Mastercard SPME §10.1 · Feb 2024 → Sep 2024

Applicability and Defined Terms

substantive

Added new definitions for "Potential Account Data Compromise Event" and "Qualified Forensic Investigator" to clarify roles and events related to account data compromise. Minor formatting changes were made to references for terms in the Definitions appendix.

Sources Mastercard SPME · Feb 2024 · page 114 PDF Mastercard SPME · Sep 2024 · page 117 PDF Chargeback Handling current
Also in §10.x this release breaking §10.2 Policy Concerning Account Data Compromise Events and Potential Account Data breaking §10.3.1 Time-Specific Procedures for ADC Events and Potential ADC Events breaking §10.3.2 Ongoing Procedures for ADC Events and Potential ADC Events breaking §10.5 Alternative Acquirer Investigation (AAI) Standards substantive §10 Should the responsible Customer cause a PFI to conduct an examination, the responsible substantive §10.3 Responsibilities in Connection with ADC Events and Potential ADC Events substantive §10.4 Forensic Report substantive §10.6 Mastercard Determination of ADC Event or Potential ADC Event substantive §10.6.2 Potential Reduction of Financial Responsibility substantive §10.6.4 Determination of Operational Reimbursement (OR) substantive §10.7 Assessments and/or Disqualification for Noncompliance
Why these edits? The addition of definitions for "Potential Account Data Compromise Event" and "Qualified Forensic Investigator" directly affects obligations related to investigating and handling chargebacks associated with account data compromises.
Mastercard SPME §10.1
Security Rules and Procedures—Merchant Edition • 6 February August 2024 An entity engaged to conduct an independent forensic investigation to assess the cause, scope, magnitude, duration, and effects of an ADC Event or Potential ADC Event. The PFI helps determine the occurrence of a Cardholder data compromise and when and how such Cardholder data compromise may have occurred. The entity must be qualified to act as a PFI under the PCI Forensic Investigator Program and must work for a Qualified Security Assessor (QSA) operating a dedicated forensic investigation practice. Potential Account Data Compromise Event or Potential ADC Event An occurrence that could result, directly or indirectly, in the unauthorized access to or disclosure of Account data or the unauthorized manipulation of Account data controls, such as Account usage and spending limits. Sensitive Authentication Data This term has the meaning set forth in the Payment Card Industry Data Security Standard (PCI DSS), and includes, by way of example and not limitation, the full contents of a Card’s magnetic stripe or the equivalent on a chip, Card validation code 2 (CVC 2) data, and PIN or PIN block data. Standards This term appears in the Definitions "Definitions" appendix at the end of this manual. Wallet Token Requestor This term appears in the Definitions "Definitions" appendix at the end of this manual. Terms used in this chapter (such as Issuer, Acquirer, and Card) are used consistent with the definitions of such terms set forth in the Definitions "Definitions" appendix at the end of this manual. With regard to Accounts and Card issuance, Mastercard Standards reflect the use of different types of licensing structures and relationships, including: • Principal Customer and Affiliate Customer; • Association Customer and Affiliate Customer; • Principal Debit Licensee and Affiliate Debit Licensee; and • Type I TPP and Affiliate Customer (in the U.S. Region only). For purposes of this chapter, an Issuer is the entity having responsibility in accordance with the Standards and, if applicable, any license agreement between the entity and Mastercard, with respect to Activity pertaining to a particular Card or Account.
Halyard Pay · 2 files
program: Chargeback Handling
authority: Mastercard SPME §10.1, §10.3, §10.4, and §11.5
acknowledgement_business_days: 1
lifecycle_states:
- first_presentment
- chargeback
- second_presentment
- pre_arbitration
- arbitration
evidence_requirements:
first_presentment:
- transaction_receipt
- authorization_record
chargeback:
- merchant_rebuttal_letter
- delivery_confirmation
- customer_communication
- fraud_and_chargeback_data_analysis
second_presentment:
- compelling_evidence
- signed_cardholder_agreement
pre_arbitration:
- full_dispute_record
- prior_correspondence
arbitration:
- full_dispute_record
- arbitration_filing
+ account_data_compromise_investigation:
+ - qualified_forensic_investigator_report
+ - investigation_findings
agent_owner: chargeback_agent
 
- # Added evidence requirement for fraud and chargeback data analysis to address new MATCH reason codes
- # related to excessive chargebacks and fraud ratios as introduced in Mastercard SPME §11.5 update,
- # supporting compliance with chargeback management standards per Mastercard SPME §10.1 and §10.3.
+ # Added new lifecycle state 'account_data_compromise_investigation' with specific evidence requirements
+ # to comply with new Mastercard definitions related to Potential Account Data Compromise Events and the need
+ # for Qualified Forensic Investigators to assess such events, as introduced in Mastercard SPME §10.1 update.
+ # This ensures thorough investigation and proper documentation in chargeback cases involving account data compromises.

Chargeback Handling

Chargebacks are cardholder-initiated disputes against a transaction. Halyard Pay, acting as the acquirer, manages disputes from initial presentment through potential arbitration, adhering to Mastercard's requirements to protect all parties involved. involved, including obligations related to account data compromise events.

Lifecycle overview

Disputes progress through defined phases: first presentment, chargeback, second presentment (re-presentment), pre-arbitration, and arbitration. Compliance with evidence standards and timelines at each step is essential to prevent adverse rulings.

Required actions

  1. Acknowledge incoming chargebacks within one business day.

  2. Gather necessary evidence relevant to the dispute stage. stage, including any forensic investigation findings if an account data compromise event is suspected.

  3. Engage qualified forensic investigators (PFIs) when a potential account data compromise event is identified, to assess cause, scope, and impact, as defined in Mastercard's standards.

4. Submit second presentments when liability is disputable, supported by strong documentation.

4. 5. Escalate to pre-arbitration and arbitration only after issuer rejection of second presentment.

5. 6. Retain comprehensive case documentation for auditing and reporting purposes.

6. 7. Provide all requested documentation promptly to Mastercard during investigations or appeals as governed by sections 10.3 and 10.4 of the Mastercard SPME.

Monitoring and Risk Factors

Halyard Pay evaluates merchant risk using updated Mastercard MATCH Listing Reason Codes, including new, specific definitions for elevated chargeback and fraud concerns:

  • Laundering: Merchant presenting invalid transaction records rather than bona fide sales.

  • Excessive Chargebacks: Monthly Mastercard chargebacks exceed 1% of sales transactions with total chargebacks ≥ USD 5,000.

  • Excessive Fraud: Fraud-to-sales ratio of 8% or more, with at least 10 fraudulent transactions totaling USD 5,000+ in a calendar month.

These clarified definitions, part of Mastercard's updated SPME MATCH Listing Reason Codes (see section 11.5), guide Halyard Pay’s risk assessments and chargeback management protocols to align with Mastercard’s evolving standards.

Source authority: Mastercard SPME §§10.1, 10.3, 10.4, 11.5.

policies/chargeback_handling/policy.md — after applying change

Chargeback Handling

Chargebacks are cardholder-initiated disputes against a transaction. Halyard Pay, acting as the acquirer, manages disputes from initial presentment through potential arbitration, adhering to Mastercard's requirements to protect all parties involved. involved, including obligations related to account data compromise events.

Lifecycle overview

Disputes progress through defined phases: first presentment, chargeback, second presentment (re-presentment), pre-arbitration, and arbitration. Compliance with evidence standards and timelines at each step is essential to prevent adverse rulings.

Required actions

  1. Acknowledge incoming chargebacks within one business day.

  2. Gather necessary evidence relevant to the dispute stage. stage, including any forensic investigation findings if an account data compromise event is suspected.

  3. Engage qualified forensic investigators (PFIs) when a potential account data compromise event is identified, to assess cause, scope, and impact, as defined in Mastercard's standards.

4. Submit second presentments when liability is disputable, supported by strong documentation.

4. 5. Escalate to pre-arbitration and arbitration only after issuer rejection of second presentment.

5. 6. Retain comprehensive case documentation for auditing and reporting purposes.

6. 7. Provide all requested documentation promptly to Mastercard during investigations or appeals as governed by sections 10.3 and 10.4 of the Mastercard SPME.

Monitoring and Risk Factors

Halyard Pay evaluates merchant risk using updated Mastercard MATCH Listing Reason Codes, including new, specific definitions for elevated chargeback and fraud concerns:

  • Laundering: Merchant presenting invalid transaction records rather than bona fide sales.

  • Excessive Chargebacks: Monthly Mastercard chargebacks exceed 1% of sales transactions with total chargebacks ≥ USD 5,000.

  • Excessive Fraud: Fraud-to-sales ratio of 8% or more, with at least 10 fraudulent transactions totaling USD 5,000+ in a calendar month.

These clarified definitions, part of Mastercard's updated SPME MATCH Listing Reason Codes (see section 11.5), guide Halyard Pay’s risk assessments and chargeback management protocols to align with Mastercard’s evolving standards.

Source authority: Mastercard SPME §§10.1, 10.3, 10.4, 11.5.

Source authority: Mastercard SPME §10.1.

--- a/policies/chargeback_handling/rules.yaml
+++ b/policies/chargeback_handling/rules.yaml
@@ -25,8 +25,12 @@
   arbitration:
     - full_dispute_record
     - arbitration_filing
+  account_data_compromise_investigation:
+    - qualified_forensic_investigator_report
+    - investigation_findings
 agent_owner: chargeback_agent
 
-# Added evidence requirement for fraud and chargeback data analysis to address new MATCH reason codes
-# related to excessive chargebacks and fraud ratios as introduced in Mastercard SPME §11.5 update,
-# supporting compliance with chargeback management standards per Mastercard SPME §10.1 and §10.3.
+# Added new lifecycle state 'account_data_compromise_investigation' with specific evidence requirements
+# to comply with new Mastercard definitions related to Potential Account Data Compromise Events and the need
+# for Qualified Forensic Investigators to assess such events, as introduced in Mastercard SPME §10.1 update.
+# This ensures thorough investigation and proper documentation in chargeback cases involving account data compromises.
--- a/policies/chargeback_handling/policy.md
+++ b/policies/chargeback_handling/policy.md
@@ -1,6 +1,6 @@
 # Chargeback Handling
 
-Chargebacks are cardholder-initiated disputes against a transaction. Halyard Pay, acting as the acquirer, manages disputes from initial presentment through potential arbitration, adhering to Mastercard's requirements to protect all parties involved.
+Chargebacks are cardholder-initiated disputes against a transaction. Halyard Pay, acting as the acquirer, manages disputes from initial presentment through potential arbitration, adhering to Mastercard's requirements to protect all parties involved, including obligations related to account data compromise events.
 
 ## Lifecycle overview
 
@@ -9,11 +9,12 @@
 ## Required actions
 
 1. Acknowledge incoming chargebacks within one business day.
-2. Gather necessary evidence relevant to the dispute stage.
-3. Submit second presentments when liability is disputable, supported by strong documentation.
-4. Escalate to pre-arbitration and arbitration only after issuer rejection of second presentment.
-5. Retain comprehensive case documentation for auditing and reporting purposes.
-6. Provide all requested documentation promptly to Mastercard during investigations or appeals as governed by sections 10.3 and 10.4 of the Mastercard SPME.
+2. Gather necessary evidence relevant to the dispute stage, including any forensic investigation findings if an account data compromise event is suspected.
+3. Engage qualified forensic investigators (PFIs) when a potential account data compromise event is identified, to assess cause, scope, and impact, as defined in Mastercard's standards.
+4. Submit second presentments when liability is disputable, supported by strong documentation.
+5. Escalate to pre-arbitration and arbitration only after issuer rejection of second presentment.
+6. Retain comprehensive case documentation for auditing and reporting purposes.
+7. Provide all requested documentation promptly to Mastercard during investigations or appeals as governed by sections 10.3 and 10.4 of the Mastercard SPME.
 
 ## Monitoring and Risk Factors