MATCH code 5 is the excessive fraud reason code, and it has a published three-part trigger. Mastercard’s threshold is a fraud-to-sales dollar ratio of 8% or more in a calendar month, combined with 10 or more fraudulent transactions in that month, totalling 5,000 US dollars or more. All three conditions apply together.
What triggers MATCH code 5
Three tests, one calendar month, all of them required. The ratio test is fraud-to-sales measured by dollar volume, at 8% or higher. The count test is 10 or more fraudulent transactions. The amount test is those transactions totalling 5,000 US dollars or more.
The three-part structure is deliberate. It filters out the small business that took two fraudulent orders in a quiet month and would otherwise show a terrible-looking percentage, and it filters out the large business with an ugly absolute number that is trivial against its volume. What is left is a genuine pattern.
How code 5 differs from code 4
Code 4 measures disputes. Code 5 measures fraud, and the distinction is real rather than semantic. A chargeback can be raised by a legitimate customer who did not recognise a descriptor, never received a parcel, or simply changed their mind and found the easiest route to a refund. Fraud means the transaction was not authorised by the cardholder in the first place.
The measurement differs too. Code 4’s ratio is a count against a count, chargebacks against sales transactions. Code 5’s ratio is dollars against dollars, fraud volume against sales volume. A business with a small number of very large fraudulent orders will find code 5 the tighter constraint even while its dispute count looks fine. The code 4 detail sits in the excessive chargebacks threshold.
Why code 5 reads more harshly
It should not, strictly, because fraud happens to merchants rather than being committed by them in the ordinary case. In practice a new underwriter reads code 5 with more care than code 4, because sustained fraud at that level suggests either a product that attracts card testing and stolen-card use, or controls that were not doing their job.
The distinction an underwriter is looking for is whether you were the target or the cause. A file that shows a specific attack, a date it started, the filters put in place and the ratio falling afterwards reads completely differently to one that shows an elevated rate holding steady for a year. Give them the first, with the arithmetic shown.
The controls that actually move the number
Fraud ratio is one of the few underwriting metrics a merchant can move quickly. Address and card security code verification, velocity limits on repeated attempts from one card or one address, 3D Secure on the order profile where it fits, and manual review on orders that break your normal pattern by size or destination.
The trap is over-tightening. Filters that decline a meaningful share of good customers cost more than the fraud they prevent, and the resulting fall in sales makes the ratio’s denominator smaller, which is the opposite of what you want. Tune to your actual order pattern rather than to a template. More on the gateway side of this is in choosing a high risk payment gateway.
Visa runs its own version
Staying clear of Mastercard’s code 5 does not mean you are clear generally. Visa operates the Visa Merchant Screening Service with its own thresholds: code 21 for excessive fraud at 250,000 US dollars of fraud combined with a 1.8% fraud-to-sales ratio, and code 22 for excessive disputes at 1,000 disputes combined with a 1.8% dispute-to-sales amount ratio in a single month.
Different brands, different numbers, and an acquirer may check both systems when it screens an application. Watching a single blended figure across all card brands will not tell you where you stand on either. The full picture is on our MATCH list reference page.
If you are already listed under code 5
The route is the same as any listing but the file has to work harder. Mastercard’s rules allow the acquirer that placed the listing to remove it only where it added the business in error, or where the listing is code 12 for PCI non-compliance now remediated. Code 5 does not have a remediation path to removal, which means the realistic goal is placement rather than deletion. That is set out in how MATCH list removal actually works and getting a merchant account after a MATCH listing.
What helps most is evidence that the fraud pattern ended and why. Statements showing the ratio before and after, the date controls changed, and what those controls were. An underwriter who can see the fix and see it holding has something to underwrite.
Frequently asked questions
Is fraud the same as a chargeback? No. Fraud means the cardholder did not authorise the transaction. A chargeback is the dispute mechanism, and it covers many situations that are not fraud at all.
Does a single attack month cause a listing? The threshold is measured on a single calendar month, so a bad month can meet it. Whether the acquirer terminates on that basis is the acquirer’s decision.
Can I appeal a code 5 listing? You can dispute it factually with the acquirer that placed it if the criteria were not met, since Mastercard publishes that it does not assess the accuracy of listings. There is no appeal to Mastercard itself.
Do 3D Secure transactions still count against me? Where a transaction carries the liability shift, the fraud loss generally sits with the issuer rather than the merchant. How that interacts with a specific acquirer’s fraud reporting is a question worth asking that acquirer directly.
Sources: Mastercard Security Rules and Procedures Merchant Edition (SPME manual), and Stripe’s published documentation at docs.stripe.com/disputes/match.