Mastercard SPME §2.2.5 · Jun 2022 → May 2023

SDP Program Noncompliance Assessments

substantive

The section was significantly reduced, removing detailed forensic investigation and compliance evidence submission requirements. It now focuses on consequences such as listing removal or customer termination for noncompliance, referencing Mastercard Rules for specific enforcement actions and penalties related to late or missing compliance reports.

Sources Mastercard SPME · Jun 2022 · page 29 PDF Mastercard SPME · May 2023 · page 28 PDF KYB Acquirer current
Also in §2.x this release substantive §2.2 Mastercard Site Data Protection (SDP) Program substantive §2.2.6 Mandatory Compliance Requirements for Compromised Entities substantive §2.3.1 Global Vendor Certification Program substantive §2.3.2 Additional Card Production Requirements substantive §2.4.1 PIN Entry Devices (PEDs) and Encrypting PIN Pads (EPPs)
Why these edits? The updated section 2.2.5 shifts focus from specific forensic investigation and compliance evidence submissions to enforcement actions, including penalties and termination rights tied to issuer and acquirer obligations under Mastercard Rules, impacting Acquirer KYB obligations.
Mastercard SPME §2.2.5
This section was substantively restructured between versions (6% text overlap). Compare the texts directly below.
Before · Jun 2022 · page 29

Security Rules and Procedures—Merchant Edition • 22 February 2022

At the conclusion of the forensic investigation, Mastercard will provide a Mastercard Site Data Protection (SDP) Account Data Compromise Information Form for completion by the compromised entity itself, if the compromised entity is a Service Provider, or by its Acquirer, if the compromised entity is a Merchant. The form must be returned by email message to pci_adc@mastercard.com within 30 calendar days of its receipt, and must include:

  • The names of the the forensic investigator, QSA and the Approved Scanning Vendor (ASV);
  • The entity’s current level of compliance; and
  • A gap analysis providing detailed steps required for the entity to achieve full compliance. As soon as practical, but no later than 60 calendar days from the conclusion of the forensic nvestigation, the compromised entity or its Acquirer must provide evidence from a QSA and an ASV that the compromised entity has achieved full compliance with the PCI DSS and if applicable, the PCI TSP Security Requirements or the PCI 3DS Core Security Standard. Such evidence (a completed PCI DSS AOC produced after a successful PCI DSS assessment resulting in the completion of a ROC conducted by a PCI SSC- approved QSA and a network scan AOC conducted by a PCI SSC-approved ASV) must be submitted to Mastercard by email message to pci_adc@mastercard.com. Failure to comply with these requirements may result in SDP noncompliance assessments as described in section 2.2.5. Any Merchant that has suffered a confirmed ADC Event will be automatically reclassified to become a Level 1 Merchant. Any Service Provider that has a confirmed ADC Event, adverse inference (see section 10.3), and/or noncompliance for failure to cooperate in an ADC Event or forensic investigation will be automatically reclassified to become a Level 1 Service Provider. In addition, if the compromised entity is a Service Provider, the Service Provider must demonstrate to Mastercard its compliance with the DESV appendix of the PCI DSS within twelve (12) months from achieving full compliance with the PCI DSS. NOTE: A confirmed ADC Event, adverse inference, and/or noncompliance for failure to cooperate in an ADC Event or forensic investigation will result in the automatic delisting of a Service Provider from The Mastercard SDP Compliant Registered Service Provider List. A registered Service Provider may be placed back on the list only after the entity has re- validated compliance with the PCI DSS and has additionally demonstrated compliance with the DESV appendix of the PCI DSS. Cybersecurity Standards and Programs
After · May 2023 · page 28

Security Rules and Procedures—Merchant Edition • 7 February 2023

SDP Compliant Registered Service Provider List; or termination of the Issuer or Acquirer as a Customer as provided in Rule 2.1.2 of the Mastercard Rules manual. Late SDP Acquirer Submission and Compliance Status Forms for semi-annual merchant compliance reporting submissions or failure to submit the required form(s) may result in an additional assessment to the Customer as described for Category A violations in Rule 2.1.4 of the Mastercard Rules manual.

Halyard Pay · 2 files
program: Acquirer KYB
- authority: Mastercard SPME §2.1
+ authority: Mastercard SPME 2.1, 2.2.5
required_documents:
- incorporation
- beneficial_ownership
- aml_screen
- license_verification
min_review_cycle_days: 365
suspension_trigger: document_collection_failure
record_retention_years: 7
aml_watchlist_sources:
- ofac_sdn
- eu_consolidated
agent_owner: kyb_agent
+
+ # Updated to reflect Mastercard SPME §2.2.5 enforcement approach, emphasizing potential penalties including additional assessments and termination rights under Mastercard Rules for late or incomplete submissions relating to merchant compliance reporting.

Acquirer KYB (Know Your Business) Obligations

Acquirers processing transactions on the Mastercard network are required to perform

Know Your Business (KYB) due diligence on merchants before onboarding and on a

recurring basis thereafter. Halyard Pay, as an acquirer, must collect and verify a

minimum set of documents for each merchant to establish business legitimacy, confirm

beneficial ownership, and satisfy anti-money laundering screening requirements.

When this policy applies

This policy applies to all new merchant onboarding and to all periodic re-verification

reviews. Merchants that fail to supply required documentation within the stipulated

period must be suspended from processing until compliance is restored.

Required actions

  1. Collect all required KYB documents at onboarding prior to approval.

  2. Conduct AML screening against applicable watchlists before approval.

  3. Verify business licenses for regulated merchant categories.

  4. Schedule a full re-verification review at least once every 365 days.

  5. Document all verification outcomes and retain records for audit purposes.

## Enforcement and Compliance

Failure by Acquirers or Merchants to comply with Mastercard’s KYB requirements, including timely submission of compliance reporting forms and adherence to Mastercard network rules, may result in penalties, automatic reclassification to higher risk levels, or termination rights as outlined under Mastercard Rules (see section 2.2.5). Halyard Pay must ensure ongoing adherence to these enforcement actions as part of our compliance management.

Source authority: Mastercard SPME §2.1.��������2.1, 2.2.5.

policies/kyb_acquirer/policy.md — after applying change

Acquirer KYB (Know Your Business) Obligations

Acquirers processing transactions on the Mastercard network are required to perform

Know Your Business (KYB) due diligence on merchants before onboarding and on a

recurring basis thereafter. Halyard Pay, as an acquirer, must collect and verify a

minimum set of documents for each merchant to establish business legitimacy, confirm

beneficial ownership, and satisfy anti-money laundering screening requirements.

When this policy applies

This policy applies to all new merchant onboarding and to all periodic re-verification

reviews. Merchants that fail to supply required documentation within the stipulated

period must be suspended from processing until compliance is restored.

Required actions

  1. Collect all required KYB documents at onboarding prior to approval.

  2. Conduct AML screening against applicable watchlists before approval.

  3. Verify business licenses for regulated merchant categories.

  4. Schedule a full re-verification review at least once every 365 days.

  5. Document all verification outcomes and retain records for audit purposes.

## Enforcement and Compliance

Failure by Acquirers or Merchants to comply with Mastercard’s KYB requirements, including timely submission of compliance reporting forms and adherence to Mastercard network rules, may result in penalties, automatic reclassification to higher risk levels, or termination rights as outlined under Mastercard Rules (see section 2.2.5). Halyard Pay must ensure ongoing adherence to these enforcement actions as part of our compliance management.

Source authority: Mastercard SPME §2.1.��������2.1, 2.2.5.

Source authority: Mastercard SPME §2.2.5.

--- a/policies/kyb_acquirer/rules.yaml
+++ b/policies/kyb_acquirer/rules.yaml
@@ -1,5 +1,5 @@
 program: Acquirer KYB
-authority: Mastercard SPME §2.1
+authority: Mastercard SPME 2.1, 2.2.5
 required_documents:
   - incorporation
   - beneficial_ownership
@@ -12,3 +12,5 @@
   - ofac_sdn
   - eu_consolidated
 agent_owner: kyb_agent
+
+# Updated to reflect Mastercard SPME §2.2.5 enforcement approach, emphasizing potential penalties including additional assessments and termination rights under Mastercard Rules for late or incomplete submissions relating to merchant compliance reporting.
--- a/policies/kyb_acquirer/policy.md
+++ b/policies/kyb_acquirer/policy.md
@@ -20,4 +20,8 @@
 4. Schedule a full re-verification review at least once every 365 days.
 5. Document all verification outcomes and retain records for audit purposes.
 
-Source authority: Mastercard SPME §2.1.
+## Enforcement and Compliance
+
+Failure by Acquirers or Merchants to comply with Mastercard’s KYB requirements, including timely submission of compliance reporting forms and adherence to Mastercard network rules, may result in penalties, automatic reclassification to higher risk levels, or termination rights as outlined under Mastercard Rules (see section 2.2.5). Halyard Pay must ensure ongoing adherence to these enforcement actions as part of our compliance management.
+
+Source authority: Mastercard SPME 2.1, 2.2.5.