1 / 3100%
Summary:
During the most recent financial audit of Padgett-Beale (PBI), it was
discovered that an internal department has been leveraging a third-
party vendor for their micro payment services without the proper
authorization of PBI leaders. Micro payments are a form of electronic
commerce that charge for goods or services, and can range from
charging less than a cent up to a few dollars (Ecommerce Guide, n.d.;
Wagemann, 2021). In this specific instance, it entails customers being
issued a secondary card that they can load money onto via their
personal credit card. This card can then be used around PBI
properties at amenities that do not have a cashier, such as the
laundry facilities. The third-party vendor is responsible for the card
kiosks and supplies, transactions required to load the secondary card,
and all maintenance to the program. PBI receives a percentage of
each dollar loaded onto the vendor cards, as specified in the service
agreement.
Stance:
Although this micro payment program was not initiated according to
policies and procedures, continuing to use this service has the
potential to financially benefit the company. Over the last 10 years,
PBI has seen a drastic decrease in the use of amenities that require
physical money. During this same span of time, debit/credit cards
and contactless payments have expanded and are almost the sole
source of payment at every PBI location. If micro payment cards are
leveraged to attract customers back to these amenities, there may be
a higher return of investment and greater profit margin. But before
this project has the official stamp of approval from the Finance
Department, there are some possible security and/or customer
privacy issues that need to be addressed through PBI’s IT Team and
the third-party vendor.
The Payment Card Industry Data Security Standard (PCI DSS),
determined by the PCI Security Standards Council, “[sets] technical
and operations requirements to protect cardholder data… [which]
applies to all entities that store, process, or transmit” cashless
payment information (Willis, 2019, p. 1). Although PBI is not the
owner of the program and processes, it would be viewed as an
endorsement or promotion due to the partnership with the vender.
Therefore, any intentional or unintentional neglect or loss of PCI by
the third-party may harm PBI’s reputation and revenue stream. The
following concerns stem from the PCI DSS requirements.
Issue #1: Is the third-party vendor storing payment information?
If so, what defenses are put into place to protect this information?
The PCI DSS requires a firewall, at the bare minimum (Willis, 2019).
But useful information would also include the vendor’s software
update schedule, employee training programs, security monitoring
programs, etc.
Issue #2: Is the payment transmission encrypted (Willis, 2019)?
If a customer was to add money onto the micro payment card using
the magnetic stripe on their bank card, how is the third-party
working to mitigate that data being stolen?
Issue #3: What is the customer given before being rendered services?
Is there an agreement a customer must sign before being allowed to
use the vendor’s micro payment services? Could PBI add a liability
clause? If there is a data breach and PCI is stolen, is it possible that
PBI could end up responsible for any amounts taken from customers’
accounts?
Issue #4: Who has access to payment details (Willis, 2019)?
What safeguards does the vendor have in effect that help protect
against employees stealing customers’ PCI? What is the separation of
duties to prevent this?
Issue #5: Does PBI have account access to monitor all transactions?
Are there daily/weekly/monthly reports? Not only to ensure
transparency and honesty, but PBI needs to verify whether or not
this program attracts customers to weaker sources of revenue.
Conclusion:
Before PBI can full commit to this micro payment program, there
must be an in-depth analysis conducted on the vendor and their
program. But it does have the potential to bring in more revenue by
increasing accessibility to certain amenities for customers. If officially
implemented by PBI, success of this third-party program should be
closely monitored. Depending on the findings after a specified
amount of time, the decision can be made to either terminate the
program or look to expand similar concepts into other areas of the
company.
References
Ecommerce Guide. (n.d.).
What is ecommerce?
Ecommerce Guide.
https://ecommerceguide.com/guides/what-is-ecommerce/
Wagemann, C. (2021, December 29).
What is a micropayment?
The
Balance. https://www.thebalance.com/micropayment-5205583
Willis, L. (2019, January 3).
The Payment Card Industry Data Security
Standard
. American Bar Association.
https://www.americanbar.org/groups/litigation/committees/minority-
trial-lawyer/practice/2019/the-payment-card-industry-data-security-
standard/
Students also viewed