Mastercard SPME §8.9 · Sep 2023 → Feb 2024

Merchant Monitoring Program (MMP)

substantive

Mastercard has introduced a new Merchant Monitoring Program encouraging customers to prevent BRAM violations and transaction laundering. Acquirers opting in must use approved Merchant Monitoring Service Providers (MMSPs), with Mastercard maintaining an approved vendors list and contact info for vendor approval.

Sources Mastercard SPME · Sep 2023 PDF Mastercard SPME · Feb 2024 · page 93 PDF BRAM Response current
Also in §8.x this release breaking §8.6.5 Chargeback Responsibility substantive §8.4 Questionable Merchant Audit Program (QMAP) substantive §8.4.2 Mastercard Commencement of an Investigation substantive §8.4.3 of this manual, or substantive §8.4.6 Mastercard Determination substantive §8.4.8 Fraud Recovery substantive §8.6 Coercion Program substantive §8.6.1 Issuer Submissions substantive §8.6.2 Investigation Process substantive §8.6.7 Franchise Management Program (FMP) Questionnaire-based Review substantive §8.7.1 Definitions substantive §8.7.3 Mastercard Notification to Acquirers substantive §8.8 Business Risk Assessment and Mitigation (BRAM) Program substantive §8.8.1 BRAM Investigation Process substantive §8.8.2 Acquirer Response Requirements substantive §8.8.4 Noncompliance Assessment Mitigation substantive §8.9.1 MMP Participation Requirements
Why these edits? The new obligation for acquirers to engage Merchant Monitoring Service Providers (MMSPs) for BRAM monitoring directly impacts the BRAM Investigation Response policy, as it introduces formalized third-party monitoring requirements to prevent BRAM violations.
Mastercard SPME §8.9
This section was substantively restructured between versions (0% text overlap). Compare the texts directly below.
Before · Sep 2023
After · Feb 2024 · page 93

Mastercard encourages Customers to proactively monitor for and prevent BRAM violations and Merchant Transaction laundering. An Acquirer that chooses to participate in the Merchant Monitoring Program must engage one or more Merchant Monitoring Service Providers (MMSPs) to perform BRAM monitoring and Merchant Transaction laundering detection services on the Acquirer’s behalf. Mastercard maintains a list of vendors approved to perform MMSP Program Service, as described in Mastercard Rules section 7.1. For a current list of approved vendors, or for information on how to become an approved vendor, send an email to MMP@mastercard.com.

Halyard Pay · 2 files
program: BRAM
- authority: Mastercard SPME §8.6.2, §10.2
+ authority: Mastercard SPME 8.6.2, 8.9, 10.29
response_window_days: 180
required_evidence:
- transaction_monitoring_records
- corrective_action_plan
- - police_report # Mandatory inclusion per updated SPME §8.6.2
+ - police_report # Mandatory inclusion per updated SPME 8.6.29
halt_actions:
- halt_new_merchant_onboarding
internal_notification_hours: 24
agent_owner: bram_response_agent
 
- # Reflects updated police report requirement and acknowledges Mastercard's exclusive authority to determine ADC Event occurrence and responsibility as clarified in SPME §10.2.
- # Policy recognizes Mastercard's sole discretion in classifying and consolidating ADC Events to ensure proper investigation and response procedures.
+ # Incorporates new SPME 8.99 requirement for Acquirers to engage Merchant Monitoring Service Providers (MMSPs) for active BRAM and Merchant Transaction laundering monitoring.
+ # This policy mandates cooperation with approved MMSPs to align with Mastercard's enhanced BRAM prevention framework and ensure comprehensive transaction oversight.

BRAM Investigation Response

When Mastercard issues a Business Risk Assessment and Mitigation (BRAM) investigation

notice for one of our merchants, the acquirer must halt new merchant onboarding

immediately and submit an evidence package within one hundred eighty (180) days

of receipt of the notice.

Required actions

  1. Halt new merchant onboarding for the merchant under investigation.

  2. Compile and submit an evidence package containing:

  • Transaction monitoring records covering the prior 180 days.

  • A written corrective action plan.

  • Documentation of any police reports related to alleged coercion claims if applicable.

  1. Notify the Halyard Pay Compliance lead within 24 hours of receipt.

## Merchant Monitoring Program and MMSP Engagement Requirement

Mastercard encourages proactive monitoring to prevent BRAM violations and

Merchant Transaction Laundering. Acquirers participating in the Merchant

Monitoring Program must engage one or more Mastercard-approved Merchant

Monitoring Service Providers (MMSPs) to perform BRAM and transaction laundering

monitoring on their behalf. Mastercard maintains and updates the list of approved

MMSP vendors as described in Mastercard Rules section 7.1. Acquirers should contact

MMP@mastercard.com for current vendor listings or to become approved.

Additional Considerations for Coercion Claims

When allegations of coerced Transactions arise, note that Mastercard may extend the usual 120-day

investigation period at its discretion. At least one claim must include a police report from the Cardholder.

Transactions reported as Lost or Stolen Fraud (fraud type codes 00 or 01) are subject to investigation,

though Mastercard may consider other fraud codes. Mastercard will notify issuers with Transactions at the

merchant within the investigation period to prompt claim submissions.

Mastercard's Authority and Determinations on ADC Events

Mastercard retains exclusive authority to determine the occurrence, scope, and responsibility for Account Data Compromise (ADC) Events or Potential ADC Events, including the consolidation of related incidents into single or multiple events where applicable. Mastercard’s decisions in these matters are final and not subject to internal appeal. Customers are advised to seek Mastercard guidance if uncertain about their rights or obligations related to ADC Events. This framework ensures accountability and proper management of ADC risks in line with Mastercard's network security standards.

Source authority: Mastercard SPME §8.6.2, §10.2.78.6.2, 78.9, 710.2.

policies/bram_response/policy.md — after applying change

BRAM Investigation Response

When Mastercard issues a Business Risk Assessment and Mitigation (BRAM) investigation

notice for one of our merchants, the acquirer must halt new merchant onboarding

immediately and submit an evidence package within one hundred eighty (180) days

of receipt of the notice.

Required actions

  1. Halt new merchant onboarding for the merchant under investigation.

  2. Compile and submit an evidence package containing:

  • Transaction monitoring records covering the prior 180 days.

  • A written corrective action plan.

  • Documentation of any police reports related to alleged coercion claims if applicable.

  1. Notify the Halyard Pay Compliance lead within 24 hours of receipt.

## Merchant Monitoring Program and MMSP Engagement Requirement

Mastercard encourages proactive monitoring to prevent BRAM violations and

Merchant Transaction Laundering. Acquirers participating in the Merchant

Monitoring Program must engage one or more Mastercard-approved Merchant

Monitoring Service Providers (MMSPs) to perform BRAM and transaction laundering

monitoring on their behalf. Mastercard maintains and updates the list of approved

MMSP vendors as described in Mastercard Rules section 7.1. Acquirers should contact

MMP@mastercard.com for current vendor listings or to become approved.

Additional Considerations for Coercion Claims

When allegations of coerced Transactions arise, note that Mastercard may extend the usual 120-day

investigation period at its discretion. At least one claim must include a police report from the Cardholder.

Transactions reported as Lost or Stolen Fraud (fraud type codes 00 or 01) are subject to investigation,

though Mastercard may consider other fraud codes. Mastercard will notify issuers with Transactions at the

merchant within the investigation period to prompt claim submissions.

Mastercard's Authority and Determinations on ADC Events

Mastercard retains exclusive authority to determine the occurrence, scope, and responsibility for Account Data Compromise (ADC) Events or Potential ADC Events, including the consolidation of related incidents into single or multiple events where applicable. Mastercard’s decisions in these matters are final and not subject to internal appeal. Customers are advised to seek Mastercard guidance if uncertain about their rights or obligations related to ADC Events. This framework ensures accountability and proper management of ADC risks in line with Mastercard's network security standards.

Source authority: Mastercard SPME §8.6.2, §10.2.78.6.2, 78.9, 710.2.

Source authority: Mastercard SPME §8.9.

--- a/policies/bram_response/rules.yaml
+++ b/policies/bram_response/rules.yaml
@@ -1,14 +1,14 @@
 program: BRAM
-authority: Mastercard SPME §8.6.2, §10.2
+authority: Mastercard SPME 8.6.2, 8.9, 10.29
 response_window_days: 180
 required_evidence:
   - transaction_monitoring_records
   - corrective_action_plan
-  - police_report  # Mandatory inclusion per updated SPME §8.6.2
+  - police_report  # Mandatory inclusion per updated SPME 8.6.29
 halt_actions:
   - halt_new_merchant_onboarding
 internal_notification_hours: 24
 agent_owner: bram_response_agent
 
-# Reflects updated police report requirement and acknowledges Mastercard's exclusive authority to determine ADC Event occurrence and responsibility as clarified in SPME §10.2.
-# Policy recognizes Mastercard's sole discretion in classifying and consolidating ADC Events to ensure proper investigation and response procedures.
+# Incorporates new SPME 8.99 requirement for Acquirers to engage Merchant Monitoring Service Providers (MMSPs) for active BRAM and Merchant Transaction laundering monitoring.
+# This policy mandates cooperation with approved MMSPs to align with Mastercard's enhanced BRAM prevention framework and ensure comprehensive transaction oversight.
--- a/policies/bram_response/policy.md
+++ b/policies/bram_response/policy.md
@@ -14,6 +14,16 @@
    - Documentation of any police reports related to alleged coercion claims if applicable.
 3. Notify the Halyard Pay Compliance lead within 24 hours of receipt.
 
+## Merchant Monitoring Program and MMSP Engagement Requirement
+
+Mastercard encourages proactive monitoring to prevent BRAM violations and
+Merchant Transaction Laundering. Acquirers participating in the Merchant
+Monitoring Program must engage one or more Mastercard-approved Merchant
+Monitoring Service Providers (MMSPs) to perform BRAM and transaction laundering
+monitoring on their behalf. Mastercard maintains and updates the list of approved
+MMSP vendors as described in Mastercard Rules section 7.1. Acquirers should contact
+MMP@mastercard.com for current vendor listings or to become approved.
+
 ## Additional Considerations for Coercion Claims
 
 When allegations of coerced Transactions arise, note that Mastercard may extend the usual 120-day
@@ -26,4 +36,4 @@
 
 Mastercard retains exclusive authority to determine the occurrence, scope, and responsibility for Account Data Compromise (ADC) Events or Potential ADC Events, including the consolidation of related incidents into single or multiple events where applicable. Mastercard’s decisions in these matters are final and not subject to internal appeal. Customers are advised to seek Mastercard guidance if uncertain about their rights or obligations related to ADC Events. This framework ensures accountability and proper management of ADC risks in line with Mastercard's network security standards.
 
-Source authority: Mastercard SPME §8.6.2, §10.2.+Source authority: Mastercard SPME 78.6.2, 78.9, 710.2.