Mastercard SPME §7 · Jun 2022 → May 2023
Availability control
The section was updated to detail specific technical and organizational measures needed to protect Personal Data from accidental destruction or loss, including backup procedures, disk mirroring, uninterruptible power supplies, remote storage, antivirus/firewall systems, and disaster recovery plans.
identification information to the Covered Programs, unless as permitted under applicable law. D.6 Data Transfers A Customer may transfer the Personal Data Processed in connection with the Covered Programs outside of the EEA in accordance with EU Data Protection Law. Covered Programs Privacy and Data Protection Standards D.5 The Corporation and Customer Obligations Security Rules and Procedures—Merchant Edition • 22 February 2022
The Corporation may transfer the Personal Data Processed in connection with the Covered Programs outside of the EEA in accordance with the Mastercard BCRs or with any other lawful data transfer mechanism that provides an adequate level of protection under EU Data Protection Law. The Corporation will abide by the Mastercard BCRs when Processing Personal Data in the context of the Covered Programs. D.7 Data Disclosures The Corporation and its Customers must ensure that they will only disclose Personal Data Processed in the context of the Covered Programs in accordance with EU Data Protection Law, and in particular that they will require the data recipients to protect the data with at least the same level of protection as described in this appendix. The Corporation represents and warrants that it will only disclose Personal Data in accordance with the Mastercard BCRs. D.8 Security Measures The Corporation and its Customers must implement and maintain a comprehensive written information security program with appropriate technical and organizational measures to ensure a level of security appropriate to the risk, which includes, at a minimum, as appropriate: (1) the pseudonymization and encryption of Personal Data; (2) the ability to ensure the ongoing confidentiality, integrity, availability, and resilience of processing systems and services; (3) the ability to restore the availability and access to Personal Data in a timely manner in the event of a physical or technical incident; and (4) a process for regularly testing, assessing, and evaluating the effectiveness of technical and organizational measures for ensuring the security of the Processing. In assessing the appropriate level of security, the Corporation and its Customers must take into account the state of the art; the costs of implementation; and the nature, scope, context, and purposes of Processing of Personal Data; as well as the risk of varying likelihood and severity for the rights and freedoms of Data Subjects and the risks that are presented by the Processing of Personal Data, in particular from accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data transmitted, stored, or otherwise Processed. D.9 Confidentiality of Personal Data The Corporation and its Customers must take steps to ensure that any person acting under their authority who has access to Personal Data is subject to a duly Covered Programs Privacy and Data Protection Standards D.7 Data Disclosures Security Rules and Procedures—Merchant Edition • 22 February 2022
enforceable contractual or statutory confidentiality obligation, and if applicable, Process Personal Data in accordance with the Controller’s instructions. D.10 Personal Data Breach Notification Requirements The Parties will assist each other in complying with their Personal Data Breach notification obligations. Where required under EU Data Protection Law, the Party which became aware of a Personal Data Breach will notify, without undue delay and, where feasible, not later than 72 hours after having become aware of it, the competent supervisory authority. When the Personal Data Breach is likely to result in a high risk to the rights and freedoms of Data Subjects or upon the competent supervisory authority’s request to do so, such Party must communicate the Personal Data Breach to the Data Subject without undue delay, where required under EU Data Protection Law. D.11 Personal Data Breach Cooperation and Documentation Requirements The Corporation and its Customers will use their best efforts to reach an agreement on whether and how to notify each other when a Personal Data Breach occurs, and must document all Personal Data Breaches, including the facts relating to the Personal Data Breach, its effects, and the remedial action taken. D.12 Data Protection and Security Audit The Corporation and each Customer must conduct audits on a regular basis to control compliance with EU Data Protection Law, including the security measures provided in section D.8, and the Corporation must comply with the Mastercard BCRs. Upon prior written request, the Corporation and each Customer agrees to cooperate and, within reasonable time, provide the requesting Party with: (1) a summary of the audit reports demonstrating its compliance with EU Data Protection Law obligations and the Standards in this appendix, and as applicable Mastercard BCRs, after redacting any confidential and commercially sensitive information; and (2) confirmation that the audit has not revealed any material vulnerability, or to the extent that any such vulnerability was detected, that such vulnerability has been fully remedied. Covered Programs Privacy and Data Protection Standards D.10 Personal Data Breach Notification Requirements Security Rules and Procedures—Merchant Edition • 22 February 2022
D.13 Liability Subject to the liability clauses in the Standards, the Corporation and each Customer agrees that it will be liable towards Data Subjects for the entire damage resulting from a violation of EU Data Protection Law with regard to Processing of Personal Data for which it is a Controller. Where the Parties are involved in the same Processing and where they are responsible for any damage caused by the Processing of Personal Data, both the Corporation and each responsible Customer may be held liable for the entire damage in order to ensure effective compensation of the Data Subject. If the Corporation paid full compensation for the damage suffered, the Corporation is entitled to claim back from the Customer(s) that part of the compensation corresponding to each Customer’s part of responsibility for the damage. D.14 Termination of the Covered Programs Use Mastercard and its Customers agree that the Standards in this appendix are no longer applicable to a Customer upon the termination of such Customer’s use of the Covered Programs. D.15 Invalidity and Severability If any Standard in this appendix is found by any court or administrative body of competent jurisdiction to be invalid or unenforceable, the invalidity or unenforceability of such Standard shall not affect any other Standard in this appendix, and all Standards not affected by such invalidity or unenforceability will remain in full force and effect. Covered Programs Privacy and Data Protection Standards D.13 Liability Security Rules and Procedures—Merchant Edition • 22 February 2022
Appendix E Definitions The following terms as used in this manual have the meanings set forth below. Acceptance Mark...........................................................................................................................161 Access Device..................................................................................................................................161 Account............................................................................................................................................161 Account Enablement System......................................................................................................162 Account Holder...............................................................................................................................162 Account PAN...................................................................................................................................162 Account PAN Range...................................................................................................................... 162 Acquirer............................................................................................................................................162 Activity(ies).....................................................................................................................................162 Affiliate Customer, Affiliate........................................................................................................162 Applicable Data Protection Law................................................................................................163 Area of Use......................................................................................................................................163 Association Customer, Association........................................................................................... 163 ATM Access Fee..............................................................................................................................163 ATM Owner Agreement................................................................................................................164 ATM Terminal..................................................................................................................................164 ATM Transaction............................................................................................................................164 Automated Teller Machine (ATM)..............................................................................................164 Bank Branch Terminal...................................................................................................................164 BIN.....................................................................................................................................................164 Brand Fee........................................................................................................................................ 164 Brand Mark..................................................................................................................................... 165 Card..................................................................................................................................................165 Cardholder...................................................................................................................................... 165 Cardholder Communication........................................................................................................165 Cardholder Verification Method (CVM)................................................................................... 165 Chip Card (Smart Card, Integrated Circuit Card, IC Card, or ICC)................................... 166 Chip-only MPOS Terminal............................................................................................................166 Chip Transaction............................................................................................................................166 Cirrus Acceptance Mark...............................................................................................................166 Cirrus Access Device..................................................................................................................... 166 Cirrus Account................................................................................................................................167 Cirrus Brand Mark.........................................................................................................................167 Cirrus Card......................................................................................................................................167 Definitions Security Rules and Procedures—Merchant Edition • 22 February 2022
Cirrus Customer.............................................................................................................................167 Cirrus Payment Application........................................................................................................ 167 Cirrus Word Mark..........................................................................................................................167 Competing ATM Network............................................................................................................167 Competing EFT POS Network....................................................................................................168 Competing International ATM Network...................................................................................168 Competing North American ATM Network............................................................................. 168 Consumer Device Cardholder Verification Method, Consumer Device CVM, CDCVM..169 Contact Chip Transaction............................................................................................................169 Contactless Payment Device......................................................................................................169 Contactless Transaction.............................................................................................................. 169 Control, Controlled........................................................................................................................169 Corporation.....................................................................................................................................170 Corporation System......................................................................................................................170 Credentials Management System.............................................................................................170 Cross-border Transaction............................................................................................................170 Customer.........................................................................................................................................170 Customer Report...........................................................................................................................171 Data Storage Entity (DSE).........................................................................................................171 Data Subject...................................................................................................................................171 Device Binding................................................................................................................................171 Digital Activity(ies)........................................................................................................................171 Digital Activity Agreement..........................................................................................................172 Digital Activity Customer............................................................................................................172 Digital Activity Service Provider (DASP)..................................................................................172 Digital Activity Sponsoring Customer...................................................................................... 172 Digital Goods..................................................................................................................................172 Digital Wallet..................................................................................................................................172 Digital Wallet Operator (DWO).................................................................................................172 Digital Wallet Operator Mark, DWO Mark..............................................................................173 Digital Wallet Operator (DWO) Security Incident, DWO Security Incident.................... 173 Digitization, Digitize......................................................................................................................173 Domestic Transaction...................................................................................................................173 Dual Interface.................................................................................................................................173 Electronic Money............................................................................................................................173 Electronic Money Institution....................................................................................................... 174 Electronic Money Issuer................................................................................................................174 EMV Mode Contactless Transaction.........................................................................................174 End User...........................................................................................................................................174 Definitions Security Rules and Procedures—Merchant Edition • 22 February 2022
Gateway Customer.......................................................................................................................174 Gateway Processing..................................................................................................................... 174 Gateway Transaction................................................................................................................... 175 Global Collection Only (GCO) Data Collection Program..................................................... 175 Host Card Emulation (HCE)....................................................................................................... 175 Hybrid Terminal..............................................................................................................................175 ICA.....................................................................................................................................................175 Identification & Verification (ID&V)...........................................................................................176 Independent Sales Organization (ISO).....................................................................................176 Installment Lending Agreement.................................................................................................176 Interchange System......................................................................................................................176 Interregional Transaction.............................................................................................................176 Intracountry Transaction............................................................................................................. 176 Intra–European Transaction....................................................................................................... 177 Intra–Non–SEPA Transaction.....................................................................................................177 Intraregional Transaction.............................................................................................................177 Issuer................................................................................................................................................ 177 License, Licensed............................................................................................................................177 Licensee........................................................................................................................................... 177 Maestro............................................................................................................................................178 Maestro Acceptance Mark...........................................................................................................178 Maestro Access Device.................................................................................................................178 Maestro Account............................................................................................................................178 Maestro Brand Mark.....................................................................................................................178 Maestro Card..................................................................................................................................178 Maestro Customer........................................................................................................................178 Maestro Payment Application....................................................................................................179 Maestro Word Mark......................................................................................................................179 Magnetic Stripe Mode Contactless Transaction....................................................................179 Manual Cash Disbursement Transaction.................................................................................179 Marks................................................................................................................................................179 Mastercard......................................................................................................................................179 Mastercard Acceptance Mark.....................................................................................................180 Mastercard Access Device...........................................................................................................180 Mastercard Account......................................................................................................................180 Mastercard Biometric Card.........................................................................................................180 Mastercard-branded Application Identifier (AID)..................................................................180 Mastercard Brand Mark...............................................................................................................180 Mastercard Card............................................................................................................................180 Definitions Security Rules and Procedures—Merchant Edition • 22 February 2022
Mastercard Cloud-Based Payments......................................................................................... 181 Mastercard Consumer-Presented QR Transaction................................................................181 Mastercard Customer.................................................................................................................. 181 Mastercard Digital Enablement Service.................................................................................. 181 Mastercard Europe........................................................................................................................181 Mastercard Incorporated.............................................................................................................182 Mastercard Payment Application..............................................................................................182 Mastercard Safety Net.................................................................................................................182 Mastercard Symbol.......................................................................................................................182 Mastercard Token..........................................................................................................................182 Mastercard Token Account Range............................................................................................. 182 Mastercard Token Vault............................................................................................................... 183 Mastercard Word Mark................................................................................................................183 Member, Membership...................................................................................................................183 Merchandise Transaction.............................................................................................................183 Merchant......................................................................................................................................... 183 Merchant Agreement....................................................................................................................184 Merchant Token Requestor..........................................................................................................184 Mobile Payment Device................................................................................................................184 Mobile POS (MPOS) Terminal.....................................................................................................184 MoneySend Payment Transaction.............................................................................................184 Multi-Account Chip Card............................................................................................................. 184 Non-Mastercard Funding Source...............................................................................................185 Non-Mastercard Receiving Account..........................................................................................185 Non-Mastercard Systems and Networks Standards............................................................ 185 On-behalf Token Requestor.........................................................................................................185 On-Device Cardholder Verification............................................................................................185 Originating Account Holder.........................................................................................................185 Originating Institution (OI)..........................................................................................................185 Ownership, Owned........................................................................................................................186 Participation...................................................................................................................................186 Pass-through Digital Wallet........................................................................................................186 Pass-through Digital Wallet Operator (DWO).......................................................................186 Payment Account Reference (PAR)........................................................................................... 186 Payment Application.....................................................................................................................186 Payment Facilitator......................................................................................................................187 Payment Transaction....................................................................................................................187 Payment Transfer Activity(ies) (PTA)....................................................................................... 187 Personal Data.................................................................................................................................187 Definitions Security Rules and Procedures—Merchant Edition • 22 February 2022
Point of Interaction (POI)............................................................................................................187 Point-of-Sale (POS) Terminal.....................................................................................................187 Point–of–Sale (POS) Transaction..............................................................................................188 Portfolio...........................................................................................................................................188 Principal Customer, Principal......................................................................................................188 Processed PTA Transaction......................................................................................................... 188 Processed Transaction..................................................................................................................189 Processing of Personal Data.......................................................................................................189 Program...........................................................................................................................................189 Program Service.............................................................................................................................189 PTA Account....................................................................................................................................189 PTA Account Number....................................................................................................................190 PTA Account Portfolio...................................................................................................................190 PTA Agreement..............................................................................................................................190 PTA Customer................................................................................................................................ 190 PTA Originating Account..............................................................................................................190 PTA Program...................................................................................................................................190 PTA Receiving Account................................................................................................................. 190 PTA Settlement Guarantee Covered Program....................................................................... 191 PTA Settlement Obligation ........................................................................................................ 191 PTA Transaction.............................................................................................................................191 Quick Response (QR) Code .........................................................................................................191 Receiving Account Holder............................................................................................................ 191 Receiving Agent..............................................................................................................................191 Receiving Customer...................................................................................................................... 191 Receiving Institution (RI)..............................................................................................................192 Region...............................................................................................................................................192 Remote Electronic Transaction ..................................................................................................192 Service Provider............................................................................................................................. 192 Settlement Obligation..................................................................................................................192 Shared Deposit Transaction........................................................................................................192 Solicitation, Solicit.........................................................................................................................193 Special Issuer Program.................................................................................................................193 Sponsor, Sponsorship....................................................................................................................193 Sponsored Digital Activity Entity...............................................................................................193 Staged Digital Wallet...................................................................................................................193 Staged Digital Wallet Operator (DWO).................................................................................. 194 Standards........................................................................................................................................194 Stand-In Parameters....................................................................................................................194 Definitions Security Rules and Procedures—Merchant Edition • 22 February 2022
Stand-In Processing Service........................................................................................................194 Strong Customer Authentication (SCA)..................................................................................195 Sub-licensee....................................................................................................................................195 Submerchant..................................................................................................................................195 Submerchant Agreement............................................................................................................ 195 Terminal...........................................................................................................................................195 Third Party Processor (TPP)........................................................................................................195 Token.................................................................................................................................................195 Tokenization, Tokenize.................................................................................................................. 196 Token Requestor.............................................................................................................................196 Token Vault......................................................................................................................................196 Transaction......................................................................................................................................196 Transaction Data...........................................................................................................................196 Transaction Management System.............................................................................................196 Trusted Service Manager.............................................................................................................197 Virtual Account...............................................................................................................................197 Volume..............................................................................................................................................197 Wallet Token Requestor............................................................................................................... 197 Word Mark.......................................................................................................................................197 Inter-European Transaction........................................................................................................197 Definitions Security Rules and Procedures—Merchant Edition • 22 February 2022
Additional and/or revised terms may also be used for purposes of the Rules in a particular chapter or section of this manual. Acceptance Mark Any one of the Corporation’s Marks displayed at a Point of Interaction (POI) to indicate brand acceptance. See Cirrus Acceptance Mark, Maestro Acceptance Mark, Mastercard Acceptance Mark. Access Device A device other than a Card that has successfully completed all applicable Mastercard certification and testing requirements, if any, and:
- Uses at least one Payment Application provisioned to the device by or with the approval of a Customer to provide access to an Account;
- Supports the transmission or exchange of data using one or both of the following: – Magnetic stripe or chip data containing a dynamic cryptogram to or with a Terminal, as applicable, by implementing the EMV Contactless Specifications (Book D) to effect Transactions at the Terminal without requiring direct contact of the device to the Terminal – Chip data containing a dynamic cryptogram to or with a Terminal, as applicable, by implementing the Mastercard Cloud-Based Payments (MCBP) documentation to effect Transactions at the Terminal by capture of a QR Code containing the Transaction Data
- May also support the transmission of magnetic stripe data containing a dynamic cryptogram to a Terminal to effect Transactions identified by the Acquirer in Transaction messages as magnetic stripe Transactions. A Cirrus Access Device, Maestro Access Device, and Mastercard Access Device is each an Access Device. Also see Mobile Payment Device. Account An account maintained by or on behalf of a Cardholder by an Issuer for the processing of Transactions, and which is identified with a bank identification number (BIN) or Issuer identification number (IIN) designated by the Corporation in its routing tables for routing to the Interchange System. Also see Cirrus Account, Maestro Account, Mastercard Account. Definitions Acceptance Mark Security Rules and Procedures—Merchant Edition • 22 February 2022 Account Enablement System Performs Account enablement services for Mastercard Cloud-Based Payments, which may include Account and Access Device eligibility checks, Identification & Verification (ID&V), Digitization, and subsequent lifecycle management. Account Holder A user who holds a PTA Account and has agreed to participate in a PTA Transaction. Account PAN The primary account number (PAN) allocated to an Account by an Issuer. Account PAN Range The range of Account PANs designated by an Issuer for Digitization. Acquirer A Customer in its capacity as an acquirer of a Transaction. Activity(ies) The undertaking of any lawful act that can be undertaken only pursuant to a License granted by the Corporation. Payment Transfer Activity is a type of Activity. Also see Digital Activity(ies). Affiliate Customer, Affiliate A Customer that participates indirectly in Activity through the Sponsorship of a Principal or, solely with respect to Mastercard Activity, through the Sponsorship of an Association. An Affiliate may not Sponsor any other Customer. Definitions Account Enablement System Security Rules and Procedures—Merchant Edition • 22 February 2022 Applicable Data Protection Law All applicable law, statute, declaration, decree, legislation, enactment, order, ordinance, regulation or rule (each as amended and replaced from time to time) which relates to the protection of individuals with regards to the Processing of Personal Data to which the Parties are subject, including but not limited to the EU General Data Protection Regulation 2016/679; the e-Privacy Directive 2002/58/EC and their national implementing legislations the California Consumer Privacy Act; the U.S. Gramm-Leach-Bliley Act; the Brazil General Data Protection Act; the South Africa Protection of Personal Information Act; laws regulating unsolicited email, telephone, and text message communications; security breach notification laws; laws imposing minimum security requirements; laws requiring the secure disposal of records containing certain Personal Data; laws governing the portability and/or cross-border transfer of Personal Data; and all other similar international, federal, state, provincial, and local requirements; each as applicable. Area of Use The country or countries in which a Customer is Licensed to use the Marks and conduct Activity or in which a PTA Customer is permitted to Participate in a PTA Program, and, as a rule, set forth in the License or PTA Agreement or in an exhibit to the License or PTA Agreement. Association Customer, Association A Mastercard Customer that participates directly in Mastercard Activity using its assigned BINs and which may Sponsor one or more Mastercard Affiliates but may not directly issue Mastercard Cards or acquire Mastercard Transactions, or in the case of a PTA Association, may not directly hold PTA Accounts, without the express prior written consent of the Corporation. ATM Access Fee A fee charged by an Acquirer in connection with a cash withdrawal or Shared Deposit Transaction initiated at the Acquirer’s ATM Terminal with a Card, and added to the total Transaction amount transmitted to the Issuer. Definitions Applicable Data Protection Law Security Rules and Procedures—Merchant Edition • 22 February 2022 ATM Owner Agreement An agreement between an ATM owner and a Customer that sets forth the terms pursuant to which the ATM accepts Cards. ATM Terminal An ATM that enables a Cardholder to effect an ATM Transaction with a Card (and if contactless-enabled, an Access Device) in accordance with the Standards. ATM Transaction A cash withdrawal effected at an ATM Terminal with a Card and processed through the Mastercard ATM Network. An ATM Transaction is identified with MCC 6011 (Automated Cash Disbursements—Customer Financial Institution). Automated Teller Machine (ATM) An unattended self-service device that performs basic banking functions such as accepting deposits, cash withdrawals, ordering transfers among accounts, loan payments and account balance inquiries. Bank Branch Terminal An attended device, located on the premises of a Customer or other financial institution designated as its authorized agent by the Corporation, that facilitates a Manual Cash Disbursement Transaction by a Cardholder. BIN A bank identification number (BIN, sometimes referred to as an Issuer identification number, or IIN) is a unique number assigned by Mastercard for use by a Customer in accordance with the Standards. Brand Fee A fee charged for certain Transactions not routed to the Interchange System. Definitions ATM Owner Agreement Security Rules and Procedures—Merchant Edition • 22 February 2022 Brand Mark A Word Mark as a custom lettering legend placed within the Corporation’s interlocking circles device. The Mastercard Brand Mark, Maestro Brand Mark, and Cirrus Brand Mark is each a Brand Mark. The Mastercard Symbol is also a Brand Mark. Card A card issued by a Customer pursuant to License and in accordance with the Standards and that provides access to an Account. Unless otherwise stated herein, Standards applicable to the use and acceptance of a Card are also applicable to an Access Device and, in a Card-not-present environment, an Account. A Cirrus Card, Maestro Card, and Mastercard Card is each a Card. Cardholder The authorized user of a Card or Access Device issued by a Customer. Cardholder Communication Any communication by or on behalf of an Issuer to a Cardholder or prospective Cardholder. A Solicitation is one kind of Cardholder Communication. Cardholder Verification Method (CVM) A process used to confirm that the person presenting the Card is an authorized Cardholder. The Corporation deems the following to be valid CVMs when used in accordance with the Standards:
- The comparison, by the Merchant or Acquirer accepting the Card, of the signature on the Card’s signature panel with the signature provided on the Transaction receipt by the person presenting the Card;
- The comparison, by the Card Issuer or the EMV chip on the Card, of the value entered on a Terminal’s PIN pad with the personal identification number (PIN) given to or selected by the Cardholder upon Card issuance; and
- The use of a Consumer Device CVM (CDCVM) that Mastercard approved as a valid CVM for Transactions upon the successful completion of the certification and testing procedures set forth in section 3.11 of the Security Rules and Procedures. Definitions Brand Mark Security Rules and Procedures—Merchant Edition • 22 February 2022 In certain Card-present environments, a Merchant may complete the Transaction without a CVM (“no CVM” as the CVM), such as in Quick Payment Service (QPS) Transactions, Contactless Transactions less than or equal to the CVM limit, and Transactions at an unattended Point-of-Sale (POS) Terminal identified as Cardholder-activated Terminal (CAT) Level 2 or Level 3. Chip Card (Smart Card, Integrated Circuit Card, IC Card, or ICC) A Card with an embedded EMV-compliant chip containing memory and interactive capabilities used to identify and store additional data about a Cardholder, an Account, or both. Chip-only MPOS Terminal An MPOS Terminal that has a contact chip reader and no magnetic stripe-reading capability and that must:
Technical and organizational measures to ensure that Personal Data are protected against accidental destruction or loss (physical/logical) include: – Backup procedures; – Mirroring of hard disks (e.g., RAID technology); – Uninterruptible power supply (UPS); – Remote storage; Covered Programs Privacy and Data Protection Standards Annex 2 to Appendix D: Technical and Organizational Measures Ensure the Security of the Data Security Rules and Procedures—Merchant Edition • 7 February 2023
– Anti-virus/firewall systems; – Disaster recovery plan.
program: Fraud Monitoring- authority: Mastercard SPME §3.7+ authority: Mastercard SPME §3.7 and §7fraud_to_sales_ratio_threshold: 0.015min_count_per_month: 100monitoring_cadence: monthlyescalation_actions:- escalate_to_human_review- notify_acquirerlookback_period_months: 1remediation_review_interval_days: 30agent_owner: fraud_ops_agent++ # Updated to reflect enhanced Mastercard SPME §7 requirements on availability control+ # including backup procedures, mirroring, UPS, remote storage, antivirus/firewall,+ # and disaster recovery plans to ensure the availability and integrity of data and+ # processing systems relevant to fraud monitoring.
Fraud Monitoring
Halyard Pay diligently monitors merchant fraud activity on each month to identify patterns surpassing Mastercard's established fraud-to-sales ratio thresholds. Specifically, a monthly basis to detect patterns that ¶ exceed Mastercard's acceptable fraud-to-sales thresholds. A merchant whose triggering this policy has a rolling ¶ monthly fraud-to-sales ratio meets or exceeds equal to or above 1.5% (0.015) and whose fraud count ¶ reaches has processed at least 100 fraudulent transactions in within that same month triggers mandatory escalation ¶ under this policy. month.
When this policy applies
This policy applies Applicable to all merchants processed whose transactions are routed through Halyard Pay's acquiring platform ¶ where Mastercard using Mastercard as the card network, this policy is the applicable card network. It governs relevant for both card-present and ¶ card-not-present transaction streams. types.
Required actions
ComputeCalculate the merchant's monthly rolling fraud-to-sales ratio.
2. Once the threshold ratio each calendar month. ¶ 2. If the ratio meets or exceeds the threshold AND the and minimum fraud count is reached, ¶ are both met or exceeded, promptly escalate the merchant account to human review immediately. review.
-
NotifyAlert the acquiring compliance officer anddocumentrecord the case ID along withsupporting ¶associated transactiondata.evidence. -
TrackMonitor the caseprogresscontinuously until the merchant's accountreturns to threshold compliance oris¶ terminated.back within acceptable risk thresholds or is closed.
## Availability and Security Controls
As part of maintaining effective fraud monitoring aligned with Mastercard SPME requirements, Halyard Pay ensures robust technical and organizational controls to maintain the availability and integrity of processing systems. This includes implementing backup procedures, disk mirroring (e.g., RAID), uninterruptible power supplies, remote storage, antivirus and firewall protections, and disaster recovery planning to safeguard Personal Data against accidental loss or disruption (cf. Mastercard SPME §7).
Source authority: Mastercard SPME §3.7.§3.7 and §7.
Fraud Monitoring
Halyard Pay diligently monitors merchant fraud activity on each month to identify patterns surpassing Mastercard's established fraud-to-sales ratio thresholds. Specifically, a monthly basis to detect patterns that ¶ exceed Mastercard's acceptable fraud-to-sales thresholds. A merchant whose triggering this policy has a rolling ¶ monthly fraud-to-sales ratio meets or exceeds equal to or above 1.5% (0.015) and whose fraud count ¶ reaches has processed at least 100 fraudulent transactions in within that same month triggers mandatory escalation ¶ under this policy. month.
When this policy applies
This policy applies Applicable to all merchants processed whose transactions are routed through Halyard Pay's acquiring platform ¶ where Mastercard using Mastercard as the card network, this policy is the applicable card network. It governs relevant for both card-present and ¶ card-not-present transaction streams. types.
Required actions
ComputeCalculate the merchant's monthly rolling fraud-to-sales ratio.
2. Once the threshold ratio each calendar month. ¶ 2. If the ratio meets or exceeds the threshold AND the and minimum fraud count is reached, ¶ are both met or exceeded, promptly escalate the merchant account to human review immediately. review.
-
NotifyAlert the acquiring compliance officer anddocumentrecord the case ID along withsupporting ¶associated transactiondata.evidence. -
TrackMonitor the caseprogresscontinuously until the merchant's accountreturns to threshold compliance oris¶ terminated.back within acceptable risk thresholds or is closed.
## Availability and Security Controls
As part of maintaining effective fraud monitoring aligned with Mastercard SPME requirements, Halyard Pay ensures robust technical and organizational controls to maintain the availability and integrity of processing systems. This includes implementing backup procedures, disk mirroring (e.g., RAID), uninterruptible power supplies, remote storage, antivirus and firewall protections, and disaster recovery planning to safeguard Personal Data against accidental loss or disruption (cf. Mastercard SPME §7).
Source authority: Mastercard SPME §3.7.§3.7 and §7.
Source authority: Mastercard SPME §7.
--- a/policies/fraud_monitoring/rules.yaml +++ b/policies/fraud_monitoring/rules.yaml @@ -1,5 +1,5 @@ program: Fraud Monitoring -authority: Mastercard SPME §3.7 +authority: Mastercard SPME §3.7 and §7 fraud_to_sales_ratio_threshold: 0.015 min_count_per_month: 100 monitoring_cadence: monthly @@ -9,3 +9,8 @@ lookback_period_months: 1 remediation_review_interval_days: 30 agent_owner: fraud_ops_agent + +# Updated to reflect enhanced Mastercard SPME §7 requirements on availability control +# including backup procedures, mirroring, UPS, remote storage, antivirus/firewall, +# and disaster recovery plans to ensure the availability and integrity of data and +# processing systems relevant to fraud monitoring. --- a/policies/fraud_monitoring/policy.md +++ b/policies/fraud_monitoring/policy.md @@ -1,25 +1,20 @@ # Fraud Monitoring -Halyard Pay monitors merchant fraud activity on a monthly basis to detect patterns that -exceed Mastercard's acceptable fraud-to-sales thresholds. A merchant whose rolling -monthly fraud-to-sales ratio meets or exceeds 1.5% (0.015) and whose fraud count -reaches at least 100 transactions in that same month triggers mandatory escalation -under this policy. +Halyard Pay diligently monitors merchant fraud activity each month to identify patterns surpassing Mastercard's established fraud-to-sales ratio thresholds. Specifically, a merchant triggering this policy has a rolling monthly fraud-to-sales ratio equal to or above 1.5% (0.015) and has processed at least 100 fraudulent transactions within that month. ## When this policy applies -This policy applies to all merchants processed through Halyard Pay's acquiring platform -where Mastercard is the applicable card network. It governs both card-present and -card-not-present transaction streams. +Applicable to all merchants whose transactions are routed through Halyard Pay's acquiring platform using Mastercard as the card network, this policy is relevant for both card-present and card-not-present transaction types. ## Required actions -1. Compute the merchant's rolling fraud-to-sales ratio each calendar month. -2. If the ratio meets or exceeds the threshold AND the minimum count is reached, - escalate the merchant account to human review immediately. -3. Notify the acquiring compliance officer and document the case ID with supporting - transaction data. -4. Track case progress until the account returns to threshold compliance or is - terminated. +1. Calculate the merchant's monthly rolling fraud-to-sales ratio. +2. Once the threshold ratio and minimum fraud count are both met or exceeded, promptly escalate the merchant account to human review. +3. Alert the acquiring compliance officer and record the case ID along with associated transaction evidence. +4. Monitor the case continuously until the merchant's account is back within acceptable risk thresholds or is closed. -Source authority: Mastercard SPME §3.7. +## Availability and Security Controls + +As part of maintaining effective fraud monitoring aligned with Mastercard SPME requirements, Halyard Pay ensures robust technical and organizational controls to maintain the availability and integrity of processing systems. This includes implementing backup procedures, disk mirroring (e.g., RAID), uninterruptible power supplies, remote storage, antivirus and firewall protections, and disaster recovery planning to safeguard Personal Data against accidental loss or disruption (cf. Mastercard SPME §7). + +Source authority: Mastercard SPME §3.7 and §7.