When it comes to secure business payments, internal controls are only part of the equation. The security standards, processes and data protection measures of a payment provider play an equally important role in helping organisations reduce risk, protect sensitive information and maintain control of their transaction data.
“When discussing the security of corporate cards and payments, the focus often lies on what the company and cardholder can do to minimise the risk of fraud. Equally important is ensuring that the payment provider meets its security commitments,” says Thomas Eriksson, Chief Security Officer at AirPlus. He continues:
"The internal systems and routines of a payment provider are crucial to the security of corporate cards."
He explains that today's corporate cards are generally very secure, largely due to the ongoing digitalisation in society.
The internal systems and routines of a payment provider are crucial to the security of corporate cards.
"Digital payment methods have indeed introduced new types of fraud, such as phishing, but they have also led most banks and financial institutions to be more proactive when it comes to securing their processes and systems.”
John Mossblad, a fraud analyst at AirPlus, agrees and adds:
"The EU's Second Payment Services Directive, PSD2, which was introduced a few years ago and includes the requirement for strong customer authentication for card payments, has also been very important in the fight against financial crime," he says.
The procedures and systems used by different payment providers can vary. So, what can you as a company do to determine whether a payment provider meets your security requirements?
John and Thomas highlight five key areas organisations should consider when assessing the security of a payment provider, where the first area is essential and the rest are more supplementary, depending on how thorough an examination of the provider you wish to conduct.
Are you ISO IEC 27001:2022 certified?
“ISO/IEC 27001:2022 is an international standard and framework for how organisations should manage information and data, ensuring that threats, vulnerabilities, and business risks are continuously identified, assessed, and managed. The standard helps organisations identify risks and manage them in a structured and effective manner. To maintain the certificate, annual follow-up audits, both internal and external, are required.”
How do you protect our transactions?
“The way a payment provider follows customer transactions can vary significantly. It is important that monitoring occurs in real-time, around the clock, regardless of where the payment takes place. What systems are used, and how much of the work is done manually versus automatically? A mix of both approaches is beneficial, with one complementing the other. What types of behaviours are monitored, and what is the procedure if unusual behaviour is detected in a transaction?”
How robust are your systems?
“It is also important to understand how resilient the payment provider's own systems are to, for example, a cyberattack. Do they regularly update and test their systems, and what procedures and processes are in place to quickly get started after a potential disruption? Also ask them to describe how they proactively work to prevent these types of attacks.”
How are roles and permissions managed?
“A robust access management process is an important part of any security framework. Ask how roles and permissions are assigned, reviewed and updated. Access to customer information should be based on business need, with regular reviews to ensure that only authorised employees have access to sensitive data and systems.”
How do you work with partners?
“Most payment providers collaborate with subcontractors in some form. This means that there is another party with access to your transaction data, for example. So you should find out which partners the payment provider collaborates with and how they protect information and services related to these partnerships. Also, ask them to explain how they follow up on and ensure that partners comply with the delivery agreements.”

