On July 24, 2026, Mastercard's revised standards for scam merchant monitoring, sometimes called SMMP, took effect. The rules, laid out in Mastercard's document GLB 12772, require acquiring banks and payment facilitators to investigate any merchant flagged by specific risk criteria within 72 hours. If a merchant is confirmed as running a scam, Mastercard processing stops immediately.
If you're an eCommerce merchant, you might read that and think it doesn't concern you directly. After all, it's a programme aimed at catching scam merchants, fake storefronts, fraudulent operations, and criminal enterprises. You're a legitimate business.
But that assumption misses how monitoring programmes like this actually work, and why every eCommerce merchant should care.
How the programme works
The programme compresses the window between suspicious signals and enforcement, and it's more specific than most coverage suggests. An investigation is triggered when a merchant hits any of several criteria:
-
A 50-point approval rate drop (or a fall below 30% approval) across at least 25 transactions in 72 hours
-
A Mastercard Global Rules Investigation Program letter
-
An alert from a Merchant Monitoring Service Provider
-
Or, for merchants with under six months of processing history, a combined refund-and-chargeback rate above 5% over a rolling 30-day period
That last trigger applies once a merchant has processed at least 500 transactions in the window, and it counts refunds the same as chargebacks. A merchant with a generous, well-used returns policy can trip the same threshold as one with a genuine fraud problem, because the system flags on the pattern, not the reason behind it.
Once triggered, the acquirer has 72 hours to begin an investigation, not resolve it; begin it. The investigation itself is what determines whether the flagged activity is genuine scam behaviour or a legitimate merchant with a fraud management gap. Get that distinction wrong from the data alone, and the two can look uncomfortably similar.
The Visa connection
Mastercard isn't acting in isolation. Visa launched its own Visa Acquirer Monitoring Program (VAMP) in 2025, pursuing a similar strategy of pressing merchants and their banks to take more active roles in fraud prevention. The two largest card networks are now aligned on the principle that fraud prevention is a shared responsibility, and that acquirers and merchants need stronger incentives to participate.
For eCommerce merchants, this dual-network pressure means the threshold for acceptable fraud and dispute metrics is effectively tightening across the board. What was tolerable last year may trigger investigation this year.
Why legitimate merchants should pay attention
There are three scenarios where SMMP directly affects legitimate eCommerce businesses:
1. Elevated dispute rates trigger flags regardless of cause. If your store experiences a spike in chargebacks, perhaps due to a fulfilment delay, a product quality issue, or a confusing returns process, the monitoring system doesn't distinguish between customers who couldn't get a refund from a scam store and customers who filed a dispute because your customer service was slow. The signal looks the same.
2. Your acquirer's response affects your business. When your acquiring bank receives a flag, they're now obligated to investigate within 72 hours. That investigation involves scrutiny of your transaction data, your dispute history, and your business practices. Even if the outcome is favourable, the process creates friction, and in some cases, additional monitoring requirements or reserve adjustments.
3. Payment facilitators face the same obligations. If you process payments through a payment facilitator rather than directly through an acquiring bank, common for smaller eCommerce merchants, that facilitator is now subject to the same monitoring and investigation timelines. This means payment facilitators may tighten their own merchant risk thresholds to avoid being caught in lengthy investigations.
Mastercard itself seems aware of this tension. Alongside SMMP, the company is rolling out Merchant Trust Services, a broader push to give acquirers earlier, more precise signals before onboarding a merchant or escalating against one. Its companion tool, the Merchant Scam & Risk Indicator, was tested in a pilot that reportedly flagged around 80% of issuer-identified risky merchants, many of them up to 90 days before the issuer's own escalation. Whether that precision extends to reducing false positives for legitimate merchants caught in SMMP's net remains to be seen, but it signals Mastercard knows the distinction matters.
What eCommerce merchants should do
The practical response isn't panic; it's operational hygiene. Here's what matters:
-
Monitor your dispute rate actively. Don't wait for your acquirer or payment processor to tell you there's a problem. Track your chargeback ratio, fraud-coded dispute rate, and refund patterns on a monthly basis at minimum. Industry benchmarks vary by sector, but a chargeback rate above 1% should be treated as a warning signal.
-
Review your fraud prevention stack. Ensure you're using address verification (AVS), card verification value (CVV) checks, and ideally 3D Secure authentication on transactions where it's supported. These are baseline fraud prevention tools that also serve as evidence of good faith if you're ever subject to investigation.
-
Fix the disputes that aren't really fraud. A significant portion of chargebacks in eCommerce aren't actual fraud; they're customers who couldn't get a refund, couldn't reach customer service, or didn't recognise a charge on their statement. Every one of those "friendly fraud" disputes counts against your metrics. Improving your customer service responsiveness, making your billing descriptor clear and recognisable, and offering straightforward refund processes reduces dispute rates more effectively than any fraud tool.
-
Talk to your payment processor. Ask your acquiring bank or payment facilitator how they're implementing SMMP monitoring and what thresholds they've set for merchant investigation. Understanding where the line is helps you stay well above it.
-
Document your fraud prevention practices. If you are flagged, having documented policies, active monitoring, and a clear history of fraud prevention investment makes the difference between a quick resolution and a prolonged investigation.
The bigger picture
Programmes like this exist because the stakes are large. Consumers lost $442 billion globally to online scams last year, according to the Global Anti-Scam Alliance, a number substantial enough to reshape how seriously card networks treat merchant trust as infrastructure rather than an afterthought.
Mastercard's own leadership has been blunt about the knock-on effect for legitimate businesses: every bad scam experience makes shoppers warier of real merchants too, showing up industry-wide as more declines, more disputes, and more abandoned carts. SMMP is Mastercard's attempt to catch the scams before that erosion spreads further.
On Tap's perspective
We've seen this shift before: a compliance requirement that starts out narrow and technical, then quietly redraws the line for what counts as normal business operations. From where a merchant sits, SMMP is not really a scam-detection tool. It's a data quality test, applied under a 72-hour clock you don't control.
The merchants who navigate this cleanly won't be the ones who wait for a flag to take fraud prevention seriously. They'll be the ones who already treat dispute rates, refund patterns, and documentation the way they treat inventory accuracy or fulfilment SLAs: an operational metric someone owns and checks, not a fire to fight once it starts.
Need help figuring out what this means for your store? On Tap helps eCommerce merchants stay ahead of shifts like this, from changes to what they actually require you to update. Get in touch with our team to talk more.


