Mastercard SPME §2.2 · Jun 2022 → May 2023

Mastercard Site Data Protection (SDP) Program

substantive

The update adds 'Merchant Payment Gateways (MPGs)' to the list of entities classified as Service Providers under the SDP Program, making them subject to the same compliance requirements as other Service Providers.

Sources Mastercard SPME · Jun 2022 · page 18 PDF Mastercard SPME · May 2023 · page 18 PDF Fraud Monitoring current
Also in §2.x this release substantive §2.2.5 SDP Program Noncompliance Assessments substantive §2.2.6 Mandatory Compliance Requirements for Compromised Entities substantive §2.3.1 Global Vendor Certification Program substantive §2.3.2 Additional Card Production Requirements substantive §2.4.1 PIN Entry Devices (PEDs) and Encrypting PIN Pads (EPPs)
Why these edits? The inclusion of Merchant Payment Gateways (MPGs) as Service Providers under the SDP Program introduces an expanded scope of entities that must comply with PCI DSS standards, affecting the fraud monitoring controls related to service provider compliance.
Mastercard SPME §2.2
Security Rules and Procedures—Merchant Edition • 22 7 February 2022 2023 compliance with the PCI Security Standards. The SDP Program is designed to help Customers, Merchants, and Service Providers (Third Party Processors [TPPs], Data Storage Entities [DSEs], Payment Facilitators [PFs], Staged Digital Wallet Operators [SDWOs], Digital Activity Service Providers [DASPs], Token Service Providers [TSPs], Terminal Servicers [TSs], AML/Sanctions Service Providers, 3-D Secure Service Providers [3-DSSPs], and Installment Service Providers [ISPs]) , and Merchant Payment Gateways [MPGs]) protect against Account Data Compromise (ADC) Events. NOTE: For the purposes of the SDP Program, TPPs, DSEs, PFs, SDWOs, DASPs, TSPs, TSs, AML/Sanctions Service Providers, 3-DSSPs, and ISPs ISPs, and MPGs are collectively referred to as “Service Providers” in this chapter. Refer to section 10.1 of this manual for the definitions of an Account Data Compromise Event and a Potential Account Data Compromise Event. Compliance with the Payment Card Industry Data Security Standard (PCI DSS) and all other applicable PCI Security Standards is required for all Issuers, Acquirers, Merchants, Service Providers, and any other person or entity that a Customer permits, directly or indirectly, to store, transmit, or process Account Data. Only Merchants and Service Providers must validate their compliance to Mastercard, as set forth in sections 2.2.2 and 2.2.3 respectively, in order to be deemed compliant with the Mastercard SDP Program. Mastercard has sole discretion to interpret and enforce the SDP Program Standards.
Halyard Pay · 2 files
program: Fraud Monitoring
- authority: Mastercard SPME §3.7
+ authority: Mastercard SPME 2.2, 3.7
fraud_to_sales_ratio_threshold: 0.015
min_count_per_month: 100
monitoring_cadence: monthly
escalation_actions:
- escalate_to_human_review
- notify_acquirer
lookback_period_months: 1
remediation_review_interval_days: 30
agent_owner: fraud_ops_agent
+
+ # Updated authority to reference expanded SDP Program scope including Merchant Payment Gateways (MPGs) as Service Providers per Mastercard SPME Section 2.2 update.
+ # This expansion affects the coverage of entities monitored in fraud and compliance controls.

Fraud Monitoring

Halyard Pay monitors merchant fraud activity on a monthly basis to detect patterns that

exceed Mastercard's acceptable fraud-to-sales thresholds. A merchant whose rolling

monthly fraud-to-sales ratio meets or exceeds 1.5% (0.015) and whose fraud count

reaches at least 100 transactions in that same month triggers mandatory escalation

under this policy.

When this policy applies

This policy applies to all merchants processed through Halyard Pay's acquiring platform

where Mastercard is the applicable card network. It governs both card-present and

card-not-present transaction streams. Furthermore, as Mastercard's SDP Program now

explicitly includes Merchant Payment Gateways (MPGs) among Service Providers

(see Mastercard SPME §2.2, updated 2023), Halyard Pay will incorporate due diligence and

compliance monitoring to ensure these entities meet PCI DSS and related security standards,

which supports overall fraud risk mitigation.

Required actions

  1. Compute the merchant's rolling fraud-to-sales ratio each calendar month.

  2. If the ratio meets or exceeds the threshold AND the minimum count is reached,

escalate the merchant account to human review immediately.

  1. Notify the acquiring compliance officer and document the case ID with supporting

transaction data.

  1. Track case progress until the account returns to threshold compliance or is

terminated.

5. Include Merchant Payment Gateways in the scope of service provider compliance

monitoring as mandated by the Mastercard SDP Program, verifying PCI DSS adherence

and addressing any security deficiencies.

Source authority: Mastercard SPME §3.7.§3.7, §2.2.

policies/fraud_monitoring/policy.md — after applying change

Fraud Monitoring

Halyard Pay monitors merchant fraud activity on a monthly basis to detect patterns that

exceed Mastercard's acceptable fraud-to-sales thresholds. A merchant whose rolling

monthly fraud-to-sales ratio meets or exceeds 1.5% (0.015) and whose fraud count

reaches at least 100 transactions in that same month triggers mandatory escalation

under this policy.

When this policy applies

This policy applies to all merchants processed through Halyard Pay's acquiring platform

where Mastercard is the applicable card network. It governs both card-present and

card-not-present transaction streams. Furthermore, as Mastercard's SDP Program now

explicitly includes Merchant Payment Gateways (MPGs) among Service Providers

(see Mastercard SPME §2.2, updated 2023), Halyard Pay will incorporate due diligence and

compliance monitoring to ensure these entities meet PCI DSS and related security standards,

which supports overall fraud risk mitigation.

Required actions

  1. Compute the merchant's rolling fraud-to-sales ratio each calendar month.

  2. If the ratio meets or exceeds the threshold AND the minimum count is reached,

escalate the merchant account to human review immediately.

  1. Notify the acquiring compliance officer and document the case ID with supporting

transaction data.

  1. Track case progress until the account returns to threshold compliance or is

terminated.

5. Include Merchant Payment Gateways in the scope of service provider compliance

monitoring as mandated by the Mastercard SDP Program, verifying PCI DSS adherence

and addressing any security deficiencies.

Source authority: Mastercard SPME §3.7.§3.7, §2.2.

Source authority: Mastercard SPME §2.2.

--- a/policies/fraud_monitoring/rules.yaml
+++ b/policies/fraud_monitoring/rules.yaml
@@ -1,5 +1,5 @@
 program: Fraud Monitoring
-authority: Mastercard SPME §3.7
+authority: Mastercard SPME 2.2, 3.7
 fraud_to_sales_ratio_threshold: 0.015
 min_count_per_month: 100
 monitoring_cadence: monthly
@@ -9,3 +9,6 @@
 lookback_period_months: 1
 remediation_review_interval_days: 30
 agent_owner: fraud_ops_agent
+
+# Updated authority to reference expanded SDP Program scope including Merchant Payment Gateways (MPGs) as Service Providers per Mastercard SPME Section 2.2 update.
+# This expansion affects the coverage of entities monitored in fraud and compliance controls.
--- a/policies/fraud_monitoring/policy.md
+++ b/policies/fraud_monitoring/policy.md
@@ -10,7 +10,11 @@
 
 This policy applies to all merchants processed through Halyard Pay's acquiring platform
 where Mastercard is the applicable card network. It governs both card-present and
-card-not-present transaction streams.
+card-not-present transaction streams. Furthermore, as Mastercard's SDP Program now
+explicitly includes Merchant Payment Gateways (MPGs) among Service Providers
+(see Mastercard SPME §2.2, updated 2023), Halyard Pay will incorporate due diligence and
+compliance monitoring to ensure these entities meet PCI DSS and related security standards,
+which supports overall fraud risk mitigation.
 
 ## Required actions
 
@@ -21,5 +25,8 @@
    transaction data.
 4. Track case progress until the account returns to threshold compliance or is
    terminated.
+5. Include Merchant Payment Gateways in the scope of service provider compliance
+   monitoring as mandated by the Mastercard SDP Program, verifying PCI DSS adherence
+   and addressing any security deficiencies.
 
-Source authority: Mastercard SPME §3.7.
+Source authority: Mastercard SPME §3.7, §2.2.