Skip to main content
Payments

Call Center Merchant Accounts: High-Volume Phone Payment Processing That Gets Approved

KD

Kaleb Dickhaut

Founder, ClickWerxs

June 26, 2026
10 min read
Long-exposure night photo of a call-center desk with a single headset in sharp focus and teal light trails streaking through the dark rows of workstations behind it.

TL;DR: Call center payment processing is classified high-risk because transactions are card-not-present, and MCC codes 5966 (outbound telemarketing) and 5967 (inbound teleservices) carry enhanced underwriting scrutiny from acquiring banks. Getting approved requires documentation most standard merchant account applications never ask for, a PCI compliance posture that changed in March 2025, and a processor that actually underwrites MOTO volume.


You can process card payments over the phone at a standard merchant account. Until you can't. The first chargeback spike, the first compliance review from your acquirer, or the first audit revealing you're running a call center through a retail MCC code ends it. Frequently without notice.

Call center merchant accounts are a specific, underwritten product. More documentation, more compliance requirements, higher interchange, often a rolling reserve. The process takes longer and the costs run higher for documented reasons. Here's what each piece of the process actually looks like.


What is a call center merchant account, and why can't you use a standard one?

A call center merchant account is a merchant account specifically underwritten for MOTO (Mail Order/Telephone Order) processing. The cardholder is not physically present. The card is not swiped, dipped, or tapped. That absence is the core risk distinction.

Standard retail and card-present accounts are underwritten assuming the physical card and cardholder are at the transaction point. MOTO removes both. Someone other than the cardholder can provide stolen card numbers by phone. "I didn't authorize that charge" disputes are harder to defend without a signed receipt, a chip read, or a contactless approval log.

Payment processors know this. Standard accounts are not set up to price or manage MOTO risk. Running significant call center volume through a card-present account violates account terms. It typically ends in a reserve, a hold, or a termination. Usually the timing coincides with when the chargeback rate breaches a threshold that was never disclosed to the merchant.

A properly underwritten call center merchant account prices for MOTO risk upfront, with explicit terms. The costs are higher. The tradeoff is predictability and an account structure that doesn't collapse when volume grows.

Answer capsule: A call center merchant account is a MOTO-underwritten merchant account for businesses processing card payments by phone. Standard retail accounts are not designed for MOTO volume. Running phone-based transactions through a card-present MCC violates account terms and typically results in a hold or termination when chargeback rates breach undisclosed thresholds. A proper call center account sets explicit terms from the start, before the first chargeback dispute arrives.


What MCC code does your call center actually need?

Merchant Category Codes (MCCs) are four-digit identifiers assigned by your acquiring bank. For call centers, two codes apply directly.

MCC 5966: Direct Marketing, Outbound Telemarketing. Businesses that initiate contact with consumers to sell by phone. Outbound calling programs, subscription sales initiated by agents, upsell campaigns. This carries the higher risk profile: it signals proactive outreach, which historically correlates with elevated dispute rates.

MCC 5967: Direct Marketing, Inbound Teleservices. Businesses where the consumer initiates contact: inbound order processing, customer service lines, inbound tech support. Lower risk profile than 5966, but still classified high-risk by Visa and Mastercard due to MOTO fraud exposure.

Both are flagged for enhanced monitoring by card networks. Both require a merchant account explicitly underwritten for that code. A processor who assigns you a retail MCC or a generic direct marketing code because your application didn't flag telemarketing is setting up a future MCC audit that triggers re-underwriting, and potentially a reserve or hold on existing settlement funds.

Answer capsule: Call centers are assigned MCC 5966 (outbound telemarketing) or MCC 5967 (inbound teleservices). Both are high-risk classifications requiring explicit underwriting from the acquiring bank. Inbound (5967) carries a lower risk profile than outbound (5966), which affects reserve terms and approval likelihood. The MCC assigned at application determines the rate tier, monitoring requirements, and what the processor does when chargeback rates rise.


Why do processors decline call center accounts, and what triggers the rejection?

Standard processors (those approving small retailers in 24 hours) run simplified underwriting models. Call center accounts fall outside those models. Declines often have nothing to do with the quality of the business.

Three common decline patterns:

MCC flag. The processor sees 5966 or 5967 and declines without review. Some platforms have explicit industry exclusions for telemarketing codes. This is a product limitation, not a business evaluation.

Chargeback rate. If the business has processing history, a dispute rate above 0.5% (the Visa VAMP "above standard" threshold, enforcement effective October 1, 2025) or above 1.0% (Mastercard's monitoring trigger) will result in a decline at any risk-aware processor. Rates in the 0.3–0.5% range require explanation and a documented dispute management plan.

Missing documentation. Call center applications require materials standard merchant account forms don't ask for: call scripts, recorded authorization procedures, refund policies, and a detailed business model description. Applications submitted without these return with information requests that stall the process for weeks, or get declined if the processor doesn't want to wait.

Answer capsule: Most call center merchant account declines fall into three categories: MCC exclusion (the processor doesn't underwrite 5966 or 5967), chargeback rate concerns (above 0.5% triggers Visa VAMP monitoring effective October 1, 2025), or incomplete documentation. An application missing a refund policy, call script sample, or authorization procedure often declines on process grounds regardless of how solid the underlying business is.


What does underwriting actually look at for call center accounts?

MOTO underwriting is more document-intensive than card-present underwriting because the underwriter is evaluating fraud risk without a physical transaction trail. The standard documentation request for a call center account includes:

  • Business license and articles of incorporation
  • 3–6 months of processing statements (if processing history exists)
  • Refund and cancellation policy: written, specific, and publicly accessible to consumers
  • Sample call script or a description of the verbal authorization process used on calls
  • Website URL with visible terms and conditions
  • Chargeback management plan (required if prior dispute history exists)
  • Fulfillment model description: when the card is charged relative to when product or service is delivered

The underwriter is reading these for one primary signal: does this merchant have a documented process that reduces the probability a cardholder will call their bank instead of calling the merchant?

In MOTO merchant account applications we process through the ISO portfolio, the single documentation issue that most commonly stalls a first submission is a refund policy that exists verbally but isn't published anywhere a cardholder or processor can verify it. Underwriters require the policy to be publicly accessible. A buried terms-of-service page doesn't satisfy this requirement. A dedicated, prominently linked refund policy does. Applications that include a written policy, a sample authorization script, and a clear description of fulfillment timing move faster through underwriting than those that don't. The documentation delays the business, not the MCC classification.

Industry-standard underwriting timelines for high-risk accounts run 3–5 business days once the complete documentation package is submitted. Incomplete submissions restart the clock.


What rates should a call center expect to pay for MOTO processing?

MOTO transactions carry higher interchange than card-present transactions at the network level. The card-not-present premium is built into Visa and Mastercard's base interchange schedules. It is not a processor markup.

On an interchange-plus structure, call centers typically see:

  • Visa keyed consumer cards: 1.80%–2.30% + $0.10 per transaction
  • Visa keyed corporate and premium cards: up to 2.95% + $0.10
  • Mastercard keyed consumer cards: 1.95%–2.10% + $0.10
  • Mastercard keyed world elite and premium cards: up to 2.95% + $0.10

(Visa and Mastercard interchange schedules, 2026.)

Two recent network changes directly affect call center cost calculations:

Mastercard MOTO fee on declined authorizations (January 2026). Mastercard's MOTO fee (0.015%) now applies to all authorization attempts (including declined transactions), not only cleared and settled ones. For MOTO transactions over $500, declined authorizations carry a $75 fee cap. Call centers using outdated card data or running frequent pre-authorizations on stored card numbers will see higher fees under this structure. (merchantcostconsulting.com, 2026.)

Visa Digital Commerce Service Fee (effective January 1, 2025). Visa's 0.0075% Digital Commerce Service Fee applies to all card-not-present authorizations, approved or declined. At $100,000/month in MOTO volume, that's approximately $75/month from this fee alone on declined transactions. Small per transaction, but it applies to every authorization attempt.

Beyond interchange, high-risk accounts typically carry a rolling reserve: 5–10% of processing volume held for 90–180 days as a backstop against future chargebacks. Reserve terms are set at underwriting and vary by chargeback history and volume. After 6–12 months of clean processing, reserves can often be renegotiated.

Answer capsule: MOTO interchange on Visa consumer cards runs 1.80%–2.30% + $0.10; Mastercard consumer cards run 1.95%–2.10% + $0.10 (Visa and Mastercard interchange schedules, 2026). Two network changes add cost: Mastercard's January 2026 update makes the MOTO fee (0.015%) apply to all authorizations including declines, with a $75 cap on declined MOTO transactions over $500. Visa's Digital Commerce Service Fee (0.0075%) has applied to all card-not-present authorizations including declines since January 1, 2025.


What does PCI DSS v4.0.1 require from a call center's payment workflow?

PCI DSS v4.0.1 became mandatory on March 31, 2025, when all 51 future-dated requirements from the original v4.0 publication became enforceable. (PCI Security Standards Council, 2025.) The change with the highest operational impact for call centers is how card numbers can and cannot move through the call environment.

Pause-and-resume call recording is no longer an acceptable control.

Under PCI DSS v3.x, many call centers managed cardholder data in recordings by having agents manually pause the recording when the customer read their card number aloud. Under v4.0.1, manual controls that depend on agent behavior are insufficient. The standard requires technical architecture, not human memory, to prevent cardholder data from entering the recording system.

The accepted compliant approach is DTMF (Dual-Tone Multi-Frequency) masking: the customer enters card digits via their phone keypad rather than speaking them aloud. The audio tones are masked before reaching the recording system and the agent's headset. The card number never enters the audio stream.

Any call center still using pause-and-resume as its primary PCI control is out of compliance with a requirement that became mandatory fifteen months ago. Acquirers conducting compliance reviews (triggered by chargeback spikes, account flags, or routine audits) will identify this.

Relevant PCI DSS v4.0.1 requirements for call centers:

  • Requirement 4.2.2: Addresses transmission of primary account numbers over communication technologies in ways that expose them in the audio environment
  • Requirement 12.10.7: Incident response procedures must address cardholder data discovered in unexpected locations, including call recordings
  • SAQ C-VT: The standard Self-Assessment Questionnaire for merchants using only web-based virtual terminals: the applicable form for most call center environments

Answer capsule: PCI DSS v4.0.1 became mandatory March 31, 2025 (PCI Security Standards Council). The most significant call center compliance change: pause-and-resume call recording is no longer an acceptable control for keeping card numbers out of audio. The required standard is DTMF masking: customers enter card digits via keypad, bypassing the audio stream entirely. A call center relying on agents to pause recordings before card numbers are spoken is out of compliance with a requirement in force for over a year.


How do you keep chargebacks below the threshold that gets accounts flagged?

Visa's Acquirer Monitoring Program (VAMP) began enforcement October 1, 2025, setting portfolio-level dispute thresholds that determine when acquirers face enhanced scrutiny:

  • Above Standard: VAMP ratio at or above 0.5% of transactions
  • Excessive: VAMP ratio at or above 0.7% of transactions

(Visa VAMP Fact Sheet, 2025.)

Acquirers whose portfolios breach these thresholds manage their exposure by setting internal merchant-level limits below the published thresholds. A call center with a 0.4% chargeback rate at a processor whose acquirer portfolio is approaching 0.5% becomes a candidate for reserve increases or account review before the network threshold is formally breached.

Mastercard's Excessive Chargeback Program triggers monitoring at 1.0% and excessive status at 1.5% of monthly transactions.

For call centers, the specific dispute drivers to control:

Billing descriptor mismatch. If the name on the cardholder's statement doesn't match what the agent said the company name was on the call, disputes follow. The billing descriptor should match the name used to describe the company during authorization.

Trial and subscription model disclosures. Subscription programs with card capture at sign-up generate elevated dispute rates when trial-to-paid conversion terms aren't clearly stated on the call. Verbal disclosure during authorization, followed by a written confirmation email with exact billing dates and amounts, is the documented control.

Manual keying errors. Double charges, wrong amounts, incorrect card numbers entered into virtual terminals are preventable with a confirmation step before authorization submission.

Fulfillment timeline gaps. When product or service delivery happens after the card is charged and that timeline isn't stated during the call, cardholders who don't receive immediate delivery often dispute rather than calling back.

Answer capsule: Visa VAMP enforcement began October 1, 2025 with thresholds at 0.5% (Above Standard) and 0.7% (Excessive) at the acquirer portfolio level (Visa VAMP Fact Sheet, 2025). Mastercard's Excessive Chargeback Program triggers monitoring at 1.0%. For call centers, the four dispute drivers that consistently push rates above thresholds are billing descriptor mismatch, undisclosed trial billing terms, manual keying errors, and fulfillment timeline gaps unexplained during authorization.

For a full breakdown of dispute management, see chargeback prevention guide.


What should a call center look for in a payment processing partner?

Not all processors are set up to underwrite MOTO volume. These capabilities separate those that are from those that aren't.

Answer capsule: A payment processor capable of handling call center volume should explicitly confirm underwriting experience with MCC 5966 or 5967, offer a virtual terminal with AVS and CVV capture, explain which PCI SAQ applies to the account environment (typically SAQ C-VT), and put rolling reserve terms in writing before signing. Month-to-month contract terms are achievable. Multi-year lock-ins with early termination fees are a negotiating mechanism, not a risk requirement.

Explicit MOTO underwriting experience. Ask whether the processor has directly underwritten 5966 or 5967 accounts, not whether they "work with high-risk merchants" generally. An ISO that routes all high-risk volume through a single banking partner and passes documentation requests through without reviewing them is not the same as one with direct underwriting experience in telemarketing MCCs.

Virtual terminal with AVS and CVV. Every call center taking card payments needs a virtual terminal that captures the billing ZIP code for Address Verification Service (AVS) and the CVV security code. These are fraud controls that reduce dispute rates and are standard MOTO best practices. A processor that doesn't require both is leaving the merchant exposed to disputes that could have been filtered.

PCI scope clarity. Your processor should confirm which SAQ applies to your environment (SAQ C-VT for virtual terminal is standard for most call centers) and whether their virtual terminal architecture keeps card numbers out of scope. If the processor doesn't know what DTMF masking is, that's a disqualifier.

Written reserve terms. Rolling reserves are standard for high-risk accounts. The terms should be in writing before signing: percentage held, holding period, release schedule, and the conditions under which reserves can be reduced or eliminated. Verbal reserve discussions are not enforceable.

Month-to-month contract terms. Multi-year processing contracts with early termination fees are not a requirement for high-risk merchant accounts. The processor's risk is managed through reserves and rate structure, not contract lock-in. A multi-year contract with ETFs is a pricing mechanism.

For MOTO processing options including interchange-plus pricing on high-risk volume, see ClickWerxs merchant accounts. If a standard processor has already declined your application, see high-risk merchant accounts and the full comparison of best high-risk merchant accounts.


Frequently Asked Questions

Can a call center with prior declines from other processors still get approved for a MOTO merchant account?

Yes. A prior decline from a standard processor is not a permanent disqualification for a MOTO merchant account. Standard processors often decline based on MCC code alone, without reviewing the underlying business. A high-risk processor that actively underwrites MOTO accounts will evaluate the full application: business model, chargeback history if any, refund policies, and call authorization procedures. Prior declines should be disclosed in the application. Concealing them and having the processor discover them during underwriting is a more common rejection reason than the underlying business issue the initial decline was based on.

What is a rolling reserve, and when does the money actually get released?

A rolling reserve is a percentage of settlement funds (typically 5–10%) withheld by the processor as a backstop against future chargebacks. It functions as a 90-to-180-day lag on a portion of settlement revenue: funds held from transactions in month one are released in month four or six as new transactions roll in. After 6–12 months of clean processing history (dispute rate consistently below thresholds), reserve percentages can typically be renegotiated down or eliminated. See rolling reserves explained for a full breakdown of how reserve terms work and what triggers early release.

Does MOTO processing require a separate merchant account from existing card-present processing?

For most call centers, yes. MOTO and card-present processing are typically held in separate merchant accounts because they have different MCC classifications, rate structures, and compliance requirements. Running MOTO volume through a card-present account creates MCC mismatch issues and violates account terms. Some processors offer combined accounts for merchants with both card-present and MOTO volume, but the MOTO portion must be explicitly disclosed and underwritten, not assumed to be covered under card-present terms.

How does the FTC Telemarketing Sales Rule affect payment authorization for phone orders?

The FTC Telemarketing Sales Rule (16 CFR Part 310) requires telemarketers to obtain express verifiable authorization before submitting billing information for sales made by phone: a clear verbal authorization captured during the call or a written authorization before charging. The October 2024 amendments (effective October 15, 2024) expanded recordkeeping requirements: sellers and telemarketers must now retain records for five years, up from two, including call records, authorization documentation, and consumer opt-out requests. (Federal Register, December 10, 2024.) This directly affects how call centers store and retrieve the authorization evidence that processors and card networks require during chargeback disputes.


ClickWerxs facilitates merchant account applications and provides ongoing account management as an authorized representative of our banking and processing partners. Approval, rates, and terms are determined by the issuing processor and acquiring bank. ClickWerxs does not guarantee approval for any merchant account application. Processing rates and fee structures cited in this post reflect publicly available industry data and general ranges; your actual rate depends on your industry, volume, and card mix. This post is not legal or financial advice. For a custom quote, see clickwerxs.com/payments/get-a-quote.



Kaleb Dickhaut — Founder, ClickWerxs. Kaleb built ClickWerxs from the ground up — from payment processing ISO to the Command Center platform to the AI SEO methodology the blog runs on. He has onboarded hundreds of small businesses onto payment and CRM systems. linkedin.com/in/kaleb-dickhaut


Sources

  1. Processing rates, fee ranges and effective-rate figures in this post are industry-typical ranges compiled from published network schedules and from accounts reviewed in the ClickWerxs ISO portfolio. They are not quoted rates. Interchange itself is set by Visa and Mastercard on published schedules that change twice yearly; your actual cost depends on card mix, MCC, ticket size and volume.
  2. PCI DSS — the Payment Card Industry Data Security Standard is maintained by the PCI Security Standards Council; current version and transition dates are published in the council's document library rather than on a single rate page. pcisecuritystandards.org
  3. Card network monitoring thresholds — Visa's Acquirer Monitoring Program (VAMP) replaced the Visa Dispute Monitoring Program and Visa Fraud Monitoring Program effective 1 April 2025 and measures fraud reports and disputes combined; the merchant Excessive threshold is 1.50% above a floor of 1,500 combined events per month as of 1 April 2026. Mastercard's Excessive Chargeback Merchant tier is 100 chargebacks and 150 basis points. Visa distributes VAMP terms through acquirer bulletins rather than a public page; confirm current thresholds with your acquirer.
  4. ClickWerxs ISO portfolio, aggregate observation — patterns described from merchant accounts under ClickWerxs management. Anonymized and reported in aggregate; individual account terms vary. Operator data.

ClickWerxs facilitates merchant account applications and provides ongoing account management as an authorized representative of our banking and processing partners. Approval, rates, and terms are determined by the issuing processor and acquiring bank — ClickWerxs does not guarantee approval for any merchant account application. Processing rates and fee structures cited in this post reflect publicly available industry data and general ranges; your actual rate depends on your industry, volume, and card mix. This post is not legal or financial advice. For a custom quote, see clickwerxs.com/payments/get-a-quote.

Ready to Stop Overpaying on Payment Processing?

Get a free rate comparison and see how much you can save with interchange-plus pricing.