Mastercard’s Scam Merchant Monitoring Program went into effect on July 24, 2026. If you process card-not-present transactions, this change affects you. Not hypothetically, and not eventually. I mean right now. Today.

The program adds a third layer of compliance monitoring on top of the Excessive Chargeback Program (ECP) and the Excessive Fraud Merchant (EFM) program that merchants already navigate. Understanding how it works isn’t optional anymore.

I want to be clear about something upfront: the SMMP is designed to catch scam operations, not legitimate merchants doing business in good faith. But, the history of compliance programs in payments tells us that clean merchants get caught in enforcement nets when they don’t understand the triggers.

What the SMMP Actually Does

Previous Mastercard monitoring programs work on ratios of chargebacks to total transcations. Breach a chargeback threshold under ECP and you’ll pay fines and face escalating consequences the longer the problem persists.

The SMMP logic is different. Rather than looking at chargeback or fraud ratios alone, the SMMP tracks scam signals.

A trigger can come from multiple sources: issuer fraud reports, chargeback documentation that references scam activity, Mastercard’s own intelligence network, or alerts from approved Merchant Monitoring Service Providers. The program isn’t waiting for your ratio to climb above a threshold over several months. It’s looking for behavioral patterns that suggest scam-adjacent activity, and it acts quickly when it finds them.

The consequences of a confirmed investigation are immediate. Acquirers have 72 hours to investigate once a merchant is flagged. If scam activity is confirmed, Mastercard and Maestro processing stops right away, with no fines, no grace period, and no remediation tier. That’s a fundamentally different risk profile than what merchants have been managing under ECP and EFM, where you typically have time to course-correct before the most severe outcomes trigger.

The Triggers Merchants Need to Watch

The primary trigger is a combined rate of refunds and chargebacks that exceeds 5% of total transactions over a rolling 30-day period, with a minimum of 500 transactions during that window. This is the metric that typical legitimate merchants will need to monitor closest, because most merchants track refunds and chargebacks as separate figures. The SMMP combines them, and that combined number can cross 5% in situations that don’t look alarming when you’re looking at each metric independently.

Beyond the ratio trigger, an SMMP investigation can also be triggered by a sharp decline in authorization approval rate of more than 50 percentage points within a 72-hour period, or an overall approval rate falling below 30%. Fraud type 56 reports from two or more different issuers, chargeback documentation from multiple issuers referencing scam activity, and requests for multiple Merchant IDs without clear business justification can also prompt an investigation. So can direct alerts from Mastercard’s GRIP intelligence system or approved monitoring providers.

New merchants face particularly strict scrutiny. Any merchant with less than six months of Mastercard acceptance history enters a heightened monitoring period during which stricter thresholds apply. If you’ve recently started accepting Mastercard or recently added a new MID, this is worth paying close attention to.

Why Mastercard Implemented This

The SMMP didn’t emerge from a vacuum. It reflects something we’ve been watching develop across the payments ecosystem for several years: the growing sophistication of scam operations that exploit legitimate payment infrastructure.

I’ve spent fifteen years working with merchants on dispute management, and what I’ve seen is that bad actors have gotten considerably better at mimicking legitimate merchant behavior long enough to do meaningful damage. They exploit the fact that traditional monitoring programs are retrospective; they look at what happened last month, not what’s happening now. By the time ratio-based programs flag a scam operation, significant consumer harm has often already occurred.

Mastercard’s signal-driven approach is a direct response to that dynamic. By incorporating issuer intelligence, behavioral signals, and real-time monitoring into a single compliance framework, the network is trying to close the window between when scam activity starts and when it gets stopped. That’s a legitimate and important goal. The implementation reality, though, is that legitimate merchants need to understand how these signals can be triggered unintentionally.

What Merchants Should Do Now

The most important operational reality of the SMMP is this: winning a chargeback at representment does not reduce a merchant’s SMMP ratio. The chargeback already counted. Prevention is the only effective lever. This is a meaningful shift in how merchants need to think about chargeback strategy. Fighting disputes after they’re filed remains important for recovering revenue, but it no longer provides the ratio relief that it does under traditional chargeback management frameworks.

That means dispute prevention tools deserve more attention than they may currently be getting in your operational planning. Pre-chargeback alert programs through Verifi and Ethoca allow merchants to resolve disputes before they become chargebacks, which is the only action that keeps them out of the SMMP calculation. Tools like Consumer Clarity and First-Party Trust help establish transaction legitimacy with issuers before a dispute is even initiated, which reduces the likelihood of fraud or scam classification at the source.

Beyond prevention, merchants should be monitoring their own combined refund and chargeback ratio against the 5% threshold, ideally with the same rolling 30-day view that Mastercard uses. Most merchant dashboards don’t surface this figure by default. Building visibility into that metric now; before your acquirer flags something; is the difference between proactive management and reactive crisis response.

Clear billing practices and transparent customer communication remain foundational. Many SMMP triggers trace back to consumer confusion, billing descriptor issues, or inadequate cancellation processes that push customers toward their bank before contacting the merchant. These aren’t new problems, but the stakes attached to them have increased significantly under the SMMP framework.

The Broader Picture

The SMMP is part of a broader tightening across the major networks. Visa lowered “excessive” threshold for their VAMP program from 2.2% to 1.5% earlier this year. Mastercard now runs three concurrent monitoring programs with distinct triggers and consequences. The direction of travel is clear: networks are moving toward more granular, signal-driven oversight of merchant behavior, with less tolerance for extended remediation timelines.

For merchants operating at scale across card-not-present channels, the compliance environment of 2026 looks meaningfully different from what it looked like even eighteen months ago. The merchants who will navigate it most effectively are those who build monitoring infrastructure and prevention strategies now rather than waiting for their acquirer to surface a problem. The SMMP doesn’t offer the warning period merchants have come to expect. That alone should change how seriously this program is taken.