Mastercard SPME §11.5 · Sep 2024 → May 2025
When to Add a Merchant to MATCH Pro
The updated section emphasizes that acquirers must conduct MATCH inquiries using the correct ICA Number tied to the processing entity. Failure to add terminated merchants or to use the proper ICA Number for inquiries can lead to compliance violations and Mastercard assessments.
Security Rules and Procedures—Merchant Edition • 6 August 2024
Table 11.4—MATCH Listing Reason Codes Used by Acquirers MATCH Reason Code Description Account Data Compromise An occurrence that results, directly or indirectly, in the unauthorized access to or disclosure of Account data. Common Point of Purchase (CPP) Account data is stolen at the Merchant and then used for fraudulent purchases at other Merchant locations. Laundering The Merchant was engaged in laundering activity. Laundering means that a Merchant presented to its Acquirer Transaction records that were not valid Transactions for sales of goods or services between that Merchant and a bona fide Cardholder. Excessive Chargebacks With respect to a Merchant reported by a Mastercard Acquirer, the number of Mastercard chargebacks in any single month exceeded 1% of the number of Mastercard sales Transactions in that month, and those chargebacks totaled USD 5,000 or more. With respect to a merchant reported by an American Express acquirer (ICA numbers 102 through 125), the merchant exceeded the chargeback thresholds of American Express, as determined by American Express. Excessive Fraud The Merchant effected fraudulent Transactions of any type (counterfeit or otherwise) meeting or exceeding the following minimum reporting Standard: the Merchant’s fraud-to- sales dollar volume ratio was 8% or greater in a calendar month, and the Merchant effected 10 or more fraudulent Transactions totaling USD 5,000 or more in that calendar month. Reserved for Future Use Mastercard Questionable Merchant Audit Program The Merchant was determined to be a Questionable Merchant as per the criteria set forth in the Mastercard Questionable Merchant Audit Program (refer to section 8.4 of this manual). Bankruptcy/Liquidation/Insolvency The Merchant was unable or is likely to become unable to discharge its financial obligations. MATCH System
Security Rules and Procedures—Merchant Edition • 11 February 2025
An Acquirer must conduct inquiries under the proper ICA Number for reporting compliance reasons. If an Acquirer does not conduct the inquiry under the proper ICA Number (that is, the ICA Number that is actually processing for the MATCH Merchant), Mastercard may find the Acquirer in noncompliance and may impose an assessment. Failure to comply with either the requirement of adding a terminated MATCH Merchant or inquiring about a MATCH Merchant may result in noncompliance assessments as described in Table 11.3.
program: Acquirer KYB- authority: Mastercard SPME 2.1, 11.2.3, 11.2.6, 11.7.1, 2.4.1+ authority: Mastercard SPME 2.1, 11.2.3, 11.2.6, 11.7.1, 2.4.1, 11.5required_documents:- incorporation- beneficial_ownership- aml_screen- license_verificationmin_review_cycle_days: 365suspension_trigger: document_collection_failurerecord_retention_years: 7aml_watchlist_sources:- ofac_sdn- eu_consolidatedagent_owner: kyb_agent- # Acquirers must perform a MATCH inquiry prior to entering into any Merchant Agreement or enabling a Merchant to accept transactions, as detailed in Mastercard SPME §11.2.3. This inquiry must be conducted using the correct Member ID/ICA Number associated with the Merchant to ensure proper compliance reporting.+ # Acquirers must perform a MATCH inquiry prior to entering into any Merchant Agreement or enabling a Merchant to accept transactions, as detailed in Mastercard SPME §11.2.3. This inquiry must be conducted using the correct Member ID/ICA Number associated with the Merchant to ensure proper compliance reporting and avoid noncompliance assessments as reinforced in Mastercard SPME §11.5.# Failure to adhere to these requirements may result in noncompliance assessments.# The Acquirer is also required to retain all MATCH records related to any Merchant, Sponsored Merchant, or ATM owner for a minimum of two years post-agreement termination, as per Mastercard SPME §11.2.6.- # Additionally, Acquirers that store, transmit, or process personal data of residents in the European Economic Area (EEA), the UK, or Switzerland—or are otherwise subject to EU Data Protection Law—must comply with the standards specified in Appendix D concerning MATCH activity within the Europe Region, consistent with Mastercard SPME §11.7.1.- # Per the updated Mastercard SPME §2.4.1, Acquirers are required to properly manage their PIN Entry Device (PED) and Encrypting PIN Pad (EPP) inventories. This includes maintaining an up-to-date inventory of device types and locations, ensuring devices receive timely software security patches distributed by vendors, and conducting regular physical inspections by trained staff to detect tampering or substitution.- # Acquirers must also manage devices whose PCI PTS approvals have expired by moving them from approved lists to appropriate expired approval lists and ceasing their use for processing transactions if Mastercard issues a sunset date for specific device models.- # These controls strengthen the security posture of Acquirers in line with Mastercard's risk management directives, helping to prevent device-related compromises.+ # Additionally, Acquirers storing, transmitting, or processing personal data of residents in the European Economic Area (EEA), the UK, or Switzerland—or otherwise subject to EU Data Protection Law—must comply with the standards in Appendix D concerning MATCH activity within Europe, consistent with Mastercard SPME §11.7.1.+ # Per the updated Mastercard SPME §2.4.1, Acquirers must manage PIN Entry Device (PED) and Encrypting PIN Pad (EPP) inventories by maintaining updated device type and location records, ensuring timely software security patches, and conducting physical inspections for tampering or substitution.+ # Devices with expired PCI PTS approvals must be moved from approved to expired approval lists and removed from transaction processing upon Mastercard’s sunset date, enhancing security per Mastercard risk management directives.
Acquirer KYB (Know Your Business) Obligations
Acquirers processing transactions on the Mastercard network must perform Know Your Business (KYB) due diligence on merchants prior to onboarding and on a recurring basis. Halyard Pay is responsible for collecting and verifying required documentation to confirm business legitimacy, vet beneficial ownership, and satisfy anti-money laundering (AML) screening.
When this policy applies
This policy applies at initial merchant onboarding and during periodic re-verification reviews. Merchants that do not provide required documentation within set timelines must be suspended until compliance is restored.
Required actions
-
Collect all KYB documentation needed at onboarding.
-
Conduct AML screening against applicable watchlists before approval.
-
Verify business licenses for regulated merchant categories.
-
Schedule full re-verification at least annually.
-
Document verification outcomes and maintain records for audit.
-
Retain MATCH system records related to Merchants, Sponsored Merchants, or ATM owners for at least two years after contract termination or expiration, to meet Mastercard record retention requirements.
-
BeforePrior to executing the Merchant Agreementexecutionor enabling transactions, conduct a MATCH inquiry using Halyard Pay's Member ID/ICA Numberto ensure compliance; failurethat corresponds to the actual processing entity. Using the incorrect ICA Number may lead to Mastercardassessments.assessments for noncompliance. -
For merchants whose personal data pertains to residents of the European Economic Area, the UK, or Switzerland, Halyard Pay must comply with EU Data Protection Laws as specified in Appendix D of the Mastercard SPME manual concerning MATCH activities in the Europe Region.
-
Maintain proper management of PED and EPP device inventories,
ensuring devices receiveincluding timely application of software securitypatches and are physically tracked and inspected regularly for tampering or substitution. This includes keeping an accurate inventory ofpatches, physical tracking, regular tamper inspections, and adherence to Mastercard sunset dates for devicetypes and locations, and training staff to conduct these inspections. Any device model sunset announcements by Mastercard must be adhered to, including ceasing use of such devices by the specified deadline.models.
Source authority: Mastercard SPME §§2.1, 2.4.1, 7.1, 11.2.3, 11.2.6, 11.5, 11.7.1.
Acquirer KYB (Know Your Business) Obligations
Acquirers processing transactions on the Mastercard network must perform Know Your Business (KYB) due diligence on merchants prior to onboarding and on a recurring basis. Halyard Pay is responsible for collecting and verifying required documentation to confirm business legitimacy, vet beneficial ownership, and satisfy anti-money laundering (AML) screening.
When this policy applies
This policy applies at initial merchant onboarding and during periodic re-verification reviews. Merchants that do not provide required documentation within set timelines must be suspended until compliance is restored.
Required actions
-
Collect all KYB documentation needed at onboarding.
-
Conduct AML screening against applicable watchlists before approval.
-
Verify business licenses for regulated merchant categories.
-
Schedule full re-verification at least annually.
-
Document verification outcomes and maintain records for audit.
-
Retain MATCH system records related to Merchants, Sponsored Merchants, or ATM owners for at least two years after contract termination or expiration, to meet Mastercard record retention requirements.
-
BeforePrior to executing the Merchant Agreementexecutionor enabling transactions, conduct a MATCH inquiry using Halyard Pay's Member ID/ICA Numberto ensure compliance; failurethat corresponds to the actual processing entity. Using the incorrect ICA Number may lead to Mastercardassessments.assessments for noncompliance. -
For merchants whose personal data pertains to residents of the European Economic Area, the UK, or Switzerland, Halyard Pay must comply with EU Data Protection Laws as specified in Appendix D of the Mastercard SPME manual concerning MATCH activities in the Europe Region.
-
Maintain proper management of PED and EPP device inventories,
ensuring devices receiveincluding timely application of software securitypatches and are physically tracked and inspected regularly for tampering or substitution. This includes keeping an accurate inventory ofpatches, physical tracking, regular tamper inspections, and adherence to Mastercard sunset dates for devicetypes and locations, and training staff to conduct these inspections. Any device model sunset announcements by Mastercard must be adhered to, including ceasing use of such devices by the specified deadline.models.
Source authority: Mastercard SPME §§2.1, 2.4.1, 7.1, 11.2.3, 11.2.6, 11.5, 11.7.1.
Source authority: Mastercard SPME §11.5.
--- a/policies/kyb_acquirer/rules.yaml +++ b/policies/kyb_acquirer/rules.yaml @@ -1,5 +1,5 @@ program: Acquirer KYB -authority: Mastercard SPME 2.1, 11.2.3, 11.2.6, 11.7.1, 2.4.1 +authority: Mastercard SPME 2.1, 11.2.3, 11.2.6, 11.7.1, 2.4.1, 11.5 required_documents: - incorporation - beneficial_ownership @@ -12,10 +12,9 @@ - ofac_sdn - eu_consolidated agent_owner: kyb_agent -# Acquirers must perform a MATCH inquiry prior to entering into any Merchant Agreement or enabling a Merchant to accept transactions, as detailed in Mastercard SPME §11.2.3. This inquiry must be conducted using the correct Member ID/ICA Number associated with the Merchant to ensure proper compliance reporting. +# Acquirers must perform a MATCH inquiry prior to entering into any Merchant Agreement or enabling a Merchant to accept transactions, as detailed in Mastercard SPME §11.2.3. This inquiry must be conducted using the correct Member ID/ICA Number associated with the Merchant to ensure proper compliance reporting and avoid noncompliance assessments as reinforced in Mastercard SPME §11.5. # Failure to adhere to these requirements may result in noncompliance assessments. # The Acquirer is also required to retain all MATCH records related to any Merchant, Sponsored Merchant, or ATM owner for a minimum of two years post-agreement termination, as per Mastercard SPME §11.2.6. -# Additionally, Acquirers that store, transmit, or process personal data of residents in the European Economic Area (EEA), the UK, or Switzerland—or are otherwise subject to EU Data Protection Law—must comply with the standards specified in Appendix D concerning MATCH activity within the Europe Region, consistent with Mastercard SPME §11.7.1. -# Per the updated Mastercard SPME §2.4.1, Acquirers are required to properly manage their PIN Entry Device (PED) and Encrypting PIN Pad (EPP) inventories. This includes maintaining an up-to-date inventory of device types and locations, ensuring devices receive timely software security patches distributed by vendors, and conducting regular physical inspections by trained staff to detect tampering or substitution. -# Acquirers must also manage devices whose PCI PTS approvals have expired by moving them from approved lists to appropriate expired approval lists and ceasing their use for processing transactions if Mastercard issues a sunset date for specific device models. -# These controls strengthen the security posture of Acquirers in line with Mastercard's risk management directives, helping to prevent device-related compromises.+# Additionally, Acquirers storing, transmitting, or processing personal data of residents in the European Economic Area (EEA), the UK, or Switzerland—or otherwise subject to EU Data Protection Law—must comply with the standards in Appendix D concerning MATCH activity within Europe, consistent with Mastercard SPME §11.7.1. +# Per the updated Mastercard SPME §2.4.1, Acquirers must manage PIN Entry Device (PED) and Encrypting PIN Pad (EPP) inventories by maintaining updated device type and location records, ensuring timely software security patches, and conducting physical inspections for tampering or substitution. +# Devices with expired PCI PTS approvals must be moved from approved to expired approval lists and removed from transaction processing upon Mastercard’s sunset date, enhancing security per Mastercard risk management directives. --- a/policies/kyb_acquirer/policy.md +++ b/policies/kyb_acquirer/policy.md @@ -14,8 +14,8 @@ 4. Schedule full re-verification at least annually. 5. Document verification outcomes and maintain records for audit. 6. Retain MATCH system records related to Merchants, Sponsored Merchants, or ATM owners for at least two years after contract termination or expiration, to meet Mastercard record retention requirements. -7. Before Merchant Agreement execution or enabling transactions, conduct a MATCH inquiry using Halyard Pay's Member ID/ICA Number to ensure compliance; failure may lead to Mastercard assessments. +7. Prior to executing the Merchant Agreement or enabling transactions, conduct a MATCH inquiry using Halyard Pay's Member ID/ICA Number that corresponds to the actual processing entity. Using the incorrect ICA Number may lead to Mastercard assessments for noncompliance. 8. For merchants whose personal data pertains to residents of the European Economic Area, the UK, or Switzerland, Halyard Pay must comply with EU Data Protection Laws as specified in Appendix D of the Mastercard SPME manual concerning MATCH activities in the Europe Region. -9. Maintain proper management of PED and EPP device inventories, ensuring devices receive timely software security patches and are physically tracked and inspected regularly for tampering or substitution. This includes keeping an accurate inventory of device types and locations, and training staff to conduct these inspections. Any device model sunset announcements by Mastercard must be adhered to, including ceasing use of such devices by the specified deadline. +9. Maintain proper management of PED and EPP device inventories, including timely application of software security patches, physical tracking, regular tamper inspections, and adherence to Mastercard sunset dates for device models. -Source authority: Mastercard SPME §§2.1, 2.4.1, 7.1, 11.2.3, 11.2.6, 11.7.1. +Source authority: Mastercard SPME §§2.1, 2.4.1, 7.1, 11.2.3, 11.2.6, 11.5, 11.7.1.