If your onboarding flow still treats website review as something that happens shortly after a merchant goes live, Mastercard has moved the requirement out from under you. Two sets of revised standards landed in 2026 and both are now in force: from 1 January, a newly onboarded merchant must be scanned before it submits its first transaction; from 24 July, an acquirer must begin investigating a merchant within 72 hours once specific signals appear.
Together they put the obligation at both ends of the merchant lifecycle. Here is what each requires, as of September 2026.
Two Revisions, Two Different Gaps
The Merchant Monitoring Program (MMP) revision closes a timing gap in onboarding. Oversight traditionally concentrated on underwriting at application and periodic reviews afterwards, leaving a window in which a merchant could be approved, go live and operate outside permitted boundaries before anyone looked at the site again.
The scam merchant monitoring revision closes a detection gap during the relationship. Ratio-based programs identify a merchant only after enough disputes accumulate to move a monthly number, and an operation that collects for six weeks and disappears completes its whole lifecycle inside that measurement period.
January: The Scan Moves Ahead of the First Transaction
Mastercard's revised MMP standards took effect on 1 January 2026. The program itself is not new; what changed is its scope, its timing and the evidence it demands.
What the revised standards require
- Any merchant onboarded on or after 1 January 2026 must undergo an initial scan — content and, where relevant, transaction laundering — before it processes its first transaction.
- Persistent monitoring must continue through the lifecycle, and must now reach restricted, members-only and password-protected areas rather than stopping at public pages.
- Issues identified through monitoring must be investigated and resolved within 15 calendar days of detection.
- Acquirers must collect complete merchant identity data: legal business names, DBA names and all operational URLs.
- Acquirers must retain evidence of the initial scan and of ongoing monitoring, in reports not altered after generation, and produce them when Mastercard asks.
The gated-content requirement quietly changes cost. A scan that authenticates into a members-only area is a different product from one that crawls public pages — and that is where the risk usually lives, since a compliant storefront in front of a non-compliant catalogue is the oldest arrangement in transaction laundering.
The 15-day window changes staffing. An issue still open after 15 calendar days is not merely unresolved; it is a compliance failure in its own right. That turns remediation from a queue worked when there is capacity into a dated obligation per finding, which means someone has to own the clock.
The part that changes vendor decisions
The revised standards require acquirers to engage one or more Mastercard-approved Merchant Monitoring Service Providers and register them as service providers. The provider runs the initial scan and the ongoing monitoring and reports findings back; the acquirer investigates, confirms the violating activity has stopped, and reports the resolution back. Monitoring vendors read this as meaning an in-house team does not discharge the obligation unless it holds MMSP approval itself — which, if right, makes this a procurement decision rather than a tuning exercise.
The monitoring enforces the standard that a merchant must not submit transactions that are illegal or that damage the goodwill of the brand — the provision monitoring providers cite as Rule 5.12.7, and the basis for Business Risk Assessment and Mitigation (BRAM) findings. Published figures for BRAM assessments vary widely between sources, so treat any specific number you find online as unverified.
July: Potential Scam Merchant Monitoring and the 72-Hour Clock
Mastercard's revised standards for potential scam merchant monitoring, circulated as GLB 12772, took effect on 24 July 2026. They reach merchants and sponsored merchants processed by acquirers and payment facilitators, and do not apply in Jordan.
The mechanism is simple: when a merchant meets any one of the defined criteria, the acquirer must begin an investigation within 72 hours, and if the investigation confirms scam activity the merchant must be blocked from submitting Mastercard and Maestro transactions. What matters operationally is that the criteria are not a single ratio, and they do not all apply to the same population.
Triggers that apply to any merchant
- A drop in authorisation approval rate of at least 50 percentage points over a 72-hour period, or an approval rate below 30%, in each case with at least 25 purchase transactions. System issues at the acquirer or service provider, and BIN attacks, are excluded.
- A Global Rules Investigation Program (GRIP) letter from Mastercard linking the merchant to suspected scam activity.
- One or more alerts from a Merchant Monitoring Service Provider identifying the merchant as a potential scam or illegal operation.
Triggers that apply only to merchants with under six months of acceptance
- Two issuers reporting transactions from the merchant under fraud type 56, manipulation of the cardholder, through the Fraud and Loss Database.
- Two issuers initiating chargebacks, with supporting documentation, referencing scams or manipulation.
- A combined refund and chargeback rate above 5% of purchase transactions in any rolling 30-day period, provided the merchant has conducted at least 500 purchase transactions.
That 5% figure is the number most write-ups lead with, and the one most often quoted without its qualifiers. It is not a portfolio-wide threshold: it applies only to merchants with under six months of acceptance history, needs at least 500 purchase transactions before it means anything, and counts refunds alongside chargebacks. That last detail matters, because refunds are the metric a merchant controls directly. An operation refunding aggressively to keep its chargeback ratio presentable is not hiding from this trigger; it is walking into it.
The authorisation-rate trigger deserves its own attention
A 50-point collapse in approval rate is not a fraud signal in the ordinary sense. It is what issuer-side blocking looks like from the acquirer's side — the issuers have concluded something before you have. The instinct is to read a sharp decline as a processing fault and escalate it to a gateway vendor; under these standards it also starts a 72-hour deadline. The exclusions for system issues and BIN attacks exist because the same shape can have an innocent cause, but the exclusion has to be established by the investigation, not assumed in its place.
Why This Is Not Another Chargeback Threshold
Mastercard's Excessive Chargeback Merchant and Excessive Fraud Merchant programs continue to run as they always have: accumulate volume, compute a ratio, compare it to a threshold. Scam merchant monitoring runs alongside them on different logic. It is signal-driven rather than ratio-driven, several triggers involve no ratio at all, and it can fire on a merchant whose chargeback ratio is unremarkable.
So a dashboard built around dispute ratios will not surface these cases. Two issuer fraud reports is not a number that moves a ratio; a GRIP letter arrives as correspondence; an MMSP alert lands in whatever inbox the vendor relationship points at. Unless those are routed into the same queue as ratio-based alerts, with the same clock attached, the program will be missed in exactly the cases it was designed to catch.
What This Changes for Your Team
Underwriting and onboarding
The initial scan is now a gate, not a task. Something has to stop a merchant being enabled for processing until a clean scan result exists — a status the boarding workflow blocks on, not a checklist item someone ticks. Collect the full URL inventory at application: the standards ask for all operational URLs, and a merchant with three storefronts and a landing page has four things to scan.
Risk and monitoring
Merchants under six months of acceptance now sit under a different rule set from the rest of the portfolio, and that is worth making visible — an account age field the monitoring view can filter on, and separate alerting for that cohort, so the new-merchant triggers reach the merchants they apply to. Approval-rate monitoring also needs to exist at merchant level on a 72-hour comparison window, which is shorter than most portfolio reporting runs on.
Vendor management and evidence
Two of these requirements are ultimately documentation problems. The MMP evidence standard means scan and monitoring reports must be retained unaltered and retrievable on request, and the 72-hour rule means an investigation needs a recorded start time, not just an outcome. Both are easy if the system of record captures them as they happen, and close to unrecoverable if someone has to reconstruct them from email during an audit.
If you are an ISO rather than an acquirer
These obligations sit on acquirers and payment facilitators, but the work does not. Where an ISO runs boarding and first-line risk on an acquirer's behalf, the scan gate, the URL inventory and both clocks land in the ISO's workflow — through the sponsorship agreement rather than the rules directly. Confirm which of these your sponsor expects you to perform, and what evidence it will ask for, before the first audit request rather than after.
A Note on Names and Sources
The July revision is widely called SMMP, the Scam Merchant Monitoring Program. Mastercard's document describes revised standards for potential scam merchant monitoring rather than announcing a program under that name; the acronym is industry shorthand that settled in ahead of the effective date. It matters mainly when searching, because material filed under it is largely vendor commentary of uneven quality.
Mastercard's rules manuals and bulletins go to members and are not publicly retrievable, so almost everything written about these changes is secondary, produced by vendors with a product to sell. The details above are those on which several independent sources agree. If you need to act on a specific threshold, read it in your own copy of the rules or ask your acquirer for the bulletin — and treat any figure you find in a blog post, including this one, as a prompt to check.
Tags
About the author

Kyle Hall
Founder
Kyle Hall is a fintech entrepreneur, software engineer, and marketing strategist with over a decade of experience in high-risk payment processing and SaaS development. He is the CEO of PayKings, a leader in high-risk merchant services, and the founder of PulseCRM, a purpose-built CRM platform for the payments industry. Kyle specializes in building custom payment processing systems and growth strategies that empower merchant services providers to scale and succeed in the digital marketplace.
