Mastercard SPME §2.2 · Jun 2022 → May 2023
Mastercard Site Data Protection (SDP) Program
The update adds 'Merchant Payment Gateways (MPGs)' to the list of entities classified as Service Providers under the SDP Program, making them subject to the same compliance requirements as other Service Providers.
program: Fraud Monitoring- authority: Mastercard SPME §3.7+ authority: Mastercard SPME 2.2, 3.7fraud_to_sales_ratio_threshold: 0.015min_count_per_month: 100monitoring_cadence: monthlyescalation_actions:- escalate_to_human_review- notify_acquirerlookback_period_months: 1remediation_review_interval_days: 30agent_owner: fraud_ops_agent++ # Updated authority to reference expanded SDP Program scope including Merchant Payment Gateways (MPGs) as Service Providers per Mastercard SPME Section 2.2 update.+ # This expansion affects the coverage of entities monitored in fraud and compliance controls.
Fraud Monitoring
Halyard Pay monitors merchant fraud activity on a monthly basis to detect patterns that
exceed Mastercard's acceptable fraud-to-sales thresholds. A merchant whose rolling
monthly fraud-to-sales ratio meets or exceeds 1.5% (0.015) and whose fraud count
reaches at least 100 transactions in that same month triggers mandatory escalation
under this policy.
When this policy applies
This policy applies to all merchants processed through Halyard Pay's acquiring platform
where Mastercard is the applicable card network. It governs both card-present and
card-not-present transaction streams. Furthermore, as Mastercard's SDP Program now
explicitly includes Merchant Payment Gateways (MPGs) among Service Providers
(see Mastercard SPME §2.2, updated 2023), Halyard Pay will incorporate due diligence and
compliance monitoring to ensure these entities meet PCI DSS and related security standards,
which supports overall fraud risk mitigation.
Required actions
-
Compute the merchant's rolling fraud-to-sales ratio each calendar month.
-
If the ratio meets or exceeds the threshold AND the minimum count is reached,
escalate the merchant account to human review immediately.
- Notify the acquiring compliance officer and document the case ID with supporting
transaction data.
- Track case progress until the account returns to threshold compliance or is
terminated.
5. Include Merchant Payment Gateways in the scope of service provider compliance
monitoring as mandated by the Mastercard SDP Program, verifying PCI DSS adherence
and addressing any security deficiencies.
Source authority: Mastercard SPME §3.7.§3.7, §2.2.
Fraud Monitoring
Halyard Pay monitors merchant fraud activity on a monthly basis to detect patterns that
exceed Mastercard's acceptable fraud-to-sales thresholds. A merchant whose rolling
monthly fraud-to-sales ratio meets or exceeds 1.5% (0.015) and whose fraud count
reaches at least 100 transactions in that same month triggers mandatory escalation
under this policy.
When this policy applies
This policy applies to all merchants processed through Halyard Pay's acquiring platform
where Mastercard is the applicable card network. It governs both card-present and
card-not-present transaction streams. Furthermore, as Mastercard's SDP Program now
explicitly includes Merchant Payment Gateways (MPGs) among Service Providers
(see Mastercard SPME §2.2, updated 2023), Halyard Pay will incorporate due diligence and
compliance monitoring to ensure these entities meet PCI DSS and related security standards,
which supports overall fraud risk mitigation.
Required actions
-
Compute the merchant's rolling fraud-to-sales ratio each calendar month.
-
If the ratio meets or exceeds the threshold AND the minimum count is reached,
escalate the merchant account to human review immediately.
- Notify the acquiring compliance officer and document the case ID with supporting
transaction data.
- Track case progress until the account returns to threshold compliance or is
terminated.
5. Include Merchant Payment Gateways in the scope of service provider compliance
monitoring as mandated by the Mastercard SDP Program, verifying PCI DSS adherence
and addressing any security deficiencies.
Source authority: Mastercard SPME §3.7.§3.7, §2.2.
Source authority: Mastercard SPME §2.2.
--- a/policies/fraud_monitoring/rules.yaml
+++ b/policies/fraud_monitoring/rules.yaml
@@ -1,5 +1,5 @@
program: Fraud Monitoring
-authority: Mastercard SPME §3.7
+authority: Mastercard SPME 2.2, 3.7
fraud_to_sales_ratio_threshold: 0.015
min_count_per_month: 100
monitoring_cadence: monthly
@@ -9,3 +9,6 @@
lookback_period_months: 1
remediation_review_interval_days: 30
agent_owner: fraud_ops_agent
+
+# Updated authority to reference expanded SDP Program scope including Merchant Payment Gateways (MPGs) as Service Providers per Mastercard SPME Section 2.2 update.
+# This expansion affects the coverage of entities monitored in fraud and compliance controls.
--- a/policies/fraud_monitoring/policy.md
+++ b/policies/fraud_monitoring/policy.md
@@ -10,7 +10,11 @@
This policy applies to all merchants processed through Halyard Pay's acquiring platform
where Mastercard is the applicable card network. It governs both card-present and
-card-not-present transaction streams.
+card-not-present transaction streams. Furthermore, as Mastercard's SDP Program now
+explicitly includes Merchant Payment Gateways (MPGs) among Service Providers
+(see Mastercard SPME §2.2, updated 2023), Halyard Pay will incorporate due diligence and
+compliance monitoring to ensure these entities meet PCI DSS and related security standards,
+which supports overall fraud risk mitigation.
## Required actions
@@ -21,5 +25,8 @@
transaction data.
4. Track case progress until the account returns to threshold compliance or is
terminated.
+5. Include Merchant Payment Gateways in the scope of service provider compliance
+ monitoring as mandated by the Mastercard SDP Program, verifying PCI DSS adherence
+ and addressing any security deficiencies.
-Source authority: Mastercard SPME §3.7.
+Source authority: Mastercard SPME §3.7, §2.2.