Guideline for Contracting with Integrated Third Party Service Providers
Purpose
The purpose of this document is to provide guidance in establishing and maintaining contracts with integrated third party service providers that integrate with or have access to modify any portion of the UNC Charlotte payment card environment.
Scope
This guideline applies to all university employees, affiliates and authorized users who plan to work with a third party that will be interacting with payment card data, functions, or systems (e.g., credit and debit cards) as part of their payment processing services through a University or affiliated entity merchant account.
Contacts
Direct general questions about this guideline to the Office of the Bursar – Merchant Services at ecommerce@charlotte.edu.
Guidelines
Before Contracting for Goods or Services
- Contact Merchant Services: Prior to entering into any contract or purchasing specialized software, equipment or systems necessary for payment card processing, departments must contact the Office of the Bursar – Merchant Services. They will review customized processing applications for compliance with standards, guidelines, security measures, contract requirements and feasibility.
- Include Merchant Services in Request for Proposal (RFP): It is best practice to include the Office of the Bursar – Merchant Services in any formal RFP process involving payment acceptance.
- Third-party Service Providers interacting with payment card data, functions or systems as a part of their payment processing services must provide proof of Payment Card Industry Data Security Standards (PCI DSS) compliance and/or validation of payment software. Preferably, any third party that captures Cardholder Data (CHD) be a validated Level 1 Service Provider.
- Departmental Collaboration: The Office of the Bursar – Merchant Services in conjunction with Materials Management, OneIT, the Office of Legal Affairs, the Internal Audit Department and the applicable computer support unit, will work with the department to ensure that processing standards, safeguarding measures and legal requirements are met.
- OneIT Oversight: OneIT oversees data security governance, IT systems use, technology evaluation and recommendations and provides direction and support for the security and networking of campus infrastructure utilized for card processing systems. Submit any software and IT-related acquisition requests to OneIT for review before acquisition. OneIT will oversee the final approval, signature and execution of contracts and acquisitions involving technology.
- Additional information and Costs: Additional information or external consultation may be required. The requestor will bear all costs related to the external review if required for the approval process.
- Implementation of Approved Software/Equipment: Implement approved third-party software/equipment according to third-party guidelines. Modify default vendor passwords and settings to unique ones before installing the system on the University network or using it for card processing.
Contract Elements
Contracts and associated documentation must address these elements:
- Compliance with the OneIT Standards and Guidelines; specifically:
- Standard for Security Requirements of Information Systems, and the related Information Security Checklist
- Standard for Information Security related to Vendors and External Parties
- PCI SSC Requirements: Compliance with all appropriate Payment Card Industry Security Standards Council (PCI SSC) requirements and their responsibility for specific PCI DSS requirements. If the vendor impacts the CHD environment, they must address:
- Proof of PCI DSS compliance and/or validation of payment software
- Specific elements of the PCI DSS for which they will be responsible and those for which the University will be responsible
- Documentation that clearly details where CHD is captured, information regarding integration with the designated gateway provider and linkage type, and specifies any outside entities’ applications or servers utilized
- Service level agreements
- Remote access and use of Multi Factor Authentication
- Protection of Personally Identifiable Information (PII)
- Data retention and destruction policies
- Liability
- Business continuity
A final copy of the executed contract must be emailed to the Office of the Bursar – Merchant Services at ecommerce@charlotte.edu.
Related Resources
- Standard for Accepting Electronic Payments
- Standard for Information Security related to Vendors and External Parties
- Standard for Security Requirements of Information Systems
Revision History
- Initially approved by the AVC for Finance on November 25, 2024