MATCH is a Mastercard database in which acquirers record merchants terminated for cause, with a reason code. The record names the business and every principal owner on the application and stays on file for five years. Acquirers query it before boarding a merchant and many treat a hit as a decline. Because the listing follows the people and the entity, the next application needs a clean US director and an entity never used for processing.
MATCH is a database run by Mastercard in which acquirers record merchants they have terminated for cause. The full name is Member Alert to Control High-risk Merchants; older documents call it the Terminated Merchant File, or TMF. Each record names the business and the people behind it, carries a reason code, and stays on file for five years. This guide covers the codes in plain words, who gets listed, how acquirers query the file, what a listed merchant can still do, and why a clean US person and entity decide the next application.
What MATCH is, and what it is not
MATCH is not a court and not a regulator. It is a shared record between acquirers, maintained by Mastercard so that a merchant terminated by one acquirer for fraud, laundering or excessive chargebacks cannot walk into the next acquirer with a clean story. Mastercard rules require acquirers to query it before signing a merchant agreement and to add a record when they terminate a merchant for a listed reason. It holds facts entered by the terminating acquirer, identifiers, a reason code and a date, but no evidence, and Mastercard does not investigate the entries. Although Mastercard maintains it, US acquirers typically query it on every application, whatever card brands the merchant plans to accept. It is an alert system, not a ban: the acquirer that finds a match decides what to do with it, and many treat a match as a decline. Mastercard revises the numbering of the reason codes from time to time; your termination notice is the authoritative source for your own code.
The reason codes in plain words
| Code | Network name | What it means in practice |
|---|---|---|
| 01 | Account data compromise | Card data was accessed or disclosed without authorization through the merchant, stolen outright or exposed through poor security. |
| 02 | Common point of purchase | Cards used at the merchant later showed up in fraud elsewhere, and the merchant was the common link. |
| 03 | Laundering | The merchant submitted transactions that were not genuine sales to its own cardholders, typically by processing for another business with no merchant account. |
| 04 | Excessive chargebacks | Chargebacks exceeded the network's ratio and amount thresholds and the acquirer terminated rather than remediated. |
| 05 | Excessive fraud | Fraudulent transactions reported by issuers exceeded the network fraud program thresholds. |
| 07 | Fraud conviction | A principal owner or partner of the business has a criminal fraud conviction. |
| 09 | Bankruptcy, liquidation or insolvency | The business went bankrupt, was liquidated or could no longer meet its financial obligations. |
| 10 | Violation of standards | The merchant broke Mastercard's merchant standards in a way no other code covers, for example prohibited transactions or billing practices that breach the rules. |
| 11 | Merchant collusion | The merchant took part in fraudulent collusive activity with other parties to defraud issuers or cardholders. |
| 12 | PCI DSS non-compliance | The merchant failed to meet the card data security standard. |
| 13 | Illegal transactions | The merchant processed transactions that were illegal under applicable law: unlicensed products, restricted goods, unlawful services. |
| 14 | Identity theft | The merchant account was opened or operated under a stolen or assumed identity, of the merchant or of a principal. |
Mastercard also keeps a code for its own questionable merchant audit program, and one number is reserved. Three groups matter to a high-risk merchant. Codes 04 and 05 are ratio problems: the business sold real products but lost control of disputes or fraud. Codes 03, 10 and 13 are conduct problems: what was processed and how it was presented to the acquirer. Codes 07, 11 and 14 are integrity problems: a person, not a metric, is the reason. Underwriters read the code before anything else. A ratio code can be explained with new controls; a conduct or integrity code is much harder to explain, because the acquirer is being asked to trust the person rather than the metrics.
Who gets listed: the business and the people behind it
A MATCH record is not one line. The terminating acquirer enters identifiers for the merchant entity and, separately, for each principal owner on the application. That is the part merchants underestimate. In a small business the principal owner is usually the person who signed the merchant agreement and the personal guarantee, and that person is listed by name, address and identification number, next to the business. A new trade name changes nothing for that person.
- Business identifiers: legal name, doing-business-as name, address, phone number, tax identification number (the EIN in the US) and website URL.
- Principal identifiers: full name, home address, phone number and government identification numbers (the Social Security number for a US resident), for every principal owner on the application.
- The record itself: the reason code, the date of termination and the acquirer that made the listing.
Exact and phonetic matches.MATCH does not only return exact hits. Queries are matched phonetically as well, so a similar name at the same address, or the same phone number on a different entity, comes back as a possible match for the underwriter to judge. Changing one field on the next application does not clear the others.
Starting a new file after a termination?
The next acquirer underwrites a fresh US entity and director. Browse live inventory or describe your situation on Telegram.
How long a listing lasts, and who can remove it
Mastercard documents a retention period of five years. A record drops out of query results five years from the listing date, not from the day you notice it. There is no appeal to Mastercard as a merchant and no form to fill in. Only the acquirer that created the record can ask for it to be withdrawn earlier, and Mastercard documents two grounds: the listing was made in error, or the listing was for PCI DSS non-compliance and the merchant has since become compliant. Every other record runs its full term. If the facts entered were right, the record stays.
How acquirers query MATCH
The query happens during underwriting, before the merchant agreement is countersigned. Acquirers usually run it as one of the first gates. The KYB guide on this blog covers the whole review; here is the MATCH step alone.
- The underwriter submits the identifiers from the application: the business fields and every principal's fields, as written on the form and read from the identification documents. Leaving out a principal is not a clean application; it is a misrepresentation, and an acquirer that discovers it later can terminate for it.
- MATCH returns exact matches and phonetic possible matches on any field, together with the reason code, the listing date and the listing acquirer for each hit.
- The underwriter checks whether a possible match is really the applicant. A shared address or a common surname may be cleared; a matching identification number or tax ID is treated as the same party.
- The acquirer applies its own policy to the code. Some codes are an automatic decline at many acquirers; others open a conversation about reserves, pricing and monitoring.
- The inquiry itself is stored. If another acquirer adds the same merchant later, the earlier inquirers are notified after the fact. Because every acquirer repeats the query, moving from one processor to the next does not outrun the record.
What a listed merchant can and cannot do
A MATCH listing is not a legal prohibition. Nothing stops a listed merchant from applying, and some acquirers do board listed merchants, more readily for the ratio codes than for the integrity codes, with a rolling reserve, a lower processing cap and closer monitoring than a clean file would get. The honest picture:
- Can: ask the listing acquirer for the reason code and the listing date, and dispute a record that is factually wrong with that acquirer, with evidence.
- Can: apply to acquirers that state they consider listed merchants, and expect reserves, pricing and volume caps that reflect the code.
- Can: fix the business meanwhile (descriptor, refund policy, dispute handling, product compliance) so the next file tells a different story.
- Cannot: get Mastercard or a paid third party to change the record. Mastercard acts only on the listing acquirer's request.
- Cannot: outrun the record by changing the trade name, the website or the state of formation while keeping the same principal, tax ID, address or phone number.
- Cannot: shorten the five years by any means other than the two grounds above.
Why a clean US person and entity decide the next application
Everything above leads to one conclusion. The next acquirer will not underwrite your story; it will underwrite the identifiers on the application. If they belong to a listed principal or a listed entity, the answer arrives at step two of the query. If they belong to a US resident with no processing history, no record and a credit file above the acquirer's floor, and to an entity formed in that person's home state that has never held a merchant account, the query returns nothing and underwriting moves on to the business itself.
That is the logic behind the way IBOCore qualifies an IBO (Independent Business Operator). Every director is a real US resident with zero criminal record, a credit score of 650 or more and a complete KYC file, never used for another merchant and exclusive to one, with no processing history a MATCH query could return. The entity is an LLC or C-Corp incorporated in the director's home state, with its own EIN and a business bank account in its name, never used for processing before. IBOCore does not remove MATCH listings and does not give legal advice. It refuses the verticals listed on the industries page: adult content and cam, online gambling, pharmacy and Rx, firearms and ammunition, crypto exchanges and custody, and anything fraudulent. A misclassified business gets its package suspended: a subscription business presented as one-time e-commerce is a misrepresentation, and misrepresentation ends merchant agreements once an acquirer finds it. A structure is not a reset button either: if the last termination came from what you sold or how you billed, a fresh entity and director can be terminated for the same reason and listed with it. Change the business first; the guide on what happens after a MID termination covers descriptor, refund policy and chargeback controls.
Ready for a clean underwriting file?
Packages ship the same day from inventory: fresh US director, fresh entity, full bank access. Ask about your vertical on Telegram first.
Questions merchants ask
Does a MATCH listing follow me to a new company?
Yes, if you are on the new application. The record lists the principal owners of the terminated business by name, address and identification numbers, and acquirers query every principal on the new form, with phonetic matching. A new legal entity is only a new file when the people, the tax ID, the address and the phone number on it are not the listed ones. The person who signs the next application matters more than the paperwork of the entity.
Can a paid service remove a MATCH listing?
No. Mastercard removes a record only when the listing acquirer reports that it was made in error, or when a PCI DSS non-compliance listing has been corrected. No third party has write access to the database. What a competent adviser can do is help you obtain the reason code from the listing acquirer, check the record for factual mistakes and put the error case to that acquirer. Treat any offer of removal for a fee as a red flag, and the five-year term as the realistic horizon.
Is every terminated MID listed on MATCH?
No. Acquirers close accounts for commercial reasons too: a change in their vertical policy, volume below their minimum, a portfolio sale. Those closures are not MATCH records. A record exists when the acquirer terminates for one of the listed reasons and enters it, which Mastercard requires promptly after the decision. Ask the acquirer in writing whether a record was filed and under which code. The answer decides whether your next application starts as a fresh file or a listed one.
Compliance touchpoints that survive audit
Clean setups disclose beneficial ownership, file BOI, use genuine IDs, and keep the IBO informed of website and descriptor changes. Processors re-scan for prohibited products, undisclosed aggregation, and transaction laundering. Violations land on MATCH and kill future MID applications.
- AML / CDD: customer due diligence on the merchant entity.
- PEP screening: politically exposed persons get enhanced review.
- OFAC / SDN: sanctions lists checked on owners and signers.
- Website compliance: refund policy, terms, pricing visible before checkout.
Compliance shortcuts that trigger MATCH
Fake guarantors, borrowed SSNs, cloaked websites, and third-party processing through your MID are the fastest paths to MATCH listings. Recovery requires legal work and years of delay. Disclose, document, and keep the IBO in the loop.
FAQ: quick answers
How fast can I get an IBO package on IBOCore?
Available inventory ships the same day after payment. You receive Articles, EIN letter, registered agent details, bank onboarding pack and signer contact through your merchant dashboard. Processor onboarding typically follows over the next one to two weeks.
Where can I look up payment-processing jargon?
Use the Resources glossary on IBOCore (/resources) for 580+ definitions: MID, chargeback ratio, MATCH, rolling reserve, MCC, RDR, KYB and high-risk vertical vocabulary.
Ready for instant delivery?
Browse live IBO inventory or ask about your vertical on Telegram.