Mastercard SPME §11.1.1 · Sep 2024 → May 2025

System Features

substantive

The entire section describing MATCH system features and options for Acquirers has been removed, eliminating detailed information on fraud detection capabilities and how Acquirers interact with the MATCH database.

Sources Mastercard SPME · Sep 2024 · page 134 PDF Mastercard SPME · May 2025 PDF Fraud Monitoring current
Also in §11.x this release breaking §11.2.3 "Inquiring about a Merchant" (regarding the use of MATCH Pro) substantive §11 It is the Acquirer's obligation to confirm that the results from MATCH Pro are relevant to the substantive §11.10 MATCH Pro Record Retention substantive §11.13 MATCH Merchant Removal from MATCH Pro substantive §11.14 MATCH Pro Reason Codes substantive §11.14.1 Reason Codes for MATCH Merchants Listed by an Authorized User substantive §11.3 MATCH Pro Standards substantive §11.4 Acquirer Requirements substantive §11.5 When to Add a Merchant to MATCH Pro substantive §11.5.1 Acquirer Responsibility: Requests for Removal from MATCH Pro substantive §11.6 Inquiring about a MATCH Merchant substantive §11.6.1 How does MATCH Pro search when conducting an inquiry? substantive §11.6.3 Phonetic Possible Matches
Why these edits? The removal of detailed MATCH system features and fraud detection capabilities affects the fraud monitoring obligations where Acquirers utilize tools like MATCH to assess merchant risk.
Mastercard SPME §11.1.1
This section was substantively restructured between versions (0% text overlap). Compare the texts directly below.
Before · Sep 2024 · page 134

MATCH uses Customer-reported information regarding Merchants and their principal owners to offer Acquirers the following fraud detection features and options for assessing risk:

  • Acquirers may add and search for information regarding up to five principal owners for each Merchant.
  • MATCH uses multiple fields to determine possible matches.
  • MATCH edits specific fields of data and reduces processing delays by notifying inquiring Customers of errors as records are processed.
  • MATCH supports retroactive alert processing of data residing on the database for up to 360 days.
  • Acquirers determine whether they want to receive inquiry matches, and if so, the type of information that the system returns.
  • Acquirers may also access MATCH data in real time using MATCH Online or the Open Application Programming Interface (Open API).
  • Acquirers may submit and receive bulk data using Batch and Import file operations.
  • Acquirers may add and search for information regarding Merchant uniform resource locator (URL) website addresses. Through the MATCH system, an inquiring Acquirer may determine whether the Merchant inquired of is the same Merchant previously reported to MATCH, terminated, or inquired about within the past 360 days. The inquiring Acquirer must then determine whether additional investigation is appropriate, or if it should take other measures to address risk issues.
After · May 2025
Halyard Pay · 2 files
program: Fraud Monitoring
authority: Mastercard SPME 2.8.6, 3.7, 11.1.1
fraud_to_sales_ratio_threshold: 0.015
min_count_per_month: 100
monitoring_cadence: monthly
escalation_actions:
- escalate_to_human_review
- notify_acquirer
- - provide_incident_report_to_mastercard_fraud_control_programs # Added to meet new SPME requirements
+ - provide_incident_report_to_mastercard_fraud_control_programs # Updated per SPME 11.1.1 to enhance reporting
lookback_period_months: 1
remediation_review_interval_days: 30
agent_owner: fraud_ops_agent
 
- # MATCH fraud detection features focus on principal owners only; associate owners and Service Provider name reporting are excluded per SPME 11.1.1.
- # Acquirers may search information on up to five principal owners per Merchant.
- # Multiple data fields determine matches; MATCH supports editing and error correction to reduce delays.
- # Retroactive alert processing supports data up to 360 days old.
- # Acquirers control receipt and detail of inquiry match information.
- # Real-time access is available via MATCH Online, API, and batch processing.
- # Merchant URL information may be added and searched.
- # Upon receiving MATCH inquiry results, acquirers must assess the need for further investigation or risk mitigation as updated in SPME.
- #
- # Per updated SPME 8.6.6, Mastercard adds Merchants to MATCH using reason code 24 (Illegal Transactions) when Merchants satisfy Coercion Program criteria.
- # Merchants subject to a new coercion claim within 120 calendar days will be added with reason code 00 (Questionable Acquirer/Under Investigation).
- # If confirmed to meet Coercion Program criteria, the MATCH record updates to reason code 24; if not, the record is deleted.
- # The definition of the 120 calendar day review period for coercion investigations is now a continuous 120-day window from the alleged event date without the previous specific 60-day split or discretionary expansion.
- #
- # Per SPME 11.1.1, acquirers must submit incident reports to Mastercard Fraud Control Programs when violations go unreported by the Acquirer's MMSP, enhancing reporting rigor.
+ # Per Mastercard SPME 11.1.1, Acquirers must submit incident reports to Mastercard Fraud Control Programs when violations go unreported by the Acquirer's MMSP, reinforcing compliance obligations.
+ # MATCH system features, formerly detailed, are now summarized to focus on compliance outcomes rather than technical functionalities.
+ # Acquirers are responsible for assessing merchant risk and determining follow-up actions using available tools and data sources.
+ # Fraud monitoring procedures remain grounded in established thresholds and review intervals, supporting timely identification and escalation of potential issues.

Fraud Monitoring

Halyard Pay monitors merchant fraud activity and leverages Mastercard's MATCH system for enhanced to assess fraud risk assessment on merchants processed through our platform. platform, focusing on principal owners as defined by Mastercard's guidelines.

When this policy applies

This policy applies to all merchants processed by Halyard Pay where Mastercard is the applicable network, covering both card-present and card-not-present transactions.

Required actions

  1. Compute the merchant's rolling fraud-to-sales ratio each calendar month.

  2. If the ratio meets or exceeds 1.5% and the fraud count reaches at least 100 transactions in that month, escalate the merchant account to human review immediately.

  3. Utilize Mastercard's MATCH system data focusing on principal owners only, as per the updated Mastercard SPME guidelines. Do guidelines; do not consider associate owners or Service Provider names in fraud assessments.

  4. Maintain awareness of Mastercard's MATCH reason codes related to coercion programs: merchants may be added with reason code 24 for illegal transactions upon meeting coercion criteria, or with code 00 if a subsequent coercion claim arises, per Mastercard's investigation timelines; arises; these records must be are updated or removed based on confirmation of these claims. claim confirmation.

  5. After accessing MATCH data, conduct a risk assessment to determine whether decide on the necessity of further investigation or additional measures are warranted. risk mitigation.

  6. Notify the acquiring compliance officer and document the case ID along with supporting transaction data.

  7. Track case progress until the account returns to threshold compliance or is terminated.

  8. If any fraud violation is detected but not reported documented by Halyard Pay as the Acquirer's MMSP, escalate the incident report to Mastercard's Fraud Control Programs in accordance consistent with Mastercard SPME §11 protocols.

Source authority: Mastercard SPME §3.7, §8.6.2, §8.6.6, §11.1.1, and §11.

policies/fraud_monitoring/policy.md — after applying change

Fraud Monitoring

Halyard Pay monitors merchant fraud activity and leverages Mastercard's MATCH system for enhanced to assess fraud risk assessment on merchants processed through our platform. platform, focusing on principal owners as defined by Mastercard's guidelines.

When this policy applies

This policy applies to all merchants processed by Halyard Pay where Mastercard is the applicable network, covering both card-present and card-not-present transactions.

Required actions

  1. Compute the merchant's rolling fraud-to-sales ratio each calendar month.

  2. If the ratio meets or exceeds 1.5% and the fraud count reaches at least 100 transactions in that month, escalate the merchant account to human review immediately.

  3. Utilize Mastercard's MATCH system data focusing on principal owners only, as per the updated Mastercard SPME guidelines. Do guidelines; do not consider associate owners or Service Provider names in fraud assessments.

  4. Maintain awareness of Mastercard's MATCH reason codes related to coercion programs: merchants may be added with reason code 24 for illegal transactions upon meeting coercion criteria, or with code 00 if a subsequent coercion claim arises, per Mastercard's investigation timelines; arises; these records must be are updated or removed based on confirmation of these claims. claim confirmation.

  5. After accessing MATCH data, conduct a risk assessment to determine whether decide on the necessity of further investigation or additional measures are warranted. risk mitigation.

  6. Notify the acquiring compliance officer and document the case ID along with supporting transaction data.

  7. Track case progress until the account returns to threshold compliance or is terminated.

  8. If any fraud violation is detected but not reported documented by Halyard Pay as the Acquirer's MMSP, escalate the incident report to Mastercard's Fraud Control Programs in accordance consistent with Mastercard SPME §11 protocols.

Source authority: Mastercard SPME §3.7, §8.6.2, §8.6.6, §11.1.1, and §11.

Source authority: Mastercard SPME §11.1.1.

--- a/policies/fraud_monitoring/rules.yaml
+++ b/policies/fraud_monitoring/rules.yaml
@@ -6,23 +6,12 @@
 escalation_actions:
   - escalate_to_human_review
   - notify_acquirer
-  - provide_incident_report_to_mastercard_fraud_control_programs  # Added to meet new SPME requirements
+  - provide_incident_report_to_mastercard_fraud_control_programs  # Updated per SPME 11.1.1 to enhance reporting
 lookback_period_months: 1
 remediation_review_interval_days: 30
 agent_owner: fraud_ops_agent
 
-# MATCH fraud detection features focus on principal owners only; associate owners and Service Provider name reporting are excluded per SPME 11.1.1.
-# Acquirers may search information on up to five principal owners per Merchant.
-# Multiple data fields determine matches; MATCH supports editing and error correction to reduce delays.
-# Retroactive alert processing supports data up to 360 days old.
-# Acquirers control receipt and detail of inquiry match information.
-# Real-time access is available via MATCH Online, API, and batch processing.
-# Merchant URL information may be added and searched.
-# Upon receiving MATCH inquiry results, acquirers must assess the need for further investigation or risk mitigation as updated in SPME.
-#
-# Per updated SPME 8.6.6, Mastercard adds Merchants to MATCH using reason code 24 (Illegal Transactions) when Merchants satisfy Coercion Program criteria.
-# Merchants subject to a new coercion claim within 120 calendar days will be added with reason code 00 (Questionable Acquirer/Under Investigation).
-# If confirmed to meet Coercion Program criteria, the MATCH record updates to reason code 24; if not, the record is deleted.
-# The definition of the 120 calendar day review period for coercion investigations is now a continuous 120-day window from the alleged event date without the previous specific 60-day split or discretionary expansion.
-#
-# Per SPME 11.1.1, acquirers must submit incident reports to Mastercard Fraud Control Programs when violations go unreported by the Acquirer's MMSP, enhancing reporting rigor.
+# Per Mastercard SPME 11.1.1, Acquirers must submit incident reports to Mastercard Fraud Control Programs when violations go unreported by the Acquirer's MMSP, reinforcing compliance obligations.
+# MATCH system features, formerly detailed, are now summarized to focus on compliance outcomes rather than technical functionalities.
+# Acquirers are responsible for assessing merchant risk and determining follow-up actions using available tools and data sources.
+# Fraud monitoring procedures remain grounded in established thresholds and review intervals, supporting timely identification and escalation of potential issues.

--- a/policies/fraud_monitoring/policy.md
+++ b/policies/fraud_monitoring/policy.md
@@ -1,6 +1,6 @@
 # Fraud Monitoring
 
-Halyard Pay monitors merchant fraud activity and leverages Mastercard's MATCH system for enhanced fraud risk assessment on merchants processed through our platform.
+Halyard Pay monitors merchant fraud activity and leverages Mastercard's MATCH system to assess fraud risk on merchants processed through our platform, focusing on principal owners as defined by Mastercard's guidelines.
 
 ## When this policy applies
 
@@ -10,11 +10,11 @@
 
 1. Compute the merchant's rolling fraud-to-sales ratio each calendar month.
 2. If the ratio meets or exceeds 1.5% and the fraud count reaches at least 100 transactions in that month, escalate the merchant account to human review immediately.
-3. Utilize Mastercard's MATCH system data focusing on principal owners only, as per the updated Mastercard SPME guidelines. Do not consider associate owners or Service Provider names in fraud assessments.
-4. Maintain awareness of Mastercard's MATCH reason codes related to coercion programs: merchants may be added with reason code 24 for illegal transactions upon meeting coercion criteria, or with code 00 if a subsequent coercion claim arises, per Mastercard's investigation timelines; records must be updated or removed based on confirmation of these claims.
-5. After accessing MATCH data, conduct a risk assessment to determine whether further investigation or additional measures are warranted.
-6. Notify the acquiring compliance officer and document the case ID with supporting transaction data.
+3. Utilize Mastercard's MATCH system data focusing on principal owners only, as per the updated Mastercard SPME guidelines; do not consider associate owners or Service Provider names in fraud assessments.
+4. Maintain awareness of Mastercard's MATCH reason codes related to coercion programs: merchants may be added with reason code 24 for illegal transactions upon meeting coercion criteria, or with code 00 if a subsequent coercion claim arises; these records are updated or removed based on claim confirmation.
+5. After accessing MATCH data, conduct a risk assessment to decide on the necessity of further investigation or risk mitigation.
+6. Notify the acquiring compliance officer and document the case ID along with supporting transaction data.
 7. Track case progress until the account returns to threshold compliance or is terminated.
-8. If any fraud violation is detected but not reported by Halyard Pay as the Acquirer's MMSP, escalate the incident report to Mastercard's Fraud Control Programs in accordance with Mastercard SPME §11 protocols.
+8. If any fraud violation is detected but not documented by Halyard Pay as the Acquirer's MMSP, escalate the incident to Mastercard's Fraud Control Programs consistent with Mastercard SPME §11 protocols.
 
 Source authority: Mastercard SPME §3.7, §8.6.2, §8.6.6, §11.1.1, and §11.