Mastercard SPME §8.8.2 · Sep 2023 → Feb 2024
Acquirer Response Requirements
A new requirement was added for acquirers' Managed Merchant Service Providers (MMSPs) to provide a report explaining why an incident was not identified and how the MMSP improved its services to prevent recurrence.
Security Rules and Procedures—Merchant Edition • 6 February 2024
report reflecting why this matter was not identified by the Acquirer's MMSP and how the MMSP enhanced its service to ensure such incident will not reoccur.
program: BRAM- authority: Mastercard SPME §8.6.2, §10.2+ authority: Mastercard SPME §8.6.2, §8.8.2, §10.2response_window_days: 180required_evidence:- transaction_monitoring_records- corrective_action_plan- police_report # Mandatory inclusion per updated SPME §8.6.2+ - MMSP_incident_non_identification_report # New per SPME §8.8.2 regarding MMSP service improvementhalt_actions:- halt_new_merchant_onboardinginternal_notification_hours: 24agent_owner: bram_response_agent- # Reflects updated police report requirement and acknowledges Mastercard's exclusive authority to determine ADC Event occurrence and responsibility as clarified in SPME §10.2.- # Policy recognizes Mastercard's sole discretion in classifying and consolidating ADC Events to ensure proper investigation and response procedures.+ # Policy updated to include the MMSP incident non-identification and service enhancement report as required by Mastercard SPME §8.8.2.+ # Continues to recognize Mastercard's authority on ADC Event determination as established in SPME §10.2.
BRAM Investigation Response
When Mastercard issues a Business Risk Assessment and Mitigation (BRAM) investigation
notice for one of our merchants, the acquirer must halt new merchant onboarding
immediately and submit an evidence package within one hundred eighty (180) days
of receipt of the notice.
Required actions
-
Halt new merchant onboarding for the merchant under investigation.
-
Compile and submit an evidence package containing:
-
Transaction monitoring records covering the prior 180 days.
-
A written corrective action plan.
-
Documentation of any police reports related to alleged coercion claims if applicable.
- Notify the Halyard Pay Compliance lead within 24 hours of receipt.
Additional Considerations for Coercion Claims
When allegations of coerced Transactions arise, note that Mastercard may extend the usual 120-day
investigation period at its discretion. At least one claim must include a police report from the Cardholder.
Transactions reported as Lost or Stolen Fraud (fraud type codes 00 or 01) are subject to investigation,
though Mastercard may consider other fraud codes. Mastercard will notify issuers with Transactions at the
merchant within the investigation period to prompt claim submissions.
Mastercard’s Requirements for MMSP Incident Reporting
Mastercard requires Merchant Monitoring Service Providers (MMSPs) to submit a report explaining why any
incident was not identified by the MMSP and how the MMSP has enhanced its service to prevent recurrence.
This obligation supplements the BRAM investigation processes and ensures improved incident detection and
response going forward.
## Mastercard's Authority and Determinations on ADC Events
Mastercard retains exclusive authority to determine the occurrence, scope, and responsibility for Account Data Compromise (ADC) Events or Potential ADC Events, including the consolidation of related incidents into single or multiple events where applicable. Mastercard’s decisions in these matters are final and not subject to internal appeal. Customers are advised to seek Mastercard guidance if uncertain about their rights or obligations related to ADC Events. This framework ensures accountability and proper management of ADC risks in line with Mastercard's network security standards.
Source authority: Mastercard SPME §8.6.2, §10.2.����� 6 February 2024 update, §§8.6.2, 8.8.2, 10.2.
BRAM Investigation Response
When Mastercard issues a Business Risk Assessment and Mitigation (BRAM) investigation
notice for one of our merchants, the acquirer must halt new merchant onboarding
immediately and submit an evidence package within one hundred eighty (180) days
of receipt of the notice.
Required actions
-
Halt new merchant onboarding for the merchant under investigation.
-
Compile and submit an evidence package containing:
-
Transaction monitoring records covering the prior 180 days.
-
A written corrective action plan.
-
Documentation of any police reports related to alleged coercion claims if applicable.
- Notify the Halyard Pay Compliance lead within 24 hours of receipt.
Additional Considerations for Coercion Claims
When allegations of coerced Transactions arise, note that Mastercard may extend the usual 120-day
investigation period at its discretion. At least one claim must include a police report from the Cardholder.
Transactions reported as Lost or Stolen Fraud (fraud type codes 00 or 01) are subject to investigation,
though Mastercard may consider other fraud codes. Mastercard will notify issuers with Transactions at the
merchant within the investigation period to prompt claim submissions.
Mastercard’s Requirements for MMSP Incident Reporting
Mastercard requires Merchant Monitoring Service Providers (MMSPs) to submit a report explaining why any
incident was not identified by the MMSP and how the MMSP has enhanced its service to prevent recurrence.
This obligation supplements the BRAM investigation processes and ensures improved incident detection and
response going forward.
## Mastercard's Authority and Determinations on ADC Events
Mastercard retains exclusive authority to determine the occurrence, scope, and responsibility for Account Data Compromise (ADC) Events or Potential ADC Events, including the consolidation of related incidents into single or multiple events where applicable. Mastercard’s decisions in these matters are final and not subject to internal appeal. Customers are advised to seek Mastercard guidance if uncertain about their rights or obligations related to ADC Events. This framework ensures accountability and proper management of ADC risks in line with Mastercard's network security standards.
Source authority: Mastercard SPME §8.6.2, §10.2.����� 6 February 2024 update, §§8.6.2, 8.8.2, 10.2.
Source authority: Mastercard SPME §8.8.2.
--- a/policies/bram_response/rules.yaml +++ b/policies/bram_response/rules.yaml @@ -1,14 +1,15 @@ program: BRAM -authority: Mastercard SPME §8.6.2, §10.2 +authority: Mastercard SPME §8.6.2, §8.8.2, §10.2 response_window_days: 180 required_evidence: - transaction_monitoring_records - corrective_action_plan - police_report # Mandatory inclusion per updated SPME §8.6.2 + - MMSP_incident_non_identification_report # New per SPME §8.8.2 regarding MMSP service improvement halt_actions: - halt_new_merchant_onboarding internal_notification_hours: 24 agent_owner: bram_response_agent -# Reflects updated police report requirement and acknowledges Mastercard's exclusive authority to determine ADC Event occurrence and responsibility as clarified in SPME §10.2. -# Policy recognizes Mastercard's sole discretion in classifying and consolidating ADC Events to ensure proper investigation and response procedures. +# Policy updated to include the MMSP incident non-identification and service enhancement report as required by Mastercard SPME §8.8.2. +# Continues to recognize Mastercard's authority on ADC Event determination as established in SPME §10.2. --- a/policies/bram_response/policy.md +++ b/policies/bram_response/policy.md @@ -22,8 +22,15 @@ though Mastercard may consider other fraud codes. Mastercard will notify issuers with Transactions at the merchant within the investigation period to prompt claim submissions. +## Mastercard’s Requirements for MMSP Incident Reporting + +Mastercard requires Merchant Monitoring Service Providers (MMSPs) to submit a report explaining why any +incident was not identified by the MMSP and how the MMSP has enhanced its service to prevent recurrence. +This obligation supplements the BRAM investigation processes and ensures improved incident detection and +response going forward. + ## Mastercard's Authority and Determinations on ADC Events Mastercard retains exclusive authority to determine the occurrence, scope, and responsibility for Account Data Compromise (ADC) Events or Potential ADC Events, including the consolidation of related incidents into single or multiple events where applicable. Mastercard’s decisions in these matters are final and not subject to internal appeal. Customers are advised to seek Mastercard guidance if uncertain about their rights or obligations related to ADC Events. This framework ensures accountability and proper management of ADC risks in line with Mastercard's network security standards. -Source authority: Mastercard SPME §8.6.2, §10.2.+Source authority: Mastercard SPME 6 February 2024 update, §§8.6.2, 8.8.2, 10.2.