Mastercard GMAP Compliance for Merchant Portfolios
The Acronym Set You Will Need
This bulletin carries more acronyms than any Mastercard announcement in recent memory, and several of them are new. Here is the full set as we use it throughout:
- ACMP: the Acquirer Chargeback Monitoring Program, being retired
- GMAP: the Global Merchant Audit Program, which ACMP is being folded into
- QMAP: the Questionable Merchant Audit Program, revised on the same date
- ECP: the Excessive Chargeback Program, the umbrella that has historically contained the two chargeback tiers below
- ECM: Excessive Chargeback Merchant
- HECM: High Excessive Chargeback Merchant
- EFM: Excessive Fraud Merchant
- HDM: High Dispute Merchant
- EDM: Excessive Dispute Merchant
- HDA: High Dispute Acquirer
- EDA: Excessive Dispute Acquirer
- MID: the acquirer-assigned Merchant ID
- ICA: the Interbank Card Association number identifying an acquirer, equivalent to the BIN in Visa’s structure
- FMP: the Franchise Management Program
- QM: Questionable Merchant
What GMAP Absorbs and What It Adds
Mastercard is retiring ACMP in its current form and describes the change as evolving ACMP into GMAP. Revised GMAP Standards will be established within the Security Rules and Procedures manual. Administration runs through the Data Integrity application in My Company Performance on Mastercard Connect, which is the same path acquirers use today.
Three categories migrate intact. ECM, HECM, and EFM keep their existing criteria and continue operating. Four categories are new. HDM and EDM apply at the merchant level, HDA and EDA at the acquirer ICA level.
The addition is what creates complexity. A breach of any applicable fraud, dispute, or chargeback threshold opens the door to remediation. A merchant can be measured against ECM criteria and HDM criteria in the same month, because the two count different things. ECM and HECM count first presentment chargebacks. HDM and EDM count transactions reported as fraud to the Fraud and Loss Database, including fraud that never produced a chargeback, plus chargebacks filed for non-fraud reasons. These are different populations drawn from different reporting streams, but any threshold breach opens an audit, and most categories carry assessments once the counter advances far enough.
Portfolio modeling built around a single chargeback ratio will therefore miss the new thresholds entirely. That is the operational headline for merchant service providers.
Merchant Level Monitoring Under Mastercard GMAP
Both merchant categories, for chargebacks and disputes, use a three-part test. A minimum activity floor, a minimum dollar figure, and a basis point ratio. All three conditions must be met in the same month for identification.
The ratio deserves precision. Mastercard compares the combined count of fraud reports plus non-fraud chargebacks against the count of sales from the previous month. Counts, not dollar values. The dollar figures operate as a separate qualifying floor alongside the ratio, which means a merchant can clear one test and fail the other.
High Dispute Merchant
HDM identification requires at least five cleared transactions, $5,000 or more in reported fraud plus non-fraud chargebacks, and 500 or more basis points, which is 5 percent.
Assessments follow an escalating schedule tied to how long the audit has been open. Months one through six carry $0. Months seven through eleven move to $5,000 monthly. Months twelve through eighteen reach $10,000. From month nineteen onward, $25,000 monthly.
The early zero-assessment period is easy to misread as a grace period. The counter is already advancing beneath it. A merchant that ignores the first six months does not restart at month one when the fines begin. They must show three consecutive months of compliance in order to exit Mastercard monitoring, and only then will the clock reset. We return to this in depth under the audit counter section.
HDM also carries a reputational consequence. Mastercard may notify issuers when a merchant exceeds the threshold for two or more consecutive months. Issuer awareness could potentially affect authorization behavior on that merchant’s transactions well before any financial penalty lands.
Excessive Dispute Merchant
EDM uses the same five-transaction floor with $10,000 or more in combined fraud and non-fraud chargebacks and 5,000 or more basis points, which is 50 percent.
Assessments start immediately. Month one is $5,000. Month two jumps to $25,000. Months three through eleven sit at $100,000 monthly. Months twelve through eighteen reach $200,000. From month nineteen, $300,000 monthly.
Those figures dwarf everything else in the bulletin, and the fines are only part of the exposure.
The EDM Liability Window and Reason Code 4849
A merchant exceeding the EDM threshold for two months becomes liable for all fraud-related chargebacks tied to transactions occurring in the three months before identification, plus fraudulent transactions during the following six months. That is a nine-month liability envelope, three months of which are retroactive. Because the retroactive portion reaches transactions that have already cleared, it could potentially capture cases where 3DS liability had shifted or where a representment was previously resolved in the merchant’s favor.
Mastercard will publish a list of EDM merchants along with the applicable timeframes. Issuers may use chargeback reason code 4849, Questionable Merchant, to recover 100 percent of the transaction amount within those windows. The Chargeback Guide will be updated accordingly, including use of Message Reason Code 4849/49 for merchants identified under GMAP.
Some early industry commentary has suggested that 4849 eliminates a merchant’s ability to respond. That overstates what the bulletin says. Under current rules, 4849 chargebacks can be contested where the acquirer or merchant can demonstrate the transaction was legitimate and properly authorized, within the response window that applies to the code. The bulletin does not remove those rights, though it does confirm the Chargeback Guide is being revised, so the exact response mechanics for GMAP-identified merchants may change before April 2027.
What providers should take from this is narrower and still serious. The retroactive portion is the part worth modeling. A merchant identified in month two carries exposure on transactions already settled and already reconciled, and defending those cases requires evidence that may be months old by the time the chargeback arrives. Any pass-through arrangement written on the assumption that liability begins at identification may need revisiting.
Acquirer Level Monitoring Under Mastercard GMAP
The acquirer categories apply at the ICA level and use identical activity floors. At least 1,500 cleared transactions and 1,500 or more transactions reported as fraud or charged back for non-fraud reasons in the month.
High Dispute Acquirer
HDA triggers at 50 or more basis points, which is 0.5 percent of the previous month’s sales count. Assessments are $0 for months one through eleven, $25,000 for months twelve through eighteen, and $50,000 monthly from month nineteen.
Fifty basis points across an entire portfolio is a demanding figure for any provider serving higher-risk verticals. Worth modeling carefully before April 2027.
Excessive Dispute Acquirer
EDA triggers at 70 or more basis points, or 0.7 percent. Assessments run $0 for months one and two, $10,000 for months three through six, $25,000 for months seven through eleven, $50,000 for months twelve through eighteen, and $100,000 monthly from month nineteen.
The consequences extend past assessments. An acquirer remaining noncompliant for twelve or more months may be required to complete an FMP review at its own expense and remediate identified issues. At nineteen or more months, Mastercard cites potential restrictions, suspension, or termination of the Mastercard license.
That final escalation is the reason GMAP deserves board-level attention rather than treatment as a reporting adjustment.
How the Audit Counter Works
The mechanics are identical at merchant and acquirer levels, and they reward early action heavily.
Breaching either applicable threshold opens an audit and starts a monthly counter. The assessment charged in any given month depends on how many months that audit has been open and which threshold was exceeded. Closing the audit requires compliance with both thresholds for three consecutive months, after which the counter resets.
Read that requirement carefully. Compliance with both thresholds, sustained across three consecutive months. A portfolio that drops below one threshold while remaining above the other keeps the audit open. A portfolio that oscillates keeps the counter advancing and re-enters at whatever escalated rate the counter has reached.
The practical implication is that partial remediation produces no relief. Providers accustomed to managing merchants down to just below a threshold may find that approach leaves audits open indefinitely at escalating cost.
Sharing a Merchant ID Will No Longer Offer Cover
For ECM, HECM, and EFM, identification moves from the MID to the submerchant ID where applicable. Today Mastercard identifies the merchant using DE 42, the Card Acceptor ID Code, which carries the acquirer-assigned MID. Going forward, when a submerchant identifier is present in the field reserved for it, DE PDS208s2, Mastercard will use that identifier instead. Whether that field gets populated therefore determines the level at which a business is monitored.
This closes a structural gap. Under the current arrangement, a submerchant generating disproportionate chargeback activity can be diluted by the aggregate volume of every other submerchant sharing that MID. Aggregation has functioned as a buffer, sometimes deliberately. Monitoring at the submerchant level removes the aggregation loophole and gives Mastercard and acquirers direct visibility into which specific business is generating the activity.
Marketplaces, platforms, and aggregated acquiring arrangements such as Merchants of Record carry the most exposure here. Submerchants that have never approached identification thresholds on a blended basis may surface individually once the change takes effect on 1 April 2027, which could potentially draw attention to the parent MID as well.
What This Does Not Change
MID stacking, sometimes called load balancing, runs in the opposite direction. That is a single merchant spreading volume across several merchant IDs so no individual one accumulates a ratio high enough to trigger identification. The submerchant change addresses the reverse arrangement, where many businesses share one MID. A merchant holding multiple direct MIDs still holds them after April 2027. Worth keeping in mind that HDM and EDM draw on fraud reporting alongside chargebacks, so spreading transaction volume across accounts may not shift every number these categories track.
The ECM Phase Down and Where HECM Sits
GMAP reduces the ECM basis point threshold incrementally across five years while holding the chargeback count criterion at 100 or more throughout. No change applies during 2027 and 2028, where the band remains 150 to 299 basis points. In 2029 the floor drops to 130. In 2030 it reaches 110. In 2031 it settles at 90 to 299 basis points.
HECM sits above that band and currently identifies merchants at 300 or more chargebacks combined with 300 or more basis points. The bulletin does not revise HECM criteria, so lowering the ECM floor widens the identification band from below while its ceiling holds.
That widening is gradual by design. Mastercard frames the phased approach as giving acquirers and merchants time to adapt. For portfolio planning, the useful framing is that a merchant sustaining 0.9 percent sits comfortably outside ECM criteria today and inside them by 2031, with no change in its own behavior required.
QMAP Revisions
Mastercard is strengthening QMAP on the same 1 April 2027 effective date, and every change widens the net.
The minimum transaction volume during the case scope period falls from $50,000 to $10,000, applied consistently across bustout and non-bustout evaluations. The standard case scope period shortens from 120 days to 30, with Mastercard retaining discretion to extend to 60 days when additional analysis is required. The merchant age requirement, which previously limited non-bustout identification to merchants less than six months old, is removed entirely.
Under the revised definition, a merchant is identified as a QM when it submitted at least $10,000 in transaction volume and at least five transactions during the case scope period, and one further condition applies. For bustout situations, at least 50 percent of transaction volume involved cardholder bust-out accounts. For non-bustout situations, at least two of three tests must be met: a fraud-to-sales transaction ratio of 70 percent or greater, 20 percent or more of transactions declined or referred by the issuer, or fraudulent transactions, declines, and referrals exceeding approved transactions by count or dollar amount.
Put Your GMAP Readiness Plan in Motion
Preparing for Mastercard GMAP is a data and workflow problem before it becomes a compliance problem. If your reporting cannot currently surface combined fraud and non-fraud chargeback performance against prior-month sales counts at submerchant granularity, that gap sits upstream of every other decision. ChargebackHelp works with merchant service providers to build that visibility, model portfolio exposure against HDM, EDM, HDA, and EDA criteria, and automate the resolution and recovery workflows that hold merchant performance below thresholds. Contact the ChargebackHelp GMAP team today to assess your portfolio and prepare now, before April 2027.
GMAP Is Still Taking Shape
Mastercard has signaled that the Chargeback Guide and Security Rules will be updated ahead of the April 2027 effective date, and further clarification is likely as acquirers work through implementation. We will revise this piece as those details land, so check back periodically to make sure you are working from current information.
Why ChargebackHelp?
ChargebackHelp gives merchant service providers a single environment for managing chargeback performance across an entire portfolio. DEFLECT resolves transaction confusion at the point of inquiry through Verifi Order Insight and Ethoca Consumer Clarity, preventing the disputes that would otherwise escalate. RESOLVE consolidates alerts from Verifi CDRN, Ethoca Alerts, and Visa RDR so eligible cases are refunded before they become chargebacks. RECOVER automates representment where revenue recovery is warranted. Together these solutions reduce systemic portfolio risk, keep merchant ratios compliant, and give providers an automation capability they can extend to their own merchant customers as a competitive advantage.
FAQs: Mastercard GMAP Compliance for Merchant Portfolios
What is Mastercard GMAP?
GMAP is the Global Merchant Audit Program, the framework covered by revised Standards in bulletin GLB 14127.1, effective 1 April 2027. ACMP is being retired and its components folded into GMAP, which also adds four monitoring categories that combine confirmed fraud reporting with non-fraud chargeback activity at both merchant and acquirer levels. ChargebackHelp helps providers build the portfolio reporting these combined measurements require.
Can a merchant be identified under ECM and HDM at the same time?
Yes. The categories measure different inputs and operate independently, so a merchant can meet criteria for both in the same month. How assessments interact in that situation is one of the points the bulletin leaves open, and modeling portfolio merchants against every applicable threshold is an area where we work directly with providers.
Can a 4849 chargeback be contested?
Under current rules, 4849 chargebacks can be challenged where the acquirer or merchant can show the transaction was legitimate and properly authorized. The bulletin confirms the Chargeback Guide is being revised for GMAP-identified merchants, so providers should verify the response mechanics that will apply after April 2027 rather than assuming today’s process carries forward.
How does a GMAP audit close?
Compliance with both applicable thresholds for three consecutive months closes the audit and resets the monthly counter. Partial compliance keeps the audit open and allows assessments to continue escalating, which makes early and complete remediation considerably cheaper than gradual improvement.
What should providers do about submerchant ID monitoring?
Run submerchant-level performance analysis against current ECM, HECM, and EFM criteria to identify which accounts would be flagged under the new identification method, and confirm your DE PDS208s2 population practices with your processor. Aggregation will no longer dilute individual submerchant performance after 1 April 2027. Our team can assist with that analysis.
What happens if an acquirer stays noncompliant long term?
An acquirer noncompliant for twelve or more months may be required to complete an FMP review at its own expense and remediate identified issues. At nineteen or more months, Mastercard cites potential restrictions, suspension, or termination of the Mastercard license.


