Visa consolidated its legacy fraud and dispute monitoring programs into a single framework known as the Visa Acquirer Monitoring Program (VAMP). The program evaluates merchants using a unified risk ratio combining overall fraud signals and dispute activity. Once a merchant exceeds Visa's defined risk thresholds, the acquirer applies enforcement measures which may appear as monitoring or integrity fees on merchant statements. The biggest shift for finance teams is that fraud risk is now treated as a direct financial liability, not simply an operational issue, meaning the presence of fraud signals alone may trigger penalties even when losses are contained.
Why Fraud and Disputes Are Now a Unified Financial Risk
Historically, finance teams tracked chargebacks, while fraud teams focused on stopping unauthorized transactions. These two functions often operated independently. As long as financial losses were manageable, their separation rarely caused issues.
Visa's new VAMP framework has changed this dynamic entirely.
In early 2025, Visa began rolling out updated acquirer monitoring standards and clarified how acquirer-level fraud and dispute metrics influence enforcement. This update was referenced in Visa's public-facing bulletin announcing unified acquirer monitoring policies.
VAMP is designed to evaluate overall merchant risk rather than simply measuring confirmed fraud or processed chargebacks. By merging its previous programs into a single monitoring standard, Visa now monitors every significant fraud signal and dispute indicator together. This removes the ability for merchants to mask risk in one category by over-managing another.
For CFOs and Controllers, the result is clear: risk signals now carry direct financial consequences, even before disputes are finalized.
What Changed Under the VAMP Framework?
A Unified Risk Ratio Combining Fraud and Disputes
Visa now uses a consolidated ratio that reflects both fraud indicators and dispute activity. Although the specific formula is not disclosed in public materials, Visa confirmed in its 2025 update that acquirers must use combined fraud and dispute metrics when evaluating merchant-level exposure.
Key changes:
- Fraud signals reported by issuers are now counted alongside disputes
- Non-fraud disputes can contribute to risk
- A single transaction may register multiple signals depending on issuer reporting behavior
Because these risk counts accumulate at the network level before a merchant can respond, the ratio may increase even when the merchant wins the dispute or refunds the transaction quickly.
Updated Thresholds for Monitoring Categories
Visa introduced new thresholds under VAMP that classify merchants into multiple monitoring categories based on their fraud-dispute ratio and monthly volume. These thresholds are enforced at the acquirer level using updated Visa Risk Performance Standards released in 2025.
Processors are required to monitor the entire portfolio, meaning merchants with elevated ratios can affect acquirer-level compliance even when the merchant's own dispute losses are low.
New Enforcement Measures Applied by Acquirers
Once a merchant crosses a defined threshold, the processor is required to apply monitoring measures. These appear on statements as:
- Monitoring fees
- Integrity or compliance program fees
- Risk surcharges
- Network-required enforcement fees
These fees are not chargeback fees. They are administrative penalties tied to risk categorization. For finance teams, this means fraud signals now directly influence P&L lines that previously had no relationship with operational fraud metrics.
The Financial Impact of VAMP on Merchant Costs
Enforcement Fees Applied by Processors
When a merchant enters a monitored category, the acquirer must apply network-mandated measures. These are typically listed as monitoring or integrity fees. They apply to all qualifying transactions in the relevant period, not only the ones exceeding a threshold.
Fees apply based on the presence of reported fraud or disputes, not the outcome of a chargeback.
Processor-Level Portfolio Pressure
Visa evaluates acquirers based on the combined risk of all merchants they serve. If an acquirer's portfolio risk exceeds Visa's limits, Visa can apply corrective actions. Acquirers may be required to demonstrate enhanced oversight or apply stricter controls to merchants.
Acquirers then pass these pressures downstream through:
- Additional risk surcharges
- Stricter transaction controls
- Higher reserve requirements
- In rare cases, account termination
A merchant may face cost increases even without a spike in chargebacks because their activity contributes to acquirer-level exposure.
Three Strategies to Stay Below VAMP Monitoring Thresholds
Strategy 1: Adopt Network Tokenization
Network tokens reduce fraud exposure by improving transaction authenticity, especially for card-on-file and recurring billing models. Tokenized transactions generate fewer issuer-reported fraud indicators.
Action point for finance: Confirm that network tokens are enabled for stored or recurring transactions.
Strategy 2: Use Rapid Dispute Resolution
Visa's RDR program allows automatic refunds before a dispute becomes a formal chargeback. RDR reduces the number of dispute signals that would otherwise affect VAMP calculations.
Finance teams should coordinate with operations to define refund rules based on customer lifetime value, transaction amount, and historical patterns.
Strategy 3: Leverage Compelling Evidence Tools
Enhanced evidence requirements for certain fraud claims (particularly friendly fraud) allow issuers to suppress certain fraud reports at the network level when legitimate customer activity is demonstrated.
Reducing issuer-level fraud reports reduces the inputs in the unified VAMP ratio.
Why Configuration Issues Often Trigger VAMP Penalties
VAMP is effectively a penalty structure for unmanaged risk. Merchants often face monitoring fees not because they are high-risk, but because of structural issues such as:
- Poor descriptor clarity that confuses cardholders
- Fragmented billing practices across multiple MIDs
- Weak tokenization configurations
- Legacy fraud tools that miss modern attack patterns
- Overly strict refund controls that push customers to disputes
- Incorrect MCC classification
These issues are operational, not criminal, and are fixable without switching processors. Mapping VAMP-related fees directly back to configuration gaps allows finance teams to correct them without disrupting sales workflows.
Key Takeaways for Finance Leaders
VAMP represents a clear shift: fraud is now a financial liability, not just an operational concern.
Finance teams should:
- Request visibility into risk ratios from their processor
- Identify monitoring or integrity fees on statements
- Confirm tokenization and RDR usage
- Align descriptors, gateways, and fraud tools with modern standards
Proactive management today prevents larger downstream costs as enforcement standards tighten later in 2025.
Visa Merchant Regulations and Fee Guidelines



