
What Is Visa's VAMP Program? A Guide to the 2026 Threshold, Fines, and Compliance
Visa's VAMP threshold dropped 32% in April 2026. Here's what the program actually measures, why your acquirer may care more than Visa does, and what to do about it.
A Merchant at 1.8% Was Compliant in March. By April, They Weren't.
On April 1, 2026, Visa lowered the threshold for its merchant monitoring program by 32%, dropping the line from 2.2% to 1.5% for merchants in the US, Canada, EU, and APAC (CEMEA remains at 2.2%). No grace period for merchants already over the line. The change took effect immediately, reclassifying thousands of previously compliant merchants as "Excessive."
As Justt Co-Founder and Chief Risk Officer Roenen Ben-Ami put it: "A merchant who was comfortably within limits at a 1.8% ratio is now in excess of Visa's threshold."
If you're a CFO or payments leader at a mid-market ecommerce or SaaS company, you've probably heard the acronym VAMP floating around. Maybe your acquirer mentioned it. Maybe your fraud vendor sent a worried email. This guide breaks down what the program actually measures, where the real risks hide, and what you can do about it.
What VAMP Actually Is
VAMP stands for Visa Acquirer Monitoring Program. Visa launched it in April 2025 to replace two older programs: the Visa Fraud Monitoring Program (VFMP) and the Visa Dispute Monitoring Program (VDMP). Instead of tracking fraud and chargebacks separately, VAMP combines them into a single ratio.
The name is a clue to the real story. Notice it says "Acquirer," not "Merchant." Visa's primary enforcement target is your acquirer (the bank or payment processor that connects you to the Visa network). Your acquirer, in turn, enforces compliance on you.
That distinction matters more than most merchants realize.
VAMP applies only to card-not-present (CNP) Visa transactions, meaning online and digital purchases. In-store, card-present transactions aren't part of the calculation.
The VAMP Ratio: How Visa Counts
The formula itself is straightforward:
VAMP Ratio = (TC40 fraud reports + TC15 chargebacks) ÷ TC05 settled CNP transactions
Three codes drive the math:
TC40: The check-engine light of payments. The cardholder’s bank flags a transaction as suspected fraud early—before any chargeback is filed—so you get a warning instead of an immediate hit.
TC15: The formal undo button. The issuer reverses the charge and pulls the funds back. This is the chargeback that actually lands on your ledger.
TC05: Your settled card-not-present sales is the full odometer reading. Every completed transaction that forms the denominator against which fraud and chargeback rates are measured.
Two features of this ratio regularly ambush even seasoned merchants.
First, it’s a pure headcount, not a dollar scoreboard. A $12 subscription renewal counts exactly the same as a $3,000 luxury handbag. High-volume, lower-AOV merchants therefore carry heavier ratio exposure for every revenue dollar than those selling fewer, larger tickets.
Second, Visa sets a monthly floor. They only start watching once you hit 1,500 combined TC40 and TC15 events in a month. Stay under that threshold and your ratio can look ugly—the program simply doesn’t notice.
One Transaction, Two Counts
The detail that surprises most payment teams is a single transaction can count twice in the VAMP numerator.
When a cardholder flags a purchase as fraud, the issuer files a TC40 early warning. If that same transaction later becomes a formal chargeback, a TC15 follows. Both events count separately. One fraudulent sale therefore generates two strikes against your ratio.
At the Excessive tier, Visa charges $8 for every TC40 or TC15 event in any month you breach the threshold. A single transaction that produces both costs you $16: $8 for the warning plus $8 for the chargeback.
For a merchant running 60,000 CNP transactions a month, the math is unforgiving. At 2.2% you could absorb 1,320 combined events. At 1.5% that ceiling drops to 900 which is a cut of 420 allowable incidents. Layer on the double-counting, and the real operating margin shrinks even faster.
Your Acquirer's Threshold Is Tighter Than Yours
This is where VAMP gets genuinely complicated, and where most guides stop too early.
Visa sets the merchant threshold at 1.5%. Your acquirer’s portfolio thresholds sit far lower:
Above Standard: 0.50%
Excessive: 0.70%
Those numbers apply to their entire book of merchants, not your single account. Once an acquirer crosses 0.70%, Visa fines land across the whole portfolio and regulatory scrutiny follows.
The practical result is blunt. Even if you’re running a clean 1.2%—comfortably under the 1.5% merchant line—your acquirer can still restrict the account, demand cash reserves, or terminate the relationship. If their portfolio is drifting toward 0.50%, you become a liability they cannot afford to keep.
As the Forter team noted: "Your acquirer might not be able to afford you if you're too much above 0.7%, no matter how safely below 1.5% you are."
This is why conversations with your acquirer about their risk appetite matter as much as monitoring your own ratio.
Where to Find Your VAMP Data
You can't manage what you can't measure, and TC40 visibility remains a real gap in the industry.
Stripe provides both TC40 and TC15 data. Check Radar for Early Fraud Warnings and the Payments section for disputes.
Adyen surfaces TC40 data through the Customer Area under card monitoring programs.
Braintree and Worldpay expose TC15 chargeback data but offer limited or no native TC40 visibility.
Pagos has noted that "only Adyen and Stripe provide the TC40 data necessary to calculate the VAMP chargeback rate accurately." If your processor doesn't provide TC40 data, you may need to purchase a separate Verifi feed to see the full picture. Without it, you're monitoring only half your VAMP exposure.
CE3.0: The Primary Way to Reduce Your Ratio
Compelling Evidence 3.0 is Visa's program for removing TC40 fraud reports from your VAMP ratio. When you successfully dispute a TC40 using CE3.0 evidence, that event is excluded from the numerator.
But CE3.0 has strict requirements:
You must capture Device ID and IP address on the disputed transaction.
You need at least two prior undisputed transactions from the same cardholder.
Those prior transactions must be between 120 and 365 days old.
At least two data elements must match between the disputed and prior transactions (IP address, Device ID, User ID, or shipping address).
At least one of the matching elements must be IP address or Device ID.
The critical point: you can't build this evidence retroactively. If you aren't already capturing Device ID and IP address on every transaction, you can't file CE3.0 disputes on today's fraud reports.
An important expansion is coming. On October 24, 2026, Visa will allow cross-merchant qualifying transactions and related card credentials to count as prior evidence. This could significantly broaden CE3.0 eligibility, but the practical details for routing cross-merchant data through the acquirer chain are still being worked out.
Pre-Dispute Tools and the Timing Trap
Beyond CE3.0, pre-dispute resolution tools can keep TC15 chargebacks out of your VAMP ratio. Three tools are worth knowing:
RDR (Rapid Dispute Resolution): Automatically resolves disputes before they become chargebacks.
CDRN (Cardholder Dispute Resolution Network): Alerts you to incoming disputes so you can refund before a chargeback is filed.
Order Insight: Shares order details with issuers to help them resolve cardholder inquiries before disputes are initiated.
There's a catch. For a pre-dispute resolution to exclude a TC15 from your VAMP ratio, both the dispute and its resolution must fall within the same calendar month. VAMP evaluates each month in isolation. Resolve a dispute in May that was filed in April, and the TC15 still counts in April's ratio.
Speed matters. The faster you respond to dispute alerts, the more likely you are to resolve within the same month the dispute was filed.
The False Decline Problem Inside VAMP
Here's the trap that doesn't appear in most VAMP compliance guides: over-blocking legitimate buyers to protect your fraud ratio can actually make the ratio worse.
Remember, your VAMP ratio is a fraction. The numerator is fraud reports and chargebacks. The denominator is settled CNP transactions. When you aggressively decline orders to keep fraud out, you shrink the denominator at the same time. Fewer approved transactions means each fraud event carries more weight in the ratio.
The numbers are unforgiving. False declines cost merchants roughly $50 billion a year in lost revenue, according to Riskified. Globally the damage reaches an estimated $443 billion—about nine times the $48 billion lost to actual fraud (Aite-Novarica).
The better move is dual optimization: grow the denominator by approving more real buyers while shrinking the numerator through sharper fraud detection and CE3.0 evidence. It’s two levers, not one.
A Practical Compliance Checklist
Whether you're well under the threshold or uncomfortably close, these steps build a defensible VAMP position:
Calculate your current VAMP ratio. Pull your TC40 and TC15 counts alongside your settled CNP volume. If your processor doesn't provide TC40 data, get a Verifi feed or talk to your acquirer.
Audit your CE3.0 readiness. Confirm you're capturing Device ID and IP address on every transaction today. Check how many months of historical transaction data you retain with matching elements.
Talk to your acquirer. Ask directly about their portfolio ratio and their internal merchant thresholds. Understand their risk appetite before they enforce it.
Review your billing descriptors. Confusing descriptors drive friendly fraud. Roughly 75% of all disputes originate as friendly fraud, according to Chargebacks911 citing Visa data. Clear descriptors reduce the disputes that never should have happened.
Set up real-time monitoring. Monthly surprises are expensive. Track your ratio weekly or daily so you can respond before month-end calculations lock in.
Check your enumeration exposure. VAMP includes a separate track for card-testing attacks. Merchants exceeding a 20% enumeration ratio with 300,000 or more enumerated authorization attempts per month trigger separate monitoring.
What to Do If You're Close to the Line
First-time violators who have been out of VAMP for 12 or more months on a rolling basis get a three-month grace period. As Chief Sales Officer Oscar Bello of Chargeback Gurus explained to the Merchant Risk Council: "First-time violations within a rolling twelve-month period qualify for a three-month grace period during which enrollment will be delayed."
That grace period is a window, not a reprieve. If the ratio remains over threshold when the window closes, enrollment and fines begin. Use it to implement the checklist above aggressively.
If you're between 1.0% and 1.5%, the math is clear: you need fewer events in the numerator, more legitimate transactions in the denominator, or both. This is where understanding whether to fight a chargeback or refund proactively via an alert becomes a financial decision, not a gut call.
As Ben-Ami noted: "The right approach isn't to resolve every alert automatically. It's to understand your own situation: How close are you to your threshold? What does your acquirer expect? What's the win rate on your chargebacks?"
Where Corgi Labs Fits
VAMP compliance is a visibility problem before it's a fraud problem. You need to see your full ratio in real time, understand which transactions carry the highest risk of generating both TC40 and TC15 events, and approve more real buyers to keep your denominator healthy.
Corgi Labs helps merchants do exactly that. Corgi Intelligence surfaces your VAMP-relevant transaction data in one place, while Corgi Model uses merchant-specific machine learning to block fraud without blocking buyers. The result: a healthier ratio built on better decisions, not blanket declines.
If you want to see where your VAMP ratio stands and what levers you have to improve it, book a demo →.
Sources
Basis Theory, "VAMP 2026: What Changes on April 1 and Who Will Start Pushing on Merchants" (February 18, 2026). https://blog.basistheory.com/visa-acquirer-monitoring-program-2026-updates
Chargebacks911, "Visa Acquirer Monitoring Program: Major Visa Updates in 2026" (February 13, 2026). https://chargebacks911.com/vamp-enforcement/
Chargebacks911, "Compelling Evidence 3.0 Update — April 2026, Explained" (April 16, 2026). https://chargebacks911.com/compelling-evidence-3-0-update-april-2026/
Chargeback Gurus / MRC, "Stricter VAMP Ratio Thresholds Are Now in Effect. Here's How to Stay Compliant" (April 1, 2026). https://merchantriskcouncil.org/learning/resource-center/member-news/blog/2026/stricter-vamp-ratio-thresholds-are-now-in-effect-heres-how-to-stay-compliant
Corgi Labs, "Visa VAMP 2026: New Merchant Compliance Thresholds" (May 17, 2026). https://www.corgilabs.ai/insights/vamp-2026-merchant-compliance
Equifax, "The Visa Acquirer Monitoring Program (VAMP): What New Rules Mean for Acquirers and Merchants" (February 5, 2026). https://www.equifax.com/newsroom/all-news/-/story/the-visa-acquirer-monitoring-program-vamp-what-new-rules-mean-for-acquirers-and-merchants/
Forter, "Visa's Updated VAMP Program: What Merchants Need to Know" (March 25, 2026). https://www.forter.com/blog/visas-updated-vamp-program/
Justt, "Visa VAMP's Tighter Threshold Is Now Live: What Merchants Need to Know" (March 31, 2026). https://justt.ai/blog/visa-vamp-threshold-changes-april-2026/
Pagos, "Monitor Your VAMP Risk Exposure with Pagos" (July 30, 2025). https://pagos.ai/blog/monitor-your-vamp-risk-exposure-with-pagos
Riskified, "False Declines: What They Cost You and How to Reduce Them" (2025), citing Aite-Novarica Group for global $443B estimate. https://www.riskified.com/learning/ecommerce-checkout-optimization/false-declines/
Stripe Documentation, "Dispute and fraud card monitoring programs" (2026). https://docs.stripe.com/disputes/monitoring-programs
Visa, "Compelling Evidence 3.0 Merchant Readiness" (March 2023). https://usa.visa.com/content/dam/VCOM/regional/na/us/support-legal/documents/compelling-evidence-3-0-merchant-readiness-mar2023.pdf
Visa Business News AI16011, Updates to Remedy Rule (CE3.0) for Dispute Condition 10.4 (January 29, 2026). Cited in Forter, March 2026.


