# PaymentBrief — Full machine-readable index > Site: https://paymentbrief.com > PaymentBrief is an operator-grade payments reference and learning library: briefings, scorecards, reference pages, and decision frameworks for PSPs, merchants, and fintech operations teams. This is the machine-readable companion to https://paymentbrief.com/llms.txt — a structured index of every article, glossary term, market guide, topic, and reading list, with summaries and extractable key facts. No article bodies are included. ## Editorial positioning PaymentBrief is an operator-focused payments reference and learning library. Coverage is sourced from primary and official references (regulators, scheme rulebooks, PSP documentation, filings, and pricing), written neutrally for payments professionals — not consumers. Author: Shaun Toh, Director of Digital Payments at Razer. All editorial content is independently authored; commercial relationships are disclosed under FTC 16 C.F.R. Part 255. ## Core topic clusters - PSP / orchestration / acquirer-routing: PSP selection and economics, multi-acquirer routing, orchestration, network tokens, authorization optimization, least-cost routing. - Merchant-of-record / tax / platform-commerce: When to use a MoR, provider comparison, tax-scope handovers, exit triggers, and migration to direct PSP. - Chargebacks / VAMP / disputes: Visa/Mastercard dispute rules, reason codes, VAMP monitoring and remediation, compelling evidence, representment, and chargeback unit economics. - Fraud / AML / risk / KYB: Real-time fraud decisioning, rule-vs-ML architecture, account takeover, card testing, KYB/KYC, sanctions screening, and AML transaction monitoring. - SWIFT / cross-border / ISO 20022: SWIFT MT103/gpi mechanics, charge options, payment tracing, MT-to-ISO 20022 field mapping, camt investigations, and cross-border B2B AR. - SEPA / instant / VoP: SEPA credit transfer and direct debit, EU instant payments regulation, SCT Inst monitoring and rejections, return codes, and Verification of Payee. - Real-time rails / A2A / local methods: Pix, UPI, SPEI, PromptPay, PayNow, FedNow, PayTo/NPP, InstaPay/PESONet, VietQR, mada/sarie, M-Pesa, and open banking A2A adoption. - Stablecoins / treasury / settlement: Stablecoins as B2B rails, settlement corridors, on/off-ramp operations, treasury custody, compliance stack, issuer comparison, and regulatory frameworks. - Reconciliation / finance-ops: Payment reconciliation and continuous close, settlement-file parsing, payout and outage failover runbooks. - Country market guides: Per-market reference pages and deep operator guides on rails, regulators, MDR economics, PSP coverage, and licensing. - AI agents / AI payments / controls: Agentic commerce, AI payment APIs and MCP toolkits, agent payment controls and governance, MLOps and model drift. ## Article index Operator briefings and reference pages. Each entry: title · URL · type · summary · key facts (where present) · topic · dates. ### Joining Canada's Real-Time Rail: The PSP Participation Route - url: https://paymentbrief.com/articles/canada-real-time-rail-psp-participation-route/ - type: article - summary: Bank of Canada registration is the first of three separate gates, not a connection to the rail. Payments Canada membership, RTR participation approval, a settlement route and certification testing all come after — and the rail's own launch is sequenced into 2027. - topic: psp-and-infrastructure - keyFacts: - What RPAA registration establishes: Eligibility to apply for Payments Canada membership — not membership, not RTR participation, and not a connection - Three separate gates: Bank of Canada registration (RPAA) → Payments Canada membership (Board-approved) → RTR participation (conditional approval, then final approval by Payments Canada's President) - Membership approval cadence: Membership applications are approved by the Payments Canada Board of Directors; approval timing is typically tied to its meetings, which occur in March, May, September and December - RTR application turnaround: Approximately two to three weeks to conditional approval — granted pending completion of onboarding and testing, not as clearance to go live - Settlement route: Direct settlement participant with a Bank of Canada RTR settlement account (restricted, or unrestricted to act as a settlement agent), or indirect settlement participant using a settlement agent - Settlement account lead time: Approximately two to six months, per Payments Canada; without Bank of Canada approval an organisation cannot participate as a direct settlement participant - Rules in force vs launch: By-law No. 10 — RTR (SOR/2026-133) and the RTR Rules came into force 24 August 2026. Launch is separate and is a target: Q4 2026 following successful testing, with initial-phase participants at full volumes targeted for… - pubDate: 2026-09-12 ### Mastercard Wallet Pay Explained: What Is New, What Was Already Live, and How It Works - url: https://paymentbrief.com/articles/mastercard-wallet-pay-digital-wallet-tokenization/ - type: article - summary: Mastercard Wallet Pay, announced 9 September 2026, is a name for eight wallet products, some already live. Its namesake piece tokenizes a wallet account so users can pay where Mastercard is accepted, with no physical card. No launch dates or pricing are published. - topic: global-payments - keyFacts: - Official name: Mastercard Wallet Pay — Mastercard calls it a "global portfolio of solutions" - Announced: 9 September 2026 on Mastercard's investor site; 10 September on its newsroom (Singapore dateline) - What it contains: Eight products on Mastercard's page, from account tokenization to Pay Local, MDES and Move - The piece named Wallet Pay: Account tokenization: a wallet account becomes a Mastercard payment credential, no physical card - Live before the announcement: Pay Local (Nov 2024); Kakao Pay tap-to-pay at Mastercard merchants via Alipay+ (Sep 2025) — Mastercard does not say which Wallet Pay product that is - Launch dates and pricing: Not published. Availability may vary by market, wallet provider and issuer participation, per Mastercard - pubDate: 2026-09-11 ### Fedwire or CHIPS: When the Rail Behind a USD Wire Matters to an Operator - url: https://paymentbrief.com/articles/fedwire-vs-chips-usd-wire-operator-reference/ - type: article - summary: Only a member bank can put a payment on Fedwire or CHIPS, and neither rulebook gives its customer a say. Whether your bank will act on a routing request is a question about its terms. The rail still decides who holds the record, what 'sent' means, and which cutoff you missed. - topic: psp-and-infrastructure - keyFacts: - Who can be a direct participant: Fedwire: depository and certain other institutions holding a Federal Reserve Bank account, subject to Federal Reserve policy. CHIPS, per TCH: 43 direct participant banks; others via correspondent or respondent relationsh… - What 'sent' means: Fedwire: immediate, final and irrevocable once processed (Board); accepted payment orders are settled on acceptance (OC6). CHIPS, per TCH: final once released and settled — release depends on CHIPS rules and available li… - Fedwire business day: Opens 9:00 p.m. ET the preceding calendar day, closes 7:00 p.m. ET; customer transfers cut off 6:45 p.m. ET, bank transfers 7:00 p.m. ET - CHIPS window: 21-hour processing window per The Clearing House. Its rulebook and PFMI public disclosure give the clock: opens 9:00 p.m. ET the preceding calendar day, closes 6:00 p.m. ET for delivery of payment messages. TCH states th… - Settlement model: Fedwire: real-time gross settlement on Reserve Bank master accounts. CHIPS, per TCH: continuous intraday settlement with a liquidity-saving mechanism, ~26:1 liquidity efficiency in 2025 - Scale (basis stated): Fedwire 2025 (FRFS): 869,187 transfers and $4.59 trillion per business day on average. CHIPS (TCH): more than 630,000 transactions each business day and more than $2 trillion in average daily value - Tracing reference: Fedwire: every successfully processed message carries IMAD and OMAD (FRFS). CHIPS: the rulebook's return-of-funds procedure identifies a payment by its payment sequence number; what TCH does not state is which identifier… - Who operates and supervises: Fedwire: operated by the Federal Reserve Banks. CHIPS: operated by The Clearing House Payments Company, a designated FMU on that basis; the Board is Supervisory Agency under Dodd-Frank Title VIII and Regulation HH - pubDate: 2026-09-04 ### The Merchant of Record Operating Model: A Reference for Operators - url: https://paymentbrief.com/articles/merchant-of-record-operating-model-operator-reference/ - type: article - summary: Merchant of record is a commercial label, not a card-scheme role or a statutory status. The schemes classify by conduct. And the most detailed MoR agreement of the four examined does not absorb chargeback cost — it entitles the provider to recover the full amount plus a fee. - topic: psp-and-infrastructure - keyFacts: - Absent from the rulebooks examined: The phrases merchant of record and seller of record return no occurrences in the Visa and Mastercard rule documents reviewed for this reference - Visa's three-part conduct test: Applies to an entity that deposits a Transaction, receives Settlement from, and contracts with an Acquirer or a Payment Facilitator: sells the goods or services to the cardholder; uses its name primarily to identify its… - Liability cannot be pushed to cardholders: Visa requires marketplace and payment facilitator agreements to state that financial liability must not be transferred by asking cardholders to waive dispute rights, and separately bars any Merchant from requiring a card… - Chargeback cost returns to the supplier (Paddle): Paddle's master services agreement entitles Paddle to the full refund or chargeback amount, its fees and expenses, and a fee of up to 20 GBP, USD or EUR, or 40 AUD or CAD, with a set-off right to take it - FastSpring's vendor terms are silent on allocation: No merchant-of-record, reseller, tax-allocation, refund-funding or chargeback-allocation clause; those mechanics sit in a non-public Order Form. Payouts are addressed: a discretionary hold may be applied at onboarding - Tax law asks a different question: Singapore and HMRC both use a deemed-supplier test built on terms, charge authorisation, delivery authorisation and who the documentation names; California instead uses a facilitation test scoped to tangible merchandise - pubDate: 2026-09-03 ### When the Acquirer Statement Is Wrong: The Notice Deadlines That Can End the Claim - url: https://paymentbrief.com/articles/acquirer-statement-dispute-notice-deadlines-operator-reference/ - type: article - summary: There is no industry-standard process for disputing an acquirer statement. There is a notice deadline in your own contract — and published agreements differ in length, in what starts the clock, and in whether missing it merely weakens the claim or extinguishes it. - topic: psp-and-infrastructure - keyFacts: - The deadline is contractual, not regulated: Every deadline in this article comes from a published merchant agreement or operating guide, not from a scheme rule or a regulator's redress process - U.S. Bank Business Essentials / Elavon (US): 45 days from the date of the Elavon statement or invoice; after that Elavon 'will not be liable to you for any errors related to that statement' - The second 45-day clock in the same clause: After giving notice, the merchant may not make any claim against Elavon for 45 days; during that period Elavon may investigate and propose a resolution, but is not required to - Fiserv Merchant Agreement General Terms (Malaysia): 60 days from the earlier of first access to the statement or the statement date; late-reported errors carry 'no obligation to provide refunds for, or otherwise make good' - Worldpay Canada BCMA v4.2025: 30 business days to reject a report, notice or invoice and 5 business days to report settlement funds not received — failure 'shall constitute Merchant's acceptance of the same' - The trigger is what really differs: Elavon's UK Terms of Service (03/2026), within a month of the US terms, has no statement-specific clause — but its §22.6 general claim duty runs six months (thirteen for incorrectly executed payment transactions) from aw… - pubDate: 2026-09-02 ### Payment Link Operations: The Link Is Not the Payment, and It Is Not the Order - url: https://paymentbrief.com/articles/payment-link-operations-lifecycle-operator-reference/ - type: article - summary: A payment link is a third object alongside the payment and the order, with its own identifier, its own states and its own expiry rules where the provider defines any. The operational differences sit almost entirely in expiry, reuse and revocation defaults. - topic: psp-and-infrastructure - keyFacts: - Adyen link states: Four documented values — active, expired, completed, paymentPending — where paymentPending exists specifically for payment methods with an asynchronous flow - Adyen expiry defaults: 24 hours by default, a maximum of 70 days, and early expiry after five unsuccessful payment attempts on the same link - No time-based Stripe link expiry on the eight pages checked: No expiry default, maximum or parameter appears across the eight Stripe payment-link pages cited here; the only two uses of the word describe the page a deactivated link redirects to - A Stripe payment link cannot be deleted: Stripe states that after creation a link cannot be deleted — it can only be deactivated by setting active to false, and reactivated through the API at any time - Stripe's usage cap is opt-in: restrictions is an optional object; the limit inside it is required only once you use it, so there is no default cap and the link auto-deactivates only once a limit you set is reached - Checkout.com prevents link reuse: Checkout.com states it checks that a link has not already been used or expired before loading the payment page; links also expire after 24 hours by default and cannot be embedded in iframes - Adyen deletes link records: Payment link details are kept for three months; after that the link details are no longer retrievable through the API - pubDate: 2026-09-02 ### Zero-Value Authorization: What the Issuer Actually Verifies, and What an Approval Does Not Prove - url: https://paymentbrief.com/articles/zero-value-authorization-account-verification-operator-reference/ - type: article - summary: Visa's Account Verification is a zero-amount message confirming a card is valid and not lost or stolen. Code 00 attests only a balance greater than zero; 85 means the balance was never checked. Neither proves funds for a future charge, and a declined one bars storing the card. - topic: psp-and-infrastructure - keyFacts: - Defined term: Account Verification — a zero-currency-unit message from acquirer to issuer (Visa glossary, ID# 0029700) - Merchant rule: Verification must use zero and must not initiate a purchase (5.7.2.1) - Issuer checks: Account number valid, not reported lost or stolen; CVV/CVV2/CAVV results on request (7.3.10.1) - Response semantics: 00 = balance greater than zero; 85 = balance not checked. Neither promises future funds - Stored credentials: If the verification is not approved, the merchant must not store the credential (Table 5-22) - Reattempt budget: Verifications count in Table 7-2 — up to 20 attempts in 30 days, Category 1 never - Prepaid quirk: Non-reloadable prepaid + recurring: issuer must decline the verification with code 57 - pubDate: 2026-09-02 ### VAT and GST on PSP Fees: Why 'Payment Fee' Is Not a Tax Classification - url: https://paymentbrief.com/articles/vat-gst-on-psp-fees-uk-singapore-operator-reference/ - type: article - summary: A functional test and a closed statutory list answer the same question differently. The UK asks whether a service performs the essential functions of a transfer; Singapore asks whether your supply is on a list — and which leg of the payment chain it sits on. - topic: payments-economics - keyFacts: - The UK's test: Functional. To be exempt, a service must form a distinct whole, fulfilling the specific, essential functions of a transfer — HMRC's manual, following the CJEU in Bookit (C-607/14) and NEC (C-130/15) - HMRC moved its own guidance: VATFIN2320, filed under 'services and products falling within item 1', now says only that the guidance moved to VATFIN2450 — which sits under 'not falling within item 1' - Singapore's test: A closed statutory list. Fourth Schedule Part 1 paragraph 1(c) names the supply made by a card operation to the person who accepts the card in payment for goods or services - IRAS names the MDR: A footnote in the GST guide for the banking industry states the Merchant Discount Rate is a separate supply exempt under paragraph 1(c) - The leg changes the answer: Singapore's statutory definition of 'credit' excludes a payment card supplied to a cardholder for which a joining or subscription fee is charged - Reverse charge asymmetry: The UK reverse charge never applies to exempt services; Singapore's applies only to an RC Business — a recipient not entitled to full input tax credit - pubDate: 2026-09-01 ### Weekend and Holiday Payment Settlement: What Actually Stops, and What Doesn't - url: https://paymentbrief.com/articles/weekend-holiday-payment-settlement-operator-reference/ - type: article - summary: Authorizations don't stop on Saturday, but what happens next is per-rail. Some settlement systems pause until the next banking day; some settle Sunday morning in central bank money or against a prefunded pool. The mechanism layer: what stops, what doesn't, and why. - topic: psp-and-infrastructure - keyFacts: - FedACH non-same-day settlement: Occurs at 8:30 a.m. ET on the later of the next banking day or the Operating Circular 4 Appendix B settlement date — a file processed when there is no banking day waits for one - Fed Sunday-holiday convention: For holidays falling on Sunday, Federal Reserve Banks are closed the following Monday; for Saturday holidays they are open the preceding Friday - FedNow never closes — its business day does: Messages process continuously; the Funds Transfer Business Day closes and rolls to the next cycle day at ~7 p.m. ET, and settlement dates follow the cycle day, not the calendar date - How RTP settles on a Sunday: Payments move positions against a Prefunded Balance Account held for the joint benefit of funding participants; completion of settlement constitutes final settlement, any day - Europe's split calendar: T2 (large-value) is open Monday–Friday and closed Saturday, Sunday, and six euro closing days; TIPS settles instant payments in central bank money 24 hours a day, 365 days a year - The merchant-visible layer: Stripe's daily payout schedule transfers available funds every business day; payouts scheduled on weekends or holidays arrive on the next business day - pubDate: 2026-09-01 ### Canada RPAA PSP Registration: An Operator Reference - url: https://paymentbrief.com/articles/canada-rpaa-psp-registration-operator-reference/ - type: article - summary: Bank of Canada registration under the Retail Payment Activities Act is mandatory for any PSP active in Canada — including a foreign PSP with no Canadian office, if it directs activities at Canadians. Who's caught, what registration requires, and what follows. - topic: risk-and-compliance - keyFacts: - Who must register: A PSP meeting all four Bank of Canada criteria: performing non-incidental payment functions, constituting a retail payment activity, meeting the geographic scope test, and not falling under an exclusion (RPAA ss.2, 4-10)… - Foreign-PSP scope test: A PSP with no Canadian place of business is still caught if it performs a retail payment activity for an end user in Canada and directs retail payment activities at individuals or entities in Canada (RPAA s.5). - Registration fee: A one-time, non-refundable fee set at $2,500 for the year the fee provision came into force, adjusted annually by a Consumer Price Index formula with a floor against year-over-year decrease (Retail Payment Activities Reg… - Maximum administrative monetary penalty: Up to $1,000,000 for a serious violation and up to $10,000,000 for a very serious violation, per the Regulations' own classification (SOR/2023-229, ss.47-48) — matching the $10,000,000 ceiling the Act allows regulations… - Risk-management and safeguarding in force: 8 September 2025 — the date RPAA ss.17-22 (operational risk framework, safeguarding of funds, annual report, significant-change notice) came into force. - Registration required from: 16 November 2024, when RPAA s.23 came into force, with a transitional filing window for PSPs already active; the Bank's duty to register applicants (s.25) followed on 8 September 2025. - Annual assessment fee: The Act's own Part 6 (ss.99-100), which would authorize an annual assessment fee, is marked 'not in force' in the Department of Justice's consolidated text (current to 21 June 2026) — a status worth confirming directly w… - pubDate: 2026-08-31 ### Request for Payment on RTP and FedNow: An Operator Reference - url: https://paymentbrief.com/articles/request-for-payment-rtp-fednow-operator-reference/ - type: article - summary: RfP is a request message, not a debit — the payer's own action produces the credit push. Both networks police what a request may be FOR with a legitimate-purpose warranty and run a dispute process that isn't a chargeback. RTP and FedNow diverge on how prescriptive it is. - topic: psp-and-infrastructure - keyFacts: - RfP creates no debit obligation: RTP Rule VII.B.1: a Request for Payment 'shall not constitute the initiation of a debit or impose any obligation on the Message Receiver to pay any amount to the Message Sender' - Matching claim windows on both rails: A warranty-breach claim must be initiated within 95 calendar days of the Responding Payment/settled credit transfer on both RTP (Rule VII.C.1.b) and FedNow (Operating Procedures s.12.d); the Sender/Sending Participant mu… - RTP publishes a named permissible-use taxonomy: Business to Business, Account to Account, Consumer Bill Pay, Consumer Down Payment/Security Deposit/Final Payment, Government Payments, Healthcare Payments, and Trusted Party — TCH Rules Interpretation, effective 15 Apri… - Goods/services complaints do not, by themselves, breach the warranty: RTP: 'A complaint regarding the quality or delivery of goods or services does not by itself constitute the allegation of facts sufficient to support a claim of breach' (Rule VII.C.5.e); FedNow: dissatisfaction with quali… - RTP disputes can reach binding arbitration with an enforced money-back remedy; FedNow's cannot: RTP Rule VII.C.7 gives TCH a formal Arbitration Proceeding with a published RFP Fine Schedule and a final, binding decision; if TCH finds a breach, the Message Sending Participant must return the Responding Payment amoun… - Both rulebooks are current, not scheduled — but RTP's next edition is close: TCH's own document library labels the June 1, 2026 RTP Operating Rules used here as 'Current' as at 31 August 2026, with newer editions already published as 'Upcoming,' effective 30 September and 4 October 2026 — within… - FedNow's zero-dollar RFP is an onboarding tool, not a warranty mechanic: A biller can send a $0 RFP first to test whether a customer's bank can present and respond to RFPs before sending a real one; PaymentBrief found no equivalent practice in the RTP Operating Rules text cited here - pubDate: 2026-08-31 ### Wero and the iDEAL Migration: An Operator Reference - url: https://paymentbrief.com/articles/wero-ideal-migration-operator-reference/ - type: article - summary: Wero's own scheme site says all iDEAL merchants move to Wero by end-2027, then the iDEAL brand is phased out — but the same page hedges that timeline as subject to regulator consultation. What's live, what's announced, and what the sources don't say. - topic: psp-and-infrastructure - keyFacts: - Wero live today: P2P and online payments, available to most bank customers in Belgium, France and Germany (wero-wallet.eu) - EPI Company licence: Authorised by the National Bank of Belgium as a payment institution, 20 February 2024 — PISP and AISP services - iDEAL | Wero branding: Already live on ideal.nl today; a separate merchant-checkout co-branding rollout — 'Phase 1: iDEAL | Wero (from Q1 2026)' — is the scheme's stated next step - Netherlands launch: Not yet live — EPI Company states it is 'actively working towards launching in the Netherlands and Luxembourg,' targeted for 2026 - Full iDEAL merchant migration: 'By the end of 2027 at the latest' per ideal.nl — stated as an outer-bound target, not a locked date - Regulator caveat: ideal.nl's own migration page: communication on technical migration and final milestones is 'subject to further consultation with the regulator' - EPI scale: 18 banks and financial services companies across five European countries (epicompany.eu) - pubDate: 2026-08-31 ### Acquirer Credit Risk on Delayed-Delivery Merchants: An Operator Reference - url: https://paymentbrief.com/articles/acquirer-credit-risk-delayed-delivery-merchants-operator-reference/ - type: article - summary: When a merchant takes payment now for delivery later, the acquirer is exposed to a cardholder dispute right that outlives the transaction by months. This is how US bank supervisory guidance frames that exposure, sizes it, and mitigates it. - topic: risk-and-compliance - keyFacts: - Why exposure exists: Visa states the non-receipt filing limit by reference to the expected-delivery date as well as the transaction date, so exposure can outlast the merchant's own possession of the funds. - Visa non-receipt dispute time limit: 120 calendar days from the transaction processing date, or 120 calendar days from the last date the cardholder expected to receive the goods or services. Table 11-92 states both and does not spell out how they interact —… - Ceiling on the expected-delivery measure: Footnote 4 caps the expected-delivery measure at 540 calendar days from the transaction processing date. It attaches to that bullet only — Europe's bonding-authority deadline carries a different footnote and no 540-day c… - OCC's own examples of future/delayed delivery: Airline tickets, concert tickets, and travel/tour packages — the Comptroller's Handbook's own illustrations, not an exhaustive list. - US mitigation tool named for this exposure: Holdback or reserve accounts, funded by a lump sum or a withheld percentage of daily proceeds, per OCC guidance. - What the OCC is: Bank supervisory guidance for examiners assessing national banks and federal savings associations — not a scheme rule and not a merchant-facing obligation. - Visa's airline-specific acquirer requirement: An acquirer signing an airline merchant must meet Visa's capitalization and reserve requirements and get Visa's approval of a business plan before submitting transactions for that airline. - Underwriting instruction on chargeback history: OCC guidance tells examiners a bank should reject a merchant with a history of substantial charge-back volume at initial review, not merely price or tier it upward. - pubDate: 2026-08-30 - reviewedDate: 2026-09-02 ### SEPA Mandate Amendment and Migration: What Survives a Change of PSP, Creditor ID or Entity - url: https://paymentbrief.com/articles/sepa-direct-debit-mandate-amendment-migration-operator-reference/ - type: article - summary: Changing your Creditor PSP requires no mandate amendment at all — the PSP is not a mandate attribute. Changing your Creditor Identifier, name or mandate reference does, and the rulebook defines exactly how that data travels: in the next collection, not as a separate message. - topic: psp-and-infrastructure - keyFacts: - Rulebook: EPC016-06, 2025 version 1.1, effective 5 October 2025 - Change of Creditor PSP: No mandate amendment — the PSP is not a mandate attribute - Amendment needed for: New mandate reference, new Creditor Identifier, new creditor name, new debtor account - How it travels: As part of the next collection, not a separate message - Creditor takeover: Original Creditor Identifier and original mandate reference carried in AT-M004 and AT-M005 - Signing date: Stays fixed for the mandate's life; migrated mandates may lack it - Debtor notice: After merger or acquisition, the new creditor must inform the debtor by any means - pubDate: 2026-08-30 ### Visa's Four Decline Categories: Which Codes You May Never Retry, and the 20-in-30 Limit - url: https://paymentbrief.com/articles/visa-decline-categories-reattempt-limits-operator-reference/ - type: article - summary: Visa Core Rules Table 7-2 sorts every decline response code into four categories with different reattempt rights. Category 1 — the issuer will never approve — must never be resubmitted for the same payment credential. Categories 2, 3 and 4 permit up to 20 attempts in 30 days. - topic: risk-and-compliance - keyFacts: - Rule: Visa Core Rules 7.3.6.3 and Table 7-2, April 2026 edition - Category 1: Issuer will never approve — never resubmit for the same payment credential - Categories 2, 3, 4: Reattempt permitted, up to 20 attempts in 30 days - Category 3 examples: 54 expired card, 55 PIN incorrect, N7 CVV2 failure, 1A additional authentication (CEMEA and Europe) - Issuer duty: Send the code that most accurately reflects the decline reason; Category 1 codes must be sent consistently - New code: 83 Fraud/Security, Visa use only, effective 25 July 2026 - Exception: Mobility and transport transactions follow their own resubmission rule - pubDate: 2026-08-30 ### DebiCheck: The Mandate Your Customer's Bank Holds a Copy Of - url: https://paymentbrief.com/articles/debicheck-authenticated-mandates-operator-reference/ - type: article - summary: The payer's own bank keeps a copy of the mandate and refuses collections outside its terms — a different trust model from every other direct-debit scheme. But it is opt-in, the custody model is shared with an unauthenticated sibling, and the dispute edge was legislated away. - topic: psp-and-infrastructure - keyFacts: - Model: Payer's bank holds the mandate and validates each collection against it - Not unique to DebiCheck: Registered Mandate shares the custody model; DebiCheck adds payer authorisation - Adoption: Opt-in — service providers choose DebiCheck or EFT debit - Live since: August 2018 - Legacy replaced: AEDO and NAEDO discontinued 1 November 2021 - Non-authenticated sibling: Registered Mandate — a standalone system since May 2025 - Dispute window: Decision taken to unify at 60 days; effective date not in the primary source - Tracking: Up to 10 days — a period PASA records as under review - pubDate: 2026-08-28 ### France–Senegal Remittance: The Peg Does Not Remove Your FX Risk - url: https://paymentbrief.com/articles/france-senegal-remittance-corridor-operations/ - type: article - summary: Senegal's currency is pegged to the euro, so there is no rate to hedge. The risk moves instead into settlement mechanics: e-money issuers cannot receive foreign funds directly, and must route through an approved intermediary bank. - topic: global-payments - keyFacts: - Peg: 1 EUR = 655.957 XOF, fixed since 1994 - Sending-side licence: ACPR full payment institution — simplified status excludes remittance - Receiving-side instrument: BCEAO Instruction n°001-01-2024, 23 January 2024 - Mobile-money payout: Routes via an approved intermediary bank, not EMI-direct - PI-SPI scope: The eight UEMOA countries — not cross-border - Corridor cost: 2.41% on a EUR 140 send (World Bank, Q3 2025) - Senegal FATF status: Removed from the grey list, October 2024 - eco timetable: 2027 target reaffirmed July 2026; first participants not yet specified - pubDate: 2026-08-28 ### Nacha's Credit-Push Fraud Rules: Monitoring Duties, Not Liability - url: https://paymentbrief.com/articles/nacha-credit-push-fraud-rules-ach-operator-reference/ - type: article - summary: Both phases of Nacha's fraud-monitoring rules are live. They oblige almost every ACH originator and receiving bank to run risk-based fraud processes — but they explicitly do not require per-entry screening, do not require pre-processing checks, and do not move liability. - topic: risk-and-compliance - keyFacts: - Phase 1 effective: 20 March 2026 — all ODFIs, plus parties above the 2023 volume threshold - Phase 2 effective: 19 June 2026 — a federal holiday, so Nacha gives 22 June 2026 as the practical date - Origination threshold (Phase 1): 2023 ACH origination volume of 6 million entries or greater - Receipt threshold (Phase 1): 2023 ACH receipt volume of 10 million entries or greater - The core obligation: Risk-based processes and procedures, reviewed at least annually - Liability: Unchanged — the rules expressly disclaim modification of UCC Article 4A - Recovery after settlement: An RDFI must advise the ODFI of the status of a Request for Return within ten banking days — but complying with the request stays optional - Next deadline: 18 September 2026 — three rules: 9:00 a.m. funds availability for non-Same Day credits, its time-zone exception, and a rewritten IAT definition that can reclassify payments - pubDate: 2026-08-28 - reviewedDate: 2026-09-04 ### Nested Third-Party Senders: The ACH Role You Might Hold Without Knowing - url: https://paymentbrief.com/articles/nacha-third-party-sender-nested-tps-operator-reference/ - type: article - summary: A Nested Third-Party Sender is one that contracts with another TPS rather than directly with the bank. Nacha requires every TPS to run its own risk assessment, and says explicitly that you cannot rely on one done by another party in your chain. - topic: risk-and-compliance - keyFacts: - Nested TPS: Contracts with another TPS, not directly with the ODFI - Rule effective: 30 September 2022, with a six-month grace period for certain aspects - Nesting levels: The Rules do not address or limit how many - Risk assessment: Every TPS must do its own — it cannot be inherited - Registration timing: Later of 30 days from first entry, or 10 days from the ODFI learning of the nesting - Change updates: Within 45 days of any change to information previously provided - ODFI duty: Not required to review TPS risk assessments - pubDate: 2026-08-28 ### The PSR Directed Visa and Mastercard on Scheme Fees — and It Is Not a Price Cap - url: https://paymentbrief.com/articles/psr-card-scheme-fee-remedies-operator-reference/ - type: article - summary: The UK regulator gave Visa and Mastercard two binding directions in July 2026. One forces better fee information to acquirers, the other forces written records of pricing decisions. Neither caps a fee. The first compliance date is November 2026. - topic: payments-economics - keyFacts: - Instrument: Two specific directions under s54(3)(c) FSBRA, July 2026 - Who is directed: Mastercard and Visa — not acquirers, not merchants - Pricing Governance live: November 2026 — four months from publication - ITC live: July 2027 — twelve months from publication - Materiality threshold: £250,000 annual gross revenue — applies to ITC2 and the AFDR, not to ITC1 - Scope: UK — Pricing Governance is scoped to UK transactions, ITC to UK acquirers - What it is not: Not a price cap — no fee is capped or reduced - pubDate: 2026-08-28 ### SPAA: Europe's Paid Open Banking Scheme, and the Register That Explains Its Problem - url: https://paymentbrief.com/articles/spaa-sepa-payment-account-access-operator-reference/ - type: article - summary: PSD2 made account access mandatory and free. SPAA makes premium access contractual and paid, with a default fee schedule between participants. The scheme has been effective since November 2023 — and the EPC's own register lists five participants, every one of them a broker. - topic: psp-and-infrastructure - keyFacts: - What it is: An EPC scheme for premium API access to payment accounts - Rulebook: EPC012-22 v1.1, issued 26 June 2023, effective 30 November 2023 - Participants: Asset Holders (ASPSPs) and Asset Brokers (TPPs) - Not participants: Asset Owner (the customer) and Asset User (typically the merchant) - Commercial model: Default asset fees plus a default API access fee, variable downward by bilateral agreement - Register, 28 Aug 2026: Five participants — all Asset Brokers, no Asset Holders - Customer pricing: Explicitly outside the scheme's scope - Delegated SCA: Broker authenticates and takes fraud liability — encouraged, expressly not mandated - pubDate: 2026-08-28 ### Visa Payment Passkey: The Acquirer Mandate and the Liability Protection - url: https://paymentbrief.com/articles/visa-payment-passkey-operator-reference/ - type: article - summary: Issuers must support Visa Payment Passkey and stop systematically declining it. Acquirers must let e-commerce merchants offer it. A valid cryptogram with ECI 5 or 6 earns fraud liability protection — but check which paragraph that sentence sits in before assuming it covers you. - topic: risk-and-compliance - keyFacts: - What it is: A Visa solution using FIDO standards for cardholder verification in e-commerce - Sits inside: The Digital Commerce Authentication Program (DCAP) - Called in Europe: Visa ecommerce experience (Vee) - Issuer duty from: 18 April 2026 — AP and Europe; 24 October 2026 — Canada, CEMEA, LAC - Acquirer duty from: 18 April 2026 — AP; 24 October 2026 — Canada, CEMEA, LAC. Europe is not in this list - Liability protection: Valid cryptogram plus ECI 5 or ECI 6 — inside the acquirer paragraph's region and date scope - Does not apply: Bangladesh, Bhutan, India, Nepal (AP) and Chile (LAC) - pubDate: 2026-08-28 ### Visa Third Party Agent Registration: Who Has to Register, and What Changes in October 2026 - url: https://paymentbrief.com/articles/visa-third-party-agent-registration-operator-reference/ - type: article - summary: Provide payment-related services to a bank or its merchants, directly or indirectly, and Visa's rules likely make you a Third Party Agent. Registration is your sponsor's job, must finish before you process anything, and tightens in the US and Canada on 24 October 2026. - topic: risk-and-compliance - keyFacts: - Who registers: The Member (your sponsor bank), not the agent - Timing: Before any contracted services or transaction activity - Visa's discretion: May deny or reject a registration at any time, with or without cause - Affiliate exemption: Only where Member affiliates own and control at least 25% of the agent - Exemption does not cover: PayFacs, marketplaces, staged wallet operators, BPSPs, CBPSPs - US / Canada change: 24 October 2026 — identifier, BIN and account-range disclosure, reviewed annually - Change notification: Within 5 business days of a change in principals or business relationship - pubDate: 2026-08-28 ### How Card Scheme Mandates Reach You: Release Cycles and Notice - url: https://paymentbrief.com/articles/card-scheme-mandate-release-cycles/ - type: article - summary: The compliance date your acquirer quotes almost never comes from a scheme document you can read. Amex states its cadence and notice period publicly. For Visa and Mastercard, your PSP's release guide is the primary source in practice. - topic: psp-and-infrastructure - keyFacts: - Amex cadence: Technical Specifications published April and October - Amex notice period: Certification requirements communicated 6 months before publication - Visa pattern: Spring and autumn release periods — documented by PSPs, not publicly by Visa - Mastercard Rules edition: 2 June 2026, public PDF (503 pages) - Visa Core Rules edition: 18 April 2026, public PDF - Not public: Mastercard Announcements — the portal requires a sign-in; Visa Business News — Visa states the articles are not public materials - Regional variation: Confirmed — same mandate, different dates and thresholds by region - pubDate: 2026-08-27 - reviewedDate: 2026-09-01 ### Chile Acquiring After Transbank: Deregulation and Cross-Border Rules - url: https://paymentbrief.com/articles/chile-acquiring-transbank-deregulation-cross-border/ - type: article - summary: Two things changed in Chile within seven months: a competition regulator confirmed Transbank had fallen below 50% share and released its tariffs, and the CMF created a licensed route for foreign merchants to accept Chilean cards. - topic: global-payments - keyFacts: - Four-party model live: 1 April 2020 - Deregulation condition: TDLC Resolución 86, 11 March 2025 — below 50% for 6+ months - Condition declared met: FNE Resolución 22, 28 January 2026 - Cross-border regime: CMF NCG 541, 23 July 2025 - Sub-acquiring operator capital: UF 1,000; UF 2,000 if doing cross-border acquiring - Interchange caps in force: Debit 0.50%, credit 1.14%, prepaid 0.94% — provisionally maintained - Scheduled lower caps: 0.35% / 0.80% / 0.80% — never took effect; under review since 30 Sep 2024 - pubDate: 2026-08-27 ### Click to Pay and EMV SRC: What They Are and What They Are Not - url: https://paymentbrief.com/articles/click-to-pay-emv-src-operator-reference/ - type: article - summary: The SRC specification does not require tokenisation and does not govern authentication — it says so in its own words. Four things get collapsed into one here, and separating them is most of the work. - topic: psp-and-infrastructure - keyFacts: - SRC: The EMVCo specification — roles, APIs, checkout choreography - Click to Pay: The consumer brand built on SRC; EMVCo licenses the icon - Tokenisation: Supported as an option by SRC, not required by it - Authentication: SRC states it does not govern authentication; 3DS is layered on - Enrolment: Consumers enrol via participating card issuers, not via merchants - Returned to merchant: A payload — typically a network token, not the PAN - Current public specs: SRC API v1.5 (30 Oct 2025); CX Guidelines v1.2 (18 Mar 2026) - pubDate: 2026-08-27 ### Pix Automático Operations: Mandates, Retries, Refunds, Reconciliation - url: https://paymentbrief.com/articles/pix-automatico-recurring-debit-operations/ - type: article - summary: Pix Automático runs two separate retry obligations, and only one is optional — a flag set at recurrence creation. The refund path is not the fraud path. Two objects, not one, govern every mandate. - topic: global-payments - keyFacts: - Launched: 16 June 2025 (BCB) - Same-day attempts: Unconditional — 00:00–08:00, then a mandatory retry 18:00–21:00 - Post-due-date retries: Up to 3, on separate dates, within 7 days of the scheduled settlement date, and not past the next cycle — only if permitted - Retry flag: politicaRetentativa — PERMITE_3R_7D or NAO_PERMITE, set at recurrence creation - Scheduling window: 2 to 10 days before the scheduled settlement date - First collection window: 00:00–08:00; mandatory retry 18:00–21:00 the same day - Payer cancellation deadline: 23:59 the day before settlement - Pix Automático MED refund: Payer's PSP refunds in full within 24 hours, then seeks reimbursement - Payer-side participation: Mandatory for every Pix participant offering transactional accounts - pubDate: 2026-08-27 ### US–India Remittance: The Two Perimeters an Operator Has to Satisfy - url: https://paymentbrief.com/articles/us-india-remittance-corridor-operations/ - type: article - summary: MTSS caps a transfer at USD 2,500 and 30 per beneficiary per year. RDA forbids cash payout entirely. Regulation E gives the sender 30 minutes to cancel. And UPI does not carry money from the US to India. - topic: global-payments - keyFacts: - MTSS per-transaction cap: USD 2,500 - MTSS per-beneficiary cap: 30 remittances per calendar year - MTSS cash cap: INR 50,000 - RDA cash disbursement: Not permitted - Reg E cancellation window: 30 minutes after payment, refund within 3 business days - Reg E safe harbour: 500 or fewer transfers in prior and current calendar year - US excise tax from 1 Jan 2026: 1% — cash, money order and cashier's cheque funding only - Corridor cost: 3.68% on a USD 200 send (World Bank, Aug 2025 survey window) - pubDate: 2026-08-27 ### Colombia Payments Operator Guide: SFC Foreign Ownership, SEDPE Capital, and FX Repatriation - url: https://paymentbrief.com/articles/colombia-payments-operator-guide/ - type: article - summary: Colombia's foreign-investment decree doesn't just fail to cap foreign ownership of payment institutions — it states investors may hold shares in any proportion, a stronger posture than mere silence. Verified against Colombia's own decrees and Banco de la República's FX rules. - topic: global-payments - keyFacts: - Foreign ownership cap: None — affirmatively stated as unlimited ("cualquier proporción") - 10%+ share-acquisition gate: SFC fit-and-proper approval; nationality-neutral (EOSF Art. 88) - SEDPE minimum capital: COP 5,846,000,000 (2014 base), DANE CPI-indexed every January - SEDPE leverage ratio: 2% minimum (technical equity ÷ 30-day average e-money float) - SEDPE fund custody: Banco de la República deposits or demand deposits at supervised banks - Acquiring entry route: 4 conditions (Art. 2.17.3.1.2): SA, capital ≥1,700 SMMLV entry floor, fund segregation, PLUS an ongoing capital floor of ≥2% of trailing-12-month settled volume from year 1 onward — this scales past the entry floor as vo… - Dividend/profit repatriation: Register once with BanRep, then remit via regulated FX market — no per-dividend cap - Dividend withholding tax: 20% on payments to foreign companies/non-residents (Estatuto Tributario Art. 245) - pubDate: 2026-08-26 ### Mastercard ECP and EFM: Why Chargebacks and Fraud Still Run on Two Programmes - url: https://paymentbrief.com/articles/mastercard-merchant-monitoring-ecm-hecm-efm/ - type: article - summary: Mastercard runs two permanently separate programmes: the Excessive Chargeback Program (ECP, tiered ECM/HECM, all chargebacks any reason code) and Excessive Fraud Merchant (EFM, code 4837 plus disputed 4863). Breach both and only EFM bills — ECP suspends, not waives. - topic: risk-and-compliance - keyFacts: - Programme structure: ECP (Excessive Chargeback Program) tiers into ECM and HECM; EFM is a separate peer programme - ECM threshold: 100–299 chargebacks/month AND 1.50–2.99% ratio - HECM threshold: 300+ chargebacks/month AND ≥3.00% ratio - EFM scope: CNP fraud only — Braintree names 4837 and 4863, but 4863's live status conflicts with this site's own Mastercom reference and third-party sources; confirm with your acquirer - EFM threshold (all four required): ≥1,000 e-comm txns · ≥$50,000 fraud CBs · ≥50 bps · 3DS+Data-Only <10% (non-regulated) or <50% (regulated/Europe) - Dual non-compliance rule: Only EFM bills; ECP billing suspends, not waives - Ratio denominator (both programmes): Current-month chargebacks ÷ prior-month sales - pubDate: 2026-08-26 - reviewedDate: 2026-08-26 ### Pakistan Payments Operator Guide: SBP Licensing, PayPak Acquiring, and FX Repatriation - url: https://paymentbrief.com/articles/pakistan-payments-operator-guide/ - type: article - summary: SBP licenses EMIs and PSOs/PSPs on parallel tracks, both anchored at PKR 200 million capital — neither caps foreign ownership. PayPak is being pushed into government payroll while Raast's subsidised P2M pulls volume off cards. Verified against SBP's own rules and FX Manual. - topic: global-payments - keyFacts: - EMI minimum capital: PKR 200M startup; rises with e-money balance to PKR 1.25B + 10% above PKR 20B - PSO/PSP minimum capital: PKR 200M; +25% per additional business line - SBP security deposit (both): 10% of required capital at SBP-BSC (5% cash / 5% govt securities) - Foreign ownership cap: None stated in EMI or PSO/PSP rules - Domestic card scheme: PayPak (owned/operated by 1LINK, launched 2016) - International scheme gateway: 1LINK (Visa, Mastercard, UPI, JCB) to licensed banks/affiliates - Dividend repatriation: Via designated Authorized Dealer, net of Pakistan tax - Capital-exit valuation trigger: Independent third-party review above USD 50M in 6 months - pubDate: 2026-08-25 ### Apple Pay and Google Pay Merchant Acceptance: What Operators Actually Build and Run - url: https://paymentbrief.com/articles/apple-pay-google-pay-merchant-acceptance-operations/ - type: article - summary: Apple's domain association file and Google's Pay & Wallet Console registration are the setup steps that actually block launches. Once live, the merchant holds a device token and a cryptogram, not the PAN — and wallet liability shift is conditional, not blanket, on both networks. - topic: psp-and-infrastructure - pubDate: 2026-08-24 ### Issuing Programme Operations: Running a Card Programme Day to Day - url: https://paymentbrief.com/articles/issuing-programme-operations/ - type: article - summary: BIN sponsorship gets a card programme signed. Someone still has to provision cards into wallets, set spend controls, process issuer-side disputes, fund settlement, and report to the sponsor. This is the operational reference for that layer, day two onward. - topic: psp-and-infrastructure - pubDate: 2026-08-24 - reviewedDate: 2026-08-26 ### Turkey Payments Operator Guide: Licensing, Direct Acquiring, and TROY - url: https://paymentbrief.com/articles/turkey-payments-operator-guide/ - type: article - summary: TCMB, not BDDK, licenses Turkish acquirers — and Turkish law restricts card acceptance to Turkey-incorporated entities, ruling out direct cross-border acquiring. Capital tiers, FAST access, taksit caps, and lira settlement, sourced to TCMB's own regulation text. - topic: global-payments - keyFacts: - Licensing authority for acquirers: TCMB (Ödeme Kuruluşu / Elektronik Para Kuruluşu licence under Law No. 6493) — not BDDK - Can a foreign PSP acquire directly?: No — Article 4(2) restricts payment services to TCMB, Turkish banks, TCMB-licensed Turkey-incorporated institutions, and PTT - Initial paid-in capital (kuruluş): TRY 1M (bill-payment only) / TRY 2M (other payment services) / TRY 5M (e-money issuance) — Article 11(2) - Minimum ongoing equity (özkaynak), from 30 June 2026: TRY 20M / 40M / 105M respectively (RG No. 33154, 31 Jan 2026); TRY 15M / 30M / 80M applied from 30 June 2025 - FAST direct participation: Opened to non-bank payment/e-money institutions in 2023 (TCMB Press Release 2022-53); PSP-mediated access remains the norm - Taksit (instalment) regulator: BDDK, under Law No. 5464 (Bank Cards and Credit Cards Law) — a separate regulator from TCMB's payment-licensing track - Domestic FX rule: A licensed kuruluş may not conduct FX transactions where both parties to a payment are Turkey-resident (Article 66(3)) — domestic settlement is TRY-only - pubDate: 2026-08-24 - reviewedDate: 2026-09-11 ### US Money Transmitter Licensing: How Payment Models Change the Analysis - url: https://paymentbrief.com/articles/us-money-transmitter-licensing-payment-models/ - type: article - summary: There is no US PSP licence — only a federal registration that authorises nothing, and a state-by-state licensing layer with exemptions that don't travel across state lines. This covers the trigger, the federal/state split, and how payment models change the analysis. - topic: psp-and-infrastructure - pubDate: 2026-08-24 ### Argentina Payments Operator Guide: BCRA Licensing, Transferencias 3.0, and Cuotas - url: https://paymentbrief.com/articles/argentina-payments-operator-guide/ - type: article - summary: Argentina's acquiring layer just changed hands — Visa closed on Prisma and Newpay in February 2026. BCRA licensing (PSPCP), Transferencias 3.0 clearing, cuotas mechanics, and capital-control limits on settlement, verified against BCRA, COELSA, and Visa's disclosures. - topic: global-payments - pubDate: 2026-08-23 ### Ghana Mobile Money Operator Guide: MoMo, GhIPSS, and the Interoperability Layer - url: https://paymentbrief.com/articles/ghana-mobile-money-ghipss-operator-guide/ - type: article - summary: MoMo is Ghana's default checkout, not an add-on — and GhIPSS is the interoperability layer (GIP, GhQR, MMI) most operators never integrate against. Licence tiers, capital thresholds, e-levy status, and FX rules, verified against Bank of Ghana and GRA sources. - topic: global-payments - pubDate: 2026-08-23 ### FX and Cross-Border Settlement Architecture: Where Conversion Actually Happens - url: https://paymentbrief.com/articles/fx-cross-border-settlement-architecture/ - type: article - summary: Operators can quote their FX markup and still not know where in the transaction chain conversion happened or who bore it. Maps the currency-role stack, the four conversion points, settlement-timing mechanics, and what refunds and chargebacks do to an already-converted amount. - topic: payments-economics - pubDate: 2026-08-22 ### Nigeria Payments Operator Guide: NIP, CBN Licensing, and the Foreign-Entry Question - url: https://paymentbrief.com/articles/nigeria-payments-operator-guide/ - type: article - summary: NIP is the rail, but CBN licensing decides what you may do with it — six categories, capital NGN 50M to NGN 2B, and non-bank licensees delisted from NIP's outward beneficiary system since December 2023. Verified against CBN, NIBSS, and cross-corroborated industry sources. - topic: global-payments - pubDate: 2026-08-22 ### Payment Credential Vault Architecture: Topology, Control, and Migration - url: https://paymentbrief.com/articles/payment-credential-vault-architecture/ - type: article - summary: Vault topology — PSP-owned, merchant-hosted, or third-party independent — decides who controls stored credentials. Token Requestor ownership, not token format, is what actually determines whether card-on-file credentials move with you when you switch PSPs. - topic: psp-and-infrastructure - pubDate: 2026-08-22 ### Settlement Data Ingestion and Normalisation Across Multiple PSPs - url: https://paymentbrief.com/articles/settlement-data-ingestion-normalisation-multi-psp/ - type: article - summary: Reconciling five PSPs isn't reconciling one PSP five times — it's a different problem: the same economic event in N shapes, N schedules, N identifier systems. Covers schema design, reconciliation keys, idempotent ingestion, corrected files, and webhook-vs-file conflicts. - topic: psp-and-infrastructure - pubDate: 2026-08-22 - reviewedDate: 2026-09-02 ### Card Credential Lifecycle: What Actually Keeps a Stored Card Working - url: https://paymentbrief.com/articles/card-credential-lifecycle-account-updater-operations/ - type: article - summary: Visa Account Updater and Mastercard ABU are batch/enquiry services with optional issuer participation, not universal coverage. Network tokens update automatically and cover more ground, but neither eliminates involuntary churn from expiry, reissue, or BIN migration on its own. - topic: psp-and-infrastructure - keyFacts: - Visa VAU annual account change rate: ~30% of enrolled accounts change PAN, expiry, or close per year - Visa VAU regional strength: Highest in US, Canada, UK, Ireland, Italy, Greece - Visa VCES: default changes 30 Oct 2026: Visa enables Credential Enrichment for all card-on-file token requestors (U.S., Canada, AP, CEMEA); opt-out runs through your acquirer by 30 Sep 2026 - What VCES actually changes: It acts at provisioning: a stale or absent expiry in a provision request is replaced from VisaNet data before the issuer decides. Visa documents no step that writes back to your vault; it does claim fewer CNP declines do… - Recurly: revenue lost to involuntary churn: 53% of all customer attrition - Recurly: monthly recurring decline rate: ~13% of recurring transactions decline monthly - pubDate: 2026-08-21 - reviewedDate: 2026-09-12 ### Card Issuing and BIN Sponsorship: The Operator's Guide to Program Management - url: https://paymentbrief.com/articles/card-issuing-bin-sponsorship-program-management/ - type: article - summary: Card issuing inverts the acquiring-side economics operators already know: interchange is revenue, not cost, and liability sits with whoever is issuer of record. This is the BIN sponsorship, issuer-processor, and contract-term reference for operators launching a card program. - topic: psp-and-infrastructure - keyFacts: - Program chain: BIN sponsor → program manager → issuer-processor → operator - US debit interchange cap (issuers >$10B assets): $0.21 + 0.05% + $0.01 fraud adjustment (Reg II) - Exempt (small) issuer average interchange, 2024: $0.51 per transaction vs $0.23 for covered issuers - Reg E dispute timeline: Provisional credit within 10 business days; investigation extendable to 45 (90 for some transactions) - pubDate: 2026-08-21 - reviewedDate: 2026-08-26 ### Card-Present Payment Architecture: The Omnichannel Reconciliation Problem - url: https://paymentbrief.com/articles/card-present-omnichannel-payment-architecture/ - type: article - summary: Card-present runs terminal to acquirer, not browser to PSP — and the terminal can approve a transaction offline, which e-commerce never can. That difference propagates into fraud liability, PCI scope, MID sprawl, and a reconciliation step online-only operators never have to run. - topic: psp-and-infrastructure - keyFacts: - The core architectural difference: E-commerce always authorises online; an EMV terminal can approve offline using floor limits, random selection, and velocity checks against the chip - Store-and-forward is real exposure: Offline-approved transactions can still be declined once forwarded — Adyen puts typical store-and-forward authorisation rates at roughly 95%+, with the merchant liable for the rest - P2PE narrows PCI scope: A validated PCI P2PE solution encrypts card data at the terminal and decrypts only at the solution provider, cutting the applicable PCI DSS requirement set versus a standard (non-P2PE) terminal - Reconciliation is four-way, not three-way: Card-present adds a POS terminal batch layer in front of the acquirer settlement file, PSP/gateway ledger, and bank statement that online-only reconciliation doesn't have - Offline transaction limits are vendor-set, not scheme-set: Square defaults to a $100 offline cap (adjustable up to $50,000 per transaction); Stripe Terminal readers must reconnect online at least every 60 days to keep operating offline - pubDate: 2026-08-21 ### Chargeback Evidence and Representment: The Operator Reference by Dispute Scenario - url: https://paymentbrief.com/articles/chargeback-evidence-representment-operator-reference/ - type: article - summary: Reason-code references say which code applies. This reference sorts evidence by scenario instead — fraud, non-receipt, not-as-described, cancellation, duplicate, credit-not-processed — so operators know what to assemble and which claims are scheme rule vs. judgment call. - topic: risk-and-compliance - keyFacts: - Scenarios covered: 7 — fraud, not received, not as described, cancellation, duplicate, credit not processed, authorisation error - CE 3.0 scope: Visa 10.4 only — no Mastercard equivalent exists - Visa merchant response window: 30 days, all codes - Mastercard merchant response window: 45 days, all codes - Evidence categories in the toolkit: 12, reused across scenarios in different combinations and order - pubDate: 2026-08-21 - reviewedDate: 2026-09-02 ### Payment Aggregator Licence in India: What RBI's 2025 Directions Actually Require - url: https://paymentbrief.com/articles/india-rbi-payment-aggregator-licensing/ - type: article - summary: RBI quietly rewrote India's payment aggregator rulebook in September 2025, folding the 2020 PA Guidelines and the 2023 cross-border circular into one Master Direction with three categories — including a brand-new physical/POS category most operators haven't registered yet. - topic: psp-and-infrastructure - keyFacts: - Governing instrument: RBI/DPSS/2025-26/141 — Regulation of Payment Aggregators Directions, 2025 (15 Sept 2025) - What it replaced: 2020/2021 PA Guidelines + the October 2023 PA-Cross Border circular (RBI/2023-24/80), both repealed - Three categories now: PA-Online (PA-O), PA-Cross Border (PA-CB), PA-Physical (PA-P) — the last one is new - Net worth: ₹15 crore at application, ₹25 crore by end of third financial year — unchanged from 2020, applies to all three categories - PA-CB transaction cap: ₹25 lakh maximum per transaction, inward and outward - PA-P deadline: Apply by 31 Dec 2025 or wind up by 28 Feb 2026 - AML registration: Non-bank PAs must register with FIU-IND - pubDate: 2026-08-21 ### Interchange Regulation by Market: What the Caps Actually Cover - url: https://paymentbrief.com/articles/interchange-regulation-by-market-operator-reference/ - type: article - summary: A regulated interchange cap does not cap what a merchant pays. Across the EU, UK, US, Australia, Brazil, India, and South Africa, commercial cards, cross-border transactions, or scheme fees sit outside the cap in every single regime. - topic: payments-economics - keyFacts: - EU/UK consumer cap: 0.2% debit / 0.3% credit — commercial cards and (UK only) cross-border transactions excluded - US debit cap applies to: Debit only, issuers with $10B+ assets — credit interchange is unregulated - Australia reform: Consumer credit cut to 0.30% and the debit cap to 8¢ (or 0.16% ad valorem) from 1 Oct 2026; commercial credit keeps its 0.80% cap (already averaging 0.78%, per the RBA); the credit benchmark is removed; foreign cards cap… - Brazil: Debit capped at 0.5%, prepaid at 0.7% (Resolução BCB 246/2022, Art. 3) — credit interchange is not regulated at all - India: No interchange cap — RuPay debit and UPI zero MDR since Jan 2020; the statute behind it was amended (presidential assent 17 Aug 2026) to allow future fees by notification, none yet set - South Africa: SARB-regulated: debit 0.44%/0.58%, credit 1.48%/1.68% (EMV-CP vs 3DS-CNP tiers); Japan, by contrast, relies on published standard rates — no cap - pubDate: 2026-08-21 - reviewedDate: 2026-09-11 ### Payment Licensing in Mexico: IFPE, ITF, and Local Acquiring Under CNBV and Banxico - url: https://paymentbrief.com/articles/mexico-cnbv-banxico-licensing-local-acquiring/ - type: article - summary: Mexico doesn't licence 'a PSP' — CNBV authorises IFPE and ITF under the Ley Fintech, while card acquiring runs on a separate, older track most operators miss. Here's the structure, capital figures, and the IVA withholding rule that surprises foreign operators. - topic: psp-and-infrastructure - keyFacts: - Governing law: Ley para Regular las Instituciones de Tecnología Financiera (Ley Fintech), DOF 9 March 2018, last amended 14 Nov 2025 - Two ITF categories: IFPE (electronic payment funds) and IFC (crowdfunding) — each separately authorised by CNBV - Minimum capital: 500,000 UDI (≈MXN 4.4M) for single-activity/domestic-currency institutions; 700,000 UDI (≈MXN 6.2M) for FX, virtual-asset, derivatives, or clearing-house activity - Statutory resolution deadline: 90 calendar days by default; up to 180 days where the Inter-institutional Committee's opinion is required (IFPE/ITF applications) - Card acquiring: Separate registration track (Redes de Medios de Disposición) — Adquirente and Agregador roles, not IFPE-licensed - Foreign ownership: Ley Fintech Art. 13 — shares freely subscribed, no nationality cap in the law itself; CNBV vets any 10%+ stake or control regardless of origin - IVA on digital services: 16% general rate; foreign platforms register with SAT regardless of PE; up to 100% withheld if funds settle to a foreign account - pubDate: 2026-08-21 ### MID Lifecycle Operations: Opening, Amending, Migrating, and Closing Merchant IDs - url: https://paymentbrief.com/articles/mid-lifecycle-operations/ - type: article - summary: MID structure is a design decision made once; MID lifecycle is an operations problem that never stops. Opening, amending, migrating, and closing merchant IDs each carry their own underwriting, reserve, and scheme-monitoring consequences most operators only discover mid-event. - topic: psp-and-infrastructure - pubDate: 2026-08-21 ### Multi-Entity, Multi-MID Payment Architecture: Designing Merchant ID Structure - url: https://paymentbrief.com/articles/multi-entity-multi-mid-payment-architecture/ - type: article - summary: MID structure isn't a technicality — it's a risk lever. Scheme dispute-monitoring programmes measure fraud and chargeback ratios per merchant identifier, so how you split MIDs across brands, countries, and entities changes whether a business unit breaches a threshold. - topic: psp-and-infrastructure - pubDate: 2026-08-21 ### Payment Orchestration Architecture: Build vs Buy vs PSP-Native - url: https://paymentbrief.com/articles/payment-orchestration-architecture-build-vs-buy/ - type: article - summary: Orchestration, routing, gateway abstraction, and vaulting get sold as one decision — they aren't. A framework for which posture (PSP-native, bought, in-house) fits your PSP count, volume, and headcount, and the vault and reconciliation costs each posture defers. - topic: psp-and-infrastructure - pubDate: 2026-08-21 ### Payout Rail Selection for Marketplaces, Gig, and Creator Platforms - url: https://paymentbrief.com/articles/payout-disbursement-rail-selection-marketplaces/ - type: article - summary: Acceptance and payout are different rail decisions with different failure modes. Compares FedNow, RTP, SEPA Instant, Faster Payments, PayNow, UPI, PIX, local ACH, and card push on speed, cost, reach, and reversibility — plus the irrevocability trap most platforms learn late. - topic: psp-and-infrastructure - keyFacts: - Instant rails are typically irrevocable: FedNow, RTP, SEPA Instant, Faster Payments, PayNow, UPI, and PIX settle with finality in seconds to under a minute — none has a card-style chargeback to reverse a misdirected payout - SCT Inst has no scheme-level maximum amount: The 2025 EPC rulebook removed the scheme-wide cap; PSPs set their own transaction limits (EPC, rulebook effective 5 October 2025) - RTP settlement ceiling: Up to $10 million per transaction, 24/7/365 including weekends and bank holidays, over 1,300 participating institutions as of July 2026 (The Clearing House) - FedNow raised its limit to $10 million: Effective November 2025, up from $1 million, reachable through more than 1,400 participating organizations via FedLine (Federal Reserve Financial Services) - UPI finality is statutory, not just technical: India's Payment and Settlement Systems Act, 2007 makes a completed settlement final and irrevocable; standard UPI transactions cap at ₹1 lakh, rising to ₹5 lakh for specified categories (RBI) - pubDate: 2026-08-21 ### SCA Exemption Strategy: The Operator Playbook for TRA, Low-Value, and Trusted Beneficiary - url: https://paymentbrief.com/articles/sca-exemption-strategy-operator-playbook/ - type: article - summary: You don't claim an SCA exemption, you request one — the issuer decides. TRA qualifies on the requesting PSP's fraud rate, not the merchant's or a blended figure. Field 34 and the EMV 3DS exemption indicator carry the request; response code 1A/65 is the issuer saying no. - topic: risk-and-compliance - keyFacts: - TRA fraud-rate bands: ≤0.13% fraud rate for exemption up to €100; ≤0.06% up to €250; ≤0.01% up to €500 (RTS Article 18, confirmed via EBA Q&A 2018_4034 and Visa's PSD2 SCA Implementation Guide) - Whose fraud rate counts: The rate of whichever PSP is applying the exemption — acquirer or issuer — not the merchant's, and not a blended figure across customer segments or card types - Low-value exemption cap: Transactions under €30, capped at 5 consecutive exemption uses or €100 cumulative spend since the last SCA — tracked by the issuer, invisible to the acquirer - Soft decline codes on a rejected exemption: Visa response code 1A, Mastercard response code 65 — both mean 'perform SCA,' not 'transaction denied' - Visa vs Mastercard on MIT: Mastercard treats recurring/MIT as an exemption (3RI); Visa treats it as out of scope of SCA entirely — a real scheme difference, not equivalent labels for the same thing - An exemption request is not a guarantee: Visa's own rules explicitly prohibit issuers from systematically declining acquirer exemption requests or challenging TRA-flagged transactions — a rule that exists because the practice was common enough to need banning - Mastercard-specific mechanics could not be independently verified: PaymentBrief could not confirm these against Mastercard's own documentation; Mastercard mechanics cited here come from EMV 3DS server vendor documentation (Netcetera), not Mastercard's own site — flagged accordingly thro… - pubDate: 2026-08-21 ### Wallet Funding, Float, and Stored-Value Operations - url: https://paymentbrief.com/articles/wallet-funding-stored-value-operations/ - type: article - summary: Accepting GrabPay, OVO, DANA, or M-Pesa is the easy part. This covers the liability side: funding rails, who holds the float and earns on it, why safeguarding, insurance, and trust are different protections, and what happens to balances nobody spends. - topic: psp-and-infrastructure - keyFacts: - Indonesia float placement: ≥30% cash/demand deposits at BUKU 4 banks; ≤70% government securities or BI instruments (PBI 23/6/2021, Art. 165) - Indonesia float capital surcharge: +5% of managed float added to risk-weighted capital for e-money-issuing PJPs (PBI 23/6/2021, Art. 68) - Indonesia e-money is not a deposit: E-money value is not a "simpanan" under banking law and is not part of a failed issuer's bankruptcy estate (PBI 23/6/2021, Art. 157, 164) - Kenya float backing: 100% liquid-asset backing of outstanding e-money, held separately from the issuer's own operations, reconciled daily by 4:00pm EAT (Central Bank of Kenya, E-Money Regulations 2013) - M-Pesa customer interest: "No interest will be paid on any funds held in your M-PESA Account" (Safaricom, M-PESA Customer Terms & Conditions) - UK safeguarding reform date: New FCA reconciliation, audit, and reporting rules take effect 7 May 2026 — a statutory trust was proposed but deferred, not yet adopted (Norton Rose Fulbright; Sidley Austin, restating FCA PS25/12) - US stored value now licensable in Massachusetts: Massachusetts's amended money transmission law extends licensing to stored value, effective 1 October 2025 (Goodwin Law) - US gift-card expiry floor: Federal CARD Act sets a 5-year minimum before a gift card/stored-value instrument can expire; state escheatment treatment above that floor varies sharply by state (giftbit.com) - pubDate: 2026-08-21 ### A2A Merchant Acceptance Architecture: What to Build, What Carries Over - url: https://paymentbrief.com/articles/a2a-merchant-acceptance-architecture/ - type: article - summary: Pix, UPI, PayNow, PromptPay, and SEPA Instant get filed as 'bank payments' and treated as interchangeable. They aren't. This piece maps what's portable across A2A integrations — push-payment status handling, refund-as-new-payment — and what has to be rebuilt per rail. - topic: global-payments - keyFacts: - Pix static QR default: Carries only the payee's DICT key; a transaction reference (txid) is optional and defaults to the placeholder '***' if omitted (BCB Manual v2.10.0) - Pix fraud return window (MED): Original transaction must be ≤80 days old to open a case; receiving PSP has 7 calendar days to close analysis; refund execution generally within 6 hours per PSP once triggered. From 1 Sep 2026 a debited receiver may cont… - UPI operational-failure reversal: Auto-reversal by the beneficiary bank latest T+1; ₹100/day compensation payable without a complaint if delayed beyond T+1 (RBI TAT circular, Sep 2019) - SEPA Instant confirmation SLA: 5-second target, 10-second hard outer bound — if no confirmation arrives, the originator PSP must immediately restore the payer's account (EPC SCT Inst Rulebook, effective 5 Oct 2025) - SEPA Verification of Payee outcomes: Match, Close Match (discloses the registered name), No Match, or Verification Not Possible — advisory only, doesn't block payment (EPC VoP Rulebook, effective 5 Oct 2025) - SEPA Instant amount ceiling: No longer stipulated at scheme level, following the amended SEPA Regulation (EPC SCT Inst Rulebook change history) - pubDate: 2026-08-20 ### PSP Licensing and Local Acquiring in Brazil: The Operator Guide - url: https://paymentbrief.com/articles/brazil-psp-licensing-and-local-acquiring/ - type: article - summary: Operators keep searching for 'a PSP license in Brazil' as if it were one thing. It isn't — BCB authorises specific activities separately, and most sub-acquirers never need their own authorisation at all. Here's the actual structure, and what changed in 2025. - topic: psp-and-infrastructure - keyFacts: - No single licence: BCB authorises four distinct IP service categories separately — credenciador, e-money issuer, postpaid issuer, payment initiator - Sub-acquirer default: A subcredenciadora operating under contract with an authorised participant generally does not need its own BCB authorisation - Foreign entity: An IP must be a Brazilian sociedade limitada or sociedade anônima — no direct foreign-branch path - 2025 overhaul: BCB Rule 494/2025 (consolidated application), Joint Rule 14/2025 (new capital formula), Resolução 522/2025 (sub-acquirer settlement exemption removed) - Distinct from acquiring: Arranjo de pagamento (scheme) governance and its instituidor role are regulated separately from IP/acquirer licensing - pubDate: 2026-08-20 ### Failed Payment Recovery: Retry Decisioning After a Declined Charge - url: https://paymentbrief.com/articles/failed-payment-recovery-dunning-operations/ - type: article - summary: A decline isn't an outcome, it's a decisioning problem: retry or don't, on what schedule, with what changed, and what to tell the customer. Decline-code logic, scheme retry caps, smart-retry evaluation, and how to measure recovery rate without lying about the denominator. - topic: psp-and-infrastructure - pubDate: 2026-08-20 ### Merchant Payout Treasury Operations: Funding the Float Without Liquidity Gaps - url: https://paymentbrief.com/articles/merchant-payout-treasury-operations/ - type: article - summary: Which rail carries a payout and what happens when it fails are separate articles. This one is about the money itself — funding the payout float across markets and currencies without liquidity gaps, prefunding waste, or funding-cut-off failures. - topic: psp-and-infrastructure - pubDate: 2026-08-20 ### MT103 Field-by-Field: The Operator Reference - url: https://paymentbrief.com/articles/mt103-field-by-field-operator-reference/ - type: article - summary: MT103 was retired from SWIFT's cross-border network in Nov 2025, but operators still read it in archives and legacy documents. Field-by-field reference: mandatory/optional status, format specs, MT103 vs MT103+ vs REMIT, MT101 vs MT103, and failure modes from a wrong field. - topic: global-payments - keyFacts: - MT103 status: Retired from SWIFT FINplus cross-border traffic on 22 November 2025, replaced by ISO 20022 pacs.008 — field structure persists in archives, documentation, and legacy tooling - Mandatory fields: 20, 23B, 32A, 50a, 59a, 71A — present on every MT103 regardless of corridor - MT103 vs MT103+ (STP): MT103+ is a network-validated, structured-field-only subset of MT103 built for straight-through processing; formally documented by SWIFT as MT103 STP - MT103 REMIT: Requires Extended Remittance Information message user group registration; drops field 70 for field 77T (up to 9,000 characters of structured remittance data) - MT101 vs MT103: MT101 is a request-for-transfer instruction (often corporate-to-bank, can batch multiple payments); MT103 is the actual single customer credit transfer execution message — one MT101 can generate multiple MT103s - GPI 'semi-automatic' / 'KYC gpi' terminology: Not a SWIFT term. This phrasing is documented advance-fee scam vocabulary claiming a trapped payment needs a paid 'semi-automatic' release or 'KYC clearance' — SWIFT gpi has no such mechanism or fee - pubDate: 2026-08-20 - reviewedDate: 2026-08-20 ### pain.001 and pain.002: The Payment Initiation and Status Reference - url: https://paymentbrief.com/articles/pain001-pain002-payment-initiation-status-reference/ - type: article - summary: pain.001 is the file a corporate sends its bank to request a payment; pain.002 is the bank's structured reply — a separate ISO 20022 area from the pacs rulebook. Covers the pain.002 status-code lifecycle, MT101/CBPR+ migration, and why pain.001 is not PSD2 PISP initiation. - topic: global-payments - keyFacts: - Business area: pain.001/pain.002 sit in ISO 20022's Payments Initiation area — separate from the pacs (Payments Clearing and Settlement) rulebook - Message structure: pain.001: Group Header, Payment Information, Credit Transfer Transaction Information (three blocks) - Only mandatory status code: RJCT — every other pain.002 code (ACTC, ACCP, ACWC, PDNG, ACSP, ACCC) is sent by bilateral agreement - CBPR+ single-transaction rule: Cross-border pain.001/pacs.008 traffic under CBPR+ is restricted to one transaction per message — bulk files are decomposed - MT101 relay migration deadline: Deferred. Was 14 November 2026 and applies to MT101 used as interbank relay traffic, not corporate-to-bank SCORE/MA-CUG origination; the November 2026 Standards Release carrying it was delayed on 27 August 2026, with no… - pubDate: 2026-08-20 - reviewedDate: 2026-09-03 ### Terminal Estate Operations: Running a POS Fleet After Integration Is Done - url: https://paymentbrief.com/articles/terminal-estate-pos-fleet-operations/ - type: article - summary: Once card-present integration ships, the terminal estate becomes a standing discipline: inventory, provisioning, firmware, key management, P2PE scope, tamper handling, RMA, monitoring — running continuously, none of it optional, most invisible until it breaks. - topic: psp-and-infrastructure - pubDate: 2026-08-18 ### camt.052, camt.053 and camt.054: The Account Reporting Operator Reference - url: https://paymentbrief.com/articles/camt-052-053-054-account-reporting-reference/ - type: article - summary: camt.052 is the intraday account report, camt.053 the end-of-day statement, camt.054 the debit/credit notification. Only camt.053 carries booked entries as a closed-period statement. Covers structure (Entry vs EntryDetails vs TxDtls), balance types, and reconciliation gotchas. - topic: global-payments - keyFacts: - camt.052: BankToCustomerAccountReport — intraday; can contain pending and booked items - camt.053: BankToCustomerStatement — booked entries only, for a closed reporting period; the reconciliation reference - camt.054: BankToCustomerDebitCreditNotification — per-entry debit/credit notice; carries no balance information - Entry vs batch: One Ntry (Entry) can represent a batch; NtryDtls/TxDtls carries the underlying individual transactions - Duplicate indicator: CopyDuplicateIndicator uses CODU / COPY / DUPL to flag a message as a copy, a duplicate, or a duplicate of a copy - Mandatory camt.053 balances: OPBD (opening booked) and CLBD (closing booked) — documented as the mandatory pairing in bank implementation guides - pubDate: 2026-07-24 - reviewedDate: 2026-07-24 ### Local Acquiring vs Cross-Border Acquiring: The Operator Reference - url: https://paymentbrief.com/articles/local-acquiring-vs-cross-border-operator-reference/ - type: article - summary: Operators keep asking 'do I need local acquiring in this market' as a market-specific question. It isn't — it's the same four-question framework everywhere: reach, approval treatment, economics, and regulatory mandate. This is that framework. - topic: psp-and-infrastructure - keyFacts: - What actually changes: Acquirer of record, settlement currency, and domestic vs cross-border presentment to the issuer - Not the same as: Local payment methods, a local entity, or a Merchant of Record — each can exist without local acquiring - Four demand drivers: Domestic-only schemes, issuer approval treatment, cross-border scheme economics, regulatory data mandates - Four routes to get it: Local entity + own relationship, PSP that already holds the licence, local acquirer partnership, PayFac/MoR - Documented mandates: India (RBI in-country data storage, 2018), Indonesia (Bank Indonesia GPN domestic routing), South Korea (EFTA licensed-PG requirement for domestic cards) - Is cross-border acquiring legal?: Yes, almost everywhere — restricted only where a domestic-only scheme or routing mandate excludes it, as in Saudi Arabia, Indonesia, India, and South Korea - US cross-border scheme load: Visa ISA 1.00%/1.40% + IAF 0.45%; Mastercard 0.60%/1.00% + GAF 0.85% - Five markets compared: Mandatory for domestic cards in South Korea; regulator-routed for domestic instruments in Indonesia; scheme-reach-driven in Brazil (Elo); optional-but-beneficial in the US and Singapore - pubDate: 2026-07-24 - reviewedDate: 2026-07-24 ### MT202 COV and pacs.009 COV: The Cover-Payment Operator Reference - url: https://paymentbrief.com/articles/mt202-cov-pacs009-cover-payment-reference/ - type: article - summary: MT202 COV and pacs.009 COV carry a cover payment's settlement leg separately from the customer instruction. Covers SttlmMtd INDA/INGA/COVE, why the cover message exists (sanctions screening), UETR sharing across both legs, reconciliation, and concrete failure modes. - topic: global-payments - keyFacts: - MT202 COV go-live: November 2009 — following a Wolfsberg Group/Clearing House industry initiative endorsed by the Basel Committee (BIS, May 2009) - SttlmMtd codes (pacs.009): INDA (instructed agent settles) · INGA (instructing agent settles) · COVE (settled via a separate covering pacs.009) · CLRG (settled via RTGS/clearing system) - UETR sharing: The cover leg carries the same UETR as its underlying customer transfer — MT202 COV field 121 copies the MT103's UETR unchanged; pacs.009 COV transports the UETR of the underlying pacs.008 - Amount rule: Commonly documented as market practice, not confirmed here from SWIFT's own published standard: the cover leg should not carry a lower amount than the customer leg, and charges should not be deducted from it — verify the… - MT202/MT202 COV retirement: Retired from SWIFT FINplus cross-border traffic on 22 November 2025 alongside MT103, replaced by pacs.009 and pacs.009 COV under CBPR+ - pacs.009 has three CBPR+ variants: pacs.009 core (replaces plain MT202/200/205), pacs.009 COV (replaces MT202 COV/205 COV, carries the Underlying Customer Credit Transfer block), and pacs.009 ADV (a new CBPR+-only concept to advise a cover via pacs.009 co… - pubDate: 2026-07-24 - reviewedDate: 2026-07-24 ### Refund Operations: Controls, the Chargeback Double-Pay Trap, and Refund Fraud - url: https://paymentbrief.com/articles/refund-operations-runbook/ - type: article - summary: Refunds are not a support action — they are a money-movement control problem. Poor refund ops cause chargeback double-pays, fraud exposure, and reconciliation breaks. This runbook covers the controls, the refund-vs-chargeback trap, refund fraud, and reconciliation. - topic: psp-and-infrastructure - keyFacts: - A refund is a credit, not a reversal: A refund is a new credit to the original card after settlement; a void/auth-reversal cancels an uncaptured hold before settlement, and a chargeback is a forced reversal via the issuer — different instruments with differe… - The double-pay is the most expensive failure: Refund a transaction that is also disputed and you can be debited twice — refund plus chargeback — unless you contest the dispute with proof the credit was already issued (e.g. Visa 'credit not processed' representment). - Lock refunds on any open dispute: Once a chargeback or pre-dispute alert exists for a transaction, refunding it separately risks paying twice; gate refunds on dispute status and sync the support and chargeback queues. - Refund to the original instrument: Visa's rule is 'to the extent possible' credit the same card used on the original sale; only if that's genuinely not possible does Visa allow a secondary card or cash/check/store credit, and only under specific named con… - Make refunds idempotent: Retries, double-clicks, and webhook replays cause duplicate refunds; an idempotency key per refund request prevents paying the customer twice. - Original fees usually aren't returned: Most acquirers do not return the original processing fees on a refund and some add a refund fee — it varies by PSP, pricing, and region, so verify your contract; a refund is a real cost, not a wash. - pubDate: 2026-06-26 - reviewedDate: 2026-08-31 ### Marketplace Payment Operations: The Split-Payment & Connected-Account Runbook - url: https://paymentbrief.com/articles/marketplace-split-payment-operations-runbook/ - type: article - summary: A day-2 runbook for platforms already live on split payments and connected accounts: how the funds-flow model assigns liability, and how to run payouts, holds, reserves, negative-balance recovery, split refunds, disputes, reporting, and reconciliation. - topic: psp-and-infrastructure - keyFacts: - The funds-flow model decides liability: Separate charges, destination charges, and direct/split charges differ in who is merchant of record per transaction — and that sets who funds refunds, owns chargebacks, carries reserves, and files the tax report. - Negative balances are the default failure mode: A refund or chargeback that settles after the seller is paid out leaves the connected account owing money it no longer holds; under separate and destination charges the platform is the backstop to the acquirer. - Recover in a fixed waterfall: Net against future earnings, then debit the linked instrument, then draw the reserve, then manual collection, then write-off and offboard. Skipping straight to write-off forfeits recoverable funds. - Size reserves to the risk window, not a percentage: Reserves should track the delivery and dispute window of the seller's category — future-dated goods, new sellers, high-dispute verticals — because there is no universal reserve rate. - Evidence and liability can sit with different parties: The seller holds the fulfillment proof but the platform often owns the PSP dispute interface, so representment needs an evidence-handoff SLA that beats the network deadline. - Reporting follows the settlement entity: Whoever settles funds to sellers typically carries the 1099-K (US) or DAC7 (EU) reporting obligation; verify the current threshold and effective year per jurisdiction. - pubDate: 2026-06-25 - reviewedDate: 2026-06-25 ### Egypt Payments Operator Guide: Fawry, Meeza, InstaPay, Cards, and Wallets - url: https://paymentbrief.com/articles/egypt-payments-operator-guide-fawry-meeza-instapay/ - type: article - summary: Egypt's stack is multi-rail and cash-heavy — international cards, the Meeza domestic scheme, InstaPay transfers, Fawry's acceptance network, wallets, and cash-on-delivery. Accepting payments is a routing and reconciliation problem, not one integration. The operator how-to. - topic: global-payments - keyFacts: - It's a routing problem: Egypt is multi-rail — cards plus Meeza, InstaPay, Fawry, wallets, and cash-on-delivery — so accepting payments is a routing and reconciliation job across several settlement sources, not one integration - You need a local acquirer/PSP: International cards alone don't cover Egypt; domestic Meeza acceptance, InstaPay, and Fawry integration generally run through a locally-licensed acquirer or PSP - Recourse differs sharply by rail: Cards carry chargeback rights; account-to-account (InstaPay) and cash-adjacent flows are designed to be final once completed, with limited or no chargeback recourse - Cash is still in the mix: Cash-on-delivery and cash-adjacent collection remain material, which pushes reconciliation and payment-confirmation timing — not auth rates — to the centre of operations - Coverage varies by provider: Which rails, settlement currencies, and reconciliation files you get vary by PSP, acquirer, bank, merchant category, and contract — confirm each explicitly - pubDate: 2026-06-17 - reviewedDate: 2026-07-23 ### AI Agent Payment Controls: Governance for Payment Operators - url: https://paymentbrief.com/articles/ai-agent-payment-controls-governance/ - type: article - summary: The winning agent payment spec is unknowable; the durable operator job is controls. Scoped revocable mandates, spending and velocity limits, agent identity, human-in-the-loop, instant kill-switch, and immutable audit — plus a control reference table and pre-enablement checklist. - topic: ai-and-automation - keyFacts: - Pick controls, not specs: The winning agent payment standard is unknowable today; what is durable is the set of control objectives — scope, limits, identity, approval, revocation, audit — that any spec must satisfy - Card-on-file controls are necessary but insufficient: Existing per-card limits and MCC blocks help, but a non-human actor at machine speed needs delegated-authority bounds, agent identity, and an instant kill-switch on top - The mandate is the unit of control: A scoped, time-limited, revocable mandate — what an agent may buy, for whom, how much, how long — is the foundational control everything else hangs off - Revocation latency is a real number: A kill-switch is only as good as how fast it propagates; measure the time from 'revoke' to 'agent can no longer transact' and treat it as an SLA to interrogate - Liability is unsettled, so contract it: Responsibility for agent-initiated payments across user, agent platform, PSP/wallet, and merchant varies by scheme, contract, and jurisdiction and is not yet settled in law — resolve it in your provider contracts, do not… - pubDate: 2026-06-15 - reviewedDate: 2026-06-15 ### Authorization, Capture, and Settlement: Payment Lifecycle for Operators - url: https://paymentbrief.com/articles/authorization-capture-settlement-payment-lifecycle/ - type: article - summary: "Approved" is a promise, not a payment. This is the operator guide to what happens after a card payment: authorization holds, capture windows, full vs partial capture, incremental auth, reversals vs refunds, and why settlement does not equal capture. - topic: psp-and-infrastructure - keyFacts: - Approved is not paid: An approved authorization is a promise to pay, not a payment — money does not move until capture and clearing, and lands at settlement, often days later - Capture windows vary — never hardcode one: How long a hold survives before it expires depends on scheme, card type, acquirer, region, and merchant category; any specific number is a provider example, not a universal rule - Capture, reverse, refund are different operations: Capture claims the held funds; a reversal or void releases an uncaptured hold; a refund returns funds already captured — only the refund is a new money movement - Settlement is not capture: The amount you captured can differ from the amount that settles to your account once fees, FX, and adjustments are applied - The pain lives in the gaps: Auth approved but capture failed, holds expiring before fulfillment, duplicate captures, and capture-vs-settlement mismatches are the recurring operator failure modes - pubDate: 2026-06-15 - reviewedDate: 2026-08-31 ### Fraud Incident Response Runbook for Payment Operators - url: https://paymentbrief.com/articles/fraud-incident-response-runbook-payment-operators/ - type: article - summary: A live fraud attack is an incident, not a dashboard number. This runbook is the command workflow: confirm it is real, classify the attack type, contain with reversible controls while watching the false-positive cost, then recover by rolling those controls back deliberately. - topic: risk-and-compliance - keyFacts: - A spike is an incident, not a metric: A live fraud attack — fraudulent auths, abuse, or takeovers in progress — is run as an incident with an owner and a war-room, not watched on a dashboard - Confirm before you mobilize: Distinguish a real attack from a model blip or a legitimate surge (a viral campaign, a flash sale) before declaring and blocking — quantify first - Over-blocking is its own incident: Panic-blocking with blunt rules harms good customers and the approval rate; the false-positive cost is a live metric during the incident, not an afterthought - Temporary controls must be rolled back deliberately: Incident rules that are not rolled back in a staged, monitored way silently become permanent false-positive sources - This is command, not detection: Per-attack detection lives in the detection articles; this runbook is what you do once an attack is confirmed live and the clock is running - pubDate: 2026-06-15 - reviewedDate: 2026-06-15 ### Issuer, Acquirer, Gateway, PSP: The Payment Stack Operators Actually Contract With - url: https://paymentbrief.com/articles/issuer-acquirer-gateway-psp-payment-stack/ - type: article - summary: Issuer, acquirer, gateway, processor, orchestrator, PSP, PayFac, MoR — operators conflate these until a payment breaks and they don't know who to call. This is the operator map: who you contract with, who holds your money, who carries liability, and who you escalate to per actor. - topic: psp-and-infrastructure - keyFacts: - It's a map, not a glossary: Frame every actor by four operator questions — who you contract with, who holds your money, who carries liability, who you escalate to — not by its textbook definition - Who holds your money: Funds don't move at authorization; at capture/clearing the acquirer or PSP holds them in transit and controls payout timing and reserves before they reach you - The same word means different things: Processor, acquirer, gateway, and PSP are used loosely across the industry, and one vendor routinely plays several of these roles at once - Bundled vs split: A PSP wraps gateway + processor + acquiring access behind one contract; a classic stack splits them across vendors you integrate and reconcile yourself - Liability is contractual: Who eats a chargeback or a fraud loss is set by your contracts and scheme rules, not by which box an actor sits in on a diagram - pubDate: 2026-06-15 - reviewedDate: 2026-06-15 ### Ongoing Merchant Monitoring: KYB Does Not End at Onboarding - url: https://paymentbrief.com/articles/ongoing-merchant-monitoring-kyb-offboarding/ - type: article - summary: KYB is a lifecycle, not a one-time gate. An operator playbook for risk-tiering and review cadence, the monitoring signals that force a re-look, periodic re-screening, the graduated ladder from enhanced review to reserve to suspension, and offboarding and MATCH. - topic: risk-and-compliance - keyFacts: - KYB is a lifecycle, not a gate: The entity you approved drifts — ownership, volume, product, and risk change over months; treating KYB as a one-time onboarding check leaves you blind to that drift - Cadence should scale to risk tier: Assign a risk tier at onboarding and review higher-risk merchants more often; a re-tiering trigger forces an off-cycle look when a signal fires - Re-screening is periodic, not one-time: Sanctions, PEP, and adverse-media status changes after onboarding — periodic re-screening against current lists is the only way to catch them - Respond on a graduated ladder: Enhanced review, reserve or hold, payout pause, account restriction, suspension, and offboarding are escalating tools — match the response to the signal, not the panic - A for-cause termination can follow the merchant: Mastercard's MATCH can make a for-cause offboarding visible to other acquirers; the listing criteria and effects are scheme-defined and consequential — verify against current scheme rules - pubDate: 2026-06-15 - reviewedDate: 2026-06-15 ### Payout and Disbursement Failure Runbook for Payment Operators - url: https://paymentbrief.com/articles/payout-disbursement-failure-runbook/ - type: article - summary: A failed payout is money you owe that did not arrive, and it hits your highest-trust relationships. This runbook localizes the failed leg, uses idempotency to avoid paying twice, and decides repair vs retry vs reissue vs cancel — with an evidence pack and KPI scorecard. - topic: psp-and-infrastructure - keyFacts: - A failed payout is money you owe: Acceptance failures lose a sale; payout failures break trust with creators, sellers, and refund recipients who are already owed money — the relationship cost is higher - Localize the leg before acting: Internal ledger → funding → PSP → bank rail → wallet → beneficiary → compliance hold — find WHERE it failed before you retry, repair, or reissue anything - Idempotency prevents double-disbursement: An idempotency key on every payout request lets a retry return the original result instead of paying twice; treat any uncertain payout as possibly-sent until verified - Return codes are rail- and provider-specific: US ACH uses Nacha return reason codes (R01, R02, R03, R04…); wires, RTP, and local rails use different schemes — there is no universal payout return-code table - Recovery is not guaranteed: Some failed payouts return automatically, others need manual repair, and some are not recoverable — never promise a customer a refund of a failed payout will come back - pubDate: 2026-06-15 - reviewedDate: 2026-09-01 ### Promo and Referral Abuse: Controls for Payment Operators - url: https://paymentbrief.com/articles/promo-referral-abuse-payment-controls/ - type: article - summary: Promo and referral abuse games growth rewards by exploiting eligibility — not stealing payment instruments. An operator playbook: how it differs from card testing, ATO, and first-party fraud; the abuse patterns and signals; layered controls; and a measured response. - topic: risk-and-compliance - keyFacts: - Abuse exploits eligibility, not payment instruments: The abuser is usually not using a stolen card — they are gaming campaign terms and eligibility rules with real or farmed identities to extract rewards, which makes this a different discipline from payment fraud - No single signal proves abuse — cluster and score: Shared devices, IPs, and bank accounts have innocent explanations (families, offices, travel); abuse signals are probabilistic and must be clustered, scored, and confirmed by human review before acting - False positives are a real cost: Over-blocking legitimate users to stop abuse burns acquisition spend, hurts retention, and generates support load — the false-positive cost belongs in the same ledger as the abuse loss - Controls tie to the reward lifecycle: Eligibility rules, staged reward release, hold periods, account linking, payment-method limits, and campaign caps each cover a different stage from earn to release — no single control is sufficient - Freeze the reward, follow your terms: Where possible freeze the incentive rather than the user's own funds, and reverse a reward only if your published campaign terms permit it; design an appeal path - pubDate: 2026-06-15 - reviewedDate: 2026-06-15 ### PSP and Acquirer Outage Failover Runbook: Detecting Degradation, Failing Over Cleanly, and Recovering Without Double Charges - url: https://paymentbrief.com/articles/psp-acquirer-outage-failover-runbook/ - type: article - summary: PSPs and acquirers go down, and multi-PSP is not automatic failover. This runbook covers detecting gray failures from your own telemetry, the failover decision and its risks, idempotency keys against double charges, what breaks across two processors, and a readiness checklist. - topic: psp-and-infrastructure - keyFacts: - Multi-PSP is not failover: Having a second PSP in your stack does not mean traffic reroutes automatically — failover is an orchestration capability you build and test, not a side effect of two contracts - Gray failures are the hard part: Partial degradation — elevated declines, latency creep, intermittent timeouts — is harder to detect than a clean outage and easier to mistake for normal noise - Your telemetry beats the status page: Vendor status pages lag the incident; auth-rate, latency, error-rate, and decline clustering against your own baselines detect degradation first - Idempotency keys prevent double charges: An idempotency key on every payment request lets a retry or failover return the original result instead of charging the customer twice - Network tokens are provisioned per token requestor: Network tokens improve continuity but are issued per token requestor and acquirer; portability across acquirers is limited and evolving — do not assume seamless cross-PSP reuse - pubDate: 2026-06-15 - reviewedDate: 2026-06-15 ### Stablecoin On/Off-Ramp Failure Runbook for Operators - url: https://paymentbrief.com/articles/stablecoin-on-off-ramp-failure-runbook/ - type: article - summary: Ramp failures cluster into legs: fiat bank, ramp provider, blockchain, screening, and treasury. Localize the failure before acting. On-chain sends are irreversible — wrong-chain or wrong-address is generally unrecoverable; a refund is a new transfer, not a reversal. - topic: stablecoins - keyFacts: - On-chain transfers are irreversible: Once a transaction is confirmed on-chain it cannot be cancelled, reversed, or recalled by the issuer or the ramp provider - No chargeback mechanism: Stablecoin transfers are not chargeback-style payments — there is no card-network dispute or general clawback; a refund is a new transfer in the opposite direction - Wrong-chain / wrong-address is generally unrecoverable: Sending to an incorrect, incompatible, or wrong-chain address generally results in permanent loss; recovery is counterparty-goodwill or custodial-only, never guaranteed - Failures localize to five external legs: Fiat bank, ramp provider, blockchain transaction, wallet/compliance screening, and treasury/liquidity — each with its own signature and escalation owner - Core on-chain evidence: Transaction hash + chain/network + source and destination address are the irreducible evidence set for any on-chain investigation - Depeg is a conversion/timing exposure: Quote-to-settlement timing gaps and thin off-ramp liquidity are operational exposures on the conversion leg — not a prediction that any coin will or will not hold peg - pubDate: 2026-06-14 - reviewedDate: 2026-06-14 ### ISO 20022 Investigation Messages: A camt Operator Reference - url: https://paymentbrief.com/articles/iso-20022-investigation-messages-camt-reference/ - type: article - summary: Two request/response pairs. camt.056 requests a cancellation; camt.029 resolves it. camt.110 raises an investigation; camt.111 responds. camt.110/111 are the newer case-management framework with phased CBPR+ adoption — not the SEPA recall path (camt.056 → camt.029 → pacs.004). - topic: global-payments - keyFacts: - camt.056: FIToFIPaymentCancellationRequest — request to cancel or recall a payment already sent - camt.029: ResolutionOfInvestigation — the response to camt.056; carries the outcome (cancelled / rejected) - camt.110 / camt.111: InvestigationRequest / InvestigationResponse — the newer ISO 20022 investigations and case-management pair - Response pairing: camt.029 resolves a camt.056 cancellation; camt.111 responds to a camt.110 investigation — they are not interchangeable - camt.110/111 adoption: Newer framework; SWIFT/CBPR+ adoption is phased and implementation-dependent, not universally live - SEPA recall path: camt.056 → camt.029 → pacs.004 — SEPA/SCT Inst do not use camt.110/111 - MT–ISO coexistence: Ended 22 November 2025 for SWIFT cross-border instructions (per the MT103/pacs.008 reference) - pubDate: 2026-06-13 - reviewedDate: 2026-06-13 ### PayTo and the NPP: An Operator Guide to Australia's A2A Rails - url: https://paymentbrief.com/articles/payto-npp-australia-a2a-operator-guide/ - type: article - summary: PayTo is the NPP's Mandated Payments Service: payer-authorised digital mandates held centrally, under which an initiator pulls real-time NPP payments. Not a card. BECS migration is an industry direction under consultation — not a fixed date. - topic: global-payments - keyFacts: - NPP: Australia's real-time, 24/7 account-to-account rail; settles in central bank funds via the RBA's Fast Settlement Service - PayTo: The consumer/market brand for the NPP's Mandated Payments Service (MPS) — payer-authorised digital payment agreements (mandates) - Mandate storage: Mandates are created and held centrally in the Mandate Management Service (MMS), operated by NPP Australia (part of Australian Payments Plus) - Settlement: Real-time, line-by-line settlement in ESA funds via the Fast Settlement Service (a service of the RBA's RITS) — no netting or batching - BECS migration: An RBA/industry direction to migrate A2A off BECS toward the NPP — timeline under ongoing consultation; AusPayNet removed the June 2030 target end-date in December 2025 (confirm the current position) - PayTo adoption: Rolling out progressively across NPP participants; coverage expanding and varies by institution — confirm a given bank's/PSP's support - pubDate: 2026-06-13 ### PSP vs PayFac Operations: A Model Reference for Operators - url: https://paymentbrief.com/articles/psp-payfac-operations-reference/ - type: article - summary: PSP, PayFac, acquirer, marketplace, and MoR overlap commercially but differ operationally. This reference separates them by who holds the merchant account, onboards, owns risk and chargebacks, and settles — with documented PayFac-as-a-service examples and a contract checklist. - topic: psp-and-infrastructure - keyFacts: - PayFac master merchant account: A payment facilitator holds a master merchant account and boards merchants beneath it as sub-merchants - Direct PSP model: Your business holds its own merchant account (MID) and boards directly with an acquirer; you own your own risk - Acquirer role: The acquirer is the card-network-licensed entity that settles transactions with the schemes; PSPs and PayFacs sit on top of one - Documented PayFac-as-a-service: Stripe Connect and Adyen for Platforms are publicly documented platform / PayFac-as-a-service offerings - Risk ownership differs by model: Who owns chargebacks, fraud, and reserves shifts from the merchant (direct PSP) to the facilitator/platform (PayFac) - Licensing and thresholds vary: Sub-merchant volume thresholds and licensing depend on the market and card-network program — confirm current rules with your acquirer - pubDate: 2026-06-13 - reviewedDate: 2026-06-13 ### SEPA Instant Monitoring and Reconciliation KPIs for Payment Operators - url: https://paymentbrief.com/articles/sepa-instant-monitoring-reconciliation-kpis/ - type: article - summary: Blended payment metrics hide SCT Inst-specific failure modes. This scorecard covers seven bands — initiation, timeouts, rejections, recalls, reconciliation, VoP, and customer comms — with operator-set targets, since no public SEPA Instant KPI benchmarks exist. - topic: global-payments - keyFacts: - Execution window: 10 seconds end-to-end (internal thresholds T+5/T+7/T+9/T+10) under EPC004-16 2025 v1.1 — the fixed clock KPIs are measured against - Account restoration: T+10 payer-account unfreeze if no confirmation — a fixed compliance obligation, not an operator target - Recall response deadline: 15 banking business days for the beneficiary PSP to respond — a fixed scheme threshold (100% compliance KPI) - FRAD recovery window: 13 months — the fixed outer bound for fraud-recall investigation aging - Verification of Payee: Pre-submission advisory with 4 result codes (MTCH/CMTC/NMTC/NOAP) — never a rejection mechanism; no scheme KPI mix - IPR send + pricing parity: 9 October 2025 (eurozone) under Regulation (EU) 2024/886 — the date the monitored SCT Inst volume became mandatory - pubDate: 2026-06-13 ### SPEI Mexico: An Operator Guide to the Payment Rail - url: https://paymentbrief.com/articles/spei-mexico-payment-rail-operator-guide/ - type: article - summary: SPEI is Banxico's real-time account-to-account rail for MXN collections and payouts. It is irrevocable once settled — no chargeback, no scheme return. A refund is a new SPEI transfer to the payer's CLABE. This guide covers the four layers operators must separate. - topic: global-payments - keyFacts: - Operator: Banco de México (Banxico) — the central bank develops and operates SPEI - Rail type: Real-time account-to-account credit transfer (push payment) in MXN - Account identifier: CLABE — 18-digit standardized bank account number (bank + branch/plaza + account + check digit) - Availability (per Banxico): Online/mobile services available 24 hours a day, every day; a payment should not take more than 30 seconds - Reversibility: Irrevocable once deposited — no chargeback, no scheme return; a refund is a new transfer to the payer's CLABE - Access for operators: Via a Mexican bank/CLABE, usually through a licensed PSP or local partner; direct participation requires a regulated entity (bank, IFPE, etc.) - pubDate: 2026-06-13 ### Reading PSP Settlement Files: Stripe vs Adyen - url: https://paymentbrief.com/articles/stripe-adyen-settlement-file-reference/ - type: article - summary: A PSP settlement file is a processor record, not a bank statement. Maps Stripe (balance_transaction/payout, pays net) and Adyen (pspReference/batch, gross + fee lines) into one object model — plus the IDs to persist so a PSP switch doesn't break recon. - topic: psp-and-infrastructure - keyFacts: - Stripe balance transaction ID: balance_transaction id uses the txn_ prefix; carries amount, fee, and net on every row - Stripe settlement model: Pays net by default — the Stripe fee is deducted per balance_transaction, no separate fee invoice - Adyen transaction reference: pspReference — a 16-digit per-transaction reference; modifications carry their own Modification Reference - Adyen fee breakdown: Settlement Details Report reports gross plus separate Commission (NC), Markup (NC), Scheme Fees (NC), Interchange (NC) columns - Dates are not interchangeable: Transaction date != settlement/batch date != payout date != expected bank-credit date - Settlement file vs bank statement: A settlement file is a processor record; only the bank statement confirms funds actually landed - pubDate: 2026-06-13 - reviewedDate: 2026-09-01 ### Visa Compelling Evidence 3.0: An Evidence-Build Guide - url: https://paymentbrief.com/articles/visa-compelling-evidence-3-evidence-build-guide/ - type: article - summary: CE 3.0 lets merchants fight Visa 10.4 fraud disputes with prior matching transactions — but the evidence must be captured before the dispute. The evidence-build guide: matching elements, prior-transaction logic, the Oct 2025 auto-qualification update, and a readiness scorecard. - topic: risk-and-compliance - keyFacts: - Applies to: Visa fraud dispute reason code 10.4 (Other Fraud — Card-Absent Environment) only - Evidence basis: Two prior undisputed transactions sharing matching data elements - Change ahead: From 24 Oct 2026 the two prior transactions need not all be with the same merchant (Visa Rules, 18 Apr 2026 ed.) - Matching elements: IP address, device ID/fingerprint, user/account ID, shipping address — at least one must be IP or device ID/fingerprint (confirm against current Visa rules) - Historical window: Prior transactions 120–365 days older than the disputed transaction (confirm against current Visa rules) - Launched: April 2023 (effective ~15 April 2023) - Oct 2025 update: Auto-qualification via Visa Secure / Visa Data Only from 17 October 2025; qualification establishes eligibility, not a guaranteed win - pubDate: 2026-06-13 - reviewedDate: 2026-06-13 ### MT103 to pacs.008 Field Mapping: The Operator Reference - url: https://paymentbrief.com/articles/mt103-pacs008-field-mapping-reference/ - type: article - summary: MT103 retired 22 Nov 2025. pacs.008 CBPR+ is now live. This maps every material MT103 field to its pacs.008 element, explains what changed and what didn't, and covers the investigation flow — pacs.002, camt.056, camt.110/111 — operators need post-migration. - topic: global-payments - keyFacts: - MT103 retirement date: 22 November 2025 — retired from SWIFT FINplus for cross-border payment instructions - pacs.008 version on SWIFT: pacs.008.001.08 (CBPR+); business service swift.cbprplus.02 (standard) or swift.cbprplus.stp.02 (STP) - EndToEndId on translated messages: NOTPROVIDED — legacy MT103-era messages have no originator end-to-end reference; translation inserts this placeholder - ChrgBr mapping: OUR → DEBT; SHA → SHAR; BEN → CRED - Structured address deadline: Deferred. Was 14 November 2026; Swift delayed its November 2026 Standards Release on 27 August 2026 and no replacement CBPR+ date has been announced. The format target is unchanged — hybrid (TwnNm + Ctry structured, mini… - camt.110/111 go-live: Opt-in since November 2024 on FINplus (Case Management CUG); replaces MT199/MT299 for exceptions and investigations - pubDate: 2026-06-12 - reviewedDate: 2026-08-24 ### PSP Reconciliation Failure Runbook: Break Types, Matching IDs, and Escalation Checklists - url: https://paymentbrief.com/articles/psp-reconciliation-failure-runbook/ - type: article - summary: PSP reconciliation requires a three-way match: internal ledger vs PSP settlement report vs bank statement. Covers per-PSP ID chains, gross-vs-net settlement per PSP, 10 break types with root causes and fixes, and escalation checklists. - topic: psp-and-infrastructure - keyFacts: - Three-way match layers: Internal order ledger → PSP settlement report → bank statement - Two-way match blind spot: PSP reports a payout; money never arrived at the bank — two-way misses this - Stripe settlement model: Net per-transaction — fee and net on every balance_transaction row - Adyen settlement model: Net batch + InvoiceDeduction true-up in the following batch for monthly fee reconciliation - Checkout.com settlement model: Contractually net or gross with separate invoice — confirm per contract - Adyen weekend consolidation: Friday, Saturday, and Sunday sales are consolidated into a single batch paid out the following week - Stripe negative balance: When refunds exceed charges, Stripe pulls from the merchant bank account — a bank debit that recon must expect - pubDate: 2026-06-12 - reviewedDate: 2026-06-12 ### SCT Inst Rejection and Timeout Runbook for Payment Operators - url: https://paymentbrief.com/articles/sct-inst-rejection-timeout-runbook/ - type: article - summary: SCT Inst failures are synchronous: pacs.002 RJCT or silence within 10 seconds, not a next-day return. Covers the 5/7/9/10-second framework, rejection vs timeout vs return vs recall taxonomy, ACCP/RJCT handling, operator action per failure class, and bank escalation checklists. - topic: global-payments - keyFacts: - Execution hard limit: 10 seconds end-to-end; beneficiary PSP must respond by 7 seconds - Originator PSP timeout obligation: Must restore payer account by 10th second if no confirmation received - pacs.002 outcomes: ACCP (positive acceptance) or RJCT (rejection) — no interim ACSC/ACCC in the SCT Inst flow - Recall window: 10 banking business days (FRAD: 13 months); beneficiary must respond within 15 banking business days - Sanctions screening shift: IPR Art 5d: per-customer daily screening replaces per-transaction checks — reduces payment-level rejects from sanctions hits - Amount cap: EPC-level €100,000 cap removed in 2025 rulebook; PSPs set own limits (cannot be lower than their SCT limits under IPR) - pubDate: 2026-06-12 - reviewedDate: 2026-06-12 ### SEPA Return and Reject Codes: The R-Transaction Reference - url: https://paymentbrief.com/articles/sepa-return-reject-codes-r-transaction-reference/ - type: article - summary: Six SEPA R-transaction types: Reject, Return, Refund, Reversal, Refusal, Recall. SDD Core: 8-week authorized / 13-month unauthorized refund. SDD B2B: no refund; 3-day irrevocability. SCT Recall 10 days (FRAD 13 months); RFRO 13 months. MS03 masks AC04/AM04 by data-protection law. - topic: global-payments - keyFacts: - R-transaction types: 6 — Reject, Return, Refund, Reversal, Refusal, Recall - SDD Core refund right: 8 weeks authorized / 13 months unauthorized (no-questions-asked) - SDD B2B refund right: None for authorized transactions; technical return window typically 3 business days (verify with your PSP/bank) - SCT Recall (bank-initiated): 10 banking business days (FRAD: 13 months); RFRO (customer-initiated): 13 months - SCT Inst return window: Rejects within 10-second execution window; post-settlement returns follow a longer window (see rulebook) - MS03 masking: Used in AT, BE, DE, LU, NL, SK, SI, CH when national law blocks AC04/AM04 disclosure - pubDate: 2026-06-11 - reviewedDate: 2026-09-01 ### Verification of Payee and Confirmation of Payee: The Match-Code Reference - url: https://paymentbrief.com/articles/verification-of-payee-match-codes-reference/ - type: article - summary: VoP and CoP verify payee name against account. EU VoP = 4 result codes (MTCH/NMTC/CMTC/NOAP), no reason granularity. UK CoP = ~13 provider-documented reason codes. Results are advisory; liability turns on whether the PSP warned. - topic: risk-and-compliance - keyFacts: - EU VoP mandatory: 9 Oct 2025 (euro-area); 9 Jul 2027 (non-euro) - EU result codes: 4 only — MTCH / NMTC / CMTC / NOAP; no reason granularity - UK CoP reason codes: ~13, provider-documented (ANNM, AC01, OPTO, CASS, …) - EU scheme docs: EPC218-23 rulebook + EPC103-24 API spec - UK CoP coverage: ~99% of Faster Payments + CHAPS by Oct 2024 - UK APP reimbursement: Live 7 Oct 2024 — £85k cap, 50/50 PSP split - pubDate: 2026-06-11 - reviewedDate: 2026-06-11 ### Tracing a SWIFT Payment: UETR, gpi, and Where It Gets Stuck - url: https://paymentbrief.com/articles/tracing-swift-payments-uetr-gpi-status-codes/ - type: article - summary: When a SWIFT payment stalls, UETR is the primary diagnostic key. This runbook covers: how to obtain the UETR, reading ACSP/ACCC/RJCT status codes, the six stall categories with detection signals, how to raise a formal case, and what to ask your bank. - topic: global-payments - keyFacts: - UETR format: 36-character UUID v4 (RFC 4122) in field 121, Block 3 of SWIFT messages — mandatory since 18 November 2018 (SR 2018) - ACSP vs ACCC: ACSP = settlement in process, payment in transit (not credited); ACCC = credited to the beneficiary's account (terminal success) - gpi coverage (2024): 90% of SWIFT cross-border payments reach destination bank within 1 hour; 43% reach end customer within 1 hour (SWIFT, October 2024) - Key stall indicators: ACSP/G001 = exited gpi network; ACSP/G002 = manual review / pending credit; ACSP/G003 = awaiting documents; no status update after 2 days = raise a case - Investigation messages: ISO 20022: camt.056 (cancellation request), camt.029 (resolution), camt.110/111 (exceptions and investigations, available since November 2024) - pubDate: 2026-06-10 - reviewedDate: 2026-09-03 ### PSP Selection Checklist: How to Evaluate Shortlisted Providers Before You Sign - url: https://paymentbrief.com/articles/psp-selection-checklist/ - type: article - summary: Once the Decision Matrix has narrowed you to a provider class and three named finalists, evaluation begins. Score them across 8–12 dimensions, convert claims into proof, and apply disqualifiers before you reach the contract stage. - topic: psp-and-infrastructure - keyFacts: - Buying-journey stage: Finalist evaluation (post-shortlist, pre-contract) - Typical shortlist size: 3 providers - Core evaluation dimensions: 8–12 - Guiding principle: Proof-of-claim: make providers demonstrate, not assert - Primary tool for the full questionnaire: PSP Selection RFP Kit (60+ questions, weighted scorecard) - pubDate: 2026-06-09 ### Recurring Payments Operations: How Operators Recover and Retain Subscription Revenue - url: https://paymentbrief.com/articles/recurring-payments-billing-operations/ - type: article - summary: Card-on-file MIT chains break without an SCA-anchored CIT. Network tokens recover card expiry churn. Direct debit mandates carry reverse-flow risk. Retry logic recovers soft declines — hard declines require mandate reauthorization. Each has a specific fix. - topic: psp-and-infrastructure - keyFacts: - MIT SCA anchor (EEA): Card recurring in the EEA requires a 3DS2-authenticated CIT — the network transaction ID from that first charge anchors every subsequent MIT in the stored credential chain (PSD2 RTS Art. 14) - MIT subtypes: Visa and Mastercard define three stored credential subtypes: R (recurring — fixed amount, fixed interval), I (instalment — fixed amount, fixed number), U (unscheduled credential-on-file — variable amount or timing) - SEPA SDD consumer refund right: 8-week no-questions-asked refund under EPC SDD Core 2025 Rulebook v1.0 (effective 5 October 2025) — creates a reverse-flow revenue exposure window that card chargebacks do not replicate - Hard decline rule: Hard declines — account closed (R02), authorization revoked (R07), card lost/stolen — must not be retried; Nacha and card network rules treat excessive retries on confirmed hard declines as a compliance violation - UPI AutoPay standard cap: ₹15,000 per debit for standard recurring categories including OTT, SaaS, utilities, and mobile bills (NPCI UPI-OC-151A; ₹1,00,000 for insurance, SIPs, loan EMIs, and credit card bill payments) - pubDate: 2026-06-07 - reviewedDate: 2026-09-02 ### VAMP Remediation Checklist: Steps to Exit Visa Acquirer Monitoring - url: https://paymentbrief.com/articles/vamp-remediation-checklist/ - type: article - summary: When a merchant enters VAMP Above Standard or Excessive, confirm the exact TC40/TC15 split first. Remediation runs two parallel workstreams — fraud (TC40) and disputes (TC15) — with a documented weekly action plan sent to the acquirer. - topic: risk-and-compliance - keyFacts: - VAMP ratio formula: TC40 fraud + TC15 disputes ÷ TC05 settled transactions × 100 - Acquirer Above Standard: ≥0.50% VAMP ratio - Acquirer Excessive: ≥0.70% VAMP ratio - Merchant Excessive threshold: ≥1.5% since 1 April 2026 (AP/Canada/EU/US; previously ≥2.2%) - Enumeration tracking: Tracked separately under Visa's enumeration ratio, not inside the core VAMP ratio - pubDate: 2026-06-07 - reviewedDate: 2026-08-21 ### OUR, SHA, and BEN: Why SWIFT Payments Arrive Short - url: https://paymentbrief.com/articles/swift-charge-options-our-sha-ben/ - type: article - summary: SHA is the SWIFT default — correspondent deductions come out of the recipient's principal. A $50,000 invoice paid SHA arrives short by a corridor-dependent amount. OUR instructs all correspondent fees to the sender, protecting the recipient amount. - topic: global-payments - keyFacts: - Field 71A: SWIFT MT103 field that carries the charge instruction: OUR, SHA, or BEN - ISO 20022 equivalent: pacs.008 ChrgBr field: DEBT (OUR), SHAR (SHA), CRED (BEN) - SHA default: SHA is the market default; sender pays originating bank fees while correspondent charges are deducted from the principal in transit - OUR protects recipient amount: OUR instructs the correspondent chain to pass all fees to the sender; recipient receives full transfer amount, subject to any incoming wire fee from the receiving bank - BEN rarely suitable for B2B: Under BEN, originating bank fees are deducted from principal before forwarding; sender cannot predict recipient amount, making invoice reconciliation unreliable - pubDate: 2026-06-06 - reviewedDate: 2026-08-26 ### South Korea Payments Operator Guide: Local Acquiring, PGs, and VANs - url: https://paymentbrief.com/articles/south-korea-payments-operator-guide/ - type: article - summary: Korean local acquiring runs on two licensed layers: PGs for online cards (KG Inicis, Toss, NHN KCP), VANs for offline terminals (NICE, KICC, KSNET) — no cross-border acquiring option. Costs stack regulated MDR tiers plus PG/VAN fees. Financial data stays on Korean servers. - topic: global-payments - keyFacts: - Card spend — mobile share: 54.3% of total card spend (2025, Bank of Korea) - Domestic card acceptance: Via a licensed Korean PG only — foreign acquiring not available - Offline/POS acceptance: Via a licensed Korean VAN (NICE, KICC, KSNET) — a separate registration from the online PG - Entry without local entity: Via aggregator (e.g. Stripe); direct PG contract requires a Business Registration Number - FSC-regulated MDR (preferential credit): 0.4–1.45% by annual sales bracket, effective 14 Aug 2025 - FSS PG/intermediary fee (avg): ~1.98% across 18 e-finance firms (FSS, Sept 2025 disclosure) - KFTC Open Banking: Launched Dec 2019 — centralized API hub for A2A transfers - Data residency: EFSR requires domestic storage; phased relaxation since Aug 2024; EU adequacy decision excludes FSC-supervised credit data - Real-time rail operator: KFTC — Korea Financial Telecommunications & Clearings Institute - pubDate: 2026-06-05 - reviewedDate: 2026-08-24 ### China Payments: The Foreign Operator's Guide - url: https://paymentbrief.com/articles/china-payments-operator-guide/ - type: article - summary: Alipay and WeChat Pay hold over 90% of China's mobile payments, with non-bank clearing routed through NetsUnion. Foreign operators accept them via intermediaries (Adyen, Antom/2C2P, Stripe) — direct PBOC licensing rarely works for foreigners. CIPS handles B2B CNY settlement. - topic: global-payments - keyFacts: - Mobile payment duopoly: Alipay + WeChat Pay >90% of volume - Clearing mandate: All non-bank PSP flows route via NetsUnion (since 30 Jun 2018) - CIPS direct participants: 210 (Jun 2026, CIPS Announcement No. 118) - CIPS indirect participants: 1,619 across 130 countries - PBOC minimum capital: CNY 100M base under 2024 regulations - Non-bank payment regulation: Two licence categories, effective 1 May 2024 - pubDate: 2026-06-02 - reviewedDate: 2026-09-11 ### Indonesia Payments Operator Guide: QRIS, BI-FAST, and the Wallet Stack - url: https://paymentbrief.com/articles/indonesia-payments-operator-guide/ - type: article - summary: Indonesia's payments run on QRIS (42M merchants, 13.66B txns in FY2025, per BI) and BI-FAST. GoPay, OVO, DANA, ShopeePay converge under one QR code. Foreign operators enter via licensed aggregators; domestic parties must keep voting control. - topic: global-payments - keyFacts: - QRIS merchants: ~42M (FY2025, per Bank Indonesia) - QRIS transactions: 13.66B (FY2025, per Bank Indonesia) - QRIS MDR (UMI ≤IDR 500K): 0% - QRIS MDR (UMI >IDR 500K): 0.3% - QRIS MDR (regular merchants): 0.7% (UKE/UME/UBE); 0% on transactions up to IDR 100K from 1 Oct 2026 - QRIS MDR from 1 Oct 2026: 0% for all merchant categories on transactions up to IDR 100K (Bank Indonesia, announced 17 Aug 2026) - BI-FAST transfer limit: IDR 250M per transaction - BI-FAST max customer fee: IDR 2,500 - BI-FAST volume, Q2 2026: 1.53B txns / IDR 3,777T (+38.09% YoY, per Bank Indonesia) - BI-FAST non-bank participant capital: IDR 100B minimum (PADG 3/2026, eff. 31 Mar 2026) - QRIS MDR — education / SPBU / BLU-PSO: 0.6% / 0.4% / 0% (eff. 15 Mar 2025); 0% on transactions up to IDR 100K from 1 Oct 2026 - Licensing regime: BI Reg 10/2025, in effect since 31 Mar 2026 - Foreign ownership (PJP): Up to ~85% economic; domestic retains ≥51% voting control - Foreign ownership (PIP): Domestic ownership and control both ≥80% - pubDate: 2026-06-02 - reviewedDate: 2026-07-23 ### Chargeback Management Compared: Alerts, Representment, and Recovery Models - url: https://paymentbrief.com/articles/chargeback-management-platforms-compared-alerts-representment-recovery/ - type: article - summary: Chargeback management is a layered operating stack, not a single product category: network pre-dispute alerts, representment automation, managed recovery services, PSP tooling, and in-house operations. Match layers to your dispute volume, reason-code mix, and team capacity. - topic: risk-and-compliance - keyFacts: - Layer 1 — Network pre-dispute alerts: Verifi (Visa) and Ethoca Alerts (Mastercard) deflect disputes before filing; accessed via PSP/acquirer or API — not merchant-side representment SaaS - Layer 2 — Representment automation: Merchant-configured software (Chargeflow, Justt) handles evidence gathering and submission on contingency pricing - Layer 3 — Managed recovery: Team-led managed operations (Chargebacks911) run chargeback management as a done-for-you service, not software the merchant configures - Key distinction: Network alert tools and representment tools operate at different lifecycle stages — before vs after a chargeback files — and are frequently used together - PSP tooling is the baseline: Every operator already has dispute tooling through their PSP or acquirer; specialist layers add on top of it - Source discipline: All vendor claims sourced from vendor product pages accessed 2026-05-30; verify current model, coverage, and terms directly before committing - Verifi vs Ethoca Alerts: Different card schemes (Visa vs Mastercard), not competing products for the same transaction; CDRN is a Verifi product, not a rival to Ethoca — see the dedicated head-to-head subsection - pubDate: 2026-05-29 - reviewedDate: 2026-08-20 ### Direct Debit Payments Explained: ACH, SEPA SDD, Bacs, and eGIRO - url: https://paymentbrief.com/articles/direct-debit-payments-explained-ach-sepa-bacs-egiro/ - type: article - summary: Direct debit pulls from a bank account against a pre-authorized mandate — no card network, typically no per-collection authentication after mandate setup. ACH, SEPA SDD, Bacs, and eGIRO share the model but differ in settlement timing, return windows, and consumer protections. - topic: psp-and-infrastructure - keyFacts: - ACH settlement: 1–3 business days (standard); same-day via Same Day ACH (three daily windows; $1M per-item cap) - SEPA SDD Core refund right: 8 weeks no-questions-asked; up to 13 months for unauthorized debits - Bacs settlement cycle: 3 business days from file submission to receipt - eGIRO scope: SGD-denominated recurring debits; API-based mandate setup; Singapore-licensed banks only - SEPA pre-notification default: 14 calendar days before collection (shorter period by mutual agreement) - Nacha unauthorized return threshold: 0.5% of debit entries — exceeding triggers compliance review - pubDate: 2026-05-29 - reviewedDate: 2026-08-21 ### Fraud Prevention Platforms Compared: Guarantee, Managed Decisioning, and Risk Scoring Models - url: https://paymentbrief.com/articles/fraud-prevention-platform-comparison-guarantee-decisioning-risk-scoring/ - type: article - summary: Fraud-platform selection is a model decision, not a vendor decision: guarantee/liability-shift, managed decisioning, or risk scoring. Each transfers different liability and control. Match to your fraud maturity and chargeback exposure — not vendor marketing. - topic: risk-and-compliance - keyFacts: - Guarantee / liability-shift: Vendor assumes fraud chargeback liability on approved orders; verify exact coverage, exclusions, and reason-code scope directly - Managed decisioning: Vendor automates the approve/decline decision; contractual performance commitments rather than pure liability shift - Risk scoring / decisioning: Vendor returns a score; merchant team makes the final decision and retains liability - Bake-off discipline: Shadow-mode before live cut-over; baseline fraud, chargeback, approval, manual-review, and false-positive metrics first - What public pages don't tell you: Exact liability scope, exclusion lists, covered reason codes, merchant override rights, SLA, and regional terms require the RFP - Source discipline: Vendor claims sourced from vendor product pages accessed 2026-05-30, 2026-07-07, or 2026-08-20 (see each source's dateAccessed); verify current positioning at evaluation time - Lifecycle layer: This article covers pre-auth fraud scoring only; pre-dispute deflection (Verifi, Ethoca Alerts) and post-chargeback representment (Chargeflow, Justt, Chargebacks911) are separate, complementary layers — see the sibling c… - Head-to-head pairs: Forter vs Signifyd, Sift vs Riskified, Forter vs Riskified, Sift vs Signifyd, and Kount vs Riskified compared directly on guarantee scope, approval/false-positive posture, decisioning model, pricing shape, dashboards, an… - pubDate: 2026-05-29 - reviewedDate: 2026-08-24 ### Recurring Payments: Cards, Direct Debit, A2A, and Wallet Billing Compared - url: https://paymentbrief.com/articles/recurring-payments-rails-compared/ - type: article - summary: Card-on-file is the default recurring rail — global coverage, no local entity required. SEPA SDD, UPI AutoPay, UK VRP, and Pix Automático lower cost for operators with local presence. Wallet billing passes an underlying card or bank credential — not a standalone pull rail. - topic: psp-and-infrastructure - keyFacts: - MIT SCA anchor: Initial CIT must be 3DS2-authenticated in EEA — MIT chain breaks without the network transaction ID from that first charge - SEPA SDD Core refund right: 8 weeks, no-questions-asked — EPC SDD Core Rulebook 2025 v1.0, effective October 5, 2025 - UK sweeping VRP live: January 2022 — mandated for all CMA9 banks; commercial merchant VRP rolling out 2026–2027 - UPI AutoPay standard cap: ₹15,000 per debit for standard categories (OTT, SaaS, utilities, mobile bills) - Pix Automático launched: June 16, 2025 — pull-debit layer on Pix infrastructure with instant settlement (BCB) - Wallet billing caveat: Apple Pay, Google Pay, and PayPal are credential surfaces — recurring capability depends on wallet, PSP, app-store model, and region - Entity requirement: SEPA SDD, UPI AutoPay, Pix Automático, and BACS (via SUN) require local entity presence or local PSP relationship — card-on-file does not - pubDate: 2026-05-28 ### SWIFT Payment Costs and Rail Selection: The Operator's Decision Guide - url: https://paymentbrief.com/articles/swift-payment-processing-mt103-gpi-iso-20022/ - type: article - summary: SWIFT payment cost stacks sending fee, correspondent transit fees, FX spread, and receiving fee — allocated by OUR/SHA/BEN. This guide walks the cost breakdown, then when to use SWIFT gpi versus a local rail or platform, before the MT103-to-ISO-20022 and gpi mechanics underneath. - topic: global-payments - keyFacts: - Typical all-in cost: 1.5–3% on major corridors (correspondent fees + FX spread); 3–5% on less liquid routes - Settlement time: 1–5 business days depending on corridor, number of hops, and cut-off timing - What SWIFT is: A messaging network, not a payment system — SWIFT carries instructions; banks settle funds bilaterally - UETR ≠ gpi tracking: UETR has been mandatory on all cross-border SWIFT MT103/202/205 messages — gpi and non-gpi alike — since 18 November 2018; its presence alone doesn't mean a payment is gpi-tracked - Structured address deadline: Deferred. Swift delayed its November 2026 Standards Release on 27 August 2026, citing industry readiness on unstructured-address removal; no replacement CBPR+ date announced - SWIFT gpi coverage: Over 4,450 institutions live on gpi; 90% of cross-border payments reach the destination bank within 1 hour, but only 43% reach the end customer's account within 1 hour — it's the 43% that compares to the G20's 75%-by-202… - pubDate: 2026-05-25 - reviewedDate: 2026-09-03 ### Fraud Operations KPIs: Metrics, Targets, and Escalation Triggers - url: https://paymentbrief.com/articles/fraud-operations-kpis/ - type: article - summary: Tracking only fraud loss rate and chargeback ratio gives a lagging view. A complete fraud operations scorecard covers six categories — Loss Exposure, Detection, Customer Friction, Operational Efficiency, Model Quality, and Chargeback Spillover — with cadence and escalation logic. - topic: risk-and-compliance - keyFacts: - KPI categories: 6 — Loss Exposure, Detection & Prevention, Customer Friction, Operational Efficiency, Model & Rule Quality, Chargeback Spillover - Metrics in scorecard: 18 across all six categories - Published benchmarks: Sparse — PSI drift thresholds and VAMP scheme components are the main external references; most targets are operator-set - pubDate: 2026-05-21 ### Payment Routing KPIs: Auth Rate, Failover, Cost, and Recovery - url: https://paymentbrief.com/articles/payment-routing-kpis/ - type: article - summary: Most routing teams track a blended auth rate and a blended cost. Both hide per-route signals. A routing scorecard covers five categories: approval performance, routing reliability, cost efficiency, latency, and recovery — segmented by acquirer and BIN range. - topic: payments-economics - keyFacts: - KPI categories: 5 — Approval Performance, Routing Reliability, Cost Efficiency, Latency, Recovery - Metrics in scorecard: 15 across all five categories - Published benchmarks: Sparse — scheme thresholds cover chargeback and fraud ratios, not routing performance; most targets are operator-set - Segmentation discipline: Track every metric per acquirer, BIN range, issuer region, and traffic type before aggregating - Sibling scorecards: Fraud Operations KPIs (18 metrics, 6 categories) and Chargeback Operations KPIs (16 metrics, 5 categories) - pubDate: 2026-05-21 ### Multi-Currency Treasury Architecture for Payment Operators - url: https://paymentbrief.com/articles/multi-currency-treasury-architecture-payment-operators/ - type: article - summary: Converting everything at the PSP spot rate is a decision by inaction. This framework covers where to hold multi-currency balances, when to convert, when to hedge, and how virtual IBANs and stablecoins fit your operating profile and exposure size. - topic: global-payments - keyFacts: - PSP default FX spread: 1.5–3.0% above mid-market (operator estimate) - Specialist platform spread: ~0.5% for major currencies (Airwallex published) - Bulk treasury conversion: 0.05–0.30% at volume (operator estimate) - Global avg remittance cost: 6.36% (World Bank Q3 2025) - pubDate: 2026-05-20 ### Chargeback Operations KPIs: Metrics, Targets, and Escalation Triggers - url: https://paymentbrief.com/articles/chargeback-operations-kpis/ - type: article - summary: Tracking only the chargeback ratio and win rate gives a lagging view of a dispute operation. A complete scorecard covers five categories — Compliance, Operational, Outcome, Quality, and Cost — and distinguishes scheme-set thresholds from operator-set targets. - topic: risk-and-compliance - keyFacts: - KPI categories: 5 — Compliance, Operational, Outcome, Quality, Cost/Efficiency - VAMP acquirer thresholds: Above Standard ≥0.50%; Excessive ≥0.70% (Visa, portfolio level) - VAMP merchant excessive threshold: ≥2.2%, reducing to ≥1.5% from 1 April 2026 (AP/Canada/EU/U.S.) - Metrics in scorecard: 16 across all five categories - pubDate: 2026-05-19 ### How to Choose a PSP: A Decision Matrix for Payment Operators - url: https://paymentbrief.com/articles/how-to-choose-psp-decision-matrix/ - type: article - summary: Most operators compare PSPs before answering the prior question: which class of provider fits my volume, operating model, and geography? This matrix answers that first — the class decision determines which head-to-heads are worth running. - topic: psp-and-infrastructure - keyFacts: - Provider classes: 5 major PSP setup types - Decision axes: Volume, region, model, vertical risk - Volume bands: <$1M to $1B+ annual volume - Scope: Standard-risk card-accepting businesses - pubDate: 2026-05-19 ### Mastercard Mastercom Dispute Categories Reference - url: https://paymentbrief.com/articles/mastercard-mastercom-dispute-categories-reference/ - type: article - summary: Mastercard Mastercom: 4 categories, 7 active codes, 45-day merchant response window. Auth and POI Error: 90-day filing window. Fraud and Cardholder Disputes: 120 days. ECM at 100+ chargebacks + 1.5–2.99% ratio; HECM at 300+ and ≥3.00%. - topic: risk-and-compliance - keyFacts: - Dispute platform: Mastercom — mandatory for all acquirers since 2023 - Active categories: 4 (Authorization / POI Error / Fraud / Cardholder Disputes) - Active codes: 7 (4808 / 4834 / 4837 / 4870 / 4841 / 4853 / 4855) - Merchant response window: 45 days — all categories (vs Visa's 30 days) - ECM threshold: ≥100 chargebacks/month AND 1.5–2.99% ratio - HECM threshold: ≥300 chargebacks/month AND ≥3.00% ratio - pubDate: 2026-05-18 - reviewedDate: 2026-05-31 ### Real-Time Payment Rails Comparison Matrix - url: https://paymentbrief.com/articles/real-time-payment-rails-comparison-matrix/ - type: article - summary: Eight real-time payment rails compared: UPI and Pix P2P mandate zero MDR; SPEI and PayNow Corporate are market-priced. All eight deliver T+0 irrevocable settlement. None have native dispute mechanisms — operators must build independent refund infrastructure. - topic: global-payments - keyFacts: - Rails covered: 8 — Pix, UPI, SPEI, PromptPay, PayNow, NAPAS 247 / VietQR, InstaPay, DuitNow - Zero-MDR mandate: UPI (Government of India, 2020 — statutory basis removed Aug 2026, policy still in force) and Pix P2P (BCB policy) - All 8 rails: T+0 settlement, no batch window; sender-initiated reversal is not available, but several rails have fraud freeze/recall processes - Native dispute mechanism: None — all transfers irrevocable; operators must build independent refund flows - Live cross-border links: UPI↔PayNow, UPI↔AANI (UAE), PromptPay↔PayNow, PromptPay↔DuitNow, QRIS↔PayNow - pubDate: 2026-05-18 - reviewedDate: 2026-05-31 ### The True Cost of a Chargeback: Unit Economics Beyond the Dispute Fee - url: https://paymentbrief.com/articles/true-cost-of-a-chargeback-unit-economics/ - type: article - summary: The true cost of a chargeback extends far beyond the dispute fee — lost goods, representment overhead, and VAMP consequences can make a single dispute cost 2–3x face value. Break-even math determines whether to fight or accept. - topic: payments-economics - keyFacts: - Full chargeback cost vs face value: 2–3x the original transaction value - Dispute fee range: $15–100 per dispute (varies by PSP, risk tier, region) - Industry win rate on contested disputes: ~40–45% - Break-even rule (fight vs accept): Fight if (transaction value × win rate) > (dispute fee + representment cost) - VAMP acquirer portfolio threshold: Above Standard: ≥50 bps (0.50%) - VAMP acquirer portfolio threshold: Excessive: ≥70 bps (0.70%) - pubDate: 2026-05-18 ### Visa Reason Codes: VCR Workflows, Deadlines, and How to Choose - url: https://paymentbrief.com/articles/visa-reason-codes-reference/ - type: article - summary: Visa's VCR: 4 categories, 2 workflows — Allocation for Fraud/Authorization, Collaboration for Processing Errors/Consumer Disputes. 30-day merchant response throughout; CE 3.0 eligible: 10.4 only. Per-code lookup is in the reason-code tool; this is the strategy explainer. - topic: risk-and-compliance - keyFacts: - VCR launched: April 2018 — replaced 22 legacy codes - Code categories: 4 (Fraud / Authorization / Processing Errors / Consumer Disputes) - Workflows: 2 (Allocation for 10.x and 11.x; Collaboration for 12.x and 13.x) - Merchant response deadline: 30 days (all VCR codes) - CE 3.0 eligible code: 10.4 only (Other Fraud — Card-Absent) - Last major consolidation: April 2024 (11.3 absorbed Late Presentment 12.1) - pubDate: 2026-05-18 - reviewedDate: 2026-07-23 ### Authorized Push Payment Fraud and the Real-Time Rail Liability Problem - url: https://paymentbrief.com/articles/authorized-push-payment-fraud-real-time-rails/ - type: article - summary: APP fraud victims authorize the payment themselves — standard fraud controls don't fire. The UK PSR mandatory reimbursement scheme (October 2024) created 50/50 liability for sending and receiving PSPs. Growing real-time rail adoption makes this a cross-market problem. - topic: risk-and-compliance - pubDate: 2026-05-17 ### Stripe vs Square: An Operator's Decision Framework - url: https://paymentbrief.com/articles/stripe-vs-square-operator-guide/ - type: article - summary: Stripe wins for online, SaaS, marketplace, and global operators. Square wins for card-present retail and SMB US. Decision framework by operator archetype — not a feature comparison. - topic: global-payments - pubDate: 2026-05-17 ### DORA for Payment Operators: EU Digital Operational Resilience - url: https://paymentbrief.com/articles/dora-payment-operators-eu-digital-operational-resilience/ - type: article - summary: DORA came into force 17 January 2025 and applies to payment institutions, e-money institutions, and AISPs. Its five pillars — ICT risk management, incident reporting, resilience testing, third-party risk, and information sharing — are now active obligations. - topic: risk-and-compliance - pubDate: 2026-05-16 ### Least-Cost Routing: Sending Payments to the Cheapest Eligible Rail - url: https://paymentbrief.com/articles/least-cost-routing-cheapest-payment-rail/ - type: article - summary: Least-cost routing means three non-interchangeable things: Australia's self-regulatory eftpos/RBA framework, the US Durbin Amendment's Regulation II network-choice mandate, and generic cost-based routing with no mandate at all. Conflating them produces the wrong architecture. - topic: payments-economics - keyFacts: - Three regimes, one phrase: Australian eftpos/RBA self-regulation, US Regulation II (Durbin) dual-network mandate, generic cost-based routing — mechanically distinct - US dual-network rule applies to: All debit issuers regardless of asset size — the $10B threshold governs interchange caps only, not routing - US card-not-present dual-routing effective: July 1, 2023 (extended from card-present, required since April 1, 2012) - Australian LCR basis: Self-regulatory industry framework (AusPayNet), RBA-endorsed since 2015 — not a statute - pubDate: 2026-05-15 - reviewedDate: 2026-08-21 ### The MDR Stack: Reading Your Processing Statement Line by Line - url: https://paymentbrief.com/articles/mdr-stack-reading-processing-statement-line-by-line/ - type: article - summary: MDR decomposes into 5 fee layers — interchange, scheme fees, acquirer margin, FX markup, ancillaries — plus a sixth off-statement cost: working capital tied up by reserves and settlement timing. Acquirer margin, FX, ancillaries, and reserves are all negotiable to varying degrees. - topic: payments-economics - pubDate: 2026-05-15 - reviewedDate: 2026-08-26 ### AI Agents and Payment APIs: MCP, Stripe Agent Toolkit, and Mastercard - url: https://paymentbrief.com/articles/ai-agents-payment-apis-mcp-stripe-toolkit/ - type: article - summary: MCP: 97M monthly SDK downloads, donated to Linux Foundation Dec 2025. Stripe Agent Toolkit production — refunds, subscriptions, invoices via LLM. Visa TAP + Mastercard Agentic Tokens live. SCA regulatory gap for agent transactions unresolved in PSD3/PSR final text. - topic: ai-and-automation - keyFacts: - MCP launched: November 25, 2024 (Anthropic); donated to Linux Foundation December 2025 - MCP scale (March 2026): 97M monthly SDK downloads; 10,000+ public servers - Stripe MCP server: mcp.stripe.com — ~25 tools, OAuth-authenticated, production - Mastercard Europe first AI payment: Santander + Mastercard, March 2026 - Visa TAP launched: October 2025 — open spec on GitHub, cryptographic agent verification - SCA regulatory status: No AI-agent provisions in PSD3/PSR final text (April 2026) - pubDate: 2026-05-14 - reviewedDate: 2026-06-14 ### AI in Merchant Onboarding: KYB Automation, Risk Scoring, and Approvals - url: https://paymentbrief.com/articles/ai-merchant-onboarding-kyb-risk-scoring/ - type: article - summary: AI has compressed merchant onboarding from days to minutes for low-risk applicants. The ML stack covers document verification, UBO extraction, risk scoring, and instant-approval routing — with Persona, Alloy, and Sardine leading the vendor landscape. - topic: ai-and-automation - pubDate: 2026-05-14 ### SEPA Credit Transfer, Instant, and Direct Debit: Operator Guide - url: https://paymentbrief.com/articles/sepa-credit-transfer-instant-direct-debit-merchant-guide/ - type: article - summary: Four SEPA schemes, 36 countries, one reference. SCT Inst mandatory for eurozone PSPs since Oct 2025. SDD Core carries an 8-week consumer refund right. IBAN name check mandatory from Oct 2025. SEPA ≠ euro — 16 non-eurozone members use national schemes for local currency. - topic: global-payments - keyFacts: - SEPA countries: 36 — but only 20 are eurozone; 16 members use national schemes for local currency - SCT Inst mandate: Mandatory for all eurozone PSPs since October 9, 2025 under EU Instant Payments Regulation - SDD Core refund right: 8 weeks no-questions-asked for authorised; 13 months for unauthorised transactions - IBAN name check: Verification of Payee mandatory for all outbound SCT and SCT Inst from October 2025 - pubDate: 2026-05-14 ### Subscription Rails: eGIRO, UPI AutoPay, SEPA SDD, Pix Automático - url: https://paymentbrief.com/articles/subscription-payments-rail-paynow-upi-sepa-pix/ - type: article - summary: PayNow is push-only — eGIRO handles recurring billing in Singapore. UPI AutoPay hit 175M monthly transactions in Jan 2025, tripling YoY. SEPA SDD Core has an 8-week consumer refund right. Pix Automático launched June 2025. Cards remain default for operators without local entity. - topic: global-payments - keyFacts: - PayNow recurring support: None — push-only rail - UPI AutoPay monthly txns (Jan 2025): 175M, up 3× year-on-year - UPI AutoPay standard cap: ₹15,000 per debit - Pix Automático launched: June 16, 2025 (BCB) - SEPA SDD refund window: 8 weeks, no-questions-asked (Core) - eGIRO activation time: Minutes vs 21 working days (paper GIRO) - pubDate: 2026-05-14 ### Variable Recurring Payments (VRP): Open Banking vs Card-on-File - url: https://paymentbrief.com/articles/variable-recurring-payments-vrp-open-banking-billing/ - type: article - summary: Sweeping VRP live in the UK since 2022. Commercial VRP went live 2 June 2026 under UKPI — but Wave 1 covers only utilities, financial services, government and charities. Subscription billing waits for Wave 2, no confirmed date. Near-zero MDR, no expiry churn, no chargebacks. - topic: psp-and-infrastructure - keyFacts: - UK sweeping VRP live since: January 2022 — mandated for all CMA9 banks - Commercial VRP status: Live 2 June 2026 via UKPI Wave 1 (utilities, financial services, government, charities). Subscriptions await Wave 2 — no confirmed date - Settlement: Faster Payments — typically under 10 seconds, 24/7 - MDR vs card: Near-zero vs 0.3–1.5%+ for card-on-file subscriptions - pubDate: 2026-05-14 ### Merchant-Initiated Transactions: SCA, Reason Codes, Auth Rate Impact - url: https://paymentbrief.com/articles/merchant-initiated-transaction-mit-cit-subscription-billing/ - type: article - summary: MIT SCA exemption only works if the initial CIT was 3DS2-authenticated — the anchor requirement many operators skip. Six MIT subtypes, each with its own scheme code. Correct flagging lifts authorization on recurring charges, especially where SCA is enforced. - topic: psp-and-infrastructure - keyFacts: - MIT subtypes: 6 distinct categories — recurring, instalment, unscheduled COF, resubmission, delayed charge, no-show - SCA anchor requirement: Initial CIT must be 3DS2-authenticated in EEA — MIT chain breaks without it - Auth rate uplift: Correct MIT flagging authorizes more reliably than unflagged recurring charges; the gain is largest where SCA is enforced — size it on your own data - Subscription involuntary churn: Failed recurring authorizations are a major driver of involuntary churn — recover them as a billing-operations workflow, not just a flagging detail - A stale-card decline is not a broken MIT chain: An expired or reissued card throws a hard decline; the fix is Account Updater (VAU/ABU) or network tokens, not re-flagging — operators routinely misdiagnose this as a chain break. - Authentication-required declines can't be retried off-session: A soft decline asking for SCA (e.g. Visa 1A / Mastercard 65) means the issuer wants the cardholder present; an off-session retry returns the same code — bring the customer back to re-authenticate. - Network tokens survive card replacement: Unlike a static PAN, a network token auto-updates when the card is reissued, so the MIT chain keeps working without a separate Account Updater fetch — the durable fix for credential staleness. - pubDate: 2026-05-13 - reviewedDate: 2026-06-26 ### Payment AI MLOps: Model Drift, Retraining, and Production Monitoring - url: https://paymentbrief.com/articles/payment-ai-mlops-model-drift-retraining/ - type: article - summary: Fraud model: 95%→87% accuracy in 8 months. Chargebacks arrive 60–120 days late — ground truth structurally delayed. PSI >0.2 triggers retraining. Monthly beats quarterly. NYDFS Oct 2024, PRA SS1/23 (May 2024) require formal model governance. WhyLabs shut down 2025. - topic: ai-and-automation - keyFacts: - Model degradation timeline: 95% → 87% accuracy in 8 months (practitioner case, 2024) - McKinsey 2023 survey: 40% of AI deployments show noticeable degradation within year one - Chargeback labeling lag: Visa and Mastercard: up to 120 days from transaction date - PSI retraining threshold: >0.2 = model needs retraining; 0.1–0.2 = moderate drift - Revolut PRAGMA (April 2025): Foundation model on 24B banking events — 65% fraud recall lift - PRA SS1/23: Model risk management, enforceable May 2024 for UK banks - pubDate: 2026-05-13 - reviewedDate: 2026-06-14 ### AI-Powered Payment Reconciliation: From Settlement Exceptions to Close - url: https://paymentbrief.com/articles/payment-reconciliation-ai-continuous-close/ - type: article - summary: Reconciliation depends on deterministic matching rules — AI adds exception categorization, narrative generation, and anomaly detection at the edges. The continuous close pattern resolves exceptions per settlement batch rather than at month-end. - topic: ai-and-automation - pubDate: 2026-05-13 ### PCI DSS 4.0 — Year One: What Operators Got Wrong - url: https://paymentbrief.com/articles/pci-dss-4-year-one-what-operators-got-wrong/ - type: article - summary: 51 future-dated PCI DSS 4.0 requirements became mandatory March 31, 2025. First post-enforcement assessments show Req 6.4.3/11.6.1 script inventory and Req 8.4.2 MFA scope expansion as the most common gaps; SAQ-A merchants are misjudging reduced-scope eligibility. - topic: risk-and-compliance - pubDate: 2026-05-13 ### Stripe vs PayPal for SaaS Subscriptions: An Operator's Comparison - url: https://paymentbrief.com/articles/stripe-vs-paypal-saas-subscriptions/ - type: article - summary: PayPal's checkout conversion wins where customers have funded PayPal wallets. Stripe Billing wins for subscription lifecycle depth. Decision framework for SaaS operators choosing between them. - topic: psp-and-infrastructure - pubDate: 2026-05-13 ### AI-Powered Payment Routing: How ML Replaced the Static Routing Table - url: https://paymentbrief.com/articles/ai-payment-routing-ml-orchestration/ - type: article - summary: Stripe PFM (May 2025): tens of billions of transactions, $6B falsely declined txns recovered in 2024. Adyen Uplift (Jan 2025): 9.4% cost reduction, 42% fewer false declines. ML routing: 96.7% vs 94.1% auth rate vs rules (A/B, 200K txns, sub-30ms decisions). - topic: ai-and-automation - keyFacts: - Stripe PFM announced: May 2025 — transformer model trained on tens of billions of transactions - Stripe Adaptive Acceptance (2024): Recovered $6B in falsely declined transactions — 60% YoY retry success rate increase - Stripe Authorization Boost: 3.8% average auth rate uplift across eligible merchants - Adyen Uplift (January 2025): 9.4% cost reduction on eligible traffic; 42% fewer false positive declines - Adyen Intelligent Routing result: 26% cost savings, 0.22% auth rate uplift (pilot: eBay, Microsoft, 24 Hour Fitness) - ML vs rule-based A/B test: 96.7% vs 94.1% auth rate across 200,000 transactions - pubDate: 2026-05-12 ### EU AI Act and Payment Systems: High-Risk vs Limited-Risk Use Cases - url: https://paymentbrief.com/articles/eu-ai-act-payment-systems-risk-classification/ - type: article - summary: Fraud scoring is not automatically high-risk under the EU AI Act — Annex III explicitly excludes AI for detecting financial fraud. BNPL consumer credit scoring likely is. The act is progressively live; full application from August 2026. - topic: ai-and-automation - pubDate: 2026-05-12 ### Multi-Acquirer Routing: When and How to Add a Second PSP - url: https://paymentbrief.com/articles/multi-acquirer-routing/ - type: article - summary: Adding a second PSP improves auth rates, adds redundancy, and creates contract leverage. The hidden costs — reconciliation, token portability, and orchestration build — are what most operators underestimate. - topic: psp-and-infrastructure - keyFacts: - Orchestration market size (2025): USD 2.65 billion - Market forecast (2031): USD 7.27 billion - CAGR (2026–2031): 18.31% - Typical volume threshold to justify second PSP: $5–10M monthly - pubDate: 2026-05-12 ### Network Tokens vs PSP Tokens: When Each Wins - url: https://paymentbrief.com/articles/network-tokens-vs-psp-tokens/ - type: article - summary: Network tokens (Visa VTS, Mastercard MDES) are scheme-issued, MID-bound, and auto-update on card reissue. PSP tokens are processor-locked and don't travel. The difference matters most at migration time. - topic: psp-and-infrastructure - keyFacts: - Visa network token auth lift: +4.6% CNP vs PAN (Visa, FY2022) - Visa tokens provisioned (FY2024): 11.5 billion - Tokenised transactions forecast (2029): 574 billion (from 283B in 2025) - pubDate: 2026-05-12 ### 14 PSP Contract Red Flags That Cost Merchants Millions - url: https://paymentbrief.com/articles/psp-contract-red-flags/ - type: article - summary: Most operators sign PSP contracts without redlining a single clause. These 14 terms are where processors shift risk to merchants — on reserves, pricing, exit rights, and liability. - topic: psp-and-infrastructure - keyFacts: - Flags covered: 14 - Rolling reserve typical range: 5–10% of transactions - Reserve hold period: 90–180 days - Standard settlement: T+2 for standard risk - pubDate: 2026-05-12 ### MoR vs PSP: When the Premium Beats Doing It Yourself - url: https://paymentbrief.com/articles/merchant-of-record-vs-psp-when-to-switch/ - type: article - summary: MoR providers take on tax, fraud, chargeback handling and global compliance — and charge a premium. The right question is not the premium but how much compliance infrastructure you would build to replace what they handle. - topic: psp-and-infrastructure - keyFacts: - Who is the seller: PSP: you. MoR: the MoR. - Tax registration burden: PSP: yours. MoR: theirs. - Chargeback liability: PSP: yours. MoR: theirs to the network — but the agreement usually lets them pass the cost back to you for disputes attributable to your product or service. - Customer relationship on statement: PSP: your brand. MoR: MoR brand or 'via MoR'. - Refund authority: PSP: yours. MoR: shared per their policy. - Typical inflection point: When per-jurisdiction tax cost exceeds MoR premium - pubDate: 2026-05-11 ### Scheme Chargeback Rules 2026: Visa VCR, Mastercard, and Reason Codes - url: https://paymentbrief.com/articles/visa-vcr-mastercard-chargeback-rules-2026/ - type: article - summary: VAMP merchant threshold 2.2% → 1.5% from April 2026 (AP/Canada/EU/US), with fees now charged directly to merchants. CE 3.0 gained a qualification fee April 2026. Mastercard TLID rollout continues through 2027; undefined-authorization fee began July 2025. - topic: risk-and-compliance - keyFacts: - VCR launched: April 2018 — replaced 22 legacy Visa codes with 4-category structure - VAMP effective: April 1, 2025 — replaces VDMP + VFMP; ratio formula effective 1 June 2025; enforcement began October 1, 2025 - Current merchant VAMP threshold: 1.5% for AP/Canada/EU/US (dropped from 2.2% on April 1, 2026); LAC already at 1.5%; CEMEA remains at 2.2% - VAMP enumeration threshold: 20% of authorization transactions, once a merchant has 300,000+ enumerated transactions in a month - CE 3.0 — next change: 24 October 2026 — CE 3.0 evidence expands to multi-merchant history (Visa Rules, 18 Apr 2026 ed.) - CE 3.0 auto-qualification: October 17, 2025 — Visa Secure merchants qualify automatically for eligible 10.4 disputes; a qualification fee was added April 17, 2026 - Mastercard merchant response window: 45 days (vs Visa's 30 days) - Mastercard ECP threshold: 100 chargebacks/month + 1.5–2.99% ratio triggers Excessive Chargeback Merchant status - pubDate: 2026-05-11 - reviewedDate: 2026-08-21 ### LLMs in AML Transaction Monitoring: What Operators Can Deploy Today - url: https://paymentbrief.com/articles/llms-aml-transaction-monitoring/ - type: article - summary: Traditional TM: 90–95% false positive rate. LLMs are a third layer — alert triage, SAR drafting, investigator support. NICE X-Sight AI Narrate: 70% SAR time savings (Feb 2024). HSBC: 2–4x suspicious activity found, 60% fewer alerts. SR 26-2 (Apr 2026) supersedes SR 11-7. - topic: risk-and-compliance - keyFacts: - Traditional TM false positive rate: 90–95% (Gartner 2025 Financial Conduct Operations Survey) - SAR filing time savings with LLM narration: 70% — NICE Actimize X-Sight AI Narrate (launched February 2024) - Manual monitoring effort reduction: Up to 87% with AI agents; ~115 minutes saved per analyst per day - HSBC AI deployment: 2–4x more suspicious activity identified; 60% fewer alerts generated - FinCEN civil penalties H1 2025: 81% YoY increase — $1.07B vs $590M in H1 2024 - SR 26-2 effective: April 17, 2026 — supersedes SR 11-7; risk-based model risk management framework - pubDate: 2026-05-10 ### MoR Migration Playbook: Paddle, Polar, Lemon Squeezy to Direct PSP - url: https://paymentbrief.com/articles/mor-migration-playbook-paddle-polar-to-direct-psp/ - type: article - summary: Migrating off MoR is a 6-12 month project, not a vendor swap. The hard parts: subscription re-authorisation (tokens don't transfer), tax registration sequencing (no gap allowed), invoice continuity for B2B, and the hybrid landing that almost everyone ends up at. - topic: psp-and-infrastructure - keyFacts: - Realistic timeline: 6-12 months from decision to stable hybrid - Re-auth churn range: 10-25% of migrated subscribers typically; plan conservatively - Tax registrations: Must be active in every jurisdiction before first sale under your name - Card tokens: Don't transfer between MIDs — every subscriber re-authorises - Historical liability: Stays with MoR; you inherit forward liability from cutover date - Common landing: Hybrid (direct PSP for core / B2B; MoR for new markets / self-serve) - pubDate: 2026-05-10 ### Pix vs UPI vs SPEI vs PromptPay: Real-Time Rail Economics Compared - url: https://paymentbrief.com/articles/realtime-rail-comparison-pix-upi-spei-promptpay/ - type: article - summary: Pix, UPI, SPEI, and PromptPay all deliver T+0 settlement but differ on governance, MDR mandate, and identifier architecture. Pix and UPI mandated zero-MDR to displace cards; SPEI and PromptPay grew alongside cards. The right comparison is not volume but the regulatory model. - topic: global-payments - keyFacts: - Largest by volume: UPI — 22.35B transactions/month (April 2026) - Fastest adoption: Pix — 160M+ users in under 2 years - Oldest rail: SPEI — live since August 2004 - Most accounts vs population: PromptPay — 90M+ on 71M population - Zero-MDR mandated: UPI (government, 2020 — statutory basis removed Aug 2026, still zero in practice) and Pix (BCB policy) - Market-priced MDR: SPEI and PromptPay (no government mandate) - pubDate: 2026-05-10 ### AI Chargeback Representment Automation: What Actually Works in 2026 - url: https://paymentbrief.com/articles/ai-chargeback-representment-automation/ - type: article - summary: US merchants win 54% of disputes they fight but just 8.1% of all disputes overall (Mastercard/Datos Insights) — most losses are uncontested, not unwinnable. AI lifts contested win rates toward 65-80% on friendly fraud (Kount). CE 3.0 and VAMP fees both changed in April 2026. - topic: ai-and-automation - keyFacts: - Global chargeback value (2025): $33.8B across 261M transactions (Mastercard/Datos Insights) - US merchant win rate, all disputes received: 8.1% (Mastercard/Datos Insights, 2025) — most disputes are never contested - US merchant win rate, disputes actually contested: 54% (Mastercard/Datos Insights) - Net recovery after representment: 10.7% of cases once wins escalated to a second-cycle chargeback are factored in (Chargebacks911 2026 Field Report, a merchant survey with no stated geography); the same company's win-rate figure is stated inconsistently… - Manual vs AI-assisted win rate on contested disputes: 20-40% manual vs 65-80% AI-assisted, targeted disputes (Kount/Equifax) - Fraud-cost multiplier per $1 lost (2026): $5.13, up from ~$3.36 in 2020 (LexisNexis Risk Solutions) - VAMP merchant threshold and fee scope: Dropped 2.2%→1.5% (AP/Canada/EU/US) and Excessive fee now billed directly to merchants, both effective April 1, 2026 - CE 3.0 qualification fee: Added April 17, 2026; amount undisclosed by Visa - pubDate: 2026-05-09 - reviewedDate: 2026-08-24 ### Brazil's Stablecoin Cross-Border Ban: BCB Resolution 561 Explained - url: https://paymentbrief.com/articles/brazil-stablecoin-cross-border-ban-2026/ - type: article - summary: BCB Resolution 561 (April 30, 2026) bans eFX providers from settling cross-border flows in stablecoin or crypto from October 1 — directly hitting Wise, Nomad, and Braza Bank's Brazil-corridor architectures and forcing a return to FX transactions or non-resident real accounts. - topic: stablecoins - pubDate: 2026-05-09 ### PSD3 and PSR: ECON Vote, 21-Month Clock, Operator Checklist - url: https://paymentbrief.com/articles/psd3-psr-implementation-operator-checklist-2026/ - type: article - summary: ECON approved PSD3 (55–3–5) and PSR (50–2–2) on May 5, 2026. Plenary expected late May, OJ publication June/July, 21-month application clock starts then. Operators have ~24 months to rebuild fraud liability, SCA, open banking, and safeguarding architecture. - topic: risk-and-compliance - pubDate: 2026-05-09 ### Spreedly vs Primer vs Gr4vy: Payment Orchestration Layer Compared - url: https://paymentbrief.com/articles/spreedly-vs-primer-vs-gr4vy-orchestration/ - type: article - summary: Spreedly, Primer, and Gr4vy each solve the orchestration problem differently. Spreedly for enterprise vaulting, Primer for no-code workflows, Gr4vy for cloud-native flexibility. Decision framework for operators. - topic: psp-and-infrastructure - pubDate: 2026-05-09 ### Account Takeover Detection: The ML Stack Behind ATO Prevention - url: https://paymentbrief.com/articles/account-takeover-detection-ml-payments/ - type: article - summary: ATO attacks up 148% YoY (Sift Q4 2025). FBI: $1.1B+ retail losses. Market: $4.52B (2025) → $18.58B by 2034. Four layers: device fingerprinting, behavioral biometrics, session ML scoring, adaptive MFA. BioCatch DeviceIQ launched March 2026. - topic: risk-and-compliance - keyFacts: - ATO attack increase Q4 2025: 148% YoY (Sift Digital Trust Index Q4 2025) - FBI reported ATO losses (retail): $1.1B+ in credential-fraud and ATO losses (2025 IC3 report) - ATO prevention market size (2025): $4.52B — projected $18.58B by 2034 at 17% CAGR - BioCatch DeviceIQ: Launched March 2026 — device-level AI targeting banking ATO fraud - Mastercard GenAI fraud detection: 300% improvement in detection rates (2025) - Four-layer ATO defense: Passkeys + adaptive MFA + device intelligence + behavioral biometrics - pubDate: 2026-05-08 ### What Your MoR Actually Handles for Tax (And What You Still Have to Do) - url: https://paymentbrief.com/articles/what-your-mor-handles-for-tax-and-what-you-still-do/ - type: article - summary: MoR providers handle VAT/GST/sales tax registration, collection, and remittance globally. They do not handle your income tax, corporate filings, transfer pricing, or 1099 reporting. The line between 'covered' and 'still your job' is sharper than most operators realise. - topic: psp-and-infrastructure - keyFacts: - MoR handles: Consumption tax (VAT/GST/sales tax): registration, collection, invoicing, remittance - MoR does not handle: Income tax, corporate tax filings, transfer pricing, your 1099 obligations - EU coverage model: OSS for digital services; per-country invoicing where required - US coverage model: Marketplace facilitator laws + Wayfair economic nexus per state - B2B reverse charge: MoR handles in EU when buyer VAT ID validated; seller still tracks for reporting - Historical liability: MoR retains; you inherit forward liability from migration date if you switch - pubDate: 2026-05-08 ### Real-Time Fraud Decisioning: How Payment AI Makes Sub-100ms Calls - url: https://paymentbrief.com/articles/real-time-fraud-decisioning-payment-ai/ - type: article - summary: 100ms total window. ML scoring: 10–50ms. Feature store must be sub-millisecond (Redis, Aerospike). Cascade: fast model filters 90%+ volume, accurate model scores the rest. Labeling lag: chargebacks arrive 60–120 days after the transaction. - topic: ai-and-automation - keyFacts: - Total authorization window: ~100ms end-to-end (network + feature retrieval + model inference + response) - ML fraud scoring latency: 10–50ms for gradient boosting; transformer models require GPU inference - Feature store retrieval requirement: Sub-millisecond — in-memory stores (Redis, Aerospike) required at scale - Features per prediction: 20–100+ features within the 100ms window - Chargeback labeling lag: 60–120 days from transaction — ground truth structurally delayed - Sift real-time scoring: Sub-100ms fraud scores on every payment; approve, flag, or block before settlement - pubDate: 2026-05-07 ### Stripe vs Adyen vs Checkout.com: A 2026 PSP Pricing Teardown - url: https://paymentbrief.com/articles/stripe-vs-adyen-vs-checkout-2026-pricing-teardown/ - type: article - summary: Stripe publishes rate cards. Adyen publishes indicative IC++ but gates the rest. Checkout.com keeps all rates behind a sales call. The right comparison is landed effective cost per successful dollar, not headline rate — auth-rate gaps usually dwarf processing-fee deltas. - topic: psp-and-infrastructure - pubDate: 2026-05-07 - reviewedDate: 2026-08-25 ### When MoR Stops Making Sense: The Qualitative Thresholds - url: https://paymentbrief.com/articles/when-merchant-of-record-stops-making-sense/ - type: article - summary: Outgrowing an MoR isn't triggered by a revenue milestone. The real signals are qualitative: enterprise B2B mix, compliance maturity, market concentration, product gaps, and data ownership limits. Migration takes 6-12 months and usually ends in a hybrid, not a full cutover. - topic: psp-and-infrastructure - keyFacts: - Primary trigger: Enterprise B2B mix — accounts-payable teams want invoices from your brand - Second trigger: Compliance team maturity — when in-house can absorb what MoR replaces - Third trigger: Market concentration — few markets, direct registration becomes cost-effective - Fourth trigger: Payment method gap — MoR doesn't support a critical local rail - Fifth trigger: Data ownership walls — marketing and product teams hit access limits - Migration timeline: 6-12 months; most companies land on a hybrid, not a full cutover - pubDate: 2026-05-06 ### Adyen vs Worldpay for European Enterprise: An Operator's Comparison - url: https://paymentbrief.com/articles/adyen-vs-worldpay-european-enterprise/ - type: article - summary: Adyen wins on unified platform data and omnichannel consistency. Worldpay wins on acquiring coverage and legacy issuer relationships. Worldpay is now part of Global Payments after a January 2026 acquisition; pricing-autonomy claims should be verified, not assumed. - topic: global-payments - pubDate: 2026-05-05 - reviewedDate: 2026-08-24 ### AI Fraud Detection in 2026: What the Models Are Actually Doing - url: https://paymentbrief.com/articles/ai-fraud-detection-2026/ - type: article - summary: Production AI fraud detection in 2026 runs ensemble models combining supervised transaction scoring, unsupervised anomaly detection, and behavioral biometrics — delivering 30–40% fraud reduction while cutting false positives. - topic: ai-and-automation - pubDate: 2026-05-04 ### MoR Provider Guide: Paddle, Polar, FastSpring, and Lemon Squeezy - url: https://paymentbrief.com/articles/merchant-of-record-provider-comparison-paddle-polar-fastspring/ - type: article - summary: Paddle, Lemon Squeezy (now Stripe-owned), Polar, and FastSpring compared by coverage, tax footprint, DX, and strategic fit — not pricing. The right MoR isn't the cheapest; it's the one whose structural trade-offs match your seller archetype and growth trajectory. - topic: psp-and-infrastructure - keyFacts: - Established pure-play: Paddle — SaaS recurring billing depth, ProfitWell analytics, enterprise push - Stripe-owned MoR: Lemon Squeezy — acquired July 2024; Stripe dual-rail strategy - Developer-tools newcomer: Polar — Y Combinator-backed; open-source, AI, dev-community monetisation - Legacy independent: FastSpring — no PSP affiliation; enterprise digital goods heritage - What to evaluate: Tax footprint, payment-method coverage, recurring billing depth, enterprise B2B fit, DX - What not to compare: Published pricing — changes too frequently to remain accurate in articles - pubDate: 2026-05-04 ### PayNow Corporate Fees, UEN Registration, and Bank APIs in Singapore - url: https://paymentbrief.com/articles/singapore-paynow-corporate-operator-guide/ - type: article - summary: PayNow Corporate: what it costs by bank (DBS, OCBC, UOB), how to register a UEN (including sole proprietorships), and how the corporate channels (RAPID/IDEAL, Velocity/OneCollect, Infinity/API Services) compare on fees and API depth — dated to each bank's own pricing page. - topic: global-payments - keyFacts: - UEN is the business alias: PayNow Corporate links a company's UEN to its bank account; payers send to the UEN over FAST, with a structured reference that carries through for reconciliation. - FAST caps single transfers at SGD 200,000: PayNow Corporate settles in real time over FAST (24/7); transfers above the SGD 200,000 FAST ceiling route via MEPS+. Banks may set lower channel limits. - No universal API — integrate your bank: Each bank exposes its own corporate channel: DBS RAPID (API) / IDEAL (portal), OCBC Velocity / OneCollect, UOB Infinity / API Services. Multi-bank customers mean multiple integrations. - UOB and OCBC list inbound PayNow at SGD 0.20, waived to 2028: As published by each bank (retrieved 2026-08-20): UOB and OCBC's list price for an inbound PayNow Corporate transaction is SGD 0.20, but both currently waive it under promotions running to 31 December 2028 — the list pri… - DBS has not published a post-2025 inbound rate: DBS's own PayNow Corporate page (retrieved 2026-08-20) states inward PayNow 'will remain free until end of 2025' with no rate confirmed for after that date on the same page — treat DBS pricing beyond 2025 as unverified a… - Bank-direct vs aggregator is the core trade: Bank-direct means lowest cost and direct reconciliation but single-bank lock-in; an aggregator (Stripe, Adyen, Fiuu, HitPay) means one integration across banks and methods at an MDR. - Reconciliation rides on the reference field: A PayNow QR can pre-fill amount plus a bill reference; that reference carries through FAST to the recipient's transaction record, enabling auto-match to invoices in your ERP. - pubDate: 2026-05-04 - reviewedDate: 2026-08-20 ### Agentic Commerce: When AI Agents Become Cardholders - url: https://paymentbrief.com/articles/agentic-commerce-ai-agents-payments/ - type: article - summary: AI agents making autonomous purchases is no longer theoretical — Visa, Mastercard, and OpenAI have live infrastructure. The hard problems are authentication (3DS fails for agents), liability assignment, and MCC coding when an agent acts on behalf of a human. - topic: ai-and-automation - pubDate: 2026-05-03 ### Klarna vs Afterpay vs Affirm: A BNPL Operator's Comparison - url: https://paymentbrief.com/articles/klarna-vs-afterpay-vs-affirm-bnpl-operator-guide/ - type: article - summary: Klarna for European reach and BNPL product breadth. Afterpay for 18–35 US/AU demographics via Square/Block. Affirm for high-AOV US purchases and Shopify. Operator selection guide. - topic: global-payments - pubDate: 2026-05-02 - reviewedDate: 2026-06-14 ### Variable Recurring Payments: Open Banking's Killer Use Case (and Why It's Still Hard) - url: https://paymentbrief.com/articles/open-banking-uk-eu-variable-recurring-payments/ - type: article - summary: UK commercial VRP went live via the UKPI scheme on 2 June 2026, but Wave 1 covers only utilities, financial services, government, and charities — subscriptions wait for Wave 2, expected later in 2026 with no confirmed date. EU PSD3/PSR remain pre-Official Journal. - topic: global-payments - pubDate: 2026-05-01 - reviewedDate: 2026-08-21 ### Understanding PSP Contracts: What Merchants Never Read But Should - url: https://paymentbrief.com/articles/understanding-psp-contracts/ - type: article - summary: PSP contracts contain clauses on rolling reserves, chargeback termination triggers, and unilateral fee changes that can materially drain merchant margins — most are negotiable before signing but rarely challenged afterward. - topic: payments-economics - keyFacts: - Rolling reserve clause: Review holdback percentage, release timing, rolling basis, and release triggers. - Reserve hold period: Review the defined hold window and confirm it is tied to a release trigger, not open-ended. - PSP chargeback threshold (internal): PSP internal thresholds are often set below card-network thresholds; negotiate a cure period before termination rights vest. - Cure period to negotiate: Push for a written notice requirement and a defined cure window after threshold breach before termination rights vest. - Fee-change notice standard to push for: Fee-change clauses should define notice period, a materiality threshold, and post-effective-date-only scope. - pubDate: 2026-05-01 ### Multi-Chain Stablecoin Strategy: Ethereum, L2s, Solana, Tron Compared - url: https://paymentbrief.com/articles/multi-chain-stablecoin-strategy-ethereum-l2-solana-tron/ - type: article - summary: USDC and USDT exist on 15+ chains. Each has different cost, finality, custody coverage, and regulatory standing. Framework for operators choosing which chains to accept, settle, and hold stablecoins on in 2026. - topic: stablecoins - pubDate: 2026-04-30 ### Saudi Arabia's Payment Stack: Mada, SARIE, and the Vision 2030 Infrastructure - url: https://paymentbrief.com/articles/saudi-arabia-mada-sarie-payment-stack/ - type: article - summary: Mada dominates Saudi domestic card transactions; e-payments hit 85% of retail in 2025 (SAMA, April 2026); STC Pay leads the wallet market — SAMA licensing and mandatory Mada acceptance mean foreign operators need a licensed local acquirer like HyperPay or Checkout.com. - topic: global-payments - pubDate: 2026-04-30 - reviewedDate: 2026-08-27 ### Reconciliation Automation: Where LLMs Actually Move the Needle - url: https://paymentbrief.com/articles/reconciliation-automation-llms/ - type: article - summary: LLMs work for fuzzy merchant-name matching and exception triage in reconciliation, but fail at high-precision matching where money is on the line. Production architecture: deterministic matching for clean data, LLM triage for exceptions. - topic: ai-and-automation - pubDate: 2026-04-29 ### Stablecoin Settlement Loop: Anatomy of a Cross-Border B2B Payment - url: https://paymentbrief.com/articles/stablecoin-settlement-loop-anatomy-cross-border-payment/ - type: article - summary: A cross-border stablecoin B2B payment is a six-stage loop — fiat in, on-ramp, custody, on-chain, off-ramp, fiat out — with separate providers, costs, and failure modes at each stage. The blockchain is the smallest part. - topic: stablecoins - pubDate: 2026-04-29 ### How AI Is Rewiring Payments Infrastructure in 2026 - url: https://paymentbrief.com/articles/ai-payments-infrastructure-2026/ - type: article - summary: AI is embedded in every layer of the 2026 payments stack — fraud scoring, dynamic routing, and treasury — with intelligent routing delivering 2–12 point authorization rate gains depending on market. - topic: ai-and-automation - pubDate: 2026-04-28 ### Stablecoins as B2B Payment Rails: Infrastructure Shift for Operators - url: https://paymentbrief.com/articles/stablecoins-as-b2b-payment-rails/ - type: article - summary: Stablecoins are genuine B2B settlement infrastructure in 2026 — USDC via Solana or Base settles cross-border supplier payments in under 30 seconds at sub-cent fees versus 2–4 days and $25–45 via SWIFT correspondent banking. - topic: stablecoins - pubDate: 2026-04-28 ### M-Pesa Interoperability in East Africa: What It Means for Payment Operators - url: https://paymentbrief.com/articles/mpesa-interoperability-east-africa/ - type: article - summary: M-Pesa spans 7 countries and 62M+ users (Safaricom Group, Sept 2025) but Kenya and Tanzania are different products with incompatible APIs — multi-country operators need Flutterwave or Cellulant as aggregators rather than direct per-market integrations. - topic: global-payments - pubDate: 2026-04-26 ### Stablecoin Compliance Stack: Travel Rule, Chain Analysis, Sanctions - url: https://paymentbrief.com/articles/stablecoin-compliance-stack-travel-rule-chain-analysis/ - type: article - summary: Stablecoin compliance requires Travel Rule messaging, wallet sanctions screening, and chain analysis — obligations that don't exist in traditional payments. What each covers, which tools to use, and how to handle flagged wallets. - topic: stablecoins - pubDate: 2026-04-26 ### Why You Still Need Rule Engines in 2026 - url: https://paymentbrief.com/articles/rule-engines-vs-ml-fraud-hybrid-architecture/ - type: article - summary: ML fraud models beat rules on aggregate metrics, but rules win on explainability, instant deployment for novel attacks, and sparse-data edge cases. Pure fraud detection is excluded from EU AI Act Annex III high-risk — hybrid waterfall stacks are the production standard. - topic: ai-and-automation - pubDate: 2026-04-25 ### Synthetic Identity Fraud: The Pattern Banks Miss and Operators Pay For - url: https://paymentbrief.com/articles/synthetic-identity-fraud-pattern/ - type: article - summary: Synthetic identity fraud combines real and fabricated credentials into fictitious persons who pass verification. The bust-out pattern looks clean until it doesn't. How the fraud works and the signals operators use to detect it. - topic: risk-and-compliance - pubDate: 2026-04-25 ### FX Markup Economics: How Cross-Currency Acceptance Quietly Eats Margin - url: https://paymentbrief.com/articles/fx-markup-cross-currency-acceptance/ - type: article - summary: FX markup on cross-currency transactions is embedded in the conversion rate, not shown as a fee. Often the largest variable cost for operators with international volume — how to measure, benchmark, and negotiate it. - topic: payments-economics - pubDate: 2026-04-24 - reviewedDate: 2026-08-26 ### India's RBI Card Tokenization Mandate: What Payment Operators Must Know - url: https://paymentbrief.com/articles/india-rbi-tokenization-mandate/ - type: article - summary: RBI banned raw card-on-file PAN storage from October 2022, mandating network tokenization across Visa, Mastercard, and RuPay. Covers the gaps operators still miss: guest checkout, token lifecycle, detokenisation limits, and failure handling for tokenised transactions. - topic: global-payments - keyFacts: - Detokenisation: Only the card network (TSP) can reverse a token to the PAN, and only at authorization/refund routing — the PA, gateway, and merchant never hold this capability - e-Mandate AFA threshold: Unchanged at ₹15,000 (₹1,00,000 for insurance/SIP/credit card bill categories) under the consolidated RBI/DPSS/2026-27/396 framework, 21 Apr 2026 - Token de-registration: Dual path — the merchant/TR must expose it, and separately the issuer must expose it via app/IVR/branch, independent of the merchant - Portability: Merchant CoF tokens are scoped to the token requestor ID, not just the MID — switching PA typically forces full re-registration, not a lighter migration - pubDate: 2026-04-23 - reviewedDate: 2026-08-21 ### MiCA, MAS, and the GENIUS Act: Stablecoin Regulatory Triangle - url: https://paymentbrief.com/articles/mica-mas-genius-stablecoin-regulatory-comparison/ - type: article - summary: MiCA, MAS, and GENIUS converge on 1:1 HQLA reserves and licensed issuance but diverge on issuer structure, reserve currency, and extraterritorial reach. Cross-border operators need issuer-by-jurisdiction compliance mapping, not categorical assumptions. - topic: stablecoins - pubDate: 2026-04-22 ### Authorization Optimization: The Hidden Margin in Card Acceptance - url: https://paymentbrief.com/articles/authorization-optimization-card-acceptance/ - type: article - summary: A 1% auth rate uplift on $1B GMV = $10M recovered. Key levers: network tokenization (+2.5% uplift), intelligent retry timing by decline code, BIN-level acquirer routing, and 3DS2 soft-decline recovery. Most merchants aren't pulling any of them. - topic: ai-and-automation - pubDate: 2026-04-21 ### How CBDC Pilots Are Reshaping Payment Infrastructure - url: https://paymentbrief.com/articles/cbdc-pilots-payment-infrastructure/ - type: article - summary: Wholesale CBDCs — not retail ones — are what payment operators should track now: mBridge reached MVP in June 2024 and enables atomic cross-border settlement between UAE, Hong Kong, Thailand, China, and Saudi Arabia without correspondent banks. - topic: global-payments - pubDate: 2026-04-21 ### Vietnam's Payment Rails: VietQR, NAPAS 247, and What Operators Need to Know - url: https://paymentbrief.com/articles/vietnam-vietqr-napas247-operator-guide/ - type: article - summary: NAPAS 247 processed 8.9 billion instant transfers in 2024 (+33.8% YoY); VietQR unified QR adoption across 40+ banks — but foreign operators still need SBV's payment intermediary license or a licensed local partner to access either rail. - topic: global-payments - pubDate: 2026-04-21 - reviewedDate: 2026-08-26 ### PromptPay and the Rise of Real-Time Rails Across Southeast Asia - url: https://paymentbrief.com/articles/promptpay-and-sea-realtime-payments/ - type: article - summary: PromptPay hit 77M+ registrations and 74M+ daily transactions by 2025 by combining zero-fee transfers, alias-based routing, and a single mandated QR standard — the design choices that Singapore, Malaysia, and Indonesia are now adapting. - topic: global-payments - pubDate: 2026-04-20 ### Sanctions Screening: OFAC, EU, and UN Lists and the Dynamic Risk Layer - url: https://paymentbrief.com/articles/sanctions-screening-payment-operators/ - type: article - summary: Sanctions violations are strict liability — no knowledge required. How the lists work, building a defensible screening programme, and what happens after a match: the US block-versus-reject decision and its OFAC reporting clocks, plus the separate UK asset-freeze duty. - topic: risk-and-compliance - pubDate: 2026-04-20 - reviewedDate: 2026-09-03 ### EU Instant Payments Regulation: The Compliance Timeline Every Operator Needs - url: https://paymentbrief.com/articles/eu-instant-payments-regulation-compliance/ - type: article - summary: EU IPR (2024/886) required euro PSPs to receive SCT Inst by January 2025 and send by October 2025, with pricing parity enforced and IBAN/name Verification of Payee mandatory — operators must collect payee name data and rebuild cost models. - topic: global-payments - keyFacts: - Regulation: Regulation (EU) 2024/886 — amends SEPA Credit Transfer rules; in force April 2024 - Eurozone receive deadline: 9 January 2025 — inbound SCT Inst mandatory - Eurozone send + pricing parity: 9 October 2025 — instant priced ≤ standard SCT - Non-euro EU deadlines: Receive 9 July 2027; send + parity 9 January 2028 - Verification of Payee: Mandatory from 9 October 2025 — IBAN/name match before send - UK scope: Out — IPR does not apply to UK-regulated entities post-Brexit - pubDate: 2026-04-19 - reviewedDate: 2026-06-14 ### Surcharging and Convenience Fees: Legal, Operational, Margin Reality - url: https://paymentbrief.com/articles/surcharging-convenience-fees-operator-guide/ - type: article - summary: Surcharging and convenience fees are legally and operationally distinct. Where each is permitted, the scheme rules you must follow, the consumer pushback risk, and when the margin math actually makes it worth implementing. - topic: payments-economics - pubDate: 2026-04-19 - reviewedDate: 2026-08-26 ### Tokenised Deposits vs Stablecoins: JPM Coin, Citi Token Services - url: https://paymentbrief.com/articles/tokenised-deposits-vs-stablecoins-jpm-coin-citi/ - type: article - summary: Tokenised deposits (JPM Coin, Citi Token Services) are bank money on chain — not stablecoins. The distinction carries different regulatory treatment, bankruptcy standing, and access. Most operators cannot use them directly. - topic: stablecoins - pubDate: 2026-04-19 ### Cross-Border B2B Accounts Receivable: The Infrastructure Problem - url: https://paymentbrief.com/articles/cross-border-b2b-ar-automation/ - type: article - summary: Cross-border B2B AR breaks at SWIFT correspondent chain delays (2–5 days), remittance memo truncation, and FX timing risk on open invoices — virtual IBANs per customer and local collection via Nium or Airwallex eliminate manual reconciliation and cut DSO by 5–10 days. - topic: global-payments - pubDate: 2026-04-16 ### Stablecoin On/Off-Ramp Operations: Where the Cost Advantage Gets Eaten - url: https://paymentbrief.com/articles/stablecoin-on-off-ramp-operations-cost-economics/ - type: article - summary: On-chain settlement costs cents. The on-ramp and off-ramp at each end charge 0.1–1.0% per conversion, take 1–2 business days, require KYB, and dominate the corridor economics. Where the ramps are cheap, stablecoin payments win. Where they are not, they don't. - topic: stablecoins - pubDate: 2026-04-16 ### First-Party Fraud: Friendly Fraud and the Largest Chargeback Category - url: https://paymentbrief.com/articles/first-party-fraud-friendly-fraud-chargebacks/ - type: article - summary: First-party fraud — chargebacks from real cardholders on genuine transactions — now outweighs third-party fraud for most e-commerce merchants. Why it's growing, how to build an evidence package, and when to fight versus accept. - topic: risk-and-compliance - keyFacts: - Definition: Legitimate cardholder disputes a transaction they authorised and received - Dispute volume share: Majority of dispute volume at most e-commerce merchants in developed markets - Fight threshold (economics): Disputes under $20–30 often cost more to contest than to accept - CE 3.0 defence mechanism: Two prior undisputed transactions from same device and IP shifts burden for 10.4 disputes - Highest-ROI prevention tactic: Pre-renewal email notifications with easy cancellation link (7 days before billing) - pubDate: 2026-04-15 ### What an Auth Rate Point Is Worth: Authorisation Optimisation Economics - url: https://paymentbrief.com/articles/auth-rate-point-economics/ - type: article - summary: A 1% auth rate improvement is a revenue number, not an engineering metric. How to calculate the value for your business, what drives soft versus hard declines, and which interventions move the rate at scale. - topic: payments-economics - pubDate: 2026-04-14 ### Embedded Finance and Payments: What Operators Actually Need to Build - url: https://paymentbrief.com/articles/embedded-finance-payments-operators/ - type: article - summary: Embedded finance requires five distinct infrastructure layers — sponsor bank, ledger, card issuing, KYB, and compliance — and conflating it with BaaS leads to misspecified architectures and regulatory failures. - topic: psp-and-infrastructure - pubDate: 2026-04-14 - reviewedDate: 2026-08-26 ### InstaPay and PESONet: The Philippines' Dual Real-Time Rail Architecture - url: https://paymentbrief.com/articles/philippines-instapay-pesonet-rails/ - type: article - summary: InstaPay processes real-time 24/7 transfers up to PHP 50,000 while PESONet handles high-value batch clearing — both operated by BancNet under BSP mandate — and GCash/Maya sit on top of these rails serving 90M+ registered users between them. - topic: global-payments - pubDate: 2026-04-14 - reviewedDate: 2026-08-27 ### 3DS2 and the Authentication Tax: What Operators Are Actually Paying - url: https://paymentbrief.com/articles/3ds2-and-the-authentication-tax/ - type: article - summary: 3DS2 shifts fraud liability from merchants to issuers via frictionless and challenge flows, but every issuer-triggered challenge costs conversion — operators on PSD2 SCA exemptions routinely gain 15–20 points of frictionless rate. - topic: risk-and-compliance - pubDate: 2026-04-12 - reviewedDate: 2026-08-31 ### Card Scheme Fees Demystified: What's Inside the MDR - url: https://paymentbrief.com/articles/card-scheme-fees-demystified/ - type: article - summary: Card MDR stacks interchange, scheme fees (30+ line items; UK PSR found over 30% real-terms growth, 2017/18–2021/22), and acquirer margin — scheme fees are the fastest-growing, least-transparent layer, but LCR, surcharging, and interchange-plus pricing cut real cost. - topic: payments-economics - pubDate: 2026-04-12 - reviewedDate: 2026-08-26 ### Stablecoin Treasury Operations: Custody, Keys, and Multisig - url: https://paymentbrief.com/articles/stablecoin-treasury-operations-custody-keys-multisig/ - type: article - summary: Stablecoin treasury requires custody, key management, and security decisions that traditional treasury doesn't. Self-custody vs custodial, multi-sig vs MPC, hot/cold tiering, and operator segregation of duties. - topic: stablecoins - pubDate: 2026-04-12 ### Why CoDi Failed and Pix Didn't: Lessons for New Rail Launches - url: https://paymentbrief.com/articles/codi-vs-pix-real-time-rail-lessons/ - type: article - summary: Pix hit 112M users in 12 months; CoDi reached 4M in 5 years. Same mandate, opposite outcomes. The delta: zero merchant fees, phone-number aliases, enforced bank UX quality, and P2P-first sequencing — all design choices, none accidents. - topic: global-payments - pubDate: 2026-04-10 - reviewedDate: 2026-09-12 ### Braintree vs Stripe: An Operator's Decision Framework - url: https://paymentbrief.com/articles/braintree-vs-stripe-operator-guide/ - type: article - summary: Braintree's PayPal network access and interchange-plus pricing win for high-volume US merchants; Stripe's Connect, Billing, Radar, and 46-country acquiring coverage win for marketplaces, SaaS platforms, and operators expanding globally. - topic: global-payments - pubDate: 2026-04-09 ### Card Testing and Enumeration Attacks: How to Detect and Stop Them - url: https://paymentbrief.com/articles/card-testing-enumeration-attacks/ - type: article - summary: Card testing attacks validate stolen card credentials against merchant payment endpoints. How the attack works, why merchants are targeted, what it costs, and the technical and operational defences that cut attack volume. - topic: risk-and-compliance - pubDate: 2026-04-09 ### Stablecoin Reserve Report Due Diligence: USDC, USDT, PYUSD, USDe - url: https://paymentbrief.com/articles/reading-stablecoin-reserve-reports-operator-due-diligence/ - type: article - summary: A stablecoin reserve attestation is not an audit. Read it for composition (HQLA vs commercial paper), custodian concentration, maturity profile, off-balance-sheet exposure, and timing — five lenses that separate documented backing from marketing copy. - topic: stablecoins - pubDate: 2026-04-09 ### Japan Payment Landscape: JCB, PayPay, and the Cash-Heavy Market Guide - url: https://paymentbrief.com/articles/japan-payment-landscape-jcb-paypay/ - type: article - summary: Japan's cashless ratio hit 42.8% in 2024 — PayPay has 75M registered users (Aug 2026), JCB's domestic share is undisclosed, and Zengin 24/7 underpins bank transfers; operators without JCB acquiring and PayPay acceptance exclude a large share of Japanese payment volume. - topic: global-payments - pubDate: 2026-04-08 - reviewedDate: 2026-08-25 ### Working Capital Cost of Payments: Reserves, Settlement Timing, Float - url: https://paymentbrief.com/articles/working-capital-cost-of-payments/ - type: article - summary: Rolling reserves and settlement timing lock up working capital without appearing on the processing statement. How to calculate the real cost, what drives reserve size, and the contract terms that move it. - topic: payments-economics - pubDate: 2026-04-08 ### Chargeback Representment: Why Merchants Lose Money They Could Recover - url: https://paymentbrief.com/articles/chargeback-representment-merchants/ - type: article - summary: Manual representment wins 20–40% of contested chargebacks; automated platforms report 65–80%. Visa's VCR window is 30 days network-wide, but acquirers like Adyen enforce 9 days (US/Canada) or 18 days (elsewhere) since July 2025 — check your actual deadline. - topic: risk-and-compliance - keyFacts: - Manual representment win rate: 20–40% of contested cases - Automated/AI-assisted representment win rate: 65–80% on targeted disputes - Visa VCR merchant response window (network rule): 30 days — Allocation and Collaboration workflows - Visa response window in practice (Adyen, since July 21, 2025): 9 days (US/Canada), 18 days (other regions) — acquirer-imposed, tighter than the 30-day network rule - Mastercard Mastercom response window: 45 days — all categories - Visa CE 3.0 auto-qualification: Automatic since October 17, 2025 for Visa Secure/Visa Data Only merchants; qualification fee added April 17, 2026 - Visa arbitration filing fee: USD 600 (raised from USD 500 on April 1, 2025), charged to the losing party - pubDate: 2026-04-07 - reviewedDate: 2026-08-22 ### USDC vs USDT vs PYUSD vs USDe: The Operator's Issuer Comparison - url: https://paymentbrief.com/articles/usdc-usdt-pyusd-usde-stablecoin-issuer-comparison/ - type: article - summary: USDC, USDT, PYUSD, and USDe have different reserve backing, regulatory standing, and redemption mechanics. Side-by-side comparison for operators choosing which stablecoin to accept, hold, or settle with. - topic: stablecoins - pubDate: 2026-04-05 ### Cross-Border B2B Payments: What's Still Broken and What's Fixing It - url: https://paymentbrief.com/articles/why-cross-border-b2b-payments-are-broken/ - type: article - summary: Cross-border B2B payments under $5M still take 2–3 days and cost 1.5–3% in FX spread because correspondent banking chains, de-risking-driven hop increases, and unstructured MT messaging are structural problems — not legacy oversights. - topic: payments-economics - pubDate: 2026-04-05 ### The Card Acquiring Margin Compression Trap - url: https://paymentbrief.com/articles/card-acquiring-margin-compression/ - type: article - summary: Acquiring margins are compressed from both sides: interchange caps trend down, scheme fees trend up, and real-time rails take volume at zero MDR. Stripe and Adyen pivoted to software; FIS and WorldPay face a structural problem acquisitions can't fix. - topic: psp-and-infrastructure - pubDate: 2026-04-04 - reviewedDate: 2026-08-26 ### VAMP: Visa Acquirer Monitoring That Replaced VDMP and VFMP - url: https://paymentbrief.com/articles/vamp-visa-acquirer-monitoring-programme/ - type: article - summary: Visa consolidated VDMP and VFMP into a single programme — VAMP — in April 2025: a unified ratio of fraud (TC40) plus disputes (TC15) over settled transactions, with separate enumeration tracking. What changed, how enforcement works, and how merchants respond. - topic: risk-and-compliance - keyFacts: - Programmes replaced: VDMP (chargeback) + VFMP (fraud) — consolidated April 2025 - VAMP ratio formula: Count of Fraud (TC40) + Disputes (TC15) ÷ Settled Transactions (TC05) - Acquirer threshold: Above Standard: ≥50 bps (0.50%) - Acquirer threshold: Excessive: ≥70 bps (0.70%) - Merchant excessive threshold (AP/Canada/EU/US): ≥150 bps since 1 April 2026 (previously ≥220 bps) - Enumeration tracking: Separate enumeration ratio — not included in core VAMP ratio - pubDate: 2026-04-03 - reviewedDate: 2026-08-21 ### The GENIUS Act: What US Federal Stablecoin Law Means for Operators - url: https://paymentbrief.com/articles/genius-act-us-stablecoin-law-operator-implications/ - type: article - summary: The GENIUS Act created the first US federal licensing regime for payment stablecoins — 1:1 reserves in HQLA, monthly attestations, OCC or Fed oversight. USDC and PYUSD already comply; algorithmic stablecoins are prohibited from claiming payment status. - topic: stablecoins - pubDate: 2026-04-02 ### Interchange-Plus vs Blended Pricing: When Each Wins and What You Pay - url: https://paymentbrief.com/articles/interchange-plus-vs-blended-pricing/ - type: article - summary: Blended pricing bundles interchange, scheme fees, and acquirer margin into one rate — hiding what's negotiable. IC+ makes each layer visible. How to calculate which model you're better on, and when to push for IC+. - topic: payments-economics - pubDate: 2026-04-02 - reviewedDate: 2026-08-26 ### GrabPay, OVO, and Dana: The Wallet Wars in Southeast Asia Payments - url: https://paymentbrief.com/articles/grabpay-ovo-dana-sea-wallet-wars/ - type: article - summary: Southeast Asia's digital wallet market has no single regional winner — GrabPay, OVO, Dana, and ShopeePay each dominate different countries under different regulatory regimes, making multi-market acceptance a country-by-country problem. - topic: global-payments - pubDate: 2026-03-31 - reviewedDate: 2026-09-11 ### PSP Vendor Lock-In: The Hidden Cost of Easy Onboarding - url: https://paymentbrief.com/articles/psp-vendor-lock-in-hidden-costs/ - type: article - summary: PSP switching costs accumulate invisibly after onboarding. Token non-portability is the biggest lock-in vector — followed by settlement format dependence, dispute history gaps, and termination penalties. Negotiate network token portability and data export rights at signing. - topic: psp-and-infrastructure - pubDate: 2026-03-28 ### India's UPI at Scale: Infrastructure Realities for Payment Operators - url: https://paymentbrief.com/articles/india-upi-infrastructure-payment-operators/ - type: article - summary: UPI processed 24,162 crore transactions worth ₹314.23 lakh crore (~$3.7T) in FY26, with July 2026 setting a fresh monthly record. A new law now lets Delhi impose MDR on UPI/RuPay by notification, the TPAP cap deadline has moved to Dec 2026, and UPI now reaches 10 countries. - topic: global-payments - pubDate: 2026-03-24 - reviewedDate: 2026-08-22 ### Grab's Financial Services: Margin Is in the Wallet, Not the Ride - url: https://paymentbrief.com/articles/grab-financial-services-super-app-strategy/ - type: article - summary: Grab's financial services segment grew 44% in 2024 to $253M — the GXS and GXBank digital banking licenses (combined $1.2B deposits by end-2024) are the structural unlock that makes the unit economics work at scale. - topic: global-payments - pubDate: 2026-03-18 ### Stablecoins for B2B Settlement: Where They Actually Work - url: https://paymentbrief.com/articles/stablecoin-b2b-settlement-corridors/ - type: article - summary: Stablecoin B2B settlement works in corridors where SWIFT is expensive and slow — US→Mexico, UAE→South Asia, US→LatAm. Settlement is solved; the off-ramp to local fiat is the bottleneck. USDC wins on enterprise compliance; USDT dominates emerging market liquidity. - topic: stablecoins - pubDate: 2026-03-14 - reviewedDate: 2026-06-14 ### PSP Negotiation Playbook: Getting Better Rates After Year One - url: https://paymentbrief.com/articles/psp-negotiation-playbook/ - type: article - summary: PSP rates are negotiable at renewal — merchants processing $1M+ annually should push for interchange-plus pricing, know their own interchange floor, and arrive with a credible competitive quote. - topic: payments-economics - keyFacts: - Renegotiation timing: Open renegotiation well before contract expiry, while switching leverage is still credible. - IC+ pricing benchmark: No published margin-by-volume benchmark exists; insist on a line-item breakdown and benchmark against a real competitive quote instead. - Rolling reserve clause: Review holdback percentage, release timing, rolling basis, and release triggers. - Fee-change clause: Fee-change clauses should define notice period, a materiality threshold, and post-effective-date-only scope. - Leverage trigger: Tie concessions to volume growth, a clean chargeback ratio, and a credible alternative processor. - pubDate: 2026-03-11 - reviewedDate: 2026-08-26 ### USDC vs USDT for Business Treasury: A Corporate Decision Framework - url: https://paymentbrief.com/articles/usdc-vs-usdt-for-business-treasury/ - type: article - summary: USDC offers monthly audited reserves and MiCA/MAS regulatory alignment; USDT has superior liquidity depth in emerging markets — the right choice depends on whether your treasury function needs documented compliance or offshore market access. - topic: stablecoins - pubDate: 2026-03-10 - reviewedDate: 2026-06-14 ### US-Mexico Remittance Corridor: Infrastructure, Cost, and Fintech - url: https://paymentbrief.com/articles/us-mexico-remittance-corridor/ - type: article - summary: The US-Mexico corridor moved $64.7 billion in 2024 — the world's largest remittance flow — yet average transfer fees remain near 5% because licensing complexity, SPEI access constraints, and cash-pickup networks sustain incumbent margins. - topic: global-payments - pubDate: 2026-03-07 - reviewedDate: 2026-06-14 ### SWIFT gpi vs Local Rail Interconnects: The Right Cross-Border Stack - url: https://paymentbrief.com/articles/swift-gpi-vs-local-rails/ - type: article - summary: SWIFT gpi improved correspondent banking speed and transparency but left FX spreads untouched — bilateral real-time rail links like the Singapore-Thailand QR interop bypass correspondents entirely and settle in seconds. - topic: psp-and-infrastructure - pubDate: 2026-02-28 ### KYB vs KYC: Why Business Verification Differs for Payment Operators - url: https://paymentbrief.com/articles/kyb-vs-kyc-risk-frameworks/ - type: article - summary: KYB is structurally harder than KYC because beneficial ownership structures involve nested legal entities, offshore vehicles, and PEP screening across the full UBO tree — not just a name and ID number check. - topic: risk-and-compliance - pubDate: 2026-02-15 - reviewedDate: 2026-08-26 ### Brazil's PIX: What Payment Operators Entering LatAm Must Understand - url: https://paymentbrief.com/articles/brazil-pix-payment-operators/ - type: article - summary: PIX is Brazil's mandatory instant payment rail approaching 8 billion monthly transactions — zero MDR for merchants, immediate settlement, and near-universal bank coverage make it the baseline for any LatAm payments stack. - topic: global-payments - pubDate: 2025-11-14 - reviewedDate: 2026-06-11 ### Open Banking Payments: What's Actually Shipping in 2026 - url: https://paymentbrief.com/articles/open-banking-payments-real-adoption-2026/ - type: article - summary: Open banking payment initiation is shipping in specific use cases — UK utility bill pay and top-ups, EU variable recurring payments, Australia CDR action initiation — but is not displacing card checkout at scale. The conversion and UX friction gap remains real. - topic: global-payments - pubDate: 2025-11-01 - reviewedDate: 2026-06-11 ### Klarna's IPO and the BNPL Unit Economics Problem - url: https://paymentbrief.com/articles/klarna-ipo-bnpl-unit-economics/ - type: article - summary: Klarna's F-1 (Sep 2025 NYSE IPO) shows $112B GMV, 0.52% credit loss rate, 790K merchants, 111M users — a profitable but margin-thin business with high credit loss sensitivity and rising AU/UK/US regulatory compliance costs. - topic: payments-economics - pubDate: 2025-09-10 - reviewedDate: 2026-06-14 ## Glossary index Term · URL · definition. - [3DS2](https://paymentbrief.com/glossary/3ds2/): 3DS2 is the authentication protocol for card-not-present transactions that shifts fraud chargeback liability from merchant to issuer when authentication succeeds. - [Account Takeover (ATO)](https://paymentbrief.com/glossary/ato/): Account takeover is fraud where an attacker gains control of a legitimate customer account and exploits the stored payment credentials or account value within it. - [Account Updater](https://paymentbrief.com/glossary/account-updater/): Account Updater (Visa VAU / Mastercard ABU) automatically refreshes stored card credentials when a card is reissued, preventing subscription declines from outdated card details. - [ACH](https://paymentbrief.com/glossary/ach/): ACH is the US interbank network for batch bank transfers — ACH debit is the pull payment mechanism for US bank-account recurring billing, governed by Nacha's Operating Rules. - [Acquirer](https://paymentbrief.com/glossary/acquirer/): The acquirer is the bank or PSP that processes card payments on behalf of merchants and holds the relationship with card networks. - [Anti-Money Laundering (AML)](https://paymentbrief.com/glossary/aml/): AML is the legal framework requiring payment businesses to detect, monitor, and report transactions that may represent money laundering or financial crime. - [Authorization](https://paymentbrief.com/glossary/authorization/): Authorization is the real-time request sent to the card issuer to verify funds availability and approve a transaction before capture. - [Authorization Rate](https://paymentbrief.com/glossary/authorization-rate/): Authorization rate is the share of payment attempts approved by the issuing bank — the primary metric for payment stack performance. - [Authorization Reversal](https://paymentbrief.com/glossary/auth-reversal/): Cancels an authorization hold before capture, releasing the held funds — distinct from a refund (which returns captured funds) and overlapping with a void. - [Bacs Direct Debit](https://paymentbrief.com/glossary/bacs/): Bacs Direct Debit is the dominant UK bank-account pull payment mechanism — a mandate-based recurring collection scheme governed by Pay.UK with a fixed three-day settlement cycle. - [BIN](https://paymentbrief.com/glossary/bin/): A BIN is the first 6–8 digits of a payment card number, identifying the issuing bank, card network, card type, and country of issue. - [BNPL](https://paymentbrief.com/glossary/bnpl/): BNPL is a point-of-sale installment credit product — typically 3–6 payments — offering deferred payment with no interest if paid on time. - [Capture](https://paymentbrief.com/glossary/capture/): Capture is the instruction to collect funds from a previously authorised transaction, triggering clearing and settlement. - [Card on File](https://paymentbrief.com/glossary/card-on-file/): Card on file is stored card credential (tokenised or vaulted) used for future transactions without re-entry — the foundation of subscriptions, one-click checkout, and MIT billing. - [Card Scheme](https://paymentbrief.com/glossary/card-scheme/): A card scheme is an organization such as Visa or Mastercard that sets the rules, interchange rates, and technical standards governing card payments globally. - [Card Testing](https://paymentbrief.com/glossary/card-testing/): Card testing is a fraud attack using automated scripts to validate stolen card numbers via small test transactions before exploiting them for larger fraud. - [Card-Not-Present (CNP)](https://paymentbrief.com/glossary/cnp/): CNP (Card Not Present) describes transactions — primarily e-commerce — where the physical card is absent, carrying higher fraud rates and interchange than card-present. - [CBPR+](https://paymentbrief.com/glossary/cbpr-plus/): CBPR+ is SWIFT's ISO 20022 usage guideline set for cross-border payments on the SWIFT network — narrowing the standard to an interoperable profile; MT coexistence ended 22 November 2025. - [Chain Analysis](https://paymentbrief.com/glossary/chain-analysis/): Chain analysis is the forensic tracing and risk-scoring of blockchain transactions using graph analysis and address clustering to identify entities and flag illicit fund flows. - [Chargeback](https://paymentbrief.com/glossary/chargeback/): A chargeback is a forced transaction reversal initiated by the card issuer on a cardholder's behalf, debiting the merchant and returning funds. - [Chargeback Ratio](https://paymentbrief.com/glossary/chargeback-ratio/): Chargeback ratio is chargebacks received as a percentage of total transactions, with scheme thresholds typically at 0.65–1.0% before fines and monitoring programmes trigger. - [Chargeback Representment](https://paymentbrief.com/glossary/chargeback-representment/): Chargeback representment is a merchant's formal dispute of a chargeback, submitted via the acquirer with transaction evidence to reverse the card network's initial ruling. - [Compelling Evidence 3.0 (CE 3.0)](https://paymentbrief.com/glossary/compelling-evidence-3/): CE 3.0 is Visa's 2023 framework letting merchants defeat first-party fraud chargebacks by proving a prior undisputed transaction history with the same device or IP. - [Confirmation of Payee (CoP)](https://paymentbrief.com/glossary/confirmation-of-payee/): CoP is the UK's Pay.UK name-check on Faster Payments and CHAPS — Match, Close Match, No Match, or Unavailable — covering ~99% of volume since October 2024 and feeding the APP-fraud liability framework. - [Connected Account](https://paymentbrief.com/glossary/connected-account/): A seller account a platform creates and manages inside its payment provider to receive funds and be paid out. - [Correspondent Banking](https://paymentbrief.com/glossary/correspondent-banking/): Correspondent banking is an arrangement where one bank holds accounts for another to execute cross-border payments in markets or currencies it doesn't directly access. - [Cross-Border Payments](https://paymentbrief.com/glossary/cross-border-payments/): Cross-border payments are transactions between parties in different countries, involving currency conversion, correspondent banking, and additional compliance overhead. - [CVV / CVC](https://paymentbrief.com/glossary/cvv/): CVV/CVC is the 3–4 digit security code on a payment card used to verify physical card possession in CNP transactions — prohibited from storage under PCI DSS. - [Decline Codes](https://paymentbrief.com/glossary/decline-codes/): Decline codes are the issuer's response codes indicating why a transaction was rejected and whether a retry is appropriate — meaning varies by network, and some are deliberate catch-alls. - [Digital Wallet](https://paymentbrief.com/glossary/digital-wallet/): A digital wallet stores tokenized payment credentials for card or account-based transactions, eliminating the need to present a physical card or enter card details manually. - [Direct Debit](https://paymentbrief.com/glossary/direct-debit/): Direct debit is a pull payment where the operator initiates a bank account debit against a pre-authorized mandate, without requiring customer action per collection. - [Dispute](https://paymentbrief.com/glossary/dispute/): A dispute is a cardholder's challenge to a transaction with their issuer, which escalates to a chargeback if the merchant doesn't respond or loses the review. - [Dynamic Currency Conversion (DCC)](https://paymentbrief.com/glossary/dcc/): DCC lets cardholders pay in their home currency at point of sale, with conversion applied by the acquirer at a marked-up rate that generates a rebate to the merchant. - [e-Mandate](https://paymentbrief.com/glossary/e-mandate/): An e-mandate is a digital standing authorization from a payer allowing a merchant or biller to initiate recurring direct debit collections from their bank account. - [eGIRO](https://paymentbrief.com/glossary/egiro/): eGIRO is Singapore's API-based digital mandate system for recurring SGD bank account debits — the modern replacement for paper GIRO forms, live since 2021. - [Embedded Finance](https://paymentbrief.com/glossary/embedded-finance/): Embedded finance is the integration of financial products (payments, lending, insurance) directly into non-financial platforms via BaaS and payment facilitator infrastructure. - [EMV](https://paymentbrief.com/glossary/emv/): EMV is the global chip card standard that generates a unique cryptographic code per transaction, making card cloning at point of sale effectively impossible. - [FATF Travel Rule](https://paymentbrief.com/glossary/travel-rule/): The FATF Travel Rule requires VASPs to transmit originator and beneficiary identity data alongside virtual asset transfers above defined thresholds. - [Friendly Fraud](https://paymentbrief.com/glossary/friendly-fraud/): Friendly fraud is when a cardholder disputes a legitimate transaction they made and received, either deliberately or because they didn't recognise the charge. - [FX Markup](https://paymentbrief.com/glossary/fx-markup/): FX markup is the margin a PSP charges above the interbank exchange rate when converting currencies in cross-border transactions, on top of any stated FX fee. - [IBAN](https://paymentbrief.com/glossary/iban/): An IBAN is a standardized account identifier used across Europe and parts of APAC to route bank transfers precisely and reduce payment failures. - [Incremental Authorization](https://paymentbrief.com/glossary/incremental-authorization/): Increases an existing authorization hold without a new authorization, for cases where the final amount grows after the initial auth (hotels, rideshare, tabs, fuel). - [Interchange](https://paymentbrief.com/glossary/interchange/): Interchange is the per-transaction fee paid by the acquirer to the card issuer, set by card networks and the largest single component of MDR. - [Interchange-Plus Pricing](https://paymentbrief.com/glossary/interchange-plus/): Interchange-plus pricing passes interchange and scheme fees through at cost with a transparent, fixed acquirer margin on top, making total card acceptance costs variable but itemised. - [ISO 20022](https://paymentbrief.com/glossary/iso-20022/): ISO 20022 is the XML-based international financial messaging standard used by SWIFT, SEPA, and modern payment rails — replacing legacy MT formats with structured, rich data that survives every hop. - [Issuer](https://paymentbrief.com/glossary/issuer/): The issuer is the bank or financial institution that provides a payment card to a consumer and is responsible for authorization and fraud liability. - [Know Your Business (KYB)](https://paymentbrief.com/glossary/kyb/): KYB is the regulatory due diligence process payment providers use to verify a merchant's identity, ownership structure, and business legitimacy before onboarding. - [Know Your Customer (KYC)](https://paymentbrief.com/glossary/kyc/): KYC is the regulatory requirement for payment businesses to verify the identity of individuals before providing financial services or processing payments. - [Least-Cost Routing](https://paymentbrief.com/glossary/least-cost-routing/): Least-cost routing automatically selects the lowest-cost network path for debit transactions — typically routing via a domestic network instead of Visa or Mastercard. - [Markets in Crypto-Assets (MiCA)](https://paymentbrief.com/glossary/mica/): MiCA is the EU's regulatory framework for crypto-asset issuers and service providers — operators must check stablecoin authorisation status before offering it to EU users. - [Master Merchant Account](https://paymentbrief.com/glossary/master-merchant-account/): The acquiring account a payment facilitator holds and boards its sub-merchants under, through which all their transactions flow. - [MDR](https://paymentbrief.com/glossary/mdr/): MDR is the total percentage fee a merchant pays per card transaction, comprising interchange paid to the issuer, scheme fees, and the acquirer's margin. - [Merchant Category Code (MCC)](https://paymentbrief.com/glossary/mcc/): An MCC is a four-digit code assigned by card networks to classify a merchant's business type, directly determining interchange rates and card acceptance rules. - [Merchant of Record](https://paymentbrief.com/glossary/merchant-of-record/): A Merchant of Record is the entity legally responsible for a sale — owning tax collection, refund liability, compliance, and the card network relationship. - [Merchant-Initiated Transaction (MIT)](https://paymentbrief.com/glossary/mit/): A Merchant-Initiated Transaction is a charge triggered by the merchant against stored card credentials without the cardholder present — used for subscriptions, instalments, and usage billing. - [MPC (Multi-Party Computation)](https://paymentbrief.com/glossary/mpc/): MPC splits a private key into distributed shares that sign transactions cooperatively, so the full key is never assembled in any single location. - [Multi-Signature (Multi-Sig)](https://paymentbrief.com/glossary/multi-sig/): Multi-sig requires M of N designated key-holders to sign a transaction on-chain before it executes, enforced by smart contract logic. - [Netting](https://paymentbrief.com/glossary/netting/): Netting consolidates multiple payment obligations between counterparties into a single net amount, reducing settlement volume and liquidity requirements. - [Network Token](https://paymentbrief.com/glossary/network-token/): A network token is a payment credential issued by Visa or Mastercard that replaces the card number for storage and transactions, reducing fraud exposure. - [OFAC SDN List](https://paymentbrief.com/glossary/sdn-list/): The OFAC SDN List is the US Treasury sanctions list of blocked persons and entities, including crypto wallet addresses, against which US persons cannot transact. - [Open Banking](https://paymentbrief.com/glossary/open-banking/): Open banking is a regulatory framework requiring banks to share customer account data and payment initiation access with licensed third parties via secure APIs. - [PAN (Primary Account Number)](https://paymentbrief.com/glossary/pan/): A PAN is the full card number on a payment card — classified as sensitive data under PCI DSS and replaced by tokens in most modern payment flows. - [Partial Authorization](https://paymentbrief.com/glossary/partial-authorization/): A partial authorization is an issuer approval for less than the requested transaction amount — common on prepaid cards and requiring split tender or decline handling. - [Payment Facilitator](https://paymentbrief.com/glossary/payment-facilitator/): A payment facilitator aggregates sub-merchants under its own acquiring agreement, handling onboarding, risk management, and settlement on their behalf. - [Payment Gateway](https://paymentbrief.com/glossary/payment-gateway/): A payment gateway is the technology layer that encrypts and routes card transaction data between a merchant's checkout and the acquiring bank or PSP. - [Payment Orchestration](https://paymentbrief.com/glossary/payment-orchestration/): Payment orchestration intelligently routes transactions across multiple PSPs, acquirers, and payment methods to optimize authorization rates and reduce acceptance cost. - [PCI DSS](https://paymentbrief.com/glossary/pci-dss/): PCI DSS is the card-industry security standard mandating specific controls for any entity that stores, processes, or transmits cardholder data. - [Pix Automático](https://paymentbrief.com/glossary/pix-automatico/): Pix Automático is Brazil's bank-native recurring debit feature on the Pix rail — enabling scheduled pulls from customer accounts with near-zero MDR and no card expiry risk. - [Pre-Authorization](https://paymentbrief.com/glossary/pre-authorization/): A pre-authorization is a temporary hold placed on cardholder funds before the final transaction amount is confirmed, common in hotels, car rentals, and fuel. - [PSD2](https://paymentbrief.com/glossary/psd2/): PSD2 is the EU directive that mandates Strong Customer Authentication for online payments and requires banks to grant API access to licensed third-party providers. - [PSD3](https://paymentbrief.com/glossary/psd3/): PSD3 is the EU's update to PSD2, sharpening open banking, adjusting SCA rules, and improving non-bank payment access — provisionally agreed in late 2025 and not yet in force, with application expected around 2028. - [PSP](https://paymentbrief.com/glossary/psp/): A PSP is a company that provides merchants with the technology and banking connections needed to accept electronic payments across cards, wallets, and bank transfers. - [Qualified Custodian](https://paymentbrief.com/glossary/qualified-custodian/): A qualified custodian is a regulated entity authorised to hold digital assets on behalf of clients, subject to capital, segregation, and oversight requirements. - [Real-Time Rail](https://paymentbrief.com/glossary/real-time-rail/): A real-time rail is a national payment infrastructure settling bank transfers instantly and 24/7 — such as UPI in India, PIX in Brazil, or Faster Payments in the UK. - [Reconciliation](https://paymentbrief.com/glossary/reconciliation/): Reconciliation is the process of matching payment records across a merchant's internal systems, PSP statements, and bank settlements to identify and resolve discrepancies. - [Recurring Payment](https://paymentbrief.com/glossary/recurring-payment/): A recurring payment is a pre-authorised repeating charge against a stored payment credential, with operational mechanics that differ significantly between card and bank rails. - [Rolling Reserve](https://paymentbrief.com/glossary/rolling-reserve/): A rolling reserve is a percentage of merchant settlements withheld by a PSP for a defined period as a buffer against chargebacks and financial exposure. - [Scheme Fees](https://paymentbrief.com/glossary/scheme-fees/): Scheme fees are charges levied by card networks (Visa, Mastercard) on acquirers and issuers for network access, typically 0.10–0.25% of transaction value. - [SEPA](https://paymentbrief.com/glossary/sepa/): SEPA is the EU's unified payment infrastructure covering 36 countries — standardising euro bank transfers via Credit Transfer, Instant, and Direct Debit schemes. - [Settlement](https://paymentbrief.com/glossary/settlement/): Settlement is the transfer of transaction funds from the acquirer to the merchant's bank account, typically occurring 1–3 business days after capture. - [Soft Decline](https://paymentbrief.com/glossary/soft-decline/): A soft decline is an authorization failure where the issuer signals the transaction can be retried — typically due to insufficient funds, a temporary flag, or SCA required. - [Split Payment](https://paymentbrief.com/glossary/split-payment/): A single buyer payment divided across multiple recipients — platform and sellers — at settlement. - [Stablecoin](https://paymentbrief.com/glossary/stablecoin/): A stablecoin is a cryptocurrency pegged to a fiat currency — typically USD — designed to hold price stability, used increasingly for cross-border B2B settlement. - [Strong Customer Authentication (SCA)](https://paymentbrief.com/glossary/sca/): SCA is the EU regulatory requirement for two-factor authentication on electronic payments, implemented primarily via 3DS2 for card-not-present transactions. - [Sub-Merchant](https://paymentbrief.com/glossary/sub-merchant/): A business that accepts card payments under a payment facilitator's master merchant account instead of holding its own merchant account. - [Surcharging](https://paymentbrief.com/glossary/surcharging/): Surcharging is adding a fee to card transactions to recover acceptance costs, subject to card network rules and local regulations that vary significantly by market. - [Suspicious Activity Report (SAR)](https://paymentbrief.com/glossary/sar/): A SAR is a mandatory confidential regulatory filing submitted to a financial intelligence unit when suspicious transactions suggest money laundering or financial crime. - [SWIFT](https://paymentbrief.com/glossary/swift/): SWIFT is the global interbank messaging network used to transmit cross-border payment instructions — it moves messages, not money, across 11,000+ institutions in 200+ countries. - [Synthetic Identity Fraud](https://paymentbrief.com/glossary/synthetic-identity/): Synthetic identity fraud combines a real SSN with fabricated personal data to create a fictitious consumer identity used to bust out credit lines. - [Third-Party Provider (TPP)](https://paymentbrief.com/glossary/tpp/): A TPP is a licensed entity under PSD2 that accesses bank accounts via open banking APIs to initiate payments (PISP) or retrieve account information (AISP). - [Tokenised Deposit](https://paymentbrief.com/glossary/tokenised-deposit/): A tokenised deposit is a bank deposit represented as a blockchain token, issued directly by the chartered bank and retaining deposit insurance and regulatory protections. - [Tokenization](https://paymentbrief.com/glossary/tokenization/): Tokenization replaces sensitive card data with a non-sensitive token for storage and processing, reducing PCI DSS scope and limiting fraud from data breaches. - [UETR](https://paymentbrief.com/glossary/uetr/): UETR is the 36-character UUID set at payment origination and carried unchanged through every SWIFT correspondent hop — the single reference to quote when tracing a payment or raising a bank enquiry. - [UPI AutoPay](https://paymentbrief.com/glossary/upi-autopay/): UPI AutoPay is NPCI's mandate-based recurring debit framework for UPI — enabling scheduled collections from bank accounts without per-transaction authentication up to ₹15,000. - [VAMP (Visa Acquirer Monitoring Programme)](https://paymentbrief.com/glossary/vamp/): VAMP is Visa's April 2025 unified acquirer monitoring framework that consolidates dispute and fraud ratios into a single threshold metric managed at the acquirer level. - [Variable Recurring Payments (VRP)](https://paymentbrief.com/glossary/vrp/): VRP is the open banking mechanism for recurring pull payments — a customer-authorised standing consent allowing variable amount collections at near-zero MDR. - [Velocity Check](https://paymentbrief.com/glossary/velocity-check/): A velocity check is a fraud control that flags or blocks a card or account when transaction frequency or volume exceeds a defined threshold within a time window. - [Verification of Payee (VoP)](https://paymentbrief.com/glossary/verification-of-payee/): VoP is the EU's EPC scheme checking a payee's name against the IBAN before a SEPA credit transfer — Match, Close Match, No Match, or Verification Not Possible — mandatory in the euro area since 9 Oct 2025. - [Virtual IBAN](https://paymentbrief.com/glossary/virtual-iban/): A virtual IBAN is a unique account number mapped to a master account, used to reconcile incoming payments by giving each payer a dedicated reference. - [Void](https://paymentbrief.com/glossary/void/): A void cancels an authorized transaction before capture, releasing the hold without any funds movement — the correct alternative to a refund pre-settlement. ## Market guide index Market · URL · summary · real-time rail (where present). - [Côte d'Ivoire](https://paymentbrief.com/markets/cote-divoire/): Côte d'Ivoire is the WAEMU zone's largest economy and mobile-money-dominant. Wave entered at 0% P2P fees — undercutting Orange Money and MTN MoMo's 1–2% model — and passed 6M+ users by 2024. One BCEAO e-money licence covers eight countries, but per-country presence still applies. (real-time rail: Mobile money (Orange Money, MTN MoMo, Wave)) - [Egypt](https://paymentbrief.com/markets/egypt/): Egypt's payment stack centres on Meeza cards, the InstaPay instant rail and Fawry's agent network. Financial inclusion jumped from 27.4% in 2016 to 76.3% by June 2025, with Paymob and MNT-Halan rounding out a deep fintech base. (real-time rail: InstaPay (launched 2022)) - [Ethiopia](https://paymentbrief.com/markets/ethiopia/): Africa's second-largest population with the fastest mobile money ramp in history — Telebirr hit 40M users in two years, but ETB is not freely convertible. (real-time rail: Telebirr (telco-led) + EthSwitch (interbank)) - [Ghana](https://paymentbrief.com/markets/ghana/): Ghana is West Africa's clearest telco-led mobile money market: MTN MoMo holds ~73% of active accounts and Telecel Cash (ex-Vodafone Cash) ~23%, with mobile money dwarfing the bank rail. GhIPSS Instant Pay clears roughly one-seventh of MoMo volume. (real-time rail: MTN MoMo / Telecel Cash (telco-led) + GhIPSS Instant Pay (bank rail)) - [Kenya](https://paymentbrief.com/markets/kenya/): Kenya is the global proof point that telco-led mobile money can replace banking. M-Pesa has ~41 million active monthly customers — more than Safaricom's own mobile subscriber base. (real-time rail: M-Pesa (telco-led, dominant) + PesaLink (bank-to-bank, 2017)) - [Morocco](https://paymentbrief.com/markets/morocco/): Morocco's payments are unusually centralised: CMI, a 9-bank consortium, handles essentially all card transactions with mandatory 3D Secure. Virement Instantané (launched June 2023) settles in under 20 seconds, and m-wallets top 10M accounts — though cash still leads retail. (real-time rail: Virement Instantané (launched June 2023, GSIMT-operated, <20s)) - [Nigeria](https://paymentbrief.com/markets/nigeria/): Nigeria is Africa's largest economy and most dynamic fintech market. NIP processes 10B+ transactions annually. Flutterwave and Paystack power payments. (real-time rail: NIBSS Instant Payment (NIP)) - [Rwanda](https://paymentbrief.com/markets/rwanda/): ~90% mobile money penetration, the fastest PSP licensing in Africa (3–6 months), and KIFC positioning Rwanda as East Africa's financial hub. (real-time rail: MTN MoMo + RSwitch (national interbank switch)) - [Senegal](https://paymentbrief.com/markets/senegal/): Senegal is Wave's home market — Wave launched in Dakar in 2019 and reached 2M+ daily actives on 18M population. First oil production began March 2024. (real-time rail: Mobile money (Wave, Orange Money, Free Money)) - [South Africa](https://paymentbrief.com/markets/south-africa/): South Africa is sub-Saharan Africa's most-banked market — only 2% of adults are unbanked. PayShap launched March 2023 as the real-time A2A rail. (real-time rail: PayShap (launched March 2023)) - [Tanzania](https://paymentbrief.com/markets/tanzania/): Tanzania is East Africa's second-largest mobile money market after Kenya. 6.3 billion mobile money transactions in 2025 (+68.7% YoY); 76M+ active. (real-time rail: TIPS (Tanzania Instant Payment System, BoT) + mobile money networks) - [China](https://paymentbrief.com/markets/china/): China's payments are defined by the Alipay and WeChat Pay duopoly — roughly 95% of mobile payment volume — cleared through PBOC-mandated NetsUnion. Foreign operators face a binary: full PBOC Payment Business Licence and local entity, or arm's-length cross-border e-commerce. (real-time rail: CNAPS / NetsUnion) - [Hong Kong](https://paymentbrief.com/markets/hong-kong/): Hong Kong, a Special Administrative Region of the People's Republic of China, is Asia's most accessible payment market for foreign operators. FPS. (real-time rail: Faster Payment System (FPS)) - [Japan](https://paymentbrief.com/markets/japan/): Japan is the most counterintuitive developed payment market: cash still clears via konbini (~10% of purchases, ~55,000 stores 24/7), MDR runs a high 2–4%, and PayPay has 75M+ registered users. Card-only checkout leaves real conversion on the table here. (real-time rail: Zengin System) - [South Korea](https://paymentbrief.com/markets/south-korea/): South Korea has near-100% card penetration. KakaoPay and Naver Pay dominate simple-pay wallets as card-on-file overlays. Foreign operators must route domestic cards through a licensed local PG — direct foreign acquiring is not possible. (real-time rail: Interbank Transfer (KFTC)) - [Belgium](https://paymentbrief.com/markets/belgium/): Bancontact covers ~55% of Belgian card-based payments — the domestic debit scheme underpins both POS and QR checkout. Wero launched via ING Belgium in. (real-time rail: Payconiq by Bancontact (mobile A2A QR); SEPA Instant Credit Transfer) - [Denmark](https://paymentbrief.com/markets/denmark/): MobilePay reaches ~4.6M users in a 5.9M-person country. Dankort accounts for ~40% of all Danish payments, with Nets processing 75–80% of card. (real-time rail: MobilePay (P2P and merchant A2A); Straksoverførsel (instant credit transfer via Nets)) - [Finland](https://paymentbrief.com/markets/finland/): MobilePay passed 3M Finnish users in August 2026 — grown organically, not by acquiring Pivo, which the owner banks left out of the 2022 merger after EU competition concerns. Cards dominate: 947M POS transactions in H1 2024. (real-time rail: Siirto (Finnish instant P2P, managed by Siirto Brand Oy); SEPA SCT Inst (EU Instant Credit Transfer)) - [France](https://paymentbrief.com/markets/france/): France is Western Europe's 2nd-largest e-commerce market (€196B in 2025). Cartes Bancaires (CB) is co-badged on 95%+ of French cards and handles ~64%. (real-time rail: SCT Inst via Wero (e-commerce piloted from April 2026; general merchant availability targeted autumn 2026; POS not yet live)) - [Germany](https://paymentbrief.com/markets/germany/): A card-first checkout reaches only ~14% of German e-commerce. PayPal leads online at 28.7%, invoice and Lastschrift carry the rest, and girocard — not Visa or Mastercard — owns 40.5% of POS turnover. Getting Germany right means running three distinct payment stacks. (real-time rail: SCT Inst (SEPA Instant Credit Transfer), consumer-facing via Wero) - [Italy](https://paymentbrief.com/markets/italy/): Italy is the EU's 3rd-largest economy where cards lead by value but cash still leads point-of-sale by transaction count — Bancomat debit leads at 80% of everyday spending. Satispay and Bancomat Pay. (real-time rail: SCT Inst via Bancomat Pay + Satispay (consumer A2A)) - [Netherlands](https://paymentbrief.com/markets/netherlands/): iDEAL dominates Dutch online payments with ~60% share — a fixed-fee A2A rail now on open-banking infrastructure (iDEAL 2.0, 2023 rollout). Adyen is. (real-time rail: iDEAL 2.0 (open-banking A2A); SEPA Instant Credit Transfer) - [Norway](https://paymentbrief.com/markets/norway/): Vipps reaches ~4.6M users in a 5.5M-person country — near-saturation for adult mobile payment. BankAxept handled 1.5 billion card transactions in 2024. (real-time rail: Vipps (P2P and merchant A2A payments)) - [Poland](https://paymentbrief.com/markets/poland/): BLIK is one of EU's most successful A2A apps — 21.1M active users and 756M transactions in Q1 2026 alone. Distinctive 6-digit one-time code mechanic (no QR or alias). Owned by Polski Standard Płatności — Poland's major banks plus Mastercard. Largest unfilled CEE e-commerce market… (real-time rail: Express Elixir (KIR-operated) + BLIK (PSP-operated mobile layer)) - [Spain](https://paymentbrief.com/markets/spain/): Spain is Western Europe's 4th-largest e-commerce market. Bizum (30M+ users — nearly the entire adult banking population) processes 3.4M instant. (real-time rail: Bizum (SCT Inst-based; e-com mature, NFC at POS from 18 May 2026)) - [Sweden](https://paymentbrief.com/markets/sweden/): Swish reaches ~8.5M users in a 10.5M-person country, built on BankID digital identity and real-time bank rails since 2012. Sweden retains the SEK (not Eurozone). Klarna is Stockholm-headquartered. EU IFR applies to card interchange. Cards remain the dominant in-store method. (real-time rail: Swish (P2P and merchant); Bankgirot BiR (Betalningar i Realtid)) - [Switzerland](https://paymentbrief.com/markets/switzerland/): TWINT reaches ~6M users in Switzerland's 8.7M population — a bank-consortium A2A app approaching saturation. Switzerland is non-EU with its own SIC. (real-time rail: TWINT (A2A mobile payments); SIC (Swiss Interbank Clearing, CHF RTGS and instant)) - [United Kingdom](https://paymentbrief.com/markets/united-kingdom/): The UK is Europe's most sophisticated payment market. Faster Payments was the world's first real-time interbank rail. Open Banking under PSD2/PSR has. (real-time rail: Faster Payments) - [Argentina](https://paymentbrief.com/markets/argentina/): Argentina is Mercado Pago's home market — the wallet holds ~80% of digital wallet float. Transferencias 3.0 (BCRA) makes every QR code interoperable. (real-time rail: Transferencias 3.0 (universal QR interoperability via CVU/CBU)) - [Brazil](https://paymentbrief.com/markets/brazil/): Brazil pairs Pix — the world's fastest-adopted real-time rail, used by 148M+ people (about 86% of adults) — with parcelamento, the merchant-funded installment culture that is table stakes for checkout. An assertive BCB has banned stablecoin settlement for cross-border eFX from Oc… (real-time rail: Pix) - [Chile](https://paymentbrief.com/markets/chile/): Chile's 2020 reform ended Transbank's acquiring monopoly. In January 2026 a competition regulator confirmed Transbank had fallen below 50% of acquirer processing and released its tariffs from regulation. (real-time rail: Khipu (A2A) + interbank transfers via TEF (BancoEstado-anchored)) - [Colombia](https://paymentbrief.com/markets/colombia/): Colombia launched Bre-B — its central-bank-operated real-time payment system — in September 2025, with the BR absorbing institution fees for the first. (real-time rail: Bre-B (launched September 2025; BR-operated, alias-based)) - [Costa Rica](https://paymentbrief.com/markets/costa-rica/): Costa Rica is Central America's most banked market — SINPE Móvil, operated by the BCCR, covers ~60% of adults with free instant P2P payments. (real-time rail: SINPE Móvil (BCCR-operated, launched 2015)) - [Mexico](https://paymentbrief.com/markets/mexico/): Mexico has SPEI as its real-time rail and OXXO cash vouchers as a critical checkout method for its large unbanked population. The 2018 Fintech Law. (real-time rail: SPEI) - [Peru](https://paymentbrief.com/markets/peru/): Peru's Yape-Plin wallet duopoly handles roughly 88% of in-person wallet transactions, and cash fell from 40% to 18% of payments in five years. Operators integrate the two BCRP-interoperable wallets — not a single central rail — to reach the consumer payment layer. (real-time rail: Yape-Plin interoperability + BCRP CCE (Cámara de Compensación Electrónica)) - [Uruguay](https://paymentbrief.com/markets/uruguay/): Uruguay has South America's highest GDP per capita and banking penetration, and is home to dLocal — LatAm's most globally deployed payment aggregator. (real-time rail: SPI (Sistema de Pagos Instantáneo, BCU-operated)) - [Saudi Arabia](https://paymentbrief.com/markets/saudi-arabia/): Saudi Arabia's payment stack runs on SAMA-mandated mada cards, SARIE Instant transfers and Tabby/Tamara BNPL, a BNPL-dominant market outside Sweden. E-payment penetration hit 85% in 2025, years ahead of Vision 2030's 70% target. (real-time rail: SARIE Instant (2021 instant retail layer over 1997 SARIE RTGS)) - [Turkey](https://paymentbrief.com/markets/turkey/): Turkey is a mature card-dominant market — 120M+ debit and 59M+ credit cards, with Visa and Mastercard splitting ~96% of volume — layered over TCMB's FAST instant rail (3.5M+ payments/day) and TROY, BKM's lower-fee domestic card scheme. Installment cards shape checkout. (real-time rail: FAST (Fonların Anlık ve Sürekli Transferi, launched January 2021)) - [United Arab Emirates](https://paymentbrief.com/markets/uae/): The UAE is the Middle East's leading fintech hub. Aani launched as its real-time rail in 2023. DIFC and ADGM offer common-law entry routes for. (real-time rail: Aani) - [Canada](https://paymentbrief.com/markets/canada/): Canada's Real-Time Rail (RTR), originally planned for 2019, is now set by Payments Canada to launch in Q4 2026, with full initial-phase volumes targeted for Q3 2027. Interac e-Transfer (1.4B transactions in 2024) remains the dominant P2P method; Interac Debit dominates in-person… (real-time rail: Interac e-Transfer (proprietary); RTR (target launch Q4 2026; phased onboarding through 2027)) - [United States](https://paymentbrief.com/markets/united-states/): The United States runs the world's most complex card-dominated payment system. FedNow and RTP have launched real-time rails, but adoption remains under 5% of transaction volume. (real-time rail: FedNow / RTP) - [Australia](https://paymentbrief.com/markets/australia/): Australia has a mature, card-dominant market with NPP/PayID as its real-time rail. The birthplace of BNPL — Afterpay and Zip pioneered the category. (real-time rail: New Payments Platform (NPP) / PayID) - [Bangladesh](https://paymentbrief.com/markets/bangladesh/): Bangladesh runs one of Asia's largest Mobile Financial Services markets — 238.6M MFS accounts (Dec 2024), led by bKash, Nagad and Rocket — where MFS has displaced both cash and cards. From Nov 2024, NPSB enables bank-to-MFS interoperability, folding wallets into the banking rails… (real-time rail: NPSB (National Payment Switch Bangladesh) + MFS networks (bKash/Nagad/Rocket)) - [India](https://paymentbrief.com/markets/india/): UPI has made India the world's largest real-time payments market by volume, processing 21B+ monthly transactions as of late 2025. Zero MDR on UPI. (real-time rail: UPI) - [Pakistan](https://paymentbrief.com/markets/pakistan/): Pakistan's Raast — the SBP-operated instant payment rail launched in 2021 — has reached 48 million users in 2025, processing PKR 50 trillion across. (real-time rail: Raast (launched 2021)) - [Sri Lanka](https://paymentbrief.com/markets/sri-lanka/): LANKAQR (launched 2019) is the CBSL-mandated national QR interoperability standard; LankaPay underpins bank-transfer settlement. Economy recovering. (real-time rail: LANKAQR (QR interoperability); JustPay (CBSL common payment interface); LankaPay CEFTS (Credit Card and Electronic Fund Transfer Switch)) - [Indonesia](https://paymentbrief.com/markets/indonesia/): Indonesia is SEA's largest payments market — 277M people, e-wallet-led rather than card-led, on two mandatory pillars: BI's unified QRIS code and the BI-FAST real-time rail. Operators must integrate multiple wallets (GoPay, OVO, DANA, ShopeePay); no single one covers the market. (real-time rail: BI-FAST) - [Malaysia](https://paymentbrief.com/markets/malaysia/): Malaysia has one of SEA's most balanced payment mixes: DuitNow real-time rail with strong adoption, mature card infrastructure, and Touch 'n Go as the. (real-time rail: DuitNow) - [Philippines](https://paymentbrief.com/markets/philippines/): The Philippines is mobile-first to an extreme: GCash has reached ~40M monthly active users on a 115M population, effectively acting as banking infrastructure. InstaPay (real-time) and PESONet (batch) are the two BSP-mandated interbank rails governed by PPMI. (real-time rail: InstaPay) - [Singapore](https://paymentbrief.com/markets/singapore/): Singapore is Southeast Asia's most mature payments market: near-universal PayNow penetration, high card density, and a prescriptive but predictable MAS. (real-time rail: PayNow) - [Thailand](https://paymentbrief.com/markets/thailand/): PromptPay, Thailand's BOT-mandated real-time rail, carries near-zero merchant MDR and a unified Thai QR standard — letting operators cut card acceptance costs of 1.5–2.5%. TrueMoney leads a fragmented wallet market alongside Rabbit LINE Pay and ShopeePay. (real-time rail: PromptPay) - [Vietnam](https://paymentbrief.com/markets/vietnam/): Vietnam is one of SEA's fastest-growing digital payment markets. MoMo leads a fragmented e-wallet landscape. NAPAS 247 enables real-time interbank. (real-time rail: NAPAS 247) ## Tools index Free interactive operator tools. - [PaymentBrief Reason-Code Lookup](https://paymentbrief.com/tools/reason-codes/): Interactive Visa + Mastercard chargeback reason-code lookup — 22 active codes with triggers, evidence checklists, and response windows. - [Legacy Visa Reason Codes: 83, 76, 71 and 75](https://paymentbrief.com/tools/reason-codes/visa-legacy-codes/): Reference for retired pre-2018 Visa dispute codes 83, 76, 71, and 75 — current-code mapping (conditional where applicable) and disambiguation from unrelated authorization decline codes. - [SEPA Return & Reject Code Lookup](https://paymentbrief.com/tools/sepa-return-codes/): Interactive SEPA R-transaction reason-code lookup — 43 codes across SCT, SCT Inst, SDD Core, and SDD B2B with rulebook scope, who generates each code, and operator action. - [ACH Return Reason Code Lookup](https://paymentbrief.com/tools/ach-return-codes/): Interactive Nacha ACH return-code lookup — 71 codes (R01–R85 plus the 2028 R90) with Nacha's own definition and SEC scope from its public ISO 20022 mapping guide, the camt.053 reason-code mapping, and the return time frame and reinitiation position only where a public Nacha rule page states them. - [MT to ISO 20022 Message Equivalence Lookup](https://paymentbrief.com/tools/mt-iso-equivalence/): Bidirectional SWIFT MT to ISO 20022 equivalence lookup — pacs, camt, and pain messages, each carrying an honest equivalence tier (direct / close-functional / partial / workflow-replacement) rather than assuming a 1:1 CBPR+ mapping. - [Card Decline-Code Lookup](https://paymentbrief.com/tools/decline-codes/): Interactive lookup for 16 cross-source-corroborated card decline codes (04, 05, 07, 14, 41, 43, 51, 54, 57, 61, 62, 65, 75, 91, 96, 1A) — meaning, variability, retryability, and operator action, verified against Stripe, Adyen, and a dated processor ISO 8583 implementation. These are legacy/conventional codes, not the current ISO 8583:2023 standard. ## Topic index - [AI & Automation](https://paymentbrief.com/topics/ai-and-automation/): How AI and automation are reshaping payment operations — fraud detection, smart routing, reconciliation automation, agentic commerce, and AI-driven monitoring. - [Global Payments](https://paymentbrief.com/topics/global-payments/): Payment methods, rails, and global infrastructure — real-time networks, card schemes, e-wallets, BNPL, bank transfers, and the corridors connecting them. - [Payments Economics](https://paymentbrief.com/topics/payments-economics/): The commercial and cost architecture of payment acceptance — interchange, MDR, FX markup, rolling reserves, settlement fees, PSP pricing, and contract terms. - [PSP & Infrastructure](https://paymentbrief.com/topics/psp-and-infrastructure/): The plumbing of payments — PSPs, acquiring banks, payment gateways, orchestration layers, merchant-of-record platforms, and routing logic. - [Risk & Compliance](https://paymentbrief.com/topics/risk-and-compliance/): Fraud, disputes, chargebacks, and the regulatory frameworks governing payment operations — KYC, KYB, AML, PCI DSS, 3DS2, and compliance requirements. - [Stablecoins](https://paymentbrief.com/topics/stablecoins/): Stablecoins as payment rails for businesses — USDC and USDT as settlement infrastructure, merchant acceptance, B2B payouts, and treasury management. ## Reading list index - [Chargeback Operator Reading List](https://paymentbrief.com/lists/chargeback-operator/): A 7-article guide to the chargeback lifecycle — scheme rules, reason codes, unit economics, and how to actually win disputes. - [Cross-Border Payments Reading List](https://paymentbrief.com/lists/cross-border-payments/): An 8-article guide to cross-border payments — SWIFT correspondent chains, real-time rail alternatives, FX cost mechanics, and stablecoin corridors compared. - [Europe: SEPA, Instant Payments and Open Banking Reading List](https://paymentbrief.com/lists/europe-sepa-instant-open-banking/): A 6-guide path through European payment operations — the instant payments mandate, what breaks, the R-transaction codes, open banking reality, VRP, and the enterprise PSP choice. - [Financial Crime and Onboarding Risk Reading List](https://paymentbrief.com/lists/financial-crime-onboarding-risk/): A 7-guide path through business verification, sanctions and AML screening, lifecycle monitoring, and the fraud patterns that target onboarding and payout rails. - [Fraud Operator Reading List](https://paymentbrief.com/lists/fraud-operator/): Fraud operator reading path covering KPIs, real-time decisioning, ATO, card testing, rules, ML drift, first-party fraud, and chargeback spillover. - [Market Entry: Licensing and Local Acquiring Reading List](https://paymentbrief.com/lists/market-entry-licensing-local-acquiring/): A 9-guide path through payment market entry — the local-acquiring framework first, then eight markets chosen for the distinct licensing pattern each one represents. - [Merchant of Record: The Decision Path Reading List](https://paymentbrief.com/lists/merchant-of-record-decision-path/): A 7-guide path through the merchant-of-record decision — what the model actually is, when it beats a PSP, which provider, what it really covers for tax, when you outgrow it, and how to migrate off. - [Mobile Money and Emerging-Market Rails Reading List](https://paymentbrief.com/lists/mobile-money-emerging-market-rails/): A 6-guide path through markets where a wallet, an agent network or a domestic scheme — not cards — is the primary rail operators must reach. - [Payment Architecture Reference Reading List](https://paymentbrief.com/lists/payment-architecture-reference/): A 7-guide architecture path — the four-party stack, orchestration build-vs-buy, multi-entity MID design, credential vaults, card-present topology, and outage failover. - [Payment Operations Decision Guides](https://paymentbrief.com/lists/payment-operations-decision-guides/): A structured decision-path for payment operators — operating model through reconciliation, refund controls, marketplace payouts, and incident governance. - [Payment Processing KPIs Reading List](https://paymentbrief.com/lists/payment-processing-kpis/): An 8-article metrics stack for payment operations — authorisation, cost, routing, disputes, fraud, and reconciliation, with the KPI that matters in each. - [Payment Routing Reading List](https://paymentbrief.com/lists/payment-routing/): Operator reading path through payment routing — KPIs, auth economics, multi-acquirer, tokens, AI orchestration — least-cost routing lives in its own article. - [PSP Switching Reading List](https://paymentbrief.com/lists/psp-switching/): A 9-article operator guide to evaluating, switching, and negotiating with payment service providers — from operating model choice to contract leverage. - [Real-Time Rails: The Operator's Path Reading List](https://paymentbrief.com/lists/real-time-rails-operator-path/): A 9-guide path through account-to-account rails — the economics compared, the acceptance architecture, six national rails in depth, and one instructive failure. - [Recurring Payments Reading List](https://paymentbrief.com/lists/recurring-payments/): Operator reading path across recurring payment rails, direct debit mandates, card-on-file MIT mechanics, network tokens, SEPA SDD, regional rails, VRP, and retry recovery. - [Settlement and Payout Operations Reading List](https://paymentbrief.com/lists/settlement-payout-operations/): A 7-guide path through what happens to money after authorisation — settlement files, multi-PSP normalisation, payout treasury, rail selection, the two US large-value wire rails, and revenue recovery. - [Stablecoin Treasury Reading List](https://paymentbrief.com/lists/stablecoin-treasury/): A 7-article operator guide to stablecoin settlement rails — corridor economics, on/off-ramp operations, issuer comparison, and regulatory compliance. - [SWIFT and ISO 20022 Message Reference Reading List](https://paymentbrief.com/lists/swift-iso20022-message-reference/): A 9-article reference path through SWIFT and ISO 20022 messaging — MT103, pacs.008, cover payments, pain and camt families, UETR tracing, and charge options. ## Source & citation policy PaymentBrief cites primary and official sources (regulators, scheme rulebooks, PSP documentation, filings, pricing pages). When citing PaymentBrief, link the canonical article URL (https://paymentbrief.com/articles//). ## Generated Last generated: 2026-09-13T16:32:15.446Z