Mastercard SPME §10.6.2 · Feb 2024 → Sep 2024

Potential Reduction of Financial Responsibility

substantive

The revised section broadens the scope from specifically terminal servicers to any compromised entity, replacing Terminal Servicer (TS) references with Merchant and clarifying requirements. The compliance demonstration shifts slightly, including updated references to programs and reporting obligations, but obligations to report, cooperate, and remediate remain. Responsibility monitoring via My Company Manager references was removed.

Sources Mastercard SPME · Feb 2024 · page 123 PDF Mastercard SPME · Sep 2024 · page 126 PDF Chargeback Handling current
Also in §10.x this release breaking §10.2 Policy Concerning Account Data Compromise Events and Potential Account Data breaking §10.3.1 Time-Specific Procedures for ADC Events and Potential ADC Events breaking §10.3.2 Ongoing Procedures for ADC Events and Potential ADC Events breaking §10.5 Alternative Acquirer Investigation (AAI) Standards substantive §10 Should the responsible Customer cause a PFI to conduct an examination, the responsible substantive §10.1 Applicability and Defined Terms substantive §10.3 Responsibilities in Connection with ADC Events and Potential ADC Events substantive §10.4 Forensic Report substantive §10.6 Mastercard Determination of ADC Event or Potential ADC Event substantive §10.6.4 Determination of Operational Reimbursement (OR) substantive §10.7 Assessments and/or Disqualification for Noncompliance
Why these edits? The revision broadens financial responsibility considerations from Terminal Servicers to any compromised entity, including Merchants, expanding scope for chargeback assessments and investigative costs, which directly relates to chargeback handling obligations.
Mastercard SPME §10.6.2
This section was substantively restructured between versions (2% text overlap). Compare the texts directly below.
Before · Feb 2024 · page 123

Security Rules and Procedures—Merchant Edition • 6 February 2024

application, notifying all impacted parties of the impending financial obligation or compensation, as applicable. It is the sole responsibility of each Customer, not Mastercard, to include current and complete information in the My Company Manager application. 10.6.2.1 Potential Reduction of Financial Responsibility for Terminal Servicer ADC Events Notwithstanding a Mastercard determination that an ADC Event occurred, Mastercard may consider the following actions taken by the compromised TS or the responsible Customer, as applicable, to establish, implement, and maintain procedures and support best practices to safeguard Account data prior to, during, and after the ADC Event or Potential ADC Event, in order to relieve, partially or fully, an otherwise responsible Customer of responsibility for any assessments, ADC operational reimbursement, and/or investigative costs. In determining whether to relieve a responsible Customer of any or all financial responsibility, Mastercard may consider whether the Terminal Servicer or the responsible Customer, as applicable, complied with all of the following requirements:

  • Substantiation to Mastercard from a PCI SSC-approved QSA of the compromised TS’s compliance with the PCI DSS at the time of the ADC Event or Potential ADC Event.
  • Reporting that certifies any Terminal Servicer(s) associated with the ADC Event or Potential ADC Event as compliant with the PCI DSS and all applicable Mastercard SDP Program requirements at the time of the ADC Event or Potential ADC Event in accordance with section 2.2.3 of this manual. Such reporting must also affirm that all third party-provided payment applications used by the Terminal Servicer(s) associated with the ADC Event or Potential ADC Event are compliant with the Payment Card Industry Payment Application Data Security Standard or the Payment Card Industry Secure Software Standard, as applicable. The applicability of the PCI PA-DSS to third party-provided payment applications is defined in the PCI PA-DSS Program Guide and the applicability of the PCI Secure Software Standard to third party-provided payment software is defined in the PCI Secure Software Program Guide, found at www.pcisecuritystandards.org.
  • Registration of any TS(s) associated with the ADC Event through Mastercard Connect, in accordance with Chapter 7 of the Mastercard Rules, within 10 calendar days of the TS or the responsible Customer being deemed aware of the ADC Event or Potential ADC Event.
  • Notification of an ADC Event or Potential ADC Event to and cooperation with Mastercard and, as appropriate, law enforcement authorities.
  • Verification that the PFI investigation was initiated within seventy-two (72) hours of the ADC Event or Potential ADC Event and completed as soon as practical.
  • Timely receipt by Mastercard of the unedited (by other than the forensic examiner) forensic examination findings.
  • Confirmation that any TS(s) associated with the ADC Event or Potential ADC Event completed all of the containment recommendations set forth in the forensic report, and that each such TS revalidated its compliance with the PCI DSS to Mastercard within 90 calendar days after the conclusion of the PFI’s investigation and has additionally demonstrated compliance with the DESV appendix of the PCI DSS within twelve (12) months from achieving full compliance with the PCI DSS. Account Data Compromise Events 10.6.2.1 Potential Reduction of Financial Responsibility for Terminal Servicer ADC Events Security Rules and Procedures—Merchant Edition • 6 February 2024 In connection with its evaluation of the Customer’s or its TS’s actions, Mastercard will consider, and may draw adverse inferences from, evidence that a Customer or its TS(s) deleted or altered data. As soon as practicable, Mastercard will contact the Customer’s Security Contact, Principal Contact, or Account Data Compromise Contact as they are listed in the My Company Manager application, notifying all impacted parties of the impending financial obligation or compensation, as applicable. It is the sole responsibility of each Customer, not Mastercard, to include current and complete information in the Company Contact Management application.
After · Sep 2024 · page 126

Notwithstanding a Mastercard determination that an ADC Event occurred, Mastercard may consider any actions taken by the compromised entity to establish, implement, and maintain procedures and support best practices to safeguard Account data prior to, during, and after the ADC Event or Potential ADC Event, in order to relieve, partially or fully, an otherwise responsible Customer of responsibility for any assessments, ADC operational reimbursement, and/or investigative costs. In determining whether to relieve a responsible Customer of any or all financial responsibility, Mastercard may consider whether the Customer has complied with all of the following requirements:

  • Substantiation to Mastercard from a PCI SSC-approved Qualified Security Assessor (QSA) of the compromised entity’s compliance with the PCI DSS at the time of the ADC Event or Potential ADC Event.
  • Reporting that certifies any Merchant(s) associated with the ADC Event or Potential ADC Event as compliant with the PCI DSS and all applicable Mastercard Site Data Protection (SDP) Program requirements at the time of the ADC Event or Potential ADC Event in accordance with section 2.2.1 of this manual. Such reporting must also affirm that all third party-provided payment applications used by the Merchant(s) associated with the ADC Event or Potential ADC Event are compliant with the Payment Card Industry Payment Account Data Compromise Events
Halyard Pay · 2 files
program: Chargeback Handling
- authority: Mastercard SPME §10.1, §10.3, §10.4, and §11.5
+ authority: Mastercard SPME 10.1, 10.3, 10.4, .6.2, 11.5
acknowledgement_business_days: 1
lifecycle_states:
- first_presentment
- chargeback
- second_presentment
- pre_arbitration
- arbitration
evidence_requirements:
first_presentment:
- transaction_receipt
- authorization_record
chargeback:
- merchant_rebuttal_letter
- delivery_confirmation
- customer_communication
- fraud_and_chargeback_data_analysis
second_presentment:
- compelling_evidence
- signed_cardholder_agreement
pre_arbitration:
- full_dispute_record
- prior_correspondence
arbitration:
- full_dispute_record
- arbitration_filing
agent_owner: chargeback_agent
 
- # Added evidence requirement for fraud and chargeback data analysis to address new MATCH reason codes
- # related to excessive chargebacks and fraud ratios as introduced in Mastercard SPME §11.5 update,
- # supporting compliance with chargeback management standards per Mastercard SPME §10.1 and §10.3.
+ # Updated authority to include Mastercard SPME 10.6.2 reflecting expansion of financial responsibility considerations from terminal servicers to any compromised entity.
+ # This affects assessment procedures and evidentiary tracking in chargeback handling per Mastercard standards.

Chargeback Handling

Chargebacks are cardholder-initiated disputes against a transaction. Halyard Pay, acting as the acquirer, manages disputes from initial presentment through potential arbitration, adhering to Mastercard's requirements to protect all parties involved.

Lifecycle overview

Disputes progress through defined phases: first presentment, chargeback, second presentment (re-presentment), pre-arbitration, and arbitration. Compliance with evidence standards and timelines at each step is essential to prevent adverse rulings.

Required actions

  1. Acknowledge incoming chargebacks within one business day.

  2. Gather necessary evidence relevant to the dispute stage.

  3. Submit second presentments when liability is disputable, supported by strong documentation.

  4. Escalate to pre-arbitration and arbitration only after issuer rejection of second presentment.

  5. Retain comprehensive case documentation for auditing and reporting purposes.

  6. Provide all requested documentation promptly to Mastercard during investigations or appeals as governed by sections 10.3 and 10.4 of the Mastercard SPME.

Additionally, in cases involving Account Data Compromise (ADC) events, Halyard Pay recognizes that Mastercard may adjust financial responsibilities based on the compromised party's adherence to PCI DSS and Mastercard Site Data Protection Program requirements before, during, and after the event, as detailed in section 10.6.2 of the Mastercard SPME. This consideration impacts our chargeback risk assessments and may influence liability in ADC-related chargebacks.

Monitoring and Risk Factors

Halyard Pay evaluates merchant risk using updated Mastercard MATCH Listing Reason Codes, including new, specific definitions for elevated chargeback and fraud concerns:

  • Laundering: Merchant presenting invalid transaction records rather than bona fide sales.

  • Excessive Chargebacks: Monthly Mastercard chargebacks exceed 1% of sales transactions with total chargebacks ≥ USD 5,000.

  • Excessive Fraud: Fraud-to-sales ratio of 8% or more, with at least 10 fraudulent transactions totaling USD 5,000+ in a calendar month.

These clarified definitions, part of Mastercard's updated SPME MATCH Listing Reason Codes (see section 11.5), guide Halyard Pay’s risk assessments and chargeback management protocols to align with Mastercard’s evolving standards.

Source authority: Mastercard SPME §§10.1, 10.3, 10.4, 10.6.2, 11.5.

policies/chargeback_handling/policy.md — after applying change

Chargeback Handling

Chargebacks are cardholder-initiated disputes against a transaction. Halyard Pay, acting as the acquirer, manages disputes from initial presentment through potential arbitration, adhering to Mastercard's requirements to protect all parties involved.

Lifecycle overview

Disputes progress through defined phases: first presentment, chargeback, second presentment (re-presentment), pre-arbitration, and arbitration. Compliance with evidence standards and timelines at each step is essential to prevent adverse rulings.

Required actions

  1. Acknowledge incoming chargebacks within one business day.

  2. Gather necessary evidence relevant to the dispute stage.

  3. Submit second presentments when liability is disputable, supported by strong documentation.

  4. Escalate to pre-arbitration and arbitration only after issuer rejection of second presentment.

  5. Retain comprehensive case documentation for auditing and reporting purposes.

  6. Provide all requested documentation promptly to Mastercard during investigations or appeals as governed by sections 10.3 and 10.4 of the Mastercard SPME.

Additionally, in cases involving Account Data Compromise (ADC) events, Halyard Pay recognizes that Mastercard may adjust financial responsibilities based on the compromised party's adherence to PCI DSS and Mastercard Site Data Protection Program requirements before, during, and after the event, as detailed in section 10.6.2 of the Mastercard SPME. This consideration impacts our chargeback risk assessments and may influence liability in ADC-related chargebacks.

Monitoring and Risk Factors

Halyard Pay evaluates merchant risk using updated Mastercard MATCH Listing Reason Codes, including new, specific definitions for elevated chargeback and fraud concerns:

  • Laundering: Merchant presenting invalid transaction records rather than bona fide sales.

  • Excessive Chargebacks: Monthly Mastercard chargebacks exceed 1% of sales transactions with total chargebacks ≥ USD 5,000.

  • Excessive Fraud: Fraud-to-sales ratio of 8% or more, with at least 10 fraudulent transactions totaling USD 5,000+ in a calendar month.

These clarified definitions, part of Mastercard's updated SPME MATCH Listing Reason Codes (see section 11.5), guide Halyard Pay’s risk assessments and chargeback management protocols to align with Mastercard’s evolving standards.

Source authority: Mastercard SPME §§10.1, 10.3, 10.4, 10.6.2, 11.5.

Source authority: Mastercard SPME §10.6.2.

--- a/policies/chargeback_handling/rules.yaml
+++ b/policies/chargeback_handling/rules.yaml
@@ -1,5 +1,5 @@
 program: Chargeback Handling
-authority: Mastercard SPME §10.1, §10.3, §10.4, and §11.5
+authority: Mastercard SPME 10.1, 10.3, 10.4, .6.2, 11.5
 acknowledgement_business_days: 1
 lifecycle_states:
   - first_presentment
@@ -27,6 +27,5 @@
     - arbitration_filing
 agent_owner: chargeback_agent
 
-# Added evidence requirement for fraud and chargeback data analysis to address new MATCH reason codes
-# related to excessive chargebacks and fraud ratios as introduced in Mastercard SPME §11.5 update,
-# supporting compliance with chargeback management standards per Mastercard SPME §10.1 and §10.3.
+# Updated authority to include Mastercard SPME 10.6.2 reflecting expansion of financial responsibility considerations from terminal servicers to any compromised entity.
+# This affects assessment procedures and evidentiary tracking in chargeback handling per Mastercard standards.

--- a/policies/chargeback_handling/policy.md
+++ b/policies/chargeback_handling/policy.md
@@ -15,6 +15,8 @@
 5. Retain comprehensive case documentation for auditing and reporting purposes.
 6. Provide all requested documentation promptly to Mastercard during investigations or appeals as governed by sections 10.3 and 10.4 of the Mastercard SPME.
 
+Additionally, in cases involving Account Data Compromise (ADC) events, Halyard Pay recognizes that Mastercard may adjust financial responsibilities based on the compromised party's adherence to PCI DSS and Mastercard Site Data Protection Program requirements before, during, and after the event, as detailed in section 10.6.2 of the Mastercard SPME. This consideration impacts our chargeback risk assessments and may influence liability in ADC-related chargebacks.
+
 ## Monitoring and Risk Factors
 
 Halyard Pay evaluates merchant risk using updated Mastercard MATCH Listing Reason Codes, including new, specific definitions for elevated chargeback and fraud concerns:
@@ -25,4 +27,4 @@
 
 These clarified definitions, part of Mastercard's updated SPME MATCH Listing Reason Codes (see section 11.5), guide Halyard Pay’s risk assessments and chargeback management protocols to align with Mastercard’s evolving standards.
 
-Source authority: Mastercard SPME §§10.1, 10.3, 10.4, 11.5.+Source authority: Mastercard SPME §§10.1, 10.3, 10.4, 10.6.2, 11.5.