Mastercard SPME §2.4.1 · Jun 2022 → May 2023
PIN Entry Devices (PEDs) and Encrypting PIN Pads (EPPs)
The updated rules clarify that devices with expired PCI PTS approvals must be tracked in inventory and that device management systems must ensure receipt of security patches and physical management, such as device listing and tampering checks.
Security Rules and Procedures—Merchant Edition • 22 February 2022
Security Rules and Procedures—Merchant Edition • 7 February 2023
– The device set is in inventory when the PCI PTS approval expired. Device models that reach approval expiration are moved from the PCI Approved PTS Devices list to the PIN Transaction Security Devices With Expired Approvals list. – The device set is under a device management system. Such system must ensure that devices are able to both receive software security patches when made available by the device vendor and are physically managed (for example, maintaining a list of devices and periodically inspecting devices to look for tampering or substitution).
program: Fraud Monitoring- authority: Mastercard SPME §3.7+ authority: Mastercard SPME §3.7, §2.4.1fraud_to_sales_ratio_threshold: 0.015min_count_per_month: 100monitoring_cadence: monthlyescalation_actions:- escalate_to_human_review- notify_acquirerlookback_period_months: 1remediation_review_interval_days: 30agent_owner: fraud_ops_agent+ # Added oversight requirements for device management, including+ # tracking of devices with expired PCI PTS approvals and ensuring+ # receipt of security patches, to prevent tampering or substitution.+ # This aligns with updates in Mastercard SPME §2.4.1 regarding device+ # security and inventory controls for PIN entry devices.
Fraud Monitoring
Halyard Pay monitors merchant fraud activity on a monthly basis to detect patterns that
exceed Mastercard's acceptable fraud-to-sales thresholds. A merchant whose rolling
monthly fraud-to-sales ratio meets or exceeds 1.5% (0.015) and whose fraud count
reaches at least 100 transactions in that same month triggers mandatory escalation
under this policy.
When this policy applies
This policy applies to all merchants processed through Halyard Pay's acquiring platform
where Mastercard is the applicable card network. It governs both card-present and
card-not-present transaction streams.
Required actions
-
Compute the merchant's rolling fraud-to-sales ratio each calendar month.
-
If the ratio meets or exceeds the threshold AND the minimum count is reached,
escalate the merchant account to human review immediately.
- Notify the acquiring compliance officer and document the case ID with supporting
transaction data.
- Track case progress until the account returns to threshold compliance or is
terminated.
5. Ensure that all PIN Entry Devices used by merchants are under a device management system that tracks devices, including those with expired PCI PTS approvals, ensures timely application of security patches, and conducts periodic inspections to detect tampering or substitutions.
Source authority: Mastercard SPME §3.7.§3.7, §2.4.1.
Fraud Monitoring
Halyard Pay monitors merchant fraud activity on a monthly basis to detect patterns that
exceed Mastercard's acceptable fraud-to-sales thresholds. A merchant whose rolling
monthly fraud-to-sales ratio meets or exceeds 1.5% (0.015) and whose fraud count
reaches at least 100 transactions in that same month triggers mandatory escalation
under this policy.
When this policy applies
This policy applies to all merchants processed through Halyard Pay's acquiring platform
where Mastercard is the applicable card network. It governs both card-present and
card-not-present transaction streams.
Required actions
-
Compute the merchant's rolling fraud-to-sales ratio each calendar month.
-
If the ratio meets or exceeds the threshold AND the minimum count is reached,
escalate the merchant account to human review immediately.
- Notify the acquiring compliance officer and document the case ID with supporting
transaction data.
- Track case progress until the account returns to threshold compliance or is
terminated.
5. Ensure that all PIN Entry Devices used by merchants are under a device management system that tracks devices, including those with expired PCI PTS approvals, ensures timely application of security patches, and conducts periodic inspections to detect tampering or substitutions.
Source authority: Mastercard SPME §3.7.§3.7, §2.4.1.
Source authority: Mastercard SPME §2.4.1.
--- a/policies/fraud_monitoring/rules.yaml
+++ b/policies/fraud_monitoring/rules.yaml
@@ -1,5 +1,5 @@
program: Fraud Monitoring
-authority: Mastercard SPME §3.7
+authority: Mastercard SPME §3.7, §2.4.1
fraud_to_sales_ratio_threshold: 0.015
min_count_per_month: 100
monitoring_cadence: monthly
@@ -9,3 +9,8 @@
lookback_period_months: 1
remediation_review_interval_days: 30
agent_owner: fraud_ops_agent
+# Added oversight requirements for device management, including
+# tracking of devices with expired PCI PTS approvals and ensuring
+# receipt of security patches, to prevent tampering or substitution.
+# This aligns with updates in Mastercard SPME §2.4.1 regarding device
+# security and inventory controls for PIN entry devices.
--- a/policies/fraud_monitoring/policy.md
+++ b/policies/fraud_monitoring/policy.md
@@ -21,5 +21,6 @@
transaction data.
4. Track case progress until the account returns to threshold compliance or is
terminated.
+5. Ensure that all PIN Entry Devices used by merchants are under a device management system that tracks devices, including those with expired PCI PTS approvals, ensures timely application of security patches, and conducts periodic inspections to detect tampering or substitutions.
-Source authority: Mastercard SPME §3.7.
+Source authority: Mastercard SPME §3.7, §2.4.1.