France is already taking action on unauthenticated MOTO payments. European businesses should pay attention.
A telephone payment can protect card data, be fully compliant with PCI DSS and still leave the merchant exposed to fraud and chargebacks.
This is one of the most common conceptual mistakes made by companies, contact centres and payment departments:
“Our telephone payment process is secure because it is PCI DSS compliant.”
That statement may be true, but it addresses only one part of the problem.
PCI DSS protects card data. It does not prove that the person making the payment is the legitimate cardholder.
That distinction fundamentally changes the risk assumed by the merchant.
Two different layers of security
Every telephone card payment should answer two separate questions.
1. Is the card data protected?
This is the role of PCI DSS.
Its purpose is to prevent the card number, expiry date and security code from being heard by an agent, captured in call recordings, stored unnecessarily or transmitted through unprotected systems.
The PCI Security Standards Council defines PCI DSS as a set of technical and operational requirements designed to protect payment account data.
In a contact centre, this protection can be achieved through:
- DTMF masking.
- Secure IVR.
- Automated card-data capture.
- Tokenisation.
- Network and system segmentation.
- Removal of sensitive data from call recordings.
- Outsourcing PCI responsibilities through PCIaaS.
All these measures are essential. However, none of them authenticates the cardholder.
2. Has the payer proved that they are the legitimate cardholder?
This is the role of authentication, Strong Customer Authentication —SCA— and EMV 3-D Secure.
SCA enables the card issuer to verify the identity of the payer. EMV 3DS is the protocol that connects the merchant, acquirer and issuer to perform this authentication in an e-commerce transaction.
EMVCo explains that EMV 3DS enables issuers to verify that the person making a purchase is the legitimate user of the card and helps prevent card-not-present fraud.
Therefore:
PCI DSS protects the card data.
EMV 3-D Secure authenticates the cardholder.
These are two complementary security layers. They are not interchangeable.
The problem with traditional MOTO payments
In a MOTO —Mail Order/Telephone Order— transaction, the customer provides their card details during a telephone call and the merchant submits the transaction as a telephone payment.
Even when the data is captured securely and in full compliance with PCI DSS, the transaction may still lack authentication by the card issuer.
The issuer may authorize the payment because the card is valid, has sufficient funds and has not been blocked. But:
Authorizing a card is not the same as authenticating its cardholder.
If the legitimate cardholder later claims not to recognize the transaction, the merchant may receive a chargeback.
PCI DSS compliance alone does not create a liability shift or transfer responsibility for the fraudulent transaction to the issuer.
EMV 3DS, by contrast, enables eligible authenticated transactions —or transactions where authentication has been attempted— to benefit from liability shift, subject to the applicable card-scheme and acquirer rules.
This does not eliminate every type of chargeback. Disputes concerning services not provided, duplicate transactions, cancellations or commercial disagreements may still occur.
What changes substantially is the merchant’s exposure to fraud-related and unrecognized-transaction chargebacks.
Pay-by-Link: secure, but at the cost of changing channels
The usual response to the authentication problem has been to send the customer a Pay-by-Link by SMS or email.
This can be a secure payment journey, but it requires the customer to:
- Interrupt the conversation.
- Find the SMS or email.
- Open the link.
- Access a web page.
- Enter their card details again.
- Complete authentication.
- Return to the call to confirm the result.
Imagine ordering a coffee and, when you ask to pay, being told:
“You cannot pay here. Please leave the café, find the parking meter outside, make the payment there and then come back to show us the receipt.”
The parking meter may be completely secure. The problem is that the customer has been sent outside the experience they were already using.
This change of channel can cause:
- Payment abandonment.
- Lower conversion rates.
- Longer handling times.
- Difficulties for less digitally confident customers.
- Problems finding or opening the link.
- Mistrust of links received by SMS.
- Loss of agent assistance.
- A fragmented customer experience.
Businesses should not have to choose between payment security and customer experience.
From MOTO to ATO: Authenticated Telephone Order
At Pay by Call, we have developed the concept of ATO —Authenticated Telephone Order— to bring both security layers into the same telephone interaction:
PBC PCIaaS + PBC 3DS = ATO
With ATO:
- The voice call remains the service and assistance channel.
- The customer enters their card details using DTMF masking or Secure IVR.
- The agent cannot hear, view or store the sensitive card information.
- Pay by Call protects the capture process through its PCIaaS infrastructure.
- The payment is submitted and authenticated as an e-commerce transaction.
- The issuer authenticates the cardholder through EMV 3-D Secure.
- If the issuer requires an SCA challenge, the customer completes it in real time.
- The payment result is returned to the call flow.
- The agent can continue assisting the customer until the process is complete.
The company therefore obtains, within a single customer journey:
- PCIaaS, protecting card data and dramatically reducing the contact centre’s PCI scope.
- PBC 3DS, authenticating the cardholder and reducing exposure to fraud and chargebacks.
- A continuous customer experience without sending the customer to a Pay-by-Link.
PBC 3DS is Pay by Call’s patent-pending technology for enabling native EMV 3-D Secure authentication in the voice channel.
Pay by Call does not replace the merchant’s bank, PSP, telephony, CCaaS or contact-centre platform. It operates as a transparent technology layer between the conversation and the existing payment ecosystem.
France: a warning for European businesses
The French case is particularly relevant because it demonstrates that the distinction between protecting card data and authenticating the payer is already producing operational and financial consequences.
The Observatory for the Security of Payment Means —OSMP—, chaired by the Banque de France, introduced a specific action plan to reduce fraud in remote card payments processed outside 3-D Secure.
The plan clearly separates two requirements.
Recommendation No. 4: protect payment data
Merchants accepting telephone payments should, wherever possible, allow customers to enter their card details through an automated system or directly through the telephone keypad instead of communicating them verbally to an agent.
This recommendation addresses PCI and card-data security.
Recommendation No. 5: authenticate the payer
Merchants, PSPs, card schemes and technology providers are encouraged to develop authentication solutions adapted to the telephone channel.
The OSMP called on the payments ecosystem to work towards the deployment of strong authentication for telephone payments.
This second recommendation addresses a different question: proving that the payer is the legitimate cardholder.
France is therefore officially recognizing a fundamental principle:
Capturing card data securely is not the same as authenticating the payment.
What is a velocity limit?
The French action plan introduced a velocity limit for certain MOTO payments and internet payments processed outside 3-D Secure.
Velocity is defined as:
The cumulative value of payments made with the same card, at the same merchant, within a rolling 24-hour period.
It is not a limit on the merchant’s total daily turnover, nor is it necessarily a limit on one individual transaction.
For example, if a card has already been used to make a €350 payment and, within the same rolling 24-hour period, the customer attempts another €200 payment at the same merchant, the cumulative value would be €550.
If the applicable velocity limit is €500, the second transaction may be declined.
The OSMP encouraged issuers to reject transactions that caused the cumulative value to exceed the applicable limit.
French implementation dates and financial thresholds
The French timetable is particularly significant:
- 10 June 2024: a general velocity limit of €500 came into effect for MOTO payments at merchants that did not belong to an exempt sector.
- A reduction to €250 on 9 September 2024 had initially been planned.
- A further reduction to €100 on 14 October 2024 had also been planned.
- These two subsequent reductions were suspended to give the market more time to deploy alternative journeys and authentication solutions.
- The €500 limit remained in place for non-exempt merchants while the market progressed towards a strong-authentication solution based on 3-D Secure.
According to data collected by the Banque de France, the implementation of the €500 threshold initially caused 0.45% of MOTO authorization requests to be declined.
The fraud rate among the Merchant Category Codes subject to the plan also fell from 0.357% in the second quarter of 2024 to 0.297% in the third quarter of 2024, although the OSMP advised caution when interpreting these early results.
On 10 October 2024, French payment-market participants conducted an experiment involving the strong authentication of MOTO payments using the 3-D Secure protocol.
The experiment confirmed the technical feasibility of authenticating telephone-initiated payments.
The verticals initially exempted
France initially recognized that some industries have a legitimate operational need to use MOTO payments. It therefore created a list of exempt sectors identified through their Merchant Category Codes —MCCs—.
These included:
Travel, transport and hospitality
- Airlines.
- Air transport.
- Travel agencies.
- Hotel chains.
- Hotels and motels.
- Other tourist accommodation.
- Holiday camps and similar activities.
- Rail transport.
- Passenger railways.
- Maritime transport.
- Car-rental companies.
- Vehicle rental and leasing.
Insurance, financial services and debt collection
- Insurance companies.
- Financial institutions.
- Credit distribution.
- Debt-collection companies.
Utilities and telecommunications
- Electricity providers.
- Gas providers.
- Water and sanitary services.
- Telecommunications services.
Housing and professional services
- Housing rental and social landlords.
- Legal services and law firms.
Retail and other activities
- Catalogue sales.
- Press and publishing.
- Certain concrete and construction-related activities.
The list included MCC 6300 for insurance, MCC 7322 for debt collection, MCC 4900 for electricity, gas and water, MCC 4722 for travel agencies and MCC 4814 for telecommunications, together with the corresponding MCCs for airlines, hotels, transport and car rental.
An exemption did not mean immunity
The Banque de France subsequently found that the initially exempt sectors represented:
- 59% of the total value processed as MOTO.
- 58% of the total value of MOTO fraud.
In other words, a significant proportion of MOTO fraud was occurring within the very verticals that had initially been excluded from the general €500 limit.
The 2025 roadmap therefore changed the approach.
The OSMP identified approximately ten priority merchants belonging to exempt sectors that had substantial MOTO activity and fraud exposure regularly above the market average.
These merchants were required to submit an action plan to the Banque de France by the end of February 2025, demonstrating their commitment to:
- Protecting card data.
- Reducing fraud.
- Using MOTO correctly.
- Implementing more secure alternative payment journeys.
- Progressing towards stronger authentication.
If a priority merchant failed to present an adequate action plan, the Steering Committee could progressively impose the following velocity limits:
- From 10 March 2025: €2,000.
- From 10 April 2025: €1,000.
- From 12 May 2025: €500.
These limits were again calculated as the cumulative amount per card, merchant and rolling 24-hour period.
The stated direction was to move away from general exemptions granted to an entire vertical and towards individual exemptions, reserved for merchants able to demonstrate that their fraud levels were controlled and that their telephone-payment journeys were being properly secured.
In other words:
Operating in a sector with a legitimate dependence on MOTO was no longer sufficient to guarantee an exemption.
Insurers, airlines, hotels, travel agencies, transport companies, utilities, financial institutions, debt-collection companies and telecommunications operators could be assessed individually according to their MOTO volumes, fraud exposure and remediation plans.
Authentication changes the scenario
There is a crucial detail in the French plan:
MOTO payments that had undergone strong authentication were excluded from the general velocity limit.
This demonstrates that the fundamental problem is not the telephone as a channel.
The problem is continuing to submit telephone payments without authenticating the cardholder.
The French roadmap proposed maintaining the velocity restriction until a commercially available strong-authentication solution based on 3-D Secure could be recognized throughout the payment chain.
It also set the objective of supporting the deployment of strong authentication for telephone-initiated payments.
The OSMP’s 2025 annual report, published by the Banque de France in September 2026, confirms that the action plan covering remote card payments that do not use 3-D Secure is continuing throughout 2026.
The warning for the rest of Europe
The French measures do not automatically apply across the entire European Union.
However, they clearly illustrate the direction in which payment supervision may evolve:
- MOTO is identified as a channel with significant fraud exposure.
- Merchants are first required to protect card data.
- Supervisors then recognize that card-data protection alone is insufficient.
- Strong authentication solutions are encouraged.
- Restrictions are applied to unauthenticated transactions.
- Sector-wide exemptions gradually give way to individual assessments.
- Merchants that fail to adapt may experience more declines and reduced payment acceptance.
European businesses operating in insurance, travel, hospitality, transport, utilities, telecommunications, financial services, debt collection, healthcare and public services should not wait for their national authorities to introduce similar measures.
Nor should their strategy be limited to “being PCI compliant” or systematically moving every caller to a Pay-by-Link journey.
The strategic question is:
Can we protect the card data, authenticate the cardholder and preserve the entire experience within the same conversation?
With ATO, the answer is yes.
Do not wait for velocity restrictions to arrive
Any company currently accepting telephone payments should begin reviewing:
- What percentage of its payments is still submitted as MOTO.
- Its current fraud and chargeback levels.
- Whether agents can hear or view card details.
- Whether sensitive data appears in call recordings.
- Whether the issuer authenticates the cardholder.
- Whether eligible transactions can benefit from liability shift.
- How many customers abandon the payment after receiving a Pay-by-Link.
- What impact a velocity limit would have on its ability to collect payments.
- How long it would take to transform its current payment journeys.
Acting now allows the company to move from:
MOTO secured from a PCI perspective
to:
ATO protected through PCIaaS and authenticated through EMV 3-D Secure.
Without waiting for supervisory restrictions to force an urgent migration.
Without changing bank, PSP, telephony or CCaaS provider.
Without sending the customer outside the conversation.
Without turning payment into a journey from the café to the parking meter.
The final question
If your company accepts telephone payments, do not ask only:
“Are we protecting the card data correctly?”
Also ask:
“Are we authenticating the cardholder?”
“Are we still submitting the transaction as MOTO?”
“Are we exposed to unrecognized-transaction chargebacks?”
“What would happen if a velocity limit were applied to our industry tomorrow?”
“Can we evolve to ATO without disrupting the customer experience?”
The future of telephone payments is not simply about protecting card data more effectively.
It is about protecting the data and authenticating the payment within the same call.
That is ATO.
Learn more about ATO and Pay by Call’s patent-pending PBC 3DS technology: