Compliance Alert / QSA Perspective
Sub-merchant "Refund + Chargeback" Hits 5%, 72-Hour Investigation Mandatory
Mastercard's New Rule Effective July 24, How Should PFs Prepare?
Effective Date: 2026-07-24
Recently, there has been widespread discussion surrounding "Scam Merchant Monitoring." Mastercard appears to have released document GLB 12772, revising the standards for "Potential Scam Merchant Monitoring." As this document was only distributed through member channels and not publicly disclosed, we can only analyze this issue through indirect sources. On the official website of Austreme, a Mastercard-approved MMSP (Merchant Monitoring Service Provider), we found information regarding Mastercard's new transaction risk regulations under GLB 12772. The effective date of this document is July 24, 2026, and the compliance obligations seem to fall primarily on Acquirers and PFs (Payment Facilitators). Even though specific details remain to be confirmed, we believe it is crucial to inform you in advance so you can prepare accordingly.
Fraud is Evolving from "Fraud" to "Scam"
"You've won! Just one step away!" or "Fill in your details for a free trial"—these types of one-page posts have long been a daily sight on social media, serving as entry points for many scams. According to statistics from the National Police Agency's "165 Anti-Fraud Dashboard," tens of thousands of scam cases are reported monthly, with financial losses reaching billions. More importantly, most of these cases are not traditional unauthorized credit card fraud, but rather situations where consumers "voluntarily" send their money. In a recent interview with Business Next, Visa's Head of Risk for Asia Pacific pointed out that the global fraud landscape is shifting from "Unauthorized Fraud" to "Authorized Scam." Victims are misled into manually authorizing payments, making it much harder for banks and regulatory bodies to define liability.
The funds from authorized scams ultimately flow into "seemingly normal" merchant accounts. These types of merchants and transactions trigger very few unauthorized fraud reports but generate abnormal refund ratios, chargebacks, and unusual merchant behavior patterns. Consequently, the defense line of card networks has shifted. The focus has moved from tracking stolen cards to monitoring the merchants receiving the funds. Mastercard's GLB 12772 follows exactly this logic, utilizing the "Refund + Chargeback Combined Ratio" to filter out Scam merchants, with Acquirers and PFs being the executors of this mandate.
Key Requirements: 5%, 500 Transactions, 30 Days
Based on our research, the core triggering condition is: if a merchant's combined "Refund + Chargeback" ratio exceeds 5% of their transaction volume within a rolling 30-day window (calculated backward from the current date, with a minimum of 500 transactions—meaning if just 25 out of 500 transactions have issues, it triggers), the Acquirer or PF must initiate an investigation within 72 hours. Once confirmed as a scam, Mastercard and Maestro acceptance must reportedly be blocked immediately, with no warning letters or grace periods. Refunds are also included in the numerator (which is different from existing ECP programs that only look at chargebacks), and chargebacks are counted as soon as they are filed; even if a dispute is later won, it is unlikely to be deducted. For actual calculation details, please refer to the original document and the instructions provided by your Acquirer.
Figure 1 | GLB 12772 72-Hour Investigation Workflow (Additional triggers include authorization rate drop, GRIP letters, MMSP alerts)
The 5% threshold is not the only trigger. The same document reportedly lists other conditions: a sudden drop in authorization success rate (at least 25 transactions within 72 hours, with the approval rate dropping by more than 50 percentage points or falling below 30%), receipt of GRIP investigation letters, and MMSP scam alerts. Additionally, Acquirers must perform daily checks of newly added scam merchants on the FLD (Fraud and Loss Database). Since card networks like Mastercard provide services like the Merchant Scam & Risk Indicator (MSRI) to Issuers for risk reference during authorization, or because Issuers' own risk systems have already flagged a merchant as high-risk due to cardholder scam reports, the authorization success rate will decrease. Therefore, once an Acquirer or PF notices a significant drop in a merchant's authorization approval rate, it may indicate that the merchant has already been listed as a risk in MSRI; hence, a sudden drop in authorization rate is also a critical trigger.
A Reminder for Payment Facilitators (PFs)
Based on current information from various sources, the obligated entities under GLB 12772 are not the merchants themselves, but rather Acquirers and Payment Facilitators. If this understanding is correct, whenever any sub-merchant under your umbrella hits the trigger conditions, the 72-hour investigation clock is placed on your wall. If an investigation is missed or a block is delayed, Mastercard will likely hold you accountable. In other words, your merchant's risk ratio is effectively your compliance risk. Here are several types of merchants that are prone to triggering an investigation:
|
■ New Merchants (< 6 Months) Merchants with less than six months of processing history are subject to the strictest reviews; a website scan must be completed prior to onboarding (reportedly effective Jan 2026). |
■ High-Refund Industries Digital goods, online courses, subscriptions, free-trial-to-paid conversions—refunds are routine, easily approaching the 5% threshold. |
|
■ Cross-Border E-commerce / Purchasing Agents Naturally prone to higher dispute and fraud reports, as consumers are more likely to "not recognize" the billing descriptor. |
■ Inconsistent Billing Descriptors When the billing descriptor does not match the website/brand, it is the primary reason consumers directly initiate chargebacks. |
Figure 2 | Four Types of Sub-merchants on Your Platform Most Likely to Trigger Investigations
Recommendations to Start Preparing
Based on the regulations we've seen from various sources, we recommend that your primary execution focus should begin with monitoring the legitimacy of transactions, followed by accurate assessment, ensuring sub-merchant transactions remain under control and avoid crossing the red line. Below are the recommended preparatory actions:
- Provide a "Refund + Chargeback" Query Feature or API for Sub-merchants (Crucial)
Most merchants view refunds and chargebacks separately and are entirely unaware of the "combined 5%" threshold. Allowing merchants to check their rolling 30-day combined ratio in real-time (and how close they are to 5%) is the lowest-cost and most direct way to shift risk forward. If merchants see it themselves, they won't wait for you to block them. - Establish Platform-Side 30-Day Rolling Monitoring and Internal Warning Thresholds
Calculate the combined ratio for all merchants using a 30-day rolling window, and set an internal warning threshold before 5% (e.g., 3.5%). Triggering this warning allows for proactive guidance before the 72-hour clock starts. - Develop a 72-Hour Investigation SOP and Evidence Retrieval Checklist
Within the time limit, you must complete: retrieval of transaction records, refund behavior, chargeback documents, website content, billing descriptors, and merchant communication logs, retaining time-stamped evidence of the investigation. Prepare the workflows and forms in advance to ensure deadlines are met. - Review New Merchant Onboarding Workflows (Reportedly Effective Jan 2026)
According to interpretations, a website scan must be completed prior to a new merchant's first transaction, executed or co-executed by a Mastercard-approved MMSP. We recommend verifying whether your partnership with an MMSP and your scanning coverage are adequate. - Incorporate Abnormal Authorization Rates into Alerts
A sudden collapse in a single merchant's authorization approval rate within 72 hours is often the first signal of card testing or public scam reports. This is also one of the official trigger conditions of the new rule. - Update Sub-merchant Agreement Terms
Incorporate clauses for mandatory investigation cooperation, data provision deadlines, and immediate termination, ensuring your 72-hour actions have a contractual basis. - Request the Original GLB 12772 Document from Your Acquirer
Publicly available information is based on secondary sources. For implementation details, such as how partial refunds are counted or the exact definition of the 500 transactions, please rely on the original document and the implementation guidelines from your Acquirer.
Source of Information: Mastercard Document GLB 12772 (Member-only, targeted at Acquirers and Payment Facilitators); parameters cited from Mastercard-approved MMSP Austreme's public notice (austreme.com) and consensus interpretations by multiple payment risk management firms. Background on fraud trends cited from Business Next's interview report with Visa's Head of Risk for Asia Pacific (bnext.com.tw). This article serves as a compliance alert; specific clauses are subject to Mastercard's original document.
