On August 20, the Office of the Comptroller of the Currency (OCC) issued the “Merchant Processing” booklet of the Comptroller’s Handbook. This booklet, which replaces the booklet of the same name issued in December 2001, has been revised to include the supervision of federal savings associations. The “Merchant Processing” booklet provides updated guidance to examiners and bankers on assessing and managing the risks associated with merchant processing activities.Specifically, the booklet includes updated guidance on:
-
selection of third-party organizations and due diligence;
-
technology service providers;
-
on-site inspections, audits and attestation engagements, including the “Statement on Standards for Attestation Engagement” (SSAE 16) and the “International Standard on Assurance Engagements” (ISAE 3402);
-
data security standards in the payment card industry for merchants and processors;
-
member alert to control high-risk merchants (MATCH) list;
-
Bank Secrecy Act/Anti-Money Laundering compliance programs and appropriate policies, procedures and processes to monitor and identify unusual activity; and
-
appropriate capital for merchant processing activities.