How Visa and Mastercard Ensure Compliance for Acquirers and Issuers

Visa and Mastercard compliance consists of mandated standards, monitoring programs, validation cycles, and financial penalties. For payment compliance and risk managers at acquirers and issuers, each one means a defined set of obligations, enforced differently on each card network.

January 12, 2026
How Visa & Mastercard Ensure Compliance for Acquirers & Issuers

The card association compliance programs and requirements are set out in network rulebooks and enforced through monitoring programs, merchant validation levels, registration obligations, and non-compliance assessments.

How Card Network Compliance Is Structured

The PCI DSS Compliance Mandate

Visa and Mastercard are PCI compliance champions across their respective networks.

Compliance with the Payment Card Industry Data Security Standard (PCI DSS) is mandated for any individual or entity that engages in the acceptance, retention, processing, or transmission of cardholder data. This means merchants, service providers, and banks.

The standard in force is PCI DSS v4.0.1, the only active version since v4.0 was retired at the end of 2024, so any validation evidence an acquirer accepts must be assessed against v4 requirements.

While the PCI Security Standards Council owns and manages the compliance requirements relative to PCI-related standards, only the brand owners of Visa and Mastercard enforce all data security compliance requirements relative to their own networks.

This split is the reason card scheme compliance for acquirers and issuers operates in two layers: the Council writes the standard, and each network decides how it is validated and penalized on its own rails.

Responsibility flows downward through the payment chain:

  • Acquirers are responsible for the compliance of the merchants and service providers in their portfolio
  • Issuers are responsible for compliance across their own cardholder data environment and third-party agents

Mastercard's Security Monitoring Program refers to a form of monitoring that acquirers need to pay attention to after the requirement is passed down to the merchants and compliance is determined through the Self-Assessment Questionnaire (SAQ) or Report on Compliance (ROC).

The same goes for the issuers who need to champion compliance through the review of the same SAQ or ROC.

The SAQ is the lighter, self-attested route available to lower-volume merchants, while the ROC is the full assessment documented by a Qualified Security Assessor, an assessor firm accredited by the PCI Security Standards Council rather than by either network, so which document lands on the acquirer's desk depends entirely on the merchant's assigned level.

Card Network Compliance Ecosystem Overview diagram showing Visa and Mastercard card networks connected to acquirers and issuers, outlining merchant monitoring, validation, risk management, chargeback enforcement, and PCI DSS compliance requirements.

Core Rulebooks and Governance Structures

The rulebooks differ by network but serve the same function:

These rulebooks are the contractual source of nearly every obligation described below, which is why licensees are held to them regardless of local regulation.

As of April 1, 2025, Visa implemented a new Acquirer Monitoring Program (VAMP) which consolidated these five existing programs:

  • Visa Dispute Monitoring Program (VDMP), the legacy chargeback-ratio program
  • Visa Fraud Monitoring Program (VFMP), the legacy fraud-ratio program
  • VFMP 3D Secure (3DS), which tracked fraud on authenticated transactions
  • Digital Goods Merchant Fraud Monitoring Program (DGMFM), aimed at digital goods sellers
  • VAMP (existing program)

Consolidation matters operationally because acquirers that previously tracked five separate ratios against five separate thresholds now report against a single combined framework.

The new Acquirer Monitoring Program adds two new measurements for monitoring, each with its own breach thresholds:

Measurement
VAMP Ratio
Enumeration Ratio
What it captures
CC fraud (TC40) + nondisputed fraud (TC15) / total CNP transactions settled
Percentage of unauthorized authorizations which indicate potential card testing efforts
Thresholds
Standard (>0.5%), Excessive (>1.5%)
Excessive (>20%)

TC40 and TC15 refer to the fraud reporting records feeding this calculation, so acquirers without visibility into both data feeds cannot predict a breach before Visa flags it.

The Enumeration Ratio is a distinct risk from fraud losses: it captures card testing, where attackers run high volumes of small authorization attempts to identify live card numbers.

Lower thresholds took effect in January 2026 and are now in force across the network.

Keep Fraud Ratios Inside Scheme Thresholds

DECTA provides 3D Secure 2 authentication with PSD2 SCA support for issuers and acquirers across Visa, Mastercard, and UnionPay.

Explore 3D Secure

Monitoring Programs and Risk Management

Visa's Monitoring Infrastructure

Visa Acquirer Monitoring Program (VAMP)

Under the current VAMP framework, merchants have been subject to assessment since October 1, 2025, following an initial six-month grace period.

Merchants exceeding compliance thresholds must acknowledge and provide plans of remediation within 15 calendar days and cite failures.

A variety of fee levels are assessed based on the length and extent of non-compliance.

Visa Acceptance Risk Standards (VARS)

VARS are defined as requirements of controls that acquirers must put in place with some variance including but not limited to:

  • Record of assessments/review
  • Ability to monitor for transaction anomalies

Where VAMP measures outcomes after the fact, VARS governs the controls expected to be in place beforehand, so an acquirer can sit inside VAMP thresholds and still be found deficient on VARS.

Mastercard's Monitoring Ecosystem

Business Risk Assessment and Mitigation (BRAM) Program

The BRAM Program aims to assess and mitigate any of the brands' high-risk merchants.

These are often the merchants that exist on the edge of legality or put Mastercard's brand at risk.

The program was established in 2005 and continues to broaden its scope to include new concerns which arise, such as fraud, counterfeiting, adult entertainment, and child pornography.

For acquirers, BRAM is the reason merchant category and content due diligence sits at onboarding rather than after a complaint arrives.

Questionable Merchant Audit Program (QMAP)

The QMAP seeks to assess those merchants who may be engaged in potentially fraudulent behaviour via a review of questionable merchant transactions in conjunction with excessive chargeback levels.

If Mastercard determines a merchant is questionable, it communicates with the acquirer through the Company Contact Management system.

This is the formal notification channel acquirers must monitor to avoid missing a case deadline.

PCI 360 Education Program

The PCI 360 Education Program seeks to help acquirers teach merchants how to reinforce and expand PCI Security Standards compliance.

Because merchant failures land on the acquirer, education is a risk control rather than a courtesy.

Validation Requirements for Acquirers and Issuers

Both card associations assess levels of merchants and service providers according to the volume of transactions and necessary validations.

Visa's Merchant Levels and Validation Structure

Visa levels merchants according to aggregate transaction volume over a 12-month period, from Level 1 at the top of the volume range down to Level 4 at the bottom.

Some merchants require an Annual On-Site Security Assessment and Quarterly Network Vulnerability Scan, while others only require an Annual Self-Assessment Questionnaire and Quarterly Network Vulnerability Scan.

Service providers are levelled separately on the same volume logic, which is why a single processor can sit at a different level from the merchants it serves.

These merchant levels define how much validation workload an acquirer carries, since the highest tiers demand assessor-led reviews rather than self-attestation.

Visa's PCI compliance attributes mean that as long as all efforts have been made to remain compliant and the merchant has little control over a third-party failing, compliance will still not be warranted.

For instance, PCI compliance is waived for compliant technology implementations, 75% of annual transactions are processed through EMV chip-enabled terminals verified point-to-point encryption, or tokenization solutions.

Recently, to pivot PCI compliance as a standard, merchants who undertake PCI-compliant efforts qualify for Visa's Technology Innovation Program (TIP) which waives PCI compliance assessment.

TIP gives acquirers a practical route to reduce validation burden across a portfolio by steering merchants toward EMV, point-to-point encryption, and tokenization.

Each of the three works by keeping raw card data out of the merchant environment:

  • EMV chip authentication: removes the counterfeit-magstripe exposure
  • Point-to-point encryption: ciphers card data at the terminal so it is never readable in the merchant's systems
  • Tokenization: replaces the card number with a surrogate value that is useless if stolen

Anything that shrinks the cardholder data environment shrinks the compliance requirements for acquirers and issuers that follow from it.

Mastercard's Site Data Protection Framework

Mastercard assigns merchants to Levels 1 through 4 on transaction volume in the same way Visa does, and the Site Data Protection (SDP) Program sets what the acquirer owes at each level.

With respect to SDP, acquirers must:

  • Submit the SDP Acquirer Submission and Compliance Status Form for Level 1 and Level 2 merchants every 6 months.
  • Submit forms for Level 3 merchants as requested, where required by applicable law or regulations.
  • Validate to Mastercard that they have a risk management program in place for Level 3 and Level 4 portfolios.

SDP defines the reporting cadence acquirers owe per merchant level, so the program effectively defines the compliance calendar for a Mastercard portfolio.

Enforcement Mechanisms and Non-Compliance Penalties

Visa's Enforcement Structure

If a merchant does not comply, and a service provider is found not adhering to PCI DSS requirements, Visa can levy Non-Compliance Assessments.

These can be charged to the issuer or acquirer, yet waived for those with clear PCI DSS compliance for a reasonable period before the breach and during the breach to forensic assessment.

Mastercard's Enforcement Approach

Mastercard has similar enforcement provisions, including assessments for non-compliance.

For instance, with QMAP, if fraud occurs, the merchant is to be terminated by the acquirer and the issuer may initiate chargebacks in order to recover the issuer's funds.

Registration and Third-Party Obligations

Third-Party Agent Registration

Visa requires registration of Third Party Agents (TPAs).

A Third Party Agent is defined as any person or entity that solicits for an acquirer/issuer, installs acceptance devices, issues en/decryption keys, or has access to cardholder data.

Without TPAs registered pursuant to the TPA Registration Program, no issuer/acquirer/merchant may engage in TPA services.

Unregistered vendors are a common compliance gap, since agents are often engaged commercially before anyone checks the registration requirement.

For issuers the exposure runs through card program vendors such as personalisation bureaux, processors, and cardholder support providers, all of which meet the TPA definition once they touch cardholder data.

Global Registry of Service Providers

Visa holds the Global Registry of Service Providers, which refers to the industry's official registry for payment processing to check if agents affiliated with any party are registered and in good standing.

This is to promote proper operations and use licensed service providers.

Checking the registry before integrating a provider is the simplest way for an acquirer or issuer to avoid inheriting an unregistered party's exposure.

Visa Direct Controls

For all transactions using Visa Direct, the acquirer must ensure all senders are in compliance with applicable money licensing requirements, that all Know Your Customer (KYC) and screening requirements are completed, and that velocity controls are established.

Visa Direct is push-payment infrastructure, so the obligations sit on the sending side rather than on merchant acceptance, which is why it carries its own control set.

What Recent Changes Mean for Compliance and Risk Managers at Acquirers and Issuers

The payment card networks have continued to evolve, with several developments now firmly established as of 2026.

Visa's VAMP Transformation

The consolidation of various monitoring programs under the VAMP framework reflects a broader industry shift from reactive anomaly detection toward proactive, preemptable fraud prevention.

Acquirers and merchants have had to adjust their risk assessment approaches accordingly, incorporating mandated monitoring technology and a more hands-on stance toward prevention in-house.

Enhanced Authentication Requirements

Both networks have layered on new authentication requirements, for example, Mastercard's Authentication Best Practices guide and required authentication data in authorization and clearing messages.

3D Secure sits at the centre of this, since authentication outcomes feed directly into the fraud ratios acquirers are measured on, and in Europe it is also the mechanism through which PSD2 strong customer authentication obligations are met.

That overlap is worth tracking, because card network compliance and regional regulation are enforced by different bodies on the same transaction data, and meeting one does not automatically satisfy the other.

Conclusion

Visa and Mastercard don't leave compliance to acquirers and issuers up to chance, with an array of steps to ensure adherence across their networks.

From mandatory standards to monitoring programs to validation requirements to enforcement actions, they've taken every step necessary to preserve the security of their payment infrastructure.

As the global nature of fraud continues to evolve, so does compliance, with the frameworks established in 2025 now serving as the baseline standard across both networks heading into 2026.

The consolidation of Visa's supervisory initiatives and the tightening of minimum thresholds signal that the networks remain firmly in a preventative posture rather than a reactive one. To stay compliant, acquirers and issuers must continue to invest in security measures, maintain vigilant oversight, and remediate any identified issues promptly.

Compliance Built Into the Processing Layer

DECTA is a certified Visa, Mastercard, and UnionPay payment processor in the EEA and APAC, audited by a Big Four firm.

Talk to DECTA