More Control Over Card Authorizations and Conversion
Together with issuers and card schemes, PAY works towards secure payment traffic and optimal conversion for merchants.
Card acquiring involves several parties in processing and authorizing a payment. Think of the merchant, the acquirer, the card schemes such as Visa and Mastercard, and the issuer of the card.
All these parties share a common interest: keeping payment traffic reliable and secure. At the same time, a merchant naturally wants as many legitimate payments as possible to be completed successfully. There is therefore a constant balance between security, fraud prevention, and conversion.
The issuer ultimately determines whether a payment is approved
When a consumer pays with a credit card or debit card, an authorization request is sent to the issuer via the payment infrastructure. The issuer is the party that issued the card to the cardholder.
The issuer assesses the transaction and ultimately determines whether it is approved or declined.
Many different factors can play a role in this assessment. Think, for example, of:
- the available balance or spending limit;
- the transaction amount;
- the country in which the payment takes place;
- the country of the merchant;
- the type of business and the associated Merchant Category Code (MCC);
- the payment behavior of the cardholder;
- signals that may indicate fraud;
- risk models and policy rules of the issuer.
This also means that two issuers may assess the same transaction differently.
MCCs and countries can be restricted
Issuers try to keep fraud and abuse within their card portfolio as low as possible. To do this, they can take various measures.
For example, an issuer may decide to assess certain Merchant Category Codes (MCCs) extra critically. An MCC indicates the category in which a merchant is active. When an issuer sees relatively high fraud or chargebacks within a certain category, this may be a reason to assess transactions within that category more strictly, restrict them, or in some cases block them.
The same can apply to certain countries or regions. For example, an issuer may apply additional restrictions to transactions from countries where, according to its own risk analysis, there is an increased risk.
Such rules can vary by issuer, card product, country, and situation. A lower authorization ratio therefore does not automatically mean that something is technically going wrong at the merchant or the acquirer.
A dedicated MID: more control and less dependency
At PAY, every merchant receives its own Merchant ID. This ensures that merchants' payment traffic remains separated from each other as much as possible, and that problems at one merchant do not unnecessarily affect others.
What is a MID?
In card acquiring, the Merchant ID (MID) plays an important role. A MID is a unique identifier by which a merchant is recognized within the acquiring chain.
A MID is linked to, among other things, data about the merchant, the company's activities, and the way card payments are processed. The MID therefore also plays a role in monitoring, risk management, and fraud prevention.
A MID can also be restricted, blocked, or whitelisted.
Every party within the card payment ecosystem has a responsibility to keep the market safe. Merchants, acquirers, issuers, and card schemes such as Visa and Mastercard therefore continuously monitor risks, fraud, and anomalous transaction patterns.
When serious or structural problems arise around a merchant, measures can be taken. Depending on the situation, a MID can, for example, be restricted, temporarily suspended, or fully blocked.
Possible reasons include:
- high fraud or chargeback levels;
- activities that do not match the registered business activities;
- violation of the rules of an acquirer or card scheme;
- increased risks around certain products, services, or markets;
- unusual or suspicious transaction patterns.
Restricting or blocking a MID is a drastic measure. After all, it can mean that the merchant can no longer process card payments through that MID.
An issuer may choose to block certain Merchant Category Codes (MCCs) by default or assess them more strictly, for example because that category has historically had more fraud or chargebacks.
At the same time, an issuer can make an exception for specific merchants. For example, such a merchant can be whitelisted, allowing transactions to still be permitted despite a general restriction on the relevant MCC.
A dedicated MID is important here. Because the merchant is uniquely identifiable within the acquiring chain, an issuer can apply an exception much more precisely to that specific merchant. This is more difficult when multiple merchants are processed under a shared structure or identification.
Because PAY gives every merchant its own MID, this not only creates more separation between merchants, but also more room for targeted exceptions and optimization at the issuer level.
Why PAY gives every merchant its own MID
PAY chooses to give every merchant its own MID.
This creates a clear separation between merchants. As a result, a merchant's payment activities and performance can be assessed and monitored individually.
This has an important advantage: when problems arise at one merchant, we want to prevent other merchants from being unnecessarily affected by this.
A merchant with, for example, a sharp rise in fraud or chargebacks should not automatically affect the payment performance of other, well-performing merchants.
The difference with the Payment Facilitator model?
There are various models within the market for offering card acquiring. One of these is the Payment Facilitator model (PayFac).
In a PayFac structure, multiple merchants can be processed as sub-merchants under the acquiring structure of the Payment Facilitator. As a result, there is more shared infrastructure and risk interdependency between merchants at certain levels.
PAY opts for a different setup: every merchant gets its own MID.
This allows risk, performance, and any measures to be linked much more specifically to the merchant in question. If a problem arises at one merchant, this does not automatically have to affect other merchants on the PAY platform.
Having a dedicated MID does not mean that a merchant can never face restrictions. Every merchant must continue to comply with the applicable terms and rules of PAY, acquirers, and the card schemes.
When measures are necessary, they can be targeted much more specifically at the merchant in question. This reduces the chance that other merchants are affected by behavior or risks over which they themselves have no influence.
Security and healthy conversion
A secure payment market is created when every party takes responsibility. PAY therefore not only monitors the general conversion of card payments, but also looks at risks and developments within payment traffic.
A secure card payment landscape is a shared responsibility. Merchants must handle their payment traffic carefully and try to prevent fraud. Acquirers and payment service providers monitor their platform and transaction flows. Issuers protect their cardholders and try to stop fraudulent transactions.
The card schemes, including Visa and Mastercard, also monitor performance and risks within their networks. Among other things, this includes looking at developments around fraud, chargebacks, and the quality of payment traffic.
Security and conversion are therefore closely linked. When anomalous patterns arise somewhere in the chain, this can ultimately affect the way transactions are assessed.
PAY monitors conversion and response codes.
PAY monitors the general conversion of card payments as well as at the bank level. This allows us to track developments in authorization ratios and detect when notable changes occur.
A decline in conversion can have various causes. Sometimes the cause lies with the merchant or the technical setup, but a change can also result from the policy of one or more issuers.
That is why it is important not only to look at the overall approval rate, but also, where possible, at patterns. Are there, for example, differences per issuer, country, card type, or MCC?
With that information, a more targeted investigation can be done into where a deviation originates.
Interesting response codes in the case of a suspected merchant block
The codes that we most often see follow in this context are 05, 57, 58 and 59. Here, the pattern is more important than a single individual transaction.
| Response code | Description | Relationship with MCC or MID blockage | What could it mean? |
|---|---|---|---|
| 05 | Do not honor | High | Very generic issuer decline. Can stem from fraud rules, merchant/MCC policy, country restrictions, or other internal issuer rules. Not proof of a block in itself, but is often used in the case of a merchant block. |
| 07 | Pick up card – special condition / fraud | Low | The issuer observes a serious fraud-related situation regarding the card/account. |
| 41 | Lost card | Low | The card is registered as lost. This primarily concerns the card and not the merchant. |
| 43 | Stolen card | Low | The card is registered as stolen. Also primarily cardholder/card-related. |
| 57 | Transaction not permitted to cardholder | Resourse | The issuer does not allow this transaction. This may be related to the transaction type, merchant category, card product, or an issuer restriction, for example. Mastercard also explicitly uses code 57 for transactions that are not allowed for the issuer/cardholder. |
| 58 | Transaction not allowed at terminal | Resourse | The transaction is not allowed within the acceptance context used. May indicate restrictions regarding terminal, channel, or merchant configuration. |
| 59 | Suspected fraud | High | The issuer has flagged the transaction as suspicious based on fraud detection. Visa explicitly describes this code as “Suspected fraud”. |
| 61 | Exceeds approval amount limit | Resourse | An amount or risk limit has been exceeded. This may be part of issuer risk management, but is not directly a merchant block. |
Reaching out to an issuer (issuer reach out)
PAY has an extensive catalog of issuers and contact details for this purpose. This allows us, in certain situations, to contact the relevant issuer directly and ask whether more information is available about, for example, notable declines or an anomalous authorization rate.
However, such an inquiry does not mean that the issuer is obliged to provide information. A response from an issuer therefore cannot be guaranteed. An issuer may also be limited in the information it can share for security, privacy, or policy reasons.
A decline is not always a technical problem
When a card payment is declined, a technical problem is often the first assumption. In reality, a decline can be the result of a deliberate risk assessment by the issuer.
For example, an issuer may restrict specific MCCs or countries, perform additional checks, or decline a transaction based on its own fraud model. These decisions are part of the measures with which issuers try to protect their cardholders and the broader payment system.
From the Business package with Premium Service onwards, PAY can also, at a merchant's request, make inquiries with an issuer when there are questions about the authorization of transactions.
Does switching MCC help?
It is important that a merchant chooses the correct category that matches the actual products or services offered. Based on this category, the corresponding Merchant Category Code (MCC) is determined.
There are, of course, also more general MCCs, such as MCC 5999. However, using a general MCC does not automatically mean that conversion will be better. Issuers use the MCC as one of the factors in their risk assessment of a transaction. The higher the estimated risk, the greater the chance that a payment will be declined.
It is therefore important to always choose the category that represents the merchant's activities as accurately as possible. If an incorrect category is chosen, resulting in the wrong MCC being sent with transactions, this can also lead to compliance issues and possible fines. An issuer may, for example, claim that an incorrect MCC hindered a proper risk and fraud assessment.
A correct MCC is therefore not only important for compliance, but also contributes to as reliable an assessment of transactions by issuers as possible.
Ultimately, all players in the card chain share the same interest: creating a payment environment in which legitimate transactions run as smoothly as possible, while fraud and abuse are prevented as much as possible.