Sign up (7-day free trial)
thumbnail_image

Card on File Payments: A Safer Alternative to MOTO

✨ Quick Summary

Card on file payments store a customer's card securely after one-time passcode verification, letting a business charge it again with recorded consent. For UK firms this is safer than MOTO, where staff key in details read out by phone, because it cuts fraud, chargeback and data-handling risk. Atoa has disabled MOTO card payments and offers card on file instead.
Anisha Suvarna

By Anisha Suvarna

25 May 2026

  • 10 min read

Taking payments over the phone has been standard practice for UK businesses for decades. A customer calls, reads out their card number, expiry date, and CVV, and the business keys it in manually. It works, in the sense that money changes hands. But card on file vs MOTO payments is not really a close comparison when you look at the risk involved on both sides.

MOTO (Mail Order/Telephone Order) payments carry a level of exposure that many businesses have simply accepted as the cost of doing things the old way. That exposure is no longer necessary. Here is why card on file is the more secure, more compliant, and more customer-friendly alternative.

The problem with MOTO payments

MOTO transactions are card-not-present payments with no chip-and-PIN, no biometric verification, and no Strong Customer Authentication under PSD2. A fraudster with a stolen card number can use it over the phone as easily as the genuine cardholder.

The consequences fall on the merchant. Because MOTO transactions are exempt from SCA, disputed payments are typically the business’s liability rather than the bank’s. According to UK Finance’s Annual Fraud Report, remote purchase fraud saw losses increase 11% to just under £400 million in 2024, with case numbers up 22%. This is the category MOTO falls under. When a chargeback occurs on a MOTO payment, it is almost always the business that absorbs the cost.

There is also the data handling issue. When a customer reads out their card details, those details have to be processed somehow. Staff members who write them down, enter them into a spreadsheet, or store them temporarily in any form are handling sensitive financial data in ways that fall short of GDPR and PCI-DSS requirements. Even with the best intentions, manual handling of card data creates compliance risk.

How card on file works differently

Card on file removes the manual handling entirely. The customer saves their card details once through a secure payment platform, verified with a one-time passcode. Future charges are made against that stored card without any card data passing through staff hands at any point. The customer consents explicitly to the arrangement, the data is stored within the payment provider’s secure infrastructure, and the business charges when needed.

Every payment made this way is tied to a specific customer who has actively authorised the arrangement. That is a fundamentally different risk profile to a MOTO transaction, where the business has no way to verify that the person calling is the genuine cardholder.

Card on file vs MOTO: a direct comparison

FactorMOTO paymentsCard on file

Customer verification
None; caller identity unverifiedOTP verified at setup

SCA compliance
Exempt from SCA; higher merchant liabilityCustomer-authorised at point of consent

Chargeback risk
High. Merchant typically liableLow. Customer consent on record

Data handling
Card details handled manually by staffStored securely within payment platform

GDPR and PCI-DSS
Manual handling creates compliance gapsData handled entirely by secure platform

Customer experience
Reads out card details every timeSaved once, charged seamlessly

Staff involvement
Staff must manually enter card dataNo staff contact with card data

Which businesses should make the switch

Any business currently taking card details over the phone for repeat or recurring payments is a candidate for card on file. This includes law firms managing retainer billing, private clinics charging for treatment packages, accountants billing on monthly retainers, and service businesses with regular clients. In all of these cases, card on file replaces the MOTO process with something that is safer for the business, cleaner from a compliance perspective, and more convenient for the customer.

Card on file vs MOTO payments is not really a debate about preference. It is a question of whether the risks that come with MOTO are worth carrying. This includes fraud exposure, chargeback liability, and data handling obligations. Especially when a more secure alternative exists. For most UK businesses, they are not.

How Atoa handles this

Atoa has taken the decision to disable MOTO card payments across its platform, guiding merchants towards safer alternatives instead. For businesses that previously relied on MOTO for repeat payments, Atoa’s card on file feature covers the same use cases without the associated risk. The customer saves their card once, the business charges when needed, and no card data is ever handled manually. Card on file is available to Atoa businesses with card payments enabled on their account.

Frequently asked Questions

What is a chargeback?

A chargeback is a forced reversal of a card payment, raised when a customer disputes a transaction with their bank. The funds are taken back from the merchant, often with an added fee, and repeated chargebacks can harm a business’s standing with its processor. On MOTO payments the merchant is usually liable, because the transaction lacks Strong Customer Authentication.

When is Strong Customer Authentication required?

Strong Customer Authentication is required for most electronic card payments and account access under PSD2 in the UK and EU, using two independent factors such as a passcode and a biometric check. Certain payments, such as MOTO transactions, are exempt, which is what removes a key layer of protection and shifts liability to the merchant. Card on file records explicit customer consent at setup, giving a stronger position than an SCA-exempt MOTO payment.

How can businesses avoid chargebacks?

Businesses can avoid chargebacks by using authenticated payment methods that put verification with the customer and their bank. Pay by Bank has no chargebacks because each payment is approved in the customer’s banking app with Strong Customer Authentication, and card on file records consent at setup rather than relying on details read out by phone. Moving away from MOTO removes the highest-liability transactions.

What is tokenisation in payments?

Tokenisation replaces sensitive card details with a unique token that has no value if intercepted. The real card data is held securely within the payment provider’s infrastructure, so future charges use the token rather than the raw card number. This is how card on file stores a card safely, keeping card data out of staff hands entirely.

Why is card on file safer than MOTO?

Card on file is safer than MOTO because the card is saved once through a secure platform, verified with a one-time passcode, and charged later with recorded consent, so no card data passes through staff hands. MOTO relies on staff keying in details read out by phone, with no authentication and merchant liability for disputes. Atoa has disabled MOTO card payments and offers card on file to cover the same repeat-billing use cases with less risk.