Mastercard SPME §11.2.3 · Sep 2023 → Feb 2024

Inquiring about a Merchant

substantive

The updated section introduces detailed procedures for removing a Merchant from MATCH reason code 12 (PCI DSS Noncompliance) listings. It requires Acquirers or the Merchant to submit a written request with specific business and owner information, along with attesting compliance confirmed by a certified forensic examiner's letter or certificate.

Sources Mastercard SPME · Sep 2023 · page 134 PDF Mastercard SPME · Feb 2024 · page 135 PDF KYB Acquirer current
Also in §11.x this release substantive §11 If the Acquirer is currently participating in the Merchant Monitoring Program, and this substantive §11.2.2 When to Add a Merchant to MATCH substantive §11.5 MATCH Reason Codes substantive §11.5.1 Reason Codes for Merchants Listed by the Acquirer substantive §11.7.1 Privacy and Data Protection
Why these edits? The update to section 11.2.3 introduces detailed procedures requiring Acquirers to submit written requests with specific business and owner information and certified compliance attestation for removing a Merchant from MATCH reason code 12 listings, which directly affects the Acquirer KYB obligations related to merchant vetting and monitoring.
Mastercard SPME §11.2.3
This section was substantively restructured between versions (5% text overlap). Compare the texts directly below.
Before · Sep 2023 · page 134

An Acquirer must check MATCH before signing an agreement with a Merchant and/or enabling a Merchant to accept Transactions, in accordance with section 7.1 of this manual. An Acquirer that enters into a Merchant Agreement without first submitting an inquiry to MATCH about the Merchant may be subject to an unfavorable ruling in a compliance case filed by a subsequent Acquirer of that Merchant. Acquirers must conduct inquiries under the proper Member ID/ICA Number for reporting compliance reasons. If an Acquirer does not conduct the inquiry under the proper Member ID/ICA Number (that is, the Member ID/ICA Number that is actually processing for the Merchant), Mastercard may find the Acquirer in noncompliance and may impose an assessment. Failure to comply with either the requirement of adding a terminated Merchant or inquiring about a Merchant may result in noncompliance assessments as described in Table 11.3.

After · Feb 2024 · page 135

Security Rules and Procedures—Merchant Edition • 6 February 2024

  • The Acquirer reports to Mastercard that the Acquirer added the Merchant to MATCH in error.
  • The Merchant listing is for reason code 12 (Payment Card Industry Data Security Standard Noncompliance) and the Acquirer has confirmed that the Merchant has become compliant with the Payment Card Industry Data Security Standard. The Acquirer must submit the request to remove a MATCH reason code 12 Merchant listing from MATCH in writing on the Acquirer’s letterhead to matchbusinessowner@mastercom.com. Such request must include the following information:
  1. Acquirer ID Number
  2. Merchant ID Number
  3. Merchant Name
  4. Doing Business As (DBA) Name
  5. Business Address
    1. Street Address
    2. City
    3. State
    4. Country
    5. Postal Code
  6. Principal Owner (PO) Data
    1. PO’s First Name and Last Name
    2. PO’s Country of Residence Any request relating to a Merchant listed for reason code 12 must contain: – The Acquirer’s attestation that the Merchant is in compliance with the Payment Card Industry Data Security Standard, and – A letter or certificate of validation from a Mastercard certified forensic examiner, certifying that the Merchant has become compliant with the Payment Card Industry Data Security Standard. If an Acquirer is unwilling or unable to submit a request to Mastercard with respect to a Merchant removal from a MATCH listing as a result of the Merchant obtaining compliance with the Payment Card Industry Data Security Standard, the Merchant itself may submit a request to Mastercard for this reason. The Merchant must follow the same process as described above for Acquirers to submit the MATCH removal request.
Halyard Pay · 2 files
program: Acquirer KYB
authority: Mastercard SPME 2.1, 11.2.3, 11.2.6
required_documents:
- incorporation
- beneficial_ownership
- aml_screen
- license_verification
min_review_cycle_days: 365
suspension_trigger: document_collection_failure
record_retention_years: 7
aml_watchlist_sources:
- ofac_sdn
- eu_consolidated
agent_owner: kyb_agent
- # Acquirers must perform a MATCH inquiry prior to entering into any Merchant Agreement or enabling a Merchant to accept transactions, as detailed in Mastercard SPME §11.2.3. This inquiry must be conducted using the correct Member ID/ICA Number associated with the Merchant to ensure proper compliance reporting.
- # Failure to adhere to these requirements may result in noncompliance assessments.
- # The Acquirer is also required to retain all MATCH records related to any Merchant, Sponsored Merchant, or ATM owner for a minimum of two years post-agreement termination, as per Mastercard SPME §11.2.6.
+ # Acquirers must perform a MATCH inquiry prior to signing any Merchant Agreement or enabling a Merchant to accept transactions, ensuring the inquiry uses the correct Member ID/ICA Number for compliance reporting, as established in Mastercard SPME §11.2.3.
+ # Additionally, if a Merchant is listed in MATCH for reason code 12 (PCI Data Security Standard Noncompliance), Acquirers must submit a written removal request to Mastercard with detailed Merchant and Principal Owner information, along with a certified attestation of PCI compliance, or allow the Merchant to submit such a request, reflecting the requirements updated in Mastercard SPME §11.2.3.
+ # All MATCH records for Merchants, Sponsored Merchants, or ATM owners must be retained for a minimum of two years after agreement termination, per Mastercard SPME §11.2.6.

Acquirer KYB (Know Your Business) Obligations

Acquirers processing transactions on the Mastercard network are required to perform

Know Your Business (KYB) due diligence on merchants before onboarding and on a

recurring basis thereafter. Halyard Pay, as an acquirer, must collect and verify a

minimum set of documents for each merchant to establish business legitimacy, confirm

beneficial ownership, and satisfy anti-money laundering screening requirements.

When this policy applies

This policy applies to all new merchant onboarding and to all periodic re-verification

reviews. Merchants that fail to supply required documentation within the stipulated

period must be suspended from processing until compliance is restored.

Required actions

  1. Collect all required KYB documents at onboarding prior to approval.

  2. Conduct AML screening against applicable watchlists before approval.

  3. Verify business licenses for regulated merchant categories.

  4. Schedule a full re-verification review at least once every 365 days.

  5. Document all verification outcomes and retain records for audit purposes.

  6. Retain all MATCH system records related to Merchants, Sponsored Merchants, or ATM owners for a minimum of two years after termination or expiration of the applicable agreement, to comply with Mastercard's explicit record retention requirements.

  7. Before entering into a Merchant Agreement or enabling a Merchant to accept transactions, Halyard Pay must conduct a MATCH inquiry using the proper Member ID/ICA Number assigned to Halyard Pay to ensure compliance. Failure to perform this check or to use the correct Member ID/ICA may result in noncompliance and assessments by Mastercard.

8. If a Merchant is listed on MATCH for reason code 12 (PCI DSS Noncompliance) and subsequently becomes compliant, Halyard Pay must submit a written removal request on company letterhead to matchbusinessowner@mastercom.com. This request must include detailed Merchant and principal owner information, an attestation of PCI DSS compliance, and certification from a Mastercard certified forensic examiner. Alternatively, Merchants may submit removal requests directly if Halyard Pay is unwilling or unable to do so.

Source authority: Mastercard SPME §§2.1, 7.1, 11.2.3, 11.2.6.

policies/kyb_acquirer/policy.md — after applying change

Acquirer KYB (Know Your Business) Obligations

Acquirers processing transactions on the Mastercard network are required to perform

Know Your Business (KYB) due diligence on merchants before onboarding and on a

recurring basis thereafter. Halyard Pay, as an acquirer, must collect and verify a

minimum set of documents for each merchant to establish business legitimacy, confirm

beneficial ownership, and satisfy anti-money laundering screening requirements.

When this policy applies

This policy applies to all new merchant onboarding and to all periodic re-verification

reviews. Merchants that fail to supply required documentation within the stipulated

period must be suspended from processing until compliance is restored.

Required actions

  1. Collect all required KYB documents at onboarding prior to approval.

  2. Conduct AML screening against applicable watchlists before approval.

  3. Verify business licenses for regulated merchant categories.

  4. Schedule a full re-verification review at least once every 365 days.

  5. Document all verification outcomes and retain records for audit purposes.

  6. Retain all MATCH system records related to Merchants, Sponsored Merchants, or ATM owners for a minimum of two years after termination or expiration of the applicable agreement, to comply with Mastercard's explicit record retention requirements.

  7. Before entering into a Merchant Agreement or enabling a Merchant to accept transactions, Halyard Pay must conduct a MATCH inquiry using the proper Member ID/ICA Number assigned to Halyard Pay to ensure compliance. Failure to perform this check or to use the correct Member ID/ICA may result in noncompliance and assessments by Mastercard.

8. If a Merchant is listed on MATCH for reason code 12 (PCI DSS Noncompliance) and subsequently becomes compliant, Halyard Pay must submit a written removal request on company letterhead to matchbusinessowner@mastercom.com. This request must include detailed Merchant and principal owner information, an attestation of PCI DSS compliance, and certification from a Mastercard certified forensic examiner. Alternatively, Merchants may submit removal requests directly if Halyard Pay is unwilling or unable to do so.

Source authority: Mastercard SPME §§2.1, 7.1, 11.2.3, 11.2.6.

Source authority: Mastercard SPME §11.2.3.

--- a/policies/kyb_acquirer/rules.yaml
+++ b/policies/kyb_acquirer/rules.yaml
@@ -12,6 +12,6 @@
   - ofac_sdn
   - eu_consolidated
 agent_owner: kyb_agent
-# Acquirers must perform a MATCH inquiry prior to entering into any Merchant Agreement or enabling a Merchant to accept transactions, as detailed in Mastercard SPME §11.2.3. This inquiry must be conducted using the correct Member ID/ICA Number associated with the Merchant to ensure proper compliance reporting.
-# Failure to adhere to these requirements may result in noncompliance assessments.
-# The Acquirer is also required to retain all MATCH records related to any Merchant, Sponsored Merchant, or ATM owner for a minimum of two years post-agreement termination, as per Mastercard SPME §11.2.6.
+# Acquirers must perform a MATCH inquiry prior to signing any Merchant Agreement or enabling a Merchant to accept transactions, ensuring the inquiry uses the correct Member ID/ICA Number for compliance reporting, as established in Mastercard SPME §11.2.3.
+# Additionally, if a Merchant is listed in MATCH for reason code 12 (PCI Data Security Standard Noncompliance), Acquirers must submit a written removal request to Mastercard with detailed Merchant and Principal Owner information, along with a certified attestation of PCI compliance, or allow the Merchant to submit such a request, reflecting the requirements updated in Mastercard SPME §11.2.3.
+# All MATCH records for Merchants, Sponsored Merchants, or ATM owners must be retained for a minimum of two years after agreement termination, per Mastercard SPME §11.2.6.
--- a/policies/kyb_acquirer/policy.md
+++ b/policies/kyb_acquirer/policy.md
@@ -21,5 +21,6 @@
 5. Document all verification outcomes and retain records for audit purposes.
 6. Retain all MATCH system records related to Merchants, Sponsored Merchants, or ATM owners for a minimum of two years after termination or expiration of the applicable agreement, to comply with Mastercard's explicit record retention requirements.
 7. Before entering into a Merchant Agreement or enabling a Merchant to accept transactions, Halyard Pay must conduct a MATCH inquiry using the proper Member ID/ICA Number assigned to Halyard Pay to ensure compliance. Failure to perform this check or to use the correct Member ID/ICA may result in noncompliance and assessments by Mastercard.
+8. If a Merchant is listed on MATCH for reason code 12 (PCI DSS Noncompliance) and subsequently becomes compliant, Halyard Pay must submit a written removal request on company letterhead to matchbusinessowner@mastercom.com. This request must include detailed Merchant and principal owner information, an attestation of PCI DSS compliance, and certification from a Mastercard certified forensic examiner. Alternatively, Merchants may submit removal requests directly if Halyard Pay is unwilling or unable to do so.
 
 Source authority: Mastercard SPME §§2.1, 7.1, 11.2.3, 11.2.6.