Item 1. Business
ITEM 1. BUSINESS
Preferential or Protective Government Actions. Some governments have taken action to provide resources, preferential treatment or other protection to selected domestic payments and processing providers, as well as to create their own national providers. For example, governments in some countries (such as South Africa) mandate switching of domestic payments either entirely in that country or by only domestic companies. Some jurisdictions are currently considering adopting or have adopted data localization requirements, which mandate the collection, storage, and/or other processing of data within their borders. This is the case, for instance, in India, China and Saudi Arabia. Various forms of data localization requirements or data transfer restrictions are also under consideration in other countries and jurisdictions, including the EU.
Anti-Money Laundering, Countering the Financing of Terrorism, Economic Sanctions and Anti-Corruption. We are subject to anti-money laundering (“AML”) and countering the financing of terrorism (“CFT”) laws and regulations globally, including the U.S. Bank Secrecy Act and the USA PATRIOT Act, as well as the various economic sanctions programs, including those imposed and administered by the U.S. Office of Foreign Assets Control (“OFAC”) and the European Union. We have implemented a comprehensive AML/CFT program, comprised of policies, procedures and internal controls, including the designation of a compliance officer, which is designed to prevent our payment network from being used to facilitate money laundering and other illicit activity and to address these legal and regulatory requirements and assist in managing money laundering and terrorist financing risks. The economic sanctions programs administered by OFAC restrict financial transactions and other dealings with certain countries and geographies (specifically Crimea, the Donetsk People’s Republic and Luhansk People’s Republic regions of Ukraine, Cuba, Iran and North Korea) and with persons and entities included in OFAC sanctions lists including its list of Specially Designated Nationals and Blocked Persons (the “SDN List”). We take measures to prevent transactions that do not comply with OFAC and other applicable sanctions, including establishing a risk-based compliance program that has policies, procedures and controls designed to prevent us from having unlawful business dealings with prohibited countries, regions, individuals or entities. As part of this program, we obligate issuers and acquirers to comply with their local sanctions obligations and U.S. and EU sanctions programs. In the U.S., these obligations include requiring the screening of account holders and merchants against OFAC sanctions lists (including the SDN List). Iran and Syria have been identified by the U.S. State Department as terrorist-sponsoring states. We do not maintain operations, assets or licensed customers in Iran. While we currently have no operations in Syria, we are evaluating market entry in strict accordance with applicable laws and restrictions. We are also subject to anti-corruption laws and regulations globally, including the U.S. Foreign Corrupt Practices Act and the U.K. Bribery Act, which, among other things, generally prohibit giving or offering payments or anything of value for the purpose of improperly influencing a business decision or to gain an unfair business advantage. We have implemented policies, procedures and internal controls to proactively manage corruption risk.
Issuer and Acquirer Practices Legislation and Regulation. Our issuers and acquirers are subject to numerous regulations and investigations applicable to banks, financial institutions and other licensed entities, which can indirectly impact us. Additionally, regulations such as the EU’s Payment Services Directive in the EEA require financial institutions to provide third-party payment processors access to consumer payment accounts, enabling them to route transactions away from Mastercard products and provide payment initiation and account information services directly to consumers who use our products.
Regulation of Internet and High-Risk Merchant Categories. Various jurisdictions have enacted regulation related to internet transactions (such as laws surrounding gambling, including fantasy sports), which impacts both us and our customers. We are also impacted by evolving laws surrounding certain legally permissible but high-risk merchant categories, such as adult content, firearms, alcohol and tobacco.
Privacy, Data, AI and Information Security. Aspects of our operations or business are subject to increasingly complex, fragmented, overlapping and/or divergent privacy, data, AI and information security laws and regulations in the U.S., the EU and elsewhere around the world. For example, in the U.S., we and our customers are respectively subject to, among other laws and regulations, Federal Trade Commission and federal banking agency information safeguarding requirements under the Gramm-Leach-Bliley Act (GLBA) that require, among other things, the maintenance of a written, comprehensive information security program and, increasingly, a number of state data and privacy laws. We and our customers may also be subject (where applicable) to evolving U.S. federal and/or state AI and data laws and regulations, including those related to national security. With respect to information security, we are subject to new and evolving cyber notification regimes, including data protection authorities, cyber authorities and law-enforcement. We are also subject to public disclosure requirements related to cyber incidents, such as the U.S. Securities and Exchange Commission (the SEC) disclosure rules that require, among other things, disclosing material cybersecurity incidents in a Current Report on Form 8-K, generally within four business days of determining an incident is material. In the EU, we are subject to the General Data Protection Regulation (the GDPR) and its equivalent in the U.K., which requires, among other things, a comprehensive privacy, data protection and information security program to protect the personal and sensitive data of EEA residents. Several regulators and policymakers around the globe use the GDPR as a reference to adopt new or updated privacy, data and information security laws and regulations, although divergences have occurred. Laws and regulations in this area are constantly evolving due to several factors, including increasing data collection and data flows, numerous data breaches and security incidents, more sensitive data categories, and emerging technologies such as AI (which is now subject to regulation in the EU as well as other
MASTERCARD 2025 FORM 10-K 25
PART I
ITEM 1. BUSINESS
places). In addition, the interpretation and application of these privacy, data, AI and information security laws and regulations are often uncertain and in a state of flux, thus requiring constant monitoring and governance.
Additional Regulatory Developments. Various regulatory agencies around the world continue to examine a wide variety of issues that could impact us, including evolving laws and guidance surrounding buy-now-pay-later, open finance, credit reporting, digital currencies (including stablecoins), marijuana, prepaid payroll cards, identity theft, account management guidelines, disclosure rules, marketing and operational resilience. Additionally, various jurisdictions have adopted or are increasingly considering adopting laws, regulations and oversight expectations requiring disclosure on environmental, social and governance matters. The focus of such efforts includes climate-related matters, as well as social matters, such as human rights, the treatment of employees and other workforce-related matters.
Additional Information
Mastercard Incorporated was incorporated as a Delaware corporation in May 2001. We conduct our business principally through our principal operating subsidiary, Mastercard International Incorporated, a Delaware non-stock (or membership) corporation that was formed in November 1966. For more information about our capital structure, including our Class A common stock (our voting stock) and Class B common stock (our non-voting stock), see Note 14 (Stockholders' Equity) to the consolidated financial statements included in Part II, Item 8.
Website and SEC Reports
Our internet address is www.mastercard.com. From time to time, we may use our corporate website as a channel of distribution of material company information. Financial and other material information is routinely posted and accessible on the investor relations section of our corporate website. You can also visit “Investor Alerts” in the investor relations section to enroll your email address to automatically receive email alerts and other information about Mastercard.
Our annual report on Form 10-K, quarterly reports on Form 10-Q, current reports on Form 8-K and amendments to those reports are available for review, without charge, on the investor relations section of our corporate website as soon as reasonably practicable after they are filed with, or furnished to, the SEC. The information contained on our corporate website, including, but not limited to, our Impact Report and our U.S. Consolidated EEO-1 Report, is not incorporated by reference into this Report. Our filings are also available electronically from the SEC at www.sec.gov.
26 MASTERCARD 2025 FORM 10-K
PART I
ITEM 1A. RISK FACTORS
Item 1A. Risk factors
RISK HIGHLIGHTS
Legal and Regulatory Business and Operations
Payments Industry Regulation Competition and Technology Brand, Reputational Impact and Environmental, Social and Governance
Preferential or Protective Government Actions Information Security and Operational Resilience Talent and Culture
Privacy, Data, AI and Information Security
Stakeholder Relationships Acquisitions and Strategic Investments
Other Regulation Global Economic and Political Environment Settlement and Third-Party Obligations
Litigation
Class A Common Stock and Governance Structure
Legal and Regulatory
Payments Industry Regulation
Global regulatory and legislative activity related to the payments industry may have a material adverse impact on our overall business and results of operations.
Central banks and similar regulatory bodies have increasingly established or further expanded their authority over certain aspects of payments systems such as ours, including obligations or restrictions with respect to the types of products and services that we may offer, the countries in which our products and services may be used, the way we structure and operate our business and the types of consumers and merchants who can obtain or accept our products or services. Similarly, jurisdictions that regulate a particular product may consider extending their jurisdiction to other products. For example, debit regulations could lead to regulation of credit products. Moreover, several jurisdictions are demonstrating increased interest about the network fees we charge to our customers (in some cases as part of broader market reviews of retail payments), which could in the future lead to regulation relating to our network fees. In several jurisdictions, we have been designated as a “systemically important payment system”, with other regulators considering similar designations. This type of regulation and oversight is related to switching activities, and includes policies, procedures and requirements related to risk management, collateral, participant default, timely switching of financial transactions, and capital and financial resources. Parts of our business have also been deemed as a “specified service provider” or considered “critical infrastructure”. The impact to our business created by any new law, regulation or designation is magnified by the potential it has to be replicated in, or conflict with, other jurisdictions, or involve other products within any particular jurisdiction.
Our strategic expansion of our products and services has also created the need for us to obtain new types and increasing numbers of regulatory licenses, resulting in increased supervision and additional compliance burdens distinct from those imposed on our payment network activities. For example, certain of our subsidiaries maintain money transfer licenses that typically impose supervisory and examination requirements, as well as capital, safeguarding, risk management and other business obligations.
Increased regulation and oversight of payments systems, as well as increased exposure to regulation resulting from changes to our products and services, have resulted and may continue to result in significant compliance and governance burdens or otherwise increase our costs. As a result, customers could be less willing to participate in our payments system and/or use our other products or services, reduce the benefits offered in connection with the use of our products (making our products less desirable to consumers), reduce the volume of domestic and cross-border transactions or other operational metrics, disintermediate us, impact our profitability and/or limit our ability to innovate or offer differentiated products and services, all of which could materially and adversely impact our financial performance. In addition, any regulation that is enacted related to the type and level of network fees we charge our customers could also materially and adversely impact our results of operations. Regulators could also require us to obtain prior approval for changes to our system rules, procedures or operations, or could require customization with regard to such
MASTERCARD 2025 FORM 10-K 27
PART I
ITEM 1A. RISK FACTORS
changes, which could negatively impact us. Moreover, failure to comply with the laws and regulations to which we are subject could result in fines, sanctions, civil damages or other penalties, which could materially and adversely affect our overall business and results of operations, as well as have an impact on our brand and reputation.
Increased activity with respect to interchange rates could have an adverse impact on our business.
Interchange rates are a significant component of the costs that merchants pay in connection with the acceptance of products associated with our payment network. Although we do not earn revenues from interchange, interchange rates can impact the volume of transactions we see on our payment products. If interchange rates are too high, merchants may stop accepting our products or route transactions away from our network. If interchange rates are too low, issuers may stop promoting our products and services, eliminate or reduce loyalty rewards programs or other account holder benefits (e.g., free checking or low interest rates on balances), or charge fees to account holders (e.g., annual fees or late payment fees).
Governments and merchant groups in a number of countries have implemented or are seeking interchange rate reductions through legislation, regulation and litigation. See “Business - Government Regulation” in Part I, Item 1 and Note 19 (Legal and Regulatory Proceedings) to the consolidated financial statements included in Part II, Item 8 for more details.
If issuers cannot collect or we are required to reduce interchange rates, issuers may be less willing to participate in our four-party payments system. Alternatively, they may reduce the benefits associated with our products, choose to charge higher fees to consumers to attempt to recoup a portion of the costs incurred for their services, or seek a fee reduction from us to decrease the expense of their payment programs (particularly if regulation has a disproportionate impact on us as compared to our competitors in terms of the fees we can charge). These and other impacts could make our products less desirable to consumers, limit our ability to innovate or offer differentiated products, and/or make proprietary three-party networks or other forms of payment more attractive, ultimately reducing the volume of transactions over our network and our profitability.
We are devoting substantial resources to defending our right to establish interchange rates in regulatory proceedings, litigation and legislative activity. The potential outcome of any of these activities could have a more positive or negative impact on us relative to our competitors. If we are ultimately unsuccessful in defending our ability to establish interchange rates, any resulting legislation, regulation and/or litigation may have a material adverse impact on our overall business and results of operations. In addition, regulatory proceedings and litigation could result (and in some cases has resulted) in us being fined and/or having to pay civil damages, the amount of which could be material.
Limitations on our ability to restrict merchant surcharging could materially and adversely impact our results of operations.
We have historically implemented policies, referred to as no-surcharge rules, in certain jurisdictions, including the U.S. and Canada, that prohibit merchants from charging higher prices to consumers who pay using our products instead of other means. Authorities in several jurisdictions have acted to end or limit the application of these no-surcharge rules (or indicated interest in doing so). Additionally, our no-surcharge rules now permit U.S. and Canadian merchants to surcharge credit cards (subject to certain limitations). If, over time, an increased number of merchants choose to surcharge as permitted, this could result in consumers viewing our products less favorably and/or using alternative means of payment. These responses could result in a decrease in our overall transaction volumes, which in turn could materially and adversely impact our results of operations.
Preferential or Protective Government Actions
Preferential or protective government actions related to domestic payment services could adversely affect our ability to maintain or increase our revenues.
Governments in some countries have acted, or in the future may act, to provide resources, preferential treatment or other protection to selected national or domestic payment and switching providers, or have created, or may in the future create, their own national provider. These actions may displace us from, prevent us from entering into, or substantially restrict us from participating in, particular geographies, and may prevent us from competing effectively against those providers. For example:
• Governments in some countries have implemented, or may implement, regulatory requirements that mandate switching of domestic payments either entirely in that country or by only domestic companies.
• Some jurisdictions have implemented, or are considering implementing, requirements to collect, store and/or process data within their borders, as well as prohibitions on the transfer of data abroad, leading to technological and operational implications as well as increased compliance burdens and other costs.
• Geopolitical events and any resulting OFAC sanctions, adverse trade policies, enforcement of U.S. laws related to countering the financing of terrorism, economic sanctions and anti-corruption, or other types of government actions could lead affected or other jurisdictions to take actions in response that could adversely affect our business. Moreover, because of various concerns jurisdictions may have with respect to our business, including any decisions we may make relating to entering or exiting a
28 MASTERCARD 2025 FORM 10-K
PART I
ITEM 1A. RISK FACTORS
particular market, such jurisdictions may decide to begin to or increase their focus on growing local payment networks and other solutions.
• Regional groups of countries are considering, or may consider, efforts to restrict our switching of regional transactions.
• Governments have been increasingly creating and expanding local payments structures, which are increasingly being considered as alternatives to traditional domestic payment solutions and schemes such as ours.
Such developments prevent us from utilizing our global switching capabilities for domestic or regional customers. In addition, to the extent a jurisdiction determines us not to be in compliance with regulatory requirements (including those related to data localization), we have been, and may again in the future be, subject to resource and time pressures in order to come back into compliance. Our inability to effect change in, or work with, these jurisdictions could adversely affect our ability to maintain or increase our revenues and extend our global brand.
Additionally, some jurisdictions have implemented, or may implement, foreign ownership restrictions, which could potentially have the effect of forcing or inducing the transfer of our technology and proprietary information as a condition of access to their markets. Such restrictions could adversely impact our ability to compete in these markets.
Privacy, Data, AI and Information Security
Regulation and enforcement of privacy, data, AI, information security and the digital economy could increase our costs and lead to legal claims and fines, as well as negatively impact our growth and reputation.
We are subject to increasingly complex, fragmented, overlapping and/or divergent laws and regulations related to privacy and data protection, data use and governance, AI and information security (including with respect to cybersecurity and cyber-risk) in the jurisdictions in which we do business. New or updated laws and regulations have led, and may continue to lead, to similar, stricter or at times conflicting requirements, creating an uncertain regulatory environment. For example, some jurisdictions have implemented or are otherwise considering requirements to collect, store and/or process data within their borders, as well as prohibitions on the transfer of and access to data abroad, leading to technological and operational implications. Other jurisdictions have adopted or are otherwise considering adopting sector-specific regulations for the payments industry and other industries in which we participate, including forced data sharing requirements or additional verification requirements. With respect to information security, any single breach could require parallel notifications to data protection authorities, cyber authorities and/or law-enforcement, often requiring different thresholds, reporting deadlines and formats. In addition, laws and regulations on AI, data governance and credit decisioning may overlap or conflict with, or diverge from, general privacy rules. Overall, these myriad laws and regulations may require us to modify or limit our data processing practices and policies, incur substantial compliance-related costs and expenses, and otherwise suffer adverse impacts on our business. Failure to comply with any of these laws, regulations and requirements (including as a result of conflicting regulations) could result in fines, sanctions or other enforcement actions or penalties (both civil and criminal), which could materially and adversely affect our results of operations and overall business, as well as have an impact on our reputation.
As a user and deployer of AI technology, we are also subject to increasing and evolving laws and regulations related to AI governance, including the EU AI Act, and new applications of existing laws and regulations to AI. How our use and deployment of AI will be regulated is still developing as policymakers around the world consider how to regulate AI, and uncertainty remains as to how AI technology or its application (such as in agentic commerce) will continue to advance. In addition, the use of AI creates or amplifies risks that are challenging to fully prevent or mitigate. In particular, AI algorithms may generate inaccurate, unintended, unfair, biased or discriminatory outcomes (which may not be easily detectable or explainable) and may inadvertently disclose confidential information and/or breach intellectual property, privacy or other rights. Our implementation of robust AI governance and risk management frameworks, designed to ensure our responsible use of AI and help us to comply with emerging laws and regulations, may not be sufficient protection against these emerging risks.
Further, as we acquire new companies and develop integrated and personalized products and services to meet the needs of a changing marketplace, we have expanded and may further expand our data profile through additional data types and sources, across multiple channels, and involving new partners. This expansion has amplified and may continue to amplify the impact of these various laws and regulations on our business or subject us to new laws and regulations. For example, as a provider of global threat intelligence services through Recorded Future, we are subject to increased exposure to certain laws and regulations, including global cybercrime and other laws and regulations in various jurisdictions. As a result, we are required to constantly monitor our data practices and potentially change them when necessary or appropriate. We also need to provide increased care in our data management, governance, quality and accuracy practices, particularly as it relates to the use of data in products leveraging AI.
New requirements and rules, or changing interpretations of existing requirements in these areas, or the development of new regulatory schemes related to the digital economy in general, may also increase our costs and/or restrict our ability to leverage data or use AI for innovation. This could impact the products and services we offer and other aspects of our business, such as fraud
MASTERCARD 2025 FORM 10-K 29
PART I
ITEM 1A. RISK FACTORS
monitoring, the need for improved data management, governance, quality and accuracy practices, the development of information-based products and solutions, and technology operations. In addition, these requirements may increase the costs to our customers of issuing payment products or using information products, which may, in turn, decrease the number of our products that they offer. While we intend to comply with all regulatory requirements, innovate responsibly and deploy Privacy by Design, Data by Design and AI Governance approaches to all of our product development, the speed and pace of changes in laws (as well as stakeholder interests) may not allow us to meet rapidly evolving regulatory and stakeholder expectations. Any of these developments could materially and adversely affect our overall business and results of operations.
Other Regulation
Regulations that directly or indirectly apply to Mastercard as a result of our participation in the global payments industry may materially and adversely affect our overall business and results of operations.
We are subject to regulations that affect the payments industry in the many jurisdictions in which our products and services are used. Many of our customers are also subject to regulations applicable to banks and other financial institutions that, at times, consequently affect us. Such regulation has increased significantly in the last several years (as described in “Business - Government Regulation” in Part I, Item 1). Examples include:
• Anti-Money Laundering, Countering the Financing of Terrorism, Economic Sanctions and Anti-Corruption . We are subject to AML and CFT laws and regulations globally. Economic sanctions programs administered by OFAC restrict financial transactions and other dealings with certain countries and geographies, and persons and entities. We are also subject to anti-corruption laws and regulations globally, which, among other things, generally prohibit giving or offering payments or anything of value for the purpose of improperly influencing a business decision or to gain an unfair business advantage.
• Account-based Payments Systems . In the U.K., aspects of our Vocalink business are subject to the U.K. payment system oversight regime and are directly overseen by the Bank of England.
• Issuer and Acquirer Practices Legislation and Regulation. Certain regulations or legislation that do or could impact our issuers and acquirers (such as caps on issuer interest rates) may impact various aspects of our business. Additionally, strong authentication requirements within the EU’s Payment Services Directive in the EEA could increase the number of transactions consumers abandon if we are unable to secure a frictionless authentication experience under these standards. Such an increase could adversely impact our volumes or other operational metrics.
Increased regulatory focus on us has resulted and may continue to result in significant compliance and governance burdens or otherwise increase our costs. Similarly, increased regulatory focus on our customers and other stakeholders may cause them to reduce the volume of transactions processed through our systems, or may otherwise impact the competitiveness of our products. Actions by regulators could influence other organizations around the world to enact or consider adopting similar measures, amplifying any potential compliance burden. Additionally, our compliance with new economic sanctions and related laws with respect to particular jurisdictions or customers could result in a loss of business, which could be significant. Moreover, while our risk-based compliance program obligates issuers and acquirers to comply with U.S., EU and local sanctions programs (among other obligations), the failure of those issuers and acquirers to identify potential non-compliance issues either during or after their customer onboarding processes could ultimately impact our compliance with economic sanctions and related laws. Finally, failure to comply with the laws and regulations discussed above to which we are subject could result in fines, sanctions or other penalties. In particular, a violation and subsequent judgment or settlement against us, or those with whom we may be associated, under economic sanctions and AML, CFT, and anti-corruption laws could subject us to substantial monetary penalties, damages, and/or have a significant reputational impact. Each instance may individually or collectively materially and adversely affect our financial performance and/or our overall business and results of operations, as well as have an impact on our reputation.
We could be subject to adverse changes in tax laws, regulations and interpretations or challenges to our tax positions.
We are subject to tax laws and regulations of the U.S. federal, state and local governments as well as various non-U.S. jurisdictions. Current and potential future changes in existing tax laws, including regulatory guidance, are continuously being considered and have been or may be enacted (such as guidelines issued by the Organization for Economic Co-operation and Development (OECD) which impact how multinational enterprises are taxed on their global profits). These changes have and in the future may continue to have an impact on our effective income tax rate and tax payments. Similarly, changes in tax laws and regulations that impact our customers and counterparties, or the economy generally, have impacted and may continue to impact us.
In addition, tax laws and regulations are complex and subject to varying interpretations, and any significant failure to comply with applicable tax laws and regulations in all relevant jurisdictions could give rise to substantial penalties and liabilities. Jurisdictions around the globe have also increased tax-related audits, which require time and resources to resolve.
30 MASTERCARD 2025 FORM 10-K
PART I
ITEM 1A. RISK FACTORS
Any changes in enacted tax laws, rules, regulatory or judicial interpretations or guidance; any adverse outcome in connection with tax audits in any jurisdiction; or any changes in the pronouncements relating to accounting for income taxes could materially and adversely impact our effective income tax rate, tax payments, financial condition and results of operations.
Litigation
Liabilities or business limitations resulting from litigation could materially and adversely affect our results of operations.
We are a defendant in a number of civil litigations and regulatory proceedings and investigations, including among others, those alleging violations of competition and antitrust law and those involving intellectual property claims (as described in Note 19 (Legal and Regulatory Proceedings) to the consolidated financial statements included in Part II, Item 8). In the event we are found liable in any material litigations or proceedings (particularly in a large class-action lawsuit or on the basis of an antitrust claim entitling the plaintiff to treble damages or under which we were jointly and severally liable), we could be subject to significant damages, which could have a material adverse impact on our overall business and results of operations.
Certain limitations have been placed on our business because of litigation and litigation settlements, such as changes to our no-surcharge rule in the U.S. and Canada. Any future limitations resulting from the outcomes of any litigation and litigation settlements (such as the Rules Relief Class settlement as described in Note 19 (Legal and Regulatory Proceedings) to the consolidated financial statements included in Part II, Item 8) or regulatory proceeding, including any changes to our rules or business practices, could impact our relationships with our customers, including reducing the volume of business that we do with them, which may materially and adversely affect our overall business and results of operations.
Business and Operations
Competition and Technology
Substantial and intense competition worldwide in the global payments industry may materially and adversely affect our overall business and results of operations.
The global payments industry is highly competitive. Our payment programs compete against competitors both within and outside of the global payments industry and compete in all payment categories, including paper-based payments and all forms of electronic payments. We compete against general purpose payments networks, debit and local networks, ACH and real-time account-based payments systems, digital wallets and other fintechs (focused on online activity across various channels and processing payments using in-house capabilities), digital public infrastructure and other government-backed solutions and digital currencies. We also face competition from companies that provide alternatives to our services and other solutions.
Our traditional competitors may have substantially greater financial and other resources than we have, may offer a wider range of programs, services, and payment capabilities than we offer or may use more effective advertising and marketing strategies to achieve broader brand recognition and merchant acceptance than we have. They may also introduce their own innovative programs, services and capabilities that adversely impact our growth.
Certain of our competitors to our payment network operate three-party payments systems with direct connections to both merchants and consumers, potentially providing competitive advantages. If we continue to attract more regulatory scrutiny than these competitors because we operate a four-party system, or we are regulated because of the system we operate in a way in which our competitors are not, we could lose business to these competitors. See “Business - Competition” in Part I, Item 1.
Certain of our competitors have developed alternative, e-commerce and/or mobile device payments systems, as well as physical store locations. A number of these competitors rely principally on technology to support their services that provides cost advantages, and as a result may benefit from lower costs than we do. Many of these competitors are also able to use existing payment networks without being subject to many of the associated costs. Moreover, these competitors also occupy various roles in the payments ecosystem that enable them to influence payment choice of other participants. With respect to government-backed solutions, including those involving DPI, government participation in structures could prevent us from entering into, or substantially restrict us from participating in, particular geographies. Any of these factors could put us at a competitive disadvantage.
Our ability to compete may also be affected by regulatory and legislative initiatives, as well as the outcomes of litigation, competition-related regulatory proceedings and both central bank and legislative activity.
If we are not able to differentiate ourselves from our competitors, drive value for our customers and/or effectively align our resources with our goals and objectives, we may not be able to compete effectively against these threats. Our failure to compete effectively against any of the foregoing threats could materially and adversely affect our overall business and results of operations.
MASTERCARD 2025 FORM 10-K 31
PART I
ITEM 1A. RISK FACTORS
Disintermediation from stakeholders both within and outside of the payments value chain could harm our business.
As the payments industry continues to develop and change, we face disintermediation and related risks, including the following:
• Parties that process our transactions in certain countries (such as merchants and third-party payment processors) may try to eliminate our position as an intermediary in the payment process by switching transactions directly with issuers or processing transactions directly between issuers and acquirers.
• Payments industry participants may develop their own products and services to support our switched transaction and payments offerings, forcing us to change our pricing or practices for our own offerings in order to compete. Participants may also withhold rights to data we use to power our solutions in order to support their own potential future solutions, potentially impacting the effectiveness of our solutions. In addition, governments may promote their own national or international payments platforms, potentially putting us at a competitive disadvantage in those markets, or requiring us to compete differently. Moreover, as central banks experiment with CBDCs, policies and design considerations that governments adopt could impact the extent of our role in facilitating CBDC-based payment transactions, potentially impacting the transactions that we may process over our network.
• Payments industry participants continue to invest in and develop alternative capabilities, such as account-based payments, which could facilitate P2M transactions that compete with both our payment network and our additional payments capabilities.
• Fintechs and technology companies could develop platforms or networks that disintermediate us from digital payments as well as develop products or services that compete with our customers and could diminish demand for our products and services. In addition, we face a heightened risk that data we share with these companies as part of our products and services could be used in a way that could put us at a competitive disadvantage.
• Payments industry participants may merge, create joint ventures or form other business combinations that may strengthen their existing business services, leverage other business models to create a competitive edge over us or create new payment products and services that compete with our products and services.
• Regulation may disintermediate issuers by enabling third-party providers opportunities to route payment transactions toward their own forms of payment by offering account information or payment initiation services directly to our product users. Such regulation may also provide these processors with the opportunity to commoditize the data that are included in the transactions they are servicing. Disintermediation of our customers’ business could diminish demand for our products and services.
Our failure to compete effectively against any of the foregoing competitive threats could materially and adversely affect our overall business and results of operations.
Continued intense pricing pressure may materially and adversely affect our overall business and results of operations.
In order to increase transaction volumes, enter new markets and expand our products and services, we seek to enter into business agreements with customers through which we offer incentives, pricing discounts and other support that promote our products. In order to stay competitive, we may have to increase the amount of these incentives and pricing discounts so as to meet customer demand for better pricing arrangements and greater rebates and incentives. As a result, we may not be able to grow our volume and/or services to the extent necessary to compensate for the additional costs related to these increased incentives and pricing discounts. In addition, increased pressure on prices increases the importance of cost containment and productivity initiatives in areas other than those relating to customer incentives.
In the future, we may not be able to enter into agreements with our customers if they require terms that we are unable or unwilling to offer, and we may be required to modify existing agreements in order to maintain relationships and compete with others in the industry. Some of our competitors are larger with greater financial resources and accordingly may be able to charge lower prices. In addition, to the extent that we offer discounts or incentives under such agreements, we will need to further increase transaction volumes or the amount of services provided in order to benefit from such agreements and to increase revenue and profit, and we may not be successful in doing so, particularly in the current regulatory environment. Our customers also may implement cost reduction initiatives that reduce or eliminate payment product marketing or increase requests for greater incentives or greater cost stability. In addition to decisions made by competitors and customers, we also face pressure from pricing regulation and litigation.
Additionally, we face pricing pressure related to real-time account-based payment schemes. These pressures impact both domestic pricing (such as the increased use of schemes that offer increasingly lower or subsidized P2M pricing) and cross-border pricing (including from both competing schemes and global initiatives to lower the cost of cross-border payments to end users).
Any of these factors could have a material adverse impact on our overall business and results of operations.
32 MASTERCARD 2025 FORM 10-K
PART I
ITEM 1A. RISK FACTORS
Rapid and significant technological developments and changes could negatively impact our overall business and results of operations or limit our future growth.
The payments industry is subject to rapid and significant technological changes, including new technologies and changes to existing technologies (such as digital assets and blockchain, AI, machine learning, privacy enhancement and cybersecurity). These changes could result in new technologies that may be superior to, or render obsolete, the technologies we currently use in our programs and services. They may also result in new and innovative payment methods, products and services.
Additionally, there are a number of factors relating to technology change that could impact us. These include: the inability of third parties on which we rely for the development of and access to new technologies to keep pace with technological changes (including with regard to AI); potential action from third-party patent holders, including notices or inquiries threatening litigation against us or our customers for alleged patent infringement or demanding significant license fees; the scope of, as well as customer and merchant resistance to, industry-wide solutions and standards (such as those related to tokenization or other security technologies); any difficulty we may experience in attracting and retaining employees with technology expertise; and the need to invest resources for new technologies, which could lead to further additional expenses. Any of these developments could impact our ability to develop and adopt new technologies, as well as improve and keep pace with current technologies and reflect such technology in our payments offerings.
Moreover, regulatory or government requirements could continue to require us to host and deliver certain products and services on-soil in certain markets. As a result, we may need to alter our technology and delivery model, potentially resulting in additional expenses and/or other operational impacts.
Our future success will depend, in part, on our ability to anticipate, develop or adapt to technological changes and evolving industry standards. If we fail to sufficiently develop and adopt new technologies, or improve and keep pace with current technologies and reflect such technology in our payments offerings, our payments offerings could be negatively impacted and/or we could be put at a competitive disadvantage. This could impact our ability to compete with new technologies and products, as well as encourage customers that use our technology to enhance and deliver their payment-related products and services (including fintechs and technology companies) to use their own technology to compete against us. These developments could lead to a decline in the use of our technology, products and services, which could have a material adverse impact on our overall business and results of operations.
Operating a real-time account-based payments network presents risks that could materially affect our business.
U.K. regulators have designated Vocalink, our real-time account-based payments network platform, to be a “specified service provider” and regulators in other countries may in the future expand their regulatory oversight of real-time account-based payments systems in similar ways. Any prolonged service outage on this network could result in quickly escalating impacts, including potential intervention by the Bank of England and significant reputational risk to Vocalink and us. For a discussion of related regulatory risks, see our risk factor in “Risk Factors - Payments Industry Regulation” in this Part I, Item 1A. Furthermore, the complexity of this payment technology requires careful management to address information security vulnerabilities that are different from those faced on our payment network. Operational difficulties, such as the temporary unavailability of our services or products, or information security breaches on our real-time account-based payments network could cause a loss of business for these products and services, result in potential liability for us and adversely affect our reputation.
Working with new customers and end users as we continue to expand our products and services can present operational and onboarding challenges, be costly and result in reputational damage if the new products or services do not perform as intended.
The payments markets in which we compete are characterized by rapid technological change, new product introductions, evolving industry standards and changing customer and consumer needs. In order to remain competitive and meet the needs of the payments markets, we are continually involved in developing and implementing complex multi-rail solutions and diversifying our products and services. These efforts carry the risks associated with any diversification initiative, including cost overruns, delays in delivery and performance problems. These projects also carry risks associated with working with different types of customers (such as corporations that are not financial institutions, non-governmental organizations (NGOs) and new end users). These differences may present new operational challenges, such as enhanced infrastructure and monitoring for less regulated customers.
Our failure to effectively design and deliver these products and services could make our other offerings less desirable to these customers, or put us at a competitive disadvantage. In addition, if there is a delay in the implementation of our products or services (which could include compliance obligations, such as AML and CFT, and licensing requirements for applicable products and services), if our products or services do not perform as anticipated, or we are unable to otherwise adequately anticipate risks related to new types of customers, we could face additional regulatory scrutiny, fines, sanctions or other penalties, which could materially and adversely affect our overall business and results of operations, as well as negatively impact our brand and reputation.
MASTERCARD 2025 FORM 10-K 33
PART I