Mastercard SPME §8.4.6 · Sep 2023 → Feb 2024
Mastercard Determination
The section changes from detailing Issuer fraud recovery conditions to outlining Mastercard's procedures for classifying and notifying about Questionable Merchants, including notifications, MATCH record updates, and Acquirer obligations upon Merchant termination for being a Questionable Merchant.
Security Rules and Procedures—Merchant Edition • 1 August 2023
- If the Issuer’s total volume of reported fraudulent Transactions occurring at the Questionable Merchant during the Case Scope Period was less than USD 2,000, or
- For which the Issuer received recovery through any existing remedy in the Mastercard system, including chargeback, recovery process, or the Issuer’s own collection process, or
- Performed with a Card with only magnetic stripe functionality. Mastercard reserves the right to request additional information as a condition of determining whether a Transaction satisfactorily meets the eligibility requirements for Issuer partial recovery. In addition, Mastercard will not pay claims in excess of the amount collected from the Acquirer(s) for that purpose. Mastercard will debit the fraud recovery amount from the Acquirer account and credit the Issuer account (less any administrative fee). Mastercard will process Issuer fraud recoveries according to MCBS.
Mastercard will determine if a Merchant is a Questionable Merchant. If Mastercard determines that the Merchant is not a Questionable Merchant, Mastercard will so notify each Issuer and Acquirer that provided information pertinent to the investigation. Such notice will be provided by email message to the Security Contact listed for the Customer in the Company Contact Management application available on Mastercard Connect. In addition, Mastercard will delete the MATCH™ listing of the Merchant for MATCH reason code 00. If Mastercard determines that the Merchant is a Questionable Merchant, Mastercard will:
- Notify the Merchant’s Acquirer, and
- Identify the Merchant as a Questionable Merchant in a Mastercard Announcement for each of twelve (12) consecutive months, and
- Modify the Merchant’s MATCH record to reflect a reason code change from 00 (Under Investigation) to 20 (Mastercard Questionable Merchant Audit Program). If the Acquirer terminates the Merchant Agreement because Mastercard determines the Merchant to be a Questionable Merchant, the Acquirer is required to identify the Merchant in MATCH with reason code 08 (Mastercard Questionable Merchant Audit Program).
program: BRAM- authority: Mastercard SPME §8.6.2, §10.2+ authority: Mastercard SPME 20.4.6, 8.6.2, 10.2response_window_days: 180required_evidence:- transaction_monitoring_records- corrective_action_plan- - police_report # Mandatory inclusion per updated SPME §8.6.2+ - police_report # Mandatory inclusion per updated SPME 8.6.2halt_actions:- halt_new_merchant_onboardinginternal_notification_hours: 24agent_owner: bram_response_agent- # Reflects updated police report requirement and acknowledges Mastercard's exclusive authority to determine ADC Event occurrence and responsibility as clarified in SPME §10.2.- # Policy recognizes Mastercard's sole discretion in classifying and consolidating ADC Events to ensure proper investigation and response procedures.+ # Updated to incorporate Mastercard's clarified procedures in SPME 20.4.6 regarding determination and notification of Questionable Merchants.+ # The policy reflects Mastercard's exclusive role in identifying Questionable Merchants and related Acquirer obligations upon Merchant termination.+ # Retains existing requirements from SPME 8.6.2 and 10.2 concerning evidence and investigation protocols.
BRAM Investigation Response
When Mastercard issues a Business Risk Assessment and Mitigation (BRAM) investigation
notice for one of our merchants, the acquirer must halt new merchant onboarding
immediately and submit an evidence package within one hundred eighty (180) days
of receipt of the notice.
Required actions
-
Halt new merchant onboarding for the merchant under investigation.
-
Compile and submit an evidence package containing:
-
Transaction monitoring records covering the prior 180 days.
-
A written corrective action plan.
-
Documentation of any police reports related to alleged coercion claims if applicable.
- Notify the Halyard Pay Compliance lead within 24 hours of receipt.
Additional Considerations for Coercion Claims
When allegations of coerced Transactions arise, note that Mastercard may extend the usual 120-day
investigation period at its discretion. At least one claim must include a police report from the Cardholder.
Transactions reported as Lost or Stolen Fraud (fraud type codes 00 or 01) are subject to investigation,
though Mastercard may consider other fraud codes. Mastercard will notify issuers with Transactions at the
merchant within the investigation period to prompt claim submissions.
Mastercard Procedures and Roles Regarding Questionable Merchants
Mastercard now defines procedures for handling merchants designated as Questionable Merchants. Mastercard will notify all relevant issuers and acquirers via email if a merchant is determined not to be questionable, and remove the MATCH listing accordingly. For merchants deemed questionable, Mastercard will notify the acquirer, publicly identify the merchant in announcements for twelve months, and update the merchant's MATCH record with appropriate reason codes. Acquirers terminating agreements due to this designation are obligated to mark the merchant accordingly in MATCH. These procedural updates complement BRAM responses by clarifying responsibilities during merchant risk assessments.
## Mastercard's Authority and Determinations on ADC Events
Mastercard retains exclusive authority to determine the occurrence, scope, and responsibility for Account Data Compromise (ADC) Events or Potential ADC Events, including the consolidation of related incidents into single or multiple events where applicable. Mastercard’s decisions in these matters are final and not subject to internal appeal. Customers are advised to seek Mastercard guidance if uncertain about their rights or obligations related to ADC Events. This framework ensures accountability and proper management of ADC risks in line with Mastercard's network security standards.
Source authority: Mastercard SPME §8.6.2, §10.2.§10.2, §8.4.6.
BRAM Investigation Response
When Mastercard issues a Business Risk Assessment and Mitigation (BRAM) investigation
notice for one of our merchants, the acquirer must halt new merchant onboarding
immediately and submit an evidence package within one hundred eighty (180) days
of receipt of the notice.
Required actions
-
Halt new merchant onboarding for the merchant under investigation.
-
Compile and submit an evidence package containing:
-
Transaction monitoring records covering the prior 180 days.
-
A written corrective action plan.
-
Documentation of any police reports related to alleged coercion claims if applicable.
- Notify the Halyard Pay Compliance lead within 24 hours of receipt.
Additional Considerations for Coercion Claims
When allegations of coerced Transactions arise, note that Mastercard may extend the usual 120-day
investigation period at its discretion. At least one claim must include a police report from the Cardholder.
Transactions reported as Lost or Stolen Fraud (fraud type codes 00 or 01) are subject to investigation,
though Mastercard may consider other fraud codes. Mastercard will notify issuers with Transactions at the
merchant within the investigation period to prompt claim submissions.
Mastercard Procedures and Roles Regarding Questionable Merchants
Mastercard now defines procedures for handling merchants designated as Questionable Merchants. Mastercard will notify all relevant issuers and acquirers via email if a merchant is determined not to be questionable, and remove the MATCH listing accordingly. For merchants deemed questionable, Mastercard will notify the acquirer, publicly identify the merchant in announcements for twelve months, and update the merchant's MATCH record with appropriate reason codes. Acquirers terminating agreements due to this designation are obligated to mark the merchant accordingly in MATCH. These procedural updates complement BRAM responses by clarifying responsibilities during merchant risk assessments.
## Mastercard's Authority and Determinations on ADC Events
Mastercard retains exclusive authority to determine the occurrence, scope, and responsibility for Account Data Compromise (ADC) Events or Potential ADC Events, including the consolidation of related incidents into single or multiple events where applicable. Mastercard’s decisions in these matters are final and not subject to internal appeal. Customers are advised to seek Mastercard guidance if uncertain about their rights or obligations related to ADC Events. This framework ensures accountability and proper management of ADC risks in line with Mastercard's network security standards.
Source authority: Mastercard SPME §8.6.2, §10.2.§10.2, §8.4.6.
Source authority: Mastercard SPME §8.4.6.
--- a/policies/bram_response/rules.yaml +++ b/policies/bram_response/rules.yaml @@ -1,14 +1,15 @@ program: BRAM -authority: Mastercard SPME §8.6.2, §10.2 +authority: Mastercard SPME 20.4.6, 8.6.2, 10.2 response_window_days: 180 required_evidence: - transaction_monitoring_records - corrective_action_plan - - police_report # Mandatory inclusion per updated SPME §8.6.2 + - police_report # Mandatory inclusion per updated SPME 8.6.2 halt_actions: - halt_new_merchant_onboarding internal_notification_hours: 24 agent_owner: bram_response_agent -# Reflects updated police report requirement and acknowledges Mastercard's exclusive authority to determine ADC Event occurrence and responsibility as clarified in SPME §10.2. -# Policy recognizes Mastercard's sole discretion in classifying and consolidating ADC Events to ensure proper investigation and response procedures. +# Updated to incorporate Mastercard's clarified procedures in SPME 20.4.6 regarding determination and notification of Questionable Merchants. +# The policy reflects Mastercard's exclusive role in identifying Questionable Merchants and related Acquirer obligations upon Merchant termination. +# Retains existing requirements from SPME 8.6.2 and 10.2 concerning evidence and investigation protocols. --- a/policies/bram_response/policy.md +++ b/policies/bram_response/policy.md @@ -22,8 +22,12 @@ though Mastercard may consider other fraud codes. Mastercard will notify issuers with Transactions at the merchant within the investigation period to prompt claim submissions. +## Mastercard Procedures and Roles Regarding Questionable Merchants + +Mastercard now defines procedures for handling merchants designated as Questionable Merchants. Mastercard will notify all relevant issuers and acquirers via email if a merchant is determined not to be questionable, and remove the MATCH listing accordingly. For merchants deemed questionable, Mastercard will notify the acquirer, publicly identify the merchant in announcements for twelve months, and update the merchant's MATCH record with appropriate reason codes. Acquirers terminating agreements due to this designation are obligated to mark the merchant accordingly in MATCH. These procedural updates complement BRAM responses by clarifying responsibilities during merchant risk assessments. + ## Mastercard's Authority and Determinations on ADC Events Mastercard retains exclusive authority to determine the occurrence, scope, and responsibility for Account Data Compromise (ADC) Events or Potential ADC Events, including the consolidation of related incidents into single or multiple events where applicable. Mastercard’s decisions in these matters are final and not subject to internal appeal. Customers are advised to seek Mastercard guidance if uncertain about their rights or obligations related to ADC Events. This framework ensures accountability and proper management of ADC risks in line with Mastercard's network security standards. -Source authority: Mastercard SPME §8.6.2, §10.2.+Source authority: Mastercard SPME §8.6.2, §10.2, §8.4.6.