Mastercard SPME §10 · Feb 2024 → Sep 2024

Should the responsible Customer cause a PFI to conduct an examination, the responsible

substantive

The change adds a new subsection specifically for Card-present Alternative Acquirer Investigations, extending the investigation reporting deadline from 20 to 30 business days and clarifying requirements for responsible Customers choosing to investigate instead of engaging a PFI.

Sources Mastercard SPME · Feb 2024 · page 11 PDF Mastercard SPME · Sep 2024 · page 11 PDF BRAM Response current
Also in §10.x this release breaking §10.2 Policy Concerning Account Data Compromise Events and Potential Account Data breaking §10.3.1 Time-Specific Procedures for ADC Events and Potential ADC Events breaking §10.3.2 Ongoing Procedures for ADC Events and Potential ADC Events breaking §10.5 Alternative Acquirer Investigation (AAI) Standards substantive §10.1 Applicability and Defined Terms substantive §10.3 Responsibilities in Connection with ADC Events and Potential ADC Events substantive §10.4 Forensic Report substantive §10.6 Mastercard Determination of ADC Event or Potential ADC Event substantive §10.6.2 Potential Reduction of Financial Responsibility substantive §10.6.4 Determination of Operational Reimbursement (OR) substantive §10.7 Assessments and/or Disqualification for Noncompliance
Why these edits? The updated subsection extends the investigation reporting deadline for Card-present Alternative Acquirer Investigations from 20 to 30 business days, which alters the timing obligations covered in the BRAM Investigation Response policy that cites section 10.2.
Mastercard SPME §10
Customer must notify Mastercard within 24 hours of the engagement of the PFI. Failure to notify Mastercard within the 24-hour time frame may result in a noncompliance assessment as described in section Section 10.7. Alternatively, and provided the responsible Customer determines that Criterion C is satisfied, the responsible Customer itself may elect to investigate the Event in lieu of causing a PFI to conduct an examination of the Merchant or other Agent. If Card-present (CP) Alternative Acquirer Investigations (AAIs) For CP AAIs, if the responsible Customer itself elects to conduct the investigation, not later than twenty thirty (2030) business days following the date of the notice by Mastercard described above, the responsible Customer must provide to Mastercard that all of the following are true: 1. The responsible Customer elected to investigate the ADC Event or Potential ADC Event in lieu of causing a PFI to investigate the ADC Event or Potential ADC Event; and • ¶ The Merchant (or other Agent) that is the subject of the ADC Event or Potential ADC Event ¶ does not use a computer-based acceptance system that is used by another Merchant (or ¶ Agent) or is connected to Merchants (or Agents) or third parties; and ¶ • ¶ The responsible Customer’s investigation of the ADC Event or Potential ADC Event has been ¶ completed and the ADC Event or Potential ADC Event has been fully contained. ¶ Documentation satisfactory to Mastercard confirming such containment (including the date ¶ of containment) and a written explanation of how the security event was contained ¶ (including the steps taken to ensure that Account data are no longer at risk of compromise) ¶ must be provided to Mastercard; and ¶ • ¶ The Merchant has newly validated, or revalidated or has a road map to achieve compliance ¶ with the PCI DSS. Documentation confirming such validation or revalidation must be ¶ provided to Mastercard upon completion of the investigation. ¶ Failure to comply with any obligation of the responsible Customer may result in the imposition ¶ of a noncompliance assessment as described in section 10.7. ¶ Mastercard may conduct periodic reviews of an ADC Event or Potential ADC Event investigated ¶ by the responsible Customer to confirm that the Event has been fully contained. Should ¶ Mastercard determine that an Event continues to place Accounts at risk of unauthorized ¶ disclosure, Mastercard will provide notice to the responsible Customer by way of an email ¶ message to the responsible Customer's Security Contact then listed in the My Company ¶ Manager application. ¶ Within ten (10) business days of such notice, the responsible Customer must provide to ¶ Mastercard a remediation action plan describing the steps (and relevant dates of the steps) ¶ Account Data Compromise Events
Halyard Pay · 2 files
program: BRAM
authority: Mastercard SPME 8.6.2, 10.2, 12
response_window_days: 180
required_evidence:
- transaction_monitoring_records
- corrective_action_plan
- police_report # Mandatory inclusion per updated SPME 8.6.2
halt_actions:
- halt_new_merchant_onboarding
internal_notification_hours: 24
agent_owner: bram_response_agent
 
# Includes updated police report requirement per SPME 8.6.2 and affirms Mastercard's exclusive authority in determining ADC Event responsibility (SPME 10.2).
+ # Updated the reporting timeframe for Card-present Alternative Acquirer Investigations investigations from 20 to 30 business days per revised SPME 10.2.
# Added policy note on consequences for failure to provide complete responses by deadlines, including escalating Category C noncompliance assessments as specified in SPME 12.
# Allows for potential additional time granted by Mastercard upon Acquirer's confirmation of cessation of violating activity.

BRAM Investigation Response

When Mastercard issues a Business Risk Assessment and Mitigation (BRAM) investigation

notice for one of our merchants, the acquirer must halt new merchant onboarding

immediately and submit an evidence package within one hundred eighty (180) days

of receipt of the notice.

Required actions

  1. Halt new merchant onboarding for the merchant under investigation.

  2. Compile and submit an evidence package containing:

  • Transaction monitoring records covering the prior 180 days.

  • A written corrective action plan.

  • Documentation of any police reports related to alleged coercion claims if applicable.

  1. Notify the Halyard Pay Compliance lead within 24 hours of receipt.

Failure to submit a complete response by the deadline will be considered a violation of Mastercard Rules section 3.9, resulting in escalating Category C noncompliance assessments until compliance is met. Additional assessments may occur for other Standards violations revealed during the BRAM investigation. Mastercard may grant extensions if the acquirer confirms cessation of violating activities.

Additional Considerations for Coercion Claims

When allegations of coerced Transactions arise, note that Mastercard may extend the usual 120-day

investigation period at its discretion. At least one claim must include a police report from the Cardholder.

Transactions reported as Lost or Stolen Fraud (fraud type codes 00 or 01) are subject to investigation,

though Mastercard may consider other fraud codes. Mastercard will notify issuers with Transactions at the

merchant within the investigation period to prompt claim submissions.

Mastercard's Authority and Determinations on ADC Events

Mastercard retains exclusive authority to determine the occurrence, scope, and responsibility for Account Data Compromise (ADC) Events or Potential ADC Events, including the consolidation of related incidents into single or multiple events where applicable. Mastercard’s decisions in these matters are final and not subject to internal appeal. Customers are advised to seek Mastercard guidance if uncertain about their rights or obligations related to ADC Events. This framework ensures accountability and proper management of ADC risks in line with Mastercard's network security standards.

## Investigation Reporting Timeframes for ADC Events

Customers notified by Mastercard of an ADC Event or Potential ADC Event must notify Mastercard within 24 hours of engaging a Payment Forensic Investigator (PFI). Failure to notify within this timeframe may lead to noncompliance assessments under section 10.7 of Mastercard Rules. Alternatively, if the responsible Customer satisfies Criterion C, it may elect to investigate the ADC Event internally rather than engage a PFI.

For Card-present Alternative Acquirer Investigations (CP AAIs), when the responsible Customer elects to conduct the investigation, it must provide evidence to Mastercard within thirty (30) business days from the notification date that:

1. The Customer has elected to investigate rather than use a PFI.

2. The Merchant under investigation does not use a computer-based acceptance system shared with other Merchants or Agents, nor connected to third parties.

3. The investigation is complete, and the ADC Event has been fully contained, with documentation including containment date and how the breach was mitigated.

4. The Merchant has newly validated, revalidated, or has a plan to achieve PCI DSS compliance, supported by documentation upon investigation completion.

Failure to meet these obligations may result in noncompliance assessments as per section 10.7. Mastercard may perform periodic reviews to ensure risk containment and may request a remediation plan if ongoing risks are identified.

Source authority: Mastercard SPME ������8.6.2, ������10.2, 12.0, and section 3.9.§§ 3.9, 8.6.2, 10.2, and 12.0.

policies/bram_response/policy.md — after applying change

BRAM Investigation Response

When Mastercard issues a Business Risk Assessment and Mitigation (BRAM) investigation

notice for one of our merchants, the acquirer must halt new merchant onboarding

immediately and submit an evidence package within one hundred eighty (180) days

of receipt of the notice.

Required actions

  1. Halt new merchant onboarding for the merchant under investigation.

  2. Compile and submit an evidence package containing:

  • Transaction monitoring records covering the prior 180 days.

  • A written corrective action plan.

  • Documentation of any police reports related to alleged coercion claims if applicable.

  1. Notify the Halyard Pay Compliance lead within 24 hours of receipt.

Failure to submit a complete response by the deadline will be considered a violation of Mastercard Rules section 3.9, resulting in escalating Category C noncompliance assessments until compliance is met. Additional assessments may occur for other Standards violations revealed during the BRAM investigation. Mastercard may grant extensions if the acquirer confirms cessation of violating activities.

Additional Considerations for Coercion Claims

When allegations of coerced Transactions arise, note that Mastercard may extend the usual 120-day

investigation period at its discretion. At least one claim must include a police report from the Cardholder.

Transactions reported as Lost or Stolen Fraud (fraud type codes 00 or 01) are subject to investigation,

though Mastercard may consider other fraud codes. Mastercard will notify issuers with Transactions at the

merchant within the investigation period to prompt claim submissions.

Mastercard's Authority and Determinations on ADC Events

Mastercard retains exclusive authority to determine the occurrence, scope, and responsibility for Account Data Compromise (ADC) Events or Potential ADC Events, including the consolidation of related incidents into single or multiple events where applicable. Mastercard’s decisions in these matters are final and not subject to internal appeal. Customers are advised to seek Mastercard guidance if uncertain about their rights or obligations related to ADC Events. This framework ensures accountability and proper management of ADC risks in line with Mastercard's network security standards.

## Investigation Reporting Timeframes for ADC Events

Customers notified by Mastercard of an ADC Event or Potential ADC Event must notify Mastercard within 24 hours of engaging a Payment Forensic Investigator (PFI). Failure to notify within this timeframe may lead to noncompliance assessments under section 10.7 of Mastercard Rules. Alternatively, if the responsible Customer satisfies Criterion C, it may elect to investigate the ADC Event internally rather than engage a PFI.

For Card-present Alternative Acquirer Investigations (CP AAIs), when the responsible Customer elects to conduct the investigation, it must provide evidence to Mastercard within thirty (30) business days from the notification date that:

1. The Customer has elected to investigate rather than use a PFI.

2. The Merchant under investigation does not use a computer-based acceptance system shared with other Merchants or Agents, nor connected to third parties.

3. The investigation is complete, and the ADC Event has been fully contained, with documentation including containment date and how the breach was mitigated.

4. The Merchant has newly validated, revalidated, or has a plan to achieve PCI DSS compliance, supported by documentation upon investigation completion.

Failure to meet these obligations may result in noncompliance assessments as per section 10.7. Mastercard may perform periodic reviews to ensure risk containment and may request a remediation plan if ongoing risks are identified.

Source authority: Mastercard SPME ������8.6.2, ������10.2, 12.0, and section 3.9.§§ 3.9, 8.6.2, 10.2, and 12.0.

Source authority: Mastercard SPME §10.

--- a/policies/bram_response/rules.yaml
+++ b/policies/bram_response/rules.yaml
@@ -11,5 +11,6 @@
 agent_owner: bram_response_agent
 
 # Includes updated police report requirement per SPME 8.6.2 and affirms Mastercard's exclusive authority in determining ADC Event responsibility (SPME 10.2).
+# Updated the reporting timeframe for Card-present Alternative Acquirer Investigations investigations from 20 to 30 business days per revised SPME 10.2.
 # Added policy note on consequences for failure to provide complete responses by deadlines, including escalating Category C noncompliance assessments as specified in SPME 12.
-# Allows for potential additional time granted by Mastercard upon Acquirer's confirmation of cessation of violating activity.+# Allows for potential additional time granted by Mastercard upon Acquirer's confirmation of cessation of violating activity.

--- a/policies/bram_response/policy.md
+++ b/policies/bram_response/policy.md
@@ -28,4 +28,17 @@
 
 Mastercard retains exclusive authority to determine the occurrence, scope, and responsibility for Account Data Compromise (ADC) Events or Potential ADC Events, including the consolidation of related incidents into single or multiple events where applicable. Mastercard’s decisions in these matters are final and not subject to internal appeal. Customers are advised to seek Mastercard guidance if uncertain about their rights or obligations related to ADC Events. This framework ensures accountability and proper management of ADC risks in line with Mastercard's network security standards.
 
-Source authority: Mastercard SPME 8.6.2, 10.2, 12.0, and section 3.9.+## Investigation Reporting Timeframes for ADC Events
+
+Customers notified by Mastercard of an ADC Event or Potential ADC Event must notify Mastercard within 24 hours of engaging a Payment Forensic Investigator (PFI). Failure to notify within this timeframe may lead to noncompliance assessments under section 10.7 of Mastercard Rules. Alternatively, if the responsible Customer satisfies Criterion C, it may elect to investigate the ADC Event internally rather than engage a PFI.
+
+For Card-present Alternative Acquirer Investigations (CP AAIs), when the responsible Customer elects to conduct the investigation, it must provide evidence to Mastercard within thirty (30) business days from the notification date that:
+
+1. The Customer has elected to investigate rather than use a PFI.
+2. The Merchant under investigation does not use a computer-based acceptance system shared with other Merchants or Agents, nor connected to third parties.
+3. The investigation is complete, and the ADC Event has been fully contained, with documentation including containment date and how the breach was mitigated.
+4. The Merchant has newly validated, revalidated, or has a plan to achieve PCI DSS compliance, supported by documentation upon investigation completion.
+
+Failure to meet these obligations may result in noncompliance assessments as per section 10.7. Mastercard may perform periodic reviews to ensure risk containment and may request a remediation plan if ongoing risks are identified.
+
+Source authority: Mastercard SPME §§ 3.9, 8.6.2, 10.2, and 12.0.