Payment processing is the system that allows businesses to accept and complete electronic payments from customers. It connects merchants, payment processors, acquiring institutions, payment networks, issuing banks, and customers during a transaction.
A typical card transaction involves several participants:
Cardholder: The person making the payment
Merchant: The business receiving the payment
Issuer: The financial institution that issued the customer's card
Acquirer: The institution that supports the merchant's card acceptance
Payment network: The network that routes transaction information
Payment processor: The technology that helps transmit and manage transaction data
The transaction generally moves from the merchant through an acquirer or processor and payment network to the issuing institution, which returns an authorization or decline response.
Modern payment processing can support credit cards, debit cards, ACH transfers, digital wallets, bank payments, contactless transactions, and other electronic payment methods.
Payment processing is a fundamental part of business operations because it connects a customer's payment method with the merchant's financial account.
A well-designed payment environment can help businesses manage:
Customer payments
Online transactions
In-person transactions
Recurring payments
Invoices
Refunds
Payment reconciliation
Transaction reporting
Fraud monitoring
Chargebacks
Payment security
Accounting integration
The payment system should be evaluated not only for transaction speed but also for security, reliability, reporting, compliance, integration, and the types of payments a business needs to accept.
A merchant account is a type of account arrangement used to receive funds from card transactions before those funds are transferred to the business's designated bank account.
Merchant-account structures can vary depending on the provider and business model.
Important considerations can include:
Business type
Transaction volume
Average transaction amount
Card-present versus online transactions
International transactions
Recurring billing
Risk profile
Refund activity
Chargeback history
A merchant account should not be confused with an ordinary business checking account. The merchant account is part of the payment acceptance and settlement process.
A payment processor facilitates the movement of transaction information between relevant parties.
During a card transaction, the processor can help transmit authorization information, receive the response, and support settlement and reporting.
Processors may support:
Credit cards
Debit cards
Digital wallets
ACH
Recurring billing
Payment links
Online checkout
Point-of-sale transactions
The exact capabilities depend on the processing arrangement.
A payment gateway is technology that securely transmits payment information between a merchant's payment environment and the payment-processing ecosystem.
For an online transaction, the gateway can connect:
Customer → Checkout → Payment Gateway → Processor/Acquirer → Card Network → Issuing Institution
The authorization response then travels back through the system.
A gateway may also support features such as:
Tokenization
Encryption
Fraud screening
Recurring payments
Payment-method management
Transaction reporting
API integration
A gateway and processor are related but are not necessarily the same component.
A simplified card-payment process generally looks like this:
1. Customer initiates payment
The customer enters or presents payment credentials.
2. Merchant submits authorization
The payment system sends the transaction information to the appropriate processing infrastructure.
3. Network routing
The transaction moves through the relevant payment network toward the card issuer.
4. Issuer decision
The issuing institution evaluates the transaction and returns an approval or decline response.
5. Merchant receives the result
The customer sees whether the transaction was approved.
6. Clearing and settlement
Approved transactions are processed for settlement, and funds are transferred according to the applicable processing arrangement.
The FTC describes this basic flow as merchant → acquirer or processor → payment-card network → issuer, followed by the authorization response in the opposite direction.
These three terms describe different stages of a transaction.
Authorization
The issuer confirms whether the transaction can be approved based on applicable account and transaction information.
Capture
The merchant or payment system confirms that the authorized amount should be processed for settlement.
Settlement
Funds are transferred through the payment ecosystem and ultimately made available to the merchant according to the applicable settlement schedule.
Some businesses use separate authorization and capture processes, particularly when goods or orders are fulfilled later.
Credit and debit cards are among the most widely used electronic payment methods.
The transaction experience can differ depending on:
Card type
Card-present versus card-not-present environment
Authentication method
Payment network
Merchant category
Transaction amount
Geographic location
Card-present payments may involve physical cards, contactless payments, or mobile wallets.
Card-not-present transactions generally include online and other remote transactions and can involve additional fraud considerations.
Automated Clearing House payments transfer funds electronically between participating financial institutions through the ACH network.
ACH can be used for:
Business-to-business payments
Recurring payments
Payroll-related transactions
Invoices
Account transfers
Subscription billing
ACH transactions operate differently from card payments and can have different authorization, settlement, return, and dispute processes.
Businesses should understand the applicable rules for authorization and transaction records before implementing recurring ACH payments.
Digital wallets allow customers to use stored payment credentials through supported devices and applications.
Examples of payment technologies include:
NFC contactless payments
Mobile wallets
Device-based authentication
Tokenized card credentials
Contactless transactions can reduce the need to physically insert or swipe a card.
PCI SSC maintains separate standards covering payment technologies, including contactless payment solutions using commercial off-the-shelf devices.
Recurring payment systems allow a business to process scheduled transactions according to an established billing arrangement.
They can be used for:
Memberships
Subscriptions
Software access
Recurring invoices
Scheduled payments
Other ongoing billing arrangements
Recurring transactions require careful management of authorization records, failed payments, expired credentials, cancellations, refunds, and customer communications.
Businesses should also make sure recurring billing terms are clearly disclosed and that cancellation processes comply with applicable requirements.
Payment processing can involve multiple types of charges.
Potential components include:
Interchange fees
Network fees
Processor fees
Assessment fees
Gateway fees
Account fees
Chargeback-related fees
Equipment-related charges
The exact pricing structure depends on the provider, transaction type, business category, payment method, and contractual arrangement.
The FTC describes the merchant discount as potentially including interchange and other processing-related fees.
Businesses comparing processing arrangements should evaluate the complete fee structure rather than focusing on a single advertised rate.
Interchange is a component of card-payment economics involving the payment-card ecosystem.
The interchange amount can vary according to factors such as:
Card type
Transaction type
Merchant category
Transaction environment
Qualification criteria
Applicable network rules
Interchange should not be confused with the total amount a business may pay to its processor.
The final processing expense can contain several different components.
Payment security is critical because payment systems can involve sensitive financial information.
Security measures can include:
Encryption
Tokenization
Strong authentication
Access controls
Secure software
Network security
Vulnerability management
Monitoring
Employee security training
Incident-response procedures
PCI DSS provides baseline technical and operational requirements intended to protect payment-account data. It applies to organizations that store, process, or transmit cardholder data or could affect the cardholder-data environment.
The Payment Card Industry Data Security Standard, commonly called PCI DSS, establishes security requirements for payment-card data environments.
PCI DSS v4.0.1 is the current limited revision listed by the PCI Security Standards Council.
The standard addresses areas such as:
Network security
Secure configurations
Protection of stored account data
Encryption during transmission
Access controls
Authentication
Security testing
Vulnerability management
Monitoring
Incident response
The specific validation requirements depend on the merchant's payment environment and applicable payment-brand requirements.
Some businesses outsource payment processing to a third-party provider.
Outsourcing can reduce the amount of payment infrastructure a merchant directly operates, but it does not automatically eliminate PCI responsibilities.
PCI SSC states that merchants remain responsible for ensuring that relevant third-party providers maintain appropriate compliance and for understanding shared responsibilities.
Businesses should therefore document:
Which party handles card data
Which systems are in scope
Which security controls belong to the merchant
Which controls belong to the provider
How provider compliance is monitored
What contractual responsibilities exist
Tokenization replaces sensitive payment information with a token that can be used by the payment system without exposing the underlying account number in every transaction environment.
Tokenization can help reduce exposure of payment credentials.
However, tokenization does not automatically make an entire payment environment outside PCI DSS scope. PCI SSC specifically notes that encryption or other techniques do not automatically remove systems from PCI DSS scope.
Point-to-point encryption, or P2PE, protects payment information from the point where it is captured through the point where it is decrypted within an appropriate validated environment.
PCI SSC maintains a P2PE standard for validated solutions designed to protect payment account data.
Businesses using payment terminals should determine whether their equipment and payment environment use validated security technologies where appropriate.
Payment fraud can involve stolen credentials, account takeover, unauthorized transactions, synthetic identities, compromised websites, and other methods.
Fraud-management tools can evaluate signals such as:
Transaction history
Device information
Geographic indicators
IP information
Transaction velocity
Account behavior
Authentication results
Unusual purchase patterns
No single fraud-control technique is appropriate for every business.
Controls should balance fraud prevention with legitimate-customer experience.
A chargeback occurs when a card transaction is disputed through the applicable payment-card process.
Potential causes include:
Unauthorized transactions
Duplicate transactions
Processing errors
Merchandise or transaction disputes
Customer claims
Other network-defined dispute reasons
Businesses should maintain relevant documentation, which may include:
Transaction records
Order information
Customer communications
Delivery evidence
Refund records
Authorization information
Terms and disclosures
Chargeback-management procedures should be established before transaction disputes occur.
Refunds return funds to a customer after an applicable transaction has been processed.
Businesses should establish consistent procedures covering:
Refund authorization
Refund timing
Partial refunds
Full refunds
Transaction matching
Accounting records
Customer notifications
Refunds should be properly reconciled against the original payment transaction.
Payment reconciliation compares payment-system records with the business's accounting and banking records.
A reconciliation process can identify:
Missing transactions
Duplicate transactions
Unmatched deposits
Refund differences
Fee discrepancies
Chargebacks
Settlement timing differences
Automated reconciliation can become particularly valuable as transaction volumes increase.
Payment systems can integrate with:
E-commerce platforms
Accounting software
Customer relationship systems
Enterprise resource planning platforms
Inventory systems
Subscription-management systems
Point-of-sale systems
API-based integrations can allow businesses to automate payment creation, transaction retrieval, refunds, customer records, and reporting.
Integration design should consider security, authentication, error handling, data retention, system availability, and regulatory requirements.
Online businesses generally need to consider:
Checkout design
Payment methods
Card-not-present fraud
Payment-page security
Customer authentication
Refund processing
Recurring billing
Transaction records
PCI compliance
PCI SSC's current guidance specifically addresses security considerations for e-commerce payment pages, including situations involving embedded third-party payment forms and redirects.
Physical businesses may use:
Countertop terminals
Contactless readers
POS systems
Mobile payment devices
Integrated cash registers
Security considerations include protecting payment terminals from tampering and using appropriately validated payment technology.
PCI SSC recommends using approved payment devices and validated payment software where applicable.
Business-to-business payments can involve larger transaction amounts and more complex reconciliation requirements.
Common payment methods include:
ACH
Commercial cards
Bank transfers
Electronic invoices
Virtual payment arrangements
Other account-based payment methods
B2B payment systems often need strong integration with accounting and enterprise systems.
Important considerations include authorization controls, invoice matching, payment approval workflows, fraud prevention, and reconciliation.
Businesses should establish appropriate data-retention policies.
Payment records can include:
Transaction identifiers
Dates and times
Amounts
Payment method
Authorization information
Refund information
Settlement information
Dispute records
Businesses should avoid retaining sensitive authentication data when it is not permitted or necessary.
PCI DSS provides specific requirements concerning protection and retention of payment-account information.
Before selecting a payment-processing provider, businesses can evaluate:
Supported payment methods
Geographic coverage
Security certifications
PCI responsibilities
Integration options
Reporting
Settlement schedules
Dispute processes
Fraud controls
Contract terms
Account restrictions
Customer support
Business continuity
A provider's compliance status should be verified rather than assumed.
Payment providers may monitor merchants for unusual transaction patterns or elevated risk.
Factors that may affect payment risk can include:
High transaction volumes
Large transaction amounts
High refund rates
Chargeback levels
Sudden volume changes
International activity
Certain business categories
Unusual transaction patterns
Payment providers may establish reserves, transaction limits, verification procedures, or other controls depending on their risk-management policies.
Payment security requirements continue to evolve in 2026.
PCI SSC currently lists PCI DSS v4.0.1 as the current limited revision of the standard.
PCI SSC also published updated guidance during 2026 concerning e-commerce merchants and vulnerability scanning requirements under certain SAQ A environments. The guidance emphasizes that outsourcing payment processing does not necessarily remove all merchant responsibilities.
Another 2026 development involves PCI SSC's technology standards. The Council announced a formal sunset period from May 1 through October 31, 2026, for the PCI Contactless Payments on COTS and Software-based PIN Entry on COTS standards. Businesses using these technologies should therefore monitor the applicable replacement or transition requirements.
Payment processors are also subject to regulatory scrutiny.
In September 2026, the Federal Trade Commission announced a $4.85 million settlement with payment processor Nuvei related to allegations that the company processed payments for merchants it knew or should have known were involved in deceptive activity. The FTC said the settlement requires stronger merchant-screening practices.
For businesses, this illustrates why payment processing is not simply a technical function. Merchant onboarding, transaction monitoring, fraud controls, and compliance procedures can also be important parts of payment operations.
Businesses should clearly understand how payment-related fees are presented to customers.
The FTC's rules concerning unfair or deceptive fees address how certain mandatory charges must be disclosed and explain circumstances involving credit-card or other payment-processing fees.
Businesses should also consider applicable state laws, payment-network rules, and contractual requirements before applying payment-related surcharges.
A business evaluating its payment environment can review:
Identify required payment methods
Determine whether a merchant account is needed
Select an appropriate processor
Evaluate gateway requirements
Review transaction fees
Review settlement schedules
Establish refund procedures
Establish chargeback procedures
Evaluate fraud controls
Review PCI DSS responsibilities
Secure payment pages
Protect payment terminals
Define data-retention policies
Integrate payment data with accounting
Establish reconciliation procedures
Monitor provider compliance
Document incident-response procedures
PCI Security Standards Council
PCI SSC provides official standards, FAQs, merchant resources, security guidance, and compliance documentation for payment-card environments.
PCI DSS v4.0.1
Businesses handling payment-card information can review the current PCI DSS documentation and applicable Self-Assessment Questionnaires.
Payment Gateway Documentation
Gateway documentation can explain APIs, payment methods, authentication, transaction processing, refunds, webhooks, and integration requirements.
Accounting and Reconciliation Systems
Accounting integrations can help match payment transactions with invoices, deposits, refunds, and processing records.
Fraud Monitoring Tools
Fraud systems can evaluate transaction patterns and risk signals to identify potentially suspicious activity.
What is payment processing?
Payment processing is the system that moves payment information through merchants, processors, acquiring institutions, payment networks, and issuing institutions so transactions can be authorized and settled.
What is a merchant account?
A merchant account is an account arrangement associated with accepting card payments and receiving settlement funds before they are transferred according to the merchant's banking arrangement.
What is the difference between a payment gateway and a payment processor?
A payment gateway securely transmits payment information between a merchant's payment environment and the processing ecosystem, while a payment processor facilitates transaction processing and communication between relevant parties. The exact architecture varies by provider.
Does outsourcing payment processing eliminate PCI DSS responsibilities?
No. PCI SSC states that outsourcing payment processing does not automatically eliminate the merchant's PCI DSS responsibilities. Merchants must understand their remaining responsibilities and their third-party provider's responsibilities.
What is PCI DSS?
PCI DSS is a security standard designed to protect payment-account data. It provides technical and operational requirements for organizations involved in environments that store, process, or transmit payment-card data.
Payment processing connects customers, businesses, financial institutions, payment networks, and technology providers through a coordinated transaction system.
A complete payment environment can include a merchant account, processor, payment gateway, payment terminal or online checkout, fraud controls, security technology, accounting integration, and reconciliation processes.
Security is a central consideration. PCI DSS provides a baseline for protecting payment-account data, while tokenization, encryption, access controls, secure software, and appropriate payment infrastructure can help reduce exposure.
Businesses should also evaluate transaction fees, settlement procedures, refunds, chargebacks, fraud monitoring, payment-provider requirements, and applicable consumer-protection rules.
As payment technology continues to evolve, businesses should periodically review their payment architecture, PCI responsibilities, third-party providers, security controls, and transaction-management procedures.
By: Wilson
Updated: August 31, 2026
Read More
By: Wilson
Updated: September 07, 2026
Read More
By: Wilson
Updated: August 31, 2026
Read More
By: Wilson
Updated: August 31, 2026
Read More