.png)
If you've kept your fraud dispute rate below the threshold you were given, you probably assumed you were doing everything right.
For many merchants, that assumption changed when Visa introduced its Acquirer Monitoring Program (VAMP), which began rolling out in 2025 and entered its latest phase in April 2026.
VAMP represents a fundamental shift in how payment risk is managed. Rather than evaluating fraud and disputes separately, VAMP combines these signals into a broader view of merchant risk. Instead of looking only at individual merchant performance, the program holds acquirers accountable for the combined risk across their entire merchant portfolio.
That means a merchant's risk profile is no longer determined by their own performance alone.
.png)
"Your acquirer's whole portfolio carries its own threshold, and if enough of their other merchants surpass the threshold, everyone on that portfolio can feel the consequences," explains Anna Slavin, Payment Fraud Product SME at Riskified. That portfolio-level dynamic became a wake-up call for many merchants after Shopify Payments closed a number of merchant accounts, highlighting how decisions made at the acquirer level can affect individual businesses.
The challenge is that a healthy-looking chargeback rate doesn't mean you're in the clear anymore. VAMP changes how Visa calculates risk itself, combining signals that used to be tracked separately into one number. Merchants now need a wider view of their risk than a chargeback count alone can give them.
To better understand what this shift means for merchants, we spoke with experts across the payments ecosystem at J.P. Morgan, Riskified, Chargebacks911, Chargeblast, and our own team here at Primer. Together, their perspectives point to a broader shift: VAMP is shifting payment risk from a compliance exercise into an operational discipline shared by merchants and acquirers.
VAMP is more than just a new chargeback threshold
"The biggest misconception is that VAMP is simply a new chargeback-ratio threshold that merchants can manage the same way they used to," says Christopher Bucceri, VP and senior relationship manager at J.P. Morgan. "It's broader than that."
%20(1).png)
The reason comes down to what VAMP actually measures, and Qi Cao, Co-founder and CEO of Chargeblast, says most merchants still don't fully get it. "People still don't really fully grasp what it means for their business, and who's actually policing who," he said in a recent appearance on Payments Unfiltered. He breaks down the two signals now included in the calculation:
- A TC15 is a dispute: any time a customer or their bank requests their money back, whatever the reason, fraud or otherwise.
- A TC40 represents a fraud report, flagging that a transaction may have involved a stolen card even if it never becomes a formal dispute.
The programs VAMP consolidated, the Visa Dispute Monitoring Program (VDMP) and the Visa Fraud Monitoring Program (VFMP), tracked these signals separately with separate thresholds.
VAMP brings them together into a single ratio, and a single transaction can now contribute to it twice, once as a TC40 fraud report, once as the dispute it later becomes. That means your actual ratio can run higher than a straightforward chargeback count would suggest.
Riskified’s Slavin flags another problem: plenty of disputes may have nothing to do with fraud in the first place. "Visa now folds fraud reports and disputes into a single ratio, so a merchant can have strong fraud prevention performance and still trip the threshold because of other, service-related disputes like slow refunds, a billing descriptor nobody recognizes, or a rough return experience."
Aladin Taleb, Senior Product Manager at Primer, points to why this catches merchants off guard. TC15 and TC40 data is "post-payment" information, not something visible in real time the way authorization data is. He also flags a third signal, tracked completely separately from either of those: enumeration, which is bots testing stolen card numbers against your checkout. Visa confirms it through an entirely different system, Visa Account Attack Intelligence (VAAI), and it only applies once a merchant clears 300,000 of those attempts in a month. It's a small, telling example of how unevenly unified this "unified" ratio actually is.
None of this is well understood, either. Chargebacks911's 2026 Chargeback Field Report, based on a survey of more than 250 merchants, found that only 23% of respondents considered themselves "very" informed about card network rules. Another 16% said they had no knowledge of them at all.
Beyond the ratio, payments visibility is key
Visa puts the merchant-level threshold at 1.5%, down from 2.2% as of this April, Slavin confirms. But the threshold that actually determines your fate sits at the acquirer level, and it's stricter.
Monica Eaton, Founder and CEO of Chargebacks911, puts the first trigger at 0.5%, the point where an acquirer's portfolio-wide ratio starts drawing per-transaction penalties.
"The biggest misconception is that only merchants who are at risk of breaching VAMP thresholds need to care," she says. J.P. Morgan’s Bucceri makes the same point from the acquirer's side, noting that staying under your own 1.5% doesn't guarantee safety. If an acquirer's whole portfolio is trending toward its threshold, it can impose tighter reserves, repricing, or traffic restrictions on individual merchants well before those merchants cross their own line.
Those are the mechanics behind the Shopify Payments closures mentioned earlier, and Shopify isn't the only example. One merchant surveyed for Chargebacks911's report described chargebacks now causing consequences up to "bank and money freezes," despite being compliant on paper.
It's reshaping the market, too. Chargeblast’s Cao has watched high-risk merchants deliberately move to lower-risk processors this year to dilute their exposure inside a cleaner portfolio, while some of the same acquirers that used to specialize in high-risk merchants are now stuck cutting those businesses, because concentrating that risk pushed their own ratio too high.
For Taleb, the whole challenge comes down to knowing where you stand. "The merchants who handle VAMP well are the ones who can actually track the entire lifecycle of a payment, from its inception to dispute resolution, to calculate their VAMP indicators before their acquirers tell them that something is wrong. Visibility is the whole game here."
.png)
What separates the merchants getting this right
The obvious response to rising fraud reports is to tighten controls everywhere. But according to Bucceri at J.P. Morgan, that's often the wrong move.
One merchant who applied broad restrictions saw fraud drop, but false declines skyrocketed and revenue suffered. A more effective strategy is identifying the specific SKUs, geographies, or traffic sources driving the increase, then applying step-up authentication selectively.
Slavin has seen a similar pattern from the fraud prevention side. A digital payments platform came to Riskified, concerned that its fraud reports and TC40 volume were putting its PSP relationship at risk. Rather than introducing blanket restrictions, the team focused on transaction-level visibility and more targeted decisioning. Within months, both fraud reports and TC40 rates had fallen enough to take the business off its provider’s risk list.
The common thread isn't stricter fraud rules, but better visibility into where risk is actually coming from. That's why J.P. Morgan’s Bucceri argues merchants and acquirers now need what he calls a "shared responsibility model." Merchants must take ownership of customer data and TC40 reports, while acquirers provide the visibility needed to act before thresholds are breached.
One practical example is Visa's Compelling Evidence 3.0 (CE 3.0). Recent updates mean qualifying merchants can now prevent a much broader set of fraud reports from counting toward their VAMP ratio. But the catch, according to Slavin, is that a successful case depends on proving a pattern across a customer's undisputed prior transactions. So her advice is to start saving that transaction history now because you won't be able to collect it later.
VAMP demands a more proactive approach to payment risk
Chargebacks911’s Eaton calls the next 12 months a "prove it" period. Merchants who've stayed compliant for a quarter may simply not have been tested by real stress yet, like the dispute spike that typically follows the peak holiday season. Visa has already adjusted its threshold once this year, and further refinements are expected.
Acquirers are already changing how they operate, not just what they measure. As J.P. Morgan’s Bucceri puts it, "the more important change is behavioral, as the bar is raised - even for merchants that have not technically entered VAMP."
Merchants are adjusting too, moving from blanket fraud rules toward targeted ones and treating their acquirer as a partner rather than a gatekeeper. None of it is finished yet. Merchants and acquirers are still finding their footing as Visa keeps adjusting its own rules and Eaton's "prove it" year still lies ahead.
And the shift isn't limited to Visa. Mastercard has now announced its own Global Merchant Audit Program (GMAP), its version of VAMP, bringing fraud and disputes into a single monitoring framework. The program takes effect on April 1, 2027, with Mastercard also planning to lower key thresholds between 2029 and 2031.
And the shift isn't limited to Visa. Mastercard has now announced its own Global Merchant Audit Program (GMAP), bringing fraud and disputes into a single monitoring framework similar to VAMP. The program takes effect on April 1, 2027, with Mastercard also planning to lower key thresholds between 2029 and 2031.
The real shift with VAMP is that payment risk is becoming something merchants need to manage proactively across the payment lifecycle, in close coordination with their acquirer, rather than a number to check once and forget.
.png)


.avif)
%20(1).avif)
%20(1).avif)