Most creator economy platforms think about compliance in terms of their direct processor — Stripe, PayPal, whoever handles their payouts. That is the relationship they signed, the terms they read, the account they log into. But sitting behind that processor is a card network, and the card network runs its own monitoring program that most platforms never think about until it produces a bill. For Visa, that program is VAMP.

This article explains what the Visa Acquirer Monitoring Program is, how its thresholds work, and why a platform can inherit exposure from it without ever interacting with Visa directly.

What VAMP is

VAMP, the Visa Acquirer Monitoring Program, is Visa's framework for monitoring transaction activity at the acquirer level. It consolidated several earlier Visa monitoring programs into a single structure and tracks metrics such as fraud rates and dispute ratios across an acquirer's portfolio.

The key words there are acquirer level. VAMP does not primarily monitor individual merchants in isolation. It monitors the acquiring bank, and the acquiring bank's performance is the aggregate of all the merchants it serves — including every platform in its book, and by extension every creator those platforms pay.

How the thresholds work

Visa defines thresholds for the metrics it tracks. When an acquirer's numbers cross those lines, the acquirer moves into a monitoring state that carries fines and remediation requirements. The specific figures are set by Visa and revised over time, which is one reason platforms should treat the current published thresholds as the reference rather than any number they memorized a year ago.

The mechanism that matters for platforms is what happens next. Visa fines the acquirer. The acquirer, facing a cost driven by specific merchants in its portfolio, passes that cost down to the merchants responsible — and applies pressure to clean up or exit the relationship. A platform that is a meaningful contributor to its acquirer's fraud or dispute numbers becomes the acquirer's problem, and the acquirer has every incentive to make it the platform's problem in turn.

Why this is different from a prohibited business list

A prohibited business list is about what is being sold. It is categorical: piracy, counterfeit, certain adult content, and so on. VAMP is about patterns — the rate at which a merchant generates fraud and disputes, regardless of category.

This distinction matters because a platform can be scrupulous about prohibited categories and still drift toward VAMP thresholds. Creators who attract chargebacks, who operate in dispute-prone niches, or who are fronts for activity that buyers later contest all push the numbers up. The activity may not be a clean prohibited-business violation, but it still shows up in the fraud and dispute ratios that VAMP watches.

Why the exposure is often invisible

The hardest feature of acquirer-level monitoring is that it is a lagging, aggregated signal. By the time a platform's contribution to its acquirer's numbers is large enough to matter, the transactions have already happened, the disputes have already been filed, and the creators responsible have already been paid.

There is no single dramatic event that announces the problem. It accumulates. A cluster of problem creators raises the platform's dispute ratio gradually, and the first clear signal often arrives as a message from the acquirer rather than something the platform detected itself. This is the opposite of catching a discrete policy violation; it is watching a slow-moving aggregate that only becomes legible once it is already a problem.

What platforms can actually do

Because VAMP is driven by the aggregate behavior of the creators a platform pays, the durable lever is upstream: reducing the share of risky creators before they generate the disputes and fraud that feed the ratios. That means understanding, before payout, which creators are likely to be dispute magnets or fronts for contested activity — not just which ones are selling something in a prohibited category.

The two problems are related but distinct. Prohibited-business screening asks whether a creator's activity is categorically off-limits. VAMP-oriented thinking asks whether a creator's activity is likely to generate the fraud and dispute patterns that accumulate into acquirer-level exposure. A platform serious about protecting its processor relationships needs a view of both.

This article is provided for general educational purposes and is not legal or compliance advice. It is not endorsed by or affiliated with Visa. Consult Visa's official program documentation and qualified counsel for definitive requirements and current thresholds. Tumban provides advisory risk guidance and does not guarantee compliance outcomes.

Processor Policy

6 min read

Visa VAMP in 2026: Thresholds, Enforcement, and What Platforms Inherit From Their Acquirer

VAMP monitors fraud and disputes at the acquirer level, and a platform's creators roll up into that number. Here is how the program works and why the exposure is often invisible until a threshold is already breached.

Mahesh Premachandran

Founder, Tumban

Most creator economy platforms think about compliance in terms of their direct processor — Stripe, PayPal, whoever handles their payouts. That is the relationship they signed, the terms they read, the account they log into. But sitting behind that processor is a card network, and the card network runs its own monitoring program that most platforms never think about until it produces a bill. For Visa, that program is VAMP.

This article explains what the Visa Acquirer Monitoring Program is, how its thresholds work, and why a platform can inherit exposure from it without ever interacting with Visa directly.

What VAMP is

VAMP, the Visa Acquirer Monitoring Program, is Visa's framework for monitoring transaction activity at the acquirer level. It consolidated several earlier Visa monitoring programs into a single structure and tracks metrics such as fraud rates and dispute ratios across an acquirer's portfolio.

The key words there are acquirer level. VAMP does not primarily monitor individual merchants in isolation. It monitors the acquiring bank, and the acquiring bank's performance is the aggregate of all the merchants it serves — including every platform in its book, and by extension every creator those platforms pay.

How the thresholds work

Visa defines thresholds for the metrics it tracks. When an acquirer's numbers cross those lines, the acquirer moves into a monitoring state that carries fines and remediation requirements. The specific figures are set by Visa and revised over time, which is one reason platforms should treat the current published thresholds as the reference rather than any number they memorized a year ago.

The mechanism that matters for platforms is what happens next. Visa fines the acquirer. The acquirer, facing a cost driven by specific merchants in its portfolio, passes that cost down to the merchants responsible — and applies pressure to clean up or exit the relationship. A platform that is a meaningful contributor to its acquirer's fraud or dispute numbers becomes the acquirer's problem, and the acquirer has every incentive to make it the platform's problem in turn.

Why this is different from a prohibited business list

A prohibited business list is about what is being sold. It is categorical: piracy, counterfeit, certain adult content, and so on. VAMP is about patterns — the rate at which a merchant generates fraud and disputes, regardless of category.

This distinction matters because a platform can be scrupulous about prohibited categories and still drift toward VAMP thresholds. Creators who attract chargebacks, who operate in dispute-prone niches, or who are fronts for activity that buyers later contest all push the numbers up. The activity may not be a clean prohibited-business violation, but it still shows up in the fraud and dispute ratios that VAMP watches.

Why the exposure is often invisible

The hardest feature of acquirer-level monitoring is that it is a lagging, aggregated signal. By the time a platform's contribution to its acquirer's numbers is large enough to matter, the transactions have already happened, the disputes have already been filed, and the creators responsible have already been paid.

There is no single dramatic event that announces the problem. It accumulates. A cluster of problem creators raises the platform's dispute ratio gradually, and the first clear signal often arrives as a message from the acquirer rather than something the platform detected itself. This is the opposite of catching a discrete policy violation; it is watching a slow-moving aggregate that only becomes legible once it is already a problem.

What platforms can actually do

Because VAMP is driven by the aggregate behavior of the creators a platform pays, the durable lever is upstream: reducing the share of risky creators before they generate the disputes and fraud that feed the ratios. That means understanding, before payout, which creators are likely to be dispute magnets or fronts for contested activity — not just which ones are selling something in a prohibited category.

The two problems are related but distinct. Prohibited-business screening asks whether a creator's activity is categorically off-limits. VAMP-oriented thinking asks whether a creator's activity is likely to generate the fraud and dispute patterns that accumulate into acquirer-level exposure. A platform serious about protecting its processor relationships needs a view of both.

This article is provided for general educational purposes and is not legal or compliance advice. It is not endorsed by or affiliated with Visa. Consult Visa's official program documentation and qualified counsel for definitive requirements and current thresholds. Tumban provides advisory risk guidance and does not guarantee compliance outcomes.