Notes
Notes - notes.io |
Summary
Use this solution to confirm proper scoring and call handling
Goals
Confirm proper scoring and call handling
Understand the impact of incorrect activities on scoring
Learn best practices and guidelines for authentication and call transfers
Review procedures for dealing with mismatches in business names and addresses
Understand the requirements for top level authentication and one-time codes
Environment
UI: Softphone / Client360 / FDPOS
Platform: North / South / Memphis / Concord / Omaha (ISO)
Alliance: RSA / ISO / Wells / PNC / Memphis / Concord
Internal Version
Procedure
NOTE: Scoring may be affected by the following activities being performed incorrectly. See pillar scoring column for details and review the action column for the best practices and guidelines
TIP: Select the following links to expand.
Doing Business As (DBA)
Action Pillar Scoring
Agent must ask for the business name. If the business name is not provided at all then basic is not completed.
Agent can verify either the DBA or corporate name.
Fail in Non-Negotiable under Did the agent meet our commitment to authentication requirements?
If the agent cannot locate the name, the agent should suggest the caller look at a sales slip - this will help the agent to determine how to properly conduct a name search.
If Basic Authentication of the business name cannot be done, the agent can use the phone number, DDA, contact name, Terminal ID (TID) or higher level of security as back up.
EXAMPLES: When a back-up item would be necessary:
Caller provides Quick Cuts but we have Exquisite Hair Salon
Caller provides Dr. Steven Smith but we have Montgomery Hospital
Giving out the business name (before basic authentication is complete) means a loss of points. Fail in Non-Negotiable under Did the agent meet our commitment to authentication requirements?
The business name can be considered verified if it can be reasonably assumed correct.
NOTE: Another unique identifier (back-up item) is not necessary if we can reasonably assume we have access the correct account.
EXAMPLES: Reasonably assumed correct:
Caller provides Bob's Fish Fry and we have Bob's Fish Fry and Grill
Caller provides ATB Inc and we have All Things Beautiful
Caller provides Dr. John Smith and we have Offices of John Smith MD
NOTE: The discussion of secondary items or slight mismatches can offer additional details to help ensure the correct account has been accessed but is not required unless the caller makes a secondary issue known during the call that could be caused by a DBA mismatch (such as statements not being received). This will be scored as a secondary issue if not clarified.
Fail in Non-Negotiable under Did the agent meet our commitment to authentication requirements?
If a backup item or higher level of security had to be used because the DBA on file could not be verified, then the incorrect DBA must be discussed by the agent for clarification.
EXAMPLE: "I show that the business name we have on file is Bob's Fish Fry and Grill, is that correct?"
If the merchant states he/she has had a change, the agent must address it to prevent a repeat call.
Fail in Proper Resolution-Did the agent meet our commitment to provide the caller with a proper resolution?
Address
Action Pillar Scoring
Agent can verify either the DBA or corporate address to fulfill Basic Authentication requirements.
If the merchant cannot verify the street address, the agent should suggest the caller look at a sales receipt.
Secondary items for address are not required for validation (suite, building or floor number, city, state, zip code)
Once Basic Authentication is complete, secondary items can be discussed to confirm proper mailing (agent can give out for clarification).
NOTE: This is not required unless the caller makes a secondary issue known during the call that could be caused by an address mismatch (such as statements not being received). This will be scored as a secondary issue if not clarified.
EXAMPLE: Agent can say: "I show suite xxx is that correct?"
If Basic Authentication of the address cannot be done, the agent can use the phone number, DDA, contact name, Terminal ID (TID) or higher level of security as back up.
EXAMPLES: When a back-up item would be needed:
Caller provides 123 Center Street and we have 456 Center Street
Caller provides 123 Jackson Court and we have 123 Monroe Court
Fail in Proper Resolution
If a backup item or higher level of security had to be used because the address on file could not be verified, then the incorrect address must be discussed by the agent for clarification.
EXAMPLE: "I show that we have the address of 123 Main Street, is that correct?"
If the merchant states he/she has had a change, the agent must address it to prevent a repeat call.
NOTE: This does not include small misses such as a direction or thoroughfare mismatch.
EXAMPLES: When we can reasonably assume the address is correct and a back-up item would not be necessary:
Caller provides 123 East Center Street and we have 123 Center Street
Caller provides 123 Jackson Road and we have 123 Jackson Boulevard
Fail in Proper Resolution
Giving out any part of the business address before Basic Authentication is complete will be a loss of points.
NOTE: This does not include items such as street/road/avenue.
EXAMPLE: If the caller says 1106 Red River and our system has 1106 Red River Road, Basic Authentication has been done and the agent may say: "I show Red River Road."
Fail in Non-Negotiable under Did the agent meet our commitment to authentication requirements?
Agent must ask for the street address. If the street number is not provided at all or is incorrect, then Basic Authentication was not completed. Fail in Non-Negotiable under Did the agent meet our commitment to authentication requirements?
Agent should not provide address corrections without proper level of authentication with the exception of a one digit correction for the ZIP code. Fail in Non-Negotiable under Did the agent meet our commitment to authentication requirements?
Callers Name
Action Pillar Scoring
First and last name must be asked for compliance reasons. Even small merchant groups must provide their first/last names to agents.
ATTENTION: This is not required if Softphone displays the caller's name.
Fail in Non-Negotiable under Did the agent meet our commitment to authentication requirements?
First and last name must be notated for compliance reasons. FYI in Final Impression under Documentation
Agent does not need to confirm spelling of the caller’s name unless there is a specific procedure requiring it.
Refusal to supply the last name or a higher level of security should be considered a security flag. General business questions can be discussed. If account-specific information is disclosed, the call will be adverse. Fail in Non-Negotiable under Security/Fraud prevention.
Other call center agents or bank reps (inside/outside FD) can give an operator code, an extension, or the name of their business or department, instead of a last name.
Agents should not give out contact name or main name on account (Confirmation Only).
How do I respond if the caller wants me to provide the address or other information?
Explain that, based on PII security, you can verify the information given against what is on file, but you are unable to provide that information.
ATTENTION: Follow alliance-specific procedures
Fail in Non-Negotiable under Security/Fraud Prevention?
Agents are not required to ask for, or notate, the last name of internal business consultants.
Connecting Calls - Sending
Action Pillar Scoring
Identify the department you are with and your name. Fail in Final Impressions under Transfers
Provide the receiving agent the caller's first and last name. (verbally or w/ Softphone) Fail in Final Impressions under Transfers
Inform receiving agent of the caller's issue. (verbally or w/ Softphone) Fail in Final Impressions under Transfers
Accurately explaining the issue to the receiver. (verbally or w/ Softphone) Fail in Final Impressions under Transfers
No scoring impact if the agent does not provide authentication level on an external transfer.
Repeat the address if requested by an external receiving agent. Some groups external to CCO have different systems and need to validate the address we display. Fail in Final Impressions under Transfers
If you were unable to validate any of the basic information (because it was not available in your system), make the receiving agent aware of this so they can validate what they have in their system. Fail in Final Impressions under Transfers
Scoring may be affected for conversation beyond basic transfer items. Fail in Final Impressions under Transfers
Failure to inform receiving agent of the authentication information (verbally or through Softphone Transfers)
No authentication discussed between agents
No visual or report indication of authentication level
Fail in Final Impressions under Transfers
Discussion, visual (ex. Softphone or Client360) or report evidence that misrepresents the level of authentication as lower than completed.
EXAMPLE: When a lower level (Basic) is represented but a higher level (Top) was completed.
Fail in Final Impressions under Transfers
Discussion, visual (ex. Softphone or Client360) or report evidence that misrepresents the level of authentication as being higher than completed
EXAMPLE: When a higher level (Top) is represented but a lower level (Basic) was completed.
NOTE: Excludes deductions for Basic Authentication. QA will use MID/DBA/Name/Address categories above for basic deductions.
ATTENTION: This would include if Technical Helpdesks verify the Serial Number for troubleshooting and advise the receiving agent (verbally or through Softphone transfers) that top level was verified.
Fail in Non-Negotiable under Did the agent meet our commitment to authentication requirements?
Connecting Calls - Receiving
Action Pillar Scoring
If the sending agent disconnects before you have confirmed authentication was completed, you must complete authentication unless this information is provided by softphone.
No authentication discussed between agents
No visual or report indication of authentication level
No verbal indication
EXAMPLES:
"Thank you for successfully confirming your credentials within our automated service."
"We successfully received the information you entered in our automated service."
See steps below
Failure to confirm authentication has been verified with sending agent verbally or via Softphone.
If Basic Authentication is not confirmed/completed with sending agent
Failure to confirm that Top Level Authentication has been verified and performing a Top Level activity
Fail in Non-Negotiable under Did the agent meet our commitment to authentication requirements?
If authentication is not confirmed with sending agent when not available in soft phone and authentication needs to be repeated. Fail in Set Up For Success under Over Authentication
If the sending agent did not provide the caller's first and last name, ask the caller's name and memo the account.
Re-state the issue to the merchant to ensure the communication of the issue was correct; failure to do so could result in a loss of points if the caller experience is impacted. Fail in Final Impressions under Transfers
Failure to confirm first and last name of the caller with the sending agent verbally or via Softphone, or failure to reconfirm (when not confirmed with the sending agent) Fail in Non-Negotiable under Did the agent meet our commitment to authentication requirements?
Top Level Authentication
Action Pillar Scoring
No account changes should be made to an account without Top level authentication being completed first. Fail in Non-Negotiable under Did the agent meet our commitment to authentication requirements?
Expiration date request - agents could also verify full card number, case number, or Top Level security.
Batch reports with partial card numbers should still have Top Level Authentication verified since the last 4 digits of other sales or batch total can be used for Top Level Authentication.
Best Practice: Receive card sale information to avoid giving out information that could be used later to gain access to full card numbers.
Three transactions verification:
One transaction must be requested by the agent.
Failure to request at least one sale will be a loss in points
Suggested method:
Agent asks for a transaction by dollar amount and date. Agent requests the caller confirm the last four digits of the card.
Caller offers last four digits and amount of two other transactions.
NOTE: If the caller cannot complete the requested sale and has to offer all three transactions, the agent should complete a fourth transaction of the merchant's choice with the caller.
Fail in Non-Negotiable under Did the agent meet our commitment to authentication requirements?
Failure to use all Top Level Authentication options could result in the merchant being unassisted.
ATTENTION: Multiple methods should not be used during the same call, however all methods should be explored to give the caller sufficient options
Fail in Proper Resolution-Did the agent meet our commitment to provide the caller with a proper resolution?
Top Level Authentication must be completed before divulging (cardholder/merchant account information to an unauthorized person, sending a batch report, falsifying information, download, account change, divulging full/truncated card numbers, replacement units to alternate address, etc.) without completing Top Level Authentication.
Exceptions:
Replacement units to address on file, swap outs, and replacements of equipment buy outs (does not include stand-alone PIN pads) shipped to address on file
Add/delete entitlement, removal of Clover Security, adjustment of American Express split dial, violated to active.
NOTE: These changes require a partial download
Fail in Non-Negotiable under Security/Fraud prevention.
If the MID is given out without verifying the proper level of security. Fail in Non-Negotiable under Security/Fraud prevention.
If the agent uses the requested card information as one of the three transactions verified, loss of points will occur.
NOTE: Agent can verify sales from a batch report that is being requested without incurring a loss of points.
Fail in Non-Negotiable under Did the agent meet our commitment to authentication requirements?
If a batch report or other report containing full or partial card numbers is sent out without all proper levels of security would be considered a Security violation, including divulging cardholder/merchant account information to an unauthorized person, or falsifying information Fail in Non-Negotiable under Security/Fraud prevention.
If a full card number and or expiration date is given out without all proper levels of security would be considered a Security violation, including divulging cardholder/merchant account information to an unauthorized person, or falsifying information. Fail in Non-Negotiable under Security/Fraud prevention.
Request for changes/card numbers (with the exception of a DDA change) on multiple MIDs that are for one entity with shared business information such address, Tax ID, etc. can be considered authenticated with all proper levels of authentication completed on initial account.
Divulging an email address or phone number.
Agent cannot give out any part(s) of the clients email address or phone number on file.
If the caller does not recognize or can't confirm the information on file, then another form of Top Level Authentication must be completed prior to updating the account for the caller.
Fail in Non-Negotiable under Security/Fraud prevention.
If an agent makes a change to the terminal without Top Level Authentication, which in turn unlocks the terminal, (the agent did not physically hit unlock). Agents can view lock status from summary screen of FDPOS.
Fail in Non-Negotiable under Security/Fraud prevention.
In instances where top level authentication is necessary, you are required to note “Top and item name” in your memo. An example would be: Top – transactions. This will reduce confusion for groups that read notes on an account and use different Top level items. FYI in Final Impression under Documentation
If an agent manually unlocks a TID without completing Top Level Authentication. Fail in Non-Negotiable under Did the agent meet our commitment to authentication requirements?
If a terminal needs to be unlocked, and an outbound call needs to be done for Top Level Authentication, then only the contact name on the account or the business owner can authorize us to move forward. If Top Level Authentication is completed with another caller type, a deduction will occur. Fail in Non-Negotiable under Did the agent meet our commitment to authentication requirements?
If an outbound call needs to be made (for call types other than to unlock a terminal or DDA/Account changes) the person who answers the phone number on file can authorize us to move forward.
When requesting the Serial Number (S/N) for Top Level verification we cannot give out any numerical characters of the serial number.
NOTE: To assist the merchant with finding the SN# you can give them directions as to where its located on the terminal or advise it starts with "sn number followed by 2 letters." You can also assist the merchant with locating or printing it from the terminal.
EXAMPLE: "The Serial Number can be located on the bottom of the terminal next to the S/N and starts with FD."
Fail in Non-Negotiable under Did the agent meet our commitment to authentication requirements?
When the terminal Serial Number (S/N) is missing or incorrect and cannot be used for Top Level Authentication, once Top Level is completed the terminal S/N must be updated in FDPOSM.
Failure to update the terminal Serial Number (S/N) will result in a Fail in Proper Resolution except for the following scenarios:
Top level was already verified through the IVR or by a previous agent.
The call type does not permit the terminal Serial Number (S/N) to be used for top level.
EXAMPLE: If the caller needs a full card number but the Serial Number (S/N) is missing, this would be a coaching opportunity if the OA does not make the update after completing top level.
Fail in Proper Resolution-Did the agent meet our commitment to provide the caller with a proper resolution?
When the terminal Serial Number (S/N) is first used for terminal troubleshooting, another form of top level MUST be verified for any other Call Type it cannot be used for.
Failure to perform additional verification before divulging information will result in a miss.
Fail in Non-Negotiable under Did the agent meet our commitment to authentication requirements?
One Time Code (OTC)
Action Pillar Scoring
Suggested Scripting: "Do I have your permission to send a one-time code to the phone number/email on file?. Standard text/data rates may apply. Do I have your permission to send you the text message?."
ATTENTION:
A verbal "yes" or agreement to receive an OTC must be gained.
Agent must advise the caller that standard text messaging rates apply.
Agent must confirm the information on file with the caller before sending the OTC.
Consent: Fail in Non-Negotiable under Regulatory Requirements.
STM Statement: Fail in Non-Negotiable under Call Disclosure.
Sending a one-time code to a phone number not on file will result in a deduction unless it is a white listed number or a valid Phone Finder session is completed.
ATTENTION: When using Phone Finder to search a third party phone number, we should verify the caller's name/business name, the city and state on the report, and that the phone number is established more than 30 days ago.
Fail in Non-Negotiable under Did the agent meet our commitment to authentication requirements?
Sending a one-time code to an email account not on file (unless it is an approved known domain) will result in a deduction. Fail in Non-Negotiable under Did the agent meet our commitment to authentication requirements?
Sending a one-time code to an email account or phone number that has been updated within the last 14 days will result in a deduction.
NOTE: Before sending a OTC agents should check Account History > Change History in Client360 to see if either phone or email has been recently updated.
Fail in Non-Negotiable under Did the agent meet our commitment to authentication requirements?
Divulging an email address or phone number.
Agent must not give out additional details as hints.
If the caller does not recognize or can't confirm the information on file, then another form of Top Level Authentication must be completed prior to updating the account for the caller.
Fail in Non-Negotiable under Security/Fraud prevention.
ISO/FSP/Bank Specific Instructions: Not validating or using an approved white list variation/exception to the standard process. Fail in Non-Negotiable under Did the agent meet our commitment to authentication requirements?
The agent sends out an OTC to the same phone more than two times on the same call, instead of moving to the next tool Fail in Non-Negotiable under Did the agent meet our commitment to authentication requirements?
If the agent sends out an OTC to a variety of phone numbers or email addresses at the request of the caller, instead of moving to the next tool (on the same call) it could compromise security. Sending to more than two different phones or two different emails, or a combination of the two options will result in a loss of points. Fail in Non-Negotiable under Did the agent meet our commitment to authentication requirements?
The agent should memo the account with the transaction number for the successful and unsuccessful OTC session
NOTE: As long as the case is re-authenticated to show Top Level, agents are not required to include it in the detailed notes, unless the option is not available in Client360.
Fail in Final Impressions under Notation.
The agent should not offer the transaction number for the successful OTC session as an option to call back with for repeat authentication validation. Fail in Proper Resolution-Did the agent meet our commitment to provide the caller with a proper resolution?
Softphone Authentication
Action Pillar Scoring
Softphone or IVR authentication report displays that Basic or Top Level Authentication has been verified and we ask the caller to repeat authentication.
ATTENTION: Caller's name needs to be asked if it is not displayed in softphone in order to meet noting requirements.
NOTE: Specific Call Types, or Alliance/Department procedures may restrict what type of Top Level can be used. To confirm what verification information was obtained by the IVR or the transferring agent, agents must select the Authentication tab.
NOTE: For Technical products that use the Terminal SN# for Top Level, if an agent asks for the SN# when Top Level is verified through the IVR, this will be a coaching opportunity.
Fail in Setup for Success - Over Authentication
ATTENTION: Must be confirmed using screen scrape or IVR auth report to score.
Softphone displays Identified w/o Auth and we have the caller perform full basic.
NOTE: Agents must select in to the Authentication tab and only verify missing pieces.
EXAMPLES:
The caller enters the MID and the ANI (phone) matched a number on file, but are unable to confirm the business name and address. Agent should only verify 1 piece (Business Name, Address, or another back - up item)
The caller enters the MID and confirms the address, but not they are calling from a number on file (no ANI) and unable to confirm the business name. Agent should only verify 1 piece (business name or backup item)
The caller enters a single identification item (MID or Phone), but they are not able to verify any other information. Agents should verify 2 additional pieces based on what was entered into the IVR; MID (verify DBA and Address), Phone (verify MID and DBA or Address)
Fail in Setup for Success - Over Authentication
ATTENTION: Must be confirmed using Screen Scrape in order to score. IVR Auth report does not show what pieces were verified.
If IVR Auth report shows a MID associated with the Session ID and the agent asks for the MID, this will be a Fail in setup for success for Over Authentication.
Softphone displays Unidentified and we do not perform basic authentication. Fail in Non-Negotiable under Did the agent meet our commitment to authentication requirements?
ATTENTION: Must be confirmed using screen scrape or IVR auth report to score.
Softphone displays Unidentified and we perform a top level activity without verifying top level. Fail in Non-Negotiable under Did the agent meet our commitment to authentication requirements?
ATTENTION: Must be confirmed using screen scrape or IVR auth report to score.
Softphone displays the caller’s name and we ask the caller to repeat.
Softphone displays Call Data or Call Attributes such as CC Number, Merchant ID, Reason for Call (If clearly stated in screen pop) and we ask the caller to repeat.
Fail in Setup for Success - Over Authentication
ATTENTION: Must be confirmed using screen scrape to score.
![]() |
Notes is a web-based application for online taking notes. You can take your notes and share with others people. If you like taking long notes, notes.io is designed for you. To date, over 8,000,000,000+ notes created and continuing...
With notes.io;
- * You can take a note from anywhere and any device with internet connection.
- * You can share the notes in social platforms (YouTube, Facebook, Twitter, instagram etc.).
- * You can quickly share your contents without website, blog and e-mail.
- * You don't need to create any Account to share a note. As you wish you can use quick, easy and best shortened notes with sms, websites, e-mail, or messaging services (WhatsApp, iMessage, Telegram, Signal).
- * Notes.io has fabulous infrastructure design for a short link and allows you to share the note as an easy and understandable link.
Fast: Notes.io is built for speed and performance. You can take a notes quickly and browse your archive.
Easy: Notes.io doesn’t require installation. Just write and share note!
Short: Notes.io’s url just 8 character. You’ll get shorten link of your note when you want to share. (Ex: notes.io/q )
Free: Notes.io works for 14 years and has been free since the day it was started.
You immediately create your first note and start sharing with the ones you wish. If you want to contact us, you can use the following communication channels;
Email: [email protected]
Twitter: http://twitter.com/notesio
Instagram: http://instagram.com/notes.io
Facebook: http://facebook.com/notesio
Regards;
Notes.io Team
