Mastercard SPME §10.2 · May 2023 → Sep 2023

Policy Concerning Account Data Compromise Events and Potential Account Data

substantive
⚠ Extraction warning — review against source PDF. One side of the Mastercard SPME text below appears to contain only the page-running header, not body content. This usually means the section heading fell on a page boundary and the body was attributed to a neighbouring section in the source PDF. The AI summary and proposed edit below may be misleading. Verify in: May 2023 · page 6 ↗ · Sep 2023 · page 6 ↗.

The updated section clarifies Mastercard's authority over Account Data Compromise (ADC) Events, emphasizing that Mastercard has the final say on ADC occurrences, can impose assessments, recover costs, and enforce standards. It also details how multiple related breaches might be considered a single ADC event and advises customers to seek guidance if uncertain.

Sources Mastercard SPME · May 2023 · page 6 PDF Mastercard SPME · Sep 2023 · page 6 PDF BRAM Response current
Also in §10.x this release substantive §10 Should the responsible Customer cause a PFI to conduct an examination, the responsible substantive §10.3 Responsibilities in Connection with ADC Events and Potential ADC Events substantive §10.3.1 Time-Specific Procedures for ADC Events and Potential ADC Events substantive §10.3.2 Ongoing Procedures for ADC Events and Potential ADC Events substantive §10.6.2 Potential Reduction of Financial Responsibility substantive §10.6.5 Determination of Fraud Recovery (FR) substantive §10.7 Assessments and/or Disqualification for Noncompliance
Why these edits? The update to section 10.2 clarifies Mastercard's exclusive authority to determine the occurrence and responsibility for ADC Events and their consolidated handling, affecting how investigations and responses must be managed according to Mastercard's determinations.
Mastercard SPME §10.2
This section was substantively restructured between versions (6% text overlap). Compare the texts directly below.
Before · May 2023 · page 6

Compromise Events Security Rules and Procedures—Merchant Edition • 7 February 2023

After · Sep 2023 · page 6

Compromise Events Security Rules and Procedures—Merchant Edition • 1 August 2023

is in the best position to safeguard its systems, to require and monitor the safeguarding of its Agents’ systems, and to insure against, and respond to, ADC Events and Potential ADC Events. Mastercard requires that each Customer apply the utmost diligence and forthrightness in protecting against and responding to any ADC Event or Potential ADC Event. Each Customer acknowledges and agrees that Mastercard has both the right and need to obtain full disclosure (as determined by Mastercard) concerning the causes and effects of an ADC Event or Potential ADC Event as well as the authority to impose assessments, recover costs, and administer compensation, if appropriate, to Customers that have incurred costs, expenses, losses, and/or other liabilities in connection with ADC Events and Potential ADC Events. Except as otherwise expressly provided for in the Standards, Mastercard determinations with respect to the occurrence of and responsibility for ADC Events or Potential ADC Events are conclusive and are not subject to appeal or review within Mastercard. Any Customer that is uncertain with respect to rights and obligations relating to or arising in connection with the Account Data Compromise Event Standards and Programs set forth in this Chapter 10 should request advice from Mastercard. Notwithstanding the generality of the foregoing, the relationship of network, system, and environment configurations with other networks, systems, and environments will often vary, and each ADC Event and Potential ADC Event tends to have its own particular set of circumstances. Mastercard has the sole authority to interpret and enforce the Standards, including those set forth in this chapter. Consistent with the foregoing and pursuant to the definitions set forth in section 10.1 above, Mastercard may determine, as a threshold matter, whether a given set of circumstances constitutes a single ADC Event or multiple ADC Events. In this regard, and by way of example, where a Customer or Merchant connects to, utilizes, accesses, or participates in a common network, system, or environment with one or more other Customers, Merchants, Service Providers, or third parties, a breach of the common network, system, or environment that results, directly or indirectly, in the compromise of local networks, systems, or environments connected thereto may be deemed to constitute a single ADC Event.

Halyard Pay · 2 files
program: BRAM
authority: Mastercard SPME §8.6.2, §10.2
response_window_days: 180
required_evidence:
- transaction_monitoring_records
- corrective_action_plan
- - police_report # Added requirement for police report according to updated SPME §8.6.2
+ - police_report # Mandatory inclusion per updated SPME §8.6.2
halt_actions:
- halt_new_merchant_onboarding
internal_notification_hours: 24
agent_owner: bram_response_agent
 
- # Updated to reflect the extended discretionary investigation period and mandatory police report inclusion for at least one coercion claim as specified in Mastercard SPME §8.6.2.
+ # Reflects updated police report requirement and acknowledges Mastercard's exclusive authority to determine ADC Event occurrence and responsibility as clarified in SPME §10.2.
+ # Policy recognizes Mastercard's sole discretion in classifying and consolidating ADC Events to ensure proper investigation and response procedures.

BRAM Investigation Response

When Mastercard issues a Business Risk Assessment and Mitigation (BRAM) investigation

notice for one of our merchants, the acquirer must halt new merchant onboarding

immediately and submit an evidence package within one hundred eighty (180) days

of receipt of the notice.

Required actions

  1. Halt new merchant onboarding for the merchant under investigation.

  2. Compile and submit an evidence package containing:

  • Transaction monitoring records covering the prior 180 days.

  • A written corrective action plan.

  • Documentation of any police reports related to alleged coercion claims if applicable.

  1. Notify the Halyard Pay Compliance lead within 24 hours of receipt.

Additional Considerations for Coercion Claims

When allegations of coerced Transactions arise, note that Mastercard may extend the usual 120-day

investigation period at its discretion. At least one claim must include a police report from the Cardholder.

Transactions reported as Lost or Stolen Fraud (fraud type codes 00 or 01) are subject to investigation,

though Mastercard may consider other fraud codes. Mastercard will notify issuers with Transactions at the

merchant within the investigation period to prompt claim submissions.

## Mastercard's Authority and Determinations on ADC Events

Mastercard retains exclusive authority to determine the occurrence, scope, and responsibility for Account Data Compromise (ADC) Events or Potential ADC Events, including the consolidation of related incidents into single or multiple events where applicable. Mastercard’s decisions in these matters are final and not subject to internal appeal. Customers are advised to seek Mastercard guidance if uncertain about their rights or obligations related to ADC Events. This framework ensures accountability and proper management of ADC risks in line with Mastercard's network security standards.

Source authority: Mastercard SPME §8.6.2, §10.2.

policies/bram_response/policy.md — after applying change

BRAM Investigation Response

When Mastercard issues a Business Risk Assessment and Mitigation (BRAM) investigation

notice for one of our merchants, the acquirer must halt new merchant onboarding

immediately and submit an evidence package within one hundred eighty (180) days

of receipt of the notice.

Required actions

  1. Halt new merchant onboarding for the merchant under investigation.

  2. Compile and submit an evidence package containing:

  • Transaction monitoring records covering the prior 180 days.

  • A written corrective action plan.

  • Documentation of any police reports related to alleged coercion claims if applicable.

  1. Notify the Halyard Pay Compliance lead within 24 hours of receipt.

Additional Considerations for Coercion Claims

When allegations of coerced Transactions arise, note that Mastercard may extend the usual 120-day

investigation period at its discretion. At least one claim must include a police report from the Cardholder.

Transactions reported as Lost or Stolen Fraud (fraud type codes 00 or 01) are subject to investigation,

though Mastercard may consider other fraud codes. Mastercard will notify issuers with Transactions at the

merchant within the investigation period to prompt claim submissions.

## Mastercard's Authority and Determinations on ADC Events

Mastercard retains exclusive authority to determine the occurrence, scope, and responsibility for Account Data Compromise (ADC) Events or Potential ADC Events, including the consolidation of related incidents into single or multiple events where applicable. Mastercard’s decisions in these matters are final and not subject to internal appeal. Customers are advised to seek Mastercard guidance if uncertain about their rights or obligations related to ADC Events. This framework ensures accountability and proper management of ADC risks in line with Mastercard's network security standards.

Source authority: Mastercard SPME §8.6.2, §10.2.

Source authority: Mastercard SPME §10.2.

--- a/policies/bram_response/rules.yaml
+++ b/policies/bram_response/rules.yaml
@@ -4,10 +4,11 @@
 required_evidence:
   - transaction_monitoring_records
   - corrective_action_plan
-  - police_report  # Added requirement for police report according to updated SPME §8.6.2
+  - police_report  # Mandatory inclusion per updated SPME §8.6.2
 halt_actions:
   - halt_new_merchant_onboarding
 internal_notification_hours: 24
 agent_owner: bram_response_agent
 
-# Updated to reflect the extended discretionary investigation period and mandatory police report inclusion for at least one coercion claim as specified in Mastercard SPME §8.6.2.+# Reflects updated police report requirement and acknowledges Mastercard's exclusive authority to determine ADC Event occurrence and responsibility as clarified in SPME §10.2.
+# Policy recognizes Mastercard's sole discretion in classifying and consolidating ADC Events to ensure proper investigation and response procedures.

--- a/policies/bram_response/policy.md
+++ b/policies/bram_response/policy.md
@@ -22,4 +22,8 @@
 though Mastercard may consider other fraud codes. Mastercard will notify issuers with Transactions at the
 merchant within the investigation period to prompt claim submissions.
 
-Source authority: Mastercard SPME §8.6.2, §10.2.
+## Mastercard's Authority and Determinations on ADC Events
+
+Mastercard retains exclusive authority to determine the occurrence, scope, and responsibility for Account Data Compromise (ADC) Events or Potential ADC Events, including the consolidation of related incidents into single or multiple events where applicable. Mastercard’s decisions in these matters are final and not subject to internal appeal. Customers are advised to seek Mastercard guidance if uncertain about their rights or obligations related to ADC Events. This framework ensures accountability and proper management of ADC risks in line with Mastercard's network security standards.
+
+Source authority: Mastercard SPME §8.6.2, §10.2.