National payment operations resource
Recurring Payments & Card-on-File
A practical guide to mapping repeat-payment workflows, customer instructions, secure data handling, exceptions, reporting, and the responsibilities that must be confirmed with each provider.
Start with definitions
Separate the schedule from the stored credential
Recurring payments and card-on-file transactions overlap, but they are not interchangeable. Document why a credential is retained, who initiates each future payment, and whether amounts and timing are fixed, variable, or customer-directed.
Recurring schedule
A series of payments expected at regular intervals under a documented customer arrangement. The business should be able to connect each payment to that arrangement and its current status.
Customer-initiated reuse
A returning customer chooses to use a previously saved payment method for a new purchase. Checkout, authentication, and provider handling may differ from scheduled billing.
Merchant-initiated event
The business initiates a payment after the original interaction, such as a scheduled service or an amount determined later. Confirm the correct workflow and indicators with the responsible provider.
Credential storage
Identify which provider or system stores payment data, what the business can see, who has access, how records are protected, and how a stored method is removed.
Workflow map
Follow the complete payment lifecycle
Enrollment and customer instructions
Record what the customer selected, the business or service involved, the expected amount or calculation method, timing, contact details, and the path for questions or changes. Keep the accepted version and timestamp in the appropriate business system.
Payment initiation
Define which system starts the transaction, how it identifies the customer and agreement, what happens before submission, and which provider returns the result.
Receipts and account history
Give customers a useful reference and maintain an understandable history of scheduled, successful, declined, refunded, skipped, and canceled events without exposing complete payment credentials.
Change and closure
Document how customers update a payment method, pause or end the arrangement, and how staff confirm that connected schedules, tokens, notifications, and account records reflect the change.
Data boundaries
Minimize what the business stores and displays
Map every data location
Review checkout forms, portals, POS systems, billing tools, support tickets, exports, logs, email, paper records, integrations, backups, and provider dashboards.
Use provider-supported capture
Ask where payment data enters the workflow, whether a hosted form or token can reduce exposure, and which systems remain within the business's security responsibilities.
Limit access and exports
Give named users only the access needed for their roles. Review downloads, reports, shared accounts, temporary access, former staff, and service-provider connections.
Keep sensitive details out of support
Do not place complete card numbers, security codes, passwords, bank credentials, or secret keys in general forms, email, screenshots, or tickets.
Operations
Design for exceptions, not only successful payments
Before a retry
Check the stored transaction status, provider response, schedule, customer record, and current instructions. Avoid assuming that an unfamiliar status is a final failure.
When details change
Use the provider's authenticated update flow. Record who requested the change, when it became effective, and which connected schedules or systems were updated.
When a customer questions a payment
Trace the agreement, service period, receipt, notifications, payment history, and cancellation record. Escalate through the responsible provider using non-sensitive references.
During an outage
Define whether billing pauses, queues, or requires manual review. Preserve timestamps and provider status information, then reconcile every affected item after service returns.
Provider questions
Confirm ownership before implementation
Customer experience
How are payment methods added, identified, updated, and removed? What appears on receipts, account history, notices, and customer-facing statements?
Transaction handling
How does the system distinguish initial, customer-initiated, recurring, and other provider-supported transactions? Who configures and validates that behavior?
Security and access
Which party stores credentials, what token or masked information is returned, what data reaches connected systems, and which controls remain the merchant's responsibility?
Support and exit
Who handles declines, updates, cancellations, disputes, exports, migrations, and account closure? What happens to active schedules and stored credentials when service ends?
Related guidance
Continue your payment research
Common questions
Recurring payment and card-on-file FAQ
Does card-on-file always mean a recurring payment?
No. A saved credential may support a customer-initiated future purchase, a regular recurring schedule, or another provider-defined workflow. Document the use case and confirm the correct handling with the provider.
Should a business store card details itself?
First ask whether storing card data is necessary. PCI SSC merchant guidance recommends minimizing storage and asking the merchant bank or service provider about supported options such as outsourced capture or tokenization.
Can a card security code be kept for future payments?
PCI SSC states that card verification codes must not be stored after authorization. Ask the acquirer or payment brand how to process recurring or card-on-file transactions without retaining prohibited data.
What should be reviewed when a recurring payment fails?
Check the provider response, customer and schedule status, recent account changes, prior attempts, and current provider instructions. Do not repeatedly retry without understanding the workflow and result.
Last editorial review: August 11, 2026. Sources reviewed: PCI SSC small-merchant and stored-data guidance, plus Visa's merchant resource library and stored-credential framework.
Next step
Map your repeat-payment workflow
Payments Max can help organize customer journeys, billing systems, payment providers, data boundaries, reporting, and support questions before you compare available options.
To learn more about how TSYS can help improve the way your organization accepts payments, markets to new customers, or manages its HR responsibilities, get in touch by calling 585-981-8463 to get started.
CONTACT US