Mastercard SPME §8.6.1 · Sep 2023 → Feb 2024
Issuer Submissions
The update clarifies submission methods for Cardholder coercion claims, differentiating processes pre- and post- January 1, 2022, shifting from email and web submissions to web form only, and explicitly requires police report inclusion if available, with detailed reasons if absent, plus maintaining other supporting documents.
program: BRAM- authority: Mastercard SPME §8.6.2, §10.2+ authority: Mastercard SPME §8.6.2, §10.2, §8.6.1response_window_days: 180required_evidence:- transaction_monitoring_records- corrective_action_plan- - police_report # Mandatory inclusion per updated SPME §8.6.2+ - police_report # Mandatory if available; if not, detailed explanation required per updated SPME §8.6.1halt_actions:- halt_new_merchant_onboardinginternal_notification_hours: 24agent_owner: bram_response_agent- # Reflects updated police report requirement and acknowledges Mastercard's exclusive authority to determine ADC Event occurrence and responsibility as clarified in SPME §10.2.- # Policy recognizes Mastercard's sole discretion in classifying and consolidating ADC Events to ensure proper investigation and response procedures.+ # Updated to reflect Mastercard SPME §8.6.1 revisions clarifying issuer submission process for coercion claims,+ # including mandatory use of Mastercard web-based form starting January 2022 and refinement of police report documentation requirements.+ # Confirms that when police reports are unavailable, issuers must provide detailed explanations as part of evidence.+ # Policy also notes Mastercard's exclusive authority over ADC Event determination and response per §10.2.
BRAM Investigation Response
When Mastercard issues a Business Risk Assessment and Mitigation (BRAM) investigation
notice for one of our merchants, the acquirer must halt new merchant onboarding
immediately and submit an evidence package within one hundred eighty (180) days
of receipt of the notice.
Required actions
-
Halt new merchant onboarding for the merchant under investigation.
-
Compile and submit an evidence package containing:
-
Transaction monitoring records covering the prior 180 days.
-
A written corrective action plan.
-
Documentation of any police reports related to alleged coercion claims if applicable.
- Notify the Halyard Pay Compliance lead within 24 hours of receipt.
Additional Considerations for Coercion Claims
When allegations of coerced Transactions arise, note that Mastercard may extend the usual 120-day ¶ investigation period at its discretion. At least one claim Issuer submissions of Cardholder coercion claims must follow Mastercard’s updated process:
- Effective January 1, 2022, claims must be submitted via Mastercard’s designated web form.
- Documentation must include a police report from the Cardholder. ¶ Transactions reported as Lost or Stolen Fraud (fraud type codes 00 or 01) are subject to investigation, ¶ though Mastercard may consider other fraud codes. Mastercard will notify issuers if available; if not, the Cardholder's explanation must describe whether an attempt to file was made and why no report exists.
- The Cardholder’s detailed description of the alleged coercive event is required.
- Issuers must complete and submit the Coercion Claim Affidavit Form with Transactions at the ¶ merchant within the investigation period to prompt claim submissions. Cardholder consent, authorizing law enforcement contact.
This ensures adherence to Mastercard’s latest documentation standards for coercion claims during BRAM investigations.
Mastercard's Authority and Determinations on ADC Events
Mastercard retains exclusive authority to determine the occurrence, scope, and responsibility for Account Data Compromise (ADC) Events or Potential ADC Events, including the consolidation of related incidents into single or multiple events where applicable. Mastercard’s decisions in these matters are final and not subject to internal appeal. Customers are advised to seek Mastercard guidance if uncertain about their rights or obligations related to ADC Events. This framework ensures accountability and proper management of ADC risks in line with Mastercard's network security standards.
Source authority: Mastercard SPME §8.6.2, §8.6.1, §10.2.
BRAM Investigation Response
When Mastercard issues a Business Risk Assessment and Mitigation (BRAM) investigation
notice for one of our merchants, the acquirer must halt new merchant onboarding
immediately and submit an evidence package within one hundred eighty (180) days
of receipt of the notice.
Required actions
-
Halt new merchant onboarding for the merchant under investigation.
-
Compile and submit an evidence package containing:
-
Transaction monitoring records covering the prior 180 days.
-
A written corrective action plan.
-
Documentation of any police reports related to alleged coercion claims if applicable.
- Notify the Halyard Pay Compliance lead within 24 hours of receipt.
Additional Considerations for Coercion Claims
When allegations of coerced Transactions arise, note that Mastercard may extend the usual 120-day ¶ investigation period at its discretion. At least one claim Issuer submissions of Cardholder coercion claims must follow Mastercard’s updated process:
- Effective January 1, 2022, claims must be submitted via Mastercard’s designated web form.
- Documentation must include a police report from the Cardholder. ¶ Transactions reported as Lost or Stolen Fraud (fraud type codes 00 or 01) are subject to investigation, ¶ though Mastercard may consider other fraud codes. Mastercard will notify issuers if available; if not, the Cardholder's explanation must describe whether an attempt to file was made and why no report exists.
- The Cardholder’s detailed description of the alleged coercive event is required.
- Issuers must complete and submit the Coercion Claim Affidavit Form with Transactions at the ¶ merchant within the investigation period to prompt claim submissions. Cardholder consent, authorizing law enforcement contact.
This ensures adherence to Mastercard’s latest documentation standards for coercion claims during BRAM investigations.
Mastercard's Authority and Determinations on ADC Events
Mastercard retains exclusive authority to determine the occurrence, scope, and responsibility for Account Data Compromise (ADC) Events or Potential ADC Events, including the consolidation of related incidents into single or multiple events where applicable. Mastercard’s decisions in these matters are final and not subject to internal appeal. Customers are advised to seek Mastercard guidance if uncertain about their rights or obligations related to ADC Events. This framework ensures accountability and proper management of ADC risks in line with Mastercard's network security standards.
Source authority: Mastercard SPME §8.6.2, §8.6.1, §10.2.
Source authority: Mastercard SPME §8.6.1.
--- a/policies/bram_response/rules.yaml +++ b/policies/bram_response/rules.yaml @@ -1,14 +1,16 @@ program: BRAM -authority: Mastercard SPME §8.6.2, §10.2 +authority: Mastercard SPME §8.6.2, §10.2, §8.6.1 response_window_days: 180 required_evidence: - transaction_monitoring_records - corrective_action_plan - - police_report # Mandatory inclusion per updated SPME §8.6.2 + - police_report # Mandatory if available; if not, detailed explanation required per updated SPME §8.6.1 halt_actions: - halt_new_merchant_onboarding internal_notification_hours: 24 agent_owner: bram_response_agent -# Reflects updated police report requirement and acknowledges Mastercard's exclusive authority to determine ADC Event occurrence and responsibility as clarified in SPME §10.2. -# Policy recognizes Mastercard's sole discretion in classifying and consolidating ADC Events to ensure proper investigation and response procedures. +# Updated to reflect Mastercard SPME §8.6.1 revisions clarifying issuer submission process for coercion claims, +# including mandatory use of Mastercard web-based form starting January 2022 and refinement of police report documentation requirements. +# Confirms that when police reports are unavailable, issuers must provide detailed explanations as part of evidence. +# Policy also notes Mastercard's exclusive authority over ADC Event determination and response per §10.2. --- a/policies/bram_response/policy.md +++ b/policies/bram_response/policy.md @@ -16,14 +16,16 @@ ## Additional Considerations for Coercion Claims -When allegations of coerced Transactions arise, note that Mastercard may extend the usual 120-day -investigation period at its discretion. At least one claim must include a police report from the Cardholder. -Transactions reported as Lost or Stolen Fraud (fraud type codes 00 or 01) are subject to investigation, -though Mastercard may consider other fraud codes. Mastercard will notify issuers with Transactions at the -merchant within the investigation period to prompt claim submissions. +Issuer submissions of Cardholder coercion claims must follow Mastercard’s updated process: +- Effective January 1, 2022, claims must be submitted via Mastercard’s designated web form. +- Documentation must include a police report if available; if not, the Cardholder's explanation must describe whether an attempt to file was made and why no report exists. +- The Cardholder’s detailed description of the alleged coercive event is required. +- Issuers must complete and submit the Coercion Claim Affidavit Form with Cardholder consent, authorizing law enforcement contact. + +This ensures adherence to Mastercard’s latest documentation standards for coercion claims during BRAM investigations. ## Mastercard's Authority and Determinations on ADC Events Mastercard retains exclusive authority to determine the occurrence, scope, and responsibility for Account Data Compromise (ADC) Events or Potential ADC Events, including the consolidation of related incidents into single or multiple events where applicable. Mastercard’s decisions in these matters are final and not subject to internal appeal. Customers are advised to seek Mastercard guidance if uncertain about their rights or obligations related to ADC Events. This framework ensures accountability and proper management of ADC risks in line with Mastercard's network security standards. -Source authority: Mastercard SPME §8.6.2, §10.2.+Source authority: Mastercard SPME §8.6.2, §8.6.1, §10.2.