Mastercard SPME §2.4.1 · May 2023 → Sep 2023

PIN Entry Devices (PEDs) and Encrypting PIN Pads (EPPs)

substantive

The updated section adds explicit requirements for Acquirers to manage PED and EPP inventories by identifying device types and locations and having trained staff conduct inspections. It also introduces Mastercard’s authority to mandate risk mitigation actions, including device model sunsetting in case of security threats, prohibiting use after a sunset date.

Sources Mastercard SPME · May 2023 · page 34 PDF Mastercard SPME · Sep 2023 · page 32 PDF KYB Acquirer current
Also in §2.x this release substantive §2 Cleared, meaning the Acquirer transferred the Transaction Data within the substantive §2.1.1 Payment Card Industry (PCI) Security Standards substantive §2.2 Mastercard Site Data Protection (SDP) Program substantive §2.2.2 Merchant Compliance Requirements substantive §2.2.4 Mastercard Cybersecurity Incentive Program (CSIP) substantive §2.2.5 SDP Program Noncompliance Assessments substantive §2.2.6 Mandatory Compliance Requirements for Compromised Entities substantive §2.3 Card Production Security Standards
Why these edits? The updated obligations specifically require Acquirers to maintain detailed PED and EPP device inventories, conduct inspections with trained staff, and comply with Mastercard's authority to mandate risk mitigation actions such as device model sunsetting, expanding the scope of Acquirer KYB responsibilities.
Mastercard SPME §2.4.1
Security Rules and Procedures—Merchant Edition • 7 February 1 August 2023 – The device set is in inventory when the PCI PTS approval expired. Device models that reach approval expiration are moved from the PCI Approved PTS Devices list to the PIN Transaction Security Devices With Expired Approvals list. – The device set is under a device management system. Such system must ensure that devices are able to both receive software security patches when made available by the device vendor and are physically managed (for example, maintaining a list of devices and periodically inspecting devices to look for tampering or substitution). 3. An Acquirer must properly manage its PED and EPP inventory. Such management must include: – Identifying the type and location of each deployed device; and – Having trained staff to conduct periodic visual inspections for signs of tampering or device substitution. 4. In exceptional circumstances, such as widespread successful attacks to a specific model of PED or EPP, Mastercard may, at any point in time, require Acquirers to follow specific risk management actions that may include the sunsetting of that model. Should Mastercard announce a sunset date for a given model, devices of that model, as of the specified sunset date, must no longer be used to process Transactions.
Halyard Pay · 2 files
program: Acquirer KYB
- authority: Mastercard SPME 2.1, 11.2.6
+ authority: Mastercard SPME 2.1, 11.2.6, 2.4.1
required_documents:
- incorporation
- beneficial_ownership
- aml_screen
- license_verification
min_review_cycle_days: 365
suspension_trigger: document_collection_failure
record_retention_years: 7
aml_watchlist_sources:
- ofac_sdn
- eu_consolidated
agent_owner: kyb_agent
# The Acquirer must specifically retain all MATCH records concerning any Merchant, Sponsored Merchant, or ATM owner for at least two years following the termination or expiration of the related agreement, per Mastercard SPME 11.2.6.
- # This retention requirement updates prior guidance by imposing a defined minimum retention period beyond the MATCH system's internal data purging schedule.
+ #
+ # Mastercard SPME 2.4.1 expands Acquirer responsibilities to include detailed management of PED and EPP devices.
+ # This includes maintaining accurate inventories of all deployed devices, by type and location, and assigning trained personnel to perform routine visual inspections for tampering or substitution.
+ # Additionally, Acquirers must comply with Mastercard directives requiring risk mitigation such as device model sunsetting in response to security threats.
+ # These enhanced device management requirements enhance transaction security and risk control within the Acquirer KYB framework.

Acquirer KYB (Know Your Business) Obligations

Acquirers processing transactions on the Mastercard network are required to perform Know Your Business (KYB) due diligence on merchants before onboarding and on a recurring basis thereafter. Halyard Pay, as an acquirer, must collect and verify a minimum set of documents for each merchant to establish business legitimacy, confirm beneficial ownership, and satisfy anti-money laundering screening requirements.

When this policy applies

This policy applies to all new merchant onboarding and to all periodic re-verification reviews. Merchants that fail to supply required documentation within the stipulated period must be suspended from processing until compliance is restored.

Required actions

  1. Collect all required KYB documents at onboarding prior to approval.

  2. Conduct AML screening against applicable watchlists before approval.

  3. Verify business licenses for regulated merchant categories.

  4. Schedule a full re-verification review at least once every 365 days.

  5. Document all verification outcomes and retain records for audit purposes.

  6. Retain all MATCH system records related to Merchants, Sponsored Merchants, or ATM owners for a minimum of two years after termination or expiration of the applicable agreement, to comply with Mastercard's explicit record retention requirements.

7. Maintain an accurate inventory of Payment Entry Devices (PED) and Encrypting PIN Pads (EPP), including device type and location information.

8. Assign trained personnel to perform periodic visual inspections of PED and EPP devices to detect tampering or substitution.

9. Comply with Mastercard directives requiring risk mitigation actions on devices, including device model sunset mandates in response to security threats.

Source authority: Mastercard SPME ��������2.1, §2.1, 2.4.1, 11.2.6.

policies/kyb_acquirer/policy.md — after applying change

Acquirer KYB (Know Your Business) Obligations

Acquirers processing transactions on the Mastercard network are required to perform Know Your Business (KYB) due diligence on merchants before onboarding and on a recurring basis thereafter. Halyard Pay, as an acquirer, must collect and verify a minimum set of documents for each merchant to establish business legitimacy, confirm beneficial ownership, and satisfy anti-money laundering screening requirements.

When this policy applies

This policy applies to all new merchant onboarding and to all periodic re-verification reviews. Merchants that fail to supply required documentation within the stipulated period must be suspended from processing until compliance is restored.

Required actions

  1. Collect all required KYB documents at onboarding prior to approval.

  2. Conduct AML screening against applicable watchlists before approval.

  3. Verify business licenses for regulated merchant categories.

  4. Schedule a full re-verification review at least once every 365 days.

  5. Document all verification outcomes and retain records for audit purposes.

  6. Retain all MATCH system records related to Merchants, Sponsored Merchants, or ATM owners for a minimum of two years after termination or expiration of the applicable agreement, to comply with Mastercard's explicit record retention requirements.

7. Maintain an accurate inventory of Payment Entry Devices (PED) and Encrypting PIN Pads (EPP), including device type and location information.

8. Assign trained personnel to perform periodic visual inspections of PED and EPP devices to detect tampering or substitution.

9. Comply with Mastercard directives requiring risk mitigation actions on devices, including device model sunset mandates in response to security threats.

Source authority: Mastercard SPME ��������2.1, §2.1, 2.4.1, 11.2.6.

Source authority: Mastercard SPME §2.4.1.

--- a/policies/kyb_acquirer/rules.yaml
+++ b/policies/kyb_acquirer/rules.yaml
@@ -1,5 +1,5 @@
 program: Acquirer KYB
-authority: Mastercard SPME 2.1, 11.2.6
+authority: Mastercard SPME 2.1, 11.2.6, 2.4.1
 required_documents:
   - incorporation
   - beneficial_ownership
@@ -13,4 +13,8 @@
   - eu_consolidated
 agent_owner: kyb_agent
 # The Acquirer must specifically retain all MATCH records concerning any Merchant, Sponsored Merchant, or ATM owner for at least two years following the termination or expiration of the related agreement, per Mastercard SPME 11.2.6.
-# This retention requirement updates prior guidance by imposing a defined minimum retention period beyond the MATCH system's internal data purging schedule.+#
+# Mastercard SPME 2.4.1 expands Acquirer responsibilities to include detailed management of PED and EPP devices.
+# This includes maintaining accurate inventories of all deployed devices, by type and location, and assigning trained personnel to perform routine visual inspections for tampering or substitution.
+# Additionally, Acquirers must comply with Mastercard directives requiring risk mitigation such as device model sunsetting in response to security threats.
+# These enhanced device management requirements enhance transaction security and risk control within the Acquirer KYB framework.
--- a/policies/kyb_acquirer/policy.md
+++ b/policies/kyb_acquirer/policy.md
@@ -1,16 +1,10 @@
 # Acquirer KYB (Know Your Business) Obligations
 
-Acquirers processing transactions on the Mastercard network are required to perform
-Know Your Business (KYB) due diligence on merchants before onboarding and on a
-recurring basis thereafter. Halyard Pay, as an acquirer, must collect and verify a
-minimum set of documents for each merchant to establish business legitimacy, confirm
-beneficial ownership, and satisfy anti-money laundering screening requirements.
+Acquirers processing transactions on the Mastercard network are required to perform Know Your Business (KYB) due diligence on merchants before onboarding and on a recurring basis thereafter. Halyard Pay, as an acquirer, must collect and verify a minimum set of documents for each merchant to establish business legitimacy, confirm beneficial ownership, and satisfy anti-money laundering screening requirements.
 
 ## When this policy applies
 
-This policy applies to all new merchant onboarding and to all periodic re-verification
-reviews. Merchants that fail to supply required documentation within the stipulated
-period must be suspended from processing until compliance is restored.
+This policy applies to all new merchant onboarding and to all periodic re-verification reviews. Merchants that fail to supply required documentation within the stipulated period must be suspended from processing until compliance is restored.
 
 ## Required actions
 
@@ -20,5 +14,8 @@
 4. Schedule a full re-verification review at least once every 365 days.
 5. Document all verification outcomes and retain records for audit purposes.
 6. Retain all MATCH system records related to Merchants, Sponsored Merchants, or ATM owners for a minimum of two years after termination or expiration of the applicable agreement, to comply with Mastercard's explicit record retention requirements.
+7. Maintain an accurate inventory of Payment Entry Devices (PED) and Encrypting PIN Pads (EPP), including device type and location information.
+8. Assign trained personnel to perform periodic visual inspections of PED and EPP devices to detect tampering or substitution.
+9. Comply with Mastercard directives requiring risk mitigation actions on devices, including device model sunset mandates in response to security threats.
 
-Source authority: Mastercard SPME 2.1, 11.2.6.+Source authority: Mastercard SPME §2.1, 2.4.1, 11.2.6.