6 min read

In this article, you’ll learn:

  • Why PCI matters beyond compliance and regulation.
  • What businesses often misunderstand about handling card payments.
  • The real risks of taking payments over the phone.
  • What a secure, compliant approach looks like in practice.
  • How partners can turn PCI into a meaningful revenue opportunity.

PCI often gets framed as a regulatory obligation. But for most UK businesses, especially those taking payments over the phone, the reality is far more commercial.

UK credit card fraud now stands at £572 million. It’s an extraordinary number, but it also reflects how easily everyday processes expose businesses to risk.

Andy Herring (Commercial and Strategy Product Manager) sat down with Ed Savory (Channel Head – South East) to explore the practicalities behind PCI. While it’s easy to focus on the ‘fear aspect of PCI’, a shift in thinking is critical.

PCI matters more than just avoiding fines. It’s about protecting revenue and improving how transactions are handled day-to-day. For small businesses, having that protection is crucial when looking to build towards success.

What do businesses often get wrong about PCI?

Many businesses assume PCI only applies to large financial organisations. But that’s far from how the standard works.

Andy highlights how the PCI regulations ‘don’t care about size.’ Compliance is still compliance, regardless of whether it’s a two-person florist or multi-national financial organisation.

Any business that takes card payments over the phone must comply. Nobody should look at PCI and think ‘we’re too small to be at risk’, or that pause and resume makes a business compliant.

For Ed, there are companies already doing PCI who ‘might not know it as PCI.’  The result is a gap between perceived compliance and actual compliance. That’s where risk builds up.

What are the real risks of taking payments over the phone?

Most businesses underestimate how exposed traditional phone payments are.

Think about the typical process. Customers read their card details aloud, with agents then repeating or writing them down. Those calls may also be recorded to assist with other regulatory processes or training scenarios.

As Ed explains, a process like that introduces risk. What happens to that piece of paper? Who else is listening to the conversation?

In terms of key risk areas, they’re easy to pick out. Chargebacks, for example, can typically cost an SMB £65. For these smaller businesses, that impact quickly compounds.

Operational costs can also build up over time. Handling disputes involve staff time, bank engagement, and customer complaints themselves. These are the unseen costs away from revenue and outright expenses.

It’s the ‘lost revenue aspect’ of a failed transaction that should be considered as well. Again, smaller businesses require the right processes in place to better protect revenue. Larger businesses can absorb missed revenue opportunities, while smaller businesses will struggle.

The most serious risk is the potential loss of merchant services as part of those potential PCI fines. ‘Being unable to take those payments’, as Ed says, can put SMBs at risk. While nobody wants to ‘[instil] the fear factor’ around PCI, losing those services is ‘the main reason why [SMBs] should consider this.’

Which UK sectors are most exposed?

Any business taking payments over the phone is in scope. Some sectors are, however, more reliant on it than others.

According to Ed, these key industries include:

  • Retail, including high street shops and smaller businesses.
  • Hospitality, such as restaurants, hotels and even takeaways.
  • Automotive companies.
  • Service-based businesses, like skip hire or tradesmen.

What’s the common factor here? It’s the phone-based transactions that are part of the customer journey. These businesses are often smaller, making the financial impact greater.

What does a secure, compliant approach look like?

A modern PCI solution removes the risk from the process entirely.

Ed summarises how it’s all about making something ‘simple [and] secure.’ Staff shouldn’t have to handle card details over the phone.

In practice, that means:

  • Customers enter their card details via keypad and are never spoken aloud.
  • Sensitive tones are removed from the call.
  • Agents never see full card details.
  • Call recordings stay compliant.

Andy explains how this works technically in the iPECS platform. A specific PCI trunk runs through the service, with all the DTMF tones stripped out of the data stream.

The aim is to ‘[inject] silence into the call.’ Even if someone is saying the numbers aloud while typing them, that’s not being captured.

Through iPECS, businesses can secure their transactions and make sure recordings are compliant. There are no concerns about interrupting the call flow either.

Why is PCI a strategic decision?

For many SMBs, PCI is better understood as risk management.

Andy frames it as ‘almost like an insurance… you’re protecting yourself from those chargebacks.’ PCI is then reframed from being a cost burden into a predictable, fixed-cost safeguard.

For smaller organisations, that shift is powerful. For partners, it becomes a strategic conversation.

Ed mentions how partners need to position themselves as a ‘trusted advisor.’ They need to understand the importance of these merchant services and making solutions ‘more compliant.’ From there, it ‘eliminates the risks’ for these smaller businesses.

When partners have these conversations, they can:

  • Create stronger customer relationships by moving from supplier to advisor, helping secure that long-term retention.
  • Open new revenue streams, ‘boost the value of a new sale’, and install base growth by selling more services into customers.
  • Gives businesses a market differentiator with a proposition that moves beyond price-based selling.

All this fits within the channel-first model Gamma operates. Long-term value arises from expansive, deeper services as opposed to one-off sales.

PCI shouldn’t be treated as a compliance box to tick. When done properly, it reduces fraud risk while protecting revenue and improving customer trust. That kind of compliance creates meaningful commercial opportunities for partners.

As Ed says, ‘it’s not a compliance burden… it’s a practical improvement to how they do things today.’

Quick Answers: What PCI Means for UK Businesses Taking Payments Over the Phone

What is PCI compliance?

PCI compliance allows businesses to securely handle card payments, particularly protecting sensitive cardholder data during transactions.

Does PCI apply to small businesses?

Yes, as PCI regulations are applicable to businesses of all sizes and sectors.

Why is taking card payments over the phone risky?

Card details can be overheard, recorded, written down, or stored insecurely, increasing exposure to fraud and disputes.

What are chargebacks and why do they matter?

Chargebacks occur when a customer disputes a transaction, costing businesses money and time to resolve.

What should a secure payment process look like?

Customers should enter card details securely (e.g. via keypad), with no exposure to staff or call recordings.

Keep SMBs safe from fraud

Learn more about how Gamma can support partners with a PCI-compliant solution like iPECS that unlock new value