Fayetteville Policies and Procedures  309.0 

Payment Card Processing

Any department, entity, or individual engaged in any form of payment card processing (e.g., POS/swipe or e-commerce) on campus, using the university network, or on behalf of the university, including Registered Student Organizations, must have the approval of Credit Card Operations prior to engaging in commerce activity. No University of Arkansas (university) Department and/or entity may enter into any contracts or otherwise arrange for payment transaction processing or obtain any related equipment, software or services without the involvement and approval of Credit Card Operations .All payment activity must be established within the centralized university banking and accounting environment with receipts deposited into designated university bank accounts, unless an exception is approved by the Associate Vice Chancellor for Financial Affairs.

The university’s official online payment system is Transact Payments. All departments and/or entities wishing to accept online payment card transactions must use Transact Payments unless a waiver by Credit Card Operations is granted. (See Payment Card Usage section below for additional information.)

Purpose

The purpose of this policy is to outline the payment card acceptance methods suitable for university business and the usage restrictions for payment card transactions. Credit Card Operations is responsible for campus compliance with payment card processing and security regulations and is granted authority to take appropriate action to ensure conformity with university policies and procedures. Appropriate action up to and including immediate termination of payment card processing activities will be imposed for any university department and/or entity that violates the provisions of Fayetteville Policies and Procedures (FPP) 309.0 through 309.3, which relate to payment card processing, security, and incident reporting. Further, university employees who violate any of these policies are subject to appropriate disciplinary action, up to and including termination.

Definitions

All terms used in this policy are defined in FPP 309.3 Payment Card Policies Glossary. All campus users of payment card information are required to know and fully understand all terms associated with FPP 309.0 through 309.3.

Training

Training and re-certification is required for all staff handling payment card information on behalf of the university. Training is required annually and is offered throughout the year.  For additional information regarding the Credit Card Operations training program for departmental or entity users, please see https://cardops.uark.edu/training.aspx .

Payment Card Usage

The university accepts American Express, Discover, MasterCard and Visa payment cards for university business. (Debit card transactions that require a PIN number are acceptable payment options for walk-in payments.) The university accepts payment only via telephone, walk-in traffic or an online portal approved by Credit Card Operations. Acceptance via mail, email, fax or other end-user messaging technologies is prohibited. Telephone and walk-in payments are to be processed on technology supplied by  Credit Card Operations. The use of Transact Payments is for customer-facing e-commerce sites only.

If a department and/or entity has a specific business operational need that the approved, official university processing methods cannot meet, the department can apply for a system usage waiver. Departments and/or entities initiate the waiver request by submitting written justification to Credit Card Operations that explains their need and why Transact Payments or other approved methods cannot adequately support the operation. Waiver requests must be submitted annually to Credit Card Operations and are evaluated on a case-by-case basis. As part of the waiver application process, Credit Card Operations will conduct a full evaluation of proposed equipment, network structure and remote access privilege use.

In addition, departments and/or entities applying for a system usage waiver must achieve and maintain full compliance with FPP 309.0 through 309.3, as well as applicable legal and industry regulations. A full list of requirements is available in the system usage waiver supplement document provided by Credit Card Operations. Any department and/or entity granted a waiver is responsible for the fiscal costs associated with payment card security as detailed in FPP 309.0 through 309.3. These costs will include the purchase and implementation of the most current Payment Application Data Security Standard (PA DSS) validated software upgrade versions as older versions are removed from validation.

Acceptable Technology

Credit Card Operations will provide all technology/devices for telephone and walk-in payments. Departments and/or entities pay a monthly leasing fee to Credit Card Operations for use of the technology. Payment processing devices must be configured and implemented as instructed by Credit Card Operations, including limiting access on the device to only applications needed for payment processing.

Technology usage for system waiver environments is evaluated on a case-by-case basis. Payment card processing must be completed only on devices approved or provided by Credit Card Operations.

All departments and/or entities must supply Credit Card Operations with a device inventory of all equipment to be used in the processing environment prior to authorization and implementation of the system. The inventory must include: the physical location of the device, a description of the device, the model number, the asset serial and tag numbers, operating system or firmware information, DNS/IP address, and MAC address. Devices must be registered in accordance with University Property Accounting requirements.. Departments and/or entities must notify Credit Card Operations within seven days of any changes in processing equipment, including location changes.

Departments and/or entities are responsible for the physical security of all devices used in payment card processing within the department and/or entity. Requirements for physical security of devices can be found on the Credit Card Operations website. Processing devices must be secured from tampering and/or attended at all times. This requirement also includes access to network jacks that are dedicated to any of the secure commerce networks. Departmental and/or entity users may not plug a non-commerce device into a network jack on the secure commerce networks or in any other way modify those networks without first gaining approval from Credit Card Operations and involving the IT Services Network Engineering Team.

The use of wi-fi for payment card processing is prohibited. If a department and/or entity requires a mobile processing terminal, Credit Card Operations will provide cellular equipment to the department and/or entity with applicable fees assessed. Any wireless capable equipment used in the processing environment must have the wireless radio disabled while processing transactions.

User Access to Processing Environments

Departments and/or entities authorized to accept payment card transactions will have one or more payment card merchant accounts established by the Office of Financial Affairs. All payment card transactions for the department and/or entity will flow through this account. As a condition of merchant account assignment, all requirements detailed in FPP 309.0 through 309.3 must be met.

Access to the cardholder data environment will be restricted by job duties of each individual.  Every user must be assigned a unique user ID and password to access the cardholder data environment, where applicable. Departments and/or entities are responsible for ensuring staff are validated to handle payment information prior to assignment of job duties involving cardholder data. System IDs and shared IDs are not permitted for staff use. Passwords for users MUST be changed every 90 days. User accounts must also be locked after a maximum of three failed login attempts and remain locked out for either 30 minutes or until an administrator verifies the user’s identity and re-activates the account. Accounts inactive for at least 90 days must be removed or locked. Credentials for automated services and service accounts must have a password change every 90 days. Departments and/or entities are required to submit an Access Control List (ACL) to Credit Card Operations based on the schedule established by Credit Card Operations which can be found in the SAQ Tool. The ACL must include all accounts in the payment processing system, including sponsored/service accounts.

Vendors that require access to the department and/or entity processing environment must be granted access by Credit Card Operations before modifying any campus equipment. Depending on the access requested, this may require the vendor to install software to make a secure connection through the commerce firewall environment. Vendor accounts for this type of connection are managed by Credit Card Operations and are only enabled for one business day upon request. Departmental and/or entity staff are responsible for monitoring the activity of the vendor while handling campus equipment.

Refund Handling

All payment card processing departments and/or entities must display a refund notification for customers.  The refund notification must state that all refunds will be processed back to the card used during the sale. Departmental and/or entity refund notification must be displayed at point-of-sale locations or on the departmental or entity website (for e-commerce applications).

All departments and /or entities engaged in any form of payment card processing must comply with the procedures listed below for their  payment acceptance method with refund approval duties assigned to a responsible party.

  • Refunds must be processed on the same Merchant ID account as the original sale.
  • Refunds cannot exceed the original sale amount.
  • Refunds must be processed back to the same card used in the original sale.
  • Departments and/or entities will account for refunds for processing terminals and third-party systems per the Treasurer’s Office departmental deposit requirements.
  • Refund requests for Transact and CyberSource transactions will be submitted via the AskCommerce portal and processed by the Treasurer’s Office.  Departments and/or entities can request approval from Credit Card Operations to process their own refunds.

Fees

Each department and/or entity is responsible for the costs incurred by the university to process its transactions, plus setup fees for any new merchant account. Processing fees will be deducted monthly using a Workday driving worktag. A current fee schedule can be obtained from Credit Card Operations.

In addition, each department and/or entity is responsible for any hardware, software, setup and/or maintenance costs to maintain the processing environment, including the cost of any PCI-related services. Additionally, departments and/or entities may  be required to pay for training and background checks when required by Fayetteville Policies and Procedures.

Revised February 2, 2026
Revised June 6, 2022
Revised May 27, 2015
Reformatted for Web May 28, 2014
November 19, 2010