Ready to get started?
Easily integrate next-generation payments and financial data into any app. Build powerful products your customers love.
Taking payments over the phone has been standard practice for UK businesses for decades. A customer calls, reads out their card number, expiry date, and CVV, and the business keys it in manually. It works, in the sense that money changes hands. But card on file vs MOTO payments is not really a close comparison when you look at the risk involved on both sides.
MOTO (Mail Order/Telephone Order) payments carry a level of exposure that many businesses have simply accepted as the cost of doing things the old way. That exposure is no longer necessary. Here is why card on file is the more secure, more compliant, and more customer-friendly alternative.
The problem with MOTO payments
MOTO transactions are card-not-present payments with no chip-and-PIN, no biometric verification, and no Strong Customer Authentication under PSD2. A fraudster with a stolen card number can use it over the phone as easily as the genuine cardholder.
The consequences fall on the merchant. Because MOTO transactions are exempt from SCA, disputed payments are typically the business’s liability rather than the bank’s. According to UK Finance’s Annual Fraud Report, remote purchase fraud saw losses increase 11% to just under £400 million in 2024, with case numbers up 22%. This is the category MOTO falls under. When a chargeback occurs on a MOTO payment, it is almost always the business that absorbs the cost.
There is also the data handling issue. When a customer reads out their card details, those details have to be processed somehow. Staff members who write them down, enter them into a spreadsheet, or store them temporarily in any form are handling sensitive financial data in ways that fall short of GDPR and PCI-DSS requirements. Even with the best intentions, manual handling of card data creates compliance risk.
How card on file works differently
Card on file removes the manual handling entirely. The customer saves their card details once through a secure payment platform, verified with a one-time passcode. Future charges are made against that stored card without any card data passing through staff hands at any point. The customer consents explicitly to the arrangement, the data is stored within the payment provider’s secure infrastructure, and the business charges when needed.
Every payment made this way is tied to a specific customer who has actively authorised the arrangement. That is a fundamentally different risk profile to a MOTO transaction, where the business has no way to verify that the person calling is the genuine cardholder.
Card on file vs MOTO: a direct comparison
| Factor | MOTO payments | Card on file |
|---|---|---|
Customer verification | None; caller identity unverified | OTP verified at setup |
SCA compliance | Exempt from SCA; higher merchant liability | Customer-authorised at point of consent |
Chargeback risk | High. Merchant typically liable | Low. Customer consent on record |
Data handling | Card details handled manually by staff | Stored securely within payment platform |
GDPR and PCI-DSS | Manual handling creates compliance gaps | Data handled entirely by secure platform |
Customer experience | Reads out card details every time | Saved once, charged seamlessly |
Staff involvement | Staff must manually enter card data | No staff contact with card data |
Which businesses should make the switch
Any business currently taking card details over the phone for repeat or recurring payments is a candidate for card on file. This includes law firms managing retainer billing, private clinics charging for treatment packages, accountants billing on monthly retainers, and service businesses with regular clients. In all of these cases, card on file replaces the MOTO process with something that is safer for the business, cleaner from a compliance perspective, and more convenient for the customer.
Card on file vs MOTO payments is not really a debate about preference. It is a question of whether the risks that come with MOTO are worth carrying. This includes fraud exposure, chargeback liability, and data handling obligations. Especially when a more secure alternative exists. For most UK businesses, they are not.
How Atoa handles this
Atoa has taken the decision to disable MOTO card payments across its platform, guiding merchants towards safer alternatives instead. For businesses that previously relied on MOTO for repeat payments, Atoa’s card on file feature covers the same use cases without the associated risk. The customer saves their card once, the business charges when needed, and no card data is ever handled manually. Card on file is available to Atoa businesses with card payments enabled on their account.
Frequently asked Questions
What is a chargeback?
A chargeback is a forced reversal of a card payment, raised when a customer disputes a transaction with their bank. The funds are taken back from the merchant, often with an added fee, and repeated chargebacks can harm a business’s standing with its processor. On MOTO payments the merchant is usually liable, because the transaction lacks Strong Customer Authentication.
When is Strong Customer Authentication required?
Strong Customer Authentication is required for most electronic card payments and account access under PSD2 in the UK and EU, using two independent factors such as a passcode and a biometric check. Certain payments, such as MOTO transactions, are exempt, which is what removes a key layer of protection and shifts liability to the merchant. Card on file records explicit customer consent at setup, giving a stronger position than an SCA-exempt MOTO payment.
How can businesses avoid chargebacks?
Businesses can avoid chargebacks by using authenticated payment methods that put verification with the customer and their bank. Pay by Bank has no chargebacks because each payment is approved in the customer’s banking app with Strong Customer Authentication, and card on file records consent at setup rather than relying on details read out by phone. Moving away from MOTO removes the highest-liability transactions.
What is tokenisation in payments?
Tokenisation replaces sensitive card details with a unique token that has no value if intercepted. The real card data is held securely within the payment provider’s infrastructure, so future charges use the token rather than the raw card number. This is how card on file stores a card safely, keeping card data out of staff hands entirely.
Why is card on file safer than MOTO?
Card on file is safer than MOTO because the card is saved once through a secure platform, verified with a one-time passcode, and charged later with recorded consent, so no card data passes through staff hands. MOTO relies on staff keying in details read out by phone, with no authentication and merchant liability for disputes. Atoa has disabled MOTO card payments and offers card on file to cover the same repeat-billing use cases with less risk.