A source-checked field guide. The linked primary sources were reviewed for the explanations in this note. Provider examples are not universal terms. This is a local editorial preview, not individualized advice; publication review remains pending.

A small business is ready to accept payments when it can take an order, recognize the money’s state, fulfill or return it, protect access, and explain every adjustment. Turning on a terminal or hosted page is only one step. Use this checklist to conduct a launch review with operations, finance, customer support, and whoever owns the website or devices.

Map every acceptance path

List the channels customers will actually use: counter, mobile reader, invoice, website, phone order, recurring billing, cash, check, and bank transfer. For each, record who initiates the payment, whether the customer is present, what receipt is produced, when fulfillment begins, and what happens when the connection fails. Provider and network instructions differ by country, contract, device, and payment type; Visa’s small-business setup paper is useful as a network-specific checklist, not a universal implementation standard (Visa).

Do not make card acceptance the only recovery path. Define how staff records cash and checks, how an offline or deferred transaction is handled, and when an order waits for confirmed payment. The ACH credit versus debit guide helps distinguish pushes from pulls; the authorization lifecycle guide explains why an authorization is not yet a completed capture.

Prove the cash-flow path

Document the provider’s batch cutoff, expected payout schedule, bank account, payout descriptor, fee-deduction method, reserve terms, and failed-payout process. Run a low-value transaction through every enabled channel, then a permitted void or refund. Confirm that the receipt, provider record, payout activity, and bank record share enough identifiers to reconcile. This is validation of the business’s own setup, not a claim that a provider always behaves the same way.

Create a processor clearing account before the first full day. Name the person who reviews unmatched payouts and negative balances. Set a cash buffer based on the business’s actual refund and fulfillment cycle. The payout reconciliation workflow gives the ledger pattern.

Make returns and failures boring

Publish a return and cancellation policy the team can apply consistently. Decide who may refund, partially refund, void, or issue store credit; require an order reference and reason. Define what happens when a refund request is accepted but its later completion is uncertain. Train staff not to promise a bank posting date they cannot control.

Prepare scripts for a duplicate charge, pending authorization, declined payment, missing receipt, shipment failure, and dispute notice. Decide when support pauses fulfillment and when it escalates to finance or the provider. Preserve order, delivery, cancellation, and customer-communication records from the start rather than reconstructing them after a dispute.

Protect the acceptance surface

Use named accounts, least privilege, multifactor authentication, and a documented offboarding step. Keep payment devices inventoried and inspect them for tampering. Restrict vendor access to the systems and time needed. The FTC’s small-business guidance recommends limiting vendor access, using strong encryption, securing networks, and enabling multifactor authentication (FTC).

Hosted payment collection can reduce the systems that handle card data, but it does not make the merchant’s site irrelevant. PCI SSC’s current SAQ A clarification says embedded payment forms have a script-attack eligibility condition, while redirects and fully outsourced flows are treated differently (PCI SSC). Confirm the correct validation path with the acquiring bank or compliance-accepting entity; do not self-select an SAQ from a marketing label.

Sign-off before volume

  • Every enabled channel has an owner, receipt, failure path, and fulfillment rule.
  • A test transaction and permitted reversal or refund can be traced end to end.
  • Payout, fee, reserve, and reconciliation responsibilities are assigned.
  • Return, cancellation, privacy, and receipt language matches actual practice.
  • Admin access uses named accounts and multifactor authentication.
  • Provider contacts and incident steps are available without a login owned by one employee.
  • Daily and month-end exception reports have an owner.

Revisit the checklist after adding a location, device, subscription, new payment method, or new fulfillment partner. Those are operating-model changes, not mere settings.

Sources

Evidence & dates

Prepared 19 Sept 2026 · source checks 19 Sept 2026 · website publication pending. Undated means no publication date was established on the reviewed page.

Federal Trade Commission · Cybersecurity for Small Business

Small-business controls for vendor access, encryption, multifactor authentication, and breach response.

Source publication date: undated · checked 2026-09-19 · full page reviewed · evidence: verified · recheck by 2026-12-19

Read the primary source ↗
PCI Security Standards Council · How does an e-commerce merchant meet the SAQ A eligibility criteria for scripts?

Current SAQ A script-attack eligibility clarification for embedded payment forms and redirect boundaries.

Source reviewed month: 2025-02-01 · checked 2026-09-19 · full page reviewed · evidence: verified · recheck by 2026-12-19

Read the primary source ↗
Visa · How to: Set Up Digital Payment Acceptance (In-Store and Online)

Network-specific checklist topics for in-store and online acceptance, gateways, fraud tools, records, and PCI responsibilities.

Source document month: 2019-10-01 · checked 2026-09-19 · full page reviewed · evidence: verified · recheck by 2026-12-19

Read the primary source ↗
KEEP THE THREAD GOINGNormalize processor quotes before comparing the headline rate →Reconcile a merchant payout without mistaking it for sales →Merchant reserves and negative balances: read the cash position in layers →Reading path: From the first sale to a balanced ledger ↗Return to the library →