Mastercard SPME release
Sep 2023 → Feb 2024
2 breaking and 31 substantive revisions proposed, affecting 6 policies.
breaking
2 revisions
Payment Card Industry (PCI) Security Standards
The entire detailed text about PCI Software Security Framework and compliance recommendations has been removed from the section, leaving only the general document header without content.
Chargeback Responsibility
The original specific instructions on reason codes for chargebacks related to coerced transactions have been completely removed and replaced with a generic statement about Interchange Recovery related to Brazil Domestic Transactions processed via GCMS, and a note on Mastercard's discretion over MCC Performance Program enforcement.
substantive
31 revisions
Data Protection
The compliance requirements for processing personal data have been expanded to explicitly include several specific programs: the MATCH system, the Excessive Chargeback Program, the Merchant Registration Program, and the Franchise Management Program, collectively called "Covered Programs."
Compliance with Privacy, Data Protection and Information Security Requirements
The section now explicitly requires the Corporation and Customers to comply with applicable data protection laws when processing personal data related to Covered Programs, introducing a clear legal compliance obligation where previously only general cybersecurity standards were mentioned.
If the Acquirer is currently participating in the Merchant Monitoring Program, and this
The section adds a requirement that if a violation was not reported by the Acquirer's MMSP, the Acquirer must provide an incident report to Mastercard Fraud Control Programs.
When to Add a Merchant to MATCH
The requirement now explicitly mandates Acquirers to add merchant information to MATCH within five calendar days if termination occurs and suspicious conditions exist, replacing a previous note about record retention and adding a compliance timeframe and conditions for updates.
Inquiring about a Merchant
The updated section introduces detailed procedures for removing a Merchant from MATCH reason code 12 (PCI DSS Noncompliance) listings. It requires Acquirers or the Merchant to submit a written request with specific business and owner information, along with attesting compliance confirmed by a certified forensic examiner's letter or certificate.
MATCH Reason Codes
The MATCH Reason Codes have been extensively revised to include new categories such as Account Data Compromise, Common Point of Purchase, Laundering, Excessive Chargebacks, and Excessive Fraud, with detailed thresholds for chargebacks and fraud ratios. Some previous codes were removed or restructured, adding specificity to reporting requirements.
Reason Codes for Merchants Listed by the Acquirer
The section's MATCH listing reason codes were completely replaced. Previous specific codes like Account Data Compromise and Excessive Chargebacks were removed, replaced with broader categories including Violation of Standards, Merchant Collusion, PCI Data Security Standard Noncompliance, Illegal Transactions, and Identity Theft.
Privacy and Data Protection
The section adds a new requirement that any Acquirer handling personal data of residents in the EEA, UK, or Switzerland, or subject to EU Data Protection Law, must comply with specific standards in Appendix D related to MATCH activity in Europe.
Any other information the Acquirer determines relevant to be considered.
The updated section states that failing to provide complete responses by deadlines is a violation punishable with escalating Category C noncompliance assessments, and possibly other assessments if further violations are found. Mastercard may allow more time if the Acquirer confirms the offending activity has stopped.
Customer Compliance Requirements
The updated section adds explicit obligations for Issuers to communicate SDP Program requirements to Level 1 and 2 Service Providers and validate their PCI DSS compliance by reviewing SAQs or ROCs. Issuers must also submit annual PCI compliance validation to Mastercard, and address non-compliance with an action plan. This was not previously required.
Service Provider Compliance Requirements
The update removes the transaction volume condition from the definition of Level 1 Service Providers, clarifying that certain service provider types are Level 1 regardless of volume. This change alters the scope of who qualifies as a Level 1 Service Provider, impacting validation requirements.
SDP Program Noncompliance Assessments
The section changed from describing forensic investigation response and PCI DSS compliance deadlines to detailing specific monetary penalties for failing to comply with the SDP Program by merchant or service provider level. It also added potential consequences like merchant termination and deregistration from MasterCard programs for noncompliance.
Persistent Authentication
The updated rules clarify that the IoT device must disable authentication within three seconds if the Cardholder is no longer authenticated, detected, or there is a significant detection change, enhancing security measures for Persistent Authentication in IoT devices.
Mastercard Fraud Loss Control Program Standards
The update refines fraud monitoring requirements, notably reducing the technical fallback rate threshold from 5% to 2% for merchant deposit monitoring, adds mandatory reversal of unauthorized refund transactions, and reclassifies some procedural recommendations. These changes strengthen fraud controls and verification processes without altering overall obligations drastically.
Questionable Merchant Audit Program (QMAP)
The criteria for identifying Questionable Merchants have been expanded to include specific rules for Brazil, requiring certain fraud thresholds and transaction types during a 120-day investigation period. Other original criteria remain, with some minor formatting and punctuation changes.
Mastercard Commencement of an Investigation
The section was overhauled: previously, issuers notified Mastercard about questionable merchants via a web form with detailed info. Now, Mastercard initiates investigations, notifying issuers with transaction details, requiring issuers to report fraud within 60 days. Different processes apply if issues involve bust-out accounts or not, with Brazil having a unique reporting rule.
of this manual, or
The section now specifies conditions under which Mastercard will handle issuer fraud recovery, including thresholds for reported fraudulent transaction volumes, recovery methods, and transaction types. It clarifies Mastercard's rights to request information and explains the financial process of debiting Acquirer accounts and crediting Issuer accounts for fraud recovery.
Mastercard Determination
The section changes from detailing Issuer fraud recovery conditions to outlining Mastercard's procedures for classifying and notifying about Questionable Merchants, including notifications, MATCH record updates, and Acquirer obligations upon Merchant termination for being a Questionable Merchant.
Fraud Recovery
The previous process of notifying issuers about partial recovery of losses from questionable merchants has been removed and replaced with a new rule allowing Mastercard to charge acquirers an audit fee of up to $2,500 per questionable merchant identification.
Coercion Program
The Coercion Program description was fully replaced with detailed procedural requirements, including evidence submission such as police reports and fraud reporting codes, and a process for notifying issuers to collect claims and affidavits within specified timeframes. This adds specific documentation and notification steps for handling coercion claims involving cardholders.
Issuer Submissions
The update clarifies submission methods for Cardholder coercion claims, differentiating processes pre- and post- January 1, 2022, shifting from email and web submissions to web form only, and explicitly requires police report inclusion if available, with detailed reasons if absent, plus maintaining other supporting documents.
Investigation Process
The updated section removes requirements about the police report submissions and the reporting of Transactions with specific fraud type codes related to alleged coercion claims, simplifying the criteria for Mastercard's investigation initiation.
Franchise Management Program (FMP) Questionnaire-based Review
The updated section introduces mandatory and conditional requirements for acquirers to have merchants complete a Coercion Program FMP questionnaire based on the number of coercion identifications within specified timeframes, and states that questionnaire responses may trigger an on-site review.
Definitions
The original MCC Performance Program definitions, including Case Scope Period and exclusions, were removed. They were replaced with detailed specifications regarding data elements such as Payment Facilitator ID, MCC in the message, Tax ID in Brazilian transactions, and Issuer explanations for MCC discrepancies.
Mastercard Notification to Acquirers
A new Issuer Filing Fee of BRL 25,000 per Merchant or relevant entity was introduced for unsubstantiated claims. Minor formatting changes and heading adjustments clarify billing for Acquirer Non-Performance Assessments and Issuer Interchange Recovery but do not change the substantive billing or assessment obligations.
Business Risk Assessment and Mitigation (BRAM) Program
A new section describes the BRAM Program, which investigates merchants potentially involved in illegal or brand-damaging transactions to protect Mastercard and its customers from fraud, regulatory, and legal risks. Mastercard collaborates with acquirers to stop violations and reduce future risk, enforcing specific Mastercard Rules related to brand integrity.
BRAM Investigation Process
This new section requires the Acquirer to provide Mastercard a detailed investigation report within two days for law enforcement or Mastercard-initiated cases, or five days for others, including remediation plans, merchant documentation, business overview, transaction data, service provider identity, MATCH system usage, and termination details.
Acquirer Response Requirements
A new requirement was added for acquirers' Managed Merchant Service Providers (MMSPs) to provide a report explaining why an incident was not identified and how the MMSP improved its services to prevent recurrence.
Noncompliance Assessment Mitigation
A new section requires Acquirers to have MMSPs report potential merchant violations within 5 business days, investigate and resolve issues within 15 calendar days, provide monthly reports on monitored merchants and violations, adhere to MATCH Standards, and respond to BRAM notifications with detailed incident reports explaining monitoring and detection efforts.
Merchant Monitoring Program (MMP)
Mastercard has introduced a new Merchant Monitoring Program encouraging customers to prevent BRAM violations and transaction laundering. Acquirers opting in must use approved Merchant Monitoring Service Providers (MMSPs), with Mastercard maintaining an approved vendors list and contact info for vendor approval.
MMP Participation Requirements
A new section was added specifying that Acquirers must register the MMSP as their Service Provider, submit all required Merchant information to the MMSP for monitoring, and ensure continuous monitoring of Merchant activity to detect violations related to BRAM content and transaction laundering.