Enforcement Mechanisms and Non-Compliance Penalties
Visa's Enforcement Structure
If a merchant does not comply, and a service provider is found not adhering to PCI DSS requirements, Visa can levy Non-Compliance Assessments.
These can be charged to the issuer or acquirer, yet waived for those with clear PCI DSS compliance for a reasonable period before the breach and during the breach to forensic assessment.
Mastercard's Enforcement Approach
Mastercard has similar enforcement provisions, including assessments for non-compliance.
For instance, with QMAP, if fraud occurs, the merchant is to be terminated by the acquirer and the issuer may initiate chargebacks in order to recover the issuer's funds.
Registration and Third-Party Obligations
Third-Party Agent Registration
Visa requires registration of Third Party Agents (TPAs).
A Third Party Agent is defined as any person or entity that solicits for an acquirer/issuer, installs acceptance devices, issues en/decryption keys, or has access to cardholder data.
Without TPAs registered pursuant to the TPA Registration Program, no issuer/acquirer/merchant may engage in TPA services.
Unregistered vendors are a common compliance gap, since agents are often engaged commercially before anyone checks the registration requirement.
For issuers the exposure runs through card program vendors such as personalisation bureaux, processors, and cardholder support providers, all of which meet the TPA definition once they touch cardholder data.
Global Registry of Service Providers
Visa holds the Global Registry of Service Providers, which refers to the industry's official registry for payment processing to check if agents affiliated with any party are registered and in good standing.
This is to promote proper operations and use licensed service providers.
Checking the registry before integrating a provider is the simplest way for an acquirer or issuer to avoid inheriting an unregistered party's exposure.
Visa Direct Controls
For all transactions using Visa Direct, the acquirer must ensure all senders are in compliance with applicable money licensing requirements, that all Know Your Customer (KYC) and screening requirements are completed, and that velocity controls are established.
Visa Direct is push-payment infrastructure, so the obligations sit on the sending side rather than on merchant acceptance, which is why it carries its own control set.
What Recent Changes Mean for Compliance and Risk Managers at Acquirers and Issuers
The payment card networks have continued to evolve, with several developments now firmly established as of 2026.
Visa's VAMP Transformation
The consolidation of various monitoring programs under the VAMP framework reflects a broader industry shift from reactive anomaly detection toward proactive, preemptable fraud prevention.
Acquirers and merchants have had to adjust their risk assessment approaches accordingly, incorporating mandated monitoring technology and a more hands-on stance toward prevention in-house.
Enhanced Authentication Requirements
Both networks have layered on new authentication requirements, for example, Mastercard's Authentication Best Practices guide and required authentication data in authorization and clearing messages.
3D Secure sits at the centre of this, since authentication outcomes feed directly into the fraud ratios acquirers are measured on, and in Europe it is also the mechanism through which PSD2 strong customer authentication obligations are met.
That overlap is worth tracking, because card network compliance and regional regulation are enforced by different bodies on the same transaction data, and meeting one does not automatically satisfy the other.
Conclusion
Visa and Mastercard don't leave compliance to acquirers and issuers up to chance, with an array of steps to ensure adherence across their networks.
From mandatory standards to monitoring programs to validation requirements to enforcement actions, they've taken every step necessary to preserve the security of their payment infrastructure.
As the global nature of fraud continues to evolve, so does compliance, with the frameworks established in 2025 now serving as the baseline standard across both networks heading into 2026.
The consolidation of Visa's supervisory initiatives and the tightening of minimum thresholds signal that the networks remain firmly in a preventative posture rather than a reactive one. To stay compliant, acquirers and issuers must continue to invest in security measures, maintain vigilant oversight, and remediate any identified issues promptly.