Chapter 1. Setting up the structure: who holds the dollars, and under which license.
The first decision in a US payments project is legal, not technical. It comes down to one question: do your systems hold someone else’s money, even for a second? If they do, you are engaged in money transmission. You then need a license in every state where your customers live. There is no passporting, no single license, and no single payments regulator. Federal law sets a baseline; the states grant the right to operate. Ask this question in month three of a project and you push the launch back a year.
| Structure | Who holds the funds | License in your name | What you give up | When to choose it |
|---|---|---|---|---|
| Merchant-of-record PSP (the PSP holds the network contract) | The PSP, until payout | None: you rely on the PSP’s | The direct network relationship, reporting granularity, part of the margin | Fast launch, simple catalog, early-stage volumes |
| Payment facilitator under a sponsor acquirer | You, in dedicated accounts, under the acquirer’s responsibility | Often no state license if the structure fits the agent-of-the-payee exemption; have US counsel confirm it | You carry the merchant risk and the compliance of your sub-merchants | A platform or vertical software company that collects for its customers |
| Your own license (money transmitter license) | You | Yes, state by state, through NMLS | Lead times in quarters, net worth requirements, surety bonds, ongoing prudential supervision | Models where holding funds is the product: wallets, accounts, transfers |
Chapter 2. Cards and rewards: running the numbers before negotiating.
In the US, your acceptance cost is not a rate; it is a mix. Credit interchange has no legal cap, while debit interchange does, so the gap between a premium rewards card and a big bank’s debit card runs to whole percentage points. A payments lead who negotiates “the rate” before measuring the mix is negotiating the only variable the PSP controls: its margin. That lead overlooks the variable that weighs most, the mix of cards their customers carry. The right order is: measure, segment, then negotiate.
MONTHLY VOLUME 1,000,000 USD
AVERAGE TICKET 60 USD
TRANSACTIONS 16,666
MIX (PULL from PSP reporting, never estimate)
regulated debit 35% 350,000 USD 5,833 tx
exempt debit 15% 150,000 USD 2,500 tx
standard credit 30% 300,000 USD 5,000 tx
premium credit 15% 150,000 USD 2,500 tx
commercial 5% 50,000 USD 833 tx
INTERCHANGE
(debit: Federal Reserve Board 2024 averages
credit: WORKING ASSUMPTIONS, replace with your actual numbers)
regulated debit 5,833 tx x 0.23 USD = 1,342 USD i.e. 0.38%
exempt debit 2,500 tx x 0.51 USD = 1,275 USD i.e. 0.85%
standard credit 300,000 x 1.80% = 5,400 USD
premium credit 150,000 x 2.30% = 3,450 USD
commercial 50,000 x 2.70% = 1,350 USD
TOTAL = 12,817 USD
i.e. 1.28% of volume, BEFORE network fees and PSP margin
WHAT YOU TRACK AFTERWARD, MONTH AFTER MONTH
- the all-in effective rate
= (interchange + network fees + PSP margin + dispute fees) / volume
- the SHARE of premium credit in the mix: that is what drifts
- cost by card type, never the average: the average hides the drift| Lever | What it affects | Requirement | Who is responsible |
|---|---|---|---|
| Debit routing | Interchange and network fees on the debit share | A PSP that can route PINless, including card-not-present | The PSP, on written request |
| Level II / Level III data | The interchange tier on commercial and corporate cards | Send the additional fields at both authorization and settlement | Your engineering team, with the PSP |
| Transaction qualification | Moving from one interchange tier to another | Timely settlement, correct indicators, AVS populated, no avoidable key entry | Your engineering team |
| Surcharge or cash discount | Passing part of the cost on to the cardholder | Network rules, advance notice to the acquirer, signage, and a state-by-state legal check | Commercial leadership, not engineering |
| Limited acceptance by category | Excluding an entire type of card | Formal election, and registration with the network by the acquirer | Executive leadership: it is a commercial trade-off |
Level II and Level III: the one lever you control on your own
On commercial and corporate cards, the networks offer lower interchange tiers when the transaction carries enhanced purchase data. Level II typically adds the tax amount and a customer code; Level III adds line-item detail (description, quantity, product code, amount). There is no contract to renegotiate and no approval to seek. The work is integration, in the authorization and in the settlement record. This is also the first lever a B2B seller should reach for on finding that its average rate is higher than a consumer-facing competitor’s. It isn’t paying more for the same product. It sells to commercial cardholders without sending the data that qualifies those transactions.
Chapter 3. PIN debit and Durbin: capturing least-cost routing.
A US debit card doesn’t carry one network. It carries at least two: a global brand and at least one unaffiliated PIN network. The requirement comes from Regulation II (12 CFR Part 235), which implements the Durbin Amendment. The rule “prohibits all issuers and networks from restricting the number of networks over which electronic debit transactions may be processed to less than two unaffiliated networks” (Federal Reserve Board). For a merchant, the consequence is operational. The network is chosen at authorization. You make that choice yourself, or your PSP makes it for you. Since the clarification that took effect on July 1, 2023, this also applies to card-not-present transactions.
| Path | Message format | Effect on authorization | Effect on disputes | Where the savings are |
|---|---|---|---|---|
| Signature (global brand: Visa Debit, Debit Mastercard) | Dual message: authorization, then settlement | Delayed capture, incremental authorization, tips, preauthorization | Global network rules; 3-D Secure liability shift available | None: it’s the default rate |
| PIN (STAR, Accel, NYCE, PULSE, SHAZAM…) | Single message: authorization and clearing together | No delayed capture or incremental authorization; PIN entry when the card is present | The rules of the PIN network in question, which differ from the global brand’s | Interchange and network fees, especially on exempt issuers’ cards |
| PINless (PIN network, no PIN entry) | Single message, no PIN authentication | Works for e-commerce and small tickets; eligibility checked in the BIN table | PIN network rules; no 3-D Secure liability shift | The real card-not-present savings since July 2023 |
STEP 1 Request debit authorizations broken down BY NETWORK
(Visa/Interlink, Mastercard/Maestro, STAR, Accel, NYCE,
PULSE, SHAZAM) for three full months.
If the PSP can't produce this file: you have your answer.
STEP 2 Isolate the share issued by banks NOT subject to the cap.
Average interchange 2024: USD 0.51 vs. USD 0.23 (Fed).
STEP 3 Maximum theoretical gap: 0.51 - 0.23 = USD 0.28 / transaction.
STEP 4 Example, 2,500 exempt debit transactions per month:
2,500 x 0.28 = USD 700 / month
= USD 8,400 / year in GROSS savings
STEP 5 Subtract the following, or the number is wrong:
- the fees of the chosen PIN network
- PINless certification / implementation cost
- the value of the 3DS liability shift you give up
on the routed share (see chapter 7)
STEP 6 What's left is negotiable. Not before.One last point should be spelled out in any business case. The debit interchange cap is living on borrowed time in the courts. On August 6, 2025, in Corner Post, Inc. v. Board of Governors, the US District Court for the District of North Dakota ruled that the Federal Reserve had exceeded its authority and vacated the interchange standard. The court stayed its own ruling pending appeal, and briefing before the 8th Circuit closed in March 2026. So the cap applies today, but don’t model either a cut or its disappearance. The dual-routing requirement doesn’t depend on this litigation, and it, not the cap, is what drives your savings.
Chapter 4. ACH: choosing your SEC code and keeping return rates in check.
ACH is not a European direct debit in disguise. There is no interbank mandate, no creditor identifier, and no enforceable mandate format. What serves as the authorization framework is the SEC code, three letters carried in the entry itself. They determine what form your proof must take, how long the debit can come back, and which checks the rules require of you. Choosing an SEC code isn’t just filling in a field. It sets your risk profile for the next 60 days.
| What you collect | Code | Proof to archive | Return window to reserve for |
|---|---|---|---|
| Recurring consumer debit, authorized in a signed writing or a compliant electronic equivalent | PPD | The signed authorization, its date, its scope (amount, frequency), and proof that it can be revoked | 60 calendar days (R10/R11, entry reported as unauthorized) |
| Consumer debit authorized on a website or app | WEB | The time-stamped authorization flow, plus proof of account validation on the first debit to a given account | 60 calendar days, plus mandatory account validation since March 19, 2021 |
| Consumer debit authorized by phone | TEL | A recording of the authorization, or the written confirmation sent to the customer; an existing relationship is required | 60 calendar days |
| Collecting from a business (cash concentration, B2B invoice) | CCD | The contractual agreement; only one addenda record available | 2 banking days (R29), a window 30 times shorter |
| B2B collection with structured remittance data | CTX | The contractual agreement and the EDI addenda (ANSI X12 820) | 2 banking days (R29) |
| Any entry where part of the transaction takes place outside the US | IAT | The seven mandatory addenda records, which enable OFAC screening | Depends on the underlying type, but a miscoded IAT is a compliance violation, not a technical glitch |
- Re-presenting after an R07 or R02. Authorization revoked or account closed: any new presentment is an unauthorized entry. After an R01 (insufficient funds), however, the rules allow up to two re-presentments.
- Forgetting the IAT code whenever any part of the transaction takes place outside the US: sanctions screening becomes impossible, and the liability has no materiality threshold.
- Showing your holding company’s name in the statement descriptor instead of the name the customer knows: it’s the leading cause of avoidable R10s.
- Booking an ACH credit as final on settlement day while the return window is still open.
- Not archiving proof of authorization in an enforceable format. A screenshot of the flow isn’t proof; the timestamp, the exact content displayed, and the session ID are.
Chapter 5. Instant and P2P: RTP, FedNow, and Zelle without illusions.
Three things to know before writing a single line of spec. First, US instant rails only carry push credits, final immediately, and there is no instant direct debit, so no collection in the European sense. Second, RTP and FedNow are not interoperable. A payment can’t cross from one to the other, and your payee’s bank may be on neither. Third, Zelle is not a rail; it is a directory layer that sits on top of ACH or RTP, depending on the bank. A US instant payment use case is designed starting from the payee, never from the rail.
| Your need | Rail to target | Why | What can make it fail |
|---|---|---|---|
| Paying out to US sellers or suppliers | Same Day ACH first; RTP or FedNow if the payee’s bank participates | Available everywhere, low cost, three windows per business day | The payee’s instant coverage, not yours |
| Refunding an unhappy customer in seconds | RTP or FedNow | Immediate finality, strong impact on satisfaction | Irrevocable: a refund sent in error can’t be recalled |
| Collecting a business invoice on its due date | Request for Payment on RTP or FedNow | The payer approves in their banking app: the only billing use case for US instant payments | Support for the feature at the payer’s bank, which is very uneven |
| Receiving a large amount (closing, margin call, intragroup transfer) | RTP, FedNow, or Fedwire | Limits raised to $10 million on RTP and FedNow; no network limit on Fedwire | The bank’s internal limit, often far below the network limit |
| Collecting from a US consumer in their banking app | None: Zelle has no public API | Zelle access goes through your own bank, not a provider | Counting on it in a product roadmap |
The only recall mechanism available is the request for return of funds, which is nothing more than a request to the receiving bank, subject to its goodwill and its customer’s. Treat it as a collections process, never a guarantee, and say so in your terms and conditions. On an instant rail, fraud changes character: it is no longer the misuse of a payment instrument but manipulation of the payer, who pushes the payment themselves. The Nacha rules on monitoring credit-push payments target exactly this kind of fraud. Phase 1 has applied since March 20, 2026, and phase 2 since June 19, 2026.
- Before you promise instant payments: measure the share of your payees whose bank participates in RTP or FedNow, and build a named Same Day ACH fallback into the flow.
- Ask your bank in writing for its per-transaction and daily limits, not the operator’s.
- Check that Request for Payment is supported by your target payers’ banks before you use it as a selling point.
- Write into your procedures that every instant payment is final, and require dual approval for amounts above a threshold you set.
- Never confuse Zelle’s instant customer experience with interbank settlement finality: your value dates depend on it.
Chapter 6. US chargebacks: two layers, and evidence to prepare in advance.
In Europe, disputing a payment is first a matter of EU law. PSD2 governs refunds of unauthorized transactions, and scheme rules come second. The US has no single statute. Instead, federal law gives consumers different rights depending on the payment instrument: Regulation Z for credit cards, Regulation E for debit and electronic fund transfers. On top of that, network rules govern the fight between banks. As the merchant, you are party to neither. You supply evidence to your acquirer within windows you don’t negotiate, so only one strategy works: prepare your evidence before the dispute.
| Regime | What it covers | Consumer deadline | Deadline for the consumer’s bank | What it means for you |
|---|---|---|---|---|
| Regulation Z (12 CFR 1026.13), credit cards | Billing errors: unauthorized or unidentified transactions, goods not delivered or not accepted, incorrect amount | Notice received no later than 60 days after the first statement reflecting the error is sent | Acknowledge within 30 days; resolve within 2 complete billing cycles, and no more than 90 days | Short, non-negotiable response deadlines all along the chain |
| Regulation E (12 CFR 1005.11 and 1005.6), debit and electronic fund transfers | Unauthorized electronic fund transfers and account errors | Notice no later than 60 days after the statement reflecting the error is sent | Resolve within 10 business days, or 45 days with provisional credit, extended to 90 days for point-of-sale debit card transactions or those initiated outside the US | A transaction the customer authorized, even if tricked by a scammer, falls outside the scope |
| Network rules (Visa Core Rules, April 18, 2026) | Four categories: 10 fraud, 11 authorization, 12 processing errors, 13 consumer disputes | Not applicable: the issuer initiates | 120 calendar days from the transaction processing date for most conditions | This is where you compete: evidence is judged under network rules, not the law |
Two procedural details change how you should organize. First, categories 10 (fraud) and 11 (authorization) have no response step. The dispute is allocated, and the acquirer must go straight to a pre-arbitration attempt within 30 calendar days. Second, the same transaction can be disputed under one condition, then recategorized by the issuer based on your response. A team that handles disputes ad hoc, with no evidence template per condition, loses on procedure long before it loses on the merits.
- Customer login ID, in clear text and unhashed: the one the cardholder recognizes, not your internal ID
- Full shipping address: street, city, state, zip code, country, in clear text
- Device ID, at least 15 characters, in clear text
- Device fingerprint, at least 20 characters, derived from at least two hardware or software attributes
- The cardholder’s public IP address, in IPv4 and IPv6 formats, unhashed
- Detailed description of the goods or services, stored exactly as shown to the customer, on every order, including those that will never be disputed, since those are the ones that will serve as evidence
Chapter 7. Fraud without SCA: approving more, declining smarter.
In the US, there is no strong customer authentication requirement: no PSD2, no exemptions to document, no reference fraud rate to monitor to keep the right to skip authentication. 3-D Secure is a business choice, made transaction by transaction. European teams therefore arrive with the wrong reflex: looking for ways to avoid the challenge. The US question is the reverse: when is triggering it worth it? The answer is a trade-off among three costs: challenge friction, the fraud you absorb, and the disputes you lose.
| Scenario | What goes in the authorization | Effect on the fraud dispute | What it costs |
|---|---|---|---|
| Full 3-D Secure (Visa Secure, EMV 3DS), cardholder authenticated | Electronic commerce indicator ECI 5 and CAVV | The 10.4 dispute is invalid: liability stays with the issuer | Challenge friction, and the drop-off it causes |
| Attempted authentication (issuer not participating, attempt response) | ECI 6 and CAVV returned for the attempt | The 10.4 dispute is also invalid: the attempt is enough | Almost nothing: the best protection-to-friction ratio |
| Authenticated tokenized wallet (authenticated credential) | ECI 5 and TAVV, with cardholder verification approved | The 10.4 dispute is invalid | A wallet integration, not a challenge |
| No authentication | No CAVV, no TAVV | The 10.4 dispute stays open: the loss is yours, unless you have evidence under Compelling Evidence 3.0 | Zero friction, all the risk |
Declines: exactly what the rules let you do
| Card type | Typical codes | What the rule allows | What to do |
|---|---|---|---|
| 1. Issuer will never approve | 04, 07, 12, 14, 15, 41, 43, 46, 57, R0, R1, R3 | Never retry the same credential, for any amount | Purge the payment method, stop retrying, ask for another card. R0, R1, and R3 are cardholder stop-payment orders: pushing on is a legal problem, not a commercial one |
| 2. Issuer cannot approve at this time | 51 (insufficient funds), 59, 61, 65, 78, 91, 96, 5C, 9G… | Retries allowed, up to 20 attempts over 30 days | Smart retries: space them out, target paydays, change the amount only if the contract allows it |
| 3. Data needs to be revalidated | 54 (expired card), 55, 82, 6P, N7 (CVV2 failure) | Retries allowed within the same limit, but only after the data is corrected | Automatic card updates through the network, or ask the customer. Retrying without changing anything just burns your allowance |
| 4. Generic codes | All others, including the notorious “do not honor” | Retries allowed within the same limit | Treat them like category 2, and report the volumes to your PSP: an issuer that overuses the generic code is supposed to reserve it for cases where nothing else applies |
- AVS, address verification, is specific to North America: it compares the numeric part of the street address and the zip code. On its own it blocks nothing, but a full-match result is useful evidence in a dispute file.
- CVV2: actually collect and send it, never fake it. Since April 2026, it is also a condition for invalidating a fraud dispute.
- Device fingerprint and IP address: an anti-fraud building block first, but above all the raw material for Compelling Evidence 3.0. Logging them is an investment in your own defense.
- Network tokenization replaces the card number with a token and structurally lifts authorization rates by updating expired credentials automatically.
- Velocity checks and lists, with limits per device, per address, and per card, within the cap of 25 transactions a day set by the rules.
- Selective 3-D Secure, triggered on high-risk or high-value orders, taking advantage of the fact that a mere attempt is enough to invalidate a fraud dispute.
A final word on measurement, because this is where teams aim at the wrong target. The right metric isn’t the fraud rate or the authorization rate on its own; it’s the total cost of declines. It adds up revenue lost to false declines, net fraud, amounts lost in disputes, and the value of customers who left after a challenge. Track it by issuer and by card type. An overall authorization rate of 92% can hide an issuer at 70% that accounts for a quarter of your volume, and that line, not the average, can be fixed in a single meeting with your PSP.