Society of Payment Security Professionals Forum  

Go Back   Society of Payment Security Professionals Forum > Discussion Groups > PCI DSS Q&A

Reply
 
Thread Tools Display Modes
  #1  
Old 03-10-2009, 04:58 AM
MistySue MistySue is offline
Junior Member
 
Join Date: Mar 2009
Posts: 2
Default Recovering the Cost of Compliance from Customers

Hello All, I am not sure if this is the correct spot to ask this question, but none of the other forums looked right either.

I am wondering what other companies have done to recover the cost of PCI Compliance from customers. For my company a lot of the custormers are pushing for PCI. We would like to charge for this service as there are not a lot of companies in Canada that are compliant. Have any of you done this and what was your experience/ideas.
Reply With Quote
  #2  
Old 03-10-2009, 10:22 AM
jonassono jonassono is offline
Senior Member
 
Join Date: Apr 2008
Location: Vancouver, Canada
Posts: 279
Default

All of my compliance work is with Canadian companies and, yes, there are very few that have validated their PCI-DSS compliance.

To the best of my knowledge, no clients are openly charging back the compliance costs (as an additional fee on the transaction slip) to their customers, but maybe not such a bad idea.

1000's of small merchants now advise customers of a small additional fee ($.25 to $.50) for payment card purchases versus cash for transactions under $5 to $10. Not certain how the additional fee is working, i.e. ratio of fee payers to use a payment card versus opting to use cash.

In your case, perhaps you could simply advise customers that a small additional fee for all credit card purchases will be automatically added to the purchase to cover the cost of PCI-DSS compliance.

You may want to check with the card brands you accept, your merchant bank and your acquirer before proceeding, as there may be restrictive covenants in place that prohibit this practice.
__________________
OJ Jonasson CMC
Reply With Quote
  #3  
Old 03-10-2009, 05:54 PM
MistySue MistySue is offline
Junior Member
 
Join Date: Mar 2009
Posts: 2
Default

Hey Jonassono, Thanks for your reply. I actually work for Call Centre we are a third Party Service supplier. We do all e-commerce transactions. Basically we take the call authorize or process the card using either an online processing company or the client's site. However we are still required to be PCI compliant. Do you think there would still be restrictions in place, as we already charge per minute for time the call takes (which includes time for the transaction)
Reply With Quote
  #4  
Old 03-10-2009, 07:22 PM
jbhall56's Avatar
jbhall56 jbhall56 is offline
Senior Member
 
Join Date: Feb 2007
Location: Minneapolis, MN
Posts: 1,282
Default

In the SAS 70 world, it's not unusual to have a data center or call center charge their customers a fee to obtain a copy of the SAS 70 report.

Therefore, I would think it's not out of question for you to charge some sort of fees to be PCI compliant and for conducting whatever work you might have to to be PCI compliant.

Billing by the length of call is not controllable and would likely irritate your customers. After all, you would penalize customers whose customers are less organized and therefore take longer to conduct the transaction. That's not necessarily your customer's fault, but does affect your ability to process more calls per operator. I would recommend surcharges per call instead for PCI costs as well as for any reduced efficiencies of your operators due to extra call lengths. I would think that is a much more justifiable way to recoup your costs.
__________________
Jeff Hall, Director, Risk Advisory Services
RSM McGladrey Inc
801 Nicollet Mall, 11th Floor, West Tower
Minneapolis, MN 55402-2526
612 376 9280 - office
612 395 7280 - facsimile
www.mcgladrey.com

The views presented are those of the writer and are not necessarily those of RSM McGladrey Inc
Reply With Quote
  #5  
Old 03-11-2009, 03:34 PM
jonassono jonassono is offline
Senior Member
 
Join Date: Apr 2008
Location: Vancouver, Canada
Posts: 279
Default

Quote:
Originally Posted by MistySue View Post
Hey Jonassono, Thanks for your reply. I actually work for Call Centre we are a third Party Service supplier. We do all e-commerce transactions. Basically we take the call authorize or process the card using either an online processing company or the client's site. However we are still required to be PCI compliant. Do you think there would still be restrictions in place, as we already charge per minute for time the call takes (which includes time for the transaction)
Since you are a service provider and not a merchant, you can pretty much do as you as wish, within the confines of your SLA's/OLA's or contracts with the merchants you serve.

If you can readily quantify your PCI-DSS compliance costs, it would be fairly straightforward to add these costs somewhere in your billing stream, i.e. increase the per minute call charges, add a % at each merchant invoice cycle....
__________________
OJ Jonasson CMC
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -8. The time now is 03:18 PM.


Copyright (c) The Aegenis Group, Inc.