Mastercard SPME §8.3.1 · Feb 2024 → Sep 2024
ECP Definitions
The definition and explanation of 'Basis Points' in the ECP definitions section was removed entirely, eliminating how basis points are calculated based on chargebacks and transactions.
program: ECP- authority: Mastercard SPME §11.4, §11.5, §13.1.2+ authority: Mastercard SPME 11.4, 11.5, 13.1.2chargeback_to_transaction_ratio_threshold: 0.015min_chargeback_count: 100program_tiers:- standard- excessivetier_thresholds:standard: 0.015excessive: 0.030merchant_notification_business_days: 5monitoring_cadence: monthlyagent_owner: ecp_ops_agent- # The reason codes used by Acquirers for MATCH reporting have evolved, removing explicit Excessive Chargebacks code and replacing it with broader violation categories such as 'Violation of Standards' and 'Illegal Transactions' per Mastercard SPME §11.5.1.- # Despite this change, the Excessive Chargeback Program's internal thresholds and monitoring parameters remain unchanged to maintain continuity in risk management.- # The policy continues to reference SPME sections relevant to chargeback handling and privacy, reflecting ongoing compliance without modifying program metrics or tier definitions.-+ # The SPME discontinued the explicit definition of 'Basis Points' in section 8.3.1, which previously described chargeback rate calculations.+ # Despite this removal, the ECP Thresholds policy retains chargeback rate thresholds expressed as ratios rather than basis points,+ # maintaining consistency with Mastercard's monitoring requirements under section 11.4.+ # Program thresholds and tier definitions remain unchanged, preserving the integrity of risk evaluation and compliance.
Excessive Chargeback Program (ECP) Thresholds
Mastercard's Excessive Chargeback Program (ECP) monitors merchants whose chargeback activity exceeds established thresholds relative to monthly transaction volume and chargeback amounts. Halyard Pay tracks these metrics monthly and escalates merchants meeting or surpassing program criteria into risk management processes.
Program tiers
There are two escalation tiers: tiers based on chargeback-to-transaction ratios calculated monthly:
-
Standard:
chargeback-to-transaction ratio ofChargeback ratio of at least 1.5% (0.015)or higher and at leastwith a minimum of 100chargebacks in a month.chargebacks. -
Excessive:
chargebackChargeback ratio of 3.0% (0.03) orgreatergreater.
The chargeback ratio is determined by dividing the number of chargebacks received for the a merchant within a month by the total Mastercard transactions for that merchant in the preceding month.
MATCH Listing criteria
Merchants may be reported to the MATCH system under broad reasons such as including compliance violations, fraudulent activity, behavior, or illegal transactions, rather than activity—not solely for excessive chargebacks. Reporting continues if monthly Mastercard criteria require chargebacks to exceed 1% of Mastercard sales transactions and amount to and a USD 5,000 or more. chargeback amount. Acquirers must evaluate applicable assess relevant standards violations or risk-related behaviors as and risk behavior per Mastercard and American Express requirements. protocols.
Required actions
-
Calculate each merchant's monthly chargeback-to-transaction ratio and total chargeback
amount at month-end.amount. -
Assign
the merchantmerchants to the appropriate escalation tier based on ratio thresholds. -
Evaluate MATCH reporting
criterianeeds considering broader compliance or legalviolations, not limited to chargeback counts.issues. -
Open an ECP case and notify the merchant within five business days.
-
Continuously monitor merchants'Monitor merchants monthlyperformanceuntilthey exit the program.program exit. -
Escalate cases to chargeback agents for automated
casehandling.
Data Protection and Privacy Considerations
In line Aligned with Mastercard's updated data protection framework requirements under EU Data Protection Law, regulations, Halyard Pay ensures that all processing of personal data involved in the processing related to ECP complies with enhanced privacy and security requirements. This includes limiting data protocols, including minimizing access, applying robust safeguards, adhering to data safeguarding data, complying with transfer restrictions, and facilitating timely notification and cooperation in case of personal data breaches. cooperating on breach notifications. Halyard Pay and its customers act clients function as independent controllers of personal data related to the ECP and maintain transparent accountability mechanisms to meet these obligations. controllers, maintaining transparency and accountability.
Source authority: Mastercard SPME §§11.4, 11.5, 13.1.2, 11.5.1.
Excessive Chargeback Program (ECP) Thresholds
Mastercard's Excessive Chargeback Program (ECP) monitors merchants whose chargeback activity exceeds established thresholds relative to monthly transaction volume and chargeback amounts. Halyard Pay tracks these metrics monthly and escalates merchants meeting or surpassing program criteria into risk management processes.
Program tiers
There are two escalation tiers: tiers based on chargeback-to-transaction ratios calculated monthly:
-
Standard:
chargeback-to-transaction ratio ofChargeback ratio of at least 1.5% (0.015)or higher and at leastwith a minimum of 100chargebacks in a month.chargebacks. -
Excessive:
chargebackChargeback ratio of 3.0% (0.03) orgreatergreater.
The chargeback ratio is determined by dividing the number of chargebacks received for the a merchant within a month by the total Mastercard transactions for that merchant in the preceding month.
MATCH Listing criteria
Merchants may be reported to the MATCH system under broad reasons such as including compliance violations, fraudulent activity, behavior, or illegal transactions, rather than activity—not solely for excessive chargebacks. Reporting continues if monthly Mastercard criteria require chargebacks to exceed 1% of Mastercard sales transactions and amount to and a USD 5,000 or more. chargeback amount. Acquirers must evaluate applicable assess relevant standards violations or risk-related behaviors as and risk behavior per Mastercard and American Express requirements. protocols.
Required actions
-
Calculate each merchant's monthly chargeback-to-transaction ratio and total chargeback
amount at month-end.amount. -
Assign
the merchantmerchants to the appropriate escalation tier based on ratio thresholds. -
Evaluate MATCH reporting
criterianeeds considering broader compliance or legalviolations, not limited to chargeback counts.issues. -
Open an ECP case and notify the merchant within five business days.
-
Continuously monitor merchants'Monitor merchants monthlyperformanceuntilthey exit the program.program exit. -
Escalate cases to chargeback agents for automated
casehandling.
Data Protection and Privacy Considerations
In line Aligned with Mastercard's updated data protection framework requirements under EU Data Protection Law, regulations, Halyard Pay ensures that all processing of personal data involved in the processing related to ECP complies with enhanced privacy and security requirements. This includes limiting data protocols, including minimizing access, applying robust safeguards, adhering to data safeguarding data, complying with transfer restrictions, and facilitating timely notification and cooperation in case of personal data breaches. cooperating on breach notifications. Halyard Pay and its customers act clients function as independent controllers of personal data related to the ECP and maintain transparent accountability mechanisms to meet these obligations. controllers, maintaining transparency and accountability.
Source authority: Mastercard SPME §§11.4, 11.5, 13.1.2, 11.5.1.
Source authority: Mastercard SPME §8.3.1.
--- a/policies/ecp_thresholds/rules.yaml +++ b/policies/ecp_thresholds/rules.yaml @@ -1,5 +1,5 @@ program: ECP -authority: Mastercard SPME §11.4, §11.5, §13.1.2 +authority: Mastercard SPME 11.4, 11.5, 13.1.2 chargeback_to_transaction_ratio_threshold: 0.015 min_chargeback_count: 100 program_tiers: @@ -12,7 +12,7 @@ monitoring_cadence: monthly agent_owner: ecp_ops_agent -# The reason codes used by Acquirers for MATCH reporting have evolved, removing explicit Excessive Chargebacks code and replacing it with broader violation categories such as 'Violation of Standards' and 'Illegal Transactions' per Mastercard SPME §11.5.1. -# Despite this change, the Excessive Chargeback Program's internal thresholds and monitoring parameters remain unchanged to maintain continuity in risk management. -# The policy continues to reference SPME sections relevant to chargeback handling and privacy, reflecting ongoing compliance without modifying program metrics or tier definitions. - +# The SPME discontinued the explicit definition of 'Basis Points' in section 8.3.1, which previously described chargeback rate calculations. +# Despite this removal, the ECP Thresholds policy retains chargeback rate thresholds expressed as ratios rather than basis points, +# maintaining consistency with Mastercard's monitoring requirements under section 11.4. +# Program thresholds and tier definitions remain unchanged, preserving the integrity of risk evaluation and compliance. --- a/policies/ecp_thresholds/policy.md +++ b/policies/ecp_thresholds/policy.md @@ -4,25 +4,27 @@ ## Program tiers -There are two escalation tiers: -- **Standard**: chargeback-to-transaction ratio of 1.5% (0.015) or higher and at least 100 chargebacks in a month. -- **Excessive**: chargeback ratio of 3.0% (0.03) or greater for the month. +There are two escalation tiers based on chargeback-to-transaction ratios calculated monthly: +- **Standard**: Chargeback ratio of at least 1.5% (0.015) with a minimum of 100 chargebacks. +- **Excessive**: Chargeback ratio of 3.0% (0.03) or greater. + +The chargeback ratio is determined by dividing the number of chargebacks received for a merchant within a month by the total Mastercard transactions for that merchant in the preceding month. ## MATCH Listing criteria -Merchants may be reported to the MATCH system under broad reasons such as compliance violations, fraudulent activity, or illegal transactions, rather than solely for excessive chargebacks. Reporting continues if monthly Mastercard chargebacks exceed 1% of Mastercard sales transactions and amount to USD 5,000 or more. Acquirers must evaluate applicable standards violations or risk-related behaviors as per Mastercard and American Express requirements. +Merchants may be reported to the MATCH system under reasons including compliance violations, fraudulent behavior, or illegal activity—not solely for excessive chargebacks. Reporting criteria require chargebacks to exceed 1% of Mastercard sales and a USD 5,000 chargeback amount. Acquirers must assess relevant standards and risk behavior per Mastercard and American Express protocols. ## Required actions -1. Calculate each merchant's chargeback-to-transaction ratio and total chargeback amount at month-end. -2. Assign the merchant to the appropriate tier based on ratio thresholds. -3. Evaluate MATCH reporting criteria considering compliance or legal violations, not limited to chargeback counts. +1. Calculate each merchant's monthly chargeback-to-transaction ratio and total chargeback amount. +2. Assign merchants to the appropriate escalation tier based on ratio thresholds. +3. Evaluate MATCH reporting needs considering broader compliance or legal issues. 4. Open an ECP case and notify the merchant within five business days. -5. Continuously monitor merchants' monthly performance until they exit the program. -6. Escalate to chargeback agents for automated case handling. +5. Monitor merchants monthly until program exit. +6. Escalate cases to chargeback agents for automated handling. ## Data Protection and Privacy Considerations -In line with Mastercard's updated data protection framework under EU Data Protection Law, Halyard Pay ensures that all processing of personal data involved in the ECP complies with enhanced privacy and security requirements. This includes limiting data access, applying robust safeguards, adhering to data transfer restrictions, and facilitating timely notification and cooperation in case of personal data breaches. Halyard Pay and its customers act as independent controllers of personal data related to the ECP and maintain transparent accountability mechanisms to meet these obligations. +Aligned with Mastercard's data protection requirements under EU regulations, Halyard Pay ensures all personal data processing related to ECP complies with enhanced privacy and security protocols, including minimizing access, safeguarding data, complying with transfer restrictions, and cooperating on breach notifications. Halyard Pay and clients function as independent data controllers, maintaining transparency and accountability. Source authority: Mastercard SPME §§11.4, 11.5, 13.1.2, 11.5.1.