Item 1. Business
ITEM 1. BUSINESS
Anti-Money Laundering, Countering the Financing of Terrorism, Economic Sanctions and Anti-Corruption. We are subject to anti-money laundering (“AML”) and countering the financing of terrorism (“CFT”) laws and regulations globally, including the U.S. Bank Secrecy Act and the USA PATRIOT Act, as well as the various economic sanctions programs, including those imposed and administered by the U.S. Office of Foreign Assets Control (“OFAC”). We have implemented a comprehensive AML/CFT program, comprised of policies, procedures and internal controls, including the designation of a compliance officer, which is designed to prevent our payments network from being used to facilitate money laundering and other illicit activity and to address these legal and regulatory requirements and assist in managing money laundering and terrorist financing risks. The economic sanctions programs administered by OFAC restrict financial transactions and other dealings with certain countries and geographies (specifically Crimea, the Donetsk People’s Republic and Luhansk People’s Republic regions of Ukraine, Cuba, Iran, North Korea and Syria) and with persons and entities included in OFAC sanctions lists including its list of Specially Designated Nationals and Blocked Persons (the “SDN List”). We take measures to prevent transactions that do not comply with OFAC and other applicable sanctions, including establishing a risk-based compliance program that has policies, procedures and controls designed to prevent us from having unlawful business dealings with prohibited countries, regions, individuals or entities. As part of this program, we obligate issuers and acquirers to comply with their local sanctions obligations and U.S. and EU sanctions programs. In the U.S., these obligations include requiring the screening of account holders and merchants, respectively, against OFAC sanctions lists (including the SDN List). Iran and Syria have been identified by the U.S. State Department as terrorist-sponsoring states, and we have no offices, subsidiaries or affiliated entities located in these countries and do not license entities domiciled there. We are also subject to anti-corruption laws and regulations globally, including the U.S. Foreign Corrupt Practices Act and the U.K. Bribery Act, which, among other things, generally prohibit giving or offering payments or anything of value for the purpose of improperly influencing a business decision or to gain an unfair business advantage. We have implemented policies, procedures and internal controls to proactively manage corruption risk.
Issuer and Acquirer Practices Legislation and Regulation. Our issuers and acquirers are subject to numerous regulations and investigations applicable to banks, financial institutions and other licensed entities, impacting us as a consequence. Additionally, regulations such as the revised Payment Services Directive (commonly referred to as “PSD2”) in the EEA require financial institutions to provide third-party payment processors access to consumer payment accounts, enabling them to route transactions away from Mastercard products and provide payment initiation and account information services directly to consumers who use our products. PSD2 also requires a new standard for authentication of transactions, which necessitates additional verification information from consumers to complete transactions. This may increase the number of transactions that consumers abandon if we are unable to ensure a frictionless authentication experience under the new standards.
Regulation of Internet, Digital Transactions and High-Risk Merchant Categories. Various jurisdictions have enacted or have proposed regulation related to internet transactions which applies to payments system participants, including us and our customers. We may also be impacted by evolving laws surrounding gambling, including fantasy sports, as well as certain legally permissible but high-risk merchant categories, such as adult content, firearms, alcohol and tobacco.
Privacy, Data Protection, AI and Information Security. Aspects of our operations or business are subject to increasingly complex and fragmented privacy, data and information security laws and regulations in the U.S., the EU and elsewhere around the world. For example, in the U.S., we and our customers are respectively subject to, among other laws and regulations, Federal Trade Commission and federal banking agency information safeguarding requirements under the Gramm-Leach-Bliley Act (“GLBA”) that require, among other things, the maintenance of a written, comprehensive information security program and, increasingly, a number of state data and privacy laws. With respect to information security, the U.S. Securities and Exchange Commission (the “SEC”) adopted new disclosure rules that require, among other things, disclosing material cybersecurity incidents in a Current Report on Form 8-K, generally within four business days of determining an incident is material. In the EU, we are subject to the General Data Protection Regulation (the “GDPR”) and its equivalent in the U.K., which requires, among other things, a comprehensive privacy, data protection and information security program to protect the personal and sensitive data of EEA residents. Several regulators and policymakers around the globe use the GDPR as a reference to adopt new or updated privacy, data protection and information security laws and regulations, although divergences have occurred. Laws and regulations in this area are constantly evolving due to several factors, including increasing data collection and data flows, numerous data breaches and security incidents, more sensitive data categories, and emerging technologies such as AI. In addition, the interpretation and application of these privacy, data protection and information security laws and regulations are often uncertain and in a state of flux, thus requiring constant monitoring for compliance.
MASTERCARD 2023 FORM 10-K 25
PART I
ITEM 1. BUSINESS
ESG. Various jurisdictions have adopted or are increasingly considering adopting laws and regulations impacting our reporting on ESG governance, strategy, risk management, metrics and targets, and results. Regulations already adopted or being considered include required corporate reporting and disclosures on specific topics as well as broader ESG matters. Specific topics include climate (such as the U.K. Streamlined Energy and Carbon Reporting, the EU Corporate Sustainability Reporting Directive, or “EU CSRD”, and the SEC proposed rules related to climate change) and human rights (such as the EU Corporate Sustainability Due Diligence Directive). Broader ESG matters include other environmental matters, treatment of employees and diversity of workforce (such as in the EU CSRD).
Additional Regulatory Developments. Various regulatory agencies also continue to examine a wide variety of issues that could impact us, including evolving laws surrounding buy-now-pay-later, open banking, digital currencies, marijuana, prepaid payroll cards, identity theft, account management guidelines, disclosure rules and marketing.
Additional Information
Mastercard Incorporated was incorporated as a Delaware corporation in May 2001. We conduct our business principally through our principal operating subsidiary, Mastercard International Incorporated, a Delaware non-stock (or membership) corporation that was formed in November 1966. For more information about our capital structure, including our Class A common stock (our voting stock) and Class B common stock (our non-voting stock), see Note 16 (Stockholders' Equity) to the consolidated financial statements included in Part II, Item 8.
Website and SEC Reports
Our internet address is www.mastercard.com. From time to time, we may use our corporate website as a channel of distribution of material company information. Financial and other material information is routinely posted and accessible on the investor relations section of our corporate website. You can also visit “Investor Alerts” in the investor relations section to enroll your email address to automatically receive email alerts and other information about Mastercard.
Our annual report on Form 10-K, quarterly reports on Form 10-Q, current reports on Form 8-K and amendments to those reports are available for review, without charge, on the investor relations section of our corporate website as soon as reasonably practicable after they are filed with, or furnished to, the SEC. The information contained on our corporate website, including, but not limited to, our Environmental, Social and Governance Report and our U.S. Consolidated EEO-1 Report, is not incorporated by reference into this Report. Our filings are also available electronically from the SEC at www.sec.gov.
26 MASTERCARD 2023 FORM 10-K
PART I
ITEM 1A. RISK FACTORS
Item 1A. Risk factors
RISK HIGHLIGHTS
Legal and Regulatory Business and Operations
Payments Industry Regulation Competition and Technology Brand, Reputational Impact and ESG
Preferential or Protective Government Actions Information Security and Operational Resilience Talent and Culture
Privacy, Data Protection, AI and Information Security
Stakeholder Relationships Acquisitions and Strategic Investments
Other Regulation Global Economic and Political Environment Settlement and Third-Party Obligations
Litigation
Class A Common Stock and Governance Structure
Legal and Regulatory
Payments Industry Regulation
Global regulatory and legislative activity related to the payments industry may have a material adverse impact on our overall business and results of operations.
Central banks and similar regulatory bodies have increasingly established or further expanded their authority over certain aspects of payments systems such as ours, including obligations or restrictions with respect to the types of products and services that we may offer, the countries in which our products and services may be used, the way we structure and operate our business and the types of consumers and merchants who can obtain or accept our products or services. Similarly, jurisdictions that regulate a particular product may consider extending their jurisdiction to other products. For example, debit regulations could lead to regulation of credit products. Moreover, several jurisdictions are demonstrating increased interest about the network fees we charge to our customers (in some cases as part of broader market reviews of retail payments), which could in the future lead to regulation of our network fees. In several jurisdictions, we have been designated as a “systemically important payment system”, with other regulators considering similar designations. This type of regulation and oversight is related to switching activities (authorization, clearing and settlement), and includes policies, procedures and requirements related to risk management, collateral, participant default, timely switching of financial transactions, and capital and financial resources. Parts of our business have also been deemed as a “specified service provider” or considered “critical infrastructure”. The impact to our business created by any new law, regulation or designation is magnified by the potential it has to be replicated in, or conflict with, other jurisdictions, or involve other products within any particular jurisdiction.
The expansion of our products and services as part of our multi-rail strategy has also created the need for us to obtain new types and increasing numbers of regulatory licenses, resulting in increased supervision and additional compliance burdens distinct from those imposed on our core payment network activities. For example, certain of our subsidiaries maintain money transfer licenses to support certain activities. These licenses typically impose supervisory and examination requirements, as well as capital, safeguarding, risk management and other business obligations.
Increased regulation and oversight of payments systems, as well as increased exposure to regulation resulting from changes to our products and services, have resulted and may continue to result in significant compliance and governance burdens or otherwise increase our costs. As a result, customers could be less willing to participate in our payments system and/or use our other products or services, reduce the benefits offered in connection with the use of our products (making our products less desirable to consumers), reduce the volume of domestic and cross-border transactions or other operational metrics, disintermediate us, impact our profitability and/or limit our ability to innovate or offer differentiated products and services, all of which could materially and adversely impact our financial performance. In addition, any regulation that is enacted related to the type and level of network fees
MASTERCARD 2023 FORM 10-K 27
PART I
ITEM 1A. RISK FACTORS
we charge our customers could also materially and adversely impact our results of operations. Regulators could also require us to obtain prior approval for changes to our system rules, procedures or operations, or could require customization with regard to such changes, which could negatively impact us. Moreover, failure to comply with the laws and regulations to which we are subject could result in fines, sanctions, civil damages or other penalties, which could materially and adversely affect our overall business and results of operations, as well as have an impact on our brand and reputation.
Increased regulatory, legislative and litigation activity with respect to interchange rates could have an adverse impact on our business.
Interchange rates are a significant component of the costs that merchants pay in connection with the acceptance of products associated with our core payment network. Although we do not earn revenues from interchange, interchange rates can impact the volume of transactions we see on our payment products. If interchange rates are too high, merchants may stop accepting our products or route transactions away from our network. If interchange rates are too low, issuers may stop promoting our products and services, eliminate or reduce loyalty rewards programs or other account holder benefits (e.g., free checking or low interest rates on balances), or charge fees to account holders (e.g., annual fees or late payment fees).
Governments and merchant groups in a number of countries have implemented or are seeking interchange rate reductions through legislation, regulation and litigation. See “Business - Government Regulation” in Part I, Item 1 and Note 21 (Legal and Regulatory Proceedings) to the consolidated financial statements included in Part II, Item 8 for more details.
If issuers cannot collect or we are required to reduce interchange rates, issuers may be less willing to participate in our four-party payments system. Alternatively, they may reduce the benefits associated with our products, choose to charge higher fees to consumers to attempt to recoup a portion of the costs incurred for their services, or seek a fee reduction from us to decrease the expense of their payment programs (particularly if regulation has a disproportionate impact on us as compared to our competitors in terms of the fees we can charge). These and other impacts could make our products less desirable to consumers, limit our ability to innovate or offer differentiated products, and/or make proprietary three-party networks or other forms of payment more attractive, ultimately reducing the volume of transactions over our network and our profitability.
We are devoting substantial resources to defending our right to establish interchange rates in regulatory proceedings, litigation and legislative activity. The potential outcome of any of these activities could have a more positive or negative impact on us relative to our competitors. If we are ultimately unsuccessful in defending our ability to establish interchange rates, any resulting legislation, regulation and/or litigation may have a material adverse impact on our overall business and results of operations. In addition, regulatory proceedings and litigation could result (and in some cases has resulted) in us being fined and/or having to pay civil damages, the amount of which could be material.
Limitations on our ability to restrict merchant surcharging could materially and adversely impact our results of operations.
We have historically implemented policies, referred to as no-surcharge rules, in certain jurisdictions, including the U.S. and Canada, that prohibit merchants from charging higher prices to consumers who pay using our products instead of other means. Authorities in several jurisdictions have acted to end or limit the application of these no-surcharge rules (or indicated interest in doing so). Additionally, our no-surcharge rules now permit U.S. and Canadian merchants to surcharge credit cards (subject to certain limitations), which over time could lead merchants in some or all merchant categories in these jurisdictions to choose to surcharge as permitted. This could result in consumers viewing our products less favorably and/or using alternative means of payment instead of electronic products, which could result in a decrease in our overall transaction volumes, and which in turn could materially and adversely impact our results of operations.
Preferential or Protective Government Actions
Preferential and protective government actions related to domestic payment services could adversely affect our ability to maintain or increase our revenues.
Governments in some countries have acted, or in the future may act, to provide resources, preferential treatment or other protection to selected national payment and switching providers, or have created, or may in the future create, their own national provider. This action may displace us from, prevent us from entering into, or substantially restrict us from participating in, particular geographies, and may prevent us from competing effectively against those providers. For example:
• Governments in some countries have implemented, or may implement, regulatory requirements that mandate switching of domestic payments either entirely in that country or by only domestic companies.
• Some jurisdictions have implemented, or are considering, requirements to collect, store and/or process data within their borders, as well as prohibitions on the transfer of data abroad, leading to technological and operational implications as well as increased compliance burdens and other costs.
28 MASTERCARD 2023 FORM 10-K
PART I
ITEM 1A. RISK FACTORS
• Geopolitical events (such as Russia’s invasion of Ukraine) and resulting OFAC sanctions, adverse trade policies, enforcement of U.S. laws related to countering the financing of terrorism, economic sanctions and anti-corruption, or other types of government actions could lead affected or other jurisdictions to take actions in response that could adversely affect our business. Moreover, given our decision to suspend business operations in Russia, other separate jurisdictions may decide to begin to or increase their focus on growing local payment networks and other solutions.
• Regional groups of countries are considering, or may consider, efforts to restrict our switching of regional transactions.
• Governments have been increasingly creating and expanding local payments structures (such as the Brazilian Instant Payment System-PIX, FedNow in the U.S. and UPI in India), which are increasingly being considered as alternatives to traditional domestic payment solutions and schemes such as ours.
Such developments prevent us from utilizing our global switching capabilities for domestic or regional customers. In addition, to the extent a jurisdiction determines us not to be in compliance with regulatory requirements (including those related to data localization), we have been, and may again in the future be, subject to resource and time pressures in order to come back into compliance. Our inability to effect change in, or work with, these jurisdictions could adversely affect our ability to maintain or increase our revenues and extend our global brand.
Additionally, some jurisdictions have implemented, or may implement, foreign ownership restrictions, which could potentially have the effect of forcing or inducing the transfer of our technology and proprietary information as a condition of access to their markets. Such restrictions could adversely impact our ability to compete in these markets.
Privacy, Data Protection, AI and Information Security
Regulation and enforcement of privacy, data, AI, information security and the digital economy could increase our costs and lead to legal claims and fines, as well as negatively impact our growth and reputation.
We are subject to increasingly complex, fragmented and divergent laws and regulations related to privacy and data protection, data use and governance, AI and information security in the jurisdictions in which we do business. While policymakers around the globe look to the EU and the GDPR when adopting new or updated privacy and data protection laws, divergences have occurred and continue to occur. As a result, new or updated privacy and data protection and information security laws and regulations have led, and may continue to lead, to similar, stricter or at times conflicting requirements, creating an uncertain regulatory environment. For example, some jurisdictions have implemented or are otherwise considering requirements to collect, store and/or process data within their borders, as well as prohibitions on the transfer of data abroad, leading to technological and operational implications. Other jurisdictions have adopted or are otherwise considering adopting sector-specific regulations for the payments industry and other industries in which we participate, including forced data sharing requirements or additional verification requirements. In addition, laws and regulations on AI, data governance and credit decisioning may overlap or conflict with, or diverge from, general privacy rules. Overall, these myriad laws and regulations may require us to modify our data processing practices and policies, incur substantial compliance-related costs and expenses, and otherwise suffer adverse impacts on our business. Failure to comply with any of these laws, regulations and requirements could result in fines, sanctions or other enforcement actions or penalties, which could materially and adversely affect our results of operations and overall business, as well as have an impact on our reputation.
As a user and deployer of AI technology, we are also subject to increasing and evolving laws and regulations related to AI governance and new applications of existing laws and regulations to AI. How our use and deployment of AI will be regulated remains uncertain given the uncertainty that exists as to how AI technology will develop. In addition, the use of AI creates or amplifies risks that are challenging to fully prevent or mitigate. In particular, AI algorithms may generate inaccurate, unintended, unfair or discriminatory outcomes, which may not be easily detectable or explainable, and may inadvertently breach intellectual property, privacy or other rights, as well as confidential information. Our implementation of robust AI governance and risk management frameworks aimed at complying with emerging laws and regulations may not be sufficient protection against these emerging risks.
Further, as we acquire new companies and develop integrated and personalized products and services to meet the needs of a changing marketplace, we have expanded our data profile through additional data types and sources, across multiple channels, and involving new partners. This expansion has amplified the impact of these various laws and regulations on our business. As a result, we are required to constantly monitor our data practices and potentially change them when necessary or appropriate. We also need to provide increased care in our data management, governance and quality practices, particularly as it relates to the use of data in products leveraging AI.
New requirements or changing interpretations of existing requirements in these areas, or the development of new regulatory schemes related to the digital economy in general, may also increase our costs and/or restrict our ability to leverage data or use AI for innovation. This could impact the products and services we offer and other aspects of our business, such as fraud monitoring, the need for improved data management, governance and quality practices, the development of information-based products and solutions, and technology operations. In addition, these requirements may increase the costs to our customers of issuing payment
MASTERCARD 2023 FORM 10-K 29
PART I
ITEM 1A. RISK FACTORS
products or using information products, which may, in turn, decrease the number of our products that they offer. While we intend to comply with all regulatory requirements, innovate responsibly and deploy Privacy by Design, Data by Design and AI Governance approaches to all of our product development, the speed and pace of changes in laws (as well as stakeholder interests) may not allow us to meet rapidly evolving regulatory and stakeholder expectations. Any of these developments could materially and adversely affect our overall business and results of operations.
Other Regulation
Regulations that directly or indirectly apply to Mastercard as a result of our participation in the global payments industry may materially and adversely affect our overall business and results of operations.
We are subject to regulations that affect the payments industry in the many jurisdictions in which our products and services are used. Many of our customers are also subject to regulations applicable to banks and other financial institutions that, at times, consequently affect us. Such regulation has increased significantly in the last several years (as described in “Business - Government Regulation” in Part I, Item 1). Examples include:
• Anti-Money Laundering, Countering the Financing of Terrorism, Economic Sanctions and Anti-Corruption - We are subject to AML and CFT laws and regulations globally. Economic sanctions programs administered by OFAC restrict financial transactions and other dealings with certain countries and geographies, and persons and entities. We are also subject to anti-corruption laws and regulations globally, which, among other things, generally prohibit giving or offering payments or anything of value for the purpose of improperly influencing a business decision or to gain an unfair business advantage.
• Account-based Payments Systems - In the U.K., aspects of our Vocalink business are subject to the U.K. payment system oversight regime and are directly overseen by the Bank of England.
• Issuer and Acquirer Practices Legislation and Regulation - Certain regulations (such as PSD2 in the EEA) may impact various aspects of our business. For example, PSD2’s strong authentication requirement could increase the number of transactions that consumers abandon if we are unable to secure a frictionless authentication experience under these standards. An increase in the rate of abandoned transactions could adversely impact our volumes or other operational metrics.
Increased regulatory focus on us has resulted and may continue to result in significant compliance and governance burdens or otherwise increase our costs. Similarly, increased regulatory focus on our customers may cause such customers to reduce the volume of transactions processed through our systems, or may otherwise impact the competitiveness of our products. Actions by regulators could influence other organizations around the world to enact or consider adopting similar measures, amplifying any potential compliance burden. Additionally, our compliance with new economic sanctions and related laws with respect to particular jurisdictions or customers could result in a loss of business, which could be significant. Moreover, while our risk-based compliance program obligates issuers and acquirers to comply with U.S., EU and local sanctions programs (among other obligations), the failure of those issuers and acquirers to identify potential non-compliance issues either during or after their customer onboarding processes could ultimately impact our compliance with economic sanctions and related laws. Finally, failure to comply with the laws and regulations discussed above to which we are subject could result in fines, sanctions or other penalties. In particular, a violation and subsequent judgment or settlement against us, or those with whom we may be associated, under economic sanctions and AML, CFT, and anti-corruption laws could subject us to substantial monetary penalties, damages, and/or have a significant reputational impact. Each instance may individually or collectively materially and adversely affect our financial performance and/or our overall business and results of operations, as well as have an impact on our reputation.
We could be subject to adverse changes in tax laws, regulations and interpretations or challenges to our tax positions.
We are subject to tax laws and regulations of the U.S. federal, state and local governments as well as various non-U.S. jurisdictions. Current and potential future changes in existing tax laws, including regulatory guidance, are continuously being considered and have been or may be enacted (such as guidelines issued by the Organization for Economic Co-operation and Development (OECD) which impact how multinational enterprises are taxed on their global profits). These changes have and in the future may continue to have an impact on our effective income tax rate and tax payments. Similarly, changes in tax laws and regulations that impact our customers and counterparties, or the economy generally, have impacted and may continue to impact us as well.
In addition, tax laws and regulations are complex and subject to varying interpretations, and any significant failure to comply with applicable tax laws and regulations in all relevant jurisdictions could give rise to substantial penalties and liabilities. Jurisdictions around the globe have also increased tax-related audits, which require time and resources to resolve.
Any changes in enacted tax laws, rules, regulatory or judicial interpretations or guidance; any adverse outcome in connection with tax audits in any jurisdiction; or any changes in the pronouncements relating to accounting for income taxes could materially and adversely impact our effective income tax rate, tax payments, financial condition and results of operations.
30 MASTERCARD 2023 FORM 10-K
PART I
ITEM 1A. RISK FACTORS
Litigation
Liabilities we may incur or limitations on our business related to any litigation or litigation settlements could materially and adversely affect our results of operations.
We are a defendant in a number of civil litigations and regulatory proceedings and investigations, including among others, those alleging violations of competition and antitrust law and those involving intellectual property claims (as described in Note 21 (Legal and Regulatory Proceedings) to the consolidated financial statements included in Part II, Item 8). In the event we are found liable in any material litigations or proceedings (particularly in a large class-action lawsuit or on the basis of an antitrust claim entitling the plaintiff to treble damages or under which we were jointly and severally liable), we could be subject to significant damages, which could have a material adverse impact on our overall business and results of operations.
Certain limitations have been placed on our business in recent years because of litigation and litigation settlements, such as changes to our no-surcharge rule in the U.S. and Canada. Any future limitations on our business resulting from the outcomes of any litigation or regulatory proceeding, including any changes to our rules or business practices, could impact our relationships with our customers, including reducing the volume of business that we do with them, which may materially and adversely affect our overall business and results of operations.
Business and Operations
Competition and Technology
Substantial and intense competition worldwide in the global payments industry may materially and adversely affect our overall business and results of operations.
The global payments industry is highly competitive. Our payment programs compete against competitors both within and outside of the global payments industry and compete in all payment categories, including paper-based payments and all forms of electronic payments. We compete against general purpose payments networks, debit and local networks, ACH and real-time account-based payments systems, digital wallets and other fintechs (focused on online activity across various channels and processing payments using in-house capabilities), government-backed networks and digital currencies. We also face competition from companies that provide alternatives to our value-added services and new adjacent network capabilities (including open banking and digital identity).
Our traditional competitors may have substantially greater financial and other resources than we have, may offer a wider range of programs, services, and payment capabilities than we offer or may use more effective advertising and marketing strategies to achieve broader brand recognition and merchant acceptance than we have. They may also introduce their own innovative programs, value-added services and capabilities that adversely impact our growth.
Certain of our competitors to our core payment network operate three-party payments systems with direct connections to both merchants and consumers, potentially providing competitive advantages. If we continue to attract more regulatory scrutiny than these competitors because we operate a four-party system, or we are regulated because of the system we operate in a way in which our competitors are not, we could lose business to these competitors. See “Business - Competition” in Part I, Item 1.
Certain of our competitors have developed alternative payments systems, e-commerce payments systems and payments systems for mobile devices, as well as physical store locations. A number of these competitors rely principally on technology to support their services that provides cost advantages, and as a result may enjoy lower costs than we do. Many of these competitors are also able to use existing payment networks without being subject to many of the associated costs. Moreover, these competitors also occupy various roles in the payments ecosystem that enable them to influence payment choice of other participants. Any of these factors could put us at a competitive disadvantage.
Our ability to compete may also be affected by regulatory and legislative initiatives, as well as the outcomes of litigation, competition-related regulatory proceedings and both central bank and legislative activity.
If we are not able to differentiate ourselves from our competitors, drive value for our customers and/or effectively align our resources with our goals and objectives, we may not be able to compete effectively against these threats. Our failure to compete effectively against any of the foregoing threats could materially and adversely affect our overall business and results of operations.
MASTERCARD 2023 FORM 10-K 31
PART I
ITEM 1A. RISK FACTORS
Disintermediation from stakeholders both within and outside of the payments value chain could harm our business.
As the payments industry continues to develop and change, we face disintermediation and related risks, including:
• Parties that process our transactions in certain countries may try to eliminate our position as an intermediary in the payment process. For example, merchants could switch (and in some cases are switching) transactions directly with issuers. Additionally, processors could process transactions directly between issuers and acquirers. Large scale consolidation within processors could result in these processors developing bilateral agreements or in some cases switching the entire transaction on their own network, thereby disintermediating us.
• Industry participants continue to invest in and develop alternative capabilities, such as account-based payments, which could facilitate P2M transactions that compete with both our core payment network and our additional payment capabilities.
• Regulation (such as PSD2 in the EEA) may disintermediate issuers by enabling third-party providers opportunities to route payment transactions away from our network and products and towards other forms of payment by offering account information or payment initiation services directly to those who currently use our products. Such regulation may also provide these processors with the opportunity to commoditize the data that are included in the transactions they are servicing. If our customers are disintermediated in their business, we could face diminished demand for our products and services.
• Although we partner with fintechs and technology companies (such as digital players and mobile providers) that leverage our technology, platforms and networks to deliver their products, they could develop platforms or networks that disintermediate us from digital payments and impact our ability to compete in the digital economy. These companies may also develop products or services that compete with our customers within the payments ecosystem and, as a result, could diminish demand for our products and services. When we do partner with fintechs and technology companies, we face a heightened risk when we share data as part of those relationships. While we share this data in a controlled manner subject to applicable anonymization and privacy and data standards, sharing this data without proper oversight could provide partners with a competitive advantage.
• Competitors, customers, fintechs, technology companies, governments and other industry participants may develop products that compete with or replace products and services we currently provide to support our switched transaction and payments offerings. These products could either replace, or force us to change our pricing or practices, for these offerings. In addition, governments that develop or encourage the creation of national or international payments platforms may promote their platforms in such a way that could put us at a competitive disadvantage in those markets, or require us to compete differently.
• Participants in the payments industry may merge, create joint ventures or form other business combinations that may strengthen their existing business services or create new payment products and services that compete with our products and services.
Our failure to compete effectively against any of the foregoing competitive threats could materially and adversely affect our overall business and results of operations.
Continued intense pricing pressure may materially and adversely affect our overall business and results of operations.
In order to increase transaction volumes, enter new markets and expand our products and services, we seek to enter into business agreements with customers through which we offer incentives, pricing discounts and other support that promote our products. In order to stay competitive, we may have to increase the amount of these incentives and pricing discounts so as to meet customer demand for better pricing arrangements and greater rebates and incentives, which moderates our growth. Our inability to switch additional transaction volumes or to provide additional services to our customers at levels sufficient to compensate for such lower fees or increased costs in the future could materially and adversely affect our overall business and results of operations. In addition, increased pressure on prices increases the importance of cost containment and productivity initiatives in areas other than those relating to customer incentives.
In the future, we may not be able to enter into agreements with our customers if they require terms that we are unable or unwilling to offer, and we may be required to modify existing agreements in order to maintain relationships and to compete with others in the industry. Some of our competitors are larger with greater financial resources and accordingly may be able to charge lower prices to our customers. In addition, to the extent that we offer discounts or incentives under such agreements, we will need to further increase transaction volumes or the amount of services provided in order to benefit from such agreements and to increase revenue and profit, and we may not be successful in doing so, particularly in the current regulatory environment. Our customers also may implement cost reduction initiatives that reduce or eliminate payment product marketing or increase requests for greater incentives or greater cost stability. These factors could have a material adverse impact on our overall business and results of operations.
Additionally, we face pricing pressure related to real-time account-based payment schemes and cross-border payments (including the increased use of domestic real-time account-based payment schemes offering increasingly lower or subsidized pricing for P2M transactions as well as continued downward pressure on pricing for cross-border payments resulting from competition from real-time account-based payment schemes and from initiatives to lower the cost of cross-border payments to end users (such as the G20
32 MASTERCARD 2023 FORM 10-K
PART I
ITEM 1A. RISK FACTORS
Roadmap for Enhancing Cross-border Payments)). These factors could have a material adverse impact on our overall business and results of operations.
Rapid and significant technological developments and changes could negatively impact our overall business and results of operations or limit our future growth.
The payments industry is subject to rapid and significant technological changes, which can impact our business in several ways:
• Technological changes (including continuing developments of technologies in the areas of smart cards and devices, contactless and mobile payments, e-commerce, cryptocurrency and blockchain, AI, machine learning, privacy enhancement and cybersecurity) could result in new technologies that may be superior to, or render obsolete, the technologies we currently use in our programs and services. Moreover, these changes could result in new and innovative payment methods, products and services that could place us at a competitive disadvantage and that could reduce the use of our products and services.
• We rely in part on third parties (including some of our competitors and potential competitors) for the development of and access to new technologies. The inability of these companies to keep pace with technological developments, or the acquisition of these companies by competitors, could negatively impact our offerings.
• Our ability to develop and adopt new services and technologies may be inhibited by industry-wide solutions and standards (such as those related to EMV, tokenization or other safety and security technologies), and by resistance from customers or merchants to such changes.
• Our ability to develop evolving systems and products may be inhibited by any difficulty we may experience in attracting and retaining employees with technology expertise.
• Our ability to adopt these technologies can also be inhibited by intellectual property rights of third parties. We have received, and we may in the future receive, notices or inquiries from patent holders (including operating companies or non-practicing entities) suggesting that we may be infringing patents or that we need to license the use of their patents to avoid infringement. Such notices may, among other things, threaten litigation against us or our customers or demand significant license fees.
• Our ability to develop new technologies and reflect technological changes in our payments offerings requires resources, which has resulted in and may further result in additional expenses.
• We work with fintechs, technology companies (such as digital players and mobile providers) and traditional customers that use our technology to enhance payment safety and security and to deliver their payment-related products and services quickly and efficiently to consumers. Our inability to keep pace technologically could negatively impact the willingness of these customers to work with us, and could encourage them to use their own technology and compete against us.
• Regulatory or government requirements have and could continue to require us to host and deliver certain products and services on-soil in certain markets, requiring us to alter our technology and delivery model, potentially resulting in additional expenses.
• Various central banks are experimenting with CBDCs which may be launched with their own networks to transfer money between participants. Policy and design considerations that governments adopt could impact the extent of our role in facilitating CBDC-based payment transactions, potentially impacting the transactions that we may process over our network.
We cannot predict the effect of future technological changes on our business, and our future success will depend, in part, on our ability to anticipate, develop or adapt to technological changes and evolving industry standards. Failure to keep pace with these technological developments or otherwise bring to market products that reflect these technologies could lead to a decline in the use of our products, which could have a material adverse impact on our overall business and results of operations.
Operating a real-time account-based payments network presents risks that could materially affect our business.
U.K. regulators have designated Vocalink, our real-time account-based payments network platform, to be a “specified service provider” and regulators in other countries may in the future expand their regulatory oversight of real-time account-based payments systems in similar ways. In addition, any prolonged service outage on this network could result in quickly escalating impacts, including potential intervention by the Bank of England and significant reputational risk to Vocalink and us. For a discussion of the regulatory risks related to our real-time account-based payments platform and oversight by regulators, see our risk factor in “Risk Factors - Payments Industry Regulation” in this Part I, Item 1A. Furthermore, the complexity of this payment technology requires careful management to address information security vulnerabilities that are different from those faced on our core payment network. Operational difficulties, such as the temporary unavailability of our services or products, or information security breaches on our real-time account-based payments network could cause a loss of business for these products and services, result in potential liability for us and adversely affect our reputation.
MASTERCARD 2023 FORM 10-K 33
PART I
ITEM 1A. RISK FACTORS
Working with new customers and end users as we expand our multi-rail solutions and products and services can present operational and onboarding challenges, be costly and result in reputational damage if the new products or services do not perform as intended.
The payments markets in which we compete are characterized by rapid technological change, new product introductions, evolving industry standards and changing customer and consumer needs. In order to remain competitive and meet the needs of the payments markets, we are continually involved in developing and implementing complex multi-rail solutions and diversifying our products and services. These efforts carry the risks associated with any diversification initiative, including cost overruns, delays in delivery and performance problems. These projects also carry risks associated with working with different types of customers (such as corporations that are not financial institutions, non-governmental organizations (“NGOs”) and new end users). These differences may present new operational challenges, such as enhanced infrastructure and monitoring for less regulated customers.
Our failure to effectively design and deliver these multi-rail solutions and products and services could make our other offerings less desirable to these customers, or put us at a competitive disadvantage. In addition, if there is a delay in the implementation of our products or services (which could include compliance obligations, such as AML and CFT, and licensing requirements for our products and services that operate under regulatory licenses), if our products or services do not perform as anticipated, or we are unable to otherwise adequately anticipate risks related to new types of customers, we could face additional regulatory scrutiny, fines, sanctions or other penalties, which could materially and adversely affect our overall business and results of operations, as well as negatively impact our brand and reputation.
Information Security and Operational Resilience
Information security incidents or account data compromise events could disrupt our business, damage our reputation, increase our costs and cause losses.
Information security risks for payments and technology companies such as ours have significantly increased in recent years in part because of the proliferation of new technologies, the use of the Internet and telecommunications technologies to conduct financial transactions, and the increased sophistication and activities of organized crime, hackers, “hacktivists”, terrorists, nation-states, state-sponsored actors and other external parties. These threats may derive from fraud or malice on the part of our employees or third parties, or may result from human error, software bugs, server malfunctions, software or hardware failure or other technological failure. These threats include cyber-attacks such as computer viruses, denial-of-service attacks, malicious code (including ransomware), social-engineering attacks (including phishing attacks) or information security breaches and could lead to the misappropriation or loss of consumer account and other information and identity theft. These types of threats have risen significantly due to a significant portion of our workforce working in a hybrid environment. These threats also may be further enhanced in frequency or effectiveness through threat actors’ use of AI.
Our operations rely on the secure transmission, storage and other processing of confidential, proprietary, sensitive and personal information and technology in our computer systems and networks, as well as the systems of our third-party providers. Our customers and other parties in the payments value chain, as well as account holders, rely on our digital technologies, computer systems, software and networks to conduct their operations. In addition, to access our products and services, our customers and account holders increasingly use personal smartphones, tablet PCs and other mobile devices that may be beyond our control. We, like other financial technology organizations, routinely are subject to cyber-threats and our technologies, systems and networks, as well as the systems of our third-party providers, have been subject to attempted cyber-attacks. Because of our position in the payments value chain, we believe that we are likely to continue to be a target of such threats and attacks. Geopolitical events and resulting government activity could also lead to information security threats and attacks by affected or sympathizing jurisdictions or other actors, which could put our information and assets at risk, as well as result in network disruption.
To date, we have not experienced any material impact relating to cyber-attacks or other information security breaches. However, future attacks or breaches could lead to security breaches of the networks, systems (including third-party provider systems) or devices that our customers use to access our products and services, which in turn could result in the unauthorized disclosure, release, gathering, monitoring, misuse, loss or destruction of confidential, proprietary, sensitive and personal information (including account data information) or data security compromises. Such attacks or breaches could also cause service interruptions, malfunctions or other failures in the physical infrastructure, networks or operations systems that support our business and customers (such as the lack of availability of our value-added services), as well as the operations of our customers or other third parties. In addition, they could lead to damage to our reputation with our customers, other stakeholders and the broader payments ecosystem, additional costs to us (such as repairing systems, adding new personnel or protection technologies or compliance costs), regulatory penalties, financial losses to both us and our customers and partners and the loss of customers and business opportunities. These consequences could be further pronounced in jurisdictions in which we are deemed critical national infrastructure. If such attacks are not detected immediately, or disclosed as required by law, their effect could be compounded.
34 MASTERCARD 2023 FORM 10-K
PART I