Enumeration counts against your VAMP ratio the moment it happens. No chargeback required.
Although your chargeback and dispute numbers might look fine at first glance, that's not the same as actually complying with Visa's Acquirer Monitoring Program (VAMP) requirements. VAMP combines fraud reports and disputes into a single ratio, and enumeration counts against that ratio the moment it happens, on any merchant in your portfolio, whether or not a chargeback is ever filed. Reducing your risk of violations depends on catching enumeration and identifying problem merchants as early as possible, with a real-time card testing solution.
What VAMP is, and why enumeration counts against it
VAMP measures TC40 fraud reports and TC15 disputes against total settled card-not-present sales, calculated at the merchant descriptor level, and then rolls them up into the aggregate exposure for which Visa holds you accountable as the acquirer. Before VAMP, fraud and disputes were tracked separately, and one of your merchants with a clean dispute record could offset a weaker fraud picture. Under VAMP, they can't: the two get added together into one number.
The merchant "Excessive" threshold sits at 1.5% in most regions, but the bar Visa holds you to as their acquirer is noticeably tighter: 0.5% Above Standard, 0.7% Excessive. The specific number matters less than the fact that fraud and disputes now share it equally. Enumeration falls on the fraud side of that combined ratio, and it has its own threshold that can trip even faster than your acquirer-level ratio does.
For example, one merchant in your portfolio processes 12,000 monthly card-not-present sales with 170 combined fraud reports and disputes, and has a rate of roughly 1.4%, just under their own 1.5% threshold. Those same 170 events, however, land on your side of the ledger too, and your ceiling is less than half as high. A modest increase in either number is enough to cross it, even if the merchant’s own risk profile hasn’t changed.
The VAMP Enumeration Ratio is a separate, earlier trigger
Enumeration has its own trigger, separate from the ratio above. The VAMP Enumeration Ratio is 20%, with a minimum of 300,000 enumerated transactions per month, a flat number instead of a range. Visa identifies these transactions through its own scoring system, which runs against every authorization attempt, regardless of whether it's approved or declined.
Therefore, your merchants could trigger the Enumeration Ratio before generating a single chargeback, since the transactions counted are attempts rather than disputes. Approved and declined authorizations both count toward the 300,000 minimum, so if a single merchant of yours is absorbing thousands of failed test transactions, it accumulates exposure even when every one of those attempts is rejected at the door. A 100% decline rate may not look suspicious at first glance, but in the background, the enumeration count keeps growing. A portfolio could be flagged as Excessive before anyone on your team ever notices.
Does enumeration count toward VAMP without a chargeback?
Yes. The VAMP Enumeration Ratio counts the attempted-fraud signal itself, cards tested against a stolen or guessed range, not whatever happens to the transaction afterward. One of your merchants can sit firmly inside Excessive territory on enumeration alone, with a clean chargeback record everywhere else. Nothing about that gap appears on a dashboard designed to monitor chargebacks — including yours, if it's built the same way.
What "Excessive" status actually costs a portfolio
Merchants move straight into "Excessive" status once they cross the threshold, with no intermediate warning category, the way you have as the acquirer. Your own “Above Standard” tier gives you an earlier signal, well before you’d ever reach “Excessive” yourself. First-time violations do get a real cushion, at either level: a 3-month grace period per rolling 12-month window, during which Visa requests remediation but doesn't apply fines.
After that window closes, the consequences compound the longer a merchant stays enrolled:
- A per-transaction fee on every fraudulent or disputed transaction that is counted against the ratio, assessed at your level too, not just theirs.
- A mandatory monthly remediation plan, detailing root cause and recovery actions, including one you have to produce for your book, not just something each merchant handles on their own.
- If you operate under a sponsor bank or additional acquiring relationship, expect the same pattern one level up: higher costs, required reserves, or tighter terms, independent of anything Visa directly assesses.
- Potential account closure if non-compliance continues.
None of this arrives in isolation. A fee here, a stricter contract there, and a portfolio that was comfortably profitable could find its standing, either with Visa or the sponsor-acquirer relationship you operate under, getting harder to maintain, not just more expensive.
Why reactive, chargeback-based tools can't see this coming
Most fraud stacks still treat card testing as something reconciled well after the fact, once chargebacks surface a pattern that started weeks earlier. Chargebacks are a lagging indicator. Under VAMP, they're also an expensive one, since the ratio has already moved by the time a dispute lands.
Even fraud stacks that already monitor velocity spikes are usually tuned only to catch high-frequency activity at a single merchant in isolation. They're structurally blind to the same card range hitting dozens of merchants in your portfolio at once, which is exactly the shape an enumeration attack takes — and exactly the shape merchant-by-merchant tooling was never built to see.
The manual alternative doesn't close the gap either. Your analysts pulling transaction data into a spreadsheet after a chargeback spike are still doing range analysis, just reactively, and one incident at a time, well after the ratio already reflects the damage. That approach also depends entirely on someone noticing the spike in the first place, and by the time a chargeback pattern is obvious enough to prompt a manual pull, the underlying enumeration activity has usually already run its course.
Catching the same pattern before it posts means continuously monitoring the card range across all prefixes, rather than investigating it only after a spike triggers a look. For compliance teams tracking VAMP exposure specifically, a continuous view is the early-warning system that chargeback-based monitoring never gave you.
Real-time card testing detection with FraudNet
Catching enumeration before it's counted takes a different kind of visibility than most fraud stacks are built for. It means continuously monitoring authorization activity at the card-range level across every merchant in your portfolio that a given range touches, rather than reviewing transactions one at a time within a single merchant's data after the fact.
Card Testing Detection is FraudNet's implementation of that model, reducing VAMP exposure at the source. Enumeration is caught pre-chargeback, addressing the ratio directly instead of after enforcement, at the merchant level and at yours:
- Real-time, not retrospective: Signals fire in as fast as one hour, inside the window that determines whether enumeration gets counted against the ratio.
- Fraud Ops stays in control: Tunable independently through the portal, merchant by merchant or across your whole portfolio, with no engineering ticket required to change a threshold.
- Fits into existing workflows: Detection results feed the fraud review and dispute-management processes already in place, rather than requiring a new one.
Enumeration moving the ratio before a dispute ever exists is the part of VAMP that most fraud programs haven't adjusted for yet. The same detection logic that catches a card-testing attack in progress is what keeps a portfolio's ratio and its standing with Visa clean in the first place.
The fastest way to know where you actually stand under VAMP is to look at your data directly. Book a meeting and see what FraudNet's platform would surface.
Want to learn more?

You might be interested in…
Get Started Today
Experience how FraudNet can help you reduce fraud, stay compliant, and protect your business and bottom line
%20(640%20x%201229%20px).png)
