Meaning
Local device logic evaluates various transaction factors to decide whether to process a payment offline, send it for online authorization or decline it. Performing terminal risk management involves checking the card’s internal security settings and the merchant’s predefined rules at the point of sale. This process occurs before the terminal attempts to communicate with the bank, providing a first line of defense against fraud.
It balances the need for fast transaction times with the requirement for secure payment processing.
Decision Logic
Analysis includes checking the card’s expiration date, the transaction amount, the card type and the country code to identify potential red flags. If the card has been used too many times offline, the terminal risk management logic will force an online connection to reset the counters. These checks also verify if the card is on a local exception list of known lost or stolen accounts.
The outcome of these tests determines the next step in the emv transaction flow.
Configuration Control
Acquirers provide the specific risk settings to the terminal during the initial setup and through periodic remote updates. By adjusting these settings, a merchant can tailor the terminal risk management behavior to suit their specific business environment. High-risk environments might require more frequent online checks, while low-risk settings favor speed and offline acceptance.
These configurations are part of the broader agreement between the merchant and the payment service provider. Changes to these parameters are transmitted to the hardware during a terminal management system heartbeat.
Performance Outcome
Results of the local evaluation are passed to the card. Accurate configuration ensures that legitimate customers are not inconvenienced while maintaining high security standards.