Back to Glossary

Excessive Fraud Merchant (EFM)

The Excessive Fraud Merchant (EFM) program is Mastercard's compliance mechanism for identifying and penalizing merchants with elevated e-commerce fraud levels.

Unlike the Excessive Chargeback Program, which tracks overall chargeback volume, EFM focuses specifically on fraud-related chargebacks filed under reason code 4837 (No Cardholder Authorization). A merchant triggers EFM classification when four criteria are met simultaneously: 1,000 or more e-commerce transactions in the prior month, $50,000 or more in fraud-related chargebacks, a fraud chargeback-to-sales ratio of 0.5% (50 basis points) or higher, and 3D Secure authentication usage below 10% in non-regulated countries or below 50% in regulated countries. Enrollment occurs after a merchant meets all four criteria for two months.

Why EFM Matters

Four-Criteria Threshold Structure

EFM is the only Mastercard monitoring program that requires all four conditions to be met simultaneously. This means a merchant processing high fraud volume but with strong 3D Secure adoption may avoid EFM classification. Conversely, a merchant with moderate fraud but minimal 3DS usage can trigger enrollment. Understanding which criteria the merchant is closest to breaching determines the most effective remediation path.

3D Secure as a Compliance Lever

The 3DS utilization threshold distinguishes EFM from other Mastercard programs. In non-regulated countries, merchants must process more than 10% of clearing volume through 3DS to avoid meeting this criterion. In regulated countries (where Strong Customer Authentication applies), the threshold is 50%. Increasing 3DS adoption is the fastest way to exit EFM eligibility, even before fraud volumes decline.

Single-Tier Escalation

EFM operates as a single tier with no "high" sub-category. Monthly assessments start at $500 in month two and escalate to $100,000 per month at month 19. While the penalty curve is less steep than HECM, the cumulative cost over 19 months exceeds $900,000 in assessments alone. Exit requires three consecutive months below any one of the four thresholds.

How to Manage EFM Compliance

1. Audit 3DS Adoption Rates First

Because EFM requires all four criteria, dropping below any single threshold removes the merchant from eligibility. 3DS adoption is typically the fastest to change. Review current authentication rates against the applicable threshold (10% for non-regulated, 50% for regulated markets) and prioritize 3DS enrollment for transaction types where it is underutilized.

2. Isolate Fraud-Specific Chargebacks From General Disputes

EFM only counts reason code 4837 chargebacks. Separate fraud-related chargebacks from customer disputes, service complaints, and other non-fraud categories. A merchant with a high overall chargeback rate but low 4837 volume may face ECM risk rather than EFM risk. The remediation strategy differs significantly.

3. Implement Velocity Controls on High-Risk Transaction Patterns

Fraud chargebacks concentrate around specific patterns: high-value orders from new customers, transactions from mismatched geographies, and rapid repeat purchases. Implementing velocity limits and address verification on these patterns reduces the 4837 chargeback count without restricting legitimate transaction flow.

4. Track the $50,000 Dollar Threshold Monthly

The $50,000 fraud chargeback dollar threshold is absolute, not ratio-based. For mid-volume merchants, a small number of high-value fraudulent transactions can breach this threshold even with an otherwise low fraud rate. Monitor the dollar amount separately from the basis point ratio.

5. Plan for the Three-Month Exit Window

EFM exit requires falling below any one of the four thresholds for three consecutive months. Identify which threshold is most achievable and sustain the reduction for a full quarter. A one-month dip followed by a rebound resets the exit clock.

EFM in Practice: A Real-World Scenario

An e-commerce merchant processing 5,000 Mastercard transactions monthly reports $62,000 in fraud-related chargebacks (reason code 4837) with a fraud ratio of 0.8%. The merchant's 3DS utilization is 7%, below the 10% threshold for non-regulated countries. All four EFM criteria are met for two consecutive months, triggering enrollment.

The acquirer analyzes the merchant's transaction data and identifies that 3DS is enabled for only one of three payment flows. Expanding 3DS to all flows raises utilization to 35% within 45 days. Because the merchant now fails to meet the 3DS criterion, it falls below the four-criteria threshold and exits EFM after three consecutive months, having accumulated $1,500 in assessments during months two and three.

Strategic Impact on Payment Providers

Fraud-Specific Risk Segmentation

EFM identifies merchants with fraud exposure distinct from general chargeback problems. Acquirers that monitor only overall chargeback ratios may miss merchants accumulating fraud-specific chargebacks below the ECM threshold but above EFM criteria. Separating fraud chargebacks (4837) from non-fraud disputes in merchant monitoring systems enables earlier intervention.

Authentication Strategy as Risk Mitigation

The 3DS criterion creates a direct link between authentication policy and compliance risk. Acquirers that enforce minimum 3DS adoption rates during merchant underwriting reduce EFM exposure across their portfolio before merchants begin processing. This is a policy decision, not a reactive remediation.

Transition to GMAP Combined Measurement

Under GMAP (effective April 2027), fraud reports from Mastercard's Fraud and Loss Database will be combined with non-fraud chargebacks into a single metric. Merchants currently managed under EFM for fraud-specific issues may face compounded thresholds when non-fraud disputes are added. Acquirers should model the impact of combined measurement on current EFM-flagged merchants.

How Ballerine Supports EFM Management

Ballerine's merchant monitoring platform tracks fraud-specific chargebacks separately from general disputes, enabling acquirers to identify merchants approaching EFM thresholds before enrollment triggers. The system monitors all four EFM criteria in parallel, surfaces the most actionable remediation path, and maintains audit-ready documentation of compliance actions. As one of five solutions globally certified under Mastercard's MMSP, Ballerine helps acquirers reduce scheme fines by up to 75% while managing fraud risk across the merchant lifecycle.

Trusted by

Trusted by Leaders in the Payments Ecosystem

70%

Reduced manual efforts

49%

Improved review resolution time

30%

Increase in 
detected fraud

“We were able to downsize our compliance staff’s workload significantly, which allowed us to allocate the savings and workforce into more improvement projects.”

Shmulik Davar

VP Product at Fido

67%

Reduced Hiring Time

“Proactively navigating fintech regulations requires faster technology adoption. Next-gen compliance infrastructures should seamlessly integrate with existing and new systems and data sources.”

Ran Nachman

VP Regulation Solutions 
at eToro

67%

Reduced Hiring Time

“Proactively navigating fintech regulations requires faster technology adoption. Next-gen compliance infrastructures should seamlessly integrate with existing and new systems and data sources.”

Vicente Mederos

Head of Risk 

at Access Group

98%

Local Compliance

“User-friendly, reliable, and fast. It’s exactly what we needed to scale without adding complexity.”

Emily Rivera

Co-Founder

4.8 rating from 1.5k reviews

Author ImageAuthor ImageAuthor ImageAuthor Image

10+

Download from app store

Download for iOS

Ready to transform how your bank onboards, underwrites, and manages merchant risk?