Mastercard SPME §8.8.1 · Sep 2023 → Feb 2024

BRAM Investigation Process

substantive

This new section requires the Acquirer to provide Mastercard a detailed investigation report within two days for law enforcement or Mastercard-initiated cases, or five days for others, including remediation plans, merchant documentation, business overview, transaction data, service provider identity, MATCH system usage, and termination details.

Sources Mastercard SPME · Sep 2023 PDF Mastercard SPME · Feb 2024 · page 90 PDF BRAM Response current
Also in §8.x this release breaking §8.6.5 Chargeback Responsibility substantive §8.4 Questionable Merchant Audit Program (QMAP) substantive §8.4.2 Mastercard Commencement of an Investigation substantive §8.4.3 of this manual, or substantive §8.4.6 Mastercard Determination substantive §8.4.8 Fraud Recovery substantive §8.6 Coercion Program substantive §8.6.1 Issuer Submissions substantive §8.6.2 Investigation Process substantive §8.6.7 Franchise Management Program (FMP) Questionnaire-based Review substantive §8.7.1 Definitions substantive §8.7.3 Mastercard Notification to Acquirers substantive §8.8 Business Risk Assessment and Mitigation (BRAM) Program substantive §8.8.2 Acquirer Response Requirements substantive §8.8.4 Noncompliance Assessment Mitigation substantive §8.9 Merchant Monitoring Program (MMP) substantive §8.9.1 MMP Participation Requirements
Why these edits? The new section 8.8.1 requires Acquirers to provide detailed investigation reports within defined timeframes and include specific documentation and remediation plans for BRAM investigations, directly aligning with and expanding the obligations under the 'bram_response' policy which cites section 10.2.
Mastercard SPME §8.8.1
This section was substantively restructured between versions (0% text overlap). Compare the texts directly below.
Before · Sep 2023
After · Feb 2024 · page 90

Security Rules and Procedures—Merchant Edition • 6 February 2024

  • For cases initiated by law enforcement or other government entity, or at Mastercard's discretion, the Acquirer must provide Mastercard with the results of its investigation within two (2) business days of notification; and
  • For all other cases, the Acquirer must respond and provide Mastercard with all requested information within five (5) business days of notification. For each case, the Acquirer's response must include:
  1. A remediation plan that describes in detail the incident and all information and corrective action taken by the Acquirer to address each suspected instance of noncompliance with a Standard.
  2. A copy of the Merchant application and signed Merchant Agreement executed between the Merchant and the Acquirer. The documentation provided must include the Merchant's legal name, doing business as name, address, principal owner(s), and a physical or electronic signature.
  3. A summarized overview of the Merchant's business operations as described by the Merchant in its application and approved by the Acquirer prior to onboarding, including Merchant website URLs and descriptions of products and services offered for sale.
  4. Documentation supporting the relationship between the violating URL and the Acquirer's approved Merchant and its URL.
  5. Documentation showing the dates on which the Acquirer submitted into interchange the first Transaction received from the Acquirer-approved Merchant account, including each Acquirer-approved URL and the violating URL.
  6. Documentation showing the total number and total USD volume amount of the Merchant's Mastercard Transactions acquired in each month, for the duration of the Acquiring relationship or for the preceding twelve (12) months if the relationship duration exceeds twelve (12) months, for each Acquirer-approved URL and if known, for the violating URL.
  7. The identity of any Service Provider involved in the signing of this Merchant.
  8. If the Mastercard Alert to Control High-risk (Merchants) (MATCH™) system was used (where permitted by applicable law): – A copy of the MATCH inquiry conducted by the Acquirer prior to onboarding the Merchant and the results received; and – If the Acquirer terminated its relationship with the Merchant, confirmation that the Acquirer added the Merchant to the MATCH system. This requirement can be fulfilled by providing screen prints reflecting the MATCH add listing or the MATCH add reference number.
  9. If applicable, the date on which the Acquirer ceased processing Transactions for the Merchant, and (if different) the date on which the Acquirer terminated its relationship with the Merchant.
Halyard Pay · 2 files
program: BRAM
- authority: Mastercard SPME §8.6.2, §10.2
+ authority: Mastercard SPME 8.6.2, 10.2, 8.8.1
response_window_days: 180
required_evidence:
- transaction_monitoring_records
- corrective_action_plan
- - police_report # Mandatory inclusion per updated SPME §8.6.2
+ - police_report # Mandatory inclusion per updated SPME 8.6.2
+ - merchant_application_and_agreement # As required by SPME 8.8.1
+ - remediation_plan # Detailed remediation and investigation plan per SPME 8.8.1
+ - merchant_business_overview # Including URLs and product descriptions per SPME 8.8.1
+ - service_provider_identity # For involved service providers per SPME 8.8.1
halt_actions:
- halt_new_merchant_onboarding
internal_notification_hours: 24
agent_owner: bram_response_agent
 
- # Reflects updated police report requirement and acknowledges Mastercard's exclusive authority to determine ADC Event occurrence and responsibility as clarified in SPME §10.2.
- # Policy recognizes Mastercard's sole discretion in classifying and consolidating ADC Events to ensure proper investigation and response procedures.
+ # Updated to incorporate new Acquirer reporting requirements from SPME 8.8.1, including detailed timelines and documentation obligations for investigations.
+ # This aligns the BRAM response policy with Mastercard's specified evidence and procedural expectations for case responses under sections 8.6.2, 10.2, and now 8.8.1, ensuring comprehensive compliance and clear guidelines for agent actions.

BRAM Investigation Response

When Mastercard issues a Business Risk Assessment and Mitigation (BRAM) investigation notice for one of our merchants, the acquirer must halt new merchant onboarding immediately and submit an evidence package within one hundred eighty (180) days of receipt of the notice.

Required actions

  1. Halt new merchant onboarding for the merchant under investigation.

  2. Compile and submit to Mastercard, within the required timeframes, an evidence package containing: including:

  • Transaction monitoring records covering the prior 180 days.

  • A written detailed remediation plan describing the incident and corrective action plan. actions taken.

- A copy of the Merchant application and signed Merchant Agreement with legal name, doing business as name, address, principal owner(s), and signature.

- A summarized overview of the Merchant's business operations, including website URLs and product/service descriptions.

  • Documentation of linking any police reports related to alleged coercion claims violating URL to the Acquirer's approved Merchant and its URL.

- Dates of first transactions submitted for each approved and any violating URL.

- Total monthly number and volume of Mastercard transactions for the Merchant for the duration of the relationship or previous 12 months.

- Identification of any Service Provider involved in signing the Merchant.

- MATCH system inquiry results if applicable. used, and confirmation of addition to MATCH if the Merchant was terminated.

- The date processing ceased for the Merchant and, if different, the relationship termination date.

Documentation must be provided within two (2) business days if the case is initiated by law enforcement or Mastercard's discretion; otherwise, within five (5) business days of notification.

  1. Notify the Halyard Pay Compliance lead within 24 hours of receipt.

Additional Considerations for Coercion Claims

When allegations of coerced Transactions arise, note that Mastercard may extend the usual 120-day investigation period at its discretion. At least one claim must include a police report from the Cardholder. Transactions reported as Lost or Stolen Fraud (fraud type codes 00 or 01) are subject to investigation, though Mastercard may consider other fraud codes. Mastercard will notify issuers with Transactions at the merchant within the investigation period to prompt claim submissions.

Mastercard's Authority and Determinations on ADC Events

Mastercard retains exclusive authority to determine the occurrence, scope, and responsibility for Account Data Compromise (ADC) Events or Potential ADC Events, including the consolidation of related incidents into single or multiple events where applicable. Mastercard’s decisions in these matters are final and not subject to internal appeal. Customers are advised to seek Mastercard guidance if uncertain about their rights or obligations related to ADC Events. This framework ensures accountability and proper management of ADC risks in line with Mastercard's network security standards.

Source authority: Mastercard SPME §8.6.2, §8.8.1, §10.2.

policies/bram_response/policy.md — after applying change

BRAM Investigation Response

When Mastercard issues a Business Risk Assessment and Mitigation (BRAM) investigation notice for one of our merchants, the acquirer must halt new merchant onboarding immediately and submit an evidence package within one hundred eighty (180) days of receipt of the notice.

Required actions

  1. Halt new merchant onboarding for the merchant under investigation.

  2. Compile and submit to Mastercard, within the required timeframes, an evidence package containing: including:

  • Transaction monitoring records covering the prior 180 days.

  • A written detailed remediation plan describing the incident and corrective action plan. actions taken.

- A copy of the Merchant application and signed Merchant Agreement with legal name, doing business as name, address, principal owner(s), and signature.

- A summarized overview of the Merchant's business operations, including website URLs and product/service descriptions.

  • Documentation of linking any police reports related to alleged coercion claims violating URL to the Acquirer's approved Merchant and its URL.

- Dates of first transactions submitted for each approved and any violating URL.

- Total monthly number and volume of Mastercard transactions for the Merchant for the duration of the relationship or previous 12 months.

- Identification of any Service Provider involved in signing the Merchant.

- MATCH system inquiry results if applicable. used, and confirmation of addition to MATCH if the Merchant was terminated.

- The date processing ceased for the Merchant and, if different, the relationship termination date.

Documentation must be provided within two (2) business days if the case is initiated by law enforcement or Mastercard's discretion; otherwise, within five (5) business days of notification.

  1. Notify the Halyard Pay Compliance lead within 24 hours of receipt.

Additional Considerations for Coercion Claims

When allegations of coerced Transactions arise, note that Mastercard may extend the usual 120-day investigation period at its discretion. At least one claim must include a police report from the Cardholder. Transactions reported as Lost or Stolen Fraud (fraud type codes 00 or 01) are subject to investigation, though Mastercard may consider other fraud codes. Mastercard will notify issuers with Transactions at the merchant within the investigation period to prompt claim submissions.

Mastercard's Authority and Determinations on ADC Events

Mastercard retains exclusive authority to determine the occurrence, scope, and responsibility for Account Data Compromise (ADC) Events or Potential ADC Events, including the consolidation of related incidents into single or multiple events where applicable. Mastercard’s decisions in these matters are final and not subject to internal appeal. Customers are advised to seek Mastercard guidance if uncertain about their rights or obligations related to ADC Events. This framework ensures accountability and proper management of ADC risks in line with Mastercard's network security standards.

Source authority: Mastercard SPME §8.6.2, §8.8.1, §10.2.

Source authority: Mastercard SPME §8.8.1.

--- a/policies/bram_response/rules.yaml
+++ b/policies/bram_response/rules.yaml
@@ -1,14 +1,18 @@
 program: BRAM
-authority: Mastercard SPME §8.6.2, §10.2
+authority: Mastercard SPME 8.6.2, 10.2, 8.8.1
 response_window_days: 180
 required_evidence:
   - transaction_monitoring_records
   - corrective_action_plan
-  - police_report  # Mandatory inclusion per updated SPME §8.6.2
+  - police_report  # Mandatory inclusion per updated SPME 8.6.2
+  - merchant_application_and_agreement  # As required by SPME 8.8.1
+  - remediation_plan  # Detailed remediation and investigation plan per SPME 8.8.1
+  - merchant_business_overview  # Including URLs and product descriptions per SPME 8.8.1
+  - service_provider_identity  # For involved service providers per SPME 8.8.1
 halt_actions:
   - halt_new_merchant_onboarding
 internal_notification_hours: 24
 agent_owner: bram_response_agent
 
-# Reflects updated police report requirement and acknowledges Mastercard's exclusive authority to determine ADC Event occurrence and responsibility as clarified in SPME §10.2.
-# Policy recognizes Mastercard's sole discretion in classifying and consolidating ADC Events to ensure proper investigation and response procedures.
+# Updated to incorporate new Acquirer reporting requirements from SPME 8.8.1, including detailed timelines and documentation obligations for investigations.
+# This aligns the BRAM response policy with Mastercard's specified evidence and procedural expectations for case responses under sections 8.6.2, 10.2, and now 8.8.1, ensuring comprehensive compliance and clear guidelines for agent actions.

--- a/policies/bram_response/policy.md
+++ b/policies/bram_response/policy.md
@@ -1,29 +1,30 @@
 # BRAM Investigation Response
 
-When Mastercard issues a Business Risk Assessment and Mitigation (BRAM) investigation
-notice for one of our merchants, the acquirer must halt new merchant onboarding
-immediately and submit an evidence package within one hundred eighty (180) days
-of receipt of the notice.
+When Mastercard issues a Business Risk Assessment and Mitigation (BRAM) investigation notice for one of our merchants, the acquirer must halt new merchant onboarding immediately and submit an evidence package within one hundred eighty (180) days of receipt of the notice.
 
 ## Required actions
 
 1. Halt new merchant onboarding for the merchant under investigation.
-2. Compile and submit an evidence package containing:
+2. Compile and submit to Mastercard, within the required timeframes, an evidence package including:
    - Transaction monitoring records covering the prior 180 days.
-   - A written corrective action plan.
-   - Documentation of any police reports related to alleged coercion claims if applicable.
+   - A detailed remediation plan describing the incident and corrective actions taken.
+   - A copy of the Merchant application and signed Merchant Agreement with legal name, doing business as name, address, principal owner(s), and signature.
+   - A summarized overview of the Merchant's business operations, including website URLs and product/service descriptions.
+   - Documentation linking any violating URL to the Acquirer's approved Merchant and its URL.
+   - Dates of first transactions submitted for each approved and any violating URL.
+   - Total monthly number and volume of Mastercard transactions for the Merchant for the duration of the relationship or previous 12 months.
+   - Identification of any Service Provider involved in signing the Merchant.
+   - MATCH system inquiry results if used, and confirmation of addition to MATCH if the Merchant was terminated.
+   - The date processing ceased for the Merchant and, if different, the relationship termination date.
+   Documentation must be provided within two (2) business days if the case is initiated by law enforcement or Mastercard's discretion; otherwise, within five (5) business days of notification.
 3. Notify the Halyard Pay Compliance lead within 24 hours of receipt.
 
 ## Additional Considerations for Coercion Claims
 
-When allegations of coerced Transactions arise, note that Mastercard may extend the usual 120-day
-investigation period at its discretion. At least one claim must include a police report from the Cardholder.
-Transactions reported as Lost or Stolen Fraud (fraud type codes 00 or 01) are subject to investigation,
-though Mastercard may consider other fraud codes. Mastercard will notify issuers with Transactions at the
-merchant within the investigation period to prompt claim submissions.
+When allegations of coerced Transactions arise, note that Mastercard may extend the usual 120-day investigation period at its discretion. At least one claim must include a police report from the Cardholder. Transactions reported as Lost or Stolen Fraud (fraud type codes 00 or 01) are subject to investigation, though Mastercard may consider other fraud codes. Mastercard will notify issuers with Transactions at the merchant within the investigation period to prompt claim submissions.
 
 ## Mastercard's Authority and Determinations on ADC Events
 
 Mastercard retains exclusive authority to determine the occurrence, scope, and responsibility for Account Data Compromise (ADC) Events or Potential ADC Events, including the consolidation of related incidents into single or multiple events where applicable. Mastercard’s decisions in these matters are final and not subject to internal appeal. Customers are advised to seek Mastercard guidance if uncertain about their rights or obligations related to ADC Events. This framework ensures accountability and proper management of ADC risks in line with Mastercard's network security standards.
 
-Source authority: Mastercard SPME §8.6.2, §10.2.+Source authority: Mastercard SPME §8.6.2, §8.8.1, §10.2.