Solidgate logo in black and white.

What is VAMP?

Visa Acquirer Monitoring Program (VAMP) is a risk monitoring program run by Visa that identifies and merchants with excessive or rates. Enhanced on April 1, 2025, it merges what were previously separate fraud and dispute monitoring tracks into a single program.
VAMP measures risk at the acquirer level and at the individual level using monthly processing data. Its scope covers three behaviors: fraud reported by issuers, card-not-present disputes, and enumeration attacks, where an attacker tests card numbers in bulk to find working ones. Because one ratio now carries both the fraud signal and the dispute signal, a merchant with clean fraud numbers can still be identified on disputes alone. Under the earlier split monitoring tracks, the same merchant could stay below each individual limit while its combined fraud-plus-dispute count ran higher than either track showed on its own.

Key requirements

VAMP runs on two transaction-based ratios, both calculated monthly.
  • VAMP ratio – (TC40 + TC15) ÷ total sales count. It combines fraud notifications raised by with all card-not-present disputes reported through TC15, producing one measure instead of two.
  • VAMP enumeration ratio – enumerated transactions ÷ total transaction count. This tracks card testing, where an attacker runs high volumes of small or zero-value attempts to discover valid card details.
  • Monthly review – Visa reviews processing activity each month and identifies participants that exceed program thresholds.
  • Two thresholds, not one – a participant has to breach a rate threshold and a volume threshold to be enrolled, so a merchant with a high ratio but very few transactions doesn't automatically qualify.
  • Tiered thresholds – thresholds are set at Excessive, Above Standard, and Early Warning levels, with different criteria by region, including the EU, the US, the UAE, and LATAM. Visa publishes the current figures in its scheme bulletins, and they have been revised since the program launched.
Both ratios use a transaction count as the denominator, not transaction value. A high-ticket merchant gets no relief from the size of its sales, while a low-ticket merchant processing heavy volume can absorb more fraud notifications and disputes before the ratio moves.

Who it applies to

  • Acquirers – monitored on portfolio-wide performance across every merchant they sponsor, which is why an acquirer's own risk team polices merchant behavior before Visa does.
  • Merchants – monitored individually against the same ratios. A single merchant whose volume climbs can pull its acquirer's portfolio ratio up with it.
Card-not-present businesses carry most of the exposure, because TC15 counts all card-not-present disputes rather than only fraud-coded ones. That puts subscription, digital goods, and other categories under the ratio even when the underlying complaint is a billing dispute rather than stolen-card fraud.

Penalties for non-compliance

VAMP includes a 90-day grace period for every 12 months a participant isn't identified in the program. Remediation is expected during that window, but no fees are charged. Once the grace period ends, enforcement fees apply per monthly count of fraud and disputes, so the cost scales with the number of flagged transactions rather than arriving as a flat fine. The ratio is recalculated at every monthly review, so a participant that brings its counts back under threshold stops being identified in a later period.
Fees are billed to the acquirer, which passes them to the merchant driving the ratio. Sustained identification also changes : acquirers respond by tightening terms, holding reserves, or ending the merchant agreement. Visa's program sits alongside equivalents from other networks, such as the , so a business processing across multiple can be monitored separately on each, against a different in each case.

Related terms