Quick answer
Starting July 24, 2026, Mastercard requires acquirers to investigate any merchant showing scam signals within 72 hours. Confirmed scam merchants lose Mastercard processing immediately — no fines, no grace period. The 5% combined refund + chargeback threshold is the most commonly triggered signal for legitimate subscription businesses.
SMMP is not ECM. The consequences are different
Most merchants running subscription or eCommerce businesses know Mastercard's existing monitoring programs: ECM (Excessive Chargeback Merchant) and EFM (Excessive Fraud Merchant). These programs are uncomfortable — monthly fines, acquirer pressure, escalating categories — but they're survivable. You get flagged, you get time to fix things, you pay fines while you improve.
SMMP operates on completely different logic. There are no fines. There is no remediation window. When an acquirer confirms scam activity under SMMP, Mastercard and Maestro processing stops immediately. For a subscription business, that means no new signups, no renewals, no payment recovery — until the situation is resolved, which can take weeks or months.
| Program | What triggers it | Consequence |
|---|---|---|
| ECM / HECM | Excessive chargeback ratio | Fines + time to remediate |
| EFM | Excessive fraud volume | Fines + fraud controls required |
| SMMP (July 2026) | Suspected scam activity signals | Immediate processing termination |
The key distinction: ECM and EFM measure outcomes (ratios). SMMP detects signals that pattern-match to scam behavior. A merchant can be fully compliant under ECM and EFM while still triggering SMMP — because your legitimate subscription business might look like a scam operation from the outside.
This isn't happening in isolation. Visa launched VAMP in June 2025 with a similar accountability shift. Together, SMMP and VAMP represent a coordinated change across both card networks: acquirers are now responsible for their merchants' fraud and dispute behavior, and the enforcement timelines are compressed to days, not months.
Who is most at risk
SMMP is designed to catch actual scammers — fake digital subscriptions that bill cardholders and deliver nothing, trial-to-paid traps, and organized fraud operations. But the triggers are broad enough to catch legitimate merchants who produce similar signals.
Highest-risk merchant profiles:
- ⚠ New merchants with less than 6 months of Mastercard processing history — subject to heightened monitoring from January 2026
- ⚠ Subscription and SaaS businesses with recurring billing confusion, free trial conversions, and high refund rates
- ⚠ Businesses running aggressive acquisition campaigns or using performance affiliates
- ⚠ CNP-only merchants in digital goods, streaming, or software categories
What the 5% combined threshold means in practice: If more than 5% of your purchase transactions result in refunds or chargebacks combined in any rolling 30-day window (minimum 500 transactions), your acquirer must investigate you as a potential scam merchant. For a business processing 2,000 transactions per month, that's 100 combined refunds and chargebacks before the clock starts.
A surprise billing situation — a poorly communicated campaign, a failed cancellation flow, one bad affiliate — can cross this in a single month.
ChargeMate
Generate your response in minutes
Upload your evidence — AI writes a network-compliant rebuttal letter for you.
Try free → 3 responses includedThe 4 triggers that start the 72-hour clock
Acquirers are legally required to begin investigating within 72 hours when any of these conditions occur.
Authorization approval rate drop
Your authorization rate falls by 50 or more percentage points in 72 hours, or drops below 30% — while processing at least 25 transactions.
Why legitimate merchants get caught: Issuers block transactions when they suspect fraud. If your authorization rate suddenly collapses — from a technical issue, aggressive retry strategy, or routing misconfiguration — that pattern itself is a SMMP signal. Misconfigured payment retry logic that hammers declined cards, or a surge of low-quality traffic from a new affiliate, can produce exactly this.
GRIP letter from Mastercard
Your acquirer receives a Global Rules Investigation Program letter linking your merchant account to suspected scam activity. By the time this arrives, Mastercard has already identified concerns at the network level. The 72-hour clock starts immediately upon receipt.
New merchant scam signals
Applies to merchants with less than 6 months of Mastercard acceptance history. Any one of the following triggers investigation:
- →Multiple issuer fraud reports: Two or more different issuers each report at least one transaction as fraud type 56 (Manipulation of Cardholder — friendly fraud).
- →Documented chargeback pattern: Chargebacks from two or more issuers where documentation references scam activity, manipulation, or cardholder deception.
- →5% combined refund/chargeback rate: Over a rolling 30-day window with minimum 500 transactions.
Monitoring provider alert
Your acquirer uses a third-party monitoring service that flags your account for scam-related activity patterns. This catch-all allows network intelligence — patterns observed across many merchants and issuers — to trigger an investigation even when the specific criteria above aren't individually met.
What happens during a 72-hour investigation
When a trigger fires, the acquirer has 72 hours to complete the investigation.
Acquirer reviews transaction data, refund rates, chargeback reason codes, and dispute documentation
Acquirer contacts the merchant for explanation and evidence
Acquirer determines: scam activity confirmed, or legitimate merchant with explainable signals
If scam confirmed
Mastercard and Maestro processing blocked immediately. Merchant reported to Mastercard. Acquirer faces compliance consequences.
If cleared
Investigation closes, processing continues. But being cleared doesn't end enhanced monitoring — repeated triggers will be investigated again.
72 hours is not enough time to build a response from scratch. Merchants who get through investigations successfully are the ones who already had documentation ready: consent records, cancellation confirmation logs, transaction histories, and a clear explanation of their business model.
Since January 2026: Website scanning for new merchants
A separate requirement has been in effect since January 2026: acquirers must scan every new merchant's website before approving them for processing. This scan is performed by a Mastercard-approved monitoring provider and looks for signals associated with scam operations — deceptive pricing, unclear cancellation terms, misleading free trial language.
If the scan flags something, the acquirer has 15 days to investigate and remediate before the merchant can begin processing.
Pages now treated as compliance documents:
- → Checkout page
- → Pricing page
- → Terms of service
- → Cancellation flow and self-service portal
What SMMP means alongside VAMP
Visa's VAMP program launched June 1, 2025, and tightened to a 1.5% threshold for EU and US merchants in April 2026. SMMP adds Mastercard coverage to the same compliance landscape.
The two programs differ in mechanism — VAMP calculates a ratio (TC40 + TC15 divided by total sales), SMMP looks for specific behavioral signals — but share the same underlying goal: make acquirers accountable for their merchants' fraud and dispute patterns.
For merchants, the practical effect is that both programs need to be managed simultaneously. Actions that reduce your VAMP ratio (fewer disputes reaching the chargeback stage, better fraud screening, pre-dispute resolution tools) also reduce your SMMP exposure. The overlap is substantial.
Don't want to handle this yourself?
We write and submit the response for you. $10 per case or 20% on wins. No monthly minimum.
How to reduce your SMMP exposure
Most SMMP triggers for legitimate merchants trace back to the same root causes that drive VAMP exposure: friendly fraud from billing confusion, poor cancellation UX, and insufficient fraud screening.
Keep your combined refund + chargeback rate below 5%
This is the most directly actionable threshold. The fastest ways to reduce it:
- ✓Proactive communication: Trial-end reminder emails 3–7 days before conversion. Immediate receipts for every charge. Renewal reminders for annual subscriptions. Customers who know what to expect cancel properly instead of disputing.
- ✓Frictionless cancellation: Self-service in 3 clicks or fewer. No support contact required. Immediate on-screen and email confirmation. A customer who can cancel easily doesn't dispute — they cancel.
- ✓Clear checkout disclosure: Exact trial duration, exact amount after trial, exact date of first full charge — visible before purchase, not in footer fine print. Active consent checkbox stored with timestamp and IP.
- ✓Rapid refund policy: If a customer contacts you within 48 hours of an unexpected charge, refund immediately. A $29 refund costs $29. A disputed charge costs $29 plus $15–$50 in chargeback fees, plus SMMP exposure.
Protect your authorization rate
A sudden authorization rate drop is a trigger regardless of your chargeback ratio.
- → Don't retry declined cards more than 2–3 times in a 24-hour window
- → Monitor decline rates by reason code — unusual patterns are early warning
- → When running a new campaign, watch authorization rates in real time for the first 48 hours
- → Use fraud screening that blocks bad transactions before authorization attempts, not after
Manage new merchant risk
If you're within your first 6 months of Mastercard processing:
- → Set conservative fraud rules — accept slightly more false positives to avoid true fraud accumulating
- → Require 3DS for international transactions and high-value orders
- → Monitor affiliate and traffic source chargeback rates weekly, not monthly
- → Ensure your website, pricing page, and cancellation flow are compliant before submitting for processing — the website scan happens before your first transaction
Document everything
When a 72-hour investigation starts, documentation is the difference between "cleared" and "terminated." These records also serve as raw material for Compelling Evidence 3.0 submissions under VAMP, creating dual-use compliance value.
Records to maintain at all times:
- → Signed consent to recurring billing terms (timestamp + IP address)
- → Cancellation confirmations sent to customers
- → Refund records showing rapid response to complaints
- → Fraud screening configuration and velocity rules
- → Customer communication logs for disputed transactions
How ChargeMate helps
ChargeMate is designed around the documentation and dispute response workflows that SMMP and VAMP compliance require.
- ✓Dispute response generation — AI-generated evidence packages that pull transaction history, device data, and cardholder behavior patterns — exactly the documentation format that clears investigations and wins representments.
- ✓Dispute analytics — Your combined refund and chargeback rate in real time, segmented by processor, reason code, and acquisition channel — so you see a 5% trend developing before it triggers a monitoring event.
- ✓Any processor — ChargeMate works with any payment processor, not just Stripe or Shopify Payments. Your SMMP and VAMP compliance does not depend on your payment stack.
- ✓$10 per case, no monthly fee — Dispute management at a predictable, per-case cost.
Reduce your SMMP and VAMP exposure
3 cases free. No contract, no setup. Works with any payment processor.
Try free →Frequently asked questions
When does SMMP take effect?▾
Does SMMP replace ECM and EFM?▾
What's fraud type 56?▾
If I get investigated and cleared, is it over?▾
Can I appeal a processing termination under SMMP?▾
What's the difference between SMMP and VAMP?▾
Does SMMP apply to PayPal, Apple Pay, or other wallets?▾
Last reviewed: June 2026. Mastercard program details subject to change — verify current requirements with your acquirer or Mastercard's official documentation.