Mastercard SPME release
Jun 2022 → May 2023
4 breaking and 44 substantive revisions proposed, affecting 7 policies.
breaking
4 revisions
Mastercard Counterfeit Card Fraud Loss Control Standards
Section 6.3, outlining Mastercard's standards for countering counterfeit card fraud and related issuer/acquirer obligations, was completely removed from the documentation. This section mandated issuers and acquirers to implement specific fraud loss controls and security feature usage.
Counterfeit Card Notification
The entire section on Counterfeit Card Notification, including details on Acquirer counterfeit volume ratio (ACVR) monitoring, liability thresholds, and relief criteria, has been removed from the manual.
Merchant Registration Fees and Noncompliance Assessments
The entire paragraph regarding fraud deterrent measures and acquirer responsibilities was removed from the section.
Non-face-to-face Adult Content and Services Merchants
The section defining non-face-to-face adult content transactions and Acquirer obligations to identify these using specific MCC and TCC codes, as well as the requirement for Merchant registration with Mastercard, has been removed entirely.
substantive
44 revisions
Assessments for PCI Violations in Connection with ADC Events
The changes update timelines and compliance requirements for Terminal Servicers after an ADC Event. Specifically, PCI DSS revalidation is extended from 60 to 90 days post-investigation, and an additional requirement for compliance with the DESV appendix within 12 months is added, strengthening ongoing security obligations.
System Features
The updated section removes references to associate business owners and Service Provider names, limits information to principal owners only, and adds a requirement for the inquiring Acquirer to decide on further investigation or measures after accessing MATCH data.
MATCH Standards
The updated rules now mandate all Acquirers globally to use MATCH, encompassing both adding terminated Merchants under certain conditions and querying the MATCH database. Additionally, Acquirers are charged an annual usage fee and per inquiry fees. This replaces the prior guidance cautioning against using MATCH for minor discretionary issues and clarifies obligations for compliance.
Certification
The revised section removes the requirement for Acquirer MATCH certification and clarifies that failure to enter a Merchant into MATCH can result in noncompliance assessments and unfavorable compliance rulings by subsequent Acquirers.
MATCH Record Retention
The update changes record retention rules by requiring Acquirers to keep all MATCH records related to Merchants, Sponsored Merchants, or ATM owners for at least two years after their respective agreements end, whereas previously only retention and easy retrieval were recommended. The automatic five-year purge by Mastercard remains unchanged.
Merchant Removal from MATCH
The updated section adds specific reasons Mastercard may remove a Merchant listing from MATCH, including when the Acquirer reports an error in adding the Merchant or confirms PCI DSS compliance for a reason code 12 listing, requiring a written removal request on the Acquirer's letterhead.
MATCH Reason Codes
The MATCH Reason Codes table was updated to include detailed thresholds for chargeback and fraud rates, specify American Express thresholds for certain merchants, and add clarifications on laundering and bankruptcy reasons. The timing of the manual changed from 2022 to 2023. These updates refine the criteria for listing merchants on MATCH.
Mastercard Site Data Protection (SDP) Program
The update adds 'Merchant Payment Gateways (MPGs)' to the list of entities classified as Service Providers under the SDP Program, making them subject to the same compliance requirements as other Service Providers.
SDP Program Noncompliance Assessments
The section was significantly reduced, removing detailed forensic investigation and compliance evidence submission requirements. It now focuses on consequences such as listing removal or customer termination for noncompliance, referencing Mastercard Rules for specific enforcement actions and penalties related to late or missing compliance reports.
Mandatory Compliance Requirements for Compromised Entities
The updated rule states that Service Providers failing compliance will be automatically removed from the Mastercard SDP Compliant Registered Service Provider List and can be reinstated only after revalidating PCI DSS compliance and demonstrating adherence to the DESV appendix within 12 months.
Global Vendor Certification Program
The requirement for an on-site audit for vendor certification was changed to a security assessment conducted approximately every 12 months. References to vendor agreements and contact info for GVCP were removed.
Additional Card Production Requirements
The updated section adds requirements for card count verification by opening and auditing sealed cartons, allowing the use of card counts on cartons. It also mandates reporting any suspected or confirmed loss/theft of cards within 24 hours to Mastercard, with specified detailed information. Other disposal requirements remain unchanged.
PIN Entry Devices (PEDs) and Encrypting PIN Pads (EPPs)
The updated rules clarify that devices with expired PCI PTS approvals must be tracked in inventory and that device management systems must ensure receipt of security patches and physical management, such as device listing and tampering checks.
Use of a Vendor
The new version expands rules on Card-not-present Transactions, detailing when CVC 2 data collection is not required, including valid AAV from EMV 3DS, recurring payments with Identity Check Insights, credential-on-file, commercial Card Virtual Accounts, and Click-To-Pay transactions. Issuers must decline POS transactions if CVC 2 mismatches for mail, phone, or e-commerce orders.
Acquirer Requirements for CVC 2
The new version adds a requirement that Acquirers must monitor their Merchants and take action if a Merchant exceeds 100 gross basis points in fraudulent Card-not-present transactions for two consecutive months, a new threshold-based fraud control obligation not present in the prior version.
Additional Service Code Information
The chapter title and scope have been broadened to include Multi-Factor Authentication (MFA) Methods for Remote Commerce Token Transactions, extending beyond just PIN use. The wording now addresses Customers broadly rather than only Issuers and Acquirers, reflecting an expanded focus on authentication methods in the security standards.
Multi-Factor Authentication Methods for Remote Commerce
The section adds guidelines allowing implementing cardholder authentication technologies for remote commerce using two or more factors from different categories, subject to regulatory approval and compliance with applicable laws.
Security Evaluation of Multi-Factor Authentication Methods
Added a new requirement stating that in the EEA, San Marino, UK, and Gibraltar, Multi-Factor Authentication methods must comply with audit requirements from PSD2 RTS on Strong Customer Authentication and UK Technical Standards on SCA, with assurance levels affecting issuer reliance on fraud prevention.
Persistent Authentication
New detailed requirements for implementing Persistent Authentication in IoT devices were added, including Mastercard and regulatory approvals, testing and certification, use of inherence factors, a 3-second disable window, explicit cardholder consent, and a maximum 24-hour duration before re-authentication is required.
Prolonged Authentication
This added section defines conditions for Prolonged Authentication, requiring initial MFA, explicit cardholder consent, one authentication factor for each transaction, and a maximum authentication open period of five continuous minutes to allow transactions without repeated MFA.
Use of a Vendor
New requirement mandates that any agreement with a vendor providing Multi-Factor Authentication services must explicitly include the vendor's agreement to protect personal information and comply with all applicable standards.
Entry control
The text now specifies that technical and organizational measures like logging, reporting, audit trails, and documentation are used to monitor data entry, changes, or removal in data processing systems, replacing a vague statement about developing risk information for merchant acquiring risk assessment.
ATM Card Retention
New requirements specify that ATM card retention must occur only upon issuer's command, with exceptions for terminal malfunctions or cardholder errors. If unclear within 2 business days, the card is presumed retained by issuer command. Acquirers must honor card capture commands from any issuer and provide completion messages reflecting actions taken.
Control of instructions
The updated section now specifies technical and organizational measures required to ensure Personal Data processing aligns strictly with Controller Instructions, including contract clarity, formal commissioning via request forms, and Processor selection criteria, replacing a vague reference to automated decision-making or profiling.
Mastercard Fraud Loss Control Program Standards
The updated section replaces detailed specific requirements for monitoring merchant deposit volumes, transaction anomalies, fraud detection, and ongoing merchant reviews with new mandates including MDES for Merchants to use tokenized credentials, EMV Chip terminals with PIN, matching MCC codes between authentication and authorization, and a requirement to mitigate BIN attacks within 72 hours.
Acquirer Fraud Loss Control Programs
The updated rules require acquirers to generate daily fraud reports and real-time alerts, have fraud-trained staff capable of managing cases and writing detection rules, implement strong authentication controls, and be able to stop authorization flows during major fraud or emergencies. Alerts must be analyzed within 24 hours, with mitigation within 72 hours.
Availability control
The section was updated to detail specific technical and organizational measures needed to protect Personal Data from accidental destruction or loss, including backup procedures, disk mirroring, uninterruptible power supplies, remote storage, antivirus/firewall systems, and disaster recovery plans.
Screening New Merchants, Sponsored Merchants, and ATM Owners
The updated section adds requirements for acquirers to assign accurate MCCs and to identify and register entities handling Account data for negative option billing Merchants or Sponsored Merchants, while retaining the MATCH participation note with broadened scope to include Sponsored Merchants.
Required Screening Procedures
The updated section changes terminology from 'Submerchant' to 'Sponsored Merchant', expands location confirmation to include 'country or territory', adds requirements to verify merchant names to prevent impersonation and fraud, and clarifies controls for name consistency in authentication and authorization messages, strengthening screening procedures.
Assessments for Noncompliance with Screening Procedures
The update clarifies that Acquirers must regularly review e-commerce Merchants’ websites and activities to ensure compliance with standards, including Payment Facilitators doing the same for Sponsored Merchants. It adds specific circumstances requiring re-screening, such as ownership or location changes, activity changes, or suspected violations, and recommends annual screening for certain high-risk merchant categories.
Ongoing Monitoring
The term 'Submerchant' has been replaced with 'Sponsored Merchant' to clarify the entities monitored, and the detailed requirements around monitoring e-commerce merchant websites and the best practice recommendation have been removed, streamlining the ongoing monitoring obligations.
Merchant Education
The updated section adds a requirement for Acquirers to ensure that Payment Facilitators provide adequate education activities to each of their Sponsored Merchants, emphasizing compliance with data storage and encryption standards.
Separation control
The section on separation control was expanded to specify technical and organizational measures for processing personal data separately based on different purposes. It added examples such as separation of databases, limiting internal client use, segregating functions, and procedures for data storage, modification, deletion, and transmission.
Issuer Monitoring Program (IMP)
The section describing the Issuer Monitoring Program (IMP), which set standards for issuer chargeback behavior and encouraged ongoing monitoring of fraud and chargeback performance, has been removed entirely.
Coercion Program
The updated text replaces detailed reporting and procedural requirements for coercion claims with a simplified definition of coercion involving threats or harm to the cardholder or their family, removing specific mandates about police reports, fraud codes, and issuer notifications previously required.
Issuer Submissions
The updated section removes details about submission methods and introduces a 10-calendar-day timeframe for Issuers to contact the Cardholder to provide specific documentation regarding coercion claims.
Investigation Process
The investigation process for coercion claims now allows Mastercard discretion to extend the 120-day claim period and requires at least one claim to include a police report. Additionally, transactions must be reported with specific fraud codes, though Mastercard may consider others at its discretion. Mastercard will notify issuers with transactions during the inquiry period.
Chargeback Responsibility
The updated text specifies exact chargeback reason codes (4849 for Dual Message System and 49 for Single Message System Debit Mastercard transactions) to be used when disputing confirmed coerced transactions, enhancing clarity on processing these chargebacks.
Assessments, Recovery Amounts, and Fees
This update expands the Acquirer Non-Performance Assessments by adding penalties for third and subsequent violations within twelve months, significantly increasing maximum fees. It also introduces mitigation guidelines for assessments if merchants are recoded within specified timeframes. The Issuer Interchange Recovery section was expanded with more detail on calculation and processes for crediting issuers and debiting acquirers.
General Monitoring Requirements
The updated section adds specific guidance that merchants should use temporary BIN blocking when fraud is evident and requires acquirers to ensure merchants comply with the fraud control standards in Chapter 6, extending current monitoring obligations to include these additional fraud control measures.
Non–face-to-face Gambling Merchants
The updated rules require Acquirers to obtain and submit a legal opinion to Mastercard confirming that both the merchant and their cardholders comply with all applicable gambling laws, rather than just keeping information current. This legal opinion must be acceptable to Mastercard.
Pharmaceutical and Tobacco Product Merchants
The updated rules require Acquirers to register merchants selling pharmaceuticals or tobacco products non-face-to-face with Mastercard, using specific MCC and TCC codes for transaction identification. Acquirers must verify and annually confirm legal compliance of these merchants, maintain documentation, and provide it to Mastercard upon request, adding more detailed obligations than before.
High-Risk Cyberlocker Merchants
The updated rules specify that Acquirers must identify all non-face-to-face cyberlocker transactions using MCC 4816 and TCC T, verify legal compliance of merchants with documented evidence at registration, maintain this verification while acquiring transactions, and confirm compliance annually. Additionally, Acquirers must provide documentation promptly to Mastercard upon request.
Recreational Cannabis Merchants (Canada Region Only)
The updated section introduces new requirements for acquirers managing recreational cannabis merchants in Canada. Acquirers must obtain and retain provincial retail licenses, promptly provide documentation to Mastercard upon request, notify Mastercard within 10 business days of any license changes, and cease Mastercard payments acceptance if a merchant loses licensing.