Home  /  News  /  Payments & Risk
Payments & RiskOctober 7, 2025

Card Scheme Monitoring Programs: What Gaming Merchants Must Know

Card scheme monitoring programs create real compliance risk for gaming merchants. Learn what Visa and Mastercard expect and how to stay off their watchlists.

Card Scheme Monitoring Programs: What Gaming Merchants Must Know

Card scheme monitoring programs are among the most consequential yet least discussed compliance obligations facing licensed gaming operators today. Visa and Mastercard run structured programs that track dispute and fraud rates at the merchant level, and gaming sits permanently in their highest-scrutiny category. Falling into a monitoring program triggers direct costs, reputational pressure with acquiring banks, and, in serious cases, the loss of card acceptance altogether.

How Card Scheme Monitoring Programs Work

Both Visa and Mastercard operate tiered monitoring frameworks that assess merchants on a rolling monthly basis. The two core metrics are chargeback rate and fraud-to-sales ratio, each measured against the prior month's settled transaction volume. Gaming merchants are classified under high-risk merchant category codes, which means the threshold for entering a monitoring program is lower than it would be for a standard e-commerce retailer.

Visa's Dispute Monitoring Program (VDMP) and High Excessive programs, along with Mastercard's Excessive Chargeback Program (ECP) and Excessive Fraud Merchant (EFM) program, share a similar structure. An operator that breaches the entry threshold receives a formal notification from its acquirer. From that point, a remediation clock starts. Monthly fees accumulate for every period the merchant remains in the program, and those fees escalate the longer the situation persists. Disengagement, meaning scheme-level removal of processing rights, becomes a real possibility after several consecutive months without meaningful improvement.

Thresholds Operators Need to Monitor Internally

The specific thresholds change periodically, but as of October 2025 the broadly understood entry points for gaming operators are:

  • Visa VDMP standard entry: chargeback ratio above 0.9 percent with at least 100 chargebacks in a month
  • Visa High Excessive: chargeback ratio above 1.8 percent with at least 1,000 chargebacks
  • Mastercard ECP standard: chargeback ratio above 1.5 percent
  • Mastercard EFM: fraud basis points above 50 combined with minimum transaction volume thresholds

Gaming operators should set internal early-warning alerts well below these figures. A practical approach is to flag any month where the chargeback ratio exceeds 0.6 percent, giving the payments and risk team time to investigate root causes before a formal notification arrives from the acquirer.

What Acquiring Banks and Regulators Expect to See

When an operator enters a monitoring program, the acquirer will typically request a formal remediation plan within 30 to 45 days. Regulators in jurisdictions such as Malta, Gibraltar, and the Isle of Man have also started asking operators to disclose active scheme monitoring status during licence renewals and material-change notifications. The expectation from both sides is broadly the same: a documented, data-driven response rather than a generic commitment to improvement.

A credible remediation plan should contain the following elements:

  • A root-cause analysis segmenting chargebacks by reason code, payment method, and player cohort
  • Evidence of enhanced transaction screening at the point of deposit, including velocity checks and device fingerprinting
  • A clear responsible gambling review to determine whether problem-gambling behaviour is driving dispute volumes
  • Updated terms and conditions ensuring players understand the no-refund policy before completing a deposit
  • A monthly reporting cadence shared with the acquirer, showing trend lines rather than point-in-time snapshots

Operational Steps That Move the Metrics

Reducing chargebacks in gaming requires coordination across payments, customer support, and compliance. The dispute reason codes tell operators where to focus. Reason codes related to "transaction not recognised" almost always indicate weak player communication at the point of purchase, a problem solved by clearer descriptor naming and confirmation emails. Codes related to "services not rendered" frequently arise from account verification failures or delayed withdrawal processing, which create player frustration and prompt bank disputes as a workaround.

On the fraud side, operators running 3D Secure 2.0 with optimised exemption strategies tend to maintain lower fraud rates than those applying blanket exemptions to maximise conversion. The short-term conversion gain from skipping authentication is frequently erased by fraud losses and scheme fees within two to three months.

The Acquirer Relationship as a Risk Asset

Gaming operators sometimes treat their acquiring relationship as a commodity. In practice, a stable, communicative acquirer is a competitive advantage. Acquirers that understand gaming can advocate within the scheme on an operator's behalf, negotiate remediation timelines, and provide early visibility into rule changes before they are publicly announced. Operators that communicate proactively when metrics deteriorate are significantly less likely to face abrupt contract termination than those whose acquirer discovers a problem through the scheme's own reporting cycle.

Scheme monitoring programs reward operators who treat payments data as a compliance input, not just a revenue metric. The operators who avoid watchlists are those who review chargeback and fraud rates with the same discipline they apply to their AML transaction monitoring.
FAQ

Frequently asked questions

What is a card scheme monitoring program and why does it affect gaming operators?

A card scheme monitoring program is a structured surveillance framework run by Visa or Mastercard that tracks chargeback and fraud rates at the individual merchant level each month. Gaming operators are classified under high-risk merchant category codes, which means they face lower entry thresholds than standard e-commerce businesses. Operators that exceed these thresholds are formally enrolled in the program, face escalating monthly fees, and risk losing card acceptance rights if the metrics do not improve within the remediation period.

What chargeback rate should a gaming operator treat as an internal warning level?

Although Visa's standard monitoring program entry point is broadly understood to be a chargeback ratio above 0.9 percent, gaming operators should set an internal alert at 0.6 percent or lower. This buffer gives the payments and risk team time to investigate root causes and implement corrective measures before the operator receives a formal notification from its acquirer. Catching the trend early is far less costly than responding to a scheme notification under time pressure.

What does an acquiring bank typically require when a gaming merchant enters a monitoring program?

Most acquiring banks request a formal written remediation plan within 30 to 45 days of a monitoring program notification. The plan should include a root-cause analysis of chargebacks broken down by reason code and player segment, evidence of enhanced deposit screening, a responsible gambling review, and a schedule of monthly reporting to demonstrate improving trend lines. Generic promises of improvement are generally insufficient; acquirers expect data-backed documentation that shows the operator understands the specific drivers of its dispute volume.

How does 3D Secure 2.0 affect a gaming operator's fraud monitoring program risk?

3D Secure 2.0 reduces fraud-related chargebacks by shifting liability to the card issuer when authentication is completed, which directly lowers the fraud basis points that scheme fraud monitoring programs measure. Operators that apply blanket exemptions to maximise deposit conversion often experience short-term revenue gains that are reversed within two to three months by higher fraud losses and scheme program fees. A calibrated exemption strategy that prioritises authentication for higher-risk transactions tends to produce better long-term fraud metrics without materially harming overall conversion rates.

Keep reading

Related articles

Show us one brand.
We will find the leaks.

Book a 30-minute teardown. We walk through one of your brands and show you exactly where revenue, retention or compliance is slipping, no obligation.