Mastercard SPME §2.3 · May 2023 → Sep 2023
Card Production Security Standards
The updated section adds details about the GVCP certification process for vendor facilities, including annual security assessments, issuance of compliance certifications, and a publicly available list of certified vendors. Existing terms about vendor agreements and data safeguarding remain unchanged.
Security Rules and Procedures—Merchant Edition • 7 February 2023
Any agreement between an Issuer and a vendor for Card production services should contain terms stating that the vendor agrees to safeguard and control usage of Account data and to comply with all applicable Standards then in effect, including but not limited to those set forth in section 2.3 and in the Card Design Standards manual. For more information about the GVCP, contact Mastercard by sending an email message to gvcp-helpdesk@mastercard.com.
Security Rules and Procedures—Merchant Edition • 1 August 2023
Prior to certification and annual recertification of a vendor facility under the GVCP, a security assessment of the facility is conducted at approximately 12-month intervals to evaluate the facility's compliance with the PCI documents referenced in section 2.3. A certified vendor facility is issued a compliance certification, which is subject to annual renewal, provided the vendor facility remains in good standing. The “List of Certified Vendors,” as published monthly in a Mastercard Announcement (AN) available on the Technical Resource Center on Mastercard Connect®, contains the name of each vendor facility then certified and a description of the specific services that the facility is authorized to perform. Any agreement between an Issuer and a vendor for Card production services should contain terms stating that the vendor agrees to safeguard and control usage of Account data and to comply with all applicable Standards then in effect, including but not limited to those set forth in section 2.3 and in the Card Design Standards manual. For more information about the GVCP, contact Mastercard by sending an email message to gvcp-helpdesk@mastercard.com.
program: Acquirer KYB- authority: Mastercard SPME 2.1, 11.2.6+ authority: Mastercard SPME 2.1, 2.3, 11.2.6required_documents:- incorporation- beneficial_ownership- aml_screen- license_verificationmin_review_cycle_days: 365suspension_trigger: document_collection_failurerecord_retention_years: 7aml_watchlist_sources:- ofac_sdn- eu_consolidatedagent_owner: kyb_agent# The Acquirer must specifically retain all MATCH records concerning any Merchant, Sponsored Merchant, or ATM owner for at least two years following the termination or expiration of the related agreement, per Mastercard SPME 11.2.6.- # This retention requirement updates prior guidance by imposing a defined minimum retention period beyond the MATCH system's internal data purging schedule.+ #+ # Regarding Mastercard SPME §2.3, the Acquirer must verify that Card production vendors have current GVCP certification, which includes annual security assessments and compliance certifications. This ensures vendors comply with PCI standards and Mastercard's Card Design Standards.+ # Vendor agreements must include terms requiring safeguarding and proper use of Account data in accordance with all applicable standards.+ # This addition supports enhanced due diligence and ongoing vendor compliance verification obligations under the updated GVCP requirements.
Acquirer KYB (Know Your Business) Obligations
Acquirers processing transactions on the Mastercard network are required to perform
Know Your Business (KYB) due diligence on merchants before onboarding and on a
recurring basis thereafter. Halyard Pay, as an acquirer, must collect and verify a
minimum set of documents for each merchant to establish business legitimacy, confirm
beneficial ownership, and satisfy anti-money laundering screening requirements.
When this policy applies
This policy applies to all new merchant onboarding and to all periodic re-verification
reviews. Merchants that fail to supply required documentation within the stipulated
period must be suspended from processing until compliance is restored.
Required actions
-
Collect all required KYB documents at onboarding prior to approval.
-
Conduct AML screening against applicable watchlists before approval.
-
Verify business licenses for regulated merchant categories.
-
Schedule a full re-verification review at least once every 365 days.
-
Document all verification outcomes and retain records for audit purposes.
-
Retain all MATCH system records related to Merchants, Sponsored Merchants, or ATM owners for a minimum of two years after termination or expiration of the applicable agreement, to comply with Mastercard's explicit record retention requirements.
## Vendor Certification
Halyard Pay must ensure that any vendor facilities used for card production services by Issuers involved in the merchant ecosystem are certified under Mastercard's Global Vendor Certification Program (GVCP). This includes verifying that such vendors maintain current compliance certifications, achieved through annual security assessments per Mastercard SPME section 2.3. Agreements with these vendors should explicitly require adherence to applicable standards, including those in section 2.3 and the Card Design Standards manual.
Source authority: Mastercard SPME ��������2.1, §§2.1, 2.3, 11.2.6.
Acquirer KYB (Know Your Business) Obligations
Acquirers processing transactions on the Mastercard network are required to perform
Know Your Business (KYB) due diligence on merchants before onboarding and on a
recurring basis thereafter. Halyard Pay, as an acquirer, must collect and verify a
minimum set of documents for each merchant to establish business legitimacy, confirm
beneficial ownership, and satisfy anti-money laundering screening requirements.
When this policy applies
This policy applies to all new merchant onboarding and to all periodic re-verification
reviews. Merchants that fail to supply required documentation within the stipulated
period must be suspended from processing until compliance is restored.
Required actions
-
Collect all required KYB documents at onboarding prior to approval.
-
Conduct AML screening against applicable watchlists before approval.
-
Verify business licenses for regulated merchant categories.
-
Schedule a full re-verification review at least once every 365 days.
-
Document all verification outcomes and retain records for audit purposes.
-
Retain all MATCH system records related to Merchants, Sponsored Merchants, or ATM owners for a minimum of two years after termination or expiration of the applicable agreement, to comply with Mastercard's explicit record retention requirements.
## Vendor Certification
Halyard Pay must ensure that any vendor facilities used for card production services by Issuers involved in the merchant ecosystem are certified under Mastercard's Global Vendor Certification Program (GVCP). This includes verifying that such vendors maintain current compliance certifications, achieved through annual security assessments per Mastercard SPME section 2.3. Agreements with these vendors should explicitly require adherence to applicable standards, including those in section 2.3 and the Card Design Standards manual.
Source authority: Mastercard SPME ��������2.1, §§2.1, 2.3, 11.2.6.
Source authority: Mastercard SPME §2.3.
--- a/policies/kyb_acquirer/rules.yaml +++ b/policies/kyb_acquirer/rules.yaml @@ -1,5 +1,5 @@ program: Acquirer KYB -authority: Mastercard SPME 2.1, 11.2.6 +authority: Mastercard SPME 2.1, 2.3, 11.2.6 required_documents: - incorporation - beneficial_ownership @@ -13,4 +13,7 @@ - eu_consolidated agent_owner: kyb_agent # The Acquirer must specifically retain all MATCH records concerning any Merchant, Sponsored Merchant, or ATM owner for at least two years following the termination or expiration of the related agreement, per Mastercard SPME 11.2.6. -# This retention requirement updates prior guidance by imposing a defined minimum retention period beyond the MATCH system's internal data purging schedule.+# +# Regarding Mastercard SPME §2.3, the Acquirer must verify that Card production vendors have current GVCP certification, which includes annual security assessments and compliance certifications. This ensures vendors comply with PCI standards and Mastercard's Card Design Standards. +# Vendor agreements must include terms requiring safeguarding and proper use of Account data in accordance with all applicable standards. +# This addition supports enhanced due diligence and ongoing vendor compliance verification obligations under the updated GVCP requirements. --- a/policies/kyb_acquirer/policy.md +++ b/policies/kyb_acquirer/policy.md @@ -21,4 +21,9 @@ 5. Document all verification outcomes and retain records for audit purposes. 6. Retain all MATCH system records related to Merchants, Sponsored Merchants, or ATM owners for a minimum of two years after termination or expiration of the applicable agreement, to comply with Mastercard's explicit record retention requirements. -Source authority: Mastercard SPME 2.1, 11.2.6.+ +## Vendor Certification + +Halyard Pay must ensure that any vendor facilities used for card production services by Issuers involved in the merchant ecosystem are certified under Mastercard's Global Vendor Certification Program (GVCP). This includes verifying that such vendors maintain current compliance certifications, achieved through annual security assessments per Mastercard SPME section 2.3. Agreements with these vendors should explicitly require adherence to applicable standards, including those in section 2.3 and the Card Design Standards manual. + +Source authority: Mastercard SPME §§2.1, 2.3, 11.2.6.