Mastercard SPME §2.2.5 · Sep 2023 → Feb 2024
SDP Program Noncompliance Assessments
The section changed from describing forensic investigation response and PCI DSS compliance deadlines to detailing specific monetary penalties for failing to comply with the SDP Program by merchant or service provider level. It also added potential consequences like merchant termination and deregistration from MasterCard programs for noncompliance.
Security Rules and Procedures—Merchant Edition • 1 August 2023
At the conclusion of the forensic investigation, Mastercard will provide a Mastercard Site Data Protection (SDP) Account Data Compromise Information Form for completion by the compromised entity itself, if the compromised entity is a Service Provider, or by its Acquirer, if the compromised entity is a Merchant. The form must be returned by email message to pci_adc@mastercard.com within 30 calendar days of its receipt, and must include:
- The names of the forensic investigator, QSA and the Approved Scanning Vendor (ASV);
- The entity’s current level of compliance; and
- A gap analysis providing detailed steps required for the entity to achieve full compliance. PCI DSS Compliance As soon as practical, but no later than the PCI DSS compliance deadline shown in Table 2.3, the compromised entity or its Acquirer must provide evidence of compliance to Mastercard that the compromised entity has achieved full compliance with the PCI DSS. Table 2.3 PCI DSS Compliance Deadlines and Evidence of Compliance for Compromised Entities Classification PCI DSS Compliance deadline from the Conclusion of the Forensic Investigation Evidence of Compliance Service Providers 90 calendar days Both of the following:
- PCI DSS ROC AOC conducted by a PCI SSC-approved QSA; and
- DESV Supplemental ROC (S- ROC) AOC conducted by a PCI SSC-approved QSA within twelve (12) months from achieving full compliance with the PCI DSS Level 1 or Level 2 Merchants 180 calendar days PCI DSS ROC AOC conducted by a PCI SSC-approved QSA Level 3 or Level 4 Merchants 180 calendar days Either of the following:
- PCI DSS ROC AOC conducted by a PCI SSC-approved QSA; or
- PCI DSS SAQ AOC Evidence of compliance for compromised entities must be submitted to Mastercard by email message to pci_adc@mastercard.com no later than the PCI DSS compliance deadline shown in Table 2.3. Cybersecurity Standards and Programs
Security Rules and Procedures—Merchant Edition • 6 February 2024
Table 2.2—Assessments for Noncompliance with the SDP Program Failure of the following to comply with the SDP Program mandate... May result in an assessment of... Classification Violations per calendar year Level 1 and Level 2 Merchants Up to USD 25,000 for the first violation Up to USD 50,000 for the second violation Up to USD 100,000 for the third violation Up to USD 200,000 for the fourth violation Level 3 Merchants Up to USD 10,000 for the first violation Up to USD 20,000 for the second violation Up to USD 40,000 for the third violation Up to USD 80,000 for the fourth violation Level 1 and Level 2 Service Providers Up to USD 25,000 for the first violation Up to USD 50,000 for the second violation Up to USD 100,000 for the third violation Up to USD 200,000 for the fourth violation Noncompliance also may result in Merchant termination; deregistration of a TPP, DSE, PF, SDWO, DASP, TSP, TS, AML/Sanctions Service Provider, 3-DSSP, ISP, or MPG as a Service Provider; delisting of a Service Provider from The Mastercard SDP Compliant Registered Service Provider List; or termination of the Issuer or Acquirer as a Customer as provided in Rule 2.1.2 of the Mastercard Rules manual. Late SDP Acquirer Submission and Compliance Status Forms for semi-annual merchant compliance reporting submissions or failure to submit the required form(s) may result in an additional assessment to the Customer as described for Category A violations in Rule 2.1.4 of the Mastercard Rules manual.
program: Acquirer KYB- authority: Mastercard SPME 2.1, 11.2.3, 11.2.6+ authority: Mastercard SPME 2.1, 2.2.5, 11.2.3, 11.2.6required_documents:- incorporation- beneficial_ownership- aml_screen- license_verificationmin_review_cycle_days: 365suspension_trigger: document_collection_failurerecord_retention_years: 7aml_watchlist_sources:- ofac_sdn- eu_consolidatedagent_owner: kyb_agent# Acquirers must perform a MATCH inquiry prior to entering into any Merchant Agreement or enabling a Merchant to accept transactions, as detailed in Mastercard SPME §11.2.3. This inquiry must be conducted using the correct Member ID/ICA Number associated with the Merchant to ensure proper compliance reporting.- # Failure to adhere to these requirements may result in noncompliance assessments.- # The Acquirer is also required to retain all MATCH records related to any Merchant, Sponsored Merchant, or ATM owner for a minimum of two years post-agreement termination, as per Mastercard SPME §11.2.6.+ # The Acquirer is required to retain all MATCH records related to any Merchant, Sponsored Merchant, or ATM owner for a minimum of two years post-agreement termination, as per Mastercard SPME §11.2.6.+ # Updated Mastercard SPME §2.2.5 introduces escalating monetary penalties and potential merchant termination or deregistration as consequences for failure to comply with the SDP Program mandates. Acquirers must enforce compliance diligently and ensure timely submission of SDP compliance and reporting forms per Mastercard requirements to avoid these sanctions.
Acquirer KYB (Know Your Business) Obligations
Acquirers processing transactions on the Mastercard network are required to perform
Know Your Business (KYB) due diligence on merchants before onboarding and on a
recurring basis thereafter. Halyard Pay, as an acquirer, must collect and verify a
minimum set of documents for each merchant to establish business legitimacy, confirm
beneficial ownership, and satisfy anti-money laundering screening requirements.
When this policy applies
This policy applies to all new merchant onboarding and to all periodic re-verification
reviews. Merchants that fail to supply required documentation within the stipulated
period must be suspended from processing until compliance is restored.
Required actions
-
Collect all required KYB documents at onboarding prior to approval.
-
Conduct AML screening against applicable watchlists before approval.
-
Verify business licenses for regulated merchant categories.
-
Schedule a full re-verification review at least once every 365 days.
-
Document all verification outcomes and retain records for audit purposes.
-
Retain all MATCH system records related to Merchants, Sponsored Merchants, or ATM owners for a minimum of two years after termination or expiration of the applicable agreement, to comply with Mastercard's explicit record retention requirements.
-
Before entering into a Merchant Agreement or enabling a Merchant to accept transactions, Halyard Pay must conduct a MATCH inquiry using the proper Member ID/ICA Number assigned to Halyard Pay to ensure compliance. Failure to perform this check or to use the correct Member ID/ICA may result in noncompliance and assessments by Mastercard.
8. Ensure prompt and full compliance with the Site Data Protection (SDP) program requirements, including timely submission of required compliance evidence. Noncompliance may lead to escalating financial penalties, merchant termination, or deregistration of involved parties as mandated by Mastercard.
Source authority: Mastercard SPME §§2.1, 2.2.5, 7.1, 11.2.3, 11.2.6.
Acquirer KYB (Know Your Business) Obligations
Acquirers processing transactions on the Mastercard network are required to perform
Know Your Business (KYB) due diligence on merchants before onboarding and on a
recurring basis thereafter. Halyard Pay, as an acquirer, must collect and verify a
minimum set of documents for each merchant to establish business legitimacy, confirm
beneficial ownership, and satisfy anti-money laundering screening requirements.
When this policy applies
This policy applies to all new merchant onboarding and to all periodic re-verification
reviews. Merchants that fail to supply required documentation within the stipulated
period must be suspended from processing until compliance is restored.
Required actions
-
Collect all required KYB documents at onboarding prior to approval.
-
Conduct AML screening against applicable watchlists before approval.
-
Verify business licenses for regulated merchant categories.
-
Schedule a full re-verification review at least once every 365 days.
-
Document all verification outcomes and retain records for audit purposes.
-
Retain all MATCH system records related to Merchants, Sponsored Merchants, or ATM owners for a minimum of two years after termination or expiration of the applicable agreement, to comply with Mastercard's explicit record retention requirements.
-
Before entering into a Merchant Agreement or enabling a Merchant to accept transactions, Halyard Pay must conduct a MATCH inquiry using the proper Member ID/ICA Number assigned to Halyard Pay to ensure compliance. Failure to perform this check or to use the correct Member ID/ICA may result in noncompliance and assessments by Mastercard.
8. Ensure prompt and full compliance with the Site Data Protection (SDP) program requirements, including timely submission of required compliance evidence. Noncompliance may lead to escalating financial penalties, merchant termination, or deregistration of involved parties as mandated by Mastercard.
Source authority: Mastercard SPME §§2.1, 2.2.5, 7.1, 11.2.3, 11.2.6.
Source authority: Mastercard SPME §2.2.5.
--- a/policies/kyb_acquirer/rules.yaml +++ b/policies/kyb_acquirer/rules.yaml @@ -1,5 +1,5 @@ program: Acquirer KYB -authority: Mastercard SPME 2.1, 11.2.3, 11.2.6 +authority: Mastercard SPME 2.1, 2.2.5, 11.2.3, 11.2.6 required_documents: - incorporation - beneficial_ownership @@ -13,5 +13,5 @@ - eu_consolidated agent_owner: kyb_agent # Acquirers must perform a MATCH inquiry prior to entering into any Merchant Agreement or enabling a Merchant to accept transactions, as detailed in Mastercard SPME §11.2.3. This inquiry must be conducted using the correct Member ID/ICA Number associated with the Merchant to ensure proper compliance reporting. -# Failure to adhere to these requirements may result in noncompliance assessments. -# The Acquirer is also required to retain all MATCH records related to any Merchant, Sponsored Merchant, or ATM owner for a minimum of two years post-agreement termination, as per Mastercard SPME §11.2.6. +# The Acquirer is required to retain all MATCH records related to any Merchant, Sponsored Merchant, or ATM owner for a minimum of two years post-agreement termination, as per Mastercard SPME §11.2.6. +# Updated Mastercard SPME §2.2.5 introduces escalating monetary penalties and potential merchant termination or deregistration as consequences for failure to comply with the SDP Program mandates. Acquirers must enforce compliance diligently and ensure timely submission of SDP compliance and reporting forms per Mastercard requirements to avoid these sanctions. --- a/policies/kyb_acquirer/policy.md +++ b/policies/kyb_acquirer/policy.md @@ -21,5 +21,6 @@ 5. Document all verification outcomes and retain records for audit purposes. 6. Retain all MATCH system records related to Merchants, Sponsored Merchants, or ATM owners for a minimum of two years after termination or expiration of the applicable agreement, to comply with Mastercard's explicit record retention requirements. 7. Before entering into a Merchant Agreement or enabling a Merchant to accept transactions, Halyard Pay must conduct a MATCH inquiry using the proper Member ID/ICA Number assigned to Halyard Pay to ensure compliance. Failure to perform this check or to use the correct Member ID/ICA may result in noncompliance and assessments by Mastercard. +8. Ensure prompt and full compliance with the Site Data Protection (SDP) program requirements, including timely submission of required compliance evidence. Noncompliance may lead to escalating financial penalties, merchant termination, or deregistration of involved parties as mandated by Mastercard. -Source authority: Mastercard SPME §§2.1, 7.1, 11.2.3, 11.2.6.+Source authority: Mastercard SPME §§2.1, 2.2.5, 7.1, 11.2.3, 11.2.6.