Mastercard SPME release

Sep 2023 → Feb 2024

2 breaking and 31 substantive revisions proposed, affecting 6 policies.

33 of 33
Materiality
Policy
breaking 2 revisions
Payment Card Industry (PCI) Security Standards
The entire detailed text about PCI Software Security Framework and compliance recommendations has been removed from the section, leaving only the general document header without content.
SPME §2.1.1 KYB Acquirer ⚠ verify source
Chargeback Responsibility
The original specific instructions on reason codes for chargebacks related to coerced transactions have been completely removed and replaced with a generic statement about Interchange Recovery related to Brazil Domestic Transactions processed via GCMS, and a note on Mastercard's discretion over MCC Performance Program enforcement.
SPME §8.6.5 Chargeback Handling
substantive 31 revisions
Data Protection
The compliance requirements for processing personal data have been expanded to explicitly include several specific programs: the MATCH system, the Excessive Chargeback Program, the Merchant Registration Program, and the Franchise Management Program, collectively called "Covered Programs."
SPME §1.5 ECP Thresholds
Compliance with Privacy, Data Protection and Information Security Requirements
The section now explicitly requires the Corporation and Customers to comply with applicable data protection laws when processing personal data related to Covered Programs, introducing a clear legal compliance obligation where previously only general cybersecurity standards were mentioned.
SPME §1.5.1 KYB Acquirer
If the Acquirer is currently participating in the Merchant Monitoring Program, and this
The section adds a requirement that if a violation was not reported by the Acquirer's MMSP, the Acquirer must provide an incident report to Mastercard Fraud Control Programs.
SPME §11 Fraud Monitoring
When to Add a Merchant to MATCH
The requirement now explicitly mandates Acquirers to add merchant information to MATCH within five calendar days if termination occurs and suspicious conditions exist, replacing a previous note about record retention and adding a compliance timeframe and conditions for updates.
SPME §11.2.2 KYB Acquirer
Inquiring about a Merchant
The updated section introduces detailed procedures for removing a Merchant from MATCH reason code 12 (PCI DSS Noncompliance) listings. It requires Acquirers or the Merchant to submit a written request with specific business and owner information, along with attesting compliance confirmed by a certified forensic examiner's letter or certificate.
SPME §11.2.3 KYB Acquirer
MATCH Reason Codes
The MATCH Reason Codes have been extensively revised to include new categories such as Account Data Compromise, Common Point of Purchase, Laundering, Excessive Chargebacks, and Excessive Fraud, with detailed thresholds for chargebacks and fraud ratios. Some previous codes were removed or restructured, adding specificity to reporting requirements.
SPME §11.5 Chargeback HandlingECP Thresholds
Reason Codes for Merchants Listed by the Acquirer
The section's MATCH listing reason codes were completely replaced. Previous specific codes like Account Data Compromise and Excessive Chargebacks were removed, replaced with broader categories including Violation of Standards, Merchant Collusion, PCI Data Security Standard Noncompliance, Illegal Transactions, and Identity Theft.
SPME §11.5.1 ECP Thresholds
Privacy and Data Protection
The section adds a new requirement that any Acquirer handling personal data of residents in the EEA, UK, or Switzerland, or subject to EU Data Protection Law, must comply with specific standards in Appendix D related to MATCH activity in Europe.
SPME §11.7.1 KYB Acquirer
Any other information the Acquirer determines relevant to be considered.
The updated section states that failing to provide complete responses by deadlines is a violation punishable with escalating Category C noncompliance assessments, and possibly other assessments if further violations are found. Mastercard may allow more time if the Acquirer confirms the offending activity has stopped.
SPME §12 BRAM Response
Customer Compliance Requirements
The updated section adds explicit obligations for Issuers to communicate SDP Program requirements to Level 1 and 2 Service Providers and validate their PCI DSS compliance by reviewing SAQs or ROCs. Issuers must also submit annual PCI compliance validation to Mastercard, and address non-compliance with an action plan. This was not previously required.
SPME §2.2.1 KYB Acquirer
Service Provider Compliance Requirements
The update removes the transaction volume condition from the definition of Level 1 Service Providers, clarifying that certain service provider types are Level 1 regardless of volume. This change alters the scope of who qualifies as a Level 1 Service Provider, impacting validation requirements.
SPME §2.2.3 KYB Acquirer
SDP Program Noncompliance Assessments
The section changed from describing forensic investigation response and PCI DSS compliance deadlines to detailing specific monetary penalties for failing to comply with the SDP Program by merchant or service provider level. It also added potential consequences like merchant termination and deregistration from MasterCard programs for noncompliance.
SPME §2.2.5 KYB Acquirer
Persistent Authentication
The updated rules clarify that the IoT device must disable authentication within three seconds if the Cardholder is no longer authenticated, detected, or there is a significant detection change, enhancing security measures for Persistent Authentication in IoT devices.
SPME §4.10.3 Fraud Monitoring
Mastercard Fraud Loss Control Program Standards
The update refines fraud monitoring requirements, notably reducing the technical fallback rate threshold from 5% to 2% for merchant deposit monitoring, adds mandatory reversal of unauthorized refund transactions, and reclassifies some procedural recommendations. These changes strengthen fraud controls and verification processes without altering overall obligations drastically.
SPME §6.2 Fraud Monitoring
Questionable Merchant Audit Program (QMAP)
The criteria for identifying Questionable Merchants have been expanded to include specific rules for Brazil, requiring certain fraud thresholds and transaction types during a 120-day investigation period. Other original criteria remain, with some minor formatting and punctuation changes.
SPME §8.4 Fraud Monitoring
Mastercard Commencement of an Investigation
The section was overhauled: previously, issuers notified Mastercard about questionable merchants via a web form with detailed info. Now, Mastercard initiates investigations, notifying issuers with transaction details, requiring issuers to report fraud within 60 days. Different processes apply if issues involve bust-out accounts or not, with Brazil having a unique reporting rule.
SPME §8.4.2 BRAM ResponseFraud Monitoring
of this manual, or
The section now specifies conditions under which Mastercard will handle issuer fraud recovery, including thresholds for reported fraudulent transaction volumes, recovery methods, and transaction types. It clarifies Mastercard's rights to request information and explains the financial process of debiting Acquirer accounts and crediting Issuer accounts for fraud recovery.
SPME §8.4.3 Chargeback Handling
Mastercard Determination
The section changes from detailing Issuer fraud recovery conditions to outlining Mastercard's procedures for classifying and notifying about Questionable Merchants, including notifications, MATCH record updates, and Acquirer obligations upon Merchant termination for being a Questionable Merchant.
SPME §8.4.6 BRAM Response
Fraud Recovery
The previous process of notifying issuers about partial recovery of losses from questionable merchants has been removed and replaced with a new rule allowing Mastercard to charge acquirers an audit fee of up to $2,500 per questionable merchant identification.
SPME §8.4.8 Fraud Monitoring
Coercion Program
The Coercion Program description was fully replaced with detailed procedural requirements, including evidence submission such as police reports and fraud reporting codes, and a process for notifying issuers to collect claims and affidavits within specified timeframes. This adds specific documentation and notification steps for handling coercion claims involving cardholders.
SPME §8.6 Fraud Monitoring
Issuer Submissions
The update clarifies submission methods for Cardholder coercion claims, differentiating processes pre- and post- January 1, 2022, shifting from email and web submissions to web form only, and explicitly requires police report inclusion if available, with detailed reasons if absent, plus maintaining other supporting documents.
SPME §8.6.1 BRAM Response
Investigation Process
The updated section removes requirements about the police report submissions and the reporting of Transactions with specific fraud type codes related to alleged coercion claims, simplifying the criteria for Mastercard's investigation initiation.
SPME §8.6.2 Fraud Monitoring
Franchise Management Program (FMP) Questionnaire-based Review
The updated section introduces mandatory and conditional requirements for acquirers to have merchants complete a Coercion Program FMP questionnaire based on the number of coercion identifications within specified timeframes, and states that questionnaire responses may trigger an on-site review.
SPME §8.6.7 KYB Acquirer
Definitions
The original MCC Performance Program definitions, including Case Scope Period and exclusions, were removed. They were replaced with detailed specifications regarding data elements such as Payment Facilitator ID, MCC in the message, Tax ID in Brazilian transactions, and Issuer explanations for MCC discrepancies.
SPME §8.7.1 Chargeback Handling
Mastercard Notification to Acquirers
A new Issuer Filing Fee of BRL 25,000 per Merchant or relevant entity was introduced for unsubstantiated claims. Minor formatting changes and heading adjustments clarify billing for Acquirer Non-Performance Assessments and Issuer Interchange Recovery but do not change the substantive billing or assessment obligations.
SPME §8.7.3 Chargeback Handling
Business Risk Assessment and Mitigation (BRAM) Program
A new section describes the BRAM Program, which investigates merchants potentially involved in illegal or brand-damaging transactions to protect Mastercard and its customers from fraud, regulatory, and legal risks. Mastercard collaborates with acquirers to stop violations and reduce future risk, enforcing specific Mastercard Rules related to brand integrity.
SPME §8.8 BRAM Response
BRAM Investigation Process
This new section requires the Acquirer to provide Mastercard a detailed investigation report within two days for law enforcement or Mastercard-initiated cases, or five days for others, including remediation plans, merchant documentation, business overview, transaction data, service provider identity, MATCH system usage, and termination details.
SPME §8.8.1 BRAM Response
Acquirer Response Requirements
A new requirement was added for acquirers' Managed Merchant Service Providers (MMSPs) to provide a report explaining why an incident was not identified and how the MMSP improved its services to prevent recurrence.
SPME §8.8.2 BRAM Response
Noncompliance Assessment Mitigation
A new section requires Acquirers to have MMSPs report potential merchant violations within 5 business days, investigate and resolve issues within 15 calendar days, provide monthly reports on monitored merchants and violations, adhere to MATCH Standards, and respond to BRAM notifications with detailed incident reports explaining monitoring and detection efforts.
SPME §8.8.4 BRAM Response
Merchant Monitoring Program (MMP)
Mastercard has introduced a new Merchant Monitoring Program encouraging customers to prevent BRAM violations and transaction laundering. Acquirers opting in must use approved Merchant Monitoring Service Providers (MMSPs), with Mastercard maintaining an approved vendors list and contact info for vendor approval.
SPME §8.9 BRAM Response
MMP Participation Requirements
A new section was added specifying that Acquirers must register the MMSP as their Service Provider, submit all required Merchant information to the MMSP for monitoring, and ensure continuous monitoring of Merchant activity to detect violations related to BRAM content and transaction laundering.
SPME §8.9.1 Content Moderation