Mastercard SPME §2.3.1 · Jun 2022 → May 2023

Global Vendor Certification Program

substantive

The requirement for an on-site audit for vendor certification was changed to a security assessment conducted approximately every 12 months. References to vendor agreements and contact info for GVCP were removed.

Sources Mastercard SPME · Jun 2022 · page 31 PDF Mastercard SPME · May 2023 · page 31 PDF KYB Acquirer current
Also in §2.x this release substantive §2.2 Mastercard Site Data Protection (SDP) Program substantive §2.2.5 SDP Program Noncompliance Assessments substantive §2.2.6 Mandatory Compliance Requirements for Compromised Entities substantive §2.3.2 Additional Card Production Requirements substantive §2.4.1 PIN Entry Devices (PEDs) and Encrypting PIN Pads (EPPs)
Why these edits? The change in the Global Vendor Certification Program from an on-site audit to a security assessment every 12 months affects Acquirer KYB obligations by modifying the required vendor certification process referenced in section 2.1.
Mastercard SPME §2.3.1
Before employing the services of a vendor to perform any Card production activities, a Customer must ensure that the vendor has been certified by Mastercard under the Global Vendor Certification Program (GVCP). Prior to certification and annual recertification of a vendor facility under the GVCP, an on-site audit a security assessment of the facility is conducted at approximately 12-month intervals to evaluate the facility's compliance with the PCI documents referenced in section 2.3. A certified vendor facility is issued a compliance certification, which is subject to annual renewal, provided the vendor facility remains in good standing. The “List of Certified Vendors,” as published monthly in a Mastercard Announcement (AN) available on the Technical Resource Center on Mastercard Connect™, contains the name of each vendor facility then certified and a description of the specific services that the facility is authorized to perform. Any agreement between an Issuer and a vendor for Card production services ¶ should contain terms stating that the vendor agrees to safeguard and control ¶ usage of Account data and to comply with all applicable Standards then in effect, ¶ including but not limited to those set forth in section 2.3 and in the Card Design ¶ Standards manual. ¶ For more information about the GVCP, contact Mastercard by sending an email ¶ message to gvcp-helpdesk@mastercard.com. ¶ Cybersecurity Standards and Programs
Halyard Pay · 2 files
program: Acquirer KYB
- authority: Mastercard SPME §2.1
+ authority: Mastercard SPME 2.1, 2.3.1
required_documents:
- incorporation
- beneficial_ownership
- aml_screen
- license_verification
min_review_cycle_days: 365
suspension_trigger: document_collection_failure
record_retention_years: 7
aml_watchlist_sources:
- ofac_sdn
- eu_consolidated
agent_owner: kyb_agent
+
+ # Updated authority references to include GVCP changes in §2.3.1
+ # The vendor certification process now requires a security assessment rather than an on-site audit annually, affecting vendor compliance verification under Acquirer KYB.

Acquirer KYB (Know Your Business) Obligations

Acquirers processing transactions on the Mastercard network are required to perform

Know Your Business (KYB) due diligence on merchants before onboarding and on a

recurring basis thereafter. Halyard Pay, as an acquirer, must collect and verify a

minimum set of documents for each merchant to establish business legitimacy, confirm

beneficial ownership, and satisfy anti-money laundering screening requirements.

When this policy applies

This policy applies to all new merchant onboarding and to all periodic re-verification

reviews. Merchants that fail to supply required documentation within the stipulated

period must be suspended from processing until compliance is restored.

Required actions

  1. Collect all required KYB documents at onboarding prior to approval.

  2. Conduct AML screening against applicable watchlists before approval.

  3. Verify business licenses for regulated merchant categories.

  4. Schedule a full re-verification review at least once every 365 days.

  5. Document all verification outcomes and retain records for audit purposes.

6. Ensure that any vendor used for Card production services holds valid Mastercard GVCP certification, noting that the certification process includes an annual security assessment of the vendor facility as per Mastercard SPME §2.3.1, replacing the previous on-site audit requirement.

Source authority: Mastercard SPME §2.1.§2.1, §2.3.1.

policies/kyb_acquirer/policy.md — after applying change

Acquirer KYB (Know Your Business) Obligations

Acquirers processing transactions on the Mastercard network are required to perform

Know Your Business (KYB) due diligence on merchants before onboarding and on a

recurring basis thereafter. Halyard Pay, as an acquirer, must collect and verify a

minimum set of documents for each merchant to establish business legitimacy, confirm

beneficial ownership, and satisfy anti-money laundering screening requirements.

When this policy applies

This policy applies to all new merchant onboarding and to all periodic re-verification

reviews. Merchants that fail to supply required documentation within the stipulated

period must be suspended from processing until compliance is restored.

Required actions

  1. Collect all required KYB documents at onboarding prior to approval.

  2. Conduct AML screening against applicable watchlists before approval.

  3. Verify business licenses for regulated merchant categories.

  4. Schedule a full re-verification review at least once every 365 days.

  5. Document all verification outcomes and retain records for audit purposes.

6. Ensure that any vendor used for Card production services holds valid Mastercard GVCP certification, noting that the certification process includes an annual security assessment of the vendor facility as per Mastercard SPME §2.3.1, replacing the previous on-site audit requirement.

Source authority: Mastercard SPME §2.1.§2.1, §2.3.1.

Source authority: Mastercard SPME §2.3.1.

--- a/policies/kyb_acquirer/rules.yaml
+++ b/policies/kyb_acquirer/rules.yaml
@@ -1,5 +1,5 @@
 program: Acquirer KYB
-authority: Mastercard SPME §2.1
+authority: Mastercard SPME 2.1, 2.3.1
 required_documents:
   - incorporation
   - beneficial_ownership
@@ -12,3 +12,6 @@
   - ofac_sdn
   - eu_consolidated
 agent_owner: kyb_agent
+
+# Updated authority references to include GVCP changes in §2.3.1
+# The vendor certification process now requires a security assessment rather than an on-site audit annually, affecting vendor compliance verification under Acquirer KYB.

--- a/policies/kyb_acquirer/policy.md
+++ b/policies/kyb_acquirer/policy.md
@@ -19,5 +19,6 @@
 3. Verify business licenses for regulated merchant categories.
 4. Schedule a full re-verification review at least once every 365 days.
 5. Document all verification outcomes and retain records for audit purposes.
+6. Ensure that any vendor used for Card production services holds valid Mastercard GVCP certification, noting that the certification process includes an annual security assessment of the vendor facility as per Mastercard SPME §2.3.1, replacing the previous on-site audit requirement.
 
-Source authority: Mastercard SPME §2.1.
+Source authority: Mastercard SPME §2.1, §2.3.1.