Card Not Present (CNP) transactions carry lots of risks associated with fraud. Today, merchants have a broad range of fraud control functionalities and solutions available to them.
But merchants must find the right balance between business needs and protection.
Using too much fraud control can negatively impact revenue by reducing potential sales and adding up cost:
- Protecting yourself from fraud means that you will reject good payments. This is life. However, ensure that your fraud control logic does not result in too high a rate of rejection of good payments.
- Fraud control functionalities and solutions can add up to significant cost. Make sure your business really requires the fraud control level you are paying for.
Many solution providers make it very easy to add / play with fraud control functionalities and solutions. In turn, they make it very easy to overdo it and to quickly increase cost.
CARD VERIFICATION VALUE code is free fraud control tool.
Reconciliation discrepancies - basic checks
Reconciliation process can get very frustrating. One must TAKE CHARGE and INVESTIGATE discrepancies.
See Neglect Card Payment Reconciliation at Your Peril
Start by checking the following steps and work with your team + get help from your providers/vendors.
- Understand the processes
Make sure you understand the card payment processes and reconciliation processes. If you do not understand how it works and what needs to be accomplished chances it is not done right.
Note to new merchants: Bank deposits are not instantaneous. There are several days between payments completed on a payment application and the bank deposits. In addition, depending on the country and the card type, the number of days can vary. In other words, not all payments for one day will get deposited into your bank account on the same day.
- Make sure your process is accurate. Don't assume it is.
- Create a Reconciliation table
Do not review individual reports to compare data. Input data into a single reconciliation table and then look at the data side by side. Basic reconciliation table should at least allow to account for payment date by card type and bank deposit date by card type.
- Is your data accurate?
You must be absolutely sure that the data you are using is in fact what you need to use or what you think you have. One obvious mistake is when one uses reports that are created based on the wrong querries and parameters. For example, a report by settlement date when one is thinking it is by capture date (=payment completed date). 2 apples will never match with 2 pears.
- Ensure that the revenue reports you compare are based on the same time frame
Example: if one report includes revenue for 24 hr period from 8 pm to 8 pm while the other from 12 midnight to 12 midnight, they will not match.
In this situation, you need to decide what your business day should be from a card processing standpoint and ensure that all your systems / reports open /close at the same time.
- Not all transactions are part of revenue
Make sure you do not include any declined/errored transactions that are not completed payments.
- Make sure to account for all transactions and adjustments
One must be sure to include all refunds / charges from all payment solutions using the same set of merchant IDs + all refunds / charges created/issued by various parties within the organization (for example finance or customer service groups) + account for all charge back and disputed amounts.
See Neglect Card Payment Reconciliation at Your Peril
Start by checking the following steps and work with your team + get help from your providers/vendors.
- Understand the processes
Make sure you understand the card payment processes and reconciliation processes. If you do not understand how it works and what needs to be accomplished chances it is not done right.
Note to new merchants: Bank deposits are not instantaneous. There are several days between payments completed on a payment application and the bank deposits. In addition, depending on the country and the card type, the number of days can vary. In other words, not all payments for one day will get deposited into your bank account on the same day.
- Make sure your process is accurate. Don't assume it is.
- Create a Reconciliation table
Do not review individual reports to compare data. Input data into a single reconciliation table and then look at the data side by side. Basic reconciliation table should at least allow to account for payment date by card type and bank deposit date by card type.
- Is your data accurate?
You must be absolutely sure that the data you are using is in fact what you need to use or what you think you have. One obvious mistake is when one uses reports that are created based on the wrong querries and parameters. For example, a report by settlement date when one is thinking it is by capture date (=payment completed date). 2 apples will never match with 2 pears.
- Ensure that the revenue reports you compare are based on the same time frame
Example: if one report includes revenue for 24 hr period from 8 pm to 8 pm while the other from 12 midnight to 12 midnight, they will not match.
In this situation, you need to decide what your business day should be from a card processing standpoint and ensure that all your systems / reports open /close at the same time.
- Not all transactions are part of revenue
Make sure you do not include any declined/errored transactions that are not completed payments.
- Make sure to account for all transactions and adjustments
One must be sure to include all refunds / charges from all payment solutions using the same set of merchant IDs + all refunds / charges created/issued by various parties within the organization (for example finance or customer service groups) + account for all charge back and disputed amounts.
Reconciliation - You need to do it!
Reconciliation = process through which one ensures that all transactions accepted at the Payment Applications + all adjustments are deposited in the bank account.
There is no magic with reconciliation ... it will not get done by itself except if one has implemented an automated reconciliation process. And even then, one will still need to investigate if a discrepancy is identified.
Although Reconciliation is one of the most essential requirements associated with accepting card payments, it is too often neglected.
There is no magic with reconciliation ... it will not get done by itself except if one has implemented an automated reconciliation process. And even then, one will still need to investigate if a discrepancy is identified.
Although Reconciliation is one of the most essential requirements associated with accepting card payments, it is too often neglected.
How it works
Here are a few good highlight documents:
THE ANATOMY OF A TRANSACTION by MasterCard http://www.mastercard.com/us/company/en/docs/TheAnatomyOfATransaction.2007.pdf
THE ANATOMY OF A TRANSACTION by MasterCard http://www.mastercard.com/us/company/en/docs/TheAnatomyOfATransaction.2007.pdf
Merchant levels and PCI compliance requirements
Compliance with card security programs is essential when accepting card payments. One of the first steps for a merchant of any size is to define their Merchant Level and the associated PCI compliance actions. Scope of work ranges from completing PCI Self-Assessment Questionnaire to engaging a QSA (Qualified Security Assessor) and undergo audits to validate compliance.
See http://usa.visa.com/merchants/risk_management/cisp_merchants.html
See http://usa.visa.com/merchants/risk_management/cisp_merchants.html
What To Do If Compromised
Download "What To Do If Compromised" from Visa http://usa.visa.com/download/merchants/cisp_what_to_do_if_compromised.pdf
A transaction was not charged but card holder reports it is
When a transaction is authorized the card issuer holds the authorized amount waiting for settlement request to actually process the transaction for payment.
With a Debit card (Credit card vs. Debit card) the authorized amount is blocked directly from the funds on the bank account. Although the amount is not actually processed for payment and it becomes unavailable for use. On online systems of most banks, this authorized transaction will show as "pending" and is easily mistaken by the card holder as a charge.
The amount will be held either until the authorization expires or until the bank releases the amount. Depending on the bank, it can take just 1-2 days to quite a few days.
If the merchant wants to help the card holder get the amount released earlier, merchant may have to contact the issuing bank with the authorization code. Contact details for the issuer can be obtained from the Merchant Service Provider.
See Gift card / pre-paid cards and pre-authorization
With a Debit card (Credit card vs. Debit card) the authorized amount is blocked directly from the funds on the bank account. Although the amount is not actually processed for payment and it becomes unavailable for use. On online systems of most banks, this authorized transaction will show as "pending" and is easily mistaken by the card holder as a charge.
The amount will be held either until the authorization expires or until the bank releases the amount. Depending on the bank, it can take just 1-2 days to quite a few days.
If the merchant wants to help the card holder get the amount released earlier, merchant may have to contact the issuing bank with the authorization code. Contact details for the issuer can be obtained from the Merchant Service Provider.
See Gift card / pre-paid cards and pre-authorization
Credit card vs. Debit card
A Credit card allows card holder to make payments based on line of credit established with the card issuer.
A Debit card is issued by a bank and payments are debited directly from the bank account. A Debit card transaction can be processed either as a debit transaction when processing is completed over a debit network or as a credit transaction is processed as a Visa or MasterCard transaction depending on the logo on the front of the card.
A Debit card is issued by a bank and payments are debited directly from the bank account. A Debit card transaction can be processed either as a debit transaction when processing is completed over a debit network or as a credit transaction is processed as a Visa or MasterCard transaction depending on the logo on the front of the card.
Interchange Rates
Many hear about Interchange Rates. Lots of confusion. See official information.
http://www.mastercard.com/us/merchant/pdf/MasterCard_Interchange_Rates_and_Criteria_-_October_2008-final.pdf
http://corporate.visa.com/_media/interchange-brochure.pdf
Also http://corporate.visa.com/viewpoints/interchange-index.shtml
http://www.mastercard.com/us/merchant/pdf/MasterCard_Interchange_Rates_and_Criteria_-_October_2008-final.pdf
http://corporate.visa.com/_media/interchange-brochure.pdf
Also http://corporate.visa.com/viewpoints/interchange-index.shtml
Interchange Systems
Networks that act as authorization service for Visa and MasterCard transactions as wells as settlement service to transfer information between Issuers and acquires.
Getting quotes for merchant services
This is one of the most tricky steps. Do not rush and beware of of quick quotes. Not much is standard with merchant services so before you get a quote you must be sure that the sales person understand your own requirements, especially if you are in a speciality business. Fees are directly related to your industry, your card processing logic (not all business have the same processing logic especially when using an integrated payment application), the annual revenue for Visa and MasterCard and the average transaction value. A sales person should take the time to understand your business. Unfortunately it is too common for sales person to issue quick quotes with a statement such as "pricing applies to qualifying transactions" or "non-qualifying transactions will be charged at a higher rate". Sales people have to specify various factors to get pricing. When a transaction meets all these factors they "qualify". Transactions that do not qualify will be charged at a higher rate which often can be significantly higher. So when you get a quick quote you risk that the sales person issue a standard quote based on the wrong assumptions regarding your specific business. Even if the fees look great upfront at the end, your transactions will never qualify and you will end up paying much more than what was quoted to you. So ... BEWARE OF QUICK QUOTES and before doing anything Define your requirements .
Reach out for guidance
Beware of sales people especially the ones who tend to give quick answers and seem to be rushing you to get a quick sale. A good sales persone - one who spends time to understand your own needs and requirements - can be a great consultant, a great source of information and should be able to guide you through the processes.
Searching for providers
Not all gateway solutions and merchant service providers are equal. They do not provide the same funtionalities / services. Your first step is to define your requirements. See Define your requirements so you can select the right partners.
Identify your merchant DBA and charge descriptor
Merchant DBA: "doing business as" name as set in the merchant account
Charge descriptor: text identifying the charge on the card holder statement
Normally the charge descriptor is set as the merchant DBA.
These are too often overlooked when in fact they are critical for your operations.
If the charge descriptor does not clearly identify your business the card holders will not recognize the charge and will most likely dispute it with her/his card Issuer . This will result in a charge back and more importantly result in more work for you as you will need to response to all disputes.
Make sure your DBA and charge descriptor match the business name that the card holder knows. For online purchases for example make sure that the DBA and charge descriptor match the name of the website from which the order is placed.
Charge descriptor: text identifying the charge on the card holder statement
Normally the charge descriptor is set as the merchant DBA.
These are too often overlooked when in fact they are critical for your operations.
If the charge descriptor does not clearly identify your business the card holders will not recognize the charge and will most likely dispute it with her/his card Issuer . This will result in a charge back and more importantly result in more work for you as you will need to response to all disputes.
Make sure your DBA and charge descriptor match the business name that the card holder knows. For online purchases for example make sure that the DBA and charge descriptor match the name of the website from which the order is placed.
Define your card processing requirements
One of the most common mistakes is to start looking for gateway solution and merchant account without having a good definition of actual needs and requirements.
1. Understand your own requirements.
2. Identify your own needs
3. Define your estimated credit card revenue = annual Visa + MasterCard $ volume.
These details are key in searching for the right technical gateway solution, requesting quotes (especially for merchant services) and getting accurate quotes.
1. Understand your own requirements.
2. Identify your own needs
3. Define your estimated credit card revenue = annual Visa + MasterCard $ volume.
These details are key in searching for the right technical gateway solution, requesting quotes (especially for merchant services) and getting accurate quotes.
Subscribe to:
Posts (Atom)