All articles

Visa's VAMP ratio: what actually gets an adult classifieds site's merchant account flagged in 2026

10 min read

The ratio behind the warning nobody named

If you run an adult classifieds site and card payments matter to your business, you have probably already been told, in some form, that too many disputes will get your merchant account closed. What almost nobody tells an operator is the name of the mechanism that actually decides the line: a Visa program called the Visa Acquirer Monitoring Program, VAMP, and a single formula that has changed twice in the past year in ways that matter directly to a small, high-risk seller.

Before April 2025, Visa ran two separate programs: one that watched fraud reports and one that watched chargebacks, each with its own threshold. A merchant could run high on one and low on the other and never trip either wire on its own. VAMP folded both into one ratio, and that single change is the reason a business that used to feel comfortable can suddenly find itself close to a line it never watched before.

The formula itself is simple to state and easy to get wrong in your head: fraud reports (called TC40 messages) plus disputes and chargebacks (called TC15 messages), divided by settled transactions (TC05). Every one of those three letters-and-numbers codes refers to a specific message Visa's own systems generate, not something your processor makes up, which is why the number your acquirer calculates from raw network data can differ from whatever total your payment dashboard shows you.

The part that trips up an operator doing the math on their own is that this is a plain count, not a dollar figure. A ten-euro disputed listing fee counts exactly the same as a five-hundred-euro annual package once it becomes a TC15 or TC40 entry. If you have been reassuring yourself that disputes are a small fraction of your revenue, that comfort does not transfer to the ratio Visa is actually reading, because a count does not care what any single transaction was worth.

It is also worth saying plainly what this program is not. It is a separate mechanism from Visa's Integrity Risk Program, which screens the nature of the business itself before an account is ever approved. VAMP does not care what you sell. It only reads what happens to the transactions you already process, which means a fully compliant, properly categorized adult classifieds account can still get flagged on transaction behavior alone.

The 2026 numbers, and why the region matters

On April 1, 2026, Visa cut the merchant-level threshold that defines an "Excessive" account from 2.2% to 1.5% across the United States, the European Union, Canada, and Asia-Pacific. That is not a rounding change. A merchant running a ratio that was comfortably under the old line by half a point can be over the new one without a single additional dispute, purely because the goalposts moved under a business that changed nothing.

Two regional details are easy to get wrong, so it is worth stating them exactly. Latin America and the Caribbean were already held to the 1.5% line before this cut, so nothing changed there in April 2026. Central Europe, the Middle East, and Africa remain at the older 2.2% threshold, unchanged. An operator running payment rails across more than one of these regions is not managing one ratio; they are managing whichever regional line applies to each transaction's issuing bank.

There is a floor below which the ratio does not formally apply at all: a combined monthly count of roughly 1,500 fraud reports and disputes together, in most regions, before Visa's own monitoring switches on. A small classifieds site processing a few hundred transactions a month will likely sit under that floor for a long time. That is not the same as being safe. Your own processor almost always sets an internal limit well below Visa's published number, precisely because it does not want its whole book of merchants anywhere near the line before Visa's monitoring even starts counting.

The denominator matters as much as the numerator, and it is where a lot of operators misread their own risk. Only settled transactions count, not attempted ones. Tightening your fraud rules at checkout so that suspicious payments get declined before they settle does nothing for this ratio, because a decline never enters the denominator either. The only two levers that move this number are the count of completed sales going up, or the count of disputes and fraud reports against them going down.

This is also why calculating your own version of the ratio at home, using whatever numbers your payment dashboard shows, tends to look better than reality. Most dashboards report dollar totals refunded or disputed against dollar totals processed. Rebuild the number the way Visa actually does, as a straight count of settled card-not-present transactions against a straight count of disputes and fraud reports, and the picture usually gets worse, not better.

Why your processor feels this before you do

VAMP does not reach an individual merchant directly. Visa monitors the acquiring bank or payment facilitator's entire portfolio of merchants as a single unit, and the thresholds at that level are tighter than the merchant-level ones: 0.5% for a portfolio flagged "above standard" and 0.7% for one flagged "excessive," roughly a third of the merchant number, and unchanged since the program launched in 2025.

That gap is the whole explanation for why a processor pushes limits onto individual accounts that feel stricter than anything Visa has published for merchants. An adult classifieds account sitting at 1.3%, still technically under the 1.5% merchant line, is nonetheless one of the accounts dragging its acquirer's whole book toward 0.7%. The acquirer has every reason to act on that account long before Visa's own merchant-level number would ever flag it directly.

A piece on what actually threatens a merchant account described this pressure before, without naming the specific mechanism behind Visa's side of it. VAMP is that mechanism. The Mastercard program that piece described in detail runs on its own separate rules; VAMP is Visa's equivalent, built differently, with the two-ratio structure and the count-based formula described above.

There is no single, published, per-transaction dollar fine that Visa states publicly for crossing the merchant threshold. Several payment blogs repeat specific fee figures as though they came from a public Visa document; they do not appear in Visa's own published materials, and the actual amount an operator pays typically comes from their processor's contract, not from a number Visa discloses to merchants directly. What is consistent and real across processors is the shape of the consequence: a demand for a reserve held back from your own revenue, tighter processing limits, a formal remediation plan, or, if none of that brings the number down, the account being pushed out of the portfolio entirely.

None of this is optional paperwork your processor invented to justify a fee. The acquirer's own survival in Visa's system depends on keeping its book under 0.7%, and a small number of merchants running hot is exactly the kind of concentrated risk that pushes a whole portfolio over that line.

The mistake that costs a whole quarter

Here is the detail that catches operators who think they are handling this correctly: winning a dispute does not take it off the ratio. The count locks in the moment a chargeback or fraud report is filed, not when it is resolved. Fight a dispute through ordinary representment, win, get the money back, and the entry still sits in your VAMP numerator exactly as if you had lost.

Only two things actually keep an entry out of the count. The first is resolving the complaint before it is ever filed as a formal chargeback at all, through a pre-dispute alert service such as Visa's own Rapid Dispute Resolution or its CDRN network, or Mastercard's equivalent, Ethoca, on cards issued through that network. Refund inside that short window, typically about a day, and the case never becomes a TC15 entry in the first place.

The second applies to exactly one category of dispute: Visa reason code 10.4, where a cardholder claims they never authorized the transaction at all. A defense called Compelling Evidence 3.0 lets a merchant retroactively remove the associated fraud report from the ratio, but only if very specific conditions are met, and this is where most small operators discover they never kept the right records in the first place.

Compelling Evidence 3.0 requires proof of at least two earlier, undisputed transactions from the same customer, made between roughly four months and a year before the disputed one, matching on at least two of four data points: the account identifier, the shipping or billing address, the IP address, and the device used, with at least one of those two matches being the IP address or the device itself. A single prior purchase is not enough, and evidence assembled after the dispute already arrived cannot substitute for records kept as the transactions happened.

This is the direct, practical reason that the account and login records a directory keeps for identity checks are worth designing with chargebacks in mind from the start, not as an afterthought once a dispute arrives. A customer's device fingerprint and IP address at signup, kept for long enough and tied cleanly to their account, is the difference between being able to use this specific defense and not being able to use it at all, months later, when the one dispute that would have qualified shows up.

The practical split to hold in your head is this: fighting a chargeback through ordinary representment is a revenue lever, not a ratio lever. It gets the money back. Deflecting a dispute before it is filed, or qualifying for Compelling Evidence 3.0 on the narrow case where it applies, are the only ratio levers that exist. An operator who spends all their effort on winning fights and none on avoiding the filing in the first place will keep recovering money while the number that actually threatens the account keeps climbing.

What to actually do this month

Start by finding out who your real acquirer is, which is not always obvious if you process through a payment facilitator or an aggregator rather than a direct merchant account, and ask them in writing for your TC40 and TC15 counts against your settled transaction count for the past six months. Most operators have never seen this number, because it is not what a standard payment dashboard reports.

Calculate your own ratio the way Visa does, as a count against a count of settled card-not-present transactions, not as a dollar figure against a dollar figure. Do this for each of the last six months rather than the most recent one alone, and look at the direction it is moving rather than the single most recent number. A ratio is a trailing monthly measure, so a fix made this month will not show up in the number until one or two months later.

If your dispute volume justifies the ongoing cost, enroll in a pre-dispute alert service and put someone in charge of checking it daily rather than occasionally, since the window to act on an alert before it becomes a formal chargeback is short. Weigh the fee against what an entry on the ratio actually risks, not just against the value of the single disputed transaction.

Review whatever records your signup and payment flow already capture, and confirm that a device identifier, an IP address, and an address tied to each paying customer are being kept for at least a year, in a form your team can retrieve quickly if a reason-code 10.4 dispute arrives. Building this after the fact does not work; the qualifying prior transactions have to already exist in your records before the dispute does.

Finally, ask your processor directly, in writing, what internal ratio they apply to your account and what happens contractually if you cross it. Most acquirers run tighter than Visa's own published number as a buffer for their whole portfolio, and finding out what that number is before a bad month arrives is the difference between a planned conversation and a surprise reserve hold on revenue you were counting on.

Try the DEMO

Escort directory software, ready to go