Mastercard SPME §8.9 · Sep 2023 → Feb 2024
Merchant Monitoring Program (MMP)
Mastercard has introduced a new Merchant Monitoring Program encouraging customers to prevent BRAM violations and transaction laundering. Acquirers opting in must use approved Merchant Monitoring Service Providers (MMSPs), with Mastercard maintaining an approved vendors list and contact info for vendor approval.
Mastercard encourages Customers to proactively monitor for and prevent BRAM violations and Merchant Transaction laundering. An Acquirer that chooses to participate in the Merchant Monitoring Program must engage one or more Merchant Monitoring Service Providers (MMSPs) to perform BRAM monitoring and Merchant Transaction laundering detection services on the Acquirer’s behalf. Mastercard maintains a list of vendors approved to perform MMSP Program Service, as described in Mastercard Rules section 7.1. For a current list of approved vendors, or for information on how to become an approved vendor, send an email to MMP@mastercard.com.
program: BRAM- authority: Mastercard SPME §8.6.2, §10.2+ authority: Mastercard SPME 8.6.2, 8.9, 10.29response_window_days: 180required_evidence:- transaction_monitoring_records- corrective_action_plan- - police_report # Mandatory inclusion per updated SPME §8.6.2+ - police_report # Mandatory inclusion per updated SPME 8.6.29halt_actions:- halt_new_merchant_onboardinginternal_notification_hours: 24agent_owner: bram_response_agent- # Reflects updated police report requirement and acknowledges Mastercard's exclusive authority to determine ADC Event occurrence and responsibility as clarified in SPME §10.2.- # Policy recognizes Mastercard's sole discretion in classifying and consolidating ADC Events to ensure proper investigation and response procedures.+ # Incorporates new SPME 8.99 requirement for Acquirers to engage Merchant Monitoring Service Providers (MMSPs) for active BRAM and Merchant Transaction laundering monitoring.+ # This policy mandates cooperation with approved MMSPs to align with Mastercard's enhanced BRAM prevention framework and ensure comprehensive transaction oversight.
BRAM Investigation Response
When Mastercard issues a Business Risk Assessment and Mitigation (BRAM) investigation
notice for one of our merchants, the acquirer must halt new merchant onboarding
immediately and submit an evidence package within one hundred eighty (180) days
of receipt of the notice.
Required actions
-
Halt new merchant onboarding for the merchant under investigation.
-
Compile and submit an evidence package containing:
-
Transaction monitoring records covering the prior 180 days.
-
A written corrective action plan.
-
Documentation of any police reports related to alleged coercion claims if applicable.
- Notify the Halyard Pay Compliance lead within 24 hours of receipt.
## Merchant Monitoring Program and MMSP Engagement Requirement
Mastercard encourages proactive monitoring to prevent BRAM violations and
Merchant Transaction Laundering. Acquirers participating in the Merchant
Monitoring Program must engage one or more Mastercard-approved Merchant
Monitoring Service Providers (MMSPs) to perform BRAM and transaction laundering
monitoring on their behalf. Mastercard maintains and updates the list of approved
MMSP vendors as described in Mastercard Rules section 7.1. Acquirers should contact
MMP@mastercard.com for current vendor listings or to become approved.
Additional Considerations for Coercion Claims
When allegations of coerced Transactions arise, note that Mastercard may extend the usual 120-day
investigation period at its discretion. At least one claim must include a police report from the Cardholder.
Transactions reported as Lost or Stolen Fraud (fraud type codes 00 or 01) are subject to investigation,
though Mastercard may consider other fraud codes. Mastercard will notify issuers with Transactions at the
merchant within the investigation period to prompt claim submissions.
Mastercard's Authority and Determinations on ADC Events
Mastercard retains exclusive authority to determine the occurrence, scope, and responsibility for Account Data Compromise (ADC) Events or Potential ADC Events, including the consolidation of related incidents into single or multiple events where applicable. Mastercard’s decisions in these matters are final and not subject to internal appeal. Customers are advised to seek Mastercard guidance if uncertain about their rights or obligations related to ADC Events. This framework ensures accountability and proper management of ADC risks in line with Mastercard's network security standards.
Source authority: Mastercard SPME §8.6.2, §10.2.78.6.2, 78.9, 710.2.
BRAM Investigation Response
When Mastercard issues a Business Risk Assessment and Mitigation (BRAM) investigation
notice for one of our merchants, the acquirer must halt new merchant onboarding
immediately and submit an evidence package within one hundred eighty (180) days
of receipt of the notice.
Required actions
-
Halt new merchant onboarding for the merchant under investigation.
-
Compile and submit an evidence package containing:
-
Transaction monitoring records covering the prior 180 days.
-
A written corrective action plan.
-
Documentation of any police reports related to alleged coercion claims if applicable.
- Notify the Halyard Pay Compliance lead within 24 hours of receipt.
## Merchant Monitoring Program and MMSP Engagement Requirement
Mastercard encourages proactive monitoring to prevent BRAM violations and
Merchant Transaction Laundering. Acquirers participating in the Merchant
Monitoring Program must engage one or more Mastercard-approved Merchant
Monitoring Service Providers (MMSPs) to perform BRAM and transaction laundering
monitoring on their behalf. Mastercard maintains and updates the list of approved
MMSP vendors as described in Mastercard Rules section 7.1. Acquirers should contact
MMP@mastercard.com for current vendor listings or to become approved.
Additional Considerations for Coercion Claims
When allegations of coerced Transactions arise, note that Mastercard may extend the usual 120-day
investigation period at its discretion. At least one claim must include a police report from the Cardholder.
Transactions reported as Lost or Stolen Fraud (fraud type codes 00 or 01) are subject to investigation,
though Mastercard may consider other fraud codes. Mastercard will notify issuers with Transactions at the
merchant within the investigation period to prompt claim submissions.
Mastercard's Authority and Determinations on ADC Events
Mastercard retains exclusive authority to determine the occurrence, scope, and responsibility for Account Data Compromise (ADC) Events or Potential ADC Events, including the consolidation of related incidents into single or multiple events where applicable. Mastercard’s decisions in these matters are final and not subject to internal appeal. Customers are advised to seek Mastercard guidance if uncertain about their rights or obligations related to ADC Events. This framework ensures accountability and proper management of ADC risks in line with Mastercard's network security standards.
Source authority: Mastercard SPME §8.6.2, §10.2.78.6.2, 78.9, 710.2.
Source authority: Mastercard SPME §8.9.
--- a/policies/bram_response/rules.yaml
+++ b/policies/bram_response/rules.yaml
@@ -1,14 +1,14 @@
program: BRAM
-authority: Mastercard SPME §8.6.2, §10.2
+authority: Mastercard SPME 8.6.2, 8.9, 10.29
response_window_days: 180
required_evidence:
- transaction_monitoring_records
- corrective_action_plan
- - police_report # Mandatory inclusion per updated SPME §8.6.2
+ - police_report # Mandatory inclusion per updated SPME 8.6.29
halt_actions:
- halt_new_merchant_onboarding
internal_notification_hours: 24
agent_owner: bram_response_agent
-# Reflects updated police report requirement and acknowledges Mastercard's exclusive authority to determine ADC Event occurrence and responsibility as clarified in SPME §10.2.
-# Policy recognizes Mastercard's sole discretion in classifying and consolidating ADC Events to ensure proper investigation and response procedures.
+# Incorporates new SPME 8.99 requirement for Acquirers to engage Merchant Monitoring Service Providers (MMSPs) for active BRAM and Merchant Transaction laundering monitoring.
+# This policy mandates cooperation with approved MMSPs to align with Mastercard's enhanced BRAM prevention framework and ensure comprehensive transaction oversight.
--- a/policies/bram_response/policy.md
+++ b/policies/bram_response/policy.md
@@ -14,6 +14,16 @@
- Documentation of any police reports related to alleged coercion claims if applicable.
3. Notify the Halyard Pay Compliance lead within 24 hours of receipt.
+## Merchant Monitoring Program and MMSP Engagement Requirement
+
+Mastercard encourages proactive monitoring to prevent BRAM violations and
+Merchant Transaction Laundering. Acquirers participating in the Merchant
+Monitoring Program must engage one or more Mastercard-approved Merchant
+Monitoring Service Providers (MMSPs) to perform BRAM and transaction laundering
+monitoring on their behalf. Mastercard maintains and updates the list of approved
+MMSP vendors as described in Mastercard Rules section 7.1. Acquirers should contact
+MMP@mastercard.com for current vendor listings or to become approved.
+
## Additional Considerations for Coercion Claims
When allegations of coerced Transactions arise, note that Mastercard may extend the usual 120-day
@@ -26,4 +36,4 @@
Mastercard retains exclusive authority to determine the occurrence, scope, and responsibility for Account Data Compromise (ADC) Events or Potential ADC Events, including the consolidation of related incidents into single or multiple events where applicable. Mastercard’s decisions in these matters are final and not subject to internal appeal. Customers are advised to seek Mastercard guidance if uncertain about their rights or obligations related to ADC Events. This framework ensures accountability and proper management of ADC risks in line with Mastercard's network security standards.
-Source authority: Mastercard SPME §8.6.2, §10.2.+Source authority: Mastercard SPME 78.6.2, 78.9, 710.2.