Skip to main content
Category: Chargebacks and Disputes

Excessive Fraud Merchant

Also known as: EFM, Mastercard Excessive Fraud Merchant Program, EFM Program
Simply put

The Excessive Fraud Merchant (EFM) program is a Mastercard compliance scheme aimed at reducing fraud on e-commerce transactions. Merchants are identified under the program when their fraud levels rise above thresholds set by the network. It is intended to encourage merchants with severe fraud rates to bring those levels back down and create a more secure payment environment.

Formal definition

EFM is a Mastercard card-brand monitoring program focused on e-commerce (card-not-present) transactions. According to the evidence, a merchant may enter the program when its fraud chargeback ratio exceeds 0.50% (50 basis points) alongside a defined fraud chargeback count; practitioners should confirm current thresholds, counts, and program mechanics against Mastercard's published rules, which vary by region and change over time. EFM is distinct from and more severe in scope than related Mastercard monitoring programs such as the Merchant Fraud Monitoring Program (MFMP) and the Excessive Chargeback Program (ECP), the latter of which monitors dispute/chargeback data rather than fraud-specific ratios. The program is intended to reduce fraud and improve ecosystem security but does not by itself eliminate fraud; specific fines, remediation requirements, and exact qualification criteria are governed by Mastercard network rules referenced in the evidence.

Why it matters

For merchants operating in e-commerce, the Excessive Fraud Merchant (EFM) program represents a card-network compliance threshold that carries real financial and operational consequences. Because it targets card-not-present fraud specifically, it applies to the transaction environment where fraud pressure is typically highest and where the merchant, rather than the issuer, more often bears liability. Being identified under EFM signals to Mastercard that a merchant's fraud levels have risen above acceptable network thresholds, which can trigger remediation obligations and potential fines governed by Mastercard's rules.

EFM is intended to reduce fraud on e-commerce transactions and to create a more secure payment ecosystem, but it is important to understand what the program is and is not. It is a monitoring and enforcement mechanism, not a control that by itself eliminates fraud. Merchants that fall under its thresholds are being flagged to bring fraud levels back down, and the program is more severe in scope than related Mastercard programs such as the Merchant Fraud Monitoring Program (MFMP). Distinguishing EFM from the Excessive Chargeback Program (ECP) also matters, because ECP monitors dispute and chargeback data broadly rather than fraud-specific ratios; a merchant can face different programs for different reasons.

The practical stakes for compliance officers and risk teams are that thresholds, fraud chargeback counts, fines, and remediation requirements are set by Mastercard network rules that vary by region and change over time. Treating a specific threshold figure as permanent, or assuming that avoiding one program means avoiding all of them, can leave a merchant exposed. Confirming current program mechanics against Mastercard's published rules is essential before making enforcement or remediation decisions.

Who it's relevant to

Merchant Risk and Fraud Teams
Teams managing e-commerce fraud need to track their fraud chargeback ratio and count against Mastercard's current thresholds to understand whether they are approaching or have entered EFM. Because EFM is fraud-specific and more severe in scope than MFMP, these teams should monitor where their metrics stand relative to multiple programs and confirm current figures against Mastercard's published rules, which vary by region and change over time.
Compliance Officers
Compliance staff are responsible for interpreting Mastercard network rules that govern EFM qualification criteria, fines, and remediation requirements. They should distinguish EFM from related programs such as MFMP and the Excessive Chargeback Program (ECP), since ECP monitors dispute and chargeback data rather than fraud-specific ratios, and should avoid treating any single threshold figure as fixed.
Acquirers and Payment Processors
Acquirers and processors often surface network monitoring program status to their merchants and may be involved in remediation. Understanding that EFM applies specifically to card-not-present e-commerce fraud, and that its mechanics differ from chargeback-focused programs, helps them advise merchants accurately and confirm current program details against Mastercard's rules.
Merchant Leadership and Finance
Because EFM can carry fines and remediation obligations governed by Mastercard rules, leadership and finance stakeholders have an interest in understanding the financial and operational consequences of exceeding fraud thresholds, while recognizing that the program is a monitoring and enforcement mechanism intended to reduce fraud rather than a control that eliminates it.

Inside EFM

Excessive Fraud Merchant (EFM) Designation
A classification applied by a card brand's fraud monitoring program when a merchant exceeds defined fraud thresholds over a monitoring period. The specific thresholds, measurement methods, and program names vary by card brand and region and are governed by network rules that change over time; practitioners should confirm current criteria against the applicable brand's published program documentation.
Fraud Monitoring Thresholds
Metrics such as fraud volume and fraud-to-transaction ratios that a card network uses to identify merchants generating disproportionate fraud. Exact threshold values and calculation windows are set by each card brand and may differ by region and merchant category, so no fixed figures should be assumed.
Monitoring and Remediation Period
A defined timeframe during which an identified merchant is expected to reduce fraud below program thresholds, typically involving reporting obligations and remediation steps as specified by the card brand's program rules.
Fees, Assessments, and Potential Consequences
Financial and operational consequences that a card brand may apply to merchants remaining above thresholds, which can escalate over time. The nature and amount of any assessments are governed by network rules that vary by brand and region.
Acquirer and Processor Role
Acquirers and payment processors are generally responsible for notifying affected merchants, coordinating remediation, and interfacing with the card brand's program, since the merchant relationship and network compliance obligations flow through the acquirer.
Relationship to Fraud Types
EFM programs are commonly associated with card-not-present fraud in e-commerce contexts, though the underlying fraud may include account takeover, synthetic identity fraud, or other categories. The designation reflects fraud outcomes rather than a single fraud mechanism.

Common questions

Answers to the questions practitioners most commonly ask about EFM.

Is being flagged as an Excessive Fraud Merchant the same as being classified under an excessive chargeback program?
No. Excessive fraud and excessive chargeback classifications address related but distinct signals. An Excessive Fraud Merchant designation is generally tied to fraud-related metrics, such as reported fraudulent transaction counts or amounts relative to sales, while excessive chargeback classifications focus on chargeback volume or ratio, which can include disputes that are not fraud-related (for example, service or friendly/first-party disputes). A merchant may fall into one program, both, or neither. The specific thresholds, metric definitions, and program names are set by individual card brands and networks, vary by region, and change over time, so confirm the exact criteria against the applicable current network rules rather than assuming the two designations are interchangeable.
Does achieving PCI DSS compliance mean a merchant cannot be classified as an Excessive Fraud Merchant?
No. PCI DSS focuses on protecting account data and securing the cardholder data environment; it is a separate concern from a merchant's fraud performance as measured by card brand and network monitoring programs. A merchant can be fully validated against the applicable PCI DSS version and still exceed a network's fraud thresholds, because fraud outcomes depend on factors such as transaction acceptance decisions, use of authentication tools, and the merchant's exposure to card-not-present fraud. Compliance with PCI DSS may help reduce certain data-compromise risks, but it does not by itself govern or determine Excessive Fraud Merchant status.
How does a merchant find out it is being monitored or classified under an excessive fraud program?
Notification typically flows through the merchant's acquirer, which receives program communications from the card brands or networks. Merchants generally do not interact with the network monitoring programs directly. Because notification timing, format, and any remediation windows are defined by network rules and acquirer agreements, a merchant should establish clear communication channels with its acquirer and review its merchant agreement to understand how and when program status, metrics, and required actions will be communicated. Exact procedures vary by network and region and can change, so confirm current details with the acquirer.
What metrics should a merchant track internally to anticipate excessive fraud classification?
A merchant should monitor the same categories of signals the networks evaluate, which commonly relate to reported fraud counts or amounts measured against sales volume over a defined period. Internally, that means tracking fraud-related transactions, distinguishing card-not-present from card-present activity, and watching trends by channel, product, and time window. Because the precise metric definitions, measurement periods, and thresholds are set by each network and can differ by region and change over time, internal tracking should be calibrated to the applicable current program definitions confirmed through the acquirer rather than to assumed fixed numbers.
What controls can a merchant implement to help reduce the risk of excessive fraud classification?
Merchants can layer controls that address fraud at different points in the transaction. For card-not-present acceptance, these may include 3-D Secure to support authentication and, where applicable, liability considerations, along with fraud screening and velocity or anomaly checks. Card-present environments may benefit from EMV chip acceptance. These controls are intended to help reduce fraud exposure but involve trade-offs, including potential false positives that decline legitimate transactions and false negatives that miss fraud. No single control eliminates fraud, and liability treatment for authenticated transactions is governed by network and brand rules that vary by region and change over time.
What are the typical consequences if a merchant remains in an excessive fraud program without remediation?
Consequences are defined by the card brand and network rules and administered through the acquirer, and they may escalate the longer a merchant remains above threshold without effective remediation. Potential outcomes can include additional monitoring, required remediation plans, assessments or fees, and in more severe or prolonged cases, restrictions on acceptance. The specific stages, timelines, and financial impacts vary by network and region and are subject to change, so a merchant should confirm the applicable current program structure and remediation expectations with its acquirer.

Common misconceptions

EFM designation and its thresholds are the same across all card brands.
Fraud monitoring programs, their thresholds, measurement methods, and consequences are defined independently by each card brand and can vary by region. There is no single universal EFM standard, and program rules change over time, so criteria must be confirmed against the applicable brand's current documentation.
Achieving PCI DSS compliance prevents a merchant from being designated an EFM.
PCI DSS addresses the protection of cardholder data and sensitive authentication data, not fraud rates on authorized transactions. A merchant can be fully validated against PCI DSS and still exceed a card brand's fraud thresholds, because fraud monitoring programs are governed by separate network rules and measure different outcomes.
Deploying a single control such as 3-D Secure guarantees a merchant will exit or avoid EFM status.
3-D Secure is one authentication mechanism intended to help reduce certain card-not-present fraud and may shift liability under specific network rules, but it does not eliminate fraud and addresses only part of the risk. Reducing fraud below program thresholds generally requires layered controls, and outcomes depend on implementation and fraud patterns.

Best practices

Confirm the specific card brand fraud program criteria, thresholds, and monitoring windows against the current published network rules, since these vary by brand and region and change over time.
Coordinate early with your acquirer or processor upon notification, and establish clear reporting and remediation timelines aligned to the applicable program's monitoring period.
Deploy layered fraud controls appropriate to your channel, combining measures such as 3-D Secure for card-not-present flows with other detection and authentication tools, while monitoring for false-positive and false-negative trade-offs.
Analyze fraud by type, for example card-not-present fraud, account takeover, and synthetic identity fraud, so remediation targets the actual mechanisms rather than applying a single generic control.
Track fraud-to-transaction ratios continuously against the relevant thresholds so trends can be addressed before a formal designation, rather than only reacting after notification.
Maintain separation between PCI DSS data-protection efforts and fraud-rate remediation, recognizing that compliance with data security standards does not by itself resolve an EFM designation.