Visa and Mastercard rule guidance
Visa and Mastercard mandates govern how card transactions are authorised, cleared and monitored. Card network scheme rules compliance is supported through routing controls for message indicators, merchant category codes, clearing timeframes and dispute thresholds.
- Category
- Onboarding
- Capabilities
- 10
- Available on
- All plans
Understanding and adhering to Visa and Mastercard's intricate rule sets is critical for maintaining payment processing capabilities. Cardflo offers expert guidance on these evolving regulations, helping merchants avoid penalties, reduce chargebacks, and ensure continuous compliance across all transactions.
We demystify the complexities of scheme rules.
Navigating card scheme rules, this service helps merchants interpret complex Visa and Mastercard mandates, preventing non-compliance and potential penalties. Understanding these regulations protects revenue and reduces chargeback risks.
Visa and Mastercard rule guidance overview
Visa and Mastercard maintain extensive rulebooks that dictate every technical and operational aspect of a merchant’s relationship with the card networks. These mandates cover technical specifications for authorisation messages, the correct use of Merchant Category Codes (MCC), and the strict handling of sensitive data under PCI DSS.
For businesses, compliance is not a static state but a continuous process of adapting to biannual scheme updates. Navigating these requirements involves understanding the hierarchy of rules where local regulations like PSD2 intersect with global network standards.
Failure to adhere to these specifications can lead to non-compliance assessments, elevated interchange costs, or the eventual termination of a Merchant Identification Number (MID). Specialist guidance ensures that transaction flows are optimised to meet issuer expectations while maintaining alignment with the latest network requirements for secure electronic commerce and recurring billing frameworks.
How visa and Mastercard rule guidance works
Analysing MCC and business models
The process begins with an analysis of the merchant's business model to assign the correct Merchant Category Code. Misclassification can lead to immediate fines from card schemes or high decline rates from issuers. Identifying the specific MCC allows the business to align with corresponding rule sets for high-risk or specialised sectors.
Reviewing technical message specifications
Each transaction must carry specific data elements within the ISO 8583 message format. This includes fields for 3D Secure authentication data, stored credential indicators for recurring payments, and point-of-sale entry modes. Validating these technical fields ensures that authorisation requests are not refused for technical non-compliance by the processor or issuer.
Mapping chargeback according to rules
Visa and Mastercard have distinct dispute resolution frameworks, such as the Visa Claims Resolution (VCR) and Mastercard Dispute Resolution (MDR) systems. Systems are reviewed to ensure that response timelines, evidence requirements, and representment procedures match these network-specific protocols to minimise the impact of financial losses and administrative penalties.
Monitoring biannual scheme mandates
Card schemes release major rule updates twice a year, typically in April and October. This step involves reviewing upcoming mandates, such as changes to interchange structures or new requirements for network tokenisation, to adjust internal logic and operational workflows before the mandates become effective and enforceable by the acquirer.
Why visa and Mastercard rule guidance matters
Mitigating non-compliance financial assessments
Visa and Mastercard impose financial penalties, often called non-compliance assessments, for breaches of scheme rules such as excessive chargeback rates or incorrect processing of MIT transactions. By maintaining strict adherence to the latest rulebooks, a merchant can avoid these unpredictable costs which otherwise impact the net margin of every transaction processed.
Optimising authorisation and settlement rates
Issuers use compliance with scheme rules as a proxy for transaction legitimacy. When a merchant correctly flags a transaction using network tokens or applies SCA appropriately, the issuer is more likely to authorise the payment. Proper rule guidance directly influences the success of settlement and reduces the likelihood of transactions being flagged as fraudulent.
Visa and Mastercard rule guidance use cases
Recurring billing authorisation rules
Payment operations teams must track Visa and Mastercard dispute ratios, counts and notification periods before a portfolio enters a scheme monitoring programme. Cardflo consolidates dispute data by MID, network and reason code, while its acquirer partners support remediation plans and evidence that scheme reporting deadlines have been met.
Late presentment prevention
Merchants capturing card payments after goods or services are supplied risk missing Visa and Mastercard clearing timeframes, creating late presentment disputes or interchange downgrades. Cardflo flags ageing authorisations, controls capture submission and helps finance teams reconcile clearing files before applicable network deadlines expire.
Booking clearings and dispute timeframes
Retail operators that cancel sales, reduce final amounts or abandon partial approvals must send timely reversals using the network’s required message sequence. Cardflo maps authorisation, capture and reversal events, then routes compliant messages through its acquirer partner network to release issuer holds and reduce scheme exceptions.
Visa and Mastercard rule guidance by the numbers
Standard industry thresholds for Visa and Mastercard monitoring programmes, though these vary by region and business risk profile.
The range of interchange fluctuation often seen when transaction data is not compliant with the highest level of network mandates.
Typical uplift in authorisation rates when correct scheme-compliant indicators for recurring payments are applied versus generic processing.
Methodology: these figures are illustrative ranges drawn from published industry data and observed merchant cohorts, not guarantees. Actual results depend on your risk profile, card mix, geography and acquiring setup, and are confirmed only in your own pricing and approval terms.
Related terms
Talk to our team about a live rollout across our acquirer partners' rails.
What you get with Visa and Mastercard rule guidance
- Analysis of biannual Visa and Mastercard system enhancements and mandate documentation.
- Correct assignment of Merchant Category Codes to ensure accurate interchange pricing.
- Validation of authorisation message indicators for Merchant Initiated Transactions (MIT).
- Guidance on the implementation of 3D Secure protocols to satisfy SCA requirements.
- Adherence to maximum dispute and fraud thresholds specified by card schemes.
- Monitoring of technical compliance for network tokenisation and account updater services.
- Management of soft descriptors to reduce customer confusion and retrieval requests.
- Alignment with PCI DSS requirements for secure handling of primary account numbers.
- Optimisation of transaction routing to favour lower interchange through scheme-compliant data.
- Support for representment procedures to recover funds according to network dispute rules.
A short scoping call, then a written plan for your MIDs.
Questions about Visa and Mastercard rule guidance
How should merchants respond to Visa and Mastercard monitoring programme notifications?
Merchants should confirm the programme, measurement period, affected MID and transaction population stated in the notification.
Payment operations and risk teams should then reconcile scheme data against gateway, acquirer partner and dispute records, identify the activity driving the breach, and document corrective actions with owners and deadlines.
Cardflo can support data analysis and operational remediation through its acquirer partner network, while the relevant acquirer partner remains responsible for formal scheme communications and any required submissions.
How do Visa and Mastercard rules differ regarding 3D Secure?
While both schemes support the EMV 3D Secure standard, they have different rules regarding liability shift and implementation timelines.
For instance, Mastercard's Identity Check and Visa's Secure correspond to the same technical standard but may have different requirements for data elements like the Directory Server ID.
Navigating these involves ensuring the gateway and 3DS provider are correctly configured for both schemes to ensure authentication results are properly passed to the issuer.
What is the consequence of using the wrong Merchant Category Code (MCC)?
Using an incorrect MCC is considered a serious breach of scheme rules. From a financial perspective, it can lead to incorrect interchange fees, which both schemes view as a form of fee circumvention.
It also leads to higher decline rates because issuer risk models are calibrated based on the expected behaviour of specific MCCs. If a scheme discovers misclassification, it can result in substantial backward-dated fines and immediate suspension of the MID.
Are scheme rules different for card-present and card-not-present transactions?
Yes, Visa and Mastercard maintain separate rule chapters for different environments. Card-not-present (CNP) transactions face more rigorous requirements for data validation, such as CVV2 and AVS checks, due to the higher inherent risk of fraud.
Card-present rules focus more on terminal hardware standards, kernel versions, and the physical handling of the card. Understanding these distinctions is vital for omnichannel retailers who process across multiple environments.
What are Stored Credential Transaction (SCT) mandates?
Visa and Mastercard require specific indicators for any transaction where the cardholder's details are stored for future use. This involves a framework for the initial transaction (CIT) where consent is obtained, and subsequent transactions (MIT).
Correct flagging allows issuers to recognise these as legitimate recurring payments, which is essential for maintaining high authorisation rates and complying with rules designed to prevent unauthorised billing.
How often do scheme rules change and how are they communicated?
Scheme rules are updated via technical bulletins and global rulebooks, usually twice a year. Acquirers and PSPs receive these notifications first and are responsible for ensuring their merchants are informed.
However, the technical burden for implementation often falls on the merchant's developers or their payment partner. Proactive monitoring of these updates is necessary to ensure that technical integrations remain compliant with new data field requirements or security standards.
Related guides.
See how Cardflo compares.
From the blog
Opening a merchant account is essential for any eCommerce or retail business wanting to accept electronic payments. This guide explains how acquiring banks and providers process transactions from Visa and Mastercard. It details the necessary documentation and steps required to receive funds from customer card payments. Merchants must select the specific networks they wish to accept before applying.
Read articleHigh-risk industries require specialised merchant accounts to manage financial instability and fraud risks. These accounts enable secure credit and debit card processing for sectors like adult entertainment. Cardflo supports high-risk models by providing tailored accounts with advanced risk tools to ensure efficient business operations. This guide outlines the key considerations for researching these accounts.
Read articleReady to improve your payments setup?
Tell us about your business. We'll match you with the right acquiring partners and the right route, typically inside a week.