Mastercard SPME §11.1.1 · Jun 2022 → May 2023

System Features

substantive

The updated section removes references to associate business owners and Service Provider names, limits information to principal owners only, and adds a requirement for the inquiring Acquirer to decide on further investigation or measures after accessing MATCH data.

Sources Mastercard SPME · Jun 2022 · page 131 PDF Mastercard SPME · May 2023 · page 141 PDF Fraud Monitoring current
Also in §11.x this release substantive §11.2 MATCH Standards substantive §11.2.1 Certification substantive §11.2.6 MATCH Record Retention substantive §11.4 Merchant Removal from MATCH substantive §11.5 MATCH Reason Codes
Why these edits? The update restricts MATCH data reporting to principal owners only, removing associate owners and Service Provider names, and imposes a new obligation on inquiring Acquirers to decide on further investigation or measures after accessing MATCH data, affecting how fraud risk monitoring is conducted.
Mastercard SPME §11.1.1
MATCH uses Customer-reported information regarding Merchants and their principal owners to offer Acquirers the following fraud detection features and options for assessing risk: • Acquirers may add and search for information regarding up to five principal and ¶ associate business owners for each Merchant. ¶ • ¶ Acquirers may designate regions and countries for database searches. • MATCH uses multiple fields to determine possible matches. • MATCH edits specific fields of data and reduces processing delays by notifying inquiring Customers of errors as records are processed. • MATCH supports retroactive alert processing of data residing on the database for up to 360 days. • Acquirers determine whether they want to receive inquiry matches, and if so, the type of information that the system returns. • MATCH processes data submitted by Acquirers once a day and provides daily ¶ detail response files. ¶ • ¶ Acquirers may add the name of the Service Provider associated with signing the ¶ Merchant. ¶ • ¶ Acquirers may Acquirers may also access MATCH data in real time using MATCH Online or the Open Application Programming Interface (Open API). • Acquirers may submit and receive bulk data using Batch and Import file operations. • Acquirers may add and search for information regarding Merchant uniform resource locator (URL) website addresses. Through direct communication with the listing Acquirer, the MATCH system, an inquiring Acquirer may determine whether the Merchant inquired of is the same Merchant previously reported to MATCH, terminated, or inquired about within the past 360 days. The inquiring Acquirer must then determine whether additional investigation is appropriate, or if it should take other measures to address risk issues. MATCH System
Halyard Pay · 2 files
program: Fraud Monitoring
- authority: Mastercard SPME §3.7
+ authority: Mastercard SPME §3.7, §11.1.1
fraud_to_sales_ratio_threshold: 0.015
min_count_per_month: 100
monitoring_cadence: monthly
escalation_actions:
- escalate_to_human_review
- notify_acquirer
lookback_period_months: 1
remediation_review_interval_days: 30
agent_owner: fraud_ops_agent
+
+ # MATCH fraud detection features are limited to principal owners only; associate owners and Service Provider name reporting are removed per SPME §11.1.1.
+ # Acquirers may add and search for information on up to five principal owners per Merchant.
+ # Multiple data fields are used to determine matches; MATCH supports editing and error notification to reduce delays.
+ # Retroactive alert processing is supported for data up to 360 days old.
+ # Acquirers control receipt and detail of inquiry match information.
+ # Real-time access via MATCH Online and API, and batch operations remain available.
+ # Merchant URL information may be added and searched.
+ # Crucially, after obtaining MATCH inquiry results, Acquirers must assess whether further investigation or risk mitigation actions are warranted, per updated SPME requirements.

Fraud Monitoring

Halyard Pay monitors merchant fraud activity and leverages Mastercard's MATCH system for enhanced fraud risk assessment on a monthly basis to detect patterns that ¶ exceed Mastercard's acceptable fraud-to-sales thresholds. A merchant whose rolling ¶ monthly fraud-to-sales ratio meets or exceeds 1.5% (0.015) and whose fraud count ¶ reaches at least 100 transactions in that same month triggers mandatory escalation ¶ under this policy. merchants processed through our platform.

When this policy applies

This policy applies to all merchants processed through by Halyard Pay's acquiring platform ¶ Pay where Mastercard is the applicable card network. It governs network, covering both card-present and card-not-present transaction streams. transactions.

Required actions

  1. Compute the merchant's rolling fraud-to-sales ratio each calendar month.

  2. If the ratio meets or exceeds 1.5% and the threshold AND the minimum fraud count is reached, ¶ reaches at least 100 transactions in that month, escalate the merchant account to human review immediately.

  3. Utilize Mastercard's MATCH system data focusing on principal owners only, as per the updated Mastercard SPME guidelines. Do not consider associate owners or Service Provider names in fraud assessments.

4. After accessing MATCH data, conduct a risk assessment to determine whether further investigation or additional measures are warranted.

5. Notify the acquiring compliance officer and document the case ID with supporting transaction data.

4. 6. Track case progress until the account returns to threshold compliance or is terminated.

Source authority: Mastercard SPME §3.7.§3.7 and §11.1.1.

policies/fraud_monitoring/policy.md — after applying change

Fraud Monitoring

Halyard Pay monitors merchant fraud activity and leverages Mastercard's MATCH system for enhanced fraud risk assessment on a monthly basis to detect patterns that ¶ exceed Mastercard's acceptable fraud-to-sales thresholds. A merchant whose rolling ¶ monthly fraud-to-sales ratio meets or exceeds 1.5% (0.015) and whose fraud count ¶ reaches at least 100 transactions in that same month triggers mandatory escalation ¶ under this policy. merchants processed through our platform.

When this policy applies

This policy applies to all merchants processed through by Halyard Pay's acquiring platform ¶ Pay where Mastercard is the applicable card network. It governs network, covering both card-present and card-not-present transaction streams. transactions.

Required actions

  1. Compute the merchant's rolling fraud-to-sales ratio each calendar month.

  2. If the ratio meets or exceeds 1.5% and the threshold AND the minimum fraud count is reached, ¶ reaches at least 100 transactions in that month, escalate the merchant account to human review immediately.

  3. Utilize Mastercard's MATCH system data focusing on principal owners only, as per the updated Mastercard SPME guidelines. Do not consider associate owners or Service Provider names in fraud assessments.

4. After accessing MATCH data, conduct a risk assessment to determine whether further investigation or additional measures are warranted.

5. Notify the acquiring compliance officer and document the case ID with supporting transaction data.

4. 6. Track case progress until the account returns to threshold compliance or is terminated.

Source authority: Mastercard SPME §3.7.§3.7 and §11.1.1.

Source authority: Mastercard SPME §11.1.1.

--- a/policies/fraud_monitoring/rules.yaml
+++ b/policies/fraud_monitoring/rules.yaml
@@ -1,5 +1,5 @@
 program: Fraud Monitoring
-authority: Mastercard SPME §3.7
+authority: Mastercard SPME §3.7, §11.1.1
 fraud_to_sales_ratio_threshold: 0.015
 min_count_per_month: 100
 monitoring_cadence: monthly
@@ -9,3 +9,12 @@
 lookback_period_months: 1
 remediation_review_interval_days: 30
 agent_owner: fraud_ops_agent
+
+# MATCH fraud detection features are limited to principal owners only; associate owners and Service Provider name reporting are removed per SPME §11.1.1.
+# Acquirers may add and search for information on up to five principal owners per Merchant.
+# Multiple data fields are used to determine matches; MATCH supports editing and error notification to reduce delays.
+# Retroactive alert processing is supported for data up to 360 days old.
+# Acquirers control receipt and detail of inquiry match information.
+# Real-time access via MATCH Online and API, and batch operations remain available.
+# Merchant URL information may be added and searched.
+# Crucially, after obtaining MATCH inquiry results, Acquirers must assess whether further investigation or risk mitigation actions are warranted, per updated SPME requirements.

--- a/policies/fraud_monitoring/policy.md
+++ b/policies/fraud_monitoring/policy.md
@@ -1,25 +1,18 @@
 # Fraud Monitoring
 
-Halyard Pay monitors merchant fraud activity on a monthly basis to detect patterns that
-exceed Mastercard's acceptable fraud-to-sales thresholds. A merchant whose rolling
-monthly fraud-to-sales ratio meets or exceeds 1.5% (0.015) and whose fraud count
-reaches at least 100 transactions in that same month triggers mandatory escalation
-under this policy.
+Halyard Pay monitors merchant fraud activity and leverages Mastercard's MATCH system for enhanced fraud risk assessment on merchants processed through our platform.
 
 ## When this policy applies
 
-This policy applies to all merchants processed through Halyard Pay's acquiring platform
-where Mastercard is the applicable card network. It governs both card-present and
-card-not-present transaction streams.
+This policy applies to all merchants processed by Halyard Pay where Mastercard is the applicable network, covering both card-present and card-not-present transactions.
 
 ## Required actions
 
 1. Compute the merchant's rolling fraud-to-sales ratio each calendar month.
-2. If the ratio meets or exceeds the threshold AND the minimum count is reached,
-   escalate the merchant account to human review immediately.
-3. Notify the acquiring compliance officer and document the case ID with supporting
-   transaction data.
-4. Track case progress until the account returns to threshold compliance or is
-   terminated.
+2. If the ratio meets or exceeds 1.5% and the fraud count reaches at least 100 transactions in that month, escalate the merchant account to human review immediately.
+3. Utilize Mastercard's MATCH system data focusing on principal owners only, as per the updated Mastercard SPME guidelines. Do not consider associate owners or Service Provider names in fraud assessments.
+4. After accessing MATCH data, conduct a risk assessment to determine whether further investigation or additional measures are warranted.
+5. Notify the acquiring compliance officer and document the case ID with supporting transaction data.
+6. Track case progress until the account returns to threshold compliance or is terminated.
 
-Source authority: Mastercard SPME §3.7.
+Source authority: Mastercard SPME §3.7 and §11.1.1.