Mastercard SPME §11.5.1 · Sep 2023 → Feb 2024

Reason Codes for Merchants Listed by the Acquirer

substantive

The section's MATCH listing reason codes were completely replaced. Previous specific codes like Account Data Compromise and Excessive Chargebacks were removed, replaced with broader categories including Violation of Standards, Merchant Collusion, PCI Data Security Standard Noncompliance, Illegal Transactions, and Identity Theft.

Sources Mastercard SPME · Sep 2023 · page 136 PDF Mastercard SPME · Feb 2024 · page 136 PDF ECP Thresholds current
Also in §11.x this release substantive §11 If the Acquirer is currently participating in the Merchant Monitoring Program, and this substantive §11.2.2 When to Add a Merchant to MATCH substantive §11.2.3 Inquiring about a Merchant substantive §11.5 MATCH Reason Codes substantive §11.7.1 Privacy and Data Protection
Why these edits? The reason codes related to Excessive Chargebacks have been removed and replaced with broader categories including 'Violation of Standards' and 'Illegal Transactions', affecting the ECP Thresholds policy tied to chargeback thresholds enforcement.
Mastercard SPME §11.5.1
This section was substantively restructured between versions (14% text overlap). Compare the texts directly below.
Before · Sep 2023 · page 136

The following reason codes indicate why an Acquirer reported a terminated Merchant to MATCH. Table 11.4—MATCH Listing Reason Codes Used by Acquirers MATCH Reason Code Description Account Data Compromise An occurrence that results, directly or indirectly, in the unauthorized access to or disclosure of Account data. Common Point of Purchase (CPP) Account data is stolen at the Merchant and then used for fraudulent purchases at other Merchant locations. Laundering The Merchant was engaged in laundering activity. Laundering means that a Merchant presented to its Acquirer Transaction records that were not valid Transactions for sales of goods or services between that Merchant and a bona fide Cardholder. Excessive Chargebacks With respect to a Merchant reported by a Mastercard Acquirer, the number of Mastercard chargebacks in any single month exceeded 1% of the number of Mastercard sales Transactions in that month, and those chargebacks totaled USD 5,000 or more. With respect to a merchant reported by an American Express acquirer (ICA numbers 102 through 125), the merchant exceeded the chargeback thresholds of American Express, as determined by American Express. Excessive Fraud The Merchant effected fraudulent Transactions of any type (counterfeit or otherwise) meeting or exceeding the following minimum reporting Standard: the Merchant’s fraud- to-sales dollar volume ratio was 8% or greater in a calendar month, and the Merchant effected 10 or more fraudulent Transactions totaling USD 5,000 or more in that calendar month. Reserved for Future Use MATCH System

After · Feb 2024 · page 136

Security Rules and Procedures—Merchant Edition • 6 February 2024

MATCH Reason Code Description Violation of Standards With respect to a Merchant reported by a Mastercard Acquirer, the Merchant was in violation of one or more Standards that describe procedures to be employed by the Merchant in Transactions in which Cards are used, including, by way of example and not limitation, the Standards for honoring all Cards, displaying the Marks, charges to Cardholders, minimum/maximum Transaction amount restrictions, and prohibited Transactions set forth in Chapter 5 of the Mastercard Rules manual. With respect to a merchant reported by an American Express acquirer (ICA numbers 102 through 125), the merchant was in violation of one or more American Express bylaws, rules, operating regulations, and policies that set forth procedures to be employed by the merchant in transactions in which American Express cards are used. Merchant Collusion The Merchant participated in fraudulent collusive activity. PCI Data Security Standard Noncompliance The Merchant failed to comply with Payment Card Industry (PCI) Data Security Standard requirements. Illegal Transactions The Merchant was engaged in illegal Transactions. Identity Theft The Acquirer has reason to believe that the identity of the listed Merchant or its principal owner(s) was unlawfully assumed for the purpose of unlawfully entering into a Merchant Agreement.

Halyard Pay · 2 files
program: ECP
authority: Mastercard SPME §11.4, §11.5, §13.1.2
chargeback_to_transaction_ratio_threshold: 0.015
min_chargeback_count: 100
program_tiers:
- standard
- excessive
tier_thresholds:
standard: 0.015
excessive: 0.030
merchant_notification_business_days: 5
monitoring_cadence: monthly
agent_owner: ecp_ops_agent
 
- # Updated authority citation to include Mastercard SPME §13.1.2, reflecting the revised Covered Programs Privacy and Data Protection Standards.
- # This update acknowledges enhanced requirements related to Processing of Personal Data under EU Data Protection Law impacting the Excessive Chargeback Program's monitoring and notification practices.
- # No changes to thresholds or other parameters were necessary at this time, as the program continues to adhere to existing ECP chargeback criteria while incorporating heightened privacy provisions.
+ # The reason codes used by Acquirers for MATCH reporting have evolved, removing explicit Excessive Chargebacks code and replacing it with broader violation categories such as 'Violation of Standards' and 'Illegal Transactions' per Mastercard SPME §11.5.1.
+ # Despite this change, the Excessive Chargeback Program's internal thresholds and monitoring parameters remain unchanged to maintain continuity in risk management.
+ # The policy continues to reference SPME sections relevant to chargeback handling and privacy, reflecting ongoing compliance without modifying program metrics or tier definitions.
+

Excessive Chargeback Program (ECP) Thresholds

Mastercard's Excessive Chargeback Program (ECP) monitors merchants whose chargeback activity exceeds established thresholds relative to monthly transaction volume and chargeback amounts. Halyard Pay tracks these metrics monthly and escalates merchants meeting or surpassing program criteria into risk management processes.

Program tiers

There are two escalation tiers:

  • Standard: chargeback-to-transaction ratio of 1.5% (0.015) or higher and at least 100 chargebacks in a month.

  • Excessive: chargeback ratio of 3.0% (0.03) or greater for the month.

MATCH Listing criteria

Merchants may also be reported to the MATCH system under broad reasons such as compliance violations, fraudulent activity, or illegal transactions, rather than solely for excessive chargebacks. Reporting continues if the number of monthly Mastercard chargebacks in a month exceeds exceed 1% of Mastercard sales transactions and chargebacks total at least amount to USD 5,000. Note that 5,000 or more. Acquirers must evaluate applicable standards violations or risk-related behaviors as per Mastercard and American Express acquirers use distinct MATCH reporting thresholds. requirements.

Required actions

  1. Calculate each merchant's chargeback-to-transaction ratio and total chargeback amount at month-end.

  2. Assign the merchant to the appropriate tier based on ratio thresholds.

  3. Evaluate MATCH reporting criteria to identify additional risk. considering compliance or legal violations, not limited to chargeback counts.

  4. Open an ECP case and notify the merchant within five business days.

  5. Continuously monitor merchants' monthly performance until they exit the program.

  6. Escalate to chargeback agents for automated case handling.

Data Protection and Privacy Considerations

In line with Mastercard's updated data protection framework under EU Data Protection Law, Halyard Pay ensures that all processing of personal data involved in the ECP complies with enhanced privacy and security requirements. This includes limiting data access, applying robust safeguards, adhering to data transfer restrictions, and facilitating timely notification and cooperation in case of personal data breaches. Halyard Pay and its customers act as independent controllers of personal data related to the ECP and maintain transparent accountability mechanisms to meet these obligations.

Source authority: Mastercard SPME §§11.4, 11.5, 13.1.2.13.1.2, 11.5.1.

policies/ecp_thresholds/policy.md — after applying change

Excessive Chargeback Program (ECP) Thresholds

Mastercard's Excessive Chargeback Program (ECP) monitors merchants whose chargeback activity exceeds established thresholds relative to monthly transaction volume and chargeback amounts. Halyard Pay tracks these metrics monthly and escalates merchants meeting or surpassing program criteria into risk management processes.

Program tiers

There are two escalation tiers:

  • Standard: chargeback-to-transaction ratio of 1.5% (0.015) or higher and at least 100 chargebacks in a month.

  • Excessive: chargeback ratio of 3.0% (0.03) or greater for the month.

MATCH Listing criteria

Merchants may also be reported to the MATCH system under broad reasons such as compliance violations, fraudulent activity, or illegal transactions, rather than solely for excessive chargebacks. Reporting continues if the number of monthly Mastercard chargebacks in a month exceeds exceed 1% of Mastercard sales transactions and chargebacks total at least amount to USD 5,000. Note that 5,000 or more. Acquirers must evaluate applicable standards violations or risk-related behaviors as per Mastercard and American Express acquirers use distinct MATCH reporting thresholds. requirements.

Required actions

  1. Calculate each merchant's chargeback-to-transaction ratio and total chargeback amount at month-end.

  2. Assign the merchant to the appropriate tier based on ratio thresholds.

  3. Evaluate MATCH reporting criteria to identify additional risk. considering compliance or legal violations, not limited to chargeback counts.

  4. Open an ECP case and notify the merchant within five business days.

  5. Continuously monitor merchants' monthly performance until they exit the program.

  6. Escalate to chargeback agents for automated case handling.

Data Protection and Privacy Considerations

In line with Mastercard's updated data protection framework under EU Data Protection Law, Halyard Pay ensures that all processing of personal data involved in the ECP complies with enhanced privacy and security requirements. This includes limiting data access, applying robust safeguards, adhering to data transfer restrictions, and facilitating timely notification and cooperation in case of personal data breaches. Halyard Pay and its customers act as independent controllers of personal data related to the ECP and maintain transparent accountability mechanisms to meet these obligations.

Source authority: Mastercard SPME §§11.4, 11.5, 13.1.2.13.1.2, 11.5.1.

Source authority: Mastercard SPME §11.5.1.

--- a/policies/ecp_thresholds/rules.yaml
+++ b/policies/ecp_thresholds/rules.yaml
@@ -12,6 +12,7 @@
 monitoring_cadence: monthly
 agent_owner: ecp_ops_agent
 
-# Updated authority citation to include Mastercard SPME §13.1.2, reflecting the revised Covered Programs Privacy and Data Protection Standards.
-# This update acknowledges enhanced requirements related to Processing of Personal Data under EU Data Protection Law impacting the Excessive Chargeback Program's monitoring and notification practices.
-# No changes to thresholds or other parameters were necessary at this time, as the program continues to adhere to existing ECP chargeback criteria while incorporating heightened privacy provisions.
+# The reason codes used by Acquirers for MATCH reporting have evolved, removing explicit Excessive Chargebacks code and replacing it with broader violation categories such as 'Violation of Standards' and 'Illegal Transactions' per Mastercard SPME §11.5.1.
+# Despite this change, the Excessive Chargeback Program's internal thresholds and monitoring parameters remain unchanged to maintain continuity in risk management.
+# The policy continues to reference SPME sections relevant to chargeback handling and privacy, reflecting ongoing compliance without modifying program metrics or tier definitions.
+

--- a/policies/ecp_thresholds/policy.md
+++ b/policies/ecp_thresholds/policy.md
@@ -10,13 +10,13 @@
 
 ## MATCH Listing criteria
 
-Merchants may also be reported to the MATCH system if the number of Mastercard chargebacks in a month exceeds 1% of Mastercard sales transactions and chargebacks total at least USD 5,000. Note that American Express acquirers use distinct MATCH reporting thresholds.
+Merchants may be reported to the MATCH system under broad reasons such as compliance violations, fraudulent activity, or illegal transactions, rather than solely for excessive chargebacks. Reporting continues if monthly Mastercard chargebacks exceed 1% of Mastercard sales transactions and amount to USD 5,000 or more. Acquirers must evaluate applicable standards violations or risk-related behaviors as per Mastercard and American Express requirements.
 
 ## Required actions
 
 1. Calculate each merchant's chargeback-to-transaction ratio and total chargeback amount at month-end.
 2. Assign the merchant to the appropriate tier based on ratio thresholds.
-3. Evaluate MATCH reporting criteria to identify additional risk.
+3. Evaluate MATCH reporting criteria considering compliance or legal violations, not limited to chargeback counts.
 4. Open an ECP case and notify the merchant within five business days.
 5. Continuously monitor merchants' monthly performance until they exit the program.
 6. Escalate to chargeback agents for automated case handling.
@@ -25,4 +25,4 @@
 
 In line with Mastercard's updated data protection framework under EU Data Protection Law, Halyard Pay ensures that all processing of personal data involved in the ECP complies with enhanced privacy and security requirements. This includes limiting data access, applying robust safeguards, adhering to data transfer restrictions, and facilitating timely notification and cooperation in case of personal data breaches. Halyard Pay and its customers act as independent controllers of personal data related to the ECP and maintain transparent accountability mechanisms to meet these obligations.
 
-Source authority: Mastercard SPME §§11.4, 11.5, 13.1.2.+Source authority: Mastercard SPME §§11.4, 11.5, 13.1.2, 11.5.1.