Mastercard SPME §8.4 · Sep 2023 → Feb 2024
Questionable Merchant Audit Program (QMAP)
The criteria for identifying Questionable Merchants have been expanded to include specific rules for Brazil, requiring certain fraud thresholds and transaction types during a 120-day investigation period. Other original criteria remain, with some minor formatting and punctuation changes.
program: Fraud Monitoring- authority: Mastercard SPME §3.7, §8.6.6, §11.1.1+ authority: Mastercard SPME 2.4, 3.7, 8.6.6, 11.1.1fraud_to_sales_ratio_threshold: 0.015min_count_per_month: 100monitoring_cadence: monthlyescalation_actions:- escalate_to_human_review- notify_acquirerlookback_period_months: 1remediation_review_interval_days: 30agent_owner: fraud_ops_agent- # MATCH fraud detection features are limited to principal owners only; associate owners and Service Provider name reporting are removed per SPME §11.1.1.- # Acquirers may add and search for information on up to five principal owners per Merchant.- # Multiple data fields are used to determine matches; MATCH supports editing and error notification to reduce delays.- # Retroactive alert processing is supported for data up to 360 days old.- # Acquirers control receipt and detail of inquiry match information.- # Real-time access via MATCH Online and API, and batch operations remain available.- # Merchant URL information may be added and searched.- # After obtaining MATCH inquiry results, acquirers must assess whether further investigation or risk mitigation actions are warranted, per updated SPME requirements.+ # MATCH fraud detection features remain limited to principal owners as per updated SPME 11.1.1 guidance.+ # Acquirers may continue to add and query up to five principal owners per Merchant, with multiple data fields employed for accurate matching.+ # MATCH supports editing and error notification functionality to optimize processing timelines, with retroactive alerts permitted for data up to 360 days old.+ # Acquirers retain control of inquiry match data access and detail level.+ # Merchant URL reporting and searching is supported.+ # Following MATCH inquiries, assessment of further investigation or risk mitigation is mandatory, in compliance with SPME directives.#- # New requirements under SPME §8.6.6 specify that Mastercard will add Merchants to MATCH using reason code 24 (Illegal Transactions) when Merchants meet Coercion Program criteria.- # Merchants subject to a subsequent claim of coercion within 12 months will be added with reason code 00 (Questionable Acquirer/Under Investigation).- # If the claim is confirmed to meet Coercion Program criteria, the MATCH record will be updated to reason code 24.- # If not confirmed, the MATCH record will be deleted.- # These provisions enhance fraud monitoring by requiring tracking of coercion-related transaction risks.+ # SPME 8.6.6 introduces mandates for Mastercard to add Merchants to MATCH using reason code 24 for illegal transactions tied to coercion programs. Merchants linked to coercion claims within 12 months are flagged with reason code 00 initially, updated to 24 on confirmation, or deleted if unconfirmed.+ # This bolsters fraud monitoring through enhanced tracking of coercion-related fraud exposures.+ #+ # Importantly, SPME 2.4 adds a new regional definition of "Questionable Merchant" specific to Brazil, with criteria including:+ # - Minimum BRL 100,000 in 3DS fully-authenticated fraud transactions per Acquirer under fraud type 56 within the 120-day case scope period;+ # - Fraud-to-sales ratio threshold increased to 75% for fraud type "56-Manipulation of Cardholder";+ # - Inclusion of both card-present (POS entry mode 05 or 07) and CNP (POS entry mode 10 or 81) transactions;+ # - Base case scope period remains 120 calendar days prior to Mastercard investigation date.+ #+ # The program incorporates these regional fraud identification criteria alongside the global metrics to ensure comprehensive monitoring coverage.+
Fraud Monitoring
Halyard Pay monitors merchant fraud activity and leverages Mastercard's MATCH system for enhanced fraud risk assessment on merchants processed through our platform.
When this policy applies
This policy applies to all merchants processed by Halyard Pay where Mastercard is the applicable network, covering both card-present and card-not-present transactions.
Required actions
-
Compute the merchant's rolling fraud-to-sales ratio each calendar month.
-
If the ratio meets or exceeds 1.5% and the fraud count reaches at least 100 transactions in that month, escalate the merchant account to human review immediately.
-
Utilize Mastercard's MATCH system data focusing on principal owners only, as per the updated Mastercard SPME guidelines. Do not consider associate owners or Service Provider names in fraud assessments.
-
Maintain awareness of Mastercard's MATCH reason codes related to coercion programs: merchants may be added with reason code 24 for illegal transactions upon meeting coercion criteria, or with code 00 if a subsequent coercion claim arises within 12 months; records must be updated or removed based on confirmation of these claims.
-
After accessing MATCH data, conduct a risk assessment to determine whether further investigation or additional measures are warranted.
-
Consider additional regional criteria, specifically for Brazil, where higher fraud-to-sales ratios (75% or greater based on fraud type 56) and authentication conditions for transactions apply to identifying questionable merchants, pursuant to Mastercard SPME §8.4.
7. Notify the acquiring compliance officer and document the case ID with supporting transaction data.
7. 8. Track case progress until the account returns to threshold compliance or is terminated.
Source authority: Mastercard SPME §3.7, §8.4, §8.6.6, and §11.1.1.
Fraud Monitoring
Halyard Pay monitors merchant fraud activity and leverages Mastercard's MATCH system for enhanced fraud risk assessment on merchants processed through our platform.
When this policy applies
This policy applies to all merchants processed by Halyard Pay where Mastercard is the applicable network, covering both card-present and card-not-present transactions.
Required actions
-
Compute the merchant's rolling fraud-to-sales ratio each calendar month.
-
If the ratio meets or exceeds 1.5% and the fraud count reaches at least 100 transactions in that month, escalate the merchant account to human review immediately.
-
Utilize Mastercard's MATCH system data focusing on principal owners only, as per the updated Mastercard SPME guidelines. Do not consider associate owners or Service Provider names in fraud assessments.
-
Maintain awareness of Mastercard's MATCH reason codes related to coercion programs: merchants may be added with reason code 24 for illegal transactions upon meeting coercion criteria, or with code 00 if a subsequent coercion claim arises within 12 months; records must be updated or removed based on confirmation of these claims.
-
After accessing MATCH data, conduct a risk assessment to determine whether further investigation or additional measures are warranted.
-
Consider additional regional criteria, specifically for Brazil, where higher fraud-to-sales ratios (75% or greater based on fraud type 56) and authentication conditions for transactions apply to identifying questionable merchants, pursuant to Mastercard SPME §8.4.
7. Notify the acquiring compliance officer and document the case ID with supporting transaction data.
7. 8. Track case progress until the account returns to threshold compliance or is terminated.
Source authority: Mastercard SPME §3.7, §8.4, §8.6.6, and §11.1.1.
Source authority: Mastercard SPME §8.4.
--- a/policies/fraud_monitoring/rules.yaml +++ b/policies/fraud_monitoring/rules.yaml @@ -1,5 +1,5 @@ program: Fraud Monitoring -authority: Mastercard SPME §3.7, §8.6.6, §11.1.1 +authority: Mastercard SPME 2.4, 3.7, 8.6.6, 11.1.1 fraud_to_sales_ratio_threshold: 0.015 min_count_per_month: 100 monitoring_cadence: monthly @@ -10,17 +10,21 @@ remediation_review_interval_days: 30 agent_owner: fraud_ops_agent -# MATCH fraud detection features are limited to principal owners only; associate owners and Service Provider name reporting are removed per SPME §11.1.1. -# Acquirers may add and search for information on up to five principal owners per Merchant. -# Multiple data fields are used to determine matches; MATCH supports editing and error notification to reduce delays. -# Retroactive alert processing is supported for data up to 360 days old. -# Acquirers control receipt and detail of inquiry match information. -# Real-time access via MATCH Online and API, and batch operations remain available. -# Merchant URL information may be added and searched. -# After obtaining MATCH inquiry results, acquirers must assess whether further investigation or risk mitigation actions are warranted, per updated SPME requirements. +# MATCH fraud detection features remain limited to principal owners as per updated SPME 11.1.1 guidance. +# Acquirers may continue to add and query up to five principal owners per Merchant, with multiple data fields employed for accurate matching. +# MATCH supports editing and error notification functionality to optimize processing timelines, with retroactive alerts permitted for data up to 360 days old. +# Acquirers retain control of inquiry match data access and detail level. +# Merchant URL reporting and searching is supported. +# Following MATCH inquiries, assessment of further investigation or risk mitigation is mandatory, in compliance with SPME directives. # -# New requirements under SPME §8.6.6 specify that Mastercard will add Merchants to MATCH using reason code 24 (Illegal Transactions) when Merchants meet Coercion Program criteria. -# Merchants subject to a subsequent claim of coercion within 12 months will be added with reason code 00 (Questionable Acquirer/Under Investigation). -# If the claim is confirmed to meet Coercion Program criteria, the MATCH record will be updated to reason code 24. -# If not confirmed, the MATCH record will be deleted. -# These provisions enhance fraud monitoring by requiring tracking of coercion-related transaction risks.+# SPME 8.6.6 introduces mandates for Mastercard to add Merchants to MATCH using reason code 24 for illegal transactions tied to coercion programs. Merchants linked to coercion claims within 12 months are flagged with reason code 00 initially, updated to 24 on confirmation, or deleted if unconfirmed. +# This bolsters fraud monitoring through enhanced tracking of coercion-related fraud exposures. +# +# Importantly, SPME 2.4 adds a new regional definition of "Questionable Merchant" specific to Brazil, with criteria including: +# - Minimum BRL 100,000 in 3DS fully-authenticated fraud transactions per Acquirer under fraud type 56 within the 120-day case scope period; +# - Fraud-to-sales ratio threshold increased to 75% for fraud type "56-Manipulation of Cardholder"; +# - Inclusion of both card-present (POS entry mode 05 or 07) and CNP (POS entry mode 10 or 81) transactions; +# - Base case scope period remains 120 calendar days prior to Mastercard investigation date. +# +# The program incorporates these regional fraud identification criteria alongside the global metrics to ensure comprehensive monitoring coverage. + --- a/policies/fraud_monitoring/policy.md +++ b/policies/fraud_monitoring/policy.md @@ -13,7 +13,8 @@ 3. Utilize Mastercard's MATCH system data focusing on principal owners only, as per the updated Mastercard SPME guidelines. Do not consider associate owners or Service Provider names in fraud assessments. 4. Maintain awareness of Mastercard's MATCH reason codes related to coercion programs: merchants may be added with reason code 24 for illegal transactions upon meeting coercion criteria, or with code 00 if a subsequent coercion claim arises within 12 months; records must be updated or removed based on confirmation of these claims. 5. After accessing MATCH data, conduct a risk assessment to determine whether further investigation or additional measures are warranted. -6. Notify the acquiring compliance officer and document the case ID with supporting transaction data. -7. Track case progress until the account returns to threshold compliance or is terminated. +6. Consider additional regional criteria, specifically for Brazil, where higher fraud-to-sales ratios (75% or greater based on fraud type 56) and authentication conditions for transactions apply to identifying questionable merchants, pursuant to Mastercard SPME §8.4. +7. Notify the acquiring compliance officer and document the case ID with supporting transaction data. +8. Track case progress until the account returns to threshold compliance or is terminated. -Source authority: Mastercard SPME §3.7, §8.6.6, and §11.1.1. +Source authority: Mastercard SPME §3.7, §8.4, §8.6.6, and §11.1.1.