Skip to content
Italy

SIPAF and SIMEC: card-fraud reporting to UCAMP in Italy

Fintech Passport
October 8, 2026 · 8-min read
SIPAF and SIMEC: card-fraud reporting to UCAMP in Italy

Italy runs a state card-fraud database that most foreign card issuers have never heard of. SIPAF — the computerised archive created by Law 166/2005 and run by the Ministry of Economy and Finance’s anti-fraud office, UCAMP — collects disputed card transactions, revoked merchants and tampered ATMs from the firms that issue and acquire cards. Since 2017 it lives inside SIMEC, the ministry’s euro-and-cards monitoring system. This piece covers who reports, what goes in, the two-working-day clock, the fraud-risk parameters that open a monitoring window, and how a payments firm builds the feed.

1. What SIPAF is

Law 17 August 2005, no. 166 set up a system for the administrative prevention of payment-card fraud at the Ministry of Economy and Finance (MEF). Prevention here means sharing data between issuers and acquirers so each can spot compromised merchants, cards and ATMs faster — not criminal investigation, which stays with the police and the courts.

The implementing rules are in Ministerial Decree 30 April 2007, no. 112, in force since 14 August 2007. It names the UCAMP (Ufficio centrale antifrode dei mezzi di pagamento) as the controller of the archive, sets the data items, the deadlines and the fraud-risk parameters, and creates a consultative working group, the GIPAF, in which ministries, the Bank of Italy, police experts and reporting firms take part. The MEF states that SIPAF was absorbed into SIMEC (Sistema di monitoraggio euro e carte) in 2017; firms now work in the SIMEC “Area Carte”, reached through the MEF services portal.

2. Who reports, and how you join

Article 1(3) of the law brings in the “reporting companies” (società segnalanti): companies, banks, payment institutions and financial intermediaries that issue payment cards and run card-acceptance networks. Payment institutions were added to the text by Legislative Decree 90/2017. E-money institutions are not named separately; an EMI issuing cards in Italy falls within the general reference to companies issuing payment cards, and should confirm its position with UCAMP before launch rather than assume it is out.

  • Accreditation. A firm joins by sending the accreditation form (Formulario) to UCAMP by certified e-mail (PEC). Paper submissions are no longer accepted; the current procedure has applied since 25 May 2023.
  • Referent. The form names an organisational referent, who creates and maintains the firm’s user accounts in the SIMEC reserved area. Leavers must be removed.
  • Delegation. Article 2 of the decree lets a firm meet its duties directly or through another reporting company it delegates, provided the delegation protects data integrity and confidentiality.
  • Manuals. The operating manuals for the data and information segments are available to accredited firms in the reserved area, not on the public site.
  • Exit. A firm that no longer meets the Article 1(3) conditions can ask to leave by a letter on company letterhead sent by PEC.

3. The “Data”: four categories and a two-day clock

Article 6 of the decree defines four categories of Dati. All are entered electronically as soon as available and no later than the second working day after the firm acquires them (Article 10(2)). They stay in the archive for three years (Article 13).

CategoryTriggerMain fields
Revoked merchants — 6(b)Acquirer revokes a merchant agreement for security reasons or after reporting the merchant to the judicial authorityMerchant code, trading name, company name, address, chamber-of-commerce number, VAT number, signatory and tax code, merchant category, POS terminal IDs, agreement and termination dates, reason, details of the criminal complaint
Disputed transactions — 6(c)Cardholder does not recognise a transaction or reports it to the judicial authorityCard number and expiry, date, amount and currency, acquirer ID, authorisation code, PAN, reason, merchant code, terminal ID or ATM code, details of the cardholder’s complaint
Renewed agreements — 6(d)A new agreement is signed with a merchant previously revokedNew merchant code and the same identification set, with the date of the earlier revocation
Tampered ATMs — 6(e)An ATM has been fraudulently manipulatedLocation, ATM identifiers and model, tampering method, PIN-capture method

The decree fixes six reasons for a disputed transaction: card stolen, card lost, card counterfeit, card not received, fraudulent use of the card number, and card used under a false identity. Mapping your own chargeback and dispute reason codes to these six is the first build task.

4. The “Information”: fraud-risk parameters and monitoring windows

Separately from the Data, Article 3 of the law and Articles 7 to 9 of the decree create a second layer: Informazioni on merchants and cards that show a risk of fraud. A firm notifies UCAMP that a monitoring period has opened when one of the Article 8 parameters is hit.

ObjectParameter (Article 8)Maximum monitoring period (Article 9)
MerchantFive or more declined authorisation requests with different cards at the same point of sale within 24 hours15 days
MerchantThree or more authorisation requests on the same card at the same point of sale within 24 hours15 days
MerchantAn authorisation request, approved or declined, more than 150% above the average transaction at that point of sale over the previous three months15 days
CardSeven or more authorisation requests on the same card within 24 hours72 hours
CardOne or more requests that use up the card’s whole limit within 24 hours72 hours
CardTwo or more requests from different countries on the same card within 60 minutes72 hours

Information is entered immediately after the monitoring period opens, and no later than the first working day after acquisition (Article 10(4)). At the end, the firm reports the outcome: for a merchant, “revocation” or “closed without further action”; for a card, “transaction not recognised by the cardholder” or “closed without further action”. UCAMP then reclassifies the record as Data or deletes it. If the firm reports no outcome, UCAMP deletes the record when the window expires.

5. Who can see what

Article 5 of the decree organises the archive in four levels: a public level (the list of reporting firms, card types and the legal framework, published on the MEF site); anonymised fraud statistics for reporting firms; the Data; and the Information. Reporting firms consult the Data without prior authorisation. Consulting other firms’ Information needs UCAMP authorisation, granted case by case to firms that have reported their own Information regularly and completely (Article 11). The police reach the archive through a link with the Interior Ministry’s data centre, governed by a 2012 convention between the two ministries. UCAMP can also query the Bank of Italy’s archive of stolen and lost cards, the same interbank alarm system described in our CAI article.

6. Worked scenarios

Scenario 1 — a dispute on a debit card. Facts: an EMI issues debit cards to Italian residents. On a Monday a cardholder disputes a EUR 640 online purchase and says the replacement card never arrived. Rule: Article 2(c) of the law and Article 6(c) of the decree, reason “card not received”; the two-working-day clock of Article 10(2). What the team does: the dispute workflow maps the internal reason code to the SIPAF reason and queues the record with card, PAN, merchant code and the details of the cardholder’s complaint if one was filed. The record is entered by Wednesday. Outcome: other issuers and acquirers see the merchant and terminal behind the fraud while it is still useful.

Scenario 2 — a merchant that trips the decline parameter. Facts: a payment institution acquiring for small merchants sees six declined authorisations with six different cards at one point of sale in an afternoon. Rule: Article 8(a)(1) opens a merchant monitoring period of up to 15 days; Information goes in by the next working day. What the team does: notifies UCAMP, enters the merchant identification set, and reviews the merchant during the window. The review finds card testing, and the acquirer terminates the agreement for security reasons. Outcome: the firm reports “revocation”, UCAMP turns the Information into Data under Article 6(b), and any acquirer that later signs the same merchant must report the renewed agreement under Article 6(d).

Scenario 3 — two countries in an hour. Facts: a card shows authorisation requests from Italy and Spain 40 minutes apart. Rule: Article 8(b)(3) opens a 72-hour card monitoring period. What the team does: enters the Information, contacts the cardholder, and learns that the Spanish request was a hotel pre-authorisation made by phone. Outcome: the firm reports “closed without further action” and the record is deleted. Had the cardholder denied the transaction, the outcome would be “not recognised” and the record would become Data.

7. SIPAF is not the PSD2 fraud return

Payment firms in Italy already report payment-fraud statistics to the Bank of Italy under the EBA fraud-reporting guidelines. That return is aggregated, prudential and periodic. SIPAF is transaction-level, operational and runs on a two-day clock. The two draw on the same dispute data, so build them from one source and reconcile counts; an inspector who sees 400 card-not-received cases in the half-year fraud return and 40 in SIPAF will ask why. See our pieces on the EBA fraud-reporting guidelines and on card-fraud typologies.

8. FAQ

Is SIPAF still in use after the move to SIMEC?

Yes. The MEF describes SIPAF as absorbed into SIMEC in 2017. The legal duties under Law 166/2005 and Decree 112/2007 are unchanged; the technical access point is the SIMEC “Area Carte”.

What is the deadline to report a disputed transaction?

As soon as the data are available and no later than the second working day after the firm acquires them (Article 10(2) of Decree 112/2007).

How long do records stay in the archive?

Data remain in the archive for three years (Article 13). Information is kept only for the monitoring period, then reclassified as Data or deleted.

Do payment institutions have to report?

Payment institutions that issue cards or run acceptance networks are named in Article 1(3) of Law 166/2005 since its amendment by Legislative Decree 90/2017.

Can we outsource the feed?

Article 2 of the decree allows a firm to act through another reporting company it delegates, provided integrity and confidentiality are protected. The firm still declares the arrangement in its accreditation form.

Who can see our reports?

Other reporting firms see the Data. They see Information only with UCAMP authorisation. The police have access through the Interior Ministry’s data centre for card-fraud crimes.

9. What to do, today

  • Decide whether you are a reporting company: do you issue cards or acquire card payments in Italy? If unsure, write to UCAMP before launch.
  • Send the accreditation form by PEC and name a referent who owns user access.
  • Map your dispute and chargeback reason codes to the six SIPAF reasons.
  • Build the two-working-day clock into the dispute workflow, with a daily exception report.
  • Implement the six Article 8 parameters as monitoring rules, with the 15-day and 72-hour windows and outcome reporting.
  • Reconcile SIPAF counts with the half-yearly fraud return to the Bank of Italy.

Related: CAI — the interbank alarm register · Card-fraud typologies · PSD2 fraud reporting

Related reads.