Mastercard SPME §8.4.2 · Feb 2024 → Sep 2024

Mastercard Commencement of an Investigation

breaking
⚠ Extraction warning — review against source PDF. One side of the Mastercard SPME text below appears to contain only the page-running header, not body content. This usually means the section heading fell on a page boundary and the body was attributed to a neighbouring section in the source PDF. The AI summary and proposed edit below may be misleading. Verify in: Feb 2024 · page 79 ↗ · Sep 2024 · page 82 ↗.

The section on how Mastercard notifies Issuers during QMAP investigations was removed or replaced; previously detailed processes for bust-out and non-bust-out investigations, including specific reporting codes and Brazil-specific procedures, are no longer present in this version.

Sources Mastercard SPME · Feb 2024 · page 79 PDF Mastercard SPME · Sep 2024 · page 82 PDF Fraud Monitoring current
Also in §8.x this release substantive §8.3.1 ECP Definitions substantive §8.4 Questionable Merchant Audit Program (QMAP) substantive §8.4.7 Chargeback Responsibility substantive §8.4.8 Fraud Recovery substantive §8.6.2 Investigation Process
Why these edits? The removal of Mastercard's detailed procedures for notifying Issuers during QMAP investigations, including specific reporting codes and issuer notification methods, affects fraud monitoring obligations by eliminating requirements for Issuer notification and fraud reporting coordination during bust-out and other QMAP investigations.
Mastercard SPME §8.4.2
This section was substantively restructured between versions (5% text overlap). Compare the texts directly below.
Before · Feb 2024 · page 79

Security Rules and Procedures—Merchant Edition • 6 February 2024

8.4.3.1 Investigations Concerning Cardholder Bust-out Accounts If Mastercard commences a QMAP investigation concerning Cardholder bust-out accounts, Mastercard will notify an Issuer that Mastercard determines had accounts used in Transactions with the Merchant being investigated during the Case Scope Period. The notification will be sent by email message to the Issuer’s Security Contact then listed in the Company Contact Management application available on Mastercard Connect. With the notification, Mastercard will provide details of Transactions arising from use of the Issuer’s accounts at the Merchant during the Case Scope Period. Within 60 days following such notice, an Issuer must report to the Fraud and Loss Database all fraudulent Transactions conducted during the Case Scope Period associated with the Merchant being investigated. Transactions conducted on Cardholder bust-out accounts should be reported using fraud type code 51 (Bust-out Collusive Merchant). NOTE: To accelerate the determination by Mastercard of whether a Merchant is a Questionable Merchant, Issuers are urged to report fraudulent Transactions to the Fraud and Loss Database as expeditiously as feasible. For purposes of making such a determination, Mastercard only considers Transactions that take place (and the resulting fraudulent Transactions timely reported to the Fraud and Loss Database) during the Case Scope Period. 8.4.3.2 Investigations Not Concerning Cardholder Bust-out Accounts If Mastercard commences a QMAP investigation not concerning Cardholder bust-out accounts, Mastercard will notify an Issuer that Mastercard determines had accounts used in Transactions with the Merchant being investigated during the Case Scope Period only if Mastercard determines that the Merchant is a Questionable Merchant. The notification will be sent by email message to the Issuer's Security Contact then listed in the Company Contact Management application available on Mastercard Connect. For Brazil: Instead of sending each Issuer a notice, Mastercard will rely on the fraud reported under Fraud Code 56.

After · Sep 2024 · page 82

Security Rules and Procedures—Merchant Edition • 6 August 2024

Halyard Pay · 2 files
program: Fraud Monitoring
- authority: Mastercard SPME §3.7, §8.6.6, §11.1.1
+ authority: Mastercard SPME 23, 8.6.6, 11.1.1
fraud_to_sales_ratio_threshold: 0.015
min_count_per_month: 100
monitoring_cadence: monthly
escalation_actions:
- escalate_to_human_review
- notify_acquirer
- provide_incident_report_to_mastercard_fraud_control_programs # Added to meet new SPME requirements
lookback_period_months: 1
remediation_review_interval_days: 30
agent_owner: fraud_ops_agent
 
- # MATCH fraud detection features are limited to principal owners only; associate owners and Service Provider name reporting are removed per SPME §11.1.1.
+ # MATCH fraud detection features are limited to principal owners only; associate owners and Service Provider name reporting are removed per SPME 11.1.1.
# Acquirers may add and search for information on up to five principal owners per Merchant.
# Multiple data fields are used to determine matches; MATCH supports editing and error notification to reduce delays.
# Retroactive alert processing is supported for data up to 360 days old.
# Acquirers control receipt and detail of inquiry match information.
# Real-time access via MATCH Online and API, and batch operations remain available.
# Merchant URL information may be added and searched.
# After obtaining MATCH inquiry results, acquirers must assess whether further investigation or risk mitigation actions are warranted, per updated SPME requirements.
#
- # New requirements under SPME §8.6.6 specify that Mastercard will add Merchants to MATCH using reason code 24 (Illegal Transactions) when Merchants meet Coercion Program criteria.
+ # New requirements under SPME 8.6.6 specify that Mastercard will add Merchants to MATCH using reason code 24 (Illegal Transactions) when Merchants meet Coercion Program criteria.
# Merchants subject to a subsequent claim of coercion within 12 months will be added with reason code 00 (Questionable Acquirer/Under Investigation).
# If the claim is confirmed to meet Coercion Program criteria, the MATCH record will be updated to reason code 24.
# If not confirmed, the MATCH record will be deleted.
# These provisions enhance fraud monitoring by requiring tracking of coercion-related transaction risks.
#
- # New SPME §11.1.1 further requires acquirers to submit incident reports to Mastercard Fraud Control Programs when violations are not reported by the Acquirer's MMSP, strengthening incident response and reporting cadence.
-
+ # New SPME 11.1.1 further requires acquirers to submit incident reports to Mastercard Fraud Control Programs when violations are not reported by the Acquirer's MMSP, strengthening incident response and reporting cadence.
+ #
+ # Removed previous SPME 8.4.3.1 and 8.4.3.2 issuer notification and fraud reporting requirements during QMAP investigations, eliminating issuer notification obligations for bust-out and other QMAP investigations and related fraud code reporting mandates.

Fraud Monitoring

Halyard Pay monitors merchant fraud activity and leverages Mastercard's MATCH system for enhanced fraud risk assessment on merchants processed through our platform.

When this policy applies

This policy applies to all merchants processed by Halyard Pay where Mastercard is the applicable network, covering both card-present and card-not-present transactions.

Required actions

  1. Compute the merchant's rolling fraud-to-sales ratio each calendar month.

  2. If the ratio meets or exceeds 1.5% and the fraud count reaches at least 100 transactions in that month, escalate the merchant account to human review immediately.

  3. Utilize Mastercard's MATCH system data focusing on principal owners only, as per the updated Mastercard SPME guidelines. Do not consider associate owners or Service Provider names in fraud assessments.

  4. Maintain awareness of Mastercard's MATCH reason codes related to coercion programs: merchants may be added with reason code 24 for illegal transactions upon meeting coercion criteria, or with code 00 if a subsequent coercion claim arises within 12 months; records must be updated or removed based on confirmation of these claims.

  5. After accessing MATCH data, conduct a risk assessment to determine whether further investigation or additional measures are warranted.

  6. Notify the acquiring compliance officer and document the case ID with supporting transaction data.

  7. Track case progress until the account returns to threshold compliance or is terminated.

  8. If any fraud violation is detected but not reported by Halyard Pay as the Acquirer's MMSP, escalate the incident report to Mastercard's Fraud Control Programs in accordance with according to Mastercard SPME §11 protocols. requirements.

This policy no longer includes requirements for coordinating issuer notifications or reporting fraudulent transactions related to bust-out account or other QMAP investigations, as Mastercard has removed these notification provisions from their procedures.

Source authority: Mastercard SPME §3.7, §8.6.6, §11.1.1, and §11.

policies/fraud_monitoring/policy.md — after applying change

Fraud Monitoring

Halyard Pay monitors merchant fraud activity and leverages Mastercard's MATCH system for enhanced fraud risk assessment on merchants processed through our platform.

When this policy applies

This policy applies to all merchants processed by Halyard Pay where Mastercard is the applicable network, covering both card-present and card-not-present transactions.

Required actions

  1. Compute the merchant's rolling fraud-to-sales ratio each calendar month.

  2. If the ratio meets or exceeds 1.5% and the fraud count reaches at least 100 transactions in that month, escalate the merchant account to human review immediately.

  3. Utilize Mastercard's MATCH system data focusing on principal owners only, as per the updated Mastercard SPME guidelines. Do not consider associate owners or Service Provider names in fraud assessments.

  4. Maintain awareness of Mastercard's MATCH reason codes related to coercion programs: merchants may be added with reason code 24 for illegal transactions upon meeting coercion criteria, or with code 00 if a subsequent coercion claim arises within 12 months; records must be updated or removed based on confirmation of these claims.

  5. After accessing MATCH data, conduct a risk assessment to determine whether further investigation or additional measures are warranted.

  6. Notify the acquiring compliance officer and document the case ID with supporting transaction data.

  7. Track case progress until the account returns to threshold compliance or is terminated.

  8. If any fraud violation is detected but not reported by Halyard Pay as the Acquirer's MMSP, escalate the incident report to Mastercard's Fraud Control Programs in accordance with according to Mastercard SPME §11 protocols. requirements.

This policy no longer includes requirements for coordinating issuer notifications or reporting fraudulent transactions related to bust-out account or other QMAP investigations, as Mastercard has removed these notification provisions from their procedures.

Source authority: Mastercard SPME §3.7, §8.6.6, §11.1.1, and §11.

Source authority: Mastercard SPME §8.4.2.

--- a/policies/fraud_monitoring/rules.yaml
+++ b/policies/fraud_monitoring/rules.yaml
@@ -1,5 +1,5 @@
 program: Fraud Monitoring
-authority: Mastercard SPME §3.7, §8.6.6, §11.1.1
+authority: Mastercard SPME 23, 8.6.6, 11.1.1
 fraud_to_sales_ratio_threshold: 0.015
 min_count_per_month: 100
 monitoring_cadence: monthly
@@ -11,7 +11,7 @@
 remediation_review_interval_days: 30
 agent_owner: fraud_ops_agent
 
-# MATCH fraud detection features are limited to principal owners only; associate owners and Service Provider name reporting are removed per SPME §11.1.1.
+# MATCH fraud detection features are limited to principal owners only; associate owners and Service Provider name reporting are removed per SPME 11.1.1.
 # Acquirers may add and search for information on up to five principal owners per Merchant.
 # Multiple data fields are used to determine matches; MATCH supports editing and error notification to reduce delays.
 # Retroactive alert processing is supported for data up to 360 days old.
@@ -20,11 +20,12 @@
 # Merchant URL information may be added and searched.
 # After obtaining MATCH inquiry results, acquirers must assess whether further investigation or risk mitigation actions are warranted, per updated SPME requirements.
 #
-# New requirements under SPME §8.6.6 specify that Mastercard will add Merchants to MATCH using reason code 24 (Illegal Transactions) when Merchants meet Coercion Program criteria.
+# New requirements under SPME 8.6.6 specify that Mastercard will add Merchants to MATCH using reason code 24 (Illegal Transactions) when Merchants meet Coercion Program criteria.
 # Merchants subject to a subsequent claim of coercion within 12 months will be added with reason code 00 (Questionable Acquirer/Under Investigation).
 # If the claim is confirmed to meet Coercion Program criteria, the MATCH record will be updated to reason code 24.
 # If not confirmed, the MATCH record will be deleted.
 # These provisions enhance fraud monitoring by requiring tracking of coercion-related transaction risks.
 #
-# New SPME §11.1.1 further requires acquirers to submit incident reports to Mastercard Fraud Control Programs when violations are not reported by the Acquirer's MMSP, strengthening incident response and reporting cadence.
-
+# New SPME 11.1.1 further requires acquirers to submit incident reports to Mastercard Fraud Control Programs when violations are not reported by the Acquirer's MMSP, strengthening incident response and reporting cadence.
+#
+# Removed previous SPME 8.4.3.1 and 8.4.3.2 issuer notification and fraud reporting requirements during QMAP investigations, eliminating issuer notification obligations for bust-out and other QMAP investigations and related fraud code reporting mandates.

--- a/policies/fraud_monitoring/policy.md
+++ b/policies/fraud_monitoring/policy.md
@@ -15,6 +15,8 @@
 5. After accessing MATCH data, conduct a risk assessment to determine whether further investigation or additional measures are warranted.
 6. Notify the acquiring compliance officer and document the case ID with supporting transaction data.
 7. Track case progress until the account returns to threshold compliance or is terminated.
-8. If any fraud violation is detected but not reported by Halyard Pay as the Acquirer's MMSP, escalate the incident report to Mastercard's Fraud Control Programs in accordance with Mastercard SPME §11 protocols.
+8. If any fraud violation is detected but not reported by Halyard Pay as the Acquirer's MMSP, escalate the incident report to Mastercard's Fraud Control Programs according to Mastercard SPME §11 requirements.
+
+This policy no longer includes requirements for coordinating issuer notifications or reporting fraudulent transactions related to bust-out account or other QMAP investigations, as Mastercard has removed these notification provisions from their procedures.
 
 Source authority: Mastercard SPME §3.7, §8.6.6, §11.1.1, and §11.