Mastercard Scam Merchant Monitoring: what actually triggers it
Not a single metric. A multi-trigger framework where authorization collapse, a GRIP letter, two issuers, or a third-party alert can each independently start the clock.

In my last post, I summarized Mastercard’s new “Scam Merchant” monitoring requirements, which go into effect on July 24, 2026.
Today I want to review their multi-trigger framework, and any one of several conditions can initiate a required investigation.
One of the more straightforward triggers is a breakdown in authorization performance. If a merchant’s approval rate drops sharply over a short period — for example, a decline of 50 percentage points, or falling below 30% overall — that alone can put them into scope. The measurement window is tight: a minimum 72-hour period with at least 25 transactions.
There is also a direct escalation path from Mastercard itself. If a merchant is the subject of a Global Rules Investigation Program (GRIP) letter, that independently triggers the requirement to investigate.
For newer merchants — defined as those with less than six months of processing history — there is an additional layer of sensitivity tied to issuer behavior and early performance signals.
In those cases, just two different issuers reporting scam-related transactions under the “manipulation of cardholder” fraud classification is enough to initiate the process. The same applies if two issuers initiate chargebacks that reference scams or similar behavior.
The 5% threshold also sits specifically in this category. If a newer merchant sees more than 5% of its transactions result in refunds or chargebacks over a 30-day rolling period, and has processed at least 500 transactions, that condition alone can trigger monitoring.
Outside of that early-life window, those issuer-count and 5% thresholds are NOT explicitly defined as triggers in the same way.
Beyond performance and issuer-driven signals, third-party and network alerts can also initiate the process. If a merchant is flagged by a Merchant Monitoring Service Provider or through Mastercard’s own monitoring programs, that alone can be sufficient.
Once any of these conditions are met, the timeline is clear. The acquirer or payment facilitator has 72 hours to initiate an investigation, and if the merchant is confirmed to be conducting scam activity, they are required to block that merchant from processing Mastercard transactions.
Separate from the trigger events themselves, Mastercard is reinforcing expectations around ongoing monitoring. Acquirers are expected to CONTINUOUSLY evaluate transaction patterns, refund and chargeback activity, fraud indicators, and behavior that doesn’t align with the merchant’s stated business model. There is also an expectation to review Mastercard’s Fraud & Loss Database on a daily basis for new signals.
Taken together, this is not a single metric program. It’s a system with multiple entry points, where performance changes, network escalation, issuer activity, and third-party alerts can all independently set the process in motion.


