Glossary
MOTO (Mail Order / Telephone Order)

MOTO (Mail Order / Telephone Order)

MOTO transactions are card-not-present payments where card details are given over the phone or via written order.

GLOSSARY
What is a
MOTO (Mail Order / Telephone Order)

MOTO stands for mail order and telephone order. It covers card payments taken without the card or the cardholder there. The details come by post, over the phone, or read out to an agent. PCI's own glossary keeps the entry to a single line, which shows how settled the term is. What matters more than the wording is what follows from it. MOTO is a card-not-present channel, and it is treated that way for risk, liability and compliance.

The channel is older than e-commerce and has not gone away with it. Call centres, phone bookings, plan renewals taken by phone and business-to-business ordering all still bring in MOTO volume. In some trades it is still large. What has changed is the compliance picture. PCI SSC guidance on protecting card data taken by phone has been through several drafts. Its central scoping point is one many firms find out late. Accepting spoken account data over the telephone puts staff, the kit they use and whatever it connects to into scope of PCI DSS.

Why MOTO Counts As Card-Not-Present

The defining feature is what is missing. There is no chip to check, no PIN entry, and no till reading the card. So the shop leans on details a caller reads out. PCI's guidance notes that for card-not-present fraud a criminal only needs the account number, the cardholder name, the expiry date and sometimes the verification code. That is exactly what a phone order hands over. Which is why the channel sits next to e-commerce rather than next to in-shop trade.

The Scope Consequence Firms Underestimate

The scoping line above is the one that catches people out. It is not only the payment application that falls in scope. The agent, the desktop environment, the phone system and whatever it wires into can all be pulled in. A firm that assumed only its gateway build mattered can find its whole call centre inside the assessed zone. That is a far larger and costlier job than it planned for.

Call Recording Creates A Storage Problem

Recording calls for quality or legal reasons is normal. The trouble is that a recording holding spoken card details is stored cardholder data. PCI's line on sensitive check data is firm. It should not be kept after approval even if encrypted. Where it has been captured, it must be made unreadable for good. PCI SSC has warned that pressure to record calls can lead to card data being kept when it need not be. That is a real tension, not a made-up one.

Pause And Resume, And Its Limits

Pausing a recording while card details are read out is the common fix. It does help with the storage problem. PCI is careful about what it achieves though. A well built pause-and-resume setup could cut how far PCI DSS reaches into the recording and storage systems. It does not cut how far the rules reach into the agent, the agent desktop, or other systems in the phone estate. The obvious failure mode is flagged too. The agent forgets to pause at the right moment.

DTMF Masking As Another Route

A different approach takes the agent out of the data path. With DTMF masking the buyer keys their card number into their own handset. The tones are swapped for a random or flat tone, so the agent neither hears nor sees the number. PCI's guidance notes that recordings holding only flat tones that cannot be turned back do not need to be made unreadable. That is why this route is seen as cutting scope further than pausing alone.

Fraud Exposure And Liability

Because nothing checks the caller, MOTO carries the fraud shape of a remote channel and usually the blame that goes with it. AVS checks and card codes give some signal. A criminal reading details off a stolen record often has both, though. Where 3D Secure is not on offer for a channel, the liability shift that a full check can bring is usually not on offer either. How that plays out varies by scheme and by region.

Practical Controls That Help

Beyond the tech, the controls that matter are dull. Limit which staff may take card details. Ban written notes and screen grabs. Do not store the card verification code. Train agents on what to do if a buyer reads out details unprompted. PCI's guidance cites rules on security policy, staff screening and third-party oversight next to the tech ones. That shows how much of the risk here is about process rather than design.

Shrinking The Channel Rather Than Only Securing It

For many firms the better move is to shrink the channel rather than harden it. Send a secure payment link mid-call, or move the buyer to a hosted page. The sale still lands, and the agent is out of the data path. finera.'s look at hosted payment fields and direct API integration covers the same trade-off online. The logic carries over. The less card data touches a firm's own systems, the smaller its compliance surface tends to be.

Table of contents

Frequently Asked Questions

Why is MOTO classed as card-not-present?

Because nothing authenticates the card or the cardholder at the point of sale: no chip, no PIN, no terminal reading the card. PCI's guidance notes that card-not-present fraud only requires the account number, name, expiry date and sometimes the verification code, which is precisely what a telephone order provides.

Does taking card details by phone bring a contact centre into PCI DSS scope?

PCI SSC's guidance is explicit that accepting spoken account data over the telephone puts personnel, the technology used and the connected infrastructure into scope. That commonly extends well beyond the payment application to the agent, the desktop and the telephony platform.

Can calls be recorded if customers read out card numbers?

Not without dealing with the storage problem. Sensitive authentication data shouldn't be retained after authorisation even if encrypted, and where captured it must be rendered unrecoverable. PCI SSC has specifically warned about regulatory pressure to record calls leading to unnecessary storage of card data.

Is pause and resume enough to solve the problem?

It helps with recordings but doesn't do as much as businesses often assume. PCI's guidance states it could reduce applicability to the call-recording and storage systems, while explicitly not reducing applicability to the agent, the agent desktop or other systems in the telephone environment.

What's the alternative to an agent hearing the card number?

DTMF masking, where the customer keys the number into their own handset and the tones are replaced with a random or flat tone. PCI notes that recordings containing only flat tones that can't be converted back don't need to be rendered unreadable. Sending a secure payment link mid-call achieves something similar.

Still Have Questions?

Let’s Find the Right Solution for You

Share this article
Glossary

Stay Connected with Us!

Follow us on social media to stay up to date with the latest news, updates, and exclusive insights!