Visa and Mastercard Chargeback Thresholds
Visa publishes its rulebook for anyone to download, and the number that matters most is not in it.
Section 10.4.3.1 of the Visa Core Rules and Visa Product and Service Rules, 18 April 2026 edition, is titled "Visa Acquirer Monitoring Program (VAMP)." Four sentences and two bullets. It says Visa will identify an acquirer under VAMP "if it meets requirements, as specified in the Visa Acquirer Monitoring Program Guide," and that an acquirer exits the program the same way. Appendix A lists that guide under "Visa Supplemental Requirements (Enforceable Documents and Websites)," applicable in all Visa regions. Enforceable, and not in the 923-page public PDF I read on 2026-09-06.
Which tells you something before you find a single number. The threshold that can end your ability to accept cards is not in the document everyone links to.
The other two pieces on this site about card disputes are about one order: who decides a chargeback and on what clock, and what goes in the packet you send back. This one is about the pile. Nobody terminates an account over a single lost dispute. They terminate it over a ratio, and the ratio is counted in a way that will surprise you.
The Visa formula is a count, and it includes things you never saw
Visa's own fact sheet on VAMP prints the formula the rulebook leaves out:
VAMP Ratio = Count of [Fraud (TC40) + Disputes (TC15)] / Count of Settled Transactions (TC05)
That is from the Visa Acquirer Monitoring Program fact sheet, read 2026-09-06. Three things in that line matter more than the threshold does.
It is a count, not a dollar amount. A $9 dispute and a $900 dispute weigh the same. If you sell cheap items, your ratio moves faster than your losses do.
The numerator holds TC40 fraud reports, not only chargebacks. A TC40 is what an issuer files when a cardholder says a charge was fraudulent. It can exist without any money ever leaving your account. Stripe describes these as early fraud warnings and notes plainly that they "aren't disputes" but that Visa's VAMP program includes them in its calculations (Dispute and fraud card monitoring programs, read 2026-09-06). The same page adds the part that stings: a transaction appearing in both the TC40 and TC15 reports "will be counted twice for the VAMP count."
The denominator is card-not-present settled transactions only. Visa's fact sheet limits the metric to card-not-present VisaNet transactions, domestic and cross-border. If you also take payment at a market stall or a counter, that volume does not dilute anything.
Two exclusions are worth memorising because they are the only levers here that work after the fact: disputes resolved through pre-dispute solutions are excluded, and TC40 fraud that qualified for Compelling Evidence 3.0 is excluded, both "contingent on the timing of the data extract." Resolving something after the extract does not help that month.
What Visa's fact sheet actually prints
| Level being measured | Tier | VAMP ratio | Monthly count of fraud and disputes |
|---|---|---|---|
| Acquirer portfolio | Above Standard | 50 bps or more | 1,500 or more (CEMEA: 150 or more and USD 75,000 or more) |
| Acquirer portfolio | Excessive | 70 bps or more | same minimum as Above Standard |
| Individual merchant, AP/Canada/EU/US | Excessive Merchant | 150 bps or more (footnote 5 cut it from 220 bps on 1 April 2026) | 1,500 or more |
| Individual merchant, LAC | Excessive Merchant | 150 bps or more | 1,500 or more |
| Individual merchant, CEMEA | Excessive Merchant | 220 bps or more | 150 or more, and USD 75,000 or more |
One condition on that table is easy to skip: the fact sheet applies the Excessive Merchant thresholds only "if acquirer is not Above Standard or Excessive." If your acquirer's whole portfolio is already in the program, the merchant-level line is not the one being read.
What Stripe publishes for the accounts it acquires
| Tier | VAMP ratio | VAMP count |
|---|---|---|
| Non-compliant | 0.5% | 5 |
| Excessive | 1.5% (2.2% in CEMEA) | 1,500 (150 in CEMEA) |
Read the two tables as two different documents, because that is what they are. The excessive line lines up: 150 basis points is 1.5%, footnote 5's cut took effect on 1 April 2026, and Stripe now prints 1.5% for those regions. Two sources, same number.
The 0.5% row is the one to be careful with. Visa's fact sheet has no merchant-level Non-Compliant tier at all — its 50 bps figure describes an acquirer's portfolio, which is the acquirer's whole book of business and not your account. Stripe publishes a Non-compliant tier of 0.5% with a minimum of five events and applies it to an individual account. Five. That is a threshold a garage seller can hit in a bad month.
I cannot reconcile those two from public documents, and there is no point pretending otherwise: the Visa Acquirer Monitoring Program Guide, where a merchant-level Non-Compliant tier would be defined if one exists, is not published outside Visa's client channels. So read the second table as Stripe's own published tiers for Stripe accounts, not as a Visa merchant threshold anyone can show you in a Visa document. Stripe's wording in the same place is careful too — Visa "may assess fees to merchants that exceed the Non-Compliant threshold." May, not will. Ask your processor which line it applies to your account, and ask for the answer in writing.
Count it yourself, and get the two months right
Here is the arithmetic mistake that is easy to make and expensive to keep making: counting disputes against the sales that caused them.
Networks do not do that. Stripe states it directly. Both networks "assign a dispute or fraud report to the month in which they received it, regardless of when the original payment occurred." So a July order disputed in October is an October dispute.
For a seasonal seller that is not a detail, it is the whole picture. Take 600 orders in December carrying six disputes: 1.0% if you score them against the month they were sold. Those same six disputes arriving in February, against 150 February orders, come to 4.0%. Same six buyers, same six complaints, four times the ratio, and nothing about the business got worse between the two numbers. The quiet month after a busy one is where ratios spike, and they spike for arithmetic reasons.
To estimate your own Visa figure for a month:
- Count every captured card-not-present payment in the calendar month. That is the denominator.
- Count every dispute created in that month, plus every fraud notification received in that month, whether or not you were debited. That is the numerator.
- Divide. Multiply by 100 for a percentage, by 10,000 for basis points, since Visa's documents speak in basis points.
One wrinkle for US accounts, from the same Stripe page: because of a reporting delay to the network, Stripe suggests counting payments for the calendar month but counting disputes "from the 5th of that month to the 5th of the following month." Your dashboard's tidy month is not the month the network scored.
And do not net out refunds. Monitoring programs "don't consider refunds when identifying disputes," and they do not consider outcomes either. Win the representment and the dispute still sits in the numerator. That is the most counter-intuitive line on this page, and it reorders your priorities. Preventing a dispute is worth more than winning one, and it is not close.
Mastercard divides by last month's sales
A caveat belongs before the numbers in this section rather than after them. Mastercard's Chargeback Guide is the authority for all of it, and I could not open it. Every request I made for the PDF on 2026-09-06 came back HTTP 403, across three URL paths and two user agents, which is the same wall the representment packet piece hit in August. Everything below is Stripe's published account of Mastercard's rules — a processor that files under those rules daily, but not the rulebook itself. If a specific month or a specific fine is at stake, get the guide through your acquirer before you argue about it.
With that said, the denominator really is built differently, and the difference is not cosmetic.
Per Stripe's documentation of the Excessive Chargeback Program, the rate is "the ratio of the chargeback count for the current month to the total number of captured payments from the preceding month." February's calculation uses January's payments and February's chargebacks, including chargebacks on payments captured in February. A month where sales fall by half raises your Mastercard ratio a month later even if your chargeback count never moves.
The two tiers, as Stripe publishes them:
| Tier | Chargeback count | Rate |
|---|---|---|
| Excessive Chargeback Merchant (ECM) | 100 to 299 | 1.5% to 2.99% |
| High Excessive Chargeback Merchant (HECM) | 300 or more | 3% |
Fines start in month two, not month one. Stripe's published ECM ladder runs $0 in month 1, $1,000 in months 2 to 3, $5,000 in months 4 to 6, $25,000 in months 7 to 11, $50,000 in months 12 to 18, and $100,000 from 19 months on. The HECM ladder on the same page runs steeper and tops out at $200,000. From month four an issuer recovery assessment adds $5 per chargeback for every chargeback above 300; Stripe's worked example is an account in month 4 of ECM with 400 disputes, assessed $5,500.
Exit is a clean rule, at least as written. Stripe says Mastercard removes an account from a program once chargebacks stay below the threshold for three consecutive months. One good month buys nothing.
Whose ratio is it, if you sell on a marketplace
This is the part that changes what any of the above means for someone shipping out of a garage.
Visa's rules say an entity that deposits a transaction, receives settlement from, and contracts with an acquirer or a payment facilitator is classified as a Merchant or Sponsored Merchant only if all three of these hold: "The entity is selling the goods or services to the Cardholder," "The entity uses its name primarily to identify its Merchant Outlet to the Cardholder," and "The entity provides recourse to the Cardholder in the event of a dispute" (section 5.3.2.2, Qualification as a Marketplace, Merchant, Payment Facilitator, Sponsored Merchant, Digital Wallet Operator, or Ramp Provider). Fail those and Visa classifies the entity as something else. A Marketplace is defined in the glossary as "an entity that brings together Cardholders and retailers on an electronic commerce website or mobile application and processes Transactions and receives Settlement on behalf of those retailers."
On the marketplace, you are the retailer. The card account is theirs. Your disputes go into a pool with everyone else's, and no fine ladder arrives addressed to you.
That is not the same as being invisible. Section 10.4.3.1 says Visa may evaluate an acquirer, its third party agent, its payment facilitator, or its merchant at "an Aggregated Merchant-level" or "a Sponsored Merchant-level." And the marketplace keeps its own ceiling for you, which is the one that actually bites. Amazon counts a service credit card chargeback as an order defect against a target of under 1%, stricter than either network threshold and measured on a far smaller order count. How ODR, late shipment rate and valid tracking rate are each counted is where that number lives.
If you also run your own storefront on Shopify Payments, Stripe or PayPal, then everything above applies to you personally, on that account, with your name on it.
Your processor moves before the network does
Waiting for a network fine is the wrong mental model. The processor acts first, because the processor is the one carrying your risk.
PayPal publishes a rate-driven fee tier. A seller with more than 100 sales transactions in the previous three full months and a dispute rate of 1.5% or more over that time is charged the High Volume Dispute Fee rather than the Standard one. The ratio is the total disputed amount of item-not-received and not-as-described claims against net sales for the previous three calendar months, and claims for unauthorized transactions and billing errors are left out of it. PayPal's help article "When is the dispute rate applied and how is it calculated?" (read 2026-09-06) also describes a 90-day grace period, and that one repays a careful reading: it runs from the point at which User Agreement changes relating to the dispute fee take effect in your region, not from the day your own rate crosses 1.5%. Note too that the denominator here is an amount, not a count, which is the opposite of Visa's design. Three formulas, three shapes, and none of them agrees with the number on your own spreadsheet.
Shopify Payments puts it on the money instead of the fee. Shopify's Shopify Payments reserves page (read 2026-09-06) lists elevated chargeback activity among the risk indicators that lead to a reserve, and describes fixed amount and percentage-based reserves held for a specified period, with 120 days as its worked example. Money you have already earned stops arriving on schedule. Shopify does say the remaining funds are returned in full at the end of the reserve period, which is worth knowing and is also not something to plan four months of rent around. If a hold shows up on a marketplace payout instead, the vocabulary differs, and reserved, deferred and available balances are three separate things.
Stripe states the endgame without decoration: failure to comply with a program's requirements in the specified period "can result in the network refusing to process further payments to you."
The five-year part nobody mentions until it happens
Termination is not the bottom.
Visa and Mastercard both run terminated merchant files: Mastercard's MATCH and Visa's VMSS. Stripe's terminated merchant files documentation (read 2026-09-06) sets out the mechanics, and is again the source for the Mastercard side of this. Acquirers must screen applicants against these databases and must report merchants they terminate for fraud, severe policy violations or excessive chargebacks; for MATCH, within one business day of termination or eligibility. Listings remain active for five years.
The MATCH excessive chargeback code, code 4, is quantitative rather than a judgment call. Per Stripe's account of the criteria, it triggers when monthly Mastercard chargebacks exceed 1% of total monthly Mastercard sales transactions and total $5,000 or more, both in the same calendar month. There is no minimum chargeback count. The worked example on that page is 125 transactions with 6 chargebacks totalling $6,250: a 4.8% ratio, both conditions met, qualifying on termination. The same page describes Visa's VMSS quantitative codes: code 22 for excessive disputes, which takes 1,000 disputes and 180 basis points of a dispute-to-sales amount ratio in a single month and a failure to adequately remediate, and code 21 for excessive fraud, which takes USD 250,000 in fraud at those same 180 basis points.
Removal is narrower than most people expect. On that page's account, an acquirer can remove a MATCH listing only where the listing was made in error, or under the PCI DSS code once compliance has been verified. Fixing the chargeback rate afterward does not clear a code 4 listing. Stripe says it cannot remove a merchant who met the excessive chargeback criteria "even if the business has resolved its dispute issues." If you do not know which acquirer listed you, Stripe points to matchbusinessowner@mastercard.com for listing details.
Two more things from that page that people get wrong. Closing your account does not prevent a listing, because the acquirer must still report you if the criteria are met, even months after the relationship ends. And the personal fields go in: principal owner name, address, phone and tax ID. The listing follows the person, not only the company.
Visa also fines merchant-data games directly, and this one is in the public rulebook. Section 12.5.3.2 provides that where Visa determines a merchant name, merchant data or merchant performance was "changed, modified, or altered ... in any way to circumvent" VAMP or the Visa Integrity Risk Program, Visa may impose a non-compliance assessment of USD 25,000 per merchant per month on the acquirer, and may "permanently disqualify the Merchant, or Sponsored Merchant, and its principals from participating in the Visa system." The assessment lands on your acquirer; the disqualification lands on you. Splitting volume across fresh descriptors to flatten a ratio is a named offence with a printed price.
What I read, and when I read it again
Everything above was read on 2026-09-06: the Visa Core Rules and Visa Product and Service Rules, 18 April 2026 edition (sections 5.3.2.2, 10.4.3.1 and 12.5.3.2, Appendix A, and the glossary entry for Marketplace); Visa's Acquirer Monitoring Program fact sheet, dated 2025; Stripe's "Dispute and fraud card monitoring programs" and "Terminated merchant files"; PayPal's dispute rate help article; and Shopify's Shopify Payments reserves page.
What I could not open: Mastercard's Chargeback Guide, 403 on every attempt, and the Visa Acquirer Monitoring Program Guide, which is not published outside Visa's client channels. Every Mastercard figure here is second-hand from a processor that files under those rules daily. That is a real limitation, and it is why nothing on this page tells you what your own case will be scored at.
These figures move on an announced schedule and an unannounced one at the same time. Visa's own footnote moved the Excessive Merchant threshold on 1 April 2026, and the rulebook is reissued twice a year. I re-read this set every 90 days, and the next pass is 2026-12-06.
The useful thing to do today takes about fifteen minutes and needs none of those documents. Export last month's payments and last month's disputes from whichever account is genuinely yours. Count both. Divide the second by the first, then do it again using the previous month's payments as the denominator so you have the Mastercard version too. Write both numbers somewhere you will see them monthly. If the count in the numerator is small enough that one more dispute moves the ratio visibly, you now know exactly how much room you have, which is the only number on this page that is actually about you.
Frequently asked questions
How is a chargeback ratio actually calculated?
It depends on the network, and the difference is a whole month. Visa's VAMP ratio is a count of fraud reports (TC40) plus disputes (TC15) divided by the count of settled card-not-present transactions (TC05) in the same month. Mastercard's Excessive Chargeback Program, as Stripe documents it, divides this month's chargeback count by last month's captured payment count. The same business can look compliant under one formula and not the other.
What chargeback rate gets a merchant fined?
Visa's 2025 VAMP fact sheet set the Excessive Merchant threshold at 220 basis points with at least 1,500 fraud and dispute events per month in the US, EU, Canada and AP, and footnote 5 of that sheet reduced the ratio to 150 basis points on 1 April 2026, a date now past. Stripe's page prints 1.5% for the same regions, which is the same number. For Mastercard, Stripe documents an Excessive Chargeback Merchant tier starting at 100 chargebacks and a 1.5% rate. Both are network programs applied to a merchant account, so confirm with your own processor which line it applies to you.
Does my Amazon or eBay chargeback rate put me in one of these programs?
Not directly, in most cases. Under Visa's rules an entity that contracts with an acquirer is classified as a Merchant or Sponsored Merchant only if it sells to the cardholder, uses its own name to identify the outlet, and provides recourse in a dispute; a Marketplace processes and settles on behalf of retailers instead. The marketplace holds the merchant account. Your equivalent ceiling is the platform's own metric, such as Amazon's Order Defect Rate target of under 1%.
How long does a MATCH listing last and can I get off it?
Five years, and removal is narrow. Stripe's terminated merchant file documentation states that only the acquirer that created the listing can remove it, and only if the listing was made in error or, for the PCI DSS code, after compliance is verified. Fixing your chargeback rate afterward does not clear a listing made under the excessive chargeback code.