Pay by Call is engaging with EMVCo and the EBA to help the payments industry distinguish traditional MOTO from telephone-initiated transactions that use issuer-controlled authentication.
By José Chillerón, Chief Strategy Officer and Co-Founder, Pay by Call
For decades, the payments industry has placed almost every card transaction initiated by telephone under the same label: MOTO — Mail Order or Telephone Order.
That classification made sense when a telephone order was fundamentally analogue. A customer called a merchant, communicated payment details and relied on the merchant and its acquirer to manage the resulting risk. The channel described the transaction, and the category reflected the limited authentication capabilities available at the time.
But the channel has changed.
Today, telephone payments can be handled by human agents, interactive voice response systems and AI voice agents. Card data can be isolated from the agent. Authentication can be controlled by the issuer. EMV® 3-D Secure messages can be incorporated into the payment journey. The customer can remain inside the voice interaction instead of being redirected to a web checkout.
When those controls are present, is it still accurate to classify the transaction in exactly the same way as an unauthenticated telephone order?
Pay by Call believes the answer is no. We propose a distinct category: ATO — Authenticated Telephone Order.
ATO is not a marketing label for a safer version of MOTO. It is a proposal for a technically meaningful, auditable and interoperable category that would allow the industry to distinguish between telephone orders that do not use issuer-controlled authentication and telephone-initiated transactions that do.
The regulatory moment: Article 85 and the definition of MOTO
The timing matters because the European payments framework is being rewritten.
As of August 2026, the European Parliament describes the proposed EU Payment Services Regulation as close to adoption following a provisional interinstitutional agreement. The Council’s final compromise text of 17 April 2026 introduces a formal definition of a MOTO transaction and addresses its treatment under Article 85 on Strong Customer Authentication.
The compromise text defines MOTO by the way the payer places the payment order: through modalities other than electronic platforms or devices, such as paper-based, mail or telephone orders. It also states in Article 85(7) that MOTO transactions are not subject to SCA, provided that the payer’s payment service provider performs security requirements and checks that allow a form of transaction authentication.
This is an important improvement over an undefined category. It also exposes the next question.
The current wording distinguishes electronic from non-electronic placement of the payment order, but it does not create a separate category for a telephone-initiated journey in which the cardholder is subsequently authenticated by the issuer using an SCA-capable EMV 3DS process.
In other words, the framework recognises that a MOTO transaction may include some form of authentication, but the market still lacks a common classification for a telephone order that achieves a defined, issuer-controlled authentication outcome.
This is precisely the gap ATO is intended to address.
The distinction is not merely semantic. Classification affects transaction data, issuer decisioning, fraud analysis, scheme rules, merchant operations and the ability of regulators to compare security outcomes across channels.
MOTO describes an origin channel; ATO would describe a security outcome
Traditional MOTO is primarily a channel classification. It tells the ecosystem that the order originated by mail or telephone. It does not, by itself, provide evidence that the payer was strongly authenticated or that the authentication result was bound to the payment context.
ATO would add that missing information.
Under the framework proposed by Pay by Call, an ATO transaction would be a telephone-initiated card-not-present payment that meets defined conditions such as:
- The customer intentionally initiates or confirms the transaction in a voice interaction.
- Sensitive card data is captured in a controlled PCI DSS environment and is not exposed to the human or AI agent.
- The issuer participates in authenticating the cardholder through an EMV 3DS-compatible process capable of supporting SCA.
- The authentication is linked to the relevant merchant and transaction context.
- The authentication result and the payment execution can be correlated and audited.
- The customer can complete the journey without being forced to abandon the voice channel for a separate web checkout.
These principles are deliberately outcome-based. The objective is not to prescribe a single vendor architecture. It is to establish the minimum properties that justify distinguishing an authenticated telephone order from traditional MOTO.
MOTO, pay-by-link and ATO are not the same journey
Pay-by-link is often used when a merchant wants to introduce SCA into a telephone sale. The agent sends a URL by SMS or email, the customer opens a web page and completes an e-commerce payment.
This can be secure, but it is no longer a continuous telephone payment. It is a channel switch from voice to web.
That switch creates operational consequences: messages may arrive late, links may not be opened, customers may distrust unfamiliar URLs, accessibility may suffer and the agent may lose visibility of the customer’s progress. In AI-led conversations, the interruption is even more significant because the conversational agent cannot complete the transaction within the interaction it is managing.
ATO is intended to provide a different path: issuer-controlled authentication without converting the journey into a separate e-commerce checkout.
| Capability | Traditional MOTO | Pay-by-link | Proposed ATO |
|---|---|---|---|
| Customer remains in the voice journey | Yes | No | Yes |
| Issuer-controlled authentication | Not inherent to the category | Normally available in the web checkout | Required by the proposed category |
| EMV 3DS within the payment workflow | Not inherent | Applied to the linked e-commerce transaction | Native to the authenticated voice workflow |
| Channel switch | No | Yes | No |
| Protected card-data capture | Depends on implementation | Handled by the web payment page | Isolated within a controlled PCI environment |
| Authentication and transaction correlation | Limited or implementation-specific | Available in the e-commerce flow | Required and auditable |
| Current industry status | Established category | Established e-commerce method | Category proposed by Pay by Call |
The purpose of this comparison is not to argue that every MOTO transaction is insecure or that pay-by-link has no value. Both can be appropriate in specific circumstances. The point is that neither label accurately describes a telephone payment that remains in the voice channel while generating issuer-controlled authentication evidence.
Why EMV 3-D Secure is central to ATO
EMVCo describes EMV 3-D Secure as a technology that enables merchants and issuers to exchange transaction, payment-method and device data so the issuer can authenticate the consumer and reduce card-not-present fraud.
Historically, EMV 3DS has been associated with browser and app-based e-commerce. Yet the underlying need — giving the issuer relevant information and control over authentication — is not unique to a visual checkout.
EMVCo has already extended EMV 3DS towards a broader range of devices and technical environments. Version 2.3, for example, introduced greater flexibility for non-traditional e-commerce environments, including smart speakers and other IoT devices. That evolution demonstrates an important principle: authentication standards can adapt as commerce moves beyond the browser.
Voice commerce is the next logical environment to address.
Pay by Call’s patent-pending PBC 3DS architecture provides practical evidence that EMV 3DS authentication can be orchestrated in a telephone payment journey without requiring the customer to complete the purchase through a pay-by-link redirect. It is designed to work with human agents, IVR systems and AI voice agents while complementing the merchant’s existing contact-centre platform, acquirer and payment service provider.
Pay by Call is a technical orchestration layer, not a PSP. Our role is to connect the voice interaction, protected card-data capture, authentication and payment execution while leaving the movement of funds and the acquiring relationship with the merchant’s chosen payment providers.
Our engagement with EMVCo and the EBA
Pay by Call has opened two complementary industry conversations.
First, we submitted a technical proposal to EMVCo setting out why authenticated telephone commerce deserves explicit consideration within the evolution of EMV 3DS. In August 2026, the EMVCo 3DS team confirmed that it had started reviewing the proposal. That review is important, but it should be described accurately: it is a technical assessment, not an endorsement, approval or specification change.
Second, we submitted a regulatory position paper to the European Banking Authority proposing that ATO be considered separately from traditional MOTO in the interpretation and future technical development of Article 85. The proposal focuses on the policy outcome: transactions that generate issuer-controlled authentication evidence should be identifiable and assessable separately from transactions that do not.
This engagement builds on a concern already recognised by European authorities. In its 2022 response on the review of PSD2, the EBA recommended a clear definition of MOTO and clarification of its regulatory treatment. The latest compromise text makes substantial progress on that point. ATO would be the next step: recognising that the modern telephone channel can support a materially different authentication outcome.
Our standards and regulatory work is centred on the category, the eligibility criteria and the security outcome. It does not require the disclosure or standardisation of Pay by Call’s proprietary implementation. A neutral ATO framework should allow different compliant technical approaches, while PBC 3DS remains one patent-pending implementation capable of delivering that outcome.
What ATO could mean for the payments ecosystem
For issuers
ATO could provide clearer data and a stronger basis for risk-based decisioning. Instead of receiving a generic MOTO indicator, issuers could distinguish a telephone order supported by issuer-controlled authentication and transaction correlation. This could improve fraud monitoring and make authentication policy more consistent across channels.
ATO should not automatically be equated with a liability shift. Liability outcomes depend on applicable regulation, scheme rules and the specific authentication result. Any future framework must preserve that distinction.
For merchants and contact centres
Merchants could offer a secure telephone payment journey without exposing card data to agents and without forcing every customer into a web redirect. This is particularly relevant for airlines, travel, utilities, insurance, public services, hospitality, collections and other sectors where the call is part of the service and payment context.
For acquirers, PSPs and payment schemes
A defined ATO category could improve routing, reporting, rule application and interoperability. It could also reduce the ambiguity created when a transaction has the origin characteristics of MOTO but the authentication characteristics of modern e-commerce.
For BPOs, CCaaS providers and AI platforms
ATO could become a reusable secure-execution layer. Providers would not need to become payment institutions or expose their agents and AI systems to raw card data. They could connect the conversation to an authenticated payment capability that works with the merchant’s existing payment stack.
For regulators
ATO would make security outcomes more visible. Regulators could evaluate authenticated and unauthenticated telephone transactions separately instead of treating the entire channel as a single risk population. This would support technology neutrality: regulation would focus on what the transaction achieves, not simply on whether the customer started by speaking.
ATO is increasingly important for Agentic Voice Commerce
The rise of AI agents makes this distinction urgent.
An AI voice agent may identify a product, confirm availability, calculate a price and guide a customer through a purchase. But conversational intelligence is not payment authentication. The fact that an AI system has understood the customer does not prove that the payer is the legitimate cardholder or that the authenticated intent is bound to a specific amount and merchant.
Secure Agentic Voice Commerce therefore requires a boundary between conversation and payment execution.
The human or AI agent should be able to initiate the payment workflow, but it should not see or retain raw card data, authenticate the cardholder on behalf of the issuer or determine whether authentication can be bypassed. Those functions should remain within controlled payment and authentication infrastructure.
ATO provides the conceptual framework for that separation:
- the conversational system manages dialogue and service intent;
- the PCI-controlled layer protects payment credentials;
- the issuer controls cardholder authentication;
- the payment ecosystem executes and records the transaction;
- auditable correlation connects the stages without exposing sensitive data to the agent.
Without such a framework, the industry risks scaling intelligent voice experiences on top of a payment category designed for an analogue era.
What ATO is — and what it is not
ATO is not an attempt to rename every telephone payment.
It is not a mechanism for circumventing SCA.
It is not a claim that voice recognition alone authenticates a payment.
It is not a proprietary payment scheme or a replacement for issuers, acquirers, PSPs or EMVCo specifications.
ATO is a proposed classification for telephone-initiated transactions that meet defined authentication, data-protection, transaction-binding and auditability requirements.
That distinction matters because better classification creates better incentives. If authenticated telephone orders remain operationally indistinguishable from unauthenticated MOTO, merchants and technology providers receive limited recognition for investing in stronger controls, while issuers receive limited evidence with which to make better decisions.
A proposed industry work programme
Pay by Call believes the next phase should be collaborative. ATO should be evaluated by issuers, acquirers, schemes, PSPs, merchants, contact-centre providers, AI platforms, regulators and security bodies.
A practical work programme could address five questions:
- What minimum authentication and transaction-binding criteria should an ATO transaction meet?
- Which data elements are required to identify ATO consistently across the ecosystem?
- How should ATO interact with EMV 3DS, scheme indicators, authorisation and fraud reporting?
- What PCI, privacy and audit requirements should apply to human-, IVR- and AI-assisted voice journeys?
- How should regulation distinguish ATO from non-electronic MOTO without creating a proprietary or technology-specific rule?
Pay by Call is available to contribute to technical working groups, regulatory discussions, pilots, industry roundtables and sector conferences addressing these questions.
From a legacy exception to an authenticated payment channel
MOTO was created for a world in which the telephone channel had limited capacity to support modern authentication. That is no longer the only technical reality.
The industry now has an opportunity to recognise two different outcomes:
- a traditional telephone order that relies on MOTO controls; and
- an authenticated telephone order that brings issuer-controlled authentication into the voice journey.
Calling both transactions MOTO conceals a difference that matters to merchants, issuers, regulators and customers.
ATO makes that difference visible.
The objective is simple: preserve the accessibility and continuity of the telephone channel while bringing it closer to the authentication standards expected in modern digital commerce. If the industry can define that outcome clearly and implement it interoperably, voice can evolve from a legacy exception into a trusted payment channel for human and agentic commerce.
Official sources and further reading
- Council of the European Union — final PSR compromise text, 17 April 2026
- European Parliament Legislative Train — Payment Services Regulation
- European Banking Authority — response to the call for advice on the review of PSD2
- EBA Single Rulebook Q&A — Interactive Voice Response and MOTO
- EMVCo — EMV® 3-D Secure
- Pay by Call — From MOTO to ATO on LinkedIn
ATO is a category proposed by Pay by Call and is not currently an adopted EMVCo or regulatory classification. PBC 3DS is patent pending. Regulatory and scheme outcomes remain subject to the applicable final legislation, technical standards and card-scheme rules.