From MOTO to ATO: A Framework for Authenticated Telephone Payments (v.0.2)

From MOTO to ATO: a technical framework for distinguishing authenticated telephone payments within MOTO.

Pay by Call is engaging with EMVCo and the EBA to help the payments industry distinguish traditional MOTO from telephone-initiated transactions that use issuer-controlled authentication (ATO).

By José Chillerón, Chief Strategy Officer and Co-Founder, Pay by Call

For decades, card payments made by mail or telephone have been grouped under MOTO —Mail Order or Telephone Order. This classification principally describes how the payer communicates the instruction to make the payment. In the terminology of the Regulation, this is how the payer “places the payment order”: by mail or telephone rather than through an electronic platform or device.

The security capabilities available to the telephone channel have nevertheless changed. Card data can now be captured inside a controlled PCI DSS environment, the conversation can remain active, and issuer-controlled authentication can be orchestrated through EMV® 3-D Secure without necessarily turning the merchant payment into a separate web checkout or relying on pay-by-link.

This raises a relevant industry question:

If two transactions remain legally MOTO, but one generates verifiable issuer-authentication evidence and the other does not, should the payments ecosystem be able to distinguish their different security outcomes?

Pay by Call believes it should. We therefore propose ATO —Authenticated Telephone Order— as a technical and operational designation for an authenticated telephone payment.

ATO is not currently a legal category recognised by EU law, EMVCo, the European Banking Authority or the card schemes. Nor do we claim that authentication, by itself, changes the legal classification of a transaction. The proposal is intended to make a material security outcome identifiable, assessable and interoperable even where the underlying order remains MOTO.

The current legal basis: why MOTO is outside mandatory SCA

The treatment of MOTO outside the mandatory Strong Customer Authentication —SCA— perimeter derives from Directive (EU) 2015/2366 —PSD2, rather than from Commission Delegated Regulation (EU) 2018/389.

Article 97(1)(b) of PSD2 requires SCA where the payer initiates an electronic payment transaction. Recital 95 distinguishes electronic transactions from payment processes initiated and executed in the context of mail or telephone orders. MOTO has therefore been treated as non-electronic for the purpose of this SCA trigger.

Delegated Regulation 2018/389 develops the technical standards for SCA and secure communication, but it is not the legal source of the MOTO exclusion. This distinction matters: MOTO is not simply a risk exemption created by the RTS; it falls outside the PSD2 trigger for mandatory SCA.

The EBA has applied this approach in several Single Rulebook Q&As, including questions concerning manually keyed transactions and IVR solutions. Those responses also demonstrate that classification depends on the facts of the actual payment flow, not merely the label used by a merchant or acquirer.

What the agreed PSR text says

The EU framework is evolving through PSD3 and the future Payment Services Regulation —PSR. The Council final compromise text of 17 April 2026, confirmed through the interinstitutional process and still subject to formal completion of the legislative procedure, expressly addresses MOTO.

Recital 108 establishes that a transaction may continue to qualify as MOTO when the customer communicates by telephone the instruction to make the payment. In this context, “placing the payment order” means communicating or giving that payment instruction. The fact that the bank subsequently authenticates the payer electronically and that the payment is processed electronically does not, by itself, change that classification.

Article 3(57) defines MOTO as a payment transaction for which the payer communicates the order —or, in the terminology of the Regulation, “places” it— through modalities other than electronic platforms or devices, such as paper-based, mail or telephone orders, irrespective of whether execution takes place electronically.

Article 85(7) further provides that MOTO transactions are not subject to SCA, provided that the payer’s payment service provider carries out security requirements and checks allowing a form of authentication of the transaction.

The legal classification axis is therefore not authenticated versus unauthenticated. It is whether the customer communicates the payment instruction —that is, places the payment order— through an electronic or non-electronic modality.

The consequence is clear:

A telephone payment does not automatically cease to be MOTO because issuer authentication, EMV 3-D Secure or equivalent controls have been added.

This does not remove the value of ATO. It defines its proper role: ATO can identify an authentication outcome within MOTO without being presented as an automatic legal reclassification.

MOTO describes how the payment instruction is communicated; ATO would describe the security outcome

MOTO and ATO answer different questions:

  • MOTO: How did the payer communicate the instruction to make the payment?
  • ATO: Which authentication, credential-protection, transaction-correlation and evidence controls were applied to the telephone payment?

The same transaction could therefore be legally MOTO and also satisfy a technical ATO profile.

Pay by Call proposes using ATO for a telephone payment in which:

  1. The customer intentionally initiates or confirms the payment during a voice interaction.
  2. Sensitive payment data is captured in a controlled PCI DSS environment without unnecessary exposure to the human agent, AI agent or recording.
  3. The issuer or payer’s payment service provider retains control over risk assessment and authentication.
  4. The authentication result can be correlated with the relevant merchant, amount and transaction.
  5. Authentication and authorisation generate auditable evidence, without being confused with an absolute guarantee against fraud or chargebacks.
  6. The outcome returns to the voice workflow so service can continue without the merchant creating a separate web checkout.

These are proposed criteria. Operational recognition will depend on issuers, acquirers, PSPs, card schemes and the standards applicable to the implementation.

Traditional MOTO, pay-by-link and proposed ATO

CapabilityTraditional MOTOPay-by-link during a callProposed ATO profile
Initial communication of the payment instructionMail or telephoneIntent arises in the call; checkout is completed on web or appTelephone; legal classification depends on the actual flow
Merchant payment channelMOTOSeparate e-commerce checkoutContinuous merchant voice workflow
Switch to web checkoutNoYesNo
Issuer authenticationNot inherent to the categoryNormally available in the e-commerce checkoutRequired by the proposed profile
EMV 3DSNot inherent to MOTOApplied to the e-commerce transactionOrchestrated and correlated with the voice journey
Data protectionDepends on implementationProvided by the payment pageProtected capture within a PCI DSS architecture
Correlated evidenceLimited or implementation-specificAssociated with the web checkoutRequired across voice, authentication and authorisation
Current statusEstablished legal and scheme categoryEstablished e-commerce methodTechnical designation proposed by Pay by Call

This comparison does not imply that every MOTO payment is insecure or that pay-by-link lacks value. Each can be appropriate. The objective is to make visible a security difference that the generic MOTO label does not itself reveal.

Why pay-by-link is not the same as an authenticated telephone payment

Sending a payment link during a call moves the customer to an e-commerce checkout where SCA and EMV 3DS may be applied. It can be secure, but it changes the journey:

  1. The customer receives an SMS, email or message.
  2. The customer opens a browser or app.
  3. A checkout separate from the merchant’s telephone flow is completed.
  4. The customer returns to the conversation if further assistance is needed.

This transition can create friction: late or unopened messages, distrust of links, accessibility difficulties, loss of context and abandonment.

ATO proposes a different technical model: the conversation remains the merchant’s primary context, while authentication stays under issuer control and the result returns to the same operational workflow. If the issuer requires a challenge in its banking app, biometrics, a code or another method, the customer can complete that challenge without the merchant constructing a separate web checkout.

The role of EMV 3-D Secure

EMVCo describes EMV 3-D Secure as a technology that enables merchants and issuers to exchange data so the issuer can authenticate the consumer and reduce card-not-present fraud.

EMV 3DS has been developed primarily for browser- and app-based e-commerce. The underlying need —giving the issuer relevant information and control over authentication— also exists in voice commerce.

The technical question is not how to reproduce a web page during a call. It is how to:

  • identify an authenticated telephone journey;
  • correlate the voice session with authentication and authorisation;
  • preserve the integrity of the merchant and amount;
  • maintain issuer control;
  • and produce interoperable evidence for ecosystem participants.

These questions are addressed in Pay by Call’s “Proposal for extending EMV® 3-D Secure to Telephone-Initiated Commerce (ATO)”, submitted to EMVCo.

EMVCo has confirmed that it is reviewing the proposal. That review is not an approval, endorsement, certification or specification change.

The revised EBA initiative

Pay by Call has also submitted a position paper to the European Banking Authority. In light of the agreed PSR text, the accurate request is not for the EBA to declare that an authenticated transaction ceases to be MOTO. The EBA cannot use technical standards to contradict the definition in the future Regulation.

The contribution can instead focus, within the EBA’s mandate, on more precise questions:

  • how the security requirements and checks applicable to authenticated MOTO should be understood and supervised;
  • what evidence can distinguish, for risk and supervisory purposes, a MOTO transaction supported by issuer authentication from one relying mainly on static credentials;
  • whether fraud and dispute data should distinguish authenticated and unauthenticated outcomes within MOTO;
  • where the boundary lies between electronic and non-electronic communication of the payment instruction in IVR, automation and AI-agent journeys;
  • how accessibility can be preserved through authentication alternatives that do not depend exclusively on a smartphone;
  • and whether, after sufficient evidence is collected, the EBA should advise the Commission on a future evolution of the legislative taxonomy.

Article 89 of the agreed PSR text mandates EBA RTS on authentication, communication and transaction monitoring. This provides space to examine security and risk in voice journeys, but it does not permit the EBA to redefine MOTO contrary to Article 3(57) or remove the rule in Article 85(7).

PBC 3DS: a technical implementation for authentication in the voice journey

Pay by Call has developed PBC 3DS, a patent-pending technology designed to orchestrate EMV 3DS authentication from a telephone journey and correlate the result with the payment without using pay-by-link as the merchant checkout.

PBC 3DS acts as a technical layer between the telephone-service environment and the payments ecosystem. It does not replace the bank, issuer, acquirer, PSP, ACS or contact-centre platform.

It is designed to support:

  • human agents;
  • IVR systems;
  • AI voice agents;
  • different PSPs and acquirers;
  • and PCI DSS architectures that isolate sensitive payment data.

PBC 3DS provides evidence of technical feasibility, but does not by itself determine legal classification, SCA compliance, scheme acceptance, liability shift or the outcome of a chargeback. Those effects depend on the specific flow, issuer, PSP, scheme and applicable rules.

ATO and Secure Agentic Voice Commerce

The distinction between conversation, authentication and execution becomes even more important with conversational AI agents.

An agent may understand a request, calculate an amount, modify a reservation or recommend a product. None of that proves that the speaker is the legitimate cardholder or is authorised to use the card.

A secure journey must be able to demonstrate:

  • who authorised the transaction;
  • which merchant, amount and purpose were accepted;
  • which authentication method remained under issuer control;
  • that sensitive data remained outside the agent’s reach;
  • and that all stages can be correlated and audited.

IVR and AI-agent flows may also raise new questions about who communicates the payment instruction and whether, in PSR terminology, the payment order is “placed” electronically. Those cases must be assessed against the actual design of the flow. It would be inaccurate to assume that every voice interaction is MOTO or that every automated interaction necessarily falls outside it.

ATO provides useful technical language for Secure Agentic Voice Commerce, while the regulatory classification remains dependent on the facts and applicable law.

Potential value across the ecosystem

ParticipantPotential value
ConsumersGreater protection, continuity and accessibility
Merchants and contact centresLess data exposure and stronger authentication evidence
PSPs and acquirersMore precise information for risk, acceptance and reporting
IssuersAdditional context and continued control of authentication
Card schemesA basis for interoperable indicators, rules and testing
BPOs and CCaaS providersAuthenticated payments with human, IVR or AI agents without exposing raw credentials
RegulatorsSeparate visibility of security outcomes within the telephone channel

An ATO profile would not automatically eliminate fraud, disputes or chargebacks. It would enable participants to measure and recognise controls that are not inherent in the MOTO category.

What Pay by Call proposes —and what it does not

Pay by Call proposes:

  • ATO as a technical and operational profile for telephone payments with verifiable authentication.
  • Distinguishing authenticated and unauthenticated MOTO in data, risk analysis and reporting.
  • Exploring with EMVCo an interoperable application of EMV 3DS to the voice journey.
  • Contributing to EBA work on security, authentication, transaction monitoring, accessibility and fraud.
  • A provider-neutral architecture compatible with human agents, IVR and AI.

Pay by Call does not propose:

  • Claiming that ATO is already a legal category or official standard.
  • Claiming that authentication automatically turns MOTO into an electronic payment transaction.
  • Attributing to the EBA power to amend the co-legislators’ definition through RTS.
  • Presenting EMVCo’s review as approval or endorsement.
  • Turning PBC 3DS or a patent into a mandatory specification.
  • Automatically promising SCA treatment, liability shift or elimination of chargebacks in every implementation.

From a channel label to a trust architecture

MOTO will continue to describe many payment instructions communicated by mail or telephone. ATO can complement that classification by describing something different and measurable: the authentication outcome and security controls applied within the voice journey.

Pay by Call’s engagements with EMVCo and the EBA should therefore proceed along two complementary tracks:

  • Technical: how to orchestrate interoperable authentication in the telephone journey and make the result visible.
  • Regulatory and supervisory: how to assess controls, fraud and evidence without artificially changing the legal criterion concerning how the payment instruction is communicated.

The goal is not to change a label through a technology claim. It is to build a trust architecture that allows issuers, acquirers, PSPs, merchants and regulators to distinguish an authenticated telephone payment from one that is not authenticated.

MOTO describes how the payer communicates the instruction to make the payment. ATO can describe how the telephone payment is protected and authenticated.

Official sources and further reading

ATO is a technical designation proposed by Pay by Call. It is not currently a legal classification, an EMVCo standard or an official card-scheme category. PBC 3DS is patent pending. Regulatory, scheme and liability outcomes depend on the specific flow and applicable rules.