Mastercard SPME §8.4.1 · May 2023 → Sep 2023
QMAP Definitions
The section changed from describing general criteria for identifying a Questionable Merchant to providing detailed definitions of 'Cardholder bust-out account' including specific conditions and indicators linking accounts to potential fraud and merchant investigation triggers.
Security Rules and Procedures—Merchant Edition • 7 February 2023
d. The Merchant’s total number or total dollar amount of fraudulent Transactions, authorization declines, and Issuer referrals was greater than the Merchant’s total number or total dollar amount of approved Transactions. NOTE: Transaction activity (“on-us” or otherwise) that is not processed through Mastercard systems is not considered in determining whether a Merchant meets the criteria of a Questionable Merchant. Mastercard has sole discretion, based on information from any source, to determine whether a Merchant meeting these criteria is a Questionable Merchant.
For purposes of the QMAP, the following terms have the meanings set forth below: Cardholder bust-out account means an account for which all of the following conditions are true:
- The Issuer closed the account prior to the earlier of (i) the Issuer requesting that Mastercard commence an investigation as to whether a Merchant is a Questionable Merchant, or (ii) Mastercard notifying the Issuer that Mastercard has commenced an investigation as to whether a Merchant is a Questionable Merchant; and
- A Transaction arising from use of the account has not been charged back for either an authorization-related chargeback (as set forth in Chapter 2 of the Chargeback Guide) or fraud-related chargeback (as set forth in Chapter 2 of the Chargeback Guide) during the 180 days prior to the earlier of (i) the Issuer requesting that Mastercard commence an investigation as to whether a Merchant is a Questionable Merchant, or (ii) Mastercard notifying the Issuer that Mastercard has commenced an investigation as to whether a Merchant is a Questionable Merchant; and
- At least one of the following is true:
- The account in question is “linked” to one or more Cardholder bust-out accounts. As used herein, to be “linked” means that personal, non-public information previously provided by an applicant in connection with the establishment of one or more Cardholder bust-out accounts (name, address, telephone number, social security number or other governmentissued identification number, authorized user, demand deposit account number, and the like) has been provided by an applicant in connection with the establishment of the subject account; or
- The account is linked to one or more Cardholder bust-out accounts used in Transactions with a Merchant that Mastercard identified as a Questionable Merchant in a Mastercard Announcement (AN) available on the Technical Resource Center on Mastercard Connect®; or
- The Cardholder requests that one or more additional persons be designated as an additional Cardholder of the account within a short period of time; or
- The Cardholder requests that the credit limit of the account be increased soon after the account is opened; or
- The Cardholder makes frequent balance queries or “open-to-buy” queries; or Mastercard Fraud Control Programs
program: Fraud Monitoring- authority: Mastercard SPME §3.7, §11.1.1+ authority: Mastercard SPME §3.7, §8.4.1, §11.1.1fraud_to_sales_ratio_threshold: 0.015min_count_per_month: 100monitoring_cadence: monthlyescalation_actions:- escalate_to_human_review- notify_acquirerlookback_period_months: 1remediation_review_interval_days: 30agent_owner: fraud_ops_agent- # MATCH fraud detection features are limited to principal owners only; associate owners and Service Provider name reporting are removed per SPME §11.1.1.+ # MATCH fraud detection features remain focused on principal owners only, per SPME §11.1.1.# Acquirers may add and search for information on up to five principal owners per Merchant.- # Multiple data fields are used to determine matches; MATCH supports editing and error notification to reduce delays.+ # Multiple data fields determine matches; MATCH supports editing and error notifications to reduce delays.# Retroactive alert processing is supported for data up to 360 days old.- # Acquirers control receipt and detail of inquiry match information.+ # Acquirers control receipt and details of inquiry match information.# Real-time access via MATCH Online and API, and batch operations remain available.# Merchant URL information may be added and searched.- # Crucially, after obtaining MATCH inquiry results, Acquirers must assess whether further investigation or risk mitigation actions are warranted, per updated SPME requirements.+ # Importantly, fraud monitoring now incorporates detection and review of Cardholder bust-out accounts and suspicious activity patterns as defined in Mastercard SPME §8.4.1.+ # These accounts are characterized by specific risk indicators such as linkage to previously identified bust-out accounts and unusual account activities.+ # Monitoring processes must include these enhanced criteria to align with updated Mastercard definitions of Questionable Merchants and associated fraud risks.+ # After obtaining MATCH inquiry results and analyzing bust-out account indicators, Acquirers must assess whether further investigation or risk mitigation actions are warranted as per Mastercard requirements.
Fraud Monitoring
Halyard Pay monitors merchant fraud activity and leverages uses Mastercard's MATCH system for enhanced to enhance fraud risk assessment on for merchants processed through via our platform.
When this policy applies
This policy applies to all merchants processed by Halyard Pay where Mastercard is the applicable network, covering both card-present and card-not-present transactions.
Required actions
-
Compute the merchant's
rollingmonthly fraud-to-salesratio each calendar month.ratio. -
If the ratio
meetsis 1.5% orexceeds 1.5% and the fraudhigher and fraud transactions countreachesat least 100transactionsin that month, escalate the merchant accountto humanfor manual review immediately. -
Utilize Mastercard'sUse Mastercard MATCHsystemdata focusing on principal owners only,asperthe updatedMastercard SPMEguidelines. Do not considerguidance, excluding associate ownersorand ServiceProvider names in fraud assessments.Providers. -
After accessing MATCH data, conductExpand fraud analysis to include monitoring for indicators of Cardholder bust-out accounts linked to the merchant. Key signs include account linkage to known bust-out accounts, rapid credit limit increases, multiple authorized users shortly after account opening, and frequent balance queries.
5. Conduct a risk assessment based on MATCH and bust-out indicators to determine whether need for further investigation or additional measures are warranted. ¶ 5. corrective action.
6. Notify the acquiring compliance officer and document the all relevant case ID with supporting transaction data. ¶ 6. details.
7. Track case progress and follow up until the account merchant returns to threshold compliance acceptable fraud thresholds or is terminated. discontinuance.
Source authority: Mastercard SPME §3.7 §3.7, §8.4.1, and §11.1.1.
Fraud Monitoring
Halyard Pay monitors merchant fraud activity and leverages uses Mastercard's MATCH system for enhanced to enhance fraud risk assessment on for merchants processed through via our platform.
When this policy applies
This policy applies to all merchants processed by Halyard Pay where Mastercard is the applicable network, covering both card-present and card-not-present transactions.
Required actions
-
Compute the merchant's
rollingmonthly fraud-to-salesratio each calendar month.ratio. -
If the ratio
meetsis 1.5% orexceeds 1.5% and the fraudhigher and fraud transactions countreachesat least 100transactionsin that month, escalate the merchant accountto humanfor manual review immediately. -
Utilize Mastercard'sUse Mastercard MATCHsystemdata focusing on principal owners only,asperthe updatedMastercard SPMEguidelines. Do not considerguidance, excluding associate ownersorand ServiceProvider names in fraud assessments.Providers. -
After accessing MATCH data, conductExpand fraud analysis to include monitoring for indicators of Cardholder bust-out accounts linked to the merchant. Key signs include account linkage to known bust-out accounts, rapid credit limit increases, multiple authorized users shortly after account opening, and frequent balance queries.
5. Conduct a risk assessment based on MATCH and bust-out indicators to determine whether need for further investigation or additional measures are warranted. ¶ 5. corrective action.
6. Notify the acquiring compliance officer and document the all relevant case ID with supporting transaction data. ¶ 6. details.
7. Track case progress and follow up until the account merchant returns to threshold compliance acceptable fraud thresholds or is terminated. discontinuance.
Source authority: Mastercard SPME §3.7 §3.7, §8.4.1, and §11.1.1.
Source authority: Mastercard SPME §8.4.1.
--- a/policies/fraud_monitoring/rules.yaml +++ b/policies/fraud_monitoring/rules.yaml @@ -1,5 +1,5 @@ program: Fraud Monitoring -authority: Mastercard SPME §3.7, §11.1.1 +authority: Mastercard SPME §3.7, §8.4.1, §11.1.1 fraud_to_sales_ratio_threshold: 0.015 min_count_per_month: 100 monitoring_cadence: monthly @@ -10,11 +10,14 @@ remediation_review_interval_days: 30 agent_owner: fraud_ops_agent -# MATCH fraud detection features are limited to principal owners only; associate owners and Service Provider name reporting are removed per SPME §11.1.1. +# MATCH fraud detection features remain focused on principal owners only, per SPME §11.1.1. # Acquirers may add and search for information on up to five principal owners per Merchant. -# Multiple data fields are used to determine matches; MATCH supports editing and error notification to reduce delays. +# Multiple data fields determine matches; MATCH supports editing and error notifications to reduce delays. # Retroactive alert processing is supported for data up to 360 days old. -# Acquirers control receipt and detail of inquiry match information. +# Acquirers control receipt and details of inquiry match information. # Real-time access via MATCH Online and API, and batch operations remain available. # Merchant URL information may be added and searched. -# Crucially, after obtaining MATCH inquiry results, Acquirers must assess whether further investigation or risk mitigation actions are warranted, per updated SPME requirements. +# Importantly, fraud monitoring now incorporates detection and review of Cardholder bust-out accounts and suspicious activity patterns as defined in Mastercard SPME §8.4.1. +# These accounts are characterized by specific risk indicators such as linkage to previously identified bust-out accounts and unusual account activities. +# Monitoring processes must include these enhanced criteria to align with updated Mastercard definitions of Questionable Merchants and associated fraud risks. +# After obtaining MATCH inquiry results and analyzing bust-out account indicators, Acquirers must assess whether further investigation or risk mitigation actions are warranted as per Mastercard requirements. --- a/policies/fraud_monitoring/policy.md +++ b/policies/fraud_monitoring/policy.md @@ -1,18 +1,19 @@ # Fraud Monitoring -Halyard Pay monitors merchant fraud activity and leverages Mastercard's MATCH system for enhanced fraud risk assessment on merchants processed through our platform. +Halyard Pay monitors merchant fraud activity and uses Mastercard's MATCH system to enhance fraud risk assessment for merchants processed via our platform. ## When this policy applies -This policy applies to all merchants processed by Halyard Pay where Mastercard is the applicable network, covering both card-present and card-not-present transactions. +This policy applies to all merchants processed by Halyard Pay where Mastercard is the network, covering both card-present and card-not-present transactions. ## Required actions -1. Compute the merchant's rolling fraud-to-sales ratio each calendar month. -2. If the ratio meets or exceeds 1.5% and the fraud count reaches at least 100 transactions in that month, escalate the merchant account to human review immediately. -3. Utilize Mastercard's MATCH system data focusing on principal owners only, as per the updated Mastercard SPME guidelines. Do not consider associate owners or Service Provider names in fraud assessments. -4. After accessing MATCH data, conduct a risk assessment to determine whether further investigation or additional measures are warranted. -5. Notify the acquiring compliance officer and document the case ID with supporting transaction data. -6. Track case progress until the account returns to threshold compliance or is terminated. +1. Compute the merchant's monthly fraud-to-sales ratio. +2. If the ratio is 1.5% or higher and fraud transactions count at least 100 in that month, escalate the merchant account for manual review immediately. +3. Use Mastercard MATCH data focusing on principal owners only, per Mastercard SPME guidance, excluding associate owners and Service Providers. +4. Expand fraud analysis to include monitoring for indicators of Cardholder bust-out accounts linked to the merchant. Key signs include account linkage to known bust-out accounts, rapid credit limit increases, multiple authorized users shortly after account opening, and frequent balance queries. +5. Conduct a risk assessment based on MATCH and bust-out indicators to determine need for further investigation or corrective action. +6. Notify the acquiring compliance officer and document all relevant case details. +7. Track and follow up until the merchant returns to acceptable fraud thresholds or discontinuance. -Source authority: Mastercard SPME §3.7 and §11.1.1. +Source authority: Mastercard SPME §3.7, §8.4.1, and §11.1.1.