TL;DR
- Starting July 24, 2026, Mastercard requires acquirers and payment facilitators to investigate any card-not-present (CNP, meaning the cardholder isn’t physically present to present the card, as in a subscription renewal) merchant flagged for scam activity within 72 hours. Confirmed scam activity means immediate termination of Mastercard and Maestro processing: no fine, no grace period.
- Four triggers open that investigation, including a new combined refund-plus-chargeback rate above 5% in any rolling 30-day window for merchants with under six months of Mastercard acceptance history, and an approval-rate collapse of 50+ points or a drop below 30%.
- Subscription and SaaS billing produces exactly the refund, involuntary-renewal, and billing-descriptor-confusion patterns that sit closest to these thresholds. Merchants clearing all Mastercard volume through a single acquirer face an all-or-nothing outcome if that one relationship gets flagged.
Context
Mastercard is rolling out a Scam Merchant Monitoring Program (SMMP), part of a broader Merchant Trust Services initiative, effective July 24, 2026. The rule requires acquirers and payment facilitators to actively monitor CNP merchant behavior and open an investigation within 72 hours whenever a flagged risk threshold is hit. If the investigation confirms scam activity, the merchant loses Mastercard and Maestro processing immediately, with no fine and no grace period.
Four categories of trigger open that 72-hour clock:
- Authorization approval-rate collapse. A drop of 50 or more percentage points within 72 hours, or an absolute approval rate below 30%, subject to minimum transaction volume.
- A GRIP letter. GRIP is Mastercard’s internal Global Rules Investigation Program; a GRIP letter is the notice it issues when a merchant is linked to suspected fraudulent activity.
- New-merchant fraud signals, for merchants with less than six months of Mastercard acceptance history: two or more issuers reporting fraud under reason code 56, chargebacks referencing scams or manipulation from multiple issuers, or a combined refund-plus-chargeback rate above 5% in any rolling 30-day window with a minimum of 500 transactions.
- An alert from an approved Merchant Monitoring Service Provider (MMSP, a third party Mastercard authorizes to flag merchant risk signals on its behalf).
Mastercard frames the program as a trust initiative rather than a pure enforcement measure. Ann Johnson, the company’s executive vice president of Security Solutions, said: “Digital commerce only works when people trust what’s on the other side of the screen.” Mastercard cites the Global Anti-Scam Alliance’s estimate that consumers lost $442 billion worldwide to online scams in 2025 as the backdrop for the program.
Analysis
The program folds two previously separate concerns, fraud monitoring and dispute-ratio monitoring, into a single 72-hour compliance clock. That has two implications for subscription and SaaS billing teams specifically.
First, approval rate stops being a pure conversion metric and becomes a compliance input. A 50-point drop in 72 hours, or a fall below 30%, is the kind of swing that can happen from a routing outage, an issuer-side change, or a BIN (Bank Identification Number, the digits that identify the issuing bank and country) shift just as easily as from actual fraud. A merchant with no fraud problem can still open an investigation purely on authorization volatility.
Second, the combined refund-plus-chargeback threshold is new and distinct from existing dispute-ratio programs merchants already track. A subscription business with a chargeback ratio well inside the limits of a standard dispute program can still cross the 5% combined line, because refunds now count alongside chargebacks in the same rolling 30-day number. Trial cancellations, a card that lapses and renews without the subscriber noticing, and a billing descriptor the cardholder doesn’t recognize all generate refund or dispute volume that feeds this metric, and subscription models generate more of all three than one-time-purchase businesses do. Merchants under six months of Mastercard acceptance, exactly the group with the least operating history to demonstrate legitimacy, face the tightest version of this threshold.
There’s also a concentration question the program surfaces indirectly. The consequence of a confirmed investigation, immediate termination, applies to a specific acquirer relationship. A merchant that clears all of its Mastercard card-not-present volume through one acquirer has exactly one relationship standing between normal operations and a full stop on Mastercard revenue. A merchant with multiple acquiring relationships across markets has the same exposure per relationship, but not all of its Mastercard revenue sitting behind a single point of failure.
How SGW absorbs this
Two of SGW Payment’s core mechanics map directly onto the two implications above.
On the approval-rate side, SGW connects merchants to a network of payment providers through a single SDK and API, and routes each transaction to the provider most likely to approve it. That routing decision is made per transaction, based on which provider is most likely to approve given the card, market, and current network conditions. Keeping technical and issuer-side declines to a minimum is what keeps an authorization-rate chart looking like normal variance rather than the kind of 50-point swing that opens a GRIP-adjacent investigation.
On the concentration side, SGW’s role as the payments infrastructure layer for international expansion means it stands up the local payments setup, entity, banking, acquiring, and finance operations, in every new market on the merchant’s behalf. Because transactions process locally in each market rather than cross-border, a subscription business’s Mastercard CNP volume is naturally spread across multiple local acquiring relationships instead of concentrated in one. If an investigation is opened against one relationship, it isn’t the only channel a given market’s revenue runs through. Standing up that local acquiring independently, market by market, would otherwise take a business 6 to 12 months per market; working with an infrastructure layer that already has the local relationships in place converts that timeline while distributing the exposure this program is now pricing in.
Takeaways
- Mastercard’s Scam Merchant Monitoring Program takes effect July 24, 2026, and applies to all card-not-present merchants globally. Confirmed scam activity means immediate termination, with no fine and no grace period.
- Four triggers open the 72-hour investigation clock: an approval-rate collapse (50+ points or below 30%), a GRIP letter, new-merchant fraud signals (including the new 5% combined refund-plus-chargeback threshold), or an MMSP alert.
- The 5% combined refund-plus-chargeback threshold is new. Check it separately from your existing chargeback-ratio compliance metric; a clean standing chargeback ratio does not mean a clean standing under this program.
- Audit billing descriptors, trial-cancellation flows, and involuntary-renewal handling now. Each is a direct contributor to the refund-plus-chargeback number, and each is fixable before July 24.
- If your Mastercard CNP volume runs through a single acquirer relationship, that relationship is now a single point of failure for that revenue line. Spreading acquiring relationships across markets, the natural outcome of processing locally rather than cross-border, reduces that concentration; building it out independently takes 6 to 12 months per market.
Sources
- Mastercard Merchant Trust Services targets scam merchants (Mastercard)
- Mastercard Scam Merchant Monitoring 2026: What Merchants Must Know Before July (cside)
- Mastercard SMMP 2026: What eCommerce & SaaS Merchants Must Know (Chargeflow)
- The New Rules for Mastercard’s Scam Merchant Monitoring (Chargeback Gurus)
- Mastercard SMMP 2026: Triggers, Thresholds & Compliance Guide (Justt)
About SGW Payment. SGW Payment helps online businesses capture more revenue and reduce processing costs. Through a single SDK and API, SGW connects merchants to a network of payment providers and routes each transaction to the provider most likely to approve it. On top of the technology, SGW acts as the payments infrastructure layer for international expansion, standing up the local payments stack (entity, banking, acquiring, and finance operations) in every new market, so transactions process locally rather than cross-border. Learn more at sgw-payment.com.



