ecryptpayments
Newbie
- Oct 16, 2025
- 1
- 4
First actual post – forgive me if this is the wrong place for it.
I haven’t seen a lot of information on this forum regarding the VAMP (VISA Acquirer Monitoring Program) rollout which was initially rolled out this past April. Enforcement & fines officially began this month, & I know several processors giving the axe to thousands of merchants within the past several months to become compliant with new dispute thresholds. Merchants operating in high-risk verticals will continue to be blindsided & need to know what to expect as VAMP will go into full effect (with the strictest thresholds) from January 1, 2026 onward. I figured I could give a high-level overview of the new program and what merchants can expect from their payment processors.
I’m sure many of you are familiar with the previous VISA monitoring programs (VDMP, VMFP) which were phased out this year in favor of VAMP. However, for those of you who haven’t heard of these programs, I’ll cover what those programs affected for high-risk merchants as well, and how it has changed with VAMP.
Being shut down by payment processors is a common occurrence in this space, so hopefully I can lend insight into what a payment processor’s risk department looks for before taking punitive action against a merchant flagged for elevated risk, and what to expect with VAMP going forward.
Before going on, it’s important to define a few items that will come up a lot:
VDMP (VISA Dispute Monitoring Program)
VDMP tracked overall chargeback (TC15) ratios. Thresholds were:
Fines commonly started at $50 per dispute at Standard and escalated at Excessive.
VFMP (VISA Fraud Monitoring Program)
VFMP tracked fraud rate with thresholds at:
Fines were not assessed at the early warning level, but after 4 months at the Standard level (or month one at Excessive) it was a $25,000 monthly fine that increased to $75,000/month at 10+ months.
As of April 1, 2025, VISA merged the old VDMP and VFMP into a single program. New performance thresholds began applying June 1, 2025, with an advisory period through September 30, 2025. Effective January 1, 2026, VISA will implement even stricter thresholds for acquirers & merchants moving forward.
VAMP uses one count-based ratio for CNP transactions:
Under VAMP, you can be flagged either at the portfolio level (VAMP ratio across your payment processor’s entire book of business) or as an individual merchant:
Acquirer-Level Portfolio Thresholds:
Merchant-Level Thresholds (CNP):
Issuers’ rapid-fire, low-value carding & bot disputes now count toward the ratio, so escalation can happen sooner, especially for high-velocity verticals.
Perhaps, even more importantly, if your payment processor’s portfolio is too heavily weighted in high-risk merchants, they will find themselves above the acquirer-level thresholds. This can mean scrutiny on your account even if your MID isn’t considered excessive risk at the merchant-level.
VAMP is an acquirer-level program: VISA monitors acquiring banks and their portfolios (who then monitors their payment processing ISO partners’), enforces corrective actions, and will levy fines when thresholds are breached. Payment processors then flow requirements and costs down to merchants driving the ratio (e.g., higher processing fees, monitoring fees, mandated third-party reviews, or even termination) because the acquirer is on the hook for VISA’s program compliance. This pass-through has become common industry practice and is widely expected under VAMP.
High-risk merchants can expect contractual surcharges or added “risk” fees if you’re contributing materially to your processor’s VAMP ratio, and tighter SLAs to reduce time-to-refund, reserves, and fraud controls.
All of this may seem like a doomsday scenario for businesses in these verticals (& for some it will be), but there are actionable steps high-risk merchants can take to proactively keep off VAMP.
1) Monitor your VAMP ratio weekly (not monthly)
Track TC40, TC15 counts in your online portals or risk tools. Ask your provider to expose these codes in dashboards or reports or to alert you when ratios approach internal guardrails (e.g., 100 bps, 150 bps).
2) Attack enumeration and bot traffic
VISA monitors enumeration rates too. Implement rate limiting, device/browser fingerprinting, velocity rules (per card/IP address/email), 3DS step-ups on risky attempts, and CAPTCHA on checkout. Consider allow/deny BIN lists for elevated-risk countries.
3) Use pre-dispute tools and fast refunds when appropriate
Resolve cardholder complaints through pre-dispute channels like RDR and refund when you clearly can’t fulfill. These resolved pre-disputes may be excluded from the VAMP ratio (timing dependent). Build an internal rule: refund fast if fulfillment fails; fight only when you have strong proof.
4) Tune 3DS and risk scoring intelligently
For elevated-risk items, step up with 3DS (VISA Secure). Balance approval rates against fraud pressure; don’t default to frictionless or high-risk profiles. Use targeted step-up (cart value, device mismatch, geolocation anomalies).
5) Fix billing clarity to prevent avoidable TC15s
Acquirers must produce remediation plans quickly under VAMP. Engaging early can avoid program placement and pass-through fees (and, in extreme cases - MID termination). Ask for their thresholds, timelines, and required controls so you can implement them proactively.
Bottom line is VAMP lowers the bar for escalation, and puts pressure on acquirers to act, so acquirer-level fines and controls will always cascade down to the merchant at the end of the day. Treat TC40/TC15 like vital shop-floor metrics, not back-office stats. If you systematically reduce both fraud inputs (TC40) and service-related disputes (TC15), you’ll protect your VAMP ratio, your processing costs, and, most importantly, your merchant account.
Hope this helps.
I haven’t seen a lot of information on this forum regarding the VAMP (VISA Acquirer Monitoring Program) rollout which was initially rolled out this past April. Enforcement & fines officially began this month, & I know several processors giving the axe to thousands of merchants within the past several months to become compliant with new dispute thresholds. Merchants operating in high-risk verticals will continue to be blindsided & need to know what to expect as VAMP will go into full effect (with the strictest thresholds) from January 1, 2026 onward. I figured I could give a high-level overview of the new program and what merchants can expect from their payment processors.
I’m sure many of you are familiar with the previous VISA monitoring programs (VDMP, VMFP) which were phased out this year in favor of VAMP. However, for those of you who haven’t heard of these programs, I’ll cover what those programs affected for high-risk merchants as well, and how it has changed with VAMP.
Being shut down by payment processors is a common occurrence in this space, so hopefully I can lend insight into what a payment processor’s risk department looks for before taking punitive action against a merchant flagged for elevated risk, and what to expect with VAMP going forward.
Before going on, it’s important to define a few items that will come up a lot:
- TC40 (Fraud reports): Generated by issuing banks when a cardholder claims a transaction was unauthorized. It’s a fraud signal, not a chargeback by itself, and it helps VISA track fraud trends and risk across merchants. In VAMP math, TC40 is the fraud component.
- TC15 (Disputes): VISA’s code for disputed transactions (all types, not just fraud). If a transaction becomes a chargeback (e.g., non-receipt, canceled services, processing error), it will appear as TC15 and counts fully in VAMP.
- TC05 (Settled transactions): The total number of settled CNP transactions in the month. It’s the denominator in VAMP (your overall CNP sales count for that month).
VDMP (VISA Dispute Monitoring Program)
VDMP tracked overall chargeback (TC15) ratios. Thresholds were:
- Early warning: dispute ratio of 0.65% and at least 75 total disputes
- Standard: dispute ratio of 0.9% and at least 100 total disputes
- Excessive: dispute ratio of 1.8% and at least 1,000 total disputes
Fines commonly started at $50 per dispute at Standard and escalated at Excessive.
VFMP (VISA Fraud Monitoring Program)
VFMP tracked fraud rate with thresholds at:
- Early warning: fraud rate of 0.65% or at least $50,000 in total fraud
- Standard: fraud rate of 0.9% or at least $75,000 in total fraud
- Excessive: fraud rate of 1.8% or at least $250,000 in total fraud
Fines were not assessed at the early warning level, but after 4 months at the Standard level (or month one at Excessive) it was a $25,000 monthly fine that increased to $75,000/month at 10+ months.
As of April 1, 2025, VISA merged the old VDMP and VFMP into a single program. New performance thresholds began applying June 1, 2025, with an advisory period through September 30, 2025. Effective January 1, 2026, VISA will implement even stricter thresholds for acquirers & merchants moving forward.
VAMP uses one count-based ratio for CNP transactions:
- VAMP Ratio = (Fraud reports TC40 + All disputes TC15) ÷ Settled transactions TC05
- VISA excludes disputes resolved via pre-dispute tools, such as RDR from the ratio
Under VAMP, you can be flagged either at the portfolio level (VAMP ratio across your payment processor’s entire book of business) or as an individual merchant:
Acquirer-Level Portfolio Thresholds:
- Above standard: ≥0.50% (≥0.30% after January 1, 2026)
- Excessive: ≥0.70% (≥0.50% after January 1, 2026)
Merchant-Level Thresholds (CNP):
- Early warning: ≥0.50%
- Above Standard: ≥0.70%
- Excessive: ≥1.50% (decreasing to ≥0.9% effective January 1, 2026)
Issuers’ rapid-fire, low-value carding & bot disputes now count toward the ratio, so escalation can happen sooner, especially for high-velocity verticals.
Perhaps, even more importantly, if your payment processor’s portfolio is too heavily weighted in high-risk merchants, they will find themselves above the acquirer-level thresholds. This can mean scrutiny on your account even if your MID isn’t considered excessive risk at the merchant-level.
VAMP is an acquirer-level program: VISA monitors acquiring banks and their portfolios (who then monitors their payment processing ISO partners’), enforces corrective actions, and will levy fines when thresholds are breached. Payment processors then flow requirements and costs down to merchants driving the ratio (e.g., higher processing fees, monitoring fees, mandated third-party reviews, or even termination) because the acquirer is on the hook for VISA’s program compliance. This pass-through has become common industry practice and is widely expected under VAMP.
High-risk merchants can expect contractual surcharges or added “risk” fees if you’re contributing materially to your processor’s VAMP ratio, and tighter SLAs to reduce time-to-refund, reserves, and fraud controls.
All of this may seem like a doomsday scenario for businesses in these verticals (& for some it will be), but there are actionable steps high-risk merchants can take to proactively keep off VAMP.
1) Monitor your VAMP ratio weekly (not monthly)
Track TC40, TC15 counts in your online portals or risk tools. Ask your provider to expose these codes in dashboards or reports or to alert you when ratios approach internal guardrails (e.g., 100 bps, 150 bps).
2) Attack enumeration and bot traffic
VISA monitors enumeration rates too. Implement rate limiting, device/browser fingerprinting, velocity rules (per card/IP address/email), 3DS step-ups on risky attempts, and CAPTCHA on checkout. Consider allow/deny BIN lists for elevated-risk countries.
3) Use pre-dispute tools and fast refunds when appropriate
Resolve cardholder complaints through pre-dispute channels like RDR and refund when you clearly can’t fulfill. These resolved pre-disputes may be excluded from the VAMP ratio (timing dependent). Build an internal rule: refund fast if fulfillment fails; fight only when you have strong proof.
4) Tune 3DS and risk scoring intelligently
For elevated-risk items, step up with 3DS (VISA Secure). Balance approval rates against fraud pressure; don’t default to frictionless or high-risk profiles. Use targeted step-up (cart value, device mismatch, geolocation anomalies).
5) Fix billing clarity to prevent avoidable TC15s
- Plain-language product descriptions and clear cancellation/return terms at checkout
- Realistic ETAs for delivery/activation
- Recognizable billing descriptors and easy-to-find customer service. These basics reduce “I don’t recognize this” disputes
- CBD/Nutra: subscription double-opt-in, plain “recurring” labels, reminder emails before rebills, generous first-order refund windows, and robust age/identity checks.
- iGaming/Sweeps: geofencing, device/account velocity, KYC/AML checks, deposit/bonus abuse controls, self-exclusion enforcement, and fast payout SLAs to reduce “service not provided” disputes. (All of these reduce TC15 and TC40 inputs)
Acquirers must produce remediation plans quickly under VAMP. Engaging early can avoid program placement and pass-through fees (and, in extreme cases - MID termination). Ask for their thresholds, timelines, and required controls so you can implement them proactively.
Bottom line is VAMP lowers the bar for escalation, and puts pressure on acquirers to act, so acquirer-level fines and controls will always cascade down to the merchant at the end of the day. Treat TC40/TC15 like vital shop-floor metrics, not back-office stats. If you systematically reduce both fraud inputs (TC40) and service-related disputes (TC15), you’ll protect your VAMP ratio, your processing costs, and, most importantly, your merchant account.
Hope this helps.