Card Network Rules and Risk Programs

An objective analysis of how Visa and Mastercard operating regulations govern high-risk commerce, how acquiring banks enforce scheme mandates, and how risk monitoring programs dictate merchant survival.

Reference Guide · The Decline File · September 2026

This document serves as an objective reference on payment network governance and risk frameworks. It contains no affiliate links, sponsored listings, or commercial solicitations.

01 — Regulatory Hierarchy

Where payment rules originate and how they reach your checkout

When an online merchant experiences sudden processing holds, mandatory reserve increases, or account termination, the action is rarely an isolated decision made solely by the gateway or software interface. In card payments, operational boundaries are established at the top of the payment chain by the global card networks—principally Visa and Mastercard.

Merchants do not hold direct contractual relationships with card networks. A merchant signs a merchant processing agreement with an acquiring bank or a registered payment facilitator. However, to maintain licensed access to card network rails, acquiring banks are legally bound to enforce every provision of the global scheme rulebooks across their downstream portfolios.

This structural hierarchy means that while your daily customer support interactions occur with your gateway or payment provider, the non-negotiable operational boundaries—including prohibited product categories, permitted refund windows, dispute time limits, and chargeback ratio ceilings—are dictated directly by card network bylaws.

02 — Scheme Documentation

The public rulebooks: Visa and Mastercard standards

Both major card brands publish comprehensive operating manuals that detail member bank obligations, transaction processing specifications, technical messaging standards, and brand protection rules. These documents form the ultimate legal authority governing every card-not-present transaction worldwide.

Merchants operating in elevated-risk sectors benefit from consulting these primary source texts directly rather than relying on second-hand interpretations:

Visa Core Rules and Visa Product and Service Rules

Visa publishes its global operating manual publicly. The definitive document can be accessed directly via the Visa Core Rules PDF document. This comprehensive reference governs cardholder authorization, merchant acceptance procedures, dispute resolution stages, and high-risk merchant brand standards.

Mastercard Rules and Security and Risk Services Rules

Mastercard maintains its core scheme requirements within the Mastercard Rules manual, supported by specialized volumes including the Mastercard Security and Risk Services Rules and the Mastercard Chargeback Guide. These manuals outline merchant registration mandates for specialized categories, security compliance guidelines, and acquirer risk management standards.

These rulebooks are updated multiple times each year. Changes frequently introduce new disclosure requirements for recurring billing subscriptions, revise dispute evidence submission timelines, or adjust compliance requirements for specific commercial verticals.

03 — Risk Surveillance

Merchant monitoring programs and regulatory enforcement

To protect cardholders and maintain confidence in digital payments, card networks operate automated monitoring frameworks designed to identify merchants exhibiting anomalous dispute activity, elevated fraudulent transactions, or non-compliant business practices. These programs track portfolio data reported monthly by acquiring institutions.

Surveillance programs generally fall into three operational categories:

  • Dispute and chargeback monitoring: Identifies merchants whose ratio of customer chargebacks relative to monthly sales volume crosses designated program thresholds.
  • Fraud monitoring programs: Evaluates total dollar volume and count of confirmed fraudulent card transactions, independent of whether formal chargebacks were initiated.
  • Brand integrity and risk mitigation: Evaluates merchants selling regulated, restricted, or reputational products to ensure proper licensing, accurate MCC coding, and absence of deceptive marketing practices.

When a merchant triggers a monitoring program, the network places the acquiring bank into an active tracking cycle. Consequences escalate through structured phases: initial warning and notification periods, mandatory remediation plan submissions, escalating monthly scheme fines, and ultimately mandatory termination if performance metrics are not rectified.

Because card networks periodically update their specific program threshold calculations, tier structures, and penalty schedules, merchants should not rely on outdated static metrics. Current criteria, entry thresholds, and compliance timeframes should always be confirmed against the card networks' published program documentation and direct guidance from your acquiring bank's risk department.

04 — Industry Blacklisting

The MATCH list: origin, mechanics, and consequences

The MATCH system (Member Alert to Control High-Risk Merchants) is a centralized industry risk database created and operated by Mastercard, and utilized across the global payments sector alongside complementary databases such as Visa VMAS (Visa Merchant Alert Service). Its primary purpose is to allow acquiring banks to screen new merchant applicants against a historical record of terminated accounts.

Under card network operating rules, an acquiring bank is contractually required to add a merchant to the MATCH database whenever the bank terminates a merchant processing relationship for specific enumerated causes. These causes correspond to standardized reason codes, including excessive chargebacks, confirmed fraud, severe money laundering violations, unlawful business activities, or intentional transaction laundering.

Understanding the gravity of a MATCH listing is essential for any high-risk operator:

Beneficial owner tracking

MATCH records do not merely track the corporate legal name or URL. The database indexes corporate tax identification numbers, physical business addresses, and the personal identities (names, personal tax IDs, and dates of birth) of all significant beneficial owners and corporate officers. Forming a new entity does not bypass a MATCH listing.

Five-year retention window

A listing placed on the MATCH database is generally retained in the system for up to five years from the date of submission. Removal prior to this retention period is rare and can only be executed by the specific acquiring institution that originally placed the record, typically requiring proof of administrative or factual error.

Industry-wide impact

A single declined merchant application is a routine commercial event confined to one underwriter. A MATCH listing, by contrast, creates an immediate automatic inquiry alert for any acquiring bank worldwide during application review, causing nearly all mainstream and traditional high-risk acquirers to decline processing automatically.

05 — Governance Matrix

Where payment constraints originate and who enforces them

Payment requirements originate across multiple institutional tiers. The following table delineates what each stakeholder governs and how enforcement is executed.

Table 1 — Where the constraints come from

SourceWhat it controlsWho enforces it
Card Networks (Visa, Mastercard)Global scheme rules, brand standards, dispute procedures, monitoring thresholds, MATCH placement standards.Enforces against acquiring banks via institutional fines, audit assessments, and license revocations.
Acquiring BanksMerchant underwriting eligibility, credit limits, rolling reserve percentages, settlement payout timing, account termination.Enforces directly against merchants via merchant processing agreements, daily holds, and reserve retention.
Payment Gateways & PayfacsTechnical API connectivity, checkout formatting, automated transaction screening, internal restricted business rules.Enforces at software layer via API key suspension, checkout disabling, and immediate platform bans.
Government Regulators & LawAnti-money laundering (AML), Know Your Customer (KYC) statutes, sanctions compliance, consumer protection, jurisdiction licensing.Enforces against banking institutions and corporate executives via civil penalties, banking sanctions, and legal action.

06 — Cluster Index

In this section

Detailed technical briefs on specific card network programs, dispute evidence requirements, and compliance checklists are published in this section:

Technical guides covering scheme monitoring programs, dispute representment rulebooks, and compliance workflows are indexed here.

07 — Related Topics

Explore related payment governance guides

Review emergency remediation protocols, merchant account underwriting requirements, and industry-specific payment profiles:

08 — Questions

Frequently asked questions

Do merchants sign contracts directly with Visa or Mastercard?

No. Merchants do not enter into direct commercial contracts with the card networks. Merchants contract directly with acquiring banks or payment processors. However, card networks mandate that all acquirers include terms in merchant agreements binding the business to network operating rules, brand standards, and dispute regulations.

Can an acquiring bank waive a card network compliance fine on behalf of a merchant?

No. Card networks assess program penalties and compliance fines directly against the acquiring institution. Because acquirers are contractually liable to the scheme, merchant agreements contain indemnification clauses that pass all network fines, audit costs, and administrative assessments directly through to the merchant balance.

How does a merchant discover if they have been placed on the MATCH list?

There is no public lookup portal for MATCH listings. Merchants typically learn of a listing when a new acquiring bank declines an application citing an adverse inquiry hit on the MATCH or VMAS databases. To confirm the specific reason code, the merchant must contact the acquiring bank that originally placed the record.

Last reviewed September 2026