Compliance
- The rules you have to follow. Break them and you get fined, terminated, or both
- At SMB scale it's three things: PCI, consumer protection law around refunds and subscriptions, and your card network's rules
- Start with Compliance Basics for SMBs for the short version, then come back for the detail
Nobody reads compliance pages for fun. You're here because a processor asked you for something, or you're about to build something and you don't want to build it twice.
Pick Your Mode
Start with Compliance Basics for SMBs - the 3-thing checklist that covers what actually matters at your size.
- Check your chargeback ratio. If it's above 0.65%, act now. Visa's own first line is 0.5% non-compliant, and most processors act at around 0.9%.
- Got subscriptions? Check that cancelling takes fewer than 3 clicks, and that renewal emails go out 7+ days ahead.
- If you touch card numbers directly: confirm your SAQ is current and your PCI scan passed.
That's it. Deep compliance audits can wait until something flags.
Under $100K/month: Complete your PCI SAQ annually and keep your chargeback ratio under 0.65%. If you're on hosted checkout, that's 90% of your compliance burden covered.
$100K-$1M/month: If you bill recurring, subscription rules matter now. Review your cancellation flow and your renewal notices. Threshold monitoring turns into a weekly job.
Over $1M/month: Formal compliance review annually. Know your PCI level, your acquirer's expectations, and whether PSD2/SCA affects your EU sales.
Over $10M/month: Dedicated compliance function or outside counsel. Multiple network programs to track, potential for direct network relationships, and regulatory exposure across jurisdictions.
In order of how often I see it:
By Role (specific requirements for Merchants, Acquirers, and Issuers)
- Network thresholds - VAMP, ECM fines
- Subscription rules - FTC, state laws
- PSD2 & SCA - EU authentication requirements
- PCI DSS - Right SAQ annually
- Surcharging - Caps and state laws
- Merchant monitoring - Portfolio ratios
- High-risk registration - BRAM, VIRP
- MATCH/VMSS - Check and report
What Regulators Actually Look At (hard vs. soft requirements)
There's a difference between "technically required" and "what triggers enforcement."
Hard requirements (will get you fined/terminated):
- Missing chargeback thresholds for consecutive months
- PCI breach after not completing SAQ
- Reg E timing violations with documented customer complaints
- Subscription billing without proper disclosure (FTC is active here)
Soft requirements (matters in audits or after incidents):
- Perfect documentation of every decision
- Formal policies for every edge case
- Complete training records
Focus your limited time on the hard requirements. The soft stuff matters when you're big enough for formal audits.
Sales tax and VAT compliance is jurisdictional chaos. This site doesn't provide tax guidance.
What you need to know:
- Nexus matters. You owe tax where you've got a presence, physical or economic
- Economic thresholds. Plenty of states trigger nexus at $100K+ sales
- When to automate. Multi-state or international, look at Avalara, TaxJar, or processor-native tools like Stripe Tax
- Talk to your accountant. Before you decide anything on tax, get real advice
This is a payments site, not a tax site. It's here because checkout and invoicing touch tax whether you want them to or not.
Next Steps
- PCI-DSS - Start here if you touch cards
- Network Rules - Monitoring programs
- Subscription Rules - If recurring billing
- Dispute Monitoring - Know your numbers
- Reduce Chargebacks Fast - Emergency
- Chargeback Prevention - Long-term
See Also
- Chargeback Metrics - Tracking dispute rates
- Fraud Metrics - Measuring fraud performance
- Risk Scoring - Transaction scoring
- Processor Management - Acquirer relationships
- Subscriptions & Recurring - Recurring billing rules
- Holds and Reserves - Program consequences
- Zero Point Nine Panic - Emergency response
- Reduce Chargebacks Fast - Crisis playbook