Mastercard SPME §8.9.1 · Sep 2024 → May 2025

MMP Participation Requirements

substantive

The requirements for Acquirers to participate in the Merchant Monitoring Program now include confirming that the MMSP is approved by Mastercard for BRAM monitoring and/or Merchant Transaction laundering detection before registration and data submission.

Sources Mastercard SPME · Sep 2024 · page 96 PDF Mastercard SPME · May 2025 · page 98 PDF BRAM Response current Content Moderation current
Also in §8.x this release substantive §8.6.2 Investigation Process substantive §8.6.8 Coercion Program Performance Assessments substantive §8.8.4 Noncompliance Assessment Mitigation substantive §8.9.2 MMP Monthly Reporting Format and Submission
Why these edits? The addition of the requirement that Acquirers must confirm the MMSP is approved by Mastercard for BRAM monitoring reinforces the obligation to work with authorized service providers for BRAM investigation responses.; The mandate that MMSPs must be Mastercard-approved for BRAM monitoring directly impacts the Content Moderation policy by tightening criteria for Merchant Monitoring Program participation.
Mastercard SPME §8.9.1
To participate in the Merchant Monitoring Program, an Acquirer must: Confirm the MMSP has been approved by Mastercard to perform BRAM monitoring and/or Merchant Transaction laundering detection services; • Register the MMSP as its Service Provider as described in Mastercard Rules section Section 7.10; • Submit to the MMSP all Merchant information and any additional data that the MMSP deems necessary or appropriate for the successful monitoring of the particular Merchant (including the Merchant legal name, Merchant "doing business as" name, Merchant address, and all Merchant URLs); • ¶ Ensure that the MMSP persistently monitors each Merchant's activity for the purpose of ¶ identifying potential Merchant violations related to BRAM content, products and services ¶ and/or Merchant Transaction laundering; ¶ Mastercard Fraud Control Programs
Halyard Pay · 4 files
program: BRAM
- authority: Mastercard SPME 8.6.2, 10.2, 10.7, 12
+ authority: Mastercard SPME 8.6.2, 8.9.1, 10.2, 10.7, 12
response_window_days: 180
required_evidence:
- transaction_monitoring_records
- corrective_action_plan
- police_report # Mandatory inclusion per updated SPME 8.6.2
halt_actions:
- halt_new_merchant_onboarding
internal_notification_hours: 24
agent_owner: bram_response_agent
 
- # Updated to incorporate Mastercard's new appeal process and fee for contesting financial responsibility for ADC Events as detailed in SPME §10.7.
- # Clarifies that appeals must be timely, substantiated with particularized basis, and accompanied by a non-refundable fee, impacting procedural guidance for BRAM responses.
- # Maintains existing police report requirement and escalation procedures for noncompliance per SPME 8.6.2 and 12.
- # Allows for potential additional time granted by Mastercard upon Acquirer's confirmation of cessation of violating activity.
+ # Added requirement that Acquirers must confirm that the Merchant Monitoring Service Provider (MMSP) is Mastercard-approved for BRAM monitoring, as specified in SPME §8.9.1.
+ # This change strengthens compliance by ensuring only authorized service providers participate in merchant monitoring.
+ # The police report mandate and response escalation remain per SPME §§8.6.2, 10.7, and 12.
+ # Clarification and procedural adherence to appeal with fee under SPME §10.7 are retained unchanged.

BRAM Investigation Response

When Mastercard issues a Business Risk Assessment and Mitigation (BRAM) investigation

notice for one of our merchants, the acquirer must halt new merchant onboarding

immediately and submit an evidence package within one hundred eighty (180) days

of receipt of the notice.

Required actions

  1. Halt new merchant onboarding for the merchant under investigation.

  2. Compile and submit an evidence package containing:

  • Transaction monitoring records covering the prior 180 days.

  • A written corrective action plan.

  • Documentation of any police reports related to alleged coercion claims if applicable.

  1. Notify the Halyard Pay Compliance lead within 24 hours of receipt.

Failure to submit a complete response by the deadline will be considered a violation of Mastercard Rules section 3.9, resulting in escalating Category C noncompliance assessments until compliance is met. Additional assessments may occur for other Standards violations revealed during the BRAM investigation. Mastercard may grant extensions if the acquirer confirms cessation of violating activities.

Additional Considerations for Coercion Claims

When allegations of coerced Transactions arise, note that Mastercard may extend the usual 120-day

investigation period at its discretion. At least one claim must include a police report from the Cardholder.

Transactions reported as Lost or Stolen Fraud (fraud type codes 00 or 01) are subject to investigation,

though Mastercard may consider other fraud codes. Mastercard will notify issuers with Transactions at the

merchant within the investigation period to prompt claim submissions.

Use of Mastercard-Approved MMSPs for Merchant Monitoring

Acquirers participating in the Merchant Monitoring Program must confirm that the Merchant Monitoring Service Provider (MMSP) they engage is expressly approved by Mastercard to conduct BRAM monitoring and/or Merchant Transaction laundering detection services. The MMSP must be registered as a Service Provider, and all necessary merchant information and data must be submitted to the MMSP to facilitate effective monitoring. This ensures compliance with Mastercard Rules Section 7.10 and reinforces the obligation to work with authorized providers for monitoring merchant activities relevant to BRAM investigations.

## Mastercard's Authority and Customer Appeal Rights on ADC Financial Responsibility Determinations

Mastercard retains exclusive authority to determine the occurrence, scope, and financial responsibility for Account Data Compromise (ADC) Events or Potential ADC Events, including whether to consolidate related incidents. Once Mastercard notifies a responsible Customer of the financial responsibility amount, the Customer has thirty (30) calendar days to submit a written appeal with supporting documentation, specifically contending that Mastercard's determination was not according to the Standards. Mastercard charges a non-refundable USD 5,000 fee to review such appeals. Appeals that are untimely or do not meet criteria will not be considered, and Mastercard's decisions on appeals are final without further internal review. Customers remain obligated to provide ongoing information throughout the investigation and failure to submit required documentation in a timely manner may result in such documents being excluded from the appeal consideration. This process safeguards the integrity and finality of Mastercards’ ADC financial responsibility determinations.

Source authority: Mastercard SPME �8.6.2, �10.2, 8.6.2, 10.2, 10.7, 12.0, and section 3.9.3.9; 8.9.1.

program: Content Moderation (BRAM)
authority: Mastercard SPME §10.5, §9.4.1, and §8.9.1
prohibited_categories:
- counterfeit_goods
- illegal_drugs
- adult_content_violations
- intellectual_property_violations
- gambling_in_restricted_jurisdictions
review_cadence: weekly
human_review_trigger_business_days: 1
confirmed_violation_action: suspend_processing
case_documentation_required: true
agent_owner: content_mod_agent
 
- # Updated to reflect Mastercard SPME §9.4.1 enhancements requiring Merchants to manage flagged adult content with timely removals, provide monthly reports to Acquirers (and Mastercard on request), and maintain appeal processes.
- # Added Mastercard SPME §8.9.1 obligations for Acquirers to register MMSP as service providers and provide detailed Merchant data for continuous monitoring focused on BRAM content violations.
- # Removed detailed remediation action plan and repeated ADC event penalty provisions from Mastercard SPME §10.5 to align with the revised, streamlined responsibilities. Content Moderation policy reflects this narrowing of procedural requirements, focusing on ongoing monitoring and enforcement rather than imposed remediation timelines or penalties.
- # These updates increase Merchant and Acquirer accountability and strengthen monitoring of Brand Integrity risks associated with BRAM content.
- # Removed previously outdated Merchant registration and MCC/TCC-based identification specifics no longer mandated.
+ # Updated to incorporate Mastercard SPME §8.9.1 changes requiring Acquirers to ensure MMSPs are Mastercard-approved for BRAM monitoring and/or Merchant Transaction laundering detection before registration.
+ # This refinement enhances oversight of Merchant Monitoring Program participants by specifying MMSP approval prerequisites.
+ # Previous procedural details on BRAM monitoring and reporting remain, with no changes to core content moderation workflows or prohibited category definitions.
+ # Ensures consistency between policy and Mastercard mandates on ACS provider approval.
+ # Other procedural requirements as per SPME §9.4.1 and §10.5 are maintained without amendment.

Content Moderation (BRAM Brand Integrity)

Mastercard's Business Risk Assessment and Mitigation (BRAM) program prohibits acquirers from processing transactions for merchants engaged in activities violating Mastercard's acceptable use standards. Halyard Pay monitors merchant storefront content and transaction data to identify and remediate prohibited content such as adult content and content violating applicable laws or Mastercard standards.

Prohibited categories

Merchants facilitating counterfeit goods, illegal drugs, unlawful adult content, intellectual property infringement, or gambling services in restricted jurisdictions face immediate review and possible suspension.

Required actions

  1. Review merchant storefront content weekly via automated and manual methods.

  2. Flag merchants with content in prohibited categories for human review within one business day.

  3. Suspend processing if prohibited content is confirmed.

  4. Document findings and remediation steps.

  5. Ensure merchants comply with requirements to manage flagged adult content, including timely removal upon verified complaints, monthly reporting to Acquirers on flagged content and actions taken, and appeals processes as per Mastercard SPME §9.4.1.

  6. Support Acquirers in obtaining temporary access to restricted merchant content if needed.

Acquirer and MMSP Cooperation Requirements

Per Mastercard SPME §8.9.1, Halyard Pay as the Merchant Monitoring Service Provider (MMSP) requires the MMSP to be Mastercard-approved for BRAM monitoring and/or Merchant Transaction laundering detection services. Acquirers to must register the MMSP per Mastercard Rules 7.10, provide comprehensive merchant information (including legal and trade names, addresses, and URLs) needed for necessary for effective monitoring, and ensure persistent monitoring of each merchant's activity to detect potential violations related to BRAM content, products and services, and merchant transaction laundering.

Note: Mastercard SPME removed prior MCC and Transaction Category Code requirements and registration mandates for non-face-to-face adult content transactions but added detailed content management and reporting obligations under §9.4.1, which Halyard Pay integrates with emphasis on lawful, consented adult content and proactive merchant reporting.

The prior detailed remediation action plan requirements and penalties related to repeated Account Data Compromise (ADC) events under Mastercard SPME §10.5 have been removed, reducing procedural burdens and penalty assessments for Brand Integrity investigations.

Source authority: Mastercard SPME §§8.9.1, 9.4.1, 10.5.

policies/bram_response/policy.md — after applying change

BRAM Investigation Response

When Mastercard issues a Business Risk Assessment and Mitigation (BRAM) investigation

notice for one of our merchants, the acquirer must halt new merchant onboarding

immediately and submit an evidence package within one hundred eighty (180) days

of receipt of the notice.

Required actions

  1. Halt new merchant onboarding for the merchant under investigation.

  2. Compile and submit an evidence package containing:

  • Transaction monitoring records covering the prior 180 days.

  • A written corrective action plan.

  • Documentation of any police reports related to alleged coercion claims if applicable.

  1. Notify the Halyard Pay Compliance lead within 24 hours of receipt.

Failure to submit a complete response by the deadline will be considered a violation of Mastercard Rules section 3.9, resulting in escalating Category C noncompliance assessments until compliance is met. Additional assessments may occur for other Standards violations revealed during the BRAM investigation. Mastercard may grant extensions if the acquirer confirms cessation of violating activities.

Additional Considerations for Coercion Claims

When allegations of coerced Transactions arise, note that Mastercard may extend the usual 120-day

investigation period at its discretion. At least one claim must include a police report from the Cardholder.

Transactions reported as Lost or Stolen Fraud (fraud type codes 00 or 01) are subject to investigation,

though Mastercard may consider other fraud codes. Mastercard will notify issuers with Transactions at the

merchant within the investigation period to prompt claim submissions.

Use of Mastercard-Approved MMSPs for Merchant Monitoring

Acquirers participating in the Merchant Monitoring Program must confirm that the Merchant Monitoring Service Provider (MMSP) they engage is expressly approved by Mastercard to conduct BRAM monitoring and/or Merchant Transaction laundering detection services. The MMSP must be registered as a Service Provider, and all necessary merchant information and data must be submitted to the MMSP to facilitate effective monitoring. This ensures compliance with Mastercard Rules Section 7.10 and reinforces the obligation to work with authorized providers for monitoring merchant activities relevant to BRAM investigations.

## Mastercard's Authority and Customer Appeal Rights on ADC Financial Responsibility Determinations

Mastercard retains exclusive authority to determine the occurrence, scope, and financial responsibility for Account Data Compromise (ADC) Events or Potential ADC Events, including whether to consolidate related incidents. Once Mastercard notifies a responsible Customer of the financial responsibility amount, the Customer has thirty (30) calendar days to submit a written appeal with supporting documentation, specifically contending that Mastercard's determination was not according to the Standards. Mastercard charges a non-refundable USD 5,000 fee to review such appeals. Appeals that are untimely or do not meet criteria will not be considered, and Mastercard's decisions on appeals are final without further internal review. Customers remain obligated to provide ongoing information throughout the investigation and failure to submit required documentation in a timely manner may result in such documents being excluded from the appeal consideration. This process safeguards the integrity and finality of Mastercards’ ADC financial responsibility determinations.

Source authority: Mastercard SPME �8.6.2, �10.2, 8.6.2, 10.2, 10.7, 12.0, and section 3.9.3.9; 8.9.1.

policies/content_moderation/policy.md — after applying change

Content Moderation (BRAM Brand Integrity)

Mastercard's Business Risk Assessment and Mitigation (BRAM) program prohibits acquirers from processing transactions for merchants engaged in activities violating Mastercard's acceptable use standards. Halyard Pay monitors merchant storefront content and transaction data to identify and remediate prohibited content such as adult content and content violating applicable laws or Mastercard standards.

Prohibited categories

Merchants facilitating counterfeit goods, illegal drugs, unlawful adult content, intellectual property infringement, or gambling services in restricted jurisdictions face immediate review and possible suspension.

Required actions

  1. Review merchant storefront content weekly via automated and manual methods.

  2. Flag merchants with content in prohibited categories for human review within one business day.

  3. Suspend processing if prohibited content is confirmed.

  4. Document findings and remediation steps.

  5. Ensure merchants comply with requirements to manage flagged adult content, including timely removal upon verified complaints, monthly reporting to Acquirers on flagged content and actions taken, and appeals processes as per Mastercard SPME §9.4.1.

  6. Support Acquirers in obtaining temporary access to restricted merchant content if needed.

Acquirer and MMSP Cooperation Requirements

Per Mastercard SPME §8.9.1, Halyard Pay as the Merchant Monitoring Service Provider (MMSP) requires the MMSP to be Mastercard-approved for BRAM monitoring and/or Merchant Transaction laundering detection services. Acquirers to must register the MMSP per Mastercard Rules 7.10, provide comprehensive merchant information (including legal and trade names, addresses, and URLs) needed for necessary for effective monitoring, and ensure persistent monitoring of each merchant's activity to detect potential violations related to BRAM content, products and services, and merchant transaction laundering.

Note: Mastercard SPME removed prior MCC and Transaction Category Code requirements and registration mandates for non-face-to-face adult content transactions but added detailed content management and reporting obligations under §9.4.1, which Halyard Pay integrates with emphasis on lawful, consented adult content and proactive merchant reporting.

The prior detailed remediation action plan requirements and penalties related to repeated Account Data Compromise (ADC) events under Mastercard SPME §10.5 have been removed, reducing procedural burdens and penalty assessments for Brand Integrity investigations.

Source authority: Mastercard SPME §§8.9.1, 9.4.1, 10.5.

Source authority: Mastercard SPME §8.9.1.

--- a/policies/bram_response/rules.yaml
+++ b/policies/bram_response/rules.yaml
@@ -1,5 +1,5 @@
 program: BRAM
-authority: Mastercard SPME 8.6.2, 10.2, 10.7, 12
+authority: Mastercard SPME 8.6.2, 8.9.1, 10.2, 10.7, 12
 response_window_days: 180
 required_evidence:
   - transaction_monitoring_records
@@ -10,7 +10,7 @@
 internal_notification_hours: 24
 agent_owner: bram_response_agent
 
-# Updated to incorporate Mastercard's new appeal process and fee for contesting financial responsibility for ADC Events as detailed in SPME §10.7.
-# Clarifies that appeals must be timely, substantiated with particularized basis, and accompanied by a non-refundable fee, impacting procedural guidance for BRAM responses.
-# Maintains existing police report requirement and escalation procedures for noncompliance per SPME 8.6.2 and 12.
-# Allows for potential additional time granted by Mastercard upon Acquirer's confirmation of cessation of violating activity.
+# Added requirement that Acquirers must confirm that the Merchant Monitoring Service Provider (MMSP) is Mastercard-approved for BRAM monitoring, as specified in SPME §8.9.1.
+# This change strengthens compliance by ensuring only authorized service providers participate in merchant monitoring.
+# The police report mandate and response escalation remain per SPME §§8.6.2, 10.7, and 12.
+# Clarification and procedural adherence to appeal with fee under SPME §10.7 are retained unchanged.

--- a/policies/bram_response/policy.md
+++ b/policies/bram_response/policy.md
@@ -24,8 +24,12 @@
 though Mastercard may consider other fraud codes. Mastercard will notify issuers with Transactions at the
 merchant within the investigation period to prompt claim submissions.
 
+## Use of Mastercard-Approved MMSPs for Merchant Monitoring
+
+Acquirers participating in the Merchant Monitoring Program must confirm that the Merchant Monitoring Service Provider (MMSP) they engage is expressly approved by Mastercard to conduct BRAM monitoring and/or Merchant Transaction laundering detection services. The MMSP must be registered as a Service Provider, and all necessary merchant information and data must be submitted to the MMSP to facilitate effective monitoring. This ensures compliance with Mastercard Rules Section 7.10 and reinforces the obligation to work with authorized providers for monitoring merchant activities relevant to BRAM investigations.
+
 ## Mastercard's Authority and Customer Appeal Rights on ADC Financial Responsibility Determinations
 
 Mastercard retains exclusive authority to determine the occurrence, scope, and financial responsibility for Account Data Compromise (ADC) Events or Potential ADC Events, including whether to consolidate related incidents. Once Mastercard notifies a responsible Customer of the financial responsibility amount, the Customer has thirty (30) calendar days to submit a written appeal with supporting documentation, specifically contending that Mastercard's determination was not according to the Standards. Mastercard charges a non-refundable USD 5,000 fee to review such appeals. Appeals that are untimely or do not meet criteria will not be considered, and Mastercard's decisions on appeals are final without further internal review. Customers remain obligated to provide ongoing information throughout the investigation and failure to submit required documentation in a timely manner may result in such documents being excluded from the appeal consideration. This process safeguards the integrity and finality of Mastercards’ ADC financial responsibility determinations.
 
-Source authority: Mastercard SPME 8.6.2, 10.2, 10.7, 12.0, and section 3.9.+Source authority: Mastercard SPME 8.6.2, 10.2, 10.7, 12.0, and section 3.9; 8.9.1.
--- a/policies/content_moderation/rules.yaml
+++ b/policies/content_moderation/rules.yaml
@@ -12,8 +12,8 @@
 case_documentation_required: true
 agent_owner: content_mod_agent
 
-# Updated to reflect Mastercard SPME §9.4.1 enhancements requiring Merchants to manage flagged adult content with timely removals, provide monthly reports to Acquirers (and Mastercard on request), and maintain appeal processes.
-# Added Mastercard SPME §8.9.1 obligations for Acquirers to register MMSP as service providers and provide detailed Merchant data for continuous monitoring focused on BRAM content violations.
-# Removed detailed remediation action plan and repeated ADC event penalty provisions from Mastercard SPME §10.5 to align with the revised, streamlined responsibilities. Content Moderation policy reflects this narrowing of procedural requirements, focusing on ongoing monitoring and enforcement rather than imposed remediation timelines or penalties.
-# These updates increase Merchant and Acquirer accountability and strengthen monitoring of Brand Integrity risks associated with BRAM content.
-# Removed previously outdated Merchant registration and MCC/TCC-based identification specifics no longer mandated.
+# Updated to incorporate Mastercard SPME §8.9.1 changes requiring Acquirers to ensure MMSPs are Mastercard-approved for BRAM monitoring and/or Merchant Transaction laundering detection before registration.
+# This refinement enhances oversight of Merchant Monitoring Program participants by specifying MMSP approval prerequisites.
+# Previous procedural details on BRAM monitoring and reporting remain, with no changes to core content moderation workflows or prohibited category definitions.
+# Ensures consistency between policy and Mastercard mandates on ACS provider approval.
+# Other procedural requirements as per SPME §9.4.1 and §10.5 are maintained without amendment.

--- a/policies/content_moderation/policy.md
+++ b/policies/content_moderation/policy.md
@@ -17,10 +17,10 @@
 
 ## Acquirer and MMSP Cooperation Requirements
 
-Per Mastercard SPME §8.9.1, Halyard Pay as the Merchant Monitoring Service Provider (MMSP) requires Acquirers to register the MMSP per Mastercard Rules 7.10, provide comprehensive merchant information (including legal and trade names, addresses, and URLs) needed for monitoring, and ensure persistent monitoring of each merchant's activity to detect potential violations related to BRAM content, products and services, and merchant transaction laundering.
+Per Mastercard SPME §8.9.1, Halyard Pay as the Merchant Monitoring Service Provider (MMSP) requires the MMSP to be Mastercard-approved for BRAM monitoring and/or Merchant Transaction laundering detection services. Acquirers must register the MMSP per Mastercard Rules 7.10, provide comprehensive merchant information (including legal and trade names, addresses, and URLs) necessary for effective monitoring, and ensure persistent monitoring of each merchant's activity to detect potential violations related to BRAM content, products and services, and merchant transaction laundering.
 
 Note: Mastercard SPME removed prior MCC and Transaction Category Code requirements and registration mandates for non-face-to-face adult content transactions but added detailed content management and reporting obligations under §9.4.1, which Halyard Pay integrates with emphasis on lawful, consented adult content and proactive merchant reporting.
 
 The prior detailed remediation action plan requirements and penalties related to repeated Account Data Compromise (ADC) events under Mastercard SPME §10.5 have been removed, reducing procedural burdens and penalty assessments for Brand Integrity investigations.
 
-Source authority: Mastercard SPME §§8.9.1, 9.4.1, 10.5.+Source authority: Mastercard SPME §§8.9.1, 9.4.1, 10.5.