Accepting Payments and Processing Revenue
FIN-TRE-120

About This Policy
- Effective Date:
- 07-01-2006
- Date of Last Review/Update:
- 05-29-2026
- Responsible University Office:
- Office of the Treasurer
- Responsible University Administrator:
- Vice President and Chief Financial Officer
- Policy Contact:
Matt Schaefer
Director, Treasurery Operations
ms79@iu.edu
Scope
This policy applies to all university departments, employees, and third-party vendors processing revenue on behalf of Indiana University (IU), including all Revenue Producing Activities (RPAs).
This policy applies to University Student Organizations (USO), which are considered operating units of Indiana University and are required to comply with university policies and procedures.
This policy does not apply to Self-Governed Student Organizations (SGSO), which operate independently from the university and are prohibited from using university financial systems, bank accounts, or payment processing systems.
This policy applies to revenue received in physical and electronic form, including but not limited to cash, checks, ACH credits, Fedwire transfers, payment cards, and mobile payments. Electronic payments are subject to applicable federal and state regulations and industry standards, including National Automated Clearing House Association (NACHA) operating rules and the payment card Industry Data Security Standards (PCI DSS).
Policy Statement
Training Requirements
- Revenue Processing Training is required annually for all employees involved in revenue processing (cash, checks, credit cards, KFS A/R Lockbox, etc.) or with access to university banking/payment card systems. The training is also required if you directly manage people or systems that process revenue.
- Security Awareness Education (SAE) Training is required annually for all employees involved with accepting payment cards or with access to university payment card systems. The training is also required if you directly manage people or systems that process payment cards.
Processing Physical Revenue (Cash and Checks)
- Cash and coins over $500 must be deposited within one business day of receipt. Amounts less than $500 must be deposited at least weekly. Deposits must be recorded via a Cash Receipt (CR) in KFS and sent by secure, approved methods to their respective campus Bursar or Banking Services area. Funds awaiting deposit must be kept in a secure, locked location until deposited. Treasury may authorize adjustments to deposit frequencies and/or amounts for specific departments to meet unique operational needs.
- Checks must be made payable to an approved payee and stamped immediately upon receipt using a Treasury issued endorsement stamp.
Departments using remote capture scanners must scan checks daily and complete an Advanced Deposit (AD) document the same day the deposit is processed. Once scanned, physical checks must be held in a secure, locked location for 14 calendar days before being destroyed via a cross-cut shredder.
Departments not using remote capture must complete a cash receipt (CR) document on the day of the deposit and send checks to their respective campus Bursar or Banking Services area by secure, approved methods.
Processing Electronic Revenue (ACH and Payment Cards)
- Departments accepting payment cards will sign a merchant agreement with Treasury that details their responsibilities as well as the security requirements and IU data security policies that must be followed. This agreement may be updated from time to time as requirements change. Failure to follow the requirements of the agreement may result in Treasury revoking the department’s ability to process payments.
- Only Treasury can approve the companies used to process university payments. Departments are prohibited from setting up their own accounts with third-party processors (like Stripe or PayPal) or using 'click-through' payment apps. This is to ensure that all transactions are in compliance with all PCI DSS, federal regulations, NACHA rules, service provider contracts and Indiana University policies regarding security and privacy that pertain to electronic transactions.
- Use of third‑party vendor integrations for credit card processing is limited to departments with expected annual credit card revenue exceeding $50,000 and requires prior approval by Treasury, due to the increased risks and compliance costs associated with maintaining such integrations.
- All processing equipment must be obtained via Treasury. Departments are strictly prohibited from independently purchasing hardware or entering into software contracts for payment processing. This is to ensure all systems meet PCI DSS requirements and are compatible with university network security standards. Equipment not vetted by Treasury may be denied access to the university network.
- Accounting entries to record the receipt of the payment will be linked directly into the university’s accounting system, except where manual intervention is required and approved by Treasury, to ensure timely recording of transactions and to expedite the prompt reconcilement of general ledger and bank accounts.
- No complete payment card account numbers are to be maintained in any university databases or files. For payment cards, only the first six digits and last four digits may be stored.
- To establish or maintain a payment card merchant account, departments must process a minimum of $1,000 in annual credit card revenue.
Internal Controls
- Revenue processing must maintain appropriate separation of duties in accordance with FIN-ACC-470: Internal Controls.
- Only Indiana University employees are authorized to process revenue on behalf of the university. Non-Indiana University personnel are prohibited from processing revenue without prior approval from Treasury.
- Treasury may conduct periodic reviews of all bank and merchant accounts to verify they are still required and being managed compliantly.
- Revenue must be deposited in an approved university bank account and recorded with the appropriate general ledger accounts and object codes.
Establishing a Revenue Producing Activity
This policy will aid in managing risks associated with revenue producing activities and applies to all university departments engaging in internal and external RPAs, regardless of where the revenue is processed. It also applies to any entity or individual processing revenue through IU accounts or through IU technology systems/resources. Entities include, but are not limited to, External Agencies and University Student Organizations.
All incoming revenue to the university is covered under this policy except the activities listed below:
- Revenue generated by SGSOs
- Revenue handled entirely by the Indiana University Foundation
- Sponsored Programs as defined by the Office for the Vice President for Research
- Approved University Fees
A Revenue Producing Activity Questionnaire (RPAQ) must be completed to establish an RPA. Each questionnaire will be reviewed and approved by the department’s RC Fiscal Officer, the Campus Business Officer, and the RPA Committee.
The RPA Committee evaluates each request to ensure alignment with the university’s mission and compliance with all applicable policies and external regulations. The committee further evaluates the activity to identify potential redundancies and mitigate institutional risk.
Approved RPAQs remain valid provided there are no substantial changes to the activity, payment methods, or associated risks. Units must submit a modification if such changes occur or if university policy is updated.
Existing RPAs, including those established prior to the effective date of this policy, are required to comply with the requirements of this policy and must obtain approval if not previously reviewed.
Activities generating less than $1,000 in annual revenue will only be reviewed by Treasury to ensure revenue is processed in a safe, efficient, and compliant manner.
New Revenue Producing Activity
To establish a new RPA, complete the RPAQ in the Online RPA System. Departments should allow a minimum of 15 business days for the RPA Committee to complete its review once the questionnaire has been approved by the RC Fiscal Officer and Campus Business Officer.
Modifying Approved Revenue Producing Activity
An approved RPAQ must be modified if there are substantial changes to the accepted payment methods, vendors, locations, or risks associated with the activity. Modifications would also be required if there’s a change to university policy. Departments can request a modification by emailing rprm@iu.edu.
Reason for Policy
Treasury has operational authority over the acceptance, processing, and deposit of all payments received by the university.
The purpose of this policy is to establish comprehensive guidelines and standardize revenue processing across Indiana University to ensure all receipts are managed in an efficient, consistent, and secure manner. This policy establishes controls to reduce fraud, prevent financial loss, protect sensitive data, and ensure compliance with applicable laws, regulations, and contracts.
Treasury supports these efforts by providing ongoing education and establishing the authorized methods for accepting and recording payments. Treasury partners with departments to simplify revenue processing by prioritizing standardized electronic methods over manual cash handling. By reducing the use of cash, departments can lower their administrative costs and minimize the risks associated with theft or loss. Our goal is to assist departments in implementing automated collection processes that link directly to KFS.
While Treasury provides operational oversight, departments are responsible for ensuring that revenue is processed, deposited, and recorded in accordance with this policy and standards established by Treasury.
Definitions
Automated Clearing House (ACH): A funds transfer system that was developed as an electronic payment alternative to checks.
Debit Cards: A type of payment card that deducts purchases directly from an individual’s checking account.
Endorsement: The stamping of deposit information on the back of a check using an endorsement stamp approved by Treasury. All endorsements stamps must be provided by Treasury.
External Sales: An exchange by the university of tangible or intangible products and/or services with external customers for monetary consideration. For the purposes of this policy, an external customer is anyone not paying for the goods or services from an IU account. Transactions handled for technology transfer, license and trademark agreements are excluded from this definition.
Federal Regulations: Electronic payments fall under numerous banking and disclosure regulations. Examples include Reg E, Reg J, Electronic Funds Transfer Act (1978), USA Patriot Act, and Fair and Accurate Credit Transactions Act.
Fedwire: A funds transfer system administered by the Federal Reserve. It is a real-time method of transferring funds between parties.
Financial Institution: A bank, credit union, brokerage house or financial services provider.
Internal Sales: The sale of goods or services by one university department to another department within the university and to sales within a department.
Lockbox: A collection and processing service provided by a third-party processor, typically a bank. Treasury handles all banking contacts for the university.
Merchant Account: An account established by Treasury at the university’s contracted payment processor that allows a department to accept and process credit and debit card transactions.
Merchant Agreement: A separate agreement that a department’s fiscal officer must review and agree to annually to create or maintain a credit card merchant account.
Mobile Payments: Electronic transactions that are transacted with a mobile phone.
National Automated Clearing House Association (NACHA): NACHA is the regulatory body for the ACH payment network.
Payee: An individual to whom money is being paid or is due, especially in a transaction such as the payment of a check or money order. Some examples of approved payees for Indiana University are:
- Trustees of Indiana University
- Indiana University
- Indiana University, a specific campus, unit, or school
Payment Card: Credit cards (e.g., VISA, MasterCard and Discover), American Express, Diners Club, and Debit cards.
Payment Card Industry Data Security Standards (PCI DSS): A set of comprehensive requirements for enhancing payment account data security, developed by the founding payment brands of the PCI Security Standards Council, including American Express, Discover Financial Services, JCB International, MasterCard Worldwide and Visa Inc. International, to help facilitate the broad adoption of consistent data security measures on a global basis. The PCI DSS is a multifaceted security standard that includes requirements for security management, policies, procedures, network architecture, software design and other critical protective measures. This comprehensive standard is intended to help organizations proactively protect customer account data.
Processing Equipment: Any hardware, software, or virtual terminal used to capture, transmit, or process payment card data. This includes, but is not limited to:
- Physical Hardware: Credit card terminals, card readers (EMV/chip), printers, and automated kiosks.
- Point of Sale (POS) Systems: Cash registers and computer-based checkout systems, including cloud-based or Software-as-a-Service (SaaS) platforms.
- Mobile Readers: Peripheral devices attached to mobile phones or tablets for card-present transactions.
Revenue Producing Activity Committee (RPA Committee): A group of select university administration departments that reviews and approves Revenue Producing Activity Questionnaires.
Remote Capture: The electronic transmission of check images and deposits to a bank for processing and clearing.
Revenue: Any incoming funds generated from the sale of products and/or services provided by the university or university employees.
Revenue Producing Activity: An activity that generates revenue from the sale of products and/or services provided by the university or university employees.
Self-Governed Student Organization (SGSO): Student organizations that are not University Student Organizations; considered organizations separate from Indiana University that must agree to and operate under the Self-Governed Student Organization Agreement (“SGSO Agreement”) in order to use university facilities and services, and receive benefits associated with the Indiana University name. SGSOs that have received permission to use “Indiana University” in the organization’s names must do so only in a locational sense (i.e. “The XZY Club at Indiana University”). See STU-01: Student Organizations. SGSOs cannot use Treasury provided solutions and must process all revenue external from the university.
Service Provider: The entity or entities selected by Treasury that process Payment Card, Fedwire, ACH transactions.
Sponsored Programs: Sponsored Programs will not be considered an RPA under this policy. Any questions as to whether an activity should be considered a Sponsored Program should be referred to Office for the Vice President for Research.
Tax Identification Number (TIN): The number used to identify Indiana University for federal and state tax matters.
University Bank Account: Any account (checking, savings, depository, money market, etc.) opened by Treasury at a financial institution that meets any of the following criteria:
- Uses the name Trustees of Indiana University, Indiana University, or any associated abbreviation thereof
- Uses the university’s federal tax identification number
- Receives the deposit of or disburses university funds
University Student Organization (USO): Student organizations typically formed by Indiana University to serve an important function or to provide a certain opportunity for students. USOs are treated as operating units or agencies of IU within the administrative and fiscal structure of Indiana University and are subject to all university policies and procedures. Determination of status as a USO will be made by the campus dean or vice chancellor of student affairs and the campus vice chancellor for finance and administration and/or controller. Final approval of USO status will rest with university administration. Factors to be considered are: funding sources and organizations, IU staff support, management of risk, integration with university operations, and the historical and reputational relationship between the student organization and IU. See STU-01: Student Organizations. USOs will be treated like university departments and must process all revenue in accordance with this policy.
History
This policy was established on July 1, 2006.
This policy was revised on March 5, 2015 to emphasize training requirements for full-time, part-time, and student employees.
This policy was updated on August 18, 2021.
This policy was updated on June 6, 2024 and merged with FIN-TRE-121: Establishing and Modifying Revenue Producing Activities (RPA).
This policy was revised and posted for review in May 2026.
