Home / Companies / Basis Theory / Blog / November 2023

November 2023 Summaries

8 posts from Basis Theory

Filter
Month: Year:
Post Summaries Back to Blog
High-risk merchants relying on a single payment service provider can remain compliant and operational by carefully selecting a partner suited to their merchant category, payment needs, support requirements, risk profile, and long-term growth plans. All-in-one providers may offer quick setup and integrated fraud and compliance tools but can impose strict rules and abruptly restrict high-risk businesses, while specialized providers often offer more flexibility but may require merchants to assemble additional services themselves. Keeping chargeback rates low through transparent customer communication, responsive support, clear refund policies, customer education, and ongoing review of fraud controls is essential for maintaining trust with processors and card networks. Merchants can further reduce dependence-related risks by using trusted third-party tools for fraud detection, dispute management, tokenization, payment security, and PCI compliance, allowing them to protect payment data and preserve operational flexibility even while using one primary PSP.
Nov 21, 2023 1,201 words in the original blog post.
Improving payment performance is presented as essential to revenue growth because businesses must maximize successful transactions while minimizing processing costs without limiting customers’ preferred payment choices. As merchants scale, relying on one full-service payment service provider can restrict payment options, increase cross-border costs, and prevent access to lower rates for methods such as debit cards and digital wallets, making a network of specialized PSPs more advantageous despite added complexity. Third-party tokenization can help merchants retain control of customer payment data while changing or balancing processors, and PSP selection should account for supported payment methods, high-risk product categories, and local processing capabilities in global markets. Automated payment routing can direct transactions to the most suitable provider based on location, payment type, fees, soft declines, and volume-discount targets, while careful routing of low-cost debit and wallet payments—and potentially higher-cost cards such as American Express—can further improve margins.
Nov 17, 2023 984 words in the original blog post.
High-risk merchants can be shut down either by card networks for sustained excessive chargebacks or by acquirers and payment service providers (PSPs) based on their own risk assessments, sometimes with little warning. Visa’s Dispute Monitoring Program begins with early warning at 75 disputes and a 0.65% dispute ratio, formally enrolls merchants at 100 disputes and 0.9%, and applies heightened enforcement at 1,000 disputes and 1.8%; merchants generally must remain below thresholds for three consecutive months to exit, while failure to improve after 12 months can lead to disqualification. Mastercard’s Excessive Chargeback Program applies after two months meeting thresholds of 100 chargebacks and a 1.5% ratio, or 300 chargebacks and 3%, and likewise requires three compliant months for removal. During monitoring programs, merchants and acquirers may face remediation requirements, ongoing reporting, fees, and escalating enforcement, with acquirers often passing costs to merchants. A shutdown can stop card-network acceptance entirely or merely require a merchant to find a new acquirer, and PSPs may hold funds for extended periods to cover anticipated refunds and disputes, intensifying cash-flow pressures.
Nov 16, 2023 1,584 words in the original blog post.
Basis Theory’s October updates focused on improving developer experience through API refinements, a redesigned Reactor workflow, and performance and usability fixes. The company introduced a private EU platform that mirrors its U.S. deployment, allowing European businesses to keep payment data regional, reduce latency, and support GDPR compliance by default, with access still expanding to waitlisted customers. Reactors were simplified by adding a direct code property, reducing reliance on Reactor Formulas, which the company found unnecessary in most cases and is now deprecating in favor of embedded code and templates. Proxy Transforms and Reactors also gained support for custom HTTP responses, enabling developers to halt default request processing and return tailored headers, bodies, and status codes for cases such as authentication handling and error standardization. Additional changes addressed iOS validation behavior, token updates, proxy header forwarding, and proxy performance when operating without an Expression.
Nov 09, 2023 466 words in the original blog post.
Basis Theory’s Casey Clegg and DataBright’s Dwayne Gefferie discussed how AI is beginning to reshape payments through stronger security, compliance, fraud prevention, and transaction optimization, while noting that adoption remains gradual because effective models depend on large, responsibly shared datasets and raise concerns about misuse by fraudsters. Fraud detection is currently the most developed use case, with AI-powered risk scoring and chargeback-prevention tools analyzing hundreds of transaction variables to identify suspicious activity, reduce card-not-present fraud, and improve experiences for legitimate customers through technologies such as dynamic 3DS and CAPTCHA systems. AI is also increasingly important for anti-money-laundering efforts, where providers such as Feedzai, ComplyAdvantage, and Sentinels analyze behavioral patterns and money flows to flag potentially illicit activity amid a growing volume of digital transactions. Payment optimization remains less mature, largely focused on smart routing, payment flagging, and intelligent retries, although machine learning is expanding its capabilities. The discussion also highlighted that specialized micro-acquirers using AI may gain market share from established providers as technology, data collaboration, and regulatory demands continue to evolve.
Nov 08, 2023 978 words in the original blog post.
Payment processing involves interconnected banks, card networks, merchants, service providers, and security systems that authorize, settle, and protect electronic transactions. Acquiring banks collect and settle merchant funds, while issuing banks provide consumer accounts or credit, and card networks such as Visa and Mastercard connect these parties. The glossary distinguishes credit cards, which use unsecured bank credit and can generate interest, from debit cards, which access existing deposits and face regulated U.S. fees, while also explaining authorizations, declines, chargebacks, refunds, and involuntary churn. It outlines merchant support options including payment service providers, full-service providers, high-risk specialists, and embedded iframe checkout solutions, alongside risk classifications based on merchant category codes. Security concepts include PCI-DSS compliance, multifactor authentication, encryption, tokenization, token vaults, network Token Requestor IDs, and privacy-oriented one-time-use or vaultless tokens. It also describes consumer and merchant payment products such as gift cards, frictionless payments, and fraud risks including triangulation fraud, in which a fraudulent seller uses stolen card details to purchase goods from a legitimate merchant.
Nov 07, 2023 1,288 words in the original blog post.
Payment processing separates authorization, which confirms that a customer can cover a transaction and may place a temporary hold on funds, from settlement, when the merchant formally collects payment and receives money through its acquiring bank or payment provider. This distinction supports businesses such as hotels, restaurants, online retailers, and service providers that need to verify payment capacity before final charges are known or goods and services are delivered; some authorizations are never settled or are settled for lower amounts because of cancellations or changed charges. Authorizations typically expire within 24 hours to seven days, depending on merchant category, requiring merchants to renew them if necessary. Full-service payment service providers generally pay merchants on scheduled net-of-fee payouts, while businesses using more decentralized or multi-provider systems can choose gross settlement, which delivers funds transaction by transaction but creates additional accounting work, or net settlement, which batches payments and deducts fees before payout. A settlement strategy therefore affects cash flow, bookkeeping complexity, provider flexibility, and potentially PCI-DSS compliance, with tokenization services helping reduce the compliance scope of using multiple payment partners.
Nov 03, 2023 875 words in the original blog post.
PCI DSS Requirement 12 establishes the organizational policies and programs needed to protect cardholder data and manage security responsibilities across an entity. Its ten sections require a current, widely communicated information security policy; acceptable-use rules for employee technology; formal risk analyses; executive oversight of PCI DSS compliance; documented and regularly validated scope; ongoing security awareness training; personnel screening; and management of third-party service-provider risks and responsibilities. The requirement also emphasizes maintaining current technology, cryptography, asset, data-flow, and service-provider inventories, with additional review obligations for service providers. Organizations must maintain, test, and improve an incident-response plan that assigns 24/7 responders, addresses security-monitoring alerts, supports recovery and required notifications, and provides procedures for discovering payment account numbers outside the defined cardholder data environment. The source also presents Basis Theory, a PCI Level 1 compliant service provider, as a platform intended to help companies secure and tokenize card data while reducing the number of systems brought into PCI DSS scope.
Nov 01, 2023 2,604 words in the original blog post.