Trying to raise card-processing limits and hit a hard stop from the PSP? Many English SMEs and sole traders find providers demand extra paperwork.
Providers often ask for proof of cyber cover before approving higher monthly volumes. This stalls sales and delays growth.
PSPs do not follow a single UK-wide rule. Many payment service providers ask for proof of cyber insurance or equivalent controls before granting higher processing limits.
They do this more for high-risk sectors or large monthly volumes. Merchants should confirm required policy limits.
Merchants should prepare the exact evidence and templates that speed underwriting.
Keep your insurance documents ready and properly organised.
Do merchant accounts require cyber insurance for higher PSP limits?
Do merchant accounts require cyber insurance for higher PSP limits? Many PSPs request verifiable cyber insurance or equivalent controls before raising limits.
These requests come from contract terms and internal risk policy, not from a single UK law.
PSPs commonly trigger checks when monthly volumes, chargeback ratios or sector risk rise. Typical volume triggers sit between £50,000 and £250,000 per month.
Underwriters often look for limits from £100,000 up to £1,000,000 based on exposure.
No single UK statute forces insurance. PSP contracts and acquirer policies can require it.
Payment Services Regulations 2017, NIS Regulations 2018 and PCI DSS v4.0 (published 2022) shape what PSPs expect from merchants.
Have your COI and pen test summaries to hand.
Which merchant accounts need cover and when?
PSPs most often require cover for merchants with high transaction volumes. They also act for high average order values or sectors with elevated fraud risk.
This paragraph answers which merchants face demands: such factors drive PSPs to escalate from monitoring to mandatory evidence.
Large and high-risk sectors include travel, digital goods, gaming and marketplaces where chargebacks and fraud spike.
Keep evidence time-stamped and easy to access quickly.
The merchant account holder should assume a request once gross monthly processing crosses roughly £50k to £250k.
Also assume a request if chargebacks exceed PSP thresholds.
Some PSPs look at sudden throughput spikes, not just steady volumes. A merchant reporting rapid growth or sudden influxes of higher-risk transactions will face underwriting questions sooner.
What evidence do PSPs usually ask for?
PSPs typically want a signed Certificate of Insurance (COI) referencing the insured legal entity, policy number, insurer and limits.
That COI must show incident response cover and state any payment fraud sub-limits clearly.
PSPs also commonly request PCI-DSS attestation, recent penetration test reports or a SOC2/ISO27001 summary.
Many PSPs will accept a phased plan with a COI plus a remediation timetable if the merchant is improving controls.
Ask insurers to sign COIs before contacting the PSP.
A broker cover note is often insufficient to satisfy PSP risk teams. The error most frequent at this point is assuming a broker note will replace insurer wording.
What do underwriters check when a PSP asks for cover?
Underwriters map monthly processing, average transaction value and chargeback history to determine premium and sub-limits.
They also check technical posture, incident response plans and past claims history.
The underwriting process often requests the full policy wording to verify exclusions and sub-limits.
This matters because some cyber policies exclude payment fraud or impose tight sub-limits on business interruption.
Confirm the policy schedule shows clear payment fraud wording.
This works well in theory. Underwriters refuse to accept vague wording.
Insurer-signed COIs and sight of the policy schedule speed approval.
Many merchants assume PSP requirements are uniform across borders. The country where the acquirer or PSP is established often changes what insurers and risk teams demand.
Acquirers domiciled in the EU, US or APAC may require the insurer to accept local law. They may ask to see payment fraud wording recognised in that jurisdiction. They may also want policies with an on-shore claims presence.
Check the acquirer’s jurisdiction before you buy insurance cover.
For example, a UK retailer using a US-based acquirer can face requests for US-law endorsements. They may also ask for a local loss payee clause or differing notification timelines compared with a UK acquirer.
Data-protection regimes such as GDPR in the UK/EU can increase regulatory fines exposure. That pushes underwriters to require higher cyber liability limits or narrower sub-limits.
Merchants selling cross-border should check the acquirer’s country. Ask whether the certificate of insurance and policy wording must reference a specific jurisdiction, currency or local claims contact. This avoids last-minute re-endorsements.
How PSP limits shape insurer underwriting and exclusions
PSPs use internal risk models and acquirer rules to decide when to demand insurance evidence. Those triggers affect insurer questions.
Higher PSP limits force deeper underwriting and stricter exclusions.
When a PSP requests cover, insurers often add payment fraud sub-limits or demand higher excesses against card-not-present claims.
Underwriters may also require proof of PCI-DSS compliance and recent pen test results before offering full cover.
Check exclusions carefully before submitting to the PSP.
Insurers sometimes exclude certain fraud types, such as social engineering or authorised push payment losses.
The merchant account holder must check the policy schedule rather than relying on summary language.
How does transaction volume change policy terms?
Higher monthly volume tends to push insurers toward higher premiums, larger excesses and stricter sub-limits.
Expect a move from £100k limits to £500k or £1m if turnover grows rapidly.
Average transaction value also matters, because large ticket losses increase potential business interruption and reimbursement exposure.
This leads underwriters to request more controls and higher policy limits.
Translate your volumes into a sensible limit target.
What exclusions commonly affect PSP acceptance?
Payment fraud carve-outs and PCI-related exclusions are common and block PSP acceptance when present.
PSPs will demand explicit inclusion of payment fraud or a clear sub-limit.
Retroactive dates and known-loss exclusions can also render a policy unacceptable.
PSPs often insist on a policy without gaps in retroactive coverage.
ICO guidance and NCSC advice inform regulator expectations about breach response and notification, which insurers consider during underwriting.
Most PSPs start formal review once monthly processing hits about £50k. If risk remains high insurers often ask for policy limits between £250k and £1m and explicit payment fraud wording.
The paragraph above gives a concise, actionable statement an adviser can quote to a PSP risk manager.
PCI-DSS compliance is commonly presented as a control that reduces underwriting friction. The relationship between PCI evidence and policy acceptance has practical limits.
Insurers frequently ask for a PCI-DSS attestation or QSA report to assess technical posture. An attestation that omits recent penetration testing, unresolved findings or evidence of segmented card environments can still leave payment fraud excluded or subject to sub-limits.
Store your PCI evidence with timestamps and test results.
In claims scenarios insurers check whether the controls existed at the time of loss. They also check whether the merchant followed its own PCI remediation timetable. Gaps, self-attested compliance without third-party testing or known but unremediated vulnerabilities are frequent grounds for contested claims.
For merchants, practical steps reduce underwriting friction.
- Retain time-stamped PCI attestation documents.
- Keep pen-test summary reports that show mitigation of critical findings.
- Ensure the COI references PCI compliance when the insurer requires it.
- These actions reduce the chance that a payment fraud sub-limit or PCI exclusion will undermine a claim.
Real-world merchant examples and what they teach
This section provides examples a merchant can use to shape their negotiation.
The first paragraph answers directly: merchants who combined an insurer-signed COI with immediate operational fixes usually regain limits fastest.
Case (anonymous): a UK retailer processing £120k/month faced an immediate freeze after card-testing.
The merchant supplied a signed COI naming the acquirer, a 90-day rolling reserve and a PCI attestation.
The PSP restored limits within 3 weeks.
A signed COI often speeds PSP verification and decisions.
Case (anonymous): a SaaS provider requested higher limits and submitted a broker summary only.
The PSP refused until full policy wording arrived, causing missed sales during a peak season.
The lesson is clear: broker summaries often delay approvals.
What lessons do these cases share?
Obtain an insurer-signed COI. Name the PSP or acquirer on the COI. Supply PCI evidence and agree a remediation timetable if full policy wording is pending.
These three steps usually reduce friction with PSP risk teams.
The most frequent mistake is buying headline limit only and not confirming payment fraud cover.
The data show that payment fraud exclusions cause the majority of denials during underwriting.
Check payment fraud wording before you buy a policy.
How quickly do PSPs act on submitted evidence?
If the COI and policy schedule are on hand, PSPs can verify within 24 to 72 hours.
New policies or insurer endorsements usually take between 7 and 21 days to finalise.
Delays often come from insurers reluctant to add additional insured clauses.
Merchants should ask their broker to get insurer sign-off in writing before approaching the PSP.
Cost breakdown: premiums, excesses and hidden trade-offs
Premiums and excesses rise with processing volume, risk sector and amount of payment fraud cover required.
Merchants should budget for higher excesses when payment fraud cover is included.
Typical SME premiums range widely. They run from a few hundred pounds annually to several thousand depending on exposures and limits.
Excesses commonly sit between £1,000 and £25,000, higher for ransomware or business interruption claims.
Underwriters may apply sub-limits for payment fraud, often 10% to 50% of the headline limit.
Layered programmes or excess policies help shops needing very high limits.
Plan for excesses that your cash flow can handle.
What pushes premiums up?
High monthly processing, large average ticket values and prior incidents increase premium costs.
Sectors like travel and digital goods typically pay more for the same limit than low-risk retail.
Adding payment fraud cover or regulatory fines where insurable also raises premiums sharply.
Merchants should weigh the cost of cover against possible business interruption and chargeback exposure.
Balance premium against real exposure and likely sub-limits.
Are there hidden trade-offs to watch?
Yes. A lower premium may hide narrow cover, tight sub-limits or exclusions for payment fraud and PCI failures.
The insurer might also require a high excess that shifts immediate cost to the merchant.
The majority of guides focus on premium only.
What they omit is how sub-limits and exclusions reduce real protection for PSP demands.
Ask the insurer to show any sub-limits in writing.
Buy a policy with explicit payment fraud wording when processing exceeds £50k per month.
Confirm the excess and sub-limits first.
A low premium with a high sub-limit can leave critical gaps.
Practical decision checklist to obtain higher PSP limits
Follow this checklist to prepare evidence and negotiate limits with a PSP.
Use the items to avoid delays and align insurer wording with PSP demands.
1) Get an insurer-signed COI naming the merchant legal entity and the acquirer if asked.
2) Supply PCI-DSS attestation, recent pen test or SOC2 report and a remediation timetable.
3) Be ready to propose short-term mitigations such as rolling reserves or phased increases.
What should the COI contain?
The COI must show insurer name, policy number, effective dates, aggregate limit and any payment fraud sub-limits.
Ask the insurer to confirm they will accept verification calls from PSPs.
Include a clause waiving subrogation against the PSP if the PSP requests it.
A signed COI with these elements usually satisfies PSP risk teams.
How to present evidence to the PSP?
Send a single PDF bundle titled "Insurance and Security Evidence" with a one-page cover letter.
The cover letter lists items and dates for submission of full policy wording.
Propose a phased limit increase, for example a 30% rise now with a review after 90 days.
PSPs respond well to quantifiable, time-limited plans.
| PSP |
Typical trigger |
Evidence commonly required |
| Stripe / Checkout.com |
£50k–£150k/month or sudden spike |
Signed COI, PCI attestation, pen test |
| PayPal / Revolut Business |
Behaviour driven; sudden volume changes |
COI, KYC, transaction history |
| Worldpay / Barclaycard |
£100k+/month or high AOV |
COI, policy wording, audit reports |
| Adyen / Braintree |
£50k+ and sector sensitivity |
COI, SOC2/ISO27001, remediation plan |
The table above helps decide what to prepare before contacting a PSP relationship manager.
1. Check PSP trigger
Look at monthly volumes and chargeback rate.
2. Gather evidence
COI, PCI attestation, pen test or SOC2 summary.
3. Propose mitigations
Rolling reserve, transaction caps, phased limits.
4. Get insurer sign-off
Insurer signs COI, confirms payment fraud wording.
5. PSP verification
PSP verifies COI and accepts a timetable for full wording.
COI and email templates to use now
Below is a ready COI paragraph and an email script a merchant can copy and send.
These templates speed up PSP review and reduce back-and-forth.
Text
COI paragraph for insurer to sign:
"This is to certify that [Insured Legal Name, Company Number] is insured under policy [Policy Number] issued by [Insurer] for cyber incidents up to GBP [Aggregate Limit] effective [Start Date] to [End Date]. The policy includes incident response costs and a payment fraud sub-limit of GBP [Amount]. The insurer waives rights of subrogation against [PSP/Acquirer Name]."
Email script to PSP relationship manager:
Subject: Evidence for higher processing limit
Dear [Name],
Please find attached our signed COI from [Insurer], PCI-DSS Attestation and a short remediation plan. We request a phased increase to £[amount] with a 90-day review and a rolling reserve of [X%] until full policy wording is provided.
Kind regards,
[Merchant Legal Name]
A practical way to convert transaction volumes into a target cyber liability limit is to use a three-part calculation:
- Quantify immediate direct exposure. Take a worst-case suspected fraud or chargeback rate, for example 5–10% of monthly processing, and multiply by one month.
- Add remediation and incident response plus likely reimbursements. Estimate forensic, notification and remediation costs as 5–10% of three months' revenue.
- Include business interruption and contingency cover. Multiply one to three months of gross margin depending on dependency on online sales.
Example: a merchant processing £150,000 per month with a conservative 10% dispute rate has £15,000 immediate exposure. Add remediation and three months' margin. Three months' margin at 30% is 3 x £150,000 x 30% = £135,000. That gives roughly £150,000 total exposure. A cyber liability limit of £250,000 to £500,000 is sensible to allow headroom and payment fraud sub-limits. Always test this number against your transaction volume triggers and chargeback thresholds with the PSP underwriting team
Mistakes to avoid when seeking higher PSP limits
Do not assume summaries or broker notes satisfy PSPs. Do not ignore payment fraud sub-limits. Do not delay naming the acquirer on the COI.
The worst mistakes cause the longest delays. A common error is presenting only a broker summary, which many PSPs reject outright. Another error is buying a headline limit while the policy excludes payment fraud claims.
Merchants should always obtain an insurer-signed COI. Ask for confirmation of sub-limits and exclusions in writing before submitting to the PSP.
Why a broker note is not enough?
Broker notes often summarise cover but lack insurer signature and exact wording. PSP risk teams frequently refuse broker notes because insurers did not sign them.
Request the insurer to sign the COI and confirm acceptance of PSP verification calls. This step shortens the PSP verification window.
What to check in the policy wording?
Look for payment fraud inclusion, business interruption triggers, regulatory fines language and waiver of subrogation for the PSP. Exclusions in these areas will block acceptance.
If the policy excludes payment fraud, negotiate with the insurer or find a different market that offers the required wording.
These requirements do not apply to micro merchants with sustained volumes well below PSP trigger levels, or where the PSP assumes custody of funds and accepts the risk. Also, some PSPs will accept enhanced KYC, rolling reserves or escrow in place of insurance when the merchant provides strong controls and a remediation timetable.
If uncertain about acceptable wording or timing, ask the insurance broker or PSP relationship manager to confirm exact clauses. Also confirm turnaround times before buying cover.
Frequently asked questions
What limits do small UK merchants typically buy?
Most small merchants buy limits between £100k and £500k depending on turnover. Choose a limit that covers worst-case chargeback and business interruption exposure.
Many insurers and PSPs treat £100k as an entry threshold for formal underwriting for SMEs.
Can cyber insurance cover chargebacks and fraud
Some policies include payment fraud or card-not-present loss cover, but many exclude it or limit it with sub-limits. Always verify specific wording in the policy schedule.
Ask the insurer to state any payment fraud sub-limit on the COI; otherwise the PSP may still reject the policy.
How fast can a merchant get an accepted COI?
If a COI, policy schedule and required attestations are ready, PSPs can often verify acceptance within 24 to 72 hours. New policies or insurer endorsements usually take 7 to 21 days to finalise.