Payments and compliance

PCI and EMV for POS systems, payment terminals and the checkout

PCI and EMV get talked about as paperwork. At a counter they are mostly practical: which device takes the card, how the sale reaches it, what happens to a refund, and who on the staff can do what. This is what a retailer actually has to review.

No rate quoted before somebody has read your statement.

What do PCI and EMV mean for a POS system?

EMV is the chip-card standard the payment device follows at the point of sale. PCI is the card-industry security program a merchant validates for its own business, with its acquirer or processor. A POS system sits in the middle of both: it decides how the amount reaches the device, what is kept, who can void or refund, and what the network around the counter looks like.

The useful question is not "are we compliant" in the abstract. It is which parts of the checkout the store controls, and whether each of them is set up the way the program expects. Most of what goes wrong is ordinary: a device nobody has updated, a refund process invented at the counter, a flat network with the register on the same wire as everything else.

  • The device follows the chip standardEMV is what the terminal does, not what the POS claims.
  • Validation is the merchant’s, with its processorNo supplier can declare a business compliant on its behalf.
  • The workflow is where stores slipRefunds, voids and closeout are procedures before they are settings.
  • The network is part of the answerWhat the payment device shares a connection with is a question worth asking.

BizTracker does not certify anyone as PCI compliant. Validation is between the merchant and its acquirer or processor, and what we do is make the parts a store controls — the terminals, the workflow, the network and the people — easier to get right.

What to review

The seven things a retailer should look at

None of these needs a consultant to start. Each is a question a store can answer about itself.

  • The payment devices

    Which devices take cards, how old they are, who supports them and whether anybody updates them. Confirmed by model rather than assumed.

  • The chip-card workflow

    What the cashier does when a chip is inserted, when a card is tapped, and when the device asks for something the staff have not seen before.

  • How the amount reaches the device

    Typed by a cashier, or taken from the sale. That single choice decides how much of the rest is manual.

    Terminal or integrated
  • Refunds and voids

    Who may do them, whether they are attributable to a person, and what the record looks like afterwards.

    Cash management
  • The daily closeout

    Whether the batch and the day agree, and what the store does on the night they do not.

  • The network at the counter

    What the payment device connects through, what shares that connection, and what happens when it drops.

    Network setup
  • The people

    Which staff can process a refund, who has a login of their own, and what happens to those logins when somebody leaves.

Where payment compliance work goes wrong

  • Nobody owns the question

    The annual questionnaire gets answered from memory, by whoever opens the email.

    Name the person, and answer it from how the store actually works.

  • The device is older than anyone remembers

    A terminal nobody updates is the part of the counter least likely to be reviewed.

    Each device is identified by model and checked with the processor that supports it.

  • Refunds are a favour rather than a process

    An unattributable refund is a hole in both the cash story and the audit story.

    Refunds and voids run under permissions and land against the employee who did them.

    Cash management
  • The network grew by accident

    The card terminal ends up sharing a connection with whatever was plugged in last.

    The counter network is designed rather than inherited, and the payment path is part of the design.

    Network setup

PCI and EMV questions

Does a new POS system make a store PCI compliant?

No, and nobody should say otherwise. BizTracker does not certify anyone as PCI compliant. Validation is between the merchant and its acquirer or processor, and what we do is make the parts a store controls — the terminals, the workflow, the network and the people — easier to get right.

What is the difference between EMV and PCI?

EMV is the chip-card standard the payment device follows at the point of sale. PCI is the card-industry security program the merchant validates for its own business, with its acquirer or processor. One is what the terminal does; the other is how the business is run around it.

Who decides whether we are compliant?

Your acquirer or processor, against the program that applies to your business. BizTracker helps with the parts a store controls and will tell you plainly which questions are not ours to answer.

Do we need new payment devices?

It depends on the devices you have, what they support and who maintains them. We identify them by model and check rather than recommend a replacement first.

Where does the POS actually matter here?

In how the amount reaches the device, what the cashier can do without asking, how refunds and voids are recorded, and what the network around the counter looks like. Those are the parts we set up and support.

What should we do first?

Send one recent processing statement and say what devices are on the counter. The BizTracker Merchant Statement Review is free and there is no obligation to switch processors.

Start with the statement and the devices

One recent processing statement and the payment devices on your counter are enough for a first conversation about what to review and in what order.