Mastercard SPME §8.4.4 · May 2023 → Sep 2023
Mastercard Notification to Acquirers
Mastercard will notify Acquirers by email if a Merchant meets criteria as a Questionable Merchant based on fraud reports. Acquirers have 15 days to contest and must provide supplemental information. Mastercard may audit Acquirer records and request additional information. Documentation must be submitted via a specified email.
Security Rules and Procedures—Merchant Edition • 7 February 2023
Following the Mastercard evaluation of Transactions reported to the Fraud and Loss Database by Issuers, Mastercard will notify any Acquirer of the investigated Merchant that such Merchant has initially met the criteria of a Questionable Merchant. Such notification will be sent by email message to the Security Contact then listed for the Acquirer in the Company Contact Management application available on Mastercard Connect®. Within 15 calendar days from the date of the Mastercard notification, the Acquirer may contest the Mastercard preliminary finding that a Merchant is a Questionable Merchant. In such an event, the Acquirer shall provide to Mastercard any supplemental information necessary to review the preliminary finding. Mastercard has a right, but not an obligation, to audit an Acquirer’s records for the purpose of attempting to determine whether a Merchant is a Questionable Merchant. An Acquirer must provide Mastercard such other or additional information as Mastercard may request to assist in the investigation. The Acquirer must submit all documentation and records by email message to qmap@mastercard.com.
program: Fraud Monitoring- authority: Mastercard SPME §3.7, §11.1.1+ authority: Mastercard SPME §3.7, §8.4.4, §11.1.1fraud_to_sales_ratio_threshold: 0.015min_count_per_month: 100monitoring_cadence: monthlyescalation_actions:- escalate_to_human_review- notify_acquirerlookback_period_months: 1remediation_review_interval_days: 30agent_owner: fraud_ops_agent# MATCH fraud detection features are limited to principal owners only; associate owners and Service Provider name reporting are removed per SPME §11.1.1.# Acquirers may add and search for information on up to five principal owners per Merchant.# Multiple data fields are used to determine matches; MATCH supports editing and error notification to reduce delays.# Retroactive alert processing is supported for data up to 360 days old.# Acquirers control receipt and detail of inquiry match information.# Real-time access via MATCH Online and API, and batch operations remain available.# Merchant URL information may be added and searched.- # Crucially, after obtaining MATCH inquiry results, Acquirers must assess whether further investigation or risk mitigation actions are warranted, per updated SPME requirements.+ # Per updated SPME §8.4.4, Mastercard notifies Acquirers by email about Merchants preliminarily identified as Questionable Merchants.+ # Acquirers have 15 calendar days to contest findings, submitting supplemental information to Mastercard via designated email.+ # Acquirers must cooperate with Mastercard audits and requests for additional documentation during investigations.+ # Accordingly, fraud monitoring processes and communication protocols are enhanced to support timely response and compliance with notification and contest procedures.
Fraud Monitoring
Halyard Pay monitors merchant fraud activity and leverages Mastercard's MATCH system for enhanced fraud risk assessment on merchants processed through our platform.
When this policy applies
This policy applies to all merchants processed by Halyard Pay where Mastercard is the applicable network, covering both card-present and card-not-present transactions.
Required actions
-
Compute the merchant's rolling fraud-to-sales ratio each calendar month.
-
If the ratio meets or exceeds 1.5% and the fraud count reaches at least 100 transactions in that month, escalate the merchant account to human review immediately.
-
Utilize Mastercard's MATCH system data focusing on principal owners only, as per the updated Mastercard SPME guidelines. Do not consider associate owners or Service Provider names in fraud assessments.
-
After accessing MATCH data, conduct a risk assessment to determine whether further investigation or additional measures are warranted.
-
Implement a process to acknowledge and respond to Mastercard notifications that a merchant has been preliminarily identified as Questionable, as per SPME §8.4.4. This includes monitoring email communications sent to the Acquirer's Security Contact and preparing any supplemental information for contest submissions within the required 15 calendar-day period.
6. Notify the acquiring compliance officer and document the case ID with supporting transaction data.
6. 7. Track case progress until the account returns to threshold compliance or is terminated.
Source authority: Mastercard SPME §3.7 §3.7, §8.4.4, and §11.1.1.
Fraud Monitoring
Halyard Pay monitors merchant fraud activity and leverages Mastercard's MATCH system for enhanced fraud risk assessment on merchants processed through our platform.
When this policy applies
This policy applies to all merchants processed by Halyard Pay where Mastercard is the applicable network, covering both card-present and card-not-present transactions.
Required actions
-
Compute the merchant's rolling fraud-to-sales ratio each calendar month.
-
If the ratio meets or exceeds 1.5% and the fraud count reaches at least 100 transactions in that month, escalate the merchant account to human review immediately.
-
Utilize Mastercard's MATCH system data focusing on principal owners only, as per the updated Mastercard SPME guidelines. Do not consider associate owners or Service Provider names in fraud assessments.
-
After accessing MATCH data, conduct a risk assessment to determine whether further investigation or additional measures are warranted.
-
Implement a process to acknowledge and respond to Mastercard notifications that a merchant has been preliminarily identified as Questionable, as per SPME §8.4.4. This includes monitoring email communications sent to the Acquirer's Security Contact and preparing any supplemental information for contest submissions within the required 15 calendar-day period.
6. Notify the acquiring compliance officer and document the case ID with supporting transaction data.
6. 7. Track case progress until the account returns to threshold compliance or is terminated.
Source authority: Mastercard SPME §3.7 §3.7, §8.4.4, and §11.1.1.
Source authority: Mastercard SPME §8.4.4.
--- a/policies/fraud_monitoring/rules.yaml +++ b/policies/fraud_monitoring/rules.yaml @@ -1,5 +1,5 @@ program: Fraud Monitoring -authority: Mastercard SPME §3.7, §11.1.1 +authority: Mastercard SPME §3.7, §8.4.4, §11.1.1 fraud_to_sales_ratio_threshold: 0.015 min_count_per_month: 100 monitoring_cadence: monthly @@ -17,4 +17,7 @@ # Acquirers control receipt and detail of inquiry match information. # Real-time access via MATCH Online and API, and batch operations remain available. # Merchant URL information may be added and searched. -# Crucially, after obtaining MATCH inquiry results, Acquirers must assess whether further investigation or risk mitigation actions are warranted, per updated SPME requirements. +# Per updated SPME §8.4.4, Mastercard notifies Acquirers by email about Merchants preliminarily identified as Questionable Merchants. +# Acquirers have 15 calendar days to contest findings, submitting supplemental information to Mastercard via designated email. +# Acquirers must cooperate with Mastercard audits and requests for additional documentation during investigations. +# Accordingly, fraud monitoring processes and communication protocols are enhanced to support timely response and compliance with notification and contest procedures. --- a/policies/fraud_monitoring/policy.md +++ b/policies/fraud_monitoring/policy.md @@ -12,7 +12,8 @@ 2. If the ratio meets or exceeds 1.5% and the fraud count reaches at least 100 transactions in that month, escalate the merchant account to human review immediately. 3. Utilize Mastercard's MATCH system data focusing on principal owners only, as per the updated Mastercard SPME guidelines. Do not consider associate owners or Service Provider names in fraud assessments. 4. After accessing MATCH data, conduct a risk assessment to determine whether further investigation or additional measures are warranted. -5. Notify the acquiring compliance officer and document the case ID with supporting transaction data. -6. Track case progress until the account returns to threshold compliance or is terminated. +5. Implement a process to acknowledge and respond to Mastercard notifications that a merchant has been preliminarily identified as Questionable, as per SPME §8.4.4. This includes monitoring email communications sent to the Acquirer's Security Contact and preparing any supplemental information for contest submissions within the required 15 calendar-day period. +6. Notify the acquiring compliance officer and document the case ID with supporting transaction data. +7. Track case progress until the account returns to threshold compliance or is terminated. -Source authority: Mastercard SPME §3.7 and §11.1.1. +Source authority: Mastercard SPME §3.7, §8.4.4, and §11.1.1.