Mastercard SPME §11.1 · May 2023 → Sep 2023
MATCH Overview
The update expands and clarifies the MATCH system's definition and categorization of possible matches, detailing exact and phonetic match criteria with specific fields and conditions, adds retroactive match procedures, and emphasizes acquirers must include Merchant URL for e-commerce inquiries.
Security Rules and Procedures—Merchant Edition • 7 February 2023
Security Rules and Procedures—Merchant Edition • 1 August 2023
NOTE: All MATCH responses reflecting that inquiry information is resident on MATCH are deemed “possible matches” because of the nature of the search mechanisms employed and the inability to report a true and exact match with absolute certainty. NOTE: There are two types of possible matches, including a data match (for example, name-to-name, address-to-address) and a phonetic (sound-alike) match made using special software. NOTE: For convenience only, the remainder of this manual may sometimes omit the word “possible” when referring to “possible matches” or “a possible match.” The Acquirer determines the number of phonetic matches—one to nine—that will cause a possible match to be trustworthy. MATCH returns the first 100 responses for each inquiry submitted by an Acquirer. MATCH returns all terminated Merchant MATCH responses regardless of the number of possible matches. 11.1.2.1 Retroactive Possible Matches If the information in the original inquiry finds new possible matches of a Merchant or inquiry record in the MATCH database added since the original inquiry was submitted and this information has not been previously reported to the Acquirer at least once within the past 360 days, the system returns a retroactive possible match response. 11.1.2.2 Exact Possible Matches MATCH finds an exact possible match when data in an inquiry record matches data on the MATCH system letter-for-letter, number-for-number, or both. An exact match to any of the following data results in a possible match response from Mastercard. Table 11.1—Exact Possible Match Criteria Field + Field + Field = Match Merchant Name = √ Doing Business as (DBA) Name = √ Phone Number (Merchant) = √ Alternate Phone Number (Merchant) = √ Merchant National Tax ID + Country = √ Merchant State Tax ID + State = √ Merchant Street Address + City + State1 = √ 1 If country is USA. MATCH System 11.1.2.1 Retroactive Possible Matches Security Rules and Procedures—Merchant Edition • 1 August 2023
Field + Field + Field = Match Merchant Street Address + City + Country2 = √ Merchant URL Website Address + City + Country = √ Principal Owner’s (PO) First Name + Last Name = √ PO Phone Number = √ Alternate Phone Number (PO) = √ PO Social Security Number1 = √ PO National ID2 = √ PO Street Address (lines 1 and 2) + PO City + PO State1 = √ PO Street Address (lines 1 and 2) + PO City + PO Country2 = √ PO Driver’s License (DL) Number + DL State1 = √ PO Driver’s License Number + DL Country2 = √ NOTE: MATCH uses Street, City, and State if the Merchant’s country is USA; otherwise, Street, City, and Country are used. NOTE: Acquirers must populate the Merchant URL Website Address field when performing an inquiry of an electronic commerce (e-commerce) Merchant. 11.1.2.3 Phonetic Possible Matches The MATCH system converts certain alphabetic data, such as Merchant Name and Principal Owner Last Name to a phonetic code. The phonetic code generates matches on words that sound alike, such as “Easy” and “EZ.” The phonetic matching feature of the system also matches names that are not necessarily a phonetic match but might differ because of a typographical error, such as “Rogers” and “Rokers,” or a spelling variation, such as “Lee,” “Li,” and “Leigh.” MATCH evaluates the following data to determine a phonetic possible match. Table 11.2—Phonetic Possible Match Criteria Field + Field + Field = Match Merchant Name = √ Doing Business As (DBA) Name = √ 2 If country is not USA. MATCH System 11.1.2.3 Phonetic Possible Matches Security Rules and Procedures—Merchant Edition • 1 August 2023
Field + Field + Field = Match Merchant Street Address + City + State3 = √ Merchant Street Address + City + Country4 = √ Principal Owner’s (PO) First Name + Last Name = √ PO Street Address (lines 1 and 2) + PO City + PO State3 = √ PO Street Address (lines 1 and 2) + PO City + PO Country4 = √ NOTE: MATCH uses Street, City, and State if the Merchant’s country is USA; otherwise, Street, City, and Country are used.
program: Acquirer KYB- authority: Mastercard SPME 2.1, 11.2.6+ authority: Mastercard SPME 2.1, 11.1, 11.2.6required_documents:- incorporation- beneficial_ownership- aml_screen- license_verification+ - merchant_url_verification # Added to reflect requirement to verify e-commerce merchant URLs for MATCH inquiriesmin_review_cycle_days: 365suspension_trigger: document_collection_failurerecord_retention_years: 7aml_watchlist_sources:- ofac_sdn- eu_consolidatedagent_owner: kyb_agent- # The Acquirer must specifically retain all MATCH records concerning any Merchant, Sponsored Merchant, or ATM owner for at least two years following the termination or expiration of the related agreement, per Mastercard SPME 11.2.6.- # This retention requirement updates prior guidance by imposing a defined minimum retention period beyond the MATCH system's internal data purging schedule.+ # The Acquirer must retain all MATCH records concerning any Merchant, Sponsored Merchant, or ATM owner for at least two years following termination or expiration of the related agreement, per Mastercard SPME 11.2.6.+ # According to updated Mastercard SPME 11.1, acquirers must include Merchant URL Website Address when performing MATCH inquiries on e-commerce merchants to support expanded exact and phonetic matching criteria.+ # The MATCH system now employs enhanced exact and phonetic match algorithms, which require the acquirer to carefully populate multiple merchant and principal owner data fields to ensure accurate possible match detection.+ # MATCH returns retroactive possible matches added since the original inquiry if not previously reported in the last 360 days.+ # Precise data combinations define exact and phonetic possible matches as detailed in Mastercard SPME 11.1.2.2 and 11.1.2.3.
Acquirer KYB (Know Your Business) Obligations
Acquirers processing transactions on the Mastercard network are required to must perform ¶ thorough Know Your Business (KYB) due diligence on merchants before during onboarding and on a ¶ recurring an ongoing basis thereafter. Halyard Pay, as an acquirer, must collect and verify a ¶ minimum set of documents for each merchant to establish to ensure business legitimacy, confirm ¶ beneficial ownership, and satisfy anti-money laundering screening requirements. legitimacy and compliance with Mastercard standards.
When this policy applies
This policy applies to governs all new merchant onboarding and to all subsequent periodic re-verification ¶ reviews. Merchants that fail to supply Failure to provide required documentation within the stipulated ¶ period must be suspended established deadlines leads to suspension from processing until compliance is restored. processing.
Required actions
-
Collect all
requiredKYBdocuments at onboarding prior todocumentation before merchant approval. -
Conduct
AMLanti-money laundering screening against applicable watchlistsbeforeprior to approval. -
Verify business licenses for applicable regulated
merchant categories.sectors. -
SchedulePerform a full re-verificationreviewat leastonceannually (every 365days.days). -
DocumentRecord and retain all verificationoutcomes and retain records for audit purposes.results for auditing. -
Retain all MATCH system records related to Merchants, Sponsored Merchants, or ATM owners for
a minimum ofat least two yearsafter termination or expiration ofpost-termination per Mastercard requirements.
7. When submitting MATCH inquiries, include the applicable agreement, to comply with Mastercard's explicit record retention requirements. Merchant URL for e-commerce merchants as mandated by Mastercard to enhance verification effectiveness.
8. Review MATCH possible matches carefully, understanding Mastercard’s expanded criteria for exact and phonetic matches, which include name, address, phone, tax IDs, and principal owner data, to better detect potential risks.
Source authority: Mastercard SPME ��������2.1, §§11.1, 11.2.1, 11.2.6.
Acquirer KYB (Know Your Business) Obligations
Acquirers processing transactions on the Mastercard network are required to must perform ¶ thorough Know Your Business (KYB) due diligence on merchants before during onboarding and on a ¶ recurring an ongoing basis thereafter. Halyard Pay, as an acquirer, must collect and verify a ¶ minimum set of documents for each merchant to establish to ensure business legitimacy, confirm ¶ beneficial ownership, and satisfy anti-money laundering screening requirements. legitimacy and compliance with Mastercard standards.
When this policy applies
This policy applies to governs all new merchant onboarding and to all subsequent periodic re-verification ¶ reviews. Merchants that fail to supply Failure to provide required documentation within the stipulated ¶ period must be suspended established deadlines leads to suspension from processing until compliance is restored. processing.
Required actions
-
Collect all
requiredKYBdocuments at onboarding prior todocumentation before merchant approval. -
Conduct
AMLanti-money laundering screening against applicable watchlistsbeforeprior to approval. -
Verify business licenses for applicable regulated
merchant categories.sectors. -
SchedulePerform a full re-verificationreviewat leastonceannually (every 365days.days). -
DocumentRecord and retain all verificationoutcomes and retain records for audit purposes.results for auditing. -
Retain all MATCH system records related to Merchants, Sponsored Merchants, or ATM owners for
a minimum ofat least two yearsafter termination or expiration ofpost-termination per Mastercard requirements.
7. When submitting MATCH inquiries, include the applicable agreement, to comply with Mastercard's explicit record retention requirements. Merchant URL for e-commerce merchants as mandated by Mastercard to enhance verification effectiveness.
8. Review MATCH possible matches carefully, understanding Mastercard’s expanded criteria for exact and phonetic matches, which include name, address, phone, tax IDs, and principal owner data, to better detect potential risks.
Source authority: Mastercard SPME ��������2.1, §§11.1, 11.2.1, 11.2.6.
Source authority: Mastercard SPME §11.1.
--- a/policies/kyb_acquirer/rules.yaml +++ b/policies/kyb_acquirer/rules.yaml @@ -1,10 +1,11 @@ program: Acquirer KYB -authority: Mastercard SPME 2.1, 11.2.6 +authority: Mastercard SPME 2.1, 11.1, 11.2.6 required_documents: - incorporation - beneficial_ownership - aml_screen - license_verification + - merchant_url_verification # Added to reflect requirement to verify e-commerce merchant URLs for MATCH inquiries min_review_cycle_days: 365 suspension_trigger: document_collection_failure record_retention_years: 7 @@ -12,5 +13,8 @@ - ofac_sdn - eu_consolidated agent_owner: kyb_agent -# The Acquirer must specifically retain all MATCH records concerning any Merchant, Sponsored Merchant, or ATM owner for at least two years following the termination or expiration of the related agreement, per Mastercard SPME 11.2.6. -# This retention requirement updates prior guidance by imposing a defined minimum retention period beyond the MATCH system's internal data purging schedule.+# The Acquirer must retain all MATCH records concerning any Merchant, Sponsored Merchant, or ATM owner for at least two years following termination or expiration of the related agreement, per Mastercard SPME 11.2.6. +# According to updated Mastercard SPME 11.1, acquirers must include Merchant URL Website Address when performing MATCH inquiries on e-commerce merchants to support expanded exact and phonetic matching criteria. +# The MATCH system now employs enhanced exact and phonetic match algorithms, which require the acquirer to carefully populate multiple merchant and principal owner data fields to ensure accurate possible match detection. +# MATCH returns retroactive possible matches added since the original inquiry if not previously reported in the last 360 days. +# Precise data combinations define exact and phonetic possible matches as detailed in Mastercard SPME 11.1.2.2 and 11.1.2.3. --- a/policies/kyb_acquirer/policy.md +++ b/policies/kyb_acquirer/policy.md @@ -1,24 +1,20 @@ # Acquirer KYB (Know Your Business) Obligations -Acquirers processing transactions on the Mastercard network are required to perform -Know Your Business (KYB) due diligence on merchants before onboarding and on a -recurring basis thereafter. Halyard Pay, as an acquirer, must collect and verify a -minimum set of documents for each merchant to establish business legitimacy, confirm -beneficial ownership, and satisfy anti-money laundering screening requirements. +Acquirers processing transactions on the Mastercard network must perform thorough Know Your Business (KYB) due diligence on merchants during onboarding and on an ongoing basis to ensure business legitimacy and compliance with Mastercard standards. ## When this policy applies -This policy applies to all new merchant onboarding and to all periodic re-verification -reviews. Merchants that fail to supply required documentation within the stipulated -period must be suspended from processing until compliance is restored. +This policy governs all new merchant onboarding and subsequent periodic reviews. Failure to provide required documentation within established deadlines leads to suspension from processing. ## Required actions -1. Collect all required KYB documents at onboarding prior to approval. -2. Conduct AML screening against applicable watchlists before approval. -3. Verify business licenses for regulated merchant categories. -4. Schedule a full re-verification review at least once every 365 days. -5. Document all verification outcomes and retain records for audit purposes. -6. Retain all MATCH system records related to Merchants, Sponsored Merchants, or ATM owners for a minimum of two years after termination or expiration of the applicable agreement, to comply with Mastercard's explicit record retention requirements. +1. Collect all KYB documentation before merchant approval. +2. Conduct anti-money laundering screening against applicable watchlists prior to approval. +3. Verify business licenses for applicable regulated sectors. +4. Perform a full re-verification at least annually (every 365 days). +5. Record and retain all verification results for auditing. +6. Retain all MATCH system records related to Merchants, Sponsored Merchants, or ATM owners for at least two years post-termination per Mastercard requirements. +7. When submitting MATCH inquiries, include the Merchant URL for e-commerce merchants as mandated by Mastercard to enhance verification effectiveness. +8. Review MATCH possible matches carefully, understanding Mastercard’s expanded criteria for exact and phonetic matches, which include name, address, phone, tax IDs, and principal owner data, to better detect potential risks. -Source authority: Mastercard SPME 2.1, 11.2.6.+Source authority: Mastercard SPME §§11.1, 11.2.1, 11.2.6.