Chapter 1. The rulebook hierarchy: who is bound by which rules.
Scheme rules are private contract law. They are neither statutes nor regulations, but rulebooks that are binding on anyone who wants access to the Visa, Mastercard or CB networks. Their force comes from a simple contractual cascade. The scheme binds its members, meaning issuing and acquiring banks or licensed institutions. The members then pass these obligations on to their own customers (PSPs, payment facilitators and merchants) through the acceptance agreement.
These private rules coexist with public law. In Europe, the Interchange Fee Regulation (IFR 2015/751) and PSD2 regulate some scheme clauses, and sometimes override them, as with the “honor all cards” rule or surcharging. In case of conflict, public law prevails, and the schemes publish regional exceptions.
Chapter 2. Data integrity: MCC, descriptor, transaction laundering.
Every transaction carries data the merchant declares about itself (business category code, name, city, country, ID), and the schemes require that data to be accurate and truthful. The whole ecosystem depends on it: interchange calculation, issuer risk rules, category restrictions, and whether the cardholder can make sense of their statement. Falsifying this data is one of the most severely penalized violations.
The MCC: four digits that drive everything
The Merchant Category Code (ISO 18245 standard) classifies the merchant’s business with a four-digit code. The acquirer assigns it when the merchant account is opened. It determines the interchange rate, eligibility for certain programs, and registration requirements for high-risk businesses. Some issuers also use it to block transactions, for example gambling or crypto-asset purchases.
| MCC | Activity | Main issue |
|---|---|---|
| 5411 | Supermarkets and grocery stores | Standard interchange, no special registration |
| 5732 | Electronics stores | Category with monitored dispute rates |
| 5912 | Pharmacies | Online pharmacy sales: registration and licenses required |
| 6051 | Quasi-cash, including crypto-asset purchases | Frequent issuer blocks, enhanced monitoring |
| 7995 | Gambling and betting | Mandatory high-risk registration, licenses by jurisdiction |
| 5967 | Content-based teleservices (audiotext, adult content) | High-integrity-risk category, enhanced due diligence |
The descriptor: the line that prevents disputes
The billing descriptor is the text that appears on the cardholder’s statement. The rules require it to make the merchant and the transaction recognizable: the trading name actually used, not the obscure legal name of a holding company, plus the city or a customer service contact. Dynamic descriptors specify the service (“BRAND*SUBSCRIPTION”). An unreadable descriptor is still the leading cause of “unrecognized transaction” disputes, which are entirely avoidable chargebacks.
POST /v1/charges
{
"amount": 2990,
"currency": "eur",
"statement_descriptor": "PAYPEDIA.ORG", // 5-22 characters, recognizable to the cardholder
"statement_descriptor_suffix": "MONTHLY-SUB", // dynamic part: identifies the service
"metadata": {
"merchant_legal_name": "Paypedia SAS", // legal name may differ from the descriptor
"support_phone": "+33 1 00 00 00 00" // contact shown depending on the channel
}
}Factoring and transaction laundering: the red lines
- One contract, one merchant, one business: every transaction must be submitted under the ID of the merchant that actually made the sale, with its real MCC and its real country.
- No factoring: collecting payments on behalf of a third party under your own acceptance agreement is prohibited, unless you are a duly registered payment facilitator.
- Transaction laundering: hiding a business (often an illegal or high-risk one) behind a legitimate merchant front. This is the most serious integrity violation: near-automatic termination, a MATCH listing, and a possible report to the authorities.
- Truthful location: the merchant’s country determines interchange and the applicable rules, and the schemes actively hunt down artificial offshoring setups.
Chapter 3. Brands, acceptance, and surcharging.
Accepting a card also means using a brand that you don’t own. The schemes set precise rules for how their logos are displayed, what merchants commit to accepting, and what they can charge cardholders. Three areas account for most compliance checks: brand display, the “honor all cards” rule, and surcharging.
Brand display: parity and accuracy
- Acceptance signage: accepted brands must be displayed at the store entrance and at the online checkout, so the cardholder knows before buying.
- Accurate reproduction: logos must not be distorted or recolored, and must keep the clear space defined in the schemes’ brand guidelines. The acquirer or the brand portals supply the official files.
- Parity: no accepted brand may be disparaged. Displaying one brand more prominently is regulated, and steering the choice is allowed as long as the cardholder keeps the final say.
- Co-badging (IFR, art. 8): on a CB/Visa or CB/Mastercard card, the merchant can set a default brand (CB, for example, which is cheaper for the merchant), but the cardholder has the final choice of brand, and the terminal or payment page must make that possible.
Honor all cards: a long-standing rule, now limited in Europe
Historically, the “honor all cards” rule required a merchant that accepted a brand to accept all cards of that brand. The IFR (Article 10) limited it in Europe. The obligation now applies only within a single card category that falls under the same interchange regime. A European merchant can therefore accept Visa debit cards and refuse Visa credit cards, or vice versa. It can also refuse uncapped commercial cards. What it cannot do is pick and choose card by card or bank by bank within a category it accepts.
Surcharging: geography decides
| Region | Visa/Mastercard consumer cards | Specifics |
|---|---|---|
| European Union / France | Surcharging banned (PSD2, art. 62(4)) on cards with interchange capped by the IFR | Commercial cards and three-party schemes (uncapped) can be surcharged up to the actual cost incurred |
| United Kingdom | Surcharging banned on consumer cards since January 2018 | Carried over from PSD2 transposition and kept after Brexit |
| United States | Allowed (except where some state laws prohibit it), capped by Visa at 3% since April 2023 | Advance notice to the acquirer, mandatory disclosure at the point of sale, surcharge limited to the cost of acceptance |
| Australia | Allowed up to the actual cost of acceptance, under RBA oversight | Reform in progress: in 2025 the RBA proposed banning surcharges on domestic cards, with implementation targeted for 2026 |
Chapter 4. Integrity and monitoring programs: VIRP, BRAM, VAMP, ECM.
The schemes protect their brands with two types of programs. Integrity programs look for illegal or deceptive activity in acquiring portfolios. Monitoring programs track fraud and dispute ratios. In both cases, the lever is the same: fees and fines levied on the acquirer, mandatory remediation, and, as a last resort, exclusion.
| Criterion | Visa VAMP | Mastercard ECM |
|---|---|---|
| Ratio tracked | (TC40 fraud + TC15 disputes) / settled transactions, calculated at the merchant level and the acquirer level | Chargebacks in the month / transactions in the previous month |
| Merchant threshold | “Excessive” at 2.2% at launch (2025), lowered to 1.5% on April 1, 2026, with a minimum dispute count | ECM: ~1.5% and ≥ 100 chargebacks; HECM: ~3% and ≥ 300 chargebacks |
| Specific component | Enumeration ratio (card testing) with its own threshold | Fraud tracked separately through Mastercard’s fraud programs |
| Consequences | Per-dispute fees charged to the acquirer above the thresholds, remediation plan, possible exclusion | Rising monthly fees, mandatory remediation, possible termination after several months |
All these programs measure and bill the same party: the acquirer. An acquirer whose portfolio drifts, with too many merchants over dispute thresholds or missing high-risk registrations, is penalized directly and can lose acquiring rights for certain categories. That is why acceptance agreements are packed with pass-through, reserve and fast-termination clauses.
Chapter 5. Fines, MATCH, and termination.
When prevention fails, penalties follow a well-established escalation: a remediation request, rising fines, termination of the acceptance agreement, and then a listing on interbank blacklists. If you understand how this works, you can negotiate at the right time and avoid the point of no return.
Not all fine amounts are public. The ballpark figures reported by the industry are meant to deter: a few thousand dollars for a documentation failure, and tens or even hundreds of thousands of dollars per month per merchant for BRAM/VIRP-type integrity violations. They increase for repeat offenses or concealment. On top of that come monitoring program fees, charged per dispute or per month in the program.
MATCH: the list that follows a merchant for five years
MATCH (Mastercard Alert To Control High-risk Merchants), the successor to the “Terminated Merchant File,” is the interbank database where acquirers report merchants terminated for cause. Before onboarding any merchant, the acquirer must check MATCH. A hit (legal name, principals, URL, etc.) triggers enhanced due diligence at a minimum, and most often a rejection. The listing stays on file for five years.
| Code | Reason | Example |
|---|---|---|
| 01 | Account data compromise | PAN compromise caused by the merchant’s inadequate security |
| 03 | Laundering | Transactions submitted on behalf of a concealed business |
| 04 | Excessive chargebacks | Ratios persistently above thresholds, failed remediation |
| 05 | Excessive fraud | Abnormal volume of fraudulent transactions attributable to the merchant |
| 07 | Fraud conviction | Criminal conviction of a principal |
| 10 | Violation of standards | Persistent violation of scheme rules (MCC, brand, integrity) |
| 12 | PCI DSS non-compliance | Failure to comply with card data security standards |
| 13 | Illegal transactions | Sale of illegal goods or services |
Chapter 6. Audits, rule monitoring, and day-to-day compliance.
Compliance with scheme rules is an ongoing process, not a one-off project. The rulebooks change twice a year, the programs evolve, and so do your catalog and your checkout flows. Organizations that avoid fines share three habits: structured rule monitoring, a living requirements register, and internal controls that run more often than external audits.
- Scheme rule monitoring: read your acquirer’s bulletins and the twice-yearly Visa (April/October) and Mastercard releases. Threshold changes (such as the 2026 VAMP tightening) are announced months in advance.
- Requirements register: a living table that maps each applicable requirement (MCC, descriptor, brand display, high-risk registrations, PCI DSS) to its internal owner, its evidence of compliance, and the date it was last checked.
- Recurring internal controls: a quarterly review of the MCCs and descriptors actually sent, test purchases on your own checkout flows, and monthly tracking of fraud and dispute ratios by entity and by scheme.
- Peer networks: industry associations (such as the Merchant Risk Council) and your acquirer’s risk contacts share interpretations and lessons learned that the rulebooks don’t spell out.
| Enforcement | Frequency | Who | Reach |
|---|---|---|---|
| PCI DSS self-assessment or audit (SAQ / QSA) | Annual | Merchant / QSA | Card data security; version 4 of the standard has been mandatory since March 2024, and its future-dated requirements since March 2025 |
| Acquirer portfolio review | Annual to quarterly, depending on risk | Acquirer | MCCs, descriptors, websites, actual vs. declared business, ratios |
| Scheme audits and test purchases | Random and triggered by reports | Schemes and their appointed vendors | Integrity (prohibited content, laundering), brand display, transaction data |
| Merchant/PSP internal controls | Monthly to quarterly | Compliance and risk teams | Internal VAMP/ECM ratios, requirements register, checkout flow tests |
- requirement: "Accurate MCC for each merchant entity"
source: "Visa Core Rules / Mastercard Rules"
owner: "Head of acquiring"
evidence: "Acquirer contract export vs. internal registry"
last_checked: "2026-06-15"
status: compliant
- requirement: "Recognizable descriptor + dynamic suffix for subscriptions"
source: "Scheme rules + dispute feedback"
owner: "Payments team"
evidence: "Quarterly test purchases, cardholder statements"
last_checked: "2026-05-30"
status: in_progress # suffix missing on the annual plan
- requirement: "Internal dispute ratio < 0.75% (half the 2026 VAMP threshold)"
source: "Internal policy"
owner: "Risk manager"
evidence: "Monthly dashboard by scheme and by MCC"
last_checked: "2026-07-01"
status: compliant