Mastercard SPME §11.6.1 · Sep 2024 → May 2025

How does MATCH Pro search when conducting an inquiry?

substantive

The added section details the specific data fields MATCH Pro uses in searches, varying by country, and emphasizes the requirement for using correct ISO codes in queries via API or UI to ensure accurate matching results.

Sources Mastercard SPME · Sep 2024 PDF Mastercard SPME · May 2025 · page 143 PDF Fraud Monitoring current
Also in §11.x this release breaking §11.2.3 "Inquiring about a Merchant" (regarding the use of MATCH Pro) substantive §11 It is the Acquirer's obligation to confirm that the results from MATCH Pro are relevant to the substantive §11.1.1 System Features substantive §11.10 MATCH Pro Record Retention substantive §11.13 MATCH Merchant Removal from MATCH Pro substantive §11.14 MATCH Pro Reason Codes substantive §11.14.1 Reason Codes for MATCH Merchants Listed by an Authorized User substantive §11.3 MATCH Pro Standards substantive §11.4 Acquirer Requirements substantive §11.5 When to Add a Merchant to MATCH Pro substantive §11.5.1 Acquirer Responsibility: Requests for Removal from MATCH Pro substantive §11.6 Inquiring about a MATCH Merchant substantive §11.6.3 Phonetic Possible Matches
Why these edits? The new details about MATCH Pro's search criteria including the requirement for using correct ISO codes for City, State, and Country impact fraud monitoring processes, ensuring accurate identification and matching of fraudulent activity.
Mastercard SPME §11.6.1
This section was substantively restructured between versions (0% text overlap). Compare the texts directly below.
Before · Sep 2024
After · May 2025 · page 143

Security Rules and Procedures—Merchant Edition • 11 February 2025

Field + Field + Field = Match PO National ID2 = x PO Street Address (lines 1 and 2) + PO City + PO State1 = x PO Street Address (lines 1 and 2) + PO City + PO Country2 = x PO Driver's License (DL) Number + DL State1 = x PO Driver's License Number + DL Country2 = x PO Date of Birth + First Name + Last Name = x PO Email Address = x NOTE: MATCH Pro uses Street, City, and State if the MATCH Merchant's country is USA; otherwise, Street, City, and Country are used. NOTE: MATCH Pro uses the International Organization of Standardization (ISO) values for City, State, and State and Country Name. An Authorized User must use the correct ISO values for City, State, and Country Name. For the API, the Authorized User must use the Country API, State API, and City API. For the MATCH Pro UI, the Authorized User must use the predefined drop-down values in the appropriate fields of the MATCH Pro UI.

Halyard Pay · 2 files
program: Fraud Monitoring
- authority: Mastercard SPME 2.8.6, 3.7, 11.1.1
+ authority: Mastercard SPME 2.8.6, 3.7, 11.1.1, 11.6.1
fraud_to_sales_ratio_threshold: 0.015
min_count_per_month: 100
monitoring_cadence: monthly
escalation_actions:
- escalate_to_human_review
- notify_acquirer
- provide_incident_report_to_mastercard_fraud_control_programs # Added to meet new SPME requirements
lookback_period_months: 1
remediation_review_interval_days: 30
agent_owner: fraud_ops_agent
 
# MATCH fraud detection features focus on principal owners only; associate owners and Service Provider name reporting are excluded per SPME 11.1.1.
# Acquirers may search information on up to five principal owners per Merchant.
# Multiple data fields determine matches; MATCH supports editing and error correction to reduce delays.
# Retroactive alert processing supports data up to 360 days old.
# Acquirers control receipt and detail of inquiry match information.
# Real-time access is available via MATCH Online, API, and batch processing.
# Merchant URL information may be added and searched.
# Upon receiving MATCH inquiry results, acquirers must assess the need for further investigation or risk mitigation as updated in SPME.
#
# Per updated SPME 8.6.6, Mastercard adds Merchants to MATCH using reason code 24 (Illegal Transactions) when Merchants satisfy Coercion Program criteria.
# Merchants subject to a new coercion claim within 120 calendar days will be added with reason code 00 (Questionable Acquirer/Under Investigation).
# If confirmed to meet Coercion Program criteria, the MATCH record updates to reason code 24; if not, the record is deleted.
# The definition of the 120 calendar day review period for coercion investigations is now a continuous 120-day window from the alleged event date without the previous specific 60-day split or discretionary expansion.
#
# Per SPME 11.1.1, acquirers must submit incident reports to Mastercard Fraud Control Programs when violations go unreported by the Acquirer's MMSP, enhancing reporting rigor.
+ #
+ # MATCH Pro search criteria per SPME 11.6.1 reflects precise required field combinations and mandates use of ISO standard codes for City, State, and Country fields to ensure consistency and accuracy.
+ # Authorized Users must apply the correct ISO values when using MATCH Pro, including API and UI submissions.
+ # This enhances the precision of fraud monitoring by improving match accuracy and reducing false positives or misses related to location data encoding.
+ # The guidance applies to all principal owner identification processes within MATCH fraud detection.

Fraud Monitoring

Halyard Pay monitors merchant fraud activity and leverages Mastercard's MATCH system for enhanced fraud risk assessment on merchants processed through our platform.

When this policy applies

This policy applies to all merchants processed by Halyard Pay where Mastercard is the applicable network, covering both card-present and card-not-present transactions.

Required actions

  1. Compute the merchant's rolling fraud-to-sales ratio each calendar month.

  2. If the ratio meets or exceeds 1.5% and the fraud count reaches at least 100 transactions in that month, escalate the merchant account to human review immediately.

  3. Utilize Mastercard's MATCH system data focusing on principal owners only, as per the updated Mastercard SPME guidelines. Do not consider associate owners or Service Provider names in fraud assessments.

  4. When querying MATCH Pro, ensure the use of correct ISO standard codes for city, state, and country fields to guarantee precise matching, recognizing that for USA merchants, the combination of street, city, and state is used, while for others, street, city, and country are applied.

5. Maintain awareness of Mastercard's MATCH reason codes related to coercion programs: merchants may be added with reason code 24 for illegal transactions upon meeting coercion criteria, or with code 00 if a subsequent coercion claim arises, per Mastercard's investigation timelines; records must be updated or removed based on confirmation of these claims.

5. 6. After accessing MATCH data, conduct a risk assessment to determine whether further investigation or additional measures are warranted.

6. 7. Notify the acquiring compliance officer and document the case ID with supporting transaction data.

7. 8. Track case progress until the account returns to threshold compliance or is terminated.

8. 9. If any fraud violation is detected but not reported by Halyard Pay as the Acquirer's MMSP, escalate the incident report to Mastercard's Fraud Control Programs in accordance with Mastercard SPME §11 protocols.

Source authority: Mastercard SPME §3.7, §8.6.2, §8.6.6, §11.1.1, and §11.§11, and §11.6.1.

policies/fraud_monitoring/policy.md — after applying change

Fraud Monitoring

Halyard Pay monitors merchant fraud activity and leverages Mastercard's MATCH system for enhanced fraud risk assessment on merchants processed through our platform.

When this policy applies

This policy applies to all merchants processed by Halyard Pay where Mastercard is the applicable network, covering both card-present and card-not-present transactions.

Required actions

  1. Compute the merchant's rolling fraud-to-sales ratio each calendar month.

  2. If the ratio meets or exceeds 1.5% and the fraud count reaches at least 100 transactions in that month, escalate the merchant account to human review immediately.

  3. Utilize Mastercard's MATCH system data focusing on principal owners only, as per the updated Mastercard SPME guidelines. Do not consider associate owners or Service Provider names in fraud assessments.

  4. When querying MATCH Pro, ensure the use of correct ISO standard codes for city, state, and country fields to guarantee precise matching, recognizing that for USA merchants, the combination of street, city, and state is used, while for others, street, city, and country are applied.

5. Maintain awareness of Mastercard's MATCH reason codes related to coercion programs: merchants may be added with reason code 24 for illegal transactions upon meeting coercion criteria, or with code 00 if a subsequent coercion claim arises, per Mastercard's investigation timelines; records must be updated or removed based on confirmation of these claims.

5. 6. After accessing MATCH data, conduct a risk assessment to determine whether further investigation or additional measures are warranted.

6. 7. Notify the acquiring compliance officer and document the case ID with supporting transaction data.

7. 8. Track case progress until the account returns to threshold compliance or is terminated.

8. 9. If any fraud violation is detected but not reported by Halyard Pay as the Acquirer's MMSP, escalate the incident report to Mastercard's Fraud Control Programs in accordance with Mastercard SPME §11 protocols.

Source authority: Mastercard SPME §3.7, §8.6.2, §8.6.6, §11.1.1, and §11.§11, and §11.6.1.

Source authority: Mastercard SPME §11.6.1.

--- a/policies/fraud_monitoring/rules.yaml
+++ b/policies/fraud_monitoring/rules.yaml
@@ -1,5 +1,5 @@
 program: Fraud Monitoring
-authority: Mastercard SPME 2.8.6, 3.7, 11.1.1
+authority: Mastercard SPME 2.8.6, 3.7, 11.1.1, 11.6.1
 fraud_to_sales_ratio_threshold: 0.015
 min_count_per_month: 100
 monitoring_cadence: monthly
@@ -26,3 +26,8 @@
 # The definition of the 120 calendar day review period for coercion investigations is now a continuous 120-day window from the alleged event date without the previous specific 60-day split or discretionary expansion.
 #
 # Per SPME 11.1.1, acquirers must submit incident reports to Mastercard Fraud Control Programs when violations go unreported by the Acquirer's MMSP, enhancing reporting rigor.
+#
+# MATCH Pro search criteria per SPME 11.6.1 reflects precise required field combinations and mandates use of ISO standard codes for City, State, and Country fields to ensure consistency and accuracy.
+# Authorized Users must apply the correct ISO values when using MATCH Pro, including API and UI submissions.
+# This enhances the precision of fraud monitoring by improving match accuracy and reducing false positives or misses related to location data encoding.
+# The guidance applies to all principal owner identification processes within MATCH fraud detection.
--- a/policies/fraud_monitoring/policy.md
+++ b/policies/fraud_monitoring/policy.md
@@ -11,10 +11,11 @@
 1. Compute the merchant's rolling fraud-to-sales ratio each calendar month.
 2. If the ratio meets or exceeds 1.5% and the fraud count reaches at least 100 transactions in that month, escalate the merchant account to human review immediately.
 3. Utilize Mastercard's MATCH system data focusing on principal owners only, as per the updated Mastercard SPME guidelines. Do not consider associate owners or Service Provider names in fraud assessments.
-4. Maintain awareness of Mastercard's MATCH reason codes related to coercion programs: merchants may be added with reason code 24 for illegal transactions upon meeting coercion criteria, or with code 00 if a subsequent coercion claim arises, per Mastercard's investigation timelines; records must be updated or removed based on confirmation of these claims.
-5. After accessing MATCH data, conduct a risk assessment to determine whether further investigation or additional measures are warranted.
-6. Notify the acquiring compliance officer and document the case ID with supporting transaction data.
-7. Track case progress until the account returns to threshold compliance or is terminated.
-8. If any fraud violation is detected but not reported by Halyard Pay as the Acquirer's MMSP, escalate the incident report to Mastercard's Fraud Control Programs in accordance with Mastercard SPME §11 protocols.
+4. When querying MATCH Pro, ensure the use of correct ISO standard codes for city, state, and country fields to guarantee precise matching, recognizing that for USA merchants, the combination of street, city, and state is used, while for others, street, city, and country are applied.
+5. Maintain awareness of Mastercard's MATCH reason codes related to coercion programs: merchants may be added with reason code 24 for illegal transactions upon meeting coercion criteria, or with code 00 if a subsequent coercion claim arises, per Mastercard's investigation timelines; records must be updated or removed based on confirmation of these claims.
+6. After accessing MATCH data, conduct a risk assessment to determine whether further investigation or additional measures are warranted.
+7. Notify the acquiring compliance officer and document the case ID with supporting transaction data.
+8. Track case progress until the account returns to threshold compliance or is terminated.
+9. If any fraud violation is detected but not reported by Halyard Pay as the Acquirer's MMSP, escalate the incident report to Mastercard's Fraud Control Programs in accordance with Mastercard SPME §11 protocols.
 
-Source authority: Mastercard SPME §3.7, §8.6.2, §8.6.6, §11.1.1, and §11.
+Source authority: Mastercard SPME §3.7, §8.6.2, §8.6.6, §11.1.1, §11, and §11.6.1.