Mastercard SPME §2.2.1 · Sep 2023 → Feb 2024
Customer Compliance Requirements
The updated section adds explicit obligations for Issuers to communicate SDP Program requirements to Level 1 and 2 Service Providers and validate their PCI DSS compliance by reviewing SAQs or ROCs. Issuers must also submit annual PCI compliance validation to Mastercard, and address non-compliance with an action plan. This was not previously required.
Compliance with the PCI DSS is required for all Issuers and Acquirers, although validation of the Customer’s compliance is not required. Cybersecurity Standards and Programs
Compliance with the PCI DSS is required for all Issuers and Acquirers, although validation of the Customer’s compliance is not required. To ensure compliance with the Mastercard SDP Program, an Issuer must:
- Communicate the SDP Program requirements to each Level 1 and Level 2 Service Provider, and validate the Service Provider’s compliance with the PCI DSS and any other applicable PCI Security Standard by reviewing the Payment Card Industry Self-Assessment Questionnaire (SAQ) or the Report on Compliance (ROC).
- Submit the annual PCI compliance validation (the PCI Attestation of Compliance [AOC]) for each Level 1 and Level 2 Service Provider by email message to pcireports@mastercard.com, after initial registration with Mastercard and every year thereafter. If a newly registered Service Provider is not yet compliant, the PCI Action Plan available on the Service Provider page of the SDP Program website must be completed and submitted for review. To ensure compliance with the Mastercard SDP Program, an Acquirer must: Cybersecurity Standards and Programs
program: Acquirer KYB- authority: Mastercard SPME 2.1, 11.2.3, 11.2.6+ authority: Mastercard SPME 2.1, 2.2.1, 11.2.3, 11.2.6required_documents:- incorporation- beneficial_ownership- aml_screen- license_verificationmin_review_cycle_days: 365suspension_trigger: document_collection_failurerecord_retention_years: 7aml_watchlist_sources:- ofac_sdn- eu_consolidatedagent_owner: kyb_agent# Acquirers must perform a MATCH inquiry prior to entering into any Merchant Agreement or enabling a Merchant to accept transactions, as detailed in Mastercard SPME §11.2.3. This inquiry must be conducted using the correct Member ID/ICA Number associated with the Merchant to ensure proper compliance reporting.# Failure to adhere to these requirements may result in noncompliance assessments.# The Acquirer is also required to retain all MATCH records related to any Merchant, Sponsored Merchant, or ATM owner for a minimum of two years post-agreement termination, as per Mastercard SPME §11.2.6.+ # As per Mastercard SPME §2.2.1, Acquirers must ensure that all relevant Level 1 and Level 2 Service Providers meet PCI DSS compliance requirements by verifying their Payment Card Industry Self-Assessment Questionnaire (SAQ) or Report on Compliance (ROC) documentation, aligning with Mastercard's SDP Program obligations.+ #+ # Additionally, the annual PCI compliance validation (Attestation of Compliance, AOC) must be obtained and managed accordingly to maintain compliance status with Mastercard's cybersecurity standards.
Acquirer KYB (Know Your Business) Obligations
Acquirers processing transactions on the Mastercard network are required to perform
Know Your Business (KYB) due diligence on merchants before onboarding and on a
recurring basis thereafter. Halyard Pay, as an acquirer, must collect and verify a
minimum set of documents for each merchant to establish business legitimacy, confirm
beneficial ownership, and satisfy anti-money laundering screening requirements.
When this policy applies
This policy applies to all new merchant onboarding and to all periodic re-verification
reviews. Merchants that fail to supply required documentation within the stipulated
period must be suspended from processing until compliance is restored.
Required actions
-
Collect all required KYB documents at onboarding prior to approval.
-
Conduct AML screening against applicable watchlists before approval.
-
Verify business licenses for regulated merchant categories.
-
Schedule a full re-verification review at least once every 365 days.
-
Document all verification outcomes and retain records for audit purposes.
-
Retain all MATCH system records related to Merchants, Sponsored Merchants, or ATM owners for a minimum of two years after termination or expiration of the applicable agreement, to comply with Mastercard's explicit record retention requirements.
-
Before entering into a Merchant Agreement or enabling a Merchant to accept transactions, Halyard Pay must conduct a MATCH inquiry using the proper Member ID/ICA Number assigned to Halyard Pay to ensure compliance. Failure to perform this check or to use the correct Member ID/ICA may result in noncompliance and assessments by Mastercard.
8. Ensure compliance with Mastercard's Service Provider Directory Program (SDP) by requiring that Level 1 and Level 2 Service Providers communicate and validate PCI DSS compliance through the Payment Card Industry Self-Assessment Questionnaire (SAQ) or Report on Compliance (ROC). Maintain records of annual PCI Attestation of Compliance (AOC) submissions for these Service Providers.
Source authority: Mastercard SPME §§2.1, 2.2.1, 7.1, 11.2.3, 11.2.6.
Acquirer KYB (Know Your Business) Obligations
Acquirers processing transactions on the Mastercard network are required to perform
Know Your Business (KYB) due diligence on merchants before onboarding and on a
recurring basis thereafter. Halyard Pay, as an acquirer, must collect and verify a
minimum set of documents for each merchant to establish business legitimacy, confirm
beneficial ownership, and satisfy anti-money laundering screening requirements.
When this policy applies
This policy applies to all new merchant onboarding and to all periodic re-verification
reviews. Merchants that fail to supply required documentation within the stipulated
period must be suspended from processing until compliance is restored.
Required actions
-
Collect all required KYB documents at onboarding prior to approval.
-
Conduct AML screening against applicable watchlists before approval.
-
Verify business licenses for regulated merchant categories.
-
Schedule a full re-verification review at least once every 365 days.
-
Document all verification outcomes and retain records for audit purposes.
-
Retain all MATCH system records related to Merchants, Sponsored Merchants, or ATM owners for a minimum of two years after termination or expiration of the applicable agreement, to comply with Mastercard's explicit record retention requirements.
-
Before entering into a Merchant Agreement or enabling a Merchant to accept transactions, Halyard Pay must conduct a MATCH inquiry using the proper Member ID/ICA Number assigned to Halyard Pay to ensure compliance. Failure to perform this check or to use the correct Member ID/ICA may result in noncompliance and assessments by Mastercard.
8. Ensure compliance with Mastercard's Service Provider Directory Program (SDP) by requiring that Level 1 and Level 2 Service Providers communicate and validate PCI DSS compliance through the Payment Card Industry Self-Assessment Questionnaire (SAQ) or Report on Compliance (ROC). Maintain records of annual PCI Attestation of Compliance (AOC) submissions for these Service Providers.
Source authority: Mastercard SPME §§2.1, 2.2.1, 7.1, 11.2.3, 11.2.6.
Source authority: Mastercard SPME §2.2.1.
--- a/policies/kyb_acquirer/rules.yaml +++ b/policies/kyb_acquirer/rules.yaml @@ -1,5 +1,5 @@ program: Acquirer KYB -authority: Mastercard SPME 2.1, 11.2.3, 11.2.6 +authority: Mastercard SPME 2.1, 2.2.1, 11.2.3, 11.2.6 required_documents: - incorporation - beneficial_ownership @@ -15,3 +15,6 @@ # Acquirers must perform a MATCH inquiry prior to entering into any Merchant Agreement or enabling a Merchant to accept transactions, as detailed in Mastercard SPME §11.2.3. This inquiry must be conducted using the correct Member ID/ICA Number associated with the Merchant to ensure proper compliance reporting. # Failure to adhere to these requirements may result in noncompliance assessments. # The Acquirer is also required to retain all MATCH records related to any Merchant, Sponsored Merchant, or ATM owner for a minimum of two years post-agreement termination, as per Mastercard SPME §11.2.6. +# As per Mastercard SPME §2.2.1, Acquirers must ensure that all relevant Level 1 and Level 2 Service Providers meet PCI DSS compliance requirements by verifying their Payment Card Industry Self-Assessment Questionnaire (SAQ) or Report on Compliance (ROC) documentation, aligning with Mastercard's SDP Program obligations. +# +# Additionally, the annual PCI compliance validation (Attestation of Compliance, AOC) must be obtained and managed accordingly to maintain compliance status with Mastercard's cybersecurity standards. --- a/policies/kyb_acquirer/policy.md +++ b/policies/kyb_acquirer/policy.md @@ -21,5 +21,6 @@ 5. Document all verification outcomes and retain records for audit purposes. 6. Retain all MATCH system records related to Merchants, Sponsored Merchants, or ATM owners for a minimum of two years after termination or expiration of the applicable agreement, to comply with Mastercard's explicit record retention requirements. 7. Before entering into a Merchant Agreement or enabling a Merchant to accept transactions, Halyard Pay must conduct a MATCH inquiry using the proper Member ID/ICA Number assigned to Halyard Pay to ensure compliance. Failure to perform this check or to use the correct Member ID/ICA may result in noncompliance and assessments by Mastercard. +8. Ensure compliance with Mastercard's Service Provider Directory Program (SDP) by requiring that Level 1 and Level 2 Service Providers communicate and validate PCI DSS compliance through the Payment Card Industry Self-Assessment Questionnaire (SAQ) or Report on Compliance (ROC). Maintain records of annual PCI Attestation of Compliance (AOC) submissions for these Service Providers. -Source authority: Mastercard SPME §§2.1, 7.1, 11.2.3, 11.2.6.+Source authority: Mastercard SPME §§2.1, 2.2.1, 7.1, 11.2.3, 11.2.6.