Mastercard SPME §1.4.1 · May 2023 → Sep 2023
Minimum Security Requirements
Additional specifications were added clarifying that cabinets housing Service Delivery Point Equipment must be locked both in front and rear at all times, with keys stored securely.
At a minimum, the Customer or its agent must put in place the following controls at each facility housing Service Delivery Point Equipment:
Security Rules and Procedures—Merchant Edition • 1 August 2023
cabinet that is locked both in front and the rear at all times. Keys to the cabinet must be stored in a secured location.
program: Fraud Monitoringauthority: Mastercard SPME §3.7, §11.1.1fraud_to_sales_ratio_threshold: 0.015min_count_per_month: 100monitoring_cadence: monthlyescalation_actions:- escalate_to_human_review- notify_acquirerlookback_period_months: 1remediation_review_interval_days: 30agent_owner: fraud_ops_agent# MATCH fraud detection features are limited to principal owners only; associate owners and Service Provider name reporting are removed per SPME §11.1.1.# Acquirers may add and search for information on up to five principal owners per Merchant.# Multiple data fields are used to determine matches; MATCH supports editing and error notification to reduce delays.# Retroactive alert processing is supported for data up to 360 days old.# Acquirers control receipt and detail of inquiry match information.# Real-time access via MATCH Online and API, and batch operations remain available.# Merchant URL information may be added and searched.# Crucially, after obtaining MATCH inquiry results, Acquirers must assess whether further investigation or risk mitigation actions are warranted, per updated SPME requirements.+ #+ # Updated physical security requirements for Service Delivery Point Equipment cabinets require they be locked front and rear, with keys securely stored to prevent unauthorized access. This enhances foundational fraud prevention controls as mandated in Mastercard SPME §3.7.
Fraud Monitoring
Halyard Pay monitors merchant fraud activity and leverages Mastercard's MATCH system for enhanced fraud risk assessment on merchants processed through our platform.
When this policy applies
This policy applies to all merchants processed by Halyard Pay where Mastercard is the applicable network, covering both card-present and card-not-present transactions.
Required actions
-
Compute the merchant's rolling fraud-to-sales ratio each calendar month.
-
If the ratio meets or exceeds 1.5% and the fraud count reaches at least 100 transactions in that month, escalate the merchant account to human review immediately.
-
Utilize Mastercard's MATCH system data focusing on principal owners only, as per the updated Mastercard SPME guidelines. Do not consider associate owners or Service Provider names in fraud assessments.
-
Following MATCH data access, verify physical security controls at merchant facilities, ensuring cabinets housing Service Delivery Point Equipment are securely locked front and rear with keys stored securely, in accordance with section 1.4.1 of Mastercard SPME.
5. After accessing MATCH data, assessing both fraud metrics and physical security controls, conduct a risk assessment to determine whether further investigation or additional measures are warranted.
5. 6. Notify the acquiring compliance officer and document the case ID with supporting transaction data.
6. 7. Track case progress until the account returns to threshold compliance or is terminated.
Source authority: Mastercard SPME §3.7 §1.4.1, §3.7, and §11.1.1.
Fraud Monitoring
Halyard Pay monitors merchant fraud activity and leverages Mastercard's MATCH system for enhanced fraud risk assessment on merchants processed through our platform.
When this policy applies
This policy applies to all merchants processed by Halyard Pay where Mastercard is the applicable network, covering both card-present and card-not-present transactions.
Required actions
-
Compute the merchant's rolling fraud-to-sales ratio each calendar month.
-
If the ratio meets or exceeds 1.5% and the fraud count reaches at least 100 transactions in that month, escalate the merchant account to human review immediately.
-
Utilize Mastercard's MATCH system data focusing on principal owners only, as per the updated Mastercard SPME guidelines. Do not consider associate owners or Service Provider names in fraud assessments.
-
Following MATCH data access, verify physical security controls at merchant facilities, ensuring cabinets housing Service Delivery Point Equipment are securely locked front and rear with keys stored securely, in accordance with section 1.4.1 of Mastercard SPME.
5. After accessing MATCH data, assessing both fraud metrics and physical security controls, conduct a risk assessment to determine whether further investigation or additional measures are warranted.
5. 6. Notify the acquiring compliance officer and document the case ID with supporting transaction data.
6. 7. Track case progress until the account returns to threshold compliance or is terminated.
Source authority: Mastercard SPME §3.7 §1.4.1, §3.7, and §11.1.1.
Source authority: Mastercard SPME §1.4.1.
--- a/policies/fraud_monitoring/rules.yaml +++ b/policies/fraud_monitoring/rules.yaml @@ -18,3 +18,5 @@ # Real-time access via MATCH Online and API, and batch operations remain available. # Merchant URL information may be added and searched. # Crucially, after obtaining MATCH inquiry results, Acquirers must assess whether further investigation or risk mitigation actions are warranted, per updated SPME requirements. +# +# Updated physical security requirements for Service Delivery Point Equipment cabinets require they be locked front and rear, with keys securely stored to prevent unauthorized access. This enhances foundational fraud prevention controls as mandated in Mastercard SPME §3.7. --- a/policies/fraud_monitoring/policy.md +++ b/policies/fraud_monitoring/policy.md @@ -11,8 +11,9 @@ 1. Compute the merchant's rolling fraud-to-sales ratio each calendar month. 2. If the ratio meets or exceeds 1.5% and the fraud count reaches at least 100 transactions in that month, escalate the merchant account to human review immediately. 3. Utilize Mastercard's MATCH system data focusing on principal owners only, as per the updated Mastercard SPME guidelines. Do not consider associate owners or Service Provider names in fraud assessments. -4. After accessing MATCH data, conduct a risk assessment to determine whether further investigation or additional measures are warranted. -5. Notify the acquiring compliance officer and document the case ID with supporting transaction data. -6. Track case progress until the account returns to threshold compliance or is terminated. +4. Following MATCH data access, verify physical security controls at merchant facilities, ensuring cabinets housing Service Delivery Point Equipment are securely locked front and rear with keys stored securely, in accordance with section 1.4.1 of Mastercard SPME. +5. After assessing both fraud metrics and physical security controls, conduct a risk assessment to determine whether further investigation or additional measures are warranted. +6. Notify the acquiring compliance officer and document the case ID with supporting transaction data. +7. Track case progress until the account returns to threshold compliance or is terminated. -Source authority: Mastercard SPME §3.7 and §11.1.1. +Source authority: Mastercard SPME §1.4.1, §3.7, and §11.1.1.