5 Practical Techniques to Prevent Card Fraud
Full text
(2) Practical Payment Approaches Table of Contents. @>OA KLQ MOBaPBKQ [kahrd not prez-uh nt] - noun. 1. (CNP) is a card purchase transacted via the telephone or internet whereby the physical card is not swiped through a card reader.. 1.. General Best Practices. 4. 2.. Avoiding Chargebacks. 8. 3.. Interchange, Assessments, and Fee Structures. 12. 4.. Address Verification Service. 16. 5.. Card Security Checks. 20. 6.. Recurring Payments, Installment Billing, and So# Billing Descriptors. 24. 7.. PCI Data Security Standard. 28. 8.. Advanced Authorization Services. 32. 9.. Tokenization. 36. 10. Negative Option Marketing. 2. 40.
(3) 1. In payment processing, best practices are built on the following principles: 1. Qualifying for and getting the lowest interchange rate. 2. Preventing chargebacks. 3. Winning representments. your descriptors monthly, making test purchases with various credit cards, and reviewing the descriptions online and on your statement. For detailed information on billing descriptors, see Practical Payments Approach #6. Email Confirmations: Send an immediate email confirmation whenever an order or refund is processed. Always indicate that the card issuer may require a full billing cycle to apply a refund and may not immediately appear on an online statement. Policies: Post clear policies for billing, returns, shipping, back orders, and privacy. This will provide your processor with additional evidence to fight chargebacks and win representments. Order confirmation emails should include this information in the content or via a web page link.. These general best practice approaches outline how you can use CardNot-Present (CNP) fundamentals to save money, reduce risk, and improve operational efficiency when processing digital and direct payments.. GATHERING CARDHOLDER INFORMATION. PRESENTING INFORMATION. Customer Information: Gather evening and daytime phone numbers, as well as an email address, if the shipping and billing addresses are different. This is particularly important with high value orders.. Contact Information: Clearly display contact information on every page of a catalog or web store, on shipping materials, and on all correspondences. If customers can’t reach you about a dispute, they will call their card issuer, which might lead to a chargeback. Contact information should always include a toll-free phone number (digits, no letters) and an email address.. Card Information: Ask for the name as it appears on the card, the account number, the card type, and the expiration date (make sure it is a future date). Also ask for the “CID” digits on the credit card to establish the customer’s physical possession of the card. See Practical Payments Approach #5.. Billing Descriptor: This identifies you on the customer’s credit card statement. For example:. Added Protection: Online merchants should consider using “Verified by Visa” or MasterCard’s “SecureCode.” Ask your processor if these enhanced antifraud programs are right for you.. LNC*EXECUTIVEGADGETS. 800-5551212. Back to Table of Contents. Practical Payments Approach #1 The People Behind Your Payments General Best Practices. MA. Use a company name or brand the customer will recognize and include a toll-free telephone number. If your customer doesn’t remember the purchase, they will generally call the number in the descriptor before contacting the card issuer. Billing descriptors can be truncated by processing systems, causing incomplete phone numbers. Avoid this by confirming 4. 5.
(4) PROTECTING DATA. Observing these rules can reduce your exposure to chargebacks and can result in lower interchange fees:. The following best practices are drawn from the Payment Card Industry Data Security Standard, also known as “PCI”. Please see Practical Payments Approach #7 for detailed information on PCI.. 1. Always conduct an Address Verification System (AVS) check and contact customers for order confirmation on AVS failures. See Practical Payments Approach #4. 2. To test card validity prior to deposit, use a “Zero Dollar Verification” (ZDF), also known as an “AVS-only” authorization. Avoid “$1.00 Authorizations”, as these may appear in online statements and confuse customers. 3. Each deposit should reference one and only one valid authorization. Do not submit deposits without valid authorizations (“forced deposits”). 4. Ship within seven (7) days of the authorization or obtain a new authorization. 5. Submit your deposits to your processor within two (2) days of shipment. 6. If supported by your processor, submit your authorization Transaction ID with all deposits and refunds. This prohibits forced deposits and can reduce fraud. 7. Use voice authorizations as a last resort. These bypass processors’ systems and cannot be used to refute chargebacks.. 6. @. If you have any questions or comments, please email us at [email protected]. Back to Table of Contents. PROCESSING ORDERS. 1. Make sure your company is PCI certified. 2. Make sure your payment processor is PCI certified. 3. Protect stored data. All merchants must use strong encryption to protect cardholder information stored internally or eliminate storage of actual card data through services such as tokenization (see Practical Payments Approach #9). Web merchants must not store cardholder information on web servers or computers outside of a firewall. 4. Encrypt data sent across public networks. Cardholder data sent across public networks must be encrypted. This includes email, FTP, data streams, and phone lines. The most common violation of this practice is cardholder information sent via email. There are hundreds of encryption products available, many of them free. 5. Restrict access to data by “need to know.” Your call center and chargeback departments will likely need to see cardholder data. Other departments do not. Merchants should work with processors that have online hierarchical role-based access to payments data. Store hard-copy cardholder information (e.g. paper reports from your processor, chargeback mail, and faxes) in a locked room with limited access. 6. Partners handling your data must protect your data. If your business partners have access to your customers’ credit card information, it is your responsibility to make sure that they employ adequate protection methods. Partners that typically handle credit card information include fulfillment houses, call centers, and marketing affiliates.. 7.
(5) 2. “Authorization Not Obtained” chargebacks occur when the card issuer believes that a valid authorization was not obtained for a deposit. The merchant may have attempted a forced deposit, used an invalid authorization, or obtained a voice authorization. This type of chargeback o#en occurs when multiple partial deposits are made against single authorizations. A combination of sound procedures and proper exception handling by your processor can eliminate these chargebacks.. 3. “Recurring Transactions” chargebacks occur when a consumer believes they have been billed a#er cancelling a subscription, membership, or multi-payment billing series (e.g. continuity program or installment payments). Using clear and explicit billing descriptors will help you avoid these types of chargebacks (see Practical Payments Approach #6). Be certain to quickly acknowledge and record any correspondences with customers regarding changes or cancellations. This should include keeping records of all phone calls.. Chargebacks occur when a customer disputes a charge on a card. The customer contacts his/her card issuer and initiates the process through your payment processor. Your processor will charge you a fee for each chargeback you receive. You have the right to fight the dispute in a process called representment, where you must substantiate the charge by providing verification of the sale. If you cannot substantiate the sale, you will have to reimburse the customer. Chargebacks can be costly, time consuming, and can threaten your merchant account. Depending on the card type, chargeback rates exceeding 0.5% or 1.0% (by sale count) can result in substantial fines. Back to Table of Contents. 2. Practical Payments Approach #2 The People Behind Your Payments Avoiding Chargebacks. Following are detailed guidelines to help avoid chargebacks and increase your odds of reversing chargebacks through representment.. and excessive rates can cause your merchant account to be terminated with the possibility of card brand banishment. Even a small number of chargebacks demonstrates that you have some unhappy customers.. THREE MOST COMMON REASONS FOR CHARGEBACKS The three most common chargeback reasons for CNP merchants are: 1. 8. “Unauthorized Use” chargebacks occur when consumers claim their cards were used without their knowledge or permission. In some cases, this will reflect actual fraud and may require the issuing bank to close the account. Asking the consumer for additional card information (e.g. CVV2 and CVC2 - see Practical Payments Approach #5) at the time of purchase can greatly reduce this form of chargeback.. @. If you have any questions or comments, please email us at [email protected]. 9.
(6) Unauthorized Use (Products). Unauthorized Use (Services). Cancelled Recurring Transaction. c. c c. Web Sales: Consider using “Verified By Visa” or MasterCard’s “SecureCode.” This proves card ownership and enhances the merchant’s position on chargeback representment.. c. c. Require card identification numbers like CVV2 (Visa), CVC2 (MC), and CID (AX). See Practical Payments Approach #5. c. c. c. c. Always conduct an AVS check. Only process orders with a valid AVS response. Obtain evidence of receipt of goods (i.e. signed shipping receipt).. Process refunds as quickly as possible!. c. Notify consumers in writing by email and/or mail when a refund has been issued or a membership cancelled. Provide them with the date the transaction was submitted and a reference number.. c. c. c. Always provide a clear billing descriptor with a phone number so the consumer can contact you directly rather than calling their bank to discuss any dispute.. c. c. c. Always provide a contact phone number and an email address on your website so consumers can contact you directly.. c. c. c. State the terms and conditions of the sale or service clearly and in plain view. All correspondences should include this information in the message or via a link to a web page.. c. c. c. Use email to notify consumers of the details of sales and to indicate that their cards will be charged.. c. c. Obtain written or electronic signatures from cardholders giving you permission to charge their cards on a regular basis for monthly fees or recurring payments. See Practical Payments Approach #6. c. c. Make it very easy for members or subscribers to cancel – have a “no-questionsasked” policy.. c. c. Authorizations must always be done for every deposit. Deposits must not exceed the amount you have authorized. Authorizations must be “positive.” Avoid using voice authorizations. If you are settling a transaction with an authorization more than 7 days old, you must reauthorize the transaction. While the authorization might still be valid, you will likely receive a better interchange rate. See Practical Payments Approach #3. 10. c. c. c c. c c. c c. c c. c. c. Back to Table of Contents. Authorization Not Obtained. ACTIONS TO AVOID THESE COMMON CHARGEBACK REASONS:. 11.
(7) INTERCHANGE Interchange is a fee — mandated by Visa & MasterCard — that the merchant’s acquiring bank (o#en represented by a payment processor) pays to the card issuing bank on each sales transaction. “Acquirers” or their processors pass this fee along in some form to the merchant. Interchange was developed as an income incentive for banks to issue MasterCard and Visa cards. Today, there are hundreds of distinct rates based on transaction and industry type. Interchange also typically represents the largest portion of a merchant’s total fees.. Fee. Interchange PPBPPJBKQP -OL@BPPLO (I) (A) Fee (P). Total (D). Published. 1.80% + $0.10. 0.110%. $0.25. 1.91% + $0.35. Expressed as $. $1.90. $0.11. $0.25. $2.26. Expressed as %. 1.9%. 0.110%. 0.25%. 2.26%. Back to Table of Contents. 3. Practical Payments Approach #3 The People Behind Your Payments Interchange, Assessments, and Fee Structures. Generally, interchange rates are charged as a percentage of the sale plus a fixed fee. This structure allows the card brands to protect themselves with respect to very large and very small transaction values. Assessments are mostly expressed as a small percentage only. Payment processors may structure their fees at their discretion and can vary widely. In this example, we use a fixed per-transaction charge.. ASSESSMENTS While interchange is paid to the card issuers, assessments are paid directly to Visa and MasterCard and typically offset the brands’ costs to operate and regulate the networks. These fees are also passed along in some form to the merchant and generally represent the smalllest portion of a merchant’s total fees.. FEE STRUCTURES. A PROCESSING FEE EXAMPLE. While simple to understand, this type of pricing effectively hides the true cost of doing business from the merchant. The processor will normally present the merchant with a tiered discount structure consisting of “qualified,” “midqualified,” and “non-qualified” discounts. The latter two rates are typically higher than the quoted rate and represent downgrades. Bundled rates can become even more complicated as many processors will add a fixed, per transaction fee on top of the flat percentage, making it appear exactly like an interchange rate. Discount rates are therefore o#en mistaken for interchange.. The following chart depicts the typical fees a merchant might incur for a given CNP credit card sale. It introduces another fee, which is the fee your payment processor charges for sponsoring you into the Visa and MasterCard networks. This example is based on a $100 purchase from an online merchant and uses the Visa “CPS/Card-Not-Present” interchange rate.. 12. Many payment processors use a bundled “discount” rate. That is, they present the merchant with a flat percentage rate that blends all of the fees described above. This idea can be expressed in a formula using the abbreviations in the chart: D = I + A + P. In this case, the payment processor would charge the merchant 2.26% for each qualifying transaction.. 13.
(8) For a detailed comparison of bundled and pass-through pricing please read our white paper: “Common Pitfalls of Discount Pricing.”. DOWNGRADES AND INTERCHANGE OPTIMIZATION To obtain the best interchange rate, a sale transaction must conform to certain rules established by the card brands. The following example depicts three Visa rates applicable to CNP transactions:. In today’s interchange landscape, some downgrades are unavoidable. Merchants have been particularly hard hit, for example, by higher rates associated with rewards cards. These higher rates help pay for the cardholders’ points and perks. Interchange rates are usually updated twice a year, so it is important to work closely with your processor to avoid downgrades and optimize your overall interchange exposure. You should also select a processing platform with reporting capabilities that let you review interchange qualification regularly. Rate reviews and optimization strategies should occur at least quarterly.. Back to Table of Contents. Some processors offer a “pass-through” model. Also known as the “Cost Plus” model, the processor reports on all of the constituent components, “I,” “A,” and “P” as separate fee areas. While more complex, this style of billing is transparent and essential for reducing downgrades and optimizing interchange.. For more information, please refer to the published rates on Visa and MasterCard’s websites.. AVOIDING THE REFUND TRAP CPS/Card-Not-Present. 1.80% + $0.10. Electronic Interchange Reimbursement Fee (EIRF). 2.30% + $0.10. Standard Interchange Reimbursement Fee. 2.30% + $0.10. The second and third rates are undesirable downgrades. You can get the best interchange rate (1.8% + $0.10) for CNP transactions by:. 14. a. !LKAR@QFKD>KAAOBPP3BOFȳ@>QFLK0VPQBJ30@EB@H
(9). a. 0EFMMFKDMOLAR@QTFQEFKA>VPLCQEB>RQELOFW>QFLK
(10). a. 'K@IRAFKDQEBLOFDFK>I>RQELOFW>QFLK'"COLJVLRO>RQELOFW>QFLKFK your settlement transaction.. a. ÅOLSFAFKD>KLOABOKRJ?BOFKQEBPBQQIBJBKQQO>KP>@QFLK
(11). a. BQQIFKDQEBQO>KP>@QFLKKLILKDBOQE>KA>VP>ȷBOQEB 0 authorization date.. a. BQQIFKDQEBQO>KP>@QFLKKLILKDBOQE>KA>VP>ȷBOQEB@LJMIBQFLK 0 of the sale.. What happens to interchange when you process a refund? According to Visa and MasterCard regulations, the card issuer should return the interchange to the merchant. In practice, the issuer returns the interchange back to the payment processor, and in some cases the payment processor keeps the returned interchange. If your refunds average more than 10% of sales, the missing rebates can add up. If your processor charges a 2.3% discount rate and is not rebating interchange on returns, that 2.3% can become an effective rate of 3% or higher. Of course, average ticket price must be considered in the calculation, but you can see the potential for this hidden cost.. HOW CAN YOU AVOID HIDDEN FEES? 1 1.. Negotiate a pass-through fee arrangement with your processor.. 2 2.. Establish benchmarks and work with your processor to develop interchange reduction programs.. 3 3.. Understand published interchange rates and how they apply to you.. 4 4.. Develop the mathematical foundation for analysis, auditing, and oversight of your payment processing costs.. 15.
(12) 4. a. /BPB>O@E>II30M>OQF>IJ>Q@EBP
(13) yM>OQF>IJ>Q@EzFKAF@>QBPQE>Q the billing address being compared has the same ZIP code or the same numeric values in the street address, but not both. A “no. Back to Table of Contents. Practical Payments Approach #4 The People Behind Your Payments Address Verification Service. match” response indicates that neither part of the billing address matches your data.. Address verification service (AVS) is an automated fraud. a. #S>IR>QB30yKLJ>Q@EzOBPMLKPBP@>OBCRIIV >PQEBV>OB. prevention service designed to reduce the risk associated with. typically a strong indicator of fraud. Because not all AVS “no. CNP transactions.. match” responses necessarily indicate fraud, it is a signal that the. AVS helps minimize fraudulent transactions by verifying the cardholder’s billing address with the card issuer. The merchant must initiate the AVS check by providing the proper data in each transaction. Verification results. merchant must take further steps to authenticate the order. a. yKLJ>Q@EzOBPMLKPBALBPKLQ>RQLJ>QF@>IIVOBPRIQFKQEB authorization being declined.. help the merchant decide whether to accept a particular order or take follow-up action. AVS uses two pieces of extra information in the authorization request you send to your payment processor: the numeric portion of the cardholder’s. 30/BPRIQ LAB. !BP@OFMQFLK. 00. 5-Digit ZIP and address match. 01. 9-Digit ZIP and address match. with other factors (card number, expiration date, etc.) and issues an AVS. 10. 5-Digit ZIP matches, address does not match. Response Code.. 11. 9-Digit ZIP matches, address does not match. 12. ZIP does not match, address matches. 20. Neither ZIP nor address match. 30. AVS service not supported by issuer. 31. AVS system not available. 32. Address unavailable. 33. General error. 34. AVS not performed. address and the ZIP code. Your payment processor compares this information against information at the cardholder’s issuing bank, along. HOW TO USE AVS Address Verification Service is transparent to your customer and applies to payments using VISA, MasterCard, American Express, and Discover cards. To use AVS, a merchant should: a. PHQEB@RPQLJBOCLOQEB?FIIFKD>AAOBPP>PFQ>MMB>OPLKQEBFO monthly statement.. a. 0R?JFQQEBOBNRFOBA>IME> KRJBOF@MLOQFLKPLCQEB>AAOBPPTFQE the authorization request.. 16. EXAMPLES OF AVS RESPONSE CODES*. * The AVS codes listed above are numeric, processors may use alpha or numeric characters. 17.
(14) a faxed signature to verify the order. This may not be the most costeffective means for all international orders, so a dollar threshold should be. “ZIP does not match, address matches” or “ZIP code (5 or 9 digit) matches, address does not match”. established to determine which orders must be validated.. Back to Table of Contents. HOW TO HANDLE MOST COMMON RESULTS. Establish a dollar threshold that puts these orders in an AVS Hold report for special processing. Look for these suspicious attributes: a. *>ODBOQE>KKLOJ>ILOABOP. a. 0BSBO>IRKFQPLCQEBP>JBFQBJ. a. -SBOKFDEQPEFMMFKD. a. -OABOPPEFMMBAQL>K>AAOBPPLQEBOQE>KQEB?FIIFKD>AAOBPP. WHY IS AVS IMPORTANT? 1. “Unauthorized Use” and “Non-Receipt of Merchandise” chargebacks. Without a positive AVS response, CNP merchants have no dispute rights. 2. “Neither ZIP nor address match”. A positive AVS response is one way to remedy many. VISA transactions using AVS are given a better interchange rate than those that do not, even if the AVS fails.. This is a strong indicator of fraud, but an AVS failure may be legitimate. Example: A customer has recently moved but has not notified their bank. Follow-up by: a. !>IIFKDQEB@RPQLJBOQLSBOFCVQEBQBIBMELKBKRJ?BO ?FIIFKD. AVS is not foolproof and should be combined with your internal and external fraud detection tools such as CVV2, CVC2, CID (see Practical Payments Approach #5), “Verified by Visa”, and “SecureCard.”. address, and home address. a. !LKQ>@QFKDQEB@>OAELIABO|PFPPRBOQLABQBOJFKBTEBQEBOQEBK>JB address, and telephone number match those in the issuer’s file.. a. 2PFKDAFOB@QLOV>PPFPQ>K@BLOFKQBOKBQPB>O@EQLLIPQL@LKQ>@Q the individual at the billing address and confirm that he or she initiated the transaction. “AVS Service not supported by issuer” This is a typical response to an international order which AVS does not support. One solution is to fax a credit card slip to the consumer, requesting. 18. @. If you have any questions or comments, please email us at [email protected]. 19.
(15) 5. HOW CVV2, CVC2, CMID, AND CID WORK 1.. A merchant asks the customer for the card security code and sends it to its processor as part of the authorization request.. 2.. The merchant’s processor – working through the card brands – checks the code against the card issuer’s database to determine its validity and then sends a Response Code back to the merchant along with the authorization.. 3.. The merchant evaluates the Response Code, taking into account the authorization decision and any other relevant or questionable data, like the AVS response.. To help reduce fraud for “Card Not Present” (CNP) transactions, the major credit card companies implemented authentication systems to ascertain if the credit card used in a transaction is actually in the possession of the owner. Knowledge of the card security value – known as CVV2, CVC2 (Card. Back to Table of Contents. Practical Payments Approach #5 The People Behind Your Payments Card Security Checks. Verification Value/Code), CMID (Card Member ID), and CID (Card Identification Number) by Visa, MasterCard, Discover, and American Express respectively. COMMON RESPONSE CODES. — proves that the purchaser has seen the card, or has seen a record made by somebody who saw the card. In many countries it is now mandatory to. /BPRIQ. 4E>QFQJB>KP. 0RDDBPQBA>@QFLK. provide this code when the cardholder is not present during the transaction.. M – Match. The cardholder’s number matches the number stored at the issuing bank. Complete the transaction (using other anti-fraud tools such as AVS to supplement the decision to approve). N - No Match. The number the card holder submitted did not match the number at the issuing bank. View the “No Match” as a sign of potential fraud. Examine the authorization response.. P - Request not Processed. Processor is unavailable. Resubmit the authorization request. U - Issuer does not support feature. The issuing bank is not registered with the credit card company to use this security feature. Use other anti-fraud tools to determine whether to process the transaction or investigate further. WHAT ARE CVV2, CVC2, CMID, AND CID? The diagram below shows the location and number of digits used by each major card brand. Visa, MasterCard, and Discover use a three digit code in the signature strip, while American Express uses a four digit code on the front of the card. When collected, submitted, and substantiated during the authorization process, the security value significantly increases the probability that the person placing the order is in possession of the credit card. In combination with an AVS check (see Practical Payments Approach #4), the card security value is a useful tool to minimize fraud from stolen card numbers and counterfeit cards. CVV2. xxx. CVC2. Card Member ID. xxx. CID. CID. xxxx 3000 000 000 00000. xxx xxxx 3000 000 000 00000. 20. 21.
(16) a. a. BO@E>KQP@>KKLQPQLOB!33 !3! !+'" LO!'"@LABPFKQEBFO + customer databases or record once an authorization transaction has been completed. Codes must be requested for each unique transaction. Unless the customer is contacted each time, the codes should not be used for recurring transactions. Storing codes improperly could result in fines to the merchant.. a. BO@E>KQPJRPQOBDFPQBOTFQEJBOF@>K#UMOBPPQLRPB!'"
(17) + American Express will automatically decline the authorization requests with CID failure (with no letter result response).. a. >OAPB@ROFQVS>IRBP@>KLKIV?BCLRKALKQEB@>OA
(18) 1EBV>OBKLQ ! contained in the magnetic stripe data, nor do they appear on sales receipts or statements.. a. 22. BO@E>KQPPELRIA>IT>VPL?Q>FK>KAFK@IRABQEB@>OAPB@ROFQVS>IRB + in the authorization. Some card issuers do not support the code and by regulation automatically lose chargeback rights for CNP sales.. IQELRDETFABIVFJMIBJBKQBA KLQ>IIM>VJBKQMOL@BPPLOPPRMMLOQ these codes. You must check with your processor to see if this service is available.. WHY ARE CVV2, CVC2, CMID, AND CID IMPORTANT? Better Fraud Protection. Back to Table of Contents. THINGS TO KNOW. CVV2, CVC2, CMID, and CID can help merchants differentiate between good customers and criminals. For example, these security codes can prevent fraud from cards obtained via “trash diving” or “skimming” techniques. CVV2, CVC2, CMID, and CID enable the merchant to make a more informed decision before completing a CNP transaction.. &. Reduced Chargebacks. Using card security values potentially reduces fraud-related chargeback volume. While it does not eliminate the risk of fraud, this additional security feature is designed to protect merchants by verifying that the card is present during the purchase. Reduced fraud chargebacks translate into retained revenue.. @. If you have any questions or comments, please email us at [email protected]. 23.
(19) Annual consumer spending through recurring payments is consistently growing. Merchants too have embraced recurring payment models because they make products more affordable and can generate larger, more. 3 and 10 installments. The direct response television (DRTV) industry is a good example of where installment billing is used routinely — think “three easy payments.” Because the payments are smaller, merchants can sell more product with fewer chargebacks.. IMPORTANT TIPS FOR USING AND PROCESSING RECURRING PAYMENTS 1. On the first billing transaction, ask the cardholder for his/her billing address as it appears on their statement. Obtain the “ship to” address if it is different from the billing address.. 2. Provide cardholders with a toll-free phone number to cancel services. Disclose all terms, conditions, and fees at the time of sale and on all correspondences.. 3. Process credits promptly. State clearly that credit posting dates depend on the card issuer.. 4. For internet transactions, require cardholders to click an “Accept” button on the disclosure statement to confirm that they have read your terms and conditions. Consider asking for an electronic signature acceptable under the E-SIGN act.. 5. On the first transaction, use fraud protection tools including AVS, CVC2, CVV2, and CID. Never store this data a#er obtaining the initial authorization.. 6. Use so# billing descriptors to help cardholders identify charges on their statements. A full treatment of so# billing descriptors is provided on the following page.. predictable cash flows.. RECURRING PAYMENTS AND INSTALLMENT BILLING Recurring Payments Recurring payments are used when a consumer agrees to pay for a product or a service at specific intervals over a certain period of time. For example, health club memberships, insurance premiums, utility bills, and subscription fees occur predictably over time. The recurrence may be fixed with predetermined renewal periods (e.g. magazine subscription) or perpetual (e.g. telephone bills) and might occur monthly, quarterly, or annually. The periodic payments may be equal or may vary based on the characteristics of the sale. Recurring payments can increase payment timeliness, reduce processing costs, and lower the risk of error due to manual entry. Installment Billing. Back to Table of Contents. 6. Practical Payments Approach #6 The People Behind Your Payments Recurring Payments, Installment Billing, and So! Billing Descriptors. Payments made on installment billing plans are popular recurring payments. On these plans, the period is fixed and the payments are typically identical. Payments are generally made monthly, with between 24. 25.
(20) Static Billing Descriptors Billing descriptors are line items that appear on cardholder statements describing their purchases. Billing descriptors are typically static by default. They remain the same for different products sold by the same entity. To obtain better interchange rates, most card companies require that CNP transactions use billing descriptors with a company’s name and customer service phone number. Static billing descriptors, such as the one below, are generally sufficient for companies offering a limited number of products: Acme Industries 888-555-1234 . . . . . . . . . . . . . . . . . . . $14.95 So! Billing Descriptors So# Billing Descriptors allow the merchant descriptor information to be modified on a per transaction basis (sometimes referred to as a “Dynamic Billing Descriptor”). Certain direct marketing merchants (MCCs 5966, 5968, 5967, 5969, and 5962) are required to represent their company name with a three-letter prefix followed by a more detailed description of the product or service. Note that this field is typically limited to 25 characters (excluding the phone number). Not all processors support this feature, so be sure to choose a processor with this capability in case you need it in the future. ACM* Great TV Hits 1 of 9 800-555-1234 . . . . . . . . . . $14.95. WHY USE SOFT BILLING DESCRIPTORS? So# billing descriptors are powerful tools. They enable merchants to more clearly identify transactions on cardholder statements. They are especially useful for installment billing where a cardholder’s payment progress can be noted in each statement. Dynamic billing descriptors are especially beneficial to merchants who sell multiple products or services through. 26. multiple companies or affiliates. So# billing descriptors have been proven to enable customers to keep more accurate buying records, reduce chargebacks, and improve customer satisfaction.. Back to Table of Contents. BILLING DESCRIPTORS. For additional information on Visa recurring transactions, please refer to: Recurring Payments Best Practices Guide: http://www.visacemea.com/ac/selling/pdf/recurring_payments_bpg.pdf Visa Bill Pay for Merchants: http://usa.visa.com/download/merchants/bill_pay_for_merchants.pdf Merchant Marketing Resource Guide: http://usa.visa.com/download/merchants/merchant-marketing-resource-guide.pdf For additional information on MasterCard recurring transactions, please refer to: Revealing Attitudes on Recurring Payments: http://www.mastercard.com/us/merchant/pdf/Revealing_Attitudes.pdf Bill Payment for Service Industries: http://www.mastercard.com/us/merchant/pdf/Bill_Payment_Brochure.pdf Selling Recurring Payments to Your Customers: http://www.mastercard.com/us/merchant/pdf/Selling_Recurring_Payments_to_ Your_Customers_Brochure.pdf MasterCard Recurring Payment Cancellation Service: http://www.mastercard.com/us/merchant/pdf/RP_Cancellation_Service.pdf. @. If you have any questions or comments, please email us at [email protected] 27.
(21) 7. 6.. Develop and maintain secure systems and applications.. 7.. Restrict access to data on a need-to-know basis.. 8.. Assign a unique ID to each person with computer access.. 9.. Restrict physical access to cardholder data.. Back to Table of Contents. Practical Payments Approach #7 The People Behind Your Payments PCI Data Security Standard. 10. Track and monitor all access to network resources and cardholder data. The Payment Card Industry Data Security Standard, commonly known as “PCI-DSS” or “PCI” for short, is a standard across the major global card brands Visa, MasterCard, American Express, Discover, and JCB to address cardholder account security. PCI was developed to safeguard the personal information of cardholders while in the possession or use of merchants, payment processors, and other entities that store, process, or transmit payment card information. Understanding the basics of PCI, defining your merchant level, and understanding your validation requirements are critical. Failure to adhere to these requirements may result in significant fines for merchants and potential cancellation of their merchant accounts by the payment brands.. 11. Regularly test security systems and processes. 12. Maintain a policy that addresses information security.. FINES FOR NON-COMPLIANCE Merchants may be subject to potential fines from the card brands of up to $500,000 per incident if the merchant is compromised and not PCIcompliant at the time of the breach. Additionally, the merchant may also be responsible for other systemic costs or losses such as: 1.. Fraudulent use of the compromised account numbers from the date of compromise forward.. 2.. The cost of any additional fraud prevention/detection activities required by the card brands associations (i.e. a forensic audit).. 3.. The costs incurred by credit card issuers associated with the compromise (i.e. additional monitoring of system for fraudulent activity).. 4.. Reimbursing all card-issuing banks for the cost of reissuing any compromised cards.. THE BASICS OF PCI PCI is a series of security requirements for all companies that handle cardholder information. The following is a high-level list of the current PCI “Control Objectives.” 1.. Install and maintain a firewall configuration to protect cardholder data.. 2.. Do not use vendor-supplied defaults for system passwords and other security parameters.. 3.. Protect stored cardholder data.. 4.. Encrypt transmission of cardholder data and sensitive information across public networks.. 5. 28. Use and regularly update anti-virus and so#ware on systems subject to attack.. For more information, please visit: http://www.litle.com/resources/pci-other-compliance. MERCHANT LEVEL DEFINITIONS FOR PCI VALIDATION Some aspects of PCI, including merchant classification, differ between card brands. The following chart illustrates how Visa, MasterCard, Discover, and American Express classify their merchants. 29.
(22) Merchant Level 1. Merchant Level 2. Merchant Level 3. Merchant Level 4. Merchants processing over 6 million Visa transactions annually (all channels) or Global merchants identified as Level 1 by any Visa region2. Compromised entities may be escalated at regional discretion.. Merchants processing 1 million to 6 million Visa transactions annually (all channels). Merchants processing 20,000 to 1 million Visa e-commerce transactions annually. Merchants processing less than 20,000 Visa e-commerce transactions annually and all other merchants processing up to 1 million Visa transactions annually. Greater than 6 Million MasterCard and Maestro transactions OR Discover annually Any merchant suffering an attack resulting in an account data compromise Any merchant meeting the Level 1 Criteria of another payment brand Any merchant MasterCard in its sole discretion determines should meet the Level 1 Merchant requirements to minimize risk to the system >1 but < 6 Million MasterCard and Maestro OR Discover transactions annually Any merchant meeting the Level 3 Criteria of Visa >20,000 e-commerce transactions annually but < to 1 Million e-commerce MasterCard and Maestro OR Discover transactions annually Any merchant meeting the Level 3 criteria of another payment brand. All other merchants. Transactions = deposits (credit, debit, prepaid) 30. JBOF@>K "UMOBPP. 2.5 Million transactions or more per year, or any merchant American Express otherwise deems a Level 1 Merchant. 50,000 – 2.5 Million transactions per year. PCI VALIDATION REQUIREMENTS BY MERCHANT LEVEL KKR>I,K 0FQB /BSFBT. KKR>I0BIC. PPBPPJBKQ. .R>OQBOIV0B@ROFQV 0@>KP. Merchant Level 1. Required by Qualified Security Assessor. N/A. Required use of Approved Scanning Vendor for external IP addresses*. Merchant Level 2. N/A (MasterCard – at merchant’s discretion). Required annually**. Required use of Approved Scanning Vendor for external IP addresses*. Merchant Level 3. N/A. Required annually. Required use of Approved Scanning Vendor for external IP addresses*. N/A. Required annually (compliance validation at acquirer discretion). Required use of Approved Scanning Vendor for external IP addresses* (Compliance Validation at Acquirer Discretion). Merchant Level 4. Back to Table of Contents. *>PQBO >OA >KA!FP@LSBO. 3FP>. * Internet accessible. Less than 50,000 transactions per year. N/A. ** Effective June 30, 2012, Level 2 merchants that choose to complete an annual self-assessment questionnaire must ensure that staff engaged in the selfassessment attend PCI SSC-offered merchant training programs (currently Internal Security Assessor [ISA] training) and pass any associated PCI SSC accreditation program annually in order to continue the option of self-assessment for compliance validation. Alternatively, Level 2 merchants may, at their own discretion, complete an annual onsite assessment conducted by a PCI SSC approved QSA rather than complete an annual self-assessment questionnaire.. @. If you have any questions or comments, please email us at [email protected]. 31.
(23) Affluence indicators. 2. Prepaid indicators. 3. Account updater services. Over the last decade, the major card brands have introduced many new. AFFLUENCE INDICATORS AND THEIR ROLE IN MERCHANDISING. products targeting specific population demographics. Well-known examples. Credit card companies target affluent households with premier card programs such as Visa “Signature” cards and MasterCard “World” cards. When these types of cards are used, both Visa and MasterCard provide payment processors with an “Affluence Indicator” in authorization responses. The indicators denote two levels of affluence:. include rewards cards, prepaid cards, gi# cards, and electronic benefit transfer (EBT) cards. These product lines have introduced significantly more data elements into the payment stream. The flood of new data creates challenges and opportunities in managing. 1. “Mass Affluent” – Cardholders with an income greater than $100K. authorizations for sustained and growing profitability. Now is an important. 2. “Affluent” – Cardholders with an income greater than $100K, who also spend more than $40K per year on the card. time to have a payment processor with the technology to capitalize on the opportunities and mitigate the challenges.. NEW DATA AND ITS ROLE IN MODERN PAYMENTS To support these new cardholder data streams, the major card brands developed robust and descriptive data sets that better describe cards, cardholders, and purchases. Card brands pass some of this information along to payment processors in the purchase authorization response, although not all processing platforms are able to capture and report the data. As data (payments intelligence, specifically) becomes an important differentiator in how some business sustain and build customer relationships, smart businesses see payments data as key to their success. Processing platforms that are capable of passing the data in the authorization response enable their merchants to implement better merchandising strategies, prevent customer churn, and increase revenue. There are three specific data sets that can have an immediate impact on merchants:. 32. 1. Back to Table of Contents. 8. Practical Payments Approach #8 The People Behind Your Payments Advanced Authorization Services. Merchants who have this information at the time of authorization can adjust their sales approach to the needs and spending patterns of the consumer, potentially generating additional sales. By storing and analyzing this data, merchants can plan future targeted marketing campaigns to this valuable cardholder demographic, which typically spends more o#en and tends to purchase more expensive items. These cardholders are also more likely to have higher or unlimited spending limits, providing higher authorization rates.. INCREASING AUTHORIZATION RATES USING PREPAID INDICATORS Card-branded prepaid cards represent one of the fastest growing card segments. These include non-reloadable cards like gi# cards, rebate cards, and employee incentive cards, as well as reloadable cards like payroll cards, government EBT cards, and teen cards. Authorization responses on prepaid cards also provide valuable data including:. 33.
(24) FP> +>PQBO!>OA "FP@LSBO >KAJBOF@>K#UMOBPP>IIOBQROK>K 3 indicator that identifies the card as prepaid.. a. LK OBIL>A>?IB3FP>>KA+>PQBO!>OAMOBM>FA@>OAP>IPLOBQROKQEB , available balance.. a. LJB3FP>>KA+>PQBO!>OAFPPRBOPMOLSFAB?>I>K@BFKCLOJ>QFLKCLO 0 reloadable cards.. Many CNP merchants process payments with prepaid cards the same way they process credit and debit card payments. For merchants who use recurring payments or installment billing this presents obvious problems, as prepaids are more likely to become balance-depleted at some time during the billing series. Since prepaid cards can represent anywhere from 10-40% of authorization volume for many CNP merchants, a predefined strategy as to how to manage prepaid cards is advised. In contrast, if a merchant knows that a card is prepaid and can determine the remaining balance, it creates opportunities to accept payments or make other adjustments. For example: a. a. 'KPQB>ALCLȲBOFKDOB@ROOFKDLOFKPQ>IIJBKQ?FIIFKD JBO@E>KQP@>K offer the product or service on a fixed-term basis with an attractive one-time payment. BO@E>KQPMOL@BPPFKDMOBM>FA@>OAP>IBPLOFDFK>QFKDCOLJ + affiliates can adjust the way they pay commissions based on the authorization response.. INCREASING REVENUE WITH ACCOUNT UPDATING ADVANCES Businesses that bill on a recurring or installment basis know that card changes — the result of data breaches, issuing bank portfolio swaps, card upgrades, or expiration date changes (among other reasons) — can interrupt the billing series and potentially sever the customer relationship forever.. 34. Over the past decade, the major card brands have introduced “Account Updater” services that allow merchants, via their processors, to submit card data on file to the networks for updating and correcting stale information. These services have been well received by all parties involved: merchants retain more customers; customers enjoy uninterrupted service; the networks maintain sales volume; and card issuers see increased account balances. However, traditional updater systems have some shortcomings: a. BO@E>KQP>OBOBNRFOBAQL?RFIA>KAJ>FKQ>FK>K'1FKCO>PQOR@QROBQL + support the system.. a. AABAMOL@BPPBPFKQOFKPF@>IIVFKQOLAR@BFKBȵ@FBK@FBPQLQEB merchant’s operations.. a. 1 O>KPJFPPFLKLC@OBAFQ@>OAA>Q>MOBPBKQPQEBJBO@E>KQTFQE additional risk it may wish to avoid.. Back to Table of Contents. a. A second generation of Account Updater has emerged that removes these burdens from the merchant. Payment platforms supporting this option effectively offer account updating as an automated, managed service. Benefits of this approach include: a. ,LKBBAQLFKSBPQFK'1FKCO>PQOR@QROB @LAFKD LOA>Q>QO>KPJFPPFLK
(25). a. # IFJFK>QFLKLCQEBȳIB ?>PBARMA>QBMOL@BPP OBPRIQFKDFKC>PQBO more secure, and more efficient processing.. a. /BCOBPEBA@>OAFKCLOJ>QFLKFPPQLOBAFKQEB@ILRACLOCRQROBRPB
(26). Some merchants may still want to maintain the updated credit card information in their systems. If so, they should make sure their processor offers the option to return updates in the authorization response. Additionally, as merchants consider the significant security benefits offered by an automatic Account Updater service, they should ensure that the solution they select is fully integrated with available data security solutions such as tokenization, see Practical Payments Approach #9.. 35.
(27) Data breaches occur more frequently than ever. Data thieves don’t discriminate — both merchants and processors, regardless of size, are victims. Many breaches are particularly insidious because they go undetected for months, or longer, a#er an initial incursion. Most victims are PCI compliant,. PCI, E2EE, AND TOKENIZATION PCI PCI (see Practical Payments Approach #7) has been promoted by the card brands and industry as the leading defense against card data breaches. Compliance, however, is costly, time consuming, and unfortunately does not limit the merchant’s liability. Given the number of breaches in PCI compliant businesses, firms are looking to augment their protection. Two technologies have emerged to combat the problem, end-to-end encryption and tokenization. These two technologies are o#en thought of as competitive, however, there are situations where they can be complementary.. Back to Table of Contents. 9. Practical Payments Approach #9 The People Behind Your Payments Tokenization. proving that such compliance doesn’t provide guarantees. New technologies are emerging that, when combined with other PCI approaches and standards, significantly bolster data security while lowering costs.. END-TO-END ENCRYPTION (E2EE). THE COST OF PROTECTING YOURSELF. E2EE is a methodology that addresses security when the card data is in transit or at rest. PCI compliant companies employ some level of E2EE as they are required to encrypt the data during transmission and “protect” it when it is stored. Most o#en this protection is in the form of encryption. In this scenario, the data has to be decrypted for processing and encrypted before being stored or transmitted. E2EE provides point-to-point security, but has some vulnerability when the data is decrypted for processing.. Protecting yourself against a data breach is an expensive endeavor. Merchants encounter direct expenses for both compliance and liability. According to Gartner Research, Level 2 Merchants (those processing between 1 and 6MM Visa or MasterCard transactions per year) can expect to pay $1.1MM to become PCI compliant. Maintaining compliance can cost these merchants up to $135K per year. The cost of liability insurance for these same merchants can run between $150K and $900K annually. Insurance can mitigate any financial costs associated with a breach, but it does nothing to protect the company’s reputation and valuable customer base. Using emerging technologies that lessen the likelihood of a data breach can lower the costs associated with compliance, liability, and brand damage.. 36. Tokenization Tokenization is a methodology that addresses security when the card data is in transit, at rest, and while in use. Tokenization replaces card account information with “tokens” generated by a third-party service provider. In this manner, the merchant is not required to store any card data. These tokens are designed so they can be used in place of card numbers by all of the merchant’s systems. The additional security afforded during token usage usually means that tokenization is a more secure solution for merchants. Tokenization reduces the costs associated with having to encrypt, decrypt, and re-encrypt data each time access to credit card information is required.. 37.
(28) a. In a tokenized environment, cardholder data is transmitted a single time and is stored by a third party data vault, not locally by the merchant. Upon registering a card-based account number, a token is returned and used in all subsequent transactions. A merchant may store a token locally, but its card equivalent is stored by the third-party vault provider.. 'QPELRIA?BMLPPF?IBQLRPBQLHBKPFKMI>@BLC@>OAKRJ?BOPCLO>II successive payment transactions including authorizations, deposits, refunds, and chargebacks.. a. BIB@Q>SBKALOQE>Q>IILTPVLRQLOBQ>FK>?PLIRQBLTKBOPEFMLCQEB 0 tokenized data in case you wish to move to a different solution or processing platform at a later date.. Back to Table of Contents. A CLOSER LOOK AT TOKENIZATION. ANOTHER CONSIDERATION With basic tokenization, there is a small window of vulnerability. That window is when the customer first enters his or her card data at the merchant’s site and the data is transmitted through the merchant’s systems to the processor for tokenization. Robust tokenization solutions offer a web service that allows point-to-point security during this stage. The vendor provides embeddable “payment page” code that interacts with the processor for tokenization. When the consumer enters payment card information, it is replaced with a registration key. Upon completion of check-out, the merchant uses this key to obtain a token representing card data already stored at the processor.. Tokenization is increasingly popular and is now available through more payment processors and other third parties. Every implementation is different, so it is important to choose a vendor with features that provide the most security and require the least amount of IT investment. Some features and things to consider:. 38. a. 1 LHBKPPELRIAQ>HBLKQEBDBKBO>ICLOJ>QLC@OBAFQ@>OAPPLQEBV can flow through the merchant’s systems like ordinary card numbers without significant programming changes.. a. 1 LHBKPPELRIALKIV?BS>IFACLOQEBJBO@E>KQQLTELJQEBV>OB registered. This renders them totally useless to unauthorized parties.. a. 1 LHBKPPELRIA?BRP>?IB?V>KV>RQELOFWBAFKAFSFAR>IQE>QFPFKVLRO organization.. While tokenization itself will not completely eliminate the need for PCI compliance and liability insurance, it can significantly reduce costs, better protecting your brand.. Complete documentation on tokenization can be obtained from the PCI Security Standards Council via this URL: https://www.pcisecuritystandards.org/documents/Tokenization_Guidelines_ Info_Supplement.pdf. 39.
(29) 6.. If clinical trial information is displayed, the entity conducting the trial must be identifiable and unrelated to the organization selling the product or service.. 7.. Use of “Free Trial” or “Risk Free Trial” is prohibited if at the conclusion of the trial the consumer is charged full price for the initial trial.. Do your customers consent in advance to purchase recurring products and/ or services until they cancel? If you use this type of marketing, known as negative option or continuity marketing, especially via ecommerce, you are continually on the radar of lawmakers and government regulators, both at the state and federal level.. Back to Table of Contents. 10. Practical Payments Approach #10 The People Behind Your Payments Negative Option Marketing. If there are qualifications for trial they must follow preset logic. Consumers who don’t meet qualifications must be disqualified and not allowed to receive trial. Qualifications include, but are not limited to, age, sex, race, weight, height, etc.. We’ve developed the following practical approaches for using negative option marketing, which include regulatory considerations as well as those by the major card brands.. ADVERTISING 1.. Merchants must be able to substantiate any performance claims shown on their websites. Performance claims include, but are not limited to: guaranteed results, false cures, weight loss promises, etc.. 2.. Media logos are prohibited without written consent from the media outlets (MSN, CNN, etc.).. 3.. 40. Images and endorsements of celebrities are prohibited without their express written consent.. 4.. Merchants must be able to substantiate testimonials shown on the website.. 5.. Websites must not create a false sense of urgency for purchase (e.g. countdown clock, limited time only, offers expires today, check availability, etc.).. TERMS AND CONDITIONS 1.. Terms must be at least 12 point font (or the same size as all other font on the payment page) with no confusing color contrast.. 2.. Terms must be clearly disclosed on the payment page, either adjacent to the submit button or directly above the submit button.. 3.. Terms must include details regarding the trial period, the renewal period, trial start/end period, and the cost for trial and renewals.. 4.. Billing period per cardholder should be once a month (30 days).. 5.. An “I agree to the terms” checkbox must be included on the payment page.. 6.. Pre-checked boxes are prohibited.. 7.. The cancellation policy must be disclosed in the terms on the payment page.. 41.
(30) 1.. There must be a “Contact Us” link on the website.. 2.. “Contact Us” must include a toll free phone number, email address, and hours of operation.. 3.. Average hold time must not be more than 2 minutes.. 4.. Customer service hours of operation must be reasonable for the region in which the product is sold. Example: Target Market - USA. Customer Service hours: 8:00 am ET to midnight ET should be a minimum.. 5.. A purchase confirmation email must be sent to the consumer via email. The email should restate terms, including length of trial periods, renewal terms, information on how to cancel, and customer service contact information.. 6.. Ensure billing descriptors are consistent with website name, marketing materials, and confirmations sent to the consumer.. BILLING PRACTICES. 42. 1.. CVV must be implemented — the merchant must collect and decline all transactions when CVV is “No Match”.. 2.. AVS must be implemented — the merchant must perform an AVS check and decline all transactions where AVS response is “ZIP Code Does Not Match”. 3.. If shipping insurance is offered, this must not be auto-checked. The consumer is required to opt into any additional insurance.. 4.. Shipping and handling charges cannot be billed separately from monthly recurring charges.. 5.. Shipping and handling charges associated with the trial must be charged as one transaction.. 6.. When a customer is issued a refund, the merchant must cancel all future billing events.. 7.. Full refunds must be given on all merchandise including shipping and handling for consumer satisfaction.. 8.. Mandatory up-sells are prohibited, the consumer must opt in to all up-sells.. 9.. Products up-sells must be owned by the company that owns the website. Consumer’s credit card data cannot be shared or passed to a third party. All up-sells must be for a single charge as recurring up-sells, even with the consumer’s acceptance, are prohibited.. Back to Table of Contents. CUSTOMER SERVICE. &. 10. The terms and conditions of the up-sell must be clearly displayed either adjacent to or above the “I Enroll” or “Upgrade My Order” etc.. DISTRIBUTION 1.. Merchant cannot capture the deposit transaction until the product has actually shipped.. 2.. Shipping should occur within 48 hours of purchase, or be clearly stated if the timeframe is going to be longer than 48 hours.. 3.. Tracking information should be sent to the consumer via email.. @. If you have any questions or comments, please email us at [email protected]. 43.
(31) The People Behind Your Payments.. www.litle.com | 1 800 LitleCo | [email protected]. ©2011 Litle & Co..
(32)
Related documents
1.1 The Payment Card Industry Data Security Standard (PCI DSS) is a worldwide information security standard, created to help organisations that process card payments prevent credit
• Account Data includes all of the information printed on the physical card as well as the data on the magnetic stripe or chip. • Sensitive Authentication Data cannot be stored
Therefore, if the PAN and CVC are removed from the original details (e.g. postal forms, written card data) and securely destroyed by cross shredding, storage of the remaining
The Payment Card Industry Data Security Standard (PCI DSS) is a worldwide information security standard, created to help organisations that process card payments
The Payment Card Industry Data Security Standard (PCI DSS) is an information security standard for organizations that handle cardholder information for the major debit,
WARNING: Your company may be in noncompliance with the Payment Card Industry Data Security Standard (PCI DSS), placing it at risk of brand damage, costly fines and even loss of
The consolidation of individual payment card brand’s security programs offers the best available framework to guide better protection of cardholder data resulting a
White Paper: Varonis Systems & The Payment Card Industry Data Security Standard (PCI DSS).. Varonis Systems & The Payment Card Industry Data Security Standard