Mastercard SPME §8.8.4 · Sep 2023 → Feb 2024

Noncompliance Assessment Mitigation

substantive

A new section requires Acquirers to have MMSPs report potential merchant violations within 5 business days, investigate and resolve issues within 15 calendar days, provide monthly reports on monitored merchants and violations, adhere to MATCH Standards, and respond to BRAM notifications with detailed incident reports explaining monitoring and detection efforts.

Sources Mastercard SPME · Sep 2023 PDF Mastercard SPME · Feb 2024 · page 93 PDF BRAM Response current
Also in §8.x this release breaking §8.6.5 Chargeback Responsibility substantive §8.4 Questionable Merchant Audit Program (QMAP) substantive §8.4.2 Mastercard Commencement of an Investigation substantive §8.4.3 of this manual, or substantive §8.4.6 Mastercard Determination substantive §8.4.8 Fraud Recovery substantive §8.6 Coercion Program substantive §8.6.1 Issuer Submissions substantive §8.6.2 Investigation Process substantive §8.6.7 Franchise Management Program (FMP) Questionnaire-based Review substantive §8.7.1 Definitions substantive §8.7.3 Mastercard Notification to Acquirers substantive §8.8 Business Risk Assessment and Mitigation (BRAM) Program substantive §8.8.1 BRAM Investigation Process substantive §8.8.2 Acquirer Response Requirements substantive §8.9 Merchant Monitoring Program (MMP) substantive §8.9.1 MMP Participation Requirements
Why these edits? The new obligations require detailed MMSP Incident Reports in response to BRAM notifications, expanding the existing BRAM Investigation Response policy to include timelines for reporting, investigation, monthly reporting, and adherence to MATCH Standards.
Mastercard SPME §8.8.4
This section was substantively restructured between versions (0% text overlap). Compare the texts directly below.
Before · Sep 2023
After · Feb 2024 · page 93

Security Rules and Procedures—Merchant Edition • 6 February 2024

  • Require the MMSP to report all identifications of potential Merchant violations to the Acquirer within five (5) business days;
  • Within 15 calendar days of receiving MMSP notification of an identification, investigate the potential violation, ensure that all violating activity has ceased, and report the resolution of the identification to the MMSP;
  • Provide Mastercard with monthly reports detailing all of its Merchants being monitored as part of the MMP and all violations identified by the MMSP during that time. The reports may be submitted by the MMSP on the Acquirer's behalf; and
  • Adhere to the MATCH Standards set forth in Chapter 11, when applicable. If an Acquirer receives a BRAM notification from Mastercard regarding a Merchant that is being monitored as part of the MMP, the Acquirer must provide an MMSP Incident Report as part of its response to the BRAM notification. The report must include:
  • The date on which the Acquirer provided the Merchant information to the MMSP;
  • Confirmation that the Merchant was persistently monitored;
  • The dates and contents of any alerts that the MMSP generated and sent to the Acquirer during the monthly period in which the BRAM notification occurred, and any response or action taken by the Acquirer;
  • How and why the BRAM violation was not detected by the MMSP;
  • How the MMSP will ensure the detection of future potential Merchant violations of a similar nature.
Halyard Pay · 2 files
program: BRAM
- authority: Mastercard SPME §8.6.2, §10.2
+ authority: Mastercard SPME .6.2, 0.2, .8.4
response_window_days: 180
required_evidence:
- transaction_monitoring_records
- corrective_action_plan
- - police_report # Mandatory inclusion per updated SPME §8.6.2
+ - police_report # Mandatory inclusion per updated SPME .6.2
+ - mmsp_incident_report # New requirement per SPME .8.4
halt_actions:
- halt_new_merchant_onboarding
internal_notification_hours: 24
agent_owner: bram_response_agent
 
- # Reflects updated police report requirement and acknowledges Mastercard's exclusive authority to determine ADC Event occurrence and responsibility as clarified in SPME §10.2.
- # Policy recognizes Mastercard's sole discretion in classifying and consolidating ADC Events to ensure proper investigation and response procedures.
+ # Incorporates updated police report mandate per SPME .6.2 and clarifies Mastercard's exclusive authority on ADC Event determinations as stated in SPME 0.2.
+ # Adds new MMSP Incident Report requirement in BRAM responses per SPME .8.4, including timelines for reporting and investigation, monthly merchant monitoring reporting, adherence to MATCH standards, and detailed response content obligations.
+ # Ensures comprehensive compliance with new reporting and investigative procedures mandated by Mastercard for the Merchant Monitoring Program.

BRAM Investigation Response

When Mastercard issues a Business Risk Assessment and Mitigation (BRAM) investigation

notice for one of our merchants, the acquirer must halt new merchant onboarding

immediately and submit an evidence package within one hundred eighty (180) days

of receipt of the notice.

Required actions

  1. Halt new merchant onboarding for the merchant under investigation.

  2. Compile and submit an evidence package containing:

  • Transaction monitoring records covering the prior 180 days.

  • A written corrective action plan.

  • Documentation of any police reports related to alleged coercion claims if applicable.

  1. Notify the Halyard Pay Compliance lead within 24 hours of receipt.

Additional Considerations for Coercion Claims

When allegations of coerced Transactions arise, note that Mastercard may extend the usual 120-day

investigation period at its discretion. At least one claim must include a police report from the Cardholder.

Transactions reported as Lost or Stolen Fraud (fraud type codes 00 or 01) are subject to investigation,

though Mastercard may consider other fraud codes. Mastercard will notify issuers with Transactions at the

merchant within the investigation period to prompt claim submissions.

## MMSP Involvement and Incident Reporting

Per Mastercard SPME §8.8.4, if the merchant is monitored under the Mastercard Monitoring Program (MMP), the acquirer must:

- Report all identifications of potential merchant violations from the MMSP within five (5) business days.

- Investigate potential violations and confirm cessation of violating activity within 15 calendar days of notification.

- Provide Mastercard monthly reports on monitored merchants and violations identified by the MMSP, which may be submitted by the MMSP on the acquirer's behalf.

- Follow the MATCH Standards outlined in Chapter 11, when applicable.

For any BRAM notification involving a monitored merchant, the acquirer must include an MMSP Incident Report in its response. This report must detail the timing and content of MMSP alerts, actions taken by the acquirer, reasons why the violation was not detected earlier, and plans to improve detection of similar violations.

Mastercard's Authority and Determinations on ADC Events

Mastercard retains exclusive authority to determine the occurrence, scope, and responsibility for Account Data Compromise (ADC) Events or Potential ADC Events, including the consolidation of related incidents into single or multiple events where applicable. Mastercard’s decisions in these matters are final and not subject to internal appeal. Customers are advised to seek Mastercard guidance if uncertain about their rights or obligations related to ADC Events. This framework ensures accountability and proper management of ADC risks in line with Mastercard's network security standards.

Source authority: Mastercard SPME §8.6.2, §8.8.4, §10.2.

policies/bram_response/policy.md — after applying change

BRAM Investigation Response

When Mastercard issues a Business Risk Assessment and Mitigation (BRAM) investigation

notice for one of our merchants, the acquirer must halt new merchant onboarding

immediately and submit an evidence package within one hundred eighty (180) days

of receipt of the notice.

Required actions

  1. Halt new merchant onboarding for the merchant under investigation.

  2. Compile and submit an evidence package containing:

  • Transaction monitoring records covering the prior 180 days.

  • A written corrective action plan.

  • Documentation of any police reports related to alleged coercion claims if applicable.

  1. Notify the Halyard Pay Compliance lead within 24 hours of receipt.

Additional Considerations for Coercion Claims

When allegations of coerced Transactions arise, note that Mastercard may extend the usual 120-day

investigation period at its discretion. At least one claim must include a police report from the Cardholder.

Transactions reported as Lost or Stolen Fraud (fraud type codes 00 or 01) are subject to investigation,

though Mastercard may consider other fraud codes. Mastercard will notify issuers with Transactions at the

merchant within the investigation period to prompt claim submissions.

## MMSP Involvement and Incident Reporting

Per Mastercard SPME §8.8.4, if the merchant is monitored under the Mastercard Monitoring Program (MMP), the acquirer must:

- Report all identifications of potential merchant violations from the MMSP within five (5) business days.

- Investigate potential violations and confirm cessation of violating activity within 15 calendar days of notification.

- Provide Mastercard monthly reports on monitored merchants and violations identified by the MMSP, which may be submitted by the MMSP on the acquirer's behalf.

- Follow the MATCH Standards outlined in Chapter 11, when applicable.

For any BRAM notification involving a monitored merchant, the acquirer must include an MMSP Incident Report in its response. This report must detail the timing and content of MMSP alerts, actions taken by the acquirer, reasons why the violation was not detected earlier, and plans to improve detection of similar violations.

Mastercard's Authority and Determinations on ADC Events

Mastercard retains exclusive authority to determine the occurrence, scope, and responsibility for Account Data Compromise (ADC) Events or Potential ADC Events, including the consolidation of related incidents into single or multiple events where applicable. Mastercard’s decisions in these matters are final and not subject to internal appeal. Customers are advised to seek Mastercard guidance if uncertain about their rights or obligations related to ADC Events. This framework ensures accountability and proper management of ADC risks in line with Mastercard's network security standards.

Source authority: Mastercard SPME §8.6.2, §8.8.4, §10.2.

Source authority: Mastercard SPME §8.8.4.

--- a/policies/bram_response/rules.yaml
+++ b/policies/bram_response/rules.yaml
@@ -1,14 +1,16 @@
 program: BRAM
-authority: Mastercard SPME §8.6.2, §10.2
+authority: Mastercard SPME .6.2, 0.2, .8.4
 response_window_days: 180
 required_evidence:
   - transaction_monitoring_records
   - corrective_action_plan
-  - police_report  # Mandatory inclusion per updated SPME §8.6.2
+  - police_report  # Mandatory inclusion per updated SPME .6.2
+  - mmsp_incident_report  # New requirement per SPME .8.4
 halt_actions:
   - halt_new_merchant_onboarding
 internal_notification_hours: 24
 agent_owner: bram_response_agent
 
-# Reflects updated police report requirement and acknowledges Mastercard's exclusive authority to determine ADC Event occurrence and responsibility as clarified in SPME §10.2.
-# Policy recognizes Mastercard's sole discretion in classifying and consolidating ADC Events to ensure proper investigation and response procedures.
+# Incorporates updated police report mandate per SPME .6.2 and clarifies Mastercard's exclusive authority on ADC Event determinations as stated in SPME 0.2.
+# Adds new MMSP Incident Report requirement in BRAM responses per SPME .8.4, including timelines for reporting and investigation, monthly merchant monitoring reporting, adherence to MATCH standards, and detailed response content obligations.
+# Ensures comprehensive compliance with new reporting and investigative procedures mandated by Mastercard for the Merchant Monitoring Program.

--- a/policies/bram_response/policy.md
+++ b/policies/bram_response/policy.md
@@ -22,8 +22,19 @@
 though Mastercard may consider other fraud codes. Mastercard will notify issuers with Transactions at the
 merchant within the investigation period to prompt claim submissions.
 
+## MMSP Involvement and Incident Reporting
+
+Per Mastercard SPME §8.8.4, if the merchant is monitored under the Mastercard Monitoring Program (MMP), the acquirer must:
+
+- Report all identifications of potential merchant violations from the MMSP within five (5) business days.
+- Investigate potential violations and confirm cessation of violating activity within 15 calendar days of notification.
+- Provide Mastercard monthly reports on monitored merchants and violations identified by the MMSP, which may be submitted by the MMSP on the acquirer's behalf.
+- Follow the MATCH Standards outlined in Chapter 11, when applicable.
+
+For any BRAM notification involving a monitored merchant, the acquirer must include an MMSP Incident Report in its response. This report must detail the timing and content of MMSP alerts, actions taken by the acquirer, reasons why the violation was not detected earlier, and plans to improve detection of similar violations.
+
 ## Mastercard's Authority and Determinations on ADC Events
 
 Mastercard retains exclusive authority to determine the occurrence, scope, and responsibility for Account Data Compromise (ADC) Events or Potential ADC Events, including the consolidation of related incidents into single or multiple events where applicable. Mastercard’s decisions in these matters are final and not subject to internal appeal. Customers are advised to seek Mastercard guidance if uncertain about their rights or obligations related to ADC Events. This framework ensures accountability and proper management of ADC risks in line with Mastercard's network security standards.
 
-Source authority: Mastercard SPME §8.6.2, §10.2.+Source authority: Mastercard SPME §8.6.2, §8.8.4, §10.2.