ArticleMastercard SMMPFor Acquirers & ISOs

Mastercard SMMP: Scam Merchant Monitoring Program

Published
Sep 5, 2026
Updated
Sep 5, 2026
Read time
6 min

For years, Mastercard's merchant monitoring followed a familiar rhythm. A merchant crossed a chargeback or fraud ratio, the acquirer received a notice, fines were assessed, and everyone got a few months to fix the problem. Uncomfortable, but survivable.

The Scam Merchant Monitoring Program (SMMP) breaks that rhythm. Enforceable since July 24, 2026, SMMP doesn't wait for a month-end ratio. It is triggered by scam signals, it gives the acquirer 72 hours to investigate, and a confirmed case ends in immediate termination of Mastercard and Maestro processing, not a fine.

For acquirers and ISOs, SMMP is less a merchant program than a test of your own monitoring. Here's how it works, what triggers it, and why episodic underwriting can't keep up.

What Is Mastercard's Scam Merchant Monitoring Program (SMMP)?

SMMP is a Mastercard compliance program that requires acquirers and payment facilitators to identify, investigate, and remove card-not-present (CNP) merchants suspected of running scams. It was introduced in a July 2025 update to Mastercard's Security Rules and Procedures, as part of a broader overhaul of the network's merchant monitoring standards, and became fully enforceable on July 24, 2026.

Key facts at a glance:

  • Scope: Card-not-present merchants globally, including sponsored merchants operating under payment facilitators.

  • Who acts: The acquirer. You discover a trigger has been breached, you run the investigation, and you report the outcome.

  • Timeline: The investigation must begin and be completed within 72 hours of a trigger being identified.

  • Consequence: If scam activity is confirmed, Mastercard and Maestro processing stops immediately, and the merchant can be placed on the MATCH list.

  • Runs alongside: The Excessive Chargeback Program (ECP) and Excessive Fraud Merchant (EFM) program. A merchant can be clean under both and still be investigated under SMMP.

The Four SMMP Triggers

Any one of the following conditions requires the acquirer to open an investigation.

1. Authorization rate collapse (all merchants). On at least 25 purchase transactions, the merchant's approval rate falls 50 or more percentage points within 72 hours, or drops below 30%. Declines caused by a confirmed BIN attack or an acquirer or processor outage are excluded. A collapse like this often means issuers have started treating the merchant's transactions as suspicious, but a bad retry strategy or routing error can produce the same pattern.

2. A GRIP notification (all merchants). A letter from Mastercard's Global Rules Investigation Program (GRIP) means the network has independently linked the merchant to suspected scam activity. By the time it reaches you, the clock is already running.

3. A Merchant Monitoring Service Provider alert (all merchants). Mastercard-approved Merchant Monitoring Service Providers (MMSPs) scan merchant websites, marketing, and digital signals. A single alert identifying potential scam or illegal activity is enough to require an investigation, even if the transaction data looks clean.

4. New-merchant scam signals (six months or less of Mastercard acceptance). Any one of these:

  • Two different issuers report fraud under reason code 56, "Manipulation of Cardholder."

  • Two or more issuers file chargebacks with documentation referencing scams or manipulation.

  • Combined refunds plus chargebacks exceed 5% of purchase transactions in any rolling 30-day period, with a minimum of 500 transactions.

How the 5% Combined Rate Works

The 5% rule gets the most attention, and the most misreading. It applies only to merchants with six months or less of Mastercard acceptance history. Established merchants are monitored through the other three triggers.

Formula: (refunds + chargebacks) ÷ purchase transactions, rolling 30 days

Example: a new MID processes 2,000 purchases in 30 days, with 70 refunds and 35 chargebacks. That's 105 ÷ 2,000 = 5.25%, and an investigation is required.

Two design choices matter for every underwriter:

  • Refunds count. Under chargeback-only programs, aggressive refunding kept dispute ratios low. Under SMMP, refunding to suppress chargebacks feeds the same number. That's deliberate: scam operators often refund just enough to stay under traditional thresholds.

  • Representment doesn't help. A chargeback counts when it's filed. Winning it later recovers the revenue, but it doesn't remove it from the calculation.

Why SMMP Puts the Burden on the Acquirer

SMMP extends the same shift Visa made with its Acquirer Monitoring Program (VAMP) and that Mastercard will continue with its revised Global Merchant Audit Program (GMAP) in April 2027: the networks are holding acquirers directly accountable for what happens in their portfolios.

SMMP is especially demanding because of how it's built:

  • It's signal-based, not ratio-based. You can't manage it from a monthly ratio report. An auth-rate collapse can happen over a weekend.

  • The clock starts when the trigger is identified. If your team learns about a 50-point approval drop from a report two weeks later, you're already explaining why the investigation started late.

  • The evidence has to exist before the question is asked. Seventy-two hours isn't enough to build a case file from scratch.

  • It extends to sponsored merchants. ISOs and payment facilitators with large sub-merchant portfolios inherit the same investigation burden at much larger scale.

Mastercard has also tightened onboarding. Under the revised merchant monitoring standards, new merchant websites are scanned before or at boarding, with requirements that took effect in January 2026. Mastercard now expects scrutiny at boarding and every day after.

What an SMMP Investigation Looks Like

A trigger is not an accusation. A risk indicator signals that further assessment is needed, and a legitimate merchant with good records can be cleared quickly. If cleared, processing continues under ongoing monitoring.

To reach that conclusion in 72 hours, acquirers and ISOs typically need:

  • Website screenshots and documentation of the full customer journey, including trial, renewal, refund, and cancellation terms.

  • Order records, proof of delivery or service use, and customer communications.

  • Refund, cancellation, and chargeback records, including dispute documentation and reason codes.

  • Affiliate and traffic-source data showing where the problem transactions came from.

  • A root-cause analysis and a remediation plan.

The central question is whether the merchant's behavior matches its stated business model. An acquirer that already sees its merchants' affiliates, campaigns, products, and landing pages can answer that quickly. One working from raw transaction counts can't.

Five Steps Acquirers and ISOs Should Take Now

  1. Flag every MID under six months old and track its combined refund-plus-chargeback rate daily, with internal alerts well below 5%, such as 3% to 3.5%.

  2. Monitor authorization rates per MID continuously, with alerts for any 50-point drop or fall below 30%, so you can document BIN attacks and outages before they're misread.

  3. Track reason code 56 and scam-related dispute documentation by issuer, especially for new merchants.

  4. Require merchants to report material changes, such as new affiliates, traffic sources, products, markets, or checkout flows, and verify them in the data.

  5. Pre-build the evidence file. Make sure every merchant's customer journey, fulfillment records, and refund logs can be pulled in hours, not days.

Continuous Underwriting: The Only Way to Meet a 72-Hour Clock

Most acquirers and ISOs still underwrite once at boarding, re-review annually, and react when a monthly report shows something broke. That model was built for ratio programs with remediation windows. SMMP has neither. A new merchant can cross 5% inside three weeks, and an established merchant's approval rate can collapse overnight.

The answer is continuous underwriting: ongoing, transaction-level monitoring of every merchant, every day, instead of one-time or episodic reviews.

SLYCE360 acts as a force multiplier for your risk and compliance department. Growing issues are highlighted early, before they become a 72-hour investigation, a terminated merchant, or a sponsor bank problem.

SLYCE360 integrates directly with your merchants' CRMs, overlaying the data that has historically been a black hole for compliance teams, including affiliate, campaign, product, agent, and landing page. When a trigger fires, your team already knows why, and the evidence file is already built.