A terminated-merchant listing is one of the few things in payments that follows a business and its owners for years, is usually invisible until it does damage, and cannot be argued away by fixing the thing that caused it.
Merchants in regulated categories hear the acronyms (TMF, MATCH, VMSS) without a clear picture of what they are, how someone lands on one, or what can actually be undone.
This piece explains the MATCH list, Visa’s VMSS, and the TMF label that covers both, with the numbers that matter.
How this works: Bankful provides payment software and orchestration, and depending on the arrangement may act as the direct processor. Processing eligibility and continued processing are determined at underwriting by the processor of record and its sponsor bank(s) under the applicable terms, which can change.
What TMF, MATCH, and VMSS are
“Terminated Merchant File,” or TMF, is the umbrella term for the databases acquiring banks screen against before they approve a new merchant. Two run the industry:
- MATCH: Mastercard’s Member Alert to Control High-Risk Merchants.
- VMSS: the Visa Merchant Screening Service.
When an acquirer terminates a merchant and the merchant meets the criteria, the acquirer is required to report them. For MATCH, that report is due within one business day.
The listing names the business and its principal owner: legal and DBA name, address, phone, tax ID, URL, the account open and termination dates, and a reason code. Because the owner is listed too, a person can carry a listing from one failed business into the underwriting of the next one.
How a merchant gets on the MATCH list
Mastercard’s MATCH uses thirteen reason codes (numbered 1 through 14, with 6 unused): eleven qualitative codes for conduct, and two quantitative codes a merchant can trip on the numbers alone.
The two quantitative codes are the ones that catch otherwise honest businesses, because they do not require any intent. The most relevant codes:
| Code | Reason | How a merchant triggers it |
|---|---|---|
| 04 | Excessive chargebacks | In the same calendar month, the number of Mastercard chargebacks exceeds 1% of the number of Mastercard sales transactions, and those chargebacks total $5,000 or more. No intent required. |
| 05 | Excessive fraud | In the same calendar month, fraud-to-sales dollar volume reaches 8% or more, with 10 or more fraudulent transactions totaling $5,000 or more. |
| 03 | Laundering | Presenting transactions that were not valid sales between the merchant and a real cardholder. |
| 13 | Illegal transactions | The merchant was engaged in illegal transactions. |
| 10 | Violation of standards | Breach of the card network rules governing how the merchant must conduct transactions (prohibited transactions, card-acceptance rules, and similar). |
| 12 | PCI DSS non-compliance | Failure to meet Payment Card Industry Data Security Standard requirements. This is the one code an acquirer can clear by verifying the merchant became compliant. |
| 14 | Identity theft | The acquirer believes the identity of the merchant or its owner was unlawfully assumed to open the account. |
Visa runs the same kind of database, VMSS, with its own reason codes and its own thresholds. Its excessive-dispute code applies at 1,000 disputes and a 1.8% dispute-to-sales ratio in a single month, and its excessive-fraud code at $250,000 in fraud and a 1.8% fraud-to-sales ratio, in both cases where the merchant did not adequately remediate. VMSS listings also last five years.
Monitoring is not the same as listing
Visa’s monitoring has also changed. Its older dispute and fraud programs, VDMP and VFMP, were replaced by the Visa Acquirer Monitoring Program (VAMP), which measures fraud and disputes together as a single ratio against settled card-not-present transactions.
Since April 1, 2026, the merchant “excessive” threshold in the US, Canada, Europe, and Asia-Pacific is 1.5% (150 basis points), down from 2.2%. Merchants with fewer than 1,500 fraud and dispute reports in a month are excluded. Merchants identified as excessive draw a fee of $8 per fraudulent or disputed transaction, assessed through the acquirer and typically passed on to the merchant.
Keep the two ideas separate:
- A monitoring program (Mastercard’s chargeback thresholds, Visa’s VAMP ratio) is what usually leads an acquirer to terminate a merchant.
- A database listing (MATCH or VMSS) is what follows the business and its owners for five years afterward. Closing the account does not prevent it: an acquirer must still report a qualifying merchant after the relationship ends.
You usually will not be told
There is no notification. Mastercard does not contact a merchant when an acquirer adds them, and most merchants learn they are listed only when a new application is declined, then another, with no clear reason given. By the time the pattern is obvious, the merchant has often spent weeks applying to processors that were never going to approve them.
How long a MATCH listing lasts
Five years from the date it is added, on both MATCH and VMSS. After five years the entry is removed automatically. There is no application, no fee, and no special process to age off. The listing simply expires.
What reverses, and what does not
This is the part merchants most often get wrong, because the intuition (fix the problem, clear the record) does not hold here.
What can be removed
- An error: If the acquirer added the merchant by mistake, it can correct or delete the entry. Only the acquirer that placed the listing can do this. No other bank can, and neither can the merchant directly.
- PCI DSS (code 12), once fixed: If the listing was for PCI non-compliance, the acquirer can remove it after verifying the merchant reached full compliance.
One exception that is not a removal: A merchant who can prove they were an identity-theft victim (code 14) may be considered by a new processor despite the listing. The entry itself stays.
What cannot be removed
- Winning or refunding the chargebacks later: An excessive-chargeback listing (code 04) is triggered by that month’s numbers. Reversing those chargebacks afterward, or settling with the customers, does not change the listing. The month qualified and the entry stands.
- Fixing the underlying business problem: Tightening fraud controls or hiring a chargeback team is the right thing to do, but it does not delete an entry that was validly placed. Visa is explicit that a bank may not delete a listing merely because the merchant resolved its dispute issues, and Visa allows no direct merchant appeal.
In plain terms: outside a genuine error or a verified PCI fix, a valid listing is not negotiable and not reversible. It runs for five years.
If you do not know who listed you
A merchant who suspects they are listed but does not know which acquirer did it can email Mastercard at [email protected] to request their listing details, or contact Visa through its support channels to try to locate the source. Any correction still has to go back through the acquirer that placed the entry.
What this means in practice
Because a valid listing cannot be undone and lasts five years across essentially every processor, the room to act is before the thresholds are crossed, not after.
For a merchant in a regulated category, that means checking every month against the 1% / $5,000 Mastercard chargeback line and the 1.5% Visa VAMP ratio, keeping fraud controls well ahead of the 8% / 10-transaction line, and treating an accurate underwriting application as the cheapest insurance available.
Remediation after a listing is mostly waiting.
Where Bankful fits
Bankful is a payment software and orchestration provider. Depending on the arrangement, Bankful may be the direct processor or may orchestrate routing to a third-party processor of record.
Termination and any resulting MATCH or VMSS listing are decisions made by the processor of record and its sponsor bank under their own terms and the card-network rules. A merchant’s standing on these databases is governed by their agreement with the processor of record.
Disclaimer: Bankful provides payment software and orchestration services under the Bankful Software Agreement. As described in that agreement (§5.11), merchant account services are governed by a separate agreement between the merchant and the applicable processor of record. Depending on the arrangement, Bankful may be the direct processor or may orchestrate routing to a third-party processor. Eligibility to process, including approval, continued processing, holds, freezes, and account termination, is determined by the processor of record under its own terms, which vary by provider and may change. Merchants are responsible for understanding and complying with their processor’s terms of service and acceptable use policy. Merchant onboarding also includes a Hold Harmless agreement under which the merchant acknowledges that Bankful is not responsible for processing decisions made by the processor of record.
