Mastercard SPME §4.1 · May 2023 → Sep 2023

Personal Identification Numbers (PINs)

substantive

The updated section removes the initial general compliance statement and adds explicit requirements that all PIN encryption, translation, and decryption must be performed using hardware encryption only, prohibiting software-based methods. Additionally, it advises Issuers to consult Issuer PIN Security Guidelines for comprehensive PIN management practices.

Sources Mastercard SPME · May 2023 · page 48 PDF Mastercard SPME · Sep 2023 · page 45 PDF Fraud Monitoring current
Also in §4.x this release breaking §4.7 Terminal Security Standards substantive §4.10 Multi-Factor Authentication Methods for Remote Commerce Token Transactions substantive §4.10.2 Multi-Factor Authentication Method Functionality substantive §4.10.4 Prolonged Authentication substantive §4.9 Triple DES Standards
Why these edits? The updated SPME section 4.1 introduces explicit hardware encryption requirements for PIN processing, which affects the Fraud Monitoring policy as it ensures PIN security and integrity, reducing fraud risks related to PIN transactions.
Mastercard SPME §4.1
This section was substantively restructured between versions (20% text overlap). Compare the texts directly below.
Before · May 2023 · page 48

Security Rules and Procedures—Merchant Edition • 7 February 2023

All Acquirers and their agents performing PIN Transaction processing must comply with the security requirements for PIN and key management specified in the Payment Card Industry PIN Security Requirements. In addition, all Acquirers and their agents must adhere to the following Standards for PIN encryption:

After · Sep 2023 · page 45

Security Rules and Procedures—Merchant Edition • 1 August 2023

In addition, all Acquirers and their agents must adhere to the following Standards for PIN encryption:

  1. Perform all PIN encryption, translation, and decryption for the network using hardware encryption.
  2. Do not perform PIN encryption, translation, or decryption using software routines. All Issuers and their agents performing PIN processing should refer to the Issuer PIN Security Guidelines regarding all aspects of Issuer PIN and PIN key management, including PIN selection, transmission, storage, usage guidance, and PIN change.
Halyard Pay · 2 files
program: Fraud Monitoring
- authority: Mastercard SPME §3.7, §11.1.1
+ authority: Mastercard SPME §3.7, §4.1, §11.1.1
fraud_to_sales_ratio_threshold: 0.015
min_count_per_month: 100
monitoring_cadence: monthly
escalation_actions:
- escalate_to_human_review
- notify_acquirer
lookback_period_months: 1
remediation_review_interval_days: 30
agent_owner: fraud_ops_agent
 
# MATCH fraud detection features are limited to principal owners only; associate owners and Service Provider name reporting are removed per SPME §11.1.1.
# Acquirers may add and search for information on up to five principal owners per Merchant.
# Multiple data fields are used to determine matches; MATCH supports editing and error notification to reduce delays.
# Retroactive alert processing is supported for data up to 360 days old.
# Acquirers control receipt and detail of inquiry match information.
# Real-time access via MATCH Online and API, and batch operations remain available.
# Merchant URL information may be added and searched.
# Crucially, after obtaining MATCH inquiry results, Acquirers must assess whether further investigation or risk mitigation actions are warranted, per updated SPME requirements.
+ #
+ # PIN processing security is reinforced per Mastercard SPME §4.1 update, requiring all PIN encryption, translation, and decryption to be performed exclusively via hardware encryption mechanisms to ensure PIN data integrity and reduce fraud risks.
+ # Software-based PIN encryption methods are prohibited for all Acquirers and their agents handling PIN transactions.
+ # Issuers and their agents should continue to follow the Issuer PIN Security Guidelines covering PIN selection, transmission, storage, usage, and changes.

Fraud Monitoring

Halyard Pay monitors merchant fraud activity and leverages Mastercard's MATCH system for enhanced fraud risk assessment on merchants processed through our platform.

When this policy applies

This policy applies to all merchants processed by Halyard Pay where Mastercard is the applicable network, covering both card-present and card-not-present transactions.

Required actions

  1. Compute the merchant's rolling fraud-to-sales ratio each calendar month.

  2. If the ratio meets or exceeds 1.5% and the fraud count reaches at least 100 transactions in that month, escalate the merchant account to human review immediately.

  3. Utilize Mastercard's MATCH system data focusing on principal owners only, as per the updated Mastercard SPME guidelines. Do not consider associate owners or Service Provider names in fraud assessments.

  4. After accessing MATCH data, conduct a risk assessment to determine whether further investigation or additional measures are warranted.

  5. Notify the acquiring compliance officer and document the case ID with supporting transaction data.

  6. Track case progress until the account returns to threshold compliance or is terminated.

## PIN Encryption Compliance

Halyard Pay ensures all PIN transaction processing complies with Mastercard's requirement that PIN encryption, translation, and decryption be performed exclusively using hardware encryption. Software-based PIN cryptographic operations are prohibited. This mandate supports the integrity and security of PIN data and reduces fraud risks related to PIN transactions.

Source authority: Mastercard SPME §3.7 and §11.1.1.§§3.7, 4.1, and 11.1.1.

policies/fraud_monitoring/policy.md — after applying change

Fraud Monitoring

Halyard Pay monitors merchant fraud activity and leverages Mastercard's MATCH system for enhanced fraud risk assessment on merchants processed through our platform.

When this policy applies

This policy applies to all merchants processed by Halyard Pay where Mastercard is the applicable network, covering both card-present and card-not-present transactions.

Required actions

  1. Compute the merchant's rolling fraud-to-sales ratio each calendar month.

  2. If the ratio meets or exceeds 1.5% and the fraud count reaches at least 100 transactions in that month, escalate the merchant account to human review immediately.

  3. Utilize Mastercard's MATCH system data focusing on principal owners only, as per the updated Mastercard SPME guidelines. Do not consider associate owners or Service Provider names in fraud assessments.

  4. After accessing MATCH data, conduct a risk assessment to determine whether further investigation or additional measures are warranted.

  5. Notify the acquiring compliance officer and document the case ID with supporting transaction data.

  6. Track case progress until the account returns to threshold compliance or is terminated.

## PIN Encryption Compliance

Halyard Pay ensures all PIN transaction processing complies with Mastercard's requirement that PIN encryption, translation, and decryption be performed exclusively using hardware encryption. Software-based PIN cryptographic operations are prohibited. This mandate supports the integrity and security of PIN data and reduces fraud risks related to PIN transactions.

Source authority: Mastercard SPME §3.7 and §11.1.1.§§3.7, 4.1, and 11.1.1.

Source authority: Mastercard SPME §4.1.

--- a/policies/fraud_monitoring/rules.yaml
+++ b/policies/fraud_monitoring/rules.yaml
@@ -1,5 +1,5 @@
 program: Fraud Monitoring
-authority: Mastercard SPME §3.7, §11.1.1
+authority: Mastercard SPME §3.7, §4.1, §11.1.1
 fraud_to_sales_ratio_threshold: 0.015
 min_count_per_month: 100
 monitoring_cadence: monthly
@@ -18,3 +18,7 @@
 # Real-time access via MATCH Online and API, and batch operations remain available.
 # Merchant URL information may be added and searched.
 # Crucially, after obtaining MATCH inquiry results, Acquirers must assess whether further investigation or risk mitigation actions are warranted, per updated SPME requirements.
+#
+# PIN processing security is reinforced per Mastercard SPME §4.1 update, requiring all PIN encryption, translation, and decryption to be performed exclusively via hardware encryption mechanisms to ensure PIN data integrity and reduce fraud risks.
+# Software-based PIN encryption methods are prohibited for all Acquirers and their agents handling PIN transactions.
+# Issuers and their agents should continue to follow the Issuer PIN Security Guidelines covering PIN selection, transmission, storage, usage, and changes.
--- a/policies/fraud_monitoring/policy.md
+++ b/policies/fraud_monitoring/policy.md
@@ -15,4 +15,8 @@
 5. Notify the acquiring compliance officer and document the case ID with supporting transaction data.
 6. Track case progress until the account returns to threshold compliance or is terminated.
 
-Source authority: Mastercard SPME §3.7 and §11.1.1.
+## PIN Encryption Compliance
+
+Halyard Pay ensures all PIN transaction processing complies with Mastercard's requirement that PIN encryption, translation, and decryption be performed exclusively using hardware encryption. Software-based PIN cryptographic operations are prohibited. This mandate supports the integrity and security of PIN data and reduces fraud risks related to PIN transactions.
+
+Source authority: Mastercard SPME §§3.7, 4.1, and 11.1.1.