Mastercard SPME §8.9.1 · Sep 2024 → May 2025
MMP Participation Requirements
The requirements for Acquirers to participate in the Merchant Monitoring Program now include confirming that the MMSP is approved by Mastercard for BRAM monitoring and/or Merchant Transaction laundering detection before registration and data submission.
program: BRAM- authority: Mastercard SPME 8.6.2, 10.2, 10.7, 12+ authority: Mastercard SPME 8.6.2, 8.9.1, 10.2, 10.7, 12response_window_days: 180required_evidence:- transaction_monitoring_records- corrective_action_plan- police_report # Mandatory inclusion per updated SPME 8.6.2halt_actions:- halt_new_merchant_onboardinginternal_notification_hours: 24agent_owner: bram_response_agent- # Updated to incorporate Mastercard's new appeal process and fee for contesting financial responsibility for ADC Events as detailed in SPME §10.7.- # Clarifies that appeals must be timely, substantiated with particularized basis, and accompanied by a non-refundable fee, impacting procedural guidance for BRAM responses.- # Maintains existing police report requirement and escalation procedures for noncompliance per SPME 8.6.2 and 12.- # Allows for potential additional time granted by Mastercard upon Acquirer's confirmation of cessation of violating activity.+ # Added requirement that Acquirers must confirm that the Merchant Monitoring Service Provider (MMSP) is Mastercard-approved for BRAM monitoring, as specified in SPME §8.9.1.+ # This change strengthens compliance by ensuring only authorized service providers participate in merchant monitoring.+ # The police report mandate and response escalation remain per SPME §§8.6.2, 10.7, and 12.+ # Clarification and procedural adherence to appeal with fee under SPME §10.7 are retained unchanged.
BRAM Investigation Response
When Mastercard issues a Business Risk Assessment and Mitigation (BRAM) investigation
notice for one of our merchants, the acquirer must halt new merchant onboarding
immediately and submit an evidence package within one hundred eighty (180) days
of receipt of the notice.
Required actions
-
Halt new merchant onboarding for the merchant under investigation.
-
Compile and submit an evidence package containing:
-
Transaction monitoring records covering the prior 180 days.
-
A written corrective action plan.
-
Documentation of any police reports related to alleged coercion claims if applicable.
- Notify the Halyard Pay Compliance lead within 24 hours of receipt.
Failure to submit a complete response by the deadline will be considered a violation of Mastercard Rules section 3.9, resulting in escalating Category C noncompliance assessments until compliance is met. Additional assessments may occur for other Standards violations revealed during the BRAM investigation. Mastercard may grant extensions if the acquirer confirms cessation of violating activities.
Additional Considerations for Coercion Claims
When allegations of coerced Transactions arise, note that Mastercard may extend the usual 120-day
investigation period at its discretion. At least one claim must include a police report from the Cardholder.
Transactions reported as Lost or Stolen Fraud (fraud type codes 00 or 01) are subject to investigation,
though Mastercard may consider other fraud codes. Mastercard will notify issuers with Transactions at the
merchant within the investigation period to prompt claim submissions.
Use of Mastercard-Approved MMSPs for Merchant Monitoring
Acquirers participating in the Merchant Monitoring Program must confirm that the Merchant Monitoring Service Provider (MMSP) they engage is expressly approved by Mastercard to conduct BRAM monitoring and/or Merchant Transaction laundering detection services. The MMSP must be registered as a Service Provider, and all necessary merchant information and data must be submitted to the MMSP to facilitate effective monitoring. This ensures compliance with Mastercard Rules Section 7.10 and reinforces the obligation to work with authorized providers for monitoring merchant activities relevant to BRAM investigations.
## Mastercard's Authority and Customer Appeal Rights on ADC Financial Responsibility Determinations
Mastercard retains exclusive authority to determine the occurrence, scope, and financial responsibility for Account Data Compromise (ADC) Events or Potential ADC Events, including whether to consolidate related incidents. Once Mastercard notifies a responsible Customer of the financial responsibility amount, the Customer has thirty (30) calendar days to submit a written appeal with supporting documentation, specifically contending that Mastercard's determination was not according to the Standards. Mastercard charges a non-refundable USD 5,000 fee to review such appeals. Appeals that are untimely or do not meet criteria will not be considered, and Mastercard's decisions on appeals are final without further internal review. Customers remain obligated to provide ongoing information throughout the investigation and failure to submit required documentation in a timely manner may result in such documents being excluded from the appeal consideration. This process safeguards the integrity and finality of Mastercards’ ADC financial responsibility determinations.
Source authority: Mastercard SPME �8.6.2, �10.2, 8.6.2, 10.2, 10.7, 12.0, and section 3.9.3.9; 8.9.1.
program: Content Moderation (BRAM)authority: Mastercard SPME §10.5, §9.4.1, and §8.9.1prohibited_categories:- counterfeit_goods- illegal_drugs- adult_content_violations- intellectual_property_violations- gambling_in_restricted_jurisdictionsreview_cadence: weeklyhuman_review_trigger_business_days: 1confirmed_violation_action: suspend_processingcase_documentation_required: trueagent_owner: content_mod_agent- # Updated to reflect Mastercard SPME §9.4.1 enhancements requiring Merchants to manage flagged adult content with timely removals, provide monthly reports to Acquirers (and Mastercard on request), and maintain appeal processes.- # Added Mastercard SPME §8.9.1 obligations for Acquirers to register MMSP as service providers and provide detailed Merchant data for continuous monitoring focused on BRAM content violations.- # Removed detailed remediation action plan and repeated ADC event penalty provisions from Mastercard SPME §10.5 to align with the revised, streamlined responsibilities. Content Moderation policy reflects this narrowing of procedural requirements, focusing on ongoing monitoring and enforcement rather than imposed remediation timelines or penalties.- # These updates increase Merchant and Acquirer accountability and strengthen monitoring of Brand Integrity risks associated with BRAM content.- # Removed previously outdated Merchant registration and MCC/TCC-based identification specifics no longer mandated.+ # Updated to incorporate Mastercard SPME §8.9.1 changes requiring Acquirers to ensure MMSPs are Mastercard-approved for BRAM monitoring and/or Merchant Transaction laundering detection before registration.+ # This refinement enhances oversight of Merchant Monitoring Program participants by specifying MMSP approval prerequisites.+ # Previous procedural details on BRAM monitoring and reporting remain, with no changes to core content moderation workflows or prohibited category definitions.+ # Ensures consistency between policy and Mastercard mandates on ACS provider approval.+ # Other procedural requirements as per SPME §9.4.1 and §10.5 are maintained without amendment.
Content Moderation (BRAM Brand Integrity)
Mastercard's Business Risk Assessment and Mitigation (BRAM) program prohibits acquirers from processing transactions for merchants engaged in activities violating Mastercard's acceptable use standards. Halyard Pay monitors merchant storefront content and transaction data to identify and remediate prohibited content such as adult content and content violating applicable laws or Mastercard standards.
Prohibited categories
Merchants facilitating counterfeit goods, illegal drugs, unlawful adult content, intellectual property infringement, or gambling services in restricted jurisdictions face immediate review and possible suspension.
Required actions
-
Review merchant storefront content weekly via automated and manual methods.
-
Flag merchants with content in prohibited categories for human review within one business day.
-
Suspend processing if prohibited content is confirmed.
-
Document findings and remediation steps.
-
Ensure merchants comply with requirements to manage flagged adult content, including timely removal upon verified complaints, monthly reporting to Acquirers on flagged content and actions taken, and appeals processes as per Mastercard SPME §9.4.1.
-
Support Acquirers in obtaining temporary access to restricted merchant content if needed.
Acquirer and MMSP Cooperation Requirements
Per Mastercard SPME §8.9.1, Halyard Pay as the Merchant Monitoring Service Provider (MMSP) requires the MMSP to be Mastercard-approved for BRAM monitoring and/or Merchant Transaction laundering detection services. Acquirers to must register the MMSP per Mastercard Rules 7.10, provide comprehensive merchant information (including legal and trade names, addresses, and URLs) needed for necessary for effective monitoring, and ensure persistent monitoring of each merchant's activity to detect potential violations related to BRAM content, products and services, and merchant transaction laundering.
Note: Mastercard SPME removed prior MCC and Transaction Category Code requirements and registration mandates for non-face-to-face adult content transactions but added detailed content management and reporting obligations under §9.4.1, which Halyard Pay integrates with emphasis on lawful, consented adult content and proactive merchant reporting.
The prior detailed remediation action plan requirements and penalties related to repeated Account Data Compromise (ADC) events under Mastercard SPME §10.5 have been removed, reducing procedural burdens and penalty assessments for Brand Integrity investigations.
Source authority: Mastercard SPME §§8.9.1, 9.4.1, 10.5.
BRAM Investigation Response
When Mastercard issues a Business Risk Assessment and Mitigation (BRAM) investigation
notice for one of our merchants, the acquirer must halt new merchant onboarding
immediately and submit an evidence package within one hundred eighty (180) days
of receipt of the notice.
Required actions
-
Halt new merchant onboarding for the merchant under investigation.
-
Compile and submit an evidence package containing:
-
Transaction monitoring records covering the prior 180 days.
-
A written corrective action plan.
-
Documentation of any police reports related to alleged coercion claims if applicable.
- Notify the Halyard Pay Compliance lead within 24 hours of receipt.
Failure to submit a complete response by the deadline will be considered a violation of Mastercard Rules section 3.9, resulting in escalating Category C noncompliance assessments until compliance is met. Additional assessments may occur for other Standards violations revealed during the BRAM investigation. Mastercard may grant extensions if the acquirer confirms cessation of violating activities.
Additional Considerations for Coercion Claims
When allegations of coerced Transactions arise, note that Mastercard may extend the usual 120-day
investigation period at its discretion. At least one claim must include a police report from the Cardholder.
Transactions reported as Lost or Stolen Fraud (fraud type codes 00 or 01) are subject to investigation,
though Mastercard may consider other fraud codes. Mastercard will notify issuers with Transactions at the
merchant within the investigation period to prompt claim submissions.
Use of Mastercard-Approved MMSPs for Merchant Monitoring
Acquirers participating in the Merchant Monitoring Program must confirm that the Merchant Monitoring Service Provider (MMSP) they engage is expressly approved by Mastercard to conduct BRAM monitoring and/or Merchant Transaction laundering detection services. The MMSP must be registered as a Service Provider, and all necessary merchant information and data must be submitted to the MMSP to facilitate effective monitoring. This ensures compliance with Mastercard Rules Section 7.10 and reinforces the obligation to work with authorized providers for monitoring merchant activities relevant to BRAM investigations.
## Mastercard's Authority and Customer Appeal Rights on ADC Financial Responsibility Determinations
Mastercard retains exclusive authority to determine the occurrence, scope, and financial responsibility for Account Data Compromise (ADC) Events or Potential ADC Events, including whether to consolidate related incidents. Once Mastercard notifies a responsible Customer of the financial responsibility amount, the Customer has thirty (30) calendar days to submit a written appeal with supporting documentation, specifically contending that Mastercard's determination was not according to the Standards. Mastercard charges a non-refundable USD 5,000 fee to review such appeals. Appeals that are untimely or do not meet criteria will not be considered, and Mastercard's decisions on appeals are final without further internal review. Customers remain obligated to provide ongoing information throughout the investigation and failure to submit required documentation in a timely manner may result in such documents being excluded from the appeal consideration. This process safeguards the integrity and finality of Mastercards’ ADC financial responsibility determinations.
Source authority: Mastercard SPME �8.6.2, �10.2, 8.6.2, 10.2, 10.7, 12.0, and section 3.9.3.9; 8.9.1.
Content Moderation (BRAM Brand Integrity)
Mastercard's Business Risk Assessment and Mitigation (BRAM) program prohibits acquirers from processing transactions for merchants engaged in activities violating Mastercard's acceptable use standards. Halyard Pay monitors merchant storefront content and transaction data to identify and remediate prohibited content such as adult content and content violating applicable laws or Mastercard standards.
Prohibited categories
Merchants facilitating counterfeit goods, illegal drugs, unlawful adult content, intellectual property infringement, or gambling services in restricted jurisdictions face immediate review and possible suspension.
Required actions
-
Review merchant storefront content weekly via automated and manual methods.
-
Flag merchants with content in prohibited categories for human review within one business day.
-
Suspend processing if prohibited content is confirmed.
-
Document findings and remediation steps.
-
Ensure merchants comply with requirements to manage flagged adult content, including timely removal upon verified complaints, monthly reporting to Acquirers on flagged content and actions taken, and appeals processes as per Mastercard SPME §9.4.1.
-
Support Acquirers in obtaining temporary access to restricted merchant content if needed.
Acquirer and MMSP Cooperation Requirements
Per Mastercard SPME §8.9.1, Halyard Pay as the Merchant Monitoring Service Provider (MMSP) requires the MMSP to be Mastercard-approved for BRAM monitoring and/or Merchant Transaction laundering detection services. Acquirers to must register the MMSP per Mastercard Rules 7.10, provide comprehensive merchant information (including legal and trade names, addresses, and URLs) needed for necessary for effective monitoring, and ensure persistent monitoring of each merchant's activity to detect potential violations related to BRAM content, products and services, and merchant transaction laundering.
Note: Mastercard SPME removed prior MCC and Transaction Category Code requirements and registration mandates for non-face-to-face adult content transactions but added detailed content management and reporting obligations under §9.4.1, which Halyard Pay integrates with emphasis on lawful, consented adult content and proactive merchant reporting.
The prior detailed remediation action plan requirements and penalties related to repeated Account Data Compromise (ADC) events under Mastercard SPME §10.5 have been removed, reducing procedural burdens and penalty assessments for Brand Integrity investigations.
Source authority: Mastercard SPME §§8.9.1, 9.4.1, 10.5.
Source authority: Mastercard SPME §8.9.1.
--- a/policies/bram_response/rules.yaml +++ b/policies/bram_response/rules.yaml @@ -1,5 +1,5 @@ program: BRAM -authority: Mastercard SPME 8.6.2, 10.2, 10.7, 12 +authority: Mastercard SPME 8.6.2, 8.9.1, 10.2, 10.7, 12 response_window_days: 180 required_evidence: - transaction_monitoring_records @@ -10,7 +10,7 @@ internal_notification_hours: 24 agent_owner: bram_response_agent -# Updated to incorporate Mastercard's new appeal process and fee for contesting financial responsibility for ADC Events as detailed in SPME §10.7. -# Clarifies that appeals must be timely, substantiated with particularized basis, and accompanied by a non-refundable fee, impacting procedural guidance for BRAM responses. -# Maintains existing police report requirement and escalation procedures for noncompliance per SPME 8.6.2 and 12. -# Allows for potential additional time granted by Mastercard upon Acquirer's confirmation of cessation of violating activity. +# Added requirement that Acquirers must confirm that the Merchant Monitoring Service Provider (MMSP) is Mastercard-approved for BRAM monitoring, as specified in SPME §8.9.1. +# This change strengthens compliance by ensuring only authorized service providers participate in merchant monitoring. +# The police report mandate and response escalation remain per SPME §§8.6.2, 10.7, and 12. +# Clarification and procedural adherence to appeal with fee under SPME §10.7 are retained unchanged. --- a/policies/bram_response/policy.md +++ b/policies/bram_response/policy.md @@ -24,8 +24,12 @@ though Mastercard may consider other fraud codes. Mastercard will notify issuers with Transactions at the merchant within the investigation period to prompt claim submissions. +## Use of Mastercard-Approved MMSPs for Merchant Monitoring + +Acquirers participating in the Merchant Monitoring Program must confirm that the Merchant Monitoring Service Provider (MMSP) they engage is expressly approved by Mastercard to conduct BRAM monitoring and/or Merchant Transaction laundering detection services. The MMSP must be registered as a Service Provider, and all necessary merchant information and data must be submitted to the MMSP to facilitate effective monitoring. This ensures compliance with Mastercard Rules Section 7.10 and reinforces the obligation to work with authorized providers for monitoring merchant activities relevant to BRAM investigations. + ## Mastercard's Authority and Customer Appeal Rights on ADC Financial Responsibility Determinations Mastercard retains exclusive authority to determine the occurrence, scope, and financial responsibility for Account Data Compromise (ADC) Events or Potential ADC Events, including whether to consolidate related incidents. Once Mastercard notifies a responsible Customer of the financial responsibility amount, the Customer has thirty (30) calendar days to submit a written appeal with supporting documentation, specifically contending that Mastercard's determination was not according to the Standards. Mastercard charges a non-refundable USD 5,000 fee to review such appeals. Appeals that are untimely or do not meet criteria will not be considered, and Mastercard's decisions on appeals are final without further internal review. Customers remain obligated to provide ongoing information throughout the investigation and failure to submit required documentation in a timely manner may result in such documents being excluded from the appeal consideration. This process safeguards the integrity and finality of Mastercards’ ADC financial responsibility determinations. -Source authority: Mastercard SPME 8.6.2, 10.2, 10.7, 12.0, and section 3.9.+Source authority: Mastercard SPME 8.6.2, 10.2, 10.7, 12.0, and section 3.9; 8.9.1. --- a/policies/content_moderation/rules.yaml +++ b/policies/content_moderation/rules.yaml @@ -12,8 +12,8 @@ case_documentation_required: true agent_owner: content_mod_agent -# Updated to reflect Mastercard SPME §9.4.1 enhancements requiring Merchants to manage flagged adult content with timely removals, provide monthly reports to Acquirers (and Mastercard on request), and maintain appeal processes. -# Added Mastercard SPME §8.9.1 obligations for Acquirers to register MMSP as service providers and provide detailed Merchant data for continuous monitoring focused on BRAM content violations. -# Removed detailed remediation action plan and repeated ADC event penalty provisions from Mastercard SPME §10.5 to align with the revised, streamlined responsibilities. Content Moderation policy reflects this narrowing of procedural requirements, focusing on ongoing monitoring and enforcement rather than imposed remediation timelines or penalties. -# These updates increase Merchant and Acquirer accountability and strengthen monitoring of Brand Integrity risks associated with BRAM content. -# Removed previously outdated Merchant registration and MCC/TCC-based identification specifics no longer mandated. +# Updated to incorporate Mastercard SPME §8.9.1 changes requiring Acquirers to ensure MMSPs are Mastercard-approved for BRAM monitoring and/or Merchant Transaction laundering detection before registration. +# This refinement enhances oversight of Merchant Monitoring Program participants by specifying MMSP approval prerequisites. +# Previous procedural details on BRAM monitoring and reporting remain, with no changes to core content moderation workflows or prohibited category definitions. +# Ensures consistency between policy and Mastercard mandates on ACS provider approval. +# Other procedural requirements as per SPME §9.4.1 and §10.5 are maintained without amendment. --- a/policies/content_moderation/policy.md +++ b/policies/content_moderation/policy.md @@ -17,10 +17,10 @@ ## Acquirer and MMSP Cooperation Requirements -Per Mastercard SPME §8.9.1, Halyard Pay as the Merchant Monitoring Service Provider (MMSP) requires Acquirers to register the MMSP per Mastercard Rules 7.10, provide comprehensive merchant information (including legal and trade names, addresses, and URLs) needed for monitoring, and ensure persistent monitoring of each merchant's activity to detect potential violations related to BRAM content, products and services, and merchant transaction laundering. +Per Mastercard SPME §8.9.1, Halyard Pay as the Merchant Monitoring Service Provider (MMSP) requires the MMSP to be Mastercard-approved for BRAM monitoring and/or Merchant Transaction laundering detection services. Acquirers must register the MMSP per Mastercard Rules 7.10, provide comprehensive merchant information (including legal and trade names, addresses, and URLs) necessary for effective monitoring, and ensure persistent monitoring of each merchant's activity to detect potential violations related to BRAM content, products and services, and merchant transaction laundering. Note: Mastercard SPME removed prior MCC and Transaction Category Code requirements and registration mandates for non-face-to-face adult content transactions but added detailed content management and reporting obligations under §9.4.1, which Halyard Pay integrates with emphasis on lawful, consented adult content and proactive merchant reporting. The prior detailed remediation action plan requirements and penalties related to repeated Account Data Compromise (ADC) events under Mastercard SPME §10.5 have been removed, reducing procedural burdens and penalty assessments for Brand Integrity investigations. -Source authority: Mastercard SPME §§8.9.1, 9.4.1, 10.5.+Source authority: Mastercard SPME §§8.9.1, 9.4.1, 10.5.