Mastercard SPME §10.6.2 · Feb 2024 → Sep 2024
Potential Reduction of Financial Responsibility
The revised section broadens the scope from specifically terminal servicers to any compromised entity, replacing Terminal Servicer (TS) references with Merchant and clarifying requirements. The compliance demonstration shifts slightly, including updated references to programs and reporting obligations, but obligations to report, cooperate, and remediate remain. Responsibility monitoring via My Company Manager references was removed.
Security Rules and Procedures—Merchant Edition • 6 February 2024
application, notifying all impacted parties of the impending financial obligation or compensation, as applicable. It is the sole responsibility of each Customer, not Mastercard, to include current and complete information in the My Company Manager application. 10.6.2.1 Potential Reduction of Financial Responsibility for Terminal Servicer ADC Events Notwithstanding a Mastercard determination that an ADC Event occurred, Mastercard may consider the following actions taken by the compromised TS or the responsible Customer, as applicable, to establish, implement, and maintain procedures and support best practices to safeguard Account data prior to, during, and after the ADC Event or Potential ADC Event, in order to relieve, partially or fully, an otherwise responsible Customer of responsibility for any assessments, ADC operational reimbursement, and/or investigative costs. In determining whether to relieve a responsible Customer of any or all financial responsibility, Mastercard may consider whether the Terminal Servicer or the responsible Customer, as applicable, complied with all of the following requirements:
- Substantiation to Mastercard from a PCI SSC-approved QSA of the compromised TS’s compliance with the PCI DSS at the time of the ADC Event or Potential ADC Event.
- Reporting that certifies any Terminal Servicer(s) associated with the ADC Event or Potential ADC Event as compliant with the PCI DSS and all applicable Mastercard SDP Program requirements at the time of the ADC Event or Potential ADC Event in accordance with section 2.2.3 of this manual. Such reporting must also affirm that all third party-provided payment applications used by the Terminal Servicer(s) associated with the ADC Event or Potential ADC Event are compliant with the Payment Card Industry Payment Application Data Security Standard or the Payment Card Industry Secure Software Standard, as applicable. The applicability of the PCI PA-DSS to third party-provided payment applications is defined in the PCI PA-DSS Program Guide and the applicability of the PCI Secure Software Standard to third party-provided payment software is defined in the PCI Secure Software Program Guide, found at www.pcisecuritystandards.org.
- Registration of any TS(s) associated with the ADC Event through Mastercard Connect, in accordance with Chapter 7 of the Mastercard Rules, within 10 calendar days of the TS or the responsible Customer being deemed aware of the ADC Event or Potential ADC Event.
- Notification of an ADC Event or Potential ADC Event to and cooperation with Mastercard and, as appropriate, law enforcement authorities.
- Verification that the PFI investigation was initiated within seventy-two (72) hours of the ADC Event or Potential ADC Event and completed as soon as practical.
- Timely receipt by Mastercard of the unedited (by other than the forensic examiner) forensic examination findings.
- Confirmation that any TS(s) associated with the ADC Event or Potential ADC Event completed all of the containment recommendations set forth in the forensic report, and that each such TS revalidated its compliance with the PCI DSS to Mastercard within 90 calendar days after the conclusion of the PFI’s investigation and has additionally demonstrated compliance with the DESV appendix of the PCI DSS within twelve (12) months from achieving full compliance with the PCI DSS. Account Data Compromise Events 10.6.2.1 Potential Reduction of Financial Responsibility for Terminal Servicer ADC Events Security Rules and Procedures—Merchant Edition • 6 February 2024 In connection with its evaluation of the Customer’s or its TS’s actions, Mastercard will consider, and may draw adverse inferences from, evidence that a Customer or its TS(s) deleted or altered data. As soon as practicable, Mastercard will contact the Customer’s Security Contact, Principal Contact, or Account Data Compromise Contact as they are listed in the My Company Manager application, notifying all impacted parties of the impending financial obligation or compensation, as applicable. It is the sole responsibility of each Customer, not Mastercard, to include current and complete information in the Company Contact Management application.
Notwithstanding a Mastercard determination that an ADC Event occurred, Mastercard may consider any actions taken by the compromised entity to establish, implement, and maintain procedures and support best practices to safeguard Account data prior to, during, and after the ADC Event or Potential ADC Event, in order to relieve, partially or fully, an otherwise responsible Customer of responsibility for any assessments, ADC operational reimbursement, and/or investigative costs. In determining whether to relieve a responsible Customer of any or all financial responsibility, Mastercard may consider whether the Customer has complied with all of the following requirements:
- Substantiation to Mastercard from a PCI SSC-approved Qualified Security Assessor (QSA) of the compromised entity’s compliance with the PCI DSS at the time of the ADC Event or Potential ADC Event.
- Reporting that certifies any Merchant(s) associated with the ADC Event or Potential ADC Event as compliant with the PCI DSS and all applicable Mastercard Site Data Protection (SDP) Program requirements at the time of the ADC Event or Potential ADC Event in accordance with section 2.2.1 of this manual. Such reporting must also affirm that all third party-provided payment applications used by the Merchant(s) associated with the ADC Event or Potential ADC Event are compliant with the Payment Card Industry Payment Account Data Compromise Events
program: Chargeback Handling- authority: Mastercard SPME §10.1, §10.3, §10.4, and §11.5+ authority: Mastercard SPME 10.1, 10.3, 10.4, .6.2, 11.5acknowledgement_business_days: 1lifecycle_states:- first_presentment- chargeback- second_presentment- pre_arbitration- arbitrationevidence_requirements:first_presentment:- transaction_receipt- authorization_recordchargeback:- merchant_rebuttal_letter- delivery_confirmation- customer_communication- fraud_and_chargeback_data_analysissecond_presentment:- compelling_evidence- signed_cardholder_agreementpre_arbitration:- full_dispute_record- prior_correspondencearbitration:- full_dispute_record- arbitration_filingagent_owner: chargeback_agent- # Added evidence requirement for fraud and chargeback data analysis to address new MATCH reason codes- # related to excessive chargebacks and fraud ratios as introduced in Mastercard SPME §11.5 update,- # supporting compliance with chargeback management standards per Mastercard SPME §10.1 and §10.3.+ # Updated authority to include Mastercard SPME 10.6.2 reflecting expansion of financial responsibility considerations from terminal servicers to any compromised entity.+ # This affects assessment procedures and evidentiary tracking in chargeback handling per Mastercard standards.
Chargeback Handling
Chargebacks are cardholder-initiated disputes against a transaction. Halyard Pay, acting as the acquirer, manages disputes from initial presentment through potential arbitration, adhering to Mastercard's requirements to protect all parties involved.
Lifecycle overview
Disputes progress through defined phases: first presentment, chargeback, second presentment (re-presentment), pre-arbitration, and arbitration. Compliance with evidence standards and timelines at each step is essential to prevent adverse rulings.
Required actions
-
Acknowledge incoming chargebacks within one business day.
-
Gather necessary evidence relevant to the dispute stage.
-
Submit second presentments when liability is disputable, supported by strong documentation.
-
Escalate to pre-arbitration and arbitration only after issuer rejection of second presentment.
-
Retain comprehensive case documentation for auditing and reporting purposes.
-
Provide all requested documentation promptly to Mastercard during investigations or appeals as governed by sections 10.3 and 10.4 of the Mastercard SPME.
Additionally, in cases involving Account Data Compromise (ADC) events, Halyard Pay recognizes that Mastercard may adjust financial responsibilities based on the compromised party's adherence to PCI DSS and Mastercard Site Data Protection Program requirements before, during, and after the event, as detailed in section 10.6.2 of the Mastercard SPME. This consideration impacts our chargeback risk assessments and may influence liability in ADC-related chargebacks.
Monitoring and Risk Factors
Halyard Pay evaluates merchant risk using updated Mastercard MATCH Listing Reason Codes, including new, specific definitions for elevated chargeback and fraud concerns:
-
Laundering: Merchant presenting invalid transaction records rather than bona fide sales.
-
Excessive Chargebacks: Monthly Mastercard chargebacks exceed 1% of sales transactions with total chargebacks ≥ USD 5,000.
-
Excessive Fraud: Fraud-to-sales ratio of 8% or more, with at least 10 fraudulent transactions totaling USD 5,000+ in a calendar month.
These clarified definitions, part of Mastercard's updated SPME MATCH Listing Reason Codes (see section 11.5), guide Halyard Pay’s risk assessments and chargeback management protocols to align with Mastercard’s evolving standards.
Source authority: Mastercard SPME §§10.1, 10.3, 10.4, 10.6.2, 11.5.
Chargeback Handling
Chargebacks are cardholder-initiated disputes against a transaction. Halyard Pay, acting as the acquirer, manages disputes from initial presentment through potential arbitration, adhering to Mastercard's requirements to protect all parties involved.
Lifecycle overview
Disputes progress through defined phases: first presentment, chargeback, second presentment (re-presentment), pre-arbitration, and arbitration. Compliance with evidence standards and timelines at each step is essential to prevent adverse rulings.
Required actions
-
Acknowledge incoming chargebacks within one business day.
-
Gather necessary evidence relevant to the dispute stage.
-
Submit second presentments when liability is disputable, supported by strong documentation.
-
Escalate to pre-arbitration and arbitration only after issuer rejection of second presentment.
-
Retain comprehensive case documentation for auditing and reporting purposes.
-
Provide all requested documentation promptly to Mastercard during investigations or appeals as governed by sections 10.3 and 10.4 of the Mastercard SPME.
Additionally, in cases involving Account Data Compromise (ADC) events, Halyard Pay recognizes that Mastercard may adjust financial responsibilities based on the compromised party's adherence to PCI DSS and Mastercard Site Data Protection Program requirements before, during, and after the event, as detailed in section 10.6.2 of the Mastercard SPME. This consideration impacts our chargeback risk assessments and may influence liability in ADC-related chargebacks.
Monitoring and Risk Factors
Halyard Pay evaluates merchant risk using updated Mastercard MATCH Listing Reason Codes, including new, specific definitions for elevated chargeback and fraud concerns:
-
Laundering: Merchant presenting invalid transaction records rather than bona fide sales.
-
Excessive Chargebacks: Monthly Mastercard chargebacks exceed 1% of sales transactions with total chargebacks ≥ USD 5,000.
-
Excessive Fraud: Fraud-to-sales ratio of 8% or more, with at least 10 fraudulent transactions totaling USD 5,000+ in a calendar month.
These clarified definitions, part of Mastercard's updated SPME MATCH Listing Reason Codes (see section 11.5), guide Halyard Pay’s risk assessments and chargeback management protocols to align with Mastercard’s evolving standards.
Source authority: Mastercard SPME §§10.1, 10.3, 10.4, 10.6.2, 11.5.
Source authority: Mastercard SPME §10.6.2.
--- a/policies/chargeback_handling/rules.yaml
+++ b/policies/chargeback_handling/rules.yaml
@@ -1,5 +1,5 @@
program: Chargeback Handling
-authority: Mastercard SPME §10.1, §10.3, §10.4, and §11.5
+authority: Mastercard SPME 10.1, 10.3, 10.4, .6.2, 11.5
acknowledgement_business_days: 1
lifecycle_states:
- first_presentment
@@ -27,6 +27,5 @@
- arbitration_filing
agent_owner: chargeback_agent
-# Added evidence requirement for fraud and chargeback data analysis to address new MATCH reason codes
-# related to excessive chargebacks and fraud ratios as introduced in Mastercard SPME §11.5 update,
-# supporting compliance with chargeback management standards per Mastercard SPME §10.1 and §10.3.
+# Updated authority to include Mastercard SPME 10.6.2 reflecting expansion of financial responsibility considerations from terminal servicers to any compromised entity.
+# This affects assessment procedures and evidentiary tracking in chargeback handling per Mastercard standards.
--- a/policies/chargeback_handling/policy.md
+++ b/policies/chargeback_handling/policy.md
@@ -15,6 +15,8 @@
5. Retain comprehensive case documentation for auditing and reporting purposes.
6. Provide all requested documentation promptly to Mastercard during investigations or appeals as governed by sections 10.3 and 10.4 of the Mastercard SPME.
+Additionally, in cases involving Account Data Compromise (ADC) events, Halyard Pay recognizes that Mastercard may adjust financial responsibilities based on the compromised party's adherence to PCI DSS and Mastercard Site Data Protection Program requirements before, during, and after the event, as detailed in section 10.6.2 of the Mastercard SPME. This consideration impacts our chargeback risk assessments and may influence liability in ADC-related chargebacks.
+
## Monitoring and Risk Factors
Halyard Pay evaluates merchant risk using updated Mastercard MATCH Listing Reason Codes, including new, specific definitions for elevated chargeback and fraud concerns:
@@ -25,4 +27,4 @@
These clarified definitions, part of Mastercard's updated SPME MATCH Listing Reason Codes (see section 11.5), guide Halyard Pay’s risk assessments and chargeback management protocols to align with Mastercard’s evolving standards.
-Source authority: Mastercard SPME §§10.1, 10.3, 10.4, 11.5.+Source authority: Mastercard SPME §§10.1, 10.3, 10.4, 10.6.2, 11.5.