Showing posts with label pci dss compliance. Show all posts
Showing posts with label pci dss compliance. Show all posts

Tuesday, February 26, 2013

PCI Compliance Fees: What They Tell You About Your Processor

Recently, many agents and ISOs have come to me and complained about PCI compliance fees.

Monthly PCI fees can range from $5-$20, and annual fees can set you back $60-$130 (and sometimes merchants have to pay both!). But while merchants certainly don’t like paying them, the real problem is often that processors don’t clearly explain them. They stick the fee information in the fine print or they don’t communicate all the details so when merchants receive their monthly statements and find the fees on them, they grab their phones and give their merchant processor an earful.

But while murky PCI compliance fees are a pain in the neck by themselves, they often tell a much bigger story: the general state of your relationship with your processor.

Delve into your processor’s PCI compliance process and ask yourself these questions. They’ll let you know if you need to think about a change:

  • How does your processor handle interchange fees? Do they pass them along at cost, or do they mark them up?
  • Does the merchant application or agreement clearly disclose merchant fees? Or are they hidden in the fine print somewhere?
  • On the merchant’s monthly statement, are fees labeled clearly and are the counts and amounts used to calculate the fees included?
  • Is it easy to read and understand your residual report? Or is it filled with long paragraphs of jargon and winding, tortuous sentences that go on and on, not really say anything, repeating themselves, kind of like this?

After asking yourself those questions, ask yourself one more: does your partner consistently hide fees in order to make more revenue? If so, this pattern will probably continue.

Will the amount they charge be reasonable or exorbitant? Will merchants be able to control the amount of the fee, or will they be left helpless? And will processors clearly explain the fees to merchants and ISOs, or will they conceal or camouflage them so that they can increase their profits?

Pay close attention to how your processor responds to these types of situations. If it isn’t to your liking, you probably have other issues as well. And you may need to start thinking about changing processors.

#

Jeff Zimmerman is Vice President of Product Management and Marketing at Clearent. He has 15 years of experience in marketing, finance and product management. Clearent can offer you a hassle-free PCI compliance process with no PCI compliance fees for merchants.

Thursday, May 5, 2011

PCI DSS Compliance and Adressing the Blame Game

We all know the "Blame Game." We were introduced to it as a child. It typically involves breaking, spilling, or loosing something that your mother didn't want you tinkering with in the first place. The game changes as we get older - our arguments get stronger but we still pass the blame.

Here are some classic responses we've either said - or heard - at one time or another:
• "(Name) did it."
• "It wouldn't have happened if (Name) did (Desired Action)."
• "It's not my fault."

As a result, today our society could be defined as a litigious one. People are quick to sue and claim that they shouldn't be held accountable and that it's someone else's fault that something bad happened.

Merchants are no different because of the pressures they face, especially with the varying changes in regulation and the economy over the past few years. There are all sorts of opportunities for errors and finger pointing.

One area that is very important is maintaining data security, PCI DSS compliance. Vulnerabilities can be created from careless actions, and vulnerabilities can result in a breach, as well as hefty fines, penalties and more.

When this happens, it's likely that the merchant is going to look outside of his business for someone to blame. And when he thinks he's found that someone, a lawsuit could be the next thing to follow.

To protect themselves and their merchant customers, most payment processors will insist on the completion of a PCI compliance assessment. The processor then reviews the assessment to identify merchants whose actions may put them at risk for a compromise. This helps keep the blame at bay but its not the best.

It's common for ISOs to want to provide the best possible service to their merchants and they may want to complete the self-assessment questionnaires (SAQs) on behalf of their merchant.

What happens if, for some reason, a merchant is then breached? If it is determined that the merchant was not PCI compliant and the questionnaire was not completed accurately, who will the merchant blame? It was the ISO who helped them complete their PCI compliance assessment, of course.

PCI DSS compliance and data security are very important, but processors shouldn't put ISOs in the middle of their approach. That isn't their job, and frankly, they shouldn't be expected to be a PCI compliance expert. Also, remember that why one of the best way to avoid this Blame Game is a self-assessment questionnaire, designed to be taken by merchants because they know the details of their operation best.

So what's the solution?

At Clearent, we use an online questionnaire, designed to be completed by the merchant to assist with PCI DSS compliance. We believe it shouldn't be part of the application process, but rather part of the support your payment processor provides to your merchants. And it shouldn't come with a cost to complete.

It's a simple approach, but one that any ISO today with the desire to grow should appreciate. That way if a breach should ever happen, you can easily say, "It wasn't me. I wasn't even involved." - and truly mean it. Otherwise, it may be prudent to have an attorney on retainer.