Mastercard SPME §6.2.2 · Sep 2024 → May 2025

Acquirer Fraud Loss Control Programs

substantive

The compliance date for Europe-region Acquirers' strong authentication was extended to 8 October 2024 (1 April 2025 in Serbia) from 13 October 2023. The requirement was reworded to specify that Merchants or Digital Wallet Operators must complete EMV 3DS authentication or another successful SCA method when adding Stored Credentials, wallets, or tokenized cards, or by the first subsequent transaction.

Sources Mastercard SPME · Sep 2024 · page 60 PDF Mastercard SPME · May 2025 · page 62 PDF ATO Detection current
Why these edits? The extension of the compliance date and the rewording of the Acquirer Authentication Strategy requiring Merchants or Digital Wallet Operators to complete EMV 3DS authentication or another successful SCA method when adding stored credentials or tokenized cards directly affects the Account-Takeover Detection controls outlined in this policy.
Mastercard SPME §6.2.2
An Acquirer must establish, and ensure that each of its Service Providers, ATM owners, and other agents implement, a fraud loss control program that meets the following minimum requirements, and preferably will include the recommended additional parameters. The program must automatically generate daily fraud monitoring reports and real-time or near- real-time alerts. An Acquirer must have the capability to stop the authorization flow related to fraudulent Transactions, in case of major fraud attack, emergency situations or at Mastercard’s request. The Acquirer or its Service Provider must have staff trained to write fraud detection rules and manage fraud cases. Alerts and Daily fraud monitoring reports must be analyzed by trained staff within 24 hours and measures be implemented to mitigate fraud as soon as possible and at the latest within 72 hours following the Transactions time. 6.2.2.1 Acquirer Authentication Strategy Requirements An Acquirer and its Service Providers must comply with the relevant authentication requirements set forth in the Standards, including but not limited to: • Mastercard Identity Check Program Guide • Mastercard Identity Check Compliance Program Guide • Authentication Guide for Europe (applicable to Europe Region Acquirers only) An Acquirer must implement strong authentication controls (ideally two factors) to ensure that only the Acquirer, its Service Providers (for example, any 3-D Secure Service Provider operating a 3-D Secure server, Third Party Processor, or Payment Facilitator) , and its Merchants can initiate Transactions on its platform. Effective 13 8 October 2023, 2024 (1 April 2025 in Serbia), an Acquirer in the Europe Region, excluding Armenia, Azerbaijan, Belarus, Georgia, Kazakhstan, Kyrgyzstan, Moldova, Serbia, Tajikistan, Turkey, Turkmenistan, Ukraine, and Uzbekistan, must comply with the following additional requirement: At the time of storing a Credential on file or in a wallet or Tokenizing a An Acquirer must ensure that while adding a Card as a Stored Credential, Digital Wallet, or similar, including through Tokenization, or at the latest during the first Transaction following Card-add, the Acquirer must ensure that the ¶ Acceptor subsequent Transaction, the Merchant or Digital Wallet Operator must either successfully completes complete (resulting in RReq=Y) an EMV 3-D Secure (3DS ) authentication (i.e., challenge IND = ¶ 04/SCA mandated, and RREQ = Y) or applies with Challenge Indicator=04/SCA mandated or apply another method that results in a successfully completed SCA. If SCA ¶ with Issuer step-up. was successfully Fraud Loss Control Standards
Halyard Pay · 2 files
program: ATO Detection
- authority: Mastercard SPME 10.6.2.1, 10.6.4
+ authority: Mastercard SPME 10.6.2.1, 10.6.4, 6.2.2
risk_threshold_for_3ds_challenge: 0.5
risk_score_range: [0.0, 1.0]
signals:
- geo_anomaly
- device_fingerprint_change
- velocity_breach
- credential_stuffing
challenge_method: 3ds_v2
persistent_risk_escalation_threshold: 3
persistent_risk_lookback_days: 7
agent_owner: ato_agent
 
- # This ATO Detection policy incorporates Mastercard SPME .6.4 updates that affect Account Data Compromise (ADC) event mitigation. It adjusts risk evaluation processes by recognizing that merchants in the U.S. and Canada with high tokenization rates and e-commerce transaction volumes may benefit from reduced or waived reimbursement requirements during such events. This complements detection signal thresholds by informing downstream operational decisions on ADC events, ensuring alignment with Mastercard's revised criteria for operational reimbursement and event assessment.
+ # This ATO Detection policy reflects updates from Mastercard SPME §§6.2.2 and 10.6.4.
+ # It incorporates enhanced authentication requirements for Acquirers and Merchants in the Europe Region to strengthen Stored Credential and Tokenization transaction security.
+ # Effective 8 October 2024 (or 1 April 2025 in Serbia), Merchants and Digital Wallet Operators must satisfy EMV 3DS challenge requirements or complete a strong customer authentication (SCA) alternative when adding or using stored credentials.
+ # These controls support mitigation of account takeover by ensuring robust verification at credential enrollment or first use, aligning detection thresholds and operational responses with Mastercard's evolving fraud prevention standards.

Account-Takeover (ATO) Detection

Account-takeover fraud occurs when a malicious actor gains unauthorized access to a cardholder's account and initiates transactions without the cardholder's consent. Halyard Pay implements enforces real-time risk scoring on authentication events and enforces a mandatory 3DS (3-D Secure) challenge for any session sessions where the computed risk score meets or exceeds the defined threshold.

Detection signals

The risk model incorporates multiple evaluates behavioral signals: indicators such as geographic anomalies inconsistent with a cardholder's established pattern, changes to anomalies, device fingerprint, fingerprint changes, transaction velocity breaches, and indicators velocity, and signs of credential-stuffing activity. attacks.

Required actions

  1. Evaluate each authentication event against the defined signal list using the specified signals in real time.

  2. Compute a normalized risk score between 0.0 and 1.0.

  3. If the risk score is For risk scores of 0.5 or greater, trigger a mandatory require a 3DS challenge before authorizing the transaction. prior to transaction authorization.

  4. Log all ATO signals and outcomes in the case management system.

  5. Escalate persistent high-risk accounts to for manual review by the ATO response team for manual review. team.

  6. In the event of an Upon Account Data Compromise (ADC), ensure that any involved Terminal Servicer (TS) involved promptly initiates a forensic investigation by a PCI Forensic Investigator (PFI) investigation within 72 hours, hours and completes it as soon as practical. practicable.

  7. Confirm that all involved Terminal Servicers revalidate PCI DSS compliance within 90 calendar days after the conclusion of following the forensic investigation and demonstrate compliance with the meet PCI DSS Data Encryption and Software Validation (DESV) appendix requirements within 12 months, per Mastercard SPME §10.6.2.1.

  8. Assure registration of any Register involved Terminal Servicer(s) associated with the ADC Event through Mastercard Connect within 10 calendar days of awareness, and confirm ADC awareness and ensure full cooperation with Mastercard and law enforcement authorities. enforcement.

  9. Verify timely receipt by delivery to Mastercard of unedited forensic examination findings.

  10. Complete all containment measures identified in forensic reports.

11. Ensure Acquirers and Service Providers implement strong authentication controls per Mastercard Identity Check guidelines and regional Authentication Guides.

12. For Acquirers in the Europe Region effective 8 October 2024 (1 April 2025 in Serbia), verify that all required containment actions identified in forensic reports are completed by the Terminal Servicers involved. when storing credentials or tokenizing cards, Merchants or Digital Wallet Operators complete EMV 3-D Secure authentication with Challenge Indicator=04/SCA mandated or an equivalent successful Strong Customer Authentication method, consistent with Mastercard SPME §6.2.2.1.

These enhanced controls reinforce measures maintain Halyard Pay’s adherence to compliance with Mastercard’s strengthened ADC event protocols, supporting minimized risk and financial exposure through compliance and updated fraud control and authentication standards, reducing risk from account-takeover and ensuring timely incident response and remediation.

Source authority: Mastercard SPME §6.2, §6.2.2.1, §10.6.2.1.

policies/ato_detection/policy.md — after applying change

Account-Takeover (ATO) Detection

Account-takeover fraud occurs when a malicious actor gains unauthorized access to a cardholder's account and initiates transactions without the cardholder's consent. Halyard Pay implements enforces real-time risk scoring on authentication events and enforces a mandatory 3DS (3-D Secure) challenge for any session sessions where the computed risk score meets or exceeds the defined threshold.

Detection signals

The risk model incorporates multiple evaluates behavioral signals: indicators such as geographic anomalies inconsistent with a cardholder's established pattern, changes to anomalies, device fingerprint, fingerprint changes, transaction velocity breaches, and indicators velocity, and signs of credential-stuffing activity. attacks.

Required actions

  1. Evaluate each authentication event against the defined signal list using the specified signals in real time.

  2. Compute a normalized risk score between 0.0 and 1.0.

  3. If the risk score is For risk scores of 0.5 or greater, trigger a mandatory require a 3DS challenge before authorizing the transaction. prior to transaction authorization.

  4. Log all ATO signals and outcomes in the case management system.

  5. Escalate persistent high-risk accounts to for manual review by the ATO response team for manual review. team.

  6. In the event of an Upon Account Data Compromise (ADC), ensure that any involved Terminal Servicer (TS) involved promptly initiates a forensic investigation by a PCI Forensic Investigator (PFI) investigation within 72 hours, hours and completes it as soon as practical. practicable.

  7. Confirm that all involved Terminal Servicers revalidate PCI DSS compliance within 90 calendar days after the conclusion of following the forensic investigation and demonstrate compliance with the meet PCI DSS Data Encryption and Software Validation (DESV) appendix requirements within 12 months, per Mastercard SPME §10.6.2.1.

  8. Assure registration of any Register involved Terminal Servicer(s) associated with the ADC Event through Mastercard Connect within 10 calendar days of awareness, and confirm ADC awareness and ensure full cooperation with Mastercard and law enforcement authorities. enforcement.

  9. Verify timely receipt by delivery to Mastercard of unedited forensic examination findings.

  10. Complete all containment measures identified in forensic reports.

11. Ensure Acquirers and Service Providers implement strong authentication controls per Mastercard Identity Check guidelines and regional Authentication Guides.

12. For Acquirers in the Europe Region effective 8 October 2024 (1 April 2025 in Serbia), verify that all required containment actions identified in forensic reports are completed by the Terminal Servicers involved. when storing credentials or tokenizing cards, Merchants or Digital Wallet Operators complete EMV 3-D Secure authentication with Challenge Indicator=04/SCA mandated or an equivalent successful Strong Customer Authentication method, consistent with Mastercard SPME §6.2.2.1.

These enhanced controls reinforce measures maintain Halyard Pay’s adherence to compliance with Mastercard’s strengthened ADC event protocols, supporting minimized risk and financial exposure through compliance and updated fraud control and authentication standards, reducing risk from account-takeover and ensuring timely incident response and remediation.

Source authority: Mastercard SPME §6.2, §6.2.2.1, §10.6.2.1.

Source authority: Mastercard SPME §6.2.2.

--- a/policies/ato_detection/rules.yaml
+++ b/policies/ato_detection/rules.yaml
@@ -1,5 +1,5 @@
 program: ATO Detection
-authority: Mastercard SPME 10.6.2.1, 10.6.4
+authority: Mastercard SPME 10.6.2.1, 10.6.4, 6.2.2
 risk_threshold_for_3ds_challenge: 0.5
 risk_score_range: [0.0, 1.0]
 signals:
@@ -12,4 +12,7 @@
 persistent_risk_lookback_days: 7
 agent_owner: ato_agent
 
-# This ATO Detection policy incorporates Mastercard SPME .6.4 updates that affect Account Data Compromise (ADC) event mitigation. It adjusts risk evaluation processes by recognizing that merchants in the U.S. and Canada with high tokenization rates and e-commerce transaction volumes may benefit from reduced or waived reimbursement requirements during such events. This complements detection signal thresholds by informing downstream operational decisions on ADC events, ensuring alignment with Mastercard's revised criteria for operational reimbursement and event assessment.+# This ATO Detection policy reflects updates from Mastercard SPME §§6.2.2 and 10.6.4.
+# It incorporates enhanced authentication requirements for Acquirers and Merchants in the Europe Region to strengthen Stored Credential and Tokenization transaction security.
+# Effective 8 October 2024 (or 1 April 2025 in Serbia), Merchants and Digital Wallet Operators must satisfy EMV 3DS challenge requirements or complete a strong customer authentication (SCA) alternative when adding or using stored credentials.
+# These controls support mitigation of account takeover by ensuring robust verification at credential enrollment or first use, aligning detection thresholds and operational responses with Mastercard's evolving fraud prevention standards.

--- a/policies/ato_detection/policy.md
+++ b/policies/ato_detection/policy.md
@@ -1,24 +1,26 @@
 # Account-Takeover (ATO) Detection
 
-Account-takeover fraud occurs when a malicious actor gains unauthorized access to a cardholder's account and initiates transactions without the cardholder's consent. Halyard Pay implements real-time risk scoring on authentication events and enforces a mandatory 3DS (3-D Secure) challenge for any session where the computed risk score meets or exceeds the defined threshold.
+Account-takeover fraud occurs when a malicious actor gains unauthorized access to a cardholder's account and initiates transactions without the cardholder's consent. Halyard Pay enforces real-time risk scoring on authentication events and a mandatory 3DS challenge for sessions where the risk score meets or exceeds the defined threshold.
 
 ## Detection signals
 
-The risk model incorporates multiple behavioral signals: geographic anomalies inconsistent with a cardholder's established pattern, changes to device fingerprint, transaction velocity breaches, and indicators of credential-stuffing activity.
+The risk model evaluates behavioral indicators such as geographic anomalies, device fingerprint changes, transaction velocity, and signs of credential-stuffing attacks.
 
 ## Required actions
 
-1. Evaluate each authentication event against the defined signal list in real time.
+1. Evaluate each authentication event using the specified signals in real time.
 2. Compute a normalized risk score between 0.0 and 1.0.
-3. If the risk score is 0.5 or greater, trigger a mandatory 3DS challenge before authorizing the transaction.
+3. For risk scores of 0.5 or greater, require a 3DS challenge prior to transaction authorization.
 4. Log all ATO signals and outcomes in the case management system.
-5. Escalate persistent high-risk accounts to the ATO response team for manual review.
-6. In the event of an Account Data Compromise (ADC), ensure that any Terminal Servicer (TS) involved promptly initiates a forensic investigation by a PCI Forensic Investigator (PFI) within 72 hours, and completes it as soon as practical.
-7. Confirm that all involved Terminal Servicers revalidate PCI DSS compliance within 90 calendar days after the conclusion of the forensic investigation and demonstrate compliance with the PCI DSS Data Encryption and Software Validation (DESV) appendix within 12 months, per Mastercard SPME §10.6.2.1.
-8. Assure registration of any Terminal Servicer(s) associated with the ADC Event through Mastercard Connect within 10 calendar days of awareness, and confirm full cooperation with Mastercard and law enforcement authorities.
-9. Verify timely receipt by Mastercard of unedited forensic examination findings.
-10. Ensure that all required containment actions identified in forensic reports are completed by the Terminal Servicers involved.
+5. Escalate persistent high-risk accounts for manual review by the ATO response team.
+6. Upon Account Data Compromise (ADC), ensure any involved Terminal Servicer initiates a PCI Forensic Investigator (PFI) investigation within 72 hours and completes it as soon as practicable.
+7. Confirm Terminal Servicers revalidate PCI DSS compliance within 90 calendar days following the forensic investigation and meet PCI DSS Data Encryption and Software Validation appendix requirements within 12 months, per Mastercard SPME §10.6.2.1.
+8. Register involved Terminal Servicer(s) through Mastercard Connect within 10 calendar days of ADC awareness and ensure full cooperation with Mastercard and law enforcement.
+9. Verify timely delivery to Mastercard of unedited forensic examination findings.
+10. Complete all containment measures identified in forensic reports.
+11. Ensure Acquirers and Service Providers implement strong authentication controls per Mastercard Identity Check guidelines and regional Authentication Guides.
+12. For Acquirers in the Europe Region effective 8 October 2024 (1 April 2025 in Serbia), verify that when storing credentials or tokenizing cards, Merchants or Digital Wallet Operators complete EMV 3-D Secure authentication with Challenge Indicator=04/SCA mandated or an equivalent successful Strong Customer Authentication method, consistent with Mastercard SPME §6.2.2.1.
 
-These enhanced controls reinforce Halyard Pay’s adherence to Mastercard’s strengthened ADC event protocols, supporting minimized risk and financial exposure through compliance and timely remediation.
+These measures maintain Halyard Pay’s compliance with Mastercard’s updated fraud control and authentication standards, reducing risk from account-takeover and ensuring timely incident response and remediation.
 
-Source authority: Mastercard SPME §6.2, §10.6.2.1.+Source authority: Mastercard SPME §6.2, §6.2.2.1, §10.6.2.1.