Mastercard SPME §11.13 · Sep 2024 → May 2025

MATCH Merchant Removal from MATCH Pro

substantive

This new section defines specific conditions and procedures under which Mastercard can remove a MATCH Merchant listing from MATCH Pro, including error reports by Authorized Users and removal of listings for PCI DSS noncompliance once the merchant is compliant, requiring a formal written request with detailed information.

Sources Mastercard SPME · Sep 2024 PDF Mastercard SPME · May 2025 · page 146 PDF KYB Acquirer current
Also in §11.x this release breaking §11.2.3 "Inquiring about a Merchant" (regarding the use of MATCH Pro) substantive §11 It is the Acquirer's obligation to confirm that the results from MATCH Pro are relevant to the substantive §11.1.1 System Features substantive §11.10 MATCH Pro Record Retention substantive §11.14 MATCH Pro Reason Codes substantive §11.14.1 Reason Codes for MATCH Merchants Listed by an Authorized User substantive §11.3 MATCH Pro Standards substantive §11.4 Acquirer Requirements substantive §11.5 When to Add a Merchant to MATCH Pro substantive §11.5.1 Acquirer Responsibility: Requests for Removal from MATCH Pro substantive §11.6 Inquiring about a MATCH Merchant substantive §11.6.1 How does MATCH Pro search when conducting an inquiry? substantive §11.6.3 Phonetic Possible Matches
Why these edits? The new Mastercard SPME section 11.13 introduces specific removal procedures for MATCH Merchant listings, including formal written requests by Authorized Users, which affects Acquirer Know Your Business (KYB) obligations requiring accurate merchant validation and listing management.
Mastercard SPME §11.13
This section was substantively restructured between versions (0% text overlap). Compare the texts directly below.
Before · Sep 2024
After · May 2025 · page 146

Mastercard may remove a MATCH Merchant listing from MATCH Pro for the following reasons:

  • The Authorized User reports to Mastercard that the Authorized User added the MATCH Merchant to MATCH Pro in error.
  • The MATCH Merchant listing is for reason code 12 (Payment Card Industry Data Security Standard Noncompliance) and the Authorized User has confirmed that the MATCH Merchant has become compliant with the Payment Card Industry Data Security Standard. The Authorized User must submit the request to remove a MATCH Pro reason code 12 Merchant listing from MATCH Pro in writing on the Authorized User's letterhead to MATCHPro.help@mastercard.com. Such request must include the following information:
  1. Acquirer ID Number
  2. MATCH Merchant ID Number
  3. MATCH Merchant Name
  4. Doing Business As (DBA) Name
  5. Business Address
    1. Street Address
    2. City
    3. State
    4. Country
    5. Postal Code
  6. Principal Owner (PO) Data
    1. PO's First Name and Last Name MATCH Pro System
Halyard Pay · 2 files
program: Acquirer KYB
- authority: Mastercard SPME 2.1, 11.2.3, 11.2.6, 11.7.1, 2.4.1
+ authority: Mastercard SPME 2.1, 11.2.3, 11.2.6, 11.7.1, 2.4.1, 11.13
required_documents:
- incorporation
- beneficial_ownership
- aml_screen
- license_verification
min_review_cycle_days: 365
suspension_trigger: document_collection_failure
record_retention_years: 7
aml_watchlist_sources:
- ofac_sdn
- eu_consolidated
agent_owner: kyb_agent
# Acquirers must perform a MATCH inquiry prior to entering into any Merchant Agreement or enabling a Merchant to accept transactions, as detailed in Mastercard SPME §11.2.3. This inquiry must be conducted using the correct Member ID/ICA Number associated with the Merchant to ensure proper compliance reporting.
# Failure to adhere to these requirements may result in noncompliance assessments.
# The Acquirer is also required to retain all MATCH records related to any Merchant, Sponsored Merchant, or ATM owner for a minimum of two years post-agreement termination, as per Mastercard SPME §11.2.6.
# Additionally, Acquirers that store, transmit, or process personal data of residents in the European Economic Area (EEA), the UK, or Switzerland—or are otherwise subject to EU Data Protection Law—must comply with the standards specified in Appendix D concerning MATCH activity within the Europe Region, consistent with Mastercard SPME §11.7.1.
# Per the updated Mastercard SPME §2.4.1, Acquirers are required to properly manage their PIN Entry Device (PED) and Encrypting PIN Pad (EPP) inventories. This includes maintaining an up-to-date inventory of device types and locations, ensuring devices receive timely software security patches distributed by vendors, and conducting regular physical inspections by trained staff to detect tampering or substitution.
# Acquirers must also manage devices whose PCI PTS approvals have expired by moving them from approved lists to appropriate expired approval lists and ceasing their use for processing transactions if Mastercard issues a sunset date for specific device models.
- # These controls strengthen the security posture of Acquirers in line with Mastercard's risk management directives, helping to prevent device-related compromises.
+ # Furthermore, under Mastercard SPME §11.13, Authorized Users may request removal of MATCH Merchant listings from MATCH Pro for reasons including erroneous listing submissions or confirmed resolution of PCI DSS noncompliance (reason code 12). Such requests must be submitted in writing on the Authorized User's letterhead to MATCHPro.help@mastercard.com and include detailed merchant and principal owner information.
+ # These controls strengthen the security posture of Acquirers in line with Mastercard's risk management directives, helping to prevent device-related compromises and ensure accurate merchant data management.

Acquirer KYB (Know Your Business) Obligations

Acquirers processing transactions on the Mastercard network must perform Know Your Business (KYB) due diligence on merchants prior to onboarding and on a recurring basis. Halyard Pay is responsible for collecting and verifying required documentation to confirm business legitimacy, vet beneficial ownership, and satisfy anti-money laundering (AML) screening.

When this policy applies

This policy applies at initial merchant onboarding and during periodic re-verification reviews. Merchants that do not provide required documentation within set timelines must be suspended until compliance is restored.

Required actions

  1. Collect all KYB documentation needed at onboarding.

  2. Conduct AML screening against applicable watchlists before approval.

  3. Verify business licenses for regulated merchant categories.

  4. Schedule full re-verification at least annually.

  5. Document verification outcomes and maintain records for audit.

  6. Retain MATCH system records related to Merchants, Sponsored Merchants, or ATM owners for at least two years after contract termination or expiration, to meet Mastercard record retention requirements.

  7. Before Merchant Agreement execution or enabling transactions, conduct a MATCH inquiry using Halyard Pay's Member ID/ICA Number to ensure compliance; failure may lead to Mastercard assessments.

  8. For merchants whose personal data pertains to residents of the European Economic Area, the UK, or Switzerland, Halyard Pay must comply with EU Data Protection Laws as specified in Appendix D of the Mastercard SPME manual concerning MATCH activities in the Europe Region.

  9. Maintain proper management of PED and EPP device inventories, ensuring devices receive timely software security patches and are physically tracked and inspected regularly for tampering or substitution. This includes keeping an accurate inventory of device types and locations, and training staff to conduct these inspections. Any device model sunset announcements by Mastercard must be adhered to, including ceasing use of such devices by the specified deadline.

10. To request removal of a MATCH Merchant listing due to resolution of a Payment Card Industry Data Security Standard noncompliance or if the listing was added in error, submit a formal written request on authorized letterhead including Acquirer ID, Merchant ID, merchant and DBA names, full business address, and principal owner details to MATCHPro.help@mastercard.com, per Mastercard SPME §11.13.

Source authority: Mastercard SPME §§2.1, 2.4.1, 7.1, 11.2.3, 11.2.6, 11.7.1.11.7.1, 11.13.

policies/kyb_acquirer/policy.md — after applying change

Acquirer KYB (Know Your Business) Obligations

Acquirers processing transactions on the Mastercard network must perform Know Your Business (KYB) due diligence on merchants prior to onboarding and on a recurring basis. Halyard Pay is responsible for collecting and verifying required documentation to confirm business legitimacy, vet beneficial ownership, and satisfy anti-money laundering (AML) screening.

When this policy applies

This policy applies at initial merchant onboarding and during periodic re-verification reviews. Merchants that do not provide required documentation within set timelines must be suspended until compliance is restored.

Required actions

  1. Collect all KYB documentation needed at onboarding.

  2. Conduct AML screening against applicable watchlists before approval.

  3. Verify business licenses for regulated merchant categories.

  4. Schedule full re-verification at least annually.

  5. Document verification outcomes and maintain records for audit.

  6. Retain MATCH system records related to Merchants, Sponsored Merchants, or ATM owners for at least two years after contract termination or expiration, to meet Mastercard record retention requirements.

  7. Before Merchant Agreement execution or enabling transactions, conduct a MATCH inquiry using Halyard Pay's Member ID/ICA Number to ensure compliance; failure may lead to Mastercard assessments.

  8. For merchants whose personal data pertains to residents of the European Economic Area, the UK, or Switzerland, Halyard Pay must comply with EU Data Protection Laws as specified in Appendix D of the Mastercard SPME manual concerning MATCH activities in the Europe Region.

  9. Maintain proper management of PED and EPP device inventories, ensuring devices receive timely software security patches and are physically tracked and inspected regularly for tampering or substitution. This includes keeping an accurate inventory of device types and locations, and training staff to conduct these inspections. Any device model sunset announcements by Mastercard must be adhered to, including ceasing use of such devices by the specified deadline.

10. To request removal of a MATCH Merchant listing due to resolution of a Payment Card Industry Data Security Standard noncompliance or if the listing was added in error, submit a formal written request on authorized letterhead including Acquirer ID, Merchant ID, merchant and DBA names, full business address, and principal owner details to MATCHPro.help@mastercard.com, per Mastercard SPME §11.13.

Source authority: Mastercard SPME §§2.1, 2.4.1, 7.1, 11.2.3, 11.2.6, 11.7.1.11.7.1, 11.13.

Source authority: Mastercard SPME §11.13.

--- a/policies/kyb_acquirer/rules.yaml
+++ b/policies/kyb_acquirer/rules.yaml
@@ -1,5 +1,5 @@
 program: Acquirer KYB
-authority: Mastercard SPME 2.1, 11.2.3, 11.2.6, 11.7.1, 2.4.1
+authority: Mastercard SPME 2.1, 11.2.3, 11.2.6, 11.7.1, 2.4.1, 11.13
 required_documents:
   - incorporation
   - beneficial_ownership
@@ -18,4 +18,5 @@
 # Additionally, Acquirers that store, transmit, or process personal data of residents in the European Economic Area (EEA), the UK, or Switzerland—or are otherwise subject to EU Data Protection Law—must comply with the standards specified in Appendix D concerning MATCH activity within the Europe Region, consistent with Mastercard SPME §11.7.1.
 # Per the updated Mastercard SPME §2.4.1, Acquirers are required to properly manage their PIN Entry Device (PED) and Encrypting PIN Pad (EPP) inventories. This includes maintaining an up-to-date inventory of device types and locations, ensuring devices receive timely software security patches distributed by vendors, and conducting regular physical inspections by trained staff to detect tampering or substitution.
 # Acquirers must also manage devices whose PCI PTS approvals have expired by moving them from approved lists to appropriate expired approval lists and ceasing their use for processing transactions if Mastercard issues a sunset date for specific device models.
-# These controls strengthen the security posture of Acquirers in line with Mastercard's risk management directives, helping to prevent device-related compromises.+# Furthermore, under Mastercard SPME §11.13, Authorized Users may request removal of MATCH Merchant listings from MATCH Pro for reasons including erroneous listing submissions or confirmed resolution of PCI DSS noncompliance (reason code 12). Such requests must be submitted in writing on the Authorized User's letterhead to MATCHPro.help@mastercard.com and include detailed merchant and principal owner information.
+# These controls strengthen the security posture of Acquirers in line with Mastercard's risk management directives, helping to prevent device-related compromises and ensure accurate merchant data management.

--- a/policies/kyb_acquirer/policy.md
+++ b/policies/kyb_acquirer/policy.md
@@ -17,5 +17,6 @@
 7. Before Merchant Agreement execution or enabling transactions, conduct a MATCH inquiry using Halyard Pay's Member ID/ICA Number to ensure compliance; failure may lead to Mastercard assessments.
 8. For merchants whose personal data pertains to residents of the European Economic Area, the UK, or Switzerland, Halyard Pay must comply with EU Data Protection Laws as specified in Appendix D of the Mastercard SPME manual concerning MATCH activities in the Europe Region.
 9. Maintain proper management of PED and EPP device inventories, ensuring devices receive timely software security patches and are physically tracked and inspected regularly for tampering or substitution. This includes keeping an accurate inventory of device types and locations, and training staff to conduct these inspections. Any device model sunset announcements by Mastercard must be adhered to, including ceasing use of such devices by the specified deadline.
+10. To request removal of a MATCH Merchant listing due to resolution of a Payment Card Industry Data Security Standard noncompliance or if the listing was added in error, submit a formal written request on authorized letterhead including Acquirer ID, Merchant ID, merchant and DBA names, full business address, and principal owner details to MATCHPro.help@mastercard.com, per Mastercard SPME §11.13.
 
-Source authority: Mastercard SPME §§2.1, 2.4.1, 7.1, 11.2.3, 11.2.6, 11.7.1.
+Source authority: Mastercard SPME §§2.1, 2.4.1, 7.1, 11.2.3, 11.2.6, 11.7.1, 11.13.