IXOPAY releases Payments Intelligence: Get Payments Insights here!
Blog

Mastercard GMAP: What Merchants Need to Know About the New Dispute and Fraud Monitoring Framework

August 19, 2026

Mastercard’s revised Global Merchant Audit Program (GMAP) is scheduled to take effect on April 1, 2027

This new monitoring framework will 1) assess fraud reports and non-fraud chargebacks together at both the merchant and acquirer level, 2) introduce four new monitoring categories with low-volume triggers, and 3) gradually tighten existing Excessive Chargeback Merchant (ECM) thresholds over time. For businesses using multiple payment service providers (PSPs), acquirers, or merchant identification numbers (MIDs), preparation should begin well before enforcement—the sooner the better. The program will fundamentally change how Mastercard assesses merchant performance, making unified fraud, dispute, and transaction visibility essential for maintaining healthy processing relationships. In this article, we’ll explain what the revised GMAP entails, what the new thresholds mean, and how merchants can start preparing.

Note: This guidance is based on industry summaries of Mastercard’s non-public bulletin (GLB 14127.1), as the official rulebook update has not yet been published. We will update this information when Mastercard formally incorporates these standards into its public documentation.

What is Mastercard’s Global Merchant Audit Program (GMAP)?

At its core, Mastercard’s GMAP is a new umbrella framework for monitoring merchant and acquirer fraud and dispute performance. It represents a significant shift from the current approach, which treats fraud and chargebacks as largely separate metrics.

Key changes scheduled for April 1, 2027, include the following:

  • Combining confirmed fraud reports with chargebacks filed for non-fraud reasons.

  • Evaluating performance at both the merchant level and across an acquirer’s portfolio.

  • Including fraud that was reported but never resulted in a chargeback.

  • Using Mastercard’s Fraud and Loss Database (FLD) as the source for reported fraud.

    • Mastercard describes the FLD as its repository and source of truth for fraud transactions. This means that fraud reported to Mastercard can contribute to a merchant’s or acquirer’s GMAP performance assessment, even when that fraud does not ultimately result in a chargeback.

A note on the GMAP name: Mastercard has used the GMAP name previously for a different program. The currently published February 2026 manual still identifies that earlier program as suspended. For purposes of understanding the 2027 changes, however, the important point is that Mastercard is introducing a new framework that brings fraud reporting and dispute performance together under a single monitoring approach.

How the GMAP Ratio is Calculated

The GMAP ratio is the core metric for the new HDM, EDM, HDA, and EDA categories. It is calculated as:

GMAP ratio = (Fraud reports + non-fraud chargebacks) ÷ Number of

sales from the previous month 

The calculation brings together three distinct data elements:

  1. Fraud records submitted to Mastercard’s FLD.

  2. Chargebacks filed for non-fraud reasons.

  3. The count of sales from the preceding month.

The key thing to remember is that the numerator does not simply include fraud reports plus all chargebacks. Only chargebacks raised for non-fraud reasons are added to the reported fraud records. This helps prevent the same fraudulent transaction from being counted twice.

A Simple Example

Suppose a merchant recorded 10,000 sales in the previous month. During the measurement period, Mastercard received 75 fraud reports through the FLD and the merchant had 25 chargebacks for non-fraud reasons.

The GMAP ratio would be:

(75 + 25) ÷ 10,000 = 1%

That 1% ratio is an important part of the GMAP assessment, but it is not the only requirement. Merchant categories also take into account minimum sales volumes and dollar-value thresholds. Merchants therefore need a complete view of their transaction, fraud, and dispute data to understand how they may be assessed under GMAP.

Naturally, this introduces a need for consolidated, provider-agnostic transaction data. IXOPAY Payments Analytics currently consolidates data across PSPs, acquirers, fraud tools and internal systems and supports analysis by provider, MID, issuer, bank identification number (BIN), geography and payment method.

GMAP Thresholds for Merchants and Acquirers

Merchants and acquirers will be monitored against specific thresholds for the new categories. A merchant must meet all applicable conditions for a category to be triggered. Mastercard is also expected to evaluate card-present and card-not-present acquirer activity separately. 

HDM and EDM categories can be triggered with as few as five cleared transactions in a month, provided the dollar and ratio thresholds are met. This means even smaller or newer merchants with a handful of problematic transactions in a slow month could fall into these categories—a volume level that would never have approached the 100-chargeback floor for ECM.

Existing ECM Thresholds

Merchants should also be aware of the phased reduction in the ECM ratio threshold.

Period

ECM ratio range

2027–2028

1.50%–2.99%

2029

1.30%–2.99%

2030

1.10%–2.99%

2031 onward

0.90%–2.99%

The 100-chargeback minimum is expected to remain in place, while High Excessive Chargeback Merchant (HECM) continues to begin at 3% or more. (These reductions will be introduced after the main April 2027 GMAP change.)

What Happens When a Merchant Exceeds a GMAP Threshold?

Exceeding a GMAP threshold triggers a formal audit process with escalating consequences. The process looks like this:

  1. Mastercard opens an audit. When a merchant exceeds an applicable GMAP threshold, Mastercard begins tracking its performance and counting consecutive months above the threshold.

  2. Assessments increase as non-compliance continues. Reported assessments can increase as the merchant remains above the applicable threshold rather than returning to compliance.

  3. Two consecutive HDM months can trigger issuer notification. After a merchant records two consecutive months in the HDM category, Mastercard may notify the merchant's issuers about its status.

  4. Two consecutive EDM months can create additional chargeback liability. If the merchant reaches the EDM level for two consecutive months, it may become liable for fraud-related chargebacks associated with transactions from the three months preceding identification and the following six months.

  5. The audit remains open until the merchant returns to compliance.

  6. An audit closes only after the merchant or acquirer remains below both applicable thresholds for three consecutive months.

It’s Time to Start Preparing

The April 2027 effective date provides merchants with a valuable window for preparation. IXOPAY Payments Intelligence can support GMAP readiness through a simple three-step model wherein data is unified, performance is monitored, and risks are addressed before becoming formal disputes. 


You can also assess your payments intelligence maturity or download the Payments Intelligence Checklist. The checklist already covers transaction visibility, chargeback prevention, monitoring, reporting and card-scheme monitoring.

The Future is Agentic.
Are You Ready?

As commerce shifts from clicks to agents, your infrastructure must be protocol-agnostic. IXOPAY acts as the neutral trust layer, orchestrating identity and value across the fragmenting landscape of AI agent protocols.