Mastercard SPME §8.8.4 · Sep 2023 → Feb 2024
Noncompliance Assessment Mitigation
A new section requires Acquirers to have MMSPs report potential merchant violations within 5 business days, investigate and resolve issues within 15 calendar days, provide monthly reports on monitored merchants and violations, adhere to MATCH Standards, and respond to BRAM notifications with detailed incident reports explaining monitoring and detection efforts.
Security Rules and Procedures—Merchant Edition • 6 February 2024
- Require the MMSP to report all identifications of potential Merchant violations to the Acquirer within five (5) business days;
- Within 15 calendar days of receiving MMSP notification of an identification, investigate the potential violation, ensure that all violating activity has ceased, and report the resolution of the identification to the MMSP;
- Provide Mastercard with monthly reports detailing all of its Merchants being monitored as part of the MMP and all violations identified by the MMSP during that time. The reports may be submitted by the MMSP on the Acquirer's behalf; and
- Adhere to the MATCH Standards set forth in Chapter 11, when applicable. If an Acquirer receives a BRAM notification from Mastercard regarding a Merchant that is being monitored as part of the MMP, the Acquirer must provide an MMSP Incident Report as part of its response to the BRAM notification. The report must include:
- The date on which the Acquirer provided the Merchant information to the MMSP;
- Confirmation that the Merchant was persistently monitored;
- The dates and contents of any alerts that the MMSP generated and sent to the Acquirer during the monthly period in which the BRAM notification occurred, and any response or action taken by the Acquirer;
- How and why the BRAM violation was not detected by the MMSP;
- How the MMSP will ensure the detection of future potential Merchant violations of a similar nature.
program: BRAM- authority: Mastercard SPME §8.6.2, §10.2+ authority: Mastercard SPME .6.2, 0.2, .8.4response_window_days: 180required_evidence:- transaction_monitoring_records- corrective_action_plan- - police_report # Mandatory inclusion per updated SPME §8.6.2+ - police_report # Mandatory inclusion per updated SPME .6.2+ - mmsp_incident_report # New requirement per SPME .8.4halt_actions:- halt_new_merchant_onboardinginternal_notification_hours: 24agent_owner: bram_response_agent- # Reflects updated police report requirement and acknowledges Mastercard's exclusive authority to determine ADC Event occurrence and responsibility as clarified in SPME §10.2.- # Policy recognizes Mastercard's sole discretion in classifying and consolidating ADC Events to ensure proper investigation and response procedures.+ # Incorporates updated police report mandate per SPME .6.2 and clarifies Mastercard's exclusive authority on ADC Event determinations as stated in SPME 0.2.+ # Adds new MMSP Incident Report requirement in BRAM responses per SPME .8.4, including timelines for reporting and investigation, monthly merchant monitoring reporting, adherence to MATCH standards, and detailed response content obligations.+ # Ensures comprehensive compliance with new reporting and investigative procedures mandated by Mastercard for the Merchant Monitoring Program.
BRAM Investigation Response
When Mastercard issues a Business Risk Assessment and Mitigation (BRAM) investigation
notice for one of our merchants, the acquirer must halt new merchant onboarding
immediately and submit an evidence package within one hundred eighty (180) days
of receipt of the notice.
Required actions
-
Halt new merchant onboarding for the merchant under investigation.
-
Compile and submit an evidence package containing:
-
Transaction monitoring records covering the prior 180 days.
-
A written corrective action plan.
-
Documentation of any police reports related to alleged coercion claims if applicable.
- Notify the Halyard Pay Compliance lead within 24 hours of receipt.
Additional Considerations for Coercion Claims
When allegations of coerced Transactions arise, note that Mastercard may extend the usual 120-day
investigation period at its discretion. At least one claim must include a police report from the Cardholder.
Transactions reported as Lost or Stolen Fraud (fraud type codes 00 or 01) are subject to investigation,
though Mastercard may consider other fraud codes. Mastercard will notify issuers with Transactions at the
merchant within the investigation period to prompt claim submissions.
## MMSP Involvement and Incident Reporting
Per Mastercard SPME §8.8.4, if the merchant is monitored under the Mastercard Monitoring Program (MMP), the acquirer must:
- Report all identifications of potential merchant violations from the MMSP within five (5) business days.
- Investigate potential violations and confirm cessation of violating activity within 15 calendar days of notification.
- Provide Mastercard monthly reports on monitored merchants and violations identified by the MMSP, which may be submitted by the MMSP on the acquirer's behalf.
- Follow the MATCH Standards outlined in Chapter 11, when applicable.
For any BRAM notification involving a monitored merchant, the acquirer must include an MMSP Incident Report in its response. This report must detail the timing and content of MMSP alerts, actions taken by the acquirer, reasons why the violation was not detected earlier, and plans to improve detection of similar violations.
Mastercard's Authority and Determinations on ADC Events
Mastercard retains exclusive authority to determine the occurrence, scope, and responsibility for Account Data Compromise (ADC) Events or Potential ADC Events, including the consolidation of related incidents into single or multiple events where applicable. Mastercard’s decisions in these matters are final and not subject to internal appeal. Customers are advised to seek Mastercard guidance if uncertain about their rights or obligations related to ADC Events. This framework ensures accountability and proper management of ADC risks in line with Mastercard's network security standards.
Source authority: Mastercard SPME §8.6.2, §8.8.4, §10.2.
BRAM Investigation Response
When Mastercard issues a Business Risk Assessment and Mitigation (BRAM) investigation
notice for one of our merchants, the acquirer must halt new merchant onboarding
immediately and submit an evidence package within one hundred eighty (180) days
of receipt of the notice.
Required actions
-
Halt new merchant onboarding for the merchant under investigation.
-
Compile and submit an evidence package containing:
-
Transaction monitoring records covering the prior 180 days.
-
A written corrective action plan.
-
Documentation of any police reports related to alleged coercion claims if applicable.
- Notify the Halyard Pay Compliance lead within 24 hours of receipt.
Additional Considerations for Coercion Claims
When allegations of coerced Transactions arise, note that Mastercard may extend the usual 120-day
investigation period at its discretion. At least one claim must include a police report from the Cardholder.
Transactions reported as Lost or Stolen Fraud (fraud type codes 00 or 01) are subject to investigation,
though Mastercard may consider other fraud codes. Mastercard will notify issuers with Transactions at the
merchant within the investigation period to prompt claim submissions.
## MMSP Involvement and Incident Reporting
Per Mastercard SPME §8.8.4, if the merchant is monitored under the Mastercard Monitoring Program (MMP), the acquirer must:
- Report all identifications of potential merchant violations from the MMSP within five (5) business days.
- Investigate potential violations and confirm cessation of violating activity within 15 calendar days of notification.
- Provide Mastercard monthly reports on monitored merchants and violations identified by the MMSP, which may be submitted by the MMSP on the acquirer's behalf.
- Follow the MATCH Standards outlined in Chapter 11, when applicable.
For any BRAM notification involving a monitored merchant, the acquirer must include an MMSP Incident Report in its response. This report must detail the timing and content of MMSP alerts, actions taken by the acquirer, reasons why the violation was not detected earlier, and plans to improve detection of similar violations.
Mastercard's Authority and Determinations on ADC Events
Mastercard retains exclusive authority to determine the occurrence, scope, and responsibility for Account Data Compromise (ADC) Events or Potential ADC Events, including the consolidation of related incidents into single or multiple events where applicable. Mastercard’s decisions in these matters are final and not subject to internal appeal. Customers are advised to seek Mastercard guidance if uncertain about their rights or obligations related to ADC Events. This framework ensures accountability and proper management of ADC risks in line with Mastercard's network security standards.
Source authority: Mastercard SPME §8.6.2, §8.8.4, §10.2.
Source authority: Mastercard SPME §8.8.4.
--- a/policies/bram_response/rules.yaml +++ b/policies/bram_response/rules.yaml @@ -1,14 +1,16 @@ program: BRAM -authority: Mastercard SPME §8.6.2, §10.2 +authority: Mastercard SPME .6.2, 0.2, .8.4 response_window_days: 180 required_evidence: - transaction_monitoring_records - corrective_action_plan - - police_report # Mandatory inclusion per updated SPME §8.6.2 + - police_report # Mandatory inclusion per updated SPME .6.2 + - mmsp_incident_report # New requirement per SPME .8.4 halt_actions: - halt_new_merchant_onboarding internal_notification_hours: 24 agent_owner: bram_response_agent -# Reflects updated police report requirement and acknowledges Mastercard's exclusive authority to determine ADC Event occurrence and responsibility as clarified in SPME §10.2. -# Policy recognizes Mastercard's sole discretion in classifying and consolidating ADC Events to ensure proper investigation and response procedures. +# Incorporates updated police report mandate per SPME .6.2 and clarifies Mastercard's exclusive authority on ADC Event determinations as stated in SPME 0.2. +# Adds new MMSP Incident Report requirement in BRAM responses per SPME .8.4, including timelines for reporting and investigation, monthly merchant monitoring reporting, adherence to MATCH standards, and detailed response content obligations. +# Ensures comprehensive compliance with new reporting and investigative procedures mandated by Mastercard for the Merchant Monitoring Program. --- a/policies/bram_response/policy.md +++ b/policies/bram_response/policy.md @@ -22,8 +22,19 @@ though Mastercard may consider other fraud codes. Mastercard will notify issuers with Transactions at the merchant within the investigation period to prompt claim submissions. +## MMSP Involvement and Incident Reporting + +Per Mastercard SPME §8.8.4, if the merchant is monitored under the Mastercard Monitoring Program (MMP), the acquirer must: + +- Report all identifications of potential merchant violations from the MMSP within five (5) business days. +- Investigate potential violations and confirm cessation of violating activity within 15 calendar days of notification. +- Provide Mastercard monthly reports on monitored merchants and violations identified by the MMSP, which may be submitted by the MMSP on the acquirer's behalf. +- Follow the MATCH Standards outlined in Chapter 11, when applicable. + +For any BRAM notification involving a monitored merchant, the acquirer must include an MMSP Incident Report in its response. This report must detail the timing and content of MMSP alerts, actions taken by the acquirer, reasons why the violation was not detected earlier, and plans to improve detection of similar violations. + ## Mastercard's Authority and Determinations on ADC Events Mastercard retains exclusive authority to determine the occurrence, scope, and responsibility for Account Data Compromise (ADC) Events or Potential ADC Events, including the consolidation of related incidents into single or multiple events where applicable. Mastercard’s decisions in these matters are final and not subject to internal appeal. Customers are advised to seek Mastercard guidance if uncertain about their rights or obligations related to ADC Events. This framework ensures accountability and proper management of ADC risks in line with Mastercard's network security standards. -Source authority: Mastercard SPME §8.6.2, §10.2.+Source authority: Mastercard SPME §8.6.2, §8.8.4, §10.2.