Mastercard SPME §8.4 · May 2023 → Sep 2023
Questionable Merchant Audit Program (QMAP)
The updated QMAP section replaces the previous general description with specific, detailed criteria to identify a Questionable Merchant, including transaction volume thresholds, number of transactions, and detailed fraud metrics. It defines the Case Scope Period and clarifies Mastercard's sole discretion in designating a merchant as questionable.
The Questionable Merchant Audit Program (QMAP) establishes minimum standards of acceptable Merchant behavior and identifies Merchants that may fail to meet such minimum standards by participating in collusive or otherwise fraudulent or inappropriate activity. The QMAP also permits an Issuer to obtain partial recovery of up to one-half of actual fraud losses, which total at least USD 2,000 in volume during the Case Scope Period resulting from fraudulent Transactions at a Questionable Merchant, based on Fraud and Loss Database reporting. The criteria to identify a Questionable Merchant and the fraud recovery process are described below.
Security Rules and Procedures—Merchant Edition • 1 August 2023
- No payment has been made of charges to the account; or
- The Issuer closed the account after a failed payment (dishonored check or the like) of charges to the account. Case Scope Period means the 120-calendar-day period preceding the date on which Mastercard commences an investigation into the activities of a suspected Questionable Merchant. Questionable Merchant means a Merchant that satisfies all of the following criteria:
- The Merchant submitted at least USD 50,000 in Transaction volume during the Case Scope Period;
- The Merchant submitted at least five (5) Transactions to one or more Acquirers during the Case Scope Period; and
- At least fifty (50) percent of the Merchant’s total Transaction volume involved the use of Cardholder bust-out accounts OR At least three (3) of the following four (4) conditions apply to the Merchant’s Transaction activity during the Case Scope Period:
- The Merchant’s fraud-to-sales Transaction ratio was seventy (70) percent or greater.
- At least twenty (20) percent of the Merchant’s Transactions submitted for authorization were declined by the Issuer or received a response of “01—Refer to issuer” during the Case Scope Period.
- The Merchant has been submitting Transactions for fewer than six (6) months.
- The Merchant’s total number or total dollar amount of fraudulent Transactions, authorization declines, and Issuer referrals was greater than the Merchant’s total number or total dollar amount of approved Transactions. NOTE: Transaction activity (“on-us” or otherwise) that is not processed through Mastercard systems is not considered in determining whether a Merchant meets the criteria of a Questionable Merchant. Mastercard has sole discretion, based on information from any source, to determine whether a Merchant meeting these criteria is a Questionable Merchant.
program: Fraud Monitoring- authority: Mastercard SPME §3.7, §11.1.1+ authority: Mastercard SPME §3.7, §11.1.1, §8.4fraud_to_sales_ratio_threshold: 0.015min_count_per_month: 100monitoring_cadence: monthlyescalation_actions:- escalate_to_human_review- notify_acquirerlookback_period_months: 1remediation_review_interval_days: 30agent_owner: fraud_ops_agent# MATCH fraud detection features are limited to principal owners only; associate owners and Service Provider name reporting are removed per SPME §11.1.1.# Acquirers may add and search for information on up to five principal owners per Merchant.# Multiple data fields are used to determine matches; MATCH supports editing and error notification to reduce delays.# Retroactive alert processing is supported for data up to 360 days old.# Acquirers control receipt and detail of inquiry match information.# Real-time access via MATCH Online and API, and batch operations remain available.# Merchant URL information may be added and searched.# Crucially, after obtaining MATCH inquiry results, Acquirers must assess whether further investigation or risk mitigation actions are warranted, per updated SPME requirements.++ # Enhanced Fraud Monitoring Criteria per SPME §8.4:+ # Incorporate quantitative thresholds for identifying Questionable Merchants including minimum transaction volume (≥ USD 50,000), transaction count (≥ 5), and fraud indicators such as elevated fraud-to-sales ratio (≥ 70%), high authorization declines or issuer referrals (≥ 20%), recent merchant activity (< 6 months), or disproportionate fraud/decline volume relative to approved transactions.+ # Utilize these criteria in ongoing fraud monitoring to escalate appropriate cases for review and possible recovery efforts under QMAP provisions.+ # Note: Transactions not processed via Mastercard systems are excluded from these determinations.+ # Mastercard retains sole discretion to designate Questionable Merchants based on these and other relevant factors.
Fraud Monitoring
Halyard Pay monitors merchant fraud activity and leverages Mastercard's MATCH system for enhanced fraud risk assessment on merchants processed through our platform.
When this policy applies
This policy applies to all merchants processed by Halyard Pay where Mastercard is the applicable network, covering both card-present and card-not-present transactions.
Required actions
-
Compute the merchant's rolling fraud-to-sales ratio each calendar month.
-
If the ratio meets or exceeds 1.5% and the fraud count reaches at least 100 transactions in that month, escalate the merchant account to human review immediately.
-
Utilize Mastercard's MATCH system data focusing on principal owners only, as per the updated Mastercard SPME guidelines. Do not consider associate owners or Service Provider names in fraud assessments.
-
Incorporate the Questionable Merchant Audit Program (QMAP) criteria from Mastercard SPME §8.4 to identify high-risk merchants. This includes assessing if a merchant has submitted at least USD 50,000 in transaction volume over a 120-day period and evaluating specific fraud-related conditions such as high fraud-to-sales ratios and issuer declines.
5. After accessing MATCH data, data and applying QMAP criteria, conduct a comprehensive risk assessment to determine whether further investigation or additional measures are warranted.
5. 6. Notify the acquiring compliance officer and document the case ID with supporting transaction data.
6. 7. Track case progress until the account returns to threshold compliance or is terminated.
Source authority: Mastercard SPME §3.7 and §11.1.1.§§3.7, 8.4, and 11.1.1.
Fraud Monitoring
Halyard Pay monitors merchant fraud activity and leverages Mastercard's MATCH system for enhanced fraud risk assessment on merchants processed through our platform.
When this policy applies
This policy applies to all merchants processed by Halyard Pay where Mastercard is the applicable network, covering both card-present and card-not-present transactions.
Required actions
-
Compute the merchant's rolling fraud-to-sales ratio each calendar month.
-
If the ratio meets or exceeds 1.5% and the fraud count reaches at least 100 transactions in that month, escalate the merchant account to human review immediately.
-
Utilize Mastercard's MATCH system data focusing on principal owners only, as per the updated Mastercard SPME guidelines. Do not consider associate owners or Service Provider names in fraud assessments.
-
Incorporate the Questionable Merchant Audit Program (QMAP) criteria from Mastercard SPME §8.4 to identify high-risk merchants. This includes assessing if a merchant has submitted at least USD 50,000 in transaction volume over a 120-day period and evaluating specific fraud-related conditions such as high fraud-to-sales ratios and issuer declines.
5. After accessing MATCH data, data and applying QMAP criteria, conduct a comprehensive risk assessment to determine whether further investigation or additional measures are warranted.
5. 6. Notify the acquiring compliance officer and document the case ID with supporting transaction data.
6. 7. Track case progress until the account returns to threshold compliance or is terminated.
Source authority: Mastercard SPME §3.7 and §11.1.1.§§3.7, 8.4, and 11.1.1.
Source authority: Mastercard SPME §8.4.
--- a/policies/fraud_monitoring/rules.yaml +++ b/policies/fraud_monitoring/rules.yaml @@ -1,5 +1,5 @@ program: Fraud Monitoring -authority: Mastercard SPME §3.7, §11.1.1 +authority: Mastercard SPME §3.7, §11.1.1, §8.4 fraud_to_sales_ratio_threshold: 0.015 min_count_per_month: 100 monitoring_cadence: monthly @@ -18,3 +18,9 @@ # Real-time access via MATCH Online and API, and batch operations remain available. # Merchant URL information may be added and searched. # Crucially, after obtaining MATCH inquiry results, Acquirers must assess whether further investigation or risk mitigation actions are warranted, per updated SPME requirements. + +# Enhanced Fraud Monitoring Criteria per SPME §8.4: +# Incorporate quantitative thresholds for identifying Questionable Merchants including minimum transaction volume (≥ USD 50,000), transaction count (≥ 5), and fraud indicators such as elevated fraud-to-sales ratio (≥ 70%), high authorization declines or issuer referrals (≥ 20%), recent merchant activity (< 6 months), or disproportionate fraud/decline volume relative to approved transactions. +# Utilize these criteria in ongoing fraud monitoring to escalate appropriate cases for review and possible recovery efforts under QMAP provisions. +# Note: Transactions not processed via Mastercard systems are excluded from these determinations. +# Mastercard retains sole discretion to designate Questionable Merchants based on these and other relevant factors. --- a/policies/fraud_monitoring/policy.md +++ b/policies/fraud_monitoring/policy.md @@ -11,8 +11,9 @@ 1. Compute the merchant's rolling fraud-to-sales ratio each calendar month. 2. If the ratio meets or exceeds 1.5% and the fraud count reaches at least 100 transactions in that month, escalate the merchant account to human review immediately. 3. Utilize Mastercard's MATCH system data focusing on principal owners only, as per the updated Mastercard SPME guidelines. Do not consider associate owners or Service Provider names in fraud assessments. -4. After accessing MATCH data, conduct a risk assessment to determine whether further investigation or additional measures are warranted. -5. Notify the acquiring compliance officer and document the case ID with supporting transaction data. -6. Track case progress until the account returns to threshold compliance or is terminated. +4. Incorporate the Questionable Merchant Audit Program (QMAP) criteria from Mastercard SPME §8.4 to identify high-risk merchants. This includes assessing if a merchant has submitted at least USD 50,000 in transaction volume over a 120-day period and evaluating specific fraud-related conditions such as high fraud-to-sales ratios and issuer declines. +5. After accessing MATCH data and applying QMAP criteria, conduct a comprehensive risk assessment to determine whether further investigation or additional measures are warranted. +6. Notify the acquiring compliance officer and document the case ID with supporting transaction data. +7. Track case progress until the account returns to threshold compliance or is terminated. -Source authority: Mastercard SPME §3.7 and §11.1.1. +Source authority: Mastercard SPME §§3.7, 8.4, and 11.1.1.