Mastercard SPME §3.13.4 · Jun 2022 → May 2023

Additional Service Code Information

substantive

The chapter title and scope have been broadened to include Multi-Factor Authentication (MFA) Methods for Remote Commerce Token Transactions, extending beyond just PIN use. The wording now addresses Customers broadly rather than only Issuers and Acquirers, reflecting an expanded focus on authentication methods in the security standards.

Sources Mastercard SPME · Jun 2022 · page 44 PDF Mastercard SPME · May 2023 · page 45 PDF Fraud Monitoring current
Also in §3.x this release substantive §3.11.7 Use of a Vendor substantive §3.12.4 Acquirer Requirements for CVC 2
Why these edits? The update broadens the scope from PIN usage to also include Multi-Factor Authentication (MFA) Methods for Remote Commerce Token Transactions, expanding fraud monitoring obligations to cover enhanced authentication security measures for Customers.
Mastercard SPME §3.13.4
Security Rules and Procedures—Merchant Edition • 22 7 February 2022 2023 Chapter 4 Terminal Terminal, PIN, and PIN MFA Method Security Standards This chapter may be of particular interest to Issuers of Cards Customers that support or enable PIN as a Cardholder Verification Method (CVM) and Acquirers of Terminals that accept PIN as a or Multi-Factor Authentication (MFA) Methods for CVM. Remote Commerce Token Transactions. Refer to the applicable technical specifications and the Transaction Processing Rules manual for additional Terminal and Transaction processing requirements relating to the use of a PIN.
Halyard Pay · 2 files
program: Fraud Monitoring
- authority: Mastercard SPME §3.7
+ authority: Mastercard SPME §3.7, §3.13.4
fraud_to_sales_ratio_threshold: 0.015
min_count_per_month: 100
monitoring_cadence: monthly
escalation_actions:
- escalate_to_human_review
- notify_acquirer
lookback_period_months: 1
remediation_review_interval_days: 30
agent_owner: fraud_ops_agent
+
+ # Updated authority reference to include Mastercard SPME §3.13.4,
+ # which expands security monitoring considerations to cover
+ # Multi-Factor Authentication (MFA) Methods for Remote Commerce
+ # Token Transactions in addition to PIN verification methods, thereby
+ # broadening fraud monitoring obligations to enhance authentication
+ # security measures for Customers.

Fraud Monitoring

Halyard Pay monitors merchant fraud activity on a monthly basis to detect patterns that exceed Mastercard's acceptable fraud-to-sales thresholds. A merchant whose rolling monthly fraud-to-sales ratio meets or exceeds 1.5% (0.015) and whose fraud count reaches at least 100 transactions in that same month triggers mandatory escalation under this policy.

When this policy applies

This policy applies to all merchants processed through Halyard Pay's acquiring platform where Mastercard is the applicable card network. It governs both card-present and card-not-present transaction streams. streams, including scenarios involving PIN and Multi-Factor Authentication (MFA) methods as referenced in Mastercard SPME §4.

Required actions

  1. Compute the merchant's rolling fraud-to-sales ratio each calendar month.

  2. If the ratio meets or exceeds the threshold AND the minimum count is reached, escalate the merchant account to human review immediately.

  3. Notify the acquiring compliance officer and document the case ID with supporting transaction data.

  4. Track case progress until the account returns to threshold compliance or is terminated.

This policy incorporates enhanced monitoring in recognition of Mastercard's expanded security requirements covering PIN and MFA for Remote Commerce Token Transactions.

Source authority: Mastercard SPME §3.7.§3.7, §4.

policies/fraud_monitoring/policy.md — after applying change

Fraud Monitoring

Halyard Pay monitors merchant fraud activity on a monthly basis to detect patterns that exceed Mastercard's acceptable fraud-to-sales thresholds. A merchant whose rolling monthly fraud-to-sales ratio meets or exceeds 1.5% (0.015) and whose fraud count reaches at least 100 transactions in that same month triggers mandatory escalation under this policy.

When this policy applies

This policy applies to all merchants processed through Halyard Pay's acquiring platform where Mastercard is the applicable card network. It governs both card-present and card-not-present transaction streams. streams, including scenarios involving PIN and Multi-Factor Authentication (MFA) methods as referenced in Mastercard SPME §4.

Required actions

  1. Compute the merchant's rolling fraud-to-sales ratio each calendar month.

  2. If the ratio meets or exceeds the threshold AND the minimum count is reached, escalate the merchant account to human review immediately.

  3. Notify the acquiring compliance officer and document the case ID with supporting transaction data.

  4. Track case progress until the account returns to threshold compliance or is terminated.

This policy incorporates enhanced monitoring in recognition of Mastercard's expanded security requirements covering PIN and MFA for Remote Commerce Token Transactions.

Source authority: Mastercard SPME §3.7.§3.7, §4.

Source authority: Mastercard SPME §3.13.4.

--- a/policies/fraud_monitoring/rules.yaml
+++ b/policies/fraud_monitoring/rules.yaml
@@ -1,5 +1,5 @@
 program: Fraud Monitoring
-authority: Mastercard SPME §3.7
+authority: Mastercard SPME §3.7, §3.13.4
 fraud_to_sales_ratio_threshold: 0.015
 min_count_per_month: 100
 monitoring_cadence: monthly
@@ -9,3 +9,10 @@
 lookback_period_months: 1
 remediation_review_interval_days: 30
 agent_owner: fraud_ops_agent
+
+# Updated authority reference to include Mastercard SPME §3.13.4,
+# which expands security monitoring considerations to cover
+# Multi-Factor Authentication (MFA) Methods for Remote Commerce
+# Token Transactions in addition to PIN verification methods, thereby
+# broadening fraud monitoring obligations to enhance authentication
+# security measures for Customers.
--- a/policies/fraud_monitoring/policy.md
+++ b/policies/fraud_monitoring/policy.md
@@ -1,25 +1,18 @@
 # Fraud Monitoring
 
-Halyard Pay monitors merchant fraud activity on a monthly basis to detect patterns that
-exceed Mastercard's acceptable fraud-to-sales thresholds. A merchant whose rolling
-monthly fraud-to-sales ratio meets or exceeds 1.5% (0.015) and whose fraud count
-reaches at least 100 transactions in that same month triggers mandatory escalation
-under this policy.
+Halyard Pay monitors merchant fraud activity on a monthly basis to detect patterns that exceed Mastercard's acceptable fraud-to-sales thresholds. A merchant whose rolling monthly fraud-to-sales ratio meets or exceeds 1.5% (0.015) and whose fraud count reaches at least 100 transactions in that same month triggers mandatory escalation under this policy.
 
 ## When this policy applies
 
-This policy applies to all merchants processed through Halyard Pay's acquiring platform
-where Mastercard is the applicable card network. It governs both card-present and
-card-not-present transaction streams.
+This policy applies to all merchants processed through Halyard Pay's acquiring platform where Mastercard is the applicable card network. It governs both card-present and card-not-present transaction streams, including scenarios involving PIN and Multi-Factor Authentication (MFA) methods as referenced in Mastercard SPME §4.
 
 ## Required actions
 
 1. Compute the merchant's rolling fraud-to-sales ratio each calendar month.
-2. If the ratio meets or exceeds the threshold AND the minimum count is reached,
-   escalate the merchant account to human review immediately.
-3. Notify the acquiring compliance officer and document the case ID with supporting
-   transaction data.
-4. Track case progress until the account returns to threshold compliance or is
-   terminated.
+2. If the ratio meets or exceeds the threshold AND the minimum count is reached, escalate the merchant account to human review immediately.
+3. Notify the acquiring compliance officer and document the case ID with supporting transaction data.
+4. Track case progress until the account returns to threshold compliance or is terminated.
 
-Source authority: Mastercard SPME §3.7.
+This policy incorporates enhanced monitoring in recognition of Mastercard's expanded security requirements covering PIN and MFA for Remote Commerce Token Transactions.
+
+Source authority: Mastercard SPME §3.7, §4.