Compliance Basics for SMBs
- Do now: file your PCI SAQ every year. Keep the chargeback ratio under 0.65%. Use a billing descriptor people recognize.
- Do if you bill recurring: a clear cancel flow, renewal notices seven days out, an easy opt-out.
- Can wait: formal audits, AML/KYC programs, PSD2/SCA unless you sell into the EU.
- Most SMBs need three things: the PCI questionnaire, chargeback monitoring, a clear refund policy.
- 0.65% isn't the crisis point, it's the early warning. Processors flag you around 0.9%, and Mastercard ECM starts at 1.5%. Act at 0.65% and you never get there.
Compliance sounds enormous, but at SMB size it's three things and the rest can wait.
The 3-Thing Checklist
If you do nothing else, do these three things:
1. Complete Your PCI Questionnaire
The SAQ is an annual self-assessment questionnaire. It confirms you're handling card data safely.
What to do:
- Hosted checkout (Stripe Checkout, Square, Shopify Payments) puts you on SAQ A. That's the simplest one, 15-20 minutes.
- Embed a payment form on your own site and you're probably on SAQ A-EP. Still manageable.
- Touch card numbers directly and you're on SAQ D. Switch to hosted checkout instead.
Skip it: your processor bills a PCI non-compliance fee, $10-150 a month. You're also on your own if you get breached.
See PCI DSS for the full guide.
2. Monitor Your Chargeback Ratio
Your ratio is the share of transactions that turn into chargebacks. Processors start watching at 0.65%, and usually act around 0.9%.
What to do:
- Check your ratio monthly: total chargebacks / total transactions
- Set an internal alarm at 0.65%
- If you're above 0.65%, start reducing chargebacks immediately
0.65% is where your processor starts watching. It's your cue to act, not the point where fines begin. Enforcement sits higher up.
- Visa VAMP (live April 2025): merchant excessive is 1.5%, since 1 April 2026, with 1,500+ disputes. CEMEA keeps 2.2%. The ratio counts fraud reports (TC40) and chargebacks (TC15). That makes it harder to stay under than the old program. Your processor's own line is usually around 0.9%.
- Mastercard ECM: 100-299 chargebacks and a 1.50-2.99% ratio. Both, not either. Go past 299 and 3.00% together and it's HECM, where the fines double.
Don't wait for enforcement. Fixing this at 0.65% is cheap. Fighting your way out of a monitoring program at 1%+ isn't. See Dispute Monitoring Programs for the full breakdown.
Skip it: you land in a network monitoring program. VAMP per-dispute fees are reported at US$8 on CNP disputes, passed through by your acquirer. Visa doesn't publish that number itself. Mastercard ECM fines run from $1,000 to $100,000+ a month. Then comes MATCH, which sticks for five years.
See Chargeback Ratio Crisis for emergency response.
3. Post a Clear Refund Policy
The policy is a visible page telling customers how to get a refund, return something, or cancel.
What to do:
- Link your refund policy in your website footer, checkout page, and order confirmation emails
- Make cancellation possible in 3 clicks or fewer
- Include timeframes ("Refund within 30 days of purchase")
Skip it: customers who can't find your refund process call their bank. That's a chargeback.
See Refund Policy Design for templates.
What Matters at Your Size
| Your Monthly Volume | What to Focus On | What Can Wait |
|---|---|---|
| Under $10K | PCI SAQ, clear refund policy, recognizable billing descriptor | Everything else |
| $10K-$50K | Above + monthly chargeback monitoring, subscription compliance if applicable | Formal audits, international compliance |
| $50K-$100K | Above + chargeback alerts, dispute monitoring | AML/KYC, multi-network optimization |
| $100K-$500K | Above + quarterly compliance review, network threshold tracking | Direct network relationships |
| Over $500K | Formal compliance program, consider outside counsel | Nothing - everything matters now |
Common Mistakes
| Mistake | What Happens | Fix |
|---|---|---|
| Ignoring PCI SAQ | Non-compliance fee + breach liability | Complete SAQ A annually (15 min) |
| No billing descriptor | Customers don't recognize charges, file chargebacks | Set descriptor to your business name |
| Hard-to-cancel subscriptions | Chargebacks from frustrated customers | 3-click cancellation, pre-renewal emails |
| No chargeback monitoring | Breach threshold without warning | Monthly ratio check, alert at 0.65% |
| Ignoring processor emails | Escalation to monitoring program | Reply within 24 hours, always |
Subscription Businesses: Extra Requirements
Recurring billing adds obligations.
□ Disclose recurring terms before first charge (amount, frequency, duration)
□ Send renewal/billing reminders 7+ days before each charge
□ Make cancellation available online (no phone-only cancellation)
□ Cancellation flow completes in 3 clicks or fewer
□ Send confirmation when customer cancels
□ Stop charging within 3 business days of cancellation
Break these and the chargebacks pile up fast, and regulators notice too.
See Subscription Rules for the full requirements.
When to Get Professional Help
You need a compliance consultant or payment attorney when:
- Your chargeback ratio is above 0.9% and climbing
- You're entering a network monitoring program
- You process over $500K/month
- You're expanding internationally (PSD2/SCA requirements)
- You receive a processor termination notice
- You handle sensitive data beyond basic card processing
This site and your processor's support team cover the rest.
Next Steps
Just starting out?
- Complete your PCI SAQ (15-20 minutes)
- Check your billing descriptor
- Post a refund policy
Already processing?
- Calculate your chargeback ratio
- Review your subscription compliance if applicable
- Set up chargeback alerts
See Also
- PCI DSS - Cardholder data security requirements
- Network Rules - Visa and Mastercard mandates
- Dispute Monitoring - VAMP, ECM thresholds
- Chargeback Prevention - Stop disputes before they start
- Reduce Chargebacks Fast - Emergency playbook
- MATCH List - The merchant blacklist and how to avoid it