Mastercard SPME §2.1.1 · May 2023 → Sep 2023
Payment Card Industry (PCI) Security Standards
The updated section removes all references to PCI PIN Security Requirements, PIN Transaction Security, Forensic Investigator Program Guide, and focuses solely on PCI Software Security Framework standards, emphasizing compliance and recommendations related only to software security for merchants and service providers.
program: Acquirer KYBauthority: Mastercard SPME 2.1, 11.2.6required_documents:- incorporation- beneficial_ownership- aml_screen- license_verificationmin_review_cycle_days: 365suspension_trigger: document_collection_failurerecord_retention_years: 7aml_watchlist_sources:- ofac_sdn- eu_consolidatedagent_owner: kyb_agent# The Acquirer must specifically retain all MATCH records concerning any Merchant, Sponsored Merchant, or ATM owner for at least two years following the termination or expiration of the related agreement, per Mastercard SPME 11.2.6.# This retention requirement updates prior guidance by imposing a defined minimum retention period beyond the MATCH system's internal data purging schedule.+ # Updated Mastercard SPME 2.1.1 simplifies PCI compliance obligations relevant to software security standards, removing references to PIN and forensic requirements, thus emphasizing adherence to the PCI Secure Software Standard and Secure SLC Standard only.
Acquirer KYB (Know Your Business) Obligations
Acquirers processing transactions on the Mastercard network are required to perform
Know Your Business (KYB) due diligence on merchants before onboarding and on a
recurring basis thereafter. Halyard Pay, as an acquirer, must collect and verify a
minimum set of documents for each merchant to establish business legitimacy, confirm
beneficial ownership, and satisfy anti-money laundering screening requirements.
When this policy applies
This policy applies to all new merchant onboarding and to all periodic re-verification
reviews. Merchants that fail to supply required documentation within the stipulated
period must be suspended from processing until compliance is restored.
Required actions
-
Collect all required KYB documents at onboarding prior to approval.
-
Conduct AML screening against applicable watchlists before approval.
-
Verify business licenses for regulated merchant categories.
-
Schedule a full re-verification review at least once every 365 days.
-
Document all verification outcomes and retain records for audit purposes.
-
Retain all MATCH system records related to Merchants, Sponsored Merchants, or ATM owners for a minimum of two years after termination or expiration of the applicable agreement, to comply with Mastercard's explicit record retention requirements.
Note: Recent updates to Mastercard SPME §2.1.1 emphasize compliance focus on software security standards under the PCI Software Security Framework, superseding prior hardware-focused and forensic investigation requirements. This shift reinforces the importance of software security for merchants and service providers using third-party payment software.
Source authority: Mastercard SPME ��������2.1, 11.2.6.§§2.1, 11.2.6, 2.1.1.
Acquirer KYB (Know Your Business) Obligations
Acquirers processing transactions on the Mastercard network are required to perform
Know Your Business (KYB) due diligence on merchants before onboarding and on a
recurring basis thereafter. Halyard Pay, as an acquirer, must collect and verify a
minimum set of documents for each merchant to establish business legitimacy, confirm
beneficial ownership, and satisfy anti-money laundering screening requirements.
When this policy applies
This policy applies to all new merchant onboarding and to all periodic re-verification
reviews. Merchants that fail to supply required documentation within the stipulated
period must be suspended from processing until compliance is restored.
Required actions
-
Collect all required KYB documents at onboarding prior to approval.
-
Conduct AML screening against applicable watchlists before approval.
-
Verify business licenses for regulated merchant categories.
-
Schedule a full re-verification review at least once every 365 days.
-
Document all verification outcomes and retain records for audit purposes.
-
Retain all MATCH system records related to Merchants, Sponsored Merchants, or ATM owners for a minimum of two years after termination or expiration of the applicable agreement, to comply with Mastercard's explicit record retention requirements.
Note: Recent updates to Mastercard SPME §2.1.1 emphasize compliance focus on software security standards under the PCI Software Security Framework, superseding prior hardware-focused and forensic investigation requirements. This shift reinforces the importance of software security for merchants and service providers using third-party payment software.
Source authority: Mastercard SPME ��������2.1, 11.2.6.§§2.1, 11.2.6, 2.1.1.
Source authority: Mastercard SPME §2.1.1.
--- a/policies/kyb_acquirer/rules.yaml +++ b/policies/kyb_acquirer/rules.yaml @@ -13,4 +13,5 @@ - eu_consolidated agent_owner: kyb_agent # The Acquirer must specifically retain all MATCH records concerning any Merchant, Sponsored Merchant, or ATM owner for at least two years following the termination or expiration of the related agreement, per Mastercard SPME 11.2.6. -# This retention requirement updates prior guidance by imposing a defined minimum retention period beyond the MATCH system's internal data purging schedule.+# This retention requirement updates prior guidance by imposing a defined minimum retention period beyond the MATCH system's internal data purging schedule. +# Updated Mastercard SPME 2.1.1 simplifies PCI compliance obligations relevant to software security standards, removing references to PIN and forensic requirements, thus emphasizing adherence to the PCI Secure Software Standard and Secure SLC Standard only. --- a/policies/kyb_acquirer/policy.md +++ b/policies/kyb_acquirer/policy.md @@ -21,4 +21,6 @@ 5. Document all verification outcomes and retain records for audit purposes. 6. Retain all MATCH system records related to Merchants, Sponsored Merchants, or ATM owners for a minimum of two years after termination or expiration of the applicable agreement, to comply with Mastercard's explicit record retention requirements. -Source authority: Mastercard SPME 2.1, 11.2.6.+Note: Recent updates to Mastercard SPME §2.1.1 emphasize compliance focus on software security standards under the PCI Software Security Framework, superseding prior hardware-focused and forensic investigation requirements. This shift reinforces the importance of software security for merchants and service providers using third-party payment software. + +Source authority: Mastercard SPME §§2.1, 11.2.6, 2.1.1.