Mastercard SPME §11.2.3 · Sep 2024 → May 2025

"Inquiring about a Merchant" (regarding the use of MATCH Pro)

breaking

The section was fully replaced, removing the prior process for removing Merchant listings from MATCH due to PCI compliance, and adding new penalties for Acquirers violating BRAM Rules or submitting illegal/brand-damaging Transactions, including significant fines and documentation requirements for approved URLs for Transactions.

Sources Mastercard SPME · Sep 2024 · page 138 PDF Mastercard SPME · May 2025 · page 97 PDF BRAM Response current
Also in §11.x this release substantive §11 It is the Acquirer's obligation to confirm that the results from MATCH Pro are relevant to the substantive §11.1.1 System Features substantive §11.10 MATCH Pro Record Retention substantive §11.13 MATCH Merchant Removal from MATCH Pro substantive §11.14 MATCH Pro Reason Codes substantive §11.14.1 Reason Codes for MATCH Merchants Listed by an Authorized User substantive §11.3 MATCH Pro Standards substantive §11.4 Acquirer Requirements substantive §11.5 When to Add a Merchant to MATCH Pro substantive §11.5.1 Acquirer Responsibility: Requests for Removal from MATCH Pro substantive §11.6 Inquiring about a MATCH Merchant substantive §11.6.1 How does MATCH Pro search when conducting an inquiry? substantive §11.6.3 Phonetic Possible Matches
Why these edits? The new penalties for Acquirers violating BRAM Rules and the requirement to document approved URLs for Transactions expands investigation and compliance response obligations under BRAM.
Mastercard SPME §11.2.3
This section was substantively restructured between versions (1% text overlap). Compare the texts directly below.
Before · Sep 2024 · page 138

Security Rules and Procedures—Merchant Edition • 6 August 2024

  • The Acquirer reports to Mastercard that the Acquirer added the Merchant to MATCH in error.
  • The Merchant listing is for reason code 12 (Payment Card Industry Data Security Standard Noncompliance) and the Acquirer has confirmed that the Merchant has become compliant with the Payment Card Industry Data Security Standard. The Acquirer must submit the request to remove a MATCH reason code 12 Merchant listing from MATCH in writing on the Acquirer’s letterhead to matchbusinessowner@mastercom.com. Such request must include the following information:
  1. Acquirer ID Number
  2. Merchant ID Number
  3. Merchant Name
  4. Doing Business As (DBA) Name
  5. Business Address
    1. Street Address
    2. City
    3. State
    4. Country
    5. Postal Code
  6. Principal Owner (PO) Data
    1. PO’s First Name and Last Name
    2. PO’s Country of Residence Any request relating to a Merchant listed for reason code 12 must contain: – The Acquirer’s attestation that the Merchant is in compliance with the Payment Card Industry Data Security Standard, and – A letter or certificate of validation from a Mastercard certified forensic examiner, certifying that the Merchant has become compliant with the Payment Card Industry Data Security Standard. If an Acquirer is unwilling or unable to submit a request to Mastercard with respect to a Merchant removal from a MATCH listing as a result of the Merchant obtaining compliance with the Payment Card Industry Data Security Standard, the Merchant itself may submit a request to Mastercard for this reason. The Merchant must follow the same process as described above for Acquirers to submit the MATCH removal request.
After · May 2025 · page 97

In addition to or in lieu of any other disciplinary action by the Corporation, an Acquirer deemed to be in violation of the BRAM Rules and/or the Merchant Agreement Rule may be assessed, with respect to each Merchant, entity, affiliate, agent, or person on whose behalf the Acquirer submits illegal or brand-damaging Transactions into interchange:

  • USD 200,000 or
  • USD 2,500 per day, retroactive to the first day of the noncompliant practice, provided the Acquirer can show clear and convincing evidence that such noncompliant practice began less than 80 days prior to the date of the Corporation's notification to the Acquirer. For the avoidance of doubt, an Acquirer must document, as part of the Merchant record, all approved URLs from which the Merchant may submit Transactions for processing through the Interchange System. Mastercard Fraud Control Programs
Halyard Pay · 2 files
program: BRAM
- authority: Mastercard SPME 8.6.2, 10.2, 10.7, 12
+ authority: Mastercard SPME 8.6.2, 10.2, 10.7, 11.2.3, 12
response_window_days: 180
required_evidence:
- transaction_monitoring_records
- corrective_action_plan
- police_report # Mandatory inclusion per updated SPME 8.6.2
halt_actions:
- halt_new_merchant_onboarding
internal_notification_hours: 24
agent_owner: bram_response_agent
 
# Updated to incorporate Mastercard's new appeal process and fee for contesting financial responsibility for ADC Events as detailed in SPME §10.7.
+ # Added financial penalties applicable to Acquirers for violations of BRAM Rules per SPME §11.2.3, including daily and total fines and documentation requirements.
# Clarifies that appeals must be timely, substantiated with particularized basis, and accompanied by a non-refundable fee, impacting procedural guidance for BRAM responses.
# Maintains existing police report requirement and escalation procedures for noncompliance per SPME 8.6.2 and 12.
# Allows for potential additional time granted by Mastercard upon Acquirer's confirmation of cessation of violating activity.
+ # Requires documentation of approved URLs from which Merchants may submit Transactions as part of Merchant record to support compliance review.

BRAM Investigation Response

When Mastercard issues a Business Risk Assessment and Mitigation (BRAM) investigation notice for one of our merchants, the acquirer must halt new merchant onboarding immediately and submit an evidence package within one hundred eighty (180) days of receipt of the notice.

Required actions

  1. Halt new merchant onboarding for the merchant under investigation.

  2. Compile and submit an evidence package containing:

  • Transaction monitoring records covering the prior 180 days.

  • A written corrective action plan.

  • Documentation of any police reports related to alleged coercion claims if applicable.

  1. Notify the Halyard Pay Compliance lead within 24 hours of receipt.

Failure to submit a complete response by the deadline will be considered a violation of Mastercard Rules section 3.9, resulting in escalating Category C noncompliance assessments until compliance is met. Additional assessments may occur for other Standards violations revealed during the BRAM investigation. Mastercard may grant extensions if the acquirer confirms cessation of violating activities.

Additional Considerations for Coercion Claims

When allegations of coerced Transactions arise, note that Mastercard may extend the usual 120-day investigation period at its discretion. At least one claim must include a police report from the Cardholder. Transactions reported as Lost or Stolen Fraud (fraud type codes 00 or 01) are subject to investigation, though Mastercard may consider other fraud codes. Mastercard will notify issuers with Transactions at the merchant within the investigation period to prompt claim submissions.

Mastercard's Authority and Customer Appeal Rights on ADC Financial Responsibility Determinations

Mastercard retains exclusive authority to determine the occurrence, scope, and financial responsibility for Account Data Compromise (ADC) Events or Potential ADC Events, including whether to consolidate related incidents. Once Mastercard notifies a responsible Customer of the financial responsibility amount, the Customer has thirty (30) calendar days to submit a written appeal with supporting documentation, specifically contending that Mastercard's determination was not according to the Standards. Mastercard charges a non-refundable USD 5,000 fee to review such appeals. Appeals that are untimely or do not meet criteria will not be considered, and Mastercard's decisions on appeals are final without further internal review. Customers remain obligated to provide ongoing information throughout the investigation and investigation; failure to submit required documentation in a timely manner may result in on time may exclude such documents being excluded from the appeal consideration. This process safeguards the integrity and finality of Mastercards’ Mastercard’s ADC financial responsibility determinations.

## Penalties for BRAM Non-Compliance and Transaction Source Documentation

In addition to the established requirements, an Acquirer found in violation of BRAM Rules or the Merchant Agreement Rule may face financial penalties including a fine of USD 200,000 or USD 2,500 per day retroactive to the first day of noncompliance, contingent on clear evidence that the violation began less than 80 days prior to notification. Acquirers must also document all approved URLs from which a merchant may submit Transactions to the Interchange System, ensuring traceability and compliance.

Source authority: Mastercard SPME �8.6.2, �10.2, §§3.9, 8.6.2, 10.2, 10.7, 12.0, and section 3.9.11.2.3, 12.0.

policies/bram_response/policy.md — after applying change

BRAM Investigation Response

When Mastercard issues a Business Risk Assessment and Mitigation (BRAM) investigation notice for one of our merchants, the acquirer must halt new merchant onboarding immediately and submit an evidence package within one hundred eighty (180) days of receipt of the notice.

Required actions

  1. Halt new merchant onboarding for the merchant under investigation.

  2. Compile and submit an evidence package containing:

  • Transaction monitoring records covering the prior 180 days.

  • A written corrective action plan.

  • Documentation of any police reports related to alleged coercion claims if applicable.

  1. Notify the Halyard Pay Compliance lead within 24 hours of receipt.

Failure to submit a complete response by the deadline will be considered a violation of Mastercard Rules section 3.9, resulting in escalating Category C noncompliance assessments until compliance is met. Additional assessments may occur for other Standards violations revealed during the BRAM investigation. Mastercard may grant extensions if the acquirer confirms cessation of violating activities.

Additional Considerations for Coercion Claims

When allegations of coerced Transactions arise, note that Mastercard may extend the usual 120-day investigation period at its discretion. At least one claim must include a police report from the Cardholder. Transactions reported as Lost or Stolen Fraud (fraud type codes 00 or 01) are subject to investigation, though Mastercard may consider other fraud codes. Mastercard will notify issuers with Transactions at the merchant within the investigation period to prompt claim submissions.

Mastercard's Authority and Customer Appeal Rights on ADC Financial Responsibility Determinations

Mastercard retains exclusive authority to determine the occurrence, scope, and financial responsibility for Account Data Compromise (ADC) Events or Potential ADC Events, including whether to consolidate related incidents. Once Mastercard notifies a responsible Customer of the financial responsibility amount, the Customer has thirty (30) calendar days to submit a written appeal with supporting documentation, specifically contending that Mastercard's determination was not according to the Standards. Mastercard charges a non-refundable USD 5,000 fee to review such appeals. Appeals that are untimely or do not meet criteria will not be considered, and Mastercard's decisions on appeals are final without further internal review. Customers remain obligated to provide ongoing information throughout the investigation and investigation; failure to submit required documentation in a timely manner may result in on time may exclude such documents being excluded from the appeal consideration. This process safeguards the integrity and finality of Mastercards’ Mastercard’s ADC financial responsibility determinations.

## Penalties for BRAM Non-Compliance and Transaction Source Documentation

In addition to the established requirements, an Acquirer found in violation of BRAM Rules or the Merchant Agreement Rule may face financial penalties including a fine of USD 200,000 or USD 2,500 per day retroactive to the first day of noncompliance, contingent on clear evidence that the violation began less than 80 days prior to notification. Acquirers must also document all approved URLs from which a merchant may submit Transactions to the Interchange System, ensuring traceability and compliance.

Source authority: Mastercard SPME �8.6.2, �10.2, §§3.9, 8.6.2, 10.2, 10.7, 12.0, and section 3.9.11.2.3, 12.0.

Source authority: Mastercard SPME §11.2.3.

--- a/policies/bram_response/rules.yaml
+++ b/policies/bram_response/rules.yaml
@@ -1,5 +1,5 @@
 program: BRAM
-authority: Mastercard SPME 8.6.2, 10.2, 10.7, 12
+authority: Mastercard SPME 8.6.2, 10.2, 10.7, 11.2.3, 12
 response_window_days: 180
 required_evidence:
   - transaction_monitoring_records
@@ -11,6 +11,8 @@
 agent_owner: bram_response_agent
 
 # Updated to incorporate Mastercard's new appeal process and fee for contesting financial responsibility for ADC Events as detailed in SPME §10.7.
+# Added financial penalties applicable to Acquirers for violations of BRAM Rules per SPME §11.2.3, including daily and total fines and documentation requirements.
 # Clarifies that appeals must be timely, substantiated with particularized basis, and accompanied by a non-refundable fee, impacting procedural guidance for BRAM responses.
 # Maintains existing police report requirement and escalation procedures for noncompliance per SPME 8.6.2 and 12.
 # Allows for potential additional time granted by Mastercard upon Acquirer's confirmation of cessation of violating activity.
+# Requires documentation of approved URLs from which Merchants may submit Transactions as part of Merchant record to support compliance review.
--- a/policies/bram_response/policy.md
+++ b/policies/bram_response/policy.md
@@ -1,9 +1,6 @@
 # BRAM Investigation Response
 
-When Mastercard issues a Business Risk Assessment and Mitigation (BRAM) investigation
-notice for one of our merchants, the acquirer must halt new merchant onboarding
-immediately and submit an evidence package within one hundred eighty (180) days
-of receipt of the notice.
+When Mastercard issues a Business Risk Assessment and Mitigation (BRAM) investigation notice for one of our merchants, the acquirer must halt new merchant onboarding immediately and submit an evidence package within one hundred eighty (180) days of receipt of the notice.
 
 ## Required actions
 
@@ -18,14 +15,14 @@
 
 ## Additional Considerations for Coercion Claims
 
-When allegations of coerced Transactions arise, note that Mastercard may extend the usual 120-day
-investigation period at its discretion. At least one claim must include a police report from the Cardholder.
-Transactions reported as Lost or Stolen Fraud (fraud type codes 00 or 01) are subject to investigation,
-though Mastercard may consider other fraud codes. Mastercard will notify issuers with Transactions at the
-merchant within the investigation period to prompt claim submissions.
+When allegations of coerced Transactions arise, note that Mastercard may extend the usual 120-day investigation period at its discretion. At least one claim must include a police report from the Cardholder. Transactions reported as Lost or Stolen Fraud (fraud type codes 00 or 01) are subject to investigation, though Mastercard may consider other fraud codes. Mastercard will notify issuers with Transactions at the merchant within the investigation period to prompt claim submissions.
 
 ## Mastercard's Authority and Customer Appeal Rights on ADC Financial Responsibility Determinations
 
-Mastercard retains exclusive authority to determine the occurrence, scope, and financial responsibility for Account Data Compromise (ADC) Events or Potential ADC Events, including whether to consolidate related incidents. Once Mastercard notifies a responsible Customer of the financial responsibility amount, the Customer has thirty (30) calendar days to submit a written appeal with supporting documentation, specifically contending that Mastercard's determination was not according to the Standards. Mastercard charges a non-refundable USD 5,000 fee to review such appeals. Appeals that are untimely or do not meet criteria will not be considered, and Mastercard's decisions on appeals are final without further internal review. Customers remain obligated to provide ongoing information throughout the investigation and failure to submit required documentation in a timely manner may result in such documents being excluded from the appeal consideration. This process safeguards the integrity and finality of Mastercards’ ADC financial responsibility determinations.
+Mastercard retains exclusive authority to determine the occurrence, scope, and financial responsibility for Account Data Compromise (ADC) Events or Potential ADC Events, including whether to consolidate related incidents. Once Mastercard notifies a responsible Customer of the financial responsibility amount, the Customer has thirty (30) calendar days to submit a written appeal with supporting documentation, specifically contending that Mastercard's determination was not according to the Standards. Mastercard charges a non-refundable USD 5,000 fee to review such appeals. Appeals that are untimely or do not meet criteria will not be considered, and Mastercard's decisions on appeals are final without further internal review. Customers remain obligated to provide ongoing information throughout the investigation; failure to submit required documentation on time may exclude such documents from appeal consideration. This process safeguards the integrity and finality of Mastercard’s ADC financial responsibility determinations.
 
-Source authority: Mastercard SPME 8.6.2, 10.2, 10.7, 12.0, and section 3.9.+## Penalties for BRAM Non-Compliance and Transaction Source Documentation
+
+In addition to the established requirements, an Acquirer found in violation of BRAM Rules or the Merchant Agreement Rule may face financial penalties including a fine of USD 200,000 or USD 2,500 per day retroactive to the first day of noncompliance, contingent on clear evidence that the violation began less than 80 days prior to notification. Acquirers must also document all approved URLs from which a merchant may submit Transactions to the Interchange System, ensuring traceability and compliance.
+
+Source authority: Mastercard SPME §§3.9, 8.6.2, 10.2, 10.7, 11.2.3, 12.0.