Card-scheme compliance · Acquiring & PSP portfolios

Get out of the monitoring programs. Stay out.

Ashlar Risk is a remediation practice for acquirers, PSPs and PayFacs carrying high-risk portfolios. We diagnose why a portfolio breached, build the plan the network will accept, and hold performance under threshold across Visa, Mastercard, American Express and Discover — in one view instead of four.

VAMP ratio Excessive
0.94%
Illustrative portfolio ratio meter An illustrative portfolio ratio falls from 0.94 percent, above the 0.70 percent excessive marker, down past the 0.50 percent above-standard marker, to 0.31 percent. Above-standard Excessive Start 0.50% 0.70% 0.94% 0.00% 1.00%
Illustrative: a portfolio moving from excessive to sustained compliance.

The notification arrives with a clock attached.

A monitoring notification is not a warning — it is the start of a remediation window measured in days. The plan you file is read by people who see hundreds like it, and a plan that misidentifies the root cause buys nothing but another month in the program. Most portfolios do not breach for one reason. They breach because a handful of MIDs, a misleading descriptor, an unmanaged subscription cohort and a missing alert integration all compound in the same quarter.

  1. Day 0Notification
  2. Days 1–5Diagnosis
  3. Days 6–12Root cause & controls
  4. Day 15Plan filed
  5. Months 1–3Sustained under threshold
  6. Exit

And a second clock, running since 24 July.

Fifteen calendar days to file a remediation plan 15 Calendar days

Visa · VAMP

Remediation plan filed

Seventy-two hours to open a formal investigation 72 Hours

Mastercard · SMMP

Investigation opened

Mastercard's revised scam merchant monitoring standards took effect on 24 July 2026 and apply to acquirers and payment facilitators across every card-not-present portfolio. They are not ratio-based and there is no grace period. Once a trigger condition is met, a formal investigation must begin within 72 hours, and a merchant confirmed as a scam operator must be blocked from authorization and clearing immediately.

The triggers are operational rather than statistical. Most portfolios can produce a monthly chargeback report. Far fewer can evidence that they detected a trigger and opened a documented investigation inside three days — with a named owner, defined findings criteria and the authority to block. That gap is a written procedure, not a platform.

  • Approval-rate collapse A fall of 50 percentage points or more, or a rate below 30%, over a rolling 72-hour window in which the merchant processed at least 25 purchases.
  • Global Rules Investigation Program letter Correspondence linking the merchant to suspected scam activity.
  • Monitoring provider alert An identification from a Mastercard-recognized merchant monitoring service provider.
  • Refund and chargeback rate above 5% At merchants with under six months of processing history and at least 500 transactions in 30 days. Refunds are counted alongside chargebacks, which closes the practice of settling complaints quietly.

We build the procedure, the investigation record and the escalation path, and we do it in weeks rather than quarters.

What we do

Remediation

You are already in a program. We reconstruct what drove the ratio at MID and cohort level, write the remediation plan, and run the execution — control changes, merchant-level interventions, offboarding decisions where the arithmetic requires it — until performance clears the exit criteria.

Cross-network monitoring

Four networks, four sets of thresholds, four reporting cadences, four sets of reason codes. We consolidate dispute and fraud performance across all of them into a single portfolio view with alerting calibrated to the distance from each threshold, not to the breach.

Portfolio risk & underwriting review

Standing exposure assessment for high-risk books: concentration by vertical and MID, descriptor and billing-model hygiene, onboarding criteria that predict the disputes you will be arguing about in six months.

Four card networks converging on one portfolio view Visa, Mastercard, American Express and Discover each connect by a single path to one central node labelled "Your portfolio". Visa Mastercard American Express Discover Your portfolio

The thresholds we work against

Scroll the table horizontally →

Network monitoring programs, measures, thresholds and response windows.
Network Program What it measures Threshold Response window
Visa VAMP Fraud reports (TC40) plus disputes (TC15) over settled card-not-present transactions Acquirer: above-standard 0.50%, excessive 0.70%. Merchant: excessive 1.50% from 1 April 2026 (CEMEA 2.20%). Minimum 1,500 combined events per month Remediation plan within 15 calendar days
Visa VAMP Enumeration Confirmed enumerated transactions over total sales Assessed as a separate ratio, identified through Visa Account Attack Intelligence scoring Per notification
Visa VIRP High-risk merchant registration and control assessment Tier-based Per registration terms
Mastercard ECM Chargeback count and rate at merchant level 100–299 chargebacks in a calendar month and a rate of 1.50% or higher, sustained across two consecutive months Per notification
Mastercard HECM As ECM, upper band 300 or more chargebacks and a rate of 3.00% or higher Per notification
Mastercard EFM Card-not-present fraud, with a 3-D Secure adoption criterion All four required: 1,000 or more CNP transactions, USD 50,000 or more in fraud chargebacks, a fraud rate of 50 bps or higher, and low 3-D Secure usage Per notification
Mastercard BRAM Brand protection: illegal or brand-damaging content and transaction laundering Violation-based, not ratio-based Per notification
Mastercard SMMP Scam merchant identification across card-not-present portfolios Trigger-based, in force since 24 July 2026. See the triggers above Investigation must begin within 72 hours
American Express FFRP Fraud rate. Enrollment removes the right to dispute fraud chargebacks Enrollment follows sustained fraud performance. Exit requires a fraud-to-gross ratio below 0.90% and fraud disputes under USD 25,000 across three consecutive months Per notification
American Express ICP / Partial ICP Chargeback rate across all reason codes Above 1% Per notification
Discover Discover both issues and acquires, and manages disputes directly rather than through a published ratio program of this kind Handled case by case with the network Per notification

Exit from the ratio-based programs generally requires sustained performance below threshold across consecutive months — commonly three — with the criteria set by the network.

Thresholds and windows as published by the networks and current to July 2026. Program rules change frequently — figures here are orientation, not a substitute for the applicable rulebook or your network contact. Ashlar Risk is not affiliated with, endorsed by, or acting on behalf of Visa, Mastercard, American Express or Discover.

A remediation plan is an argument. We build the argument.

  1. Diagnosis

    Reconstruct the ratio: which MIDs, which cohorts, which reason codes, which months. Separate the structural from the incidental.

  2. Root cause

    Distinguish genuine fraud from first-party misuse, descriptor confusion, subscription and free-trial mechanics, and fulfillment failure. The four demand different remedies and the network can tell them apart.

  3. Action plan

    Controls, thresholds and merchant-level decisions, each mapped to the specific driver it addresses, each with an owner and a date.

  4. The filing

    The remediation plan itself, in the structure and language the network expects to read, filed inside the window.

  5. Exit criteria & monitoring

    Define what clearing the program requires, then instrument performance against it monthly until the criteria are met and hold.

  6. Evidence mapping

    Reason code to evidence, per network. Compelling-evidence eligibility assessed rather than assumed, so representments are filed where they win and abandoned where they do not. Since 18 April 2026 Visa's compelling-evidence framework also reaches fraud reports that never became chargebacks — the part of the numerator that was previously unanswerable, and in high-risk books frequently the larger part.

Built for the acquiring side.

Acquirers & sponsor banks

Portfolio-level exposure, program enforcement, and the merchant decisions that follow.

PSPs, PayFacs & ISOs

Where the aggregate ratio is yours but the behavior driving it belongs to a hundred sub-merchants.

High-risk verticals

Lawful, licensed merchants in verticals where dispute and fraud pressure is structural rather than exceptional. We do not work with illegal merchants, and portfolios containing them are a remediation finding, not a client segment.

Who you are dealing with

Ashlar Risk was founded by Alex Maskalovs, who has spent roughly a decade in high-risk payments — white-label acquiring, cross-border processing and payment aggregation across EEA, CIS, LATAM and Africa — following a fraud role on the bank side. The practice is deliberately small and senior: the person who diagnoses your portfolio is the person who writes the plan and sits on the call with your network contact.

How engagements are structured

Remediation project

Fixed scope, defined by the program and the window. Diagnosis through filing through exit.

Monitoring subscription

Ongoing cross-network portfolio surveillance with threshold-distance alerting.

Advisory retainer

Standing access for underwriting decisions, network correspondence and escalations.

Pricing is set per portfolio after a scoping call. We are selective about engagements and will tell you if the work does not need us.

Questions we are asked

Almost certainly not, and a firm that tells you otherwise is selling you something. Only the acquirer that filed the listing can remove it, and only where the listing was made in error, or where it was filed under reason code 12 for PCI DSS non-compliance and the deficiency has since been remediated. Where a listing is accurate and tied to chargebacks or fraud, the five-year term runs. MATCH is also searched against principals, not only the business, so a new DBA does not solve it. Our value here is upstream: keeping merchants out of the trajectory that ends in termination.

Exit generally requires sustained performance below threshold across consecutive months — commonly three, though the criteria are program-specific and set by the network. The realistic question is not how fast, but whether the drivers have actually been removed or merely suppressed for a month.

No. Ashlar Risk is independent and has no affiliation with, endorsement from, or authority to act on behalf of Visa, Mastercard, American Express or Discover. All program and trademark references are for identification only.

No. We work with aggregated and MID-level dispute and fraud reporting. Our architecture is deliberately designed to stay out of PCI DSS scope, and we do not request, receive or store primary account numbers.

We do the work. We maintain tooling to consolidate cross-network reporting because the alternative is four spreadsheets, but the deliverable is a remediated portfolio, not a dashboard license.

No. MMSP is a registered function performed on behalf of an acquirer, and the identification alerts referenced above come from approved providers. What we consolidate is your own dispute and fraud reporting across the four networks into a single view — a management instrument, not a network-recognized monitoring service. Where a portfolio needs an MMSP, that is a finding we surface, not a service we substitute for.

No. Scheme rules are global and the programs apply wherever you process. Engagements run remotely.

Request a portfolio review

Tell us the network, the program and where you are in the window. If there is a notification on your desk, say so in the first line — those move to the front.

Inquiries are treated as confidential. We will sign an NDA before any portfolio detail is shared.