Why do card networks run compliance programs at all?
Visa, Mastercard, American Express, and Discover each maintain their own programs designed to monitor and limit excessive chargebacks and fraud activity across the merchants processing on their networks. These programs exist because unusually high chargeback or fraud rates at a merchant — or across a portfolio of merchants — represent real risk to the network's own reputation and to the issuing banks that ultimately absorb disputed transactions. The programs put concrete thresholds on that activity, and merchants (or the ISOs and acquirers responsible for them) that exceed those thresholds face escalating consequences, from fees to eventual network-level restrictions.
The specific program names and mechanics differ by network — Visa's program is commonly referred to as VAMP (Visa Acquirer Monitoring Program), and Mastercard's as ECM (Excessive Chargeback Merchant program), with American Express and Discover maintaining their own equivalents — but the underlying structure is similar across all of them: monitor chargeback and fraud ratios, and escalate consequences as those ratios cross defined thresholds.
What actually gets measured?
While exact mechanics and thresholds are set and periodically updated by each network directly (and any ISO or FSP should track network documentation for current specifics, since these change), the general categories of what gets monitored are consistent:
- Chargeback ratio — the number of chargebacks relative to total transaction volume, over a defined period.
- Fraud ratio — transactions identified as fraudulent relative to total volume.
- Absolute chargeback or fraud counts — some programs also apply thresholds based on raw counts, not just ratios, which matters for lower-volume merchants where a small number of chargebacks can still represent a high ratio.
A merchant that crosses a threshold typically enters an escalating series of consequences — additional fees, mandatory reporting, and in persistent cases, restrictions on the merchant's ability to continue processing under that network.
Why does this matter beyond the individual merchant?
For an ISO or FSP, card brand program exposure isn't just an individual merchant's problem — it reflects on the entire portfolio's standing with the network, and in aggregate, on the sponsor bank backing that portfolio. A pattern of merchants crossing thresholds, even if no single merchant is dramatically over, can draw scrutiny to the ISO's underwriting practices or the sponsor bank's program oversight more broadly.
This is part of why card brand program monitoring belongs at the portfolio level, not just the individual merchant level — an ISO or FSP needs visibility into which merchants are trending toward a threshold across the entire book of business, not just reactive alerts after a specific merchant has already crossed one.
What makes monitoring this difficult in practice?
A few recurring operational challenges show up across the industry:
- Thresholds and program mechanics change periodically, and staying current requires actively tracking network updates rather than assuming last year's rules still apply.
- Chargeback and fraud data often lives in a different system than underwriting and onboarding data, making it hard to connect "this merchant is trending toward a threshold" with "here's what we know about this merchant's risk profile from onboarding."
- Reactive monitoring catches problems late. If exposure is only visible after a merchant has already crossed a threshold, the ISO is managing consequences rather than preventing them.
What does proactive monitoring actually require?
Effective card brand program monitoring generally needs:
- Per-merchant, per-network tracking of chargeback and fraud ratios, updated frequently enough to catch a trend before it becomes a violation.
- Portfolio-level visibility, so patterns across multiple merchants (not just outliers) are visible to whoever owns program risk.
- A connection back to underwriting data, so a merchant approaching a threshold can be evaluated in the context of what was already known about it at onboarding.
- Escalation paths defined in advance — knowing what action to take (increased monitoring, additional reserves, in severe cases offboarding) before a threshold is actually crossed, not improvised afterward.
This is the kind of monitoring NGnair builds directly into merchant onboarding and portfolio operations — per-card-brand program tracking across VAMP, ECM, and their Amex and Discover equivalents, visible at the portfolio level rather than discovered merchant by merchant after the fact.
The short version
Card brand compliance programs like VAMP and ECM put real thresholds on chargeback and fraud activity, with consequences that scale from fees to processing restrictions. The operational challenge for ISOs and FSPs isn't understanding that these programs exist — it's building monitoring that connects chargeback data, fraud data, and underwriting data at the portfolio level, early enough to act before a threshold is actually crossed.
NGnair builds this monitoring directly into onboarding and portfolio operations — portfolio-wide visibility, not merchant-by-merchant discovery after the fact.