Secure Payments for Contact Centres
A practical guide for contact centre managers navigating PCI compliance. Covers agent payment workflows, the conflict between call recording and PCI DSS, compliance for remote and hybrid agents, and integration with existing telephony systems.
What you'll learn
- Agent payment workflow best practices for PCI compliance
- How to handle the call recording vs PCI DSS conflict
- Compliance strategies for remote and hybrid contact centre agents
- Integration options for existing telephony and CRM systems
PDF · 11 pages · 16 min read
Trusted by banks, law firms, and regulated businesses worldwide.
If a customer reads their 16-digit card number out loud and an agent types it into a CRM, you've just turned every desktop, headset, recording server and screen-share session in your contact centre into part of your cardholder data environment. That's the worst place to be. Your PCI scope balloons, your audit gets longer and more expensive, and one phished agent or a misconfigured call recorder can turn into a notifiable breach.
The whole job of a modern contact centre payment design is to stop card data ever reaching that environment in the first place. This guide covers how that's done, what the options actually cost you, and what to ask before you buy.
What PCI DSS actually asks of you
Most people arrive at this problem thinking PCI compliance is a checklist. It isn't. What you complete is a Self-Assessment Questionnaire, and which one you get depends entirely on how card data moves through your business.
That distinction is the whole game. If agents hear, see or type card numbers, you're looking at SAQ D — several hundred questions, annual evidence gathering, and a cardholder data environment that includes your telephony, your desktops and your call recordings. If card data never touches your systems because it's captured somewhere else entirely, you're looking at SAQ A: a fraction of the questions, and a scope that stops at your front door.
Nobody moves from D to A by writing policies. You move by changing where the card data goes. That's what de-scoping means, and it's the only reliable way to make contact centre payments cheap to run year after year.
If you want to know which SAQ you'd actually land on, our free Comply app walks you through it in a few minutes rather than a few weeks.
Four ways to take a card payment without breaking scope
Most guides in this category describe three approaches. There are four, and the one that usually gets left out is the one that suits multi-site and outsourced operations best.
Pause and resume
The agent pauses call recording while the customer reads their card number aloud, then resumes afterwards. It's the cheapest thing to implement and the weakest thing to rely on. The agent still hears the card number. The desktop is still in scope. And the control depends on a human remembering to press a button on every single call, which is exactly the kind of control an assessor will probe and exactly the kind that fails under pressure on a busy Friday afternoon.
Pause and resume solves a recording problem. It doesn't solve a scope problem.
DTMF masking
The customer types their card number on their phone keypad instead of speaking it. The tones are masked so the agent hears flat monotone, and the digits route to the payment platform rather than into the call. The agent stays on the line throughout, so the conversation never breaks and the customer never gets handed to a robot mid-sentence.
This is the workhorse. It keeps card data out of the agent's ears, off their screen and out of the recording, and it's where most contact centres should start. See how DTMF masking works for the mechanics.
Channel separation
Card data travels on a completely separate path from the voice call, rather than being stripped out of it. The voice channel carries conversation and nothing else, so there's no masking to configure, no tones to suppress, and no dependency on the telephony vendor handling DTMF correctly at every hop.
It matters most where the telephony estate is complicated — multiple carriers, multiple sites, homeworkers on varying connections, or a softphone stack you don't fully control. If DTMF masking has ever behaved inconsistently across your estate, channel separation is why it's worth a look.
AI and automated capture
The customer completes payment inside an automated flow: an IVR, a voice assistant, or an AI agent handling the call end to end. No human hears anything, and scope is minimal because there's no agent environment left to protect.
The trade-off is conversational. Automation handles routine payments well and struggles with anything needing judgement, so most operations run automated capture alongside agent-assisted rather than instead of it.
Comparing them honestly
| Approach | Agent hears card | Recording safe | Agent stays on call | Telephony dependency | Typical SAQ |
|---|---|---|---|---|---|
| Pause and resume | Yes | Partly | Yes | Low | D |
| DTMF masking | No | Yes | Yes | Medium | A |
| Channel separation | No | Yes | Yes | Low | A |
| AI / automated | No | Yes | No | Low | A |
The honest summary is that pause and resume is the only one of the four that leaves you where you started on scope. The other three all get you to SAQ A; which one fits depends on your telephony and how much of the conversation you want to keep.
Nine things worth evaluating
Once you've picked an approach, most of the difference between suppliers shows up in these nine areas.
Certification
Ask what the provider is certified as, not what they help you achieve. A PCI DSS Level 1 service provider has been assessed annually by a Qualified Security Assessor against the full standard. A vendor saying they're "PCI compliant" may only mean their own paperwork is in order. We've been Level 1 since 2016 and we publish the Attestation of Compliance.
Card capture quality
Card entry over a phone keypad fails in predictable ways: poor lines, mobile handsets, customers who mistype. Ask what happens on a failed digit, whether the customer can correct without restarting the whole payment, and what completion rates look like in practice rather than in a demo.
Gateway and acquirer support
You want your existing acquiring relationship to survive the project. We connect to Stripe, PayPal and Braintree, Adyen, Elavon, Lloyds Cardnet, NatWest Tyl, ACI Worldwide, BridgerPay and Acquired.com among others, so most people keep the rates they've already negotiated rather than starting that conversation again.
Channel coverage
Phone is where this starts and rarely where it ends. Payment links, SMS, web chat, QR codes and in-person capture all tend to arrive within a year of the first project. Buying a phone-only solution usually means buying again later.
Carrier requirements
Some approaches need your telephony provider to pass DTMF cleanly, or to support SIP trunking in a particular way. Establish this before procurement rather than during implementation. It's the single most common reason a project stalls.
Agent experience
If the flow adds thirty seconds to every call, your average handling time moves and your agents will find ways around it. Ask to watch a real call rather than a slide, and ask what the agent sees while the customer is typing.
Reporting and reconciliation
Finance needs transactions to match the acquirer's settlement file without manual work. This is the dull part and it's where most of the ongoing cost quietly sits.
Pricing model
Per-agent licensing punishes you for growing and for seasonal peaks. Per-transaction pricing tracks what you actually use. Neither is automatically better, but if your headcount swings through the year, per-agent will hurt. We've written separately on choosing between the two.
Implementation reality
Ask how long, who does what, and what happens if it doesn't work first time. A realistic answer is weeks rather than days, and it involves your telephony team more than your payments team.
If you're a BPO or outsourcer
Multi-tenant is a different problem, and most solutions in this space weren't designed for it.
You're taking payments on behalf of several clients, each with their own acquirer, their own merchant IDs, their own reconciliation requirements and their own compliance obligations. A platform built for a single merchant forces you into one of two bad options: run a separate instance per client and multiply your admin, or route everything through your own merchant account and become the merchant of record for business that isn't yours.
What you actually need is one platform where each client's payments route to that client's acquirer, reporting separates cleanly by tenant, and your PCI scope covers the routing rather than the card data. Ask any prospective supplier how they handle a client leaving. If the answer involves migrating other clients too, walk away.
Objections we hear, and what's behind them
Our agents will hate it. They usually don't, once they stop being the person responsible for a card number. The complaint that does land is handling time, which is why capture quality matters more than any other technical factor on the list above.
We already pause recording. That solves the recording problem and leaves the desktop, the headset and the agent's memory in scope. It's a control, not an architecture.
Our telephony provider says they handle it. Sometimes true. Ask specifically whether card data enters their platform at any point, and what their own certification covers. Plenty of telephony vendors mask tones without ever removing themselves from scope.
We'll do it after the audit. The audit is cheaper and shorter after de-scoping. Doing it in this order means paying for a full assessment cycle you didn't need.
Questions we get asked
Does DTMF masking take me to SAQ A on its own? Usually, provided card data never reaches your environment at any point in the flow. The detail that catches people out is call recording and screen capture — if either can capture card data in an edge case, you're not there yet.
What happens if the customer can't use their keypad? You need a fallback that doesn't collapse back to reading digits aloud. A payment link sent by SMS during the call is the usual answer.
How long does implementation take? Weeks rather than months for a standard setup, and the long pole is nearly always telephony configuration rather than the payment platform itself.
Can remote and homeworking agents use this? Yes, and it's one of the stronger arguments for it. Once card data never reaches the agent, where the agent sits stops being a compliance question.
Does this work for collections and arrears? Yes, with a specific benefit: capture works the same whether the customer pays in full, part-pays, or sets up a plan, so agents don't switch tools mid-conversation.
What about the acquirer we already use? Most likely supported. The point of the platform is that it sits between your contact centre and whichever acquirer you've already chosen.
Where to go next
If you're working out which approach fits, agent-assisted payments is the usual starting point and our contact centre page covers the sector detail. If you're earlier than that and just need to know which questionnaire applies to you, start with the free Comply app.
Related Compliance 101 Guides
Related Glossary Terms
Ready to simplify your PCI compliance?
Book a personalised demo and we'll show you how Paytia can descope your telephone payment environment.
Trusted by law firms, insurers, healthcare providers and regulated businesses worldwide. Learn more about Paytia