Hostcomm's solution for PCI compliance in call centres
The Payment Card Industry Data Security Standard (PCI DSS) is an information security standard for organizations that handle cardholder information for the major debit, credit, prepaid, e-purse, ATM, and POS cards. Defined by the Payment Card Industry Security Standards Council, the standard was created to increase controls around cardholder data to reduce credit card fraud via its exposure. Validation of compliance is done annually - by an external Qualified Security Assessor (QSA) for organisations handling large volumes of transactions, or by Self-Assessment Questionnaire (SAQ) for companies handling smaller volumes.
Hostcomm has two solutions which will enable a call centre to pass a PCI audit and gain PCI certification:
PCI compliant Hosted IVR
The agent hands off the client by pressing a hotkey to a PCI compliant interactive voice response (IVR) system. The agent can then continue taking calls and the IVR processes the clients payment and updates the database. This system is very easy for the agent's to understand and reduces the average cost per transaction as well preventing the agent from being exposed to the client's credit card details. The service is provided on a 'pay as you go' basis and there are no hardware / software costs to pay.
Agent assisted payments
The solution enables contact centre agents to perform MOTO CNP transactions without having to receive client’s card numbers verbally over the phone. The contact centre agent simply requests that the cardholder enter their card number using the keypad on their phone. The assisted payments solution automatically populates the relevant fields with the data collected. When the agent is ready they then process the masked data to retrieve an authorisation code from the merchant bank. This solution enables the agent to remain in contact with the agent throughout the duration of the telephone call. The telephone call can be recorded because the DTMF tones (key presses) are effectively scrambled.
The service is provided on a 'pay as you go' basis and there are no hardware / software costs to pay.