Mastercard SPME §9.4.8 · Sep 2024 → May 2025

High-Risk Securities Merchants

substantive

The updated rules add requirements for Acquirers to obtain and provide updated licenses before expiration and to cease processing if licenses are not updated. It also mandates obtaining a reasoned legal opinion detailing laws applicable to Merchants and Cardholders, ensuring full compliance with relevant laws.

Sources Mastercard SPME · Sep 2024 · page 112 PDF Mastercard SPME · May 2025 · page 116 PDF KYB Acquirer current
Also in §9.x this release substantive §9.2 General Registration Requirements substantive §9.3 General Monitoring Requirements substantive §9.4.1 Non-face-to-face Adult Content and Services Merchants substantive §9.4.2 Non-face-to-face Gambling Merchants substantive §9.4.3 Pharmaceutical and Tobacco Product Merchants substantive §9.4.4 Government-owned Lottery Merchants substantive §9.4.5 Skill Games Merchants substantive §9.4.7 Recreational Cannabis Merchants (Canada Region Only) substantive §9.4.9 Cryptocurrency Merchants
Why these edits? The updated rules in section 9.4.8 introduce new obligations for Acquirers to obtain and provide updated licenses before expiration and to cease processing if licenses are not updated, expanding on the existing requirements for maintaining lawful status and permits. These changes impact Acquirer Know Your Business (KYB) Obligations, particularly related to ongoing compliance and documentation for high-risk securities merchants.
Mastercard SPME §9.4.8
Security Rules and Procedures—Merchant Edition • 6 August 2024 11 February 2025 – a copy of the Merchant’s registration, where required under applicable law, with a licensed exchange or licensed trading platform; and – any law applicable to the Merchant that permits such high-risk trading activity. The Acquirer must provide an updated license(s) to Mastercard prior to expiration. If an Acquirer is unable to obtain an updated license, then the Acquirer must cease processing applicable high-risk securities Transactions from such Merchant until the Acquirer is able to provide an updated license to Mastercard. 2. Legal opinion. The Acquirer must obtain a reasoned legal opinion, addressed to the Acquirer, from a reputable law firm located in each country where high-risk trading activity as described in this section will occur or be offered to Cardholders. The legal opinion must: – identify all relevant trading laws and other laws applicable to the Merchant; – identify all relevant trading laws and other laws applicable to Cardholders that may transact with the Merchant; and – demonstrate that the Merchant’s and Cardholders’ trading activities comply at all times with any laws identified above. The legal opinion must be acceptable to Mastercard. Further, the Acquirer shall ensure that: – the Merchant properly maintains its lawful status in any jurisdiction where such Merchant engages in high-risk trading activities as described in this section; and – any relevant permits remain unexpired. 3. Effective controls. The Acquirer must obtain certification from a qualified independent third party demonstrating that the Merchant’s systems for operating its high-risk securities business: – include effective age and location verification; and – are reasonably designed to ensure that the Merchant’s high-risk securities business will remain within legal limits (including in connection with cross-border Transactions). 4. Notification of changes. The Acquirer must certify that the Acquirer will notify Mastercard of any changes to the information that the Acquirer has provided to Mastercard, including changes in applicable law, Merchant activities, and Merchant systems. Such notification shall include any revisions or additions to the information provided to Mastercard (for example, legal opinion, third-party certification) to make the information current and complete. Such notification is required within ten (10) days of any such change. 5. Acceptance of responsibilities. The Acquirer must specifically affirm that it will not submit restricted Transactions from the Merchant for authorization. If a Merchant’s non-face-to-face high-risk trading activities are regulated as gambling in any jurisdiction, then the Acquirer must register such Merchant as a non-face-to-face gambling Merchant with Mastercard as described in section 9.2 and section 9.4.2 of this manual.
Halyard Pay · 2 files
program: Acquirer KYB
- authority: Mastercard SPME 2.1, 11.2.3, 11.2.6, 11.7.1, 2.4.1
+ authority: Mastercard SPME 2.1, 9.4.8, 11.2.3, 11.2.6, 11.7.1, 2.4.1
required_documents:
- incorporation
- beneficial_ownership
- aml_screen
- license_verification
min_review_cycle_days: 365
suspension_trigger: document_collection_failure
record_retention_years: 7
aml_watchlist_sources:
- ofac_sdn
- eu_consolidated
agent_owner: kyb_agent
# Acquirers must perform a MATCH inquiry prior to entering into any Merchant Agreement or enabling a Merchant to accept transactions, as detailed in Mastercard SPME §11.2.3. This inquiry must be conducted using the correct Member ID/ICA Number associated with the Merchant to ensure proper compliance reporting.
# Failure to adhere to these requirements may result in noncompliance assessments.
# The Acquirer is also required to retain all MATCH records related to any Merchant, Sponsored Merchant, or ATM owner for a minimum of two years post-agreement termination, as per Mastercard SPME §11.2.6.
# Additionally, Acquirers that store, transmit, or process personal data of residents in the European Economic Area (EEA), the UK, or Switzerland—or are otherwise subject to EU Data Protection Law—must comply with the standards specified in Appendix D concerning MATCH activity within the Europe Region, consistent with Mastercard SPME §11.7.1.
- # Per the updated Mastercard SPME §2.4.1, Acquirers are required to properly manage their PIN Entry Device (PED) and Encrypting PIN Pad (EPP) inventories. This includes maintaining an up-to-date inventory of device types and locations, ensuring devices receive timely software security patches distributed by vendors, and conducting regular physical inspections by trained staff to detect tampering or substitution.
- # Acquirers must also manage devices whose PCI PTS approvals have expired by moving them from approved lists to appropriate expired approval lists and ceasing their use for processing transactions if Mastercard issues a sunset date for specific device models.
- # These controls strengthen the security posture of Acquirers in line with Mastercard's risk management directives, helping to prevent device-related compromises.
+ # Per Mastercard SPME §2.4.1, Acquirers must maintain accurate PIN Entry Device (PED) and Encrypting PIN Pad (EPP) inventories, ensure timely application of vendor security patches, conduct regular physical inspections for tampering, and appropriately manage devices with expired PCI PTS approvals.
+ # In accordance with the updated Mastercard SPME §9.4.8, Acquirers handling high-risk securities merchants must obtain and maintain current merchant licenses and legal opinions evidencing compliance with relevant laws; Acquirers are required to provide updated licenses to Mastercard prior to expiration and must cease processing high-risk securities transactions if updated licenses are not obtained.
+ # These procedures enhance ongoing due diligence and compliance monitoring obligations for high-risk securities merchants.

Acquirer KYB (Know Your Business) Obligations

Acquirers processing transactions on the Mastercard network must perform Know Your Business (KYB) due diligence on merchants prior to onboarding and on a recurring basis. Halyard Pay is responsible for collecting and verifying required documentation to confirm business legitimacy, vet beneficial ownership, and satisfy anti-money laundering (AML) screening.

When this policy applies

This policy applies at initial merchant onboarding and during periodic re-verification reviews. Merchants that do not provide required documentation within set timelines must be suspended until compliance is restored.

Required actions

  1. Collect all KYB documentation needed at onboarding.

  2. Conduct AML screening against applicable watchlists before approval.

  3. Verify business licenses for regulated merchant categories. categories, including obtaining and maintaining all applicable licenses and permits for high-risk securities merchants as required by law.

  4. Ensure that for high-risk securities merchants, updated licenses are obtained prior to expiration and provided to Mastercard; cease processing transactions if updated licenses cannot be obtained until compliance is restored.

5. Schedule full re-verification at least annually.

5. 6. Document verification outcomes and maintain records for audit.

6. 7. Retain MATCH system records related to Merchants, Sponsored Merchants, or ATM owners for at least two years after contract termination or expiration, to meet Mastercard record retention requirements.

7. 8. Before Merchant Agreement execution or enabling transactions, conduct a MATCH inquiry using Halyard Pay's Member ID/ICA Number to ensure compliance; failure may lead to Mastercard assessments.

8. 9. For merchants whose personal data pertains to residents of the European Economic Area, the UK, or Switzerland, Halyard Pay must comply with EU Data Protection Laws as specified in Appendix D of the Mastercard SPME manual concerning MATCH activities in the Europe Region.

9. 10. Maintain proper management of PED and EPP device inventories, ensuring devices receive timely software security patches and are physically tracked and inspected regularly for tampering or substitution. This includes keeping an accurate inventory of device types and locations, and training staff to conduct these inspections. Any device model sunset announcements by Mastercard must be adhered to, including ceasing use of such devices by the specified deadline.

Source authority: Mastercard SPME §§2.1, 2.4.1, 7.1, 9.4.8, 11.2.3, 11.2.6, 11.7.1.

policies/kyb_acquirer/policy.md — after applying change

Acquirer KYB (Know Your Business) Obligations

Acquirers processing transactions on the Mastercard network must perform Know Your Business (KYB) due diligence on merchants prior to onboarding and on a recurring basis. Halyard Pay is responsible for collecting and verifying required documentation to confirm business legitimacy, vet beneficial ownership, and satisfy anti-money laundering (AML) screening.

When this policy applies

This policy applies at initial merchant onboarding and during periodic re-verification reviews. Merchants that do not provide required documentation within set timelines must be suspended until compliance is restored.

Required actions

  1. Collect all KYB documentation needed at onboarding.

  2. Conduct AML screening against applicable watchlists before approval.

  3. Verify business licenses for regulated merchant categories. categories, including obtaining and maintaining all applicable licenses and permits for high-risk securities merchants as required by law.

  4. Ensure that for high-risk securities merchants, updated licenses are obtained prior to expiration and provided to Mastercard; cease processing transactions if updated licenses cannot be obtained until compliance is restored.

5. Schedule full re-verification at least annually.

5. 6. Document verification outcomes and maintain records for audit.

6. 7. Retain MATCH system records related to Merchants, Sponsored Merchants, or ATM owners for at least two years after contract termination or expiration, to meet Mastercard record retention requirements.

7. 8. Before Merchant Agreement execution or enabling transactions, conduct a MATCH inquiry using Halyard Pay's Member ID/ICA Number to ensure compliance; failure may lead to Mastercard assessments.

8. 9. For merchants whose personal data pertains to residents of the European Economic Area, the UK, or Switzerland, Halyard Pay must comply with EU Data Protection Laws as specified in Appendix D of the Mastercard SPME manual concerning MATCH activities in the Europe Region.

9. 10. Maintain proper management of PED and EPP device inventories, ensuring devices receive timely software security patches and are physically tracked and inspected regularly for tampering or substitution. This includes keeping an accurate inventory of device types and locations, and training staff to conduct these inspections. Any device model sunset announcements by Mastercard must be adhered to, including ceasing use of such devices by the specified deadline.

Source authority: Mastercard SPME §§2.1, 2.4.1, 7.1, 9.4.8, 11.2.3, 11.2.6, 11.7.1.

Source authority: Mastercard SPME §9.4.8.

--- a/policies/kyb_acquirer/rules.yaml
+++ b/policies/kyb_acquirer/rules.yaml
@@ -1,5 +1,5 @@
 program: Acquirer KYB
-authority: Mastercard SPME 2.1, 11.2.3, 11.2.6, 11.7.1, 2.4.1
+authority: Mastercard SPME 2.1, 9.4.8, 11.2.3, 11.2.6, 11.7.1, 2.4.1
 required_documents:
   - incorporation
   - beneficial_ownership
@@ -16,6 +16,6 @@
 # Failure to adhere to these requirements may result in noncompliance assessments.
 # The Acquirer is also required to retain all MATCH records related to any Merchant, Sponsored Merchant, or ATM owner for a minimum of two years post-agreement termination, as per Mastercard SPME §11.2.6.
 # Additionally, Acquirers that store, transmit, or process personal data of residents in the European Economic Area (EEA), the UK, or Switzerland—or are otherwise subject to EU Data Protection Law—must comply with the standards specified in Appendix D concerning MATCH activity within the Europe Region, consistent with Mastercard SPME §11.7.1.
-# Per the updated Mastercard SPME §2.4.1, Acquirers are required to properly manage their PIN Entry Device (PED) and Encrypting PIN Pad (EPP) inventories. This includes maintaining an up-to-date inventory of device types and locations, ensuring devices receive timely software security patches distributed by vendors, and conducting regular physical inspections by trained staff to detect tampering or substitution.
-# Acquirers must also manage devices whose PCI PTS approvals have expired by moving them from approved lists to appropriate expired approval lists and ceasing their use for processing transactions if Mastercard issues a sunset date for specific device models.
-# These controls strengthen the security posture of Acquirers in line with Mastercard's risk management directives, helping to prevent device-related compromises.+# Per Mastercard SPME §2.4.1, Acquirers must maintain accurate PIN Entry Device (PED) and Encrypting PIN Pad (EPP) inventories, ensure timely application of vendor security patches, conduct regular physical inspections for tampering, and appropriately manage devices with expired PCI PTS approvals.
+# In accordance with the updated Mastercard SPME §9.4.8, Acquirers handling high-risk securities merchants must obtain and maintain current merchant licenses and legal opinions evidencing compliance with relevant laws; Acquirers are required to provide updated licenses to Mastercard prior to expiration and must cease processing high-risk securities transactions if updated licenses are not obtained.
+# These procedures enhance ongoing due diligence and compliance monitoring obligations for high-risk securities merchants.

--- a/policies/kyb_acquirer/policy.md
+++ b/policies/kyb_acquirer/policy.md
@@ -10,12 +10,13 @@
 
 1. Collect all KYB documentation needed at onboarding.
 2. Conduct AML screening against applicable watchlists before approval.
-3. Verify business licenses for regulated merchant categories.
-4. Schedule full re-verification at least annually.
-5. Document verification outcomes and maintain records for audit.
-6. Retain MATCH system records related to Merchants, Sponsored Merchants, or ATM owners for at least two years after contract termination or expiration, to meet Mastercard record retention requirements.
-7. Before Merchant Agreement execution or enabling transactions, conduct a MATCH inquiry using Halyard Pay's Member ID/ICA Number to ensure compliance; failure may lead to Mastercard assessments.
-8. For merchants whose personal data pertains to residents of the European Economic Area, the UK, or Switzerland, Halyard Pay must comply with EU Data Protection Laws as specified in Appendix D of the Mastercard SPME manual concerning MATCH activities in the Europe Region.
-9. Maintain proper management of PED and EPP device inventories, ensuring devices receive timely software security patches and are physically tracked and inspected regularly for tampering or substitution. This includes keeping an accurate inventory of device types and locations, and training staff to conduct these inspections. Any device model sunset announcements by Mastercard must be adhered to, including ceasing use of such devices by the specified deadline.
+3. Verify business licenses for regulated merchant categories, including obtaining and maintaining all applicable licenses and permits for high-risk securities merchants as required by law.
+4. Ensure that for high-risk securities merchants, updated licenses are obtained prior to expiration and provided to Mastercard; cease processing transactions if updated licenses cannot be obtained until compliance is restored.
+5. Schedule full re-verification at least annually.
+6. Document verification outcomes and maintain records for audit.
+7. Retain MATCH system records related to Merchants, Sponsored Merchants, or ATM owners for at least two years after contract termination or expiration, to meet Mastercard record retention requirements.
+8. Before Merchant Agreement execution or enabling transactions, conduct a MATCH inquiry using Halyard Pay's Member ID/ICA Number to ensure compliance; failure may lead to Mastercard assessments.
+9. For merchants whose personal data pertains to residents of the European Economic Area, the UK, or Switzerland, Halyard Pay must comply with EU Data Protection Laws as specified in Appendix D of the Mastercard SPME manual concerning MATCH activities in the Europe Region.
+10. Maintain proper management of PED and EPP device inventories, ensuring devices receive timely software security patches and are physically tracked and inspected regularly for tampering or substitution. This includes keeping an accurate inventory of device types and locations, and training staff to conduct these inspections. Any device model sunset announcements by Mastercard must be adhered to, including ceasing use of such devices by the specified deadline.
 
-Source authority: Mastercard SPME §§2.1, 2.4.1, 7.1, 11.2.3, 11.2.6, 11.7.1.
+Source authority: Mastercard SPME §§2.1, 2.4.1, 7.1, 9.4.8, 11.2.3, 11.2.6, 11.7.1.