Mastercard SPME §10.3.2 · May 2023 → Sep 2023

Ongoing Procedures for ADC Events and Potential ADC Events

substantive

The updated section adds a new requirement for entities to consent and cooperate with Mastercard-led investigations if the customer fails in their responsibilities, in addition to the existing obligations for remediation planning and monitoring.

Sources Mastercard SPME · May 2023 · page 125 PDF Mastercard SPME · Sep 2023 · page 115 PDF Chargeback Handling current
Also in §10.x this release substantive §10 Should the responsible Customer cause a PFI to conduct an examination, the responsible substantive §10.2 Policy Concerning Account Data Compromise Events and Potential Account Data substantive §10.3 Responsibilities in Connection with ADC Events and Potential ADC Events substantive §10.3.1 Time-Specific Procedures for ADC Events and Potential ADC Events substantive §10.6.2 Potential Reduction of Financial Responsibility substantive §10.6.5 Determination of Fraud Recovery (FR) substantive §10.7 Assessments and/or Disqualification for Noncompliance
Why these edits? The updated section 10.3.2 introduces a new obligation for entities to consent to and cooperate with Mastercard-led investigations if the customer fails to fulfill their responsibilities, expanding the previous focus on remediation planning and monitoring.
Mastercard SPME §10.3.2
This section was substantively restructured between versions (34% text overlap). Compare the texts directly below.
Before · May 2023 · page 125

Security Rules and Procedures—Merchant Edition • 7 February 2023

  • Ensure that the compromised entity develops a remediation action plan, including implementation and milestone dates related to findings, corrective measures, and recommendations identified by the PFI and set forth in the final forensic report.
  • Monitor and validate that the compromised entity has fully implemented the remediation action plan, recommendations, and corrective measures.
After · Sep 2023 · page 115

Security Rules and Procedures—Merchant Edition • 1 August 2023

  • Consent to, and cooperate with, any effort by Mastercard to engage and direct a PFI to perform an investigation and prepare a forensic report concerning the ADC Event or Potential ADC Event, in the event that the Customer fails to satisfy any of the foregoing responsibilities.
  • Ensure that the compromised entity develops a remediation action plan, including implementation and milestone dates related to findings, corrective measures, and recommendations identified by the PFI and set forth in the final forensic report.
  • Monitor and validate that the compromised entity has fully implemented the remediation action plan, recommendations, and corrective measures.
Halyard Pay · 2 files
program: Chargeback Handling
- authority: Mastercard SPME §10.1 and §11.5
- acknowledgement_business_days: 1
+ authority: Mastercard SPME §10.1, §10.3.2, and §11.5
+ ecknowledgement_business_days: 1
lifecycle_states:
- first_presentment
- chargeback
- second_presentment
- pre_arbitration
- arbitration
evidence_requirements:
first_presentment:
- transaction_receipt
- authorization_record
chargeback:
- merchant_rebuttal_letter
- delivery_confirmation
- customer_communication
second_presentment:
- compelling_evidence
- signed_cardholder_agreement
pre_arbitration:
- full_dispute_record
- prior_correspondence
arbitration:
- full_dispute_record
- arbitration_filing
agent_owner: chargeback_agent
 
- # Updated to reflect refined definitions and thresholds relating to laundering, excessive chargebacks, fraudulent transactions, and bankruptcy as defined in Mastercard SPME §11.5 (2023 edition).
- # These criteria impact evaluation triggers and risk assessment during chargeback handling.
+ # Updated to include obligations for cooperation with Mastercard-led forensic investigations as per the revised Mastercard SPME §10.3.2, reflecting the requirement
+ # that compromised entities must consent and cooperate if customers fail their investigatory responsibilities.
+ # Existing criteria on remediation planning and monitoring continue as outlined.

Chargeback Handling

Chargebacks are cardholder-initiated disputes against a transaction. Halyard Pay, as the acquirer, manages the entire dispute lifecycle for its merchants, from initial first presentment through arbitration, in compliance with Mastercard's requirements.

Lifecycle overview

Disputes move through defined stages: first presentment, chargeback, second presentment (re-presentment), pre-arbitration, and arbitration. Adherence to strict evidence requirements and deadlines at each stage is critical to avoid automatic rulings against the acquirer.

Required actions

  1. Acknowledge each incoming chargeback within one business day.

  2. Collect the necessary evidence based on the current lifecycle stage.

  3. Submit second presentments when merchant liability is disputable, providing strong supporting evidence.

  4. Only escalate to pre-arbitration and arbitration after issuer rejection of the second presentment.

  5. Maintain full case documentation for audits and reporting.

6. Cooperate fully with Mastercard-initiated investigations and permit any qualified PFI to conduct forensic reviews if the merchant fails to meet required responsibilities, as outlined in Mastercard SPME §10.3.2.

Monitoring and Risk Factors

Halyard Pay monitors merchant risk factors including chargeback ratios, fraud rates, and financial stability. Updated Mastercard MATCH Listing Reason Codes define specific grounds for elevated scrutiny or match listing, including but not limited to laundering (presentation of invalid transaction records), excessive chargebacks (over 1% chargeback-to-sales ratio with minimum USD 5,000 monthly), excessive fraud (fraud-to-sales ratio of 8% or more including at least 10 fraudulent transactions totaling USD 5,000 or more), questionable merchant classification, and bankruptcy.

These refined definitions inform Halyard Pay's chargeback and risk management policies to ensure compliance and mitigate risk exposure.

Source authority: Mastercard SPME §§10.1, 10.3.2, 11.5.

policies/chargeback_handling/policy.md — after applying change

Chargeback Handling

Chargebacks are cardholder-initiated disputes against a transaction. Halyard Pay, as the acquirer, manages the entire dispute lifecycle for its merchants, from initial first presentment through arbitration, in compliance with Mastercard's requirements.

Lifecycle overview

Disputes move through defined stages: first presentment, chargeback, second presentment (re-presentment), pre-arbitration, and arbitration. Adherence to strict evidence requirements and deadlines at each stage is critical to avoid automatic rulings against the acquirer.

Required actions

  1. Acknowledge each incoming chargeback within one business day.

  2. Collect the necessary evidence based on the current lifecycle stage.

  3. Submit second presentments when merchant liability is disputable, providing strong supporting evidence.

  4. Only escalate to pre-arbitration and arbitration after issuer rejection of the second presentment.

  5. Maintain full case documentation for audits and reporting.

6. Cooperate fully with Mastercard-initiated investigations and permit any qualified PFI to conduct forensic reviews if the merchant fails to meet required responsibilities, as outlined in Mastercard SPME §10.3.2.

Monitoring and Risk Factors

Halyard Pay monitors merchant risk factors including chargeback ratios, fraud rates, and financial stability. Updated Mastercard MATCH Listing Reason Codes define specific grounds for elevated scrutiny or match listing, including but not limited to laundering (presentation of invalid transaction records), excessive chargebacks (over 1% chargeback-to-sales ratio with minimum USD 5,000 monthly), excessive fraud (fraud-to-sales ratio of 8% or more including at least 10 fraudulent transactions totaling USD 5,000 or more), questionable merchant classification, and bankruptcy.

These refined definitions inform Halyard Pay's chargeback and risk management policies to ensure compliance and mitigate risk exposure.

Source authority: Mastercard SPME §§10.1, 10.3.2, 11.5.

Source authority: Mastercard SPME §10.3.2.

--- a/policies/chargeback_handling/rules.yaml
+++ b/policies/chargeback_handling/rules.yaml
@@ -1,6 +1,6 @@
 program: Chargeback Handling
-authority: Mastercard SPME §10.1 and §11.5
-acknowledgement_business_days: 1
+authority: Mastercard SPME §10.1, §10.3.2, and §11.5
+ecknowledgement_business_days: 1
 lifecycle_states:
   - first_presentment
   - chargeback
@@ -26,5 +26,6 @@
     - arbitration_filing
 agent_owner: chargeback_agent
 
-# Updated to reflect refined definitions and thresholds relating to laundering, excessive chargebacks, fraudulent transactions, and bankruptcy as defined in Mastercard SPME §11.5 (2023 edition).
-# These criteria impact evaluation triggers and risk assessment during chargeback handling.+# Updated to include obligations for cooperation with Mastercard-led forensic investigations as per the revised Mastercard SPME §10.3.2, reflecting the requirement
+# that compromised entities must consent and cooperate if customers fail their investigatory responsibilities.
+# Existing criteria on remediation planning and monitoring continue as outlined.

--- a/policies/chargeback_handling/policy.md
+++ b/policies/chargeback_handling/policy.md
@@ -13,6 +13,7 @@
 3. Submit second presentments when merchant liability is disputable, providing strong supporting evidence.
 4. Only escalate to pre-arbitration and arbitration after issuer rejection of the second presentment.
 5. Maintain full case documentation for audits and reporting.
+6. Cooperate fully with Mastercard-initiated investigations and permit any qualified PFI to conduct forensic reviews if the merchant fails to meet required responsibilities, as outlined in Mastercard SPME §10.3.2.
 
 ## Monitoring and Risk Factors
 
@@ -20,4 +21,4 @@
 
 These refined definitions inform Halyard Pay's chargeback and risk management policies to ensure compliance and mitigate risk exposure.
 
-Source authority: Mastercard SPME §§10.1, 11.5.+Source authority: Mastercard SPME §§10.1, 10.3.2, 11.5.