Mastercard SPME §4.10.6 · Jun 2022 → May 2023

Use of a Vendor

substantive

New requirement mandates that any agreement with a vendor providing Multi-Factor Authentication services must explicitly include the vendor's agreement to protect personal information and comply with all applicable standards.

Sources Mastercard SPME · Jun 2022 PDF Mastercard SPME · May 2023 · page 57 PDF Fraud Monitoring current
Also in §4.x this release substantive §4.10 Multi-Factor Authentication Methods for Remote Commerce substantive §4.10.1 Security Evaluation of Multi-Factor Authentication Methods substantive §4.10.3 Persistent Authentication substantive §4.10.4 Prolonged Authentication
Why these edits? The updated requirement mandates that agreements with vendors providing Multi-Factor Authentication services explicitly include the vendor's commitment to protect personal information and comply with standards, aligning with the fraud monitoring obligations that ensure secure authentication methods.
Mastercard SPME §4.10.6
This section was substantively restructured between versions (0% text overlap). Compare the texts directly below.
Before · Jun 2022
After · May 2023 · page 57

Any agreement that an Authenticating Entity enters with a vendor for the provision of Multi-Factor Authentication Method services must include the vendor’s express agreement to safeguard and control usage of personal information and to comply with all applicable Standards. Terminal, PIN, and MFA Method Security Standards

Halyard Pay · 2 files
program: Fraud Monitoring
- authority: Mastercard SPME §3.7
+ authority: Mastercard SPME §3.7, §4.10.6
fraud_to_sales_ratio_threshold: 0.015
min_count_per_month: 100
monitoring_cadence: monthly
escalation_actions:
- escalate_to_human_review
- notify_acquirer
lookback_period_months: 1
remediation_review_interval_days: 30
agent_owner: fraud_ops_agent
+
+ # The fraud monitoring program now explicitly recognizes the need for agreements with MFA vendors to require protection and control of personal data and adherence to applicable standards, per Mastercard SPME §4.10.6.

Fraud Monitoring

Halyard Pay monitors merchant fraud activity on a monthly basis to detect patterns that

exceed Mastercard's acceptable fraud-to-sales thresholds. A merchant whose rolling

monthly fraud-to-sales ratio meets or exceeds 1.5% (0.015) and whose fraud count

reaches at least 100 transactions in that same month triggers mandatory escalation

under this policy.

When this policy applies

This policy applies to all merchants processed through Halyard Pay's acquiring platform

where Mastercard is the applicable card network. It governs both card-present and

card-not-present transaction streams.

Required actions

  1. Compute the merchant's rolling fraud-to-sales ratio each calendar month.

  2. If the ratio meets or exceeds the threshold AND the minimum count is reached,

escalate the merchant account to human review immediately.

  1. Notify the acquiring compliance officer and document the case ID with supporting

transaction data.

  1. Track case progress until the account returns to threshold compliance or is

terminated.

### Vendor Agreements for MFA Services

All agreements with vendors providing Multi-Factor Authentication (MFA) services

must explicitly require the vendor to safeguard personal information and comply

with all applicable Mastercard security standards. This ensures that authentication

methods maintain strong protections consistent with Mastercard's fraud monitoring

and security requirements.

Source authority: Mastercard SPME §3.7.§§3.7, 4.10.6.

policies/fraud_monitoring/policy.md — after applying change

Fraud Monitoring

Halyard Pay monitors merchant fraud activity on a monthly basis to detect patterns that

exceed Mastercard's acceptable fraud-to-sales thresholds. A merchant whose rolling

monthly fraud-to-sales ratio meets or exceeds 1.5% (0.015) and whose fraud count

reaches at least 100 transactions in that same month triggers mandatory escalation

under this policy.

When this policy applies

This policy applies to all merchants processed through Halyard Pay's acquiring platform

where Mastercard is the applicable card network. It governs both card-present and

card-not-present transaction streams.

Required actions

  1. Compute the merchant's rolling fraud-to-sales ratio each calendar month.

  2. If the ratio meets or exceeds the threshold AND the minimum count is reached,

escalate the merchant account to human review immediately.

  1. Notify the acquiring compliance officer and document the case ID with supporting

transaction data.

  1. Track case progress until the account returns to threshold compliance or is

terminated.

### Vendor Agreements for MFA Services

All agreements with vendors providing Multi-Factor Authentication (MFA) services

must explicitly require the vendor to safeguard personal information and comply

with all applicable Mastercard security standards. This ensures that authentication

methods maintain strong protections consistent with Mastercard's fraud monitoring

and security requirements.

Source authority: Mastercard SPME §3.7.§§3.7, 4.10.6.

Source authority: Mastercard SPME §4.10.6.

--- a/policies/fraud_monitoring/rules.yaml
+++ b/policies/fraud_monitoring/rules.yaml
@@ -1,5 +1,5 @@
 program: Fraud Monitoring
-authority: Mastercard SPME §3.7
+authority: Mastercard SPME §3.7, §4.10.6
 fraud_to_sales_ratio_threshold: 0.015
 min_count_per_month: 100
 monitoring_cadence: monthly
@@ -9,3 +9,5 @@
 lookback_period_months: 1
 remediation_review_interval_days: 30
 agent_owner: fraud_ops_agent
+
+# The fraud monitoring program now explicitly recognizes the need for agreements with MFA vendors to require protection and control of personal data and adherence to applicable standards, per Mastercard SPME §4.10.6.
--- a/policies/fraud_monitoring/policy.md
+++ b/policies/fraud_monitoring/policy.md
@@ -22,4 +22,12 @@
 4. Track case progress until the account returns to threshold compliance or is
    terminated.
 
-Source authority: Mastercard SPME §3.7.
+### Vendor Agreements for MFA Services
+
+All agreements with vendors providing Multi-Factor Authentication (MFA) services
+must explicitly require the vendor to safeguard personal information and comply
+with all applicable Mastercard security standards. This ensures that authentication
+methods maintain strong protections consistent with Mastercard's fraud monitoring
+and security requirements.
+
+Source authority: Mastercard SPME §§3.7, 4.10.6.