Summary
Approval for a high-risk merchant account is a documents problem you solve once. Keeping that account is an engineering problem your store solves every month. Visa’s VAMP ratio, Mastercard’s chargeback programs, MATCH and VMSS all measure you automatically now.
The thresholds moved in 2025 and move again on 1 April 2026. Most published guidance on approval predates every one of those changes. This playbook walks the phases in order, from underwriting posture to the checkout fields your ratio depends on.
Introduction
The failure you are trying to avoid is not a decline letter from an underwriter. It is an approval, six clean months of trading, and then a termination notice. That second outcome costs more, because by then your revenue depends on the account.
Approval is a documents problem, and you solve it once with evidence. Staying approved is an engineering problem, and your store solves it every single month. The card networks now measure your operating posture automatically against published numeric thresholds.
Those thresholds are the part most guidance gets wrong, because the numbers are regional and conditional. This playbook gives you the formula, the conditions, and the exclusions that keep disputes out of it.
No independent dataset exists on approval rates, underwriting timelines or reserve norms. Every number in circulation comes from a company selling merchant accounts, so we publish rules rather than rate cards.
Table of Contents
- What makes an underwriter classify your store as high risk?
- What goes in the document pack, and what is the underwriter reading it for?
- What terms come with an approval, and what should you get in writing?
- Which card network thresholds are you measured against in 2026?
- How do you keep the ratio down without refunding every complaint?
- What puts you on MATCH or VMSS, and what happens after that?
- What has to be true in WooCommerce or Magento for any of this to work?
- People also ask
- Conclusion
- Frequently asked questions
What makes an underwriter classify your store as high risk?
Underwriters classify your store as high risk when your category, billing model or history raises your expected chargeback rate. Merchant account underwriting is a judgement about probability, not about morality. It is made before anyone reads your pitch.
Risk signal | Why underwriters weigh it | What you can change before applying |
|---|---|---|
Product category and MCC code | It sets the expected dispute and regulatory exposure for the whole file. | Little, beyond describing the catalogue accurately and requesting the right code. |
Chargeback and refund history | It shows how you handled demand you already had. | Improve it now, because the trailing months are what gets read. |
Average ticket paired with delivery lag | A high ticket with a long wait is the classic dispute pattern. | Shorten fulfilment time, or publish delivery windows you can actually hit. |
Subscription or free-trial billing | Recurring and negative-option models generate first-party disputes. | Make renewal terms, pricing and cancellation obvious before checkout. |
Prior terminations and principal history | Terminated-merchant files follow the person, not only the business. | Prepare a written explanation instead of hoping it goes unnoticed. |
Thin or absent processing history | There is nothing to score, so the file defaults to the worst case. | Build history on a compliant account before you scale volume. |
Framing is Virtina’s, drawn from the underwriting criteria described across the network and processor sources cited in this article. Data as of 9 September 2026.
Our earlier guide to high-risk payment processing covers categories, fee structures and reserve types at length. This article assumes you have read it.
Which risk signals come from your product, and which come from your operations?
Product-side signals are mostly fixed, and operational signals are the ones you can still change. Delivery lag, refund policy visibility and free-trial mechanics are build and process decisions.
Tighten those before you apply, because they are the part you control. Regulated sellers in online firearms sales, hemp and vape all face the same product-side ceiling.
Why aggregator approval is not underwriting
A payment aggregator boards you into a shared account against a published policy list, not an individual file. Stripe’s prohibited business list rules out gambling, adult services, credit repair, unsafe-claim nutraceuticals and negative-option marketing. Tobacco, e-liquid, hemp-derived CBD within local THC limits and legal firearms are restricted.
There is no individual file to revisit, so the only lever anyone has is removal. You were a sub-merchant on somebody else’s MID, not a merchant holding your own.
If your operational signals are still messy, fix them before you submit the application.
What goes in the document pack, and what is the underwriter reading it for?
The pack is formation documents, processing history, bank statements, financials and the live site itself. The underwriter reads all of it for one thing: whether your claims, your category and your operations agree. Individual documents rarely fail an application, but contradictions between them do.
Steps one and two are the KYC and KYB layer.
- Step 1. Formation documents, the operating agreement and ownership percentages.
- Step 2. Government ID and tax ID for every principal owner named on the application.
- Step 3. Three to six months of processing statements plus matching business bank statements.
- Step 4. Vertical compliance documents: lab reports, licences, age-gating evidence and state registrations.
- Step 5. A live site showing refund, cancellation, shipping and contact terms without a login.
- Step 6. Fulfilment timing evidence that matches your average ticket.
- Step 7. A written explanation of any prior termination.
- Step 8. The MCC code you expect to be assigned, and why it fits what you sell.
What the documents have to agree on
Three things have to line up, and a mismatch between any two reads as misrepresentation. Your site’s claims must match the MCC code you are requesting. Your fulfilment timing must match your average ticket, because slow high-value delivery is a dispute engine.
Refund and cancellation terms must be visible without a login or a support ticket. Underwriters are not scoring these documents individually, they are checking them against each other and against your storefront.
You are applying for a merchant account, not for the payment gateway service providers that connect to it.
What a MATCH or VMSS screen does to your application
A hit on the MATCH list or on VMSS usually ends the application before an underwriter reads anything. Acquirers screen every applicant against both files first, because they are required to.
A clean business with a listed principal is still a decline in most cases.
Why nobody can tell you your approval odds
Nobody can tell you your approval odds, because there is no neutral dataset to calculate them from. No regulator, network or trade body publishes high-risk approval rates, decline rates, reserve norms or underwriting timelines.
What moves the answer is pack completeness, screening results, and whether your site matches your requested MCC code.
If your documents disagree with each other today, do not submit the application yet.
What terms come with an approval, and what should you get in writing?
An approval arrives with a reserve structure, a monthly volume cap and a settlement schedule. Every one of those is negotiable, so never accept any of them verbally. The offer comes from an acquirer backed by a sponsor bank.
We publish no numbers here, because every range in circulation traces back to one processor’s rate card.
Reserves come in three shapes. A rolling reserve holds a share of each batch and releases it on a schedule. An upfront reserve takes a lump sum before you process anything.
A capped reserve accrues to an agreed ceiling, then stops.
Your volume cap is the monthly number the account was underwritten for. Exceed it and the acquirer can hold funds, raise the reserve, or close the account.
Which terms you should insist are written into the agreement
Six terms belong in the signed agreement, not in an email.
- Reserve. The reserve type and its exact release schedule.
- Triggers. The conditions that allow the acquirer to raise that reserve.
- Cap. The monthly volume cap and the process for raising it.
- Settlement. Settlement timing, including weekends and holidays.
- Notice. The notice period you get before termination.
- Tokens. Who owns the customer card tokens if the relationship ends.
That last one matters most. Losing your tokens means every returning customer must re-enter a card at checkout. That is a conversion event, which is why B2B checkout best practices belong in this negotiation.
What changes after the first six months of clean processing
Clean processing history is the only asset that reliably improves your terms. Six months below the monitoring thresholds gives you a real argument for a lower reserve. Twelve gives you an argument for a higher cap.
That makes the threshold work in the rest of this article a commercial argument, not only a compliance one.
If your agreement does not name the reserve release schedule in writing, do not sign it.
Which card network thresholds are you measured against in 2026?
You are measured against Visa’s VAMP ratio and Mastercard’s chargeback programs every month, automatically. From 1 April 2026, the Visa merchant threshold in AP, Canada, the EU and US drops to 150 basis points. It was 220.
Program | How the ratio is measured | Threshold (2026) | The condition most pages omit |
|---|---|---|---|
Visa VAMP, merchant level (AP, Canada, EU, US) | Count of TC40 fraud plus TC15 disputes, divided by settled TC05 count. | 150 bps from 1 April 2026, paired with a 1,500 monthly count. | It applies only when your acquirer is not itself Above Standard or Excessive. |
Visa VAMP, merchant level (LAC) | The same count-based formula. | 150 bps and a 1,500 monthly count. | LAC has been at 150 bps since 1 June 2025, so no step-down applies. |
Visa VAMP, merchant level (CEMEA) | The same count-based formula, with an amount test added. | 220 bps, a 150 monthly count, and USD 75,000 in amount. | Three conditions, not one, and the count floor is far lower here. |
Visa VAMP, acquirer portfolio | The same ratio, aggregated across the acquirer’s whole portfolio. | Above Standard at 50 bps, Excessive at 70 bps. | Your acquirer’s standing decides whether your merchant threshold applies at all. |
Mastercard ECM | Monthly chargebacks divided by the prior month’s sales transactions. | 100 to 299 chargebacks and a ratio of 1.50% to 2.99%. | The denominator lags by a month, so falling sales raise the ratio. |
Mastercard HECM | The same lagged calculation. | 300 or more chargebacks and a ratio of 3.00% or higher. | Exit needs three consecutive months below the ECM thresholds. |
Sources: Visa’s Acquirer Monitoring Program fact sheet, with thresholds effective 1 June 2025 and the step-down on 1 April 2026. Mastercard ECM and HECM figures are as published by processors. Data as of 9 September 2026.
How is the VAMP ratio actually calculated?
The VAMP ratio is the count of TC40 fraud plus TC15 disputes, divided by settled TC05 transactions. It is count-based rather than dollar-based, which surprises most merchants.
It covers card-not-present VisaNet transactions only, domestic and cross-border. The thresholds took effect on 1 June 2025, and the program advisory period ended on 30 September 2025. Visa sets out the formula and the regional thresholds in its Visa Acquirer Monitoring Program fact sheet.
Two exclusions matter most. Disputes resolved through pre-dispute solutions are excluded from the ratio. So is TC40 fraud that qualifies for Compelling Evidence 3.0, subject to data-extract timing.
Why two merchants with the same ratio get treated differently
Merchant-level thresholds apply only when your acquirer is not itself in trouble. Visa measures acquirers at portfolio level, with Above Standard at 50 basis points and Excessive at 70. If your acquirer crosses either line, the enforcement conversation changes for everyone in that portfolio.
That is a real reason to ask an acquirer about its own portfolio standing before you sign.
Why the Mastercard ratio spikes when your sales fall
Mastercard divides this month’s chargebacks by last month’s sales transactions, so the denominator lags. A merchant whose volume drops sees the ratio climb without a single extra chargeback.
ECM starts at 100 chargebacks in a month with a ratio between 1.50% and 2.99%. HECM starts at 300 chargebacks and a ratio of 3.00% or higher. Exit needs three consecutive months below the ECM thresholds, so recovery is slow by design.
Fines start at nothing in month one and reach USD 1,000 from month two. They escalate over roughly a year and a half to USD 100,000 for ECM and USD 200,000 for HECM. HECM merchants may also face a USD 5 issuer recovery assessment on each chargeback above 300.
How do you keep the ratio down without refunding every complaint?

You keep the ratio down by stopping disputes before they are filed. A dispute resolved through a pre-dispute solution never enters the VAMP numerator at all. Refunding every complaint protects the ratio and destroys the margin.
Verifi is Visa’s pre-dispute network and Ethoca is Mastercard’s. Verifi provides Order Insight, which shows the issuer your transaction detail during the call. It also provides Rapid Dispute Resolution, which settles the transaction before a chargeback is created.
Disputes resolved through RDR do not count toward dispute rates, which is the whole point. Ethoca Alerts work the same way and help merchants exit ECM, HECM and EFM. RDR handles full-amount disputes on non-refunded transactions only, with no partial resolution.
Both apply only to chargebacks initiated after you enrol. Enrolling once you are already flagged does not repair the month you are in.
How does Compelling Evidence 3.0 block a dispute before it is filed?
Compelling Evidence 3.0 blocks a dispute by proving the cardholder has bought from you before. The rule needs at least two prior transactions with complete product descriptions and matching IP addresses. At least one matching email address or delivery address is also required.
When those conditions are met, the issuer must block the dispute. It is never filed, so there is no dispute fee and no ratio impact. CE 3.0 applies to Visa reason code 10.4, other fraud in a card-absent environment.
That is the first-party misuse case, where most regulated merchants bleed. All of it depends on four fields reaching the processor at transaction time.
Those fields are IP address, customer email address, product descriptions, and shipping or customer address. Section seven covers what that means inside your build.
Where representment and 3-D Secure 2 actually help
Representment recovers money, but it does not recover your ratio. A dispute that has been filed is already counted, whatever happens afterwards. Most merchants conflate the two, then wonder why a strong win rate changed nothing.
Representment protects revenue and prevention protects the account. 3-D Secure 2 belongs in the prevention half of that split, because it authenticates the cardholder before authorisation.
We are not stating liability-shift rules here, because we did not verify them against a primary source. Checkout data capture also fails silently, which is where WooCommerce checkout fixes pay for themselves.
What puts you on MATCH or VMSS, and what happens after that?
MATCH and VMSS are terminated-merchant files that acquirers screen every applicant against. Mastercard runs MATCH and Visa runs VMSS. Listings last five years, and only the acquirer that created one can remove it.
The rules below are as processors document them, because Mastercard’s own manual is not publicly retrievable. Removal happens in two circumstances only.
Either the acquirer listed you in error and corrects it. Or the listing was Reason Code 12 for PCI DSS non-compliance, and compliance has since been verified.
An acquirer must add a qualifying merchant within one working day of termination. Closing the account first does not prevent the listing.
MATCH records the principal owner’s name, address, phone number and tax ID. Your next venture inherits it, which is the part most founders learn too late.
MATCH uses 11 qualitative reason codes plus 2 quantitative ones, not the 14 that affiliate pages often claim. VMSS uses 13 qualitative codes, numbered 23 to 35.
Which triggers fire automatically, without anyone reviewing your case?
Four quantitative codes fire on numbers alone, with no case review. MATCH Reason Code 04, excessive chargebacks, triggers when monthly Mastercard chargebacks exceed 1% of monthly Mastercard sales transactions. Those chargebacks must also total USD 5,000 or more in the same month.
There is no minimum chargeback count. MATCH Reason Code 05, excessive fraud, triggers at 8% or more fraud-to-sales dollar volume. It also needs 10 or more fraudulent transactions totalling USD 5,000 or more in one calendar month.
VMSS Code 21, excessive fraud, needs USD 250,000 in fraud and a 180 bps fraud-to-sales ratio. VMSS Code 22, excessive disputes, needs 1,000 disputes and a 180 bps dispute-to-sales ratio. Merchants leaving an aggregator, including anyone planning a vape store WooCommerce migration, should confirm their status first.
Why winning the chargebacks afterwards does not undo it
Qualification is measured in the month it happens, and winning the disputes later does not reverse it. Neither does closing the account, as the one-working-day rule above makes clear.
Your dispute-response process, however good, cannot protect you from a listing. Only the prevention mechanics in section five can, because they stop the count from forming.
What has to be true in WooCommerce or Magento for any of this to work?

Three things have to be true in your build, and none of them is default behaviour. Your store must transmit the transaction fields the dispute rules depend on. It must route to a merchant account you control, and keep your payment page inside a scope you can defend.
Which transaction fields does your checkout have to send?
Four fields have to reach the processor at transaction time: IP address, customer email, product descriptions and address. Sitting in the order record is not the same as being transmitted.
If the fields are missing, your prevention tooling underperforms silently. Nobody finds out until the ratio moves, and by then the month is already counted.
A generic SKU string is not a product description and will not satisfy the rule.
Gateway, merchant account, and multi-MID routing
A gateway moves the transaction, and a merchant account holds the money and carries the risk. Merchants conflate them, then find the gateway was never what got terminated. Routing across more than one MID is the practical answer for mixed catalogues.
Separate product lines by MCC code and isolate a subscription book from one-off sales.
Authorize.Net Payments for WooCommerce is an official extension built by the Authorize.Net team, with tokenised storage through Customer Information Manager. Authorize.Net also publishes a first-party module on the Adobe Commerce marketplace.
The WordPress.org WP NMI plugin states it is not affiliated with or endorsed by NMI, WooCommerce or Automattic. We are not claiming the two platforms have equivalent high-risk gateway coverage.
Check which WooCommerce payment gateways support your codes before you commit to one. On Adobe Commerce, confirm first-party module availability with your Magento development services partner.
What PCI DSS 4.x changed for your payment page
PCI DSS 4.0 added 64 new requirements, and 51 of them were future-dated to 31 March 2025. Requirement 6.4.3 requires you to authorise and integrity-check every script on your payment page. Version 4.0.1 did not move that date.
Requirement 11.6.1 requires you to detect and alert on unauthorised changes to that page. Both target e-skimming. The PCI SSC guidance on future-dated requirements sets out what became mandatory and when.
Hosted checkout is therefore a scope decision with a named consequence, not a convenience. It narrows your obligations and your control over the fields section five depends on. WooCommerce security work and PCI scope are the same conversation on this platform.
This is the work, and it is what we ship on high-risk gateway integration projects.
People also ask
How long does high-risk merchant account approval take?
No independent data exists on high-risk underwriting timelines, so any range you read is a seller’s estimate. What actually drives it is the completeness of your document pack and your MATCH and VMSS screening results. A file whose site claims match the requested MCC code moves faster than one that raises questions.
Can you get approved after being listed on MATCH?
Usually not through normal channels, because only the acquirer that created the listing can remove it. Listings run five years, and removal happens in two circumstances only. Either the acquirer added you in error, or Reason Code 12 applied and PCI compliance is now verified.
What chargeback ratio gets a merchant account shut down?
It depends which network is measuring you, because the two programs use different formulas. From 1 April 2026, Visa’s merchant threshold in AP, Canada, the EU and US is 150 basis points. It is paired with a monthly fraud and dispute count floor of 1,500.
Mastercard’s ECM starts at 100 chargebacks in a month and a ratio of 1.50%.
Conclusion
Documents get you approved, and engineering keeps you approved. That split survives every rule change the networks publish. The application is a one-time event, while the thresholds run every month for as long as you trade.
Do one thing first. Find out whether your checkout is transmitting IP address, customer email, product descriptions and address today. Capture a live transaction and read exactly what the processor received.
If those fields are missing, your dispute prevention is running on paper only. Fix that before you spend another hour on representment templates.
Frequently asked questions
What is the difference between a payment gateway and a merchant account?
A gateway transmits the transaction, and a merchant account holds the funds and carries the risk. You can change gateways without changing acquirers. Underwriting applies to the merchant account, not to the gateway.
How is the VAMP ratio calculated?
Visa divides the count of TC40 fraud plus TC15 disputes by the count of settled TC05 transactions. It is count-based rather than dollar-based, and it covers card-not-present VisaNet transactions only. Disputes resolved before filing and TC40 fraud qualified for Compelling Evidence 3.0 are excluded.
Does winning a chargeback remove it from your ratio?
No, a dispute counts from the moment it is filed, whatever the outcome. Representment recovers the revenue, but the ratio and any program qualification stay where they were.
What is VMSS, and how is it different from MATCH?
VMSS is Visa’s terminated-merchant file and MATCH is Mastercard’s, and acquirers screen applicants against both. VMSS uses 13 qualitative reason codes numbered 23 to 35, plus quantitative fraud and dispute triggers.
Do PCI DSS requirements 6.4.3 and 11.6.1 apply if you use a hosted checkout page?
They were removed from SAQ A, so a fully outsourced payment page changes your validation route. They remain in the standard and apply under other SAQ types where payment functions are not fully outsourced. Confirm your SAQ type with your acquirer.
What transaction data does Compelling Evidence 3.0 need?
It needs IP address, customer email address, product descriptions, and shipping or customer address. At least two prior transactions must carry matching IP addresses and one matching email or delivery address. Those fields have to reach the processor at transaction time, not just your order table.
Can one WooCommerce store run more than one merchant account?
Yes, and for mixed catalogues it is often the right build. You route by product line or MCC code so one book’s dispute rate does not contaminate another. It needs deliberate gateway configuration and order routing logic, which is not a settings-page change.
What happens to your Mastercard chargeback ratio if your sales volume drops?
It rises, because the denominator is the prior month’s sales transactions rather than the current month’s. A merchant with falling volume can cross into ECM without a single extra chargeback. Plan for it before a seasonal dip.

