Stored Card on File: Tips for Manufacturers and Distributors

Your customer places a $75,000 order today. Three months later, a different authorized buyer places a $120,000 order using the same card on file. The products, amounts, and people placing the orders are different. It’s not a subscription and it’s not recurring billing, but it’s still a stored card on file transaction. Compliance with card brand rules is different than PCI compliance, which is about accepting and processing a credit card transaction vs security.

That distinction matters. Visa and other card brands have detailed technical requirements for how stored credit cards are saved and used. When merchants don’t send the right transaction information, they risk higher interchange rates, non-compliance assessments, and non-customer initiated chargebacks.

It’s impossible for manufacturers and distributors to manage payment requirements internally. The best payment gateway, whether standalone solution or integrated with ERP or ecommerce, automates compliance. The inability of payment gateways to keep up with changing rules was exploited when merchants were mandated to accept EMV chip cards in October 2015. Virtually none were able to comply day one, some took years, and some went out of business. Merchants using our recommended solution went live the same day acquirers were ready to accept them. This historical perspective is important as the same issues are reoccurring today in the card not present world.

STORED CARD ON FILE: CUSTOMER VS MERCHANT INITIATED PAYMENT

In B2B sales an authorized buyer may log in to a portal, call a sales representative, or approve an invoice payment using the saved card.

Card brands distinguish between customer-initiated transactions and merchant-initiated transactions. A customer-initiated transaction occurs when the customer participates in the purchase. A merchant-initiated transaction is a later charge made without the customer present under a prior agreement. The acquirer needs to receive the correct data. In either case, the initial process for storing the card is critical to compliance for processing all future transactions.

Businesses cannot rely on people to tell the gateway how to code payments. The best B2B payment gateway solution applies the right process automatically based on many factors.

WHY YOUR PAYMENT GATEWAY MAY NO LONGER BE COMPLIANT

Stored-credential rules have changed over time, and card brands continually update their technical requirements. A payment gateway that successfully ran card payments years ago may not send the data now expected for stored-card transactions.

“It’s always worked” or “It’s a public company” is not a compliance test. An approval response only tells you that the transaction was approved at that moment. It does not confirm that the payment was submitted with all of the information required for the particular stored-card use case.

The most common issue is not that a manufacturer or distributor intentionally ignores the rules. It’s that its gateway, ERP connector, or custom integration was designed around an older process and does not automatically manage current requirements across all payment flows.

QUESTIONS TO ASK ABOUT ANY PAYMENT GATEWAY

  • Is the solution compliant with current rules for storing a card, Merchant initiated transactions and customer initiated transactions using a stored card on file?
  • Can it support cards stored on file compliance across order entry, ecommerce, invoice payment, and customer-service workflows?
  • Will compliance handling remain with the gateway if we update our ERP, replace a connector, or change other software?
  • Does the payment gateway system retain the customer stored card authorization records?
  • Can the customer manage their stored cards via a portal?
  • What is the payment gateway past history regarding compliance at the time of new rules going into effect? Merchants are unlikely to get direct answers on this; developer forums are a great place to learn more. For example, the authorize.net developers forum is very active with people asking …”when will it support…”

A SIGN OF NON-COMPLIANCE- $1 AUTHORIZATION

When a card is stored for future payments, the stored card framework requires a merchant send a zero dollar authorization. At that point the card is verified along with whatever the current rules are. Outdated payment gateways use a one dollar authorization, a sure sign either the gateway (or the developer) is not keeping up with continuously changing rules. Shopper alert- if you see a one dollar authorization pending on your credit card, we’d love your referral.

TIP: Is your payment gateway compliance with Zero Dollar Authorization? Search your merchant statements for “Zero Dollar Verification” Fees. Your merchant account portal may let you search for this also. Due to potential abbreviation, try “zero” if you get no results.

WHAT AN AUTOMATED B2B PAYMENT GATEWAY SOLUTION SHOULD DO

The ideal payment gateway makes it easy to store and use cards while managing the complexity in the background. It should tokenize the card, connect the payment to the appropriate order or invoice workflow, and automatically handle transaction classification and the related card-brand data.

That approach matters even more when payments touch multiple systems. ERP software, ecommerce tools, customer portals, and order-entry applications change. The payment gateway should remain the compliance layer—not leave the merchant dependent on every connector or custom software update to keep up with card-brand rules.

WORK WITH A B2B PAYMENT GATEWAY EXPERT

Stored cards on file reduces DSO. The goal is not to turn the credit department into payment-compliance specialists. The goal is to choose a solution that makes payments easy for the customer and automatically manages the technical requirements.

3D Merchant Services specializes in B2B payment gateway solutions for manufacturers, distributors, and dealers, including standalone and ERP-integrated payment technology. We help businesses implement solutions that automate payment processes and reduce the complexity of staying current with stored-card requirements.

For additional background:
https://3dmerchant.com/blog/merchant-processing-services/visa-stored-credential-mandate-overview
https://3dmerchant.com/blog/cenpos/what-is-mastercard-data-integrity-reporting

SOURCES

Visa Acceptance Solutions — Supporting Merchant-Initiated Transactions and Credential-on-File for Visa, Mastercard, and Discover
https://support.visaacceptance.com/knowledgebase/knowledgearticle/?code=000003041

Visa Developer — Getting Started with Card on File Data Inquiry
https://developer.visa.com/capabilities/card-on-file-data-inquiry/docs-getting-started

Bookmark our Card Brand Rules https://3dmerchant.com/blog/merchant-bulletins-downloads

Visa Core Rules and Visa Product and Service Rules, April 2026 edition
https://usa.visa.com/dam/VCOM/download/about-visa/visa-rules-public.pdf

Sign up for our monthly newsletter for news you can use.https://eepurl.com/dIwboT

Leave a Reply