Published by Capital Insight Ltd · Nicosia Herausgegeben von Capital Insight Ltd · Nikosia
The Banking Dossier
Disputes

Inside a monitoring programme: the private penalty system above your acquirer

Im Überwachungsprogramm: das private Strafsystem über dem Acquirer

There is a layer of enforcement in card payments that has no statute behind it, publishes no decisions, offers no appeal to the party it penalises, and can remove a business from online commerce entirely. It is administered by the card networks through the acquiring banks, it operates on arithmetic, and most merchants learn it exists on the day they enter it.

The arithmetic

Every card network runs monitoring programmes that track two ratios per merchant: disputes as a share of transactions, and reported fraud as a share of transactions. Exceed a threshold and the merchant is identified to its acquirer. Stay above it and the fees begin.

Visa consolidated its two older programmes — the Visa Dispute Monitoring Program and the Visa Fraud Monitoring Program — into a single Visa Acquirer Monitoring Program. The consolidation changed the arithmetic in a way that deserves attention: VAMP works on a combined ratio, adding reported fraudulent transactions and total disputes together and dividing by settled transactions. Only card-not-present transactions count. Fraud comes from TC40 reports filed by issuers; disputes are tracked as TC15.

The merchant threshold has moved twice in short order. It fell to 1.5 per cent on 1 April 2026 for merchants in the United States, Canada, the European Union and Asia-Pacific, from 2.2 per cent previously. The CEMEA region remains at 2.2 per cent. At the portfolio level, acquirers face an above-standard line at 0.5 per cent and an excessive line at 0.7 per cent. Merchants classified excessive are charged eight dollars per dispute, billed through the acquirer.

Mastercard’s Excessive Chargeback Merchant programme uses a different construction. It requires both a count and a ratio: at least 100 chargebacks in a month and a chargeback-to-transaction ratio of 1.5 per cent or above. Its assessments escalate with time above threshold rather than with volume — nothing in the first month, 1,000 dollars in months two and three, 5,000 in months four to six, 25,500 in months seven to eleven, 50,000 in months twelve to eighteen, and 100,000 a month thereafter. There is a 25-dollar issuer reimbursement fee for each chargeback above the threshold, and a 100-dollar fee for each report. Exit requires the count and the ratio to sit below threshold for three consecutive months.

What the structure actually does

Three features of this design matter more than the numbers.

The escalation is by duration, not by severity. Mastercard’s schedule prices persistence. A merchant with a stable, moderate breach of the threshold pays more in month thirteen than a merchant with a severe breach pays in month two. The incentive this creates is to get out fast by any available means — which is a defensible design if the fastest means are also the right ones, and a problem if they are not.

The denominator is a lever. Both ratios divide by transaction count. A merchant can reduce its ratio by fixing the numerator — resolving disputes, tightening fraud controls, improving the product — or by increasing the denominator. Increasing the denominator means processing more transactions, which can be achieved by splitting transactions, by pushing low-risk volume through the same merchant identifier, or by routing high-risk volume elsewhere. None of that reduces the harm the programme exists to measure. All of it reduces the measured ratio.

Enforcement runs through a party with its own exposure. The network does not bill the merchant. It bills the acquirer, which bills the merchant if it can. An acquirer facing portfolio-level thresholds has an interest in the merchant’s ratio that is independent of the merchant’s business — and the cheapest way for an acquirer to protect its portfolio position is to remove the merchant, not to fix the underlying problem. That is a rational response to the incentive the programme creates, and it explains a good deal of behaviour that merchants experience as arbitrary.

The chargeback that is not fraud

A material and unmeasured share of disputes are not fraud at all. They are cardholders who did not recognise a charge, forgot a subscription, could not reach a merchant’s support, or found it easier to call the bank than to request a refund. The industry term for this is first-party misuse, and the networks have introduced dispute reason codes and evidence mechanisms intended to separate it from genuine third-party fraud.

The separation is imperfect, and it is imperfect in a specific direction. A dispute filed as unauthorised enters the fraud numerator. Whether it later turns out to be a customer who forgot a recurring charge does not necessarily remove it. The merchant carries a fraud statistic generated by a billing descriptor the customer could not read — which is why the descriptor, a field of at most 25 characters, is a risk control and not a cosmetic detail.

Why this looks arbitrary from inside

Merchants describe monitoring programmes as opaque and capricious. The description is understandable, and mostly wrong about the cause. The thresholds are published. The formulas are published. What is not available is the merchant’s own position in real time.

The data reaching the merchant is delayed and partial. TC40 fraud reports are filed by issuers and reach the merchant, if at all, through the acquirer, on a lag. A merchant can therefore be above threshold for weeks without knowing, and can learn of it in the same communication that announces the first assessment. The system is not secret; it is unobservable to the party it governs, which produces the same experience.

The remedy available to merchants is unglamorous and effective: obtain the ratio inputs directly and monthly from the acquirer, and treat the number as an operating metric with an internal ceiling set well below the network’s. A programme entered is expensive and slow to leave. A programme avoided costs the price of a monthly report.

The governance question

Set the operational detail aside and a structural question remains, one that has no comfortable answer.

These programmes have real effects. They impose financial penalties, they cause account terminations, and a terminated merchant may find itself listed on the industry database of terminated merchants, which functions in practice as a barrier to obtaining card acceptance anywhere for several years. That is close to an exclusion from participating in online commerce, and it is imposed without a hearing, without a published decision, and without an appeal to any body independent of the party imposing it.

The case for the arrangement is straightforward and not weak. The networks bear systemic risk from merchant fraud; the programmes are demonstrably effective at removing the worst actors; and no public regulator has the transaction-level visibility to do the job. A private rulebook enforced through contract is, in practice, the only mechanism that operates at the required speed and scale.

The case against it is equally straightforward. A private body imposing consequences of this magnitude, on this many businesses, without procedural protections, is exercising something close to regulatory power without the accountability that ordinarily accompanies it. The merchant’s only counterparty is a bank with its own exposure to the same programme.

Both cases are sound. The disagreement is about which risk one prefers to bear. That is a legitimate policy dispute — but it is one that has largely not been held, because most of the people affected by the answer do not know the question exists until they are already inside it.

Im Kartenzahlungsverkehr gibt es eine Durchsetzungsebene, hinter der kein Gesetz steht, die keine Entscheidungen veröffentlicht, der bestraften Partei keinen Rechtsbehelf bietet — und die ein Unternehmen vollständig aus dem Onlinehandel entfernen kann. Verwaltet wird sie von den Kartennetzwerken über die Acquiring-Banken, sie arbeitet mit Arithmetik, und die meisten Händler erfahren von ihrer Existenz an dem Tag, an dem sie hineingeraten.

Die Arithmetik

Jedes Kartennetzwerk betreibt Überwachungsprogramme, die je Händler zwei Quoten verfolgen: Rückbelastungen im Verhältnis zu Transaktionen und gemeldeten Betrug im Verhältnis zu Transaktionen. Wer eine Schwelle überschreitet, wird seinem Acquirer gemeldet. Wer darüber bleibt, zahlt.

Visa hat seine beiden älteren Programme — das Visa Dispute Monitoring Program und das Visa Fraud Monitoring Program — im Visa Acquirer Monitoring Program zusammengeführt. Die Zusammenführung hat die Arithmetik auf eine bemerkenswerte Weise geändert: VAMP rechnet mit einer kombinierten Quote, addiert gemeldete Betrugstransaktionen und Rückbelastungen und teilt durch die abgerechneten Transaktionen. Gezählt wird nur das Kartenferngeschäft. Der Betrug stammt aus TC40-Meldungen der Kartenherausgeber, die Rückbelastungen laufen als TC15.

Die Händlerschwelle hat sich binnen kurzer Zeit zweimal bewegt. Zum 1. April 2026 sank sie in den Vereinigten Staaten, Kanada, der Europäischen Union und im asiatisch-pazifischen Raum von 2,2 auf 1,5 Prozent. Die Region CEMEA bleibt bei 2,2 Prozent. Auf Portfolioebene gilt für Acquirer eine Linie „über Standard” bei 0,5 Prozent und „exzessiv” bei 0,7 Prozent. Als exzessiv eingestufte Händler zahlen acht Dollar je Rückbelastung, abgerechnet über den Acquirer.

Mastercards Excessive-Chargeback-Merchant-Programm ist anders konstruiert. Es verlangt Anzahl und Quote zugleich: mindestens 100 Rückbelastungen im Monat und eine Rückbelastungsquote von 1,5 Prozent oder darüber. Die Abgaben steigen mit der Dauer über der Schwelle, nicht mit dem Volumen — im ersten Monat nichts, 1.000 Dollar in den Monaten zwei und drei, 5.000 in vier bis sechs, 25.500 in sieben bis elf, 50.000 in zwölf bis achtzehn, danach 100.000 monatlich. Hinzu kommen 25 Dollar Erstattung an den Kartenherausgeber je Rückbelastung über der Schwelle und 100 Dollar je Bericht. Der Ausstieg verlangt, dass Anzahl und Quote drei Monate in Folge unter der Schwelle liegen.

Was die Konstruktion tatsächlich bewirkt

Drei Eigenschaften dieses Aufbaus wiegen schwerer als die Zahlen.

Die Eskalation richtet sich nach Dauer, nicht nach Schwere. Mastercards Staffel bepreist Beharrlichkeit. Ein Händler mit stabiler, mäßiger Überschreitung zahlt im dreizehnten Monat mehr als ein Händler mit schwerer Überschreitung im zweiten. Der Anreiz lautet: mit allen verfügbaren Mitteln schnell heraus — vertretbar, wenn die schnellsten Mittel auch die richtigen sind, und ein Problem, wenn nicht.

Der Nenner ist ein Hebel. Beide Quoten teilen durch die Transaktionszahl. Ein Händler kann seine Quote senken, indem er den Zähler bearbeitet — Streitfälle klären, Betrugskontrollen schärfen, das Produkt verbessern — oder indem er den Nenner vergrößert. Den Nenner vergrößern heißt: mehr Transaktionen abwickeln, etwa durch Aufteilung von Zahlungen, durch Lenkung risikoarmen Volumens über dieselbe Händlerkennung oder durch Auslagerung risikoreichen Volumens. Nichts davon verringert den Schaden, den das Programm messen soll. Alles davon verringert die gemessene Quote.

Durchgesetzt wird über eine Partei mit eigener Betroffenheit. Das Netzwerk stellt nicht dem Händler in Rechnung, sondern dem Acquirer — und der stellt dem Händler in Rechnung, wenn er kann. Ein Acquirer mit eigenen Portfolioschwellen hat ein Interesse an der Quote des Händlers, das vom Geschäft des Händlers unabhängig ist. Und der billigste Weg, die eigene Portfolioposition zu schützen, ist, den Händler zu entfernen, nicht das zugrunde liegende Problem zu lösen. Das ist eine rationale Reaktion auf den gesetzten Anreiz — und erklärt einen guten Teil des Verhaltens, das Händler als willkürlich erleben.

Die Rückbelastung, die kein Betrug ist

Ein erheblicher, ungemessener Teil der Streitfälle ist überhaupt kein Betrug. Es sind Karteninhaber, die eine Belastung nicht wiedererkannten, ein Abonnement vergaßen, den Support eines Händlers nicht erreichten oder es einfacher fanden, die Bank anzurufen, als eine Erstattung zu verlangen. Der Fachbegriff dafür ist Erstparteien-Missbrauch, und die Netzwerke haben Streitgründe und Nachweisverfahren eingeführt, die ihn vom echten Drittbetrug trennen sollen.

Die Trennung ist unvollkommen, und sie ist es in eine bestimmte Richtung. Ein als unautorisiert eingereichter Streitfall geht in den Betrugszähler ein. Ob sich später herausstellt, dass ein Kunde eine wiederkehrende Belastung vergessen hatte, entfernt ihn nicht zwingend wieder. Der Händler trägt eine Betrugsstatistik, erzeugt von einem Zahlungstext, den der Kunde nicht lesen konnte — weshalb dieser Text, ein Feld von höchstens 25 Zeichen, eine Risikokontrolle ist und kein kosmetisches Detail.

Warum das von innen willkürlich aussieht

Händler beschreiben Überwachungsprogramme als undurchsichtig und launisch. Die Beschreibung ist nachvollziehbar und über die Ursache meist falsch. Die Schwellen sind veröffentlicht. Die Formeln sind veröffentlicht. Was nicht verfügbar ist, ist die eigene Position in Echtzeit.

Die Daten, die den Händler erreichen, sind verzögert und unvollständig. TC40-Betrugsmeldungen werden von Kartenherausgebern eingereicht und erreichen den Händler, wenn überhaupt, über den Acquirer und mit Verzug. Ein Händler kann also wochenlang über der Schwelle liegen, ohne es zu wissen, und davon in derselben Mitteilung erfahren, die die erste Abgabe ankündigt. Das System ist nicht geheim; es ist für die regulierte Partei unbeobachtbar, was dieselbe Erfahrung erzeugt.

Das verfügbare Gegenmittel ist unspektakulär und wirksam: die Eingangsgrößen der Quote direkt und monatlich beim Acquirer anfordern und die Zahl als Betriebskennzahl mit einer internen Obergrenze deutlich unter der des Netzwerks führen. Ein betretenes Programm ist teuer und langsam zu verlassen. Ein vermiedenes kostet den Preis eines Monatsberichts.

Die Governance-Frage

Lässt man das Betriebliche beiseite, bleibt eine strukturelle Frage ohne bequeme Antwort.

Diese Programme haben reale Wirkungen. Sie verhängen finanzielle Sanktionen, sie führen zu Vertragskündigungen, und ein gekündigter Händler kann in der Branchendatenbank gekündigter Händler landen, die praktisch als Hindernis wirkt, für mehrere Jahre überhaupt irgendwo Kartenakzeptanz zu erhalten. Das kommt einem Ausschluss aus dem Onlinehandel nahe — verhängt ohne Anhörung, ohne veröffentlichte Entscheidung und ohne Rechtsbehelf zu einer Stelle, die von der verhängenden unabhängig wäre.

Das Argument dafür ist geradlinig und nicht schwach. Die Netzwerke tragen systemisches Risiko aus Händlerbetrug; die Programme entfernen die schlimmsten Akteure nachweislich; und keine staatliche Aufsicht hat den Einblick auf Transaktionsebene, um diese Arbeit zu leisten. Ein privates, vertraglich durchgesetztes Regelwerk ist in der Praxis der einzige Mechanismus, der in der nötigen Geschwindigkeit und Größenordnung arbeitet.

Das Argument dagegen ist ebenso geradlinig. Eine private Stelle, die Folgen dieser Größenordnung über so viele Unternehmen verhängt, ohne Verfahrensschutz, übt etwas aus, das regulatorischer Macht nahekommt — ohne die Rechenschaft, die damit üblicherweise einhergeht. Der einzige Ansprechpartner des Händlers ist eine Bank, die demselben Programm selbst ausgesetzt ist.

Beide Argumente tragen. Der Streit geht darum, welches Risiko man lieber trägt. Das ist eine legitime politische Auseinandersetzung — nur wurde sie weitgehend nicht geführt, weil die meisten, die von der Antwort betroffen sind, von der Frage erst erfahren, wenn sie bereits drinstehen.