shifting fraud liability = big change · 2016-02-11 · cnp fraud historically rises for several...

2
Vol 6, Issue 1 2016 Payment News BE GREEN Sign up for e-newsletter here http://3dmerchant.com/contact/. SHIFTING FRAUD LIABILITY = BIG CHANGE Network non-compliance fees have effectively made EMV (Europay, MasterCard & Visa) chip card acceptance a mandate. October 1, 2015, a non- disputable Fraud Liability Shift went into effect for card present transactions. January 1, the first wave of merchants were hit with non-compliance penalties, a percentage of sales. They’ll roll out to all eventually. If your business is Card Not Present (CNP) only, YOU’RE STILL AFFECTED. CNP fraud historically rises for several years after a country adopts EMV. Like EMV does for retail, cardholder authentication for online payments can shift fraud liability back to the issuer. There are many complexities, making a rules-based solution essential for automated risk management as well as optimizing interchange qualification. With millions of cards being replaced with chip cards, expect a big rise in stored card failures. Enable customers to self-serve updates online or use a Card Updater service; prices have declined from the past- we charge $.09 per card updated. Don’t count on your banker for advice in these changing times, and maybe not even your software consultant. Bank reps service a broad spectrum of clients and have limited solutions to offer. For example, not one bank in the US today has an EMV solution that supports level III processing; our Business to Business clients save 35 basis points on average for all sales channels, regardless of processor. PCI COMPLIANCE 3.0 REQUIREMENT 9: RESTRICT ACCESS TO CARDHOLDER DATA “We keep all cardholder data in a locked file drawer and I’m the only one with a key” does not comply with 3.0 standards. The use of paper credit card authorization forms is dead. Destroy all paper records and record who, what, when, where and how for your Payment Card Industry Data Security Standards (PCI) records. 60 second BEST PRACTICES Video http://tinyurl.com/gphp4nn to collect, store, and bill customers using stored cardholder data, including signature ready PCI Compliant authorization form. Christine Speedy The only independent payment gateway protecting your front door with certified US P2PE EMV level III terminals and your back door with authentication. CALL 954-942-0483, 8-6 ET Cspeedy AT 3dmerchant.com Privacy: your email is used only to respond to your inquiry; my enewsletter is separate opt-in only! REFERENCE CenPOS- cloud-based business solutions delivering increased profits, security, and efficiencies; compatible with ALL MAJOR PROCESSORS, and multiple payment types. Over a dozen ERP & Quickbooks integrations. 3D Merchant Services is the marketing entity of Christine Speedy, a CenPOS authorized reseller. All agreements are direct with CenPOS; There’s no middleman. PARTIAL PRODUCTS LIST: Virtual terminal, gateway, level 3 processing, ACH, electronic bill presentment & payment, token billing, online payments. URL’s www.3Dmerchant.com/blog www.pcisecuritystandards.org www.cenpos.com www.quora.com/Christine-Speedy www.linkedin.com/in/cspeedy PCI 3.0 (mandated effective 1/1/2015), is a key component of data breach prevention and financial risk management. PAN data (card number) cannot be stored unencrypted CVV can never, ever be stored Collecting card data via email, texting, chat etc is not allowed Records of employee PCI Compliance understanding is required.

Upload: others

Post on 20-Jun-2020

3 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: SHIFTING FRAUD LIABILITY = BIG CHANGE · 2016-02-11 · CNP fraud historically rises for several years after a country adopts EMV. Like EMV does for retail, cardholder authentication

Vol 6, Issue 1 2016 Payment News

BE GREEN Sign up for e-newsletter here http://3dmerchant.com/contact/.

SHIFTING FRAUD LIABILITY = BIG CHANGE

Network non-compliance fees have effectively made EMV (Europay, MasterCard & Visa) chip card acceptance a mandate. October 1, 2015, a non-disputable Fraud Liability Shift went into effect for card present transactions. January 1, the first wave of merchants were hit with non-compliance penalties, a percentage of sales. They’ll roll out to all eventually.

If your business is Card Not Present (CNP) only, YOU’RE STILL AFFECTED. CNP fraud historically rises for several years after a country adopts EMV. Like EMV does for retail, cardholder authentication for online payments can shift fraud liability back to the issuer. There are many complexities, making a rules-based solution essential for automated risk management as well as optimizing interchange qualification.

With millions of cards being replaced with chip cards, expect a big rise in stored card failures. Enable customers to self-serve updates online or use a Card Updater service; prices have declined from the past- we charge $.09 per card updated.

Don’t count on your banker for advice in these changing times, and maybe not even your software consultant. Bank reps service a broad spectrum of clients and have limited solutions to offer. For example, not one bank in the US today has an EMV solution that supports level III processing; our Business to Business clients save 35 basis points on average for all sales channels, regardless of processor.

PCI COMPLIANCE 3.0 REQUIREMENT 9: RESTRICT ACCESS TO CARDHOLDER DATA

“We keep all cardholder data in a locked file drawer and I’m the only one with a key” does not comply with 3.0 standards. The use of paper credit card authorization forms is dead. Destroy all paper records and record who, what, when, where and how for your Payment Card Industry Data Security Standards (PCI) records.

60 second BEST PRACTICES Video http://tinyurl.com/gphp4nn to collect, store, and bill customers using stored cardholder data, including signature ready PCI Compliant authorization form.

Christine Speedy

The only independent payment gateway protecting your front door with certified US P2PE EMV level III terminals and your back door

with authentication.

CALL 954-942-0483, 8-6 ET Cspeedy AT 3dmerchant.com

Privacy: your email is used only to

respond to your inquiry; my enewsletter is separate opt-in only!

REFERENCE CenPOS- cloud-based business solutions delivering increased profits, security, and efficiencies; compatible with ALL MAJOR PROCESSORS, and multiple payment types. Over a dozen ERP & Quickbooks integrations.

3D Merchant Services is the marketing entity of Christine Speedy, a CenPOS authorized reseller. All agreements are direct with CenPOS; There’s no middleman.

PARTIAL PRODUCTS LIST: Virtual terminal, gateway, level 3 processing, ACH, electronic bill presentment & payment, token billing, online payments.

URL’s www.3Dmerchant.com/blog www.pcisecuritystandards.org www.cenpos.com www.quora.com/Christine-Speedy www.linkedin.com/in/cspeedy

PCI 3.0 (mandated effective 1/1/2015), is a key component of data breach prevention and financial risk management.

• PAN data (card number) cannot be stored unencrypted

• CVV can never, ever be stored • Collecting card data via email, texting, chat

etc is not allowed

Records of employee PCI Compliance understanding is required.

Page 2: SHIFTING FRAUD LIABILITY = BIG CHANGE · 2016-02-11 · CNP fraud historically rises for several years after a country adopts EMV. Like EMV does for retail, cardholder authentication

2633 NE 26th Ave, Lighthouse Pt., FL 33064 954-942-0483 direct • 954-942-9804 fax

www.3Dmerchant.com

Vol 6, Issue 1 2016

Beat my PCI Compliance test- Win a Mobile Card Reader or iPod!

IN THIS ISSUE:

EMV & CARDHOLDER AUTHENTICATION PCI Compliance 3.0 – Are you really compliant?

Preventing Card Not Present Transaction Disputes

MITIGATING LOSSES: PREVENT & WIN DISPUTES 2016 stands to be a record year for Card-Not-Present fraud. According to Javelin Research, CNP fraud is expected to grow from $10B in 2014 to over $19B in 2018. 3 Prevention Tips:

1. Never key-enter transactions on a retail merchant account (countertop terminal, for example) without a signed receipt.

2. Validate Address (AVS & Zip Code) and CVV. 3. Implement consumer authentication. Like EMV for retail, an automated rules-based solution

shifts 100% of fraud liability back to the issuer, opening new markets for sales. Because risk is reduced, USA interchange rates drop an average of .22%

Did you know? You can submit more evidence than what’s suggested on chargeback response forms, including email correspondence (require company email address for all B2B orders), dates and times of calls, buyer acknowledging acceptance of sales order terms and conditions on a signed sales order.

PASS MY PCI CHALLENGE AND WIN AN IPOD

fax address/recipient changes to (954) 942-9804

Send an email with PCI CHALLENGE in the subject. If I can’t prove a PCI problem with 10 questions, you win an Apple iPod, and bragging rights on my blog. If I win, we have a 5-minute call to discuss solutions.