On this page
- What triggers a QMAP case
- QMAP vs GMAP — the key distinction
- Two investigation tracks
- Track A: Bust-out account cases
- Track B: Non-bust-out account cases
- Post-2027 changes (effective April 1, 2027)
- Case process and timeline
- Fees and financial consequences
- Related programmes
- What practitioners report
- Official Mastercard resources
- Key terms
QMAP (Questionable Merchant Audit Program)
QMAP (Questionable Merchant Audit Program)
Mastercard's case-based investigation programme for merchants suspected of collusive, fraudulent, or otherwise inappropriate transaction activity. Unlike GMAP (Global Merchant Audit Program), which provides continuous threshold-based monitoring of the full merchant population, QMAP is initiated on a per-merchant basis — either by Mastercard proactively or by an issuer referral — and targets intentional wrongdoing such as bustout fraud, transaction laundering, and collusion. Both programmes undergo revisions effective April 1, 2027.
What triggers a QMAP case
QMAP covers "merchants suspected of collusive, fraudulent, or otherwise inappropriate transaction activity" (Chargeback Gurus, 2026-07-30). A case opens in one of two ways (PDS Council, 2024-10-24):
PDS Council source is from 2024-10-24. Thresholds may change April 1, 2027.
- Mastercard proactive detection — unusual transaction patterns, including sudden volume spikes, multiple transactions from a single cardholder in a short period, or high rates of declined authorisations associated with known bust-out accounts.
- Issuer referral — an issuer reports a suspicious merchant to Mastercard via an online form; Mastercard then decides whether to open an investigation.
The reason code used when a merchant is identified under QMAP is Mastercard Reason Code 4849 — "Questionable Merchant Activity" (Chargeback Gurus reason code page; Justt.ai, updated 2026-03-10). Code 4849 can also be filed against acquiring banks that process transactions for a merchant listed in a Mastercard Global Security Bulletin for violating GMAP or QMAP restrictions (Chargeback.io, 2025-09-01).
QMAP vs GMAP — the key distinction
MidMetrics (2024-07-25) describes GMAP as the broader umbrella programme with QMAP as a subset focused on "higher-risk" merchants — implying QMAP is subordinate. Chargeback Gurus (2026-07-30), Solidgate (2026-07-31), and PDS Council (2024-10-24) describe them as parallel, distinct programmes with different mechanisms. The MidMetrics framing predates the 2025/2026 GMAP announcement and conflates historical programme terminology with the current structure. The parallel/distinct framing is more consistent with recent sources.
One-line distinction (Solidgate, 2026-07-31): "GMAP provides ongoing monitoring of Merchant and Acquirer performance using fraud and dispute indicators, while QMAP focuses on issuer-referred investigations of Questionable Merchants."
| Dimension | GMAP | QMAP |
|---|---|---|
| Mechanism | Continuous threshold monitoring | Case-based investigation |
| Who initiates | Mastercard (automated) | Mastercard or issuer referral |
| What it targets | High fraud/dispute ratios across all merchants | Intentional fraud, collusion, bustout schemes |
| Measurement window | Monthly rolling | 30–120 day case scope period |
| Primary pressure | Assessments + issuer visibility + liability shift | Issuer chargeback rights + acquirer loss debit |
Two investigation tracks
Track A: Bust-out account cases
A bust-out scheme involves a fraudster obtaining a credit card (via fake or synthetic identity), building a legitimate credit history over months or years, then maxing out the card at a colluding merchant, splitting the proceeds, and abandoning the account without repayment (PDS Council, 2024-09-18). A "cardholder bust-out account" is any account used in this manner.
PDS Council source is from 2024-09-18. Scale reference (Alloy 2024) may not reflect 2026 figures.
Scale reference: A 2024 Alloy report found 15% of UK fraud cases involve bust-out schemes (as-of 2024-09-18, PDS Council).
Current (pre-2027) threshold — all of the following must apply:
- At least 5 transactions to one or more acquirers during the case scope period
- Minimum transaction volume of USD $50,000 during the case scope period (120 calendar days) (as-of 2024-10-24, PDS Council)
- At least 50% of the merchant's total transaction volume involved cardholder bust-out accounts (Option 1); OR at least 3 of these 4 conditions (Option 2):
- Fraud-to-sales ratio of 70% or higher
- At least 20% of transactions declined or received "01 — Refer to issuer" response
- Merchant has been submitting Mastercard transactions for fewer than 6 months
- Total number or dollar amount of fraudulent transactions, declines, and referrals exceeds total approved transactions
Track B: Non-bust-out account cases
Non-bust-out schemes bypass credit history entirely. Fraudsters create fake online stores, use stolen card details to process numerous fraudulent transactions rapidly, collect funds, and disappear — resulting in a wave of chargebacks when issuers are notified (PDS Council, 2024-10-23).
PDS Council source is from 2024-10-23.
Current (pre-2027) threshold — all of the following must apply:
- At least 5 transactions during the case scope period
- Minimum transaction volume of USD $50,000 during the case scope period (as-of 2024-10-24, PDS Council)
- At least 3 of the following 4 conditions:
- Fraud-to-sales ratio of 70% or higher
- At least 20% of transactions declined or referred
- Merchant has been submitting Mastercard transactions for fewer than 6 months
- Total fraudulent transactions, declines, and referrals exceed approved transactions by count or dollar
Post-2027 changes (effective April 1, 2027)
Three changes announced simultaneously with GMAP, same effective date (Chargeback Gurus, 2026-07-30):
| Parameter | Current (pre-2027) | Post-2027 |
|---|---|---|
| Minimum transaction volume | USD $50,000 | USD $10,000 |
| Standard case scope period | 120 calendar days | 30 days (extendable to 60) |
| Non-bustout merchant age condition | Required (≤6 months) | Removed |
Why the age rule is removed: Removing the 6-month restriction allows QMAP to investigate non-bust-out patterns in established, older merchants — catching fraud schemes that slipped past the old criteria (Chargeback Gurus, 2026-07-30).
Revised non-bust-out qualification (post-2027): Must satisfy at least 2 of 3 tests (previously 3 of 4, with condition 3 removed):
- Fraud-to-sales ratio of 70% or higher
- Decline or referral rate of at least 20%
- Fraudulent transactions, declines, and referrals exceeding approved transactions by count or dollar
[!unverified] Whether the fee structure (USD $500 filing fee, 15% admin fee, USD $2,500 audit fee, 50% fraud loss debit) changes under the 2027 revisions — no source confirmed or denied this. Gap noted.
Case process and timeline
Steps after a case is opened (PDS Council, 2024-10-24; MidMetrics, 2024-07-25):
PDS Council and MidMetrics sources are from 2024. Process steps may change April 2027.
- Mastercard identifies the suspicious merchant (via proactive monitoring or issuer referral).
- Acquirer notified via Mastercard's Company Contact Management system.
- Acquirer has 15 days to contest Mastercard's preliminary findings by submitting additional information.
- Mastercard may audit the acquirer's records (fee: up to USD $2,500).
- If fraud is confirmed: Mastercard publishes an announcement (Global Security Bulletin) notifying issuers.
- Issuers may file Reason Code 4849 chargebacks against transactions in the case scope period.
Chargeback windows after bulletin publication:
MidMetrics (2024-07-25) and Justt.ai (updated 2026-03-10): issuers have 120 days from the bulletin to file a 4849 chargeback. Chargeback.io (2025-09-01): "Once an issuer spots a qualifying transaction, it has 180 days from the bulletin date to raise a claim." Both figures are cited as fact; the 120-day figure is more widely sourced. The 180-day figure may reflect a different measurement point or an undated rule revision. Verify against the current Mastercard Rules document before relying on either.
Merchant/acquirer response window: 45 days to contest a 4849 chargeback once presented (Justt.ai, updated 2026-03-10; Chargeback Gurus reason code page).
Fees and financial consequences
(PDS Council, 2024-10-24 — pre-2027, whether these change is unconfirmed):
Fee structure from PDS Council 2024-10-24. Post-2027 fee changes unconfirmed.
For issuers filing a referral:
- Filing fee: USD $500
- Administrative fee: 15% of the amount recovered from the questionable merchant
- If the admin fee exceeds the filing fee, Mastercard deducts the filing fee from the admin fee; if the admin fee is less than the filing fee, the issuer is not charged the admin fee
For acquirers:
- Mastercard audit fee: up to USD $2,500
- 50% of actual fraud losses tied to questionable merchant activity debited from the acquirer (paid to impacted issuers)
- If the acquirer continues processing for the questionable merchant after designation: full responsibility for all resulting 4849 chargebacks
- If the acquirer terminates the merchant: merchant is added to the MATCH System (Member Alert to Control High-risk merchants)
Related programmes
Mastercard runs three distinct programmes that are frequently conflated (Solidgate, 2026-08-12; registry agent, 2026-08-13):
| Programme | What it is |
|---|---|
| QMAP | Case-based issuer-referred investigation of specific suspected fraudulent merchants |
| GMAP | Continuous threshold monitoring of merchant/acquirer fraud and dispute ratios; replaces ECM/EFM/HECM/ACMP, April 2027 |
| Scam Merchant Monitoring Programme (SMMP) | Effective July 24, 2026: acquirers must investigate any flagged merchant within 72 hours; targets CNP scam/APP fraud specifically |
| Business Risk Assessment and Mitigation (BRAM) | Separate Mastercard enforcement programme; targets reputational risk rather than fraud metrics |
What practitioners report
Recommended compliance actions (Chargeback Gurus, 2026-07-30; Chargeback.io, 2025-09-01; Solidgate, 2026-07-31):
- Monitor Mastercard Global Security Bulletins weekly — the bulletin naming a merchant is what activates 4849 chargeback eligibility
- Enrol in chargeback alerts (Ethoca, Verifi/CDRN) — pre-dispute notification enables refunds before a chargeback is filed, preventing the dispute from appearing in fraud reporting
- Use order intelligence tools (Verifi Order Insight, Ethoca Consumer Clarity) — share itemised receipts at inquiry stage to reduce friendly fraud inflating apparent fraud rates
- Implement antifraud monitoring — block enumeration attacks, as these inflate data reported to the Fraud and Loss Database which feeds both GMAP and QMAP metrics
- Maintain complete transaction records — primary 4849 representment defences: not on a Mastercard announcement; transaction outside cited time window; refund already issued
- Acquirers: set internal merchant thresholds below Mastercard's published levels; the GMAP HDA threshold (0.5%) is well below the HDM merchant threshold (5%), meaning acquirers absorb pressure first
- Response deadline is firm: 45 days to contest a 4849 chargeback; late submissions are rejected automatically
Third-party QMAP/BRAM audit costs have been cited at USD $25,000–$75,000 (Beast Insights, 2026 — as-of 2026, source undated within year).
Official Mastercard resources
- QMAP eLearning module (confirmed at mastercard.com as of 2018): https://www.mastercard.com/elearning/qmap/story.html — content is a JavaScript Storyline app, not crawlable; as of 2026 the legacy URL may redirect to the main rules page
- GMAP eLearning module: https://www.mastercard.com/elearning/gmap/story.html
- Mastercard Security Rules and Procedures — Merchant Edition (February 2026 PDF — authoritative, not machine-readable): https://www.mastercard.com/content/dam/mccom/shared/business/support/rules-pdfs/SPME-Manual.pdf
- Fraud and Loss Database developer page: https://developer.mastercard.com/product/fld-fraud-submission/
- Official Mastercard QMAP compliance video (2018, pre-reform): https://www.youtube.com/watch?v=k4WZs7dMfXk
The official YouTube QMAP video (k4WZs7dMfXk) dates from 2018 and pre-dates the April 2027 GMAP/QMAP reforms. Content describes the programme as it stood pre-reform.
Key terms
| Term | Meaning |
|---|---|
| QMAP | Questionable Merchant Audit Program — Mastercard's case-based merchant fraud investigation programme |
| GMAP | Global Merchant Audit Program — Mastercard's continuous threshold monitoring programme (new, April 2027) |
| RC 4849 | Mastercard Reason Code 4849 — "Questionable Merchant Activity" — filed by issuers after QMAP bulletin |
| Bustout fraud | Scheme where fraudster builds credit history then maxes card at colluding merchant and abandons account |
| Non-bustout fraud | Fake storefronts using stolen card details for rapid transactions without the credit-building phase |
| MATCH System | Member Alert to Control High-risk merchants — Mastercard blacklist; merchants terminated from QMAP are added |
| BRAM | Business Risk Assessment and Mitigation — separate Mastercard programme targeting reputational risk |
| SMMP | Scam Merchant Monitoring Programme — July 2026 Mastercard programme; 72-hour acquirer investigation requirement |
| Case scope period | The calendar window reviewed in a QMAP case (currently 120 days; → 30 days from April 2027) |
| Fraud and Loss Database | Replaces Mastercard's SAFE system; feeds confirmed fraud data into both GMAP and QMAP metrics |
See also: GMAP (Global Merchant Audit Program) · Chargeback · Chargeback Representment · Visa Acquirer Monitoring Program (VAMP) · Excessive Chargeback Merchant (ECM) · Excessive Fraud Merchant (EFM) · Ethoca · MATCH System · Fraud and Loss Database · Scam Merchant Monitoring Programme (SMMP) · Business Risk Assessment and Mitigation (BRAM) · Payment Facilitator (PayFac)