Mastercard SPME §8.8.4 · Sep 2024 → May 2025

Noncompliance Assessment Mitigation

substantive

The updated rules require MMSPs to monitor merchants persistently, including member-only website areas, with a focus on BRAM and transaction laundering. Reporting to Mastercard must be unaltered copies from MMSPs, and incident reports for BRAM notifications must also be MMSP-authored and unmodified. The MATCH standards referenced have been updated to MATCH Pro standards.

Sources Mastercard SPME · Sep 2024 · page 96 PDF Mastercard SPME · May 2025 · page 98 PDF BRAM Response current Content Moderation current
Also in §8.x this release substantive §8.6.2 Investigation Process substantive §8.6.8 Coercion Program Performance Assessments substantive §8.9.1 MMP Participation Requirements substantive §8.9.2 MMP Monthly Reporting Format and Submission
Why these edits? The changes require incident reports for BRAM notifications to be authored by MMSPs and submitted unaltered to Mastercard, enhancing the obligations related to BRAM investigation response reporting.; The update explicitly requires persistent monitoring of merchant URLs including member-only areas with focus on BRAM content and transaction laundering, impacting content moderation obligations.
Mastercard SPME §8.8.4
Security Rules and Procedures—Merchant Edition • 6 August 2024 11 February 2025 Ensure that the MMSP persistently monitors each Merchant's activity for the purpose of identifying potential Merchant violations related to BRAM content, products and services and/or Merchant Transaction laundering; Ensure Merchant URLs are monitored completely, which explicitly includes any restricted members-only areas; • Require the MMSP to report all identifications of potential Merchant violations to the Acquirer within five (5) business days; • Within 15 calendar days of receiving MMSP notification of an identification, investigate the potential violation, ensure that all violating activity has ceased, and report the resolution of the identification to the MMSP; • Provide Mastercard with monthly reports generated by the MMSP detailing all of its Merchants being monitored as part of the MMP and all violations identified by the MMSP during that time. A report submitted to Mastercard directly by the Acquirer must be an unaltered copy of the report generated by the MMSP. The reports may be submitted by the MMSP on the Acquirer's behalf; and • Adhere to the MATCH Pro Standards set forth in Chapter 11, when applicable. If an Acquirer receives a BRAM notification from Mastercard regarding a Merchant that is being monitored as part of the MMP, the Acquirer must provide an MMSP Incident Report incident report authored by the MMSP as part of its response to the BRAM notification. An incident report submitted to Mastercard directly by the Acquirer must be an unaltered copy of the report generated by the MMSP. The report must include: • The date on which the Acquirer provided the Merchant information to the MMSP; • Confirmation that the Merchant was persistently monitored; • The dates and contents of any alerts that the MMSP generated and sent to the Acquirer during the monthly period in which the BRAM notification occurred, and any response or action taken by the Acquirer; • How and why the BRAM violation was not detected by the MMSP; • How the MMSP will ensure the detection of future potential Merchant violations of a similar nature.
Halyard Pay · 4 files
program: BRAM
- authority: Mastercard SPME 8.6.2, 10.2, 10.7, 12
+ authority: Mastercard SPME 8.6.2, 8.8.4, 10.2, 10.7, 12
response_window_days: 180
required_evidence:
- transaction_monitoring_records
- corrective_action_plan
- police_report # Mandatory inclusion per updated SPME 8.6.2
halt_actions:
- halt_new_merchant_onboarding
internal_notification_hours: 24
agent_owner: bram_response_agent
 
- # Updated to incorporate Mastercard's new appeal process and fee for contesting financial responsibility for ADC Events as detailed in SPME §10.7.
- # Clarifies that appeals must be timely, substantiated with particularized basis, and accompanied by a non-refundable fee, impacting procedural guidance for BRAM responses.
- # Maintains existing police report requirement and escalation procedures for noncompliance per SPME 8.6.2 and 12.
+ # Updated to incorporate Mastercard's enhanced MMSP reporting and monitoring requirements per SPME §8.8.4.
+ # Specifies that incident reports responding to BRAM notifications must be authored by the MMSP and submitted unaltered.
+ # Clarifies persistent monitoring expectations, including full Merchant URL coverage.
+ # Includes prior updates related to appeals and evidence requirements as per SPME §§8.6.2, 10.7, and 12.
# Allows for potential additional time granted by Mastercard upon Acquirer's confirmation of cessation of violating activity.

BRAM Investigation Response

When Mastercard issues a Business Risk Assessment and Mitigation (BRAM) investigation

notice for one of our merchants, the acquirer must halt new merchant onboarding

immediately and submit an evidence package within one hundred eighty (180) days

of receipt of the notice.

Required actions

  1. Halt new merchant onboarding for the merchant under investigation.

  2. Compile and submit an evidence package containing:

  • Transaction monitoring records covering the prior 180 days.

  • A written corrective action plan.

  • Documentation of any police reports related to alleged coercion claims if applicable.

  1. Notify the Halyard Pay Compliance lead within 24 hours of receipt.

4. If the merchant is monitored as part of the Mastercard Monitoring and Mitigating Program (MMP),

include an unaltered MMSP-authored incident report in response to the BRAM notification.

This report must contain:

- The date when the Acquirer provided merchant information to the MMSP.

- Confirmation the merchant was persistently monitored.

- Dates and details of any MMSP alerts during the period of the BRAM notification,

including Acquirer's responses.

- Explanation why the BRAM violation was not detected by the MMSP.

- MMSP plans to prevent similar future violations.

Failure to submit a complete response by the deadline will be considered a violation of Mastercard Rules section 3.9, resulting in escalating Category C noncompliance assessments until compliance is met. Additional assessments may occur for other Standards violations revealed during the BRAM investigation. Mastercard may grant extensions if the acquirer confirms cessation of violating activities.

Additional Considerations for Coercion Claims

When allegations of coerced Transactions arise, note that Mastercard may extend the usual 120-day

investigation period at its discretion. At least one claim must include a police report from the Cardholder.

Transactions reported as Lost or Stolen Fraud (fraud type codes 00 or 01) are subject to investigation,

though Mastercard may consider other fraud codes. Mastercard will notify issuers with Transactions at the

merchant within the investigation period to prompt claim submissions.

Mastercard's Authority and Customer Appeal Rights on ADC Financial Responsibility Determinations

Mastercard retains exclusive authority to determine the occurrence, scope, and financial responsibility for Account Data Compromise (ADC) Events or Potential ADC Events, including whether to consolidate related incidents. Once Mastercard notifies a responsible Customer of the financial responsibility amount, the Customer has thirty (30) calendar days to submit a written appeal with supporting documentation, specifically contending that Mastercard's determination was not according to the Standards. Mastercard charges a non-refundable USD 5,000 fee to review such appeals. Appeals that are untimely or do not meet criteria will not be considered, and Mastercard's decisions on appeals are final without further internal review. Customers remain obligated to provide ongoing information throughout the investigation and failure to submit required documentation in a timely manner may result in such documents being excluded from the appeal consideration. This process safeguards the integrity and finality of Mastercards’ ADC financial responsibility determinations.

Source authority: Mastercard SPME �8.6.2, �10.2, 8.6.2, 10.2, 10.7, 12.0, and section 3.9.3.9, and 8.8.4.

program: Content Moderation (BRAM)
- authority: Mastercard SPME §10.5, §9.4.1, and §8.9.1
+ authority: Mastercard SPME §10.5, §9.4.1, §8.9.1, and §8.8.4
prohibited_categories:
- counterfeit_goods
- illegal_drugs
- adult_content_violations
- intellectual_property_violations
- gambling_in_restricted_jurisdictions
review_cadence: weekly
human_review_trigger_business_days: 1
confirmed_violation_action: suspend_processing
case_documentation_required: true
agent_owner: content_mod_agent
 
# Updated to reflect Mastercard SPME §9.4.1 enhancements requiring Merchants to manage flagged adult content with timely removals, provide monthly reports to Acquirers (and Mastercard on request), and maintain appeal processes.
# Added Mastercard SPME §8.9.1 obligations for Acquirers to register MMSP as service providers and provide detailed Merchant data for continuous monitoring focused on BRAM content violations.
+ # Incorporated new Mastercard SPME §8.8.4 provisions requiring persistent MMSP monitoring of Merchant URLs, including restricted members-only areas, with detailed incident reporting protocols to Acquirers and Mastercard.
# Removed detailed remediation action plan and repeated ADC event penalty provisions from Mastercard SPME §10.5 to align with the revised, streamlined responsibilities. Content Moderation policy reflects this narrowing of procedural requirements, focusing on ongoing monitoring and enforcement rather than imposed remediation timelines or penalties.
# These updates increase Merchant and Acquirer accountability and strengthen monitoring of Brand Integrity risks associated with BRAM content.
# Removed previously outdated Merchant registration and MCC/TCC-based identification specifics no longer mandated.

Content Moderation (BRAM Brand Integrity)

Mastercard's Business Risk Assessment and Mitigation (BRAM) program prohibits acquirers from processing transactions for merchants engaged engaging in activities violating Mastercard's acceptable use standards. criteria. Halyard Pay monitors merchant storefront content and transaction data to identify and remediate prohibited content such as adult content content, illegal products, and content violating applicable laws Mastercard standards or Mastercard standards. laws.

Prohibited categories

Merchants facilitating counterfeit goods, illegal drugs, unlawful adult content, intellectual property infringement, violations, or gambling services in restricted jurisdictions face immediate are subject to prompt review and possible suspension.

Required actions

  1. Review merchant storefront content weekly via automated and manual methods.

  2. Flag merchants with content in prohibited categories for human review within one business day.

  3. Suspend processing if prohibited content is confirmed.

  4. Document findings and remediation steps.

  5. Ensure merchants comply with requirements to manage flagged adult content, content management obligations, including timely removal upon verified complaints, monthly reporting to Acquirers on flagged content and actions taken, and per Mastercard SPME §9.4.1, and facilitating appeals processes as per Mastercard SPME §9.4.1. processes.

  6. Support Acquirers in obtaining Facilitate Acquirers' temporary access to restricted merchant content if needed. required.

Acquirer and MMSP Cooperation Requirements

Per In accordance with Mastercard SPME §8.9.1, §8.9.1 and updated §8.8.4, Halyard Pay as the Merchant Monitoring Service Provider (MMSP) requires Acquirers to register to:

- Register the MMSP per Mastercard Rules 7.10, provide 7.10.

- Provide comprehensive merchant information (including legal and trade names, addresses, and URLs) needed for monitoring, and ensure enabling effective and persistent monitoring of each merchant's activity to detect potential violations related to monitoring.

- Ensure that the MMSP persistently monitors all merchant URLs, explicitly including restricted members-only areas, focusing on BRAM content, products and services, and merchant transaction laundering.

- Require the MMSP to report all identified potential merchant violations within five business days.

- Investigate and resolve any identified violations promptly and report outcomes to the MMSP within fifteen calendar days.

- Provide Mastercard with monthly unaltered reports generated by the MMSP detailing all monitored merchants and violations.

If a BRAM notification is received from Mastercard regarding a monitored merchant, the Acquirer must submit the MMSP's unaltered incident report in response, detailing monitoring activities, alerts generated, response actions, and plans to improve future violation detection.

Note: The updated Mastercard SPME removed removes prior MCC and Transaction Category Code requirements and registration mandates for non-face-to-face adult content transactions transactions, but added detailed enhances content management and reporting obligations under §9.4.1, which Halyard Pay integrates with emphasis on attention to lawful, consented adult content and proactive merchant reporting.

The Additionally, the removal of prior detailed remediation action plan requirements plans and penalties related to repeated Account Data Compromise incidents (ADC§10.5) events under Mastercard SPME §10.5 have been removed, reducing reduces procedural burdens and penalty assessments for Brand Integrity investigations.

Source authority: Mastercard SPME §§8.9.1, §§8.8.4, 8.9.1, 9.4.1, 10.5.

policies/bram_response/policy.md — after applying change

BRAM Investigation Response

When Mastercard issues a Business Risk Assessment and Mitigation (BRAM) investigation

notice for one of our merchants, the acquirer must halt new merchant onboarding

immediately and submit an evidence package within one hundred eighty (180) days

of receipt of the notice.

Required actions

  1. Halt new merchant onboarding for the merchant under investigation.

  2. Compile and submit an evidence package containing:

  • Transaction monitoring records covering the prior 180 days.

  • A written corrective action plan.

  • Documentation of any police reports related to alleged coercion claims if applicable.

  1. Notify the Halyard Pay Compliance lead within 24 hours of receipt.

4. If the merchant is monitored as part of the Mastercard Monitoring and Mitigating Program (MMP),

include an unaltered MMSP-authored incident report in response to the BRAM notification.

This report must contain:

- The date when the Acquirer provided merchant information to the MMSP.

- Confirmation the merchant was persistently monitored.

- Dates and details of any MMSP alerts during the period of the BRAM notification,

including Acquirer's responses.

- Explanation why the BRAM violation was not detected by the MMSP.

- MMSP plans to prevent similar future violations.

Failure to submit a complete response by the deadline will be considered a violation of Mastercard Rules section 3.9, resulting in escalating Category C noncompliance assessments until compliance is met. Additional assessments may occur for other Standards violations revealed during the BRAM investigation. Mastercard may grant extensions if the acquirer confirms cessation of violating activities.

Additional Considerations for Coercion Claims

When allegations of coerced Transactions arise, note that Mastercard may extend the usual 120-day

investigation period at its discretion. At least one claim must include a police report from the Cardholder.

Transactions reported as Lost or Stolen Fraud (fraud type codes 00 or 01) are subject to investigation,

though Mastercard may consider other fraud codes. Mastercard will notify issuers with Transactions at the

merchant within the investigation period to prompt claim submissions.

Mastercard's Authority and Customer Appeal Rights on ADC Financial Responsibility Determinations

Mastercard retains exclusive authority to determine the occurrence, scope, and financial responsibility for Account Data Compromise (ADC) Events or Potential ADC Events, including whether to consolidate related incidents. Once Mastercard notifies a responsible Customer of the financial responsibility amount, the Customer has thirty (30) calendar days to submit a written appeal with supporting documentation, specifically contending that Mastercard's determination was not according to the Standards. Mastercard charges a non-refundable USD 5,000 fee to review such appeals. Appeals that are untimely or do not meet criteria will not be considered, and Mastercard's decisions on appeals are final without further internal review. Customers remain obligated to provide ongoing information throughout the investigation and failure to submit required documentation in a timely manner may result in such documents being excluded from the appeal consideration. This process safeguards the integrity and finality of Mastercards’ ADC financial responsibility determinations.

Source authority: Mastercard SPME �8.6.2, �10.2, 8.6.2, 10.2, 10.7, 12.0, and section 3.9.3.9, and 8.8.4.

policies/content_moderation/policy.md — after applying change

Content Moderation (BRAM Brand Integrity)

Mastercard's Business Risk Assessment and Mitigation (BRAM) program prohibits acquirers from processing transactions for merchants engaged engaging in activities violating Mastercard's acceptable use standards. criteria. Halyard Pay monitors merchant storefront content and transaction data to identify and remediate prohibited content such as adult content content, illegal products, and content violating applicable laws Mastercard standards or Mastercard standards. laws.

Prohibited categories

Merchants facilitating counterfeit goods, illegal drugs, unlawful adult content, intellectual property infringement, violations, or gambling services in restricted jurisdictions face immediate are subject to prompt review and possible suspension.

Required actions

  1. Review merchant storefront content weekly via automated and manual methods.

  2. Flag merchants with content in prohibited categories for human review within one business day.

  3. Suspend processing if prohibited content is confirmed.

  4. Document findings and remediation steps.

  5. Ensure merchants comply with requirements to manage flagged adult content, content management obligations, including timely removal upon verified complaints, monthly reporting to Acquirers on flagged content and actions taken, and per Mastercard SPME §9.4.1, and facilitating appeals processes as per Mastercard SPME §9.4.1. processes.

  6. Support Acquirers in obtaining Facilitate Acquirers' temporary access to restricted merchant content if needed. required.

Acquirer and MMSP Cooperation Requirements

Per In accordance with Mastercard SPME §8.9.1, §8.9.1 and updated §8.8.4, Halyard Pay as the Merchant Monitoring Service Provider (MMSP) requires Acquirers to register to:

- Register the MMSP per Mastercard Rules 7.10, provide 7.10.

- Provide comprehensive merchant information (including legal and trade names, addresses, and URLs) needed for monitoring, and ensure enabling effective and persistent monitoring of each merchant's activity to detect potential violations related to monitoring.

- Ensure that the MMSP persistently monitors all merchant URLs, explicitly including restricted members-only areas, focusing on BRAM content, products and services, and merchant transaction laundering.

- Require the MMSP to report all identified potential merchant violations within five business days.

- Investigate and resolve any identified violations promptly and report outcomes to the MMSP within fifteen calendar days.

- Provide Mastercard with monthly unaltered reports generated by the MMSP detailing all monitored merchants and violations.

If a BRAM notification is received from Mastercard regarding a monitored merchant, the Acquirer must submit the MMSP's unaltered incident report in response, detailing monitoring activities, alerts generated, response actions, and plans to improve future violation detection.

Note: The updated Mastercard SPME removed removes prior MCC and Transaction Category Code requirements and registration mandates for non-face-to-face adult content transactions transactions, but added detailed enhances content management and reporting obligations under §9.4.1, which Halyard Pay integrates with emphasis on attention to lawful, consented adult content and proactive merchant reporting.

The Additionally, the removal of prior detailed remediation action plan requirements plans and penalties related to repeated Account Data Compromise incidents (ADC§10.5) events under Mastercard SPME §10.5 have been removed, reducing reduces procedural burdens and penalty assessments for Brand Integrity investigations.

Source authority: Mastercard SPME §§8.9.1, §§8.8.4, 8.9.1, 9.4.1, 10.5.

Source authority: Mastercard SPME §8.8.4.

--- a/policies/bram_response/rules.yaml
+++ b/policies/bram_response/rules.yaml
@@ -1,5 +1,5 @@
 program: BRAM
-authority: Mastercard SPME 8.6.2, 10.2, 10.7, 12
+authority: Mastercard SPME 8.6.2, 8.8.4, 10.2, 10.7, 12
 response_window_days: 180
 required_evidence:
   - transaction_monitoring_records
@@ -10,7 +10,8 @@
 internal_notification_hours: 24
 agent_owner: bram_response_agent
 
-# Updated to incorporate Mastercard's new appeal process and fee for contesting financial responsibility for ADC Events as detailed in SPME §10.7.
-# Clarifies that appeals must be timely, substantiated with particularized basis, and accompanied by a non-refundable fee, impacting procedural guidance for BRAM responses.
-# Maintains existing police report requirement and escalation procedures for noncompliance per SPME 8.6.2 and 12.
+# Updated to incorporate Mastercard's enhanced MMSP reporting and monitoring requirements per SPME §8.8.4.
+# Specifies that incident reports responding to BRAM notifications must be authored by the MMSP and submitted unaltered.
+# Clarifies persistent monitoring expectations, including full Merchant URL coverage.
+# Includes prior updates related to appeals and evidence requirements as per SPME §§8.6.2, 10.7, and 12.
 # Allows for potential additional time granted by Mastercard upon Acquirer's confirmation of cessation of violating activity.

--- a/policies/bram_response/policy.md
+++ b/policies/bram_response/policy.md
@@ -13,6 +13,15 @@
    - A written corrective action plan.
    - Documentation of any police reports related to alleged coercion claims if applicable.
 3. Notify the Halyard Pay Compliance lead within 24 hours of receipt.
+4. If the merchant is monitored as part of the Mastercard Monitoring and Mitigating Program (MMP),
+   include an unaltered MMSP-authored incident report in response to the BRAM notification.
+   This report must contain:
+   - The date when the Acquirer provided merchant information to the MMSP.
+   - Confirmation the merchant was persistently monitored.
+   - Dates and details of any MMSP alerts during the period of the BRAM notification,
+     including Acquirer's responses.
+   - Explanation why the BRAM violation was not detected by the MMSP.
+   - MMSP plans to prevent similar future violations.
 
 Failure to submit a complete response by the deadline will be considered a violation of Mastercard Rules section 3.9, resulting in escalating Category C noncompliance assessments until compliance is met. Additional assessments may occur for other Standards violations revealed during the BRAM investigation. Mastercard may grant extensions if the acquirer confirms cessation of violating activities.
 
@@ -28,4 +37,4 @@
 
 Mastercard retains exclusive authority to determine the occurrence, scope, and financial responsibility for Account Data Compromise (ADC) Events or Potential ADC Events, including whether to consolidate related incidents. Once Mastercard notifies a responsible Customer of the financial responsibility amount, the Customer has thirty (30) calendar days to submit a written appeal with supporting documentation, specifically contending that Mastercard's determination was not according to the Standards. Mastercard charges a non-refundable USD 5,000 fee to review such appeals. Appeals that are untimely or do not meet criteria will not be considered, and Mastercard's decisions on appeals are final without further internal review. Customers remain obligated to provide ongoing information throughout the investigation and failure to submit required documentation in a timely manner may result in such documents being excluded from the appeal consideration. This process safeguards the integrity and finality of Mastercards’ ADC financial responsibility determinations.
 
-Source authority: Mastercard SPME 8.6.2, 10.2, 10.7, 12.0, and section 3.9.+Source authority: Mastercard SPME 8.6.2, 10.2, 10.7, 12.0, 3.9, and 8.8.4.
--- a/policies/content_moderation/rules.yaml
+++ b/policies/content_moderation/rules.yaml
@@ -1,5 +1,5 @@
 program: Content Moderation (BRAM)
-authority: Mastercard SPME §10.5, §9.4.1, and §8.9.1
+authority: Mastercard SPME §10.5, §9.4.1, §8.9.1, and §8.8.4
 prohibited_categories:
   - counterfeit_goods
   - illegal_drugs
@@ -14,6 +14,7 @@
 
 # Updated to reflect Mastercard SPME §9.4.1 enhancements requiring Merchants to manage flagged adult content with timely removals, provide monthly reports to Acquirers (and Mastercard on request), and maintain appeal processes.
 # Added Mastercard SPME §8.9.1 obligations for Acquirers to register MMSP as service providers and provide detailed Merchant data for continuous monitoring focused on BRAM content violations.
+# Incorporated new Mastercard SPME §8.8.4 provisions requiring persistent MMSP monitoring of Merchant URLs, including restricted members-only areas, with detailed incident reporting protocols to Acquirers and Mastercard.
 # Removed detailed remediation action plan and repeated ADC event penalty provisions from Mastercard SPME §10.5 to align with the revised, streamlined responsibilities. Content Moderation policy reflects this narrowing of procedural requirements, focusing on ongoing monitoring and enforcement rather than imposed remediation timelines or penalties.
 # These updates increase Merchant and Acquirer accountability and strengthen monitoring of Brand Integrity risks associated with BRAM content.
 # Removed previously outdated Merchant registration and MCC/TCC-based identification specifics no longer mandated.

--- a/policies/content_moderation/policy.md
+++ b/policies/content_moderation/policy.md
@@ -1,10 +1,10 @@
 # Content Moderation (BRAM Brand Integrity)
 
-Mastercard's Business Risk Assessment and Mitigation (BRAM) program prohibits acquirers from processing transactions for merchants engaged in activities violating Mastercard's acceptable use standards. Halyard Pay monitors merchant storefront content and transaction data to identify and remediate prohibited content such as adult content and content violating applicable laws or Mastercard standards.
+Mastercard's Business Risk Assessment and Mitigation (BRAM) program prohibits acquirers from processing transactions for merchants engaging in activities violating Mastercard's acceptable use criteria. Halyard Pay monitors merchant storefront content and transaction data to identify and remediate prohibited content such as adult content, illegal products, and content violating Mastercard standards or laws.
 
 ## Prohibited categories
 
-Merchants facilitating counterfeit goods, illegal drugs, unlawful adult content, intellectual property infringement, or gambling services in restricted jurisdictions face immediate review and possible suspension.
+Merchants facilitating counterfeit goods, illegal drugs, unlawful adult content, intellectual property violations, or gambling in restricted jurisdictions are subject to prompt review and possible suspension.
 
 ## Required actions
 
@@ -12,15 +12,24 @@
 2. Flag merchants with content in prohibited categories for human review within one business day.
 3. Suspend processing if prohibited content is confirmed.
 4. Document findings and remediation steps.
-5. Ensure merchants comply with requirements to manage flagged adult content, including timely removal upon verified complaints, monthly reporting to Acquirers on flagged content and actions taken, and appeals processes as per Mastercard SPME §9.4.1.
-6. Support Acquirers in obtaining temporary access to restricted merchant content if needed.
+5. Ensure merchants comply with content management obligations, including timely removal upon verified complaints, monthly reporting to Acquirers per Mastercard SPME §9.4.1, and facilitating appeals processes.
+6. Facilitate Acquirers' temporary access to restricted merchant content if required.
 
 ## Acquirer and MMSP Cooperation Requirements
 
-Per Mastercard SPME §8.9.1, Halyard Pay as the Merchant Monitoring Service Provider (MMSP) requires Acquirers to register the MMSP per Mastercard Rules 7.10, provide comprehensive merchant information (including legal and trade names, addresses, and URLs) needed for monitoring, and ensure persistent monitoring of each merchant's activity to detect potential violations related to BRAM content, products and services, and merchant transaction laundering.
+In accordance with Mastercard SPME §8.9.1 and updated §8.8.4, Halyard Pay as the Merchant Monitoring Service Provider (MMSP) requires Acquirers to:
 
-Note: Mastercard SPME removed prior MCC and Transaction Category Code requirements and registration mandates for non-face-to-face adult content transactions but added detailed content management and reporting obligations under §9.4.1, which Halyard Pay integrates with emphasis on lawful, consented adult content and proactive merchant reporting.
+- Register the MMSP per Mastercard Rules 7.10.
+- Provide comprehensive merchant information (legal and trade names, addresses, URLs) enabling effective and persistent monitoring.
+- Ensure that the MMSP persistently monitors all merchant URLs, explicitly including restricted members-only areas, focusing on BRAM content, products and services, and merchant transaction laundering.
+- Require the MMSP to report all identified potential merchant violations within five business days.
+- Investigate and resolve any identified violations promptly and report outcomes to the MMSP within fifteen calendar days.
+- Provide Mastercard with monthly unaltered reports generated by the MMSP detailing all monitored merchants and violations.
 
-The prior detailed remediation action plan requirements and penalties related to repeated Account Data Compromise (ADC) events under Mastercard SPME §10.5 have been removed, reducing procedural burdens and penalty assessments for Brand Integrity investigations.
+If a BRAM notification is received from Mastercard regarding a monitored merchant, the Acquirer must submit the MMSP's unaltered incident report in response, detailing monitoring activities, alerts generated, response actions, and plans to improve future violation detection.
 
-Source authority: Mastercard SPME §§8.9.1, 9.4.1, 10.5.+Note: The updated Mastercard SPME removes prior MCC and Transaction Category Code requirements for non-face-to-face adult content transactions, but enhances content management and reporting obligations under §9.4.1, which Halyard Pay integrates with attention to lawful, consented adult content and proactive merchant reporting.
+
+Additionally, the removal of prior detailed remediation plans and penalties related to repeated Account Data Compromise incidents (§10.5) reduces procedural burdens and penalty assessments for Brand Integrity investigations.
+
+Source authority: Mastercard SPME §§8.8.4, 8.9.1, 9.4.1, 10.5.