Showing posts with label PCI compliance fees. Show all posts
Showing posts with label PCI compliance fees. Show all posts

Tuesday, May 28, 2013

Three Things You Need To Know About PCI Requirements


Although “PCI requirements” and “PCI compliance fees” aren’t quite the buzz words that they were a few years ago, PCI is still vitally important to your business, your clients and their customers.

Here are three things you need to know to keep your merchants compliant and their customers safe.

1. Breach Insurance Isn’t Enough
Most merchants understand that it’s important to keep their cardholders’ data safe and sound. 

But I have found that many still believe that, because they have breach insurance, they don’t have to worry. And so when I ask them what concrete measures they’ve implemented to protect their customers, they give me a blank stare.

Don’t get me wrong--breach insurance is great. But it’s no substitute for taking the necessary steps to fulfill PCI requirements and keep cardholders safe.

That’s why, as merchant service providers, we must constantly emphasize the PCI process.

2. Never Let Them Forget PCI
To ensure that merchants are protecting their customers’ data, you have to emphasize PCI throughout the merchant lifecycle.

I like to bring up PCI at the following occasions: 
  • Installation
At installation, many providers ask their customers for referrals, or they teach the business owner and staff how to operate the terminal. But installation is also a great time to talk PCI. Remind the merchant that they need to complete a PCI compliance assessment. Reiterate how important it is to secure their network. And be transparent about any PCI compliance fees that they’ll have to pay.
  • Retention
Communication is the best way to retain your merchants, so if you don’t have a newsletter, you should put one together today. And in every newsletter, you should touch on PCI. It doesn’t have to be the main article, but a short blurb in every issue will help keep PCI top of mind. 
  • Problem Calls
Every time a merchant contacts you, you have the opportunity to mention PCI. Of course, you should answer their question or solve their problem first. But then ask them how they’re doing. Have they heard anything new about data security? 

3. Compliant Today, Breached Tomorrow
Perhaps the most important thing to communicate to your merchants is the need for constant vigilance.

You could be doing everything right. You could have completed all your compliance assessments. You could have secured your network.

And then, one day, you make a single mistake, and your customers’ accounts will be compromised. You will no longer be compliant. And that mistake will cost you.

What do you think are the most important things to know about PCI?

Tuesday, February 26, 2013

PCI Compliance Fees: What They Tell You About Your Processor

Recently, many agents and ISOs have come to me and complained about PCI compliance fees.

Monthly PCI fees can range from $5-$20, and annual fees can set you back $60-$130 (and sometimes merchants have to pay both!). But while merchants certainly don’t like paying them, the real problem is often that processors don’t clearly explain them. They stick the fee information in the fine print or they don’t communicate all the details so when merchants receive their monthly statements and find the fees on them, they grab their phones and give their merchant processor an earful.

But while murky PCI compliance fees are a pain in the neck by themselves, they often tell a much bigger story: the general state of your relationship with your processor.

Delve into your processor’s PCI compliance process and ask yourself these questions. They’ll let you know if you need to think about a change:

  • How does your processor handle interchange fees? Do they pass them along at cost, or do they mark them up?
  • Does the merchant application or agreement clearly disclose merchant fees? Or are they hidden in the fine print somewhere?
  • On the merchant’s monthly statement, are fees labeled clearly and are the counts and amounts used to calculate the fees included?
  • Is it easy to read and understand your residual report? Or is it filled with long paragraphs of jargon and winding, tortuous sentences that go on and on, not really say anything, repeating themselves, kind of like this?

After asking yourself those questions, ask yourself one more: does your partner consistently hide fees in order to make more revenue? If so, this pattern will probably continue.

Will the amount they charge be reasonable or exorbitant? Will merchants be able to control the amount of the fee, or will they be left helpless? And will processors clearly explain the fees to merchants and ISOs, or will they conceal or camouflage them so that they can increase their profits?

Pay close attention to how your processor responds to these types of situations. If it isn’t to your liking, you probably have other issues as well. And you may need to start thinking about changing processors.

#

Jeff Zimmerman is Vice President of Product Management and Marketing at Clearent. He has 15 years of experience in marketing, finance and product management. Clearent can offer you a hassle-free PCI compliance process with no PCI compliance fees for merchants.