Merchant Roles and Responsibilities
Learn how to merchant account roles and responsibilities at Columbia University.
Details
Senior Business Officers (SBOs) have overall responsibility for the merchant environment and Merchant accounts (MIDs) under their purview. The suggested roles below are designed to provide guidance to the SBO in managing all the tasks and recordkeeping required to meet the Payment Card Industry (PCI) Data Security Standards.
* Although individuals may perform more than one role, it is important that the authorized user who processes the payments is not the same individual who performs or reviews the monthly account reconciliation.
- Operational Responsibilities
- Ensure merchants with MIDs under his/her purview have departmental procedures in place to comply with CU Credit Card Acceptance and Processing Policy (CU Policy)
- PCI Compliance Responsibilities
- Complete all required training.
- Operational Responsibilities
- Ensure merchants with MIDs under his/her purview assign roles and responsibilities to ensure proper internal controls and compliance with CU Policy.
- PCI Compliance Responsibilities
- Ensure all individuals with access to Merchant environments complete all required training.
- Operational Responsibilities
- Review and approve all requests from merchants under his/her purview related to CU Merchant environments.
- PCI Compliance Responsibilities
- Review annual Self-Assessment Questionnaires (SAQs) for all open MIDs and sign Attestations of Compliance (AOCs) for each SAQ.
- Operational Responsibilities
- Ensure merchants with MIDs under his/her purview review diagrams illustrating the Cardholder Data Environment (CDE) and that diagrams are validated by the CUIT-PCI Security Group.
- PCI Compliance Responsibilities
- Take immediate action to respond to a suspected or confirmed security compromise.
- Operational Responsibilities
- Ensure merchants with MIDs under his/her purview maintain current copies of required third party service provider (TPSP) documentation and proof of PCI compliance.
- Operational Responsibilities
- Conduct reviews at least annually to review open MIDs and close unnecessary MIDs.
- Operational Responsibilities
- Coordinate all Merchant related requests with SBO and submit requests using instructions on Finance Gateway.
- PCI Compliance Responsibilities
- Complete all required training.
- Operational Responsibilities
- Receive new equipment/decommission equipment no longer needed.
- PCI Compliance Responsibilities
- Complete Monthly PCI DSS Checklist.
- Operational Responsibilities
- Maintain chain of custody records for all equipment that has direct physical interaction with Cardholder Data (CHD) from the time such equipment is delivered to when it is properly decommissioned.
- PCI Compliance Responsibilities
- Complete Monthly Device Inspection Form and Device Inventory Log for all terminals/devices used in Merchant environment.
- Operational Responsibilities
- Maintain current list and location of MIDs.
- PCI Compliance Responsibilities
- Complete annual SAQs for all open MIDs.
- Operational Responsibilities
- Maintain inventory list of all terminals/devices.
- PCI Compliance Responsibilities
- Independently verify identity of service/repair personnel who need access to credit card processing equipment; maintain access log.
- Operational Responsibilities
- Maintain up to date list of all authorized users.
- PCI Compliance Responsibilities
- Maintain list of TPSPs that affect the Merchant environment, including PCI requirements and provider role. Ensure proof of TPSP’s PCI DSS compliance is updated annually.
- Operational Responsibilities
- Promptly advise Treasury of changes to user list.
- PCI Compliance Responsibilities
- Alert SBO if a suspected or confirmed security compromise occurs.
- Operational Responsibilities
- Ensure operating procedures, data flow diagrams, third party service provider documentation and staff training & equipment inspection logs are up to date at all times.
- Operational Responsibilities
- Perform annual review with SBO to close unnecessary MIDs.
- Operational Responsibilities
- Provide a valid chartstring for both revenues & expenses/fees.
- PCI Compliance Responsibilities
- Complete required training.
- Operational Responsibilities
- Ensure a budget is setup on the expense account upon MID opening and prior to each fiscal year for as long as the MID is active.
- PCI Compliance Responsibilities
- Assist Merchant Account Coordinator in completing Monthly PCI DSS Checklist, as needed.
- Operational Responsibilities
- Complete reconciliations of all MID activity, including fees, at least monthly.
- PCI Compliance Responsibilities
- Alert SBO if a suspected or confirmed security compromise occurs.
- Operational Responsibilities
- Monitor and respond to chargeback disputes and retrieval requests.
- Operational Responsibilities
- Retain access to all online reconciliation and dispute management tools.
- Operational Responsibilities
- Coordinate completion of a Merchant Security Review Forms with Merchant Coordinator prior to setting up any new Merchant environments or making any changes to an existing Merchant environment.
- PCI Compliance Responsibilities
- Complete required training.
- Operational Responsibilities
- Setup and configure all transaction processing equipment, software and/or systems in accordance with the Credit Card Acceptance and Processing Policy.
- PCI Compliance Responsibilities
- Maintain a current diagram illustrating the CDE. The diagram must include all data flows, POS devices, network devices, servers, computing devices, applications, and any other component or device located within or connected to the CU Merchant’s CDE.
- Operational Responsibilities
- Ensure any web development activity is disclosed on the Merchant Security Review Form and approved by CUIT.
- PCI Compliance Responsibilities
- Assist Merchant Account Coordinator in completing Monthly PCI DSS Checklist as needed.
- Operational Responsibilities
- Disclose any access or control of third party payment processing pages, systems or servers and obtain approval from CUIT.
- PCI Compliance Responsibilities
- Alert SBO if a suspected or confirmed security compromise occurs.
- Operational Responsibilities
- Validate and process credit card transactions, including authorized refunds.
- PCI Compliance Responsibilities
- Complete required training.
- Operational Responsibilities
- Review transactions prior to settlement and ensure all open batches are settled daily.
- PCI Compliance Responsibilities
- Assist Merchant Account Coordinator in completing Monthly PCI DSS Checklist, as needed.
- Operational Responsibilities
- Retain Merchant copies of all signed card-present transaction receipts and submit to Financial Coordinator on a monthly basis, or as needed for retrieval requests or chargeback disputes.
- PCI Compliance Responsibilities
- Alert SBO if a suspected or confirmed security compromise occurs.
- Operational Responsibilities
- Perform daily physical inspections of transaction processing equipment and immediately report any suspected tampering.
- Operational Responsibilities
- Assist Financial Coordinator with chargeback disputes and retrieval requests as necessary. Retain Merchant copies of all signed card-present transaction receipts and submit to Financial Coordinator on a monthly basis, or as needed for retrieval requests or chargeback disputes.