Mastercard SPME §3.11 · May 2023 → Sep 2023

Consumer Device Cardholder Verification Methods

substantive

The update adds new requirements for Connected Consumer Devices (requiring consent on the device used), mandates strong device integrity checks during CDCVM use, and allows optional suppression of CDCVM for contactless transit transactions identified via specific MCC codes or authorization message data.

Sources Mastercard SPME · May 2023 · page 39 PDF Mastercard SPME · Sep 2023 · page 37 PDF Fraud Monitoring current
Also in §3.x this release substantive §3.11.3 Persistent Authentication substantive §3.11.7 Use of a Vendor substantive §3.13.2 Acquirer Information
Why these edits? The new requirements for strong device integrity checks during CDCVM (Connected Consumer Device Cardholder Verification Methods) use align with enhanced Fraud Monitoring obligations to verify device authenticity and reduce fraud risk.
Mastercard SPME §3.11
This section was substantively restructured between versions (6% text overlap). Compare the texts directly below.
Before · May 2023 · page 39

Security Rules and Procedures—Merchant Edition • 7 February 2023

b. Explicit Cardholder consent—The Cardholder takes a specific Issuer- approved action that serves to confirm that the Cardholder intends a Transaction to be performed. This must consist of an action involving the Access Device that is separate from the act of tapping the Access Device to the Merchant’s POS Terminal; for example, the clicking of a button.

After · Sep 2023 · page 37

Security Rules and Procedures—Merchant Edition • 1 August 2023

  1. Connected Consumer Devices—If two or more devices in the control of a Cardholder are able to be connected or linked to provide common payment functionality, so that each such device can be an Access Device for the same Account, then Cardholder consent must occur on the Access Device used to effect the Transaction.
  2. Device Integrity—Upon initiation and continuing throughout Cardholder authentication, the use of the CDCVM must depend on strong device integrity checks. Examples include device runtime integrity checks, remote device attestation, or a combination of both, and checks to ensure that prolonged CVM velocity is intact; for example, the device lock functionality was not disabled. CDCVM functionality requirements relating to explicit Cardholder consent apply only to the extent that a CVM is requested by the Merchant or Terminal or required by the Issuer for completion of a Transaction. A Cardholder may be offered the option to suppress CDCVM functionality relating to both Cardholder authentication and explicit Cardholder consent solely in connection with Contactless Transactions conducted to obtain transit access (for example, at a turnstile or entry gate). Such Contactless Transactions must be identified with one of the following Card acceptor business codes (MCCs):
  • MCC 4111 (Transportation—Suburban and Local Commuter Passenger, including Ferries)
  • MCC 4112 (Passenger Railways)
  • MCC 4131 (Bus Lines) In order for a Mobile Payment Device to support CDCVM suppression for transit, its mobile Payment Application must be capable of identifying either of the following conditions in a Contactless Transaction authorization request message:
  • A specific bit of Terminal Risk Management Data (Tag 9F1D); or
  • One of the above transit MCCs together with a zero Transaction amount. Either of these conditions enables the Mobile Payment Device to determine that a Contactless Transaction is being conducted for transit access, and not for another purpose (such as the purchase of a monthly transit pass).
Halyard Pay · 2 files
program: Fraud Monitoring
- authority: Mastercard SPME §3.7, §11.1.1
+ authority: Mastercard SPME §3.7, §3.11, §11.1.1
fraud_to_sales_ratio_threshold: 0.015
min_count_per_month: 100
monitoring_cadence: monthly
escalation_actions:
- escalate_to_human_review
- notify_acquirer
lookback_period_months: 1
remediation_review_interval_days: 30
agent_owner: fraud_ops_agent
 
# MATCH fraud detection features are limited to principal owners only; associate owners and Service Provider name reporting are removed per SPME §11.1.1.
# Acquirers may add and search for information on up to five principal owners per Merchant.
# Multiple data fields are used to determine matches; MATCH supports editing and error notification to reduce delays.
# Retroactive alert processing is supported for data up to 360 days old.
# Acquirers control receipt and detail of inquiry match information.
# Real-time access via MATCH Online and API, and batch operations remain available.
# Merchant URL information may be added and searched.
# Crucially, after obtaining MATCH inquiry results, Acquirers must assess whether further investigation or risk mitigation actions are warranted, per updated SPME requirements.
+ #
+ # In line with Mastercard SPME §3.11 updates, fraud monitoring processes now incorporate enhanced verification for Connected Consumer Device Cardholder Verification Methods (CDCVM).
+ # This includes ensuring strong device integrity throughout cardholder authentication, via runtime checks or remote device attestation, to mitigate device spoofing risks.
+ # Monitoring aims to confirm that CDCVM usage complies with updated explicit consent protocols, particularly for contactless transactions involving transit MCC codes where CDCVM suppression is permitted.
+ # These enhancements strengthen fraud detection accuracy by ensuring device authenticity and adherence to Mastercard's device integrity requirements.

Fraud Monitoring

Halyard Pay monitors merchant fraud activity and leverages Mastercard's MATCH system for enhanced fraud risk assessment on merchants processed through our platform.

When this policy applies

This policy applies to all merchants processed by Halyard Pay where Mastercard is the applicable network, covering both card-present and card-not-present transactions.

Required actions

  1. Compute the merchant's rolling fraud-to-sales ratio each calendar month.

  2. If the ratio meets or exceeds 1.5% and the fraud count reaches at least 100 transactions in that month, escalate the merchant account to human review immediately.

  3. Utilize Mastercard's MATCH system data focusing on principal owners only, as per the updated Mastercard SPME guidelines. Do not consider associate owners or Service Provider names in fraud assessments.

  4. After accessing MATCH data, conduct a risk assessment to determine whether further investigation or additional measures are warranted.

  5. Incorporate verification of device integrity checks related to Connected Consumer Device Cardholder Verification Methods (CDCVM) as specified by Mastercard, ensuring device authenticity during transactions.

6. Notify the acquiring compliance officer and document the case ID with supporting transaction data.

6. 7. Track case progress until the account returns to threshold compliance or is terminated.

Source authority: Mastercard SPME §3.7 §3.7, §3.11, and §11.1.1.

policies/fraud_monitoring/policy.md — after applying change

Fraud Monitoring

Halyard Pay monitors merchant fraud activity and leverages Mastercard's MATCH system for enhanced fraud risk assessment on merchants processed through our platform.

When this policy applies

This policy applies to all merchants processed by Halyard Pay where Mastercard is the applicable network, covering both card-present and card-not-present transactions.

Required actions

  1. Compute the merchant's rolling fraud-to-sales ratio each calendar month.

  2. If the ratio meets or exceeds 1.5% and the fraud count reaches at least 100 transactions in that month, escalate the merchant account to human review immediately.

  3. Utilize Mastercard's MATCH system data focusing on principal owners only, as per the updated Mastercard SPME guidelines. Do not consider associate owners or Service Provider names in fraud assessments.

  4. After accessing MATCH data, conduct a risk assessment to determine whether further investigation or additional measures are warranted.

  5. Incorporate verification of device integrity checks related to Connected Consumer Device Cardholder Verification Methods (CDCVM) as specified by Mastercard, ensuring device authenticity during transactions.

6. Notify the acquiring compliance officer and document the case ID with supporting transaction data.

6. 7. Track case progress until the account returns to threshold compliance or is terminated.

Source authority: Mastercard SPME §3.7 §3.7, §3.11, and §11.1.1.

Source authority: Mastercard SPME §3.11.

--- a/policies/fraud_monitoring/rules.yaml
+++ b/policies/fraud_monitoring/rules.yaml
@@ -1,5 +1,5 @@
 program: Fraud Monitoring
-authority: Mastercard SPME §3.7, §11.1.1
+authority: Mastercard SPME §3.7, §3.11, §11.1.1
 fraud_to_sales_ratio_threshold: 0.015
 min_count_per_month: 100
 monitoring_cadence: monthly
@@ -18,3 +18,8 @@
 # Real-time access via MATCH Online and API, and batch operations remain available.
 # Merchant URL information may be added and searched.
 # Crucially, after obtaining MATCH inquiry results, Acquirers must assess whether further investigation or risk mitigation actions are warranted, per updated SPME requirements.
+#
+# In line with Mastercard SPME §3.11 updates, fraud monitoring processes now incorporate enhanced verification for Connected Consumer Device Cardholder Verification Methods (CDCVM).
+# This includes ensuring strong device integrity throughout cardholder authentication, via runtime checks or remote device attestation, to mitigate device spoofing risks.
+# Monitoring aims to confirm that CDCVM usage complies with updated explicit consent protocols, particularly for contactless transactions involving transit MCC codes where CDCVM suppression is permitted.
+# These enhancements strengthen fraud detection accuracy by ensuring device authenticity and adherence to Mastercard's device integrity requirements.
--- a/policies/fraud_monitoring/policy.md
+++ b/policies/fraud_monitoring/policy.md
@@ -12,7 +12,8 @@
 2. If the ratio meets or exceeds 1.5% and the fraud count reaches at least 100 transactions in that month, escalate the merchant account to human review immediately.
 3. Utilize Mastercard's MATCH system data focusing on principal owners only, as per the updated Mastercard SPME guidelines. Do not consider associate owners or Service Provider names in fraud assessments.
 4. After accessing MATCH data, conduct a risk assessment to determine whether further investigation or additional measures are warranted.
-5. Notify the acquiring compliance officer and document the case ID with supporting transaction data.
-6. Track case progress until the account returns to threshold compliance or is terminated.
+5. Incorporate verification of device integrity checks related to Connected Consumer Device Cardholder Verification Methods (CDCVM) as specified by Mastercard, ensuring device authenticity during transactions.
+6. Notify the acquiring compliance officer and document the case ID with supporting transaction data.
+7. Track case progress until the account returns to threshold compliance or is terminated.
 
-Source authority: Mastercard SPME §3.7 and §11.1.1.
+Source authority: Mastercard SPME §3.7, §3.11, and §11.1.1.