Payment terminology, explained clearly
A reference guide to the terms used across payment orchestration, connectivity, and security – written in plain language, without assuming prior expertise.
CATEGORIES
Acquiring Bank
A licensed financial institution with a direct relationship to card networks, authorized to process card payments on behalf of a merchant. The acquiring bank settles funds into the merchant's account and carries regulatory and compliance responsibility for the transactions it processes.
Acquirer-Merchant Appetite
The willingness of a given acquiring bank to work with a particular merchant or merchant category, based on factors such as industry, risk profile, and transaction volume. Appetite can vary significantly between acquirers.
AML (Anti-Money Laundering)
A set of regulations and procedures designed to prevent the use of financial systems for money laundering. In payments, AML obligations typically apply to the licensed entities in the transaction chain, such as acquiring banks and payment service providers.
API (Application Programming Interface)
A defined way for two software systems to communicate. In payments, an API is typically how a merchant's system sends a payment request to a provider or platform, and receives a response.
API Key
A unique credential used to authenticate requests made to an API, ensuring that only authorized systems can access a platform's endpoints.
Approval Rate
The percentage of payment attempts that are successfully authorized. Approval rates can be affected by factors including the issuing bank's risk assessment, routing decisions, and the quality of the transaction data submitted.
Authorization
The step in a transaction where the issuing bank confirms that funds are available and approves the payment request, prior to the funds actually being captured or settled.
BIN (Bank Identification Number)
The first several digits of a card number, which identify the issuing bank and card type. BINs are often used in routing and risk decisions.
Capture
The process of collecting funds from a transaction that has already been authorized. Authorization and capture can happen simultaneously or be separated in time, depending on the transaction flow.
Card Not Present (CNP)
A transaction in which the physical card is not presented at the point of sale, such as an online or phone payment. CNP transactions typically carry higher fraud risk than in-person transactions.
Card Scheme
A network – such as Visa or Mastercard – that sets the rules and standards for card transactions and connects issuing banks, acquiring banks, and merchants. Card schemes also enforce compliance rules that participants in a transaction must follow.
Chargeback
A reversal of a card payment, initiated by the cardholder's issuing bank, typically in response to a dispute, fraud claim, or transaction error. Chargebacks are managed according to card scheme rules and typically involve the acquiring bank and merchant.
Compliance
The practice of adhering to applicable laws, regulations, and industry standards governing payments, data protection, and financial services. Compliance responsibilities in a payment chain typically sit with licensed entities such as acquiring banks and PSPs.
Cross-Border Payment
A transaction in which the payer and the recipient (or their respective banks) are located in different countries, often involving currency conversion and additional regulatory considerations.
CVV (Card Verification Value)
A short numeric code printed on a payment card, used as an additional verification step to confirm that the person making a transaction has physical possession of the card.
Data Residency
The requirement, in some jurisdictions, that certain categories of data be stored or processed within a specific geographic location, often relevant to regulatory compliance.
Dispute
A formal challenge raised by a cardholder or merchant regarding a transaction, which may result in a chargeback if resolved in the cardholder's favor.
Dynamic Currency Conversion (DCC)
A service that allows a cardholder to pay in their home currency rather than the merchant's local currency, with the conversion rate applied at the point of transaction.
Encryption
The process of converting data into a coded form to prevent unauthorized access, commonly used to protect payment and personal data both in transit and at rest.
High-Risk Merchant
A merchant classified by acquiring banks or card schemes as carrying elevated risk, often due to industry, chargeback history, or transaction patterns. High-risk merchants may face more limited acquiring options or additional scrutiny.
Interchange Fee
A fee paid between banks for the acceptance of card-based transactions, typically charged by the cardholder's issuing bank to the merchant's acquiring bank, and usually passed through to the merchant.
Issuing Bank ("Issuer")
The financial institution that issues a payment card to a cardholder and is responsible for approving or declining transactions made with that card, based on factors such as available funds and risk assessment.
KYB (Know Your Business)
A due diligence process used to verify the identity and legitimacy of a business, typically performed by acquiring banks or PSPs as part of onboarding a merchant.
KYC (Know Your Customer)
A due diligence process used to verify the identity of an individual customer, commonly required as part of AML compliance.
Latency
The time delay between a payment request being sent and a response being received. Lower latency generally contributes to a smoother checkout experience.
Local Acquiring
The practice of processing transactions through an acquiring bank located in the same country or region as the cardholder, which can improve approval rates and reduce cross-border fees.
Merchant Acquiring
The set of activities involved in enabling a merchant to accept card payments, typically performed by an acquiring bank. This includes underwriting the merchant relationship and processing the settlement of funds.
Merchant Category Code (MCC)
A four-digit code used to classify a merchant by the type of business it operates, which can influence interchange fees, risk assessment, and acquiring appetite.
Multi-Acquiring
The practice of working with more than one acquiring bank, often for reasons of redundancy, geographic coverage, or improved approval rates.
Network Token
A token issued directly by a card network (such as Visa or Mastercard) to represent a card number, used to improve security and transaction performance across the network's participants.
Onboarding
The process of setting up a new merchant with a payment partner, typically including identity verification, risk assessment, and technical integration.
Orchestration (Payment Orchestration)
A technology layer that centralizes and simplifies a merchant's connectivity to multiple payment partners – such as acquiring banks and PSPs – through a single integration, without taking on the processing, settlement, or regulatory role of those partners.
PCI DSS (Payment Card Industry Data Security Standard)
A set of security standards designed to protect card data, applicable to any organization that stores, processes, or transmits cardholder information. Certification under PCI DSS indicates that an organization meets these security requirements.
PCI Scope
The set of systems, processes, and personnel within an organization that fall under PCI DSS requirements because they store, process, or transmit cardholder data. Reducing PCI scope – for example, through tokenization – can simplify compliance.
Payment Facilitator (PayFac)
A model in which a company enables sub-merchants to accept payments under its own merchant account with an acquiring bank, taking on certain onboarding and risk responsibilities on their behalf.
Payment Gateway
A technology that captures and transmits payment information from a checkout or point of sale to a payment processor or acquiring bank. Often used alongside or as a component within a broader payment orchestration setup.
Payment Method
The specific means by which a customer pays, such as a credit card, bank transfer, digital wallet, or local payment method.
Payment Service Provider (PSP)
A company that provides the technology and services enabling a merchant to accept payments, often working with one or more acquiring banks. Depending on its licensing and setup, a PSP may handle varying degrees of processing responsibility.
Payment Token
A non-sensitive identifier that represents payment card data without exposing the underlying card number. Tokens are generated through tokenization and can be used to process or reference a transaction without the original card data being present.
Point of Sale (POS)
The location or system where a transaction is completed, whether physical (a terminal) or digital (a checkout page).
Processing
The set of technical and financial steps involved in authorizing, capturing, and settling a payment transaction, typically performed by an acquiring bank or PSP.
Reconciliation
The process of matching transaction records across systems – such as a merchant's internal records, a payment platform, and an acquiring bank – to confirm that reported figures agree.
Recurring Billing
A payment model in which a customer is charged automatically at set intervals, commonly used for subscriptions.
Refund
The return of funds to a customer for a previously completed transaction, typically initiated by the merchant and processed through the original acquiring bank or PSP.
Regulatory Exposure
The risk a business faces from failing to comply with applicable laws and regulations governing payments, data protection, or financial services. Responsibility for managing regulatory exposure typically sits with licensed entities such as acquiring banks and PSPs.
Retry Logic
A set of rules governing whether and how a failed payment attempt is automatically retried, sometimes through an alternative routing path, to improve the likelihood of success.
Risk Appetite
The level and type of risk an acquiring bank, PSP, or merchant is willing to accept, often shaping which industries or transaction types they're willing to support.
Routing
The process of directing a payment transaction to a specific acquiring bank, PSP, or processing path, based on defined rules or logic. Effective routing can influence approval rates, cost, and transaction reliability.
SaaS (Software as a Service)
A software delivery model in which a platform is hosted and maintained centrally, and accessed by users over the internet, rather than installed and run on their own infrastructure.
Sandbox Environment
A test environment that mimics live payment processing without moving real funds, used to test integrations before going live.
Settlement
The process by which funds from a completed transaction are transferred to a merchant's account, typically handled by the merchant's acquiring bank in accordance with agreed timelines and terms.
Sub-Merchant
A business that accepts payments under a payment facilitator's merchant account, rather than holding its own direct merchant account with an acquiring bank.
Tokenization
The process of replacing sensitive payment card data with a non-sensitive token, performed by a certified provider. Tokenization allows systems to reference and process transactions without handling or storing the original card data.
Underwriting
The risk assessment process an acquiring bank or PSP performs before approving a merchant, evaluating factors such as business type, financial history, and expected transaction patterns.
Uptime / SLA (Service Level Agreement)
A measure of a platform's availability over time, often formalized in a Service Level Agreement that defines expected performance and remedies if it isn't met.
Vault (Payment Vault)
A secure storage environment used to hold tokenized payment credentials, allowing them to be reused for future transactions without re-collecting card data.
Void
The cancellation of an authorized transaction before it has been captured or settled, preventing funds from being charged.
Webhook
An automated notification sent from one system to another when a specific event occurs, commonly used to notify a merchant's systems of a transaction status update in real time.
3D Secure (3DS)
An authentication protocol used in card-not-present transactions to verify the cardholder's identity, typically involving an additional verification step during checkout. Used to reduce fraud and, in many regions, required for regulatory compliance.
Acquiring Bank
A licensed financial institution with a direct relationship to card networks, authorized to process card paymentson behalf of a merchant. The acquiring bank settles funds into the merchant's account and carries regulatoryand compliance responsibility for the transactions it processes.
Card Scheme
A network – such as Visa or Mastercard – that sets the rules and standards for card transactions and connectsissuing banks, acquiring banks, and merchants. Card schemes also enforce compliance rules that participantsin a transaction must follow.
Issuing Bank (“Issuer”)
The financial institution that issues a payment card to a cardholder and is responsible for approving or decliningtransactions made with that card, based on factors such as available funds and risk assessment.
Merchant Acquiring
The set of activities involved in enabling a merchant to accept card payments, typically performed by anacquiring bank. This includes underwriting the merchant relationship and processing the settlement of funds.
Payment Facilitator (PayFac)
A model in which a company enables sub-merchants to accept payments under its own merchant account withan acquiring bank, taking on certain onboarding and risk responsibilities on their behalf.
Payment Service Provider (PSP)
A company that provides the technology and services enabling a merchant to accept payments, often workingwith one or more acquiring banks. Depending on its licensing and setup, a PSP may handle varying degrees ofprocessing responsibility.
Sub-Merchant
A business that accepts payments under a payment facilitator's merchant account, rather than holding its owndirect merchant account with an acquiring bank.
Authorization
The step in a transaction where the issuing bank confirms that funds are available and approves the paymentrequest, prior to the funds actually being captured or settled.
Capture
The process of collecting funds from a transaction that has already been authorized. Authorization and capturecan happen simultaneously or be separated in time, depending on the transaction flow.
Chargeback
A reversal of a card payment, initiated by the cardholder's issuing bank, typically in response to a dispute, fraudclaim, or transaction error. Chargebacks are managed according to card scheme rules and typically involve theacquiring bank and merchant.
Dispute
A formal challenge raised by a cardholder or merchant regarding a transaction, which may result in achargeback if resolved in the cardholder's favor.
Processing
The set of technical and financial steps involved in authorizing, capturing, and settling a payment transaction,typically performed by an acquiring bank or PSP.
Reconciliation
The process of matching transaction records across systems – such as a merchant's internal records, apayment platform, and an acquiring bank – to confirm that reported figures agree.
Refund
The return of funds to a customer for a previously completed transaction, typically initiated by the merchant andprocessed through the original acquiring bank or PSP.
Settlement
The process by which funds from a completed transaction are transferred to a merchant's account, typicallyhandled by the merchant's acquiring bank in accordance with agreed timelines and terms.
Void
The cancellation of an authorized transaction before it has been captured or settled, preventing funds frombeing charged.
Card Not Present (CNP)
A transaction in which the physical card is not presented at the point of sale, such as an online or phonepayment. CNP transactions typically carry higher fraud risk than in-person transactions.
Cross-Border Payment
A transaction in which the payer and the recipient (or their respective banks) are located in different countries,often involving currency conversion and additional regulatory considerations.
Dynamic Currency Conversion (DCC)
A service that allows a cardholder to pay in their home currency rather than the merchant's local currency, withthe conversion rate applied at the point of transaction.
Payment Method
The specific means by which a customer pays, such as a credit card, bank transfer, digital wallet, or localpayment method.
Point of Sale (POS)
The location or system where a transaction is completed, whether physical (a terminal) or digital (a checkoutpage).
Recurring Billing
A payment model in which a customer is charged automatically at set intervals, commonly used forsubscriptions.
API Key
A unique credential used to authenticate requests made to an API, ensuring that only authorized systems canaccess a platform's endpoints.
CVV (Card Verification Value)
A short numeric code printed on a payment card, used as an additional verification step to confirm that theperson making a transaction has physical possession of the card.
Encryption
The process of converting data into a coded form to prevent unauthorized access, commonly used to protectpayment and personal data both in transit and at rest.
Network Token
A token issued directly by a card network (such as Visa or Mastercard) to represent a card number, used toimprove security and transaction performance across the network's participants.
PCI DSS (Payment Card Industry Data Security Standard)
A set of security standards designed to protect card data, applicable to any organization that stores, processes,or transmits cardholder information. Certification under PCI DSS indicates that an organization meets thesesecurity requirements.
PCI Scope
The set of systems, processes, and personnel within an organization that fall under PCI DSS requirementsbecause they store, process, or transmit cardholder data. Reducing PCI scope – for example, throughtokenization – can simplify compliance.
Payment Token
A non-sensitive identifier that represents payment card data without exposing the underlying card number. Tokens are generated through tokenization and can be used to process or reference a transaction without theoriginal card data being present.
Tokenization
The process of replacing sensitive payment card data with a non-sensitive token, performed by a certifiedprovider. Tokenization allows systems to reference and process transactions without handling or storing theoriginal card data.
Vault (Payment Vault)
A secure storage environment used to hold tokenized payment credentials, allowing them to be reused forfuture transactions without re-collecting card data.
3D Secure (3DS)
An authentication protocol used in card-not-present transactions to verify the cardholder's identity, typicallyinvolving an additional verification step during checkout. Used to reduce fraud and, in many regions, requiredfor regulatory compliance.
AML (Anti-Money Laundering)
A set of regulations and procedures designed to prevent the use of financial systems for money laundering. Inpayments, AML obligations typically apply to the licensed entities in the transaction chain, such as acquiringbanks and payment service providers.
Compliance
The practice of adhering to applicable laws, regulations, and industry standards governing payments, dataprotection, and financial services. Compliance responsibilities in a payment chain typically sit with licensedentities such as acquiring banks and PSPs.
Data Residency
The requirement, in some jurisdictions, that certain categories of data be stored or processed within a specificgeographic location, often relevant to regulatory compliance.
KYB (Know Your Business)
A due diligence process used to verify the identity and legitimacy of a business, typically performed by acquiringbanks or PSPs as part of onboarding a merchant.
KYC (Know Your Customer)
A due diligence process used to verify the identity of an individual customer, commonly required as part of AMLcompliance.
Regulatory Exposure
The risk a business faces from failing to comply with applicable laws and regulations governing payments, dataprotection, or financial services. Responsibility for managing regulatory exposure typically sits with licensedentities such as acquiring banks and PSPs.
Acquirer-Merchant Appetite
The willingness of a given acquiring bank to work with a particular merchant or merchant category, based onfactors such as industry, risk profile, and transaction volume. Appetite can vary significantly between acquirers.
High-Risk Merchant
A merchant classified by acquiring banks or card schemes as carrying elevated risk, often due to industry,chargeback history, or transaction patterns. High-risk merchants may face more limited acquiring options oradditional scrutiny.
Merchant Category Code (MCC)
A four-digit code used to classify a merchant by the type of business it operates, which can influenceinterchange fees, risk assessment, and acquiring appetite.
Risk Appetite
The level and type of risk an acquiring bank, PSP, or merchant is willing to accept, often shaping whichindustries or transaction types they're willing to support.
Underwriting
The risk assessment process an acquiring bank or PSP performs before approving a merchant, evaluatingfactors such as business type, financial history, and expected transaction patterns.
API (Application Programming Interface)
A defined way for two software systems to communicate. In payments, an API is typically how a merchant'ssystem sends a payment request to a provider or platform, and receives a response.
BIN (Bank Identification Number)
The first several digits of a card number, which identify the issuing bank and card type. BINs are often used inrouting and risk decisions.
Latency
The time delay between a payment request being sent and a response being received. Lower latency generallycontributes to a smoother checkout experience.
Orchestration (Payment Orchestration)
A technology layer that centralizes and simplifies a merchant's connectivity to multiple payment partners – suchas acquiring banks and PSPs – through a single integration, without taking on the processing, settlement, orregulatory role of those partners.
Payment Gateway
A technology that captures and transmits payment information from a checkout or point of sale to a paymentprocessor or acquiring bank. Often used alongside or as a component within a broader payment orchestrationsetup.
Retry Logic
A set of rules governing whether and how a failed payment attempt is automatically retried, sometimes throughan alternative routing path, to improve the likelihood of success.
Routing
The process of directing a payment transaction to a specific acquiring bank, PSP, or processing path, based ondefined rules or logic. Effective routing can influence approval rates, cost, and transaction reliability.
SaaS (Software as a Service)
A software delivery model in which a platform is hosted and maintained centrally, and accessed by users overthe internet, rather than installed and run on their own infrastructure.
Sandbox Environment
A test environment that mimics live payment processing without moving real funds, used to test integrationsbefore going live.
Uptime / SLA (Service Level Agreement)
A measure of a platform's availability over time, often formalized in a Service Level Agreement that definesexpected performance and remedies if it isn't met.
Webhook
An automated notification sent from one system to another when a specific event occurs, commonly used tonotify a merchant's systems of a transaction status update in real time.
Local Acquiring
The practice of processing transactions through an acquiring bank located in the same country or region as thecardholder, which can improve approval rates and reduce cross-border fees.
Multi-Acquiring
The practice of working with more than one acquiring bank, often for reasons of redundancy, geographiccoverage, or improved approval rates.
Onboarding
The process of setting up a new merchant with a payment partner, typically including identity verification, riskassessment, and technical integration.
Approval Rate
The percentage of payment attempts that are successfully authorized. Approval rates can be affected by factorsincluding the issuing bank's risk assessment, routing decisions, and the quality of the transaction datasubmitted.
Interchange Fee
A fee paid between banks for the acceptance of card-based transactions, typically charged by the cardholder'sissuing bank to the merchant's acquiring bank, and usually passed through to the merchant.
adding it to this glossary.