SIPAF and SIMEC: card-fraud reporting to UCAMP in Italy
Italy runs a state card-fraud database that most foreign card issuers have never heard of. SIPAF — the computerised archive created by Law 166/2005 and run by the Ministry of Economy and Finance’s anti-fraud office, UCAMP — collects disputed card transactions, revoked merchants and tampered ATMs from the firms that issue and acquire cards. Since 2017 it lives inside SIMEC, the ministry’s euro-and-cards monitoring system. This piece covers who reports, what goes in, the two-working-day clock, the fraud-risk parameters that open a monitoring window, and how a payments firm builds the feed.
1. What SIPAF is
Law 17 August 2005, no. 166 set up a system for the administrative prevention of payment-card fraud at the Ministry of Economy and Finance (MEF). Prevention here means sharing data between issuers and acquirers so each can spot compromised merchants, cards and ATMs faster — not criminal investigation, which stays with the police and the courts.
The implementing rules are in Ministerial Decree 30 April 2007, no. 112, in force since 14 August 2007. It names the UCAMP (Ufficio centrale antifrode dei mezzi di pagamento) as the controller of the archive, sets the data items, the deadlines and the fraud-risk parameters, and creates a consultative working group, the GIPAF, in which ministries, the Bank of Italy, police experts and reporting firms take part. The MEF states that SIPAF was absorbed into SIMEC (Sistema di monitoraggio euro e carte) in 2017; firms now work in the SIMEC “Area Carte”, reached through the MEF services portal.
2. Who reports, and how you join
Article 1(3) of the law brings in the “reporting companies” (società segnalanti): companies, banks, payment institutions and financial intermediaries that issue payment cards and run card-acceptance networks. Payment institutions were added to the text by Legislative Decree 90/2017. E-money institutions are not named separately; an EMI issuing cards in Italy falls within the general reference to companies issuing payment cards, and should confirm its position with UCAMP before launch rather than assume it is out.
- Accreditation. A firm joins by sending the accreditation form (Formulario) to UCAMP by certified e-mail (PEC). Paper submissions are no longer accepted; the current procedure has applied since 25 May 2023.
- Referent. The form names an organisational referent, who creates and maintains the firm’s user accounts in the SIMEC reserved area. Leavers must be removed.
- Delegation. Article 2 of the decree lets a firm meet its duties directly or through another reporting company it delegates, provided the delegation protects data integrity and confidentiality.
- Manuals. The operating manuals for the data and information segments are available to accredited firms in the reserved area, not on the public site.
- Exit. A firm that no longer meets the Article 1(3) conditions can ask to leave by a letter on company letterhead sent by PEC.
3. The “Data”: four categories and a two-day clock
Article 6 of the decree defines four categories of Dati. All are entered electronically as soon as available and no later than the second working day after the firm acquires them (Article 10(2)). They stay in the archive for three years (Article 13).
| Category | Trigger | Main fields |
|---|---|---|
| Revoked merchants — 6(b) | Acquirer revokes a merchant agreement for security reasons or after reporting the merchant to the judicial authority | Merchant code, trading name, company name, address, chamber-of-commerce number, VAT number, signatory and tax code, merchant category, POS terminal IDs, agreement and termination dates, reason, details of the criminal complaint |
| Disputed transactions — 6(c) | Cardholder does not recognise a transaction or reports it to the judicial authority | Card number and expiry, date, amount and currency, acquirer ID, authorisation code, PAN, reason, merchant code, terminal ID or ATM code, details of the cardholder’s complaint |
| Renewed agreements — 6(d) | A new agreement is signed with a merchant previously revoked | New merchant code and the same identification set, with the date of the earlier revocation |
| Tampered ATMs — 6(e) | An ATM has been fraudulently manipulated | Location, ATM identifiers and model, tampering method, PIN-capture method |
The decree fixes six reasons for a disputed transaction: card stolen, card lost, card counterfeit, card not received, fraudulent use of the card number, and card used under a false identity. Mapping your own chargeback and dispute reason codes to these six is the first build task.
4. The “Information”: fraud-risk parameters and monitoring windows
Separately from the Data, Article 3 of the law and Articles 7 to 9 of the decree create a second layer: Informazioni on merchants and cards that show a risk of fraud. A firm notifies UCAMP that a monitoring period has opened when one of the Article 8 parameters is hit.
| Object | Parameter (Article 8) | Maximum monitoring period (Article 9) |
|---|---|---|
| Merchant | Five or more declined authorisation requests with different cards at the same point of sale within 24 hours | 15 days |
| Merchant | Three or more authorisation requests on the same card at the same point of sale within 24 hours | 15 days |
| Merchant | An authorisation request, approved or declined, more than 150% above the average transaction at that point of sale over the previous three months | 15 days |
| Card | Seven or more authorisation requests on the same card within 24 hours | 72 hours |
| Card | One or more requests that use up the card’s whole limit within 24 hours | 72 hours |
| Card | Two or more requests from different countries on the same card within 60 minutes | 72 hours |
Information is entered immediately after the monitoring period opens, and no later than the first working day after acquisition (Article 10(4)). At the end, the firm reports the outcome: for a merchant, “revocation” or “closed without further action”; for a card, “transaction not recognised by the cardholder” or “closed without further action”. UCAMP then reclassifies the record as Data or deletes it. If the firm reports no outcome, UCAMP deletes the record when the window expires.
5. Who can see what
Article 5 of the decree organises the archive in four levels: a public level (the list of reporting firms, card types and the legal framework, published on the MEF site); anonymised fraud statistics for reporting firms; the Data; and the Information. Reporting firms consult the Data without prior authorisation. Consulting other firms’ Information needs UCAMP authorisation, granted case by case to firms that have reported their own Information regularly and completely (Article 11). The police reach the archive through a link with the Interior Ministry’s data centre, governed by a 2012 convention between the two ministries. UCAMP can also query the Bank of Italy’s archive of stolen and lost cards, the same interbank alarm system described in our CAI article.
6. Worked scenarios
Scenario 1 — a dispute on a debit card. Facts: an EMI issues debit cards to Italian residents. On a Monday a cardholder disputes a EUR 640 online purchase and says the replacement card never arrived. Rule: Article 2(c) of the law and Article 6(c) of the decree, reason “card not received”; the two-working-day clock of Article 10(2). What the team does: the dispute workflow maps the internal reason code to the SIPAF reason and queues the record with card, PAN, merchant code and the details of the cardholder’s complaint if one was filed. The record is entered by Wednesday. Outcome: other issuers and acquirers see the merchant and terminal behind the fraud while it is still useful.
Scenario 2 — a merchant that trips the decline parameter. Facts: a payment institution acquiring for small merchants sees six declined authorisations with six different cards at one point of sale in an afternoon. Rule: Article 8(a)(1) opens a merchant monitoring period of up to 15 days; Information goes in by the next working day. What the team does: notifies UCAMP, enters the merchant identification set, and reviews the merchant during the window. The review finds card testing, and the acquirer terminates the agreement for security reasons. Outcome: the firm reports “revocation”, UCAMP turns the Information into Data under Article 6(b), and any acquirer that later signs the same merchant must report the renewed agreement under Article 6(d).
Scenario 3 — two countries in an hour. Facts: a card shows authorisation requests from Italy and Spain 40 minutes apart. Rule: Article 8(b)(3) opens a 72-hour card monitoring period. What the team does: enters the Information, contacts the cardholder, and learns that the Spanish request was a hotel pre-authorisation made by phone. Outcome: the firm reports “closed without further action” and the record is deleted. Had the cardholder denied the transaction, the outcome would be “not recognised” and the record would become Data.
7. SIPAF is not the PSD2 fraud return
Payment firms in Italy already report payment-fraud statistics to the Bank of Italy under the EBA fraud-reporting guidelines. That return is aggregated, prudential and periodic. SIPAF is transaction-level, operational and runs on a two-day clock. The two draw on the same dispute data, so build them from one source and reconcile counts; an inspector who sees 400 card-not-received cases in the half-year fraud return and 40 in SIPAF will ask why. See our pieces on the EBA fraud-reporting guidelines and on card-fraud typologies.
8. FAQ
Is SIPAF still in use after the move to SIMEC?
Yes. The MEF describes SIPAF as absorbed into SIMEC in 2017. The legal duties under Law 166/2005 and Decree 112/2007 are unchanged; the technical access point is the SIMEC “Area Carte”.
What is the deadline to report a disputed transaction?
As soon as the data are available and no later than the second working day after the firm acquires them (Article 10(2) of Decree 112/2007).
How long do records stay in the archive?
Data remain in the archive for three years (Article 13). Information is kept only for the monitoring period, then reclassified as Data or deleted.
Do payment institutions have to report?
Payment institutions that issue cards or run acceptance networks are named in Article 1(3) of Law 166/2005 since its amendment by Legislative Decree 90/2017.
Can we outsource the feed?
Article 2 of the decree allows a firm to act through another reporting company it delegates, provided integrity and confidentiality are protected. The firm still declares the arrangement in its accreditation form.
Who can see our reports?
Other reporting firms see the Data. They see Information only with UCAMP authorisation. The police have access through the Interior Ministry’s data centre for card-fraud crimes.
9. What to do, today
- Decide whether you are a reporting company: do you issue cards or acquire card payments in Italy? If unsure, write to UCAMP before launch.
- Send the accreditation form by PEC and name a referent who owns user access.
- Map your dispute and chargeback reason codes to the six SIPAF reasons.
- Build the two-working-day clock into the dispute workflow, with a daily exception report.
- Implement the six Article 8 parameters as monitoring rules, with the 15-day and 72-hour windows and outcome reporting.
- Reconcile SIPAF counts with the half-yearly fraud return to the Bank of Italy.
Related: CAI — the interbank alarm register · Card-fraud typologies · PSD2 fraud reporting


