Mastercard SPME §10 · Feb 2024 → Sep 2024
Should the responsible Customer cause a PFI to conduct an examination, the responsible
The change adds a new subsection specifically for Card-present Alternative Acquirer Investigations, extending the investigation reporting deadline from 20 to 30 business days and clarifying requirements for responsible Customers choosing to investigate instead of engaging a PFI.
program: BRAMauthority: Mastercard SPME 8.6.2, 10.2, 12response_window_days: 180required_evidence:- transaction_monitoring_records- corrective_action_plan- police_report # Mandatory inclusion per updated SPME 8.6.2halt_actions:- halt_new_merchant_onboardinginternal_notification_hours: 24agent_owner: bram_response_agent# Includes updated police report requirement per SPME 8.6.2 and affirms Mastercard's exclusive authority in determining ADC Event responsibility (SPME 10.2).+ # Updated the reporting timeframe for Card-present Alternative Acquirer Investigations investigations from 20 to 30 business days per revised SPME 10.2.# Added policy note on consequences for failure to provide complete responses by deadlines, including escalating Category C noncompliance assessments as specified in SPME 12.# Allows for potential additional time granted by Mastercard upon Acquirer's confirmation of cessation of violating activity.
BRAM Investigation Response
When Mastercard issues a Business Risk Assessment and Mitigation (BRAM) investigation
notice for one of our merchants, the acquirer must halt new merchant onboarding
immediately and submit an evidence package within one hundred eighty (180) days
of receipt of the notice.
Required actions
-
Halt new merchant onboarding for the merchant under investigation.
-
Compile and submit an evidence package containing:
-
Transaction monitoring records covering the prior 180 days.
-
A written corrective action plan.
-
Documentation of any police reports related to alleged coercion claims if applicable.
- Notify the Halyard Pay Compliance lead within 24 hours of receipt.
Failure to submit a complete response by the deadline will be considered a violation of Mastercard Rules section 3.9, resulting in escalating Category C noncompliance assessments until compliance is met. Additional assessments may occur for other Standards violations revealed during the BRAM investigation. Mastercard may grant extensions if the acquirer confirms cessation of violating activities.
Additional Considerations for Coercion Claims
When allegations of coerced Transactions arise, note that Mastercard may extend the usual 120-day
investigation period at its discretion. At least one claim must include a police report from the Cardholder.
Transactions reported as Lost or Stolen Fraud (fraud type codes 00 or 01) are subject to investigation,
though Mastercard may consider other fraud codes. Mastercard will notify issuers with Transactions at the
merchant within the investigation period to prompt claim submissions.
Mastercard's Authority and Determinations on ADC Events
Mastercard retains exclusive authority to determine the occurrence, scope, and responsibility for Account Data Compromise (ADC) Events or Potential ADC Events, including the consolidation of related incidents into single or multiple events where applicable. Mastercard’s decisions in these matters are final and not subject to internal appeal. Customers are advised to seek Mastercard guidance if uncertain about their rights or obligations related to ADC Events. This framework ensures accountability and proper management of ADC risks in line with Mastercard's network security standards.
## Investigation Reporting Timeframes for ADC Events
Customers notified by Mastercard of an ADC Event or Potential ADC Event must notify Mastercard within 24 hours of engaging a Payment Forensic Investigator (PFI). Failure to notify within this timeframe may lead to noncompliance assessments under section 10.7 of Mastercard Rules. Alternatively, if the responsible Customer satisfies Criterion C, it may elect to investigate the ADC Event internally rather than engage a PFI.
For Card-present Alternative Acquirer Investigations (CP AAIs), when the responsible Customer elects to conduct the investigation, it must provide evidence to Mastercard within thirty (30) business days from the notification date that:
1. The Customer has elected to investigate rather than use a PFI.
2. The Merchant under investigation does not use a computer-based acceptance system shared with other Merchants or Agents, nor connected to third parties.
3. The investigation is complete, and the ADC Event has been fully contained, with documentation including containment date and how the breach was mitigated.
4. The Merchant has newly validated, revalidated, or has a plan to achieve PCI DSS compliance, supported by documentation upon investigation completion.
Failure to meet these obligations may result in noncompliance assessments as per section 10.7. Mastercard may perform periodic reviews to ensure risk containment and may request a remediation plan if ongoing risks are identified.
Source authority: Mastercard SPME ������8.6.2, ������10.2, 12.0, and section 3.9.§§ 3.9, 8.6.2, 10.2, and 12.0.
BRAM Investigation Response
When Mastercard issues a Business Risk Assessment and Mitigation (BRAM) investigation
notice for one of our merchants, the acquirer must halt new merchant onboarding
immediately and submit an evidence package within one hundred eighty (180) days
of receipt of the notice.
Required actions
-
Halt new merchant onboarding for the merchant under investigation.
-
Compile and submit an evidence package containing:
-
Transaction monitoring records covering the prior 180 days.
-
A written corrective action plan.
-
Documentation of any police reports related to alleged coercion claims if applicable.
- Notify the Halyard Pay Compliance lead within 24 hours of receipt.
Failure to submit a complete response by the deadline will be considered a violation of Mastercard Rules section 3.9, resulting in escalating Category C noncompliance assessments until compliance is met. Additional assessments may occur for other Standards violations revealed during the BRAM investigation. Mastercard may grant extensions if the acquirer confirms cessation of violating activities.
Additional Considerations for Coercion Claims
When allegations of coerced Transactions arise, note that Mastercard may extend the usual 120-day
investigation period at its discretion. At least one claim must include a police report from the Cardholder.
Transactions reported as Lost or Stolen Fraud (fraud type codes 00 or 01) are subject to investigation,
though Mastercard may consider other fraud codes. Mastercard will notify issuers with Transactions at the
merchant within the investigation period to prompt claim submissions.
Mastercard's Authority and Determinations on ADC Events
Mastercard retains exclusive authority to determine the occurrence, scope, and responsibility for Account Data Compromise (ADC) Events or Potential ADC Events, including the consolidation of related incidents into single or multiple events where applicable. Mastercard’s decisions in these matters are final and not subject to internal appeal. Customers are advised to seek Mastercard guidance if uncertain about their rights or obligations related to ADC Events. This framework ensures accountability and proper management of ADC risks in line with Mastercard's network security standards.
## Investigation Reporting Timeframes for ADC Events
Customers notified by Mastercard of an ADC Event or Potential ADC Event must notify Mastercard within 24 hours of engaging a Payment Forensic Investigator (PFI). Failure to notify within this timeframe may lead to noncompliance assessments under section 10.7 of Mastercard Rules. Alternatively, if the responsible Customer satisfies Criterion C, it may elect to investigate the ADC Event internally rather than engage a PFI.
For Card-present Alternative Acquirer Investigations (CP AAIs), when the responsible Customer elects to conduct the investigation, it must provide evidence to Mastercard within thirty (30) business days from the notification date that:
1. The Customer has elected to investigate rather than use a PFI.
2. The Merchant under investigation does not use a computer-based acceptance system shared with other Merchants or Agents, nor connected to third parties.
3. The investigation is complete, and the ADC Event has been fully contained, with documentation including containment date and how the breach was mitigated.
4. The Merchant has newly validated, revalidated, or has a plan to achieve PCI DSS compliance, supported by documentation upon investigation completion.
Failure to meet these obligations may result in noncompliance assessments as per section 10.7. Mastercard may perform periodic reviews to ensure risk containment and may request a remediation plan if ongoing risks are identified.
Source authority: Mastercard SPME ������8.6.2, ������10.2, 12.0, and section 3.9.§§ 3.9, 8.6.2, 10.2, and 12.0.
Source authority: Mastercard SPME §10.
--- a/policies/bram_response/rules.yaml +++ b/policies/bram_response/rules.yaml @@ -11,5 +11,6 @@ agent_owner: bram_response_agent # Includes updated police report requirement per SPME 8.6.2 and affirms Mastercard's exclusive authority in determining ADC Event responsibility (SPME 10.2). +# Updated the reporting timeframe for Card-present Alternative Acquirer Investigations investigations from 20 to 30 business days per revised SPME 10.2. # Added policy note on consequences for failure to provide complete responses by deadlines, including escalating Category C noncompliance assessments as specified in SPME 12. -# Allows for potential additional time granted by Mastercard upon Acquirer's confirmation of cessation of violating activity.+# Allows for potential additional time granted by Mastercard upon Acquirer's confirmation of cessation of violating activity. --- a/policies/bram_response/policy.md +++ b/policies/bram_response/policy.md @@ -28,4 +28,17 @@ Mastercard retains exclusive authority to determine the occurrence, scope, and responsibility for Account Data Compromise (ADC) Events or Potential ADC Events, including the consolidation of related incidents into single or multiple events where applicable. Mastercard’s decisions in these matters are final and not subject to internal appeal. Customers are advised to seek Mastercard guidance if uncertain about their rights or obligations related to ADC Events. This framework ensures accountability and proper management of ADC risks in line with Mastercard's network security standards. -Source authority: Mastercard SPME 8.6.2, 10.2, 12.0, and section 3.9.+## Investigation Reporting Timeframes for ADC Events + +Customers notified by Mastercard of an ADC Event or Potential ADC Event must notify Mastercard within 24 hours of engaging a Payment Forensic Investigator (PFI). Failure to notify within this timeframe may lead to noncompliance assessments under section 10.7 of Mastercard Rules. Alternatively, if the responsible Customer satisfies Criterion C, it may elect to investigate the ADC Event internally rather than engage a PFI. + +For Card-present Alternative Acquirer Investigations (CP AAIs), when the responsible Customer elects to conduct the investigation, it must provide evidence to Mastercard within thirty (30) business days from the notification date that: + +1. The Customer has elected to investigate rather than use a PFI. +2. The Merchant under investigation does not use a computer-based acceptance system shared with other Merchants or Agents, nor connected to third parties. +3. The investigation is complete, and the ADC Event has been fully contained, with documentation including containment date and how the breach was mitigated. +4. The Merchant has newly validated, revalidated, or has a plan to achieve PCI DSS compliance, supported by documentation upon investigation completion. + +Failure to meet these obligations may result in noncompliance assessments as per section 10.7. Mastercard may perform periodic reviews to ensure risk containment and may request a remediation plan if ongoing risks are identified. + +Source authority: Mastercard SPME §§ 3.9, 8.6.2, 10.2, and 12.0.