13.2 Credit Card Security & Electronic Payment Controls

Key Takeaways

  • AIPB's credit-card lesson covers schemes that exploit lost or stolen cards, spotting counterfeit card-brand plastic, and recommended rules for company credit cards; computer and internet fraud covers passwords, laptops, wireless, remote access, and types of internet crime.
  • PCI DSS is the Payment Card Industry Data Security Standard from the PCI Security Standards Council and the card brands. It is not an AIPB rule. Do not store full primary account numbers in the clear or card verification values after authorization; tokenization replaces the PAN with a surrogate the bookkeeper can store.
  • Card-not-present fraud uses a number without the plastic; skimming copies a magstripe or inserts a reader on a terminal. Neither is fixed by a fidelity bond or by check positive pay.
  • ACH and wire callbacks must use a phone number independently verified from the vendor master, original W-9, or a known directory—not the number printed in a changed-invoice email or PDF.
  • Phishing, look-alike invoice PDFs, and remote-access tech-support scams are internet crimes a bookkeeper must refuse: no password sharing, no unsolicited remote software, no gift-card payment of a 'past-due invoice.'
Last updated: September 2026

Why cards and electronic payments are a bookkeeper skill

AIPB's internal-controls workbook next names credit card fraud: schemes that exploit lost or stolen cards, how to spot a counterfeit Visa, Mastercard, or American Express card, and recommended rules for company credit cards. A later workbook section is computer and internet fraud: password, laptop, wireless, and remote-access security, and types of internet crime. This independent OpenExamPrep section covers both, because the bookkeeper who pays Arctic Parts by ACH, books a card sale at the counter, and clicks a PDF invoice sits on all three rails. Chapter 12's fidelity bond and imprest petty cash do not tokenize a PAN. Check positive pay (Section 13.1) does not see a wire.

Maple Ridge takes cards at the counter for walk-in filter sales, issues two company cards (Pat and the operations manager), and pays most vendors by ACH or wire once the invoice is approved. Jordan is the person who downloads the card statement, initiates ACH, and opens invoice email. That is custody of payment credentials even when Jordan never holds a $20 bill.

Lost, stolen, and counterfeit cards

AIPB asks you to prevent or spot schemes that use lost or stolen cards and to spot counterfeit brand plastic. You do not need a secret list of "exactly ten named tricks" to think like a bookkeeper. You need the pattern: the thief has the plastic, the number, or a clone, and the merchant or issuer has not yet blocked it.

SchemeWhat happensMaple Ridge control
Use before reportedStolen company card buys $1,140 of tools the same afternoonReport loss immediately; issuer liability windows start when you notify
Card-not-present (CNP)Thief has the number and expiration, not the card; phones in a $890 "rush order"Documented CNP process, AVS/CVV where the processor offers them, no order from a stranger who "has the owner's card"
SkimmingOverlay or inside reader copies the magstripe (and sometimes the PIN) on Maple Ridge's terminalInspect the terminal daily, use chip/tap, call the processor on a known number if the device looks altered
Cloned / counterfeit plasticStolen data encoded on fake stockChip preference; staff training on holograms, UV, signature panel, and shoddy printing; still not a guarantee against chip fraud
Mail interceptNew or replacement card stolen from the shop mailboxCards mailed to a locked address; activate only after Pat confirms
Account takeoverPhish of the issuer login; shipping address changedMFA on issuer portals; alerts on address and limit changes
Collusive clerkEmployee keys extra charges or skims while "helping"SOD at the register (Chapter 12); independent review of voids and tips
Cash-advance drainStolen card pulls cashBlock cash advances on company cards unless Pat authorizes them in writing

Spotting counterfeit plastic (practical, not magic). Brand cards carry holograms or moving portraits, ultraviolet marks, a signature panel that should not be taped over, and—on current U.S. consumer and commercial stock—an EMV chip. Uneven type, a wrong BIN range for the brand, a "new" card with the CVV already scratched, or magstripe-only stock offered as a brand-new corporate card are red flags. Chip fraud and CNP fraud will not always show on the face of the plastic. Training staff to look still catches crude counterfeits that AIPB's "spot a counterfeit Visa, Mastercard, or American Express card" language is aimed at.

Card-not-present versus skimming. CNP is no plastic in sight: e-commerce, pay-by-link, or a phone order. The bookkeeper risk is completing a sale or a vendor payment on a number typed from an email. Skimming is physical capture at a terminal or ATM. The bookkeeper risk is a tampered reader on the counter, or an employee who palms a skimmer. Do not mash the two names together on an exam item.

Recommended rules for company credit cards

AIPB's public outline includes recommended rules for company credit cards. Translate them into a one-page policy Pat actually signs.

RuleWhy it existsMaple Ridge application
Named cardholder onlyShared cards destroy audit trailsPat's card is Pat's; the operations manager's card is not "the shop card in the drawer"
Written dollar and MCC limitsLost-card damage is a function of the limitHardware-store MCC allowed; cash advance and jewelry MCC blocked
Itemized receipts, same weekStatement-only review misses personal chargesJordan matches receipts to the $1,140 statement line; missing receipt is a Pat conversation, not a silent book
Independent statement reviewThe cardholder must not be the only reviewerDana or Pat reviews Jordan's coding; Jordan does not "approve" Pat's personal Amazon
No personal charges, or a documented reimbursement pathMixing personal spend is how statements become unreadablePersonal charges are forbidden; if one slips, reimburse that week
Immediate loss reportingIssuer rules and commercial-card agreements are unforgivingPhone the number on the back of the last statement, not a number in a phishing SMS
Collect the card at terminationA fired manager with a live card is an open checkSame-day cutoff, like payroll in Section 13.1
No card numbers in email or chatCNP and phishing start with a typed PANProcessors and virtual cards; never "reply with the CVV"

Worked statement: the operations manager's card shows $1,140 at a tool warehouse 90 miles away on a Sunday. No job ticket. No receipt. That is not "maybe job stock." It is a lost, stolen, or personal-use flag until proven otherwise. Jordan does not recode it to Shop Supplies to make the month close.

PCI DSS is a card-brand standard, not an AIPB rule

The Payment Card Industry Data Security Standard (PCI DSS) is published by the PCI Security Standards Council, created by the major card brands. It sets a baseline for entities that store, process, or transmit cardholder data or that can affect the cardholder data environment. AIPB did not write PCI DSS. The CB exam owner is AIPB. PCI DSS is still the standard a merchant's processor and acquirer will point to when Maple Ridge takes cards. Do not answer a CB item with "PCI DSS is an AIPB internal-control rule," and do not answer a processor questionnaire with "AIPB said we can keep CVVs in Excel."

What a bookkeeper must not store. After authorization, sensitive authentication data—including card verification values (CVV2, CVC2, CID) and full magstripe/track data—must not be stored. The primary account number (PAN) may be stored only if it is rendered unreadable (strong encryption, truncation, hashing, or tokenization). A spreadsheet titled cards-for-refunds.xlsx with full 16-digit numbers and CVVs is a control failure and a PCI problem. Write the last four digits plus a processor token if you must research a chargeback.

Tokenization replaces the PAN with a surrogate token that is useless on another merchant's terminal. Jordan stores the token and the last four digits. Refunds go through the processor. Tokenization is not "we printed extra copies of the magstripe." It is not an AIPB-authored standard; it is how processors shrink the cardholder data environment.

If Maple Ridge uses a point-to-point encrypted terminal and never sees a PAN, Jordan still must not handwrite full card numbers on paper invoices "in case they come back." Paper is storage.

ACH and wire callbacks on independently verified numbers

Electronic credits are the new check stock. A changed-invoice email is the new washed payee.

The rule: before you change a vendor's bank routing and account, or before you release a wire or a first-time ACH above a threshold, call the vendor using a phone number from an independent source: the vendor master created at onboarding, the original Form W-9 packet, a signed contract, or a directory number you looked up—not the letterhead, footer, or signature block of the email that asked for the change.

Worked item: Arctic Parts sends a PDF, Invoice_7791_updated.pdf, from ap-arcticparts@gmail.com (their real domain is different). The PDF moves $8,640 to a new account at a bank Arctic has never used. The PDF's footer has a "confirm at 555-0147" number. Jordan's wrong move is to call 555-0147 or to reply in-thread "please confirm." Jordan's right move is to call the 603-555-0199 number sitting on the 2024 W-9 and vendor file, ask for accounts receivable by name, and dual-approve any change with Pat. Section 13.3 repeats this as a vendor-master control; here it is a payment-rail control.

ACH origination SOD. The person who adds a payee in the bank portal is not the only person who releases a $8,640 payment. Dual approval in the portal is electronic dual signatures (Chapter 12). Callbacks sit on top of that SOD; they do not replace it.

Wires. Same callback. Same dual approval. Wires are faster to lose and harder to reverse than ACH. Treat any urgency ("fund today or the shipment dies") as a fraud signal, not as a reason to skip the call.

Computer and internet fraud the bookkeeper actually sees

AIPB's computer/internet section is password, laptop, wireless, and remote-access security, plus types of internet crime. Translate that into the shop:

Passwords and MFA. Unique passwords; a password manager; multi-factor authentication on banking, payroll, email, and the accounting file. No shared "QuickBooks" password on a sticky note. Chapter 12.3 already treated refusing to share passwords as a theft red flag; here the issue is credential theft by outsiders as well as insiders.

Laptops. Disk encryption, auto-lock, no customer lists on an unencrypted USB stick, no bookkeeping file in an unlocked van overnight. A stolen laptop with a live bank cookie is a payment incident, not only an IT incident.

Wireless. The shop guest Wi-Fi is not the network that reaches the bank portal. Home routers used for night work need a password that is not the manufacturer's default. Public café Wi-Fi plus the bank site is how session theft happens.

Remote access. Unsolicited "Microsoft," "QuickBooks support," or "your bank" callers who want AnyDesk, TeamViewer, or ScreenConnect installed are a remote-access scam. They will open the bank site while Jordan watches, or they will demand gift cards to "unlock" a fake invoice. Refuse. Hang up. Call IT or the software vendor on the number you already have. AIPB's "implement remote access security" is this refusal plus who is allowed to use a known remote tool, with logging.

Phishing. Look-alike domains (mapleridge-hvac-billing.com), urgency, a logo, and a link to a fake portal. Jordan does not click; Jordan opens the bank site by typing the address or using a bookmark.

Fake invoice PDFs. A PDF can carry a look-alike invoice, a malware dropper, or both. Treat unexpected attachments as hostile until the vendor confirms by callback. Macro-enabled "enable editing to view the PO" files are not invoices.

Worked remote-access con: a caller ID spoofed as Maple Ridge's processor says the terminal is "leaking card data" and will fine the shop $20,000 unless Jordan installs a tool and pays a "PCI reinstatement" with gift cards. That is not PCI DSS. PCI DSS does not collect Apple gift cards. Hang up. Call the processor using the number on the merchant statement.

Bookkeeper dos and don'ts for cards and e-payments

DoDon't
Store tokens and last four digits, never full PAN + CVVKeep cards-for-refunds.xlsx
Inspect the POS terminal for skimmers; prefer chip/tapIgnore a loose overlay because "the weekend kid set it up"
Review company-card statements against receipts, independentlyRecode unexplained $1,140 as shop supplies to close the month
Callback wires/ACH/bank-detail changes on a known numberCall the number inside the changed PDF
MFA on bank, payroll, email, and booksShare the bank password with "the owner is in a meeting" callers
Refuse unsolicited remote access and gift-card invoicesLet "Microsoft support" drive the laptop
Report a lost company card the same hourWait to see if it "shows up in the van"

Exam traps: (1) calling PCI DSS an AIPB-authored rule; (2) storing CVV "just for refunds"; (3) treating a callback to the number in the suspicious email as verification; (4) assuming check positive pay covers wires; (5) paying a processor "fine" with gift cards; (6) rewriting fidelity bonds or petty cash as the card answer; (7) claiming this independent guide is approved by a card brand or by AIPB.

Loading diagram...
ACH and wire callback: independently verified number versus the email
Test Your Knowledge

Which statement about PCI DSS and stored card data is correct for a bookkeeper?

A
B
C
D
Test Your Knowledge

Arctic Parts emails a PDF invoice that lists new wire instructions and a phone number in the footer. What should Jordan do before sending $8,640?

A
B
C
D
Test Your Knowledge

A caller claiming to be Microsoft support wants remote-access software installed and then asks Jordan to buy gift cards to clear a 'PCI fine.' What is this, and what should Jordan do?

A
B
C
D