Mastercard SPME §4.10 · May 2023 → Sep 2023

Multi-Factor Authentication Methods for Remote Commerce Token Transactions

substantive

The updated section adds requirements for security evaluation and qualification of MFA methods as high or low assurance, mandates Mastercard approval for low assurance methods, and specifies audit requirements under PSD2 RTS and UK Standards, impacting issuer reliance on fraud deterrence.

Sources Mastercard SPME · May 2023 · page 52 PDF Mastercard SPME · Sep 2023 · page 49 PDF Fraud Monitoring current
Also in §4.x this release breaking §4.7 Terminal Security Standards substantive §4.1 Personal Identification Numbers (PINs) substantive §4.10.2 Multi-Factor Authentication Method Functionality substantive §4.10.4 Prolonged Authentication substantive §4.9 Triple DES Standards
Why these edits? The updated SPME introduces requirements for security evaluation and assurance qualification of Multi-Factor Authentication methods, which may affect issuer reliance on fraud deterrence, directly relating to fraud monitoring obligations.
Mastercard SPME §4.10
This section was substantively restructured between versions (2% text overlap). Compare the texts directly below.
Before · May 2023 · page 52

Token Transactions Subject to any regulatory approvals and compliance with applicable laws and regulation, Cardholder authentication technologies may be implemented by an entity (herein, the "Authenticating Entity") in remote commerce use cases, to verify a person as an authorized Cardholder based on the use of two or more authentication factors. Each factor must belong to one of the three following categories, with no more than one authentication factor coming from any one category. Terminal, PIN, and MFA Method Security Standards

After · Sep 2023 · page 49

Security Rules and Procedures—Merchant Edition • 1 August 2023

This requirement also applies with respect to any proposed update, change, or modification of the consumer authentication technology that could impact the functionality or security of the MFA Method. Following successful completion of the security evaluation, the Method will be qualified as a high assurance Method. Pending Mastercard approval, the MFA Method may go through a security evaluation performed outside of a laboratory accredited by Mastercard, and be qualified as a low assurance Method instead. In this case, the entity certifying the Method must be an independent auditor that performs other certifications or similar activity. In the EEA, San Marino, United Kingdom, and Gibraltar, MFA Methods are subject to the audit requirements set out in Article 3 of the PSD2 RTS on SCA and UK Technical Standards on SCA. The level of assurance may be a relevant factor in Issuer reliance on the solution for fraud deterrence.

Halyard Pay · 2 files
program: Fraud Monitoring
- authority: Mastercard SPME §3.7, §11.1.1
+ authority: Mastercard SPME §3.7, §11.1.1, §4.10
fraud_to_sales_ratio_threshold: 0.015
min_count_per_month: 100
monitoring_cadence: monthly
escalation_actions:
- escalate_to_human_review
- notify_acquirer
lookback_period_months: 1
remediation_review_interval_days: 30
agent_owner: fraud_ops_agent
 
# MATCH fraud detection features are limited to principal owners only; associate owners and Service Provider name reporting are removed per SPME §11.1.1.
# Acquirers may add and search for information on up to five principal owners per Merchant.
# Multiple data fields are used to determine matches; MATCH supports editing and error notification to reduce delays.
# Retroactive alert processing is supported for data up to 360 days old.
# Acquirers control receipt and detail of inquiry match information.
# Real-time access via MATCH Online and API, and batch operations remain available.
# Merchant URL information may be added and searched.
- # Crucially, after obtaining MATCH inquiry results, Acquirers must assess whether further investigation or risk mitigation actions are warranted, per updated SPME requirements.
+ # After obtaining MATCH inquiry results, Acquirers must assess whether further investigation or risk mitigation actions are warranted, per updated SPME requirements.
+ #
+ # Following SPME §4.10, fraud monitoring must consider the security evaluation and assurance level of Multi-Factor Authentication (MFA) methods used by merchants and authenticating entities.
+ # MFA methods must be qualified as high or low assurance based on independent security evaluation, which impacts the issuer's fraud deterrence reliance.
+ # Regions including EEA, San Marino, United Kingdom, and Gibraltar have specific audit requirements under PSD2 RTS and UK Technical Standards on SCA, which should be monitored for compliance.
+ # These changes require updating fraud risk assessment processes to incorporate MFA method assurance levels to enhance fraud detection and monitoring efficacy.

Fraud Monitoring

Halyard Pay monitors merchant fraud activity and leverages Mastercard's MATCH system for enhanced fraud risk assessment on merchants processed through our platform.

When this policy applies

This policy applies to all merchants processed by Halyard Pay where Mastercard is the applicable network, covering both card-present and card-not-present transactions.

Required actions

  1. Compute the merchant's rolling fraud-to-sales ratio each calendar month.

  2. If the ratio meets or exceeds 1.5% and the fraud count reaches at least 100 transactions in that month, escalate the merchant account to human review immediately.

  3. Utilize Mastercard's MATCH system data focusing on principal owners only, as per the updated Mastercard SPME guidelines. Do not consider associate owners or Service Provider names in fraud assessments.

  4. After accessing MATCH data, conduct a risk assessment to determine whether further investigation or additional measures are warranted.

  5. Maintain awareness of Mastercard's requirements for Multi-Factor Authentication (MFA) methods security evaluations, as the assurance level of MFA methods may influence issuer fraud deterrence strategies.

6. Notify the acquiring compliance officer and document the case ID with supporting transaction data.

6. 7. Track case progress until the account returns to threshold compliance or is terminated.

Source authority: Mastercard SPME §3.7 §3.7, §4.10, and §11.1.1.

policies/fraud_monitoring/policy.md — after applying change

Fraud Monitoring

Halyard Pay monitors merchant fraud activity and leverages Mastercard's MATCH system for enhanced fraud risk assessment on merchants processed through our platform.

When this policy applies

This policy applies to all merchants processed by Halyard Pay where Mastercard is the applicable network, covering both card-present and card-not-present transactions.

Required actions

  1. Compute the merchant's rolling fraud-to-sales ratio each calendar month.

  2. If the ratio meets or exceeds 1.5% and the fraud count reaches at least 100 transactions in that month, escalate the merchant account to human review immediately.

  3. Utilize Mastercard's MATCH system data focusing on principal owners only, as per the updated Mastercard SPME guidelines. Do not consider associate owners or Service Provider names in fraud assessments.

  4. After accessing MATCH data, conduct a risk assessment to determine whether further investigation or additional measures are warranted.

  5. Maintain awareness of Mastercard's requirements for Multi-Factor Authentication (MFA) methods security evaluations, as the assurance level of MFA methods may influence issuer fraud deterrence strategies.

6. Notify the acquiring compliance officer and document the case ID with supporting transaction data.

6. 7. Track case progress until the account returns to threshold compliance or is terminated.

Source authority: Mastercard SPME §3.7 §3.7, §4.10, and §11.1.1.

Source authority: Mastercard SPME §4.10.

--- a/policies/fraud_monitoring/rules.yaml
+++ b/policies/fraud_monitoring/rules.yaml
@@ -1,5 +1,5 @@
 program: Fraud Monitoring
-authority: Mastercard SPME §3.7, §11.1.1
+authority: Mastercard SPME §3.7, §11.1.1, §4.10
 fraud_to_sales_ratio_threshold: 0.015
 min_count_per_month: 100
 monitoring_cadence: monthly
@@ -17,4 +17,9 @@
 # Acquirers control receipt and detail of inquiry match information.
 # Real-time access via MATCH Online and API, and batch operations remain available.
 # Merchant URL information may be added and searched.
-# Crucially, after obtaining MATCH inquiry results, Acquirers must assess whether further investigation or risk mitigation actions are warranted, per updated SPME requirements.
+# After obtaining MATCH inquiry results, Acquirers must assess whether further investigation or risk mitigation actions are warranted, per updated SPME requirements.
+#
+# Following SPME §4.10, fraud monitoring must consider the security evaluation and assurance level of Multi-Factor Authentication (MFA) methods used by merchants and authenticating entities.
+# MFA methods must be qualified as high or low assurance based on independent security evaluation, which impacts the issuer's fraud deterrence reliance.
+# Regions including EEA, San Marino, United Kingdom, and Gibraltar have specific audit requirements under PSD2 RTS and UK Technical Standards on SCA, which should be monitored for compliance.
+# These changes require updating fraud risk assessment processes to incorporate MFA method assurance levels to enhance fraud detection and monitoring efficacy.

--- a/policies/fraud_monitoring/policy.md
+++ b/policies/fraud_monitoring/policy.md
@@ -12,7 +12,8 @@
 2. If the ratio meets or exceeds 1.5% and the fraud count reaches at least 100 transactions in that month, escalate the merchant account to human review immediately.
 3. Utilize Mastercard's MATCH system data focusing on principal owners only, as per the updated Mastercard SPME guidelines. Do not consider associate owners or Service Provider names in fraud assessments.
 4. After accessing MATCH data, conduct a risk assessment to determine whether further investigation or additional measures are warranted.
-5. Notify the acquiring compliance officer and document the case ID with supporting transaction data.
-6. Track case progress until the account returns to threshold compliance or is terminated.
+5. Maintain awareness of Mastercard's requirements for Multi-Factor Authentication (MFA) methods security evaluations, as the assurance level of MFA methods may influence issuer fraud deterrence strategies.
+6. Notify the acquiring compliance officer and document the case ID with supporting transaction data.
+7. Track case progress until the account returns to threshold compliance or is terminated.
 
-Source authority: Mastercard SPME §3.7 and §11.1.1.
+Source authority: Mastercard SPME §3.7, §4.10, and §11.1.1.