Reference🧭 Global overviewsIntermediate⏱ 24 min read

⚖️ Chargebacks and disputes around the world

Visa VCR and Mastercard Mastercom rules, reason code and time limit mapping, Regulation E and Regulation Z in the US, PSD2 in Europe, alternative recourse on instant payment rails, and the VAMP and ECM monitoring thresholds

A network rule, not a universal right

A chargeback is an issuer’s right to reverse a card transaction against the acquirer and recover its amount. It is a network rule, grounded in the contract that binds both institutions to the scheme, and it gives the cardholder no legal claim. Visa codifies it in the Visa Core Rules and Visa Product and Service Rules, Mastercard in its Chargeback Guide. The merchant is party to neither document, yet it bears their full effect, which its acquirer passes on by contract.

Each jurisdiction layers its own law on top of this contractual base. In the US, two separate regimes protect the cardholder, depending on whether the purchase was paid by debit or by credit. In the European Economic Area (EEA), PSD2 requires a prompt refund and sets the burden of proof. Elsewhere, the network rulebook is often the only enforceable reference. A merchant that accepts payments in several markets is therefore subject to two layers of rules, and the stricter one governs how each dispute is handled.

MarketLegal basisCardholder filing deadlineReach
US, debit cardRegulation E (12 CFR Part 1005), implementing the Electronic Fund Transfer Act60 days after the statement showing the transaction is sentUnauthorized transactions and processing errors
US, credit cardRegulation Z (12 CFR Part 1026), implementing the Truth in Lending Act and the Fair Credit Billing Act60 days after the first statement showing the errorBilling errors, plus claims and defenses against the merchant (§ 1026.12(c))
European Economic AreaDirective (EU) 2015/2366 (PSD2), Articles 71 to 7413 months after the debit dateUnauthorized, non-executed, or defectively executed transactions
United KingdomConsumer Credit Act 1974, section 75, for credit; network rules otherwiseNo time limit specific to section 75Credit purchases from £100 to £30,000, with the lender jointly liable
IndiaReserve Bank of India, Harmonisation of Turn Around Time circular, September 20, 2019; NPCI rules45 days for a UPI chargebackTechnical failure, failure to credit, automatic reversal with compensation
BrazilBanco Central do Brasil’s Mecanismo Especial de Devolução (MED, special refund mechanism), for Pix80 daysFraud, scams, and coercion on instant transfers
Rest of the worldVisa and Mastercard rules only120 days in general, up to 540 days in specified casesWhatever the rulebook provides, nothing more
The basis for cardholder recourse, market by market
🔑
One purchase, two regimes
A US cardholder who disputes a credit card purchase sets off two parallel processes. The Regulation Z billing error procedure is a right the cardholder can assert against the issuer, and it sets the investigation timeline the issuer must follow. The network chargeback targets the merchant, through its acquirer, and determines who ultimately bears the loss. The two processes conclude separately. A merchant that wins representment at the network level may still see its customer keep the credit granted by the issuer, which then absorbs the loss.

The same dispute reason does not carry the same time limit, burden of proof, or arbiter from one card-issuing country to another. The applicable regime therefore follows the issuer, and the merchant’s home country plays only a secondary role. A store based in Singapore that sells to European cardholders faces 13-month time limits that no Singapore rule imposes on it.

The two engines: Visa Claims Resolution and Mastercom

Visa Claims Resolution (VCR) is Visa’s dispute-handling framework, which took effect in April 2018. It consolidated 22 legacy reason codes into four numbered categories and made Visa Resolve Online (VROL) the single channel between issuer, acquirer, and merchant. Since that overhaul, disputes follow one of two paths. Allocation handles categories 10 (fraud) and 11 (authorization), which Visa decides on the basis of data already in its network, with no prior exchange of documents between the parties. Collaboration handles categories 12 (processing errors) and 13 (consumer disputes), where evidence passes between the issuer, the acquirer, and the merchant.

A Visa dispute on the Collaboration path
Cardholder
Disputes the transaction with their issuer
Stated reason: merchandise not received, service not as described, credit not processed
Issuer
Classifies the reason in VROL
Selects a category 12 or 13 code; Visa checks eligibility and timing before accepting the case
Visa
Routes the case to the Collaboration path
A request for information (*inquiry*) may precede the formal chargeback
Acquirer and merchant
Respond within the time limit
VCR cut the response time from 45 to 30 days; the PSP almost always sets a shorter internal deadline
Issuer
Accepts the representment or moves to pre-arbitration
Pre-arbitration is the last exchange between the parties before Visa rules
Visa
Arbitrates and bills for the decision
The losing party pays the arbitration fee, regardless of the disputed amount

Mastercard carried out the same consolidation in stages between 2018 and 2020, under the name Mastercard Dispute Resolution Initiative. Its platform for exchanges between institutions is called Mastercom. The number of reason codes was cut in favor of four broad families, each divided into sub-reasons. Pre-arbitration is a mandatory step that the parties must complete before any arbitration. One rule of the initiative bars the acquirer, when responding to a 4837 reason code, from introducing data absent from the original authorization message.

VisaMastercard
PlatformVisa Resolve Online (VROL)Mastercom
Major overhaulVisa Claims Resolution, April 2018Mastercard Dispute Resolution Initiative, 2018–2020
Reason code families10.x fraud, 11.x authorization, 12.x processing errors, 13.x consumer disputes4837 no cardholder authorization, 4808 authorization, 4834 point-of-interaction error, 4853 cardholder dispute
Processing pathsAllocation (network decision) and Collaboration (evidence exchange)Single path, with mandatory pre-arbitration before arbitration
Acquirer response time30 days45 days
Evidence built in advanceCompelling Evidence 3.0, in effect since April 18, 2023Data that does not match between authorization and clearing is rejected
Visa and Mastercard: two dispute resolution architectures
⚠️
Compelling Evidence 3.0: evidence is prepared before the dispute
Since April 18, 2023, a merchant can have a Visa 10.4 fraud dispute reclassified as a commercial dispute. It must produce two undisputed transactions made with the same payment credentials, dated 120 to 365 days before the disputed transaction. The IP address or device fingerprint must match across all three transactions. A second data element must match as well: IP address, device fingerprint, customer account ID, or shipping address. These elements can only be captured at the time of each purchase, and nothing reconstructed later can stand in for them. A merchant that has not logged them transaction by transaction cannot use the program, however strong the rest of its case.
  • The network deadline is not the PSP deadline: an acquirer with 30 days to respond to Visa commonly gives its merchants 7 to 14, to leave time for review.
  • No response means forfeiting the case: the dispute closes in the issuer’s favor, with no further recourse.
  • Arbitration fees do not depend on the amount: taking a low-value dispute all the way to arbitration often costs more than the loss it avoids.
  • The authorization code must match: at both networks, any discrepancy between the authorization message and the clearing presentment is enough to defeat a representment.

Reason codes and time limits: the mapping table

The reason code is the identifier the issuer uses to classify the grievance behind a dispute, and it determines both the applicable time limit and the evidence required. Each network maintains its own code set, so an international merchant receives the same grievances under different codes. Mapping the taxonomies is a prerequisite for any performance measurement: a representment win rate can only be split between fraud and non-delivery once the codes are grouped into common families. The table below maps these families across the two global networks.

Card typeVisaMastercardCardholder time limitWhat the acquirer must provide
Fraud, card not present10.4 Other Fraud — Card Absent4837 No Cardholder Authorization120 daysProof linking the cardholder to the order: CE 3.0, 3DS authentication, account history
Fraud, card present10.1 to 10.3, including EMV liability shifts4870 and 4871, chip and chip-and-PIN liability shifts120 daysFull EMV data, cryptogram, entry mode, PIN verification
Authorization11.1 Card Recovery Bulletin, 11.2 Declined Authorization, 11.3 No Authorization4808 Authorization-related Chargeback120 daysAuthorization code, timestamp, authorized amount, match with the presentment
Processing error12.1 to 12.7: late presentment, incorrect currency, duplicate processing, incorrect amount4834 Point-of-Interaction Error120 daysProof of a single, correct, timely presentment
Commercial dispute13.1 to 13.9: merchandise not received, not as described, credit not processed, canceled subscription4853 Cardholder Dispute120 days from the expected delivery date; up to 540 days for delayed delivery or interrupted serviceProof of delivery, product description, accepted terms and conditions, refund record
Reason code mapping between Visa and Mastercard
ℹ️
The clock rarely starts on the purchase date
For a commercial dispute, the clock starts on the expected delivery date, not the transaction date. An annual subscription sold in January and cut off in November can therefore still be disputed. Both networks extend the time limit to as much as 540 days when the service was to be delivered long after payment, or when a prepaid service stops being provided. The exposure is concentrated in travel, events, training, multiyear subscriptions, and gyms.

Beyond Visa and Mastercard, every network keeps its own procedure. American Express Company has run a three-party model since 1958, in which issuer and acquirer are the same entity, so disputes are settled internally, with no arbitration between two banks. Three other networks each publish their own reason codes. JCB Co., Ltd. has operated in Japan since 1961, UnionPay (中国银联) in China since 2002, and Discover Network in the US since 1985. Discover came under the control of Capital One Financial Corporation on May 18, 2025.

Domestic schemes add another layer, often invisible from an international PSP’s dashboard. Elo has been operated in Brazil by Elo Serviços S.A. since 2011, RuPay by NPCI in India since 2012, and TROY by BKM in Turkey since its launch in 2016. Then come BC Card in South Korea since 1982, Bancontact in Belgium since 1979, girocard in Germany since 1990, Dankort in Denmark since 1983, and Mir in Russia since 2015. Their dispute rules sit in local rulebooks, separate from those of the global networks, and part of the dispute risk only becomes visible by reading them.

  • Measure win rates by reason code, not in aggregate: an overall rate of 30% can hide 60% on non-delivery and 5% on unauthenticated fraud.
  • Normalize codes into an internal taxonomy: without a mapping table, comparisons across networks and countries are meaningless.
  • Check when the clock started before treating a dispute as time-barred: the expected delivery date takes precedence over the purchase date.
  • Handle domestic schemes separately: their time limits and evidence requirements differ, and their volume is concentrated in a few markets.

US: Regulation E and Regulation Z

US federal law splits disputes between two separate regimes, depending on the payment method used. Regulation E (12 CFR Part 1005) implements the Electronic Fund Transfer Act and covers debit cards, prepaid cards, and consumer electronic fund transfers. Regulation Z (12 CFR Part 1026) implements the Truth in Lending Act and the Fair Credit Billing Act. It covers credit, including credit cards. The same purchase from the same merchant therefore carries a different liability cap for the cardholder, and a different investigation deadline for the institution, depending on whether the card is debit or credit.

Regulation E (debit)Regulation Z (credit)
TriggerUnauthorized transaction or error on an electronic transferBilling error, including unauthorized use of the card
Notice deadline60 days after the statement showing the transaction is sent60 days after the first statement showing the error, in writing
Cardholder liability cap$50 if reported within 2 business days; $500 after that; unlimited after 60 days$50 regardless of when the loss is reported (§ 1026.12(b))
Institution’s investigation deadline10 business days, or 45 calendar days with provisional creditAcknowledgment within 30 days; resolution within two billing cycles, 90 days at most
Extended cases20 business days for accounts open less than 30 days; 90 calendar days for point-of-sale transactions, transactions initiated outside the US, and new accountsNo extension provided
Recourse against the merchantNone under Regulation EClaims and defenses that can be asserted against the issuer (§ 1026.12(c)), subject to amount and location conditions
Two regimes, two levels of protection
Day 0
The cardholder reports the transaction
A phone call is enough; the institution can require written confirmation within 10 business days to keep the provisional credit in place.
Business day 10
Short investigation ends
The institution completes its investigation, or credits the account provisionally and extends it.
Calendar day 45
Extended investigation ends
Standard deadline with provisional credit. It rises to 90 calendar days for point-of-sale transactions, transactions initiated outside the US, and accounts open less than 30 days.
Business day 48
Results notice
The institution reports its findings within 3 business days after closing the investigation and must explain any denial.
⚠️
*Zero liability* is not the law
Visa and Mastercard advertise zero cardholder liability for fraudulent use. That guarantee is a network business policy, more generous than the law and subject to conditions: prompt reporting, no negligence, and exclusion of certain business or non-network transactions. The legal floor remains Regulation E or Regulation Z. A disputes team that mistakes the commercial guarantee for the applicable standard underestimates how often the cardholder actually bears the loss for failing to meet one of the network’s conditions.

One whole category falls outside both regimes: scams in which the account holder authorizes the payment. In December 2024, the CFPB sued Early Warning Services, LLC, which has operated Zelle since 2017, along with Bank of America, JPMorgan Chase, and Wells Fargo. The case was dismissed with prejudice on March 5, 2025. No federal rule currently requires reimbursement of authorized-payment scams in the US. The UK and Singapore took the opposite approach: the UK with mandatory, capped reimbursement, Singapore with compensation when the financial institution or the telecom operator falls short.

Europe: PSD2 and what replaces it

Directive (EU) 2015/2366, known as PSD2, governs disputes over payment transactions across the European Economic Area. It deals with the relationship between the payer and its payment service provider, whatever the rail, and never uses the concept of a chargeback. Its sequence is the reverse of the one network rules follow: the provider refunds first, then investigates.

  • Article 71. The user must report the transaction without undue delay, and no later than 13 months after the debit date. After that, the claim is inadmissible.
  • Article 72. The burden of proof lies with the provider. A record of the instrument’s use is not enough to prove that the transaction was authorized.
  • Article 73. The provider refunds immediately, and no later than the end of the following business day after noting or being notified of the transaction, restoring the account to its prior state.
  • Article 74. The payer may bear up to €50 of losses from a lost, stolen, or misappropriated instrument. The payer bears nothing if they acted without fraud or gross negligence.
  • Article 76. An authorized direct debit in euros carries an unconditional right to a refund for 8 weeks after the debit.
  • Article 77. The provider has 10 business days to refund the direct debit or justify its refusal.
🔑
The D+1 refund changes the sequence
A European issuer that receives a dispute over an unauthorized transaction must refund before investigating, unless it has reasonable grounds to suspect fraud by the payer and reports them to its national authority. The chargeback then becomes an after-the-fact recovery mechanism between banks, used once the customer has already been refunded. The US model works the other way around: Regulation E leaves provisional credit to the institution’s discretion, within the time limits it sets.

Strong customer authentication shifts the financial burden of fraud from one party to another. When the payer’s provider does not require it, the payer bears no financial consequences unless they acted fraudulently. When the payee or its provider does not support it, that party must compensate the payer’s provider. A European merchant that skips 3DS to protect its conversion rate therefore keeps the cost of the fraudulent transactions it accepts.

The Instant Payments Regulation, Regulation (EU) 2024/886, added another piece. It requires verification of payee before a euro credit transfer is executed. The provider compares the name given by the payer with the name linked to the IBAN and flags any mismatch before the order goes out. If it fails to run this check, it is liable for misdirected funds. Receiving instant payments has been mandatory in the euro area since January 9, 2025, and sending them since October 9, 2025.

13 months
maximum time to report a disputed transaction
Directive (EU) 2015/2366, Art. 71
D+1
deadline to refund an unauthorized transaction
Directive (EU) 2015/2366, Art. 73
8 weeks
unconditional right to a refund on an authorized SEPA direct debit
Directive (EU) 2015/2366, Art. 76
50 €
maximum amount the payer bears for a lost or stolen instrument
Directive (EU) 2015/2366, Art. 74

The package made up of PSD3 and the Payment Services Regulation builds on this framework. A provisional political agreement was reached in November 2025. The Council of the European Union circulated the final compromise texts in April 2026, with formal adoption expected within the year. Two additions bear directly on dispute handling. Victims gain a right to a refund when fraudsters impersonate their payment service provider, provided they file a police report and notify the provider without delay. A liability regime also attaches to name-IBAN verification. The compromise texts provide for transposition and application 21 months after entry into force, and 27 months for name-IBAN verification.

India, Brazil, UK, Singapore: recourse without cards

Markets where instant transfers have overtaken cards have built their own recourse channels without copying the chargeback. Three models stand out. The first grants automatic compensation when a transaction fails for technical reasons. The second sets up a fund recall process overseen by the central bank. The third requires reimbursement for victims of authorized-payment scams.

September 20, 2019
India: Reserve Bank of India TAT circular
Resolution times for failed transactions are harmonized across all authorized systems. Card transactions must be reversed automatically by D+5, with compensation of ₹100 per day of delay, credited automatically without any customer claim.
2020
India: NPCI launches UDIR
Unified Dispute and Issue Resolution automates dispute handling through API calls between the remitter bank, the beneficiary bank, and apps, replacing file exchanges.
July 25, 2024
India: UPI dispute window cut to 45 days
NPCI circular NPCI/UPI/OC No. 198 for FY 2024-25 sets a single 45-day filing window, whatever the dispute type and transaction type.
October 7, 2024
UK: mandatory reimbursement for push payment scams
The Payment Systems Regulator requires reimbursement for victims of authorized push payment (APP) fraud on Faster Payments and CHAPS, capped at £85,000 per claim, with the cost split equally between the sending and receiving providers.
December 16, 2024
Singapore: Shared Responsibility Framework
The MAS and the IMDA impose anti-phishing obligations on financial institutions and telecom operators, with compensation for customers when they fall short. The framework sets no liability cap and does not cover business customers.
September 1, 2026
Brazil: MED dispute window extended from 30 to 80 days
BCB Normative Instruction No. 766 and version 8.5 of the DICT manual give the debited payee the same time limit as the victim, and add a way to trace the accounts used to collect stolen funds.

Pix, operated by the Banco Central do Brasil since 2020 through the SPI infrastructure, has the most developed mechanism. The Mecanismo Especial de Devolução gives fraud victims 80 days to report the facts to their institution. The payer’s and payee’s institutions then investigate the case together. The refund is made within 96 hours of the fraud being confirmed, up to the funds still in the receiving account. The mechanism is therefore a fund recall process overseen by the central bank, and the merchant bears no liability under it.

MarketFrameworkWho paysTrigger covered
IndiaRBI TAT circular (2019) and NPCI’s UDIR (2020)The bank at fault, automaticallyTechnical failure: account debited, payee not credited
BrazilMecanismo Especial de Devolução, Banco Central do BrasilDebit from the payee’s account, up to the available balanceFraud, scams, coercion
United KingdomFaster Payments APP scams reimbursement requirement, Payment Systems RegulatorSending and receiving providers, split equallyScam that led victims to authorize the transfer themselves
SingaporeShared Responsibility Framework, MAS and IMDAFinancial institution or telecom operator that failed to meet its obligationsPhishing through a digital messaging platform
Four recourse models outside the chargeback
ℹ️
Two more regulatory responses to know
On March 17, 2023, Thailand enacted an emergency decree on preventing and suppressing technology crime. It allows financial institutions to hold a suspicious transaction on their own initiative and alert the receiving institution, without first requiring a police report. In 2025, Australia wrote a Scams Prevention Framework into Part IVF of the Competition and Consumer Act 2010. It imposes prevention and response obligations on banks, telecom operators, and digital platforms. Australia’s ePayments Code, administered by ASIC, caps the account holder’s liability for an unauthorized transaction at A$150 in the cases it covers.

Instant payment rails have no chargeback

An instant transfer is irrevocable by design: settlement becomes final within seconds, in central bank money or on a dedicated settlement account. There is therefore no unilateral reversal right equivalent to the card chargeback. All that remains is the recall request. The sending bank submits it to the receiving bank, which is free to refuse if its customer does not consent or if the funds have already left the account.

RailOperatorSinceAvailable recourse
PixBanco Central do Brasil, through the SPI infrastructure2020MED: report within 80 days, refund within 96 hours of fraud confirmation
UPINational Payments Corporation of India (NPCI)2016UPI chargeback within 45 days, handled through UDIR; automatic compensation for technical failures
PromptPayNational ITMX (NITMX), under a Bank of Thailand mandate2017Transaction hold by the institution under the 2023 emergency decree; no recall as of right
PayNowAssociation of Banks in Singapore, operated by BCS2017Compensation under the Shared Responsibility Framework if the institution falls short
QRISBank Indonesia, with the Asosiasi Sistem Pembayaran Indonesia2019Complaint to the wallet issuer; no interbank recall mechanism
DuitNowPayments Network Malaysia Sdn Bhd (PayNet)2018Complaint to the bank; no payer reversal right
Faster Payments Service (FPS)Pay.UK, with Vocalink as technical operator2008Mandatory scam reimbursement, capped at £85,000, since October 7, 2024
SEPA Instant Credit Transfer (SCT Inst)European Payments Council for the scheme; settlement through TIPS and RT12017Recall request sent within 10 business days, answered within 10 business days; may be refused
RTP networkThe Clearing House Payments Company2017Request for return of funds between banks, with no obligation to return them
FedNow ServiceFederal Reserve Banks2023Discretionary request for return of funds between participants
ZelleEarly Warning Services, LLC2017Regulation E for unauthorized transactions; nothing for authorized-payment scams
NPP (New Payments Platform)NPP Australia, a subsidiary of Australian Payments Plus2018Scams Prevention Framework and ePayments Code obligations
What a payer can actually do, rail by rail
What replaces the chargeback on an instant rail
Payer
Reports a fraudulent or mistaken transfer to their bank
No reversal right; the bank makes a request rather than exercising a right
Issuing bank
Sends a recall request
On SCT Inst, within 10 business days of the execution date, for one of the reasons listed exhaustively in the rulebook
Receiving bank
Investigates and responds
It checks the balance, asks its customer for consent, and responds within 10 business days; refusal is a legitimate outcome
Regulator or operator
Imposes a reimbursement regime, where one exists
MED in Brazil, the PSR reimbursement requirement in the UK, the *Shared Responsibility Framework* in Singapore
Payer
Recovers the funds, or not
Without a mandatory regime, the outcome depends on the remaining balance and the payee’s cooperation
⚠️
Accepting instant payments eliminates chargebacks and the risk that comes with them
For a merchant, the absence of chargebacks removes a cost: the payment is final, with no holdback or reserve for disputes. The trade-off falls on the buyer. With no recourse, the buyer bears the full risk on a large order, with an unknown seller, or on delayed delivery, and is all the more reluctant to buy. Markets dominated by instant payments have developed other safeguards to make up for this lack of recourse. The usual forms are escrow held by the marketplace, cash on delivery, and the platform’s contractual guarantee. Each has a cost, which weighs on sales conversion rather than on dispute handling.

Interac e-Transfer, operated by Interac Corp. in Canada since 2002, is a special case. The service feels almost instant, yet settlement runs through a deferred clearing system. Finality therefore comes later than the interface suggests. For a disputes team, this gap between perceived speed and actual settlement changes the practical recall window, and no customer screen reveals it.

Monitoring thresholds: VAMP and ECM

A monitoring program is how a network tracks the frequency of fraud and disputes at its acquirers and their merchants. It penalizes those that exceed the published thresholds. Visa merged three such programs into a single global framework, the Visa Acquirer Monitoring Program, which absorbs the former VAMP, the Visa Fraud Monitoring Program, and the Visa Dispute Monitoring Program. Its thresholds have applied since June 1, 2025. The advisory period ended on September 30, 2025.

The program uses a single ratio, calculated by transaction count, not value. The numerator combines reported fraud and disputes, on VisaNet card-not-present transactions only, both domestic and cross-border. Two exclusions make a real difference for an active merchant. Disputes resolved through a pre-dispute solution drop out of the numerator, as does reported fraud that meets the Compelling Evidence 3.0 criteria. A merchant that invests in deflection and data logging therefore sees its ratio fall even when the number of disputes stays the same.

VAMP ratio, Visa definition
VAMP ratio = [ Fraud (TC40) + Disputes (TC15) ] / Settled transactions (TC05)

scope        : VisaNet card-not-present transactions, domestic and cross-border
unit         : basis points (bps), counted by number of transactions
exclusions   : disputes resolved through a pre-dispute solution
               TC40 fraud eligible for Compelling Evidence 3.0
denominator  : in effect since June 1, 2025
≥ 50 bps
“Above Standard” threshold for an acquirer’s portfolio
Visa, Acquirer Monitoring Program Overview, 2025
≥ 70 bps
“Excessive” threshold for an acquirer’s portfolio
Visa, Acquirer Monitoring Program Overview, 2025
≥ 150 bps
merchant “Excessive” threshold in Asia Pacific, Canada, the EU, and the US since April 1, 2026, down from 220 bps
Visa, Acquirer Monitoring Program Overview, 2025
≥ 1 500
monthly count of fraud and disputes below which a merchant stays out of the program (AP, Canada, EU, US, LAC)
Visa, Acquirer Monitoring Program Overview, 2025
RegionVAMP ratioMonthly volume trigger
Asia Pacific, Canada, European Union, US≥ 220 bps, lowered to ≥ 150 bps on April 1, 2026≥ 1,500 fraud and dispute cases a month
Latin America and the Caribbean≥ 150 bps≥ 1,500 fraud and dispute cases a month
Central Europe, Middle East, and Africa≥ 220 bps≥ 150 fraud and dispute cases a month and amount ≥ $75,000
Enumeration (card testing), all regionsEnumeration ratio ≥ 2,000 bps≥ 300,000 enumerated transactions, approved or declined
VAMP merchant “Excessive” thresholds by region

Mastercard uses a different design. Its Excessive Chargeback Merchant program flags a merchant that reaches, in a single month, at least 100 chargebacks and 150 basis points. The higher tier, High Excessive Chargeback Merchant, is triggered at 300 chargebacks and 300 basis points. The ratio is lagged: chargebacks in the current month are divided by the previous month’s transactions. Strong volume growth therefore lowers the ratio, while a decline raises it, without a single additional dispute.

⚠️
The real risk is not the fine
Monitoring program penalties are a significant financial burden, but they do not end acceptance. Their contractual consequences do. An acquirer exposed through its merchant portfolio first raises its reserves, then imposes a remediation plan, and finally terminates the contract if the ratio does not come down. A merchant that has lost its contract this way gets a new acquiring agreement only after several months of review, and at the cost of a higher fee rate. The network’s published threshold is a ceiling. The acquirer’s threshold is almost always lower, and it appears in the merchant agreement and rarely anywhere else.

Geographic coverage of these thresholds is still incomplete. Visa says the programs for Brazil, Chile, and India will be announced separately. These three markets are among the fastest-growing, and merchants should have their acquirer confirm the local rules that apply there before any flows go live.

Running disputes across multiple rails

A dispute operation designed for one market does not carry over as is. Time limits, evidence requirements, and the competent arbiter change from country to country. Three principles hold across all markets. The first is to stop disputes before they arise, through deflection and a clear billing descriptor. The second is to build the evidence before a case is opened. The third is to measure performance by reason code and by country, not in aggregate.

🛑
Deflection before the chargeback
Verifi, acquired by Visa in 2019, and Ethoca, acquired by Mastercard the same year, relay the issuer’s alert to the merchant before the dispute is opened. An immediate refund avoids the chargeback, its fees, and its inclusion in the monitoring ratio.
🗂️
Continuous logging
Compelling Evidence 3.0 relies on the IP address, device fingerprint, customer account ID, shipping address, and timestamp. These data points are collected on every transaction, or not at all.
🔐
Authentication and liability shift
In the EEA, a transaction authenticated with 3DS shifts fraud liability to the issuer. Outside the EEA, the shift depends on the network program and the card-issuing country. Settings are decided market by market.
🧾
Statement descriptor
An unreadable billing descriptor generates “unrecognized transaction” disputes, which arrive coded as fraud. Putting the trading name and a contact method in the descriptor eliminates a measurable share of them.
  • Dispute ratio by network and by region, expressed in the unit of the applicable program: bps of settled transactions at Visa, bps of the previous month’s transactions at Mastercard.
  • Representment win rate by reason code, not overall: it is the only metric that points to the process that needs fixing.
  • Fully loaded cost per dispute: amount, chargeback fee, representment fee, any arbitration fee, agent time, lost merchandise.
  • Share of disputes avoided at the pre-dispute stage, tracked separately. These drop out of the VAMP numerator, so they count twice.
  • The actual response window set by the PSP, contract by contract: this, not the network deadline, is what drives the team’s organization.
🔑
The question to ask for every new market
Three factors size the dispute risk in a new market. The first is the dominant payment rail, and whether it has a chargeback mechanism. The second is the local law that gives the payer recourse, with the filing deadline and burden of proof it sets. The third is the monitoring threshold the acquirer applies in that market, compared with the one the network publishes. A launch that goes ahead without these three answers postpones the question to the first spike in disputes, when there is no longer any room to act.