Mastercard SPME §8.4.1 · May 2023 → Sep 2023

QMAP Definitions

substantive

The section changed from describing general criteria for identifying a Questionable Merchant to providing detailed definitions of 'Cardholder bust-out account' including specific conditions and indicators linking accounts to potential fraud and merchant investigation triggers.

Sources Mastercard SPME · May 2023 · page 84 PDF Mastercard SPME · Sep 2023 · page 79 PDF Fraud Monitoring current
Also in §8.x this release breaking §8.6.7 Franchise Management Program (FMP) Questionnaire-based Review substantive §8.3.4 Additional ECM and HECM Requirements substantive §8.4 Questionable Merchant Audit Program (QMAP) substantive §8.4.2 Mastercard Commencement of an Investigation substantive §8.4.4 Mastercard Notification to Acquirers substantive §8.4.6 Mastercard Determination substantive §8.4.7 Chargeback Responsibility substantive §8.6.2 Investigation Process substantive §8.6.6 MATCH Reporting substantive §8.7.3 Mastercard Notification to Acquirers substantive §8.7.4 Mastercard Determination substantive §8.7.5 Assessments, Recovery Amounts, and Fees
Why these edits? The updated detailed definitions of 'Cardholder bust-out account' with specific indicators require enhanced fraud monitoring to detect accounts linked to potential fraud and suspicious merchant activity.
Mastercard SPME §8.4.1
This section was substantively restructured between versions (2% text overlap). Compare the texts directly below.
Before · May 2023 · page 84

Security Rules and Procedures—Merchant Edition • 7 February 2023

d. The Merchant’s total number or total dollar amount of fraudulent Transactions, authorization declines, and Issuer referrals was greater than the Merchant’s total number or total dollar amount of approved Transactions. NOTE: Transaction activity (“on-us” or otherwise) that is not processed through Mastercard systems is not considered in determining whether a Merchant meets the criteria of a Questionable Merchant. Mastercard has sole discretion, based on information from any source, to determine whether a Merchant meeting these criteria is a Questionable Merchant.

After · Sep 2023 · page 79

For purposes of the QMAP, the following terms have the meanings set forth below: Cardholder bust-out account means an account for which all of the following conditions are true:

  1. The Issuer closed the account prior to the earlier of (i) the Issuer requesting that Mastercard commence an investigation as to whether a Merchant is a Questionable Merchant, or (ii) Mastercard notifying the Issuer that Mastercard has commenced an investigation as to whether a Merchant is a Questionable Merchant; and
  2. A Transaction arising from use of the account has not been charged back for either an authorization-related chargeback (as set forth in Chapter 2 of the Chargeback Guide) or fraud-related chargeback (as set forth in Chapter 2 of the Chargeback Guide) during the 180 days prior to the earlier of (i) the Issuer requesting that Mastercard commence an investigation as to whether a Merchant is a Questionable Merchant, or (ii) Mastercard notifying the Issuer that Mastercard has commenced an investigation as to whether a Merchant is a Questionable Merchant; and
  3. At least one of the following is true:
    1. The account in question is “linked” to one or more Cardholder bust-out accounts. As used herein, to be “linked” means that personal, non-public information previously provided by an applicant in connection with the establishment of one or more Cardholder bust-out accounts (name, address, telephone number, social security number or other governmentissued identification number, authorized user, demand deposit account number, and the like) has been provided by an applicant in connection with the establishment of the subject account; or
    2. The account is linked to one or more Cardholder bust-out accounts used in Transactions with a Merchant that Mastercard identified as a Questionable Merchant in a Mastercard Announcement (AN) available on the Technical Resource Center on Mastercard Connect®; or
    3. The Cardholder requests that one or more additional persons be designated as an additional Cardholder of the account within a short period of time; or
    4. The Cardholder requests that the credit limit of the account be increased soon after the account is opened; or
    5. The Cardholder makes frequent balance queries or “open-to-buy” queries; or Mastercard Fraud Control Programs
Halyard Pay · 2 files
program: Fraud Monitoring
- authority: Mastercard SPME §3.7, §11.1.1
+ authority: Mastercard SPME §3.7, §8.4.1, §11.1.1
fraud_to_sales_ratio_threshold: 0.015
min_count_per_month: 100
monitoring_cadence: monthly
escalation_actions:
- escalate_to_human_review
- notify_acquirer
lookback_period_months: 1
remediation_review_interval_days: 30
agent_owner: fraud_ops_agent
 
- # MATCH fraud detection features are limited to principal owners only; associate owners and Service Provider name reporting are removed per SPME §11.1.1.
+ # MATCH fraud detection features remain focused on principal owners only, per SPME §11.1.1.
# Acquirers may add and search for information on up to five principal owners per Merchant.
- # Multiple data fields are used to determine matches; MATCH supports editing and error notification to reduce delays.
+ # Multiple data fields determine matches; MATCH supports editing and error notifications to reduce delays.
# Retroactive alert processing is supported for data up to 360 days old.
- # Acquirers control receipt and detail of inquiry match information.
+ # Acquirers control receipt and details of inquiry match information.
# Real-time access via MATCH Online and API, and batch operations remain available.
# Merchant URL information may be added and searched.
- # Crucially, after obtaining MATCH inquiry results, Acquirers must assess whether further investigation or risk mitigation actions are warranted, per updated SPME requirements.
+ # Importantly, fraud monitoring now incorporates detection and review of Cardholder bust-out accounts and suspicious activity patterns as defined in Mastercard SPME §8.4.1.
+ # These accounts are characterized by specific risk indicators such as linkage to previously identified bust-out accounts and unusual account activities.
+ # Monitoring processes must include these enhanced criteria to align with updated Mastercard definitions of Questionable Merchants and associated fraud risks.
+ # After obtaining MATCH inquiry results and analyzing bust-out account indicators, Acquirers must assess whether further investigation or risk mitigation actions are warranted as per Mastercard requirements.

Fraud Monitoring

Halyard Pay monitors merchant fraud activity and leverages uses Mastercard's MATCH system for enhanced to enhance fraud risk assessment on for merchants processed through via our platform.

When this policy applies

This policy applies to all merchants processed by Halyard Pay where Mastercard is the applicable network, covering both card-present and card-not-present transactions.

Required actions

  1. Compute the merchant's rolling monthly fraud-to-sales ratio each calendar month. ratio.

  2. If the ratio meets is 1.5% or exceeds 1.5% and the fraud higher and fraud transactions count reaches at least 100 transactions in that month, escalate the merchant account to human for manual review immediately.

  3. Utilize Mastercard's Use Mastercard MATCH system data focusing on principal owners only, as per the updated Mastercard SPME guidelines. Do not consider guidance, excluding associate owners or and Service Provider names in fraud assessments. Providers.

  4. After accessing MATCH data, conduct Expand fraud analysis to include monitoring for indicators of Cardholder bust-out accounts linked to the merchant. Key signs include account linkage to known bust-out accounts, rapid credit limit increases, multiple authorized users shortly after account opening, and frequent balance queries.

5. Conduct a risk assessment based on MATCH and bust-out indicators to determine whether need for further investigation or additional measures are warranted. ¶ 5. corrective action.

6. Notify the acquiring compliance officer and document the all relevant case ID with supporting transaction data. ¶ 6. details.

7. Track case progress and follow up until the account merchant returns to threshold compliance acceptable fraud thresholds or is terminated. discontinuance.

Source authority: Mastercard SPME §3.7 §3.7, §8.4.1, and §11.1.1.

policies/fraud_monitoring/policy.md — after applying change

Fraud Monitoring

Halyard Pay monitors merchant fraud activity and leverages uses Mastercard's MATCH system for enhanced to enhance fraud risk assessment on for merchants processed through via our platform.

When this policy applies

This policy applies to all merchants processed by Halyard Pay where Mastercard is the applicable network, covering both card-present and card-not-present transactions.

Required actions

  1. Compute the merchant's rolling monthly fraud-to-sales ratio each calendar month. ratio.

  2. If the ratio meets is 1.5% or exceeds 1.5% and the fraud higher and fraud transactions count reaches at least 100 transactions in that month, escalate the merchant account to human for manual review immediately.

  3. Utilize Mastercard's Use Mastercard MATCH system data focusing on principal owners only, as per the updated Mastercard SPME guidelines. Do not consider guidance, excluding associate owners or and Service Provider names in fraud assessments. Providers.

  4. After accessing MATCH data, conduct Expand fraud analysis to include monitoring for indicators of Cardholder bust-out accounts linked to the merchant. Key signs include account linkage to known bust-out accounts, rapid credit limit increases, multiple authorized users shortly after account opening, and frequent balance queries.

5. Conduct a risk assessment based on MATCH and bust-out indicators to determine whether need for further investigation or additional measures are warranted. ¶ 5. corrective action.

6. Notify the acquiring compliance officer and document the all relevant case ID with supporting transaction data. ¶ 6. details.

7. Track case progress and follow up until the account merchant returns to threshold compliance acceptable fraud thresholds or is terminated. discontinuance.

Source authority: Mastercard SPME §3.7 §3.7, §8.4.1, and §11.1.1.

Source authority: Mastercard SPME §8.4.1.

--- a/policies/fraud_monitoring/rules.yaml
+++ b/policies/fraud_monitoring/rules.yaml
@@ -1,5 +1,5 @@
 program: Fraud Monitoring
-authority: Mastercard SPME §3.7, §11.1.1
+authority: Mastercard SPME §3.7, §8.4.1, §11.1.1
 fraud_to_sales_ratio_threshold: 0.015
 min_count_per_month: 100
 monitoring_cadence: monthly
@@ -10,11 +10,14 @@
 remediation_review_interval_days: 30
 agent_owner: fraud_ops_agent
 
-# MATCH fraud detection features are limited to principal owners only; associate owners and Service Provider name reporting are removed per SPME §11.1.1.
+# MATCH fraud detection features remain focused on principal owners only, per SPME §11.1.1.
 # Acquirers may add and search for information on up to five principal owners per Merchant.
-# Multiple data fields are used to determine matches; MATCH supports editing and error notification to reduce delays.
+# Multiple data fields determine matches; MATCH supports editing and error notifications to reduce delays.
 # Retroactive alert processing is supported for data up to 360 days old.
-# Acquirers control receipt and detail of inquiry match information.
+# Acquirers control receipt and details of inquiry match information.
 # Real-time access via MATCH Online and API, and batch operations remain available.
 # Merchant URL information may be added and searched.
-# Crucially, after obtaining MATCH inquiry results, Acquirers must assess whether further investigation or risk mitigation actions are warranted, per updated SPME requirements.
+# Importantly, fraud monitoring now incorporates detection and review of Cardholder bust-out accounts and suspicious activity patterns as defined in Mastercard SPME §8.4.1.
+# These accounts are characterized by specific risk indicators such as linkage to previously identified bust-out accounts and unusual account activities.
+# Monitoring processes must include these enhanced criteria to align with updated Mastercard definitions of Questionable Merchants and associated fraud risks.
+# After obtaining MATCH inquiry results and analyzing bust-out account indicators, Acquirers must assess whether further investigation or risk mitigation actions are warranted as per Mastercard requirements.
--- a/policies/fraud_monitoring/policy.md
+++ b/policies/fraud_monitoring/policy.md
@@ -1,18 +1,19 @@
 # Fraud Monitoring
 
-Halyard Pay monitors merchant fraud activity and leverages Mastercard's MATCH system for enhanced fraud risk assessment on merchants processed through our platform.
+Halyard Pay monitors merchant fraud activity and uses Mastercard's MATCH system to enhance fraud risk assessment for merchants processed via our platform.
 
 ## When this policy applies
 
-This policy applies to all merchants processed by Halyard Pay where Mastercard is the applicable network, covering both card-present and card-not-present transactions.
+This policy applies to all merchants processed by Halyard Pay where Mastercard is the network, covering both card-present and card-not-present transactions.
 
 ## Required actions
 
-1. Compute the merchant's rolling fraud-to-sales ratio each calendar month.
-2. If the ratio meets or exceeds 1.5% and the fraud count reaches at least 100 transactions in that month, escalate the merchant account to human review immediately.
-3. Utilize Mastercard's MATCH system data focusing on principal owners only, as per the updated Mastercard SPME guidelines. Do not consider associate owners or Service Provider names in fraud assessments.
-4. After accessing MATCH data, conduct a risk assessment to determine whether further investigation or additional measures are warranted.
-5. Notify the acquiring compliance officer and document the case ID with supporting transaction data.
-6. Track case progress until the account returns to threshold compliance or is terminated.
+1. Compute the merchant's monthly fraud-to-sales ratio.
+2. If the ratio is 1.5% or higher and fraud transactions count at least 100 in that month, escalate the merchant account for manual review immediately.
+3. Use Mastercard MATCH data focusing on principal owners only, per Mastercard SPME guidance, excluding associate owners and Service Providers.
+4. Expand fraud analysis to include monitoring for indicators of Cardholder bust-out accounts linked to the merchant. Key signs include account linkage to known bust-out accounts, rapid credit limit increases, multiple authorized users shortly after account opening, and frequent balance queries.
+5. Conduct a risk assessment based on MATCH and bust-out indicators to determine need for further investigation or corrective action.
+6. Notify the acquiring compliance officer and document all relevant case details.
+7. Track and follow up until the merchant returns to acceptable fraud thresholds or discontinuance.
 
-Source authority: Mastercard SPME §3.7 and §11.1.1.
+Source authority: Mastercard SPME §3.7, §8.4.1, and §11.1.1.