Mastercard SPME §10 · May 2023 → Sep 2023
Should the responsible Customer cause a PFI to conduct an examination, the responsible
The updated section requires the responsible Customer to notify Mastercard within 24 hours when engaging a PFI for an investigation, with noncompliance penalties for failure. Alternatively, the Customer may investigate themselves if certain criteria are met, and must report findings, containment, and PCI DSS compliance within 20 business days. Mastercard may review and require remediation if risks persist.
to what the Issuer believes to be the appropriate MCC and why the Issuer believes that MCC to be appropriate Mastercard may initiate an MCC miscoding investigation without Issuer notification.
Customer must notify Mastercard within 24 hours of the engagement of the PFI. Failure to notify Mastercard within the 24-hour time frame may result in a noncompliance assessment as described in section 10.7. Alternatively, and provided the responsible Customer determines that Criterion C is satisfied, the responsible Customer itself may elect to investigate the Event in lieu of causing a PFI to conduct an examination of the Merchant or other Agent. If the responsible Customer itself elects to conduct the investigation, not later than twenty (20) business days following the date of the notice by Mastercard described above, the responsible Customer must provide to Mastercard that all of the following are true:
- The responsible Customer elected to investigate the ADC Event or Potential ADC Event in lieu of causing a PFI to investigate the ADC Event or Potential ADC Event; and
- The Merchant (or other Agent) that is the subject of the ADC Event or Potential ADC Event does not use a computer-based acceptance system that is used by another Merchant (or Agent) or is connected to Merchants (or Agents) or third parties; and
- The responsible Customer’s investigation of the ADC Event or Potential ADC Event has been completed and the ADC Event or Potential ADC Event has been fully contained. Documentation satisfactory to Mastercard confirming such containment (including the date of containment) and a written explanation of how the security event was contained (including the steps taken to ensure that Account data are no longer at risk of compromise) must be provided to Mastercard; and
- The Merchant has newly validated, or revalidated or has a road map to achieve compliance with the PCI DSS. Documentation confirming such validation or revalidation must be provided to Mastercard upon completion of the investigation. Failure to comply with any obligation of the responsible Customer may result in the imposition of a noncompliance assessment as described in section 10.7. Mastercard may conduct periodic reviews of an ADC Event or Potential ADC Event investigated by the responsible Customer to confirm that the Event has been fully contained. Should Mastercard determine that an Event continues to place Accounts at risk of unauthorized disclosure, Mastercard will provide notice to the responsible Customer by way of an email message to the responsible Customer’s Security Contact then listed in the My Company Manager application. Within ten (10) business days of such notice, the responsible Customer must provide to Mastercard a remediation action plan describing the steps (and relevant dates of the steps) Account Data Compromise Events
program: BRAM- authority: Mastercard SPME §8.6.2, §10.2+ authority: Mastercard SPME 6, 10.2, 10response_window_days: 180required_evidence:- transaction_monitoring_records- corrective_action_plan- - police_report # Added requirement for police report according to updated SPME §8.6.2+ - police_report+ - adc_event_containment_report # Added to reflect new containment documentation requirement from updated SPME 10halt_actions:- halt_new_merchant_onboardinginternal_notification_hours: 24+ notification_requirements:+ pfi_engagement_notice_hours: 24 # Customer must notify Mastercard within 24 hours of PFI engagement+ investigation_report_due_days: 20 # Investigation findings and PCI DSS validation/reporting required within 20 business daysagent_owner: bram_response_agent- # Updated to reflect the extended discretionary investigation period and mandatory police report inclusion for at least one coercion claim as specified in Mastercard SPME §8.6.2.+ # Updated per Mastercard SPME 10 to include:+ # - Mandatory 24-hour notification to Mastercard upon PFI engagement+ # - Option for Customers to conduct their own ADC Event investigation subject to strict reporting timelines+ # - Documentation requirements for ADC Event containment and PCI DSS compliance verification+ # - Potential noncompliance assessments for failures to meet these obligations+ #+ # These enhancements align the BRAM response process with the revised Mastercard SPME 10 to ensure timely and comprehensive incident management.
BRAM Investigation Response
When Mastercard issues a Business Risk Assessment and Mitigation (BRAM) investigation
notice for one of our merchants, the acquirer must halt new merchant onboarding
immediately and submit an evidence package within one hundred eighty (180) days
of receipt of the notice.
Required actions
-
Halt new merchant onboarding for the merchant under investigation.
-
Compile and submit an evidence package containing:
-
Transaction monitoring records covering the prior 180 days.
-
A written corrective action plan.
-
Documentation of any police reports related to alleged coercion claims if applicable.
- Notify the Halyard Pay Compliance lead within 24 hours of receipt.
4. Upon engagement of a Payment Facilitator Investigator (PFI), notify Mastercard within 24 hours.
5. If the responsible Customer elects to self-investigate a potential Account Data Compromise (ADC) Event instead of engaging a PFI, provide Mastercard within twenty (20) business days with documentation that:
- Confirms the Customer elected to investigate in lieu of a PFI.
- Verifies the Merchant does not share acceptance systems with other Merchants or Agents.
- Confirms the ADC Event has been fully contained, including a written explanation of containment measures.
- Confirms the Merchant has newly validated or revalidated PCI DSS compliance or has a remediation plan to achieve compliance.
Failure to comply with these notification and reporting requirements may result in noncompliance assessments by Mastercard as described in SPME section 10.7. Mastercard may also conduct periodic reviews to confirm that ADC Events are fully contained.
Additional Considerations for Coercion Claims
When allegations of coerced Transactions arise, note that Mastercard may extend the usual 120-day
investigation period at its discretion. At least one claim must include a police report from the Cardholder.
Transactions reported as Lost or Stolen Fraud (fraud type codes 00 or 01) are subject to investigation,
though Mastercard may consider other fraud codes. Mastercard will notify issuers with Transactions at the
merchant within the investigation period to prompt claim submissions.
Source authority: Mastercard SPME §8.6.2, §10.2.§§8.6.2, 10.2, 10 (ADC Event Investigation and Notification).
BRAM Investigation Response
When Mastercard issues a Business Risk Assessment and Mitigation (BRAM) investigation
notice for one of our merchants, the acquirer must halt new merchant onboarding
immediately and submit an evidence package within one hundred eighty (180) days
of receipt of the notice.
Required actions
-
Halt new merchant onboarding for the merchant under investigation.
-
Compile and submit an evidence package containing:
-
Transaction monitoring records covering the prior 180 days.
-
A written corrective action plan.
-
Documentation of any police reports related to alleged coercion claims if applicable.
- Notify the Halyard Pay Compliance lead within 24 hours of receipt.
4. Upon engagement of a Payment Facilitator Investigator (PFI), notify Mastercard within 24 hours.
5. If the responsible Customer elects to self-investigate a potential Account Data Compromise (ADC) Event instead of engaging a PFI, provide Mastercard within twenty (20) business days with documentation that:
- Confirms the Customer elected to investigate in lieu of a PFI.
- Verifies the Merchant does not share acceptance systems with other Merchants or Agents.
- Confirms the ADC Event has been fully contained, including a written explanation of containment measures.
- Confirms the Merchant has newly validated or revalidated PCI DSS compliance or has a remediation plan to achieve compliance.
Failure to comply with these notification and reporting requirements may result in noncompliance assessments by Mastercard as described in SPME section 10.7. Mastercard may also conduct periodic reviews to confirm that ADC Events are fully contained.
Additional Considerations for Coercion Claims
When allegations of coerced Transactions arise, note that Mastercard may extend the usual 120-day
investigation period at its discretion. At least one claim must include a police report from the Cardholder.
Transactions reported as Lost or Stolen Fraud (fraud type codes 00 or 01) are subject to investigation,
though Mastercard may consider other fraud codes. Mastercard will notify issuers with Transactions at the
merchant within the investigation period to prompt claim submissions.
Source authority: Mastercard SPME §8.6.2, §10.2.§§8.6.2, 10.2, 10 (ADC Event Investigation and Notification).
Source authority: Mastercard SPME §10.
--- a/policies/bram_response/rules.yaml
+++ b/policies/bram_response/rules.yaml
@@ -1,13 +1,23 @@
program: BRAM
-authority: Mastercard SPME §8.6.2, §10.2
+authority: Mastercard SPME 6, 10.2, 10
response_window_days: 180
required_evidence:
- transaction_monitoring_records
- corrective_action_plan
- - police_report # Added requirement for police report according to updated SPME §8.6.2
+ - police_report
+ - adc_event_containment_report # Added to reflect new containment documentation requirement from updated SPME 10
halt_actions:
- halt_new_merchant_onboarding
internal_notification_hours: 24
+notification_requirements:
+ pfi_engagement_notice_hours: 24 # Customer must notify Mastercard within 24 hours of PFI engagement
+ investigation_report_due_days: 20 # Investigation findings and PCI DSS validation/reporting required within 20 business days
agent_owner: bram_response_agent
-# Updated to reflect the extended discretionary investigation period and mandatory police report inclusion for at least one coercion claim as specified in Mastercard SPME §8.6.2.+# Updated per Mastercard SPME 10 to include:
+# - Mandatory 24-hour notification to Mastercard upon PFI engagement
+# - Option for Customers to conduct their own ADC Event investigation subject to strict reporting timelines
+# - Documentation requirements for ADC Event containment and PCI DSS compliance verification
+# - Potential noncompliance assessments for failures to meet these obligations
+#
+# These enhancements align the BRAM response process with the revised Mastercard SPME 10 to ensure timely and comprehensive incident management.
--- a/policies/bram_response/policy.md
+++ b/policies/bram_response/policy.md
@@ -13,6 +13,14 @@
- A written corrective action plan.
- Documentation of any police reports related to alleged coercion claims if applicable.
3. Notify the Halyard Pay Compliance lead within 24 hours of receipt.
+4. Upon engagement of a Payment Facilitator Investigator (PFI), notify Mastercard within 24 hours.
+5. If the responsible Customer elects to self-investigate a potential Account Data Compromise (ADC) Event instead of engaging a PFI, provide Mastercard within twenty (20) business days with documentation that:
+ - Confirms the Customer elected to investigate in lieu of a PFI.
+ - Verifies the Merchant does not share acceptance systems with other Merchants or Agents.
+ - Confirms the ADC Event has been fully contained, including a written explanation of containment measures.
+ - Confirms the Merchant has newly validated or revalidated PCI DSS compliance or has a remediation plan to achieve compliance.
+
+Failure to comply with these notification and reporting requirements may result in noncompliance assessments by Mastercard as described in SPME section 10.7. Mastercard may also conduct periodic reviews to confirm that ADC Events are fully contained.
## Additional Considerations for Coercion Claims
@@ -22,4 +30,4 @@
though Mastercard may consider other fraud codes. Mastercard will notify issuers with Transactions at the
merchant within the investigation period to prompt claim submissions.
-Source authority: Mastercard SPME §8.6.2, §10.2.
+Source authority: Mastercard SPME §§8.6.2, 10.2, 10 (ADC Event Investigation and Notification).