Mastercard SPME §4.10.6 · Jun 2022 → May 2023
Use of a Vendor
New requirement mandates that any agreement with a vendor providing Multi-Factor Authentication services must explicitly include the vendor's agreement to protect personal information and comply with all applicable standards.
Any agreement that an Authenticating Entity enters with a vendor for the provision of Multi-Factor Authentication Method services must include the vendor’s express agreement to safeguard and control usage of personal information and to comply with all applicable Standards. Terminal, PIN, and MFA Method Security Standards
program: Fraud Monitoring- authority: Mastercard SPME §3.7+ authority: Mastercard SPME §3.7, §4.10.6fraud_to_sales_ratio_threshold: 0.015min_count_per_month: 100monitoring_cadence: monthlyescalation_actions:- escalate_to_human_review- notify_acquirerlookback_period_months: 1remediation_review_interval_days: 30agent_owner: fraud_ops_agent++ # The fraud monitoring program now explicitly recognizes the need for agreements with MFA vendors to require protection and control of personal data and adherence to applicable standards, per Mastercard SPME §4.10.6.
Fraud Monitoring
Halyard Pay monitors merchant fraud activity on a monthly basis to detect patterns that
exceed Mastercard's acceptable fraud-to-sales thresholds. A merchant whose rolling
monthly fraud-to-sales ratio meets or exceeds 1.5% (0.015) and whose fraud count
reaches at least 100 transactions in that same month triggers mandatory escalation
under this policy.
When this policy applies
This policy applies to all merchants processed through Halyard Pay's acquiring platform
where Mastercard is the applicable card network. It governs both card-present and
card-not-present transaction streams.
Required actions
-
Compute the merchant's rolling fraud-to-sales ratio each calendar month.
-
If the ratio meets or exceeds the threshold AND the minimum count is reached,
escalate the merchant account to human review immediately.
- Notify the acquiring compliance officer and document the case ID with supporting
transaction data.
- Track case progress until the account returns to threshold compliance or is
terminated.
### Vendor Agreements for MFA Services
All agreements with vendors providing Multi-Factor Authentication (MFA) services
must explicitly require the vendor to safeguard personal information and comply
with all applicable Mastercard security standards. This ensures that authentication
methods maintain strong protections consistent with Mastercard's fraud monitoring
and security requirements.
Source authority: Mastercard SPME §3.7.§§3.7, 4.10.6.
Fraud Monitoring
Halyard Pay monitors merchant fraud activity on a monthly basis to detect patterns that
exceed Mastercard's acceptable fraud-to-sales thresholds. A merchant whose rolling
monthly fraud-to-sales ratio meets or exceeds 1.5% (0.015) and whose fraud count
reaches at least 100 transactions in that same month triggers mandatory escalation
under this policy.
When this policy applies
This policy applies to all merchants processed through Halyard Pay's acquiring platform
where Mastercard is the applicable card network. It governs both card-present and
card-not-present transaction streams.
Required actions
-
Compute the merchant's rolling fraud-to-sales ratio each calendar month.
-
If the ratio meets or exceeds the threshold AND the minimum count is reached,
escalate the merchant account to human review immediately.
- Notify the acquiring compliance officer and document the case ID with supporting
transaction data.
- Track case progress until the account returns to threshold compliance or is
terminated.
### Vendor Agreements for MFA Services
All agreements with vendors providing Multi-Factor Authentication (MFA) services
must explicitly require the vendor to safeguard personal information and comply
with all applicable Mastercard security standards. This ensures that authentication
methods maintain strong protections consistent with Mastercard's fraud monitoring
and security requirements.
Source authority: Mastercard SPME §3.7.§§3.7, 4.10.6.
Source authority: Mastercard SPME §4.10.6.
--- a/policies/fraud_monitoring/rules.yaml
+++ b/policies/fraud_monitoring/rules.yaml
@@ -1,5 +1,5 @@
program: Fraud Monitoring
-authority: Mastercard SPME §3.7
+authority: Mastercard SPME §3.7, §4.10.6
fraud_to_sales_ratio_threshold: 0.015
min_count_per_month: 100
monitoring_cadence: monthly
@@ -9,3 +9,5 @@
lookback_period_months: 1
remediation_review_interval_days: 30
agent_owner: fraud_ops_agent
+
+# The fraud monitoring program now explicitly recognizes the need for agreements with MFA vendors to require protection and control of personal data and adherence to applicable standards, per Mastercard SPME §4.10.6.
--- a/policies/fraud_monitoring/policy.md
+++ b/policies/fraud_monitoring/policy.md
@@ -22,4 +22,12 @@
4. Track case progress until the account returns to threshold compliance or is
terminated.
-Source authority: Mastercard SPME §3.7.
+### Vendor Agreements for MFA Services
+
+All agreements with vendors providing Multi-Factor Authentication (MFA) services
+must explicitly require the vendor to safeguard personal information and comply
+with all applicable Mastercard security standards. This ensures that authentication
+methods maintain strong protections consistent with Mastercard's fraud monitoring
+and security requirements.
+
+Source authority: Mastercard SPME §§3.7, 4.10.6.