Practical device checks for merchant teams

How should employees inspect payment terminals for tampering?

Employees should compare each payment terminal with a known, documented baseline and look for unexplained changes before the device is used. A useful check covers the terminal body, card-entry areas, keypad, seals, cables, connections, labels, mounting, and nearby objects. If anything seems altered, loose, added, substituted, or inconsistent with the baseline, staff should stop using the device and follow the business's escalation procedure.

Build a reliable baseline before inspections begin

An employee can identify a change more confidently when the business has already recorded what normal looks like. Maintain an inventory with each terminal's approved location, model, asset identifier or serial number, and responsible owner. Take clear reference photographs of the front, back, sides, keypad, card slots, cords, connections, seals, and mounting arrangement. Store the inventory and photos where authorized staff can consult them without exposing sensitive system credentials.

Update the baseline after an approved replacement, repair, cable change, relocation, or vendor visit. A stale photograph can create false alarms or allow a real substitution to appear normal. Portable and unattended devices need a defined storage location and handoff process so the team can account for them at opening, closing, and shift changes.

Use the same visual inspection path every time

Compare the outer case

Check the shape, color, seams, labels, screws, privacy shield, display, and security seals against the reference images. Look for gaps, scratches, broken seals, unexpected stickers, raised surfaces, added covers, glue residue, or parts that appear misaligned.

Review card and PIN areas

Look closely at the chip slot, swipe path, contactless area, keypad, and surrounding plastic. An added overlay can resemble the original housing, so unexplained thickness, loose corners, obstructed slots, or a keypad that looks or feels different should be escalated.

Trace cables and nearby objects

Compare power, network, register, and accessory cables with the baseline. Note unknown adapters, changed connectors, extra wires, new electronics, unusual holes, or objects positioned to view the keypad. Do not disconnect equipment merely to investigate unless the approved response procedure directs it.

Set a routine based on actual exposure

The PCI Security Standards Council advises merchants to maintain a device list, inspect point-of-interaction devices periodically, and train personnel to recognize attempted tampering or substitution. The appropriate local routine depends on how the device is used and who can reach it. A staffed countertop terminal, portable restaurant device, unattended kiosk, and terminal stored after hours do not have identical exposure.

Define when checks happen, who performs them, what evidence is recorded, and who reviews exceptions. Common checkpoints include opening, shift handoff, closing, return from storage, and after any service visit or period when the device was outside normal control. Follow the current instructions from the terminal provider, acquiring organization, and the business's qualified security or compliance advisers when those instructions set a specific method or schedule.

Control service visits and device movement

  • Verify the visit. Confirm an expected technician through a known contact method rather than relying only on a badge, uniform, phone number, or work order supplied by the visitor.
  • Limit access. Keep the visitor with an authorized employee and prevent access to unrelated terminals, cables, network equipment, or back-office areas.
  • Record the work. Note the date, device identifier, authorized company, technician details, reason for service, parts or cables changed, and employee who observed the visit.
  • Refresh the baseline. Reinspect the device and update reference photographs only after the work has been confirmed as authorized.
  • Secure idle devices. Use the approved storage, mounting, access-control, and end-of-day procedure for the specific terminal environment.

Respond safely when something looks wrong

Do not process another payment on a terminal that may have been altered or substituted. Keep customers and unassigned employees from using it, and notify the manager or security contact named in the response procedure. Contact the terminal provider or merchant bank through a previously verified channel. The PCI SSC small-merchant guide specifically advises merchants not to use a suspected terminal and to report the concern immediately.

Do not force, pry apart, plug in, test, reset, clean, or discard a suspicious component. Avoid confronting a suspected person. Preserve the scene and record non-sensitive facts such as the time, device location, asset identifier, visible difference, last known inspection, and who had access. Follow instructions from the appropriate provider, security team, law-enforcement contact, or incident-response professional. Never copy cardholder data, PINs, passwords, or bank credentials into a general incident form.

Know what a visual check cannot prove

A normal-looking exterior does not prove that a terminal is safe. Some attacks may be internal, subtle, remote, or impossible for frontline staff to identify. Employees should use the documented inspection as one layer alongside controlled access, authorized service, supported equipment, account security, monitoring, and a tested response plan.

This page provides general operational guidance. It does not determine PCI DSS applicability or compliance, replace device-specific instructions, certify a terminal, or guarantee detection of tampering. Businesses should obtain requirements from the organizations responsible for their payment program and use qualified assistance for suspected compromise.

Continue the fraud-prevention review

Review broader payment controls

Use the guide to reducing credit card fraud to connect physical checks with staff access, transaction review, and response planning.

Limit internal misuse

Review how a business can reduce employee refund fraud with individual access, approvals, documentation, and monitoring.

Run one supervised inspection with the team

Select one active terminal, confirm its inventory record, compare every visible side with approved photographs, trace its connections, and rehearse the stop-and-escalate path. Correct unclear ownership, missing baseline images, unverified service contacts, or unsafe storage before relying on the routine.

When contacting Payments Max about a payment workflow, describe the business type, device environment, and operational needs without submitting cardholder data, PINs, passwords, bank credentials, complete account numbers, secret API keys, or photographs that expose sensitive information through a general inquiry form.

To learn more about how TSYS can help improve the way your organization accepts payments, markets to new customers, or manages its HR responsibilities, get in touch by calling 585-981-8463 to get started.

CONTACT US