Mastercard SPME §6.2 · Sep 2023 → Feb 2024
Mastercard Fraud Loss Control Program Standards
The update refines fraud monitoring requirements, notably reducing the technical fallback rate threshold from 5% to 2% for merchant deposit monitoring, adds mandatory reversal of unauthorized refund transactions, and reclassifies some procedural recommendations. These changes strengthen fraud controls and verification processes without altering overall obligations drastically.
program: Fraud Monitoring- authority: Mastercard SPME §3.7, §8.6.6, §11.1.1+ authority: Mastercard SPME §3.7, §8.6.6, §11.1.1, §6.2.2.2, §6.2.2.3fraud_to_sales_ratio_threshold: 0.015min_count_per_month: 100monitoring_cadence: monthlyescalation_actions:- escalate_to_human_review- notify_acquirerlookback_period_months: 1remediation_review_interval_days: 30agent_owner: fraud_ops_agent- # MATCH fraud detection features are limited to principal owners only; associate owners and Service Provider name reporting are removed per SPME §11.1.1.- # Acquirers may add and search for information on up to five principal owners per Merchant.- # Multiple data fields are used to determine matches; MATCH supports editing and error notification to reduce delays.- # Retroactive alert processing is supported for data up to 360 days old.- # Acquirers control receipt and detail of inquiry match information.- # Real-time access via MATCH Online and API, and batch operations remain available.- # Merchant URL information may be added and searched.- # After obtaining MATCH inquiry results, acquirers must assess whether further investigation or risk mitigation actions are warranted, per updated SPME requirements.- #- # New requirements under SPME §8.6.6 specify that Mastercard will add Merchants to MATCH using reason code 24 (Illegal Transactions) when Merchants meet Coercion Program criteria.- # Merchants subject to a subsequent claim of coercion within 12 months will be added with reason code 00 (Questionable Acquirer/Under Investigation).- # If the claim is confirmed to meet Coercion Program criteria, the MATCH record will be updated to reason code 24.- # If not confirmed, the MATCH record will be deleted.- # These provisions enhance fraud monitoring by requiring tracking of coercion-related transaction risks.+ # MATCH fraud detection features remain focused on principal merchant owners only as per SPME §11.1.1.+ # Reason codes for MATCH records include new coercion-related codes per §8.6.6, improving risk tracking.+ # Acquirers must monitor fraud ratios and transaction volumes continuously, evaluate MATCH inquiry results carefully.+ # Updates per SPME §6.2 incorporate tighter controls on transaction monitoring.+ # Notably, the threshold for technical fallback rates triggering alerts has been lowered from 5% to 2% to enhance detection sensitivity.+ # Additionally, reversal of unauthorized Merchant authorization refunds is now required to prevent Fraud Loss.+ # These enhancements promote more proactive detection and mitigation of emerging fraud patterns in Merchant behavior.+ # Acquirers must retain verification records of negative option billing transactions for at least one year, per §6.2.2.2.1.+ # Fraud monitoring must include real-time or near-real-time alerts on multiple parameters such as authorization volumes, approval rates, and BIN attacks per §6.2.2.2.+ # Merchant deposit monitoring alerts must be generated daily, tracking deposit volume changes, ticket sizes, frequency, and technical fallback rates with the updated 2% threshold per §6.2.2.3.+ # The policy ensures compliance with Mastercard SPME's strengthened fraud loss control standards including new merchant deposit and transaction reversal controls.
Fraud Monitoring
Halyard Pay monitors merchant fraud activity and leverages Mastercard's MATCH system for enhanced fraud risk assessment on merchants processed through our platform.
When this policy applies
This policy applies to all merchants processed by Halyard Pay where Mastercard is the applicable network, covering both card-present and card-not-present transactions.
Required actions
-
Compute the merchant's rolling fraud-to-sales ratio each calendar month.
-
If the ratio meets or exceeds 1.5% and the fraud count reaches at least 100 transactions in that month, escalate the merchant account to human review immediately.
-
Utilize Mastercard's MATCH system data focusing on principal owners only, as per
the updatedMastercard SPME guidelines. Do not consider associate owners or Service Provider names in fraud assessments. -
Maintain awareness of Mastercard's MATCH reason codes
relatedrelating to coercion programs: merchants may be added with reason code 24 for illegal transactionsupon meetingwhen coercioncriteria,criteria are met, or with code 00 if a subsequent coercion claim arises within 12 months; update or delete recordsmust be updated or removedbased onconfirmation of these claims.claim verification. -
After accessing MATCH data, conduct a thorough risk assessment to determine
whetherif further investigation or additional measures arewarranted.required. -
Monitor merchant authorization activity using real-time alerts for suspicious patterns, including BIN attacks, repeated authorization requests, abnormal increases in transaction volume or amount, high technical fallback rates above 2%, and unusually high refund volumes.
7. For deposit monitoring, generate daily or real-time alerts to identify increases in merchant deposit volume, average ticket size, frequency of deposits, or technical fallback rates exceeding 2% of total transaction volume.
8. Identify and verify authorization transactions for negative option billing merchants when the same card account is used across multiple merchant IDs within 60 days, retaining verification documents for at least one year.
9. In cases of unauthorized authorization refund transactions, implement reversal procedures in compliance with Mastercard requirements.
10. Notify the acquiring compliance officer and document the case ID with supporting transaction data.
7. 11. Track case progress until the account returns to threshold compliance or is terminated.
Source authority: Mastercard SPME §3.7, §8.6.6, and §11.1.1.§§3.7, 6.2.2.2, 6.2.2.3, 8.6.6, and 11.1.1.
Fraud Monitoring
Halyard Pay monitors merchant fraud activity and leverages Mastercard's MATCH system for enhanced fraud risk assessment on merchants processed through our platform.
When this policy applies
This policy applies to all merchants processed by Halyard Pay where Mastercard is the applicable network, covering both card-present and card-not-present transactions.
Required actions
-
Compute the merchant's rolling fraud-to-sales ratio each calendar month.
-
If the ratio meets or exceeds 1.5% and the fraud count reaches at least 100 transactions in that month, escalate the merchant account to human review immediately.
-
Utilize Mastercard's MATCH system data focusing on principal owners only, as per
the updatedMastercard SPME guidelines. Do not consider associate owners or Service Provider names in fraud assessments. -
Maintain awareness of Mastercard's MATCH reason codes
relatedrelating to coercion programs: merchants may be added with reason code 24 for illegal transactionsupon meetingwhen coercioncriteria,criteria are met, or with code 00 if a subsequent coercion claim arises within 12 months; update or delete recordsmust be updated or removedbased onconfirmation of these claims.claim verification. -
After accessing MATCH data, conduct a thorough risk assessment to determine
whetherif further investigation or additional measures arewarranted.required. -
Monitor merchant authorization activity using real-time alerts for suspicious patterns, including BIN attacks, repeated authorization requests, abnormal increases in transaction volume or amount, high technical fallback rates above 2%, and unusually high refund volumes.
7. For deposit monitoring, generate daily or real-time alerts to identify increases in merchant deposit volume, average ticket size, frequency of deposits, or technical fallback rates exceeding 2% of total transaction volume.
8. Identify and verify authorization transactions for negative option billing merchants when the same card account is used across multiple merchant IDs within 60 days, retaining verification documents for at least one year.
9. In cases of unauthorized authorization refund transactions, implement reversal procedures in compliance with Mastercard requirements.
10. Notify the acquiring compliance officer and document the case ID with supporting transaction data.
7. 11. Track case progress until the account returns to threshold compliance or is terminated.
Source authority: Mastercard SPME §3.7, §8.6.6, and §11.1.1.§§3.7, 6.2.2.2, 6.2.2.3, 8.6.6, and 11.1.1.
Source authority: Mastercard SPME §6.2.
--- a/policies/fraud_monitoring/rules.yaml +++ b/policies/fraud_monitoring/rules.yaml @@ -1,5 +1,5 @@ program: Fraud Monitoring -authority: Mastercard SPME §3.7, §8.6.6, §11.1.1 +authority: Mastercard SPME §3.7, §8.6.6, §11.1.1, §6.2.2.2, §6.2.2.3 fraud_to_sales_ratio_threshold: 0.015 min_count_per_month: 100 monitoring_cadence: monthly @@ -10,17 +10,14 @@ remediation_review_interval_days: 30 agent_owner: fraud_ops_agent -# MATCH fraud detection features are limited to principal owners only; associate owners and Service Provider name reporting are removed per SPME §11.1.1. -# Acquirers may add and search for information on up to five principal owners per Merchant. -# Multiple data fields are used to determine matches; MATCH supports editing and error notification to reduce delays. -# Retroactive alert processing is supported for data up to 360 days old. -# Acquirers control receipt and detail of inquiry match information. -# Real-time access via MATCH Online and API, and batch operations remain available. -# Merchant URL information may be added and searched. -# After obtaining MATCH inquiry results, acquirers must assess whether further investigation or risk mitigation actions are warranted, per updated SPME requirements. -# -# New requirements under SPME §8.6.6 specify that Mastercard will add Merchants to MATCH using reason code 24 (Illegal Transactions) when Merchants meet Coercion Program criteria. -# Merchants subject to a subsequent claim of coercion within 12 months will be added with reason code 00 (Questionable Acquirer/Under Investigation). -# If the claim is confirmed to meet Coercion Program criteria, the MATCH record will be updated to reason code 24. -# If not confirmed, the MATCH record will be deleted. -# These provisions enhance fraud monitoring by requiring tracking of coercion-related transaction risks.+# MATCH fraud detection features remain focused on principal merchant owners only as per SPME §11.1.1. +# Reason codes for MATCH records include new coercion-related codes per §8.6.6, improving risk tracking. +# Acquirers must monitor fraud ratios and transaction volumes continuously, evaluate MATCH inquiry results carefully. +# Updates per SPME §6.2 incorporate tighter controls on transaction monitoring. +# Notably, the threshold for technical fallback rates triggering alerts has been lowered from 5% to 2% to enhance detection sensitivity. +# Additionally, reversal of unauthorized Merchant authorization refunds is now required to prevent Fraud Loss. +# These enhancements promote more proactive detection and mitigation of emerging fraud patterns in Merchant behavior. +# Acquirers must retain verification records of negative option billing transactions for at least one year, per §6.2.2.2.1. +# Fraud monitoring must include real-time or near-real-time alerts on multiple parameters such as authorization volumes, approval rates, and BIN attacks per §6.2.2.2. +# Merchant deposit monitoring alerts must be generated daily, tracking deposit volume changes, ticket sizes, frequency, and technical fallback rates with the updated 2% threshold per §6.2.2.3. +# The policy ensures compliance with Mastercard SPME's strengthened fraud loss control standards including new merchant deposit and transaction reversal controls. --- a/policies/fraud_monitoring/policy.md +++ b/policies/fraud_monitoring/policy.md @@ -10,10 +10,14 @@ 1. Compute the merchant's rolling fraud-to-sales ratio each calendar month. 2. If the ratio meets or exceeds 1.5% and the fraud count reaches at least 100 transactions in that month, escalate the merchant account to human review immediately. -3. Utilize Mastercard's MATCH system data focusing on principal owners only, as per the updated Mastercard SPME guidelines. Do not consider associate owners or Service Provider names in fraud assessments. -4. Maintain awareness of Mastercard's MATCH reason codes related to coercion programs: merchants may be added with reason code 24 for illegal transactions upon meeting coercion criteria, or with code 00 if a subsequent coercion claim arises within 12 months; records must be updated or removed based on confirmation of these claims. -5. After accessing MATCH data, conduct a risk assessment to determine whether further investigation or additional measures are warranted. -6. Notify the acquiring compliance officer and document the case ID with supporting transaction data. -7. Track case progress until the account returns to threshold compliance or is terminated. +3. Utilize Mastercard's MATCH system data focusing on principal owners only, as per Mastercard SPME guidelines. Do not consider associate owners or Service Provider names in fraud assessments. +4. Maintain awareness of Mastercard's MATCH reason codes relating to coercion programs: merchants may be added with reason code 24 for illegal transactions when coercion criteria are met, or with code 00 if a subsequent coercion claim arises within 12 months; update or delete records based on claim verification. +5. After accessing MATCH data, conduct a thorough risk assessment to determine if further investigation or additional measures are required. +6. Monitor merchant authorization activity using real-time alerts for suspicious patterns, including BIN attacks, repeated authorization requests, abnormal increases in transaction volume or amount, high technical fallback rates above 2%, and unusually high refund volumes. +7. For deposit monitoring, generate daily or real-time alerts to identify increases in merchant deposit volume, average ticket size, frequency of deposits, or technical fallback rates exceeding 2% of total transaction volume. +8. Identify and verify authorization transactions for negative option billing merchants when the same card account is used across multiple merchant IDs within 60 days, retaining verification documents for at least one year. +9. In cases of unauthorized authorization refund transactions, implement reversal procedures in compliance with Mastercard requirements. +10. Notify the acquiring compliance officer and document the case ID with supporting transaction data. +11. Track case progress until the account returns to threshold compliance or is terminated. -Source authority: Mastercard SPME §3.7, §8.6.6, and §11.1.1. +Source authority: Mastercard SPME §§3.7, 6.2.2.2, 6.2.2.3, 8.6.6, and 11.1.1.