Mastercard SPME §8.6.2 · May 2023 → Sep 2023

Investigation Process

substantive

The updated text adds a requirement that issuers must notify cardholders within 10 days of notification to provide a police report or explanation if unavailable, enhancing issuer follow-up procedures in alleged coercion investigations.

Sources Mastercard SPME · May 2023 · page 91 PDF Mastercard SPME · Sep 2023 · page 85 PDF ATO Detection current
Also in §8.x this release breaking §8.6.7 Franchise Management Program (FMP) Questionnaire-based Review substantive §8.3.4 Additional ECM and HECM Requirements substantive §8.4 Questionable Merchant Audit Program (QMAP) substantive §8.4.1 QMAP Definitions substantive §8.4.2 Mastercard Commencement of an Investigation substantive §8.4.4 Mastercard Notification to Acquirers substantive §8.4.6 Mastercard Determination substantive §8.4.7 Chargeback Responsibility substantive §8.6.6 MATCH Reporting substantive §8.7.3 Mastercard Notification to Acquirers substantive §8.7.4 Mastercard Determination substantive §8.7.5 Assessments, Recovery Amounts, and Fees
Why these edits? The update adds a new issuer follow-up requirement to notify cardholders within 10 days to provide a police report or explanation if unavailable, impacting the Account-Takeover Detection policy related to investigation timelines and documentation verification.
Mastercard SPME §8.6.2
Mastercard will investigate a claim of alleged coercion when the following criteria are met: • Within 120 calendar days from an alleged coercive event, Mastercard receives from two or more different issuers separate claims of alleged coerced Transactions performed by two or more unrelated Cardholders at the same Merchant location. The 120 calendar day period is calculated as 60 calendar days prior to and 60 calendar days after the date of the first alleged coerced Transaction. At Mastercard’s sole discretion, the 120 calendar day period may be expanded. • At least one claim of coercion includes a copy of a police report filed by the Cardholder • The Transactions resulting from the alleged coercion were reported to the Fraud and Loss Database using fraud type code 00 (Lost Fraud) or 01 (Stolen Fraud). At Mastercard’s sole discretion, a Transaction reported with a fraud reason code other than 00 or 01 may be included in the investigation. Additionally, Mastercard will notify those Issuers whose Cardholders have performed a Transaction at the Merchant within the 120 calendar day (or longer) period of the alleged coerced event and who have not already submitted a Cardholder’s claim of coercion that each Issuer has 10 calendar days from the initial notification date to contact the Cardholder, if necessary, and provide: A police report (if available) When a police report is not provided, the Cardholder’s description must address why a police report was not provided. The Cardholder description Mastercard Fraud Control Programs
Halyard Pay · 2 files
program: ATO Detection
- authority: Mastercard SPME §10.6.2.1
+ authority: Mastercard SPME §8.6.2
risk_threshold_for_3ds_challenge: 0.5
risk_score_range: [0.0, 1.0]
signals:
- geo_anomaly
- device_fingerprint_change
- velocity_breach
- credential_stuffing
challenge_method: 3ds_v2
persistent_risk_escalation_threshold: 3
persistent_risk_lookback_days: 7
agent_owner: ato_agent
 
- # This policy incorporates the updated Mastercard SPME §10.6.2.1 requirements,
- # including extended timelines for Terminal Servicer compliance revalidation
- # after an Account Data Compromise Event, emphasizing a 90-day PCI DSS
- # revalidation period and an added 12-month DESV appendix compliance.
- # It reinforces timely and comprehensive security procedures to mitigate
- # Account Takeover risk in line with Mastercard's updated security standards.
+ # This policy updates reflect Mastercard's enhanced investigation criteria under SPME §8.6.2,
+ # incorporating issuer obligations to follow up with Cardholders within 10 calendar days
+ # after notification of alleged coerced Transactions, requesting a police report or a
+ # detailed explanation if no report is available. This strengthens documentation requirements
+ # and improves the rigor of Account Takeover detection responses by ensuring timely
+ # issuer-to-Cardholder communication for coercion claims.

Account-Takeover (ATO) Detection

Account-takeover fraud occurs when a malicious actor gains unauthorized access to

a cardholder's account and initiates transactions without the cardholder's consent.

Halyard Pay implements real-time risk scoring on authentication events and enforces a

mandatory 3DS (3-D Secure) challenge for any session where the computed risk score

meets or exceeds the defined threshold.

Detection signals

The risk model incorporates multiple behavioral signals: geographic anomalies

inconsistent with a cardholder's established pattern, changes to device fingerprint,

transaction velocity breaches, and indicators of credential-stuffing activity.

Required actions

  1. Evaluate each authentication event against the defined signal list in real time.

  2. Compute a normalized risk score between 0.0 and 1.0.

  3. If the risk score is 0.5 or greater, trigger a mandatory 3DS challenge before

authorizing the transaction.

  1. Log all ATO signals and outcomes in the case management system.

  2. Escalate persistent high-risk accounts to the ATO response team for manual review.

  3. In the event of an Account Data Compromise (ADC), ensure that any Terminal Servicer

involved revalidates PCI DSS compliance within 90 calendar days after the forensic

investigation concludes, and demonstrate compliance with the PCI DSS Data

Encryption and Software Validation (DESV) appendix within 12 months, consistent

with Mastercard requirements (SPME §10.6.2.1).

7. For cases involving alleged coercion, follow updated Mastercard protocols requiring

issuers notified of the potential coerced transactions at a merchant to contact their

cardholders within 10 calendar days to obtain a police report or, if unavailable,

a cardholder explanation for the absence of police documentation, to support

investigation and validation efforts (SPME §8.6.2).

Source authority: Mastercard SPME §6.2, §8.6.2, §10.6.2.1.

policies/ato_detection/policy.md — after applying change

Account-Takeover (ATO) Detection

Account-takeover fraud occurs when a malicious actor gains unauthorized access to

a cardholder's account and initiates transactions without the cardholder's consent.

Halyard Pay implements real-time risk scoring on authentication events and enforces a

mandatory 3DS (3-D Secure) challenge for any session where the computed risk score

meets or exceeds the defined threshold.

Detection signals

The risk model incorporates multiple behavioral signals: geographic anomalies

inconsistent with a cardholder's established pattern, changes to device fingerprint,

transaction velocity breaches, and indicators of credential-stuffing activity.

Required actions

  1. Evaluate each authentication event against the defined signal list in real time.

  2. Compute a normalized risk score between 0.0 and 1.0.

  3. If the risk score is 0.5 or greater, trigger a mandatory 3DS challenge before

authorizing the transaction.

  1. Log all ATO signals and outcomes in the case management system.

  2. Escalate persistent high-risk accounts to the ATO response team for manual review.

  3. In the event of an Account Data Compromise (ADC), ensure that any Terminal Servicer

involved revalidates PCI DSS compliance within 90 calendar days after the forensic

investigation concludes, and demonstrate compliance with the PCI DSS Data

Encryption and Software Validation (DESV) appendix within 12 months, consistent

with Mastercard requirements (SPME §10.6.2.1).

7. For cases involving alleged coercion, follow updated Mastercard protocols requiring

issuers notified of the potential coerced transactions at a merchant to contact their

cardholders within 10 calendar days to obtain a police report or, if unavailable,

a cardholder explanation for the absence of police documentation, to support

investigation and validation efforts (SPME §8.6.2).

Source authority: Mastercard SPME §6.2, §8.6.2, §10.6.2.1.

Source authority: Mastercard SPME §8.6.2.

--- a/policies/ato_detection/rules.yaml
+++ b/policies/ato_detection/rules.yaml
@@ -1,5 +1,5 @@
 program: ATO Detection
-authority: Mastercard SPME §10.6.2.1
+authority: Mastercard SPME §8.6.2
 risk_threshold_for_3ds_challenge: 0.5
 risk_score_range: [0.0, 1.0]
 signals:
@@ -12,9 +12,9 @@
 persistent_risk_lookback_days: 7
 agent_owner: ato_agent
 
-# This policy incorporates the updated Mastercard SPME §10.6.2.1 requirements,
-# including extended timelines for Terminal Servicer compliance revalidation
-# after an Account Data Compromise Event, emphasizing a 90-day PCI DSS
-# revalidation period and an added 12-month DESV appendix compliance.
-# It reinforces timely and comprehensive security procedures to mitigate
-# Account Takeover risk in line with Mastercard's updated security standards.+# This policy updates reflect Mastercard's enhanced investigation criteria under SPME §8.6.2,
+# incorporating issuer obligations to follow up with Cardholders within 10 calendar days
+# after notification of alleged coerced Transactions, requesting a police report or a
+# detailed explanation if no report is available. This strengthens documentation requirements
+# and improves the rigor of Account Takeover detection responses by ensuring timely
+# issuer-to-Cardholder communication for coercion claims.

--- a/policies/ato_detection/policy.md
+++ b/policies/ato_detection/policy.md
@@ -25,5 +25,10 @@
    investigation concludes, and demonstrate compliance with the PCI DSS Data
    Encryption and Software Validation (DESV) appendix within 12 months, consistent
    with Mastercard requirements (SPME §10.6.2.1).
+7. For cases involving alleged coercion, follow updated Mastercard protocols requiring
+   issuers notified of the potential coerced transactions at a merchant to contact their
+   cardholders within 10 calendar days to obtain a police report or, if unavailable,
+   a cardholder explanation for the absence of police documentation, to support
+   investigation and validation efforts (SPME §8.6.2).
 
-Source authority: Mastercard SPME §6.2, §10.6.2.1.+Source authority: Mastercard SPME §6.2, §8.6.2, §10.6.2.1.