Mastercard SPME §11.14.1 · Sep 2024 → May 2025
Reason Codes for MATCH Merchants Listed by an Authorized User
New reason codes for MATCH listings were added, including PCI noncompliance, illegal transactions, and identity theft, providing additional clarity on grounds for listing merchants in MATCH.
Security Rules and Procedures—Merchant Edition • 11 February 2025
MATCH Pro Reason Code Description PCI Data Security Standard Noncompliance The MATCH Merchant failed to comply with Payment Card Industry (PCI) Data Security Standard requirements. Illegal Transactions The MATCH Merchant was engaged in illegal Transactions. Identity Theft The Acquirer has reason to believe that the identity of the listed MATCH Merchant or its principal owner(s) was unlawfully assumed for the purpose of unlawfully entering into a Merchant Agreement. Privacy and Data Protection Standards for MATCH Pro This appendix describes the privacy and data protection for MATCH Pro as they relate to the Applicable Data Protection Law. MATCH Pro System Privacy and Data Protection Standards for MATCH Pro Security Rules and Procedures—Merchant Edition • 11 February 2025
Chapter 12 Omitted This chapter has been omitted. Omitted Security Rules and Procedures—Merchant Edition • 11 February 2025
Chapter 13 Franchise Management Program This chapter describes the Franchise Management Program Standards and applies to all Mastercard Customers, Service Providers, and Payment Facilitators.
program: ATO Detection- authority: Mastercard SPME 10.6.2.1, 10.6.4+ authority: Mastercard SPME 10.6.2.1, 10.6.4, 11.14.1risk_threshold_for_3ds_challenge: 0.5risk_score_range: [0.0, 1.0]signals:- geo_anomaly- device_fingerprint_change- velocity_breach- credential_stuffing+ - pci_data_security_noncompliance+ - illegal_transaction+ - identity_theftchallenge_method: 3ds_v2persistent_risk_escalation_threshold: 3persistent_risk_lookback_days: 7agent_owner: ato_agent- # This ATO Detection policy incorporates Mastercard SPME .6.4 updates that affect Account Data Compromise (ADC) event mitigation. It adjusts risk evaluation processes by recognizing that merchants in the U.S. and Canada with high tokenization rates and e-commerce transaction volumes may benefit from reduced or waived reimbursement requirements during such events. This complements detection signal thresholds by informing downstream operational decisions on ADC events, ensuring alignment with Mastercard's revised criteria for operational reimbursement and event assessment.+ # This ATO Detection policy incorporates Mastercard SPME updates from sections 10.6.2.1, 10.6.4, and 11.14.1.+ # The latest section 11.14.1 introduces new MATCH Pro reason codes such as PCI Data Security Standard Noncompliance,+ # Illegal Transactions, and Identity Theft. These expand the scope of detected fraudulent activities and account takeover risks+ # requiring monitoring and action. These additions are integrated into the risk signal list to enhance detection capabilities+ # aligned with Mastercard's updated operational standards and enforcement mechanisms.
Account-Takeover (ATO) Detection
Account-takeover fraud occurs when a malicious actor gains unauthorized access to a cardholder's account and initiates transactions without the cardholder's consent. Halyard Pay implements real-time risk scoring on authentication events and enforces a mandatory 3DS (3-D Secure) challenge for any session where the computed risk score meets or exceeds the defined threshold.
Detection signals
The risk model incorporates multiple behavioral signals: geographic anomalies inconsistent with a cardholder's established pattern, changes to device fingerprint, transaction velocity breaches, and indicators of credential-stuffing activity.
Required actions
-
Evaluate each authentication event against the defined signal list in real time.
-
Compute a normalized risk score between 0.0 and 1.0.
-
If the risk score is 0.5 or greater, trigger a mandatory 3DS challenge before authorizing the transaction.
-
Log all ATO signals and outcomes in the case management system.
-
Escalate persistent high-risk accounts to the ATO response team for manual review.
-
In the event of an Account Data Compromise (ADC), ensure that any Terminal Servicer (TS) involved promptly initiates a forensic investigation by a PCI Forensic Investigator (PFI) within 72 hours, and completes it as soon as practical.
-
Confirm that all involved Terminal Servicers revalidate PCI DSS compliance within 90 calendar days after the forensic investigation's conclusion
of the forensic investigationand demonstrate compliance with the PCI DSS Data Encryption and Software Validation (DESV) appendix within 12 months, per Mastercard SPME §10.6.2.1. -
Assure registration of any Terminal Servicer(s) associated with the ADC
Eventevent through Mastercard Connect within 10 calendar days of awareness, and confirm full cooperation with Mastercard and law enforcement authorities. -
Incorporate monitoring and detection of additional MATCH Pro reason codes for account listings, including PCI DSS noncompliance and identity theft relating to merchant accounts, reinforcing ATO detection capabilities as outlined in Mastercard SPME §11.14.1.
10. Verify timely receipt by Mastercard of unedited forensic examination findings.
10. 11. Ensure that all required containment actions identified in forensic reports are completed by the Terminal Servicers involved.
These enhanced controls reinforce Halyard Pay’s adherence to Mastercard’s strengthened ADC event protocols, protocols and expanded MATCH Pro account-listing reason codes, supporting minimized risk and financial exposure through compliance comprehensive detection and timely remediation.
Source authority: Mastercard SPME §6.2, §10.6.2.1.§10.6.2.1, §11.14.1.
Account-Takeover (ATO) Detection
Account-takeover fraud occurs when a malicious actor gains unauthorized access to a cardholder's account and initiates transactions without the cardholder's consent. Halyard Pay implements real-time risk scoring on authentication events and enforces a mandatory 3DS (3-D Secure) challenge for any session where the computed risk score meets or exceeds the defined threshold.
Detection signals
The risk model incorporates multiple behavioral signals: geographic anomalies inconsistent with a cardholder's established pattern, changes to device fingerprint, transaction velocity breaches, and indicators of credential-stuffing activity.
Required actions
-
Evaluate each authentication event against the defined signal list in real time.
-
Compute a normalized risk score between 0.0 and 1.0.
-
If the risk score is 0.5 or greater, trigger a mandatory 3DS challenge before authorizing the transaction.
-
Log all ATO signals and outcomes in the case management system.
-
Escalate persistent high-risk accounts to the ATO response team for manual review.
-
In the event of an Account Data Compromise (ADC), ensure that any Terminal Servicer (TS) involved promptly initiates a forensic investigation by a PCI Forensic Investigator (PFI) within 72 hours, and completes it as soon as practical.
-
Confirm that all involved Terminal Servicers revalidate PCI DSS compliance within 90 calendar days after the forensic investigation's conclusion
of the forensic investigationand demonstrate compliance with the PCI DSS Data Encryption and Software Validation (DESV) appendix within 12 months, per Mastercard SPME §10.6.2.1. -
Assure registration of any Terminal Servicer(s) associated with the ADC
Eventevent through Mastercard Connect within 10 calendar days of awareness, and confirm full cooperation with Mastercard and law enforcement authorities. -
Incorporate monitoring and detection of additional MATCH Pro reason codes for account listings, including PCI DSS noncompliance and identity theft relating to merchant accounts, reinforcing ATO detection capabilities as outlined in Mastercard SPME §11.14.1.
10. Verify timely receipt by Mastercard of unedited forensic examination findings.
10. 11. Ensure that all required containment actions identified in forensic reports are completed by the Terminal Servicers involved.
These enhanced controls reinforce Halyard Pay’s adherence to Mastercard’s strengthened ADC event protocols, protocols and expanded MATCH Pro account-listing reason codes, supporting minimized risk and financial exposure through compliance comprehensive detection and timely remediation.
Source authority: Mastercard SPME §6.2, §10.6.2.1.§10.6.2.1, §11.14.1.
Source authority: Mastercard SPME §11.14.1.
--- a/policies/ato_detection/rules.yaml +++ b/policies/ato_detection/rules.yaml @@ -1,5 +1,5 @@ program: ATO Detection -authority: Mastercard SPME 10.6.2.1, 10.6.4 +authority: Mastercard SPME 10.6.2.1, 10.6.4, 11.14.1 risk_threshold_for_3ds_challenge: 0.5 risk_score_range: [0.0, 1.0] signals: @@ -7,9 +7,16 @@ - device_fingerprint_change - velocity_breach - credential_stuffing + - pci_data_security_noncompliance + - illegal_transaction + - identity_theft challenge_method: 3ds_v2 persistent_risk_escalation_threshold: 3 persistent_risk_lookback_days: 7 agent_owner: ato_agent -# This ATO Detection policy incorporates Mastercard SPME .6.4 updates that affect Account Data Compromise (ADC) event mitigation. It adjusts risk evaluation processes by recognizing that merchants in the U.S. and Canada with high tokenization rates and e-commerce transaction volumes may benefit from reduced or waived reimbursement requirements during such events. This complements detection signal thresholds by informing downstream operational decisions on ADC events, ensuring alignment with Mastercard's revised criteria for operational reimbursement and event assessment.+# This ATO Detection policy incorporates Mastercard SPME updates from sections 10.6.2.1, 10.6.4, and 11.14.1. +# The latest section 11.14.1 introduces new MATCH Pro reason codes such as PCI Data Security Standard Noncompliance, +# Illegal Transactions, and Identity Theft. These expand the scope of detected fraudulent activities and account takeover risks +# requiring monitoring and action. These additions are integrated into the risk signal list to enhance detection capabilities +# aligned with Mastercard's updated operational standards and enforcement mechanisms. --- a/policies/ato_detection/policy.md +++ b/policies/ato_detection/policy.md @@ -14,11 +14,12 @@ 4. Log all ATO signals and outcomes in the case management system. 5. Escalate persistent high-risk accounts to the ATO response team for manual review. 6. In the event of an Account Data Compromise (ADC), ensure that any Terminal Servicer (TS) involved promptly initiates a forensic investigation by a PCI Forensic Investigator (PFI) within 72 hours, and completes it as soon as practical. -7. Confirm that all involved Terminal Servicers revalidate PCI DSS compliance within 90 calendar days after the conclusion of the forensic investigation and demonstrate compliance with the PCI DSS Data Encryption and Software Validation (DESV) appendix within 12 months, per Mastercard SPME §10.6.2.1. -8. Assure registration of any Terminal Servicer(s) associated with the ADC Event through Mastercard Connect within 10 calendar days of awareness, and confirm full cooperation with Mastercard and law enforcement authorities. -9. Verify timely receipt by Mastercard of unedited forensic examination findings. -10. Ensure that all required containment actions identified in forensic reports are completed by the Terminal Servicers involved. +7. Confirm that all involved Terminal Servicers revalidate PCI DSS compliance within 90 calendar days after the forensic investigation's conclusion and demonstrate compliance with the PCI DSS Data Encryption and Software Validation (DESV) appendix within 12 months, per Mastercard SPME §10.6.2.1. +8. Assure registration of any Terminal Servicer(s) associated with the ADC event through Mastercard Connect within 10 calendar days of awareness, and confirm full cooperation with Mastercard and law enforcement authorities. +9. Incorporate monitoring and detection of additional MATCH Pro reason codes for account listings, including PCI DSS noncompliance and identity theft relating to merchant accounts, reinforcing ATO detection capabilities as outlined in Mastercard SPME §11.14.1. +10. Verify timely receipt by Mastercard of unedited forensic examination findings. +11. Ensure that all required containment actions identified in forensic reports are completed by the Terminal Servicers involved. -These enhanced controls reinforce Halyard Pay’s adherence to Mastercard’s strengthened ADC event protocols, supporting minimized risk and financial exposure through compliance and timely remediation. +These enhanced controls reinforce Halyard Pay’s adherence to Mastercard’s strengthened ADC event protocols and expanded MATCH Pro account-listing reason codes, supporting minimized risk and financial exposure through comprehensive detection and timely remediation. -Source authority: Mastercard SPME §6.2, §10.6.2.1.+Source authority: Mastercard SPME §6.2, §10.6.2.1, §11.14.1.