Mastercard GMAP 2026: the program is suspended
Mastercard's GMAP remains suspended. What still applies in 2026 — ECP, EFM, the 72-hour investigation rule — and which actor each rule binds.
Does Mastercard’s GMAP still exist?
The Global Merchant Audit Program (GMAP) remains in Mastercard’s rule text, but it is not in force. The August 4, 2026 edition of the Security Rules and Procedures — Merchant Edition says the program “has been suspended until further notice.” There is therefore no primary public basis for presenting a “new GMAP” as an active program with a settled formula, defined thresholds, or enforcement in April 2027.
Source: Mastercard Security Rules and Procedures — Merchant Edition, August 4, 2026.
The suspension has not reduced Mastercard’s oversight of the acquiring chain. The Excessive Chargeback Program (ECP), Excessive Fraud Merchant (EFM), and other obligations remain in force, and each one names a different actor: the ECP measures the merchant, but the entity Mastercard bills is the acquirer; whoever operates as a Payment FacilitatorAn entity that, under an acquirer’s sponsorship, brings merchants onto the Mastercard network and monitors their activity. Here, it is the formal role a sub-acquirer may perform. (PayFac) — typically a sub-acquirer — must continuously monitor every merchant it manages; and the requirement to investigate certain potential scam signals within 72 hours falls on the acquiring chain as a whole.
This article separates what Mastercard has confirmed from what remains unconfirmed. That distinction changes decisions at every position in the chain: no link in the chain should commit on a rule the network has not published — the acquirer and the Payment Facilitator should not set reserves or promise a compliance deadline on one, and the Payment Facilitator and the merchant should not answer their sponsor on one.
Screenshots, private communications, and market interpretations may help frame questions, but they do not turn a hypothesis into an official rule.
Which Mastercard merchant monitoring rules are in force today?
Mastercard confirms programs governing chargebacks, fraud, and merchant conduct, along with ongoing monitoring standards. It also confirms the Fraud and Loss Database (FLD) as its official fraud reporting service. The table shows the status of each item without presenting unpublished limits as rules.
| Program / obligation | Full name | Status |
|---|---|---|
| ECP | Excessive Chargeback Program | In force, with a public formula |
| EFM | Excessive Fraud Merchant | In force; thresholds still to be confirmed |
| QMAP | Questionable Merchant Audit Program | In force |
| BRAM | Business Risk Assessment and Mitigation | In force |
| Merchant Monitoring / Screening Standards | — | In force |
| Potential scam merchant investigation | — | In force since July 2026 |
| FLD | Fraud and Loss Database | Official service for reporting and managing fraud transactions |
Sources: Mastercard Security Rules and Procedures — Merchant Edition, August 4, 2026; Mastercard Rules, June 2, 2026; Mastercard Developers — Fraud and Loss Database.
The EFM is in force. The thresholds applicable to Brazil and Latin America remain unconfirmed in a current primary public source, as do the minimum fraud amount, minimum transaction volume, and 3DS requirements by region.
The obligations written for a Payment Facilitator extend to every Sponsored MerchantA merchant that accepts Mastercard under a Payment Facilitator’s management and an acquirer’s sponsorship. Its risk remains the responsibility of the acquiring chain., meaning every merchant registered under it with the network. They bind the company registered in that formal role, not any company that uses the “sub-acquirer” label commercially — and they do not reach a merchant boarded directly by an acquirer, which answers to that acquirer, itself required to monitor its merchants continuously. Before applying any threshold, confirm with the sponsor acquirer which role the company is registered in.
Source: Mastercard Rules, June 2, 2026.
How does the ECP calculate a merchant’s basis points?
The ECP measures chargebacks at the merchant level. The result is expressed in basis pointsOne basis point equals 0.01 percentage point. Multiplying a ratio by 10,000 expresses the rate in this unit., or bps, using this public formula:
Basis points = chargebacks received by the acquirer for a merchant in a calendar month ÷ Mastercard transactions acquired for the same merchant in the prior month × 10,000.
Source: Mastercard Security Rules and Procedures — Merchant Edition, August 4, 2026.
Consider a merchant with 50,000 Mastercard transactions in the prior month and 600 chargebacks received in the current month. The calculation is 600 ÷ 50,000 × 10,000 = 120 bps, or 1.20%.
The decisive detail is the denominator period. The ECP uses transactions from the prior month, not the current month. Volume processed now becomes the denominator only in the following month. A calculation that divides chargebacks by the same month’s volume measures something else. If prior-month volume falls and current chargebacks do not fall at the same rate, the indicator rises.
Mastercard uses two program classifications: Excessive Chargeback Merchant (ECM) and High Excessive Chargeback Merchant (HECM). The public edition directs readers to the Data Integrity Monitoring Program manual and the Pricing and Billing Resource Center in Mastercard Connect for the numeric thresholds, which are restricted-access documents. The ECM and HECM limits therefore remain unconfirmed in a public source, as do the assessmentsAn assessment is a charge Mastercard imposes on the acquirer for program noncompliance. The contract determines whether and how that cost travels down to the sub-acquirer or the merchant. for Brazil and Latin America. The example’s 120 bps is a correct calculation, but it does not support classifying the merchant in either tier.
Source: Mastercard Security Rules and Procedures — Merchant Edition, August 4, 2026.
What happens to the acquirer when a merchant becomes ECM or HECM?
Mastercard may assess the acquirer for ECP noncompliance involving a merchant classified as ECM or HECM. The merchant is measured, but the acquirer is the entity billed by the network. Any pass-through — from the acquirer to the sub-acquirer, and from the sub-acquirer to the merchant — depends on what each contract provides.
Sources: Mastercard Security Rules and Procedures — Merchant Edition, August 4, 2026; Mastercard Rules, June 2, 2026.
After six months in ECM or HECM status, consecutive or not, Mastercard may:
- call for an action plan with measures to reduce the merchant’s basis points;
- require a Franchise Management Program Customer Risk Review at the acquirer’s expense.
Source: Mastercard Security Rules and Procedures — Merchant Edition, August 4, 2026.
There is also a separate mechanism to compensate issuers. Mastercard provides for issuer recovery fees funded by amounts collected from the acquirer and states a minimum of USD 20 per payment to an issuer. That figure is neither a merchant fine nor the amount of an individual ECP assessment. The program’s assessment amounts remain unconfirmed until checked in the specific primary sources: the Data Integrity Monitoring Program manual and the Pricing and Billing Resource Center.
Source: Mastercard Security Rules and Procedures — Merchant Edition, August 4, 2026.
The causal chain is straightforward: the merchant accumulates chargebacks, the ECP measures that merchant, Mastercard may bill or require action from the acquirer, and the contract determines whether any consequence travels down to the sub-acquirer and the merchant. No pass-through is automatic merely because the merchant was classified.
What changed for potential scam merchants in July 2026?
Since July 2026, Mastercard has required an investigation within 72 hours when the applicable potential scam merchant criteria are met. If the investigation confirms the activity, the merchant must be prevented from accepting Mastercard. The deadline applies to the investigation; blocking depends on confirmation.
The rule links two steps. It does not offer two alternatives:
- When the criteria specified by the applicable standard are met, the acquiring chain must investigate the case within 72 hours.
- Only if the investigation confirms scam activity must the merchant be blocked from accepting Mastercard.
Source: Mastercard franchise standards revision announced in 2026, effective since July 2026. The document edition and identifier are not recorded in the sources consulted.
The public material reviewed does not specify when the clock starts, which exact criteria start it, or whether the trigger requires all requirements or at least one condition. Those points remain unconfirmed in the applicable standard and with the sponsor acquirer. The deadline and the consequence of a confirmed case, by contrast, are confirmed rules.
The 72-hour period is an incident response window, not a monthly routine. Weekly reviews, fragmented spreadsheet data, or a single analyst queue can prevent an operation from detecting the signal, collecting evidence, and completing the investigation on time.
Mastercard continues to hold the acquirer responsible for the chain, and the PayFac must continuously monitor every Sponsored Merchant. In practice, the 72-hour clock runs inside the operation that has the direct merchant relationship, firsthand transaction data, and the blocking mechanism: the sub-acquirer, when the merchant is its Sponsored Merchant, or the acquirer itself, when the merchant is boarded directly. That actor must detect the signal, open the case, collect evidence, and conclude the investigation; the merchant under investigation usually holds part of the evidence, and its delay consumes the same window. Blocking follows, only if the activity is confirmed.
Source: Mastercard Rules, June 2, 2026.
Who is accountable for what under the Mastercard Rules?
Mastercard allocates responsibilities across the acquiring chain. The acquirer remains accountable for the Sponsored Merchant, while the Payment Facilitator assumes duties for the merchants it manages. All of the following apply at the same time:
- the Sponsored Merchant Agreement does not relieve the acquirer of responsibility for the Sponsored Merchant’s chargebacks or compliance;
- the Payment Facilitator must ensure its Sponsored Merchants comply with the rules;
- the Payment Facilitator must continuously monitor each Sponsored Merchant’s activity and use of the Mastercard brands;
- the Payment Facilitator may maintain chargeback reserves;
- Mastercard, the acquirer, or the PayFac may terminate a merchant for fraudulent or wrongful activity.
Source: Mastercard Rules, June 2, 2026.
This structure leaves no link out. The merchant is the unit the programs measure. The Payment Facilitator — the role a sub-acquirer performs when registered in it — monitors Sponsored Merchants and may maintain reserves or terminate their processing. The acquirer remains accountable to the network, including for merchants that reach it through a PayFac. A contractual charge from the acquirer to the sub-acquirer therefore does not create a new obligation; it may be the mechanism used to carry out responsibilities that already exist in the acquiring chain.
Is the April 2027 “new GMAP” a rule or a rumor?
The alleged “new GMAP” remains unconfirmed. Market reports describe a reactivation in April 2027, a separate formula, and the replacement of SAFE by FLD as the fraud data source. None of those claims has been found in a primary public Mastercard source.
| Piece of the alleged “new GMAP” | What circulates in the market | What would confirm it |
|---|---|---|
| Existence and effective date | Program reactivated, effective April 2027 | Reactivation published in an edition of the Mastercard Rules or the Security Rules and Procedures |
| Formula and thresholds | Its own numerator, denominator, and limits, by merchant and portfolio | The formula and limits printed in the rule, as already occurs with the ECP formula |
| Data source | SAFE replaced by FLD as the program’s fraud data source | A formal statement of the replacement; today FLD is official only as a fraud reporting service |
| Timeline and costs | Defined advisory period, enforcement, and assessments | Dates and amounts in a primary network document, not a market communication |
FLD exists and is official. Mastercard Developers describes it as a service for reporting and managing fraud transactions with Mastercard. What remains unconfirmed is its use as part of a reactivated GMAP or as the formal replacement for SAFE in that program.
Source: Mastercard Developers — Fraud and Loss Database.
Until Mastercard publishes a new rule, the following remain unconfirmed: the reactivation or replacement of GMAP, its formula and components, merchant and acquirer portfolio thresholds, the formal replacement of SAFE by FLD, April 2027, an advisory period, enforcement, and assessments. Treating any of these items as a compliance deadline would commit the operation to a requirement that no public rule supports.
The safe approach is to monitor new editions of the Security Rules and Procedures and the Mastercard Rules. If GMAP returns, the change must appear in a primary document.
What to do now, with or without a new GMAP?
GMAP’s suspension does not remove the work required today. The actions below are different in kind: some carry out a Mastercard obligation, some exercise a contractual right, and others are operational recommendations. Each item names the actor it binds or advises, because the same task changes owner depending on whether the company is an acquirer, a Payment Facilitator, or a merchant. Keeping those categories separate avoids presenting an acquirer’s decision as an automatic network penalty.
- As an operational recommendation for whoever measures a portfolio — the acquirer and the PayFac — calculate each merchant’s ECP basis points every month using the official formula: current-month chargebacks over prior-month Mastercard transactions. A merchant can run the same calculation on its own numbers. Because the ECM and HECM thresholds remain unconfirmed in a public source, the internal alert should trigger well before any applicable threshold.
- To meet the scam rule, which falls on the acquiring chain as a whole, maintain detection and an investigation runbook that fits within 72 hours, from alert to decision. Assign owners, evidence requirements, and blocking authority before the first case. When the merchant is a Sponsored Merchant, the continuous monitoring that feeds this detection is the Payment Facilitator’s obligation.
- As an onboarding recommendation for whoever boards merchants — the acquirer or the PayFac — assess MCC, business model, ticket size, recurring payments, delivery lead time, history, UBO/KYB, URLs, and related merchants. Each merchant should enter the portfolio with a risk classification, limits, and a monitoring plan.
- As a contractual right of whoever holds the contract — the acquirer with the sub-acquirer, the PayFac with the Sponsored Merchant — define objective quarantine and reserve triggers. These may include limiting volume, requiring 3DS or step-up authentication, increasing the rolling reserve, and suspending new MIDs. The Mastercard Rules permit a Payment Facilitator to maintain chargeback reserves; the contract determines when and how to apply them.
- For offboarding, whoever boarded the merchant should formalize criteria for persistent fraud or disputes, rapid deterioration, scam signals, and standards violations. When an investigation confirms scam activity, blocking the merchant from accepting Mastercard is mandatory.
- As a portfolio recommendation for all three actors, monitor both networks together. Under the Visa Acquirer Monitoring Program (VAMP), fraud and disputes form a single indicator, and the rules for Brazil take effect on October 1, 2026. See our article on VAMP in Brazil for details.
Sources: Mastercard Security Rules and Procedures — Merchant Edition, August 4, 2026; Mastercard Rules, June 2, 2026; Visa Business News, July 21, 2026 (ID AI16637).
The practical question is not whether a new GMAP will arrive in April 2027. It is which merchants, measured using the official ECP formula and reviewed against the scam criteria already in force, could expose the acquirer next month — and, through the contract, reach the sub-acquirer and the merchant itself. The answer depends on portfolio data and controls that should already be operating.
Sources
- Mastercard Security Rules and Procedures — Merchant Edition, August 4, 2026.
- Mastercard Rules, June 2, 2026.
- Mastercard Developers — Fraud and Loss Database (FLD).
- Visa Business News, July 21, 2026 (ID AI16637) — VAMP dates for Brazil.