Mastercard SPME §2.2.6 · Feb 2024 → Sep 2024

Mandatory Compliance Requirements for Compromised Entities

substantive

The updated rules add that any Merchant with a confirmed ADC Event may be reclassified as Level 1 with all related compliance requirements. For Service Providers, it clarifies that DESV appendix compliance must be validated to Mastercard once, post-forensic investigation, refining re-listing conditions.

Sources Mastercard SPME · Feb 2024 · page 26 PDF Mastercard SPME · Sep 2024 · page 26 PDF KYB Acquirer current
Also in §2.x this release substantive §2.2.2 Merchant Compliance Requirements substantive §2.2.3 Service Provider Compliance Requirements substantive §2.2.4 Mastercard Cybersecurity Incentive Program (CSIP) substantive §2.2.5 SDP Program Noncompliance Assessments substantive §2.3 Card Production Security Standards substantive §2.3.2 Additional Card Production Requirements substantive §2.4.1 PIN Entry Devices (PEDs) and Encrypting PIN Pads (EPPs)
Why these edits? The update introduced a requirement for Merchants with a confirmed ADC Event to be reclassified as Level 1, triggering stricter compliance validation requirements applicable to acquirers and merchant onboarding processes under section 2.1 cited by the kyb_acquirer policy.
Mastercard SPME §2.2.6
Security Rules and Procedures—Merchant Edition • 6 February August 2024 Merchants Any Merchant that has a confirmed ADC Event may be automatically reclassified to become a Level 1 Merchant. All compliance validation requirements and associated SDP noncompliance assessments for Level 1 Merchants will apply. Service Providers Any Service Provider that has a confirmed ADC Event, adverse inference (see section Section 10.3), and/or noncompliance for failure to cooperate in an ADC Event or forensic investigation will be automatically reclassified to become a Level 1 Service Provider. In addition, a Service Provider’s Provider's noncompliance will result in the automatic delisting from The Mastercard SDP Compliant Registered Service Provider List. A registered Service Provider may be placed back on the list only after the entity has re-validated compliance with the PCI DSS and has additionally demonstrated compliance with the DESV appendix of the PCI DSS within twelve (12) months from achieving full compliance with the PCI DSS as shown in Table 2.3.A Service Provider's compliance with the DESV appendix of the PCI DSS must be validated to Mastercard only once after the conclusion of a forensic investigation.
Halyard Pay · 2 files
program: Acquirer KYB
- authority: Mastercard SPME 2.1, 11.2.3, 11.2.6, 11.7.1
+ authority: Mastercard SPME 2.1, 2.2.6, 11.2.3, 11.2.6, 11.7.1
required_documents:
- incorporation
- beneficial_ownership
- aml_screen
- license_verification
min_review_cycle_days: 365
suspension_trigger: document_collection_failure
record_retention_years: 7
aml_watchlist_sources:
- ofac_sdn
- eu_consolidated
agent_owner: kyb_agent
# Acquirers must perform a MATCH inquiry prior to entering into any Merchant Agreement or enabling a Merchant to accept transactions, as detailed in Mastercard SPME §11.2.3. This inquiry must be conducted using the correct Member ID/ICA Number associated with the Merchant to ensure proper compliance reporting.
# Failure to adhere to these requirements may result in noncompliance assessments.
- # The Acquirer is also required to retain all MATCH records related to any Merchant, Sponsored Merchant, or ATM owner for a minimum of two years post-agreement termination, as per Mastercard SPME §11.2.6.
+ # The Acquirer is required to retain all MATCH records related to any Merchant, Sponsored Merchant, or ATM owner for a minimum of two years post-agreement termination, as per Mastercard SPME §11.2.6.
# Additionally, Acquirers that store, transmit, or process personal data of residents in the European Economic Area (EEA), the UK, or Switzerland—or are otherwise subject to EU Data Protection Law—must comply with the standards specified in Appendix D concerning MATCH activity within the Europe Region, consistent with Mastercard SPME §11.7.1.
+ # New requirements under Mastercard SPME §2.2.6 specify that any Merchant with a confirmed Account Data Compromise (ADC) Event must be automatically reclassified as a Level 1 Merchant. This triggers enhanced compliance validation requirements and associated noncompliance assessments applicable to acquirers during merchant onboarding and monitoring processes.
+ # This addition highlights the need for acquirers to implement controls for identifying and managing Level 1 Merchant reclassifications promptly to maintain compliance.

Acquirer KYB (Know Your Business) Obligations

Acquirers processing transactions on the Mastercard network must perform Know Your Business (KYB) due diligence on merchants prior to onboarding and on a recurring basis. Halyard Pay is responsible for collecting and verifying required documentation to confirm business legitimacy, vet beneficial ownership, and satisfy anti-money laundering (AML) screening.

When this policy applies

This policy applies at initial merchant onboarding and during periodic re-verification reviews. Merchants that do not provide required documentation within set timelines must be suspended until compliance is restored. Additionally, any merchant confirmed to have an ADC (Account Data Compromise) Event will be reclassified as a Level 1 Merchant, subjecting them to enhanced compliance validation and monitoring as required by Mastercard.

Required actions

  1. Collect all KYB documentation needed at onboarding.

  2. Conduct AML screening against applicable watchlists before approval.

  3. Verify business licenses for regulated merchant categories.

  4. Schedule full re-verification at least annually.

  5. Document verification outcomes and maintain records for audit.

  6. Retain MATCH system records related to Merchants, Sponsored Merchants, or ATM owners for at least two years after contract termination or expiration, to meet Mastercard record retention requirements.

  7. Before Merchant Agreement execution or enabling transactions, conduct a MATCH inquiry using Halyard Pay's Member ID/ICA Number to ensure compliance; failure may lead to Mastercard assessments.

  8. For merchants whose personal data pertains to residents of the European Economic Area, the UK, or Switzerland, Halyard Pay must comply with EU Data Protection Laws as specified in Appendix D of the Mastercard SPME manual concerning MATCH activities in the Europe Region.

9. Implement heightened due diligence and monitoring procedures for any merchant reclassified as Level 1 due to a confirmed ADC Event, consistent with Mastercard requirements for Level 1 Merchants.

Source authority: Mastercard SPME §§2.1, 2.2.6, 7.1, 11.2.3, 11.2.6, 11.7.1.

policies/kyb_acquirer/policy.md — after applying change

Acquirer KYB (Know Your Business) Obligations

Acquirers processing transactions on the Mastercard network must perform Know Your Business (KYB) due diligence on merchants prior to onboarding and on a recurring basis. Halyard Pay is responsible for collecting and verifying required documentation to confirm business legitimacy, vet beneficial ownership, and satisfy anti-money laundering (AML) screening.

When this policy applies

This policy applies at initial merchant onboarding and during periodic re-verification reviews. Merchants that do not provide required documentation within set timelines must be suspended until compliance is restored. Additionally, any merchant confirmed to have an ADC (Account Data Compromise) Event will be reclassified as a Level 1 Merchant, subjecting them to enhanced compliance validation and monitoring as required by Mastercard.

Required actions

  1. Collect all KYB documentation needed at onboarding.

  2. Conduct AML screening against applicable watchlists before approval.

  3. Verify business licenses for regulated merchant categories.

  4. Schedule full re-verification at least annually.

  5. Document verification outcomes and maintain records for audit.

  6. Retain MATCH system records related to Merchants, Sponsored Merchants, or ATM owners for at least two years after contract termination or expiration, to meet Mastercard record retention requirements.

  7. Before Merchant Agreement execution or enabling transactions, conduct a MATCH inquiry using Halyard Pay's Member ID/ICA Number to ensure compliance; failure may lead to Mastercard assessments.

  8. For merchants whose personal data pertains to residents of the European Economic Area, the UK, or Switzerland, Halyard Pay must comply with EU Data Protection Laws as specified in Appendix D of the Mastercard SPME manual concerning MATCH activities in the Europe Region.

9. Implement heightened due diligence and monitoring procedures for any merchant reclassified as Level 1 due to a confirmed ADC Event, consistent with Mastercard requirements for Level 1 Merchants.

Source authority: Mastercard SPME §§2.1, 2.2.6, 7.1, 11.2.3, 11.2.6, 11.7.1.

Source authority: Mastercard SPME §2.2.6.

--- a/policies/kyb_acquirer/rules.yaml
+++ b/policies/kyb_acquirer/rules.yaml
@@ -1,5 +1,5 @@
 program: Acquirer KYB
-authority: Mastercard SPME 2.1, 11.2.3, 11.2.6, 11.7.1
+authority: Mastercard SPME 2.1, 2.2.6, 11.2.3, 11.2.6, 11.7.1
 required_documents:
   - incorporation
   - beneficial_ownership
@@ -14,5 +14,7 @@
 agent_owner: kyb_agent
 # Acquirers must perform a MATCH inquiry prior to entering into any Merchant Agreement or enabling a Merchant to accept transactions, as detailed in Mastercard SPME §11.2.3. This inquiry must be conducted using the correct Member ID/ICA Number associated with the Merchant to ensure proper compliance reporting.
 # Failure to adhere to these requirements may result in noncompliance assessments.
-# The Acquirer is also required to retain all MATCH records related to any Merchant, Sponsored Merchant, or ATM owner for a minimum of two years post-agreement termination, as per Mastercard SPME §11.2.6.
+# The Acquirer is required to retain all MATCH records related to any Merchant, Sponsored Merchant, or ATM owner for a minimum of two years post-agreement termination, as per Mastercard SPME §11.2.6.
 # Additionally, Acquirers that store, transmit, or process personal data of residents in the European Economic Area (EEA), the UK, or Switzerland—or are otherwise subject to EU Data Protection Law—must comply with the standards specified in Appendix D concerning MATCH activity within the Europe Region, consistent with Mastercard SPME §11.7.1.
+# New requirements under Mastercard SPME §2.2.6 specify that any Merchant with a confirmed Account Data Compromise (ADC) Event must be automatically reclassified as a Level 1 Merchant. This triggers enhanced compliance validation requirements and associated noncompliance assessments applicable to acquirers during merchant onboarding and monitoring processes.
+# This addition highlights the need for acquirers to implement controls for identifying and managing Level 1 Merchant reclassifications promptly to maintain compliance.
--- a/policies/kyb_acquirer/policy.md
+++ b/policies/kyb_acquirer/policy.md
@@ -4,7 +4,7 @@
 
 ## When this policy applies
 
-This policy applies at initial merchant onboarding and during periodic re-verification reviews. Merchants that do not provide required documentation within set timelines must be suspended until compliance is restored.
+This policy applies at initial merchant onboarding and during periodic re-verification reviews. Merchants that do not provide required documentation within set timelines must be suspended until compliance is restored. Additionally, any merchant confirmed to have an ADC (Account Data Compromise) Event will be reclassified as a Level 1 Merchant, subjecting them to enhanced compliance validation and monitoring as required by Mastercard.
 
 ## Required actions
 
@@ -16,5 +16,6 @@
 6. Retain MATCH system records related to Merchants, Sponsored Merchants, or ATM owners for at least two years after contract termination or expiration, to meet Mastercard record retention requirements.
 7. Before Merchant Agreement execution or enabling transactions, conduct a MATCH inquiry using Halyard Pay's Member ID/ICA Number to ensure compliance; failure may lead to Mastercard assessments.
 8. For merchants whose personal data pertains to residents of the European Economic Area, the UK, or Switzerland, Halyard Pay must comply with EU Data Protection Laws as specified in Appendix D of the Mastercard SPME manual concerning MATCH activities in the Europe Region.
+9. Implement heightened due diligence and monitoring procedures for any merchant reclassified as Level 1 due to a confirmed ADC Event, consistent with Mastercard requirements for Level 1 Merchants.
 
-Source authority: Mastercard SPME §§2.1, 7.1, 11.2.3, 11.2.6, 11.7.1.+Source authority: Mastercard SPME §§2.1, 2.2.6, 7.1, 11.2.3, 11.2.6, 11.7.1.