Mastercard SPME §11.4 · Sep 2024 → May 2025

Acquirer Requirements

substantive

The reference to reasons for removing a merchant listing from MATCH was removed and replaced with a new requirement that a contact profile must include either a shared mailbox email or multiple individual email addresses.

Sources Mastercard SPME · Sep 2024 · page 138 PDF Mastercard SPME · May 2025 · page 140 PDF ECP Thresholds current
Also in §11.x this release breaking §11.2.3 "Inquiring about a Merchant" (regarding the use of MATCH Pro) substantive §11 It is the Acquirer's obligation to confirm that the results from MATCH Pro are relevant to the substantive §11.1.1 System Features substantive §11.10 MATCH Pro Record Retention substantive §11.13 MATCH Merchant Removal from MATCH Pro substantive §11.14 MATCH Pro Reason Codes substantive §11.14.1 Reason Codes for MATCH Merchants Listed by an Authorized User substantive §11.3 MATCH Pro Standards substantive §11.5 When to Add a Merchant to MATCH Pro substantive §11.5.1 Acquirer Responsibility: Requests for Removal from MATCH Pro substantive §11.6 Inquiring about a MATCH Merchant substantive §11.6.1 How does MATCH Pro search when conducting an inquiry? substantive §11.6.3 Phonetic Possible Matches
Why these edits? The section 11.4 update introduces a new requirement that merchant contact profiles include either a shared mailbox email or multiple individual emails, directly affecting how merchant contact information is maintained within the Excessive Chargeback Program (ECP) Thresholds policy.
Mastercard SPME §11.4
This section was substantively restructured between versions (3% text overlap). Compare the texts directly below.
Before · Sep 2024 · page 138

Mastercard may remove a Merchant listing from MATCH for the following reasons: MATCH System

After · May 2025 · page 140

Security Rules and Procedures—Merchant Edition • 11 February 2025

contact profile must include either an email address for a shared mailbox accessed by more than one person, or email addresses for multiple individuals.

Halyard Pay · 2 files
program: ECP
authority: Mastercard SPME 11.4, 11.5, 13.1.2
chargeback_to_transaction_ratio_threshold: 0.015
min_chargeback_count: 100
program_tiers:
- standard
- excessive
tier_thresholds:
standard: 0.015
excessive: 0.030
merchant_notification_business_days: 5
monitoring_cadence: monthly
agent_owner: ecp_ops_agent
 
- # The SPME discontinued the explicit definition of 'Basis Points' in section 8.3.1, which previously described chargeback rate calculations.
- # Despite this removal, the ECP Thresholds policy retains chargeback rate thresholds expressed as ratios rather than basis points,
- # maintaining consistency with Mastercard's monitoring requirements under section 11.4.
- # Program thresholds and tier definitions remain unchanged, preserving the integrity of risk evaluation and compliance.
+ # Updated per Mastercard SPME §11.4 effective 11 February 2025,
+ # requiring merchant contact profiles to include either a shared mailbox
+ # email accessible by multiple persons, or multiple individual email addresses.
+ # This preserves timely and reliable communication for merchants under ECP monitoring.

Excessive Chargeback Program (ECP) Thresholds

Mastercard's Excessive Chargeback Program (ECP) monitors merchants whose chargeback activity exceeds established thresholds relative to monthly transaction volume and chargeback amounts. Halyard Pay tracks these metrics monthly and escalates merchants meeting or surpassing program criteria into risk management processes.

Program tiers

There are two escalation tiers based on chargeback-to-transaction ratios calculated monthly:

  • Standard: Chargeback ratio of at least 1.5% (0.015) with a minimum of 100 chargebacks.

  • Excessive: Chargeback ratio of 3.0% (0.03) or greater.

The chargeback ratio is determined by dividing the number of chargebacks received for a merchant within a month by the total Mastercard transactions for that merchant in the preceding month.

MATCH Listing criteria

Merchants may be reported to the MATCH system under reasons including compliance violations, fraudulent behavior, or illegal activity—not solely for excessive chargebacks. Reporting criteria require chargebacks to exceed 1% of Mastercard sales and a USD 5,000 chargeback amount. Acquirers must assess relevant standards and risk behavior per Mastercard and American Express protocols.

Required actions

  1. Calculate each merchant's monthly chargeback-to-transaction ratio and total chargeback amount.

  2. Assign merchants to the appropriate escalation tier based on ratio thresholds.

  3. Evaluate MATCH reporting needs considering broader compliance or legal issues.

  4. Ensure merchant contact profiles include either a shared mailbox email accessed by multiple personnel or multiple individual contact emails, per Mastercard contact information requirements.

5. Open an ECP case and notify the merchant within five business days.

5. 6. Monitor merchants monthly until program exit.

6. 7. Escalate cases to chargeback agents for automated handling.

Data Protection and Privacy Considerations

Aligned with Mastercard's data protection requirements under EU regulations, Halyard Pay ensures all personal data processing related to ECP complies with enhanced privacy and security protocols, including minimizing access, safeguarding data, complying with transfer restrictions, and cooperating on breach notifications. Halyard Pay and clients function as independent data controllers, maintaining transparency and accountability.

Source authority: Mastercard SPME §§11.4, 11.5, 13.1.2, 11.5.1.

policies/ecp_thresholds/policy.md — after applying change

Excessive Chargeback Program (ECP) Thresholds

Mastercard's Excessive Chargeback Program (ECP) monitors merchants whose chargeback activity exceeds established thresholds relative to monthly transaction volume and chargeback amounts. Halyard Pay tracks these metrics monthly and escalates merchants meeting or surpassing program criteria into risk management processes.

Program tiers

There are two escalation tiers based on chargeback-to-transaction ratios calculated monthly:

  • Standard: Chargeback ratio of at least 1.5% (0.015) with a minimum of 100 chargebacks.

  • Excessive: Chargeback ratio of 3.0% (0.03) or greater.

The chargeback ratio is determined by dividing the number of chargebacks received for a merchant within a month by the total Mastercard transactions for that merchant in the preceding month.

MATCH Listing criteria

Merchants may be reported to the MATCH system under reasons including compliance violations, fraudulent behavior, or illegal activity—not solely for excessive chargebacks. Reporting criteria require chargebacks to exceed 1% of Mastercard sales and a USD 5,000 chargeback amount. Acquirers must assess relevant standards and risk behavior per Mastercard and American Express protocols.

Required actions

  1. Calculate each merchant's monthly chargeback-to-transaction ratio and total chargeback amount.

  2. Assign merchants to the appropriate escalation tier based on ratio thresholds.

  3. Evaluate MATCH reporting needs considering broader compliance or legal issues.

  4. Ensure merchant contact profiles include either a shared mailbox email accessed by multiple personnel or multiple individual contact emails, per Mastercard contact information requirements.

5. Open an ECP case and notify the merchant within five business days.

5. 6. Monitor merchants monthly until program exit.

6. 7. Escalate cases to chargeback agents for automated handling.

Data Protection and Privacy Considerations

Aligned with Mastercard's data protection requirements under EU regulations, Halyard Pay ensures all personal data processing related to ECP complies with enhanced privacy and security protocols, including minimizing access, safeguarding data, complying with transfer restrictions, and cooperating on breach notifications. Halyard Pay and clients function as independent data controllers, maintaining transparency and accountability.

Source authority: Mastercard SPME §§11.4, 11.5, 13.1.2, 11.5.1.

Source authority: Mastercard SPME §11.4.

--- a/policies/ecp_thresholds/rules.yaml
+++ b/policies/ecp_thresholds/rules.yaml
@@ -12,7 +12,7 @@
 monitoring_cadence: monthly
 agent_owner: ecp_ops_agent
 
-# The SPME discontinued the explicit definition of 'Basis Points' in section 8.3.1, which previously described chargeback rate calculations.
-# Despite this removal, the ECP Thresholds policy retains chargeback rate thresholds expressed as ratios rather than basis points,
-# maintaining consistency with Mastercard's monitoring requirements under section 11.4.
-# Program thresholds and tier definitions remain unchanged, preserving the integrity of risk evaluation and compliance.
+# Updated per Mastercard SPME §11.4 effective 11 February 2025,
+# requiring merchant contact profiles to include either a shared mailbox
+# email accessible by multiple persons, or multiple individual email addresses.
+# This preserves timely and reliable communication for merchants under ECP monitoring.

--- a/policies/ecp_thresholds/policy.md
+++ b/policies/ecp_thresholds/policy.md
@@ -19,9 +19,10 @@
 1. Calculate each merchant's monthly chargeback-to-transaction ratio and total chargeback amount.
 2. Assign merchants to the appropriate escalation tier based on ratio thresholds.
 3. Evaluate MATCH reporting needs considering broader compliance or legal issues.
-4. Open an ECP case and notify the merchant within five business days.
-5. Monitor merchants monthly until program exit.
-6. Escalate cases to chargeback agents for automated handling.
+4. Ensure merchant contact profiles include either a shared mailbox email accessed by multiple personnel or multiple individual contact emails, per Mastercard contact information requirements.
+5. Open an ECP case and notify the merchant within five business days.
+6. Monitor merchants monthly until program exit.
+7. Escalate cases to chargeback agents for automated handling.
 
 ## Data Protection and Privacy Considerations