Mastercard SPME §2.2.2 · Feb 2024 → Sep 2024
Merchant Compliance Requirements
The update adds that Level 1-3 Merchants must validate all third-party payment applications/software against PCI SSC listings. It clarifies that Level 3 and 4 Merchants' PCI DSS compliance validation to Mastercard is not required unless by law, though completing an SAQ or ROC is still encouraged. Other content remains largely unchanged.
program: Acquirer KYB- authority: Mastercard SPME 2.1, 11.2.3, 11.2.6, 11.7.1+ authority: Mastercard SPME 2.1, 11.2.3, 11.2.6, 11.7.1, 2.2.2required_documents:- incorporation- beneficial_ownership- aml_screen- license_verificationmin_review_cycle_days: 365suspension_trigger: document_collection_failurerecord_retention_years: 7aml_watchlist_sources:- ofac_sdn- eu_consolidatedagent_owner: kyb_agent- # Acquirers must perform a MATCH inquiry prior to entering into any Merchant Agreement or enabling a Merchant to accept transactions, as detailed in Mastercard SPME §11.2.3. This inquiry must be conducted using the correct Member ID/ICA Number associated with the Merchant to ensure proper compliance reporting.- # Failure to adhere to these requirements may result in noncompliance assessments.- # The Acquirer is also required to retain all MATCH records related to any Merchant, Sponsored Merchant, or ATM owner for a minimum of two years post-agreement termination, as per Mastercard SPME §11.2.6.- # Additionally, Acquirers that store, transmit, or process personal data of residents in the European Economic Area (EEA), the UK, or Switzerland—or are otherwise subject to EU Data Protection Law—must comply with the standards specified in Appendix D concerning MATCH activity within the Europe Region, consistent with Mastercard SPME §11.7.1.+ # Acquirers must perform a MATCH inquiry prior to entering into any Merchant Agreement or enabling a Merchant to accept transactions, using the correct Member ID/ICA Number, to ensure compliance as per Mastercard SPME §11.2.3.+ # MATCH records related to Merchants, Sponsored Merchants, or ATM owners must be retained for at least two years following agreement termination, according to Mastercard SPME §11.2.6.+ # For Acquirers handling personal data of EEA, UK, or Switzerland residents, adherence to the Europe Region standards in Appendix D concerning MATCH activity is mandatory in line with Mastercard SPME §11.7.1.+ # In alignment with Mastercard SPME §2.2.2, Acquirers must ensure that Level 1, 2, and 3 Merchants validate that any third party-provided payment applications or software they use are listed as compliant on the PCI Security Standards Council website, reflecting enhanced compliance validation requirements.+ # This includes confirming PCI PA-DSS or PCI Secure Software Standard compliance for payment applications and adherence to PCI Secure SLC Standard for payment software vendors.+ # These updates strengthen Merchant compliance oversight and risk mitigation related to payment application security.
Acquirer KYB (Know Your Business) Obligations
Acquirers processing transactions on the Mastercard network must perform Know Your Business (KYB) due diligence on merchants prior to onboarding and on a recurring basis. Halyard Pay is responsible for collecting and verifying required documentation to confirm business legitimacy, vet beneficial ownership, and satisfy anti-money laundering (AML) screening.
When this policy applies
This policy applies at initial merchant onboarding and during periodic re-verification reviews. Merchants that do not provide required documentation within set timelines must be suspended until compliance is restored.
Required actions
-
Collect all KYB documentation needed at onboarding.
-
Conduct AML screening against applicable watchlists before approval.
-
Verify business licenses for regulated merchant categories.
-
Schedule full re-verification at least annually.
-
Document verification outcomes and maintain records for audit.
-
Retain MATCH system records related to Merchants, Sponsored Merchants, or ATM owners for at least two years after contract termination or expiration, to meet Mastercard record retention requirements.
-
Before Merchant Agreement execution or enabling transactions, conduct a MATCH inquiry using Halyard Pay's Member ID/ICA Number to ensure compliance; failure may lead to Mastercard assessments.
-
For merchants whose personal data pertains to residents of the European Economic Area, the UK, or Switzerland, Halyard Pay must comply with EU Data Protection Laws as specified in Appendix D of the Mastercard SPME manual concerning MATCH activities in the Europe Region.
9. Ensure that Level 1, Level 2, and Level 3 Merchants validate that all third-party payment applications or software used are listed as compliant on the PCI Security Standards Council (SSC) website to meet updated Mastercard requirements for cybersecurity controls.
Source authority: Mastercard SPME §§2.1, 2.2.2, 7.1, 11.2.3, 11.2.6, 11.7.1.
Acquirer KYB (Know Your Business) Obligations
Acquirers processing transactions on the Mastercard network must perform Know Your Business (KYB) due diligence on merchants prior to onboarding and on a recurring basis. Halyard Pay is responsible for collecting and verifying required documentation to confirm business legitimacy, vet beneficial ownership, and satisfy anti-money laundering (AML) screening.
When this policy applies
This policy applies at initial merchant onboarding and during periodic re-verification reviews. Merchants that do not provide required documentation within set timelines must be suspended until compliance is restored.
Required actions
-
Collect all KYB documentation needed at onboarding.
-
Conduct AML screening against applicable watchlists before approval.
-
Verify business licenses for regulated merchant categories.
-
Schedule full re-verification at least annually.
-
Document verification outcomes and maintain records for audit.
-
Retain MATCH system records related to Merchants, Sponsored Merchants, or ATM owners for at least two years after contract termination or expiration, to meet Mastercard record retention requirements.
-
Before Merchant Agreement execution or enabling transactions, conduct a MATCH inquiry using Halyard Pay's Member ID/ICA Number to ensure compliance; failure may lead to Mastercard assessments.
-
For merchants whose personal data pertains to residents of the European Economic Area, the UK, or Switzerland, Halyard Pay must comply with EU Data Protection Laws as specified in Appendix D of the Mastercard SPME manual concerning MATCH activities in the Europe Region.
9. Ensure that Level 1, Level 2, and Level 3 Merchants validate that all third-party payment applications or software used are listed as compliant on the PCI Security Standards Council (SSC) website to meet updated Mastercard requirements for cybersecurity controls.
Source authority: Mastercard SPME §§2.1, 2.2.2, 7.1, 11.2.3, 11.2.6, 11.7.1.
Source authority: Mastercard SPME §2.2.2.
--- a/policies/kyb_acquirer/rules.yaml +++ b/policies/kyb_acquirer/rules.yaml @@ -1,5 +1,5 @@ program: Acquirer KYB -authority: Mastercard SPME 2.1, 11.2.3, 11.2.6, 11.7.1 +authority: Mastercard SPME 2.1, 11.2.3, 11.2.6, 11.7.1, 2.2.2 required_documents: - incorporation - beneficial_ownership @@ -12,7 +12,9 @@ - ofac_sdn - eu_consolidated agent_owner: kyb_agent -# Acquirers must perform a MATCH inquiry prior to entering into any Merchant Agreement or enabling a Merchant to accept transactions, as detailed in Mastercard SPME §11.2.3. This inquiry must be conducted using the correct Member ID/ICA Number associated with the Merchant to ensure proper compliance reporting. -# Failure to adhere to these requirements may result in noncompliance assessments. -# The Acquirer is also required to retain all MATCH records related to any Merchant, Sponsored Merchant, or ATM owner for a minimum of two years post-agreement termination, as per Mastercard SPME §11.2.6. -# Additionally, Acquirers that store, transmit, or process personal data of residents in the European Economic Area (EEA), the UK, or Switzerland—or are otherwise subject to EU Data Protection Law—must comply with the standards specified in Appendix D concerning MATCH activity within the Europe Region, consistent with Mastercard SPME §11.7.1. +# Acquirers must perform a MATCH inquiry prior to entering into any Merchant Agreement or enabling a Merchant to accept transactions, using the correct Member ID/ICA Number, to ensure compliance as per Mastercard SPME §11.2.3. +# MATCH records related to Merchants, Sponsored Merchants, or ATM owners must be retained for at least two years following agreement termination, according to Mastercard SPME §11.2.6. +# For Acquirers handling personal data of EEA, UK, or Switzerland residents, adherence to the Europe Region standards in Appendix D concerning MATCH activity is mandatory in line with Mastercard SPME §11.7.1. +# In alignment with Mastercard SPME §2.2.2, Acquirers must ensure that Level 1, 2, and 3 Merchants validate that any third party-provided payment applications or software they use are listed as compliant on the PCI Security Standards Council website, reflecting enhanced compliance validation requirements. +# This includes confirming PCI PA-DSS or PCI Secure Software Standard compliance for payment applications and adherence to PCI Secure SLC Standard for payment software vendors. +# These updates strengthen Merchant compliance oversight and risk mitigation related to payment application security. --- a/policies/kyb_acquirer/policy.md +++ b/policies/kyb_acquirer/policy.md @@ -16,5 +16,6 @@ 6. Retain MATCH system records related to Merchants, Sponsored Merchants, or ATM owners for at least two years after contract termination or expiration, to meet Mastercard record retention requirements. 7. Before Merchant Agreement execution or enabling transactions, conduct a MATCH inquiry using Halyard Pay's Member ID/ICA Number to ensure compliance; failure may lead to Mastercard assessments. 8. For merchants whose personal data pertains to residents of the European Economic Area, the UK, or Switzerland, Halyard Pay must comply with EU Data Protection Laws as specified in Appendix D of the Mastercard SPME manual concerning MATCH activities in the Europe Region. +9. Ensure that Level 1, Level 2, and Level 3 Merchants validate that all third-party payment applications or software used are listed as compliant on the PCI Security Standards Council (SSC) website to meet updated Mastercard requirements for cybersecurity controls. -Source authority: Mastercard SPME §§2.1, 7.1, 11.2.3, 11.2.6, 11.7.1.+Source authority: Mastercard SPME §§2.1, 2.2.2, 7.1, 11.2.3, 11.2.6, 11.7.1.