I have posited several times that compliance with the PCI DSS, with all of its idiosyncrasies and expense, has driven innovation in the payments space to a degree never before seen.  I even wrote a blog on the subject; How PCI Has Driven Innovation in Payments

However, over recent months, I have had the honour of working with several organisations who are throwing their hats in the ring, and trying to come up with ways to increase both the effectiveness of non-cash payments, but also the security.  Admittedly, these are still piggy-backing off credit cards, but the technologies are precursors to the demise of the card number itself. Basically;

If you don’t need a card number at the beginning of a transaction, why have a card OR a number in the first place?

The entire point of credit cards is to enable you to access your funds (be they debit or credit) wherever, and whenever you like.  Those funds are not handled by the card schemes, they are handled by your bank.  They secure your debit funds from your pay checks, and they are the ones that provide you lines of credit when you need it.  The risk is all theirs …and yours of course.

All the card brands are doing is providing the infrastructure to access those funds in a trusted fashion, and have been doing essentially the same thing for over 60 years.  Not knocking it, it’s brilliant, they get a percentage of every transaction made over their networks and carry the smallest fraction of the risk.  We should all be that clever.

PCI was born to protect the card number (or Primary Account Number (PAN)), and everything else ever developed by the card brands was designed to retrofit security around it.  From EMV (Chip & PIN), to 3D-Secure, to Tokenisation, these technologies are there to reduce the inherent risk of using a card number and piece of plastic for non-cash payments.

But the challenge we now face is that the credit card is as much part of our culture as Coke, or McDonald’s.  And even those who should know better, still only see payments innovation in terms of credit cards. Therefore anything non-cash has the stigma of PCI attached to it by default.  Ask any new business who has a payment method outside of credit cards, and even the BANKS still ask about their ‘PCI certification’, regardless of its obvious irrelevance.  The card brands all but encourage this.

But it’s not just the new businesses that are stuck in this PCI rut, the card brands themselves are painted into the corner of their own success; how can they push existing credit card technologies in emerging markets (which they are) and at the same time innovate away from a dying concept?

They will push – and probably help pay for – chip and PIN REALLY hard in the US, because they know adoption will delay the loss of their cash cow for a few more years.  Hopefully the US is smarter than that, as the cost of implementing EMV is over $10 BILLION, and in my view, simply not necessary; Why the US Will Not Adopt EMV (Chip & PIN)

Also, no merchant is going to make the enormous investment of new payment terminals that are EMV enabled just to throw them away when credit cards aren’t the only form of non-cash payment.  So you can also bet the terminal manufacturers (Ingenico, Verifone, Micros for example) are also pushing their wares aggressively, and I would hope that they too see the end of their reign.

The payments industry needs to adopt that most ubiquitous of clichés; back to basics.  It really isn’t that difficult, and the simpler the better.  It will NEVER be perfect, the thieves will always find a way to exploit it, but as long as the losses are no greater than losing the cash in your pocket it’s time to get away from the card brand’s plastic.  Your phone will replace your credit cards, then your bank can cut out the middle man.

The power to force innovation is with the consumer, always has been.

[If you liked this article, please share! Want more like it, subscribe!]

2 thoughts on “How PCI Is Stifling Payments Innovation

Leave a Reply

Your email address will not be published. Required fields are marked *

You may use these HTML tags and attributes:

<a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <s> <strike> <strong>

This site uses Akismet to reduce spam. Learn how your comment data is processed.