Global Payment Processing and Card Networks
Two seconds at the counter, four organisations in the chain. Each link is a place where data can leak.
A card payment that takes two seconds at a shop counter passes through at least four organisations: the customer's bank, the merchant's bank, the card network that connects them, and usually a processor or payment aggregator in between. Global payment processing is the study of that chain, and Unit 9 is in the syllabus because every link is a place where data can leak or a fraud can slip through.
A banker who knows which party does what can answer the questions that follow any card fraud: whose systems were breached, who carries the loss first, and who can stop the money.
You save ₹300
- Full 120-question mocks
- Cyber law coverage
- Module-wise practice
One payment, no subscription · Valid for 2 months
The Parties in a Card Payment
- Cardholder
- The customer who holds the card and authorises the payment.
- Issuer
- The bank (or permitted non-bank) that issued the card and holds the customer's account or credit line. It approves or declines each transaction.
- Merchant
- The shop, website or app accepting the card.
- Acquirer
- The merchant's bank, which signs up the merchant, provides or certifies the terminal or gateway, and receives the money for the merchant.
- Card network (card scheme)
- The organisation whose rules and switch connect issuers and acquirers: routing messages, setting standards and running the dispute process. In India, RBI has authorised American Express, Diners Club, Mastercard, NPCI (for RuPay) and Visa as card payment networks.
- Payment aggregator and payment gateway
- Intermediaries that let online merchants accept many payment methods. Payment aggregators handle merchants' funds and are authorised by RBI; gateways provide the technology without handling funds.
The Three Stages of a Card Transaction
- 1
Authorisation
The terminal or gateway sends the transaction to the acquirer, which routes it through the card network to the issuer. The issuer checks the card, the authentication (PIN, chip cryptogram or OTP), available balance and fraud rules, then approves or declines. This happens in real time.
- 2
Clearing
Later, approved transactions are sent in batches through the network so the issuer can post them to the cardholder's account and both sides agree on the amounts owed.
- 3
Settlement
Money actually moves: the issuer pays the network's settlement arrangement, the acquirer is paid, and the acquirer credits the merchant after deducting its fee.
Open and Closed Models
In the common four-party model, the network sits between separate issuers and acquirers, so any bank can issue a card that works at any merchant signed up by any other bank on the same network. In a closed-loop or three-party model, one organisation acts as network, issuer and acquirer at once. The distinction matters for fraud because in a four-party chain a dispute must travel through the network's chargeback rules between two banks that never deal with each other directly.
Quick practice on banking operations. No signup.
Where Fraud Enters the Chain
Cardholder side
Typical fraud
Phishing and vishing for card details and OTPs
Main control
Two-factor authentication, alerts, customer awareness
Merchant and gateway
Typical fraud
Card data stolen from checkout pages or stored data; collusive merchants processing stolen cards
Main control
Tokenisation (only issuers and networks may store card numbers), PCI DSS, acquirer due diligence on merchants
Terminal
Typical fraud
Skimming and PIN capture at PoS devices
Main control
PCI-approved PIN entry devices and point-to-point encryption
Issuer
Typical fraud
Card-number testing, counterfeit cards, account takeover
Main control
Fraud rules on velocity and invalid CVV or PIN strings, HSM-based PIN and CVV checks
Network and settlement
Typical fraud
Breaches at processors; mismatches between switch and books
Main control
Limits set at the network switch; reconciliation with networks and processors within 24 hours of the settlement files
| Stage | Typical fraud | Main control |
|---|---|---|
| Cardholder side | Phishing and vishing for card details and OTPs | Two-factor authentication, alerts, customer awareness |
| Merchant and gateway | Card data stolen from checkout pages or stored data; collusive merchants processing stolen cards | Tokenisation (only issuers and networks may store card numbers), PCI DSS, acquirer due diligence on merchants |
| Terminal | Skimming and PIN capture at PoS devices | PCI-approved PIN entry devices and point-to-point encryption |
| Issuer | Card-number testing, counterfeit cards, account takeover | Fraud rules on velocity and invalid CVV or PIN strings, HSM-based PIN and CVV checks |
| Network and settlement | Breaches at processors; mismatches between switch and books | Limits set at the network switch; reconciliation with networks and processors within 24 hours of the settlement files |
PCI Standards in RBI's Rules
The Payment Card Industry Data Security Standard (PCI DSS) is the card industry's baseline for anyone storing, processing or transmitting card data. RBI's 2026 Digital Payment Security Controls Directions expect card-issuing banks to follow PCI DSS and the related PCI standards for PIN handling, PIN entry devices, hardware security modules and point-to-point encryption.
How the IIBF Exam Tests This
Expect role questions: who approves the transaction (issuer), who signs up the merchant (acquirer), who sets the rules and routes messages (network). The trap is mixing up the issuer and the acquirer in a chargeback scenario: the cardholder's bank raises the dispute, the merchant's bank answers it.
FAQs
What is the difference between an issuer and an acquirer?expand_more
The issuer is the cardholder's bank, which issued the card and approves transactions. The acquirer is the merchant's bank, which accepts card payments on the merchant's behalf and pays the merchant.
Which card networks are authorised in India?expand_more
RBI's list of authorised payment systems names five card payment networks: American Express, Diners Club, Mastercard, NPCI (RuPay) and Visa.
What are authorisation, clearing and settlement?expand_more
Authorisation is the real-time approval of a transaction by the issuer. Clearing is the later exchange of transaction details so both banks agree what is owed. Settlement is the actual transfer of funds to the acquirer and then the merchant.
What is PCI DSS?expand_more
The Payment Card Industry Data Security Standard, a set of security requirements for every organisation that stores, processes or transmits card data. RBI expects banks to follow it along with related PCI standards.
Next steps
- SWIFT Fraudarrow_forward
- Card Not Present Fraudarrow_forward
- Encryptionarrow_forward
- Syllabusarrow_forward
120 questions, 2 hours, scored instantly.
