opinion

Maintaining Payment Processing Compliance When the Goalpost Keeps Moving

Maintaining Payment Processing Compliance When the Goalpost Keeps Moving

VIRP is the new four-letter word everyone loves to hate. The Visa Integrity Risk Program went into effect last year, and affects several business types — including MCC 5967, which covers adult and anything else with nudity, and MCC 7273, dating services that don’t allow nudity. There are nearly a dozen other MCCs on the list, but for the purposes of this article, we’ll stick to those two.

The biggest obstacle affected businesses are encountering is that the VIRP guidelines are not public; they’re confidential. You read that right. You have to play the game by secret rules, and if you don’t, the “noncompliance assessments” — don’t call them “fines” — start at $25,000.

Many processors and banks have significantly reduced the thresholds for disputes-to-sales ratios and decline-to-sales ratios they will tolerate.

For guidance, businesses must therefore rely largely on payment processors and their sponsor banks, which do have access to the rules. In this article, I will attempt to demystify a few key points that every adult and dating site should be covering to be compliant.

Identity, Age Verification and Consent

Adult businesses should require all models and performers to submit a consent form, a 2257 release, and a valid photo ID verified through a third party before making their content available for purchase.

Handling Complaints

A link to file a complaint should be on the footer of your site or outside the paywall, so anyone can access it. Complaints should be addressed within seven days. Complaints of a more severe nature — something potentially illegal, for example — should be addressed immediately. The flagged content should be removed and reviewed. If the complaint is unfounded, the content can be restored, but the complaint itself should be logged in the transparency report.

Transparency Reports

Every month, you should submit a report to your merchant service provider that includes takedown requests, complaints received, law enforcement interactions, legal requests and, if applicable, member/model bans.

These are just a few items to consider. This is by no means a complete and comprehensive list. Additionally, different processors may have slightly different interpretations of the rules.

Dispute and Fraud Ratios

Another aspect of transaction processing that has come under scrutiny with the enforcement of VIRP is dispute and fraud ratios. Many processors and banks have significantly reduced the thresholds for disputes-to-sales ratios and decline-to-sales ratios they will tolerate.

Several tools are available to help keep these ratios in check, and keep your merchant accounts off the radar of card brands, banks and processors. For instance, dispute resolution services issue a refund instead of a chargeback, which helps keep your chargeback ratios down and requires no human intervention.

Utilize Your Toolkit

Another way to help keep your fraud and fraud-related decline codes under control is by using tools that are included with your merchant account. Address verification service (AVS) checks the billing address and ZIP code entered during the checkout process against the information from the cardholder’s issuing bank, and card verification value (CVV), the three-digit security code on the back of the credit card, offers another layer of verification.

These two tools are already included with every merchant account and should be enabled in just about every gateway. It’s simply a matter of deciding how to treat transactions based on the responses. If you want to be super conservative, you can decline to proceed with any transaction that has a negative AVS or CVV response. If you want to be moderate, you can proceed with a positive AVS or CVV. You can fine-tune the rules however you like to fit your business needs.

Expertise is Key

When it comes down to it, only you know what’s best for your business. However, it’s also true that it takes a village, and a rising tide lifts all boats. Take advantage of available industry resources, like payments experts who will take the time to answer your questions and help guide you through the ambiguous world of banking acronyms and initialisms — including the four-letter ones.

Jonathan Corona has two decades of experience in the electronic payments processing industry. As chief operating officer of MobiusPay, Corona is primarily responsible for day-to-day operations as well as reviewing and advising merchants on a multitude of compliance standards mandated by the card associations, including, but not limited to, maintaining a working knowledge of BRAM guidelines and chargeback compliance rules defined in both Visa and Mastercard operating regulations.

Related:  

Copyright © 2024 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More Articles

opinion

Making the Most of Your Sales Opportunities

The compliance road has been full of twists and turns this year. For many, it’s been a companywide effort just to make it across that finish line. Hopefully, most of us can now return our attention to some important things we’ve left on the back burner for months — like driving revenue.

Cathy Beardsley ·
profile

YourPaysitePartner Marks 25-Year Anniversary Amid Indie Content Renaissance

For 25 years, YourPaysitePartner has teamed up with stars and entrepreneurial brands to bring their one-stop-shop adult content dreams to life — and given the indie paysite renaissance of the past few years, the company’s efforts have paid off in spades.

Alejandro Freixes ·
opinion

WIA Profile: B. Wilde

B. Wilde considers herself a strategic, creative, analytical and entertaining person by nature — all useful traits for a “marketing girlie,” a label she happily embraces.

Women In Adult ·
opinion

Proportionality in Age Verification

Ever-evolving age verification (AV) regulations make it critical for companies in the adult sector to ensure legal compliance while protecting the privacy of adults wishing to view adult content. In the past, however, adult sites implementing AV solutions have seen up to a 60% drop in traffic as a result.

Gavin Worrall ·
opinion

Goodbye to Noncompete Agreements in the US?

A noncompetition agreement, also known as a noncompete clause or covenant not to compete, is a contract between an employer and an employee, or between two companies.

Corey D. Silverstein ·
opinion

The Search for Perfection in Your Payments Page

There has been a lot of talk about changes to cross sales and checkout pages. You have likely noticed that acquirers are now actively pushing back on allowing merchants to offer a negative option, upsell or any cross sales on payment pages.

Cathy Beardsley ·
opinion

Unpacking the Payment Card Industry's Latest Data Security Standard

The Payment Card Industry Data Security Standard (PCI DSS) is a set of requirements and guidelines that apply to all businesses that accept credit card payments, and is designed to ensure the security of those transactions.

Jonathan Corona ·
opinion

Compliance With State Age Verification Laws

During the past year, website operators have faced a slew of new state age verification laws entailing a variety of inconsistent compliance obligations.

Lawrence Walters ·
opinion

Merchants in Spotlight With Visa's VIRP

By now, most merchants know about the Visa Integrity Risk Program (VIRP) rolled out in spring 2023. The program is designed to ensure that acquirers and their designated agents — payment facilitators, independent sales organizations and wallets — maintain proper controls and oversight to prevent illegal transactions from entering the Visa payment system.

Cathy Beardsley ·
opinion

How to Know When Hosting Upgrades Are Really Needed

I was reminded about an annoyingly common experience that often frustrates website owners: upgrades. Sometimes, an upgrade of physical system resources like CPU, RAM or storage really is required to solve a problem or improve performance… but how do you know you’re not just being upsold?

Brad Mitchell ·
Show More