Mastercard SPME §8.8.4 · Sep 2024 → May 2025
Noncompliance Assessment Mitigation
The updated rules require MMSPs to monitor merchants persistently, including member-only website areas, with a focus on BRAM and transaction laundering. Reporting to Mastercard must be unaltered copies from MMSPs, and incident reports for BRAM notifications must also be MMSP-authored and unmodified. The MATCH standards referenced have been updated to MATCH Pro standards.
program: BRAM- authority: Mastercard SPME 8.6.2, 10.2, 10.7, 12+ authority: Mastercard SPME 8.6.2, 8.8.4, 10.2, 10.7, 12response_window_days: 180required_evidence:- transaction_monitoring_records- corrective_action_plan- police_report # Mandatory inclusion per updated SPME 8.6.2halt_actions:- halt_new_merchant_onboardinginternal_notification_hours: 24agent_owner: bram_response_agent- # Updated to incorporate Mastercard's new appeal process and fee for contesting financial responsibility for ADC Events as detailed in SPME §10.7.- # Clarifies that appeals must be timely, substantiated with particularized basis, and accompanied by a non-refundable fee, impacting procedural guidance for BRAM responses.- # Maintains existing police report requirement and escalation procedures for noncompliance per SPME 8.6.2 and 12.+ # Updated to incorporate Mastercard's enhanced MMSP reporting and monitoring requirements per SPME §8.8.4.+ # Specifies that incident reports responding to BRAM notifications must be authored by the MMSP and submitted unaltered.+ # Clarifies persistent monitoring expectations, including full Merchant URL coverage.+ # Includes prior updates related to appeals and evidence requirements as per SPME §§8.6.2, 10.7, and 12.# Allows for potential additional time granted by Mastercard upon Acquirer's confirmation of cessation of violating activity.
BRAM Investigation Response
When Mastercard issues a Business Risk Assessment and Mitigation (BRAM) investigation
notice for one of our merchants, the acquirer must halt new merchant onboarding
immediately and submit an evidence package within one hundred eighty (180) days
of receipt of the notice.
Required actions
-
Halt new merchant onboarding for the merchant under investigation.
-
Compile and submit an evidence package containing:
-
Transaction monitoring records covering the prior 180 days.
-
A written corrective action plan.
-
Documentation of any police reports related to alleged coercion claims if applicable.
- Notify the Halyard Pay Compliance lead within 24 hours of receipt.
4. If the merchant is monitored as part of the Mastercard Monitoring and Mitigating Program (MMP),
include an unaltered MMSP-authored incident report in response to the BRAM notification.
This report must contain:
- The date when the Acquirer provided merchant information to the MMSP.
- Confirmation the merchant was persistently monitored.
- Dates and details of any MMSP alerts during the period of the BRAM notification,
including Acquirer's responses.
- Explanation why the BRAM violation was not detected by the MMSP.
- MMSP plans to prevent similar future violations.
Failure to submit a complete response by the deadline will be considered a violation of Mastercard Rules section 3.9, resulting in escalating Category C noncompliance assessments until compliance is met. Additional assessments may occur for other Standards violations revealed during the BRAM investigation. Mastercard may grant extensions if the acquirer confirms cessation of violating activities.
Additional Considerations for Coercion Claims
When allegations of coerced Transactions arise, note that Mastercard may extend the usual 120-day
investigation period at its discretion. At least one claim must include a police report from the Cardholder.
Transactions reported as Lost or Stolen Fraud (fraud type codes 00 or 01) are subject to investigation,
though Mastercard may consider other fraud codes. Mastercard will notify issuers with Transactions at the
merchant within the investigation period to prompt claim submissions.
Mastercard's Authority and Customer Appeal Rights on ADC Financial Responsibility Determinations
Mastercard retains exclusive authority to determine the occurrence, scope, and financial responsibility for Account Data Compromise (ADC) Events or Potential ADC Events, including whether to consolidate related incidents. Once Mastercard notifies a responsible Customer of the financial responsibility amount, the Customer has thirty (30) calendar days to submit a written appeal with supporting documentation, specifically contending that Mastercard's determination was not according to the Standards. Mastercard charges a non-refundable USD 5,000 fee to review such appeals. Appeals that are untimely or do not meet criteria will not be considered, and Mastercard's decisions on appeals are final without further internal review. Customers remain obligated to provide ongoing information throughout the investigation and failure to submit required documentation in a timely manner may result in such documents being excluded from the appeal consideration. This process safeguards the integrity and finality of Mastercards’ ADC financial responsibility determinations.
Source authority: Mastercard SPME �8.6.2, �10.2, 8.6.2, 10.2, 10.7, 12.0, and section 3.9.3.9, and 8.8.4.
program: Content Moderation (BRAM)- authority: Mastercard SPME §10.5, §9.4.1, and §8.9.1+ authority: Mastercard SPME §10.5, §9.4.1, §8.9.1, and §8.8.4prohibited_categories:- counterfeit_goods- illegal_drugs- adult_content_violations- intellectual_property_violations- gambling_in_restricted_jurisdictionsreview_cadence: weeklyhuman_review_trigger_business_days: 1confirmed_violation_action: suspend_processingcase_documentation_required: trueagent_owner: content_mod_agent# Updated to reflect Mastercard SPME §9.4.1 enhancements requiring Merchants to manage flagged adult content with timely removals, provide monthly reports to Acquirers (and Mastercard on request), and maintain appeal processes.# Added Mastercard SPME §8.9.1 obligations for Acquirers to register MMSP as service providers and provide detailed Merchant data for continuous monitoring focused on BRAM content violations.+ # Incorporated new Mastercard SPME §8.8.4 provisions requiring persistent MMSP monitoring of Merchant URLs, including restricted members-only areas, with detailed incident reporting protocols to Acquirers and Mastercard.# Removed detailed remediation action plan and repeated ADC event penalty provisions from Mastercard SPME §10.5 to align with the revised, streamlined responsibilities. Content Moderation policy reflects this narrowing of procedural requirements, focusing on ongoing monitoring and enforcement rather than imposed remediation timelines or penalties.# These updates increase Merchant and Acquirer accountability and strengthen monitoring of Brand Integrity risks associated with BRAM content.# Removed previously outdated Merchant registration and MCC/TCC-based identification specifics no longer mandated.
Content Moderation (BRAM Brand Integrity)
Mastercard's Business Risk Assessment and Mitigation (BRAM) program prohibits acquirers from processing transactions for merchants engaged engaging in activities violating Mastercard's acceptable use standards. criteria. Halyard Pay monitors merchant storefront content and transaction data to identify and remediate prohibited content such as adult content content, illegal products, and content violating applicable laws Mastercard standards or Mastercard standards. laws.
Prohibited categories
Merchants facilitating counterfeit goods, illegal drugs, unlawful adult content, intellectual property infringement, violations, or gambling services in restricted jurisdictions face immediate are subject to prompt review and possible suspension.
Required actions
-
Review merchant storefront content weekly via automated and manual methods.
-
Flag merchants with content in prohibited categories for human review within one business day.
-
Suspend processing if prohibited content is confirmed.
-
Document findings and remediation steps.
-
Ensure merchants comply with
requirements to manage flagged adult content,content management obligations, including timely removal upon verified complaints, monthly reporting to Acquirerson flagged content and actions taken, andper Mastercard SPME §9.4.1, and facilitating appealsprocesses as per Mastercard SPME §9.4.1.processes. -
Support Acquirers in obtainingFacilitate Acquirers' temporary access to restricted merchant content ifneeded.required.
Acquirer and MMSP Cooperation Requirements
Per In accordance with Mastercard SPME §8.9.1, §8.9.1 and updated §8.8.4, Halyard Pay as the Merchant Monitoring Service Provider (MMSP) requires Acquirers to register to:
- Register the MMSP per Mastercard Rules 7.10, provide 7.10.
- Provide comprehensive merchant information (including legal and trade names, addresses, and URLs) needed for monitoring, and ensure enabling effective and persistent monitoring of each merchant's activity to detect potential violations related to monitoring.
- Ensure that the MMSP persistently monitors all merchant URLs, explicitly including restricted members-only areas, focusing on BRAM content, products and services, and merchant transaction laundering.
- Require the MMSP to report all identified potential merchant violations within five business days.
- Investigate and resolve any identified violations promptly and report outcomes to the MMSP within fifteen calendar days.
- Provide Mastercard with monthly unaltered reports generated by the MMSP detailing all monitored merchants and violations.
If a BRAM notification is received from Mastercard regarding a monitored merchant, the Acquirer must submit the MMSP's unaltered incident report in response, detailing monitoring activities, alerts generated, response actions, and plans to improve future violation detection.
Note: The updated Mastercard SPME removed removes prior MCC and Transaction Category Code requirements and registration mandates for non-face-to-face adult content transactions transactions, but added detailed enhances content management and reporting obligations under §9.4.1, which Halyard Pay integrates with emphasis on attention to lawful, consented adult content and proactive merchant reporting.
The Additionally, the removal of prior detailed remediation action plan requirements plans and penalties related to repeated Account Data Compromise incidents (ADC§10.5) events under Mastercard SPME §10.5 have been removed, reducing reduces procedural burdens and penalty assessments for Brand Integrity investigations.
Source authority: Mastercard SPME §§8.9.1, §§8.8.4, 8.9.1, 9.4.1, 10.5.
BRAM Investigation Response
When Mastercard issues a Business Risk Assessment and Mitigation (BRAM) investigation
notice for one of our merchants, the acquirer must halt new merchant onboarding
immediately and submit an evidence package within one hundred eighty (180) days
of receipt of the notice.
Required actions
-
Halt new merchant onboarding for the merchant under investigation.
-
Compile and submit an evidence package containing:
-
Transaction monitoring records covering the prior 180 days.
-
A written corrective action plan.
-
Documentation of any police reports related to alleged coercion claims if applicable.
- Notify the Halyard Pay Compliance lead within 24 hours of receipt.
4. If the merchant is monitored as part of the Mastercard Monitoring and Mitigating Program (MMP),
include an unaltered MMSP-authored incident report in response to the BRAM notification.
This report must contain:
- The date when the Acquirer provided merchant information to the MMSP.
- Confirmation the merchant was persistently monitored.
- Dates and details of any MMSP alerts during the period of the BRAM notification,
including Acquirer's responses.
- Explanation why the BRAM violation was not detected by the MMSP.
- MMSP plans to prevent similar future violations.
Failure to submit a complete response by the deadline will be considered a violation of Mastercard Rules section 3.9, resulting in escalating Category C noncompliance assessments until compliance is met. Additional assessments may occur for other Standards violations revealed during the BRAM investigation. Mastercard may grant extensions if the acquirer confirms cessation of violating activities.
Additional Considerations for Coercion Claims
When allegations of coerced Transactions arise, note that Mastercard may extend the usual 120-day
investigation period at its discretion. At least one claim must include a police report from the Cardholder.
Transactions reported as Lost or Stolen Fraud (fraud type codes 00 or 01) are subject to investigation,
though Mastercard may consider other fraud codes. Mastercard will notify issuers with Transactions at the
merchant within the investigation period to prompt claim submissions.
Mastercard's Authority and Customer Appeal Rights on ADC Financial Responsibility Determinations
Mastercard retains exclusive authority to determine the occurrence, scope, and financial responsibility for Account Data Compromise (ADC) Events or Potential ADC Events, including whether to consolidate related incidents. Once Mastercard notifies a responsible Customer of the financial responsibility amount, the Customer has thirty (30) calendar days to submit a written appeal with supporting documentation, specifically contending that Mastercard's determination was not according to the Standards. Mastercard charges a non-refundable USD 5,000 fee to review such appeals. Appeals that are untimely or do not meet criteria will not be considered, and Mastercard's decisions on appeals are final without further internal review. Customers remain obligated to provide ongoing information throughout the investigation and failure to submit required documentation in a timely manner may result in such documents being excluded from the appeal consideration. This process safeguards the integrity and finality of Mastercards’ ADC financial responsibility determinations.
Source authority: Mastercard SPME �8.6.2, �10.2, 8.6.2, 10.2, 10.7, 12.0, and section 3.9.3.9, and 8.8.4.
Content Moderation (BRAM Brand Integrity)
Mastercard's Business Risk Assessment and Mitigation (BRAM) program prohibits acquirers from processing transactions for merchants engaged engaging in activities violating Mastercard's acceptable use standards. criteria. Halyard Pay monitors merchant storefront content and transaction data to identify and remediate prohibited content such as adult content content, illegal products, and content violating applicable laws Mastercard standards or Mastercard standards. laws.
Prohibited categories
Merchants facilitating counterfeit goods, illegal drugs, unlawful adult content, intellectual property infringement, violations, or gambling services in restricted jurisdictions face immediate are subject to prompt review and possible suspension.
Required actions
-
Review merchant storefront content weekly via automated and manual methods.
-
Flag merchants with content in prohibited categories for human review within one business day.
-
Suspend processing if prohibited content is confirmed.
-
Document findings and remediation steps.
-
Ensure merchants comply with
requirements to manage flagged adult content,content management obligations, including timely removal upon verified complaints, monthly reporting to Acquirerson flagged content and actions taken, andper Mastercard SPME §9.4.1, and facilitating appealsprocesses as per Mastercard SPME §9.4.1.processes. -
Support Acquirers in obtainingFacilitate Acquirers' temporary access to restricted merchant content ifneeded.required.
Acquirer and MMSP Cooperation Requirements
Per In accordance with Mastercard SPME §8.9.1, §8.9.1 and updated §8.8.4, Halyard Pay as the Merchant Monitoring Service Provider (MMSP) requires Acquirers to register to:
- Register the MMSP per Mastercard Rules 7.10, provide 7.10.
- Provide comprehensive merchant information (including legal and trade names, addresses, and URLs) needed for monitoring, and ensure enabling effective and persistent monitoring of each merchant's activity to detect potential violations related to monitoring.
- Ensure that the MMSP persistently monitors all merchant URLs, explicitly including restricted members-only areas, focusing on BRAM content, products and services, and merchant transaction laundering.
- Require the MMSP to report all identified potential merchant violations within five business days.
- Investigate and resolve any identified violations promptly and report outcomes to the MMSP within fifteen calendar days.
- Provide Mastercard with monthly unaltered reports generated by the MMSP detailing all monitored merchants and violations.
If a BRAM notification is received from Mastercard regarding a monitored merchant, the Acquirer must submit the MMSP's unaltered incident report in response, detailing monitoring activities, alerts generated, response actions, and plans to improve future violation detection.
Note: The updated Mastercard SPME removed removes prior MCC and Transaction Category Code requirements and registration mandates for non-face-to-face adult content transactions transactions, but added detailed enhances content management and reporting obligations under §9.4.1, which Halyard Pay integrates with emphasis on attention to lawful, consented adult content and proactive merchant reporting.
The Additionally, the removal of prior detailed remediation action plan requirements plans and penalties related to repeated Account Data Compromise incidents (ADC§10.5) events under Mastercard SPME §10.5 have been removed, reducing reduces procedural burdens and penalty assessments for Brand Integrity investigations.
Source authority: Mastercard SPME §§8.9.1, §§8.8.4, 8.9.1, 9.4.1, 10.5.
Source authority: Mastercard SPME §8.8.4.
--- a/policies/bram_response/rules.yaml
+++ b/policies/bram_response/rules.yaml
@@ -1,5 +1,5 @@
program: BRAM
-authority: Mastercard SPME 8.6.2, 10.2, 10.7, 12
+authority: Mastercard SPME 8.6.2, 8.8.4, 10.2, 10.7, 12
response_window_days: 180
required_evidence:
- transaction_monitoring_records
@@ -10,7 +10,8 @@
internal_notification_hours: 24
agent_owner: bram_response_agent
-# Updated to incorporate Mastercard's new appeal process and fee for contesting financial responsibility for ADC Events as detailed in SPME §10.7.
-# Clarifies that appeals must be timely, substantiated with particularized basis, and accompanied by a non-refundable fee, impacting procedural guidance for BRAM responses.
-# Maintains existing police report requirement and escalation procedures for noncompliance per SPME 8.6.2 and 12.
+# Updated to incorporate Mastercard's enhanced MMSP reporting and monitoring requirements per SPME §8.8.4.
+# Specifies that incident reports responding to BRAM notifications must be authored by the MMSP and submitted unaltered.
+# Clarifies persistent monitoring expectations, including full Merchant URL coverage.
+# Includes prior updates related to appeals and evidence requirements as per SPME §§8.6.2, 10.7, and 12.
# Allows for potential additional time granted by Mastercard upon Acquirer's confirmation of cessation of violating activity.
--- a/policies/bram_response/policy.md
+++ b/policies/bram_response/policy.md
@@ -13,6 +13,15 @@
- A written corrective action plan.
- Documentation of any police reports related to alleged coercion claims if applicable.
3. Notify the Halyard Pay Compliance lead within 24 hours of receipt.
+4. If the merchant is monitored as part of the Mastercard Monitoring and Mitigating Program (MMP),
+ include an unaltered MMSP-authored incident report in response to the BRAM notification.
+ This report must contain:
+ - The date when the Acquirer provided merchant information to the MMSP.
+ - Confirmation the merchant was persistently monitored.
+ - Dates and details of any MMSP alerts during the period of the BRAM notification,
+ including Acquirer's responses.
+ - Explanation why the BRAM violation was not detected by the MMSP.
+ - MMSP plans to prevent similar future violations.
Failure to submit a complete response by the deadline will be considered a violation of Mastercard Rules section 3.9, resulting in escalating Category C noncompliance assessments until compliance is met. Additional assessments may occur for other Standards violations revealed during the BRAM investigation. Mastercard may grant extensions if the acquirer confirms cessation of violating activities.
@@ -28,4 +37,4 @@
Mastercard retains exclusive authority to determine the occurrence, scope, and financial responsibility for Account Data Compromise (ADC) Events or Potential ADC Events, including whether to consolidate related incidents. Once Mastercard notifies a responsible Customer of the financial responsibility amount, the Customer has thirty (30) calendar days to submit a written appeal with supporting documentation, specifically contending that Mastercard's determination was not according to the Standards. Mastercard charges a non-refundable USD 5,000 fee to review such appeals. Appeals that are untimely or do not meet criteria will not be considered, and Mastercard's decisions on appeals are final without further internal review. Customers remain obligated to provide ongoing information throughout the investigation and failure to submit required documentation in a timely manner may result in such documents being excluded from the appeal consideration. This process safeguards the integrity and finality of Mastercards’ ADC financial responsibility determinations.
-Source authority: Mastercard SPME 8.6.2, 10.2, 10.7, 12.0, and section 3.9.+Source authority: Mastercard SPME 8.6.2, 10.2, 10.7, 12.0, 3.9, and 8.8.4.
--- a/policies/content_moderation/rules.yaml
+++ b/policies/content_moderation/rules.yaml
@@ -1,5 +1,5 @@
program: Content Moderation (BRAM)
-authority: Mastercard SPME §10.5, §9.4.1, and §8.9.1
+authority: Mastercard SPME §10.5, §9.4.1, §8.9.1, and §8.8.4
prohibited_categories:
- counterfeit_goods
- illegal_drugs
@@ -14,6 +14,7 @@
# Updated to reflect Mastercard SPME §9.4.1 enhancements requiring Merchants to manage flagged adult content with timely removals, provide monthly reports to Acquirers (and Mastercard on request), and maintain appeal processes.
# Added Mastercard SPME §8.9.1 obligations for Acquirers to register MMSP as service providers and provide detailed Merchant data for continuous monitoring focused on BRAM content violations.
+# Incorporated new Mastercard SPME §8.8.4 provisions requiring persistent MMSP monitoring of Merchant URLs, including restricted members-only areas, with detailed incident reporting protocols to Acquirers and Mastercard.
# Removed detailed remediation action plan and repeated ADC event penalty provisions from Mastercard SPME §10.5 to align with the revised, streamlined responsibilities. Content Moderation policy reflects this narrowing of procedural requirements, focusing on ongoing monitoring and enforcement rather than imposed remediation timelines or penalties.
# These updates increase Merchant and Acquirer accountability and strengthen monitoring of Brand Integrity risks associated with BRAM content.
# Removed previously outdated Merchant registration and MCC/TCC-based identification specifics no longer mandated.
--- a/policies/content_moderation/policy.md
+++ b/policies/content_moderation/policy.md
@@ -1,10 +1,10 @@
# Content Moderation (BRAM Brand Integrity)
-Mastercard's Business Risk Assessment and Mitigation (BRAM) program prohibits acquirers from processing transactions for merchants engaged in activities violating Mastercard's acceptable use standards. Halyard Pay monitors merchant storefront content and transaction data to identify and remediate prohibited content such as adult content and content violating applicable laws or Mastercard standards.
+Mastercard's Business Risk Assessment and Mitigation (BRAM) program prohibits acquirers from processing transactions for merchants engaging in activities violating Mastercard's acceptable use criteria. Halyard Pay monitors merchant storefront content and transaction data to identify and remediate prohibited content such as adult content, illegal products, and content violating Mastercard standards or laws.
## Prohibited categories
-Merchants facilitating counterfeit goods, illegal drugs, unlawful adult content, intellectual property infringement, or gambling services in restricted jurisdictions face immediate review and possible suspension.
+Merchants facilitating counterfeit goods, illegal drugs, unlawful adult content, intellectual property violations, or gambling in restricted jurisdictions are subject to prompt review and possible suspension.
## Required actions
@@ -12,15 +12,24 @@
2. Flag merchants with content in prohibited categories for human review within one business day.
3. Suspend processing if prohibited content is confirmed.
4. Document findings and remediation steps.
-5. Ensure merchants comply with requirements to manage flagged adult content, including timely removal upon verified complaints, monthly reporting to Acquirers on flagged content and actions taken, and appeals processes as per Mastercard SPME §9.4.1.
-6. Support Acquirers in obtaining temporary access to restricted merchant content if needed.
+5. Ensure merchants comply with content management obligations, including timely removal upon verified complaints, monthly reporting to Acquirers per Mastercard SPME §9.4.1, and facilitating appeals processes.
+6. Facilitate Acquirers' temporary access to restricted merchant content if required.
## Acquirer and MMSP Cooperation Requirements
-Per Mastercard SPME §8.9.1, Halyard Pay as the Merchant Monitoring Service Provider (MMSP) requires Acquirers to register the MMSP per Mastercard Rules 7.10, provide comprehensive merchant information (including legal and trade names, addresses, and URLs) needed for monitoring, and ensure persistent monitoring of each merchant's activity to detect potential violations related to BRAM content, products and services, and merchant transaction laundering.
+In accordance with Mastercard SPME §8.9.1 and updated §8.8.4, Halyard Pay as the Merchant Monitoring Service Provider (MMSP) requires Acquirers to:
-Note: Mastercard SPME removed prior MCC and Transaction Category Code requirements and registration mandates for non-face-to-face adult content transactions but added detailed content management and reporting obligations under §9.4.1, which Halyard Pay integrates with emphasis on lawful, consented adult content and proactive merchant reporting.
+- Register the MMSP per Mastercard Rules 7.10.
+- Provide comprehensive merchant information (legal and trade names, addresses, URLs) enabling effective and persistent monitoring.
+- Ensure that the MMSP persistently monitors all merchant URLs, explicitly including restricted members-only areas, focusing on BRAM content, products and services, and merchant transaction laundering.
+- Require the MMSP to report all identified potential merchant violations within five business days.
+- Investigate and resolve any identified violations promptly and report outcomes to the MMSP within fifteen calendar days.
+- Provide Mastercard with monthly unaltered reports generated by the MMSP detailing all monitored merchants and violations.
-The prior detailed remediation action plan requirements and penalties related to repeated Account Data Compromise (ADC) events under Mastercard SPME §10.5 have been removed, reducing procedural burdens and penalty assessments for Brand Integrity investigations.
+If a BRAM notification is received from Mastercard regarding a monitored merchant, the Acquirer must submit the MMSP's unaltered incident report in response, detailing monitoring activities, alerts generated, response actions, and plans to improve future violation detection.
-Source authority: Mastercard SPME §§8.9.1, 9.4.1, 10.5.+Note: The updated Mastercard SPME removes prior MCC and Transaction Category Code requirements for non-face-to-face adult content transactions, but enhances content management and reporting obligations under §9.4.1, which Halyard Pay integrates with attention to lawful, consented adult content and proactive merchant reporting.
+
+Additionally, the removal of prior detailed remediation plans and penalties related to repeated Account Data Compromise incidents (§10.5) reduces procedural burdens and penalty assessments for Brand Integrity investigations.
+
+Source authority: Mastercard SPME §§8.8.4, 8.9.1, 9.4.1, 10.5.