Payment Processing Checklist

Weekly payment-operations review for a DTC merchant on Shopify, Stripe, or a similar processor. Covers checkout security and PCI scope, daily transaction reconciliation, dispute and chargeback handling, and subscription billing recovery.

4 sections 17 steps Collects data
1

Checkout Security & PCI Scope

  1. Verify TLS certificate on the checkout domain
    • Run an SSL Labs scan on the checkout subdomain (checkout.shopify.com or your custom domain). Confirm cert validity, no mixed content warnings, and TLS 1.2+ only. Expired certs silently break Apple Pay / Google Pay and tank conversion before alerting fires.

  2. Confirm SAQ type matches current integration
    • Shopify Payments / Stripe Checkout / hosted iframe = SAQ A. Stripe Elements with custom fields = SAQ A-EP. If a developer recently moved card fields onto your domain, scope changes — reconfirm with your acquirer before the next attestation.

    Collects list
  3. Engage QSA to confirm scope
    • If SAQ type is unclear or you suspect SAQ A-EP / D, open a ticket with a QSA before completing self-attestation. Misclassification is the single largest source of merchant-side PCI fines after a breach.

  4. Review third-party scripts on checkout
    • List every script loaded on the checkout page (Klaviyo, Meta Pixel, Hotjar, Google Tag Manager, affiliate tags). PCI DSS 4.0 requires a script inventory and integrity monitoring. Remove anything not actively producing measurable revenue or required for compliance.

2

Daily Transaction Reconciliation

  1. Pull Stripe and Shopify Payments payouts
    • Export the prior business day's payout report from each processor. Match gross sales, processor fees, refunds, and net deposit against the bank deposit. Use a tool like A2X or Bookkeep if volume exceeds ~500 orders/day.

    Collects file
  2. Investigate authorization decline rate
    • Healthy DTC decline rate runs 8-12%. Above 15% suggests a Radar / fraud rule misconfiguration, an issuer-specific BIN block, or a 3DS challenge flow that customers are abandoning. Filter declines by reason code (insufficient funds vs. do_not_honor vs. fraudulent).

    Collects list
  3. Tune Radar fraud rules
    • Pull the Radar rule that fired most often on declines and review false-positive rate against confirmed fraud. Loosening a CVC-mismatch block or relaxing a velocity rule often recovers 2-3 points of authorization without measurable fraud increase.

  4. Reconcile marketplace payouts
    • Match Amazon disbursement, eBay payout, and Walmart settlement against expected gross sales minus referral fees, FBA fees, and reserves. Marketplace facilitator sales tax should appear as a separate line — confirm it is being remitted, not deposited to you.

3

Disputes & Chargebacks

  1. Triage new chargebacks by reason code
    • Pull every dispute opened in the last 24 hours. Bucket by reason: 4855 / product not received, 4853 / not as described, 10.4 / fraud. Fraud disputes rarely win and should be conceded; service disputes are winnable with delivery proof and order notes.

    Collects list
  2. Compile evidence package for contested disputes
    • Include AVS and CVC match results, signed delivery confirmation, customer IP, prior order history with the same card, and any support tickets. Stripe and Shopify both auto-assemble most of this — review before submission, do not just click through.

  3. Submit evidence before the deadline
    • Card networks give 7-21 days depending on type and brand. Missing the deadline is an automatic loss with no appeal. Set the calendar reminder for 2 days before the actual deadline.

  4. Check chargeback ratio against thresholds
    • Visa VAMP and Mastercard Excessive Chargeback Program flag merchants above 0.9% dispute rate or 100 disputes/month. Crossing the threshold triggers fines and risks processor termination. If trending up, escalate to leadership before the next billing cycle.

    Collects list
  5. Enroll in chargeback alerts program
    • Ethoca and Verifi RDR let you refund borderline disputes before they hit your ratio. Worth the per-alert fee once you are within 30% of the threshold. Coordinate with Stripe / Shopify support to enable.

4

Subscription Billing Recovery

  1. Pull failed-payment dunning report
    • Export this week's failed renewals from Recharge, Smartrr, or Stripe Billing. Sort by failure reason: expired card, insufficient funds, do_not_honor, lost/stolen. Each maps to a different recovery path.

  2. Confirm card updater is enabled
    • Stripe's Network Updater and the Visa Account Updater (VAU) refresh expired and reissued cards automatically. Recovers roughly 30-40% of expired-card failures with no customer interaction. Confirm it is on across every Stripe account, not just the primary.

  3. Review smart retry schedule
    • Aggressive retries (every day for 7 days) burn issuer trust and trigger more declines. Stripe Smart Retries or Recharge's intelligent dunning spaces attempts based on issuer signals. Avoid the temptation to layer a second retry tool on top.

  4. Audit the cancellation flow for compliance
    • FTC's negative-option enforcement and California / New York click-to-cancel laws require online cancellation in the same number of clicks as signup. Test the flow logged in as a real subscriber. Retention offers are allowed but cannot block the cancel button.

    Collects list Collects paragraph Collects file

Use this template

Copy it to your account, customize the steps, and run it with your team in minutes.


Sections 4
Steps 17
Category E-commerce
Price Free to start
Need a different process

Browse hundreds of free templates across every team and industry.

Back to template library

Run Payment Processing Checklist with your team

Customize the steps, assign roles, set a schedule, and keep a complete record for every run.