Our Privacy Notice has been updated!
We have updated our Privacy Notice to improve the readability and to account for recent developments in privacy laws.
By continuing to use the website, you acknowledge your receipt and acceptance of the updated Privacy Notice.

4 minute read

Back to the Basics of Payment Compliance

8/15/2023 7:00 PM

Payments compliance on campus is complex. With multiple payment locations, various payment methods across campus, and various payment channels, staying compliant with the rules and regulations becomes challenging. Moreover, these rules constantly evolve to keep pace with technological advancements and new security threats.

Similar to the situation outlined in our blog, Back to the Basics of Accepting Payments on Campus, and The Basics: Student Finance webinar, the continued expansion of your payment ecosystem on campus is necessary to meet today's expectations, but it can also increase the compliance scope for your institution.

Growing compliance scope

Think about the payment methods accepted on campus and the various channels through which they are received – whether it's via e-commerce, in-person, mail, or over the phone. It's crucial for your institution to prioritize the security of account holder data and ensure that transactions are safe, regardless of payment method or channel, across different departments, organizations, clubs, and vendors.

For each location taking payments, you have a separate:

  • Payment system or software to maintain and keep current
  • Payment processors with different business models and contracts
  • Accounting and reconciliation challenges due to data differences
  • Security and compliance standards to understand and maintain

Understanding the complexities of your payment ecosystem is key to efficiently managing the growing compliance scope.

Why compliance is important

Ensuring that you are following the regulatory rules and regulations surrounding your payment ecosystem, you avoid fines and penalties while protecting account holder data. Non-compliance could result in losing your ability to take certain types of payments, costly downtime, and damage to your institution's reputation. Compliance demonstrates your dedication to protecting your payors and defending against growing fraud attacks. And a commitment to compliance can support and complement information security procedures, privacy policies, and data collection and analysis.

Compliance governance

A strong compliance program requires knowledge and understanding of the different rules and regulations governing today’s payments ecosystem. To help, we’ve defined some of the key compliance governing bodies as they relate to campus payments:

  • US Department of Education: The agency of the federal government that establishes policy for, administers, and coordinates most federal assistance to education.


    • Cash Management: The rules and procedures that an institution must follow in requesting, maintaining, disbursing, and otherwise managing Title IV funds. 

    • Legal Compliance: Along with the Federal Trade Commission (FTC), enforces compliance with the Gramm-Leach-Bliley Act, or GLBA.

  • Your State’s Law


    • Uniform Commercial Code Article 4-404: Covers the liability of a bank for action or non-action with respect to an item (check) handled by it for purposes of presentment, payment, or collection.

  • Federal Reserve Board: Oversees the Federal Reserve Banks and helps implement the monetary policy of the United States.


    • Regulation E: Implements the Electronic Fund Transfer Act (EFTA), which establishes a basic framework of the rights, liabilities, and responsibilities of participants in the electronic fund and remittance transfer systems, including stored value or declining balance accounts. 

  • Payment Card Industry Security Standards Council (PCI SSC): Protects cardholder data and sensitive authentication data wherever it is processed, stored or transmitted, and is commonly referred to as the PCI Council. 


    • PCI Data Security Standards (PCI DSS): Policies and procedures intended to optimize the security of credit, debit and cash card transactions and protect cardholders against misuse of their personal information.

    • Software Security Framework (SSF): Security standards for developing and maintaining payment software so that it protects payment transactions and data, minimizes vulnerabilities, and defends against attacks. SSF now includes the PCI Secure Software Lifecycle (Secure SLC) Standard, which is the validation program for software vendors and their payment applications. SSF and SLC replaced the previous Payment Application Data Security Standard (PA-DSS) program in October 2022.

  • Nacha: Manages the development, administration, and governance of the ACH Network, the backbone for the electronic movement of money and related data in the United States.

  • Payments Canada, Rule H1: Outlines the procedures to clear and settle Pre-Authorized Debits (PADs) under an ongoing agreement between a Payor and a Payee.

  • European Banking Authority: An independent EU Authority which works to ensure effective and consistent prudential regulation and supervision across the European banking sector.


    • Strong Customer Authentication (SCA): European regulatory requirement to reduce fraud and make online and offline payments more secure.

Next steps

We’ve just scratched the surface of payments compliance and the various standards governing a typical campus payments environment. Find out more by registering for our upcoming webinar, The Basics: Campus Services & Compliance, where we dig into these governing bodies and share some best practices for compliance management.

This blog post is not intended to be an exhaustive list of regulatory bodies or laws, and is not a substitute for legal advice. It is important to always check with your banking, financial and legal experts on any specific compliance issues.