Mastercard SMMP Is Live: What the 72-Hour Rule Really Means

Mastercard’s Scam Merchant Monitoring Program is now live—and some of the most repeated explanations online are missing important limits in the rule.

Here is the distinction that matters most: an SMMP signal does not automatically prove that a merchant is a scam. It requires the merchant’s acquirer or payment facilitator to begin an investigation within 72 hours. If that investigation confirms scam activity, the consequences can be severe: Mastercard and Maestro authorizations must be blocked and, where applicable, clearing must be blocked.

That is a short clock for the institution managing your merchant account. It may be an even shorter practical clock for you if your processor requests evidence after the review has already started.

For legitimate merchants, the right response is not panic. It is preparation.

Quick answer: Mastercard SMMP took effect July 24, 2026. It gives acquirers and payment facilitators defined signals for investigating potential scam merchants. The 72-hour requirement is to start the investigation—not necessarily to complete it. The widely discussed 5% refund-and-chargeback test is limited to merchants with six months or less of Mastercard history and at least 500 purchases in the rolling 30-day window.

Mastercard SMMP at a glance

QuestionSource-checked answerWhat is SMMP?Mastercard’s Scam Merchant Monitoring Program, aimed at identifying potentially fraudulent or scam merchant activity.When did it take effect?July 24, 2026.Who investigates?The merchant’s acquirer or payment facilitator.What does 72 hours mean?The investigation must be started within 72 hours after a qualifying signal—not necessarily finished within that period.Does every merchant face the 5% test?No. That specific test applies to merchants with six months or less of Mastercard acceptance history and at least 500 purchase transactions in a rolling 30-day period.What happens at exactly 5%?The rule is described as more than 5%. At 500 purchases, 25 affected transactions equal exactly 5%; 26 equal 5.2%.Does a trigger prove fraud?No. A trigger initiates an investigation. Blocking follows if the investigation confirms scam activity.Is MATCH placement automatic?The public materials reviewed do not establish automatic MATCH placement merely because an SMMP trigger occurs. MATCH reporting is a separate compliance analysis tied to termination circumstances and applicable rules.

The operative details summarized here are drawn from Mastercard materials and analyses of Mastercard bulletin GLB 12772.1, which amended relevant portions of Mastercard’s Security Rules and Procedures. Mastercard’s own rules and standards page remains the controlling place to check for updated manuals.

Why Mastercard created SMMP

Scam merchants can look legitimate long enough to process real payments. They may operate polished storefronts, misrepresent goods or services, manipulate consumers into authorizing transactions, or disappear after collecting funds.

Mastercard describes its broader merchant-trust strategy as an effort to identify fraudulent storefronts earlier and stop confirmed bad actors from continuing to accept transactions. Its public explanation of Merchant Trust Services focuses on that preventive goal.

SMMP is different from a classic excessive-chargeback program. Chargeback programs usually evaluate ratios or counts over a defined reporting period. SMMP adds behavioral and intelligence signals that can require a much faster investigation.

The four SMMP trigger groups merchants should understand

Analyses of Mastercard bulletin GLB 12772.1 identify four broad groups of signals. The exact operational notice and evidence request will come through your acquirer, payment facilitator, processor or ISO.

1. A sharp authorization-performance anomaly

This signal involves at least 25 purchase transactions observed across at least 72 hours, combined with either:

  • an approval-rate decline of at least 50 percentage points; or

  • an approval rate below 30%.

Known system issues and BIN attacks are excluded from this signal. That exclusion is important, but it is useful only if the merchant and processor can document the cause quickly.

2. A GRIP letter tied to suspected scam activity

Information from Mastercard’s Global Risk Leadership Initiative Program can prompt an investigation when it points to potential scam merchant activity.

3. Defined issuer or refund/chargeback activity at a newer merchant

For a merchant with six months or less of Mastercard acceptance history, an investigation can be triggered by any of the following described signals:

  • reports from two issuers identifying scam transactions under Mastercard Fraud Type 56;

  • fraud or non-fraud chargebacks from two issuers with supporting documentation referencing a scam, manipulation or similar conduct; or

  • more than 5% of purchase transactions becoming subject to refunds, chargebacks or both during a rolling 30-day period, provided the merchant had at least 500 purchase transactions during that period.

This is where much online coverage becomes misleading. The more-than-5% test is not presented as a universal SMMP threshold for every merchant. It is one signal inside the newer-merchant group.

Established merchants are not outside SMMP. They can still be implicated by the authorization anomaly, GRIP information or MMSP alerts discussed here.

4. An alert from a registered Merchant Monitoring Service Provider

One or more alerts from a registered MMSP identifying potential scam or illegal activity can also prompt review. Registered MMSP Austreme’s summary describes the program’s signal groups, daily FLD checking and investigation requirement.

For the most detailed public legal analysis of the rule language, see Rome LLP’s review of GLB 12772.1.

The 5% rule: a simple 500-transaction example

Assume a newer merchant records 500 Mastercard purchase transactions during a rolling 30-day period.

Transactions subject to refunds, chargebacks or bothPercentageAbove 5%?244.8%No255.0%No—the published wording is “more than 5%”265.2%Yes

This does not mean a merchant should refuse legitimate refunds. Withholding a refund can harm customers, increase disputes and create separate legal or card-network problems.

The correct operational lesson is to understand why refunds are occurring, reduce preventable refund demand, and monitor the rolling window before the ratio becomes a surprise.

There is also an important counting question to settle with your processor: the rule is described in terms of purchase transactions subject to refunds, chargebacks or both. Merchants should not assume that their own dashboard’s event count uses the same deduplication logic as the acquirer’s SMMP reporting. Ask how a purchase that has both a refund and a chargeback is treated in the institution’s monitoring data.

What the 72-hour requirement does—and does not—mean

The higher-quality rule analyses say the acquirer or payment facilitator must begin its investigation within 72 hours of the qualifying signal.

That is not the same as saying:

  • the merchant receives a guaranteed 72-hour grace period;

  • the merchant will be notified at the moment the clock starts;

  • the merchant always gets 72 hours to respond; or

  • every investigation must reach a final decision within 72 hours.

Your processor may still impose a short evidence deadline or take protective action under its merchant agreement. That is why the evidence file should exist before an alert.

A trigger is not the same as a confirmed scam

This distinction deserves its own section because fear-based coverage often collapses two different stages.

  1. A defined signal occurs. The acquirer or payment facilitator must start an investigation.

  2. The institution evaluates the merchant. It reviews transaction behavior, issuer information, business legitimacy, consumer experience and other relevant evidence.

  3. If the merchant is cleared, processing may continue. The institution should retain its investigation record.

  4. If scam activity is confirmed, Mastercard/Maestro authorization must be blocked. Clearing must also be blocked where applicable.

An acquirer may terminate the merchant relationship under its agreement, but an SMMP signal alone should not be described as an automatic MATCH listing. MATCH Pro obligations depend on the facts, the termination reason and the card-network rules governing acquirer reporting.

That is a question merchants should put directly to their acquirer: If you terminate a merchant after an SMMP investigation, which MATCH Pro reason code would you evaluate, and what facts would support it?

Fraud Type 56 is not “friendly fraud”

Mastercard’s official Fraud and Loss Database annexure identifies Fraud Type 56 as Manipulation of Cardholder.

That category aligns with scam scenarios in which a consumer is deceived or manipulated into participating in a transaction. Mastercard’s scam research discusses examples such as purchase, romance, impersonation, investment and advance-fee scams in its digital-trust white paper.

Calling Type 56 “friendly fraud” or ordinary first-party misuse is inaccurate. That error can cause a merchant to prepare the wrong evidence and misunderstand why issuers are reporting the activity.

Five SMMP myths to retire

MythWhat merchants should know“Every merchant is subject to the 5% rule.”The special more-than-5% test is described for merchants with six months or less of Mastercard history and at least 500 purchases in the rolling period. Other signals can apply more broadly.“The investigation must be completed in 72 hours.”The cited rule analysis says the investigation must begin within 72 hours. Your institution may still use a faster internal response deadline.“A trigger means Mastercard has proven the merchant is a scam.”A signal starts an investigation. Blocking is required after scam activity is confirmed.“Fraud Type 56 means friendly fraud.”Mastercard defines Type 56 as Manipulation of Cardholder.“SMMP automatically puts a merchant on MATCH.”The sources reviewed do not establish automatic MATCH placement from a trigger. MATCH reporting requires a separate, fact-specific analysis.

SMMP compared with other merchant-monitoring programs

These programs can overlap, but they answer different risk questions.

ProgramPrimary focusPractical distinctionMastercard SMMPPotential scam-merchant activityBehavioral/intelligence signals can start a rapid investigation; it is not limited to a monthly dispute ratio.Mastercard ECP / ECM / HECMExcessive chargeback activityRatio-and-count monitoring focused on chargeback performance and escalation.Mastercard EFMExcessive fraud activityFraud-performance monitoring rather than a determination that the merchant itself is operating a scam.Visa VAMPAcquirer-level fraud and dispute performanceVisa’s consolidated approach combines fraud and dispute monitoring; current rules should be checked in Visa’s official materials.

For Visa’s own conceptual explanation, see its VAMP overview. Do not borrow a threshold from one program and apply it to another.

If you need a broader foundation, Align Ecommerce’s payment processing glossary explains common risk and processing terms, while our payment technology resources cover the systems behind transaction performance.

Which legitimate merchants are operationally exposed?

Mastercard does not publicly frame SMMP as a campaign against legitimate business models. Still, some operating patterns can create more investigative friction:

  • a new MID scaling quickly toward or beyond 500 transactions per month;

  • subscriptions, trials or continuity offers that generate avoidable cancellations and refunds;

  • digital services where delivery is harder to prove than physical shipment;

  • coaching, lead generation, affiliate-driven or high-ticket offers with aggressive marketing claims;

  • sudden authorization declines caused by a gateway, issuer, routing or configuration problem;

  • a rebrand or descriptor change that customers do not recognize;

  • multiple MIDs without a documented business, legal, MCC or operational rationale; and

  • support delays that turn solvable complaints into refunds, disputes or issuer reports.

These are not proof of wrongdoing. They are reasons to make the legitimate business easier to verify.

Build the evidence file before an alert

A credible response package should let the processor understand the business quickly. Maintain:

  • Entity and account map: legal entities, DBAs, owners, domains, MIDs, acquiring relationships, MCCs and fulfillment locations.

  • Multiple-MID rationale: why each MID exists, which products it covers, who approved the structure and how traffic is routed.

  • Customer journey: current screenshots of ads, landing pages, checkout, price disclosure, subscription consent, cancellation flow and confirmation pages.

  • Policy archive: dated versions of terms, refund policy, cancellation policy, privacy policy and customer-service commitments.

  • Fulfillment proof: carrier records, login/access logs, usage records, signed delivery, service milestones or other product-specific evidence.

  • Marketing controls: approved claims, affiliate agreements, monitoring results and evidence of corrective action.

  • Support records: response-time metrics, complaint categories, escalation logs and examples of resolved issues.

  • Transaction monitoring: rolling 30-day purchases, refunds, chargebacks and the internal counting method used.

  • Authorization analysis: daily approval rate, decline codes, gateway incidents, suspected BIN attacks and processor incident tickets.

  • Issuer and network alerts: GRIP, FLD, Fraud Type 56, chargeback-documentation themes and MMSP notices, if provided.

  • Response ownership: a named executive, payments lead, risk lead, customer-service lead and outside adviser who can assemble evidence immediately.

Not sure what your processor would see first? Align Ecommerce can review your merchant-account structure, transaction trends, refund and dispute exposure, customer journey and documentation readiness. Request a free risk review.

Seven questions to ask your processor or acquirer now

  1. What date do you use as the start of our Mastercard acceptance history?

  2. How do you calculate purchase transactions “subject to refunds, chargebacks or both” when a single purchase has both events?

  3. How and when will you notify us that an SMMP investigation has started?

  4. What evidence will you request, who reviews it and what response deadline will we receive?

  5. How do you distinguish a BIN attack or known system issue from a merchant-driven approval-rate collapse?

  6. If we use multiple MIDs, what documentation do you have supporting their legitimate business purpose?

  7. If an investigation led to termination, how would you evaluate separate MATCH Pro reporting obligations?

Record the answers. A vague promise that “risk will contact you if anything happens” is not an incident plan.

What merchants should do this week

Start with a narrow, evidence-driven review:

  1. Confirm the age of every Mastercard MID and identify those at six months or less.

  2. Calculate the rolling 30-day purchase count and the percentage of purchases subject to refunds, chargebacks or both.

  3. Review authorization approval rates daily, not just monthly, and document system incidents.

  4. Audit customer-facing claims, pricing, descriptors, cancellation and fulfillment evidence.

  5. Document the reason for every MID and make sure the live traffic matches that explanation.

  6. Establish a response owner and a same-day escalation path with your processor.

  7. Ask for written clarification wherever your processor’s counting or investigation process differs from your assumptions.

The goal is not to “game” SMMP. It is to reduce preventable customer harm and make legitimate activity verifiable before a compressed investigation puts the relationship under pressure.

The bottom line

SMMP raises the cost of weak documentation and slow communication. It also creates an opportunity for legitimate merchants to separate themselves from bad actors by building a clear, defensible operating record.

Three facts should guide your response:

  • the 72-hour requirement is the institution’s investigation-start clock, not a guaranteed merchant grace period;

  • the more-than-5% test is specific to a defined newer-merchant cohort and transaction minimum; and

  • a signal begins an investigation—it should not be reported as an automatic finding of fraud or automatic MATCH placement.

If your merchant account is new, complex, high-risk, experiencing rising refunds or disputes, or spread across multiple MIDs, this is the time to test your readiness.

Get a free SMMP risk review from Align Ecommerce

Align Ecommerce helps merchants assess payment risk, improve the evidence behind their processing relationships and communicate more effectively with acquiring partners. A review cannot guarantee that a processor or card network will approve, retain or clear an account—but it can expose avoidable gaps before they become urgent.

This article is educational and does not constitute legal advice or a guarantee of processor, acquirer or card-network outcomes. Mastercard rules and institutional procedures can change; confirm current requirements with your acquirer and Mastercard’s official rules.

Joshua Cobian, President of Align E-Commerce

Joshua
Cobian

President of Align E-Commerce

Joshua Cobian is the President of Align Ecommerce, a Las Vegas-based payment processing firm specializing in ecommerce, high-risk merchant accounts, and emerging verticals. With over a decade of industry experience, he helps businesses secure reliable payment infrastructure, reduce risk, and scale with confidence.

Mastercard SMMP
2026 FAQ

Mastercard SMMP is the Scam Merchant Monitoring Program. It gives acquirers and payment facilitators defined signals for investigating card-not-present or sponsored merchants that may be involved in scam activity.

The revised SMMP standards took effect July 24, 2026.

The authoritative analyses reviewed say the acquirer or payment facilitator must begin the investigation within 72 hours. Merchants should not interpret that as a guaranteed 72-hour response period or assume every investigation must be completed inside that window.

That specific trigger applies to merchants with six months or less of Mastercard acceptance history, at least 500 purchase transactions in a rolling 30-day period, and more than 5% of purchase transactions subject to refunds, chargebacks, or both.

Yes. Refunds can count in the newer-merchant more-than-5% test. Merchants should confirm with their acquirer how it counts a purchase that has both a refund and a chargeback.

No. Mastercard’s official Fraud and Loss Database documentation defines Fraud Type 56 as Manipulation of Cardholder. It should not be labeled as ordinary friendly fraud or first-party misuse.

The public materials reviewed do not establish that an SMMP trigger automatically creates a MATCH Pro listing. A trigger starts an investigation. MATCH reporting is a separate analysis tied to the facts, termination reason, and applicable reporting rules.

Prepare an entity-and-MID map, customer-journey screenshots, policy versions, fulfillment proof, marketing controls, support records, rolling transaction data, authorization-incident records, and a documented response team.

Next
Next

The Ultimate Local's Guide to the CHAMPS Trade Show Las Vegas 2026