Mastercard SPME §7.1 · Sep 2024 → May 2025
Screening New Merchants, Sponsored Merchants, and ATM Owners
The requirement now specifies participation in the MATCH Pro system instead of the MATCH system, and it adds a clear rule that if a Merchant or Sponsored Merchant is terminated for listed reasons, the Acquirer must add them to MATCH Pro.
program: Acquirer KYB- authority: Mastercard SPME 2.1, 11.2.3, 11.2.6, 11.7.1, 2.4.1+ authority: Mastercard SPME 2.1, 11.2.3, 11.2.6, 11.7.1, 2.4.1, 11.5.1required_documents:- incorporation- beneficial_ownership- aml_screen- license_verificationmin_review_cycle_days: 365suspension_trigger: document_collection_failurerecord_retention_years: 7aml_watchlist_sources:- ofac_sdn- eu_consolidatedagent_owner: kyb_agent- # Acquirers must perform a MATCH inquiry prior to entering into any Merchant Agreement or enabling a Merchant to accept transactions, as detailed in Mastercard SPME §11.2.3. This inquiry must be conducted using the correct Member ID/ICA Number associated with the Merchant to ensure proper compliance reporting.- # Failure to adhere to these requirements may result in noncompliance assessments.- # The Acquirer is also required to retain all MATCH records related to any Merchant, Sponsored Merchant, or ATM owner for a minimum of two years post-agreement termination, as per Mastercard SPME §11.2.6.- # Additionally, Acquirers that store, transmit, or process personal data of residents in the European Economic Area (EEA), the UK, or Switzerland—or are otherwise subject to EU Data Protection Law—must comply with the standards specified in Appendix D concerning MATCH activity within the Europe Region, consistent with Mastercard SPME §11.7.1.- # Per the updated Mastercard SPME §2.4.1, Acquirers are required to properly manage their PIN Entry Device (PED) and Encrypting PIN Pad (EPP) inventories. This includes maintaining an up-to-date inventory of device types and locations, ensuring devices receive timely software security patches distributed by vendors, and conducting regular physical inspections by trained staff to detect tampering or substitution.- # Acquirers must also manage devices whose PCI PTS approvals have expired by moving them from approved lists to appropriate expired approval lists and ceasing their use for processing transactions if Mastercard issues a sunset date for specific device models.- # These controls strengthen the security posture of Acquirers in line with Mastercard's risk management directives, helping to prevent device-related compromises.+ # Acquirers must perform a MATCH Pro inquiry prior to entering into any Merchant Agreement or enabling a Merchant to accept transactions, as updated in Mastercard SPME §11.2.3 and reinforced by §7.1.+ # This inquiry must use the correct Member ID/ICA Number associated with the Merchant to ensure compliance reporting.+ # Acquirers are further required to add any Merchant or Sponsored Merchant terminated for reasons listed in Mastercard SPME §11.5.1 to the MATCH Pro system, ensuring updated monitoring.+ # All MATCH records related to any Merchant, Sponsored Merchant, or ATM owner must be retained for a minimum of two years post-agreement termination, per Mastercard SPME §11.2.6.+ # Additionally, Acquirers that handle personal data of residents in the EEA, UK, or Switzerland must comply with Appendix D standards for MATCH activity in these regions, in line with Mastercard SPME §11.7.1.+ # Per Mastercard SPME §2.4.1, Acquirers must maintain accurate inventories of PIN Entry Devices (PED) and Encrypting PIN Pads (EPP), ensure devices receive vendor security patches, conduct regular physical inspections to detect tampering or substitution, and manage devices with expired PCI PTS approvals appropriately.+ # These controls collectively enhance the security and compliance posture of Acquirers under Mastercard requirements.
Acquirer KYB (Know Your Business) Obligations
Acquirers processing transactions on the Mastercard network must perform Know Your Business (KYB) due diligence on merchants prior to onboarding and on a recurring basis. Halyard Pay is responsible for collecting and verifying required documentation to confirm business legitimacy, vet beneficial ownership, and satisfy anti-money laundering (AML) screening.
When this policy applies
This policy applies at initial merchant onboarding and during periodic re-verification reviews. Merchants that do not provide required documentation within set timelines must be suspended until compliance is restored.
Required actions
-
Collect all KYB documentation needed at onboarding.
-
Conduct AML screening against applicable watchlists before approval.
-
Verify business licenses for regulated merchant categories.
-
Schedule full re-verification at least annually.
-
Document verification outcomes and maintain records for audit.
-
Retain MATCH Pro system records related to Merchants, Sponsored Merchants, or ATM owners for at least two years after contract termination or expiration, to meet Mastercard record retention requirements.
-
Before Merchant Agreement execution or enabling transactions, conduct a MATCH Pro inquiry using Halyard Pay's Member ID/ICA Number to ensure compliance; failure may lead to Mastercard assessments.
-
For merchants whose personal data pertains to residents of the European Economic Area, the UK, or Switzerland, Halyard Pay must comply with EU Data Protection Laws as specified in Appendix D of the Mastercard SPME manual concerning MATCH activities in the Europe Region.
-
Maintain proper management of PED and EPP device inventories, ensuring devices receive timely software security patches and are physically tracked and inspected regularly for tampering or substitution. This includes keeping an accurate inventory of device types and locations, and training staff to conduct these inspections. Any device model sunset announcements by Mastercard must be adhered to, including ceasing use of such devices by the specified deadline.
10. For any Merchant or Sponsored Merchant terminated for causes listed in Mastercard SPME §11.5.1, promptly add them to the MATCH Pro system to fulfill Mastercard reporting obligations.
Source authority: Mastercard SPME §§2.1, 2.4.1, 7.1, 11.2.3, 11.2.6, 11.5.1, 11.7.1.
Acquirer KYB (Know Your Business) Obligations
Acquirers processing transactions on the Mastercard network must perform Know Your Business (KYB) due diligence on merchants prior to onboarding and on a recurring basis. Halyard Pay is responsible for collecting and verifying required documentation to confirm business legitimacy, vet beneficial ownership, and satisfy anti-money laundering (AML) screening.
When this policy applies
This policy applies at initial merchant onboarding and during periodic re-verification reviews. Merchants that do not provide required documentation within set timelines must be suspended until compliance is restored.
Required actions
-
Collect all KYB documentation needed at onboarding.
-
Conduct AML screening against applicable watchlists before approval.
-
Verify business licenses for regulated merchant categories.
-
Schedule full re-verification at least annually.
-
Document verification outcomes and maintain records for audit.
-
Retain MATCH Pro system records related to Merchants, Sponsored Merchants, or ATM owners for at least two years after contract termination or expiration, to meet Mastercard record retention requirements.
-
Before Merchant Agreement execution or enabling transactions, conduct a MATCH Pro inquiry using Halyard Pay's Member ID/ICA Number to ensure compliance; failure may lead to Mastercard assessments.
-
For merchants whose personal data pertains to residents of the European Economic Area, the UK, or Switzerland, Halyard Pay must comply with EU Data Protection Laws as specified in Appendix D of the Mastercard SPME manual concerning MATCH activities in the Europe Region.
-
Maintain proper management of PED and EPP device inventories, ensuring devices receive timely software security patches and are physically tracked and inspected regularly for tampering or substitution. This includes keeping an accurate inventory of device types and locations, and training staff to conduct these inspections. Any device model sunset announcements by Mastercard must be adhered to, including ceasing use of such devices by the specified deadline.
10. For any Merchant or Sponsored Merchant terminated for causes listed in Mastercard SPME §11.5.1, promptly add them to the MATCH Pro system to fulfill Mastercard reporting obligations.
Source authority: Mastercard SPME §§2.1, 2.4.1, 7.1, 11.2.3, 11.2.6, 11.5.1, 11.7.1.
Source authority: Mastercard SPME §7.1.
--- a/policies/kyb_acquirer/rules.yaml +++ b/policies/kyb_acquirer/rules.yaml @@ -1,5 +1,5 @@ program: Acquirer KYB -authority: Mastercard SPME 2.1, 11.2.3, 11.2.6, 11.7.1, 2.4.1 +authority: Mastercard SPME 2.1, 11.2.3, 11.2.6, 11.7.1, 2.4.1, 11.5.1 required_documents: - incorporation - beneficial_ownership @@ -12,10 +12,10 @@ - ofac_sdn - eu_consolidated agent_owner: kyb_agent -# Acquirers must perform a MATCH inquiry prior to entering into any Merchant Agreement or enabling a Merchant to accept transactions, as detailed in Mastercard SPME §11.2.3. This inquiry must be conducted using the correct Member ID/ICA Number associated with the Merchant to ensure proper compliance reporting. -# Failure to adhere to these requirements may result in noncompliance assessments. -# The Acquirer is also required to retain all MATCH records related to any Merchant, Sponsored Merchant, or ATM owner for a minimum of two years post-agreement termination, as per Mastercard SPME §11.2.6. -# Additionally, Acquirers that store, transmit, or process personal data of residents in the European Economic Area (EEA), the UK, or Switzerland—or are otherwise subject to EU Data Protection Law—must comply with the standards specified in Appendix D concerning MATCH activity within the Europe Region, consistent with Mastercard SPME §11.7.1. -# Per the updated Mastercard SPME §2.4.1, Acquirers are required to properly manage their PIN Entry Device (PED) and Encrypting PIN Pad (EPP) inventories. This includes maintaining an up-to-date inventory of device types and locations, ensuring devices receive timely software security patches distributed by vendors, and conducting regular physical inspections by trained staff to detect tampering or substitution. -# Acquirers must also manage devices whose PCI PTS approvals have expired by moving them from approved lists to appropriate expired approval lists and ceasing their use for processing transactions if Mastercard issues a sunset date for specific device models. -# These controls strengthen the security posture of Acquirers in line with Mastercard's risk management directives, helping to prevent device-related compromises.+# Acquirers must perform a MATCH Pro inquiry prior to entering into any Merchant Agreement or enabling a Merchant to accept transactions, as updated in Mastercard SPME §11.2.3 and reinforced by §7.1. +# This inquiry must use the correct Member ID/ICA Number associated with the Merchant to ensure compliance reporting. +# Acquirers are further required to add any Merchant or Sponsored Merchant terminated for reasons listed in Mastercard SPME §11.5.1 to the MATCH Pro system, ensuring updated monitoring. +# All MATCH records related to any Merchant, Sponsored Merchant, or ATM owner must be retained for a minimum of two years post-agreement termination, per Mastercard SPME §11.2.6. +# Additionally, Acquirers that handle personal data of residents in the EEA, UK, or Switzerland must comply with Appendix D standards for MATCH activity in these regions, in line with Mastercard SPME §11.7.1. +# Per Mastercard SPME §2.4.1, Acquirers must maintain accurate inventories of PIN Entry Devices (PED) and Encrypting PIN Pads (EPP), ensure devices receive vendor security patches, conduct regular physical inspections to detect tampering or substitution, and manage devices with expired PCI PTS approvals appropriately. +# These controls collectively enhance the security and compliance posture of Acquirers under Mastercard requirements. --- a/policies/kyb_acquirer/policy.md +++ b/policies/kyb_acquirer/policy.md @@ -13,9 +13,10 @@ 3. Verify business licenses for regulated merchant categories. 4. Schedule full re-verification at least annually. 5. Document verification outcomes and maintain records for audit. -6. Retain MATCH system records related to Merchants, Sponsored Merchants, or ATM owners for at least two years after contract termination or expiration, to meet Mastercard record retention requirements. -7. Before Merchant Agreement execution or enabling transactions, conduct a MATCH inquiry using Halyard Pay's Member ID/ICA Number to ensure compliance; failure may lead to Mastercard assessments. +6. Retain MATCH Pro system records related to Merchants, Sponsored Merchants, or ATM owners for at least two years after contract termination or expiration, to meet Mastercard record retention requirements. +7. Before Merchant Agreement execution or enabling transactions, conduct a MATCH Pro inquiry using Halyard Pay's Member ID/ICA Number to ensure compliance; failure may lead to Mastercard assessments. 8. For merchants whose personal data pertains to residents of the European Economic Area, the UK, or Switzerland, Halyard Pay must comply with EU Data Protection Laws as specified in Appendix D of the Mastercard SPME manual concerning MATCH activities in the Europe Region. 9. Maintain proper management of PED and EPP device inventories, ensuring devices receive timely software security patches and are physically tracked and inspected regularly for tampering or substitution. This includes keeping an accurate inventory of device types and locations, and training staff to conduct these inspections. Any device model sunset announcements by Mastercard must be adhered to, including ceasing use of such devices by the specified deadline. +10. For any Merchant or Sponsored Merchant terminated for causes listed in Mastercard SPME §11.5.1, promptly add them to the MATCH Pro system to fulfill Mastercard reporting obligations. -Source authority: Mastercard SPME §§2.1, 2.4.1, 7.1, 11.2.3, 11.2.6, 11.7.1. +Source authority: Mastercard SPME §§2.1, 2.4.1, 7.1, 11.2.3, 11.2.6, 11.5.1, 11.7.1.