Mastercard SPME §10.5 · Feb 2024 → Sep 2024

Alternative Acquirer Investigation (AAI) Standards

breaking

The entire detailed process and penalties related to remediation action plans and repeated ADC events, including timelines and independent examinations, were removed, leaving only a statement that Mastercard retains its rights to require forensic examinations and that other obligations continue as previously set.

Sources Mastercard SPME · Feb 2024 · page 120 PDF Mastercard SPME · Sep 2024 · page 124 PDF Content Moderation current
Also in §10.x this release breaking §10.2 Policy Concerning Account Data Compromise Events and Potential Account Data breaking §10.3.1 Time-Specific Procedures for ADC Events and Potential ADC Events breaking §10.3.2 Ongoing Procedures for ADC Events and Potential ADC Events substantive §10 Should the responsible Customer cause a PFI to conduct an examination, the responsible substantive §10.1 Applicability and Defined Terms substantive §10.3 Responsibilities in Connection with ADC Events and Potential ADC Events substantive §10.4 Forensic Report substantive §10.6 Mastercard Determination of ADC Event or Potential ADC Event substantive §10.6.2 Potential Reduction of Financial Responsibility substantive §10.6.4 Determination of Operational Reimbursement (OR) substantive §10.7 Assessments and/or Disqualification for Noncompliance
Why these edits? The removal of detailed requirements and penalties for remediation action plans and repeated ADC events in section 10.5 significantly changes the obligations related to brand integrity investigations and responses. This impacts the Content Moderation (BRAM Brand Integrity) policy which cited section 10.5, reducing procedural and penalty details previously mandated.
Mastercard SPME §10.5
Security Rules and Procedures—Merchant Edition • 6 February August 2024 ¶ that the responsible Customer will take to ensure that Account data are no longer at risk of ¶ compromise. Failure to provide Mastercard with the remediation action plan within the 10-day ¶ time frame may result in a noncompliance assessment as described in section 10.7. ¶ Within twenty (20) business days after Mastercard provides approval of the responsible ¶ Customer's remediation action plan, the responsible Customer must implement all required ¶ steps of the action plan, including but not limited to officer certification to Mastercard that ¶ such remediation action plan has taken effect. Failure to implement the remediation action plan ¶ to the satisfaction of Mastercard within the 20-day time frame may result in a noncompliance ¶ assessment as described in section 10.7. ¶ If the Merchant (or Agent) that was the subject of an ADC Event or Potential ADC Event ¶ investigated by the responsible Customer is the subject of a different Event within thirty-six ¶ (36) months of the date on which Mastercard provided notice to the responsible Customer of ¶ the initial Event, Mastercard: ¶ • ¶ Will require the responsible Customer to engage the services of a PFI to conduct an ¶ independent examination of the Merchant or other Agent in accordance with section 10.3.1 ¶ of this chapter 10; and ¶ • ¶ May impose an assessment of up to USD 25,000 upon the responsible Customer for failure ¶ to safeguard Account data. Except as specifically set forth in this section Section 10.5, all other Mastercard and Customer rights and obligations with respect to an ADC Event or Potential ADC Event shall continue with respect to any ADC Event or Potential ADC Event that a responsible Customer itself elects to investigate in accordance with this section Section 10.5. Further, and for the avoidance of doubt, Mastercard has a right at any time to require a responsible Customer to cause a PFI to conduct a forensic examination of a Merchant notwithstanding the provisions of this section Section 10.5.
Halyard Pay · 2 files
program: Content Moderation (BRAM)
authority: Mastercard SPME §10.5, §9.4.1, and §8.9.1
prohibited_categories:
- counterfeit_goods
- illegal_drugs
- adult_content_violations
- intellectual_property_violations
- gambling_in_restricted_jurisdictions
review_cadence: weekly
human_review_trigger_business_days: 1
confirmed_violation_action: suspend_processing
case_documentation_required: true
agent_owner: content_mod_agent
 
# Updated to reflect Mastercard SPME §9.4.1 enhancements requiring Merchants to manage flagged adult content with timely removals, provide monthly reports to Acquirers (and Mastercard on request), and maintain appeal processes.
# Added Mastercard SPME §8.9.1 obligations for Acquirers to register MMSP as service providers and provide detailed Merchant data for continuous monitoring focused on BRAM content violations.
+ # Removed detailed remediation action plan and repeated ADC event penalty provisions from Mastercard SPME §10.5 to align with the revised, streamlined responsibilities. Content Moderation policy reflects this narrowing of procedural requirements, focusing on ongoing monitoring and enforcement rather than imposed remediation timelines or penalties.
# These updates increase Merchant and Acquirer accountability and strengthen monitoring of Brand Integrity risks associated with BRAM content.
# Removed previously outdated Merchant registration and MCC/TCC-based identification specifics no longer mandated.

Content Moderation (BRAM Brand Integrity)

Mastercard's Business Risk Assessment and Mitigation (BRAM) program prohibits acquirers from processing transactions for merchants engaged in activities violating Mastercard's acceptable use standards. Halyard Pay monitors merchant storefront content and transaction data to identify and remediate prohibited content such as adult content and content violating applicable laws or Mastercard standards.

Prohibited categories

Merchants facilitating counterfeit goods, illegal drugs, unlawful adult content, intellectual property infringement, or gambling services in restricted jurisdictions face immediate review and possible suspension.

Required actions

  1. Review merchant storefront content weekly via automated and manual methods.

  2. Flag merchants with content in prohibited categories for human review within one business day.

  3. Suspend processing if prohibited content is confirmed.

  4. Document findings and remediation steps.

  5. Ensure merchants comply with requirements to manage flagged adult content, including timely removal upon verified complaints, monthly reporting to Acquirers on flagged content and actions taken, and appeals processes as per Mastercard SPME §9.4.1.

  6. Support Acquirers in obtaining temporary access to restricted merchant content if needed.

Acquirer and MMSP Cooperation Requirements

Per Mastercard SPME §8.9.1, Halyard Pay as the Merchant Monitoring Service Provider (MMSP) requires Acquirers to register the MMSP per Mastercard Rules 7.10, provide comprehensive merchant information (including legal and trade names, addresses, and URLs) needed for monitoring, and ensure persistent monitoring of each merchant's activity to detect potential violations related to BRAM content, products and services, and merchant transaction laundering.

Note: Mastercard SPME removed prior MCC and Transaction Category Code requirements and registration mandates for non-face-to-face adult content transactions but added detailed content management and reporting obligations under §9.4.1, which Halyard Pay integrates with emphasis on lawful, consented adult content and proactive merchant reporting.

The prior detailed remediation action plan requirements and penalties related to repeated Account Data Compromise (ADC) events under Mastercard SPME §10.5 have been removed, reducing procedural burdens and penalty assessments for Brand Integrity investigations.

Source authority: Mastercard SPME §§8.9.1, 9.4.1, 10.5.

policies/content_moderation/policy.md — after applying change

Content Moderation (BRAM Brand Integrity)

Mastercard's Business Risk Assessment and Mitigation (BRAM) program prohibits acquirers from processing transactions for merchants engaged in activities violating Mastercard's acceptable use standards. Halyard Pay monitors merchant storefront content and transaction data to identify and remediate prohibited content such as adult content and content violating applicable laws or Mastercard standards.

Prohibited categories

Merchants facilitating counterfeit goods, illegal drugs, unlawful adult content, intellectual property infringement, or gambling services in restricted jurisdictions face immediate review and possible suspension.

Required actions

  1. Review merchant storefront content weekly via automated and manual methods.

  2. Flag merchants with content in prohibited categories for human review within one business day.

  3. Suspend processing if prohibited content is confirmed.

  4. Document findings and remediation steps.

  5. Ensure merchants comply with requirements to manage flagged adult content, including timely removal upon verified complaints, monthly reporting to Acquirers on flagged content and actions taken, and appeals processes as per Mastercard SPME §9.4.1.

  6. Support Acquirers in obtaining temporary access to restricted merchant content if needed.

Acquirer and MMSP Cooperation Requirements

Per Mastercard SPME §8.9.1, Halyard Pay as the Merchant Monitoring Service Provider (MMSP) requires Acquirers to register the MMSP per Mastercard Rules 7.10, provide comprehensive merchant information (including legal and trade names, addresses, and URLs) needed for monitoring, and ensure persistent monitoring of each merchant's activity to detect potential violations related to BRAM content, products and services, and merchant transaction laundering.

Note: Mastercard SPME removed prior MCC and Transaction Category Code requirements and registration mandates for non-face-to-face adult content transactions but added detailed content management and reporting obligations under §9.4.1, which Halyard Pay integrates with emphasis on lawful, consented adult content and proactive merchant reporting.

The prior detailed remediation action plan requirements and penalties related to repeated Account Data Compromise (ADC) events under Mastercard SPME §10.5 have been removed, reducing procedural burdens and penalty assessments for Brand Integrity investigations.

Source authority: Mastercard SPME §§8.9.1, 9.4.1, 10.5.

Source authority: Mastercard SPME §10.5.

--- a/policies/content_moderation/rules.yaml
+++ b/policies/content_moderation/rules.yaml
@@ -14,5 +14,6 @@
 
 # Updated to reflect Mastercard SPME §9.4.1 enhancements requiring Merchants to manage flagged adult content with timely removals, provide monthly reports to Acquirers (and Mastercard on request), and maintain appeal processes.
 # Added Mastercard SPME §8.9.1 obligations for Acquirers to register MMSP as service providers and provide detailed Merchant data for continuous monitoring focused on BRAM content violations.
+# Removed detailed remediation action plan and repeated ADC event penalty provisions from Mastercard SPME §10.5 to align with the revised, streamlined responsibilities. Content Moderation policy reflects this narrowing of procedural requirements, focusing on ongoing monitoring and enforcement rather than imposed remediation timelines or penalties.
 # These updates increase Merchant and Acquirer accountability and strengthen monitoring of Brand Integrity risks associated with BRAM content.
-# Removed previously outdated Merchant registration and MCC/TCC-based identification specifics no longer mandated.+# Removed previously outdated Merchant registration and MCC/TCC-based identification specifics no longer mandated.

--- a/policies/content_moderation/policy.md
+++ b/policies/content_moderation/policy.md
@@ -21,4 +21,6 @@
 
 Note: Mastercard SPME removed prior MCC and Transaction Category Code requirements and registration mandates for non-face-to-face adult content transactions but added detailed content management and reporting obligations under §9.4.1, which Halyard Pay integrates with emphasis on lawful, consented adult content and proactive merchant reporting.
 
+The prior detailed remediation action plan requirements and penalties related to repeated Account Data Compromise (ADC) events under Mastercard SPME §10.5 have been removed, reducing procedural burdens and penalty assessments for Brand Integrity investigations.
+
 Source authority: Mastercard SPME §§8.9.1, 9.4.1, 10.5.