Articles

What Visa and Mastercard’s New Fraud Mandates Mean for Your Fintech Team

A practical checklist for navigating VAMP, 3DS2, and Compelling Evidence 3.0 — the three Visa and Mastercard frameworks now shaping payment compliance across card-not-present transactions.

What Visa and Mastercard's New Fraud Mandates Mean for Your Fintech Team

Since April 2025, Visa has consolidated its fraud and chargeback monitoring into a single framework called VAMP — the Visa Acquirer Monitoring Program. Rather than tracking fraud and disputes separately, merchants and acquirers are now assessed on one combined dispute ratio. Mastercard has made parallel moves, tightening 3DS authentication requirements across the EEA and Asia-Pacific regions.

The practical effect for fintech companies, PSPs, and merchants processing card-not-present transactions is that the compliance bar has moved significantly higher. Thresholds that were manageable under the old framework are now grounds for remediation or account termination in the most severe cases. What follows is a structured checklist of what your team should have in place.

These Visa and Mastercard requirements apply to any company processing card-not-present transactions: recurring billing, SaaS subscriptions, marketplace payments, and embedded finance products.

VISA VAMP — DISPUTE RATIO

  • Calculate your current VAMP ratio. Total disputes (fraud + non-fraud) divided by total approved CNP volume. The threshold is 0.9% as of January 2026, down from 1.5% at program launch. Ratios above 1.5% are classified as “excessive” and trigger immediate enforcement review.
  • Set up automated dispute monitoring. Monthly manual reviews are not sufficient to catch threshold breaches in time to act. Automated alerting when your ratio approaches the limit is now a baseline requirement.
  • Assess your enumeration attack exposure. VAMP flags merchants where 20% or more of authorization attempts appear to be card-testing bots, provided you are processing 300,000 or more attempts. Declined transactions count toward the ratio. Velocity rules and bot detection should be in place regardless of current volume.
  • Draft a remediation template in advance. Merchants who exceed VAMP thresholds have 15 calendar days to acknowledge the breach and submit a written remediation plan citing specific failures. Having a template ready avoids a rushed response under pressure.

3DS2 AUTHENTICATION MANDATE

  • Confirm 3DS2 coverage across all CNP flows. 3D Secure 2 is now a network requirement. Mastercard’s Identity Check deadline for EEA acquirers passed in October 2025. The Asia-Pacific enforcement and fine-escalation milestone is April 2026.
  • Verify the liability shift applies correctly in your stack. When 3DS2 is active and the issuer successfully authenticates a transaction, chargeback liability transfers to the issuer. Without 3DS2, the merchant retains liability. Confirm this is reflected accurately across all markets you operate in.
  • Test frictionless and challenge flows by issuer geography. US issuers sometimes treat a 3DS invocation as a risk signal and decline rather than issue a challenge — the opposite of typical European issuer behavior. Issuer-specific testing is worth the investment if you process across regions.

COMPELLING EVIDENCE 3.0 — FRIENDLY FRAUD

  • Understand CE3.0 eligibility and fees. Compelling Evidence 3.0 is Visa’s mechanism for contesting first-party fraud, where a cardholder disputes a transaction they actually participated in. Visa began auto-qualifying transactions via Visa Secure in October 2025. A fee for successful qualifications applies from April 17, 2026.
  • Capture evidence data at the point of transaction. CE3.0 dispute responses require matching device fingerprints, IP addresses, and delivery or usage confirmation across prior non-disputed transactions. This data must be stored at transaction time — it cannot be reconstructed after the fact.
  • Review billing descriptors and cancellation policy placement. Unclear billing descriptions remain a leading cause of chargebacks. Every descriptor should clearly identify your company and the product charged. Cancellation and refund policies should be visible before the point of purchase.

ACQUIRER AND TOKEN REQUIREMENTS

  • Monitor your acquirer’s VAMP position. Acquirers face their own VAMP dispute threshold — 0.3% in 2026. A merchant with high dispute volume can contribute to pushing an acquirer toward their limit, creating grounds for the acquirer to terminate the relationship independently of any Visa action.
  • Migrate standing instruction MITs to COF tokens. Visa now restricts standing instruction merchant-initiated transactions to Credential-on-File tokens. Device tokens provisioned after July 30, 2025 are being declined for this use case. If your platform uses recurring billing, this migration should already be underway.
What this signals broadly: Both networks, Visa and Mastercard, are shifting from reactive enforcement toward continuous, threshold-based monitoring. For fintech teams, this means compliance is increasingly an engineering and data problem. Dispute ratios, authentication coverage, and token hygiene need to be tracked as product metrics, not reviewed periodically by a compliance team.
Pay Space

Pay Space

2286 Posts

https://payspacemagazine.com/author/payspacemagazineauthor/

Our editorial team delivers daily news and insights on the global payment industry, covering fintech innovations, worldwide payment methods, and modern payment options.