Mastercard SPME §2.1.1 · Sep 2023 → Feb 2024
Payment Card Industry (PCI) Security Standards
The entire detailed text about PCI Software Security Framework and compliance recommendations has been removed from the section, leaving only the general document header without content.
Security Rules and Procedures—Merchant Edition • 1 August 2023
PCI Security Standard Compliance Requirements and Recommendations PCI Software Security Framework (SSF)—PCI Secure Software Requirements and Assessment Procedures (“PCI Secure Software Standard”) Compliance is required for all Merchants and Service Providers that use eligible third party- provided payment software. Refer to the PCI Secure Software Program Guide for information about the applicability of the PCI Secure Software Standard to third party-provided payment software. PCI Software Security Framework (SSF)—PCI Secure Software Lifecycle (Secure SLC) Requirements and Assessment Procedures (“PCI Secure SLC Standard”) Compliance is strongly recommended for any Merchant or Service Provider that uses third party- provided payment software.
Security Rules and Procedures—Merchant Edition • 6 February 2024
program: Acquirer KYBauthority: Mastercard SPME 2.1, 11.2.3, 11.2.6required_documents:- incorporation- beneficial_ownership- aml_screen- license_verificationmin_review_cycle_days: 365suspension_trigger: document_collection_failurerecord_retention_years: 7aml_watchlist_sources:- ofac_sdn- eu_consolidatedagent_owner: kyb_agent# Acquirers must perform a MATCH inquiry prior to entering into any Merchant Agreement or enabling a Merchant to accept transactions, as detailed in Mastercard SPME §11.2.3. This inquiry must be conducted using the correct Member ID/ICA Number associated with the Merchant to ensure proper compliance reporting.# Failure to adhere to these requirements may result in noncompliance assessments.# The Acquirer is also required to retain all MATCH records related to any Merchant, Sponsored Merchant, or ATM owner for a minimum of two years post-agreement termination, as per Mastercard SPME §11.2.6.+ # The previous detailed requirements on PCI Software Security Framework compliance under Mastercard SPME §2.1.1 have been removed from the current edition. Therefore, this policy continues to reference section 2.1 for general compliance obligations but omits specific PCI SSF mandates previously included.
Acquirer KYB (Know Your Business) Obligations
Acquirers processing transactions on the Mastercard network are required to perform
Know Your Business (KYB) due diligence on merchants before onboarding and on a
recurring basis thereafter. Halyard Pay, as an acquirer, must collect and verify a
minimum set of documents for each merchant to establish business legitimacy, confirm
beneficial ownership, and satisfy anti-money laundering screening requirements.
When this policy applies
This policy applies to all new merchant onboarding and to all periodic re-verification
reviews. Merchants that fail to supply required documentation within the stipulated
period must be suspended from processing until compliance is restored.
Required actions
-
Collect all required KYB documents at onboarding prior to approval.
-
Conduct AML screening against applicable watchlists before approval.
-
Verify business licenses for regulated merchant categories.
-
Schedule a full re-verification review at least once every 365 days.
-
Document all verification outcomes and retain records for audit purposes.
-
Retain all MATCH system records related to Merchants, Sponsored Merchants, or ATM owners for a minimum of two years after termination or expiration of the applicable agreement, to comply with Mastercard's explicit record retention requirements.
-
Before entering into a Merchant Agreement or enabling a Merchant to accept transactions, Halyard Pay must conduct a MATCH inquiry using the proper Member ID/ICA Number assigned to Halyard Pay to ensure compliance. Failure to perform this check or to use the correct Member ID/ICA may result in noncompliance and assessments by Mastercard.
Note: The previous requirement for detailed PCI Software Security Framework compliance as cited in SPME §2.1.1 has been removed from the Mastercard standards. Halyard Pay's KYB procedures should continue to ensure merchant compliance with PCI standards but need no longer reference detailed PCI Secure Software Program requirements formerly outlined in section 2.1.1.
Source authority: Mastercard SPME §§2.1, 7.1, 11.2.3, 11.2.6.
Acquirer KYB (Know Your Business) Obligations
Acquirers processing transactions on the Mastercard network are required to perform
Know Your Business (KYB) due diligence on merchants before onboarding and on a
recurring basis thereafter. Halyard Pay, as an acquirer, must collect and verify a
minimum set of documents for each merchant to establish business legitimacy, confirm
beneficial ownership, and satisfy anti-money laundering screening requirements.
When this policy applies
This policy applies to all new merchant onboarding and to all periodic re-verification
reviews. Merchants that fail to supply required documentation within the stipulated
period must be suspended from processing until compliance is restored.
Required actions
-
Collect all required KYB documents at onboarding prior to approval.
-
Conduct AML screening against applicable watchlists before approval.
-
Verify business licenses for regulated merchant categories.
-
Schedule a full re-verification review at least once every 365 days.
-
Document all verification outcomes and retain records for audit purposes.
-
Retain all MATCH system records related to Merchants, Sponsored Merchants, or ATM owners for a minimum of two years after termination or expiration of the applicable agreement, to comply with Mastercard's explicit record retention requirements.
-
Before entering into a Merchant Agreement or enabling a Merchant to accept transactions, Halyard Pay must conduct a MATCH inquiry using the proper Member ID/ICA Number assigned to Halyard Pay to ensure compliance. Failure to perform this check or to use the correct Member ID/ICA may result in noncompliance and assessments by Mastercard.
Note: The previous requirement for detailed PCI Software Security Framework compliance as cited in SPME §2.1.1 has been removed from the Mastercard standards. Halyard Pay's KYB procedures should continue to ensure merchant compliance with PCI standards but need no longer reference detailed PCI Secure Software Program requirements formerly outlined in section 2.1.1.
Source authority: Mastercard SPME §§2.1, 7.1, 11.2.3, 11.2.6.
Source authority: Mastercard SPME §2.1.1.
--- a/policies/kyb_acquirer/rules.yaml +++ b/policies/kyb_acquirer/rules.yaml @@ -15,3 +15,4 @@ # Acquirers must perform a MATCH inquiry prior to entering into any Merchant Agreement or enabling a Merchant to accept transactions, as detailed in Mastercard SPME §11.2.3. This inquiry must be conducted using the correct Member ID/ICA Number associated with the Merchant to ensure proper compliance reporting. # Failure to adhere to these requirements may result in noncompliance assessments. # The Acquirer is also required to retain all MATCH records related to any Merchant, Sponsored Merchant, or ATM owner for a minimum of two years post-agreement termination, as per Mastercard SPME §11.2.6. +# The previous detailed requirements on PCI Software Security Framework compliance under Mastercard SPME §2.1.1 have been removed from the current edition. Therefore, this policy continues to reference section 2.1 for general compliance obligations but omits specific PCI SSF mandates previously included. --- a/policies/kyb_acquirer/policy.md +++ b/policies/kyb_acquirer/policy.md @@ -22,4 +22,6 @@ 6. Retain all MATCH system records related to Merchants, Sponsored Merchants, or ATM owners for a minimum of two years after termination or expiration of the applicable agreement, to comply with Mastercard's explicit record retention requirements. 7. Before entering into a Merchant Agreement or enabling a Merchant to accept transactions, Halyard Pay must conduct a MATCH inquiry using the proper Member ID/ICA Number assigned to Halyard Pay to ensure compliance. Failure to perform this check or to use the correct Member ID/ICA may result in noncompliance and assessments by Mastercard. +Note: The previous requirement for detailed PCI Software Security Framework compliance as cited in SPME §2.1.1 has been removed from the Mastercard standards. Halyard Pay's KYB procedures should continue to ensure merchant compliance with PCI standards but need no longer reference detailed PCI Secure Software Program requirements formerly outlined in section 2.1.1. + Source authority: Mastercard SPME §§2.1, 7.1, 11.2.3, 11.2.6.