Mastercard SPME §2.2.6 · Jun 2022 → May 2023

Mandatory Compliance Requirements for Compromised Entities

substantive
⚠ Extraction warning — review against source PDF. One side of the Mastercard SPME text below appears to contain only the page-running header, not body content. This usually means the section heading fell on a page boundary and the body was attributed to a neighbouring section in the source PDF. The AI summary and proposed edit below may be misleading. Verify in: Jun 2022 · page 29 ↗ · May 2023 · page 29 ↗.

The updated rule states that Service Providers failing compliance will be automatically removed from the Mastercard SDP Compliant Registered Service Provider List and can be reinstated only after revalidating PCI DSS compliance and demonstrating adherence to the DESV appendix within 12 months.

Sources Mastercard SPME · Jun 2022 · page 29 PDF Mastercard SPME · May 2023 · page 29 PDF KYB Acquirer current
Also in §2.x this release substantive §2.2 Mastercard Site Data Protection (SDP) Program substantive §2.2.5 SDP Program Noncompliance Assessments substantive §2.3.1 Global Vendor Certification Program substantive §2.3.2 Additional Card Production Requirements substantive §2.4.1 PIN Entry Devices (PEDs) and Encrypting PIN Pads (EPPs)
Why these edits? The updated Mastercard rule imposes mandatory compliance requirements that a noncompliant service provider must be delisted and can only be reinstated after revalidating PCI DSS compliance and adherence to the DESV appendix, which affects the Acquirer KYB obligations related to service provider compliance verification and monitoring.
Mastercard SPME §2.2.6
This section was substantively restructured between versions (18% text overlap). Compare the texts directly below.
Before · Jun 2022 · page 29

Security Rules and Procedures—Merchant Edition • 22 February 2022

After · May 2023 · page 29

Security Rules and Procedures—Merchant Edition • 7 February 2023

forensic investigation will be automatically reclassified to become a Level 1 Service Provider. In addition, a Service Provider’s noncompliance will result in the automatic delisting from The Mastercard SDP Compliant Registered Service Provider List. A registered Service Provider may be placed back on the list only after the entity has re- validated compliance with the PCI DSS and has additionally demonstrated compliance with the DESV appendix of the PCI DSS within twelve (12) months from achieving full compliance with the PCI DSS as shown in Table 2.3.

Halyard Pay · 2 files
program: Acquirer KYB
- authority: Mastercard SPME §2.1
+ authority: Mastercard SPME §2.1, §2.2.6
required_documents:
- incorporation
- beneficial_ownership
- aml_screen
- license_verification
min_review_cycle_days: 365
suspension_trigger: document_collection_failure
record_retention_years: 7
aml_watchlist_sources:
- ofac_sdn
- eu_consolidated
agent_owner: kyb_agent
+ service_provider_compliance:
+ mandatory_delisting_on_noncompliance: true
+ reinstatement_requirements:
+ - revalidate_PCI_DSS_compliance
+ - demonstrate_DESV_appendix_compliance_within_12_months
+
+ # Added specific rules referencing Mastercard SPME §2.2.6 regarding service provider delisting and reinstatement requirements based on PCI DSS and DESV appendix compliance.

Acquirer KYB (Know Your Business) Obligations

Acquirers processing transactions on the Mastercard network are required to perform

Know Your Business (KYB) due diligence on merchants before onboarding and on a

recurring basis thereafter. Halyard Pay, as an acquirer, must collect and verify a

minimum set of documents for each merchant to establish business legitimacy, confirm

beneficial ownership, and satisfy anti-money laundering screening requirements.

When this policy applies

This policy applies to all new merchant onboarding and to all periodic re-verification

reviews. Merchants that fail to supply required documentation within the stipulated

period must be suspended from processing until compliance is restored.

Required actions

  1. Collect all required KYB documents at onboarding prior to approval.

  2. Conduct AML screening against applicable watchlists before approval.

  3. Verify business licenses for regulated merchant categories.

  4. Schedule a full re-verification review at least once every 365 days.

  5. Document all verification outcomes and retain records for audit purposes.

6. Verify that all associated service providers maintain PCI DSS compliance and meet the updated requirements related to the DESV appendix; noncompliance must be flagged and reported, with service providers delisted if necessary until compliance is re-validated.

Source authority: Mastercard SPME §2.1.2.1 and 2.2.6.

policies/kyb_acquirer/policy.md — after applying change

Acquirer KYB (Know Your Business) Obligations

Acquirers processing transactions on the Mastercard network are required to perform

Know Your Business (KYB) due diligence on merchants before onboarding and on a

recurring basis thereafter. Halyard Pay, as an acquirer, must collect and verify a

minimum set of documents for each merchant to establish business legitimacy, confirm

beneficial ownership, and satisfy anti-money laundering screening requirements.

When this policy applies

This policy applies to all new merchant onboarding and to all periodic re-verification

reviews. Merchants that fail to supply required documentation within the stipulated

period must be suspended from processing until compliance is restored.

Required actions

  1. Collect all required KYB documents at onboarding prior to approval.

  2. Conduct AML screening against applicable watchlists before approval.

  3. Verify business licenses for regulated merchant categories.

  4. Schedule a full re-verification review at least once every 365 days.

  5. Document all verification outcomes and retain records for audit purposes.

6. Verify that all associated service providers maintain PCI DSS compliance and meet the updated requirements related to the DESV appendix; noncompliance must be flagged and reported, with service providers delisted if necessary until compliance is re-validated.

Source authority: Mastercard SPME §2.1.2.1 and 2.2.6.

Source authority: Mastercard SPME §2.2.6.

--- a/policies/kyb_acquirer/rules.yaml
+++ b/policies/kyb_acquirer/rules.yaml
@@ -1,5 +1,5 @@
 program: Acquirer KYB
-authority: Mastercard SPME §2.1
+authority: Mastercard SPME §2.1, §2.2.6
 required_documents:
   - incorporation
   - beneficial_ownership
@@ -12,3 +12,10 @@
   - ofac_sdn
   - eu_consolidated
 agent_owner: kyb_agent
+service_provider_compliance:
+  mandatory_delisting_on_noncompliance: true
+  reinstatement_requirements:
+    - revalidate_PCI_DSS_compliance
+    - demonstrate_DESV_appendix_compliance_within_12_months
+
+# Added specific rules referencing Mastercard SPME §2.2.6 regarding service provider delisting and reinstatement requirements based on PCI DSS and DESV appendix compliance.
--- a/policies/kyb_acquirer/policy.md
+++ b/policies/kyb_acquirer/policy.md
@@ -19,5 +19,6 @@
 3. Verify business licenses for regulated merchant categories.
 4. Schedule a full re-verification review at least once every 365 days.
 5. Document all verification outcomes and retain records for audit purposes.
+6. Verify that all associated service providers maintain PCI DSS compliance and meet the updated requirements related to the DESV appendix; noncompliance must be flagged and reported, with service providers delisted if necessary until compliance is re-validated.
 
-Source authority: Mastercard SPME §2.1.
+Source authority: Mastercard SPME 2.1 and 2.2.6.