Payment protection rules can be clear in principle and costly at the boundary.
Blocking compromised use and preserving legitimate sales can require different interpretations of the same transaction signals.
Who you’d be doing this for
“I can’t explain a decline to someone when their card worked everywhere else.”
Soojin Yamamoto · Independent café owner
Runs a high-turnover café where every declined card can mean a lost sale and an awkward customer interaction.
What is at stake
The card network now makes terminals reject a new class of compromised credentials, and the proposed rules disagree on how many good sales get declined. You pick the boundary and prove it, because the change cannot be undone.
Why it isn’t already fixed
Every obvious fix costs something else. That’s the part you’d have to decide.
- fraud interception vs. legitimate approval rate
- fixed compliance deadline vs. exhaustive verification
- centralized control vs. terminal-context precision
- machine-ranked evidence vs. human-reviewed policy
Why SumUp
At SumUp, these decisions often matter because a false decline is immediate for a merchant, while a missed control can threaten acceptance continuity.
Written with these in mind
Not your kind of problem? 9 more at SumUp, or browse every organization.
This is the setup. The work is inside.
Running it puts you in the room: the full situation and its constraints, stakeholders who push back in their own words, and the decisions that are yours to make. What you produce becomes a Day One Plan — work you can show someone instead of describing.