Card Scheme Compliance 2026: How to Stay Under Visa and Mastercard's Radar
Visa's VAMP dropped to 0.5% in 2026. Learn how payment processors stay compliant, avoid $100K+ fines, and maintain processing privileges with daily monitoring.
What Is Card Scheme Compliance and Why 2026 Changed Everything
In April 2025, Visa consolidated its Fraud Monitoring Program (VFMP) and Dispute Monitoring Program (VDMP) into a single Visa Acquirer Monitoring Program (VAMP). This fundamentally changed how acquirers, ISOs, and payment service providers get measured and penalized.
I've spent the past 18 months working with mid-market payment processors, navigating this transition. The stakes have never been higher.
Card scheme compliance refers to your adherence to the rules, standards, and monitoring programs established by card networks. In the US market, this primarily means Visa and Mastercard compliance rules. These aren't suggestions—they're enforceable requirements governing everything from transaction authentication to fraud reporting and dispute handling.
Here's what changed in 2026:
As of January 1, 2026, acquirers must keep their VAMP ratio (fraudulent transactions plus disputes divided by total card-not-present transactions) below 0.5%. That's half the previous threshold. Merchants face an "Excessive" threshold of 1.5% starting April 1, 2026, down from 2.2%.
I watched a processor burn through $200,000 in penalties and emergency compliance hires in six months because they ignored chargeback creep. Their VAMP ratio hit 0.7% before they knew they had a problem.
Mastercard operates differently but with equal rigor. Their Brand Risk Assurance Program (BRAM) targets high-risk merchant categories, while QMAP scrutinizes fraud and chargeback patterns. In 2026, Mastercard raised excessive authorization attempt fees from $0.10 to $0.50 per retry—a fivefold increase designed to curb card-testing fraud.
According to Visa's official VAMP documentation, entities identified as exceeding program thresholds are required to implement risk mitigation control measures.
Card Scheme Compliance vs. PCI Compliance: What's the Difference?
Card scheme compliance refers to network-specific rules set by Visa and Mastercard, while PCI DSS compliance is a data security standard managed by the PCI Security Standards Council and enforced by all card brands.

| Aspect | Card Scheme Compliance | PCI DSS Compliance |
|---|---|---|
| Who sets it | Visa, Mastercard (individual networks) | PCI Security Standards Council |
| Focus | Fraud prevention, chargeback management, operational mandates | Data security, cardholder protection |
| Penalties | Fines, remediation programs, license termination | $5,000-$100,000/month, breach liability |
| Enforcement | Continuous monthly monitoring | Annual audits with quarterly scans |
You need both. PCI DSS protects cardholder data. Network compliance management goes further, requiring you to meet payment scheme-specific mandates around fraud thresholds, dispute handling, and technical standards like ISO 20022 formatting.
How Visa and Mastercard Enforce Compliance in 2026
Visa and Mastercard enforce compliance through formal monitoring programs that track fraud rates, chargeback ratios, and data integrity, imposing escalating fines when thresholds are breached and terminating licenses for repeat violators.
Visa's VAMP Enforcement
Visa's Acquirer Monitoring Program (VAMP) measures two primary ratios:
- VAMP Ratio: (Fraud transactions + disputes) ÷ total CNP transactions
- Enumeration Ratio: Card-testing fraud ÷ total CNP transactions
If you're processing 100,000 CNP transactions monthly and 600 are fraud or disputes, you're at 0.6%. You've breached the 0.5% threshold and are accruing $2,400-$4,800 in monthly penalties.
The enforcement progression:
Month 1: Breach detected (0.6% VAMP ratio)
Month 2: Warning issued, 30-day plan required
Month 3: Fees start ($4-$8 per incident)
Month 4-5: Fees escalate to $8-$16 per incident
Month 6+: Fines reach $50,000-$100,000 monthly
Visa also monitors data integrity through its Integrity Risk Program. Authorization reversals, mismatched data, or formatting errors trigger separate penalties.
Mastercard's Enforcement Programs
Excessive Chargeback Program (ECP): If you exceed 1% chargebacks over two consecutive months with 100+ chargebacks, you're flagged.
QMAP: Targets merchants with suspicious fraud patterns beyond just ratios—behavioral monitoring for money laundering or fraud rings.
BRAM: Monitors prohibited or high-risk categories (gambling, adult content, unregulated financial services).
Excessive Authorization Attempts: $0.50 per retry after 20 attempts on the same card within 24 hours. During credential-stuffing attacks, this adds up fast.
Financial crime compliance costs increased for 98% of financial institutions in 2023, totaling $85 billion in EMEA, according to a Forrester Consulting study for LexisNexis Risk Solutions.
The Exact Compliance Thresholds You Must Track
You must track fraud rates, chargeback ratios, authorization patterns, and data integrity metrics in real time to stay below Visa's 0.5% VAMP threshold and Mastercard's 1% chargeback limit.
| Network | Program | Threshold | Effective Date | Your Target |
|---|---|---|---|---|
| Visa | VAMP (Acquirer) | 0.5% fraud+dispute | January 1, 2026 | 0.3-0.4% |
| Visa | VAMP (Merchant) | 1.5% fraud+dispute | April 1, 2026 | 1.2% |
| Visa | Enumeration | 20% card-testing | January 1, 2026 | <15% |
| Mastercard | Excessive Chargeback | 1% + 100 disputes | Ongoing | 0.7% |
| Mastercard | Authorization Retries | 20+ declines/24hrs | January 1, 2026 | <15 retries |
Networks review data in arrears. By the time you're flagged for February breaches, you've already accumulated January penalties. Operate 20-30% below published thresholds as a buffer against reporting lag. Discover how to optimize payment routing to maintain healthy approval rates.
The Three Essential Compliance Actions
When resources are constrained, these three actions deliver the highest risk reduction:

1. Monitor Your VAMP Ratio Daily
Set up dashboards calculating your VAMP ratio in real time. Most processors provide this data, buried in settlement reports calculated weekly or monthly. You need daily visibility.
If managing multiple merchant portfolios, segment your data. One high-risk merchant can drag your entire portfolio above 0.5%. Understanding your Visa Acquirer Monitoring Program metrics is critical for early intervention.
2. Implement Rapid Dispute Resolution
Chargebacks resolved through Rapid Dispute Resolution (RDR) or issuer cooperation don't count toward your VAMP ratio. If you respond within 24-48 hours and resolve before formal filing, it disappears from compliance metrics.
I've seen processors reduce countable chargeback volume by 40% implementing RDR with aggressive 24-hour response protocols.
3. Appoint a Dedicated Compliance Owner
This cannot be your fraud manager's side project. Visa and Mastercard issue rule bulletins weekly. Someone needs to:
- Monitor Visa Business News and Mastercard bulletins daily
- Translate network changes into internal action items
- Track compliance deadlines centrally
- Run quarterly reviews with your acquirer
- Maintain audit documentation
For mid-market processors, this is a Manager-level role. For smaller ISOs, consider fractional compliance resources.
Tools and Resources: What Actually Works
For chargeback management:
- Verifi (CDRN): Best for high-volume merchants, integrates with most processors, approximately $0.20 per alert
- Ethoca: Mastercard-owned, better for MC-heavy portfolios, strong issuer network
- Beast Insights Compliance Dashboard: Purpose-built for VAMP ratio monitoring with real-time alerts, remediation tracking, and multi-merchant portfolio segmentation
For fraud prevention:
- Stripe Radar: Good for SMBs, starts at 0.05% per transaction with machine learning scoring
- Signifyd: Enterprise-grade with a full chargeback guarantee model, best for high-risk categories
- Kount: Mid-market sweet spot with strong ML models and customizable rule engines
For tokenization:
- Visa Token Service (VTS) and Mastercard Digital Enablement Service (MDES) are network-native options that integrate with most payment gateways
For official guidance:
- Visa Core Rules and Visa Product & Service Rules
- Mastercard Rules Documentation
- PCI Security Standards Council - PCI DSS 4.0
How Do You Monitor Card Scheme Compliance Across Gateways and MIDs?
Split monitoring by dimension. One portfolio number hides the drift. Beast Insights breaks recovery, declines and disputes down by decline code, issuer, BIN, gateway/MID, acquirer, card brand and billing cycle. BIN is the bank identification number, the first digits of a card. MID is the merchant ID your acquirer assigns you. Our gateway compliance monitoring shows which MID is drifting. Our VAMP ratio guide explains the math behind it. VAMP is Visa's Acquirer Monitoring Program.
- Watch approval rate and chargeback rate per MID together: a MID that looks fine on volume can still drift on ratio.
- Segment disputes by issuer, BIN and card brand so remediation targets the segment actually causing the pressure.
- Route resolvable disputes early through RDR, CDRN and Ethoca (Beast Insights is a Visa Verifi reseller), and keep representment for the rest.
- Review by billing cycle so renewal spikes stay separate from first-payment fraud.
The Four Technical Mandates You Can't Ignore
Beyond fraud and chargeback compliance, card networks enforce technical requirements:

ISO 20022 Data Formatting
Both networks expect enhanced transaction fields: merchant category codes, geolocation, device fingerprints, and extended descriptors. Misformatted data triggers Visa's Integrity Risk Program fees.
3-D Secure 2.x Implementation
Strong Customer Authentication reduces fraud liability by 30-50%. EMV 3-D Secure authentication shifts fraud liability to issuers and reduces your VAMP contribution significantly.
Network Tokenization
Visa Token Service and Mastercard Digital Enablement Service replace stored PANs with dynamic tokens. Benefits:
- Reduced fraud exposure
- Better approval rates (2-5% improvement)
- Lower PCI scope
Subscription Billing Transparency
Visa requires:
- Clear term disclosure before sign-up
- Easy online cancellation
- Electronic reminders before renewals
Non-compliance triggers disputes, hurting your VAMP ratio. Subscription merchants reduce chargebacks 60% by adding one-click cancel and 7-day pre-billing reminders.
What Non-Compliance Actually Costs
Direct costs: $4-$8 per incident, scaling to $50,000-$100,000+ monthly. Indirect costs destroy margins:
Emergency compliance hires: $120,000-$180,000 annually
Third-party audits: $25,000-$75,000 for QMAP/BRAM audits
Opportunity cost: Can't onboard merchants during remediation
Reputational damage: Higher reserve requirements, deteriorating banking relationships
A processor trending toward 0.6% VAMP implemented real-time fraud scoring, proactive RDR protocols, and daily dashboards. Within 60 days: 0.34% ratio, $65,000 in avoided penalties.
The April 1 Deadline: What You Need to Do in the Next 6 Weeks
Visa's 1.5% merchant threshold takes effect April 1. Here's your 6-week plan:
Week 1: Calculate the current VAMP ratio from last month's settlement data. Above 1.2%? You're in danger.
Week 2: Identify your biggest gap in fraud prevention, chargeback response, or data formatting. For strategies on reducing failed transactions, review our payment retry strategies.
Week 3: Implement monitoring infrastructure with daily dashboards. Configure alerts at 1.2%, 1.3%, 1.4%.
Week 4-6: Execute highest-priority fix. Deploy 3DS 2.x for fraud, implement RDR for chargebacks, and audit ISO 20022 formatting for data integrity.

The processors that treat compliance as a cost center pay fines. The ones that treat it as a competitive advantage win market share, maintain clean banking relationships, and scale without network interference.
Conclusion: Compliance Is Your Competitive Advantage
Staying under Visa and Mastercard's radar requires three fundamentals: daily metric monitoring, proactive dispute resolution, and dedicated compliance ownership. The margin for error disappeared with VAMP's 0.5% threshold.
Networks tightened requirements because fraud is rising and consumer protection expectations are higher. Companies viewing payments compliance as a burden struggle. Those building it into operations outperform competitors, avoid fines, and earn customer trust.
Your immediate next steps:
- Calculate your current VAMP ratio using last month's data
- Identify your biggest vulnerability—fraud, chargebacks, or data integrity
- Implement daily monitoring with automated alerts
Processors treating compliance as cost centers pay fines. Those treating it as a competitive advantage win market share, maintain clean banking relationships, and scale without network interference.
The April 1 deadline is weeks away. If you're not tracking your network compliance management metrics now, you're already behind.
FAQ
What is card scheme compliance?
Card scheme compliance means adhering to all rules, technical mandates, and monitoring programs set by payment networks like Visa and Mastercard to maintain processing privileges without penalties or license termination.
How is card scheme compliance different from PCI compliance?
PCI compliance focuses on data security standards enforced by all card brands, while card scheme compliance refers to network-specific operational rules like fraud thresholds, chargeback limits, and technical mandates set by individual networks.
What is Visa's VAMP program?
VAMP (Visa Acquirer Monitoring Program) consolidates fraud and dispute monitoring, requiring acquirers to keep ratios below 0.5% and merchants below 1.5%, with escalating penalties starting at $4-$8 per incident for violations.
What happens if I exceed compliance thresholds?
Exceeding thresholds triggers mandatory remediation requiring corrective action plans within 30 days, per-incident fees starting at $4-$8 and escalating to $50,000-$100,000 monthly, and potential license termination.
Can chargebacks be removed from my VAMP ratio?
Yes, chargebacks resolved through Visa's Rapid Dispute Resolution or issuer collaboration before formal filing do not count toward your VAMP ratio, making proactive 24-48 hour dispute response critical.
How much does card scheme non-compliance cost?
Direct costs start at $4-$8 per incident and scale to $50,000-$100,000+ monthly, with indirect costs including emergency hires ($120K-$180K annually), audit fees ($25K-$75K), and restricted growth opportunities.
How do you monitor card scheme compliance across multiple MIDs?
Track each MID separately. MID means the merchant ID your acquirer assigns you. Portfolio averages hide the one gateway or MID drifting toward a threshold. Beast Insights breaks recovery, declines and disputes down by decline code, issuer, BIN, gateway/MID, acquirer, card brand and billing cycle. BIN is the bank identification number, the first digits of a card. Teams fix the actual leak instead of guessing.
Does card scheme compliance work differently for subscription billing?
Yes. Recurring billing concentrates disputes in specific billing cycles and issuer segments. Review disputes by billing cycle, issuer and BIN. BIN is the bank identification number, the first digits of a card. That review shows whether the pressure comes from renewals, failed retries or a single acquirer. It points to a narrower fix than blanket rule changes.