Mastercard SPME §8.4.2 · Sep 2023 → Feb 2024
Mastercard Commencement of an Investigation
The section was overhauled: previously, issuers notified Mastercard about questionable merchants via a web form with detailed info. Now, Mastercard initiates investigations, notifying issuers with transaction details, requiring issuers to report fraud within 60 days. Different processes apply if issues involve bust-out accounts or not, with Brazil having a unique reporting rule.
Security Rules and Procedures—Merchant Edition • 1 August 2023
The QMAP Issuer Referral Form, completed by the Issuer, is available on Mastercard Connect > Support > Form. Transactions that occurred during the Case Scope Period may qualify as eligible for recovery under the QMAP. Effective 1 January 2022, if an Issuer has reason to believe that a Merchant may be a Questionable Merchant, the Issuer may notify Mastercard by web-based form at https:// form.mastercard.com/jfe/form/SV_01AtAPzF9FXjzrD. Transactions that occurred during the Case Scope Period may qualify as eligible for recovery under the QMAP. In the notification, the Issuer must provide the basis for the Issuer’s reason to believe that the Merchant may be a Questionable Merchant, and must provide all of the following information:
- Issuer name and Member ID;
- Acquirer name and Member ID;
- Merchant name and address (city, state or province, and country);
- Total number of Transactions conducted at the Questionable Merchant by the Issuer’s Cardholders;
- Total dollar volume of Issuer losses at the Questionable Merchant;
- Percentage of Transactions attributed to Cardholder bust-out accounts, if applicable; and
- Details of each Issuer-confirmed fraudulent Transaction, including Cardholder account number, Transaction date and time, and Transaction amount in U.S. dollars. Mastercard may charge the Issuer a filing fee for each Merchant notification at the commencement of a QMAP investigation as described in section 8.4.9 of this manual. If an Acquirer becomes aware that it is acquiring for a Questionable Merchant, the Acquirer must notify Mastercard promptly by email message at qmap@mastercard.com.
Security Rules and Procedures—Merchant Edition • 6 February 2024
8.4.3.1 Investigations Concerning Cardholder Bust-out Accounts If Mastercard commences a QMAP investigation concerning Cardholder bust-out accounts, Mastercard will notify an Issuer that Mastercard determines had accounts used in Transactions with the Merchant being investigated during the Case Scope Period. The notification will be sent by email message to the Issuer’s Security Contact then listed in the Company Contact Management application available on Mastercard Connect. With the notification, Mastercard will provide details of Transactions arising from use of the Issuer’s accounts at the Merchant during the Case Scope Period. Within 60 days following such notice, an Issuer must report to the Fraud and Loss Database all fraudulent Transactions conducted during the Case Scope Period associated with the Merchant being investigated. Transactions conducted on Cardholder bust-out accounts should be reported using fraud type code 51 (Bust-out Collusive Merchant). NOTE: To accelerate the determination by Mastercard of whether a Merchant is a Questionable Merchant, Issuers are urged to report fraudulent Transactions to the Fraud and Loss Database as expeditiously as feasible. For purposes of making such a determination, Mastercard only considers Transactions that take place (and the resulting fraudulent Transactions timely reported to the Fraud and Loss Database) during the Case Scope Period. 8.4.3.2 Investigations Not Concerning Cardholder Bust-out Accounts If Mastercard commences a QMAP investigation not concerning Cardholder bust-out accounts, Mastercard will notify an Issuer that Mastercard determines had accounts used in Transactions with the Merchant being investigated during the Case Scope Period only if Mastercard determines that the Merchant is a Questionable Merchant. The notification will be sent by email message to the Issuer's Security Contact then listed in the Company Contact Management application available on Mastercard Connect. For Brazil: Instead of sending each Issuer a notice, Mastercard will rely on the fraud reported under Fraud Code 56.
program: Fraud Monitoring- authority: Mastercard SPME §3.7, §8.6.6, §11.1.1+ authority: Mastercard SPME 8.4.3fraud_to_sales_ratio_threshold: 0.015min_count_per_month: 100monitoring_cadence: monthlyescalation_actions:- escalate_to_human_review- notify_acquirerlookback_period_months: 1remediation_review_interval_days: 30agent_owner: fraud_ops_agent- # MATCH fraud detection features are limited to principal owners only; associate owners and Service Provider name reporting are removed per SPME §11.1.1.- # Acquirers may add and search for information on up to five principal owners per Merchant.- # Multiple data fields are used to determine matches; MATCH supports editing and error notification to reduce delays.- # Retroactive alert processing is supported for data up to 360 days old.- # Acquirers control receipt and detail of inquiry match information.- # Real-time access via MATCH Online and API, and batch operations remain available.- # Merchant URL information may be added and searched.- # After obtaining MATCH inquiry results, acquirers must assess whether further investigation or risk mitigation actions are warranted, per updated SPME requirements.+ # MATCH fraud detection features remain focused on principal owners only, consistent with prior policy.+ # Acquirers may associate up to five principal owners per Merchant and utilize multiple data fields for matching.+ # MATCH supports retroactive alerts for data up to 360 days old and acquirers control inquiry receipt and details.+ # Real-time and batch access modes continue to be supported.+ # Merchants may be added to MATCH under reason codes for Illegal Transactions or Questionable Acquirer status per SPME §8.6.6.+ # After receiving MATCH inquiry results, acquirers must assess risk and determine appropriate follow-up action.#- # New requirements under SPME §8.6.6 specify that Mastercard will add Merchants to MATCH using reason code 24 (Illegal Transactions) when Merchants meet Coercion Program criteria.- # Merchants subject to a subsequent claim of coercion within 12 months will be added with reason code 00 (Questionable Acquirer/Under Investigation).- # If the claim is confirmed to meet Coercion Program criteria, the MATCH record will be updated to reason code 24.- # If not confirmed, the MATCH record will be deleted.- # These provisions enhance fraud monitoring by requiring tracking of coercion-related transaction risks.+ # Per Mastercard SPME §8.4.3, Mastercard initiates QMAP investigations and notifies Issuers identified as having accounts transacting at suspected Merchants.+ # Issuers receiving notification must report fraudulent transactions related to the Merchant within 60 days, using defined fraud type codes.+ # This replaces the prior process where Issuers initiated notifications via a web form, centralizing investigation oversight and improving timeliness of fraud data reporting.++ # This update aligns the monitoring and reporting requirements with the latest Mastercard framework, emphasizing issuer notification and timely fraud reporting under QMAP investigations.
Fraud Monitoring
Halyard Pay monitors merchant fraud activity and leverages Mastercard's MATCH system along with Mastercard's QMAP investigation processes for enhanced fraud risk assessment on management of merchants processed through our platform.
When this policy applies
This policy applies to all merchants processed by Halyard Pay where Mastercard is the applicable network, covering both card-present and card-not-present transactions.
Required actions
-
Compute the merchant's rolling fraud-to-sales ratio each calendar month.
-
If the ratio meets or exceeds 1.5% and the fraud count reaches at least 100 transactions in that month, escalate the merchant account to human review immediately.
-
Utilize Mastercard's MATCH system data focusing on principal owners only,
as per the updatedin accordance with Mastercard SPME guidelines. Do not consider associate owners or Service Provider names in fraud assessments. -
Maintain awareness of Mastercard's MATCH reason codes related to coercion programs: merchants may be
addedlisted with reason code 24 for illegal transactions upon meeting coercion criteria, or with code 00 if a subsequent coercion claim arises within 12 months; update or remove recordsmust be updated or removedbased onconfirmationconfirmation.
5. Monitor Mastercard’s QMAP investigations notifications: when Mastercard notifies issuers of these claims. ¶ 5. After accessing MATCH data, conduct investigations concerning merchants—especially involving bust-out accounts—issuers must report associated fraudulent transactions within 60 days using appropriate fraud codes.
6. Perform a risk assessment after accessing MATCH and QMAP data to determine whether if further investigation or additional measures are warranted. ¶ 6. needed.
7. Notify the acquiring compliance officer and document the case ID with supporting transaction data.
7. 8. Track case progress until the account returns to threshold compliance or is terminated.
Source authority: Mastercard SPME §3.7, §8.6.6, and §11.1.1.§§3.7, 8.4.3, 8.6.6, and 11.1.1.
program: BRAM- authority: Mastercard SPME §8.6.2, §10.2+ authority: Mastercard SPME §8.4.3, §8.6.2, §10.2response_window_days: 180required_evidence:- transaction_monitoring_records- corrective_action_plan- - police_report # Mandatory inclusion per updated SPME §8.6.2+ - police_report # Updated requirement per Mastercard SPME §8.6.2halt_actions:- halt_new_merchant_onboardinginternal_notification_hours: 24agent_owner: bram_response_agent- # Reflects updated police report requirement and acknowledges Mastercard's exclusive authority to determine ADC Event occurrence and responsibility as clarified in SPME §10.2.- # Policy recognizes Mastercard's sole discretion in classifying and consolidating ADC Events to ensure proper investigation and response procedures.+ # Updated to incorporate Mastercard's procedure for issuer notifications in QMAP investigations concerning Cardholder bust-out accounts as outlined in §8.4.3.1.+ # This ensures issuer reporting of fraudulent transactions within 60 days to the Fraud and Loss Database as required by Mastercard policies.+ # Clarifies reliance on Mastercard's sole discretion for determination and classification of questionable merchants and ADC events per §10.2.+ # For Brazil, recognizes reliance on fraud code reporting as stated in §8.4.3.2.
BRAM Investigation Response
When Mastercard issues a Business Risk Assessment and Mitigation (BRAM) investigation
notice for one of our merchants, the acquirer must halt new merchant onboarding
immediately and submit an evidence package within one hundred eighty (180) days
of receipt of the notice.
Required actions
-
Halt new merchant onboarding for the merchant under investigation.
-
Compile and submit an evidence package containing:
-
Transaction monitoring records covering the prior 180 days.
-
A written corrective action plan.
-
Documentation of any police reports related to alleged coercion claims if applicable.
- Notify the Halyard Pay Compliance lead within 24 hours of receipt.
Additional Considerations for Coercion Claims
When allegations of coerced Transactions arise, note that Mastercard may extend the usual 120-day
investigation period at its discretion. At least one claim must include a police report from the Cardholder.
Transactions reported as Lost or Stolen Fraud (fraud type codes 00 or 01) are subject to investigation,
though Mastercard may consider other fraud codes. Mastercard will notify issuers with Transactions at the
merchant within the investigation period to prompt claim submissions.
Mastercard's Authority and Determinations on ADC Events
Mastercard retains exclusive authority to determine the occurrence, scope, and responsibility for Account Data Compromise (ADC) Events or Potential ADC Events, including the consolidation of related incidents into single or multiple events where applicable. Mastercard’s decisions in these matters are final and not subject to internal appeal. Customers are advised to seek Mastercard guidance if uncertain about their rights or obligations related to ADC Events. This framework ensures accountability and proper management of ADC risks in line with Mastercard's network security standards.
## QMAP Investigations and Issuer Reporting Obligations
Mastercard may initiate investigations under the Questionable Merchant Acquisition Program (QMAP) concerning merchants suspected of fraudulent activity, including Cardholder bust-out accounts. In such investigations, Mastercard notifies affected Issuers regarding Transactions with the merchant during the Case Scope Period. Issuers must report fraudulent Transactions linked to these investigations to the Fraud and Loss Database within 60 days of notification, using fraud type code 51 for bust-out related cases. This timely reporting aids Mastercard in determining merchant status and facilitates loss recovery processes. Notifications are sent to Issuers’ Security Contacts via Mastercard Connect. For non-bust-out account investigations, notifications are sent only if the merchant is determined to be questionable. Special provisions apply for Brazil, where fraud reporting under code 56 is relied upon instead of individual notices.
Source authority: Mastercard SPME §8.6.2, §10.2.§§8.6.2, 10.2, 8.4.3.
Fraud Monitoring
Halyard Pay monitors merchant fraud activity and leverages Mastercard's MATCH system along with Mastercard's QMAP investigation processes for enhanced fraud risk assessment on management of merchants processed through our platform.
When this policy applies
This policy applies to all merchants processed by Halyard Pay where Mastercard is the applicable network, covering both card-present and card-not-present transactions.
Required actions
-
Compute the merchant's rolling fraud-to-sales ratio each calendar month.
-
If the ratio meets or exceeds 1.5% and the fraud count reaches at least 100 transactions in that month, escalate the merchant account to human review immediately.
-
Utilize Mastercard's MATCH system data focusing on principal owners only,
as per the updatedin accordance with Mastercard SPME guidelines. Do not consider associate owners or Service Provider names in fraud assessments. -
Maintain awareness of Mastercard's MATCH reason codes related to coercion programs: merchants may be
addedlisted with reason code 24 for illegal transactions upon meeting coercion criteria, or with code 00 if a subsequent coercion claim arises within 12 months; update or remove recordsmust be updated or removedbased onconfirmationconfirmation.
5. Monitor Mastercard’s QMAP investigations notifications: when Mastercard notifies issuers of these claims. ¶ 5. After accessing MATCH data, conduct investigations concerning merchants—especially involving bust-out accounts—issuers must report associated fraudulent transactions within 60 days using appropriate fraud codes.
6. Perform a risk assessment after accessing MATCH and QMAP data to determine whether if further investigation or additional measures are warranted. ¶ 6. needed.
7. Notify the acquiring compliance officer and document the case ID with supporting transaction data.
7. 8. Track case progress until the account returns to threshold compliance or is terminated.
Source authority: Mastercard SPME §3.7, §8.6.6, and §11.1.1.§§3.7, 8.4.3, 8.6.6, and 11.1.1.
BRAM Investigation Response
When Mastercard issues a Business Risk Assessment and Mitigation (BRAM) investigation
notice for one of our merchants, the acquirer must halt new merchant onboarding
immediately and submit an evidence package within one hundred eighty (180) days
of receipt of the notice.
Required actions
-
Halt new merchant onboarding for the merchant under investigation.
-
Compile and submit an evidence package containing:
-
Transaction monitoring records covering the prior 180 days.
-
A written corrective action plan.
-
Documentation of any police reports related to alleged coercion claims if applicable.
- Notify the Halyard Pay Compliance lead within 24 hours of receipt.
Additional Considerations for Coercion Claims
When allegations of coerced Transactions arise, note that Mastercard may extend the usual 120-day
investigation period at its discretion. At least one claim must include a police report from the Cardholder.
Transactions reported as Lost or Stolen Fraud (fraud type codes 00 or 01) are subject to investigation,
though Mastercard may consider other fraud codes. Mastercard will notify issuers with Transactions at the
merchant within the investigation period to prompt claim submissions.
Mastercard's Authority and Determinations on ADC Events
Mastercard retains exclusive authority to determine the occurrence, scope, and responsibility for Account Data Compromise (ADC) Events or Potential ADC Events, including the consolidation of related incidents into single or multiple events where applicable. Mastercard’s decisions in these matters are final and not subject to internal appeal. Customers are advised to seek Mastercard guidance if uncertain about their rights or obligations related to ADC Events. This framework ensures accountability and proper management of ADC risks in line with Mastercard's network security standards.
## QMAP Investigations and Issuer Reporting Obligations
Mastercard may initiate investigations under the Questionable Merchant Acquisition Program (QMAP) concerning merchants suspected of fraudulent activity, including Cardholder bust-out accounts. In such investigations, Mastercard notifies affected Issuers regarding Transactions with the merchant during the Case Scope Period. Issuers must report fraudulent Transactions linked to these investigations to the Fraud and Loss Database within 60 days of notification, using fraud type code 51 for bust-out related cases. This timely reporting aids Mastercard in determining merchant status and facilitates loss recovery processes. Notifications are sent to Issuers’ Security Contacts via Mastercard Connect. For non-bust-out account investigations, notifications are sent only if the merchant is determined to be questionable. Special provisions apply for Brazil, where fraud reporting under code 56 is relied upon instead of individual notices.
Source authority: Mastercard SPME §8.6.2, §10.2.§§8.6.2, 10.2, 8.4.3.
Source authority: Mastercard SPME §8.4.2.
--- a/policies/fraud_monitoring/rules.yaml +++ b/policies/fraud_monitoring/rules.yaml @@ -1,5 +1,5 @@ program: Fraud Monitoring -authority: Mastercard SPME §3.7, §8.6.6, §11.1.1 +authority: Mastercard SPME 8.4.3 fraud_to_sales_ratio_threshold: 0.015 min_count_per_month: 100 monitoring_cadence: monthly @@ -10,17 +10,15 @@ remediation_review_interval_days: 30 agent_owner: fraud_ops_agent -# MATCH fraud detection features are limited to principal owners only; associate owners and Service Provider name reporting are removed per SPME §11.1.1. -# Acquirers may add and search for information on up to five principal owners per Merchant. -# Multiple data fields are used to determine matches; MATCH supports editing and error notification to reduce delays. -# Retroactive alert processing is supported for data up to 360 days old. -# Acquirers control receipt and detail of inquiry match information. -# Real-time access via MATCH Online and API, and batch operations remain available. -# Merchant URL information may be added and searched. -# After obtaining MATCH inquiry results, acquirers must assess whether further investigation or risk mitigation actions are warranted, per updated SPME requirements. +# MATCH fraud detection features remain focused on principal owners only, consistent with prior policy. +# Acquirers may associate up to five principal owners per Merchant and utilize multiple data fields for matching. +# MATCH supports retroactive alerts for data up to 360 days old and acquirers control inquiry receipt and details. +# Real-time and batch access modes continue to be supported. +# Merchants may be added to MATCH under reason codes for Illegal Transactions or Questionable Acquirer status per SPME §8.6.6. +# After receiving MATCH inquiry results, acquirers must assess risk and determine appropriate follow-up action. # -# New requirements under SPME §8.6.6 specify that Mastercard will add Merchants to MATCH using reason code 24 (Illegal Transactions) when Merchants meet Coercion Program criteria. -# Merchants subject to a subsequent claim of coercion within 12 months will be added with reason code 00 (Questionable Acquirer/Under Investigation). -# If the claim is confirmed to meet Coercion Program criteria, the MATCH record will be updated to reason code 24. -# If not confirmed, the MATCH record will be deleted. -# These provisions enhance fraud monitoring by requiring tracking of coercion-related transaction risks.+# Per Mastercard SPME §8.4.3, Mastercard initiates QMAP investigations and notifies Issuers identified as having accounts transacting at suspected Merchants. +# Issuers receiving notification must report fraudulent transactions related to the Merchant within 60 days, using defined fraud type codes. +# This replaces the prior process where Issuers initiated notifications via a web form, centralizing investigation oversight and improving timeliness of fraud data reporting. + +# This update aligns the monitoring and reporting requirements with the latest Mastercard framework, emphasizing issuer notification and timely fraud reporting under QMAP investigations. --- a/policies/fraud_monitoring/policy.md +++ b/policies/fraud_monitoring/policy.md @@ -1,6 +1,6 @@ # Fraud Monitoring -Halyard Pay monitors merchant fraud activity and leverages Mastercard's MATCH system for enhanced fraud risk assessment on merchants processed through our platform. +Halyard Pay monitors merchant fraud activity and leverages Mastercard's MATCH system along with Mastercard's QMAP investigation processes for enhanced fraud risk management of merchants processed through our platform. ## When this policy applies @@ -10,10 +10,11 @@ 1. Compute the merchant's rolling fraud-to-sales ratio each calendar month. 2. If the ratio meets or exceeds 1.5% and the fraud count reaches at least 100 transactions in that month, escalate the merchant account to human review immediately. -3. Utilize Mastercard's MATCH system data focusing on principal owners only, as per the updated Mastercard SPME guidelines. Do not consider associate owners or Service Provider names in fraud assessments. -4. Maintain awareness of Mastercard's MATCH reason codes related to coercion programs: merchants may be added with reason code 24 for illegal transactions upon meeting coercion criteria, or with code 00 if a subsequent coercion claim arises within 12 months; records must be updated or removed based on confirmation of these claims. -5. After accessing MATCH data, conduct a risk assessment to determine whether further investigation or additional measures are warranted. -6. Notify the acquiring compliance officer and document the case ID with supporting transaction data. -7. Track case progress until the account returns to threshold compliance or is terminated. +3. Utilize Mastercard's MATCH system data focusing on principal owners only, in accordance with Mastercard SPME guidelines. Do not consider associate owners or Service Provider names in fraud assessments. +4. Maintain awareness of Mastercard's MATCH reason codes related to coercion programs: merchants may be listed with reason code 24 for illegal transactions upon meeting coercion criteria, or with code 00 if a subsequent coercion claim arises within 12 months; update or remove records based on confirmation. +5. Monitor Mastercard’s QMAP investigations notifications: when Mastercard notifies issuers of investigations concerning merchants—especially involving bust-out accounts—issuers must report associated fraudulent transactions within 60 days using appropriate fraud codes. +6. Perform a risk assessment after accessing MATCH and QMAP data to determine if further investigation or measures are needed. +7. Notify the acquiring compliance officer and document the case ID with supporting transaction data. +8. Track case progress until the account returns to threshold compliance or is terminated. -Source authority: Mastercard SPME §3.7, §8.6.6, and §11.1.1. +Source authority: Mastercard SPME §§3.7, 8.4.3, 8.6.6, and 11.1.1. --- a/policies/bram_response/rules.yaml +++ b/policies/bram_response/rules.yaml @@ -1,14 +1,16 @@ program: BRAM -authority: Mastercard SPME §8.6.2, §10.2 +authority: Mastercard SPME §8.4.3, §8.6.2, §10.2 response_window_days: 180 required_evidence: - transaction_monitoring_records - corrective_action_plan - - police_report # Mandatory inclusion per updated SPME §8.6.2 + - police_report # Updated requirement per Mastercard SPME §8.6.2 halt_actions: - halt_new_merchant_onboarding internal_notification_hours: 24 agent_owner: bram_response_agent -# Reflects updated police report requirement and acknowledges Mastercard's exclusive authority to determine ADC Event occurrence and responsibility as clarified in SPME §10.2. -# Policy recognizes Mastercard's sole discretion in classifying and consolidating ADC Events to ensure proper investigation and response procedures. +# Updated to incorporate Mastercard's procedure for issuer notifications in QMAP investigations concerning Cardholder bust-out accounts as outlined in §8.4.3.1. +# This ensures issuer reporting of fraudulent transactions within 60 days to the Fraud and Loss Database as required by Mastercard policies. +# Clarifies reliance on Mastercard's sole discretion for determination and classification of questionable merchants and ADC events per §10.2. +# For Brazil, recognizes reliance on fraud code reporting as stated in §8.4.3.2. --- a/policies/bram_response/policy.md +++ b/policies/bram_response/policy.md @@ -26,4 +26,8 @@ Mastercard retains exclusive authority to determine the occurrence, scope, and responsibility for Account Data Compromise (ADC) Events or Potential ADC Events, including the consolidation of related incidents into single or multiple events where applicable. Mastercard’s decisions in these matters are final and not subject to internal appeal. Customers are advised to seek Mastercard guidance if uncertain about their rights or obligations related to ADC Events. This framework ensures accountability and proper management of ADC risks in line with Mastercard's network security standards. -Source authority: Mastercard SPME §8.6.2, §10.2.+## QMAP Investigations and Issuer Reporting Obligations + +Mastercard may initiate investigations under the Questionable Merchant Acquisition Program (QMAP) concerning merchants suspected of fraudulent activity, including Cardholder bust-out accounts. In such investigations, Mastercard notifies affected Issuers regarding Transactions with the merchant during the Case Scope Period. Issuers must report fraudulent Transactions linked to these investigations to the Fraud and Loss Database within 60 days of notification, using fraud type code 51 for bust-out related cases. This timely reporting aids Mastercard in determining merchant status and facilitates loss recovery processes. Notifications are sent to Issuers’ Security Contacts via Mastercard Connect. For non-bust-out account investigations, notifications are sent only if the merchant is determined to be questionable. Special provisions apply for Brazil, where fraud reporting under code 56 is relied upon instead of individual notices. + +Source authority: Mastercard SPME §§8.6.2, 10.2, 8.4.3.