Skip to main content
Category: Chargebacks and Disputes

Excessive Chargeback Program

Also known as: ECP, Excessive Chargeback Merchant Program, ECM, Mastercard Excessive Chargeback Program
Simply put

The Excessive Chargeback Program is a Mastercard monitoring program that watches how many chargebacks (disputed transactions) a merchant receives. If a merchant's chargeback levels rise too high, Mastercard may flag that merchant and apply consequences such as assessments. The program is intended to reduce fraud and disputes and to encourage merchants to keep their chargeback rates under control.

Formal definition

The Excessive Chargeback Program (also referred to as the Excessive Chargeback Merchant program, or ECM) is a dispute-monitoring and compliance program operated by Mastercard that assesses chargeback performance at the Merchant Identification Number (MID) level to identify merchants whose dispute activity exceeds defined thresholds. Merchants that breach program thresholds may be placed into a monitoring status (for example, ECM or High Excessive Chargeback Merchant status) and become subject to assessment amounts and remediation expectations. The specific thresholds, tiers, assessment schedules, and enforcement actions are established and periodically revised by Mastercard's network rules and may vary by region; practitioners should confirm current criteria against the applicable Mastercard program documentation. Note that this program is defined by card brand network rules and is distinct from PCI DSS and related PCI standards, which govern data security controls rather than dispute performance.

Why it matters

Chargeback performance is one of the ways a card brand evaluates the risk a merchant poses to the payment system, and Mastercard's Excessive Chargeback Program is a formal mechanism for identifying merchants whose dispute activity exceeds defined thresholds. Because the program operates at the Merchant Identification Number (MID) level, a merchant that breaches thresholds can be placed into a monitoring status such as ECM or High Excessive Chargeback Merchant (HECM), which can carry assessment amounts and remediation expectations. For merchants, acquirers, and processors, this makes chargeback management not merely a customer-service concern but a compliance and financial one.

The program is intended to reduce fraud and disputes and to encourage merchants to keep chargeback rates under control, but it is important to understand what it is and is not. The ECP is defined by Mastercard network rules and addresses dispute performance; it is distinct from PCI DSS and related PCI standards, which govern data security controls rather than chargeback levels. A merchant can be fully PCI DSS compliant and still breach ECP thresholds, and vice versa, because the two address different risks.

Because thresholds, tiers, assessment schedules, and enforcement actions are established and periodically revised by Mastercard and may vary by region, practitioners should not rely on a fixed figure or a remembered threshold. Exact criteria and any associated assessment amounts depend on the applicable Mastercard program documentation in effect for the relevant period and region, and should be confirmed there rather than assumed.

Who it's relevant to

Merchants and merchant risk teams
Merchants are evaluated at the MID level and bear the direct consequences of breaching program thresholds, including monitoring status and potential assessments. Risk teams should track dispute activity against current Mastercard criteria, understand which tier a MID may be approaching, and plan remediation before thresholds are breached. Note that reducing chargebacks may involve trade-offs, and that the ECP addresses dispute performance rather than data security obligations under PCI DSS.
Acquirers and payment processors
Acquirers and processors manage the MIDs through which merchants transact and are typically the parties that receive program notifications and pass assessments and remediation requirements to merchants. They need to monitor their merchant portfolios against current Mastercard thresholds, support merchants in reducing disputes, and account for regional variation in program criteria.
Fraud analysts and dispute management teams
The ECP is intended to reduce fraud and disputes, so analysts responsible for chargeback and fraud outcomes are central to keeping a merchant below program thresholds. They should understand that dispute activity monitored under this program can stem from multiple sources and that detection and prevention controls involve trade-offs; the program measures outcomes rather than prescribing specific controls.
Compliance officers
Because the ECP is a card brand network rules program, compliance officers should treat it separately from PCI DSS and related PCI standards, which govern data security rather than dispute performance. They should confirm current program thresholds, tiers, and assessment schedules against the applicable Mastercard documentation for the relevant region and period, rather than relying on fixed figures.

Inside ECP

Chargeback Threshold Monitoring
A card brand program construct that identifies merchants whose chargeback counts or ratios exceed defined thresholds over a monitoring period. Thresholds, ratio calculations (for example, chargeback-to-transaction counts), and monitoring windows are set by the individual card network and may change and vary by region; practitioners should confirm current values against the governing brand's published rules.
Program Tiers or Stages
Many networks structure their excessive chargeback frameworks in escalating stages, where continued or worsening performance moves a merchant into higher-severity tiers that carry additional obligations. The specific naming, criteria, and progression are defined by each card brand and are not standardized across networks.
Remediation and Action Plans
Requirements that an identified merchant submit or execute a plan to reduce chargebacks, which may include process changes, fraud controls, or reporting. The exact expectations are governed by the applicable card brand rules rather than by PCI DSS or any PCI Security Standards Council standard.
Fees, Assessments, and Consequences
Financial and operational consequences that may apply to merchants in the program, potentially including per-chargeback or monitoring fees and, in escalated cases, restrictions on the merchant's ability to accept the brand's cards. Amounts and conditions are determined by network rules and by the acquirer relationship, and vary by region and over time.
Acquirer and Merchant Responsibilities
The acquirer typically bears responsibility for the merchants in its portfolio and often coordinates notification, remediation tracking, and communication with the card brand. Merchant risk teams work with the acquirer to interpret obligations and demonstrate improvement.
Scope Boundary
An excessive chargeback program addresses chargeback and dispute performance under card brand and network rules. It is distinct from PCI DSS and related PCI standards (such as PA-DSS, the PCI Software Security Framework, PCI PIN, PCI P2PE, or PCI 3DS), which govern data protection and security validation rather than dispute ratios.

Common questions

Answers to the questions practitioners most commonly ask about ECP.

Is the Excessive Chargeback Program the same across all card brands?
No. Excessive chargeback monitoring is governed by individual card brand and network rules, which use different program names, thresholds, measurement periods, and remediation stages. What one network labels its excessive chargeback program differs from another's equivalent program in both criteria and consequences. Because these rules change over time and can vary by region, you should confirm the specific program terms, thresholds, and definitions against the current rules published by the relevant card brand rather than assuming they are uniform or fixed.
Does being placed in an Excessive Chargeback Program mean the merchant has committed fraud?
Not necessarily. Program placement is driven by chargeback ratios and volumes crossing brand-defined thresholds, which can result from a range of causes, including friendly or first-party fraud, disputes over product or service quality, unclear billing descriptors, processing errors, or genuine card-not-present fraud. The program is a monitoring and remediation mechanism tied to chargeback metrics, not a determination that the merchant itself perpetrated fraud. Distinguishing the underlying dispute causes is a separate analytical step that the merchant and acquirer typically undertake as part of remediation.
How does a merchant find out which chargeback program thresholds apply to them?
Merchants generally learn applicable thresholds and program status through their acquirer, which receives program notifications from the card brands and is responsible for communicating them. Because the specific ratios, counts, and measurement windows are defined in each network's current rules and can differ by region and merchant category, the authoritative source is the relevant card brand's published program documentation as relayed by the acquirer. Confirm current figures directly rather than relying on prior values, since these criteria can be revised.
What steps can a merchant take to reduce chargeback ratios while in the program?
Common measures are intended to address the specific dispute causes a merchant is experiencing and may include clarifying billing descriptors, improving refund and cancellation handling, tightening fraud screening for card-not-present transactions, and using tools such as 3-D Secure where appropriate. Effectiveness varies, and detection-oriented controls involve false-positive and false-negative trade-offs that can affect legitimate sales. The appropriate mix depends on the merchant's actual dispute drivers, so root-cause analysis of chargeback reason data typically precedes selecting remediation actions.
How are chargeback ratios calculated for program purposes?
Ratios are defined by each card brand's program rules and generally relate chargeback counts or amounts to transaction counts or amounts over a defined period, but the exact numerator, denominator, and measurement window differ between networks and can change over time. Some programs also apply absolute volume thresholds in addition to ratio thresholds. Because the precise calculation method is set by the applicable network rules, merchants and acquirers should verify the current formula and period against the relevant brand's published documentation rather than assuming a single standard method.
What role does the acquirer play when a merchant is in an Excessive Chargeback Program?
The acquirer typically serves as the intermediary that receives program notifications from the card brands, communicates status and thresholds to the merchant, and coordinates required remediation and reporting. Acquirers may also impose their own risk controls, such as reserves or enhanced monitoring, consistent with the network rules and their merchant agreement. Because program stages and any associated fees or requirements are defined by card brand rules that vary by region and change over time, the specific obligations should be confirmed with the acquirer against current published rules.

Common misconceptions

The Excessive Chargeback Program is part of PCI DSS compliance.
It is not. Excessive chargeback programs are defined and enforced by individual card brands and networks under their operating rules. PCI DSS and other PCI Security Standards Council standards govern the protection of cardholder data and sensitive authentication data, not chargeback ratios or dispute performance.
There is one universal chargeback threshold that applies to every merchant on every network.
Thresholds, ratio calculations, monitoring periods, and program stages are set separately by each card brand and may differ by region and change over time. Practitioners should confirm current criteria against the specific governing brand's published rules rather than assuming a fixed number.
Chargebacks in the program are always caused by criminal or third-party fraud.
Chargebacks can arise from multiple sources, including card-not-present fraud, account takeover, and friendly or first-party fraud where a legitimate cardholder disputes a valid purchase. Reducing program exposure requires distinguishing these types, since each responds to different controls and evidence.

Best practices

Confirm the current thresholds, ratio definitions, monitoring windows, and program stages directly from the governing card brand's published operating rules, since these vary by network and region and change over time.
Work closely with your acquirer to receive timely notification of program status, clarify obligations, and coordinate any required remediation or action plans.
Analyze chargebacks by category (for example, card-not-present fraud, account takeover, and friendly or first-party fraud) so that remediation targets the actual root causes rather than applying a single control.
Layer fraud-mitigation and authentication controls appropriate to your channels, recognizing that measures such as 3-D Secure or strong customer authentication address specific risks, may shift liability under network rules, and involve false-positive trade-offs rather than eliminating disputes.
Maintain clear transaction records and compelling evidence to contest illegitimate disputes, particularly for friendly or first-party fraud, following the representment processes defined by the applicable network.
Track chargeback ratios continuously against the relevant thresholds and document remediation actions, so you can demonstrate improvement and reduce the risk of escalation into higher program tiers.