Mastercard SPME §11.2.3 · Sep 2024 → May 2025
"Inquiring about a Merchant" (regarding the use of MATCH Pro)
The section was fully replaced, removing the prior process for removing Merchant listings from MATCH due to PCI compliance, and adding new penalties for Acquirers violating BRAM Rules or submitting illegal/brand-damaging Transactions, including significant fines and documentation requirements for approved URLs for Transactions.
Security Rules and Procedures—Merchant Edition • 6 August 2024
- The Acquirer reports to Mastercard that the Acquirer added the Merchant to MATCH in error.
- The Merchant listing is for reason code 12 (Payment Card Industry Data Security Standard Noncompliance) and the Acquirer has confirmed that the Merchant has become compliant with the Payment Card Industry Data Security Standard. The Acquirer must submit the request to remove a MATCH reason code 12 Merchant listing from MATCH in writing on the Acquirer’s letterhead to matchbusinessowner@mastercom.com. Such request must include the following information:
- Acquirer ID Number
- Merchant ID Number
- Merchant Name
- Doing Business As (DBA) Name
- Business Address
- Street Address
- City
- State
- Country
- Postal Code
- Principal Owner (PO) Data
- PO’s First Name and Last Name
- PO’s Country of Residence Any request relating to a Merchant listed for reason code 12 must contain: – The Acquirer’s attestation that the Merchant is in compliance with the Payment Card Industry Data Security Standard, and – A letter or certificate of validation from a Mastercard certified forensic examiner, certifying that the Merchant has become compliant with the Payment Card Industry Data Security Standard. If an Acquirer is unwilling or unable to submit a request to Mastercard with respect to a Merchant removal from a MATCH listing as a result of the Merchant obtaining compliance with the Payment Card Industry Data Security Standard, the Merchant itself may submit a request to Mastercard for this reason. The Merchant must follow the same process as described above for Acquirers to submit the MATCH removal request.
In addition to or in lieu of any other disciplinary action by the Corporation, an Acquirer deemed to be in violation of the BRAM Rules and/or the Merchant Agreement Rule may be assessed, with respect to each Merchant, entity, affiliate, agent, or person on whose behalf the Acquirer submits illegal or brand-damaging Transactions into interchange:
- USD 200,000 or
- USD 2,500 per day, retroactive to the first day of the noncompliant practice, provided the Acquirer can show clear and convincing evidence that such noncompliant practice began less than 80 days prior to the date of the Corporation's notification to the Acquirer. For the avoidance of doubt, an Acquirer must document, as part of the Merchant record, all approved URLs from which the Merchant may submit Transactions for processing through the Interchange System. Mastercard Fraud Control Programs
program: BRAM- authority: Mastercard SPME 8.6.2, 10.2, 10.7, 12+ authority: Mastercard SPME 8.6.2, 10.2, 10.7, 11.2.3, 12response_window_days: 180required_evidence:- transaction_monitoring_records- corrective_action_plan- police_report # Mandatory inclusion per updated SPME 8.6.2halt_actions:- halt_new_merchant_onboardinginternal_notification_hours: 24agent_owner: bram_response_agent# Updated to incorporate Mastercard's new appeal process and fee for contesting financial responsibility for ADC Events as detailed in SPME §10.7.+ # Added financial penalties applicable to Acquirers for violations of BRAM Rules per SPME §11.2.3, including daily and total fines and documentation requirements.# Clarifies that appeals must be timely, substantiated with particularized basis, and accompanied by a non-refundable fee, impacting procedural guidance for BRAM responses.# Maintains existing police report requirement and escalation procedures for noncompliance per SPME 8.6.2 and 12.# Allows for potential additional time granted by Mastercard upon Acquirer's confirmation of cessation of violating activity.+ # Requires documentation of approved URLs from which Merchants may submit Transactions as part of Merchant record to support compliance review.
BRAM Investigation Response
When Mastercard issues a Business Risk Assessment and Mitigation (BRAM) investigation ¶ notice for one of our merchants, the acquirer must halt new merchant onboarding ¶ immediately and submit an evidence package within one hundred eighty (180) days ¶ of receipt of the notice.
Required actions
-
Halt new merchant onboarding for the merchant under investigation.
-
Compile and submit an evidence package containing:
-
Transaction monitoring records covering the prior 180 days.
-
A written corrective action plan.
-
Documentation of any police reports related to alleged coercion claims if applicable.
- Notify the Halyard Pay Compliance lead within 24 hours of receipt.
Failure to submit a complete response by the deadline will be considered a violation of Mastercard Rules section 3.9, resulting in escalating Category C noncompliance assessments until compliance is met. Additional assessments may occur for other Standards violations revealed during the BRAM investigation. Mastercard may grant extensions if the acquirer confirms cessation of violating activities.
Additional Considerations for Coercion Claims
When allegations of coerced Transactions arise, note that Mastercard may extend the usual 120-day ¶ investigation period at its discretion. At least one claim must include a police report from the Cardholder. ¶ Transactions reported as Lost or Stolen Fraud (fraud type codes 00 or 01) are subject to investigation, ¶ though Mastercard may consider other fraud codes. Mastercard will notify issuers with Transactions at the ¶ merchant within the investigation period to prompt claim submissions.
Mastercard's Authority and Customer Appeal Rights on ADC Financial Responsibility Determinations
Mastercard retains exclusive authority to determine the occurrence, scope, and financial responsibility for Account Data Compromise (ADC) Events or Potential ADC Events, including whether to consolidate related incidents. Once Mastercard notifies a responsible Customer of the financial responsibility amount, the Customer has thirty (30) calendar days to submit a written appeal with supporting documentation, specifically contending that Mastercard's determination was not according to the Standards. Mastercard charges a non-refundable USD 5,000 fee to review such appeals. Appeals that are untimely or do not meet criteria will not be considered, and Mastercard's decisions on appeals are final without further internal review. Customers remain obligated to provide ongoing information throughout the investigation and investigation; failure to submit required documentation in a timely manner may result in on time may exclude such documents being excluded from the appeal consideration. This process safeguards the integrity and finality of Mastercards’ Mastercard’s ADC financial responsibility determinations.
## Penalties for BRAM Non-Compliance and Transaction Source Documentation
In addition to the established requirements, an Acquirer found in violation of BRAM Rules or the Merchant Agreement Rule may face financial penalties including a fine of USD 200,000 or USD 2,500 per day retroactive to the first day of noncompliance, contingent on clear evidence that the violation began less than 80 days prior to notification. Acquirers must also document all approved URLs from which a merchant may submit Transactions to the Interchange System, ensuring traceability and compliance.
Source authority: Mastercard SPME �8.6.2, �10.2, §§3.9, 8.6.2, 10.2, 10.7, 12.0, and section 3.9.11.2.3, 12.0.
BRAM Investigation Response
When Mastercard issues a Business Risk Assessment and Mitigation (BRAM) investigation ¶ notice for one of our merchants, the acquirer must halt new merchant onboarding ¶ immediately and submit an evidence package within one hundred eighty (180) days ¶ of receipt of the notice.
Required actions
-
Halt new merchant onboarding for the merchant under investigation.
-
Compile and submit an evidence package containing:
-
Transaction monitoring records covering the prior 180 days.
-
A written corrective action plan.
-
Documentation of any police reports related to alleged coercion claims if applicable.
- Notify the Halyard Pay Compliance lead within 24 hours of receipt.
Failure to submit a complete response by the deadline will be considered a violation of Mastercard Rules section 3.9, resulting in escalating Category C noncompliance assessments until compliance is met. Additional assessments may occur for other Standards violations revealed during the BRAM investigation. Mastercard may grant extensions if the acquirer confirms cessation of violating activities.
Additional Considerations for Coercion Claims
When allegations of coerced Transactions arise, note that Mastercard may extend the usual 120-day ¶ investigation period at its discretion. At least one claim must include a police report from the Cardholder. ¶ Transactions reported as Lost or Stolen Fraud (fraud type codes 00 or 01) are subject to investigation, ¶ though Mastercard may consider other fraud codes. Mastercard will notify issuers with Transactions at the ¶ merchant within the investigation period to prompt claim submissions.
Mastercard's Authority and Customer Appeal Rights on ADC Financial Responsibility Determinations
Mastercard retains exclusive authority to determine the occurrence, scope, and financial responsibility for Account Data Compromise (ADC) Events or Potential ADC Events, including whether to consolidate related incidents. Once Mastercard notifies a responsible Customer of the financial responsibility amount, the Customer has thirty (30) calendar days to submit a written appeal with supporting documentation, specifically contending that Mastercard's determination was not according to the Standards. Mastercard charges a non-refundable USD 5,000 fee to review such appeals. Appeals that are untimely or do not meet criteria will not be considered, and Mastercard's decisions on appeals are final without further internal review. Customers remain obligated to provide ongoing information throughout the investigation and investigation; failure to submit required documentation in a timely manner may result in on time may exclude such documents being excluded from the appeal consideration. This process safeguards the integrity and finality of Mastercards’ Mastercard’s ADC financial responsibility determinations.
## Penalties for BRAM Non-Compliance and Transaction Source Documentation
In addition to the established requirements, an Acquirer found in violation of BRAM Rules or the Merchant Agreement Rule may face financial penalties including a fine of USD 200,000 or USD 2,500 per day retroactive to the first day of noncompliance, contingent on clear evidence that the violation began less than 80 days prior to notification. Acquirers must also document all approved URLs from which a merchant may submit Transactions to the Interchange System, ensuring traceability and compliance.
Source authority: Mastercard SPME �8.6.2, �10.2, §§3.9, 8.6.2, 10.2, 10.7, 12.0, and section 3.9.11.2.3, 12.0.
Source authority: Mastercard SPME §11.2.3.
--- a/policies/bram_response/rules.yaml +++ b/policies/bram_response/rules.yaml @@ -1,5 +1,5 @@ program: BRAM -authority: Mastercard SPME 8.6.2, 10.2, 10.7, 12 +authority: Mastercard SPME 8.6.2, 10.2, 10.7, 11.2.3, 12 response_window_days: 180 required_evidence: - transaction_monitoring_records @@ -11,6 +11,8 @@ agent_owner: bram_response_agent # Updated to incorporate Mastercard's new appeal process and fee for contesting financial responsibility for ADC Events as detailed in SPME §10.7. +# Added financial penalties applicable to Acquirers for violations of BRAM Rules per SPME §11.2.3, including daily and total fines and documentation requirements. # Clarifies that appeals must be timely, substantiated with particularized basis, and accompanied by a non-refundable fee, impacting procedural guidance for BRAM responses. # Maintains existing police report requirement and escalation procedures for noncompliance per SPME 8.6.2 and 12. # Allows for potential additional time granted by Mastercard upon Acquirer's confirmation of cessation of violating activity. +# Requires documentation of approved URLs from which Merchants may submit Transactions as part of Merchant record to support compliance review. --- a/policies/bram_response/policy.md +++ b/policies/bram_response/policy.md @@ -1,9 +1,6 @@ # BRAM Investigation Response -When Mastercard issues a Business Risk Assessment and Mitigation (BRAM) investigation -notice for one of our merchants, the acquirer must halt new merchant onboarding -immediately and submit an evidence package within one hundred eighty (180) days -of receipt of the notice. +When Mastercard issues a Business Risk Assessment and Mitigation (BRAM) investigation notice for one of our merchants, the acquirer must halt new merchant onboarding immediately and submit an evidence package within one hundred eighty (180) days of receipt of the notice. ## Required actions @@ -18,14 +15,14 @@ ## Additional Considerations for Coercion Claims -When allegations of coerced Transactions arise, note that Mastercard may extend the usual 120-day -investigation period at its discretion. At least one claim must include a police report from the Cardholder. -Transactions reported as Lost or Stolen Fraud (fraud type codes 00 or 01) are subject to investigation, -though Mastercard may consider other fraud codes. Mastercard will notify issuers with Transactions at the -merchant within the investigation period to prompt claim submissions. +When allegations of coerced Transactions arise, note that Mastercard may extend the usual 120-day investigation period at its discretion. At least one claim must include a police report from the Cardholder. Transactions reported as Lost or Stolen Fraud (fraud type codes 00 or 01) are subject to investigation, though Mastercard may consider other fraud codes. Mastercard will notify issuers with Transactions at the merchant within the investigation period to prompt claim submissions. ## Mastercard's Authority and Customer Appeal Rights on ADC Financial Responsibility Determinations -Mastercard retains exclusive authority to determine the occurrence, scope, and financial responsibility for Account Data Compromise (ADC) Events or Potential ADC Events, including whether to consolidate related incidents. Once Mastercard notifies a responsible Customer of the financial responsibility amount, the Customer has thirty (30) calendar days to submit a written appeal with supporting documentation, specifically contending that Mastercard's determination was not according to the Standards. Mastercard charges a non-refundable USD 5,000 fee to review such appeals. Appeals that are untimely or do not meet criteria will not be considered, and Mastercard's decisions on appeals are final without further internal review. Customers remain obligated to provide ongoing information throughout the investigation and failure to submit required documentation in a timely manner may result in such documents being excluded from the appeal consideration. This process safeguards the integrity and finality of Mastercards’ ADC financial responsibility determinations. +Mastercard retains exclusive authority to determine the occurrence, scope, and financial responsibility for Account Data Compromise (ADC) Events or Potential ADC Events, including whether to consolidate related incidents. Once Mastercard notifies a responsible Customer of the financial responsibility amount, the Customer has thirty (30) calendar days to submit a written appeal with supporting documentation, specifically contending that Mastercard's determination was not according to the Standards. Mastercard charges a non-refundable USD 5,000 fee to review such appeals. Appeals that are untimely or do not meet criteria will not be considered, and Mastercard's decisions on appeals are final without further internal review. Customers remain obligated to provide ongoing information throughout the investigation; failure to submit required documentation on time may exclude such documents from appeal consideration. This process safeguards the integrity and finality of Mastercard’s ADC financial responsibility determinations. -Source authority: Mastercard SPME 8.6.2, 10.2, 10.7, 12.0, and section 3.9.+## Penalties for BRAM Non-Compliance and Transaction Source Documentation + +In addition to the established requirements, an Acquirer found in violation of BRAM Rules or the Merchant Agreement Rule may face financial penalties including a fine of USD 200,000 or USD 2,500 per day retroactive to the first day of noncompliance, contingent on clear evidence that the violation began less than 80 days prior to notification. Acquirers must also document all approved URLs from which a merchant may submit Transactions to the Interchange System, ensuring traceability and compliance. + +Source authority: Mastercard SPME §§3.9, 8.6.2, 10.2, 10.7, 11.2.3, 12.0.