Compliance

Disclaimer

You are responsible for protecting confidential cardholder and merchant account information. Do not send confidential information by email when diagnosing integration or production issues.

  • When sharing sample files or code with Moneris staff for analysis, remove or obscure all valid card numbers, merchant account details, and transaction tokens.
  • Do not use live cardholder accounts in the test environment.

Compliance Requirements

All merchants and service providers that store, process, or transmit cardholder data must comply with PCI DSS and Card Association Compliance Programs. Certification requirements vary by business and depend on your merchant level or service provider level. Failure to comply with PCI DSS and Card Association Compliance Programs may result in fines, fees, assessments, or termination of processing services. Non-compliant solutions may prevent merchants from onboarding with Moneris Solutions.

As a Moneris Solutions client or partner using this integration method, your solution must demonstrate compliance with the Payment Card Industry Data Security Standard (PCI DSS) and/or the Payment Application Data Security Standard (PA DSS). These standards help protect cardholders and merchants by requiring that credit card numbers are encrypted when transmitted or stored and that strong access controls are enforced.

For more information about PCI DSS and PA DSS requirements, visit https://www.pcisecuritystandards.org. To make your application PCI DSS compliant, contact our Integration Specialists and visit the PCI DSS document library to download the PCI DSS Implementation Guide.


Compliance Support

The Transaction Risk Management Tool provides additional data to help identify potentially fraudulent transactions. To maximize its effectiveness, Moneris recommends that you:

  • Define and implement clear business logic for handling the response information provided by the Transaction Risk Management Tool.
  • Implement additional fraud tools available through Moneris Gateway (for example, AVS, CVD, Verified by Visa, and MasterCard SecureCode).

When testing the Transaction Risk Management Tool, use the required test data. Review and follow the testing instructions and test data requirements in the documentation.


Did this page help you?