Card-on-file for Pakistani ISPs: 3DS, recurring collection and the operational reality
Recurring card collection via Mastercard and Visa lifts postpaid AR performance materially. Here is how it works in Pakistan, and what an operator needs to know to enable it.
For postpaid ISP subscribers who hold a Mastercard or Visa card, card-on-file recurring collection is by far the most effective AR mechanism available. It also has real operational implications — around 3D Secure, around dispute handling, and around what happens when a card expires. This is a practical guide.
Card-on-file (COF) means the subscriber's card credentials are securely stored (tokenised) after an initial 3DS-authenticated payment, so subsequent recurring collections happen without subscriber intervention. The scheme rules are set by [Mastercard](https://www.mastercard.com/global/en/business/issuers/mastercard-services/mastercard-tokenization-service.html) and [Visa](https://usa.visa.com/dam/VCOM/global/support-legal/documents/stored-credential-transaction-framework-vbs-10-may-17.pdf); the operational implementation is Netxol's responsibility as the aggregator. See [Netxol Billing](/products/modules/billing) for the full context.
The 3DS mechanics
3D Secure 2 is the current standard. On card save, the subscriber goes through a full 3DS challenge (typically OTP via SMS, or in-app confirmation with the issuing bank). Subsequent recurring charges are exempt from the challenge under the scheme rules for merchant-initiated transactions (MITs), provided the transaction is properly flagged. Netxol handles the MIT flagging automatically.
What happens when a card expires
The subscriber's card expires; Netxol's attempt to charge fails; the subscriber is notified via their preferred channel (in-app, SMS, e-mail) with a one-tap link to re-authenticate a new card. The dunning workflow proceeds only after the notification window elapses. This is critical: silent card-expiry suspension is the fastest way to lose a good-standing subscriber.
Under 2%
Silent failure rate on recurring COF
When card-expiry notification is properly wired.
30–40%
Reduction in postpaid AR days
When migrating from bank transfer to COF for eligible subscribers.
Zero
Manual reconciliation for successful charges
Netxol Billing auto-matches to the invoice.
Dispute handling
Card disputes go through the scheme (Mastercard / Visa) chargeback process. Netxol as the merchant of record receives the chargeback notice, notifies the operator, and provides the standard dispute-response evidence pack — subscriber ID, service records, session records from RADIUS, prior payments — from the shared graph. Response rates in this industry are high because the network side of the platform can prove service delivery.
Which subscribers to migrate first
The highest-value segment for COF migration is postpaid urban subscribers with historical on-time payment. Prepaid subscribers rarely benefit — they pay before use, so recurring collection is not the constraint. See our earlier post on [JazzCash and EasyPaisa](/blog/jazzcash-easypaisa-for-isps) for the wallet story, which is the better fit for prepaid.
If you enable one collection method this quarter
Wallet-first (JazzCash + EasyPaisa) for prepaid and self-service. COF second, targeted at postpaid subscribers who already hold cards. The two together cover the vast majority of Pakistani residential ISP billing.
References
- Mastercard — Card-on-File & TokenizationMastercard scheme reference.
- Visa — Stored Credential Transaction FrameworkVisa scheme reference.
- EMVCo — 3DS 2 specificationThe 3DS 2 authentication standard.
- Netxol Billing moduleWhere COF lives on the Netxol side.
- Netxol Subscriber AppThe subscriber-facing surface.
- Related: JazzCash and EasyPaisa for ISPsThe wallet side.
