Mastercard SPME §2.1.1 · Sep 2023 → Feb 2024

Payment Card Industry (PCI) Security Standards

breaking
⚠ Extraction warning — review against source PDF. One side of the Mastercard SPME text below appears to contain only the page-running header, not body content. This usually means the section heading fell on a page boundary and the body was attributed to a neighbouring section in the source PDF. The AI summary and proposed edit below may be misleading. Verify in: Sep 2023 · page 17 ↗ · Feb 2024 · page 16 ↗.

The entire detailed text about PCI Software Security Framework and compliance recommendations has been removed from the section, leaving only the general document header without content.

Sources Mastercard SPME · Sep 2023 · page 17 PDF Mastercard SPME · Feb 2024 · page 16 PDF KYB Acquirer current
Also in §2.x this release substantive §2.2.1 Customer Compliance Requirements substantive §2.2.3 Service Provider Compliance Requirements substantive §2.2.5 SDP Program Noncompliance Assessments
Why these edits? The removal of detailed PCI Software Security Framework compliance requirements in section 2.1.1 affects the Acquirer KYB Obligations policy, which cites section 2.1 and involves ensuring compliance with PCI standards for merchants and service providers.
Mastercard SPME §2.1.1
This section was substantively restructured between versions (13% text overlap). Compare the texts directly below.
Before · Sep 2023 · page 17

Security Rules and Procedures—Merchant Edition • 1 August 2023

PCI Security Standard Compliance Requirements and Recommendations PCI Software Security Framework (SSF)—PCI Secure Software Requirements and Assessment Procedures (“PCI Secure Software Standard”) Compliance is required for all Merchants and Service Providers that use eligible third party- provided payment software. Refer to the PCI Secure Software Program Guide for information about the applicability of the PCI Secure Software Standard to third party-provided payment software. PCI Software Security Framework (SSF)—PCI Secure Software Lifecycle (Secure SLC) Requirements and Assessment Procedures (“PCI Secure SLC Standard”) Compliance is strongly recommended for any Merchant or Service Provider that uses third party- provided payment software.

After · Feb 2024 · page 16

Security Rules and Procedures—Merchant Edition • 6 February 2024

Halyard Pay · 2 files
program: Acquirer KYB
authority: Mastercard SPME 2.1, 11.2.3, 11.2.6
required_documents:
- incorporation
- beneficial_ownership
- aml_screen
- license_verification
min_review_cycle_days: 365
suspension_trigger: document_collection_failure
record_retention_years: 7
aml_watchlist_sources:
- ofac_sdn
- eu_consolidated
agent_owner: kyb_agent
# Acquirers must perform a MATCH inquiry prior to entering into any Merchant Agreement or enabling a Merchant to accept transactions, as detailed in Mastercard SPME §11.2.3. This inquiry must be conducted using the correct Member ID/ICA Number associated with the Merchant to ensure proper compliance reporting.
# Failure to adhere to these requirements may result in noncompliance assessments.
# The Acquirer is also required to retain all MATCH records related to any Merchant, Sponsored Merchant, or ATM owner for a minimum of two years post-agreement termination, as per Mastercard SPME §11.2.6.
+ # The previous detailed requirements on PCI Software Security Framework compliance under Mastercard SPME §2.1.1 have been removed from the current edition. Therefore, this policy continues to reference section 2.1 for general compliance obligations but omits specific PCI SSF mandates previously included.

Acquirer KYB (Know Your Business) Obligations

Acquirers processing transactions on the Mastercard network are required to perform

Know Your Business (KYB) due diligence on merchants before onboarding and on a

recurring basis thereafter. Halyard Pay, as an acquirer, must collect and verify a

minimum set of documents for each merchant to establish business legitimacy, confirm

beneficial ownership, and satisfy anti-money laundering screening requirements.

When this policy applies

This policy applies to all new merchant onboarding and to all periodic re-verification

reviews. Merchants that fail to supply required documentation within the stipulated

period must be suspended from processing until compliance is restored.

Required actions

  1. Collect all required KYB documents at onboarding prior to approval.

  2. Conduct AML screening against applicable watchlists before approval.

  3. Verify business licenses for regulated merchant categories.

  4. Schedule a full re-verification review at least once every 365 days.

  5. Document all verification outcomes and retain records for audit purposes.

  6. Retain all MATCH system records related to Merchants, Sponsored Merchants, or ATM owners for a minimum of two years after termination or expiration of the applicable agreement, to comply with Mastercard's explicit record retention requirements.

  7. Before entering into a Merchant Agreement or enabling a Merchant to accept transactions, Halyard Pay must conduct a MATCH inquiry using the proper Member ID/ICA Number assigned to Halyard Pay to ensure compliance. Failure to perform this check or to use the correct Member ID/ICA may result in noncompliance and assessments by Mastercard.

Note: The previous requirement for detailed PCI Software Security Framework compliance as cited in SPME §2.1.1 has been removed from the Mastercard standards. Halyard Pay's KYB procedures should continue to ensure merchant compliance with PCI standards but need no longer reference detailed PCI Secure Software Program requirements formerly outlined in section 2.1.1.

Source authority: Mastercard SPME §§2.1, 7.1, 11.2.3, 11.2.6.

policies/kyb_acquirer/policy.md — after applying change

Acquirer KYB (Know Your Business) Obligations

Acquirers processing transactions on the Mastercard network are required to perform

Know Your Business (KYB) due diligence on merchants before onboarding and on a

recurring basis thereafter. Halyard Pay, as an acquirer, must collect and verify a

minimum set of documents for each merchant to establish business legitimacy, confirm

beneficial ownership, and satisfy anti-money laundering screening requirements.

When this policy applies

This policy applies to all new merchant onboarding and to all periodic re-verification

reviews. Merchants that fail to supply required documentation within the stipulated

period must be suspended from processing until compliance is restored.

Required actions

  1. Collect all required KYB documents at onboarding prior to approval.

  2. Conduct AML screening against applicable watchlists before approval.

  3. Verify business licenses for regulated merchant categories.

  4. Schedule a full re-verification review at least once every 365 days.

  5. Document all verification outcomes and retain records for audit purposes.

  6. Retain all MATCH system records related to Merchants, Sponsored Merchants, or ATM owners for a minimum of two years after termination or expiration of the applicable agreement, to comply with Mastercard's explicit record retention requirements.

  7. Before entering into a Merchant Agreement or enabling a Merchant to accept transactions, Halyard Pay must conduct a MATCH inquiry using the proper Member ID/ICA Number assigned to Halyard Pay to ensure compliance. Failure to perform this check or to use the correct Member ID/ICA may result in noncompliance and assessments by Mastercard.

Note: The previous requirement for detailed PCI Software Security Framework compliance as cited in SPME §2.1.1 has been removed from the Mastercard standards. Halyard Pay's KYB procedures should continue to ensure merchant compliance with PCI standards but need no longer reference detailed PCI Secure Software Program requirements formerly outlined in section 2.1.1.

Source authority: Mastercard SPME §§2.1, 7.1, 11.2.3, 11.2.6.

Source authority: Mastercard SPME §2.1.1.

--- a/policies/kyb_acquirer/rules.yaml
+++ b/policies/kyb_acquirer/rules.yaml
@@ -15,3 +15,4 @@
 # Acquirers must perform a MATCH inquiry prior to entering into any Merchant Agreement or enabling a Merchant to accept transactions, as detailed in Mastercard SPME §11.2.3. This inquiry must be conducted using the correct Member ID/ICA Number associated with the Merchant to ensure proper compliance reporting.
 # Failure to adhere to these requirements may result in noncompliance assessments.
 # The Acquirer is also required to retain all MATCH records related to any Merchant, Sponsored Merchant, or ATM owner for a minimum of two years post-agreement termination, as per Mastercard SPME §11.2.6.
+# The previous detailed requirements on PCI Software Security Framework compliance under Mastercard SPME §2.1.1 have been removed from the current edition. Therefore, this policy continues to reference section 2.1 for general compliance obligations but omits specific PCI SSF mandates previously included.

--- a/policies/kyb_acquirer/policy.md
+++ b/policies/kyb_acquirer/policy.md
@@ -22,4 +22,6 @@
 6. Retain all MATCH system records related to Merchants, Sponsored Merchants, or ATM owners for a minimum of two years after termination or expiration of the applicable agreement, to comply with Mastercard's explicit record retention requirements.
 7. Before entering into a Merchant Agreement or enabling a Merchant to accept transactions, Halyard Pay must conduct a MATCH inquiry using the proper Member ID/ICA Number assigned to Halyard Pay to ensure compliance. Failure to perform this check or to use the correct Member ID/ICA may result in noncompliance and assessments by Mastercard.
 
+Note: The previous requirement for detailed PCI Software Security Framework compliance as cited in SPME §2.1.1 has been removed from the Mastercard standards. Halyard Pay's KYB procedures should continue to ensure merchant compliance with PCI standards but need no longer reference detailed PCI Secure Software Program requirements formerly outlined in section 2.1.1.
+
 Source authority: Mastercard SPME §§2.1, 7.1, 11.2.3, 11.2.6.