Mastercard SPME §12 · Sep 2023 → Feb 2024

Any other information the Acquirer determines relevant to be considered.

substantive

The updated section states that failing to provide complete responses by deadlines is a violation punishable with escalating Category C noncompliance assessments, and possibly other assessments if further violations are found. Mastercard may allow more time if the Acquirer confirms the offending activity has stopped.

Sources Mastercard SPME · Sep 2023 PDF Mastercard SPME · Feb 2024 · page 92 PDF BRAM Response current
Why these edits? The amendment imposes consequences such as escalating Category C noncompliance assessments for failure to provide complete responses by deadlines, directly impacting BRAM investigation response obligations.
Mastercard SPME §12
This section was substantively restructured between versions (0% text overlap). Compare the texts directly below.
Before · Sep 2023
After · Feb 2024 · page 92

Failure to provide a complete response by the required due date will be deemed a violation of Mastercard Rules section 3.9 Obligation of Customer to Provide Information and may result in escalating Category C noncompliance assessments until the required information is provided. The Customer may also be subject to assessments with respect to any other Standards violations identified during the BRAM investigation. Mastercard may grant an Acquirer additional time to provide the requested documentation if the Acquirer has confirmed to Mastercard that the violating activity has ceased.

Halyard Pay · 2 files
program: BRAM
- authority: Mastercard SPME §8.6.2, §10.2
+ authority: Mastercard SPME 8.6.2, 10.2, 12
response_window_days: 180
required_evidence:
- transaction_monitoring_records
- corrective_action_plan
- - police_report # Mandatory inclusion per updated SPME §8.6.2
+ - police_report # Mandatory inclusion per updated SPME 8.6.2
halt_actions:
- halt_new_merchant_onboarding
internal_notification_hours: 24
agent_owner: bram_response_agent
 
- # Reflects updated police report requirement and acknowledges Mastercard's exclusive authority to determine ADC Event occurrence and responsibility as clarified in SPME §10.2.
- # Policy recognizes Mastercard's sole discretion in classifying and consolidating ADC Events to ensure proper investigation and response procedures.
+ # Includes updated police report requirement per SPME 8.6.2 and affirms Mastercard's exclusive authority in determining ADC Event responsibility (SPME 10.2).
+ # Added policy note on consequences for failure to provide complete responses by deadlines, including escalating Category C noncompliance assessments as specified in SPME 12.
+ # Allows for potential additional time granted by Mastercard upon Acquirer's confirmation of cessation of violating activity.

BRAM Investigation Response

When Mastercard issues a Business Risk Assessment and Mitigation (BRAM) investigation

notice for one of our merchants, the acquirer must halt new merchant onboarding

immediately and submit an evidence package within one hundred eighty (180) days

of receipt of the notice.

Required actions

  1. Halt new merchant onboarding for the merchant under investigation.

  2. Compile and submit an evidence package containing:

  • Transaction monitoring records covering the prior 180 days.

  • A written corrective action plan.

  • Documentation of any police reports related to alleged coercion claims if applicable.

  1. Notify the Halyard Pay Compliance lead within 24 hours of receipt.

Failure to submit a complete response by the deadline will be considered a violation of Mastercard Rules section 3.9, resulting in escalating Category C noncompliance assessments until compliance is met. Additional assessments may occur for other Standards violations revealed during the BRAM investigation. Mastercard may grant extensions if the acquirer confirms cessation of violating activities.

Additional Considerations for Coercion Claims

When allegations of coerced Transactions arise, note that Mastercard may extend the usual 120-day

investigation period at its discretion. At least one claim must include a police report from the Cardholder.

Transactions reported as Lost or Stolen Fraud (fraud type codes 00 or 01) are subject to investigation,

though Mastercard may consider other fraud codes. Mastercard will notify issuers with Transactions at the

merchant within the investigation period to prompt claim submissions.

Mastercard's Authority and Determinations on ADC Events

Mastercard retains exclusive authority to determine the occurrence, scope, and responsibility for Account Data Compromise (ADC) Events or Potential ADC Events, including the consolidation of related incidents into single or multiple events where applicable. Mastercard’s decisions in these matters are final and not subject to internal appeal. Customers are advised to seek Mastercard guidance if uncertain about their rights or obligations related to ADC Events. This framework ensures accountability and proper management of ADC risks in line with Mastercard's network security standards.

Source authority: Mastercard SPME §8.6.2, §10.2.������8.6.2, ������10.2, 12.0, and section 3.9.

policies/bram_response/policy.md — after applying change

BRAM Investigation Response

When Mastercard issues a Business Risk Assessment and Mitigation (BRAM) investigation

notice for one of our merchants, the acquirer must halt new merchant onboarding

immediately and submit an evidence package within one hundred eighty (180) days

of receipt of the notice.

Required actions

  1. Halt new merchant onboarding for the merchant under investigation.

  2. Compile and submit an evidence package containing:

  • Transaction monitoring records covering the prior 180 days.

  • A written corrective action plan.

  • Documentation of any police reports related to alleged coercion claims if applicable.

  1. Notify the Halyard Pay Compliance lead within 24 hours of receipt.

Failure to submit a complete response by the deadline will be considered a violation of Mastercard Rules section 3.9, resulting in escalating Category C noncompliance assessments until compliance is met. Additional assessments may occur for other Standards violations revealed during the BRAM investigation. Mastercard may grant extensions if the acquirer confirms cessation of violating activities.

Additional Considerations for Coercion Claims

When allegations of coerced Transactions arise, note that Mastercard may extend the usual 120-day

investigation period at its discretion. At least one claim must include a police report from the Cardholder.

Transactions reported as Lost or Stolen Fraud (fraud type codes 00 or 01) are subject to investigation,

though Mastercard may consider other fraud codes. Mastercard will notify issuers with Transactions at the

merchant within the investigation period to prompt claim submissions.

Mastercard's Authority and Determinations on ADC Events

Mastercard retains exclusive authority to determine the occurrence, scope, and responsibility for Account Data Compromise (ADC) Events or Potential ADC Events, including the consolidation of related incidents into single or multiple events where applicable. Mastercard’s decisions in these matters are final and not subject to internal appeal. Customers are advised to seek Mastercard guidance if uncertain about their rights or obligations related to ADC Events. This framework ensures accountability and proper management of ADC risks in line with Mastercard's network security standards.

Source authority: Mastercard SPME §8.6.2, §10.2.������8.6.2, ������10.2, 12.0, and section 3.9.

Source authority: Mastercard SPME §12.

--- a/policies/bram_response/rules.yaml
+++ b/policies/bram_response/rules.yaml
@@ -1,14 +1,15 @@
 program: BRAM
-authority: Mastercard SPME §8.6.2, §10.2
+authority: Mastercard SPME 8.6.2, 10.2, 12
 response_window_days: 180
 required_evidence:
   - transaction_monitoring_records
   - corrective_action_plan
-  - police_report  # Mandatory inclusion per updated SPME §8.6.2
+  - police_report  # Mandatory inclusion per updated SPME 8.6.2
 halt_actions:
   - halt_new_merchant_onboarding
 internal_notification_hours: 24
 agent_owner: bram_response_agent
 
-# Reflects updated police report requirement and acknowledges Mastercard's exclusive authority to determine ADC Event occurrence and responsibility as clarified in SPME §10.2.
-# Policy recognizes Mastercard's sole discretion in classifying and consolidating ADC Events to ensure proper investigation and response procedures.
+# Includes updated police report requirement per SPME 8.6.2 and affirms Mastercard's exclusive authority in determining ADC Event responsibility (SPME 10.2).
+# Added policy note on consequences for failure to provide complete responses by deadlines, including escalating Category C noncompliance assessments as specified in SPME 12.
+# Allows for potential additional time granted by Mastercard upon Acquirer's confirmation of cessation of violating activity.
--- a/policies/bram_response/policy.md
+++ b/policies/bram_response/policy.md
@@ -14,6 +14,8 @@
    - Documentation of any police reports related to alleged coercion claims if applicable.
 3. Notify the Halyard Pay Compliance lead within 24 hours of receipt.
 
+Failure to submit a complete response by the deadline will be considered a violation of Mastercard Rules section 3.9, resulting in escalating Category C noncompliance assessments until compliance is met. Additional assessments may occur for other Standards violations revealed during the BRAM investigation. Mastercard may grant extensions if the acquirer confirms cessation of violating activities.
+
 ## Additional Considerations for Coercion Claims
 
 When allegations of coerced Transactions arise, note that Mastercard may extend the usual 120-day
@@ -26,4 +28,4 @@
 
 Mastercard retains exclusive authority to determine the occurrence, scope, and responsibility for Account Data Compromise (ADC) Events or Potential ADC Events, including the consolidation of related incidents into single or multiple events where applicable. Mastercard’s decisions in these matters are final and not subject to internal appeal. Customers are advised to seek Mastercard guidance if uncertain about their rights or obligations related to ADC Events. This framework ensures accountability and proper management of ADC risks in line with Mastercard's network security standards.
 
-Source authority: Mastercard SPME §8.6.2, §10.2.+Source authority: Mastercard SPME 8.6.2, 10.2, 12.0, and section 3.9.