BAMS Third Party Service Providers (TPSPs) FAQs
1) What is the Third Party Service Provider (TPSP) Agent Registration Program? The TPSP Agent Registration Program is a Card Brand (Visa USA Inc and MasterCard International)-mandated program enacted to ensure that all Member Banks such as Bank of America are in compliance with Card Brand Regulations and policies regarding their use of TPSPs. All Member Banks are required to perform due diligence reviews to ensure that they understand the TPSP’s business model, financial conditions, background and Payment Card Industry Data Security Standard (PCI DSS) compliance status. TPSP Agent registration is required for all entities performing solicitation activities and / or storing, processing or transmitting cardholder data on behalf of Member Banks (or on behalf of their merchants). Card Brand registration and annual renewal fees may apply and will be collected prior to initial registration. Annual renewal fees are managed and collected by BAMS.2) What is a TPSP?
A TPSP is any entity, not connected to VisaNet and not a MasterCard Type I entity, that provides payment-related services, directly or indirectly, to a Member Bank and/or stores, processes or transmits account numbers (cardholder data). TPSPs perform multiple functions on the issuing and acquiring side of a Member Bank’s business.
Types of TPSPs include, but are not limited to:
Gateways for transactions from a Merchant location to a Processor
Providers of Back Office Support (i.e. Customer Service, Exception processing for Acquirer’s Merchants)
Supporting loyalty programs Electronic Data Capture
Fraud servicing, monitoring or scrubbing Credit Underwriting (issuing)
Collections
Voice authorization and routing Call referral processing/telemarketing Clearing file preparations and submissions Settlement processing
Cardholder and merchant statement preparation Chargeback processing
Merchant help desk support if there is access to cardholder data Loading software into a terminal which will accept cards
Loading or injecting encryption keys into terminals or PIN pads
3) TPSP functions that require registration include, but are not limited to: o Merchant or cardholder solicitation activities and / or customer service o Prepaid program solicitation activities and / or customer service o Loading or injecting encryption keys into ATMs, terminals or PIN pads o Loading software into an ATM or terminal
4) Visa TPSP Definitions:
Third Party Servicer (TPS): A type of TPSP that:
o Has a Direct contractual relationship with the Member
o Is not a Member of Visa USA & is not directly connected to VisaNet
o Provides response processing for Visa Members related to program solicitations, transaction processing, data capture, and/or other administrative functions, such as chargeback processing, risk/security reporting, and customer service.
Merchant Servicer (MS): A type of TPSP that:
o Has a Direct contractual relationship with a Merchant
o Is not a Member of Visa USA and is not directly connected to Visa Net
o Provides response processing for visa Members related to program solicitations, transaction processing, data capture, and/or administrative functions, such as chargeback processing, risk/security reporting, and customer service.
Independent Sales Organizations (ISO):
An organization or individual, which is not a Member, whose bankcard-related business relationship with a Member involves any of the following:
o Merchant or cardholder solicitation activities and / or customer service
o Prepaid program solicitation activities and / or customer service o Deploying and / or servicing ATMs
o High Risk Merchant solicitation, sales, customer service, merchant transaction solicitation and/or customer training for the following Merchant Category Codes (MCC): 5962, 5966, 5967, 7995, 5912, 5122.
Encryption and Support Organization (ESO):
Deploys ATM, POS or kiosk PIN acceptance devices that process and accept cardholder PINs and/or manage encryption keys
Payment gateway:
Payment gateways are a category of agent or service provider that stores, processes, and / or transmits cardholder data as part of a payment transaction. Specifically, they enable payment transactions (e.g., authorization or settlement) between merchants and processors (ex. VisaNet endpoints). Merchants may send their payment transactions directly to an endpoint, or indirectly to a payment gateway.
A CFS owns or operates a centralized or hosted network environment used by franchisees that can affect the franchisee’s cardholder data environment if accessed by unauthorized parties. In some cases CFS entities also provide card payment processing services to franchisees through these network environments.
Payment Service Providers (PSP):
Contracting with Visa member to provide payment services to sponsored merchants Dynamic Currency Conversion (DCC):
Providing currency conversion services to sponsored merchants at checkout.
5) MasterCard TPSP Definitions:
Third Party Processors (TPPs) – Type II: A type of TPSP that:
o Performs transaction and cardholder processing services for one or more Members (such services are referred to as "TPP" Services)
o Is not a Member of MasterCard International & is not directly connected to MasterCard
o Provides Program Services including, but are not limited to, terminal operation, authorization services, including but not limited to authorization routing, payment gateway and switching services, voice authorization, and call referral processing, electronic data capture, clearing file preparation and submission, settlement processing (excluding possession, ownership, or control of settlement funds, which are prohibited), cardholder and merchant statement preparation, chargeback processing and Mobile Remote Payment
Data Storage Entity (DSE): A type of TPSP that:
o Is an entity other than a member, merchant, ISO, or TPP that stores, transmits, or processes card or transaction data for or on behalf of a merchant, ISO, or TPP o These services include, but are not limited to, merchant web site hosting and
external hosting of payment applications, such as web site shopping carts. Third Party Processors (TPPs) – Type I:
A type of TPSP that:
o Is a Member Service Provider (MSP) that performs transaction and cardholder processing Program Services
o Is not a Member of MasterCard International & is not directly connected to MasterCard
o Generally are those that provide Program Service to a large number of Members or that otherwise could significantly impact the integrity of the Interchange System.
o Is based on, but not limited to, the annual number of authorized credit and debit
transactions processed by the TPP. MasterCard, in its sole discretion, will determine which TPPs to classify as Type I
TPPs.
Independent Sales Organizations (ISO):
An organization or individual, which is not a Member, whose bankcard-related business relationship with a Member involves any of the following:
o Merchant solicitation, sales, or service
o Merchant Transaction processing solicitation o Cardholder solicitation or Card application processing services
6) Who can register TPSPs?
Only a Visa and/or MasterCard Member Bank can register TPSPs (including any TPSPs their merchants are utilizing).
A Member Bank is ultimately liable for its TPSPs; therefore, a Member Bank must perform its own due diligence and weigh the operational and financial risks of utilizing the TPSP. Each Member whose merchants utilize a TPSP must register that TPSP for the Program Services being provided to their merchant(s).
7) How is the TPSP Agent registration requirement communicated to TPSPs? The TPSP Agent registration requirement is communicated to Member Banks, VisaNet processors, MasterCard Type I’s and TPSPs through industry conferences, direct
communications, the Visa PCI website (located at www.visa.com/cisp) and MasterCard SDP website (located at www.mastercard.com/us/sdp/serviceproviders/index.html).
8) Is there a fee for Member Banks to register TPSPs? Yes.
Agent Type Registration Fee Change Annual Renewal Fee Change (Effective 1 November 2013) (Effective With the 2013–14 Billing Period)
Independent sales organization (ISO)1 $5,000 $5,000
Payment service provider (PSP) $5,000 $5,000
High-risk Internet payment service provider (HRIPSP) $5,000 $5,000
ESO $1,000 $1,000
TPS $1,000 $1,000
Dynamic Currency Conversion (DCC) servicer $1,000 $1,000
MS $1,000 $1,000
1 Includes all ISO types: cardholder, ATM, prepaid, merchant and high-risk.
Each client that registers an ISO, ESO, TPS or MS will be billed the registration fee and annual renewal fee at the revised rates shown in the table above.
Billing of the annual renewal fee will move from July to November, effective in 2013.
The MasterCard fee schedule, effective January 2013,is as follows: $5,000 for initial registration for TPPs
$5,000 annually for TPPs
$0 for initial & annually for all DSEs
MasterCard bills each Member Bank for each TPP registration submitted. MasterCard currently does not assess registration or annual renewal fees for DSE registrations
Billing of the annual renewal fee will move from November to April, effective in 2014.
9) Prior to registering a TPSP, what due diligence must be performed by a Member Bank? The Card Brands (Visa and MasterCard) provide a minimum due diligence standard that all Member Banks must perform prior to registering a TPSP. The Card Brand’s minimum standard includes basic background, financial and operational reviews. Additionally, any TPSP that stores, processes or transmits cardholder data must be PCI DSS compliant and provide adequate validation per their Service Provider Level.
However, each Member Bank is encouraged to increase the scope of review based on the TPSP business type, services performed, relative program risk, account data held or processed and the individual Member Bank’s internal risk appetite and requirements.
10) What does a TPSP have to do to get registered?
To start the registration process, TPSPs should contact their contracted Member Bank. If the TPSP has a contract with a Member Bank’s merchant, they can directly contact the merchant’s Member Bank (usually identified by asking the merchant for their acquiring / merchant bank contact information)
Internally, you can reach out to the BAMS Third Party Programs team to initiate a review and registration on any new TPSP identified.
11) What is the PCI DSS?
Customers offering their payment card at the point of sale, over the Internet, on the phone or through the mail want assurance that their account information is safe. Mandated since 2001, the Visa Cardholder Information Security Program (CISP) and MasterCard Site Data Protection (SDP) Programs protect Visa and MasterCard cardholder data wherever it resides and ensures that Member Banks, merchants and TPSPs adhere to accepted information security standards. In 2006, CISP requirements were incorporated and adopted into an industry standard known as the Payment Card Industry Data Security Standard (PCI DSS). This standard is now owned and managed by the PCI Security Standards Council (PCI SSC). The PCI SSC was founded by Visa, MasterCard, JCB, Discover and American Express.
For detailed information concerning PCI DSS compliance and questions, please visit www.visa.com/cisp and www.mastercard.com/us/sdp/serviceproviders/index.html .
12) Are TPSPs required to be PCI DSS compliant?
Yes. Any TPSP that stores, processes or transmits cardholder data must validate PCI DSS compliance with Visa and MasterCard every 12 months. TPSP validation levels and
requirements are addressed below.
13) How does a TPSP validate PCI DSS compliance as required by Visa and MasterCard? Depending on Service Provider Level requirements (see chart below), a TPSP must validate PCI DSS compliance by either contracting with a QSA to complete a Report on Compliance, “ROC” or by completing a Self-Assessment Questionnaire (SAQ-D). In addition, all TPSPs, regardless of validation level, must also conduct quarterly network scans through an Approved Scanning Vendor (ASV).
Service Provider Levels Defined Visa CISP Service Levels:
Service
Provider Level Description
1 Third Party Agent (TPA) that stores, processes and/or transmits over 300,000 Visa transactions per year
2** Third Party Agent (TPA) that stores, processes and/or transmits fewer than 300,000 Visa transactions per year
** Effective February 1, 2009, Level 2 Service Providers are no longer listed on Visas’ list of PCI DSS Compliant Service Providers. Entities that wish to be on the Visa list of PCI DSS Compliant Service Providers must validate as a Level 1 provider.
MasterCard SDP Service Levels: Service
Provider Level Description 1*
All TPPs
All DSE’s that store, transmit, or process greater than 300,000 total combined MasterCard and Maestro transactions annually 2* Includes all DSE’s that store, transmit, or process less than 300,000 total
combined MasterCard and Maestro transactions annually
*As of October 1, 2010, MasterCard will only list those Service Providers that are also registered and approved as a Service Provider and who have also successfully completed an annual onsite assessment as a Level 1 Service Provider.
Effective January 1, 2013, MasterCard has reclassified gateway and switching Program Services from a DSE, to a TPP and must follow PCI DSS requirements as a Level 1 Service Provider, regardless of volumes.
TPSP Compliance Validation Requirements:
Level Validation Action Required Documentation Validated By
1
Annual On-Site PCI Data Security Assessment
Quarterly Network Scan
Report on Compliance (ROC)
Attestation of Compliance (AOC)
ASV Scan and AOC
Qualified Security Assessor (QSA) Approved Scanning Vendor (ASV)
2
Annual PCI Self-Assessment Questionnaire
Quarterly Network Scan
SAQ-D
Attestation of Compliance (AOC)
ASV Scan and AOC
Service Provider Approved Scanning Vendor (ASV)
14) What is the process to submit PCI DSS documents to BAMS to validate compliance? BAMS will require submission of an executed Attestation of Compliance (AOC) Form and the “Executive Summary” section of the Report on Compliance (ROC) to demonstrate PCI DSS compliance as a Level 1 service provider. Level 2 service providers will submit a completed SAQ-D and AOC, along with their most recent ASV Scan and Scan AOC.
BAMS may also require and request the TPSP’s confirmation that they, or their QSA, have submitted their PCI DSS validations to the Card Brands.
15) What is a Member Bank’s liability for a TPSP?
Member Banks are responsible for ensuring that their TPSPs comply with PCI DSS and are registered appropriately. Member Banks may be subject to fines and penalties for any TPSP
found to be out of compliance with the PCI DSS and not registered as per Visa Operating Regulations or MasterCard Rules.
16) Is registration required for all TPSPs?
Yes. If a Member Bank, or their merchants, has a relationship with a TPSP, directly or indirectly, and the TPSP is not registered by the Member Bank, the Member Bank may be assessed an unregistered agent fine starting at $10,000 per TPSP per Card Brand.
17) Is registration required for Point-of-Sale (POS) software providers?
POS software providers that provide the payment application only and do not store, process and / or transmit cardholder data do not require registration. A separate security standard, the Payment Application Data Security Standard (PA-DSS) is available to ensure the secure development of these applications. Details on payment applications are available at www.visa.com/pabp.
18) What do you (Sales, Account Management and Account Boarding) need to do when boarding a merchant using a Third Party Service Provider?
Prior to submitting an application for a merchant that is going to use a Third Party Service Provider, you must first check the BAMS Approved Third Party Service Provider List to verify that the merchant is requesting a BAMS approved provider. If the Third Party Service Provider is not listed on the BAMS Approved Third Party Service Provider List, prior to boarding or submitting your application, contact the Third Party Programs team for approval at