Mastercard SPME §8.3.1 · Feb 2024 → Sep 2024

ECP Definitions

substantive

The definition and explanation of 'Basis Points' in the ECP definitions section was removed entirely, eliminating how basis points are calculated based on chargebacks and transactions.

Sources Mastercard SPME · Feb 2024 · page 75 PDF Mastercard SPME · Sep 2024 · page 78 PDF ECP Thresholds current
Also in §8.x this release breaking §8.4.2 Mastercard Commencement of an Investigation substantive §8.4 Questionable Merchant Audit Program (QMAP) substantive §8.4.7 Chargeback Responsibility substantive §8.4.8 Fraud Recovery substantive §8.6.2 Investigation Process
Why these edits? The removal of the 'Basis Points' definition affects the Excessive Chargeback Program (ECP) Thresholds policy as it alters how chargeback rates are calculated and understood under section 11.4, which directly impacts the threshold determination and monitoring processes.
Mastercard SPME §8.3.1
The following terms used in the ECP have the meanings set forth below. Merchant A Merchant (as the term “Merchant” is defined in Appendix E of this manual) is identified by the unique Acquirer-assigned Merchant identifier (MID) populated in DE 42 (Card Acceptor ID Code) in Transaction clearing messages. Basis Points Basis points are the number of chargebacks received by the Acquirer for a Merchant in a ¶ calendar month divided by the number of Mastercard Transactions in the preceding month ¶ acquired for that same Merchant and then multiplied by 10,000. ¶ Mastercard Fraud Control Programs
Halyard Pay · 2 files
program: ECP
- authority: Mastercard SPME §11.4, §11.5, §13.1.2
+ authority: Mastercard SPME 11.4, 11.5, 13.1.2
chargeback_to_transaction_ratio_threshold: 0.015
min_chargeback_count: 100
program_tiers:
- standard
- excessive
tier_thresholds:
standard: 0.015
excessive: 0.030
merchant_notification_business_days: 5
monitoring_cadence: monthly
agent_owner: ecp_ops_agent
 
- # The reason codes used by Acquirers for MATCH reporting have evolved, removing explicit Excessive Chargebacks code and replacing it with broader violation categories such as 'Violation of Standards' and 'Illegal Transactions' per Mastercard SPME §11.5.1.
- # Despite this change, the Excessive Chargeback Program's internal thresholds and monitoring parameters remain unchanged to maintain continuity in risk management.
- # The policy continues to reference SPME sections relevant to chargeback handling and privacy, reflecting ongoing compliance without modifying program metrics or tier definitions.
-
+ # The SPME discontinued the explicit definition of 'Basis Points' in section 8.3.1, which previously described chargeback rate calculations.
+ # Despite this removal, the ECP Thresholds policy retains chargeback rate thresholds expressed as ratios rather than basis points,
+ # maintaining consistency with Mastercard's monitoring requirements under section 11.4.
+ # Program thresholds and tier definitions remain unchanged, preserving the integrity of risk evaluation and compliance.

Excessive Chargeback Program (ECP) Thresholds

Mastercard's Excessive Chargeback Program (ECP) monitors merchants whose chargeback activity exceeds established thresholds relative to monthly transaction volume and chargeback amounts. Halyard Pay tracks these metrics monthly and escalates merchants meeting or surpassing program criteria into risk management processes.

Program tiers

There are two escalation tiers: tiers based on chargeback-to-transaction ratios calculated monthly:

  • Standard: chargeback-to-transaction ratio of Chargeback ratio of at least 1.5% (0.015) or higher and at least with a minimum of 100 chargebacks in a month. chargebacks.

  • Excessive: chargeback Chargeback ratio of 3.0% (0.03) or greater greater.

The chargeback ratio is determined by dividing the number of chargebacks received for the a merchant within a month by the total Mastercard transactions for that merchant in the preceding month.

MATCH Listing criteria

Merchants may be reported to the MATCH system under broad reasons such as including compliance violations, fraudulent activity, behavior, or illegal transactions, rather than activity—not solely for excessive chargebacks. Reporting continues if monthly Mastercard criteria require chargebacks to exceed 1% of Mastercard sales transactions and amount to and a USD 5,000 or more. chargeback amount. Acquirers must evaluate applicable assess relevant standards violations or risk-related behaviors as and risk behavior per Mastercard and American Express requirements. protocols.

Required actions

  1. Calculate each merchant's monthly chargeback-to-transaction ratio and total chargeback amount at month-end. amount.

  2. Assign the merchant merchants to the appropriate escalation tier based on ratio thresholds.

  3. Evaluate MATCH reporting criteria needs considering broader compliance or legal violations, not limited to chargeback counts. issues.

  4. Open an ECP case and notify the merchant within five business days.

  5. Continuously monitor merchants' Monitor merchants monthly performance until they exit the program. program exit.

  6. Escalate cases to chargeback agents for automated case handling.

Data Protection and Privacy Considerations

In line Aligned with Mastercard's updated data protection framework requirements under EU Data Protection Law, regulations, Halyard Pay ensures that all processing of personal data involved in the processing related to ECP complies with enhanced privacy and security requirements. This includes limiting data protocols, including minimizing access, applying robust safeguards, adhering to data safeguarding data, complying with transfer restrictions, and facilitating timely notification and cooperation in case of personal data breaches. cooperating on breach notifications. Halyard Pay and its customers act clients function as independent controllers of personal data related to the ECP and maintain transparent accountability mechanisms to meet these obligations. controllers, maintaining transparency and accountability.

Source authority: Mastercard SPME §§11.4, 11.5, 13.1.2, 11.5.1.

policies/ecp_thresholds/policy.md — after applying change

Excessive Chargeback Program (ECP) Thresholds

Mastercard's Excessive Chargeback Program (ECP) monitors merchants whose chargeback activity exceeds established thresholds relative to monthly transaction volume and chargeback amounts. Halyard Pay tracks these metrics monthly and escalates merchants meeting or surpassing program criteria into risk management processes.

Program tiers

There are two escalation tiers: tiers based on chargeback-to-transaction ratios calculated monthly:

  • Standard: chargeback-to-transaction ratio of Chargeback ratio of at least 1.5% (0.015) or higher and at least with a minimum of 100 chargebacks in a month. chargebacks.

  • Excessive: chargeback Chargeback ratio of 3.0% (0.03) or greater greater.

The chargeback ratio is determined by dividing the number of chargebacks received for the a merchant within a month by the total Mastercard transactions for that merchant in the preceding month.

MATCH Listing criteria

Merchants may be reported to the MATCH system under broad reasons such as including compliance violations, fraudulent activity, behavior, or illegal transactions, rather than activity—not solely for excessive chargebacks. Reporting continues if monthly Mastercard criteria require chargebacks to exceed 1% of Mastercard sales transactions and amount to and a USD 5,000 or more. chargeback amount. Acquirers must evaluate applicable assess relevant standards violations or risk-related behaviors as and risk behavior per Mastercard and American Express requirements. protocols.

Required actions

  1. Calculate each merchant's monthly chargeback-to-transaction ratio and total chargeback amount at month-end. amount.

  2. Assign the merchant merchants to the appropriate escalation tier based on ratio thresholds.

  3. Evaluate MATCH reporting criteria needs considering broader compliance or legal violations, not limited to chargeback counts. issues.

  4. Open an ECP case and notify the merchant within five business days.

  5. Continuously monitor merchants' Monitor merchants monthly performance until they exit the program. program exit.

  6. Escalate cases to chargeback agents for automated case handling.

Data Protection and Privacy Considerations

In line Aligned with Mastercard's updated data protection framework requirements under EU Data Protection Law, regulations, Halyard Pay ensures that all processing of personal data involved in the processing related to ECP complies with enhanced privacy and security requirements. This includes limiting data protocols, including minimizing access, applying robust safeguards, adhering to data safeguarding data, complying with transfer restrictions, and facilitating timely notification and cooperation in case of personal data breaches. cooperating on breach notifications. Halyard Pay and its customers act clients function as independent controllers of personal data related to the ECP and maintain transparent accountability mechanisms to meet these obligations. controllers, maintaining transparency and accountability.

Source authority: Mastercard SPME §§11.4, 11.5, 13.1.2, 11.5.1.

Source authority: Mastercard SPME §8.3.1.

--- a/policies/ecp_thresholds/rules.yaml
+++ b/policies/ecp_thresholds/rules.yaml
@@ -1,5 +1,5 @@
 program: ECP
-authority: Mastercard SPME §11.4, §11.5, §13.1.2
+authority: Mastercard SPME 11.4, 11.5, 13.1.2
 chargeback_to_transaction_ratio_threshold: 0.015
 min_chargeback_count: 100
 program_tiers:
@@ -12,7 +12,7 @@
 monitoring_cadence: monthly
 agent_owner: ecp_ops_agent
 
-# The reason codes used by Acquirers for MATCH reporting have evolved, removing explicit Excessive Chargebacks code and replacing it with broader violation categories such as 'Violation of Standards' and 'Illegal Transactions' per Mastercard SPME §11.5.1.
-# Despite this change, the Excessive Chargeback Program's internal thresholds and monitoring parameters remain unchanged to maintain continuity in risk management.
-# The policy continues to reference SPME sections relevant to chargeback handling and privacy, reflecting ongoing compliance without modifying program metrics or tier definitions.
-
+# The SPME discontinued the explicit definition of 'Basis Points' in section 8.3.1, which previously described chargeback rate calculations.
+# Despite this removal, the ECP Thresholds policy retains chargeback rate thresholds expressed as ratios rather than basis points,
+# maintaining consistency with Mastercard's monitoring requirements under section 11.4.
+# Program thresholds and tier definitions remain unchanged, preserving the integrity of risk evaluation and compliance.

--- a/policies/ecp_thresholds/policy.md
+++ b/policies/ecp_thresholds/policy.md
@@ -4,25 +4,27 @@
 
 ## Program tiers
 
-There are two escalation tiers:
-- **Standard**: chargeback-to-transaction ratio of 1.5% (0.015) or higher and at least 100 chargebacks in a month.
-- **Excessive**: chargeback ratio of 3.0% (0.03) or greater for the month.
+There are two escalation tiers based on chargeback-to-transaction ratios calculated monthly:
+- **Standard**: Chargeback ratio of at least 1.5% (0.015) with a minimum of 100 chargebacks.
+- **Excessive**: Chargeback ratio of 3.0% (0.03) or greater.
+
+The chargeback ratio is determined by dividing the number of chargebacks received for a merchant within a month by the total Mastercard transactions for that merchant in the preceding month.
 
 ## MATCH Listing criteria
 
-Merchants may be reported to the MATCH system under broad reasons such as compliance violations, fraudulent activity, or illegal transactions, rather than solely for excessive chargebacks. Reporting continues if monthly Mastercard chargebacks exceed 1% of Mastercard sales transactions and amount to USD 5,000 or more. Acquirers must evaluate applicable standards violations or risk-related behaviors as per Mastercard and American Express requirements.
+Merchants may be reported to the MATCH system under reasons including compliance violations, fraudulent behavior, or illegal activity—not solely for excessive chargebacks. Reporting criteria require chargebacks to exceed 1% of Mastercard sales and a USD 5,000 chargeback amount. Acquirers must assess relevant standards and risk behavior per Mastercard and American Express protocols.
 
 ## Required actions
 
-1. Calculate each merchant's chargeback-to-transaction ratio and total chargeback amount at month-end.
-2. Assign the merchant to the appropriate tier based on ratio thresholds.
-3. Evaluate MATCH reporting criteria considering compliance or legal violations, not limited to chargeback counts.
+1. Calculate each merchant's monthly chargeback-to-transaction ratio and total chargeback amount.
+2. Assign merchants to the appropriate escalation tier based on ratio thresholds.
+3. Evaluate MATCH reporting needs considering broader compliance or legal issues.
 4. Open an ECP case and notify the merchant within five business days.
-5. Continuously monitor merchants' monthly performance until they exit the program.
-6. Escalate to chargeback agents for automated case handling.
+5. Monitor merchants monthly until program exit.
+6. Escalate cases to chargeback agents for automated handling.
 
 ## Data Protection and Privacy Considerations
 
-In line with Mastercard's updated data protection framework under EU Data Protection Law, Halyard Pay ensures that all processing of personal data involved in the ECP complies with enhanced privacy and security requirements. This includes limiting data access, applying robust safeguards, adhering to data transfer restrictions, and facilitating timely notification and cooperation in case of personal data breaches. Halyard Pay and its customers act as independent controllers of personal data related to the ECP and maintain transparent accountability mechanisms to meet these obligations.
+Aligned with Mastercard's data protection requirements under EU regulations, Halyard Pay ensures all personal data processing related to ECP complies with enhanced privacy and security protocols, including minimizing access, safeguarding data, complying with transfer restrictions, and cooperating on breach notifications. Halyard Pay and clients function as independent data controllers, maintaining transparency and accountability.
 
 Source authority: Mastercard SPME §§11.4, 11.5, 13.1.2, 11.5.1.