Mastercard SPME §7.2 · May 2023 → Sep 2023

Ongoing Monitoring

substantive

The updated section adds requirements for Acquirers to regularly review e-commerce Merchants' websites and business activities to ensure compliance with Standards and recommends using monitoring solutions to prevent illegal or harmful transactions. It also clarifies that monitoring includes fraud loss controls related to deposits and authorizations per section 6.2.2.

Sources Mastercard SPME · May 2023 · page 77 PDF Mastercard SPME · Sep 2023 · page 72 PDF Fraud Monitoring current
Also in §7.x this release substantive §7.1.3 Assessments for Noncompliance with Screening Procedures
Why these edits? The obligation for Acquirers to regularly review e-commerce Merchants' websites and their business activities as a form of ongoing monitoring expands the scope of fraud-related controls and ties this explicitly to fraud loss controls referred to in section 6.2.2, which is cited by the fraud_monitoring policy.
Mastercard SPME §7.2
An Acquirer must monitor and confirm regularly that the Transaction activity of each of its Merchants (sales, credits, and chargebacks) is conducted in a legal and ethical manner and in full compliance with the Standards, and ensure that a Payment Facilitator conducts such monitoring with respect to each of its Sponsored Merchants, in an effort to deter fraud. Monitoring must focus on changes in activity over time, activity inconsistent with the Merchant’s or ¶ or Sponsored Merchant’s business, or exceptional activity relating to the number of Transactions and Transaction amounts outside the normal fluctuation related to seasonal sales. Specifically for Mastercard POS Transaction processing, ongoing monitoring includes, but is not limited to, the Acquirer fraud loss controls relating to deposit (including credits) and authorization activity described in section 6.2.2. With respect to an electronic commerce (e-commerce) Merchant, Submerchant, the Acquirer regularly, as reasonably appropriate in light of all circumstances, must review and monitor the Merchant’s website(s) and business activities to confirm and to reconfirm regularly that any activity related to or using a Mark is conducted in a legal and ethical manner and in full compliance with the Standards. The Acquirer must ensure that a Payment Facilitator conducts such monitoring with respect to each of its Sponsored Merchant’s website(s). As a best practice, Mastercard recommends that Acquirers use a Merchant monitoring solution to review their e-commerce Merchants’ and Sponsored Merchants’ activity to avoid processing illegal or brand-damaging Transactions. Merchant, Sponsored Merchant, and ATM Owner Screening and Monitoring Standards
Halyard Pay · 2 files
program: Fraud Monitoring
- authority: Mastercard SPME §3.7, §11.1.1
+ authority: Mastercard SPME §3.7, §6.2.2, §11.1.1, §7.2
fraud_to_sales_ratio_threshold: 0.015
min_count_per_month: 100
monitoring_cadence: monthly
escalation_actions:
- escalate_to_human_review
- notify_acquirer
lookback_period_months: 1
remediation_review_interval_days: 30
agent_owner: fraud_ops_agent
 
- # MATCH fraud detection features are limited to principal owners only; associate owners and Service Provider name reporting are removed per SPME §11.1.1.
- # Acquirers may add and search for information on up to five principal owners per Merchant.
- # Multiple data fields are used to determine matches; MATCH supports editing and error notification to reduce delays.
- # Retroactive alert processing is supported for data up to 360 days old.
- # Acquirers control receipt and detail of inquiry match information.
- # Real-time access via MATCH Online and API, and batch operations remain available.
- # Merchant URL information may be added and searched.
- # Crucially, after obtaining MATCH inquiry results, Acquirers must assess whether further investigation or risk mitigation actions are warranted, per updated SPME requirements.
+ # MATCH fraud detection features focus on principal owners only, excluding associate owners and Service Provider name reporting per SPME §11.1.1.
+ # Acquirers may add and search for up to five principal owners per Merchant.
+ # Multiple data fields enable precise matching; the system supports editing and error notifications to minimize delays.
+ # Retroactive alert processing allows consideration of data up to 360 days old.
+ # Acquirers control the receipt and detail of inquiry match information.
+ # Real-time access via MATCH Online, API, and batch operations remains available.
+ # Merchant URL information may be included and searched.
+ # Importantly, after obtaining MATCH inquiry results, Acquirers must evaluate whether further investigation or risk mitigation actions are necessary, per SPME.
+ #
+ # Per updated Mastercard SPME §7.2, ongoing monitoring mandates Acquirers to regularly review transaction activity for all Merchants, including sales, credits, and chargebacks, ensuring compliance with legal, ethical, and Standard requirements.
+ # This includes focusing on significant changes in transaction activity, inconsistency with the declared business, and atypical transaction counts or amounts outside expected seasonal variations.
+ # Additionally, monitoring explicitly encompasses fraud loss controls relevant to deposit (including credits) and authorization activity as detailed in SPME §6.2.2.
+ # For e-commerce Merchants, Acquirers must regularly review the Merchant’s website(s) and business activities to verify lawful and ethical conduct and compliance with the Standards.
+ # Acquirers are responsible for ensuring Payment Facilitators perform equivalent monitoring for their Sponsored Merchants.
+ # Mastercard recommends utilizing Merchant monitoring solutions to help identify illegal or brand-harming transactions effectively.

Fraud Monitoring

Halyard Pay monitors merchant fraud activity and leverages Mastercard's MATCH system for enhanced fraud risk assessment on merchants processed through our platform.

When this policy applies

This policy applies to all merchants processed by Halyard Pay where Mastercard is the applicable network, covering both card-present and card-not-present transactions. transactions, including e-commerce.

Required actions

  1. Compute the merchant's rolling fraud-to-sales ratio each calendar month.

  2. If the ratio meets or exceeds 1.5% and the fraud count reaches at least 100 transactions in that month, escalate the merchant account to human review immediately.

  3. Utilize Mastercard's MATCH system data focusing on principal owners only, as per the updated Mastercard SPME guidelines. Do not consider associate owners or Service Provider names in fraud assessments.

  4. Perform ongoing monitoring including review of merchant transaction activity for inconsistencies or unusual fluctuations over time, with attention to fraud loss controls on deposit and authorization activity as outlined in Mastercard SPME §6.2.2.

5. For e-commerce merchants, regularly review the merchant’s website and business activities to ensure all conduct complies with Mastercard Standards and is legal and ethical; ensure that Payment Facilitators perform equivalent monitoring for their Sponsored Merchants’ websites, aligning with Mastercard SPME §7.2 requirements.

6. After accessing MATCH data, data and ongoing activity monitoring, conduct a risk assessment to determine whether further investigation or additional measures are warranted.

5. 7. Notify the acquiring compliance officer and document the case ID with supporting transaction data.

6. 8. Track case progress until the account returns to threshold compliance or is terminated.

Source authority: Mastercard SPME §3.7 and §11.1.1.§§3.7, 6.2.2, 7.2, and 11.1.1.

policies/fraud_monitoring/policy.md — after applying change

Fraud Monitoring

Halyard Pay monitors merchant fraud activity and leverages Mastercard's MATCH system for enhanced fraud risk assessment on merchants processed through our platform.

When this policy applies

This policy applies to all merchants processed by Halyard Pay where Mastercard is the applicable network, covering both card-present and card-not-present transactions. transactions, including e-commerce.

Required actions

  1. Compute the merchant's rolling fraud-to-sales ratio each calendar month.

  2. If the ratio meets or exceeds 1.5% and the fraud count reaches at least 100 transactions in that month, escalate the merchant account to human review immediately.

  3. Utilize Mastercard's MATCH system data focusing on principal owners only, as per the updated Mastercard SPME guidelines. Do not consider associate owners or Service Provider names in fraud assessments.

  4. Perform ongoing monitoring including review of merchant transaction activity for inconsistencies or unusual fluctuations over time, with attention to fraud loss controls on deposit and authorization activity as outlined in Mastercard SPME §6.2.2.

5. For e-commerce merchants, regularly review the merchant’s website and business activities to ensure all conduct complies with Mastercard Standards and is legal and ethical; ensure that Payment Facilitators perform equivalent monitoring for their Sponsored Merchants’ websites, aligning with Mastercard SPME §7.2 requirements.

6. After accessing MATCH data, data and ongoing activity monitoring, conduct a risk assessment to determine whether further investigation or additional measures are warranted.

5. 7. Notify the acquiring compliance officer and document the case ID with supporting transaction data.

6. 8. Track case progress until the account returns to threshold compliance or is terminated.

Source authority: Mastercard SPME §3.7 and §11.1.1.§§3.7, 6.2.2, 7.2, and 11.1.1.

Source authority: Mastercard SPME §7.2.

--- a/policies/fraud_monitoring/rules.yaml
+++ b/policies/fraud_monitoring/rules.yaml
@@ -1,5 +1,5 @@
 program: Fraud Monitoring
-authority: Mastercard SPME §3.7, §11.1.1
+authority: Mastercard SPME §3.7, §6.2.2, §11.1.1, §7.2
 fraud_to_sales_ratio_threshold: 0.015
 min_count_per_month: 100
 monitoring_cadence: monthly
@@ -10,11 +10,18 @@
 remediation_review_interval_days: 30
 agent_owner: fraud_ops_agent
 
-# MATCH fraud detection features are limited to principal owners only; associate owners and Service Provider name reporting are removed per SPME §11.1.1.
-# Acquirers may add and search for information on up to five principal owners per Merchant.
-# Multiple data fields are used to determine matches; MATCH supports editing and error notification to reduce delays.
-# Retroactive alert processing is supported for data up to 360 days old.
-# Acquirers control receipt and detail of inquiry match information.
-# Real-time access via MATCH Online and API, and batch operations remain available.
-# Merchant URL information may be added and searched.
-# Crucially, after obtaining MATCH inquiry results, Acquirers must assess whether further investigation or risk mitigation actions are warranted, per updated SPME requirements.
+# MATCH fraud detection features focus on principal owners only, excluding associate owners and Service Provider name reporting per SPME §11.1.1.
+# Acquirers may add and search for up to five principal owners per Merchant.
+# Multiple data fields enable precise matching; the system supports editing and error notifications to minimize delays.
+# Retroactive alert processing allows consideration of data up to 360 days old.
+# Acquirers control the receipt and detail of inquiry match information.
+# Real-time access via MATCH Online, API, and batch operations remains available.
+# Merchant URL information may be included and searched.
+# Importantly, after obtaining MATCH inquiry results, Acquirers must evaluate whether further investigation or risk mitigation actions are necessary, per SPME.
+#
+# Per updated Mastercard SPME §7.2, ongoing monitoring mandates Acquirers to regularly review transaction activity for all Merchants, including sales, credits, and chargebacks, ensuring compliance with legal, ethical, and Standard requirements.
+# This includes focusing on significant changes in transaction activity, inconsistency with the declared business, and atypical transaction counts or amounts outside expected seasonal variations.
+# Additionally, monitoring explicitly encompasses fraud loss controls relevant to deposit (including credits) and authorization activity as detailed in SPME §6.2.2.
+# For e-commerce Merchants, Acquirers must regularly review the Merchant’s website(s) and business activities to verify lawful and ethical conduct and compliance with the Standards.
+# Acquirers are responsible for ensuring Payment Facilitators perform equivalent monitoring for their Sponsored Merchants.
+# Mastercard recommends utilizing Merchant monitoring solutions to help identify illegal or brand-harming transactions effectively.

--- a/policies/fraud_monitoring/policy.md
+++ b/policies/fraud_monitoring/policy.md
@@ -4,15 +4,17 @@
 
 ## When this policy applies
 
-This policy applies to all merchants processed by Halyard Pay where Mastercard is the applicable network, covering both card-present and card-not-present transactions.
+This policy applies to all merchants processed by Halyard Pay where Mastercard is the applicable network, covering both card-present and card-not-present transactions, including e-commerce.
 
 ## Required actions
 
 1. Compute the merchant's rolling fraud-to-sales ratio each calendar month.
 2. If the ratio meets or exceeds 1.5% and the fraud count reaches at least 100 transactions in that month, escalate the merchant account to human review immediately.
 3. Utilize Mastercard's MATCH system data focusing on principal owners only, as per the updated Mastercard SPME guidelines. Do not consider associate owners or Service Provider names in fraud assessments.
-4. After accessing MATCH data, conduct a risk assessment to determine whether further investigation or additional measures are warranted.
-5. Notify the acquiring compliance officer and document the case ID with supporting transaction data.
-6. Track case progress until the account returns to threshold compliance or is terminated.
+4. Perform ongoing monitoring including review of merchant transaction activity for inconsistencies or unusual fluctuations over time, with attention to fraud loss controls on deposit and authorization activity as outlined in Mastercard SPME §6.2.2.
+5. For e-commerce merchants, regularly review the merchant’s website and business activities to ensure all conduct complies with Mastercard Standards and is legal and ethical; ensure that Payment Facilitators perform equivalent monitoring for their Sponsored Merchants’ websites, aligning with Mastercard SPME §7.2 requirements.
+6. After accessing MATCH data and ongoing activity monitoring, conduct a risk assessment to determine whether further investigation or additional measures are warranted.
+7. Notify the acquiring compliance officer and document the case ID with supporting transaction data.
+8. Track case progress until the account returns to threshold compliance or is terminated.
 
-Source authority: Mastercard SPME §3.7 and §11.1.1.
+Source authority: Mastercard SPME §§3.7, 6.2.2, 7.2, and 11.1.1.