Skip to main content
Blog
Blog

Mastercard Scam Merchant Monitoring: SMMP Enforcement Active, What Merchants Must Do Now

Mastercard SMMP is 30+ days into active enforcement. Which merchants face investigation risk now, what the 72-hour acquirer window means in practice, and how to close the evidence gap before the next trigger fires.

May 05, 2026 Updated Aug 27, 2026 13 min read
Dark analytics dashboard graphic showing Mastercard Scam Merchant Monitoring program status
Table of Contents

TL;DR: Mastercard Scam Merchant Monitoring

Mastercard Scam Merchant Monitoring (SMMP) went live on 24 July 2026. Acquirers must investigate flagged merchants within 72 hours and immediately stop Mastercard and Maestro processing if scam activity is confirmed. SMMP differs from ECM (chargeback ratio program) and EFM (fraud ratio program): it fires on scam activity signals such as issuer reports, authorization-rate collapse, and monitoring-provider alerts. Now that the program is active, the operational posture shifts from preparation to continuous monitoring: track authorization-rate trends daily, treat every dispute response as a permanent record contribution, and keep browser-layer checkout evidence running.

Short on time? See cside's chargeback-evidence tooling. It covers everything below in one deployment.

Mastercard's Scam Merchant Monitoring Program (SMMP) has changed the risk profile for online merchants. It targets scam activity, so the trigger can come from issuer reports, chargeback documentation, Mastercard intelligence, or a monitoring provider alert.

The program went live on 24 July 2026. For Heads of Payments, Risk, and Fraud, the operational question is no longer about preparation: it is about running cleanly under an active enforcement program. A merchant that looks clean under a traditional chargeback threshold can still face a fast investigation if the activity pattern looks like a scam operation. The acquirer owns the formal obligation, but the merchant owns the evidence gap.

This guide explains what SMMP is, how it differs from ECM, HECM, and EFM, what can start an investigation, and how merchants should operate now that the program is live.

What is Mastercard Scam Merchant Monitoring?

Mastercard Scam Merchant Monitoring is part of the broader Mastercard merchant risk and monitoring environment. Mastercard's Security Rules and Procedures Merchant Edition describes Merchant Monitoring Program (MMP) participation, Merchant Monitoring Service Provider (MMSP) requirements, initial merchant scans for merchants onboarded from 1 January 2026, and persistent monitoring for merchant violations.

The scam-specific 2026 update is described by payment risk providers including Solidgate, Austreme, and G2 Risk Solutions. Their common read is that Mastercard's revised standards take effect on 24 July 2026 and require acquirers to investigate flagged merchants within 72 hours.

The merchant impact is direct. If scam activity is confirmed, the acquirer must stop Mastercard and Maestro processing for that merchant. For payment facilitators and PSPs, the responsibility flows down to sponsored merchants and sub-merchants.

The program applies most sharply to card-not-present merchants. New merchants are in the tightest window because scam operations often process quickly, accumulate disputes, and disappear before conventional monitoring catches up.

How SMMP differs from ECM, HECM, and EFM

Mastercard already has several monitoring tracks. SMMP adds a different failure mode.

ProgramPrimary triggerTypical focusMerchant consequence
ECMExcessive chargebacksDispute count and chargeback ratioMonitoring, remediation pressure, and assessments
HECMHigh excessive chargebacksHigher dispute count and chargeback ratioStronger escalation and assessments
EFMExcessive fraudFraud volume, fraud ratio, and fraud controlsFraud program enrollment and assessments
SMMPSuspected or confirmed scam activityScam indicators, issuer reports, monitoring alerts, and investigation resultsImmediate processing termination if confirmed

ECM and HECM are ratio programs. EFM is a fraud monitoring program. SMMP is an investigation program triggered by scam signals. A merchant can be inside more than one track at the same time.

That distinction matters operationally. A merchant can treat ECM as a threshold-management problem: reduce disputes, improve representment, and work back below the line. SMMP gives acquirers a compressed decision window. If the available evidence points toward scam activity, the outcome can be loss of Mastercard and Maestro acceptance, not just a fine to absorb.

What triggers an SMMP investigation?

Industry explainers describe four practical trigger groups. Mastercard should remain the source of truth for final operating rules, but merchants should monitor all four before July.

Authorization-rate collapse

A sudden fall in approval rate can make a merchant look like a scam operation, especially when the drop is concentrated in a short period. Solidgate describes this as either a drop of 50 or more percentage points within 72 hours or a fall below a 30% approval rate, subject to minimum transaction volume and exclusions such as BIN attacks or processor outages.

Legitimate merchants can still trip this pattern. A bad campaign, a payment routing issue, aggressive retries, or a traffic-quality problem can all produce authorization behavior that looks abnormal from the network's view.

GRIP notification

A Global Rules Investigation Program notification links a merchant to suspected fraudulent activity based on Mastercard intelligence. A GRIP letter is a network-level signal that the acquirer must treat seriously, not a routine merchant performance warning.

Merchants should not wait for this kind of notice before organizing evidence. Once the notice arrives, the acquirer is already on the clock.

New merchant signals

New merchants under six months of Mastercard acceptance history face heightened scrutiny. The reported trigger set includes fraud type 56 reports from two different issuers, chargebacks from multiple issuers with documentation referencing scams or manipulation, and combined refund plus chargeback rates above a 5% threshold in a rolling period.

This is the most important category for legitimate high-growth merchants. A new subscription merchant, travel seller, or iGaming operator can generate dispute language that sounds worse than the actual customer journey. Descriptor confusion, trial-to-paid billing, and intangible delivery all increase that risk.

MMSP alerts

Mastercard's MMP framework allows acquirers to work with approved Merchant Monitoring Service Providers. The current Mastercard manual describes MMSP registration, initial scans, persistent monitoring, and reporting requirements. A monitoring provider alert can put the merchant into an investigation path if the activity looks like a scam or merchant violation.

What happens during the 72-hour investigation?

The 72-hour window is an acquirer obligation, not a merchant grace period. Once a trigger fires, the acquirer has to review the merchant quickly and decide whether the activity is legitimate, suspicious but remediable, or confirmed scam activity.

That review can include onboarding files, transaction records, refund behavior, chargeback documentation, issuer reports, website content, billing descriptors, and merchant communications. For PSPs and payment facilitators, it can also include sub-merchant records and transaction-laundering risk.

The merchant's evidence matters because acquirers often do not have the full cardholder context. A processor can see authorization results, disputes, refund volume, and some onboarding data. It usually cannot reconstruct what the cardholder saw in the browser, which device completed checkout, or whether the session path supports a legitimate purchase.

That is the gap merchants need to close before the investigation starts. Evidence captured after the fact is weaker than evidence captured at checkout.

Which merchants face the highest risk?

New card-not-present merchants under six months of Mastercard acceptance history are the highest-risk group because several reported SMMP triggers specifically target early merchant behavior.

Several verticals carry extra structural exposure:

  • Subscription and SaaS: Trial-to-paid conversion, forgotten renewals, and descriptor confusion create disputes that customers may describe as unexpected
  • iGaming and digital goods: High transaction velocity and intangible fulfilment make issuer-side scam language easier to assert
  • Travel: High average order value and seasonal refund spikes can move combined refund and chargeback rates quickly
  • E-commerce and retail: Return disputes, delayed shipping, and unclear fulfilment records can weaken the merchant's position during review
  • Merchants with low descriptor recognition: Customers who do not recognize a charge often call the issuer first, and their language can become part of the dispute record

None of these characteristics prove scam activity. They increase the chance that ordinary merchant friction produces the same signals Mastercard and acquirers are watching.

How chargeback evidence reduces SMMP exposure

SMMP exposure is partly about the content and count of disputes. If multiple issuers submit chargebacks with scam or manipulation language, that record can become an investigation trigger. Every uncontested or poorly defended dispute makes the signal stronger.

Strong representment evidence helps in two ways.

First, it reduces accumulation. A chargeback that is successfully represented does not carry the same weight as an uncontested scam-referenced dispute. Merchants that fight weak claims with complete evidence keep the issuer record cleaner.

Second, it gives the acquirer something useful during the investigation. The acquirer needs to decide quickly whether the merchant is a scam operation or a legitimate business with a dispute problem. Server-side order records help, but they do not show the full checkout session.

cside's Chargeback Evidence captures browser-layer data at checkout: device identity, session continuity, real client IP context, and transaction-page activity. That evidence is useful because it shows the transaction in the environment where the customer actually completed it.

The same evidence strategy supports Visa disputes under Compelling Evidence 3.0, where device ID and IP are rate-limiting fields. For operational detail, see how to remove a TC40 from your VAMP ratio using CE 3.0 and device fingerprinting for Compelling Evidence chargebacks.

SMMP and VAMP create one evidence problem

Visa and Mastercard are approaching merchant risk from different angles in 2026. Visa's VAMP combines fraud reports and disputes into one ratio. Mastercard's SMMP focuses on scam activity and acquirer investigation.

The compliance mechanics differ, but the merchant preparation is similar. You need clean transaction records, consistent descriptors, fast dispute operations, and browser-layer evidence captured before a cardholder calls the issuer.

The VAMP 2026 merchant playbook explains how Visa's 1.5% merchant threshold changes the economics of disputes. SMMP adds a separate Mastercard risk: the documentary content of disputes can contribute to a scam-monitoring trigger, not just a chargeback ratio.

The result is one evidence standard across both networks. If the cardholder was present in the browser, navigated checkout, authenticated, and completed the transaction from a recognized device, merchants need to preserve that proof.

Merchant checklist: operating under SMMP

The July 24, 2026 enforcement date has passed. Merchants still running without these controls in place should treat each item as an open compliance gap.

  1. Audit refund and chargeback rates on a rolling 30-day basis. Track any period approaching 5% combined refunds and chargebacks, not just monthly snapshots
  2. Review scam-language disputes continuously. Segment chargebacks where issuer documentation mentions scam, manipulation, deception, or unexpected billing; these feed the SMMP trigger record
  3. Keep billing descriptor recognition current. Align descriptors across processors, currencies, subscriptions, and one-time charges; misrecognition is a direct source of scam-language disputes
  4. Monitor authorization-rate trends daily. Watch for sudden drops by BIN, issuer, market, campaign, gateway, and traffic source; a 50-point collapse or a fall below 30% approval rate can trigger SMMP criteria
  5. Run browser-layer evidence capture at checkout. Device ID, session continuity, and real client IP context cannot be reconstructed after a dispute opens
  6. Validate representment packets against recent disputes. Run the last 30 days of disputes through the evidence workflow and identify missing fields before the next investigation window
  7. Keep your acquirer briefed. High-growth merchants adding markets or payment types should notify the acquirer before expansion, not after a GRIP notification arrives

SMMP is live as of 24 July 2026: operating under the program now

Mastercard's Scam Merchant Monitoring Program took effect on 24 July 2026. The focus shifts from deadline preparation to continuous operations.

Authorization-rate monitoring is now an ongoing obligation. Collapses that previously looked like a temporary payment routing issue now trigger active investigation criteria. Merchants should track daily authorization trends by BIN, traffic source, and gateway rather than reviewing these on a monthly cycle.

Each dispute response becomes a permanent record contribution. Scam-referenced chargebacks submitted by issuers are part of the Mastercard record that an acquirer assesses during the 72-hour window. Merchants should treat dispute response quality as a compliance obligation, not just a recovery exercise.

New merchants remain in a tighter window. Merchants onboarded after 1 January 2026 were subject to initial scans. Those now moving through the six-month mark face a transition in monitoring intensity. High-growth merchants adding new markets or payment methods should brief their acquirers before expanding.

Browser-layer evidence cannot be backfilled. Device identity, session continuity, and real client IP context captured at checkout cannot be reconstructed after a dispute. Merchants that did not instrument this before July should treat the gap as an open compliance item and close it before the next dispute cycle.

For acquirers and payment facilitators, the SMMP obligation flows through to sponsored merchants. PSPs onboarding card-not-present merchants at scale should confirm that monitoring frameworks and evidence capabilities cover the full portfolio, not just the highest-volume accounts.

Operating under SMMP: 30 days past the enforcement date

The July 24, 2026 enforcement date is now more than 30 days past. The program has moved from anticipated to operational.

Acquirers are running active investigations. SMMP investigations have been underway since the effective date. Merchants whose dispute activity matched scam-signal criteria have had acquirers engaging directly under the 72-hour obligation. If you have not received acquirer contact, that reflects your current dispute profile — not a guarantee the pattern will not shift.

New merchants onboarded in 2026 are fully inside the monitoring window. Any merchant that began Mastercard acceptance after 1 January 2026 is now in active monitoring scope. Merchants approaching six months of processing history are moving into the period where heightened new-merchant scrutiny continues to apply.

The 72-hour window is not a planning parameter. Acquirers running investigations under SMMP are making decisions under real time pressure. Evidence that takes longer than a day to assemble is effectively unavailable when the clock is running.

Browser-layer evidence is the most common gap. Server-side transaction records are typically present in merchant and acquirer systems. What is often missing is the checkout-session context: the device that completed the transaction, the session path, and the client IP environment at authorization. That data can only be captured in the browser, at checkout, before the dispute opens. Merchants that have not instrumented this should treat it as an open compliance gap.

The operational checklist above has not changed. What has changed is the status: the program is active, investigations are happening, and merchants without these controls in place are operating with a live exposure.

Mastercard fraud monitoring programs compared

Merchants managing Mastercard compliance often encounter multiple program names at once. The table below shows how each program differs in trigger, measurement, and consequence.

ProgramTrigger typeWhat is measuredConsequence
ECMExcessive chargebacksChargeback ratio and count vs. rolling baseMonitoring, remediation, and assessments
HECMHigh excessive chargebacksHigher chargeback ratio and countStronger escalation, assessments
EFMExcessive fraudFraud-to-sales ratio and fraud-to-transaction countFraud program enrollment, assessments
SMMPScam activity signalsIssuer reports, authorization-rate collapse, GRIP, MMSP alertsAcquirer investigation; immediate Mastercard and Maestro termination if confirmed

A merchant can be enrolled in more than one program at a time. SMMP's uniqueness is the speed of consequence: an ECM or EFM finding triggers a remediation window, while a confirmed SMMP finding triggers immediate processing termination.

Further reading on cside

This article reflects cside's analysis of Mastercard Scam Merchant Monitoring and related merchant-risk programs as of 2026-05-05. Program rules, thresholds, deadlines, and acquirer obligations can change. Confirm operational decisions with Mastercard rules, your acquirer, and your payment processor.

Learn more about cside Chargeback Evidence

Mike Kutlu
Client-Side Security Consultant

Client-side security consultant at cside. 10+ years of experience implementing technology solutions for enterprises (previously at Oracle, Cloudflare, and Splunk). Now helping teams use client-side intelligence to catch & reduce fraud.

FAQ

Frequently Asked Questions

The SMMP is a Mastercard enforcement track for merchants suspected of scam activity. Industry explainers describe a 24 July 2026 effective date, a 72-hour acquirer investigation window for flagged merchants, and immediate Mastercard and Maestro termination when scam activity is confirmed.

ECM and HECM are chargeback monitoring programs based on excessive dispute volume or ratios. SMMP is different because it focuses on scam activity signals, including issuer reports, scam-referenced disputes, monitoring provider alerts, and sudden authorization changes.

The commonly reported triggers are a sharp authorization-rate collapse, a Mastercard GRIP notification, new merchant signals such as fraud type 56 reports or scam-referenced chargebacks from multiple issuers, and alerts from an approved Merchant Monitoring Service Provider.

New card-not-present merchants under six months of Mastercard acceptance face the highest scrutiny. Subscription, SaaS, iGaming, digital goods, travel, and merchants with unclear billing descriptors also carry elevated exposure because disputes can be described as unexpected or manipulative.

Strong representment evidence helps merchants prevent scam-referenced chargebacks from accumulating and gives acquirers better records during a compressed investigation window. Browser-layer evidence, including device and session context, is especially useful because it shows what happened during checkout.

Mastercard's fraud monitoring track flags merchants whose fraud-to-sales ratio or fraud-to-transaction count exceeds network thresholds. Unlike SMMP, the fraud monitoring program runs on issuer fraud reports (TC40 data) rather than scam-referenced disputes. Merchants in the fraud monitoring track face remediation requirements and assessments; those that do not demonstrate improvement within the review period can escalate to disqualification. SMMP and the fraud monitoring track are separate programs: a merchant can be in both at the same time, and each calls for a different remediation strategy.

Mastercard's Chargeback Monitoring Program tracks merchant dispute ratios against network-defined thresholds. The two levels are ECM (Excessive Chargeback Merchant) and HECM (High Excessive Chargeback Merchant). ECM and HECM are ratio programs measured against a rolling transaction base. SMMP is different: a merchant can receive an SMMP investigation without being in ECM or HECM, because SMMP fires on scam activity signals rather than dispute ratios. The two programs can run in parallel, and the evidence requirements differ. ECM remediation centers on reducing dispute volume; SMMP remediation centers on demonstrating that transactions were legitimate.

Prioritise browser-layer evidence captured at checkout, since acquirers rarely have full cardholder context during a 72-hour SMMP investigation. Look for device identity, session continuity, and real client IP context recorded during the session, not reconstructed afterward. Daily authorization-rate monitoring, descriptor consistency, and a fast representment workflow matter too. cside captures this checkout evidence as one first-party script, so the proof exists before a dispute or investigation opens.

Yes. ECM is a ratio program you manage by reducing dispute volume, but SMMP fires on scam signals such as issuer reports, authorization-rate collapse, and monitoring-provider alerts, so a merchant with a clean chargeback ratio can still face an investigation. SMMP remediation is about proving transactions were legitimate, which needs evidence rather than a lower ratio. Merchants should add browser-layer checkout evidence and daily authorization monitoring on top of existing chargeback controls.

Cover the full portfolio, not just high-volume accounts, because the SMMP obligation flows down to sponsored merchants and sub-merchants and scam operations often sit in newer, smaller accounts. Prioritise card-not-present merchants under six months of Mastercard acceptance, verticals with intangible fulfilment, and any merchant with unclear descriptors. Choose evidence capture that deploys uniformly across every merchant site. cside installs as one first-party script per site, so coverage does not depend on account size.

cside records browser-layer evidence at the moment of checkout: device identity, session continuity, real client IP context, and transaction-page activity. During an SMMP investigation the acquirer must decide quickly whether a merchant is a scam operation or a legitimate business, and server-side order records alone do not show what the cardholder saw or which device completed the purchase. cside preserves that session context, giving the acquirer concrete proof the transaction happened in a genuine environment.

cside deploys as one first-party JavaScript script added to your checkout, or through the agentless Scan Method, with no DNS change and without rerouting your traffic. Once live it captures browser-layer evidence on every session, so proof exists before any dispute or investigation. Pricing follows a metered model based on sessions or pageviews with a free plan to start; teams with larger portfolios can talk to the cside team for volume terms.

Merchants should confirm browser-layer evidence capture is running at checkout, review the last 30 days of dispute responses for missing checkout-session fields, and validate that daily authorization-rate monitoring is in place. The 72-hour investigation window means evidence must exist before a trigger fires, not be assembled afterward. Merchants that deferred these controls before the July 24, 2026 enforcement date should treat each gap as an open compliance item.

Existing scam-referenced disputes contribute to the signal profile that SMMP monitors. Merchants carrying a backlog of uncontested or scam-language chargebacks from before the enforcement date face elevated investigation risk because those records remain available to acquirers reviewing the activity pattern. Reducing new scam-referenced disputes through stronger representment and cleaner checkout evidence helps lower the ongoing signal, but it does not retroactively remove past records.

Monitor and Secure Your Third-Party Scripts

Gain full visibility and control over every script delivered to your users to enhance site security and performance.

Start free, or try Business with a 14-day trial.

cside dashboard interface showing script monitoring and security analytics
Related Articles
Book a demo

Want to walk through this with an engineer?

Thirty minutes, on your own site. Not a slide deck.

Book a personalized demo to see:

How to achieve PCI DSS requirement 6.4.3 & 11.6.1 compliance in 1 day
Why third-party scripts are a security risk for you and your visitors
Monitoring privacy and consent leakage (GDPR, CCPA) across every third party
Stopping signup abuse, account sharing, and chargeback fraud with device intelligence
Detecting and controlling AI agents and bots hitting your site in real time

Rather just send a question?

Finding open slots…

Real humans only. We'd know.

Having trouble booking? Open scheduler in a new tab

What are you trying to solve?

Tell us in a line and we'll come back with something useful, not a generic pitch.

We usually help with:

Seeing which third-party scripts run on your site
PCI DSS 6.4.3 and 11.6.1 evidence
Bots, AI agents and account takeover

Prefer to just book a time? Pick a slot instead