Skip to main content

MOTO merchant accounts

Published - 17 June 2024
Revised - 04 August 2026

Please provide your full name
Please provide a valid email address
Please provide a valid contact number
Invalid Input

Libby James – Founder & Payments Expert
Written by Libby James

Libby James is the founder and Managing Director of Merchant Advice Service. Since 2016, she has worked directly with businesses and payment providers across merchant accounts, card processing, payment gateways and complex provider requirements.

Libby specialises in high-risk, declined and harder-to-place merchants, as well as businesses requiring specialist payment methods, integrations or international support. She writes and reviews Merchant Advice Service content, drawing on practical experience gained from real merchant enquiries and provider relationships.

MOTO Merchant Accounts: What Providers Assess Before Approving Telephone Payments

Three businesses may all take card payments over the telephone but present completely different payment risks.

BusinessMOTO activityWhat the provider is likely to assess
Accountancy firm Existing UK clients pay £300 to £1,000 invoices by phone Staff processes, card-data handling and dispute history
Kitchen installer Customers pay remote deposits and stages averaging £5,000 High transaction values, future delivery and project evidence
Travel company Most customers book by phone several months before departure International fraud, cancellations, chargebacks and unfulfilled bookings

All three businesses process mail-order or telephone-order payments, commonly referred to as MOTO.

However, a payment provider is not simply deciding whether to supply a virtual terminal.

It is deciding:

  • Whether the business genuinely needs MOTO processing
  • What proportion of turnover can be taken through that channel
  • Which products and services are approved
  • What average and maximum transactions are acceptable
  • Which customer and cardholder countries can be supported
  • Whether the fulfilment period creates additional exposure
  • What fraud controls the business uses
  • Whether settlement should be delayed
  • Whether a rolling reserve is required
  • Whether staff can process payments from home
  • Whether IVR or payment links should be used for some transactions

MOTO is therefore more than a screen for manually entering card details.

It is a payment channel that must be understood, approved and monitored as part of the merchant account.

The central question is:

What does a payment provider need to understand about the business before it will approve telephone or mail-order payments on suitable terms?

This guide explains what genuinely counts as MOTO, how providers assess the channel and how businesses can prepare a stronger application.

Written or reviewed by Libby James, founder of Merchant Advice Service and specialist in merchant payments and complex provider requirements.

Last reviewed: August 2026


Do you already take payments?
How do you take payments?


Please select a payment type
Please let us know how you take payments
Invalid Input
Invalid Input
Turnover(*)
Turnover




Please let us know your turnover
Invalid Input
Ever Had a Terminated or Declined Account?(*)
Ever Had a Terminated or Declined Account?
Please let us know if you've ever had a terminated or declined account
Please let us know who declined or terminated a previous account
Invalid Input
Please let us know where your company is based.
Please let us know the companies location
Please let us know about your goods or services
Please let us know your name
Please let us know your email address
Please let us know a contact number
Invalid Input

Find Your New Processor

Quick answer: What is a MOTO merchant account?

A MOTO merchant account allows an approved business to accept card payments initiated through:

  • Telephone orders
  • Mail-order instructions
  • Certain staff-assisted remote-payment journeys

MOTO stands for:

Mail Order / Telephone Order

The customer is not physically presenting the card to a card machine and is not normally entering the details through an ecommerce checkout.

Instead, the card information may be:

  • Given to an authorised employee over the telephone
  • Entered by the customer through a secure IVR telephone system
  • Supplied on an approved mail-order form
  • Processed through another provider-approved telephone-payment arrangement

MOTO payments are generally treated as card-not-present transactions. A card-security code may be requested for authorisation, but PCI DSS prohibits storing that code after authorisation, even in encrypted records or call recordings. 

The provider may approve MOTO subject to conditions covering:

  • Monthly volume
  • Transaction count
  • Maximum transaction
  • Customer countries
  • Products and services
  • Staff locations
  • Fraud controls
  • Settlement
  • Reserve
  • Refunds
  • PCI DSS compliance

Access to a virtual terminal does not automatically mean that every telephone payment, value or business activity has been approved.


What genuinely counts as a MOTO transaction?

A genuine telephone-order transaction normally begins when a customer contacts the business remotely and instructs it to take a card payment over the telephone.

A genuine mail-order transaction may begin when the customer sends payment instructions through an agreed paper-based process.

Examples could include:

  • A customer calling a solicitor to pay an invoice
  • A corporate buyer telephoning a wholesaler with an order
  • A traveller booking a trip through a call centre
  • A homeowner calling to pay an agreed project stage
  • A customer returning a completed mail-order form
  • A donor making a card payment through a telephone team

The transaction must be submitted through the payment channel approved and configured by the provider.

Card-scheme and gateway systems use indicators to distinguish MOTO from ecommerce, card-present and other transaction sources. Mastercard and Visa documentation both identify MOTO as a separate transaction source or indicator. 

The payment journey matters

MOTO is determined by how the customer initiated and completed the payment journey, not simply by the fact that an employee typed the card number.

A transaction does not automatically become MOTO because:

  • Staff entered the details manually
  • An ecommerce transaction failed
  • 3D Secure was unsuccessful
  • The physical card terminal would not read the card
  • The customer was standing in the showroom
  • The amount exceeded an online limit
  • Staff found the virtual terminal more convenient

The provider should configure and classify the transaction correctly.


What is not normally genuine MOTO?

Customer present in the business

A customer standing at the counter while an employee types the card information into a virtual terminal is not automatically making a telephone order.

A card-present terminal will normally be the more appropriate route where the customer and card are physically present.

Ecommerce payment moved to MOTO after authentication fails

A business should not automatically transfer an online customer into a manually keyed MOTO payment merely because:

  • 3D Secure failed
  • The issuer declined authentication
  • The normal checkout rejected the payment
  • Fraud controls were triggered

The correct response may be to:

  • Review the payment
  • Ask the customer to contact their issuer
  • Provide another properly authenticated route
  • Decline the transaction

MOTO should not be used as an authentication workaround.

Re-entering stored card details

Staff manually re-entering card information held from a previous transaction is not a substitute for:

  • Tokenisation
  • Stored-credential processing
  • Customer consent
  • Correct recurring-payment indicators

A previous MOTO payment does not automatically authorise future charges.

Keying a card after a terminal failure

Manually typing a card number after a chip, contactless or PIN problem does not necessarily transform the transaction into a genuine telephone order.

The business should follow the provider’s approved fallback procedures.


MOTO versus virtual terminal, IVR and payment links

These terms are related but do not mean the same thing.

Payment routeWho enters the card information?Main purpose
Virtual terminal Merchant employee Manually processing an approved remote payment
Secure IVR Customer using telephone keypad Allowing the customer to pay by phone without reading details aloud
Payment link Customer through a hosted online page Customer-led remote card payment
Ecommerce checkout Customer through a website or application Online purchase and authentication
Physical terminal Customer presents card or device Card-present transaction
MOTO merchant account Depends on approved solution The provider arrangement supporting telephone and mail-order processing

The MAS guide to virtual-terminal payments explains the operating, PCI DSS, call-recording and IVR considerations in greater detail.

This MOTO guide focuses on whether the provider will approve the overall payment channel and on what terms.


Find Your New Processor

Should this payment really be MOTO?

Customer situationPayment route to consider
Customer calls and cannot access an online link Virtual terminal or secure IVR
Customer can receive an email or text Payment link may be preferable
Customer is standing in the showroom Card-present terminal
Customer wants to pay monthly in future Approved tokenised recurring-payment setup
Customer enters details through a telephone keypad Secure IVR
Staff are keying details because 3D Secure failed Do not automatically classify it as MOTO
Corporate client calls to pay an invoice Approved MOTO, IVR or payment link
Customer sends a paper order form Approved mail-order process
Customer wants to pay a large project stage Appropriate route based on value, risk and customer access

MAS insight: Provider approval should follow the real customer journey

Do not build the customer journey around whichever tool happens to be available.

Describe:

  • How customers contact the business
  • Why they pay by telephone
  • What alternatives are offered
  • Who enters the card information
  • Where staff are located
  • How the transaction is recorded
  • When the product or service is delivered

This allows the provider to assess the genuine MOTO operation rather than an incomplete description such as:

We sometimes take cards by phone.


Is MOTO automatically high risk?

No.

MOTO is a card-not-present payment channel with particular fraud, dispute and data-handling considerations, but it is not one universal business-risk category.

The provider will assess MOTO alongside:

  • Business sector
  • Products and services
  • Transaction values
  • Customer countries
  • Cardholder countries
  • Fulfilment period
  • Refund and chargeback history
  • Financial strength
  • Trading history
  • Previous provider history
  • Security controls

An accountant collecting occasional invoice payments from established clients may present a different profile from:

  • A travel business taking advance international bookings
  • A high-value retailer dispatching goods to new customers
  • A business with significant chargebacks
  • A company receiving money months before delivery
  • A call centre processing most of its turnover through MOTO

A provider may approve the business but:

  • Limit the MOTO share
  • Restrict individual transactions
  • Exclude certain countries
  • Require stronger verification
  • Introduce delayed settlement
  • Apply a rolling reserve
  • Encourage IVR or payment links

MOTO should be assessed as part of the merchant’s complete processing profile.


The provider’s actual decision

The provider is not only answering:

Can this merchant have a virtual terminal?

It may be deciding all of the following.

Business approval

  • Is the sector supported?
  • Are the products and services permitted?
  • Is the business description accurate?
  • Is the customer contract suitable?
  • Does the business have the required licences?

Channel approval

  • Is MOTO genuinely required?
  • What percentage of turnover will use it?
  • Is mail order included?
  • Is telephone payment occasional or central?
  • Are IVR and payment links also required?

Transaction approval

  • What is the average transaction?
  • What is the maximum transaction?
  • Are high-value payments expected?
  • Will payments be divided into stages?
  • Are several cards used for one order?

Geographic approval

  • Where is the merchant established?
  • Where are customers based?
  • Where are cards issued?
  • Where are goods delivered?
  • Where are services performed?

Operational approval

  • Who processes the payments?
  • Where are staff located?
  • Are calls recorded?
  • Can employees hear or see card information?
  • Are individual user accounts used?
  • Can staff work from home?

Commercial and risk terms

  • Processing rates
  • Authorisation charges
  • Settlement timetable
  • Rolling reserve
  • Refund limits
  • Daily and monthly caps
  • Contract conditions

An account can therefore be approved with conditions rather than simply accepted or declined.


Find Your New Processor

Three MOTO businesses compared

1. Accountancy practice

Monthly card turnover: £40,000
MOTO share: 10%
Average telephone payment: £500
Maximum telephone payment: £2,000
Customers: Existing UK clients
Fulfilment: Work already completed or invoiced
Chargeback history: Low

The provider may focus on:

  • Why clients pay by telephone
  • Who handles card information
  • Whether a payment link is also offered
  • Call-recording arrangements
  • User access and PCI DSS

The central risk may be operational card-data handling rather than future delivery.

2. Kitchen installation business

Monthly card turnover: £250,000
MOTO share: 45%
Average telephone payment: £5,000
Maximum telephone payment: £20,000
Customers: UK homeowners
Fulfilment: Eight to sixteen weeks
Payment model: Deposits and project stages

The provider may focus on:

  • High transaction values
  • Deposit percentages
  • Stage-payment evidence
  • Project lead times
  • Total unfulfilled customer value
  • Refund and dispute history
  • Whether payment links could be used
  • Settlement and reserve

The MAS kitchen and bathroom payments guide explains this project-payment journey in more detail.

3. Travel business

Monthly card turnover: £750,000
MOTO share: 90%
Average booking: £1,200
Maximum booking: £15,000
Customers: UK and international
Fulfilment: One to nine months
Refund rate: Seasonal
Chargebacks: Higher during disruption

The provider may focus on:

  • Advance booking exposure
  • International cards
  • Cancellation terms
  • Supplier protection
  • Refund capacity
  • Chargebacks
  • Fraud monitoring
  • Financial strength
  • Reserve requirement

All three merchants use MOTO, but the provider is underwriting three very different commercial exposures.


Worked example: A MOTO exposure profile

Consider a business applying for telephone-payment processing with the following profile:

MeasureProfile
Total monthly card turnover £300,000
Monthly MOTO turnover £180,000
MOTO share 60%
MOTO transaction count 120
Average MOTO transaction £1,500
Maximum MOTO transaction £12,000
International-card share 25%
Average payment before delivery 60 days
Refund rate 4%
Chargeback rate 0.7%
Calls recorded Yes
Secure IVR available No
Payment links offered Sometimes

A provider may ask:

  • Why does 60% of turnover need to be taken by telephone?
  • Could more customers use a secure payment link?
  • What explains the £12,000 maximum transaction?
  • Which countries account for the international cards?
  • Are goods or services delivered before or after payment?
  • What is the current unfulfilled customer value?
  • Why is the refund rate 4%?
  • Which disputes make up the 0.7% chargeback rate?
  • Can employees hear complete card details?
  • Are call recordings paused, suppressed or redacted?
  • Are staff office-based or remote?
  • Is the £12,000 transaction within the provider’s proposed limit?
  • Would a reserve be needed to cover the 60-day exposure?

The stronger application does not wait for underwriting to uncover these questions.

It explains them in advance.


Find Your New Processor

What providers assess before approving MOTO

1. The business model

The provider needs to understand:

  • What the business sells
  • Who the customer is
  • Why customers pay remotely
  • How orders are formed
  • Who delivers the goods or services
  • How long fulfilment takes
  • What happens if the customer cancels
  • How complaints and refunds are managed

A weak application might say:

Consultancy services with telephone payments.

A stronger explanation might say:

The company provides UK corporate compliance consultancy. Existing contracted clients receive invoices after agreed project milestones. Approximately 15% of invoices are paid by company card over the telephone by authorised accounts-payable staff.

The second description allows the underwriter to understand the customer and transaction.


2. Why MOTO is required

Providers may ask why the customer cannot use:

  • Ecommerce checkout
  • Payment link
  • Pay by Bank
  • Physical terminal
  • Direct debit
  • Recurring tokenised payment

Legitimate reasons can include:

  • Telephone-led sales model
  • Customers requiring staff support
  • Accessibility requirements
  • Corporate invoice collection
  • Mail-order customer base
  • Customer cannot access a link
  • Complex order confirmed during a call
  • Existing call-centre operation

The answer should explain the customer journey rather than rely on:

It is easier for our staff.


3. MOTO as a percentage of total turnover

A business processing:

  • 5% by telephone
  • 50% by telephone
  • 100% by telephone

presents three different operating profiles.

The provider may set separate limits for:

  • Card present
  • Ecommerce
  • MOTO
  • Recurring payments

Calculate:

Monthly MOTO turnover ÷ total monthly card turnover × 100

Example

MOTO turnover: £75,000
Total card turnover: £250,000

MOTO share: 30%

The merchant should declare the expected figure accurately.

A business approved for occasional telephone payments should not quietly move most of its processing to the virtual terminal.


4. Transaction count, average value and maximum value

Provide all three figures.

A monthly turnover of £100,000 could mean:

  • 10,000 payments averaging £10
  • 100 payments averaging £1,000
  • 10 payments averaging £10,000

The provider’s concerns will differ.

A significant gap between the average and maximum transaction should be explained.

For example:

Average transaction: £600
Maximum transaction: £15,000

The provider may ask:

  • What does the £15,000 payment relate to?
  • How often does it occur?
  • Is supervisor approval required?
  • Is there an invoice or contract?
  • Could the customer pay through a stronger authenticated route?
  • When will the service be delivered?

5. Customer, cardholder and delivery countries

The merchant should distinguish between:

  • Customer country
  • Card issuer country
  • Billing address
  • Delivery country
  • Service location
  • Merchant establishment

A UK customer can use a foreign-issued card.

A UK-issued card can be used to pay for delivery elsewhere.

The provider may consider:

  • Cross-border fraud
  • Sanctions
  • Restricted territories
  • Currency
  • Refund complexity
  • Delivery verification
  • Local licensing

Do not describe the business as:

UK only

if 30% of the cards or deliveries relate to other countries.


6. Fulfilment and future-delivery exposure

The provider may want to know how long the business holds customer money before completing the order.

Examples include:

  • Legal invoice already due: little future delivery
  • Furniture delivery in six weeks
  • Kitchen installation in twelve weeks
  • Travel booking nine months ahead
  • Event ticket for the following year
  • Subscription delivered over twelve months

The provider may assess not only monthly turnover but the total value of paid orders that remain unfulfilled.

Example

Customer money received: £500,000
Value already delivered: £300,000
Unfulfilled customer value: £200,000

The £200,000 may represent potential exposure if the business cannot complete or refund those orders.

Businesses with future-delivery obligations should be able to report:

  • Payment date
  • Order value
  • Delivery date
  • Amount fulfilled
  • Amount remaining
  • Refund status

7. Refund, fraud and chargeback history

The provider may request:

  • Number of refunds
  • Refund value
  • Refund percentage
  • Chargeback count
  • Chargeback value
  • Chargeback reasons
  • Fraud losses
  • Representment outcomes
  • Previous provider warnings

Explain material changes.

For example:

Refunds increased from 2% to 6% during one quarter because a supplier failure delayed 80 customer orders. All affected customers were contacted and the rate returned to normal the following quarter.

That is more useful than supplying a figure without context.

Do not omit previous problems because the application appears stronger without them.

The provider may discover them through:

  • Processing statements
  • Bank statements
  • Scheme records
  • Previous-provider information
  • Live monitoring

8. Telephone-payment security

The provider may ask:

  • Is a virtual terminal used?
  • Is secure IVR available?
  • Are calls recorded?
  • Are recordings paused or redacted?
  • Can employees hear card information?
  • Are card details written down?
  • Can customers email card information?
  • Are individual user accounts used?
  • Is multi-factor authentication enabled?
  • What PCI DSS validation applies?

PCI DSS applies to organisations that store, process or transmit payment-card data or can affect the security of that environment. Telephone systems using VoIP can fall within scope while card information travels through systems controlled by the merchant. 

PCI SSC also warns that outsourcing part of the telephone-payment operation does not remove the need to understand the merchant’s and service provider’s respective responsibilities. Different technologies may reduce exposure, but the effect depends on the complete implementation. 

The detailed security process belongs in the virtual-terminal and IVR assessment, but the MOTO application should explain the operating model clearly.


9. Office, call-centre and home-working arrangements

The provider may want to know:

  • Number of employees taking payments
  • Number of offices
  • Call-centre setup
  • Whether staff work remotely
  • Devices used
  • Network controls
  • Access restrictions
  • Refund permissions
  • Staff training
  • Leaver process

Remote telephone payments require more than giving employees a shared login.

PCI SSC advises that home workers accessing systems handling account data should use controls including multi-factor authentication and should prevent unauthorised people from accessing systems, recordings or paper records. 

A provider may:

  • Permit office use only
  • Allow approved home workers
  • Require an IVR system
  • Restrict transaction values remotely
  • Require additional PCI validation

10. Financial strength and refund capacity

Where customers pay substantially before delivery, the provider may examine:

  • Filed accounts
  • Management accounts
  • Bank statements
  • Cash position
  • Supplier obligations
  • Current liabilities
  • Refund capacity
  • Trading history
  • Growth rate

Rapid growth is not automatically negative.

However, turnover rising from £50,000 to £500,000 per month can increase the provider’s exposure much faster than the merchant’s capital and operating controls develop.

The business should explain:

  • Reason for growth
  • Staffing
  • Supplier capacity
  • Working capital
  • Customer delivery timetable
  • Refund planning

11. Current and previous provider history

Declare:

  • Current acquirer or processor
  • Length of relationship
  • Existing MOTO limits
  • Settlement
  • Reserve
  • Chargebacks
  • Restrictions
  • Reason for moving
  • Previous declines
  • Previous termination

A provider change may be straightforward where the merchant wants:

  • Better integration
  • Improved reporting
  • More suitable pricing
  • Higher approved limits

It becomes more complex where the previous account was:

  • Restricted
  • Suspended
  • Terminated
  • Subject to significant reserve
  • Experiencing fraud or chargebacks

An accurate explanation is more valuable than trying to hide the issue.


MOTO approval-readiness table

Provider questionWeak answerStronger evidence
Why is MOTO required? “Customers prefer it.” Customer journey and percentage of customers using telephone payments
Who processes payments? “The office.” Named staff roles, individual access and training controls
Are calls recorded? “Sometimes.” Recording policy, suppression process and provider details
What is the maximum payment? “It varies.” Historic maximum, expected maximum and supporting invoices
What proportion is MOTO? “Not much.” Monthly MOTO and total card turnover with calculated percentage
When is the service delivered? “After payment.” Average and maximum fulfilment periods
What is unfulfilled exposure? “We do not track it.” Current paid-but-undelivered project report
How is fraud managed? “Staff check the customer.” Defined checks, limits, escalation and review procedures
What happens after a decline? “We try again.” Retry policy and alternative secure-payment route
How are refunds handled? “Accounts deal with them.” Original-payment matching, permissions and approval limits
Why did the last provider close the account? “No reason.” Termination notice, explanation and corrective action
Can customers use another route? “No.” Payment-link, IVR, bank-payment and card-present options

Why MOTO applications are declined or restricted

The business model is not properly explained

The application only says:

We take telephone payments.

It does not explain:

  • What customers buy
  • Why they call
  • Who takes payment
  • Transaction values
  • Fulfilment
  • Customer countries

MOTO turnover is understated

The merchant applies for occasional MOTO but intends to process most sales through the virtual terminal.

Transaction values do not match the application

The merchant states a £1,000 maximum but soon begins taking £10,000 payments.

The provider does not support the sector

The provider may not accept:

  • Particular products
  • Future-delivery models
  • Certain travel activity
  • Regulated goods
  • Specific customer countries

Weak card-data controls

The business:

  • Writes card details down
  • Stores them in the CRM
  • Receives them by email
  • Records the security code
  • Uses shared credentials
  • Allows uncontrolled home processing

Future-delivery exposure is omitted

The merchant describes the transaction values but not that customers pay several months before delivery.

Fraud or chargeback history is not disclosed

The provider later discovers:

  • Fraud spikes
  • Chargeback warnings
  • Account restrictions
  • Previous termination

MOTO is being used for the wrong transactions

Staff use the virtual terminal:

  • For customers standing in the shop
  • When ecommerce authentication fails
  • To avoid transaction controls
  • To re-enter stored card details

Financial information does not support the exposure

The business may have substantial customer obligations but insufficient liquidity to manage disruption or refunds.


Find Your New Processor

MOTO limits and live monitoring

Approval is not the end of underwriting.

The provider may continue to monitor:

  • Monthly MOTO volume
  • Transaction count
  • Average transaction
  • Maximum transaction
  • Card countries
  • Refund rate
  • Chargebacks
  • Fraud
  • Authorisation attempts
  • Settlement pattern
  • Growth
  • Products and services

A material change should be discussed with the provider before processing begins.

Examples include:

  • MOTO rising from 10% to 70% of turnover
  • Maximum transaction increasing from £2,000 to £20,000
  • Launching into new countries
  • Adding a new product
  • Extending delivery from two weeks to six months
  • Moving payment staff to home working
  • Introducing recurring payments
  • Acquiring another business

A payment being technically authorised does not prove that it falls within the merchant’s approved profile.


Strong Customer Authentication and genuine MOTO

The FCA says Strong Customer Authentication applies where a payer initiates an electronic payment transaction, accesses a payment account online or carries out certain risky remote actions, unless an exemption applies. 

The FCA’s payment-fraud reporting guidance separately classifies mail orders and telephone orders as transactions initiated non-electronically

The practical position is:

A genuine mail or telephone order is generally outside the normal customer-authenticated ecommerce journey, but merely keying a card number does not establish that the transaction is genuine MOTO.

An EBA interpretation, although based on the EU framework rather than current UK supervision, reinforces the distinction between a genuine mail or telephone order and a transaction that is merely manually keyed. 

The merchant should not decide the classification alone.

The acquirer, gateway or payment provider should:

  • Approve the channel
  • Configure the transaction source
  • Explain authentication treatment
  • Confirm permitted use
  • Monitor the live activity

MAS insight: MOTO is a channel, not an SCA loophole

Do not change an ecommerce transaction into MOTO simply because authentication is inconvenient.

Where the customer can enter their own card information securely, the business should consider whether:

  • Payment link
  • Hosted checkout
  • Secure IVR
  • Physical terminal

creates a more suitable journey.


Find Your New Processor

Does MOTO use 3D Secure?

A conventional telephone or mail-order transaction normally does not follow the same 3D Secure journey as an ecommerce payment entered directly by the customer.

That can affect:

  • Authentication
  • Fraud decisioning
  • Dispute exposure
  • Provider controls

A payment link may allow the customer to enter their own details and complete authentication where required.

A secure IVR system may reduce employee exposure to card information but does not automatically provide the same authentication or liability treatment as ecommerce 3D Secure.

Ask the provider:

  • Does this transaction qualify as genuine MOTO?
  • How will it be submitted?
  • Is 3D Secure available?
  • Does another customer-led route offer stronger authentication?
  • What fraud evidence is available?
  • What liability remains with the merchant?

Do not assume that an approved authorisation prevents a later chargeback.


MOTO fraud controls

The appropriate checks depend on the business, customer and transaction.

Possible controls include:

  • Address verification
  • Card-security-code result
  • Existing-customer history
  • Contract or invoice
  • Billing and delivery comparison
  • Call-back process
  • Transaction limits
  • Country restrictions
  • Velocity controls
  • Supervisor approval
  • Delayed fulfilment of unusual orders
  • Payment-link alternative
  • Manual review

No single control proves that the cardholder authorised the transaction.

The process should be proportionate.

A £50 payment from an existing customer may not require the same review as a £15,000 telephone order from a new overseas customer requesting immediate delivery.


Warning signs during a MOTO transaction

Possible warning signs include:

  • Several cards attempted
  • Customer presses for immediate dispatch
  • Delivery address differs substantially from billing details
  • Customer cannot explain their connection to the cardholder
  • Transaction is much larger than the normal profile
  • Caller asks about provider limits
  • Customer asks staff to split the payment
  • Refund requested to another card or bank account
  • Unusually high resale-value goods
  • Customer refuses reasonable verification
  • New customer ordering from an unexpected country
  • Junior employee pressured to override controls

A warning sign does not automatically mean fraud.

It means the transaction may need additional review.


Repeated authorisation attempts

A declined transaction should not be submitted repeatedly without understanding the reason.

Repeated attempts can:

  • Increase authorisation charges
  • Trigger issuer controls
  • Obscure fraud patterns
  • Create duplicate payments
  • Affect provider monitoring

A retry policy might require staff to:

  1. Check that the amount and details were entered correctly.
  2. Confirm whether the customer has authorised another attempt.
  3. Avoid repeated use of several cards without review.
  4. Ask the customer to contact their issuer where appropriate.
  5. Offer another legitimate payment route.
  6. Escalate unusual patterns.

The merchant should not coach the customer to alter transaction information to obtain approval.


Find Your New Processor

Splitting MOTO transactions

There can be legitimate reasons to use:

  • More than one card
  • A deposit and later balance
  • Project stage payments
  • Separate invoices

However, the business should not divide one transaction to avoid:

  • Maximum transaction limits
  • Fraud controls
  • Supervisor approval
  • Provider monitoring
  • Authentication requirements

Where payments relate to one order, retain a record showing:

  • Complete contract value
  • Each payment
  • Card used
  • Payment stage
  • Remaining balance
  • Customer authorisation

High-value MOTO payments

High-value telephone payments may require additional provider approval.

The provider may examine:

  • Why the transaction is taken by phone
  • Average and maximum value
  • Customer relationship
  • Invoice or contract
  • Delivery
  • Refund exposure
  • Fraud controls
  • Staff authority

A business expecting to process occasional £25,000 payments should not apply with a maximum transaction of £2,000.

For more detail, see the MAS guide to high-value card payments.


Mail-order forms

Some businesses still accept card instructions through paper order forms.

The process may bring paper records within PCI DSS scope.

The business should control:

  • Receipt of the form
  • Access
  • Storage
  • Processing
  • Redaction
  • Retention
  • Secure destruction
  • Treatment of the card-security code

A card-security code must not remain on the form after authorisation. PCI DSS prohibits storing the code after authorisation regardless of the storage format. 

Do not leave completed order forms:

  • On desks
  • In open filing cabinets
  • In general post trays
  • Accessible to unauthorised staff

Ask the provider whether a customer-led payment link or secure telephone system could replace the paper process.


MOTO and recurring payments

A one-off MOTO transaction does not automatically authorise the business to charge the card again.

The merchant must distinguish between:

  • One-off MOTO payment
  • Customer-initiated transaction
  • Saved credential
  • Continuous payment authority
  • Subscription
  • Merchant-initiated transaction

A proper recurring setup may require:

  • Clear consent
  • Tokenisation
  • Correct initial transaction
  • Stored-credential indicators
  • Cancellation process
  • Advance notices
  • Correct classification of later payments

Do not store the card number or security code in staff notes for future re-entry.

See the MAS guide to recurring card payments.


Chargebacks and MOTO evidence

A customer may dispute a MOTO payment by claiming:

  • They did not authorise it.
  • The amount was incorrect.
  • Goods were not delivered.
  • Services were not provided.
  • The order was misrepresented.
  • A refund was promised.
  • The transaction was duplicated.
  • A later payment was not authorised.

Useful evidence can include:

  • Contract
  • Invoice
  • Order
  • Customer correspondence
  • Delivery confirmation
  • Service record
  • Customer account history
  • Payment reference
  • Call record without prohibited card data
  • Refund information
  • Staff notes
  • Evidence of previous legitimate transactions

The business should record the commercial agreement, not preserve unnecessary card information.

An approved authorisation means the issuer accepted the request at that time. It does not guarantee that the payment cannot later be disputed.


MOTO pricing

MOTO processing may be priced differently from:

  • Card-present transactions
  • Ecommerce
  • Payment links
  • Recurring payments

Possible charges include:

  • Percentage transaction fee
  • Fixed authorisation fee
  • Virtual-terminal fee
  • IVR fee
  • Gateway charge
  • User fee
  • Refund fee
  • Chargeback fee
  • International-card cost
  • Monthly minimum
  • Fraud tools

Ask whether charges apply to:

  • Successful transactions
  • Declined attempts
  • Refunds
  • Account verifications
  • Each user
  • Each telephone line

There is no single universal UK MOTO rate.

Pricing depends on the merchant’s complete profile.


Find Your New Processor

Settlement and reserves

A provider may apply:

  • Standard settlement
  • Delayed settlement
  • Rolling reserve
  • Fixed reserve
  • Transaction-level hold
  • Enhanced monitoring

Example

Monthly MOTO turnover: £200,000
Rolling reserve: 10%

New reserve retained: £20,000

A provider offering a lower transaction rate but retaining £20,000 may create a different working-capital outcome from one charging slightly more with no reserve.

Compare:

Total cost + usable cash + settlement timing

rather than one headline percentage.

For more information, see:


Preparing a MOTO application

Business information

Prepare:

  • Legal company
  • Trading name
  • Website
  • Owners and directors
  • Trading history
  • Products and services
  • Customer contract
  • Required licences
  • Financial accounts
  • Management information

Processing profile

Provide:

  • Total monthly card turnover
  • Monthly MOTO turnover
  • MOTO percentage
  • Transaction count
  • Average MOTO transaction
  • Maximum MOTO transaction
  • Card-present and ecommerce split
  • Customer countries
  • Card issuer countries
  • Currencies

Fulfilment

Explain:

  • When customers pay
  • When goods or services are delivered
  • Average fulfilment
  • Maximum fulfilment
  • Unfulfilled customer value
  • Cancellation process
  • Refund capacity

Risk history

Provide:

  • Refund count and value
  • Chargeback count and value
  • Fraud losses
  • Previous restrictions
  • Previous declines
  • Previous termination
  • Existing reserve

Operating controls

Explain:

  • Virtual terminal
  • IVR
  • Payment links
  • Call recording
  • Staff locations
  • Home working
  • Individual user access
  • Refund permissions
  • PCI DSS process
  • Fraud controls
  • Retry process

The MAS high-risk merchant-account application guide explains how to organise a more complex underwriting file.


Questions to ask a MOTO provider

Approval

  1. Is our complete business model supported?
  2. Is telephone processing approved?
  3. Is mail order approved?
  4. What MOTO share is acceptable?
  5. Are our products and customer countries approved?

Transactions

  1. What average transaction is recorded?
  2. What maximum transaction is approved?
  3. Is there a daily MOTO limit?
  4. Is there a monthly limit?
  5. Are high-value transactions reviewed separately?

Technology

  1. Is a virtual terminal included?
  2. Is secure IVR available?
  3. Are payment links included?
  4. Can the service integrate with our CRM?
  5. Can each payment carry an invoice reference?
  6. Is tokenisation available for legitimate recurring use?

Security

  1. How should calls be recorded?
  2. Can staff work from home?
  3. Are individual users supported?
  4. Is multi-factor authentication available?
  5. Can refund permissions be restricted?
  6. What PCI DSS validation may apply?

Fraud

  1. What address and security-code checks are available?
  2. Can transaction limits vary by user?
  3. Can international cards be restricted?
  4. What happens after repeated declines?
  5. Is manual review available?

Commercial terms

  1. What processing percentage applies?
  2. What fixed authorisation fee applies?
  3. Are declined attempts charged?
  4. Is there a monthly virtual-terminal fee?
  5. Does IVR have a separate charge?
  6. What are the refund and chargeback fees?

Settlement and reserve

  1. What is the settlement timetable?
  2. When will the first payout occur?
  3. Is a reserve required?
  4. What percentage or amount?
  5. How long will it be held?
  6. When can the terms be reviewed?

Contract

  1. What is the initial term?
  2. What notice is required?
  3. Can pricing or reserve terms change?
  4. What happens to refunds after closure?
  5. When is the final reserve released?

Find Your New Processor

Changing MOTO provider

When switching, do not close the existing facility before the replacement is:

  • Fully underwritten
  • Contracted
  • Configured
  • PCI-reviewed
  • Tested
  • Ready to settle
  • Ready to process refunds

Plan for:

  • Historic refunds
  • Chargebacks
  • Transaction reports
  • Existing reserves
  • Old user accounts
  • Staff training
  • Call-recording changes
  • CRM integration
  • Existing tokens
  • Recurring payments
  • First payout

A new provider will not automatically have access to transactions processed through the old facility.

Be particularly careful where the merchant has:

  • Customer deposits
  • Long fulfilment periods
  • Historic refund exposure
  • Active disputes
  • Stored payment credentials

MOTO merchant-account readiness checklist

Before applying, confirm:

  • Complete business model documented
  • Genuine reason for MOTO explained
  • MOTO turnover calculated
  • Average and maximum transaction confirmed
  • Customer and card countries identified
  • Fulfilment period measured
  • Unfulfilled customer value tracked
  • Refund and chargeback history prepared
  • Fraud controls documented
  • Call-recording process confirmed
  • PCI DSS route reviewed
  • Staff and home-working locations disclosed
  • Virtual terminal, IVR and payment-link needs compared
  • Previous provider history disclosed
  • Financial information prepared
  • Requested transaction limits commercially realistic
  • Settlement and reserve requirements understood

Looking for a MOTO merchant account?

Tell Merchant Advice Service:

  • What the business sells
  • Why customers pay by telephone or mail order
  • Total monthly card turnover
  • Monthly MOTO turnover
  • MOTO percentage
  • Transaction count
  • Average transaction
  • Maximum transaction
  • Customer and cardholder countries
  • Average fulfilment period
  • Unfulfilled customer value
  • Refund and chargeback history
  • Current provider
  • Settlement timetable
  • Existing reserve
  • Number and location of staff
  • Whether calls are recorded
  • Virtual-terminal requirements
  • IVR requirements
  • Payment-link requirements
  • Required integrations
  • Previous declines or termination
  • What you want to improve

MAS can help you:

  • Explain the MOTO business model more clearly
  • Identify information a provider may require
  • Consider potentially relevant provider routes
  • Compare channel approval, limits and functionality
  • Review settlement and reserve questions
  • Prepare a stronger application

Merchant Advice Service cannot guarantee:

  • Merchant-account approval
  • A particular transaction limit
  • A specific card rate
  • Reserve-free processing
  • Chargeback protection
  • A particular settlement timetable
  • That every provider will be compared

The relevant provider remains responsible for underwriting, transaction classification, pricing, fraud controls, settlement, reserves and final contract terms.

Find Your New Processor

Sources and regulatory references


About Merchant Advice Service

Merchant Advice Service provides free, independent guidance to businesses looking for help with card payments, payment gateways and more complex payment requirements.

Where appropriate, MAS may introduce a business to a relevant payment provider. We may receive a referral fee or commission if an introduction results in a completed account or service.

MAS does not necessarily compare every provider in the market, and all applications remain subject to the relevant provider’s own assessment, underwriting and approval.

This article provides general payments and security information. It does not constitute legal, regulatory, PCI DSS, data-protection, fraud-management or information-security advice. MOTO classification, SCA treatment, provider approval, transaction limits, settlement, reserves and security requirements vary according to the payment journey, business and provider.

FAQs

What does MOTO mean?
MOTO means Mail Order / Telephone Order. It describes card payments initiated through an approved mail or telephone-order process.
Is a MOTO merchant account the same as a virtual terminal?
No. The virtual terminal is the interface staff may use to enter payments. The MOTO merchant account is the provider arrangement approving that payment channel.
Is IVR classed as MOTO?
It can form part of an approved telephone-payment journey. The customer enters their card details through the telephone keypad rather than reading them to an employee. The provider should confirm how the transaction is submitted and classified.
Is a payment link MOTO?
A customer entering details through an online hosted page will normally follow an ecommerce-style journey rather than conventional MOTO.
Is every manually keyed payment MOTO?
No. Manual entry alone does not determine the transaction channel.
Is MOTO automatically high risk?
No. Providers assess MOTO alongside the sector, transaction values, fulfilment, countries, security and processing history.
Are MOTO payments card-not-present?
They are generally treated as card-not-present transactions because the card is not physically read by a card terminal.
Does MOTO require Strong Customer Authentication?
Genuine mail and telephone orders are generally treated as initiated non-electronically rather than following the standard ecommerce SCA journey. The payment must genuinely be MOTO and should be classified by the provider correctly.
Can MOTO be used when 3D Secure fails?
It should not automatically be used to bypass a failed authentication or ecommerce control.
Does MOTO use 3D Secure?
Conventional MOTO does not normally follow the same 3D Secure flow as customer-entered ecommerce. Ask the provider about alternative customer-authenticated routes.
Can a customer pay by phone while standing in the shop?
The physical card terminal will normally be the more appropriate route where the customer and card are present.
Can staff take MOTO payments from home?
Potentially, subject to provider approval, PCI DSS scope, device security, call controls and access restrictions.
Can staff share a virtual-terminal login?
Individual user accounts are preferable because they support accountability and transaction audit trails.
Can calls containing card details be recorded?
Sensitive authentication data such as the card-security code must not remain in a recording after authorisation. The process should suppress, pause or redact payment data where possible.
Can a customer email card details?
The customer should be directed to an approved secure route such as a payment link or authorised telephone-payment process.
Can staff write down card information?
Routine written collection should be avoided. Paper card information requires appropriate security, and the card-security code must not be retained after authorisation.
Can a MOTO account take international cards?
Potentially. The provider may apply country restrictions, fraud controls and different pricing.
Can I take large MOTO payments?
Potentially, within the approved maximum transaction and processing profile.
Can I split a large MOTO transaction?
Genuine deposits or contractual stages may be processed separately. Do not split a transaction to avoid limits or monitoring.
Why might a MOTO application be declined?
Reasons can include: Unsupported sector Weak business description High future-delivery exposure Fraud or chargebacks Poor card-data controls Insufficient financial strength Previous provider history Transaction values outside appetite
Why has my provider limited MOTO turnover?
The provider may want the live processing mix to remain within the profile it assessed during underwriting.
Can a provider introduce a rolling reserve?
Potentially. The decision may reflect transaction values, fulfilment, disputes, financial exposure and business history.
Are MOTO payments more expensive?
They may be priced differently from card-present and ecommerce transactions. Compare the complete cost and terms.
Can MOTO be used for recurring payments?
A one-off MOTO payment does not automatically authorise later charges. Use a proper tokenised recurring-payment arrangement with the required customer consent.
Can a customer charge back a MOTO payment?
Yes. Authorisation does not prevent a later dispute.
What evidence helps with a MOTO chargeback?
Useful evidence may include the contract, invoice, customer correspondence, delivery records, service records, payment reference and permitted call evidence.
Should I offer payment links as well?
Often, yes. A payment link may suit customers who can enter their own details and may reduce the amount of raw card information handled by staff.
Can MAS guarantee a MOTO account?
No. MAS can help identify potentially relevant providers and improve the application, but the provider makes the final decision.

Written or reviewed by Libby James, founder of Merchant Advice Service and specialist in merchant payments and complex provider requirements.

In this article
    Share this article with others:

    Related Articles