Why You Should Care About PCI Compliance?

FBSG Support • Sep 16, 2019

If you have ever reviewed your monthly Merchant Account Statement and discovered that you have been paying a PCI Compliance penalty fee for months on end, you know how upsetting that can be. If you remain out of compliance for 6 months, that can cost you about $180 in penalty fees.

About PCI Compliance.

In 2006, an independent body was created by Amex, Visa, MasterCard, Discover and JCB to effectively try and reduce credit card fraud caused by the poor handling of credit card information by merchants and their employees. On a grand scale, let’s think back to when Target had a data breach of nearly 40 million credit card numbers from their internal computer servers. This happened as a result of weak security walls within their computer servers, and this should paint a clear picture of why the need for PCI compliance exists. Many large companies such as Home Depot, Chipotle and even Facebook, with all of their technology have all been vulnerable to data breaches.


In a majority of merchant related fraud cases, merchants were found to be largely responsible for leaks of credit card data by improper handling of credit cards by employees or inefficient security walls and protection within their servers. Merchants are provided credit card numbers, expiration dates and the magic three or four-digit security codes needed to authenticate. If written down on paper by an employee, they become a license to steal by anyone who comes upon the written information. PCI regulations mandate that you are never allowed to write down a complete card number with the related data. It is rules like this that make PCI Compliance so important to the credit card processing industry as well as the banks who issue credit cards. It is meant to protect the cardholder who is trusting you and expecting you to safeguard their data.

PCI DSS

In 2006, an independent body was created by Amex, Visa, MasterCard, Discover and JCB to effectively try and reduce credit card fraud caused by the poor handling of credit card information by merchants and their employees. On a grand scale, let’s think back to when Target had a data breach of nearly 40 million credit card numbers from their internal computer servers. This happened as a result of weak security walls within their computer servers, and this should paint a pretty big picture of why the need for PCI compliance exists. Many large companies such as Home Depot, Chipotle and even Facebook, with all of their technology have all been vulnerable to data breaches.


In a majority of merchant related fraud cases, merchants were found to be largely responsible for leaks of credit card data by improper handling of credit cards by employees or inefficient security walls and protection within their servers. Merchants are provided credit card numbers, expiration dates and the magic three or four-digit security codes needed to authenticate. If written down on paper by an employee, they become a license to steal by anyone who happens upon the written information. PCI regulations mandate that you are never allowed to write down a complete card number with the related data. It is rules like this that make PCI Compliance so important to the credit card processing industry as well as the banks who issue credit cards. It is meant to protect the cardholder who is trusting you and expecting you to safeguard their data.


In its full acronym, it is called PCI DSS. Spelled out, it is the Payment Card Industry Data Security Standards. It is this organization that assesses a monthly penalty for failing to maintain a PCI Compliance Certificate on file with your credit card processor. That fee does not go to Aurora Payments. It is assessed by the acquiring banks who assess the penalty to your processor, such as Aurora Payments, who then passes it on to you, the merchant.

Maintaining PCI Compliance.

The easiest way to maintain compliance is to complete a simple Self-Assessment Questionnaire, also known as an (SAQ). The SAQ is to be completed by the merchant on an annual basis and submitted to your processor to insure that not only are you handling credit card numbers with sensitivity but also making sure your computers cannot be hacked by an outside source if you store credit card information on your servers as Target does. It’s simply an annual review that reinforces and reexamines the way you and your employees handle credit card information as well as testing the firewalls of your computer server.


As a merchant, you are responsible for safeguarding your client’s credit card information from the time you receive it. Once a credit card number has been entered into your computer system it should be stored in an encrypted format, so employees are only able to see the last four or five digits of the card number and never have access to the entire card number again. Using this same principle, remember, a credit card number should never be written down on a paper for later use.


Developing policies that prohibit the transmission of credit card information by email or text messaging with your employees can further prevent data breaches and exposures from occurring.


Once you complete the SAQ, you will be issued a PCI Compliance Certificate upon successful analysis of your SAQ. This proves that you accept credit cards with proper concern for security and storage handling.


Credit card fraud affects nearly 32 million people each year and your efforts as a merchant can help reduce the chance of compromising your customer’s credit card and personal information.


Here at FBSG, we begin sending reminder notices that your PCI Compliance Certificate is about expire in 90 days. We will remind you again at 60 and 30 days out to complete the annual SAQ. If you fail to take action, you will be assessed a monthly penalty that will continue to be assessed until you provide us with a new Compliance Certificate. Remember that we collect this money on behalf of the banks and we at FBSG are not the one who assesses the penalty fee.


If you need help with PCI Compliance, contact your Account Executive or if you are not a FBSG client, contact us today and we will walk you through the process step by step!

By FBSG Support 19 Oct, 2022
1. Get More With Clover POS Looking to get more revenue with lower fees from online delivery? Clover’s got you covered. Clover Online Ordering with Delivery generally costs less than orders delivered through aggregators, like Uber Eats and Postmates. DoorDash® charges a flat rate delivery fee per order, invoiced monthly, and you have the option to pass through some or all of the delivery fees to your customers. That could mean more revenue per order for you and lower delivery fees for your customers. What’s more, offering your customers more ways to place orders– through Clover Web Ordering and the Clover app–can boost your online order volume and your revenue. 2. Take Full Control Of Your Delivery Now, you can offer delivery fully managed in your Clover POS. Clover Online Ordering with Delivery gives you centralized end-to-end control of online orders. That’s menu management, ordering, payments, and reporting all processed through Clover Online Ordering–with delivery dispatched to DoorDash®. And, it gives you centralized business management for inventory, menu syncs, order management, order processing, payment, and reporting. Clover Online Ordering with Delivery can make your restaurant a one-stop order and delivery shop.
Valor Dual Pricing
By FBSG Support 16 Jun, 2022
With Financial Business Solutions Group, businesses can now significantly lower or eliminate their merchant processing costs. Our fully compliant program displays dual-pricing on either a terminal or via a virtual gateway, giving the consumer a clear choice for their payment method. The displayed card price includes the cost of payment acceptance. Program Benefits Include: Empower consumers with the choice to select cash or card. Eliminate or lower processing costs. Choose to pass some or all of the cost of acceptance to the consumer. 1 monthly Program fee. Available for Invoicing, PayNow, and Virtual Terminal Transactions. Low Cost to accept ACH transactions with ACheck21.
By FBSG Support 10 Feb, 2022
#1 : Fees There are many fees associated with credit card processing. Here is a look at the fees you'll want to address and understand before signing your agreement. Interchange fees A fee charged for every credit card transaction. Your processor pays this 2% to 3.5% fee to the bank of the card type in each transaction. It fluctuates based on several factors, including the type of card accepted (credit, debit or a rewards card), the type of transaction (if it’s done in store, by phone, or online), and the size of each transaction. It's important to note in-store transactions will cost you less in interchange fees, since the card is physically present, meaning there’s less risk of fraud. Monthly statement fees The credit card processing company might charge you monthly statement fees to cover the expense of mailing you a statement. It costs about $10 per month on average but some offer it for free and some charge as high as $25 a month. Monthly minimum fee A monthly minimum amount in card transaction fees might be required by the processing company. For example, the company’s monthly minimum fee may be $25. If your total credit card transaction fees for the month were $20, the company will charge you $5 to make up the difference. Monthly gateway access fee Processors may charge you this monthly fee for providing a payment gateway, which transmits transaction data from your processing system to the credit card companies. Monthly fees cost approximately $10 to $30. Early termination fee Processors may charge you for an early cancellation of your contract. The fee can cost anywhere from a few hundred dollars to thousands. Make sure you ask what happens if you close your business or decide to use another processor. It's important to ask about all fees. There may be other fees than listed above and you will want to understand any and all recurring fees.
Share by: