Mastercard SPME §11.1 · May 2023 → Sep 2023

MATCH Overview

substantive
⚠ Extraction warning — review against source PDF. One side of the Mastercard SPME text below appears to contain only the page-running header, not body content. This usually means the section heading fell on a page boundary and the body was attributed to a neighbouring section in the source PDF. The AI summary and proposed edit below may be misleading. Verify in: May 2023 · page 141 ↗ · Sep 2023 · page 130 ↗.

The update expands and clarifies the MATCH system's definition and categorization of possible matches, detailing exact and phonetic match criteria with specific fields and conditions, adds retroactive match procedures, and emphasizes acquirers must include Merchant URL for e-commerce inquiries.

Sources Mastercard SPME · May 2023 · page 141 PDF Mastercard SPME · Sep 2023 · page 130 PDF KYB Acquirer current
Also in §11.x this release breaking §11.4 Merchant Removal from MATCH substantive §11.1.2 How does MATCH search when conducting an inquiry? substantive §11.2.1 Certification substantive §11.2.3 Inquiring about a Merchant substantive §11.5 MATCH Reason Codes substantive §11.5.1 Reason Codes for Merchants Listed by the Acquirer
Why these edits? The update to section 11.1 clarifies MATCH system procedures including expanded exact and phonetic match criteria and requires acquirers to include the Merchant URL for e-commerce inquiries, thereby impacting Acquirer KYB obligations related to merchant verification and monitoring.
Mastercard SPME §11.1
This section was substantively restructured between versions (3% text overlap). Compare the texts directly below.
Before · May 2023 · page 141

Security Rules and Procedures—Merchant Edition • 7 February 2023

After · Sep 2023 · page 130

Security Rules and Procedures—Merchant Edition • 1 August 2023

NOTE: All MATCH responses reflecting that inquiry information is resident on MATCH are deemed “possible matches” because of the nature of the search mechanisms employed and the inability to report a true and exact match with absolute certainty. NOTE: There are two types of possible matches, including a data match (for example, name-to-name, address-to-address) and a phonetic (sound-alike) match made using special software. NOTE: For convenience only, the remainder of this manual may sometimes omit the word “possible” when referring to “possible matches” or “a possible match.” The Acquirer determines the number of phonetic matches—one to nine—that will cause a possible match to be trustworthy. MATCH returns the first 100 responses for each inquiry submitted by an Acquirer. MATCH returns all terminated Merchant MATCH responses regardless of the number of possible matches. 11.1.2.1 Retroactive Possible Matches If the information in the original inquiry finds new possible matches of a Merchant or inquiry record in the MATCH database added since the original inquiry was submitted and this information has not been previously reported to the Acquirer at least once within the past 360 days, the system returns a retroactive possible match response. 11.1.2.2 Exact Possible Matches MATCH finds an exact possible match when data in an inquiry record matches data on the MATCH system letter-for-letter, number-for-number, or both. An exact match to any of the following data results in a possible match response from Mastercard. Table 11.1—Exact Possible Match Criteria Field + Field + Field = Match Merchant Name = √ Doing Business as (DBA) Name = √ Phone Number (Merchant) = √ Alternate Phone Number (Merchant) = √ Merchant National Tax ID + Country = √ Merchant State Tax ID + State = √ Merchant Street Address + City + State1 = √ 1 If country is USA. MATCH System 11.1.2.1 Retroactive Possible Matches Security Rules and Procedures—Merchant Edition • 1 August 2023

Field + Field + Field = Match Merchant Street Address + City + Country2 = √ Merchant URL Website Address + City + Country = √ Principal Owner’s (PO) First Name + Last Name = √ PO Phone Number = √ Alternate Phone Number (PO) = √ PO Social Security Number1 = √ PO National ID2 = √ PO Street Address (lines 1 and 2) + PO City + PO State1 = √ PO Street Address (lines 1 and 2) + PO City + PO Country2 = √ PO Driver’s License (DL) Number + DL State1 = √ PO Driver’s License Number + DL Country2 = √ NOTE: MATCH uses Street, City, and State if the Merchant’s country is USA; otherwise, Street, City, and Country are used. NOTE: Acquirers must populate the Merchant URL Website Address field when performing an inquiry of an electronic commerce (e-commerce) Merchant. 11.1.2.3 Phonetic Possible Matches The MATCH system converts certain alphabetic data, such as Merchant Name and Principal Owner Last Name to a phonetic code. The phonetic code generates matches on words that sound alike, such as “Easy” and “EZ.” The phonetic matching feature of the system also matches names that are not necessarily a phonetic match but might differ because of a typographical error, such as “Rogers” and “Rokers,” or a spelling variation, such as “Lee,” “Li,” and “Leigh.” MATCH evaluates the following data to determine a phonetic possible match. Table 11.2—Phonetic Possible Match Criteria Field + Field + Field = Match Merchant Name = √ Doing Business As (DBA) Name = √ 2 If country is not USA. MATCH System 11.1.2.3 Phonetic Possible Matches Security Rules and Procedures—Merchant Edition • 1 August 2023

Field + Field + Field = Match Merchant Street Address + City + State3 = √ Merchant Street Address + City + Country4 = √ Principal Owner’s (PO) First Name + Last Name = √ PO Street Address (lines 1 and 2) + PO City + PO State3 = √ PO Street Address (lines 1 and 2) + PO City + PO Country4 = √ NOTE: MATCH uses Street, City, and State if the Merchant’s country is USA; otherwise, Street, City, and Country are used.

Halyard Pay · 2 files
program: Acquirer KYB
- authority: Mastercard SPME 2.1, 11.2.6
+ authority: Mastercard SPME 2.1, 11.1, 11.2.6
required_documents:
- incorporation
- beneficial_ownership
- aml_screen
- license_verification
+ - merchant_url_verification # Added to reflect requirement to verify e-commerce merchant URLs for MATCH inquiries
min_review_cycle_days: 365
suspension_trigger: document_collection_failure
record_retention_years: 7
aml_watchlist_sources:
- ofac_sdn
- eu_consolidated
agent_owner: kyb_agent
- # The Acquirer must specifically retain all MATCH records concerning any Merchant, Sponsored Merchant, or ATM owner for at least two years following the termination or expiration of the related agreement, per Mastercard SPME 11.2.6.
- # This retention requirement updates prior guidance by imposing a defined minimum retention period beyond the MATCH system's internal data purging schedule.
+ # The Acquirer must retain all MATCH records concerning any Merchant, Sponsored Merchant, or ATM owner for at least two years following termination or expiration of the related agreement, per Mastercard SPME 11.2.6.
+ # According to updated Mastercard SPME 11.1, acquirers must include Merchant URL Website Address when performing MATCH inquiries on e-commerce merchants to support expanded exact and phonetic matching criteria.
+ # The MATCH system now employs enhanced exact and phonetic match algorithms, which require the acquirer to carefully populate multiple merchant and principal owner data fields to ensure accurate possible match detection.
+ # MATCH returns retroactive possible matches added since the original inquiry if not previously reported in the last 360 days.
+ # Precise data combinations define exact and phonetic possible matches as detailed in Mastercard SPME 11.1.2.2 and 11.1.2.3.

Acquirer KYB (Know Your Business) Obligations

Acquirers processing transactions on the Mastercard network are required to must perform thorough Know Your Business (KYB) due diligence on merchants before during onboarding and on a ¶ recurring an ongoing basis thereafter. Halyard Pay, as an acquirer, must collect and verify a ¶ minimum set of documents for each merchant to establish to ensure business legitimacy, confirm ¶ beneficial ownership, and satisfy anti-money laundering screening requirements. legitimacy and compliance with Mastercard standards.

When this policy applies

This policy applies to governs all new merchant onboarding and to all subsequent periodic re-verification ¶ reviews. Merchants that fail to supply Failure to provide required documentation within the stipulated ¶ period must be suspended established deadlines leads to suspension from processing until compliance is restored. processing.

Required actions

  1. Collect all required KYB documents at onboarding prior to documentation before merchant approval.

  2. Conduct AML anti-money laundering screening against applicable watchlists before prior to approval.

  3. Verify business licenses for applicable regulated merchant categories. sectors.

  4. Schedule Perform a full re-verification review at least once annually (every 365 days. days).

  5. Document Record and retain all verification outcomes and retain records for audit purposes. results for auditing.

  6. Retain all MATCH system records related to Merchants, Sponsored Merchants, or ATM owners for a minimum of at least two years after termination or expiration of post-termination per Mastercard requirements.

7. When submitting MATCH inquiries, include the applicable agreement, to comply with Mastercard's explicit record retention requirements. Merchant URL for e-commerce merchants as mandated by Mastercard to enhance verification effectiveness.

8. Review MATCH possible matches carefully, understanding Mastercard’s expanded criteria for exact and phonetic matches, which include name, address, phone, tax IDs, and principal owner data, to better detect potential risks.

Source authority: Mastercard SPME ��������2.1, §§11.1, 11.2.1, 11.2.6.

policies/kyb_acquirer/policy.md — after applying change

Acquirer KYB (Know Your Business) Obligations

Acquirers processing transactions on the Mastercard network are required to must perform thorough Know Your Business (KYB) due diligence on merchants before during onboarding and on a ¶ recurring an ongoing basis thereafter. Halyard Pay, as an acquirer, must collect and verify a ¶ minimum set of documents for each merchant to establish to ensure business legitimacy, confirm ¶ beneficial ownership, and satisfy anti-money laundering screening requirements. legitimacy and compliance with Mastercard standards.

When this policy applies

This policy applies to governs all new merchant onboarding and to all subsequent periodic re-verification ¶ reviews. Merchants that fail to supply Failure to provide required documentation within the stipulated ¶ period must be suspended established deadlines leads to suspension from processing until compliance is restored. processing.

Required actions

  1. Collect all required KYB documents at onboarding prior to documentation before merchant approval.

  2. Conduct AML anti-money laundering screening against applicable watchlists before prior to approval.

  3. Verify business licenses for applicable regulated merchant categories. sectors.

  4. Schedule Perform a full re-verification review at least once annually (every 365 days. days).

  5. Document Record and retain all verification outcomes and retain records for audit purposes. results for auditing.

  6. Retain all MATCH system records related to Merchants, Sponsored Merchants, or ATM owners for a minimum of at least two years after termination or expiration of post-termination per Mastercard requirements.

7. When submitting MATCH inquiries, include the applicable agreement, to comply with Mastercard's explicit record retention requirements. Merchant URL for e-commerce merchants as mandated by Mastercard to enhance verification effectiveness.

8. Review MATCH possible matches carefully, understanding Mastercard’s expanded criteria for exact and phonetic matches, which include name, address, phone, tax IDs, and principal owner data, to better detect potential risks.

Source authority: Mastercard SPME ��������2.1, §§11.1, 11.2.1, 11.2.6.

Source authority: Mastercard SPME §11.1.

--- a/policies/kyb_acquirer/rules.yaml
+++ b/policies/kyb_acquirer/rules.yaml
@@ -1,10 +1,11 @@
 program: Acquirer KYB
-authority: Mastercard SPME 2.1, 11.2.6
+authority: Mastercard SPME 2.1, 11.1, 11.2.6
 required_documents:
   - incorporation
   - beneficial_ownership
   - aml_screen
   - license_verification
+  - merchant_url_verification  # Added to reflect requirement to verify e-commerce merchant URLs for MATCH inquiries
 min_review_cycle_days: 365
 suspension_trigger: document_collection_failure
 record_retention_years: 7
@@ -12,5 +13,8 @@
   - ofac_sdn
   - eu_consolidated
 agent_owner: kyb_agent
-# The Acquirer must specifically retain all MATCH records concerning any Merchant, Sponsored Merchant, or ATM owner for at least two years following the termination or expiration of the related agreement, per Mastercard SPME 11.2.6.
-# This retention requirement updates prior guidance by imposing a defined minimum retention period beyond the MATCH system's internal data purging schedule.+# The Acquirer must retain all MATCH records concerning any Merchant, Sponsored Merchant, or ATM owner for at least two years following termination or expiration of the related agreement, per Mastercard SPME 11.2.6.
+# According to updated Mastercard SPME 11.1, acquirers must include Merchant URL Website Address when performing MATCH inquiries on e-commerce merchants to support expanded exact and phonetic matching criteria.
+# The MATCH system now employs enhanced exact and phonetic match algorithms, which require the acquirer to carefully populate multiple merchant and principal owner data fields to ensure accurate possible match detection.
+# MATCH returns retroactive possible matches added since the original inquiry if not previously reported in the last 360 days.
+# Precise data combinations define exact and phonetic possible matches as detailed in Mastercard SPME 11.1.2.2 and 11.1.2.3.

--- a/policies/kyb_acquirer/policy.md
+++ b/policies/kyb_acquirer/policy.md
@@ -1,24 +1,20 @@
 # Acquirer KYB (Know Your Business) Obligations
 
-Acquirers processing transactions on the Mastercard network are required to perform
-Know Your Business (KYB) due diligence on merchants before onboarding and on a
-recurring basis thereafter. Halyard Pay, as an acquirer, must collect and verify a
-minimum set of documents for each merchant to establish business legitimacy, confirm
-beneficial ownership, and satisfy anti-money laundering screening requirements.
+Acquirers processing transactions on the Mastercard network must perform thorough Know Your Business (KYB) due diligence on merchants during onboarding and on an ongoing basis to ensure business legitimacy and compliance with Mastercard standards.
 
 ## When this policy applies
 
-This policy applies to all new merchant onboarding and to all periodic re-verification
-reviews. Merchants that fail to supply required documentation within the stipulated
-period must be suspended from processing until compliance is restored.
+This policy governs all new merchant onboarding and subsequent periodic reviews. Failure to provide required documentation within established deadlines leads to suspension from processing.
 
 ## Required actions
 
-1. Collect all required KYB documents at onboarding prior to approval.
-2. Conduct AML screening against applicable watchlists before approval.
-3. Verify business licenses for regulated merchant categories.
-4. Schedule a full re-verification review at least once every 365 days.
-5. Document all verification outcomes and retain records for audit purposes.
-6. Retain all MATCH system records related to Merchants, Sponsored Merchants, or ATM owners for a minimum of two years after termination or expiration of the applicable agreement, to comply with Mastercard's explicit record retention requirements.
+1. Collect all KYB documentation before merchant approval.
+2. Conduct anti-money laundering screening against applicable watchlists prior to approval.
+3. Verify business licenses for applicable regulated sectors.
+4. Perform a full re-verification at least annually (every 365 days).
+5. Record and retain all verification results for auditing.
+6. Retain all MATCH system records related to Merchants, Sponsored Merchants, or ATM owners for at least two years post-termination per Mastercard requirements.
+7. When submitting MATCH inquiries, include the Merchant URL for e-commerce merchants as mandated by Mastercard to enhance verification effectiveness.
+8. Review MATCH possible matches carefully, understanding Mastercard’s expanded criteria for exact and phonetic matches, which include name, address, phone, tax IDs, and principal owner data, to better detect potential risks.
 
-Source authority: Mastercard SPME 2.1, 11.2.6.+Source authority: Mastercard SPME §§11.1, 11.2.1, 11.2.6.