Card Payment Security: What Every UK SME Should Know
What a small business is actually responsible for when taking card payments, the daily routine that prevents most problems, and the phone call that catches people out.
Most guidance on payment security is written for people who run security teams. This is written for someone who runs a shop, a cafe or a van, and who has three minutes.
The good news is that a small business taking card payments through a terminal is not holding the dangerous data. Card numbers do not sit on your till, your laptop, or your phone. Your exposure is narrower than the subject's reputation suggests, and most of what you need to do is habit rather than technology.
This covers what you are actually responsible for, the routine that prevents most problems, what to do when a payment is disputed, and how to brief staff without frightening them.
What you are responsible for, and what you are not
| Concern | Whose problem |
|---|---|
| Encrypting card data in transit | Your terminal and your provider |
| Storing card numbers securely | Nobody's. You should never hold them |
| Keeping terminal software current | Yours, with your provider |
| Physical security of the device | Yours |
| Staff behaviour at the counter | Yours |
| Completing the annual self-assessment | Yours |
| Deciding whether to approve a payment | The customer's bank |
The three in bold are where small businesses actually come unstuck. None of them are technical.
PCI DSS, in plain terms
Taking card payments brings you inside the Payment Card Industry Data Security Standard. The current version is PCI DSS v4.0.1, and it has been mandatory since 1 April 2025.
For most small businesses this means one thing: an annual Self-Assessment Questionnaire, completed through your acquirer. Not an audit, not an inspection, not a consultant. Merchants processing fewer than 20,000 card-not-present transactions a year generally sit in the lowest tier of obligation.
The questionnaire you complete depends on how you take payments. A business using only a physical IP-connected terminal usually completes a shorter one than a business taking payments online.
The practical point: many providers charge a higher non-compliance fee when the questionnaire has not been completed. Businesses pay that for years without realising a form would stop it. If you have never completed one, ask your provider which questionnaire applies to you.
The routine that prevents most trouble
Five habits, none of them expensive.
- Never write a card number down. Not on a pad, not in a notebook, not in a message, not in your order system. If a customer offers to read out their long number, you almost certainly should not be taking it that way.
- Check your terminals daily. Look at them properly once a day. Does it look like your device? Are there scratches around the card slot, an extra layer over the keypad, or a cable that was not there yesterday?
- Keep the software current. Updates are usually pushed by the provider, but a device that has been switched off for a fortnight may need attention.
- Limit who can access what. The person who empties the till does not need access to your merchant reports.
- Complete the annual questionnaire. As above, it is the cheapest thing on this list.
The one that catches people out
Nobody legitimate will ever phone and ask you to move a terminal, enter a code, or process a refund on their instruction.
Not your bank, not your provider, not the card scheme, not the police. A caller who says they are from your payment provider and needs you to key in a sequence is not from your payment provider. Hang up, and ring the number on your statement rather than any number they give you.
That single rule prevents more loss than everything else on this page.
Chargebacks, and why records matter
A chargeback is a customer disputing a payment with their bank and the money being pulled back from you. It is not an accusation of dishonesty and it happens to every business eventually.
Common reasons:
- The customer does not recognise the entry on their statement
- Goods or services were not delivered as expected
- The card was genuinely used fraudulently
- A duplicate charge
The first of those is worth attention because it is the easiest to prevent. If your trading name and the name on the customer's statement are different, people will not recognise the charge. Ask your provider what descriptor appears, and if it is a company name nobody has heard of, change it.
What helps when a dispute arrives:
| Evidence | Why it matters |
|---|---|
| Transaction receipt or terminal record | Proves the payment was taken and how |
| Proof of delivery or of work completed | Answers the most common dispute |
| Correspondence with the customer | Shows what was agreed |
| A statement descriptor customers recognise | Prevents the dispute entirely |
Chip and PIN and mobile wallet payments carry stronger evidence of who authorised them than keyed-in payments do, which is one reason to avoid taking card numbers over the phone unless you genuinely have to.
Briefing your staff
Five things, and this is short enough to put on the wall.
- We never write down a card number, for any reason
- We never move money or key in codes because someone rang and asked us to
- If a terminal looks altered or swapped, stop using it and tell the manager
- A PIN request after several contactless taps is a normal security check, not a fault
- If a customer's card is declined, that is between them and their bank; we do not speculate about why
That last one is politeness rather than security, but a member of staff guessing out loud why a card was refused is a bad moment for everybody.
What we have deliberately not covered
This article does not explain how card fraud is carried out, how skimming devices are built, or what makes a particular transaction more likely to be approved. That information helps the wrong people far more than it helps you, and none of it changes what a shop should do on a Tuesday morning.
If you suspect a device has been tampered with, or that you have been targeted, contact your acquirer and report it to Action Fraud rather than investigating it yourself.
Key takeaways
- Your terminal does not give you usable card numbers, and you should never hold them
- PCI DSS v4.0.1 usually means one questionnaire a year, not an audit
- Non-compliance fees are commonly paid for years because nobody completed the form
- Check terminals daily; physical tampering is the realistic threat
- No legitimate caller will ever ask you to key in codes or move money
- A statement descriptor customers recognise prevents the most common chargeback
How Jos Finserv Can Help
Jos Finserv can help eligible UK businesses review how they take payments, including what their current agreement charges for PCI compliance and whether the questionnaire has ever been completed. That last question alone is worth asking, because the difference between the compliant and non-compliant rate is a recurring monthly cost.
We are a broker rather than a payment provider or a security assessor, and we cannot certify compliance on your behalf.
Want someone to look at what your current agreement charges?
Explore the options available through Jos Finserv, or read what your card statement actually charges you.
Important: This article is general information about payment security practice, not a compliance assessment or legal advice. Responsibility for meeting PCI DSS obligations rests with the merchant and should be confirmed with your acquirer. Payment solutions are subject to provider eligibility criteria and nothing here is a quote.
Want us to look at your own numbers?
Tell us how to reach you and we will come back with what is actually available for a business like yours. We are paid by the provider, not by you, so this costs you nothing either way.
- We read your current statement and explain it in plain terms
- No obligation, and no pressure to move if you are already well placed
- One conversation, not a sequence of calls
Prefer to work it out yourself first? Use the card fee calculator, or check whether finance is worth exploring.