Mastercard Scam Merchant Monitoring ProgramWhat the New Rules Actually Mean & Why the “5% Rule” Panic is Mostly Misplaced
In a Nutshell
Mastercard’s Scam Merchant Monitoring Program (SMMP) takes effect July 24, 2026, giving acquirers 72 hours to investigate flagged merchants, with immediate termination for confirmed scam activity. Concerns about the program impact are likely overblown, though; for established businesses, the real key isn’t buying more tools, but rather understanding the program, knowing your metrics, and communicating proactively with your acquirer.
Is the Market Reaction Mastercard’s Scam Merchant Monitoring Program (SMMP) Overblown?
Over the past week or two, I’ve seen a wave of content about the Mastercard Scam Merchant Monitoring Program (SMMP) sweep through the payments industry.
A lot of the discussion I’ve seen has framed the program as an existential threat to card-not-present merchants broadly, with the "5% rule" for combined refunds and chargebacks being particularly alarming. Sellers are understandably concerned. Some are panicking; I’ve had multiple merchants reach out to me directly, desperate for information about these new rules and whether they’re going to end up getting shut down as a result.
There’s a problem here, though. Most of what is currently online about SMMP either buries or misunderstands a critical detail: the 5% combined threshold does not apply to all merchants.
99% of the alarmist language about SMMP online are just scare tactics. So, before the panic spreads any further, I wanted to take this opportunity to provide a rundown on the new program rules, who is subject to the SMMP, and what the rules are meant to accomplish.
What Is the Mastercard Scam Merchant Monitoring Program?
- Scam Merchant Monitoring Program
The Scam Merchant Monitoring Program (SMMP) is Mastercard’s enforcement framework for identifying and terminating merchants engaged in scam activity. When a merchant is flagged under SMMP, their acquirer has 72 hours to investigate. If scam activity is confirmed, then the seller’s processing agreement is terminated immediately with no warnings or remediation period.
[noun]/skam • mər • CHənt • män • ə • dər • iNG • prō • ɡram/
The Mastercard SMMP represents a significant shift in how the network identifies and handles suspected scam merchants. Unlike existing monitoring programs, SMMP is designed for speed; the aim is to catch bad actors before they can disappear.
The program takes full effect on July 24, 2026, though the onboarding screening requirements for new merchants have been active since January 2026. When a merchant is flagged under SMMP, the acquirer has exactly 72 hours to conduct an investigation and report findings to Mastercard. If that investigation confirms scam activity, then the rules call for immediate MID termination and placement on the MATCH list. No fines, no warnings, and no remediation window.
This is fundamentally different from Mastercard’s Excessive Chargeback Merchant and Excessive Fraud Merchant programs. These programs mandate fines when you exceed predetermined thresholds, and give you time to bring your numbers back into compliance. You might not enjoy the process, but you can survive it. SMMP operates on different logic entirely.
Understanding this distinction is essential, because a lot of the anxiety circulating in the market conflates SMMP with the monitoring programs that merchants already know. They’re not the same thing, and preparing for them requires a different way of thinking.
Who is Subject to “The 5% Rule”?
Only MIDs that have less than six months of Mastercard processing history are subject to Mastercard SMMP rules.
Mastercard SMMP rules apply to new merchants; specifically, those with MIDs that have less than six months of Mastercard processing history.
Let’s be precise about what “the 5% rule” actually says. For merchants with less than six months of processing history and at least 500 transactions in a rolling 30-day period, a combined refund and chargeback rate exceeding 5% can trigger an SMMP investigation. That’s chargebacks plus refunds, measured as a percentage of total transactions, evaluated on a rolling monthly basis.
Mastercard SMMP will only flag merchants with:
If your MID has been processing transactions for more than six months, then this specific threshold does not apply. You’re still subject to other SMMP triggers, which I’ll explain below. But, the 5% rule that’s generating the most fear simply isn’t relevant to your situation.
This matters enormously for how merchants should interpret the program. A seasonal business with predictable Q1 return volume is not necessarily at risk of termination because post-holiday returns spiked. A subscription business with normal churn patterns is not facing an existential threat.
Why Did Mastercard Implement SMMP Rules?
Want to understand why Mastercard designed the Scam Merchant Monitoring Program this way? Then you have to understand the problem they’re trying to solve.
Scam merchants don’t behave like legitimate businesses. They spin up a MID, process as much volume as they can, accumulate disputes, and disappear as quickly as possible. By the time chargeback ratios spike high enough to raise traditional alarms, the scammer is already gone. And, the money is gone, too.
SMMP addresses this by looking at earlier signals. The six-month window exists because scam operations rarely stick around that long. A merchant who has been processing legitimately for six months is statistically much less likely to be running a scam.
This is also why the threshold is set at 5%, which sounds alarmingly low until you understand the context. For a brand-new MID with no processing history, a 5% combined rate is a meaningful signal. For an established business with years of history, seasonal patterns, and documented customer relationships, the same rate would be interpreted completely differently—which is why the threshold doesn’t apply to them.
Worried About How New Rules Will Impact Your Business?
When it comes to chargeback management, it’s better to be safe than sorry.
Request a Demo
SMMP Trigger Events Explained
Beyond the 5% rule, other events can trigger an SMMP investigation including authorization rate collapse, a GRIP letter issuance, scam signals, or a merchant monitoring notification.
This is probably all still a bit abstract. So next, I want to outline a few key scenarios in which SMMP can be triggered.
Scenario #1 | Authorization Rate Collapse
If your approval rate drops by 50 or more percentage points within a 72-hour window, or falls below 30% while you’re processing at least 25 transactions, that’s a red flag. This pattern can indicate a compromised account, a processing problem, or fraudulent activity. It doesn’t have to mean fraud; a bad campaign, a routing issue, or an aggressive retry strategy can all produce this pattern. But, it looks like fraud from Mastercard’s perspective, and so ill will trigger an investigation.
Scenario #2 | GRIP Letter
“GRIP” stands for “Global Rules Investigation Program.” Getting one of these notifications means Mastercard has already flagged your account for suspected fraudulent activity at the network level. By the time your acquirer receives a GRIP letter, the investigation clock is already running. These are serious, and they don’t appear without reason.
Scenario #3 | New Merchant Scam Signals
This is where the 5% threshold lives. For MIDs with less than six months of processing history, several signals can trigger investigation, like two or more issuers filing fraud type 56 reports against you, chargebacks with documentation that mentions “scam” or “manipulation.” Fraud type 56 is Mastercard’s classification for first-party misuse—what the industry calls friendly fraud. When two different issuers file this type of report against the same new merchant, it suggests a pattern rather than isolated incidents.
Scenario #4 | Merchant Monitoring Alert
The fourth trigger is an alert from a Merchant Monitoring Service Provider. Mastercard works with a list of approved, third-party providers that scan merchant behavior patterns. Getting an alert from one of these providers can initiate the investigation process.
Now this is crucial: triggering an investigation is not the same as being terminated. What happens during that investigation is what actually matters, which I’ll elaborate on below.
What Happens During the 72-Hour Window
The acquirer will take up to 72 hours to investigate merchants flagged under SMMP. Detailed documentation is critical to show that your business is legitimate.
When an SMMP trigger fires, your acquirer receives notification and has 72 hours to investigate and report findings to Mastercard. The outcome of that investigation determines what happens next. If the acquirer confirms scam activity, then termination is immediate. If the acquirer clears the merchant, no action is taken.
Prepping for one of these investigations is not about tools or products. It’s about communication.
Your acquirer has to be able to explain why you exceeded a threshold or triggered a flag. If they can’t reach you, they can’t defend you. If they don’t understand your business model, they can’t contextualize your metrics. A seasonal merchant with predictable post-holiday returns looks very different from a scam operation… but only if your acquirer has the context that you’re a seasonal merchant before the investigation begins.
Understand that a flag is not a termination. The investigation determines the outcome, and the investigation’s outcome depends heavily on whether your acquirer can explain your metrics.
Documentation matters; I’m talking about transaction records, refund policies, customer communication logs, evidence of legitimate business operations, etc. That way, if a flag gets raised, the acquirer can immediately explain the context to Mastercard. The investigation becomes a conversation grounded in documentation and mutual understanding. Contrast that with an investigation that has no input from you. Here, the acquirer has nothing to offer Mastercard except the raw numbers which, without context, look suspicious.
Preparing for SMMP: What Merchants Should Do
Here’s something the market isn’t saying loudly enough: this is not a problem you solve by buying more tools. I know — counterintuitive for me to say, as a guy that sells chargeback management solutions, right? But it’s true; SMMP preparation is about understanding, measurement, and communication. Those three things will serve you far better than any product purchase.
If there’s a single, key takeaway here, it’s that you need to shift your mindset. SMMP treats refunds and chargebacks as a combined metric. Most merchants track these separately, and most chargeback monitoring focuses on disputes alone. Start looking at the combined picture now, even if the 5% threshold doesn’t technically apply to you. It’s a better representation of how card networks are thinking about merchant risk.
The role of a chargeback management partner in all of this should be to help you understand and prepare. A reliable partner explains regulatory changes, helps you interpret how they apply to your specific situation, and guides you through the communication strategy with your acquirer. If your current provider isn’t doing this, then they’re functioning as a vendor, not a partner.
The distinction matters more than ever with programs like SMMP, where the solution isn’t spending money. It’s understanding, measurement, and communication.
FAQs
Does the 5% rule apply to all merchants?
No. The 5% combined refund and chargeback threshold only applies to new merchants with less than six months of Mastercard processing history and at least 500 transactions in a rolling 30-day period. Established merchants are not subject to this specific threshold, though they remain subject to other SMMP triggers.
What happens if I’m flagged under SMMP?
Your acquirer has 72 hours to investigate. If they confirm scam activity, your MID is terminated immediately and you’re added to the MATCH list. If they clear you, no action is taken. The outcome depends significantly on whether your acquirer can explain your metrics and understands your business model.
Is SMMP the same as ECM or EFM?
No. ECM and EFM are ratio-based programs that assess fines and allow time to remediate. SMMP is investigation-based with immediate termination for confirmed scam activity. There are no fines, no warnings, and no grace period under SMMP.
How is SMMP different from Visa’s VAMP?
VAMP shifted accountability to acquirers for fraud and dispute performance across their merchant portfolios. SMMP does something similar for Mastercard, with a specific focus on identifying and terminating scam merchants quickly. Together, the programs represent a coordinated shift across both major card networks toward faster enforcement and greater acquirer responsibility.
When does SMMP take effect?
Full enforcement begins July 24, 2026. New merchant onboarding screening requirements have been active since January 2026, meaning acquirers are already required to scan new merchant websites before processing their first transaction.
What should I do to prepare?
For established merchants, focus on maintaining clean authorization patterns and keeping your acquirer informed about your business model. For new merchants, track your combined refund and chargeback rate carefully and brief your acquirer proactively. For all merchants, understand that preparation means communication and documentation — not purchasing additional tools or services.