Merchant Debanking in 2026: Why I Believe VAMP and SMMP Conflict With the FTC’s Direction

This is an opinion and analysis article based on my experience in the payments industry. It is not legal advice, and it does not allege that Visa, Mastercard, any bank, or any payment provider has violated the law.

Let me begin with something important: I believe payment fraud should be taken seriously. I have worked in payments for more than a decade. At Align Ecommerce, we support complex and higher-risk businesses, but that does not mean every business should be approved or that every merchant account should remain open regardless of what happens after approval. Scam merchants should be removed. Fraud should be investigated. Businesses should be held accountable for misleading marketing, improper billing, unresolved consumer complaints, excessive disputes, transaction laundering, or activity that does not match what was disclosed during underwriting.

My concern is what happens in the space between a legitimate risk signal and a final decision to remove a merchant from the payment ecosystem. Visa’s Acquirer Monitoring Program, better known as VAMP, places significant pressure on acquiring banks to control fraud and disputes across their portfolios. Mastercard’s new scam-merchant monitoring requirements give acquirers and payment facilitators defined signals that can require an investigation to begin within 72 hours. At nearly the same time, the federal government is telling financial institutions and payment companies that lawful businesses should not be denied access to financial services on the basis of political, religious, ideological, or subjective reputational concerns. In my opinion, those directions can conflict in practice, even if they do not directly contradict one another on paper.

The question I keep coming back to is simple: How do we remove actual bad actors quickly without turning every risk signal into a reason to close a legitimate merchant account?

What the FTC Actually Said About Payment-Industry Debanking

On March 26, 2026, Federal Trade Commission Chairman Andrew Ferguson sent warning letters to the CEOs of Visa, Mastercard, Stripe, and PayPal.

The letters focused primarily on reports of consumers and businesses losing access to financial services because of political or religious views. They also raised a broader concern about payment companies refusing, suspending, or withdrawing services in ways that may be inconsistent with their stated terms or otherwise unfair.

The FTC’s warning letter to Visa specifically addressed merchant eligibility, suspension and termination procedures, prohibited conduct, and dispute resolution. The FTC also warned Visa and Mastercard about facilitating or ignoring unlawful debanking by financial institutions using their networks.

These were warning letters—not findings that the companies had violated the FTC Act. They also did not say that every lawful business must be approved for payment processing or that a processor can never terminate an account.

Fraud, financial exposure, sanctions, unlawful activity, excessive disputes, deceptive business practices, and violations of a disclosed merchant agreement remain legitimate risk considerations.

But the message from the FTC was still significant: access decisions should not be arbitrary, misleading, viewpoint-driven, or inconsistent with what a payment provider has promised its customers.

Donald Trump’s Executive Order and the Push Against Reputational Debanking

The FTC letters also referenced President Donald Trump’s August 7, 2025, Executive Order 14331, “Guaranteeing Fair Banking for All Americans”.

The executive order defines politicized or unlawful debanking as restricting financial services based on political or religious beliefs, or because a financial provider politically disfavors a customer’s lawful business activities.

It directs federal banking regulators to remove reputation risk—or similar subjective concepts that could produce politicized debanking. From supervisory materials. It also pushes regulators toward individualized, objective, and risk-based decision-making.

On June 2, 2026, the Federal Reserve, FDIC, and Office of the Comptroller of the Currency removed additional references to reputation risk from interagency supervisory documents. The agencies explained that reputation risk could be misused to pressure banks into restricting lawful businesses.

That action governs bank supervision. It does not prohibit a private bank, card network, or payment provider from maintaining its own lawful risk appetite, and the executive order itself does not create a private legal right requiring a processor to approve every merchant.

Nevertheless, the policy direction is clear: decisions should be tied to material financial, legal, fraud, or compliance risk—not a vague dislike of a business, its owners, or its audience.

This is where I believe the payments industry is entering difficult territory.

VAMP Creates Pressure Beyond the Published Merchant Threshold

Visa describes VAMP as a program for identifying excessive fraud and dispute activity at both the acquirer and merchant levels. Its purpose is understandable: reduce fraud, reduce disputes, and make the payment ecosystem safer.

The complication is that acquiring banks are responsible for the performance of their complete merchant portfolios.

That means a merchant does not operate in isolation. An acquirer approaching a portfolio threshold may tighten its internal standards, require remediation, increase reserves, reduce volume, or terminate merchants before those merchants cross a published card-brand threshold.

NMI acknowledged this pressure in its July 8, 2026, VAMP guidance for payment partners. NMI explained that merchants considered borderline under previous monitoring programs may need to be remediated or terminated earlier and recommended setting internal thresholds below VAMP’s limits.

From the bank’s perspective, that may be rational portfolio management.

From the merchant’s perspective, it can feel like debanking.

A merchant could be operating below Visa’s published excessive threshold and still lose processing because its acquirer has a lower internal limit, a concentrated portfolio, a different risk appetite, or pressure from another part of the payment chain.

VAMP does not necessarily order the closure of that particular merchant. But the economic incentive created by VAMP can still contribute to the closure.

That distinction will not mean much to a legitimate business that suddenly cannot accept payments.

For a full explanation of the program and its current metrics, read Align’s Visa VAMP 2026 guide.

SMMP Creates an Even More Difficult Question

Mastercard’s scam-merchant monitoring requirements deserve even closer attention because the triggers are different from ordinary chargeback-monitoring programs.

Under Mastercard’s current Security Rules and Procedures—Merchant Edition, an acquirer or payment facilitator must initiate an investigation within 72 hours after one of several defined signals identifies a card-not-present merchant as a potential scam merchant.

Depending on the merchant’s history and circumstances, those signals can include:

  • A sharp reduction in authorization approval rates

  • A Mastercard Global Rules Investigation Program letter connected to suspected scam activity

  • Scam reports or chargebacks from multiple issuers

  • For merchants with six months or less of Mastercard acceptance history, a combined refund-and-chargeback rate above 5% during a qualifying 30-day period

  • An alert from a Merchant Monitoring Service Provider identifying a potential scam or suspected illegal activity

The important distinction is that the 72-hour requirement is to initiate an investigation. It is not a rule requiring every triggered merchant to be terminated within 72 hours.

If the investigation confirms that the merchant is a scam merchant, Mastercard requires the acquirer to block the merchant’s Mastercard transaction authorization and, when applicable, clearing services.

That is an appropriate outcome for a confirmed scam.

The concern is whether every processor, payment facilitator, and acquiring bank will consistently preserve the distinction between potential and confirmed.

A legitimate startup could exceed the combined refund-and-chargeback trigger due to a product issue, a fulfillment disruption, seasonal returns, poor communication, a confusing subscription offer, or an operational mistake. An established merchant could experience a sudden decline rate collapse due to a technical configuration issue, issuer response, fraud attack, or an unexpected traffic source.

Those events may justify immediate attention. They do not automatically prove the merchant is operating a scam.

Our Mastercard SMMP guide explains the triggers and the 72-hour investigation requirement in greater detail.

A Risk Trigger Should Trigger a Review—Not Replace One

This is the heart of my opinion.

The card brands are telling acquirers to identify problems faster, investigate more aggressively, and protect the ecosystem from fraud and scams.

The federal government is telling financial regulators and payment companies that lawful customers should receive objective, individualized, and apolitical treatment—and that companies should honor their stated terms and customers’ reasonable expectations.

An acquiring bank or processor may have to satisfy both directions at once.

I do not believe those goals are inherently incompatible. Strong fraud controls and fair access can coexist.

They become incompatible when:

  • An automated alert becomes an automatic closure

  • A risk trigger is treated as a final finding

  • A processor cannot explain the objective reason for its decision

  • Internal standards are materially stricter than disclosed expectations but are presented as card-brand mandates

  • “Reputational risk” or “brand damage” replaces a measurable financial, legal, fraud, or compliance concern

  • A legitimate merchant is given no meaningful opportunity to provide context or corrective evidence

  • Different merchants presenting comparable risk receive materially different treatment for reasons unrelated to payment risk

Mastercard’s August 2026 rules still reference activity that may be “illegal or brand-damaging” within ongoing merchant-monitoring guidance. Illegal activity is objective enough to investigate. “Brand-damaging” activity can be far more subjective.

That language does not automatically make Mastercard’s monitoring rules unlawful. But in my opinion, it demonstrates the unresolved tension between the card brands’ interest in protecting their networks and the government’s push to remove vague reputational considerations from financial-access decisions.

Who defines brand damage? What evidence is required? Is the concern connected to fraud or financial exposure? Can the merchant correct the underlying issue? Does the same standard apply consistently across businesses and viewpoints?

Those questions matter.

Not Every Merchant Closure Is Debanking—but Some Deserve More Scrutiny

The word “debanking” is sometimes used too broadly.

A processor declining an unlawful business is not politicized debanking. Closing an account for confirmed fraud, undisclosed products, transaction laundering, excessive financial exposure, or a material violation of the merchant agreement is not automatically unfair.

Payment providers cannot be required to ignore genuine risk.

At the same time, telling a merchant only that it presents “unacceptable risk” does not explain whether the actual concern involved fraud, disputes, future delivery, regulatory exposure, prohibited products, reserves, marketing, customer complaints, or an unrelated reputational judgment.

There is a meaningful difference between legitimate risk management and a black box.

This is particularly important for lawful industries that have historically struggled to obtain stable payment services. A business can be legal and still be higher risk. Higher risk can justify specialized underwriting, reserves, limits, monitoring, or stronger controls. It should not automatically mean that no bank is permitted to understand and support the business.

That is why I believe separately underwritten merchant accounts remain important. They create an opportunity to evaluate the products, marketing, transaction flow, fulfillment, financial condition, cancellation practices, and processing history before the account begins processing.

As explained in our high-risk payment-processing guide, underwriting is not a guarantee against future monitoring or closure. It is a chance to build the relationship on accurate information from the beginning.

What I Believe a Fair Merchant Risk Review Should Include

If the payments industry wants to enforce VAMP and SMMP while respecting the direction established by the FTC and the executive order, I believe a defensible review process should include:

An objective reason for the review

The file should identify whether the concern involves fraud, disputes, authorization patterns, refund activity, consumer complaints, transaction laundering, prohibited activity, financial exposure, or another defined factor.

A distinction between a trigger and a conclusion

An alert should open the investigation. It should not decide the outcome before the evidence is reviewed.

Appropriate human oversight

Automation is necessary at scale, but severe decisions affecting a legitimate business should not depend entirely on an unexplained model or keyword.

Relevant merchant evidence

When law and consumer protection allow it, the merchant should be able to provide fulfillment records, refund logs, customer communications, marketing materials, authorization data, fraud-screening evidence, and an explanation of any operational anomaly.

Consistency with the agreement

The provider should follow the eligibility, reserve, suspension, termination, and review procedures represented in its contract and policies.

A documented final decision

The payment provider should be able to demonstrate that its decision was connected to material payment, financial, legal, or compliance risk—not political pressure, religious bias, or an undefined dislike of the business.

Not every case will permit advance notice or a lengthy appeal. Confirmed fraud and unlawful activity can require immediate action. But speed should not eliminate accuracy when a good merchant may be caught in the process.

How Align Ecommerce Approaches the Issue

Align Ecommerce is compliance-first. We do not believe that means approving every merchant or trying to avoid card-brand rules.

It means understanding the business before selecting a payment relationship.

We review what the merchant sells, how it markets, when customers are charged, how products or services are fulfilled, what the cancellation terms say, what the processing history shows, and where the actual risk originates.

If a merchant is not supportable, we should be able to explain the reason for the concern. If the business may be supported with different controls, documentation, reserves, limits, or technology, those conditions should be discussed honestly.

Changing gateways alone will not solve an underwriting or card-brand problem. Our guide to using Authorize.net instead of Stripe on Shopify explains why the complete merchant-account relationship matters more than the gateway name.

My position is not that merchants have a right to process regardless of risk.

My position is that legitimate businesses deserve accurate underwriting, objective monitoring, and a real investigation before a warning signal is treated as a verdict.

My Final Thought

I am curious to see how this plays out.

The government is moving away from subjective reputational debanking. The FTC has warned the largest payment gatekeepers about unfair or inconsistent deplatforming. Meanwhile, Visa and Mastercard are placing more responsibility on acquiring banks to identify and control merchant risk quickly.

All three objectives—fair access, consumer protection, and payment-system integrity—can be valid.

But somebody still has to decide what happens to the merchant.

If VAMP and SMMP encourage better monitoring and more accurate investigations, the ecosystem will be stronger. If they encourage processors to close legitimate merchants preemptively because an automated signal is easier to act on than it is to understand, the industry may create the very access problem federal policy is trying to prevent.

That is the contradiction I see.

And as these rules mature, I believe merchants, processors, acquiring banks, card brands, and regulators need to keep asking the same question:

Are we removing a documented threat—or are we removing a lawful business because nobody wants to take the time to understand it?

If your business is facing a reserve, account review, VAMP exposure, SMMP investigation, or unexplained processing restriction, request a free payment risk review. Approval and account terms remain subject to underwriting, but the first step should be understanding the actual issue.

Frequently Asked Questions

Merchant Debanking, VAMP, and SMMP

These answers address common questions about payment-account closures, the FTC's debanking warning, President Trump's fair-banking executive order, Visa VAMP, and Mastercard SMMP.

Do the FTC's debanking warning letters prevent a processor from terminating a merchant?

No. The FTC's letters seek information about whether major payment companies have denied or limited service based on protected speech or lawful activity. They do not automatically prevent a processor, acquirer, or bank from restricting or terminating a merchant for contractual, fraud, compliance, or risk reasons.

Does President Trump's fair-banking executive order protect merchants from payment-account closures?

The executive order directs federal banking regulators to address politicized or unlawful debanking and to remove reputation-risk concepts from relevant guidance. Whether it reaches a particular merchant-account closure can depend on the institutions involved, the reason for the action, later agency implementation, contractual terms, and applicable law. It is not a guarantee that every merchant must be approved or retained.

Are Visa VAMP and Mastercard SMMP illegal or in direct conflict with the FTC?

Not inherently. VAMP and SMMP are private card-network risk programs, while the FTC and federal banking agencies enforce public law within their respective authority. My concern is the practical tension: government policy is pushing against exclusions based on politics or lawful business activity, while aggressive network monitoring can still encourage conservative decisions that remove legitimate merchants.

How are VAMP and SMMP different?

Visa's Acquirer Monitoring Program broadly evaluates fraud and dispute performance across card-not-present activity at the acquirer and merchant levels. Mastercard's Scam Merchant Monitoring Program focuses more directly on merchants associated with alleged scam activity and can create tighter, case-specific scrutiny and response timelines. The exact consequences depend on current network rules, the evidence involved, and the acquiring relationship.

Can a legitimate merchant be terminated even if it is below a VAMP or SMMP trigger?

Yes. A published monitoring threshold is not a guaranteed safe harbor. Processors, acquiring banks, sponsor banks, platforms, and card networks can apply separate underwriting, fraud, compliance, reserve, and acceptable-use standards. That is why a merchant may face scrutiny or termination even when its headline ratios appear compliant.

What should a merchant do after receiving a payment restriction or termination notice?

Ask for the specific reason and effective date, identify which party made the decision, preserve every notice, and compare the stated concern with transaction, fraud, refund, and dispute data. Then prepare a concise remediation package and speak with qualified payments, compliance, and legal professionals before changing descriptors, routing volume, or opening a replacement account.

Next
Next

Travel Agency Payment Processing in 2026: Merchant Accounts, Reserves and Future-Delivery Risk