Skip to main content

Compliance

TL;DR
  • The rules you have to follow. Break them and you get fined, terminated, or both
  • At SMB scale it's three things: PCI, consumer protection law around refunds and subscriptions, and your card network's rules
  • Start with Compliance Basics for SMBs for the short version, then come back for the detail
Compliance illustration 12 min read

Nobody reads compliance pages for fun. You're here because a processor asked you for something, or you're about to build something and you don't want to build it twice.


Pick Your Mode

New to Compliance?

Start with Compliance Basics for SMBs - the 3-thing checklist that covers what actually matters at your size.

Popular

If You Only Have 2 Hours This Week
  1. Check your chargeback ratio. If it's above 0.65%, act now. Visa's own first line is 0.5% non-compliant, and most processors act at around 0.9%.
  2. Got subscriptions? Check that cancelling takes fewer than 3 clicks, and that renewal emails go out 7+ days ahead.
  3. If you touch card numbers directly: confirm your SAQ is current and your PCI scan passed.

That's it. Deep compliance audits can wait until something flags.

Scale Matters

Under $100K/month: Complete your PCI SAQ annually and keep your chargeback ratio under 0.65%. If you're on hosted checkout, that's 90% of your compliance burden covered.

$100K-$1M/month: If you bill recurring, subscription rules matter now. Review your cancellation flow and your renewal notices. Threshold monitoring turns into a weekly job.

Over $1M/month: Formal compliance review annually. Know your PCI level, your acquirer's expectations, and whether PSD2/SCA affects your EU sales.

Over $10M/month: Dedicated compliance function or outside counsel. Multiple network programs to track, potential for direct network relationships, and regulatory exposure across jurisdictions.


What Gets People in Trouble

In order of how often I see it:

1️⃣
Chargeback Thresholds
Cross ~0.9% and your processor flags you; Visa VAMP triggers at 1.5% (2.2% in CEMEA), Mastercard ECM at 1.5%
2️⃣
Subscription Billing Violations
Unclear cancellation, wrong renewal notices, failure to disclose terms
3️⃣
PCI Scope Creep
Accidentally handling card data you didn't need to
4️⃣
Reg E Timing Violations
Missing the 10-day provisional credit deadline (issuers)

By Domain

By Role (specific requirements for Merchants, Acquirers, and Issuers)
🏪
Merchants
🏦
Acquirers
💳
Issuers

What Regulators Actually Look At (hard vs. soft requirements)

There's a difference between "technically required" and "what triggers enforcement."

Hard requirements (will get you fined/terminated):

  • Missing chargeback thresholds for consecutive months
  • PCI breach after not completing SAQ
  • Reg E timing violations with documented customer complaints
  • Subscription billing without proper disclosure (FTC is active here)

Soft requirements (matters in audits or after incidents):

  • Perfect documentation of every decision
  • Formal policies for every edge case
  • Complete training records

Focus your limited time on the hard requirements. The soft stuff matters when you're big enough for formal audits.


Tax Is Not Covered Here

Sales tax and VAT compliance is jurisdictional chaos. This site doesn't provide tax guidance.

What you need to know:

  • Nexus matters. You owe tax where you've got a presence, physical or economic
  • Economic thresholds. Plenty of states trigger nexus at $100K+ sales
  • When to automate. Multi-state or international, look at Avalara, TaxJar, or processor-native tools like Stripe Tax
  • Talk to your accountant. Before you decide anything on tax, get real advice

This is a payments site, not a tax site. It's here because checkout and invoicing touch tax whether you want them to or not.


Next Steps

New to compliance?
  1. PCI-DSS - Start here if you touch cards
  2. Network Rules - Monitoring programs
  3. Subscription Rules - If recurring billing
Approaching thresholds?
  1. Dispute Monitoring - Know your numbers
  2. Reduce Chargebacks Fast - Emergency
  3. Chargeback Prevention - Long-term

See Also