Mastercard SPME §6.2 · Jun 2022 → May 2023

Mastercard Fraud Loss Control Program Standards

substantive

The updated section replaces detailed specific requirements for monitoring merchant deposit volumes, transaction anomalies, fraud detection, and ongoing merchant reviews with new mandates including MDES for Merchants to use tokenized credentials, EMV Chip terminals with PIN, matching MCC codes between authentication and authorization, and a requirement to mitigate BIN attacks within 72 hours.

Sources Mastercard SPME · Jun 2022 · page 56 PDF Mastercard SPME · May 2023 · page 65 PDF ATO Detection current Fraud Monitoring current
Also in §6.x this release breaking §6.3 Mastercard Counterfeit Card Fraud Loss Control Standards breaking §6.3.1 Counterfeit Card Notification substantive §6 Control of instructions substantive §6.2.2 Acquirer Fraud Loss Control Programs
Why these edits? The removal of detailed monitoring criteria for transaction anomalies and the new requirement for timely mitigation of BIN attacks within 72 hours significantly adjust the obligations for detecting account takeover fraud patterns.; The shift to mandatory use of MDES tokenized credentials and EMV Chip terminals with PIN capability, along with matching MCC codes between authentication and authorization, requires updates in fraud monitoring controls to align with these new technical and procedural mandates.
Mastercard SPME §6.2
This section was substantively restructured between versions (2% text overlap). Compare the texts directly below.
Before · Jun 2022 · page 56

Security Rules and Procedures—Merchant Edition • 22 February 2022

monitor authorization Transaction messages to identify when the same Account number appears among different negative option billing Merchant IDs in the Acquirer’s Portfolio within 60 calendar days. When the Acquirer identifies such an Account, the Acquirer must take reasonable steps to verify that each Transaction conducted by the valid Cardholder with the associated negative option billing Merchant is a bona fide Transaction. This verification may include, but is not limited to, an electronic copy or hard copy of the Transaction information document (TID). All such verification information must be:

  • Retained by the Acquirer for a period of at least one year from the verification date; and
  • Made available to Mastercard upon request. 6.2.2.2 Acquirer Merchant Deposit Monitoring Requirements Daily reports or real-time alerts monitoring Merchant deposits must be generated at the latest on the day following the deposit, and must be based on the following parameters:
  • Increases in Merchant deposit volume
  • Increase in a Merchant’s average ticket size and number of Transactions for each deposit
  • Change in frequency of deposits
  • Change in technical fallback rates, or a technical fallback rate that exceeds five percent of a Merchant’s total Transaction volume NOTE: Any report generated by the Acquirer relating to the investigation of a Merchant whose rate of technical fallback exceeds five percent of its total Transaction volume must be made available to Mastercard upon request.
  • Force-posted Transactions (i.e., a Transaction that has been declined by the Issuer or the chip or any Transaction for which authorization was required but not obtained)
  • Frequency of Transactions on the same Account, including credit (refund) Transactions
  • Unusual number of credits, or credit dollar volume, exceeding a level of sales dollar volume appropriate to the Merchant category
  • Large credit Transaction amounts, significantly greater than the average ticket size for the Merchant’s sales
  • Credit (refund) Transaction volume that exceeds purchase Transaction volume
  • Credits issued by a Merchant subsequent to the Acquirer’s receipt of a chargeback with the same PAN
  • Credits issued by a Merchant to a PAN not previously used to effect a Transaction at the Merchant location
  • Increases in Merchant chargeback volume Fraud Loss Control Standards 6.2.2.2 Acquirer Merchant Deposit Monitoring Requirements Security Rules and Procedures—Merchant Edition • 22 February 2022 90-day Rule The Acquirer must compare daily deposits against the average Transaction count and amount for each Merchant over a period of at least 90 days, to lessen the effect of normal variances in a Merchant’s business. For new Merchants, the Acquirer should compare the average Transaction count and amount for other Merchants within the same MCC assigned to the Merchant. In the event that suspicious credit or refund Transaction activity is identified, if appropriate, the Acquirer should consider the suspension of Transactions pending further investigation. 6.2.2.3 Acquirer Channel Management Requirements Mastercard requires the Acquirer to monitor, on a regular basis, each parent Member ID/ICA number, child Member ID/ICA number, and individual Merchant in its Portfolio for the following:
  • Total Transaction fraud basis points
  • Domestic Transaction fraud basis points
  • Cross-border Transaction fraud basis points (both Intraregional Transactions and Interregional Transactions)
  • Fraud basis points at the parent Member ID/ICA level for the following: – Card-present Transactions – POS – Mobile POS (MPOS) – Cardholder-activated Terminal (CAT) (for example, CAT 1, CAT 2, and CAT 3) – Card-not-present (CNP) Transactions – E-commerce, including separate monitoring of non-authenticated, attempted authentication, and fully authenticated Transactions – Mail order/telephone order (MO/TO) 6.2.2.4 Recommended Additional Acquirer Monitoring Mastercard recommends that Acquirers additionally monitor the following parameters:
  • Mismatch of Merchant name, MCC, Merchant ID, and/or Terminal ID
  • Mismatch of e-commerce Merchant Internet Protocol (IP) addresses
  • Transactions conducted at Merchant, Submerchants, and other entities registered in the Specialty Merchant Registration Program (refer to Chapter 9)
  • PAN key-entry Transactions exceeding ratio
  • Abnormal hours (i.e., outside of normal business hours) or seasons
  • Inactive Merchants (i.e., those Merchants that have not yet started to accept Cards as well as those that have ceased to accept Cards)
  • Transactions with no approval code
  • Transaction decline rate Fraud Loss Control Standards 6.2.2.3 Acquirer Channel Management Requirements Security Rules and Procedures—Merchant Edition • 22 February 2022
  • Inconsistent authorization and clearing data elements for the same Transactions
  • Mastercard SecureCode or Identity Check authentication rate
  • Fraud volume per Merchant
  • Any Merchant exceeding the Acquirer’s total Merchant average for fraud by 150 percent or more 6.2.2.5 Recommended Fraud Detection Tool Implementation An Acquirer is recommended to implement a fraud detection tool that appropriately complements the fraud strategy deployed by the Acquirer. The combination of the authorization requirements, Merchant deposit monitoring requirements, and fraud detection tool should ensure that an Acquirer controls fraud to an acceptable level. For effective performance, an Acquirer’s fraud detection tool should minimally measure the amount and number of fraud Transactions incurred, calculated for each of its Merchants, Payment Facilitators and other Service Providers, and deployed Terminals. 6.2.2.6 Ongoing Merchant Monitoring An Acquirer must implement procedures for the conduct of periodic ongoing reviews of a Merchant’s Card acceptance activity, for the purpose of detecting changes over time, including but not limited to:
  • Monthly Transaction volume with respect to: – Total Transaction count and amount – Number of credit (refund) Transactions – Number of fraudulent Transactions – Average ticket size – Number of chargebacks
  • Activity inconsistent with the Merchant’s business model
  • Transaction laundering
  • Activity that is or may potentially be illegal or brand-damaging As a best practice, Mastercard recommends that Acquirers use a Merchant monitoring solution for e-commerce Merchant activity so as to avoid processing illegal or brand-damaging Transactions. For more information on ongoing Merchant monitoring requirements, refer to section 7.2.
After · May 2023 · page 65

Security Rules and Procedures—Merchant Edition • 7 February 2023

  • Implement MDES for Merchant (M4M) to replace real card data by tokenized and digitized payment credentials (tokens)
  • EMV Chip Terminals with PIN Capability (Please refer to existing mandates in specific countries) The MCC submitted at the time of authentication should match the MCC submitted at the time of the authorization except when a single authentication relates to multiple authorizations for different merchants. Addressing BIN Attacks BIN attacks either detected by the Acquirer or communicated to the Acquirer by Mastercard, must be mitigated by the Acquirer, its processor(s) or the concerned Merchant(s) within 72 hours (or within a timeframe approved by Mastercard) of detection by the Acquirer, its Service Provider, the Merchant or notification by Mastercard. By way of example, an attack will be qualified as a BIN attack when the following two conditions are met:
Halyard Pay · 4 files
program: ATO Detection
authority: Mastercard SPME §6.2
risk_threshold_for_3ds_challenge: 0.5
risk_score_range: [0.0, 1.0]
signals:
- geo_anomaly
- device_fingerprint_change
- velocity_breach
- credential_stuffing
challenge_method: 3ds_v2
persistent_risk_escalation_threshold: 3
persistent_risk_lookback_days: 7
agent_owner: ato_agent
+
+ # Updated to reflect removal of detailed anomaly monitoring criteria and new BIN attack mitigation
+ # requirement: BIN attacks must be mitigated within 72 hours by Acquirers or their Service Providers.
+ # The MCC should be consistent between authentication and authorization except when one authentication
+ # covers multiple authorizations for distinct Merchants.
+ # See Mastercard SPME §6.2 updates effective 7 Feb 2023 for details.

Account-Takeover (ATO) Detection

Account-takeover fraud occurs when a malicious actor an unauthorized party gains unauthorized access to ¶ control of a cardholder's account and initiates to conduct transactions without the cardholder's consent. Halyard Pay implements employs real-time behavioral monitoring and risk scoring on to detect such threats, enforcing a mandatory transaction authentication events and enforces a ¶ mandatory 3DS (3-D Secure) challenge for any session where the computed risk score ¶ meets or exceeds the defined threshold. when suspicious activity is identified.

Detection signals

The risk model incorporates Our detection system analyzes multiple behavioral signals: geographic anomalies ¶ inconsistent with a cardholder's established pattern, changes to signals including transaction irregularities, device fingerprint, ¶ fingerprint changes, unusual transaction velocity breaches, velocity, and indicators of credential-stuffing activity. indicators.

Required actions

  1. Evaluate each authentication event against the defined signal list in real time. Continually monitor transaction and account activity using behavioral and transaction pattern analysis.

  2. Compute a normalized risk score Evaluate anomalies such as mismatched Merchant Category Codes (MCCs) between 0.0 authentication and 1.0. authorization and other irregular transaction patterns.

  3. If Implement risk scoring to determine the risk score is 0.5 or greater, trigger a mandatory 3DS challenge before ¶ authorizing the transaction. likelihood of account takeover.

  4. Log all ATO signals If risk exceeds the threshold, trigger enhanced customer authentication, such as 3-D Secure challenges.

5. Promptly investigate and mitigate identified BIN attacks or transaction anomalies within approved timelines (e.g., within 72 hours).

6. Maintain detailed logs of alerts, investigations, and outcomes in the case management system. ¶ 5. Escalate persistent high-risk accounts to the ATO response team for manual review. support ongoing fraud mitigation efforts.

Source authority: Mastercard SPME §6.2.

program: Fraud Monitoring
- authority: Mastercard SPME §3.7
+ authority: Mastercard SPME §3.7, §6.2
fraud_to_sales_ratio_threshold: 0.015
min_count_per_month: 100
monitoring_cadence: monthly
escalation_actions:
- escalate_to_human_review
- notify_acquirer
lookback_period_months: 1
remediation_review_interval_days: 30
agent_owner: fraud_ops_agent
+
+ # Updated to reflect Mastercard’s enhanced requirements from SPME §6.2.
+ # Fraud monitoring must now incorporate controls aligned with tokenization (MDES), EMV terminal standards, and MCC validation.
+ # BIN attacks must be detected and mitigated rapidly within prescribed timeframes.
+ # Fraud monitoring should ensure authorization MCC matches authentication MCC unless distinct merchants involved, supporting detection of suspicious activity.
+ # These changes reinforce existing deposit, transaction, and fraud monitoring thresholds and cadence, maintaining the foundational parameters.
+
+ # Additional monitoring of token usage, EMV chip PIN enforcement, and matched MCC submission forms part of ongoing fraud detection controls.

Fraud Monitoring

Halyard Pay monitors merchant fraud activity on a monthly basis to detect patterns that ¶ exceed exceeding Mastercard's acceptable permissible fraud-to-sales thresholds. ratios and to ensure compliance with evolving fraud mitigation mandates. Specifically, Halyard Pay incorporates controls aligned with Mastercard's enhanced requirements, including the mandatory use of Mastercard Digital Enablement Service (MDES) tokens, and EMV chip terminals with PIN capability where applicable.

A merchant whose rolling monthly fraud-to-sales ratio meets or exceeds 1.5% (0.015) and whose fraud count ¶ reaches with at least 100 fraudulent transactions in that same month triggers mandatory escalation under this policy.

When this policy applies

This policy applies to all merchants processed through Halyard Pay's acquiring platform ¶ where Mastercard is the applicable under Mastercard as the card network. It governs network, encompassing both card-present and card-not-present transaction streams. transactions.

Required actions

  1. Compute the merchant's rolling monthly fraud-to-sales ratio each calendar month. ratio.

  2. Confirm compliance that Merchant Category Codes (MCC) used during authentication matches MCC at authorization unless multiple authorizations occur for different merchants in a single authentication.

3. Verify that merchants have adopted MDES tokenized credentials replacing real card data, and EMV chip terminals with PIN capability as required.

4. If the ratio meets or exceeds the threshold AND the minimum count is reached, ¶ fraud thresholds are exceeded, escalate the merchant account to for human review immediately.

3. 5. Notify the acquiring compliance officer and document the record case ID details with supporting transaction data.

4. 6. Track case investigation progress until the merchant returns to compliance or the account returns to threshold compliance or is terminated.

These controls ensure Halyard Pay complies with Mastercard SPME §6.2 mandates regarding updated fraud monitoring and mitigation.

Source authority: Mastercard SPME §3.7.§§3.7, 6.2.

policies/ato_detection/policy.md — after applying change

Account-Takeover (ATO) Detection

Account-takeover fraud occurs when a malicious actor an unauthorized party gains unauthorized access to ¶ control of a cardholder's account and initiates to conduct transactions without the cardholder's consent. Halyard Pay implements employs real-time behavioral monitoring and risk scoring on to detect such threats, enforcing a mandatory transaction authentication events and enforces a ¶ mandatory 3DS (3-D Secure) challenge for any session where the computed risk score ¶ meets or exceeds the defined threshold. when suspicious activity is identified.

Detection signals

The risk model incorporates Our detection system analyzes multiple behavioral signals: geographic anomalies ¶ inconsistent with a cardholder's established pattern, changes to signals including transaction irregularities, device fingerprint, ¶ fingerprint changes, unusual transaction velocity breaches, velocity, and indicators of credential-stuffing activity. indicators.

Required actions

  1. Evaluate each authentication event against the defined signal list in real time. Continually monitor transaction and account activity using behavioral and transaction pattern analysis.

  2. Compute a normalized risk score Evaluate anomalies such as mismatched Merchant Category Codes (MCCs) between 0.0 authentication and 1.0. authorization and other irregular transaction patterns.

  3. If Implement risk scoring to determine the risk score is 0.5 or greater, trigger a mandatory 3DS challenge before ¶ authorizing the transaction. likelihood of account takeover.

  4. Log all ATO signals If risk exceeds the threshold, trigger enhanced customer authentication, such as 3-D Secure challenges.

5. Promptly investigate and mitigate identified BIN attacks or transaction anomalies within approved timelines (e.g., within 72 hours).

6. Maintain detailed logs of alerts, investigations, and outcomes in the case management system. ¶ 5. Escalate persistent high-risk accounts to the ATO response team for manual review. support ongoing fraud mitigation efforts.

Source authority: Mastercard SPME §6.2.

policies/fraud_monitoring/policy.md — after applying change

Fraud Monitoring

Halyard Pay monitors merchant fraud activity on a monthly basis to detect patterns that ¶ exceed exceeding Mastercard's acceptable permissible fraud-to-sales thresholds. ratios and to ensure compliance with evolving fraud mitigation mandates. Specifically, Halyard Pay incorporates controls aligned with Mastercard's enhanced requirements, including the mandatory use of Mastercard Digital Enablement Service (MDES) tokens, and EMV chip terminals with PIN capability where applicable.

A merchant whose rolling monthly fraud-to-sales ratio meets or exceeds 1.5% (0.015) and whose fraud count ¶ reaches with at least 100 fraudulent transactions in that same month triggers mandatory escalation under this policy.

When this policy applies

This policy applies to all merchants processed through Halyard Pay's acquiring platform ¶ where Mastercard is the applicable under Mastercard as the card network. It governs network, encompassing both card-present and card-not-present transaction streams. transactions.

Required actions

  1. Compute the merchant's rolling monthly fraud-to-sales ratio each calendar month. ratio.

  2. Confirm compliance that Merchant Category Codes (MCC) used during authentication matches MCC at authorization unless multiple authorizations occur for different merchants in a single authentication.

3. Verify that merchants have adopted MDES tokenized credentials replacing real card data, and EMV chip terminals with PIN capability as required.

4. If the ratio meets or exceeds the threshold AND the minimum count is reached, ¶ fraud thresholds are exceeded, escalate the merchant account to for human review immediately.

3. 5. Notify the acquiring compliance officer and document the record case ID details with supporting transaction data.

4. 6. Track case investigation progress until the merchant returns to compliance or the account returns to threshold compliance or is terminated.

These controls ensure Halyard Pay complies with Mastercard SPME §6.2 mandates regarding updated fraud monitoring and mitigation.

Source authority: Mastercard SPME §3.7.§§3.7, 6.2.

Source authority: Mastercard SPME §6.2.

--- a/policies/ato_detection/rules.yaml
+++ b/policies/ato_detection/rules.yaml
@@ -11,3 +11,9 @@
 persistent_risk_escalation_threshold: 3
 persistent_risk_lookback_days: 7
 agent_owner: ato_agent
+
+# Updated to reflect removal of detailed anomaly monitoring criteria and new BIN attack mitigation
+# requirement: BIN attacks must be mitigated within 72 hours by Acquirers or their Service Providers.
+# The MCC should be consistent between authentication and authorization except when one authentication
+# covers multiple authorizations for distinct Merchants.
+# See Mastercard SPME §6.2 updates effective 7 Feb 2023 for details.
--- a/policies/ato_detection/policy.md
+++ b/policies/ato_detection/policy.md
@@ -1,24 +1,18 @@
 # Account-Takeover (ATO) Detection
 
-Account-takeover fraud occurs when a malicious actor gains unauthorized access to
-a cardholder's account and initiates transactions without the cardholder's consent.
-Halyard Pay implements real-time risk scoring on authentication events and enforces a
-mandatory 3DS (3-D Secure) challenge for any session where the computed risk score
-meets or exceeds the defined threshold.
+Account-takeover fraud occurs when an unauthorized party gains control of a cardholder's account to conduct transactions without consent. Halyard Pay employs real-time behavioral monitoring and risk scoring to detect such threats, enforcing a mandatory transaction authentication when suspicious activity is identified.
 
 ## Detection signals
 
-The risk model incorporates multiple behavioral signals: geographic anomalies
-inconsistent with a cardholder's established pattern, changes to device fingerprint,
-transaction velocity breaches, and indicators of credential-stuffing activity.
+Our detection system analyzes multiple signals including transaction irregularities, device fingerprint changes, unusual transaction velocity, and credential-stuffing indicators.
 
 ## Required actions
 
-1. Evaluate each authentication event against the defined signal list in real time.
-2. Compute a normalized risk score between 0.0 and 1.0.
-3. If the risk score is 0.5 or greater, trigger a mandatory 3DS challenge before
-   authorizing the transaction.
-4. Log all ATO signals and outcomes in the case management system.
-5. Escalate persistent high-risk accounts to the ATO response team for manual review.
+1. Continually monitor transaction and account activity using behavioral and transaction pattern analysis.
+2. Evaluate anomalies such as mismatched Merchant Category Codes (MCCs) between authentication and authorization and other irregular transaction patterns.
+3. Implement risk scoring to determine the likelihood of account takeover.
+4. If risk exceeds the threshold, trigger enhanced customer authentication, such as 3-D Secure challenges.
+5. Promptly investigate and mitigate identified BIN attacks or transaction anomalies within approved timelines (e.g., within 72 hours).
+6. Maintain detailed logs of alerts, investigations, and outcomes to support ongoing fraud mitigation efforts.
 
-Source authority: Mastercard SPME §6.2.
+Source authority: Mastercard SPME §6.2.
--- a/policies/fraud_monitoring/rules.yaml
+++ b/policies/fraud_monitoring/rules.yaml
@@ -1,5 +1,5 @@
 program: Fraud Monitoring
-authority: Mastercard SPME §3.7
+authority: Mastercard SPME §3.7, §6.2
 fraud_to_sales_ratio_threshold: 0.015
 min_count_per_month: 100
 monitoring_cadence: monthly
@@ -9,3 +9,11 @@
 lookback_period_months: 1
 remediation_review_interval_days: 30
 agent_owner: fraud_ops_agent
+
+# Updated to reflect Mastercard’s enhanced requirements from SPME §6.2.
+# Fraud monitoring must now incorporate controls aligned with tokenization (MDES), EMV terminal standards, and MCC validation.
+# BIN attacks must be detected and mitigated rapidly within prescribed timeframes.
+# Fraud monitoring should ensure authorization MCC matches authentication MCC unless distinct merchants involved, supporting detection of suspicious activity.
+# These changes reinforce existing deposit, transaction, and fraud monitoring thresholds and cadence, maintaining the foundational parameters.
+
+# Additional monitoring of token usage, EMV chip PIN enforcement, and matched MCC submission forms part of ongoing fraud detection controls.

--- a/policies/fraud_monitoring/policy.md
+++ b/policies/fraud_monitoring/policy.md
@@ -1,25 +1,22 @@
 # Fraud Monitoring
 
-Halyard Pay monitors merchant fraud activity on a monthly basis to detect patterns that
-exceed Mastercard's acceptable fraud-to-sales thresholds. A merchant whose rolling
-monthly fraud-to-sales ratio meets or exceeds 1.5% (0.015) and whose fraud count
-reaches at least 100 transactions in that same month triggers mandatory escalation
-under this policy.
+Halyard Pay monitors merchant fraud activity monthly to detect patterns exceeding Mastercard's permissible fraud-to-sales ratios and to ensure compliance with evolving fraud mitigation mandates. Specifically, Halyard Pay incorporates controls aligned with Mastercard's enhanced requirements, including the mandatory use of Mastercard Digital Enablement Service (MDES) tokens, and EMV chip terminals with PIN capability where applicable.
+
+A merchant whose rolling monthly fraud-to-sales ratio meets or exceeds 1.5% (0.015) with at least 100 fraudulent transactions triggers mandatory escalation under this policy.
 
 ## When this policy applies
 
-This policy applies to all merchants processed through Halyard Pay's acquiring platform
-where Mastercard is the applicable card network. It governs both card-present and
-card-not-present transaction streams.
+This policy applies to all merchants processed through Halyard Pay's acquiring platform under Mastercard as the card network, encompassing both card-present and card-not-present transactions.
 
 ## Required actions
 
-1. Compute the merchant's rolling fraud-to-sales ratio each calendar month.
-2. If the ratio meets or exceeds the threshold AND the minimum count is reached,
-   escalate the merchant account to human review immediately.
-3. Notify the acquiring compliance officer and document the case ID with supporting
-   transaction data.
-4. Track case progress until the account returns to threshold compliance or is
-   terminated.
+1. Compute the merchant's rolling monthly fraud-to-sales ratio.
+2. Confirm compliance that Merchant Category Codes (MCC) used during authentication matches MCC at authorization unless multiple authorizations occur for different merchants in a single authentication.
+3. Verify that merchants have adopted MDES tokenized credentials replacing real card data, and EMV chip terminals with PIN capability as required.
+4. If fraud thresholds are exceeded, escalate the merchant account for human review immediately.
+5. Notify the acquiring compliance officer and record case details with supporting transaction data.
+6. Track investigation progress until the merchant returns to compliance or the account is terminated.
 
-Source authority: Mastercard SPME §3.7.
+These controls ensure Halyard Pay complies with Mastercard SPME §6.2 mandates regarding updated fraud monitoring and mitigation.
+
+Source authority: Mastercard SPME §§3.7, 6.2.