Mastercard SPME §3.11.7 · May 2023 → Sep 2023

Use of a Vendor

substantive

The text has changed from detailing specific transaction authentication requirements to emphasizing that any agreement with a vendor providing CDCVM services must ensure the vendor agrees to protect personal information and comply with all relevant standards.

Sources Mastercard SPME · May 2023 · page 42 PDF Mastercard SPME · Sep 2023 · page 39 PDF Fraud Monitoring current
Also in §3.x this release substantive §3.11 Consumer Device Cardholder Verification Methods substantive §3.11.3 Persistent Authentication substantive §3.13.2 Acquirer Information
Why these edits? The change in SPME section 3.11.7 shifts the emphasis from transaction authentication mechanisms to requirements on vendors providing CDCVM services, specifically mandating vendor compliance with personal information protection and applicable standards, which impacts fraud monitoring procedures related to authentication services.
Mastercard SPME §3.11.7
This section was substantively restructured between versions (1% text overlap). Compare the texts directly below.
Before · May 2023 · page 42

Security Rules and Procedures—Merchant Edition • 7 February 2023

  • A valid Accountholder Authentication Value (AAV) in DE 48, subelement 43 (Universal Cardholder Authentication Field [UCAF]) resulting from an EMV 3DS authentication; or
  • In the case of a recurring payment Transaction, Identity Check Insights (previously known as Data Only). With the exception of non-face-to-face gambling Transactions, the collection and/or transmission of CVC 2 data is not required when submitting the following types of Card-not-present Transaction authorization requests:
  • A valid Accountholder Authentication Value (AAV) resulting from an EMV 3DS authentication or a Digital Secure Remote Payment (DSRP) is present in the authorization request message
  • Credential-on-file Transactions (including Account Status Inquiry (ASI) and tokenization requests of a credential-on-file) flagged correctly in the authorization request message
  • Identity Check Insights Transactions (previously known as Data Only)
  • Transactions involving a Mastercard commercial Card Virtual Account
  • Click-To-Pay or Secure Remote Commerce Transactions An Issuer must decline a Mastercard POS Transaction identified as a mail order, phone order, or e-commerce Transaction when the CVC 2 transmitted by the Acquirer does not match the CVC 2 on file with the Issuer corresponding to the Mastercard Account in question (as indicated by a value of N in DE 48, subelement 87 of the Authorization Request Response/0110 message).
After · Sep 2023 · page 39

Any agreement that a Customer enters into with a vendor for the provision of CDCVM services must include the vendor’s express agreement to safeguard and control usage of personal information and to comply with all applicable Standards.

Halyard Pay · 2 files
program: Fraud Monitoring
- authority: Mastercard SPME §3.7, §11.1.1
+ authority: Mastercard SPME 7.3, 11.1.1, 3.11.7
fraud_to_sales_ratio_threshold: 0.015
min_count_per_month: 100
monitoring_cadence: monthly
escalation_actions:
- escalate_to_human_review
- notify_acquirer
lookback_period_months: 1
remediation_review_interval_days: 30
agent_owner: fraud_ops_agent
 
- # MATCH fraud detection features are limited to principal owners only; associate owners and Service Provider name reporting are removed per SPME §11.1.1.
- # Acquirers may add and search for information on up to five principal owners per Merchant.
- # Multiple data fields are used to determine matches; MATCH supports editing and error notification to reduce delays.
- # Retroactive alert processing is supported for data up to 360 days old.
+ # MATCH fraud detection features remain focused on principal owners only, per SPME 11.1.1.
+ # Acquirers may add and search for up to five principal owners per merchant.
+ # Multiple data fields enable matching; editing and error notification features reduce delays.
+ # Retroactive alerts can process data up to 360 days old.
# Acquirers control receipt and detail of inquiry match information.
- # Real-time access via MATCH Online and API, and batch operations remain available.
- # Merchant URL information may be added and searched.
- # Crucially, after obtaining MATCH inquiry results, Acquirers must assess whether further investigation or risk mitigation actions are warranted, per updated SPME requirements.
+ # Real-time access through MATCH Online and API, plus batch operations, continue.
+ # Merchant URL info may be added and searched.
+ # Importantly, after MATCH inquiry results, acquirers must determine whether further investigation or risk mitigation is needed, consistent with updated SPME requirements.
+ # Additionally, any vendor providing Consumer Device Cardholder Verification Method (CDCVM) services must expressly agree to protect personal information and comply with applicable standards as required by SPME 3.11.7.
+ # This requirement influences fraud monitoring protocols involving authentication services and vendor oversight.

Fraud Monitoring

Halyard Pay monitors merchant fraud activity and leverages Mastercard's MATCH system for enhanced fraud risk assessment on merchants processed through our platform.

When this policy applies

This policy applies to all merchants processed by Halyard Pay where Mastercard is the applicable network, covering both card-present and card-not-present transactions.

Required actions

  1. Compute the merchant's rolling fraud-to-sales ratio each calendar month.

  2. If the ratio meets or exceeds 1.5% and the fraud count reaches at least 100 transactions in that month, escalate the merchant account to human review immediately.

  3. Utilize Mastercard's MATCH system data focusing on principal owners only, as per the updated Mastercard SPME guidelines. Do not consider associate owners or Service Provider names in fraud assessments.

  4. After accessing MATCH data, conduct a risk assessment to determine whether further investigation or additional measures are warranted.

  5. Notify the acquiring compliance officer and document the case ID with supporting transaction data.

  6. Track case progress until the account returns to threshold compliance or is terminated.

7. Ensure that any Customer agreements for Consumer Device Cardholder Verification Method (CDCVM) services include the vendor's commitment to protect and control personal information and to comply with all relevant Mastercard Standards, reflecting SPME requirements to safeguard authentication-related data.

Source authority: Mastercard SPME §3.7 §3.7, §3.11.7, and §11.1.1.

policies/fraud_monitoring/policy.md — after applying change

Fraud Monitoring

Halyard Pay monitors merchant fraud activity and leverages Mastercard's MATCH system for enhanced fraud risk assessment on merchants processed through our platform.

When this policy applies

This policy applies to all merchants processed by Halyard Pay where Mastercard is the applicable network, covering both card-present and card-not-present transactions.

Required actions

  1. Compute the merchant's rolling fraud-to-sales ratio each calendar month.

  2. If the ratio meets or exceeds 1.5% and the fraud count reaches at least 100 transactions in that month, escalate the merchant account to human review immediately.

  3. Utilize Mastercard's MATCH system data focusing on principal owners only, as per the updated Mastercard SPME guidelines. Do not consider associate owners or Service Provider names in fraud assessments.

  4. After accessing MATCH data, conduct a risk assessment to determine whether further investigation or additional measures are warranted.

  5. Notify the acquiring compliance officer and document the case ID with supporting transaction data.

  6. Track case progress until the account returns to threshold compliance or is terminated.

7. Ensure that any Customer agreements for Consumer Device Cardholder Verification Method (CDCVM) services include the vendor's commitment to protect and control personal information and to comply with all relevant Mastercard Standards, reflecting SPME requirements to safeguard authentication-related data.

Source authority: Mastercard SPME §3.7 §3.7, §3.11.7, and §11.1.1.

Source authority: Mastercard SPME §3.11.7.

--- a/policies/fraud_monitoring/rules.yaml
+++ b/policies/fraud_monitoring/rules.yaml
@@ -1,5 +1,5 @@
 program: Fraud Monitoring
-authority: Mastercard SPME §3.7, §11.1.1
+authority: Mastercard SPME 7.3, 11.1.1, 3.11.7
 fraud_to_sales_ratio_threshold: 0.015
 min_count_per_month: 100
 monitoring_cadence: monthly
@@ -10,11 +10,13 @@
 remediation_review_interval_days: 30
 agent_owner: fraud_ops_agent
 
-# MATCH fraud detection features are limited to principal owners only; associate owners and Service Provider name reporting are removed per SPME §11.1.1.
-# Acquirers may add and search for information on up to five principal owners per Merchant.
-# Multiple data fields are used to determine matches; MATCH supports editing and error notification to reduce delays.
-# Retroactive alert processing is supported for data up to 360 days old.
+# MATCH fraud detection features remain focused on principal owners only, per SPME 11.1.1.
+# Acquirers may add and search for up to five principal owners per merchant.
+# Multiple data fields enable matching; editing and error notification features reduce delays.
+# Retroactive alerts can process data up to 360 days old.
 # Acquirers control receipt and detail of inquiry match information.
-# Real-time access via MATCH Online and API, and batch operations remain available.
-# Merchant URL information may be added and searched.
-# Crucially, after obtaining MATCH inquiry results, Acquirers must assess whether further investigation or risk mitigation actions are warranted, per updated SPME requirements.
+# Real-time access through MATCH Online and API, plus batch operations, continue.
+# Merchant URL info may be added and searched.
+# Importantly, after MATCH inquiry results, acquirers must determine whether further investigation or risk mitigation is needed, consistent with updated SPME requirements.
+# Additionally, any vendor providing Consumer Device Cardholder Verification Method (CDCVM) services must expressly agree to protect personal information and comply with applicable standards as required by SPME 3.11.7.
+# This requirement influences fraud monitoring protocols involving authentication services and vendor oversight.
--- a/policies/fraud_monitoring/policy.md
+++ b/policies/fraud_monitoring/policy.md
@@ -14,5 +14,6 @@
 4. After accessing MATCH data, conduct a risk assessment to determine whether further investigation or additional measures are warranted.
 5. Notify the acquiring compliance officer and document the case ID with supporting transaction data.
 6. Track case progress until the account returns to threshold compliance or is terminated.
+7. Ensure that any Customer agreements for Consumer Device Cardholder Verification Method (CDCVM) services include the vendor's commitment to protect and control personal information and to comply with all relevant Mastercard Standards, reflecting SPME requirements to safeguard authentication-related data.
 
-Source authority: Mastercard SPME §3.7 and §11.1.1.
+Source authority: Mastercard SPME §3.7, §3.11.7, and §11.1.1.