Recommended Articles

Share This Post

The way payment networks measure merchant risk is changing.

From April 1, 2027, Mastercard's revised Global Merchant Audit Program (GMAP) is expected to bring fraud and dispute monitoring under a broader framework. The changes introduce new merchant and acquirer categories, lower the transaction volume at which some merchants can be identified, and progressively tighten existing chargeback thresholds.

For merchants, this means fraud, disputes, transaction performance and payment partners need to be considered together. Understanding how these areas interact will become increasingly important as payment networks move towards more connected risk monitoring.

This is where payment orchestration can play a role.

From separate metrics to a broader view of risk

Mastercard's existing monitoring structure includes separate programs for fraud and chargebacks. GMAP brings several categories together and introduces new ones designed to assess combined fraud and dispute activity at both the merchant and acquirer levels.

The framework incorporates existing categories such as Excessive Fraud Merchant (EFM), Excessive Chargeback Merchant (ECM) and High Excessive Chargeback Merchant (HECM), while introducing:

High Dispute Merchant (HDM) Excessive Dispute Merchant (EDM) High Dispute Acquirer (HDA) Excessive Dispute Acquirer (EDA)

The important change is that fraud and non-fraud disputes can contribute to the same merchant-level assessment.

Fraud reported through Mastercard's Fraud & Loss Database (FLD), including fraud that does not result in a chargeback, also becomes part of the picture for the new dispute categories.

For merchants, this means that looking at chargebacks alone may no longer provide a complete view of payment risk.

Why smaller volumes can matter more

One of the most significant changes is the introduction of HDM and EDM.

Unlike the existing ECM framework, which has historically required a much higher volume of chargebacks, these new categories can apply to merchants with as few as five cleared transactions per month, provided they also meet the relevant amount and ratio thresholds.

CategoryMinimum activityCombined fraud + dispute amountRatio
High Dispute Merchant (HDM)5+ cleared transactions$5,000+5%+
Excessive Dispute Merchant (EDM)5+ cleared transactions$10,000+50%+

This matters particularly for businesses with lower transaction volumes, new payment operations, or individual products and markets where a small number of disputes can significantly affect the overall ratio. A handful of problematic transactions can have a very different impact when the denominator is small.

For merchants, that makes continuous monitoring more important than waiting for disputes to accumulate.

The cost of staying above the threshold

GMAP also introduces escalating financial assessments for merchants that remain above certain thresholds.

For EDM, reported assessments start at $5,000 per month, increasing as non-compliance continues and reaching up to $300,000 per month for sustained cases.

The financial impact is only part of the equation.

After a merchant remains above the EDM threshold for two consecutive months, Mastercard's framework can also introduce changes to fraud-related chargeback liability. Industry summaries report a three-month retrospective and six-month prospective period in which fraud-related disputes can be subject to different liability treatment.

The practical takeaway is simple: risk needs to be managed before a monitoring program becomes a financial problem.

How GMAP changes the conversation for acquirers

GMAP introduces High Dispute Acquirer (HDA) and Excessive Dispute Acquirer (EDA) categories, with reported combined fraud-and-dispute thresholds of 0.5% and 0.7%, respectively, alongside minimum portfolio volumes.

This creates a direct connection between merchant and acquirer risk. An acquirer is responsible for the performance of its merchant portfolio. If that portfolio consistently generates excessive fraud and dispute activity, the consequences can extend beyond individual merchants.

For merchants, this makes the relationship with an acquirer part of the wider risk strategy. An acquirer facing increasing pressure to control portfolio-level risk may respond with stricter underwriting, closer monitoring or decisions to reduce exposure to certain merchants or transaction profiles.

This is one reason why relying on a single payment provider can become increasingly restrictive as network monitoring evolves.

What happens with existing chargeback thresholds

GMAP also progressively tightens the existing Excessive Chargeback Merchant (ECM) framework.

The reported ECM ratio remains at 150–299 basis points in 2027 and 2028, then decreases to 130 basis points in 2029, 110 basis points in 2030 and 90 basis points in 2031.

Merchants that currently operate comfortably within existing chargeback thresholds may therefore need to reassess their exposure over the coming years.

The important point is the direction of travel: payment networks are placing greater emphasis on early detection, continuous monitoring and proactive risk management.

What GMAP means for merchants

For merchants, one of the biggest challenges will be connecting information that may currently sit across different parts of the payment operation.

Fraud may be monitored through one tool, chargebacks managed elsewhere, transaction performance analysed through an acquirer dashboard, and different PSPs providing separate reports.

Each system can provide useful information. The challenge is seeing how the pieces fit together.

There are several practical priorities:

  1. Bring fraud and dispute data together

    If both contribute to a combined assessment, merchants need a consolidated view of their exposure across fraud and disputes.

  2. Monitor performance at the right level

    GMAP focuses more on individual merchant and submerchant activity in relevant setups. Businesses using payment facilitators or complex merchant structures should understand how transactions are identified and reported.

  3. Look beyond your current provider

    Your acquirer is part of your risk environment. Understanding how different acquiring partners perform and where transaction volume is concentrated can help merchants make more informed infrastructure decisions.

  4. Act before thresholds become a problem

    A monthly report showing that a merchant has already crossed a threshold is useful. Identifying deteriorating performance before that happens is more valuable.

This is where real-time visibility, risk controls and intelligent payment routing become relevant.

Where payment orchestration fits in

Payment orchestration does not replace a merchant's responsibility for fraud prevention or compliance, but it provides a technology layer that can make a complex payment ecosystem easier to manage.

Celeris is an acquirer-agnostic payment orchestration platform that connects merchants with multiple PSPs, acquirers and payment providers through a unified infrastructure. Its capabilities include transaction routing, cascading and retries, fraud and risk management, 3DS, chargeback management, and consolidated reporting.

This is particularly relevant when merchants need to understand payment performance and risk across multiple providers.

One view across multiple payment partners

Working with several PSPs or acquirers can quickly fragment payment data.

Celeris brings transaction and operational data into a centralised environment, supporting visibility across the payment setup and automated reconciliation.

This can help merchants identify changes in transaction performance, spot emerging patterns, and understand how different providers contribute to the overall operation.

More control over payment routing

A multi-acquirer setup is most useful when merchants can control how transactions move through it.

Celeris provides intelligent routing, cascading and retry capabilities, allowing businesses to configure payment flows based on criteria such as provider performance, transaction type, location and currency.

This gives merchants more flexibility when a particular provider or route starts performing differently.

Risk management within the payment flow

Celeris also provides configurable risk management capabilities, including risk rules, fraud controls and 3DS, alongside integrations with fraud and chargeback services.

The objective is to give merchants more control over transactions before they progress through the payment flow, rather than relying solely on chargeback management after the fact.

Turning payment data into action

GMAP reinforces the importance of understanding payment performance across the ecosystem rather than looking at individual metrics in isolation.

A centralised orchestration layer can connect transaction performance, routing decisions, fraud controls, chargebacks, and provider performance, helping merchants spot changes and act more quickly.

GMAP is a sign of where payments are going

Visa's VAMP has already moved towards combining fraud and dispute activity within a broader monitoring framework. Mastercard's approach follows a similar direction, while introducing its own categories, thresholds and mechanisms.

For merchants, the broader lesson is that payment risk is becoming increasingly connected.

Fraud prevention affects disputes.

Disputes affect acquirer relationships.

Acquirer performance affects payment continuity.

Payment routing affects transaction outcomes.

Payment infrastructure is therefore becoming an increasingly important part of risk management.

Preparing for GMAP

Merchants should not wait until April 2027 to start preparing.

A practical starting point is to:

  • Understand your current exposure: Review fraud, disputes and chargeback ratios across Mastercard transaction flows.
  • Connect your data: Bring fraud, dispute and transaction information into a consolidated view.
  • Review your payment partners: Understand provider performance and where transaction volume is concentrated.
  • Check your merchant structure: Make sure you understand how MIDs and submerchant IDs are used across your payment setup.
  • Strengthen prevention: Review fraud controls, 3DS strategies and chargeback-prevention processes.
  • Monitor continuously: Identify changes before they become compliance or financial issues.
  • Build flexibility into your infrastructure: Make sure your setup gives you enough control to adapt providers, routing and risk strategies as requirements evolve.

Building a more resilient payment infrastructure with Celeris

GMAP reflects a broader shift towards managing payment risk across a connected ecosystem.

For merchants, that means having the data, controls and flexibility to understand what is happening across payment flows — and act before a problem escalates.

Celeris provides an orchestration layer that connects multiple payment providers, manages transaction flows, applies risk controls and brings payment data together in one platform.

As card networks continue to evolve their monitoring frameworks, greater visibility and control can help merchants keep their payment infrastructure ready for what comes next.

The rules may continue to change. Your payment infrastructure should be ready to adapt.

Santiago Angel

Frequently Asked Questions

Let's Connect

Just a few quick details. Our team will reach out to explore how our platform fits your payment stack and objectives.

    Talk with one of our payment experts

    Ready to elevate your business to new heights? Schedule a call with our experts to discuss your unique needs and uncover tailored solutions. Don’t let questions linger – seize the opportunity to pave your path to success!

    Winner !

    Best use of data analytics, MPE 2025

    Best Payments Orchestration Solution, MPE 2024

    data_analytics

    Related Resource

    Build Your Business With Celeris