Payments glossary. The words of the trade, defined one by one.

Each term has its own page: the definition, cross-references to neighbouring notions, and the topics where it is used. Search for a word or browse the alphabet.

151 payment terms. Complete vocabulary, with cross-references.

3

3-D Secure

Cardholder authentication protocol for remote card payments, specified by EMVCo (EMV 3DS version 2.x, version 1 having been decommissioned in October 2022). It has the merchant's 3DS Server, the scheme's Directory Server and the issuer's ACS exchange messages in order to authenticate the customer or apply an exemption. An authenticated transaction generally triggers a liability shift to the issuer in case of fraud.

A

A2A (account to account)

Account-to-account payment: the funds go directly from the payer's account to the payee's account, without passing through the card rails. Carried by instant credit transfer, PSD2 payment initiation and wallets such as Wero, it removes interchange and scheme fees. It is the leading candidate to disintermediate the card in Europe.

Acceptor

The merchant (or any entity) that accepts a payment method in settlement of goods or services, bound to its acquirer by an acceptance contract. It is not to be confused with the acquirer: the acceptor collects commercially, while the acquirer processes and guarantees financially. Each acceptance point is identified by a MID.

Account Updater

A scheme service (Visa Account Updater, Mastercard Automatic Billing Updater) that automatically refreshes the PANs and expiry dates of cards stored with a merchant when a card is reissued. It sharply reduces failures on recurring payments and subscriptions. Network tokens make the mechanism native, the update being handled by the network itself.

ACP (Agentic Commerce Protocol)

An open agentic commerce protocol published by OpenAI and Stripe in September 2025, which lets a conversational agent (ChatGPT) buy directly from a merchant through the Instant Checkout function. The merchant remains the merchant of record and receives a Shared Payment Token, a delegated payment token issued by Stripe, rather than raw card data. A direct competitor to Google's AP2, it turns the AI model into a new checkout surface.

ACPR

The French prudential supervision and resolution authority, attached to the Banque de France. It authorises and supervises French credit institutions, payment institutions and electronic money institutions, and checks in particular that safeguarding and AML/CFT obligations are met. Any payment services activity in France goes through its authorisation, its registration, or a European passport notified to it.

Acquirer

The institution (a bank or a payment institution) that signs up merchants, collects their transactions, guarantees them the payout of funds and carries the financial risk of chargebacks. It is a scheme member on the acceptance side and earns its revenue from the merchant service charge (MSC). Examples in France: the incumbent banks, Worldline, Adyen and Stripe.

ACS

Access Control Server: the issuer's authentication server in the 3-D Secure protocol. It assesses transaction risk, decides between a frictionless flow and a challenge, and carries out cardholder authentication (notification in the banking app, biometrics, an OTP). Its availability and configuration bear directly on merchants' conversion rates.

Payment agent (AI)

An autonomous software agent, generally driven by an AI model, that searches, compares and triggers payments on a user's behalf. It is not to be confused with the "payment agent" in the PSD2 sense, a registered representative of a PSP. Its rise brought dedicated protocols in 2025 (Google's AP2, OpenAI and Stripe's ACP, Coinbase's x402) and raised the question of the verifiable mandate linking an agent to an auditable human intention. The central security stake is to authenticate the agent and bound its authorisation, hence the concept of Know Your Agent.

AISP

Account Information Service Provider: the account information provider status created by PSD2. It reads the customer's payment accounts, with their consent, through the banking APIs (account aggregation, budgeting tools, credit scoring). In France the status is subject to a lighter registration with the ACPR.

Reversal

Cancellation of an authorisation or of a transaction before it clears: the amount reserved is released against the cardholder's limit and no funds move. To be distinguished from a refund, which comes after settlement and is a separate credit transaction. Reversing unused authorisations is good practice required by the schemes.

AP2 (Agent Payments Protocol)

Agent Payments Protocol: an open protocol unveiled by Google in September 2025 with more than 60 partners (Mastercard, PayPal, American Express, Coinbase and others), which extends the A2A and MCP protocols to payment initiated by AI agents. It rests on Mandates, cryptographically signed verifiable credentials that capture the user's intention and form an auditable chain of authorisation. Agnostic as to payment method, it covers cards, credit transfers and stablecoins, the last of these through an x402 extension.

ARN

Acquirer Reference Number: a 23-digit reference assigned by the acquirer when a card transaction is cleared. It makes it possible to trace the transaction end to end in the scheme's and the issuer's systems. It is the standard evidence that a refund was indeed issued when a customer claims to have received nothing.

Authorisation

A request sent in real time to the issuer (ISO 8583 messages) to check that the card is valid, not blocked, funded and free of fraud risk. An approved authorisation reserves the amount against the cardholder's limit but moves no funds: capture and then settlement are what turn it into a payment. The response code (00 = approved, 05 = declined and so on) determines what happens next.

AVS

Address Verification Service: a check that compares the billing address entered by the buyer with the one held by the issuer, and returns a match code (full, partial, none). Widely used in the United States, the United Kingdom and Canada, it is all but absent in France. It is an antifraud signal complementary to CVV, not authentication.

B

Trusted beneficiary

A whitelisting mechanism provided for by PSD2: the payer registers a merchant or a transfer beneficiary on a list held by their issuer or bank. Later transactions towards that beneficiary can then be exempted from SCA. The list is managed exclusively on the payer's bank side, never by the merchant.

BIC

Business Identifier Code (ISO 9362), also known as the SWIFT code: an 8 or 11 character identifier for a financial institution (bank, country, location, branch). It routes messages over the SWIFT network and historically accompanied the IBAN within SEPA. Since the "IBAN only" rule of 2016 it can no longer be required for SEPA payments.

BIN

Bank Identification Number: the first 6 to 8 digits of the PAN (8 digits since the revision of ISO/IEC 7812 applied by schemes in April 2022). It identifies issuer, scheme, product type (debit, credit, commercial, prepaid) and country of issue. BIN tables feed routing, pricing and antifraud rules at acquirers and PSPs.

BIN sponsor

A principal member of a scheme that makes its BINs, its licence and its authorisation available to non-member players (fintechs, neobanks) so that they can issue cards or acquire transactions. The sponsor remains answerable to the scheme and to the regulator, notably for the AML/CFT compliance of its partners. It is the building block that made the explosion of white-label card offerings possible.

BNPL

Buy Now Pay Later: split payment (3 or 4 instalments) or deferred payment offered at checkout, carried in France by Alma, Klarna, Oney and Floa. Long outside the scope of consumer credit thanks to its duration of less than 90 days, it is brought within it by the revised consumer credit directive (EU) 2023/2225, currently being transposed (deadline November 2025, application 2026). The model rests on a high merchant fee (1.5 to 4%) in exchange for a higher average basket.

C

camt.053

The ISO 20022 end-of-day account statement message (Bank to Customer Statement), the structured successor to MT940. It details every entry with references that can be processed automatically (end-to-end id, mandate reference, gross and net amounts), which makes it the raw material of reconciliation. Its companions are camt.052 (intraday statement) and camt.054 (debit/credit advice, notably the detail of batches).

Safeguarding

The obligation on payment institutions and electronic money institutions to protect client funds: deposit in a segregated account opened with a credit institution, or cover by a guarantee or insurance policy. Safeguarded funds are out of reach of the institution's creditors should it fail. It is the mechanism that secures collection on behalf of third parties by marketplaces and PSPs.

Capture

The merchant's confirmation that an authorisation is actually to be debited, sent to the acquirer in a batch. In e-commerce it often happens at dispatch (authorisation at order, capture when the parcel leaves), in full or in part. An uncaptured authorisation expires, generally after 7 days (longer for certain MCCs such as hotels).

Card testing

Fraud consisting of testing stolen or generated card numbers in bulk, through micro-transactions or zero-value authorisations, on poorly protected sites. It shows up as sudden spikes of declined attempts and damages the MID's reputation with issuers. Countermeasures: CAPTCHA, velocity controls, mandatory CVV, blocking of BINs that are being hit abnormally often.

Card-on-file (COF)

A card registered with a merchant or its PSP for later payments: one-click purchase, subscriptions, top-ups. COF transactions fall under the schemes' CIT / MIT framework, which requires an authenticated first payment and then the chaining of references. Good practice is to store a token, ideally a network token, rather than the PAN.

Co-badged card

A card carrying two payment brands, typically CB plus Visa or CB plus Mastercard in France. The Interchange Fee Regulation (IFR, art. 8) guarantees cardholders the right to choose the brand at the moment of payment, while merchants may set a priority choice on their terminal. The stake is economic: routing to CB or to an international scheme does not cost the acceptor the same.

Commercial card

A business or corporate card, issued for professional spending. It is excluded from the IFR interchange caps, hence interchange rates often between 1.3 and 2%, passed through in the MSC. It is also one of the rare cases where surcharging remains lawful in some EU countries.

CB

"Cartes Bancaires", the French domestic scheme created in 1984 and governed by the GIE CB: around 76 million cards and in the order of 15 billion transactions a year. Almost all CB cards are co-badged with Visa or Mastercard, CB being used in priority for domestic transactions. Its domestic interchange is lower than that of the international schemes, which makes it a cost advantage for French merchants.

CB2A

The French card messaging protocol between the acceptance point (terminal, payment server) and the acquirer, derived from ISO 8583: authorisation requests and batch collection files. Each acquirer maintains its own implementation, which complicates terminal certification. It is migrating gradually towards the European nexo standards, built on ISO 20022.

Chargeback

The card dispute procedure: at the cardholder's request (fraud, goods not received, service not as described), the issuer takes funds back from the acquirer, which debits them from the merchant. It is governed by scheme rules, with dispute windows in the order of 120 days and standardised reason codes. Real cost to the merchant: the amount lost, plus a case fee (€15 to €50), plus deterioration of its chargeback ratio.

CIT / MIT

The distinction standardised by Visa and Mastercard between transactions initiated by the customer (Customer Initiated Transaction) and by the merchant (Merchant Initiated Transaction: recurring, instalment, no-show, incremental). MITs sit outside the scope of SCA, provided an initial CIT was authenticated and the transactions are chained through the scheme references. A badly set MIT flag translates into soft declines at scale.

Clearing

Clearing: the exchange of transaction data between participants and the calculation of each one's net position, ahead of the actual settlement of funds. For cards it is operated by the schemes; for SEPA transfers and direct debits, by CSMs such as STET or EBA Clearing. Clearing and settlement are two distinct stages: the information is exchanged first, the money is settled afterwards.

CNP

Card Not Present: a transaction where the card is not physically presented (e-commerce, MOTO, subscriptions). This is where most card fraud is concentrated: the OSMP measures a fraud rate on remote payments around twenty times that of face-to-face payments, hence the SCA obligation. The pairing of 3-D Secure with tokenisation is the market's standard answer.

CSM

Clearing and Settlement Mechanism: the infrastructure that clears and settles SEPA payments between PSPs. Examples: STET in France, STEP2 and RT1 from EBA Clearing at pan-European level, TIPS from the Eurosystem for instant payments in central bank money. A PSP must be reachable, directly or indirectly, on a CSM for each scheme it belongs to.

CVV

The visual cryptogram (CVV2/CVC2): 3 digits on the back of the card (4 on the front for American Express), verified by the issuer during remote payments. It evidences physical possession of the card at the moment of entry. PCI DSS strictly forbids storing it after authorisation, even encrypted, and that is one of the most heavily sanctioned non-compliances.

D

DCC

Dynamic Currency Conversion: when paying abroad, the terminal or the ATM offers settlement in the card's currency rather than the local one. The conversion is performed by the acquirer with margins often between 3 and 12%, almost always to the cardholder's disadvantage. Regulation (EU) 2019/518 requires the margin over the ECB rate to be displayed; the golden rule remains to pay in local currency.

Deferred debit

A French arrangement: card payments made during the month are aggregated and debited in one go at month end, interest free. For the purposes of the Interchange Fee Regulation, a deferred debit card is treated as a credit card (interchange capped at 0.3%). It differs from revolving credit: there is neither revolving balance nor cost for the cardholder, only a cash-flow lag.

Directory Server (DS)

The central component of the 3-D Secure protocol, operated by each scheme: it holds the directory of enrolled BINs and routes authentication messages between the merchant's 3DS Server and the issuer's ACS. It is what knows, for a given PAN, which ACS to query and in which protocol version. Where the ACS is unavailable, it can produce an attempt response.

DORA

Digital Operational Resilience Act, regulation (EU) 2022/2554, applicable since 17 January 2025. It harmonises management of ICT risk across the European financial sector: governance, notification of major incidents, resilience testing and oversight of critical third-party providers such as cloud suppliers. Payment institutions, EMIs and PSPs are fully subject to it, under supervision by the ACPR and the European supervisory authorities. A major operational incident must now be notified to the regulator within strict deadlines.

DPAN

Device PAN: a device-specific token provisioned into a wallet (Apple Pay, Google Wallet) in place of the real PAN when the card is enrolled. It is held in the phone's Secure Element or managed through HCE, and can be revoked remotely without reissuing the physical card. The merchant never sees the underlying PAN, which reduces its PCI exposure.

Drop-in (component)

A ready-made integration component supplied by a PSP (Adyen Drop-in, Stripe Payment Element, Braintree Drop-in) that automatically displays the available payment methods and orchestrates data collection, redirections and 3-D Secure with a minimum of code. It generally relies on hosted fields in an iframe, which keeps the merchant within a lighter PCI scope. It is the usual compromise between the hosted page, simple but hard to customise, and full API integration, flexible but heavy on compliance.

DSP2

Directive (EU) 2015/2366 on payment services, applicable since January 2018: mandatory strong authentication (the SCA RTS, generalised across e-commerce in 2021), opening of accounts to third parties through APIs (AISP/PISP), a ban on surcharging consumer cards, and a cap on the payer's liability. It turned open banking into a regulatory obligation rather than a commercial option.

DSP3

The legislative package proposed by the European Commission in June 2023, combining a PSD3 directive (authorisation, supervision) and a directly applicable PSR regulation (user rights, SCA, fraud). On the agenda: stronger verification of the payee, shared liability in cases of manipulation fraud, direct access for payment institutions to payment systems, and the merger of the electronic money regime. Effective application is expected at the earliest around 2027-2028, after final adoption and a transitional period.

Dynamic linking

A requirement of the PSD2 RTS for remote electronic payments: the authentication code generated during SCA must be dynamically linked to the amount and the payee displayed to the payer. Any change to either invalidates the authentication, which neutralises transaction hijacking attacks. In practice, the banking app displays "Pay €149.90 to Merchant X" before biometric confirmation.

E

EBICS

Electronic Banking Internet Communication Standard: a secure file exchange protocol between companies and banks, adopted in France in 2010 to replace ETEBAC (and also used in Germany, Switzerland and Austria). It carries pain.001 transfer batches, pain.008 direct debits and camt.053/MT940 statements. The French EBICS TS variant adds a detached electronic signature on the orders.

ECI

Electronic Commerce Indicator: the code returned at the end of a 3-D Secure flow that qualifies the level of authentication obtained. At Visa: 05 (authenticated), 06 (attempted), 07 (not authenticated); at Mastercard: 02, 01 and 00 respectively. It is the ECI that governs liability shift and the issuer's treatment of the transaction.

Issuer

The bank or institution that issues the payer's card (or holds the account): it authorises transactions, carries credit and fraud risk on the cardholder side, and receives interchange. It also operates the ACS for 3-D Secure authentication. In the four-party model it faces the acquirer through the scheme.

EMV

The global standard for chip cards and contactless, governed by EMVCo (Visa, Mastercard, Amex, JCB, Discover, UnionPay). Each transaction generates a dynamic cryptogram, making chip cloning impractical; fraud has moved massively towards remote channels (CNP). EMVCo also specifies 3-D Secure, payment tokenisation and EMV QR codes.

EPI

European Payments Initiative: an alliance of European banks launched in 2020 to build a pan-European payment solution independent of Visa and Mastercard. After abandoning the card strand, EPI bought iDEAL and Payconiq in 2023 and launched the Wero wallet in 2024, built on instant account-to-account transfers. Notable shareholders: BNP Paribas, Crédit Agricole, BPCE, Société Générale, Deutsche Bank, ING and Worldline.

Electronic money institution

An institution authorised (by the ACPR in France) to issue electronic money: value stored on a device or an account, redeemable at any time, as in balance wallets and prepaid cards. The regime, which stems from the EMD2 directive of 2009, is set to merge with that of payment institutions under the PSD3 package. Funds collected are subject to safeguarding.

Payment Institution

A status created by the first payment services directive (PSD1, 2007, transposed in France in 2009), allowing payment services to be provided (acquiring, transfers, initiation, account information) without being a bank. Authorised and supervised by the ACPR, it is subject to capital requirements, safeguarding of funds and AML/CFT obligations, but may neither take deposits nor grant credit outside narrow exceptions. Most European PSPs and PayFacs operate under this status.

Euro numérique

The ECB's retail central bank digital currency project: a digital equivalent of the banknote, free for individuals, usable online and offline with a high level of privacy. The preparation phase has been running since November 2023 and the European legislative framework is still under discussion; issuance is not envisaged before the end of the decade. Banks fear deposit disintermediation, which a maximum holding mechanism is meant to cap.

F

Fallback

A fallback mechanism into a degraded mode: reading the magnetic stripe when the EMV chip is unreadable, keying the PAN manually, or authorising offline below a floor limit when the network is unavailable. Fallback transactions are riskier and often excluded from payment guarantees. The schemes restrict them drastically, and the magnetic stripe itself is on its way out.

Fraud by manipulation (APP fraud)

Authorized Push Payment fraud: the victim executes the transfer themselves under the effect of manipulation, whether by a bogus bank adviser, false supplier bank details or a fake listing. It is the leading cause of transfer fraud recorded by the OSMP, and the irrevocability of instant transfers makes the impact worse. Responses under way: mandatory Verification of Payee, strengthened shared liability in the PSD3/PSR package, and mandatory reimbursement in the United Kingdom since October 2024.

Frictionless

A 3-D Secure flow with no cardholder interaction: the ACS authenticates on the sole basis of risk data transmitted (device, history, IP address, amount) or applies an exemption. A challenge, by contrast, requires customer action: confirmation in the banking app, biometrics, an OTP. Optimising frictionless rates, through rich 3DS data and the TRA exemption, is a major conversion lever.

Friendly fraud

Friendly fraud: the legitimate cardholder disputes a transaction they genuinely made, whether a forgotten purchase, an unrecognised family subscription, or deliberate abuse. It accounts for a major share of e-commerce chargebacks and is hard to tell apart from genuine fraud at the moment of the dispute. Visa tightened the evidence rules with Compelling Evidence 3.0 (2023), which allows a fraud chargeback to be requalified using the customer's order history.

G

Gateway

The payment gateway: the technical layer that carries the transaction from the merchant's site or till to the acquirer or the processor, handling encryption, format conversion and orchestration of 3-D Secure. Unlike the acquirer, it never touches funds and carries no financial risk. Modern PSPs bundle gateway, acquiring and antifraud into a single offering.

GENIUS Act

Guiding and Establishing National Innovation for U.S. Stablecoins Act: the first American federal law on stablecoins, enacted on 18 July 2025. It creates a status for issuers of payment stablecoins backed entirely by liquid reserves (cash, Treasury bills), with monthly publication of the reserves and a ban on paying interest to holders. It is the American counterpart to the stablecoin strand of MiCA, whose adoption accelerated the entry of banks and payment giants into this market.

GIE CB

The Cartes Bancaires economic interest grouping, created in 1984. It governs the CB scheme (operating rules, security, equipment approval, interbank cooperation) for around a hundred members, banks and payment institutions alike. It does not process flows itself: authorisations circulate between members and clearing goes through STET. It is the historical architect of French interbank cooperation, a textbook case of a resilient domestic scheme.

H

Hosted fields

Card entry fields hosted by the PSP and embedded as iframes within the merchant's own page: the customer keeps the impression of staying on the merchant site, but the card data travels straight to the PSP without ever touching the merchant's servers. This architecture keeps the merchant in SAQ A or SAQ A-EP, unlike direct API integration, which moves it into SAQ D. It offers more control over design than a fully redirected payment page.

HSM

Hardware Security Module: a tamper-resistant hardware appliance that generates, stores and uses cryptographic keys without ever exposing them, for PIN verification, EMV cryptograms, tokenisation and signing. Certified to FIPS 140-2/3 and PCI PTS HSM, they are unavoidable at issuers, acquirers and processors. The whole security of card payments ultimately rests on these devices and their key ceremonies.

I

IBAN

International Bank Account Number (ISO 13616): the international account identifier, 27 characters in France (FR plus a modulo 97 check key, then bank code, branch code, account number and national check digits). It is the universal key of SEPA payments. Refusing an IBAN from another SEPA country ("IBAN discrimination") is unlawful, yet it is still observed at some creditors.

ICS

SEPA Creditor Identifier: it uniquely identifies the originator of SDD direct debits. In France it runs to 13 characters (FR plus a check key, a 3-character business code and a 6-digit national issuer number) and is obtained through the creditor's bank from the Banque de France. Paired with the mandate reference, it identifies each direct debit mandate uniquely across the whole SEPA area.

Interchange

The fee paid by the acquirer to the issuer on every card transaction, notionally paying for the payment guarantee and for risk carried on the cardholder side. The Interchange Fee Regulation caps it within the EEA at 0.2% for debit cards and 0.3% for consumer credit cards. It is the main component of the MSC billed to merchants, ahead of scheme fees.

Interchange++

A transparent acquiring pricing model: the merchant pays the actual interchange plus the actual scheme fees plus an explicit acquirer margin (the "++"). It stands in contrast to blended pricing, a single opaque rate that smooths out the differences between cards. IC++ is recommended as soon as volumes justify it: it passes the regulatory caps through to the merchant and reveals the true cost of each card type.

IPR

Instant Payments Regulation, regulation (EU) 2024/886. It makes instant transfers universal across the euro area: an obligation to receive since 9 January 2025 and to send since 9 October 2025, pricing capped at the price of an ordinary transfer, mandatory verification of payee (VoP) and daily rather than per-transaction sanctions screening. Countries outside the euro area follow with staggered deadlines (2027).

ISO 20022

The universal standard for structured financial messages in XML, organised into families: pain (customer to bank), pacs (interbank) and camt (reporting). It underpins SEPA, TARGET and the migration of SWIFT cross-border payments (coexistence with MT messages ending in November 2025). Its richness, from structured remittance data to LEI and standardised addresses, improves reconciliation, compliance and screening.

ISO 8583

The historical standard for card payment messages: message types (0100 authorisation, 0110 response, 0400 reversal and so on) and numbered fields such as 2 (PAN), 4 (amount), 11 (STAN), 37 (RRN) and 39 (response code). Every scheme and every domestic protocol, CB2A included, derives its own dialect from it. It remains the beating heart of card networks, despite the rise of ISO 20022 and of APIs.

K

KYA (Know Your Agent)

Know Your Agent: the extension of KYC and KYB principles to the age of AI agents, consisting of identifying an autonomous agent, verifying its mandate and the scope of its authorisation, and tying it back to a responsible person or entity. The concept emerged in 2025 with the agentic payment protocols, which rely on verifiable credentials to prove the agent's identity and entitlement. The aim is to prevent a compromised or hijacked agent from committing payments outside the user's consent.

KYB

Know Your Business: verification of a corporate customer, covering legal existence, ultimate beneficial owners (UBOs), sanctions, the reality of the activity and its consistency with the declared MCC. Acquirers and PayFacs run it when onboarding each merchant, then continuously through transaction monitoring. Weak KYB opens the door to merchant fraud (ghost websites, laundering through fake sales) and to regulatory sanctions.

KYC

Know Your Customer: identification and verification of a customer's identity at onboarding and then on an ongoing basis, through identity documents, liveness detection and PEP and sanctions screening. It is the operational foundation of AML/CFT for every PSP. In France, remote identification relies on certified verification providers (the ANSSI PVID framework) or on digital identity.

L

LCB-FT

Anti-money laundering and counter-terrorist financing: customer due diligence (KYC/KYB), transaction monitoring, suspicious activity reports to Tracfin, asset freezing and sanctions screening. The European AML package adopted in 2024 creates a single directly applicable regulation and the AMLA authority in Frankfurt (ramping up over 2025-2028, with direct supervision of the riskiest players). Payment institutions are among the entities most frequently inspected by the ACPR.

Matching

Line-by-line accounting matching between invoices and their settlements (or between debit and credit entries) in the customer and supplier subledgers. It can be automated thanks to the references carried by the payments: invoice number, the end-to-end id of transfers, the mandate reference of direct debits. Clean matching is the precondition of any reliable bank reconciliation.

Liability shift

The transfer of liability in cases of fraud: towards the issuer where the transaction was authenticated with 3-D Secure (or attempted, depending on the ECI), and towards the least EMV-compliant party in face-to-face payments. It covers fraud alone (stolen card, impersonation) and never commercial disputes, which remain open to chargeback. It is the economic incentive that drove the adoption of the chip and then of 3DS.

M

Marketplace

A platform that brings buyers and third-party sellers together and collects funds on the sellers' behalf. Collecting on behalf of third parties is a payment service: it requires an authorisation (as a payment institution), agent status, or the use of a specialist PSP that safeguards the funds and operates the payouts. PSD2 closed the old "commercial agent" tolerance that platforms had been abusing.

MCC

Merchant Category Code (ISO 18245): a 4-digit code classifying the merchant's activity, such as 5411 supermarkets, 5812 restaurants or 7995 gambling. It determines applicable interchange, risk rules, certain acceptance prohibitions and issuers' cashback programmes. A misdeclared MCC breaches scheme rules and is a signal of merchant fraud.

Merchant of record

The entity that is legally the seller towards the end customer: it collects the funds, accounts for VAT, bears compliance, fraud and chargebacks, and appears on the bank statement. Some players (Paddle, app resellers) offer this model turnkey to software publishers. It is to be distinguished from the PayFac, which facilitates the payment but is never a party to the sale.

MiCA

Markets in Crypto-Assets, regulation (EU) 2023/1114: the first harmonised European framework for crypto-assets. Its stablecoin rules, covering e-money tokens (EMT) and asset-referenced tokens (ART), have applied since 30 June 2024, and the rest of the framework since 30 December 2024. Issuers and crypto-asset service providers (CASPs) are authorised and supervised by national authorities (the AMF and the ACPR in France), under coordination by ESMA and the EBA.

MID

Merchant ID: the identifier of a merchant's acceptance contract with its acquirer. One merchant often holds several, by channel (face-to-face or e-commerce), by currency, by banner or by legal entity. It is the unit of measurement of scheme monitoring programmes: fraud and chargeback ratios are computed per MID.

four-corner model

The standard architecture of a card transaction: cardholder and issuer on one side, acceptor and acquirer on the other, and the scheme in the middle setting rules and routing flows. It stands opposed to the three-party model (historically American Express), where a single entity both issues cards and acquires merchants. Almost all Visa, Mastercard and CB volumes run on four parties.

Monétique

The French term covering the whole of electronic card payment processing: issuing, acquiring, authorisation, clearing, terminals and cryptographic security. By extension it takes in the entire card ecosystem, from the GIE CB to processors and terminal manufacturers. The word has no real English equivalent, where one speaks of cards or payments.

MOTO

Mail Order / Telephone Order: a remote payment whose card data is keyed in by the merchant itself, by phone or by post. MOTO transactions sit outside the scope of SCA, but without authentication and without liability shift: the merchant bears the fraud. They should be reserved for controlled flows such as call centres with secure DTMF entry, with payment links as an alternative.

MSC

Merchant Service Charge: the total fee paid by the merchant to its acquirer, made up of interchange (passed to the issuer), scheme fees (passed to the network) and the acquirer's margin. In France it ranges from under 0.2% for grocery retail on CB to more than 1.5% for a small e-merchant on international cards. Its structure is negotiated either blended or as Interchange++.

MT940

The end-of-day account statement in SWIFT MT format: historical, compact, but weakly structured, since the detail of each operation sits in field 86 as semi-free text, which hampers automation. It is being replaced progressively by the natively structured ISO 20022 camt.053. Many corporate treasuries still use it, for want of migrating their existing chains.

N

Network token

A token issued by the scheme (Visa Token Service, Mastercard Digital Enablement Service) that replaces the PAN for a given merchant or wallet. Its life cycle is managed by the network: it survives card reissuance and updates itself automatically. Measured benefits: 2 to 3 points of extra authorisation rate on stored payments, and sometimes more favourable interchange.

nexo

The open standards of the nexo standards association, unifying card message exchange across Europe: the terminal application specification (nexo FAST), the terminal-to-acquirer protocol (nexo Acquirer) and the till-to-terminal protocol (nexo Retailer), all built on ISO 20022. They are progressively replacing domestic protocols such as CB2A, with a single certification valid in several countries. Large pan-European terminal deployments (retail, fuel) adopted them first.

NFC

Near Field Communication: the short-range radio technology behind contactless payment, by card or by mobile. In France the limit is €50 per card transaction (above that, insertion and PIN), with no limit on mobile payments authenticated biometrically (CDCVM). Contactless accounts for around two thirds of in-store card payments in the euro area according to ECB studies.

O

On-us

A transaction where the card issuer and the merchant's acquirer are one and the same institution. It can be authorised and cleared internally, without passing through the scheme, at reduced cost, subject to the network's reporting rules. The phenomenon is significant in concentrated banking markets.

Open banking

The opening of payment accounts to authorised third parties through APIs, made mandatory by PSD2: account information aggregation (AISP) and payment initiation (PISP). Banks must expose dedicated, high-performing interfaces under supervision by regulators. The coming European framework (FIDA, the PSD3 package) is meant to extend data sharing beyond payments, into savings, credit and insurance, towards open finance.

Orchestration

A technical layer sitting above several PSPs and acquirers: intelligent routing of transactions, cascading retries to a second acquirer after a failure, centralised tokenisation in an independent vault, and unified reconciliation and reporting. It reduces dependence on a single provider and optimises both cost and acceptance rate. Players include Payrails, Gr4vy and Primer, alongside in-house solutions at large merchants.

OSMP

The French observatory for the security of payment means, chaired by the Banque de France. It publishes the reference annual report on fraud against cashless payment means, which put fraud at €1.195 billion in 2023, with a card fraud rate of 0.053%. It brings together banks, merchants, consumer associations and public authorities, and issues recommendations that carry weight on securing wallet enrolment, VoP and authentication.

P

Hosted payment page

A page, or fields in an iframe, served by the PSP, where the customer enters their card data: that data never passes through the merchant's servers. It is the simplest way to shrink PCI DSS scope (eligibility for SAQ A). The alternative, direct API integration, offers more control over the experience but moves the merchant into SAQ D with far heavier obligations.

pain.001

The ISO 20022 credit transfer instruction message (Customer Credit Transfer Initiation), sent by the company to its bank, typically over EBICS. It carries the batches, the execution dates, the beneficiaries' IBANs and the end-to-end references that will reappear in the creditor's statements. Its counterpart for issuing direct debits is pain.008.

PAN

Primary Account Number: the card number, 12 to 19 digits long (16 most of the time), structured as BIN plus account identifier plus a Luhn check digit. It is the most sensitive data item in the card ecosystem and sits at the heart of the PCI DSS requirements. The underlying trend is never to handle it in the clear again, in favour of tokens.

PAR

Payment Account Reference (EMVCo): a 29-character reference that links a PAN to all tokens derived from it (wallets, network tokens). It allows the same card account to be recognised across its representations, for loyalty, fraud management or matching, without ever exposing the PAN. It cannot be used to initiate a payment.

Passkey

A FIDO2/WebAuthn credential: a cryptographic key pair specific to each site, unlocked locally by biometrics or a code, and phishing-resistant by design. It combines possession (the device) with inherence (the biometrics), which makes it a strong candidate for banking SCA and for wallet authentication. The schemes are deploying it within Click to Pay and issuers are beginning to accept it for 3DS.

Pay-per-crawl

A mechanism launched by Cloudflare in July 2025 (in beta) that lets a publisher charge AI crawlers for each request to access its content, instead of blocking them or letting them scrape it for free. It reuses the HTTP status code 402 Payment Required to signal the price to the crawler, opening the way to usage-based monetisation between agents and sites. It belongs to the same wave as the x402 machine-to-machine payment protocol.

PayFac

Payment Facilitator: a player that aggregates sub-merchants under its own acquiring contract (a master MID) and its own KYB, allowing onboarding in minutes rather than days, a model popularised by Stripe and Square. The PayFac carries financial and compliance risk for its sub-merchants towards the acquirer and the schemes. In Europe the activity requires, in practice, payment institution or agent status.

PCI DSS

Payment Card Industry Data Security Standard: the framework for securing card data (12 requirements covering network, encryption, access, logging and testing), governed by the PCI Security Standards Council founded by the schemes. Version 4.0 has been mandatory since 31 March 2024 and its "future-dated" requirements since 31 March 2025 (v4.0.1 published in June 2024). Any entity that stores, processes or transmits card data is subject to it, with a validation level that depends on volumes.

PIN

Personal Identification Number: the cardholder's secret code, verified either online by the issuer or offline by the EMV chip. It travels exclusively encrypted inside standardised blocks (ISO 9564), handled by HSMs from end to end. In France it is required for contactless card payments above €50 and remains the reference verification method face to face.

PISP

Payment Initiation Service Provider: a licensed third party (PSD2) that initiates a credit transfer directly from the payer's bank account, with their consent, through open banking APIs. It is the foundation of pay by bank: combined with instant credit transfer, it competes with the card in e-commerce, on large baskets and in bill payment. The PSR (the PSD3 package) is intended to improve the quality and the consistency of the APIs it depends on.

Cardholder

The card holder (cardholder), bound to their issuer by the cardholder agreement. In France, their liability before notification is capped at EUR 50 in case of loss or theft with use of the PIN, and remote fraud must be refunded to them in full unless there is gross negligence or fraud on their part (art. L. 133-19 of the French Monetary and Financial Code). Strong customer authentication has moved the debate towards how that gross negligence is characterised.

Pre-authorisation

Reservation authorisation (an imprint) without immediate capture, used by hotels, rental companies and petrol stations: the estimated amount blocks the cardholder's limit until completion at the final amount or expiry. The schemes frame its life span (from a few days to 30 days depending on the MCC) and require unused funds to be released. An unsettled pre-authorisation is a classic source of cardholder disputes.

Processor

A technical provider that processes flows on behalf of an issuer (issuer processing: authorisations, card portfolio management, card blocking) or of an acquirer (acquiring processing: acceptance, clearing, disputes). Examples: Worldline, Fiserv, Global Payments, Marqeta on the new-generation issuing side. The Interchange Fee Regulation requires separation between a scheme and its processing activities.

PSP

Payment Service Provider: in the sense of PSD2, any provider of payment services — banks, payment institutions, electronic money institutions. In commercial usage, the term refers to the online collection provider (Stripe, Adyen, Worldline, Checkout.com and others) combining gateway, acquiring, anti-fraud and reporting. The choice of PSP determines the merchant's acceptance rate, costs and PCI scope.

R

R-transactions

Family of returned SEPA transactions, identified by ISO reason codes: reject (rejection before settlement), return (return after settlement), refund (refund requested by the debtor), recall (recall by the originator's bank). Their rate is the key indicator of the quality of a direct debit flow — unpaid SDDs (insufficient funds, dispute) cost fees per transaction. R-transaction files feed collections work and the updating of mandates.

Chargeback ratio

Proportion of a merchant's transactions that are disputed (the number of disputes divided by the month's transactions). The schemes impose threshold-based monitoring programmes — VAMP at Visa (consolidated in April 2025, combining reported fraud and disputes) and ECP at Mastercard — with thresholds of the order of 0.7% to 1.5%. Exceeding them brings remediation plans, fines, then termination of the acquiring contract and listing on the network's blacklists.

RDR

Rapid Dispute Resolution: a Verifi (Visa group) arrangement for automatic resolution before a dispute — the merchant sets rules (amount, reason, MCC) under which it refunds automatically, which stops the formal chargeback before it is created. It saves case fees and representment effort, but the disputes resolved still count in the VAMP ratio. The Mastercard equivalent is Ethoca alerts.

Reason code

Standardised chargeback reason code, specific to each scheme: at Visa, the 10.x families (fraud, e.g. 10.4 card-absent fraud), 12.x (processing errors) and 13.x (consumer disputes, e.g. 13.1 goods not received); at Mastercard, 4837 (transaction not authorised) or 4853 (cardholder dispute). The reason code determines the admissible evidence and the representment deadlines. Analysing their distribution guides anti-chargeback plans.

Reconciliation

End-to-end matching between orders, transactions as seen by the PSP, payouts received in the bank and accounting entries. It relies on the PSP's settlement reports, camt.053 statements and shared references (RRN, ARN, end-to-end id). It is what detects missing transactions, fee discrepancies and duplicate payouts — a time-consuming exercise that orchestration and ISO 20022 data reduce considerably.

Interchange Regulation (IFR)

Regulation (EU) 2015/751: it caps interchange on consumer cards (0.2% debit, 0.3% credit), requires accounting separation between schemes and processing activities, guarantees application choice on co-badged cards and obliges the acquirer to itemise its fees to the merchant. Commercial cards and pure three-party schemes fall outside the caps. It brought the cost of acceptance down, partly offset by the rise in scheme fees.

Refund

A credit initiated by the merchant towards the customer's card or account after settlement: it is a separate transaction (and not the cancellation of the first), credited within 2 to 5 business days. The absolute rule is refunding to the original payment method — a refund by parallel credit transfer does not stop a chargeback from succeeding and results in paying twice. The ARN of the refund serves as evidence in case of a dispute.

Submission

A batch of captured transactions sent by the merchant (or its terminal or PSP) to the acquirer for clearing, generally at the end of the day. In French card-present acceptance it is done by telecollection. Its composition and the submission cut-off time determine when funds are paid to the merchant.

Representment

Second presentment: the acquirer's challenge to a chargeback, resubmitting the transaction with the evidence supplied by the merchant, proof of delivery, 3-D Secure logs, customer correspondence, order history. Response deadlines are strict (of the order of 20 to 30 days depending on the scheme) and the case must answer precisely the reason code invoked. Visa Compelling Evidence 3.0 now makes it possible to have alleged fraud reclassified as friendly fraud on the strength of two earlier undisputed transactions.

Request to Pay (SRTP)

SEPA Request-to-Pay, an EPC scheme operational since 2021: a standardised payment request addressed to the payer, who accepts it and triggers a credit transfer, ideally instant, in return. It is not a payment method but a messaging layer that structures A2A payments: electronic invoicing, e-commerce, point of sale. Wero and several European banks use it as an underlying building block.

Retrieval request

A documentation request (copy request) issued by the issuer before a possible chargeback, to obtain the sales slip or the supporting documents for the transaction. Now rare with dematerialisation and the simplification of scheme rules, it survives on certain disputes and at certain networks. Failing to answer within the deadline can lead to a chargeback with no right of representment.

Rolling reserve

Rolling reserve: the acquirer or the PSP holds back a percentage of the merchant's takings (typically 5% to 15%) over a rolling period of 90 to 180 days, to cover future chargebacks and unpaid items. It is standard in sectors with deferred delivery or elevated risk: travel, ticketing, long subscriptions, crypto. Its terms (rate, duration, release) are negotiated in the acquiring contract.

RRN

Retrieval Reference Number: a 12-character reference (field 37 of ISO 8583 messages) assigned to the transaction at authorisation, which follows it through to settlement. It is the most widely used reconciliation key between the merchant's, the acquirer's and the issuer's systems. It appears on terminal receipts and in most back offices.

RUM

Unique Mandate Reference: an identifier (35 characters maximum) assigned by the creditor to each SEPA direct debit mandate. The creditor identifier and the UMR together identify the mandate uniquely throughout the SEPA area and must appear in every SDD instalment as well as in the pre-notification sent to the debtor. Changing the UMR without issuing a new mandate causes rejections.

S

SAQ

Self-Assessment Questionnaire: the PCI DSS self-assessment questionnaire for merchants not subject to an on-site audit by a QSA. The applicable type depends on the integration: SAQ A (payment fully outsourced, redirect or iframe), SAQ A-EP (the merchant's site influences the payment flow), SAQ D (card data touched, hundreds of requirements). The choice of payment architecture is therefore first of all a decision about compliance scope.

SCA

Strong Customer Authentication: the strong authentication required by PSD2, resting on at least two independent factors drawn from knowledge (a code), possession (a phone, a card) and inherence (biometrics). It applies to electronic payments initiated by the payer, subject to a closed list of exemptions: low value (≤ €30), TRA risk analysis, trusted beneficiaries, with MITs falling outside its scope. Its general roll-out in France in 2021 caused authenticated e-commerce fraud to collapse, at the cost of a friction the industry has been optimising ever since.

Scheme

A payment network that defines brands, rules and infrastructure: international card schemes (Visa, Mastercard, Amex), domestic ones (CB in France, girocard in Germany, Bancomat in Italy), and the SEPA interbank schemes operated by the EPC (SCT, SCT Inst, SDD, SRTP). The scheme sets interchange (below the regulatory caps), arbitrates disputes and earns its revenue from scheme fees. Joining one requires a licence, compliance and participation in settlement.

Scheme fees

Fees billed by the networks (Visa, Mastercard, CB and others) to issuers and acquirers: authorisation, clearing, brand licensing and optional services. They are a growing and barely legible component of the MSC: the British regulator PSR documented a rise of more than 30% in real terms between 2017 and 2021 at Visa and Mastercard, with no matching improvement in service. Interchange++ pricing lets the merchant see them line by line.

Fraud scoring

Real-time assessment of the risk carried by a transaction, combining expert rules, machine learning, device fingerprinting, velocity checks and behavioural signals. The score drives straight-through acceptance, a 3-D Secure challenge or a refusal, and feeds the request for a TRA exemption. PSP engines pool signals from thousands of merchants, a decisive advantage over standalone set-ups.

SCT

SEPA Credit Transfer: the standard euro credit transfer, an EPC scheme launched in 2008, credited no later than the next business day (D+1). It carries 140 characters of remittance text and end-to-end references, and is exchanged through CSMs. It remains the vehicle for salaries, pensions and supplier payments, and is gradually losing ground to the instant scheme.

SCT Inst

SEPA Instant Credit Transfer (2017): a euro transfer credited in under 10 seconds, 24 hours a day, 365 days a year. The scheme cap of €100,000 was lifted as part of the alignment with the IPR regulation, and each PSP now sets its own limits. It accounted for roughly 20% of euro area credit transfers in early 2025, accelerating sharply since the IPR made it free of extra charge.

SDD

SEPA Direct Debit: the SEPA direct debit, based on a mandate signed in favour of the creditor (identified by a creditor identifier and a mandate reference). Two variants exist: Core (any debtor, no-questions-asked refund for 8 weeks, 13 months where the operation was unauthorised) and B2B (between businesses, no refund right, mandate registered by the debtor's bank). Unpaid items travel as R-transactions billed to the creditor.

SEPA

Single Euro Payments Area: the single euro payments zone, some forty countries (EU, EEA, United Kingdom, Switzerland, micro-states) where credit transfers and direct debits follow the same standards, namely IBAN, ISO 20022 messages and EPC schemes. Migration away from national formats was completed in 2014 within the euro area. A cross-border SEPA payment must cost the same as a domestic one.

Settlement

Settlement: the actual transfer of funds between participants, once clearing has taken place. For the merchant it is the acquirer's payout (typically D+1 to D+3), net or gross of fees depending on the contract; for systemic infrastructures it happens in central bank money (TARGET, TIPS). The PSP's settlement reports are the cornerstone of reconciliation.

Smart routing

Dynamic routing of each transaction towards the best collection path: choice of brand on a co-badged card (CB versus international), choice of acquirer (cost, acceptance rate by BIN or by currency), automatic failover to a second acquirer after a technical failure. Typical gains: a few tenths of a point of acceptance rate and substantial MSC savings at high volume. This is the central argument of the orchestration platforms.

Soft decline

A soft, reversible authorisation refusal: the issuer is not rejecting the card but demanding an action, typically authentication (response 1A / 65, "SCA required"). The right reflex is to replay the transaction immediately through a 3-D Secure flow. A hard decline (stolen card, closed account, insufficient funds), by contrast, must never be retried unchanged: schemes penalise abusive retries.

Soft descriptor

The wording that appears on the cardholder's bank statement, configurable per transaction at most acquirers. A clear descriptor (recognisable trading name, city or contact details) markedly reduces "transaction not recognised" chargebacks, the leading source of unintentional friendly fraud. Schemes govern its format: length, and PayFac prefix for sub-merchants.

SoftPOS

Turning a merchant's smartphone or tablet into a contactless acceptance terminal with no dedicated hardware at all ("Tap to Pay on iPhone/Android"). Security is governed by the PCI MPoC standard, which allows PIN entry on the screen (PIN on Glass). It is the preferred route to acceptance for very small merchants, tradespeople and delivery riders.

Stablecoin

A crypto-asset whose value is stabilised by a peg to a currency (most often the dollar) and backed by reserves, as opposed to volatile crypto-assets. The market stands at around $250 billion in early 2026, dominated by Tether's USDT and Circle's USDC. In the European Union it falls under MiCA (EMT and ART tokens) and in the United States under the GENIUS Act; its use as a payment and settlement rail, notably for AI agents through x402, is growing fast.

STAN

System Trace Audit Number: a 6-digit counter (field 11 of ISO 8583 messages) assigned by the originator of the message, unique per day and per system or terminal. Combined with the date, the time and the TID, it identifies an exchange unambiguously during incident investigations and reconciliation work. It also serves to match a reversal request with the original authorisation.

Stand-in

Stand-In Processing (STIP): the scheme, or the processor, authorises in place of the issuer when the latter is unavailable or answers too slowly, according to pre-agreed parameters (limits per transaction and per period, permitted MCCs, CVV verification). It guarantees network availability but shifts risk onto the issuer, which discovers the transactions after the fact. Stand-in parameters are part of the negotiations on scheme membership.

STET

A CSM created by the large French banks: it clears French retail payments (credit transfers, direct debits and CB card transactions under the CORE(FR) system), amounting to around 30 billion operations a year, which makes it one of the very largest retail payment systems in Europe. Final settlement takes place in central bank money through TARGET. It also runs a pan-European SEPA clearing offer and processes instant payments.

Surcharging

A price uplift charged to the customer according to the payment method used. It is prohibited in the EU on consumer cards whose interchange is capped by the IFR (the ban comes from PSD2); France prohibits it generally, for every payment method. It remains possible in some countries on commercial cards, within the limit of the actual cost borne.

SWIFT

A Belgian cooperative company that operates the worldwide interbank financial messaging network: more than 11,000 institutions in more than 200 countries. It carries cross-border payments (the historical MT messages, then MX/ISO 20022, with coexistence ending in November 2025) without ever holding the funds. SWIFT gpi has brought the majority of international transfers below 30 minutes with end-to-end tracking.

T

Batch capture

The transmission, historically overnight, of the batches stored in the terminal towards the acquirer for clearing, through the CB2A protocol in France. The session chains together collection of transactions, remote parameter updates for the terminal and refresh of security tables. The move from dial-up to IP made it more reliable, and permanently connected terminals are tending towards continuous submission.

TID

Terminal ID: the identifier of a terminal, or of a logical acceptance point, assigned by the acquirer and attached to a MID. It appears on customer receipts and in authorisation messages, and pinpoints a transaction across an estate of many tills. It is indispensable to technical support, to the fight against internal fraud and to reconciliation by point of sale.

TIPS

TARGET Instant Payment Settlement: the Eurosystem service (2018) that settles instant credit transfers in central bank money, 24 hours a day, transaction by transaction, within seconds. The IPR regulation and ECB decisions are pushing every euro area PSP to be reachable on it, directly or through a CSM. It removes interbank credit risk on instant payments, unlike deferred settlement models.

Tokenisation

Replacing a sensitive data item, the PAN first and foremost, with a token that has no exploitable value, the mapping being held in a secure vault. It comes in two forms: PSP proprietary tokens and scheme network tokens, whose life cycles differ. Benefits: drastic reduction of PCI DSS scope, neutralisation of data breaches, continuity of stored payments.

TPE

Terminal de Paiement Électronique: the card acceptance device used face to face, covering chip and contactless reading, PIN entry, authorisation request and batch collection. It is certified PCI PTS for hardware security and approved by the schemes it accepts (CB in France). The market is moving towards application-rich Android terminals, hardware-free SoftPOS and unified nexo protocols.

TRA

Transaction Risk Analysis: an SCA exemption based on the overall fraud rate of the PSP requesting it, up to €100 where that fraud rate is ≤ 0.13%, €250 where it is ≤ 0.06%, €500 where it is ≤ 0.01%. The issuer remains free to refuse the exemption and to answer with a soft decline demanding authentication. The key point: when the exemption is claimed on the acquiring side, liability for fraud stays with the merchant, a conversion-versus-risk trade-off.

V

Verifiable credential

A tamper-proof, cryptographically signed digital attestation, whose data model (W3C Verifiable Credentials Data Model 2.0) has been a W3C recommendation since May 2025. It lets its holder prove an attribute, whether identity, entitlement or mandate, selectively and verifiably without querying the issuer online. A building block of the European identity wallet (eIDAS 2.0), it also underpins the mandates used by agentic payment protocols such as AP2.

Verification of Payee (VoP)

A check that the beneficiary name entered by the payer matches the actual holder of the IBAN, returning match, close match (the near name is displayed) or no match before the transfer is confirmed. It has been mandatory across the euro area since 9 October 2025 under the IPR regulation, on instant and ordinary transfers alike. It is the main weapon against fake bank-details fraud and keying errors; the EPC has standardised both scheme and interbank APIs.

Instant credit transfer

The everyday name for SCT Inst: funds are available to the beneficiary in under 10 seconds, at any hour, every day of the year. Since the IPR regulation it cannot be priced above an ordinary transfer, and is in practice free at most French banks since January 2025, which has sent its usage soaring. Its irrevocability makes it the prime target of manipulation fraud, hence the parallel obligation to run Verification of Payee.

W

Wallet

An electronic wallet. Two families exist: pass-through wallets (Apple Pay, Google Wallet), where the tokenised card (a DPAN) travels over the classic card rails, and staged or balance-holding wallets (PayPal, stored value accounts), which insert an account between the customer and the merchant. In France the OSMP pays particular attention to card enrolment into wallets, an identified fraud vector wherever it is poorly authenticated.

Wero

EPI's European payment wallet, built on instant account-to-account transfers: no card, therefore no interchange and no international scheme. Launched in 2024 for person-to-person payments (Germany, France, Belgium), it succeeds Paylib in France and is extending gradually to e-commerce and then to the point of sale over 2025-2027. It is the European banks' bet on payment sovereignty against Visa, Mastercard and the American wallets.

X

x402

An open payment protocol launched by Coinbase in May 2025, which revives the HTTP status code 402 Payment Required to embed payment natively in web exchanges. It enables per-request micropayments settled in stablecoins (USDC), with no account and no redirection, which makes it a rail of choice for AI agents and usage-billed APIs (including pay-per-crawl). It is one of the building blocks of a web where machines pay machines.