PAYMENTS, UNPACKED. / RISK & COMPLIANCE
Visa VAMP in 2026: A Detailed Guide to Fraud, Disputes, Ratios & Merchant Monitoring
Visa's Acquirer Monitoring Program combines issuer-reported fraud, disputes, and enumeration into an acquirer-centered risk framework for card-not-present activity.
Written byDave WilsonChief Operating OfficerCard-not-present activity becomes network risk data.
Visa’s Acquirer Monitoring Program changed the way fraud and disputes are measured for card-not-present merchants.
The biggest mistake is reducing VAMP to a single number.
Yes, there is a ratio. Yes, there are published thresholds. But VAMP is fundamentally an acquirer monitoring framework, which means a merchant’s individual performance sits inside a larger acquiring portfolio that Visa is also measuring.
That distinction matters.
A merchant can be below Visa’s published Merchant Excessive threshold and still create a legitimate risk problem for its processor or acquiring bank. A merchant can also look at a traditional chargeback ratio and significantly underestimate the activity Visa is measuring because VAMP includes both issuer-reported fraud and disputes.
If you process meaningful card-not-present Visa volume, you should understand the calculation before somebody sends you a warning about it.
This guide explains how VAMP works in 2026, including:
- TC40 fraud reporting;
- TC15 disputes;
- TC05 settled transactions;
- current U.S. merchant and acquirer thresholds;
- enumeration and card testing;
- pre-dispute exclusions;
- Compelling Evidence 3.0;
- common merchant misconceptions;
- and what the acquiring side actually cares about when the numbers start moving.
What Is Visa VAMP?
VAMP stands for the Visa Acquirer Monitoring Program.
Visa designed the current program to consolidate several legacy fraud and dispute monitoring programs into one broader framework focused on three major risk areas:
- fraud;
- disputes; and
- enumeration.
The program is primarily directed at acquirers—the financial institutions responsible for acquiring Visa transactions and overseeing the merchants and third parties operating beneath their Visa relationship.
That structure is important.
A merchant typically does not have a direct operational relationship with Visa for VAMP management. Its processor, ISO, payment facilitator, or acquiring bank sits between the merchant and the network.
Visa monitors VAMP performance monthly and identifies acquirers or merchants exceeding applicable thresholds. Visa’s public rules also permit it to require an acquirer or merchant to deploy remediation tools or technologies when unusual activity is identified.
The VAMP Ratio in Plain English
Visa’s core VAMP metric is a count-based ratio covering domestic and cross-border card-not-present VisaNet transactions.
The formula is:
VAMP Ratio = (TC40 Fraud Reports + TC15 Disputes) ÷ TC05 Settled Card-Not-Present Transactions
| Visa record | What it represents | Role in VAMP |
|---|---|---|
| TC40 | Issuer-reported fraud | Numerator |
| TC15 | Dispute activity | Numerator |
| TC05 | Settled transaction activity | Denominator |
This is why calling VAMP a “chargeback ratio” is misleading.
It isn’t one.
TC40 Fraud Is Not the Same Thing as a Chargeback
A TC40 fraud advice is generated when an issuer has reason to believe a Visa transaction was fraudulent.
That does not automatically mean a formal dispute has already occurred.
Visa has separately explained that a fraud advice may later be followed by a fraud dispute. In other words, fraud reporting and dispute processing are related, but they are not the same network event.
VAMP measures both.
Visa also changed the current program so that TC15 disputes can contribute to the VAMP metric, rather than looking only at fraud-related dispute activity.
That creates an important operational problem for merchants.
If your dashboard only shows formal chargebacks, you may be looking at only part of what Visa is evaluating.
One Transaction Can Create Two VAMP Events
This is one of the most important parts of VAMP for merchants to understand.
Suppose a cardholder reports a transaction as fraudulent.
The issuer reports that transaction through TC40 fraud reporting.
That creates one fraud event in the VAMP numerator.
If the same underlying transaction subsequently becomes a formal dispute or chargeback, it can also generate a TC15 dispute event.
That means one purchase can contribute:
1 TC40 fraud event
plus
1 TC15 dispute event
for a total of:
2 VAMP events
Visa's VAMP formula does not attempt to reduce those two network events back to one underlying purchase. Fraud reporting and dispute activity are separately measured signals, so both can contribute to the numerator.
This is why simply counting chargebacks can significantly understate a merchant's VAMP exposure.
Example
Assume a merchant has one $100 ecommerce transaction.
The cardholder reports it as fraud.
TC40 Fraud Report → 1 VAMP event
The issuer later processes a dispute on that same transaction.
TC15 Dispute → 1 additional VAMP event
The result is:
One transaction. Two VAMP events.
The dollar amount of the original purchase does not change that count.
VAMP is fundamentally event-count based, not based on the dollar value of the underlying transaction.
The Double Count Can Also Matter Financially
The double count matters for more than the ratio.
When applicable VAMP per-event assessment conditions are in effect, TC40 fraud reports and TC15 disputes are separate network events. If the same underlying transaction generates both, it can therefore contribute two VAMP events and can also create two separately assessable events under the applicable VAMP fee structure.
There is an important distinction here: Visa’s program relationship and assessments are directed to its Member/acquirer. Whether and how an acquiring institution, processor, payment facilitator, or ISO passes an applicable assessment through to a merchant depends on the acquiring relationship, merchant agreement, and current fee schedule.
So the safe operating assumption is not “one bad sale equals one VAMP fee.” It is that one underlying sale can generate two separately measured VAMP events, and when applicable event-based assessments are being passed through, those two events can also create two merchant-billed assessment items.
Do not publish a fixed dollar amount in this article unless the amount is separately verified against the current applicable fee schedule at the time of publication.
A Realistic VAMP Calculation
Assume an ecommerce merchant has this monthly Visa card-not-present activity:
| Metric | Count |
|---|---|
| Settled Visa CNP transactions | 100,000 |
| TC40 fraud reports | 1,050 |
| TC15 disputes | 550 |
| Combined VAMP events | 1,600 |
The calculation is:
1,050 + 550 = 1,600
Some of those events may originate from the same underlying transactions.
Then:
1,600 ÷ 100,000 = 0.016
Or:
1.60%
In basis points:
160 bps
Now compare that with a merchant looking only at disputes:
550 ÷ 100,000 = 0.55%
Those are dramatically different numbers.
A merchant looking at a 0.55% dispute ratio might believe things are under control.
Visa’s combined VAMP measurement in this example is 1.60%.
What Does “Basis Points” Mean?
Payments professionals frequently discuss ratios in basis points, abbreviated as bps.
One basis point equals 0.01 percentage point.
| Basis points | Percentage |
|---|---|
| 25 bps | 0.25% |
| 50 bps | 0.50% |
| 70 bps | 0.70% |
| 100 bps | 1.00% |
| 150 bps | 1.50% |
| 200 bps | 2.00% |
| 2,000 bps | 20.00% |
If someone tells you your VAMP ratio is “85 basis points,” they mean 0.85%.
Current U.S. VAMP Thresholds in 2026
For the U.S., Visa’s current public VAMP fact sheet establishes the following key thresholds.
Acquirer Portfolio Thresholds
Above Standard: ≥ 50 bps / 0.50%
Excessive: ≥ 70 bps / 0.70%
Visa also applies a minimum monthly fraud-and-dispute count of 1,500 in the U.S. for these acquirer identification levels.
Merchant Excessive Threshold
For the U.S., the Merchant Excessive ratio was reduced to:
≥ 150 bps / 1.50%
effective:
April 1, 2026
The published monthly count criterion is:
≥ 1,500 fraud + dispute events
One detail is easy to miss when reading Visa’s public fact sheet: the main AP/Canada/EU/U.S. merchant-threshold table still displays 220 bps, while the corresponding footnote states that the Excessive Merchant threshold was reduced to 150 bps effective April 1, 2026. For a current U.S. article, 150 bps / 1.50% is the operative figure to explain.
There is an important qualification that deserves more attention than it usually gets:
Visa’s public fact sheet states that the Merchant Excessive performance threshold applies when the acquirer itself is not already identified as Above Standard or Excessive.
That tells you something important about how the program is designed.
VAMP is not simply Visa checking thousands of merchants independently against one universal 1.50% line.
It is an acquirer-centered risk framework.
Why 1.50% Is Not a Good Target
This is probably the most important practical point in the article.
A merchant should not look at the 1.50% Merchant Excessive threshold and conclude:
“As long as we stay at 1.49%, we’re fine.”
That misses how acquiring works.
The acquiring bank is responsible for the performance of its broader portfolio.
Its published Visa thresholds are 0.50% and 0.70%, not 1.50%.
That creates a very different incentive.
If I am managing acquiring risk, I do not want to wait until an individual merchant reaches 1.50% before asking what is going wrong.
A merchant performing significantly worse than the rest of the portfolio can:
- increase the acquirer’s overall ratio;
- create avoidable fraud losses;
- increase dispute workload;
- attract network scrutiny;
- consume risk-management resources;
- and worsen the economics of the relationship.
That is why processors and acquiring banks frequently maintain merchant-level risk tolerances that are more conservative than a card network’s formal excessive-performance threshold.
Visa itself tells merchants to discuss their VAMP performance with their acquirer and understand how the acquirer’s portfolio performance affects them. Visa also recognizes that acquirers may maintain their own risk-assessment parameters.
What If the Ratio Is High but the Count Is Low?
Suppose a merchant processes 10,000 settled Visa CNP transactions and generates 120 TC40 fraud reports plus 80 TC15 disputes.
The VAMP ratio is:
200 ÷ 10,000 = 2.00%
That is well above the 1.50% U.S. Merchant Excessive ratio.
But the merchant has only 200 combined events, not 1,500.
Based on Visa’s published merchant criteria, it does not meet the published 1,500-count component of that Merchant Excessive threshold.
That does not mean the merchant has healthy fraud and dispute performance.
It means something much narrower: the merchant has not reached the published event-count criterion for that particular VAMP identification threshold.
An acquirer may still be concerned about a merchant running at 2.00%.
And it probably should be.
Especially if the trend is increasing, concentrated in one product, linked to a new marketing channel, producing actual financial loss, accompanied by enumeration, or beginning to affect the acquiring portfolio.
A network threshold is not a risk appetite.
VAMP Also Measures Enumeration
Fraud and disputes are only part of VAMP.
Visa also monitors enumeration, commonly called card testing, account testing, BIN testing, or credential testing.
Enumeration occurs when criminals use automated activity to test combinations of payment credentials in order to determine whether account information is valid.
Typical fields being tested can include card number, expiration date, CVV2, billing information, or combinations of those values.
Visa describes enumeration as automated, scalable account testing and has identified it as a material source of downstream fraud and operational cost.
The Enumeration Ratio Uses a Completely Different Denominator
This is where merchants can get confused.
The normal VAMP fraud-and-dispute formula uses settled card-not-present transactions as its denominator.
Enumeration does not.
Visa defines the VAMP Enumeration Ratio as:
Enumerated Authorization Transactions — Approved + Declined
divided by
Total Authorization Transactions — Approved + Declined
Visa publishes an enumeration ratio threshold of:
2,000 bps / 20%
and an enumerated transaction count threshold of:
300,000 authorization transactions
That difference makes sense.
A card-testing attack can generate enormous authorization volume while settling almost nothing.
The attacker does not necessarily care about buying something from your website.
Your checkout is being used as a tool to test payment credentials.
Enumeration Example
Assume a merchant receives 1,500,000 Visa authorization attempts during the month.
Visa identifies 350,000 as enumerated authorization transactions.
The calculation is:
350,000 ÷ 1,500,000 = 23.33%
The merchant is now above both the published 20% enumeration ratio and the published 300,000 transaction count.
Notice what we never needed to calculate: chargebacks.
A merchant can have a serious enumeration problem before traditional chargeback reporting makes the problem obvious.
What Enumeration Looks Like Operationally
Card testing is not always just thousands of $1 transactions.
Fraudsters adapt.
Warning signs can include:
- sudden authorization-volume spikes;
- unusually high decline rates;
- repeated attempts against similar card ranges;
- rapid-fire attempts from the same IP address;
- multiple cards associated with a single device;
- repeated CVV failures;
- abnormal transaction velocity;
- large numbers of low-dollar authorizations;
- unusual geographic patterns;
- automated checkout behavior;
- or attempts occurring at times inconsistent with normal customer behavior.
Visa recommends layered controls and monitoring signals such as authorization velocity, BIN spikes, response-code patterns, checkout automation controls, and other transaction and session indicators when investigating enumeration activity.
This is why fraud monitoring should not begin after settlement.
Some of your most important risk signals exist during the authorization attempt.
What Is Excluded From the VAMP Ratio?
Visa’s public VAMP fact sheet identifies two particularly important exclusions.
1. Qualifying Pre-Dispute Resolutions
Visa states that disputes resolved through applicable pre-dispute solutions can be excluded from the VAMP ratio, subject to the timing of Visa’s data extract.
The timing qualification matters.
Merchants should not assume that every alert, refund, or dispute-management workflow automatically removes an event from VAMP.
The solution and timing have to qualify under the relevant Visa process.
2. Qualifying Compelling Evidence 3.0 Fraud
Visa also states that TC40 fraud qualifying for Compelling Evidence 3.0 can be excluded, again subject to timing.
Visa’s public CE3.0 materials explain how qualifying historical transaction evidence can support applicable card-absent fraud disputes.
That is a meaningful benefit.
But it should not turn into the wrong strategy.
You Cannot Dispute-Manage Your Way Out of Every VAMP Problem
Pre-dispute tools are useful.
Compelling Evidence can be useful.
Representment is useful when a dispute is invalid and the merchant has good evidence.
But those tools operate at different points in the transaction lifecycle.
A merchant generating actual third-party fraud has a fraud-prevention problem.
A merchant experiencing heavy card testing has an enumeration problem.
A subscription business creating customer confusion may have a billing and customer-experience problem.
A merchant failing to deliver products may have a fulfillment problem.
A business with an unrecognizable descriptor may have a transaction-recognition problem.
All of those issues can eventually show up in dispute data.
They do not all have the same solution.
Friendly Fraud and First-Party Misuse
Some fraud claims involve a criminal using stolen payment credentials.
Others do not.
A legitimate customer may complete a transaction and later claim the purchase was unauthorized or otherwise dispute the transaction.
The industry commonly refers to this as friendly fraud, first-party misuse, or first-party fraud.
Recurring and subscription models are particularly exposed to this type of confusion.
A customer may forget signing up, fail to recognize the billing descriptor, misunderstand a free-trial conversion, believe a cancellation was completed, forget an annual renewal, allow another household member to make the purchase, or simply decide they no longer want the transaction.
Visa has continued expanding dispute tools aimed partly at transaction recognition and first-party misuse.
That means merchants should not treat every VAMP problem as a stolen-card problem.
Customer Operations Can Be a Fraud-and-Dispute Control
This sounds simple, but it matters.
A merchant can invest heavily in fraud technology and still generate unnecessary disputes because its customer experience is poor.
Unrecognizable billing descriptors
The customer sees a business name on the statement that does not match the brand it remembers purchasing from.
Slow refunds
A customer expects money back, does not see the refund quickly enough, and contacts the issuer.
Difficult cancellation
The customer cannot easily determine whether a subscription has actually been cancelled.
Poor fulfillment communication
An order is delayed without notice, so the customer assumes something has gone wrong.
Unclear recurring terms
The customer does not understand when or how often they will be charged.
Weak customer service
The cardholder contacts the issuer because contacting the merchant feels harder.
These are operational failures that eventually become payment-risk data.
What Merchants Should Monitor Internally
If the first time you calculate VAMP is after your processor contacts you, your monitoring process is late.
At minimum, a meaningful CNP merchant should understand the following every month:
| Metric | Why it matters |
|---|---|
| Visa CNP settled transaction count | VAMP denominator |
| TC40 fraud reports | VAMP numerator |
| TC15 disputes | VAMP numerator |
| TC40 / TC15 overlap | Shows how often the same underlying transaction is producing both fraud-reporting and dispute events |
| Combined fraud + dispute count | Threshold monitoring |
| Estimated VAMP ratio | Performance monitoring |
| Month-over-month trend | Direction of travel |
| Enumeration count | Card-testing exposure |
| Enumeration ratio | Card-testing exposure |
| Pre-dispute resolutions | Dispute prevention |
| Refund activity | Potential service issues |
| Authorization decline rate | Potential fraud/enumeration signal |
But the aggregate ratio is only the first layer.
When the ratio moves, break it down.
Segment the Problem Before You Try to Fix It
Useful dimensions include product, SKU, service type, website, sales channel, affiliate, marketing campaign, recurring vs. one-time billing, card BIN, issuer, geography, device, IP, authorization response, transaction amount, customer tenure, fulfillment method, refund status, dispute category, and acquisition cohort.
Suppose your VAMP ratio jumps from 0.40% to 0.75%.
That tells you there is a problem.
It does not tell you what the problem is.
Now suppose you discover 82% of the incremental fraud came from one paid-social acquisition campaign launched three weeks earlier.
That is actionable.
The right question is not:
“Why is our ratio 0.75%?”
The right question is:
“Which transaction population changed, and what changed about it?”
What the Acquiring Side Actually Cares About
A merchant sees one MID.
An acquirer sees an entire portfolio.
That difference changes the risk conversation.
When a merchant’s VAMP performance deteriorates, an acquiring risk team is not only asking whether a published Visa threshold has been crossed. It is trying to understand what is happening, how fast it is changing, how much financial and portfolio exposure it creates, and whether the merchant is capable of fixing it.
Questions we care about include:
- Is this a temporary spike or a persistent trend?
- Is the merchant growing faster than its controls?
- Is the fraud concentrated in a specific product, campaign, affiliate, geography, device population, or customer cohort?
- Are the disputes primarily fraud-related, first-party misuse, recurring-billing confusion, fulfillment, service, or another operational problem?
- Is enumeration present?
- Does the merchant understand its TC40 activity, or is it looking only at chargebacks?
- Are pre-dispute and transaction-recognition tools being used appropriately?
- Does the merchant have enough liquidity to absorb growing dispute exposure?
- Is the merchant’s activity creating material pressure on the acquirer’s portfolio-level VAMP performance?
- Is management responsive when the acquiring team requests data, controls, or a remediation plan?
The specific response will vary by acquirer and merchant agreement, but the principle is consistent: a network threshold is not the same thing as an acquiring institution’s risk appetite.
Visa’s current public rules make clear that Visa may evaluate activity at aggregated merchant and sponsored-merchant levels and may require an acquirer or merchant to deploy remediation tools or technologies to address unusual activity identified through VAMP.
That is why acquiring teams may intervene well before a merchant reaches the individual Merchant Excessive line.
What Can an Acquirer Do If Performance Deteriorates?
The exact response depends on the acquiring relationship, merchant agreement, loss exposure, business model, trend, merchant cooperation, and applicable network requirements.
Possible acquiring actions can include:
- enhanced monitoring;
- formal remediation requirements;
- tighter fraud controls;
- additional reporting;
- transaction restrictions or processing caps;
- funding changes;
- reserve increases;
- delayed settlement or other financial controls;
- enhanced underwriting or documentation requests;
- restrictions on particular channels or products; or
- in serious circumstances, termination.
Those are not automatically Visa-mandated steps.
That distinction matters.
An acquirer taking action does not necessarily mean:
“Visa required us to do this exact thing.”
It may mean:
“The acquiring institution responsible for this risk decided action was necessary before the problem became larger.”
Merchants should understand the difference between a card-network requirement and an acquirer or sponsor-bank risk decision.
Reserves and VAMP Are Related — but They Are Not the Same Thing
A reserve is an acquiring risk-control mechanism.
VAMP is a Visa network monitoring framework.
They can interact, but they are not interchangeable.
If fraud and disputes increase, the acquirer may determine that its potential financial exposure has increased as well. That can influence decisions involving:
- rolling reserves;
- fixed reserves;
- funding holds;
- delayed settlement;
- processing limits; or
- other financial-risk controls.
That does not make the reserve itself a VAMP requirement.
It means worsening fraud and dispute performance may contribute to the acquirer’s broader assessment of merchant exposure.
We cover merchant reserves separately because they deserve their own detailed explanation.
A Practical VAMP Remediation Framework
There is no single VAMP remediation checklist that works for every merchant because the same ratio can be produced by very different problems.
A practical response usually starts with five steps.
1. Reconcile the data
Confirm the settled Visa CNP denominator, TC40 count, TC15 count, known TC40/TC15 overlap, pre-dispute activity, and enumeration metrics.
If your internal numbers do not reconcile reasonably with your acquirer’s reporting, fix the visibility problem first.
2. Identify the population creating the increase
Do not stop at the company-wide ratio.
Segment the activity by product, campaign, recurring status, geography, issuer, device, transaction amount, customer tenure, fulfillment path, and other relevant dimensions.
3. Match the control to the failure
Third-party fraud may require stronger authentication, velocity, device, or fraud-screening controls. Enumeration requires authorization-layer defenses. Subscription disputes may require clearer reminders, descriptors, cancellation, and renewal handling. Fulfillment disputes may require an operations fix.
4. Measure whether the control actually changed the trend
A remediation plan is not complete because a tool was enabled.
Track the affected cohort and determine whether TC40, TC15, authorization behavior, and the combined VAMP ratio are improving.
5. Communicate before the next escalation
If your acquirer is already involved, provide specific actions, owners, dates, and measured outcomes.
“We are monitoring it” is not a remediation plan.
Match the Remediation to the Root Cause
Once the data is reconciled, the response should be specific to the failure mode.
1. Genuine third-party payment fraud
Review:
- AVS and CVV results;
- 3-D Secure strategy;
- device and identity signals;
- account-takeover indicators;
- transaction and account velocity;
- unusual transaction size or frequency;
- IP reputation and geolocation;
- card BIN and issuer concentration;
- authorization response patterns;
- manual-review rules; and
- fraud-model performance.
The objective is to stop fraudulent transactions before settlement, rather than becoming more efficient at managing disputes after the fact.
2. Enumeration or card testing
Focus on:
- request velocity;
- repeated credential attempts;
- bot detection;
- rate limiting;
- device behavior;
- IP concentration;
- repeated declines;
- low-dollar authorization bursts;
- checkout automation;
- email repetition;
- unusual BIN patterns; and
- authorization-response anomalies.
A fraudster should not be able to use your checkout as a free card-validation API.
3. Friendly fraud / first-party misuse
Review:
- billing-descriptor recognition;
- transaction details available to the customer;
- Order Insight or other applicable transaction-recognition workflows;
- Compelling Evidence eligibility;
- customer account and device history;
- fulfillment or delivery evidence;
- subscription communication;
- cancellation records;
- customer-support records; and
- applicable pre-dispute tools.
4. Service and fulfillment disputes
Examine:
- shipping promises;
- tracking;
- inventory availability;
- delivery evidence;
- product or service representations;
- refund speed;
- cancellation handling;
- customer-support response times; and
- customer communication.
A fraud solution will not fix a merchant whose customers are disputing transactions because they did not receive what they purchased.
5. Recurring billing disputes
Review:
- initial customer consent;
- trial-conversion terms;
- renewal disclosures and reminders;
- cancellation procedures;
- billing frequency;
- descriptor consistency;
- customer-service escalation; and
- account-updater and credential-on-file workflows where applicable.
Recurring billing can be extremely effective. It also needs to be extremely clear.
Common VAMP Misconceptions
“VAMP is just Visa’s new chargeback ratio.”
Incorrect.
TC40 fraud reports and TC15 disputes both feed the primary VAMP numerator, while enumeration is measured separately against authorization activity.
“One transaction equals one VAMP event.”
Incorrect.
A transaction appearing in both TC40 fraud reporting and TC15 dispute data can contribute twice to the VAMP numerator. When applicable event-based assessment conditions are in effect and those assessments are passed through under the acquiring relationship, the same underlying transaction can also create two separately billed assessment events.
“Visa allows merchants to run at 1.50%.”
Incorrect framing.
Visa publishes a Merchant Excessive program threshold. An acquirer may maintain more conservative risk parameters and may act before that threshold is reached.
“If my ratio is over 1.50%, I am automatically Merchant Excessive.”
Not necessarily.
The published U.S. merchant criteria also include an applicable monthly event-count component, and merchant threshold treatment depends on the acquirer’s VAMP status.
“We are too small to reach 1,500 events, so VAMP does not matter.”
The formal Merchant Excessive identification criteria may not be met, but a high fraud-and-dispute ratio can still be a serious acquiring-risk issue.
“If I win the chargeback, the VAMP event disappears.”
Do not assume that.
Representment outcome and VAMP event treatment are not the same concept. Qualifying pre-dispute and Compelling Evidence processes have specific treatment under Visa’s methodology, but a merchant should not assume every successfully defended dispute disappears from monitoring.
“Card testing only matters if the transactions settle.”
Incorrect.
Enumeration is authorization-based and includes approved and declined attempts.
“We just need a better fraud tool.”
Maybe. Maybe not.
If the problem is fulfillment, recurring-billing confusion, an unrecognizable descriptor, poor refund procedures, or customer service, stricter fraud rules may simply decline more good customers without solving the underlying cause.
Trend Is Often More Important Than the Snapshot
Consider two merchants.
Merchant A
Current VAMP ratio:
0.60%
Previous months:
0.24% → 0.38% → 0.60%
Merchant B
Current VAMP ratio:
0.85%
Previous months:
1.32% → 1.06% → 0.85%
Which one deserves more attention today?
Merchant B has the higher current number.
Merchant A has the worse direction.
That is why good risk management does not wait for thresholds. You monitor trajectory.
Visa reported in March 2026 that nearly half of identified acquirers improved their performance within a single quarter, and that identified acquirers collectively reduced VAMP ratios materially quarter over quarter after remediation. Visa attributed the improvement to actions including stronger merchant oversight and greater use of fraud and pre-dispute controls.
That does not mean every merchant will produce the same improvement.
The useful takeaway is simpler: remediation works when the underlying behavior changes.
Ten Questions Merchants Should Ask Their Processor or Acquirer
If you operate meaningful card-not-present Visa volume, ask:
- What is our current VAMP ratio?
- Can you provide our TC40 fraud count?
- Can you provide our TC15 dispute count?
- What settled Visa CNP transaction count are you using as the denominator?
- How much TC40/TC15 overlap are you seeing on the same underlying transactions?
- What month-over-month trend are you seeing?
- Are we experiencing enumeration activity?
- What internal thresholds do you use before Visa’s formal Merchant Excessive threshold?
- How do qualifying pre-dispute resolutions and Compelling Evidence affect our reporting?
- If our performance continues to deteriorate, what remediation would you expect from us and is our activity materially affecting the acquiring portfolio?
Those questions will tell you considerably more than:
“What’s my chargeback ratio?”
Frequently Asked Questions
What is the Visa VAMP ratio?
For the primary fraud-and-dispute metric, Visa calculates the count of TC40 fraud reports plus TC15 disputes divided by the count of settled card-not-present transactions reported through TC05.
What is the U.S. Merchant Excessive VAMP threshold in 2026?
Visa’s current public fact sheet states a U.S. Merchant Excessive ratio of 150 basis points, or 1.50%, effective April 1, 2026, with an applicable monthly fraud-and-dispute count criterion of 1,500. The fact sheet also states that this merchant threshold applies when the acquirer is not already identified as Above Standard or Excessive.
Can the same transaction count twice in VAMP?
Yes.
If the underlying transaction appears as a TC40 fraud event and later as a TC15 dispute event, both network events can contribute to the VAMP numerator.
Can one transaction also create two VAMP-related assessment items?
It can when applicable per-event assessment conditions are in effect and those amounts are passed through under the acquiring relationship. TC40 and TC15 are separate measured events. Visa’s program assessment relationship is with its Member/acquirer; merchant billing depends on the acquiring agreement and current fee schedule.
Is VAMP based on dollar volume?
The primary VAMP fraud-and-dispute ratio is count-based, not dollar-volume based. The denominator is settled CNP transaction count.
Does a chargeback dashboard show everything VAMP measures?
Usually not.
A chargeback dashboard may not expose issuer-reported TC40 fraud activity or Visa’s enumeration data, so it can materially understate what is being measured.
What is the VAMP enumeration threshold?
Visa’s public fact sheet publishes an enumeration ratio threshold of 2,000 basis points, or 20%, plus an enumerated authorization count threshold of 300,000.
Can pre-dispute resolutions reduce VAMP activity?
Qualifying disputes resolved through applicable pre-dispute solutions can be excluded from the VAMP ratio, subject to Visa’s data-extract timing and applicable program conditions.
Does Compelling Evidence 3.0 affect VAMP?
Yes, where the transaction qualifies under Visa’s applicable CE3.0 process. Visa’s public VAMP fact sheet states that qualifying TC40 fraud can be excluded from the ratio, subject to timing.
Does 3-D Secure automatically remove a transaction from VAMP?
No blanket exemption should be assumed. 3-D Secure can be an important authentication and fraud-control tool, but its use does not mean future fraud or dispute activity is automatically excluded from VAMP.
Can my processor or acquirer act before I reach 1.50%?
Yes.
An acquiring institution can maintain risk policies that are more conservative than Visa’s Merchant Excessive threshold and can act based on its own portfolio exposure, contractual rights, and risk appetite.
VAMP Is Really a Transaction-Quality Metric
I do not think merchants should treat VAMP as another compliance acronym.
Used correctly, it tells you something about the quality of the transactions moving through your business.
Ask:
Who is attempting the transaction?
Should it have been authorized?
Did it settle?
Did the customer understand the charge?
Did the merchant deliver what was promised?
Did the customer contact the merchant before contacting the issuer?
Was the transaction actually fraudulent?
Could the event have been prevented earlier?
When those answers deteriorate, the VAMP ratio eventually follows.
The best time to address fraud and dispute performance is not when the merchant crosses a published threshold.
It is when the underlying behavior changes.
Concerned About Rising Fraud or Dispute Activity?
Mentom Payments works with card-not-present merchants to evaluate payment flows, fraud controls, dispute visibility, transaction signals, and the operational processes surrounding payment risk.
If your fraud or dispute activity is moving in the wrong direction, the first step is understanding why.
Related Mentom resources can also help with online payments, payment security, recurring billing, integrated payments, and payment processing.
PRIMARY DOCUMENTATION
Sources &
References
Public Visa materials only. No competitor or confidential source is included.
Mentom prioritizes primary card-network and standards-body documentation for technical articles. For this article, publish only public Visa materials.
- Visa — Visa Acquirer Monitoring Program Overview / Fact Sheet. Primary reference for the current VAMP formula, merchant thresholds, acquirer thresholds, minimum counts, enumeration criteria, pre-dispute treatment, and Compelling Evidence treatment. https://corporate.visa.com/content/dam/VCOM/corporate/visa-perspectives/security-and-trust/documents/visa-acquirer-monitoring-program-fact-sheet-2025.pdf
- Visa — Visa Core Rules and Visa Product and Service Rules, April 2026 public edition. Public rules covering VAMP identification, aggregated/sponsored-merchant evaluation, and Visa’s authority to require remediation tools or technologies. https://usa.visa.com/dam/VCOM/download/about-visa/visa-rules-public.pdf
- Visa — New Security Program Refresh Takes Aim at Payments Fraud. Public explanation that the updated ratio incorporates disputes and that all TC40 fraud reports are counted in the new ratio. https://corporate.visa.com/en/sites/visa-perspectives/security-trust/security-program-takes-aim-payments-fraud.html
- Visa — Modernizing Payment Security: Evolving the Visa Acquirer Monitoring Program. Public discussion of merchant/acquirer monitoring, the 1,500 minimum VAMP count, portfolio context, early warnings, pre-dispute tools, and CE3.0. https://corporate.visa.com/en/sites/visa-perspectives/security-trust/visa-vamp-program-update-fraud-disputes.html
- Visa — Anti-Enumeration and Account Testing Best Practices for Merchants. Public merchant guidance on enumeration behavior, attack patterns, and mitigation. https://usa.visa.com/content/dam/VCOM/global/support-legal/documents/anti-enumeration-and-account-testing-best-practices-merchant.pdf
- Visa — Evolution of Compelling Evidence — Client FAQs. Public FAQ describing qualifying pre-dispute and Compelling Evidence treatment. https://usa.visa.com/content/dam/VCOM/regional/na/us/support-legal/documents/evolution-of-compelling-evidence-external-faqs.pdf
- Visa — Post-Purchase Solutions for Merchants. Public information on transaction recognition, pre-dispute resolution, and Compelling Evidence. https://usa.visa.com/solutions/post-purchase-solutions/merchants.html
- Visa — What’s Possible When the Payments Ecosystem Moves Together on Security. March 2026 public update describing early VAMP remediation and portfolio-performance trends. https://corporate.visa.com/en/sites/visa-perspectives/security-trust/visa-acquirer-monitoring-program-momentum.html

ABOUT THE AUTHOR
Dave Wilson
Chief Operating Officer, Mentom PaymentsDave leads the systems and operating infrastructure behind merchant acquiring—including risk, underwriting, compliance, payment operations, automation, APIs, data, and partner workflows.
With more than 15 years of experience building and scaling ISO and payment-facilitation programs, Dave writes about how payments actually work behind the scenes.
View all articles by Dave →Mentom Payments provides this content for general informational purposes. Payment-network rules, regulatory requirements, program standards, and acquiring policies may change and may apply differently based on business model, region, processing relationship, and other circumstances. Merchants should confirm requirements applicable to their specific situation.
