Mastercard SPME §2.3 · Feb 2024 → Sep 2024
Card Production Security Standards
The updated section introduces a requirement for a security assessment and certification of vendor facilities under the GVCP, including annual certification renewal and publication of certified vendors in a Mastercard Announcement, before an Issuer can engage such a vendor for card production services.
Security Rules and Procedures—Merchant Edition • 6 February 2024
Any agreement between an Issuer and a vendor for Card production services should contain terms stating that the vendor agrees to safeguard and control usage of Account data and to comply with all applicable Standards then in effect, including but not limited to those set forth in section 2.3 and in the Card Design Standards manual. For more information about the GVCP, contact Mastercard by sending an email message to gvcp-helpdesk@mastercard.com.
Security Rules and Procedures—Merchant Edition • 6 August 2024
Prior to certification and annual recertification of a vendor facility under the GVCP, a security assessment of the facility is conducted at approximately 12-month intervals to evaluate the facility's compliance with the PCI documents referenced in section 2.3. A certified vendor facility is issued a compliance certification, which is subject to annual renewal, provided the vendor facility remains in good standing. The “List of Certified Vendors,” as published monthly in a Mastercard Announcement (AN) available on the Technical Resource Center on Mastercard Connect®, contains the name of each vendor facility then certified and a description of the specific services that the facility is authorized to perform. Any agreement between an Issuer and a vendor for Card production services should contain terms stating that the vendor agrees to safeguard and control usage of Account data and to comply with all applicable Standards then in effect, including but not limited to those set forth in section 2.3 and in the Card Design Standards manual. For more information about the GVCP, contact Mastercard by sending an email message to gvcp-helpdesk@mastercard.com.
program: Acquirer KYB- authority: Mastercard SPME 2.1, 11.2.3, 11.2.6, 11.7.1+ authority: Mastercard SPME 2.1, 2.3, 11.2.3, 11.2.6, 11.7.1required_documents:- incorporation- beneficial_ownership- aml_screen- license_verification+ - gvcp_vendor_certificationmin_review_cycle_days: 365suspension_trigger: document_collection_failurerecord_retention_years: 7aml_watchlist_sources:- ofac_sdn- eu_consolidatedagent_owner: kyb_agent# Acquirers must perform a MATCH inquiry prior to entering into any Merchant Agreement or enabling a Merchant to accept transactions, as detailed in Mastercard SPME §11.2.3. This inquiry must be conducted using the correct Member ID/ICA Number associated with the Merchant to ensure proper compliance reporting.# Failure to adhere to these requirements may result in noncompliance assessments.# The Acquirer is also required to retain all MATCH records related to any Merchant, Sponsored Merchant, or ATM owner for a minimum of two years post-agreement termination, as per Mastercard SPME §11.2.6.# Additionally, Acquirers that store, transmit, or process personal data of residents in the European Economic Area (EEA), the UK, or Switzerland—or are otherwise subject to EU Data Protection Law—must comply with the standards specified in Appendix D concerning MATCH activity within the Europe Region, consistent with Mastercard SPME §11.7.1.+ #+ # Per the updated Mastercard SPME §2.3, Acquirers must verify that vendors performing card production services have undergone a security assessment and hold a current GVCP certification prior to onboarding and on an annual basis thereafter. This includes reviewing the Mastercard published List of Certified Vendors as part of the due diligence to ensure ongoing compliance with applicable security standards.
Acquirer KYB (Know Your Business) Obligations
Acquirers processing transactions on the Mastercard network must perform Know Your Business (KYB) due diligence on merchants prior to onboarding and on a recurring basis. Halyard Pay is responsible for collecting and verifying required documentation to confirm business legitimacy, vet beneficial ownership, and satisfy anti-money laundering (AML) screening.
When this policy applies
This policy applies at initial merchant onboarding and during periodic re-verification reviews. Merchants that do not provide required documentation within set timelines must be suspended until compliance is restored.
Required actions
-
Collect all KYB documentation needed at onboarding.
-
Conduct AML screening against applicable watchlists before approval.
-
Verify business licenses for regulated merchant categories.
-
Schedule full re-verification at least annually.
-
Document verification outcomes and maintain records for audit.
-
Retain MATCH system records related to Merchants, Sponsored Merchants, or ATM owners for at least two years after contract termination or expiration, to meet Mastercard record retention requirements.
-
Before Merchant Agreement execution or enabling transactions, conduct a MATCH inquiry using Halyard Pay's Member ID/ICA Number to ensure compliance; failure may lead to Mastercard assessments.
-
For merchants whose personal data pertains to residents of the European Economic Area, the UK, or Switzerland, Halyard Pay must comply with EU Data Protection Laws as specified in Appendix D of the Mastercard SPME manual concerning MATCH activities in the Europe Region.
9. When onboarding or contracting with vendors for Card production services under the Global Vendor Certification Program (GVCP), ensure vendor facilities hold current GVCP certification and comply with the annual security assessment requirements described in Mastercard SPME §2.3. Update agreements to reflect that vendors must safeguard Account data and adhere to applicable PCI standards and Mastercard Card Design Standards.
Source authority: Mastercard SPME §§2.1, 2.3, 7.1, 11.2.3, 11.2.6, 11.7.1.
Acquirer KYB (Know Your Business) Obligations
Acquirers processing transactions on the Mastercard network must perform Know Your Business (KYB) due diligence on merchants prior to onboarding and on a recurring basis. Halyard Pay is responsible for collecting and verifying required documentation to confirm business legitimacy, vet beneficial ownership, and satisfy anti-money laundering (AML) screening.
When this policy applies
This policy applies at initial merchant onboarding and during periodic re-verification reviews. Merchants that do not provide required documentation within set timelines must be suspended until compliance is restored.
Required actions
-
Collect all KYB documentation needed at onboarding.
-
Conduct AML screening against applicable watchlists before approval.
-
Verify business licenses for regulated merchant categories.
-
Schedule full re-verification at least annually.
-
Document verification outcomes and maintain records for audit.
-
Retain MATCH system records related to Merchants, Sponsored Merchants, or ATM owners for at least two years after contract termination or expiration, to meet Mastercard record retention requirements.
-
Before Merchant Agreement execution or enabling transactions, conduct a MATCH inquiry using Halyard Pay's Member ID/ICA Number to ensure compliance; failure may lead to Mastercard assessments.
-
For merchants whose personal data pertains to residents of the European Economic Area, the UK, or Switzerland, Halyard Pay must comply with EU Data Protection Laws as specified in Appendix D of the Mastercard SPME manual concerning MATCH activities in the Europe Region.
9. When onboarding or contracting with vendors for Card production services under the Global Vendor Certification Program (GVCP), ensure vendor facilities hold current GVCP certification and comply with the annual security assessment requirements described in Mastercard SPME §2.3. Update agreements to reflect that vendors must safeguard Account data and adhere to applicable PCI standards and Mastercard Card Design Standards.
Source authority: Mastercard SPME §§2.1, 2.3, 7.1, 11.2.3, 11.2.6, 11.7.1.
Source authority: Mastercard SPME §2.3.
--- a/policies/kyb_acquirer/rules.yaml +++ b/policies/kyb_acquirer/rules.yaml @@ -1,10 +1,11 @@ program: Acquirer KYB -authority: Mastercard SPME 2.1, 11.2.3, 11.2.6, 11.7.1 +authority: Mastercard SPME 2.1, 2.3, 11.2.3, 11.2.6, 11.7.1 required_documents: - incorporation - beneficial_ownership - aml_screen - license_verification + - gvcp_vendor_certification min_review_cycle_days: 365 suspension_trigger: document_collection_failure record_retention_years: 7 @@ -16,3 +17,5 @@ # Failure to adhere to these requirements may result in noncompliance assessments. # The Acquirer is also required to retain all MATCH records related to any Merchant, Sponsored Merchant, or ATM owner for a minimum of two years post-agreement termination, as per Mastercard SPME §11.2.6. # Additionally, Acquirers that store, transmit, or process personal data of residents in the European Economic Area (EEA), the UK, or Switzerland—or are otherwise subject to EU Data Protection Law—must comply with the standards specified in Appendix D concerning MATCH activity within the Europe Region, consistent with Mastercard SPME §11.7.1. +# +# Per the updated Mastercard SPME §2.3, Acquirers must verify that vendors performing card production services have undergone a security assessment and hold a current GVCP certification prior to onboarding and on an annual basis thereafter. This includes reviewing the Mastercard published List of Certified Vendors as part of the due diligence to ensure ongoing compliance with applicable security standards. --- a/policies/kyb_acquirer/policy.md +++ b/policies/kyb_acquirer/policy.md @@ -16,5 +16,6 @@ 6. Retain MATCH system records related to Merchants, Sponsored Merchants, or ATM owners for at least two years after contract termination or expiration, to meet Mastercard record retention requirements. 7. Before Merchant Agreement execution or enabling transactions, conduct a MATCH inquiry using Halyard Pay's Member ID/ICA Number to ensure compliance; failure may lead to Mastercard assessments. 8. For merchants whose personal data pertains to residents of the European Economic Area, the UK, or Switzerland, Halyard Pay must comply with EU Data Protection Laws as specified in Appendix D of the Mastercard SPME manual concerning MATCH activities in the Europe Region. +9. When onboarding or contracting with vendors for Card production services under the Global Vendor Certification Program (GVCP), ensure vendor facilities hold current GVCP certification and comply with the annual security assessment requirements described in Mastercard SPME §2.3. Update agreements to reflect that vendors must safeguard Account data and adhere to applicable PCI standards and Mastercard Card Design Standards. -Source authority: Mastercard SPME §§2.1, 7.1, 11.2.3, 11.2.6, 11.7.1.+Source authority: Mastercard SPME §§2.1, 2.3, 7.1, 11.2.3, 11.2.6, 11.7.1.