Mastercard SMMP Explained: What the Scam Merchant Monitoring Program Means for Merchants in 2026
by CatalystPay team
Mastercard's Scam Merchant Monitoring Program (SMMP) takes full effect on 24 July 2026, and it changes how online merchants are watched, judged and, in some cases, offboarded.
If you have already prepared for Visa's VAMP rules, some of this will feel familiar. But SMMP is not another ratio you slowly breach. It is an investigation triggered by scam signals, and if that investigation confirms scam activity, Mastercard and Maestro processing can be stopped immediately, with no fine and no remediation window.
At CatalystPay, we work with online merchants in exactly the verticals SMMP watches most closely, including iGaming, Forex, subscriptions, crypto and cross-border eCommerce. This guide explains what SMMP is, how it relates to VAMP and Mastercard's existing programmes, what triggers an investigation, and what to do before the deadline.
Quick Answer: What is Mastercard SMMP and who does it affect?
SMMP is a Mastercard enforcement track that requires acquirers to open an investigation within 72 hours when a merchant shows signs of scam activity, and to stop that merchant from accepting Mastercard transactions if the activity is confirmed. It takes full effect on 24 July 2026, though related onboarding checks for new merchants have applied since January 2026.
It matters most to card-not-present merchants, especially those with less than six months of Mastercard history and those in higher-refund verticals such as Forex, iGaming, subscriptions, SaaS, travel and crypto. Unlike the chargeback programmes merchants already know, the consequence is not a fine you can absorb. It can be the loss of card acceptance.
One detail catches many merchants out: for new merchants, SMMP counts refunds alongside chargebacks toward a 5% limit, so even the proactive refunds you issue to keep customers happy can raise your risk profile. More on that below.
Table of Contents
- What is Mastercard SMMP?
- SMMP vs ECM, HECM and EFM
- How SMMP relates to Visa VAMP
- The crucial difference: SMMP counts your refunds
- What triggers an SMMP investigation
- The 72-hour window and what termination means
- Merchant Trust Services and MSRI
- Which merchants face the highest risk
- How to prepare before 24 July 2026
- Why redundancy is your real defence
- How CatalystPay helps
What is Mastercard SMMP?
SMMP sits inside Mastercard's broader Merchant Monitoring Program (MMP). It requires acquirers and payment facilitators to actively monitor merchant behaviour and, when potential scam activity crosses a risk threshold, to investigate within 72 hours. If the activity is confirmed, the merchant must be stopped from processing.
The target is fake storefronts: businesses that advertise hard-to-find items or unrealistic prices, take payment, ship nothing or a counterfeit, and disappear, often harvesting card data on the way. As Mastercard explains in its Merchant Trust Services announcement, generative AI has made these operations faster and more convincing to build, so the network is compressing the window between a suspicious signal and enforcement. For context on the scale of the problem, the Global Anti-Scam Alliance reports that consumers lost roughly $442 billion to online scams in 2025 in its Global State of Scams 2025 report.
Two dates matter. The full programme is effective 24 July 2026, but onboarding requirements for new merchants, including a website scan before the first transaction, have applied since January 2026.
SMMP vs ECM, HECM and EFM
Mastercard already runs several monitoring programmes, and SMMP runs alongside them rather than replacing them.
|
Programme |
What triggers it |
Consequence |
|---|---|---|
|
ECM / HECM |
Excessive chargeback ratio |
Fines and time to remediate |
|
EFM |
Excessive fraud volume or ratio |
Fraud programme and fines |
|
SMMP |
Suspected or confirmed scam activity |
Immediate termination if confirmed |
The distinction is important. ECM and EFM are ratio programmes that give you time to correct course. A merchant can be completely within ECM limits and still be flagged under SMMP if the pattern of activity looks like a scam operation. SMMP gives acquirers a short decision window, and a confirmed case ends acceptance rather than adding a line to an assessment.
How SMMP relates to Visa VAMP
If SMMP feels like part of a wider shift, that is because it is. Visa moved first with VAMP, its Acquirer Monitoring Program, and from 1 April 2026 Visa lowered the "excessive" threshold to 1.5%, calculated by combining fraud reports and disputes into a single ratio. We covered what that means for merchants in our guide to how VAMP is reshaping merchant accounts.
The good news: VAMP has already trained merchants to think in one combined number rather than watching fraud and disputes separately. SMMP extends that mindset. The catch is in the detail.
|
Visa VAMP |
Mastercard SMMP |
|
|---|---|---|
|
Type |
Ratio programme |
Investigation programme |
|
Core metric |
Fraud reports + disputes as one ratio |
Scam signals, plus a combined refund + chargeback rate for new merchants |
|
Key number |
1.5% excessive threshold |
5% combined refund + chargeback rate (new merchants) |
|
Consequence |
Fees and enforcement |
Immediate termination if scam activity is confirmed |
There is one more difference, and it is big enough to deserve its own section: SMMP counts refunds, and VAMP does not.
The crucial difference: SMMP counts your refunds, not just chargebacks
Here is the part that catches the most merchants out, and the reason SMMP deserves attention even when your dispute numbers look healthy.
For merchants with under six months of Mastercard history, the 5% new-merchant threshold is a combined refund and chargeback rate. That means voluntary refunds, including the proactive ones you issue to keep a customer happy or to head off a dispute, count in the numerator alongside chargebacks. Refunds have always been the safe remedy, the tool merchants use to avoid chargebacks. Under SMMP, that same tool can push you toward an investigation.
This flips a habit many teams rely on. If your instinct when a customer complains is to refund quickly and move on, you have been lowering your chargeback rate while quietly raising your combined SMMP rate. At 500 or more transactions in a rolling 30-day window, it does not take many refunds to approach 5%, and subscription, SaaS, Forex and iGaming businesses tend to run higher refund rates by nature.
A few practical points:
- Proactive refunds still count. Issuing a refund before a dispute is filed does not keep it out of the SMMP calculation.
- Timing matters. A chargeback is counted when it is filed, not when it is resolved, so winning a representment removes it from the count only in a later month.
- Prevention beats refunding. Because you can no longer simply refund your way below a threshold, stopping disputes and complaints before they happen is now the stronger lever.
VAMP, by contrast, combines fraud reports and disputes; it does not count refunds. This is the one area where even a fully VAMP-ready merchant is starting from scratch. If you measure only one new number before July, make it your rolling 30-day combined refund and chargeback rate.
What triggers an SMMP investigation
Acquirers are required to act on four practical trigger groups. Mastercard's operating rules remain the source of truth, but it is worth watching all four.
- Authorization-rate collapse. A sudden fall in approvals can make a legitimate business look like a scam. The reported pattern is a drop of 50 or more percentage points within 72 hours, or an approval rate below 30% at a minimum transaction volume. A bad campaign, a routing issue or an aggressive retry strategy can all cause this. It does not have to be fraud, but it looks like fraud from the network's side.
- A GRIP notification. A Global Rules Investigation Program letter links a merchant to suspected fraudulent activity using Mastercard's own intelligence. By the time your acquirer receives one, the clock is already running.
- New-merchant scam signals. This is the category that affects legitimate high-growth businesses most. For merchants with under six months of Mastercard history, the reported triggers include Fraud Type 56 reports (first-party misuse, commonly called friendly fraud) from two different issuers, chargebacks from multiple issuers whose documentation references scams or manipulation, and a combined refund and chargeback rate above 5% in any rolling 30-day period at 500 or more transactions.
- An MMSP alert. Mastercard works with approved Merchant Monitoring Service Providers that scan merchant behaviour. An alert from one of these providers can put a merchant onto the investigation path.
The 72-hour window and what termination means
The 72 hours is an acquirer obligation, not a merchant grace period. Once a trigger fires, the acquirer has to decide quickly whether the activity is legitimate, suspicious but fixable, or confirmed scam.
That review can draw on onboarding files, transaction records, refund behaviour, chargeback documentation, issuer reports, website content and billing descriptors. For payment facilitators and platforms, the obligation flows down to sub-merchants. If a merchant on your platform triggers an investigation, your acquirer is on the hook, which means you are too. The merchants who clear quickly are the ones whose evidence is already organised before the question is asked.
Merchant Trust Services and MSRI: the issuer side
SMMP does not stand alone. Mastercard has announced Merchant Trust Services, which combines network-wide intelligence into merchant-level risk insights used from onboarding through ongoing monitoring. Alongside it sits the Merchant Scam & Risk Indicator (MSRI), which gives issuers merchant-risk signals at the point of authorization.
This matters to merchants because it can affect approvals. In a pilot with a leading issuer, MSRI detected roughly 80% of the risky merchants the issuer later identified, many flagged as early as 90 days before the issuer escalated. MSRI launches first in Europe and the United States before expanding globally. In short, risk signals will increasingly ride along at authorization, not only after disputes appear.
Which merchants face the highest risk
New card-not-present merchants under six months of Mastercard history face the strictest scrutiny, because scam operations tend to onboard, process fast, accumulate disputes and disappear, and the rules are built to catch that pattern. Several verticals carry extra structural exposure:
- Forex and iGaming: high transaction velocity, intangible delivery and difficult geographies make issuer-side scam language easier to assert.
- Subscriptions and SaaS: trials, forgotten renewals and descriptor confusion generate refunds and disputes customers may describe as unexpected.
- Travel: high average order value and seasonal refund spikes can move the combined rate quickly.
- Crypto and digital goods: velocity plus irreversible or intangible fulfilment.
None of these traits prove scam activity. They simply raise the chance that ordinary merchant friction produces the same signals Mastercard and acquirers are watching. If you operate in one of these sectors, our high-risk merchant account guidance explains how underwriters read these signals.
How to prepare before 24 July 2026
Treat the deadline as an evidence-readiness date, not a filing date.
- Track refunds and chargebacks together. If you already monitor a VAMP-style combined ratio, extend it: SMMP adds refunds to the picture for new merchants. Calculate your rolling 30-day combined refund and chargeback rate now and set an internal alert well below 5%.
- Prioritise prevention over recovery in high-refund categories. Deflecting a dispute before it files keeps the combined rate down; winning it back later does not.
- Fix your billing descriptors. Descriptor confusion is a common reason customers call their issuer instead of you, and that call's language can end up in the dispute record.
- Watch authorization trends by BIN, issuer, market, campaign and gateway to catch a collapse before it becomes a trigger.
- Keep evidence packets ready. Cancellation logs, delivery confirmations, terms acceptance and support history are now a defence against termination, not only a way to win disputes.
- Brief your acquirer on your business model before a trigger fires. They cannot defend what they do not understand.
- Build in redundancy so a single flag cannot take you fully offline.
Why multi-acquirer redundancy is your real defence
The hardest part of SMMP is not the paperwork. It is the speed and the finality. A confirmed investigation ends acceptance on that acquirer straight away, and if your whole business runs through one acquiring relationship, that is a single point of failure.
Merchants who route across multiple acquirers keep processing even when one relationship is paused, and they gain time to respond with evidence instead of scrambling. For high-risk operators in Forex and iGaming, that redundancy, together with correct MCC coding, clean descriptors and a partner who can speak to the acquirer on your behalf, is often the difference between a difficult week and a business-ending one.
How CatalystPay helps
We are not another dashboard. CatalystPay works with 30+ acquiring partners across the UK and EU and supports online merchants in higher-scrutiny verticals, including iGaming, Forex, crypto, subscriptions, digital goods and cross-border eCommerce.
Ahead of the SMMP deadline, we help merchants review their combined refund and chargeback exposure, tidy descriptors and evidence processes through our risk and compliance support, and build acquiring redundancy so a single investigation cannot switch off your revenue. If you want a second acquiring route in place before July, talk to our team.
Final thoughts
Mastercard is shifting accountability upstream, and acquirers now have every reason to offboard risky-looking merchants before an investigation reaches their desk. The businesses that will be fine are the ones that look clean before anyone asks: low combined rates, clear descriptors, organised evidence, redundant processing, and a business model their acquirer already understands. If you have prepared for VAMP, you are part of the way there. The goal is simple: be the merchant no one needs to investigate.
This article reflects SMMP and VAMP programme details as reported as of July 2026. Thresholds, deadlines and acquirer obligations can change; confirm operational decisions against Mastercard and Visa rules and your acquirer.
Frequently Asked Questions
-
What is Mastercard SMMP?
The Scam Merchant Monitoring Program is a Mastercard enforcement track requiring acquirers to investigate merchants flagged for scam activity within 72 hours and terminate processing if confirmed. It is an investigation programme, not a ratio programme like ECM.
-
When does it take effect?
The full programme is effective 24 July 2026; related onboarding requirements have applied since January 2026.
-
How is SMMP different from Visa VAMP?
Visa VAMP is a ratio programme that combines fraud and disputes into one number, with a 1.5% excessive threshold from April 2026. SMMP is triggered by scam signals and can end in immediate termination. SMMP's new-merchant trigger also counts refunds, which VAMP does not.
-
Who is most at risk?
New card-not-present merchants under six months of Mastercard history, plus Forex, iGaming, subscription, SaaS, travel, crypto and digital-goods merchants whose models naturally produce higher refund and dispute rates.
-
How can merchants avoid termination?
Keep the combined refund and chargeback rate below 5%, clean up descriptors, keep evidence ready, brief your acquirer, and maintain multi-acquirer redundancy.