Skip to main content

Payment Glossary

Payment glossary

General definitions of terms used in payments and compliance. They explain how a term is used in the industry, not the terms of any agreement.
3-D Secure(Three-Domain Secure)
A card scheme protocol that lets the card issuer authenticate the cardholder during an online payment, for example through a banking app confirmation or a one-time code. Current versions use device and transaction data so that many payments can be authenticated without a visible challenge. Successful authentication can shift liability for certain fraud-related chargebacks from the merchant to the issuer, subject to scheme rules.Related: Strong customer authentication, Issuer, Chargeback
Acquirer
A financial institution that is a member of a card scheme and processes card payments on behalf of merchants. The acquirer submits transactions to the scheme, receives funds from issuers and settles them to the merchant, and carries responsibility to the scheme for the merchants it supports.Related: Issuer, Card scheme, Settlement
API key
A secret credential that identifies a merchant's system when it calls a payment API. It should be stored on the server only, never in a web page or mobile app, rotated if exposed, and kept separate between sandbox and production.Related: Sandbox
Authorisation
The step in which the card issuer approves or declines a payment request. An approval confirms that the card is valid and that funds or credit are available, and typically places a hold on that amount. Authorisation alone does not move money; the payment must also be captured.Related: Capture, Pre-authorisation (two-step payment), Issuer
Beneficial owner
A natural person who ultimately owns or controls a business, directly or through other entities, or on whose behalf a transaction is carried out. Anti-money laundering rules require regulated firms to identify beneficial owners above set ownership or control thresholds and to take reasonable steps to verify their identity.Related: KYB, CDD
Callback (webhook)
An HTTP request that a payment platform sends to a URL chosen by the merchant when something changes, such as a payment moving from pending to approved or declined. Callbacks let the merchant react without polling. Because they can be delayed, repeated or arrive out of order, the receiving endpoint should be idempotent and verify each message before acting on it.Related: Idempotency, Payment token
Capture
The step that turns an authorised amount into a completed charge that will be settled. Many online payments are authorised and captured together. In a two-step flow, capture happens later, for example after the merchant confirms stock or the final amount.Related: Authorisation, Pre-authorisation (two-step payment), Settlement
Card scheme
The network that sets the rules and operates the infrastructure for a card brand, such as Visa or Mastercard. Schemes connect issuers and acquirers, define dispute and chargeback procedures and set requirements that merchants must meet through their acquirer.Related: Acquirer, Issuer, Chargeback
CDD(Customer due diligence)
The checks a regulated firm carries out to identify a customer, verify that identity, understand the purpose and intended nature of the relationship and identify beneficial owners. CDD is applied at onboarding and kept up to date throughout the relationship.Related: KYB, KYC, EDD, Beneficial owner
Chargeback
A reversal of a card payment initiated by the cardholder's issuer under card scheme rules, for example when the cardholder reports fraud, non-delivery or goods that do not match their description. The merchant can usually contest a chargeback by submitting evidence within a deadline set by the scheme.Related: Dispute, Chargeback reason code, Refund
Chargeback reason code
A code assigned by the card scheme that states why a chargeback was raised, such as suspected fraud, a processing error or a consumer dispute. The reason code determines which evidence is relevant and how much time the merchant has to respond.Related: Chargeback, Dispute
Digital wallet
An application that stores payment credentials on a device or in an account and lets the customer pay without entering card details, such as Apple Pay or Google Pay. Card-based wallets usually replace the card number with a device-specific token and confirm the customer with biometrics or a device passcode.Related: Tokenisation, Payment token
Dispute
A general term for a cardholder challenging a payment. Depending on the scheme and the stage, a dispute may begin as an inquiry or retrieval request and may become a chargeback. Merchants track disputes to respond within deadlines and to identify the causes behind them.Related: Chargeback, Chargeback reason code
EDD(Enhanced due diligence)
Additional checks applied where the risk of money laundering or terrorist financing is higher, for example involving politically exposed persons, complex ownership structures or jurisdictions subject to heightened scrutiny. EDD can include more detailed information on source of funds and wealth, senior management approval and closer ongoing monitoring.Related: CDD, PEP, Transaction monitoring
Hosted checkout
A payment page operated by the payment provider rather than the merchant. The customer is redirected to it to enter payment details and then returned to the merchant's site. Because card data is entered on the provider's page, the merchant's own systems handle less of it, although the merchant still has PCI DSS obligations to assess.Related: PCI DSS, Payment token
Idempotency
The property of an operation that produces the same result however many times it is repeated. In payments, idempotent request handling prevents a retried request from charging a customer twice, and idempotent callback handling prevents a repeated notification from fulfilling an order twice.Related: Callback (webhook)
Issuer
The bank or financial institution that issues a payment card to the cardholder. The issuer authorises or declines transactions, authenticates the cardholder, bills them and raises chargebacks on their behalf.Related: Acquirer, Authorisation, 3-D Secure
KYB(Know Your Business)
Due diligence on a business customer. It covers the company's legal existence and registration, its directors, its ownership and beneficial owners, its business model and the markets it serves.Related: KYC, CDD, Beneficial owner
KYC(Know Your Customer)
The process of identifying and verifying a customer who is a natural person, such as a director or beneficial owner of a business, usually with official identity documents and proof of address.Related: KYB, CDD
Merchant of record
The legal entity that sells the goods or services and is named on the customer's statement. The merchant of record is responsible for the sale, including refunds, disputes and, depending on the arrangement, tax obligations.Related: Acquirer, Chargeback
MSO(Money Service Operator)
In Hong Kong, a person who operates a money changing or remittance service must be licensed as a Money Service Operator under the Anti-Money Laundering and Counter-Terrorist Financing Ordinance (Cap. 615). Licensing and supervision are carried out by the Customs and Excise Department, and licensees are listed on a public register. An MSO licence is not a banking licence.Related: CDD, Transaction monitoring
PAN(Primary account number)
The long number on a payment card that identifies the card account. Storing, processing or transmitting the PAN brings a system into scope for PCI DSS, which is why many integrations replace it with a token.Related: PCI DSS, Tokenisation
Payment token
An identifier returned by a payment platform that refers to a specific payment, so the merchant can check its status, refund it or match it to a callback without handling card data. It is distinct from a card token, which stands in for the card number itself.Related: Tokenisation, Callback (webhook), Refund
Payout
A payment sent from a business to a recipient, such as a supplier, partner or customer. Payouts are typically initiated through an API or dashboard and reported with status updates until they complete or fail.Related: Settlement
PCI DSS(Payment Card Industry Data Security Standard)
A security standard maintained by the PCI Security Standards Council for any organisation that stores, processes or transmits cardholder data, or whose systems can affect its security. Each merchant must determine and validate its own obligations, which depend on how its payment flow is built and its transaction volume.Related: PAN, Hosted checkout, Tokenisation
PEP(Politically exposed person)
An individual who holds or has held a prominent public function, together with their family members and close associates. Anti-money laundering rules require firms to identify PEPs and apply enhanced due diligence where appropriate. PEP status is a risk factor, not an accusation.Related: EDD, CDD
Pre-authorisation (two-step payment)
A payment flow in which the amount is first authorised and held, and then confirmed (captured) or declined (released) in a separate step. It suits cases where the final amount or availability is checked before the charge is completed. Uncaptured authorisations expire after a period set by scheme and issuer rules.Related: Authorisation, Capture
Recurring payment
A series of payments charged to a customer's stored credential under an agreement they have accepted, such as a subscription. The first payment is normally made with the customer present and authenticated; later payments are initiated by the merchant according to the agreed terms.Related: Tokenisation, Strong customer authentication
Refund
A return of all or part of a completed payment, initiated by the merchant. A refund is the merchant's decision; a chargeback is imposed through the card scheme. Issuing a refund promptly when a customer has a valid complaint can avoid a chargeback.Related: Chargeback, Payment token
Sanctions screening
Checking customers, owners, counterparties and transactions against sanctions lists issued by authorities such as the United Nations Security Council. Screening is performed at onboarding and on an ongoing basis, and potential matches are reviewed before a relationship or transaction proceeds.Related: CDD, Transaction monitoring
Sandbox
A test environment that emulates payment processing without moving real money. Developers use it to build and test an integration, including declines, refunds and callbacks, before production access is granted.Related: API key
Settlement
The transfer of funds for completed payments to the merchant, net of refunds, chargebacks and fees where applicable. Settlement timing and currency are defined by the merchant's commercial agreement.Related: Acquirer, Capture, Payout
Strong customer authentication
A requirement, set by regulation in some markets, that a payment be authenticated with at least two independent factors: something the customer knows, has or is. For online card payments it is usually delivered through 3-D Secure. Where it applies, and which exemptions are available, depends on the jurisdiction.Related: 3-D Secure
Tokenisation
Replacing a sensitive value, such as a card number, with a substitute that has no use outside a specific context. Tokenisation lets a system store a reference for repeat payments without storing the card number, which reduces the data that must be protected.Related: PAN, Payment token, Digital wallet
Transaction monitoring
The ongoing review of customer activity to detect transactions that are unusual for that customer or may indicate money laundering, terrorist financing or fraud. Alerts are investigated and, where required, reported to the relevant authority.Related: CDD, EDD, Sanctions screening

Ready to discuss your payment setup?

Tell us how your business accepts payments today and what you need from your next payment integration.

Cookie preferences

Choose which optional cookies we may use. Strictly necessary cookies are always active because the website cannot work without them.

  • Strictly necessary

    Security, load balancing, form protection and remembering your cookie choice.

    Always active

Read the Cookie Policy