Mastercard SPME release
Sep 2024 → May 2025
1 breaking and 38 substantive revisions proposed, affecting 8 policies.
breaking
1 revision
"Inquiring about a Merchant" (regarding the use of MATCH Pro)
The section was fully replaced, removing the prior process for removing Merchant listings from MATCH due to PCI compliance, and adding new penalties for Acquirers violating BRAM Rules or submitting illegal/brand-damaging Transactions, including significant fines and documentation requirements for approved URLs for Transactions.
substantive
38 revisions
Compliance with Privacy, Data Protection and Information Security Requirements
The original text requiring compliance with applicable data protection laws for processing personal data was replaced with a new reference to Chapter 2 on Cybersecurity Standards, broadening scope to all customers, merchants, service providers, and agents handling account or transaction data.
Not use, or allow the use of, any type of technology or other organization measures that
The entire previous content regarding notification timelines and investigation procedures was replaced with detailed new standards about handling, processing, transferring, and securing Personal Information under CCPA and EU Data Protection laws within the MATCH Pro system, including roles, responsibilities, security measures, and breach notification protocols.
It is the Acquirer's obligation to confirm that the results from MATCH Pro are relevant to the
The section was expanded to specify that when onboarding a MATCH Merchant flagged for reason code 14 Identity Theft, the Acquirer should conduct additional due diligence to verify the legitimacy of the person or entity, noting that the legitimate party might be unaware their identity was previously misused.
System Features
The entire section describing MATCH system features and options for Acquirers has been removed, eliminating detailed information on fraud detection capabilities and how Acquirers interact with the MATCH database.
MATCH Pro Record Retention
New requirements added for removing a MATCH Merchant listed under reason code 12, mandating an acquirer's attestation of PCI DSS compliance and a certified forensic examiner's validation letter. Merchants can also request removal if the acquirer does not.
MATCH Merchant Removal from MATCH Pro
This new section defines specific conditions and procedures under which Mastercard can remove a MATCH Merchant listing from MATCH Pro, including error reports by Authorized Users and removal of listings for PCI DSS noncompliance once the merchant is compliant, requiring a formal written request with detailed information.
MATCH Pro Reason Codes
The section introduces new detailed MATCH Pro Reason Codes outlining conditions under which merchants can be reported for excessive chargebacks, excessive fraud, coercion, questionable audits, insolvency, and violation of standards, including both Mastercard and American Express specific criteria.
Reason Codes for MATCH Merchants Listed by an Authorized User
New reason codes for MATCH listings were added, including PCI noncompliance, illegal transactions, and identity theft, providing additional clarity on grounds for listing merchants in MATCH.
MATCH Pro Standards
New rules for Acquirers regarding the MATCH Pro system have been added. They must respond to inquiries within seven days, include suite or box numbers for registered agents, maintain accuracy of data in US ASCII, manage changes of control with inquiries within 90 days, retain Merchant Reference Numbers, comply diligently, not misuse MATCH Pro as a collection tool for minor issues, and face penalties for noncompliance.
Acquirer Requirements
The reference to reasons for removing a merchant listing from MATCH was removed and replaced with a new requirement that a contact profile must include either a shared mailbox email or multiple individual email addresses.
When to Add a Merchant to MATCH Pro
The updated section emphasizes that acquirers must conduct MATCH inquiries using the correct ICA Number tied to the processing entity. Failure to add terminated merchants or to use the proper ICA Number for inquiries can lead to compliance violations and Mastercard assessments.
Acquirer Responsibility: Requests for Removal from MATCH Pro
The updated section removes the MATCH reason codes and instead provides clear instructions that any MATCH merchant can request removal from MATCH Pro without legal counsel and specifies the required information for such requests, including merchant name, address, principal owner's name, and website URL.
Inquiring about a MATCH Merchant
New rules require Acquirers to check MATCH Pro before signing agreements with or enabling Merchants to accept Transactions, retain inquiry reference numbers, and warn that failing to inquire may lead to unfavorable compliance rulings.
How does MATCH Pro search when conducting an inquiry?
The added section details the specific data fields MATCH Pro uses in searches, varying by country, and emphasizes the requirement for using correct ISO codes in queries via API or UI to ensure accurate matching results.
Phonetic Possible Matches
The section introduces criteria for phonetic matching in merchant verification, specifying various combinations of fields (e.g., merchant URL with owner's name and address) to establish matches. It clarifies country-specific matching rules for US vs. non-US merchants in the MATCH Pro system.
The Acquirer is responsible for ensuring that accurate data is entered into MATCH Pro. The
The change specifies that data in MATCH Pro must match onboarding information and introduces potential noncompliance assessments if errors by the Acquirer or authorized user are not timely corrected, replacing prior guidance about investigation responses and escalation procedures.
Service Provider Risk Management Program
The appendix D privacy and data protection standards for Covered Programs have been updated to exclude MATCH and introduce a new Appendix F covering privacy/data protections specifically for MATCH Pro, with obligations realigned under applicable laws. This includes updated roles, obligations, and definitions for processing personal data and information.
Mastercard Site Data Protection (SDP) Program
The updated section broadens the scope to include more types of Service Providers under the SDP Program, requires compliance with PCI DSS or ISO/IEC 27001 for Issuers and Acquirers, and clarifies that Mastercard has sole discretion over enforcing the program. Level 1 and 2 Merchants and all Service Providers must validate compliance to be deemed compliant.
Customer Compliance Requirements
The updated section adds specific reporting deadlines for submission periods and introduces a requirement for Acquirers to have a risk management program managing payment security risks for Level 3 and Level 4 merchants. It also details potential cost reductions for Customers compliant with the SDP Program impacted by ADC Events, alongside clarifications on service provider validation and submission processes.
Service Provider Compliance Requirements
Added BPSP category to Level 1 and Level 2 Service Provider lists, with updated service provider classifications note. Minor formatting changes occurred, but no changes to validation requirements or thresholds.
SDP Program Noncompliance Assessments
The section was replaced with a new table detailing financial penalties and additional consequences for failing to comply with the SDP Program, including escalating fines for violations based on merchant or service provider level and potential termination or deregistration. Penalties now also apply for late or missing compliance reporting submissions.
Acquirer Fraud Loss Control Programs
The compliance date for Europe-region Acquirers' strong authentication was extended to 8 October 2024 (1 April 2025 in Serbia) from 13 October 2023. The requirement was reworded to specify that Merchants or Digital Wallet Operators must complete EMV 3DS authentication or another successful SCA method when adding Stored Credentials, wallets, or tokenized cards, or by the first subsequent transaction.
Screening New Merchants, Sponsored Merchants, and ATM Owners
The requirement now specifies participation in the MATCH Pro system instead of the MATCH system, and it adds a clear rule that if a Merchant or Sponsored Merchant is terminated for listed reasons, the Acquirer must add them to MATCH Pro.
Investigation Process
The timeframe for investigating alleged coercion claims is now clearly defined as 60 days before and 60 days after the first alleged coerced transaction, with Mastercard able to extend this period at its discretion, ensuring more flexibility in investigation timing.
Coercion Program Performance Assessments
The section clarifies referenced sections by adding quotation marks and changes the term "MATCH" to "MATCH Pro" for acquirer inquiry requirements when signing a merchant, specifying a particular version of the MATCH service.
Noncompliance Assessment Mitigation
The updated rules require MMSPs to monitor merchants persistently, including member-only website areas, with a focus on BRAM and transaction laundering. Reporting to Mastercard must be unaltered copies from MMSPs, and incident reports for BRAM notifications must also be MMSP-authored and unmodified. The MATCH standards referenced have been updated to MATCH Pro standards.
MMP Participation Requirements
The requirements for Acquirers to participate in the Merchant Monitoring Program now include confirming that the MMSP is approved by Mastercard for BRAM monitoring and/or Merchant Transaction laundering detection before registration and data submission.
MMP Monthly Reporting Format and Submission
The reporting requirements were expanded to include detailed merchant information and violations, with new fields such as Merchant URL, MCC, violation type, dates of reporting, and resolution details. A standardized file naming convention using the Acquirer ICA and other identifiers was also introduced, while existing submission and file requirements remained.
General Registration Requirements
The updated section adds specific registration requirements for U.S. region and territories Merchants, including submitting various intake forms and legal opinions for certain gambling and sweepstakes Merchants. It also clarifies the process for modifying registration information, distinguishing between changes Acquirers can make themselves and those that require Mastercard intervention.
General Monitoring Requirements
The updated rules add two new obligations for merchants: they must resolve reported complaints about potentially illegal content within seven business days, removing illegal content immediately, and must provide a process allowing individuals depicted in content to appeal for its removal if consent is invalid.
Non-face-to-face Adult Content and Services Merchants
The updated section removes the initial requirement for reported complaints within seven business days and the mandate for immediate removal of illegal content found in such reviews, but retains all other provisions unchanged.
Non-face-to-face Gambling Merchants
The update clarifies that Acquirers must notify Mastercard within 30 days of any changes to information provided, including legal opinions and certifications. It also mandates Acquirers to affirm they will not submit restricted transactions and requires Mastercard approval before processing non-face-to-face gambling transactions in the US and its territories.
Pharmaceutical and Tobacco Product Merchants
The update adds a requirement that Acquirers must annually verify and maintain documentation proving that registered Merchants comply with applicable laws and must provide this documentation to Mastercard upon request.
Government-owned Lottery Merchants
The update details new requirements for Acquirers of government-owned lottery merchants, including providing Mastercard with a legal opinion, obtaining independent third-party certification on controls like age verification, notifying Mastercard of any changes within 30 days, and affirming rejection of restricted transactions. Mastercard approval is now mandatory before processing transactions.
Skill Games Merchants
The new requirements now mandate acquirers to obtain an independent third-party certification verifying effective age and location controls for skill games merchants, notify Mastercard of any material changes within 30 days, and continue affirming no submission of restricted transactions. Previously, only an acquirer affirmation and Mastercard approval were required.
Recreational Cannabis Merchants (Canada Region Only)
The updated rules specify that acquirers must obtain and keep a copy of the merchant's provincial retail license for recreational cannabis sales, provide it to Mastercard upon request, promptly notify Mastercard of any license or information changes within 10 business days, and stop licensed merchants from accepting Mastercard payments if they lose their license, notifying Mastercard immediately.
High-Risk Securities Merchants
The updated rules add requirements for Acquirers to obtain and provide updated licenses before expiration and to cease processing if licenses are not updated. It also mandates obtaining a reasoned legal opinion detailing laws applicable to Merchants and Cardholders, ensuring full compliance with relevant laws.
Cryptocurrency Merchants
The updated section clarifies definitions around cryptocurrency, explicitly excluding government-issued virtual currencies, and introduces a formal registration requirement with Mastercard before processing cryptocurrency transactions. Acquirers must obtain appropriate licenses or registrations from merchants and conduct ongoing compliance verification at least annually or upon legal changes.