Mastercard SPME §8.8.2 · Sep 2023 → Feb 2024

Acquirer Response Requirements

substantive

A new requirement was added for acquirers' Managed Merchant Service Providers (MMSPs) to provide a report explaining why an incident was not identified and how the MMSP improved its services to prevent recurrence.

Sources Mastercard SPME · Sep 2023 PDF Mastercard SPME · Feb 2024 · page 90 PDF BRAM Response current
Also in §8.x this release breaking §8.6.5 Chargeback Responsibility substantive §8.4 Questionable Merchant Audit Program (QMAP) substantive §8.4.2 Mastercard Commencement of an Investigation substantive §8.4.3 of this manual, or substantive §8.4.6 Mastercard Determination substantive §8.4.8 Fraud Recovery substantive §8.6 Coercion Program substantive §8.6.1 Issuer Submissions substantive §8.6.2 Investigation Process substantive §8.6.7 Franchise Management Program (FMP) Questionnaire-based Review substantive §8.7.1 Definitions substantive §8.7.3 Mastercard Notification to Acquirers substantive §8.8 Business Risk Assessment and Mitigation (BRAM) Program substantive §8.8.1 BRAM Investigation Process substantive §8.8.4 Noncompliance Assessment Mitigation substantive §8.9 Merchant Monitoring Program (MMP) substantive §8.9.1 MMP Participation Requirements
Why these edits? The new obligation for MMSPs to provide a report explaining incident non-identification and service improvements aligns with the BRAM Investigation Response policy, which covers the handling of investigations under section 10.2, closely related to 8.8.2 requirements.
Mastercard SPME §8.8.2
This section was substantively restructured between versions (0% text overlap). Compare the texts directly below.
Before · Sep 2023
After · Feb 2024 · page 90

Security Rules and Procedures—Merchant Edition • 6 February 2024

report reflecting why this matter was not identified by the Acquirer's MMSP and how the MMSP enhanced its service to ensure such incident will not reoccur.

Halyard Pay · 2 files
program: BRAM
- authority: Mastercard SPME §8.6.2, §10.2
+ authority: Mastercard SPME §8.6.2, §8.8.2, §10.2
response_window_days: 180
required_evidence:
- transaction_monitoring_records
- corrective_action_plan
- police_report # Mandatory inclusion per updated SPME §8.6.2
+ - MMSP_incident_non_identification_report # New per SPME §8.8.2 regarding MMSP service improvement
halt_actions:
- halt_new_merchant_onboarding
internal_notification_hours: 24
agent_owner: bram_response_agent
 
- # Reflects updated police report requirement and acknowledges Mastercard's exclusive authority to determine ADC Event occurrence and responsibility as clarified in SPME §10.2.
- # Policy recognizes Mastercard's sole discretion in classifying and consolidating ADC Events to ensure proper investigation and response procedures.
+ # Policy updated to include the MMSP incident non-identification and service enhancement report as required by Mastercard SPME §8.8.2.
+ # Continues to recognize Mastercard's authority on ADC Event determination as established in SPME §10.2.

BRAM Investigation Response

When Mastercard issues a Business Risk Assessment and Mitigation (BRAM) investigation

notice for one of our merchants, the acquirer must halt new merchant onboarding

immediately and submit an evidence package within one hundred eighty (180) days

of receipt of the notice.

Required actions

  1. Halt new merchant onboarding for the merchant under investigation.

  2. Compile and submit an evidence package containing:

  • Transaction monitoring records covering the prior 180 days.

  • A written corrective action plan.

  • Documentation of any police reports related to alleged coercion claims if applicable.

  1. Notify the Halyard Pay Compliance lead within 24 hours of receipt.

Additional Considerations for Coercion Claims

When allegations of coerced Transactions arise, note that Mastercard may extend the usual 120-day

investigation period at its discretion. At least one claim must include a police report from the Cardholder.

Transactions reported as Lost or Stolen Fraud (fraud type codes 00 or 01) are subject to investigation,

though Mastercard may consider other fraud codes. Mastercard will notify issuers with Transactions at the

merchant within the investigation period to prompt claim submissions.

Mastercard’s Requirements for MMSP Incident Reporting

Mastercard requires Merchant Monitoring Service Providers (MMSPs) to submit a report explaining why any

incident was not identified by the MMSP and how the MMSP has enhanced its service to prevent recurrence.

This obligation supplements the BRAM investigation processes and ensures improved incident detection and

response going forward.

## Mastercard's Authority and Determinations on ADC Events

Mastercard retains exclusive authority to determine the occurrence, scope, and responsibility for Account Data Compromise (ADC) Events or Potential ADC Events, including the consolidation of related incidents into single or multiple events where applicable. Mastercard’s decisions in these matters are final and not subject to internal appeal. Customers are advised to seek Mastercard guidance if uncertain about their rights or obligations related to ADC Events. This framework ensures accountability and proper management of ADC risks in line with Mastercard's network security standards.

Source authority: Mastercard SPME §8.6.2, §10.2.����� 6 February 2024 update, §§8.6.2, 8.8.2, 10.2.

policies/bram_response/policy.md — after applying change

BRAM Investigation Response

When Mastercard issues a Business Risk Assessment and Mitigation (BRAM) investigation

notice for one of our merchants, the acquirer must halt new merchant onboarding

immediately and submit an evidence package within one hundred eighty (180) days

of receipt of the notice.

Required actions

  1. Halt new merchant onboarding for the merchant under investigation.

  2. Compile and submit an evidence package containing:

  • Transaction monitoring records covering the prior 180 days.

  • A written corrective action plan.

  • Documentation of any police reports related to alleged coercion claims if applicable.

  1. Notify the Halyard Pay Compliance lead within 24 hours of receipt.

Additional Considerations for Coercion Claims

When allegations of coerced Transactions arise, note that Mastercard may extend the usual 120-day

investigation period at its discretion. At least one claim must include a police report from the Cardholder.

Transactions reported as Lost or Stolen Fraud (fraud type codes 00 or 01) are subject to investigation,

though Mastercard may consider other fraud codes. Mastercard will notify issuers with Transactions at the

merchant within the investigation period to prompt claim submissions.

Mastercard’s Requirements for MMSP Incident Reporting

Mastercard requires Merchant Monitoring Service Providers (MMSPs) to submit a report explaining why any

incident was not identified by the MMSP and how the MMSP has enhanced its service to prevent recurrence.

This obligation supplements the BRAM investigation processes and ensures improved incident detection and

response going forward.

## Mastercard's Authority and Determinations on ADC Events

Mastercard retains exclusive authority to determine the occurrence, scope, and responsibility for Account Data Compromise (ADC) Events or Potential ADC Events, including the consolidation of related incidents into single or multiple events where applicable. Mastercard’s decisions in these matters are final and not subject to internal appeal. Customers are advised to seek Mastercard guidance if uncertain about their rights or obligations related to ADC Events. This framework ensures accountability and proper management of ADC risks in line with Mastercard's network security standards.

Source authority: Mastercard SPME §8.6.2, §10.2.����� 6 February 2024 update, §§8.6.2, 8.8.2, 10.2.

Source authority: Mastercard SPME §8.8.2.

--- a/policies/bram_response/rules.yaml
+++ b/policies/bram_response/rules.yaml
@@ -1,14 +1,15 @@
 program: BRAM
-authority: Mastercard SPME §8.6.2, §10.2
+authority: Mastercard SPME §8.6.2, §8.8.2, §10.2
 response_window_days: 180
 required_evidence:
   - transaction_monitoring_records
   - corrective_action_plan
   - police_report  # Mandatory inclusion per updated SPME §8.6.2
+  - MMSP_incident_non_identification_report  # New per SPME §8.8.2 regarding MMSP service improvement
 halt_actions:
   - halt_new_merchant_onboarding
 internal_notification_hours: 24
 agent_owner: bram_response_agent
 
-# Reflects updated police report requirement and acknowledges Mastercard's exclusive authority to determine ADC Event occurrence and responsibility as clarified in SPME §10.2.
-# Policy recognizes Mastercard's sole discretion in classifying and consolidating ADC Events to ensure proper investigation and response procedures.
+# Policy updated to include the MMSP incident non-identification and service enhancement report as required by Mastercard SPME §8.8.2.
+# Continues to recognize Mastercard's authority on ADC Event determination as established in SPME §10.2.
--- a/policies/bram_response/policy.md
+++ b/policies/bram_response/policy.md
@@ -22,8 +22,15 @@
 though Mastercard may consider other fraud codes. Mastercard will notify issuers with Transactions at the
 merchant within the investigation period to prompt claim submissions.
 
+## Mastercard’s Requirements for MMSP Incident Reporting
+
+Mastercard requires Merchant Monitoring Service Providers (MMSPs) to submit a report explaining why any
+incident was not identified by the MMSP and how the MMSP has enhanced its service to prevent recurrence.
+This obligation supplements the BRAM investigation processes and ensures improved incident detection and
+response going forward.
+
 ## Mastercard's Authority and Determinations on ADC Events
 
 Mastercard retains exclusive authority to determine the occurrence, scope, and responsibility for Account Data Compromise (ADC) Events or Potential ADC Events, including the consolidation of related incidents into single or multiple events where applicable. Mastercard’s decisions in these matters are final and not subject to internal appeal. Customers are advised to seek Mastercard guidance if uncertain about their rights or obligations related to ADC Events. This framework ensures accountability and proper management of ADC risks in line with Mastercard's network security standards.
 
-Source authority: Mastercard SPME §8.6.2, §10.2.+Source authority: Mastercard SPME  6 February 2024 update, §§8.6.2, 8.8.2, 10.2.