Mastercard SPME §8.6.2 · Feb 2024 → Sep 2024

Investigation Process

substantive

The specified 120 calendar day investigation period around the alleged coercive event has been shortened by removing the explanation that it includes 60 days before and after the event and Mastercard's discretion to expand the period.

Sources Mastercard SPME · Feb 2024 · page 83 PDF Mastercard SPME · Sep 2024 · page 86 PDF Fraud Monitoring current
Also in §8.x this release breaking §8.4.2 Mastercard Commencement of an Investigation substantive §8.3.1 ECP Definitions substantive §8.4 Questionable Merchant Audit Program (QMAP) substantive §8.4.7 Chargeback Responsibility substantive §8.4.8 Fraud Recovery
Why these edits? The change modifies the definition of the 120 calendar day investigation period by removing the specific breakdown of 60 days before and after the alleged coercive event and Mastercard's discretion to expand it, which affects fraud monitoring timelines related to coercion claims.
Mastercard SPME §8.6.2
Mastercard will investigate a claim of alleged coercion when the following criteria are met: • Within 120 calendar days from an alleged coercive event, Mastercard receives from two or more different issuers separate claims of alleged coerced Transactions performed by two or more unrelated Cardholders at the same Merchant location. The 120 calendar day period is calculated as 60 calendar days prior to and 60 calendar days after the date of the first ¶ alleged coerced Transaction. At Mastercard’s sole discretion, the 120 calendar day period ¶ may be expanded. ¶ Mastercard Fraud Control Programs
Halyard Pay · 2 files
program: Fraud Monitoring
- authority: Mastercard SPME §3.7, §8.6.6, §11.1.1
+ authority: Mastercard SPME 2.8.6, 3.7, 11.1.1
fraud_to_sales_ratio_threshold: 0.015
min_count_per_month: 100
monitoring_cadence: monthly
escalation_actions:
- escalate_to_human_review
- notify_acquirer
- provide_incident_report_to_mastercard_fraud_control_programs # Added to meet new SPME requirements
lookback_period_months: 1
remediation_review_interval_days: 30
agent_owner: fraud_ops_agent
 
- # MATCH fraud detection features are limited to principal owners only; associate owners and Service Provider name reporting are removed per SPME §11.1.1.
- # Acquirers may add and search for information on up to five principal owners per Merchant.
- # Multiple data fields are used to determine matches; MATCH supports editing and error notification to reduce delays.
- # Retroactive alert processing is supported for data up to 360 days old.
+ # MATCH fraud detection features focus on principal owners only; associate owners and Service Provider name reporting are excluded per SPME 11.1.1.
+ # Acquirers may search information on up to five principal owners per Merchant.
+ # Multiple data fields determine matches; MATCH supports editing and error correction to reduce delays.
+ # Retroactive alert processing supports data up to 360 days old.
# Acquirers control receipt and detail of inquiry match information.
- # Real-time access via MATCH Online and API, and batch operations remain available.
+ # Real-time access is available via MATCH Online, API, and batch processing.
# Merchant URL information may be added and searched.
- # After obtaining MATCH inquiry results, acquirers must assess whether further investigation or risk mitigation actions are warranted, per updated SPME requirements.
+ # Upon receiving MATCH inquiry results, acquirers must assess the need for further investigation or risk mitigation as updated in SPME.
#
- # New requirements under SPME §8.6.6 specify that Mastercard will add Merchants to MATCH using reason code 24 (Illegal Transactions) when Merchants meet Coercion Program criteria.
- # Merchants subject to a subsequent claim of coercion within 12 months will be added with reason code 00 (Questionable Acquirer/Under Investigation).
- # If the claim is confirmed to meet Coercion Program criteria, the MATCH record will be updated to reason code 24.
- # If not confirmed, the MATCH record will be deleted.
- # These provisions enhance fraud monitoring by requiring tracking of coercion-related transaction risks.
+ # Per updated SPME 8.6.6, Mastercard adds Merchants to MATCH using reason code 24 (Illegal Transactions) when Merchants satisfy Coercion Program criteria.
+ # Merchants subject to a new coercion claim within 120 calendar days will be added with reason code 00 (Questionable Acquirer/Under Investigation).
+ # If confirmed to meet Coercion Program criteria, the MATCH record updates to reason code 24; if not, the record is deleted.
+ # The definition of the 120 calendar day review period for coercion investigations is now a continuous 120-day window from the alleged event date without the previous specific 60-day split or discretionary expansion.
#
- # New SPME §11.1.1 further requires acquirers to submit incident reports to Mastercard Fraud Control Programs when violations are not reported by the Acquirer's MMSP, strengthening incident response and reporting cadence.
-
+ # Per SPME 11.1.1, acquirers must submit incident reports to Mastercard Fraud Control Programs when violations go unreported by the Acquirer's MMSP, enhancing reporting rigor.

Fraud Monitoring

Halyard Pay monitors merchant fraud activity and leverages Mastercard's MATCH system for enhanced fraud risk assessment on merchants processed through our platform.

When this policy applies

This policy applies to all merchants processed by Halyard Pay where Mastercard is the applicable network, covering both card-present and card-not-present transactions.

Required actions

  1. Compute the merchant's rolling fraud-to-sales ratio each calendar month.

  2. If the ratio meets or exceeds 1.5% and the fraud count reaches at least 100 transactions in that month, escalate the merchant account to human review immediately.

  3. Utilize Mastercard's MATCH system data focusing on principal owners only, as per the updated Mastercard SPME guidelines. Do not consider associate owners or Service Provider names in fraud assessments.

  4. Maintain awareness of Mastercard's MATCH reason codes related to coercion programs: merchants may be added with reason code 24 for illegal transactions upon meeting coercion criteria, or with code 00 if a subsequent coercion claim arises within 12 months; arises, per Mastercard's investigation timelines; records must be updated or removed based on confirmation of these claims.

  5. After accessing MATCH data, conduct a risk assessment to determine whether further investigation or additional measures are warranted.

  6. Notify the acquiring compliance officer and document the case ID with supporting transaction data.

  7. Track case progress until the account returns to threshold compliance or is terminated.

  8. If any fraud violation is detected but not reported by Halyard Pay as the Acquirer's MMSP, escalate the incident report to Mastercard's Fraud Control Programs in accordance with Mastercard SPME §11 protocols.

Source authority: Mastercard SPME §3.7, §8.6.2, §8.6.6, §11.1.1, and §11.

policies/fraud_monitoring/policy.md — after applying change

Fraud Monitoring

Halyard Pay monitors merchant fraud activity and leverages Mastercard's MATCH system for enhanced fraud risk assessment on merchants processed through our platform.

When this policy applies

This policy applies to all merchants processed by Halyard Pay where Mastercard is the applicable network, covering both card-present and card-not-present transactions.

Required actions

  1. Compute the merchant's rolling fraud-to-sales ratio each calendar month.

  2. If the ratio meets or exceeds 1.5% and the fraud count reaches at least 100 transactions in that month, escalate the merchant account to human review immediately.

  3. Utilize Mastercard's MATCH system data focusing on principal owners only, as per the updated Mastercard SPME guidelines. Do not consider associate owners or Service Provider names in fraud assessments.

  4. Maintain awareness of Mastercard's MATCH reason codes related to coercion programs: merchants may be added with reason code 24 for illegal transactions upon meeting coercion criteria, or with code 00 if a subsequent coercion claim arises within 12 months; arises, per Mastercard's investigation timelines; records must be updated or removed based on confirmation of these claims.

  5. After accessing MATCH data, conduct a risk assessment to determine whether further investigation or additional measures are warranted.

  6. Notify the acquiring compliance officer and document the case ID with supporting transaction data.

  7. Track case progress until the account returns to threshold compliance or is terminated.

  8. If any fraud violation is detected but not reported by Halyard Pay as the Acquirer's MMSP, escalate the incident report to Mastercard's Fraud Control Programs in accordance with Mastercard SPME §11 protocols.

Source authority: Mastercard SPME §3.7, §8.6.2, §8.6.6, §11.1.1, and §11.

Source authority: Mastercard SPME §8.6.2.

--- a/policies/fraud_monitoring/rules.yaml
+++ b/policies/fraud_monitoring/rules.yaml
@@ -1,5 +1,5 @@
 program: Fraud Monitoring
-authority: Mastercard SPME §3.7, §8.6.6, §11.1.1
+authority: Mastercard SPME 2.8.6, 3.7, 11.1.1
 fraud_to_sales_ratio_threshold: 0.015
 min_count_per_month: 100
 monitoring_cadence: monthly
@@ -11,20 +11,18 @@
 remediation_review_interval_days: 30
 agent_owner: fraud_ops_agent
 
-# MATCH fraud detection features are limited to principal owners only; associate owners and Service Provider name reporting are removed per SPME §11.1.1.
-# Acquirers may add and search for information on up to five principal owners per Merchant.
-# Multiple data fields are used to determine matches; MATCH supports editing and error notification to reduce delays.
-# Retroactive alert processing is supported for data up to 360 days old.
+# MATCH fraud detection features focus on principal owners only; associate owners and Service Provider name reporting are excluded per SPME 11.1.1.
+# Acquirers may search information on up to five principal owners per Merchant.
+# Multiple data fields determine matches; MATCH supports editing and error correction to reduce delays.
+# Retroactive alert processing supports data up to 360 days old.
 # Acquirers control receipt and detail of inquiry match information.
-# Real-time access via MATCH Online and API, and batch operations remain available.
+# Real-time access is available via MATCH Online, API, and batch processing.
 # Merchant URL information may be added and searched.
-# After obtaining MATCH inquiry results, acquirers must assess whether further investigation or risk mitigation actions are warranted, per updated SPME requirements.
+# Upon receiving MATCH inquiry results, acquirers must assess the need for further investigation or risk mitigation as updated in SPME.
 #
-# New requirements under SPME §8.6.6 specify that Mastercard will add Merchants to MATCH using reason code 24 (Illegal Transactions) when Merchants meet Coercion Program criteria.
-# Merchants subject to a subsequent claim of coercion within 12 months will be added with reason code 00 (Questionable Acquirer/Under Investigation).
-# If the claim is confirmed to meet Coercion Program criteria, the MATCH record will be updated to reason code 24.
-# If not confirmed, the MATCH record will be deleted.
-# These provisions enhance fraud monitoring by requiring tracking of coercion-related transaction risks.
+# Per updated SPME 8.6.6, Mastercard adds Merchants to MATCH using reason code 24 (Illegal Transactions) when Merchants satisfy Coercion Program criteria.
+# Merchants subject to a new coercion claim within 120 calendar days will be added with reason code 00 (Questionable Acquirer/Under Investigation).
+# If confirmed to meet Coercion Program criteria, the MATCH record updates to reason code 24; if not, the record is deleted.
+# The definition of the 120 calendar day review period for coercion investigations is now a continuous 120-day window from the alleged event date without the previous specific 60-day split or discretionary expansion.
 #
-# New SPME §11.1.1 further requires acquirers to submit incident reports to Mastercard Fraud Control Programs when violations are not reported by the Acquirer's MMSP, strengthening incident response and reporting cadence.
-
+# Per SPME 11.1.1, acquirers must submit incident reports to Mastercard Fraud Control Programs when violations go unreported by the Acquirer's MMSP, enhancing reporting rigor.

--- a/policies/fraud_monitoring/policy.md
+++ b/policies/fraud_monitoring/policy.md
@@ -11,10 +11,10 @@
 1. Compute the merchant's rolling fraud-to-sales ratio each calendar month.
 2. If the ratio meets or exceeds 1.5% and the fraud count reaches at least 100 transactions in that month, escalate the merchant account to human review immediately.
 3. Utilize Mastercard's MATCH system data focusing on principal owners only, as per the updated Mastercard SPME guidelines. Do not consider associate owners or Service Provider names in fraud assessments.
-4. Maintain awareness of Mastercard's MATCH reason codes related to coercion programs: merchants may be added with reason code 24 for illegal transactions upon meeting coercion criteria, or with code 00 if a subsequent coercion claim arises within 12 months; records must be updated or removed based on confirmation of these claims.
+4. Maintain awareness of Mastercard's MATCH reason codes related to coercion programs: merchants may be added with reason code 24 for illegal transactions upon meeting coercion criteria, or with code 00 if a subsequent coercion claim arises, per Mastercard's investigation timelines; records must be updated or removed based on confirmation of these claims.
 5. After accessing MATCH data, conduct a risk assessment to determine whether further investigation or additional measures are warranted.
 6. Notify the acquiring compliance officer and document the case ID with supporting transaction data.
 7. Track case progress until the account returns to threshold compliance or is terminated.
 8. If any fraud violation is detected but not reported by Halyard Pay as the Acquirer's MMSP, escalate the incident report to Mastercard's Fraud Control Programs in accordance with Mastercard SPME §11 protocols.
 
-Source authority: Mastercard SPME §3.7, §8.6.6, §11.1.1, and §11.+Source authority: Mastercard SPME §3.7, §8.6.2, §8.6.6, §11.1.1, and §11.