/unitycorporate.com\/ua\/wp-json\/wp\/v2\/posts\/383\/revisions\/386"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/unitycorporate.com\/ua\/wp-json\/wp\/v2\/media\/382"}],"wp:attachment":[{"href":"https:\/\/unitycorporate.com\/ua\/wp-json\/wp\/v2\/media?parent=383"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/unitycorporate.com\/ua\/wp-json\/wp\/v2\/categories?post=383"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/unitycorporate.com\/ua\/wp-json\/wp\/v2\/tags?post=383"}],"curies":[{"name":"\u0412\u041f","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}