Reference⚙️ Card processing & networksAdvanced⏱ 20 min read

🔢 Card payment codes and identifiers

MCC, BIN/IIN, ARN, RRN, STAN, ECI, and transaction codes: the coded vocabulary of card payments, and how to read a receipt or a merchant statement

MCC: the merchant category code

The MCC (Merchant Category Code, ISO 18245) is a 4-digit code, assigned by the acquirer, that classifies the merchant's business. It travels in every authorization (DE18) and every clearing presentment. It drives a wide range of processing: interchange tables, program eligibility, stand-in limits, usage restrictions (corporate cards, teen cards), cardholder cashback, reporting obligations, and even regulatory blocks (gambling, crypto).

MCCCategorySpecifics
5411Supermarkets, grocery storesOften reduced interchange (large-retailer programs)
5812 / 5814Restaurants / fast foodUseful distinction for meal voucher cards (France's titres-restaurant)
5541 / 5542Gas stations / automated fuel dispensers (AFD)5542: capped pre-auth + mandatory partial capture
5912PharmaciesHealth programs, possible prepaid card restrictions
4111 / 4131Local transit / bus linesEMV transit: trip aggregation, dedicated no-CVM rules
4511 / 3000-3299Airlines (generic / carrier-specific codes)Every major airline has its own MCC
7011 / 3501-3999Hotels (generic / chains)Extended pre-auth, incremental auths, no-shows
6011ATM withdrawalsOutside the scope of merchant interchange
6051 / 6540Quasi-cash, crypto assets / wallet top-upsOften treated as cash advances: fees and issuer blocks
7995Gambling and bettingFrequently blocked, high volumes of response code 57
4814TelecomHigh share of recurring payments (subscriptions)
5999Miscellaneous retail“Catch-all” MCC, closely watched by acquirers
Common MCCs
⚠️
The wrong MCC is expensive
An incorrect MCC has three separate effects: the wrong interchange, often overpaid; unjustified issuer declines when the cardholder or issuer blocks that MCC; and above all the risk of reclassification by the scheme, with fines. Hiding a business behind an innocuous MCC (transaction laundering) violates network rules. Conversely, some MCCs qualify for reduced interchange rates, so it pays to check the MCC in your merchant agreement.
  • The MCC is assigned per merchant agreement: a merchant with several lines of business can have several agreements or MIDs with different MCCs.
  • Issuers rely on the MCC for parental controls, corporate cards (permitted categories), and cashback programs.
  • In reporting, cross-referencing MCC and approval rate reveals specific pockets of declines (e.g., MCC 6051 declined more often by some issuers).

BIN / IIN: identifying the issuer

The first digits of the PAN form the IIN (Issuer Identification Number, ISO/IEC 7812), commonly called the BIN. Historically 6 digits long, the standard moved to 8 digits in April 2022 to deal with a shortage of ranges. The first digit (MII) indicates the family: 4 = Visa, 5 (and 2221–2720) = Mastercard, 3 = Amex/Diners/JCB, 6 = Discover/UnionPay, and so on. The BIN drives routing, meaning which issuer the authorization is sent to. It also feeds the BIN tables that PSPs use to detect the issuing country, card type (debit/credit, consumer/commercial), and co-badged brands.

PrefixBrandPAN length
4xxxxxVisa16 (sometimes 13/19)
51-55, 2221-2720Mastercard16
34, 37American Express15
6011, 644-649, 65Discover16-19
35 (3528-3589)JCB16-19
62UnionPay16-19
–Cartes Bancaires (CB)No range of its own: co-badged cards use Visa/Mastercard ranges; CB membership shows up in BIN tables
Common number ranges
Anatomy of a PAN (fictitious number)
PAN : 4 9 7 0 1 0 1 2 3 4 5 6 7 8 9 0
      |_____________|                     IIN/BIN, 8 digits: 49701012
      |                                   MII: 4 = Visa
                      |___________|       individual account identifier
                                    |     Luhn check digit (modulo 10 check)

Luhn check (right -> left):
  double every second digit, subtract 9 if > 9,
  add everything up: total % 10 == 0  =>  PAN is structurally valid.
Caution: Luhn validates the FORMAT, not whether the account exists
(response code 14 "invalid card number" is still possible).
ℹ️
8-digit BINs and their side effects
The move from 6-digit to 8-digit BINs broke many systems without any visible error: prefix-based fraud rules, PCI truncation, and local routing tables. The traditional “first 6 + last 4” no longer identifies the issuer. The PCI SSC now allows “first 8 + last 4” for PANs of at least 16 digits. Business logic built on “the first 6 digits” still needs to be reviewed in legacy systems.

ARN, RRN, STAN: tracing a transaction

A single transaction carries several distinct identifiers, which vary by processing stage and by the party that generates them. Each has its own scope: some only last for an authorization session, others survive until a dispute reaches arbitration. Telling them apart is essential for reconciliation and dispute management. Quote the wrong reference and the recipient won't find a match.

IdentifierFormatGenerated byUsed for
STAN (DE11)6 digits, cycles per terminal/sessionTerminal or acquirer hostMatch request, response, and reversal within the authorization session
RRN (DE37)12 characters (often YDDD + hour + STAN)Acquirer / switchShared lookup reference, authorization ↔ clearing
Authorization code (DE38)6 alphanumeric charactersIssuer (or stand-in)Proof of authorization; printed on the receipt
ARN23 digitsAcquirer, at clearing presentmentTHE end-to-end reference: settlement, chargebacks, arbitration
TID (DE41) / MID (DE42)8 / 15 charactersAcquirer (agreement)Identify the terminal and the merchant agreement
Scheme transaction IDVaries by network (e.g., Banknet ref + date)SchemeInternal network references, tokenization, MIT (merchant-initiated transactions)
Transaction identifiers
Breaking down an ARN (Acquirer Reference Number, 23 digits)
ARN : 2 433261 6192 00000123456 7
      |                              format: 2 = acquirer presentment
        |____|                       acquirer BIN (6 digits)
               |__|                  Julian date YDDD: 6192
                                     = year ...6, day 192 = 2026-07-11
                    |_________|      sequence number / film locator
                                |    check digit (Luhn)

Use: the ARN is what the issuer and the acquirer quote in
a chargeback or a retrieval request. Without an ARN, no
arbitration with the scheme is possible.
🔑
Which reference goes to whom?
A cardholder disputing a charge gets the date, the amount, the last 4 digits, and the descriptor. The acquirer asks for the RRN, the authorization code, and the TID/MID. The scheme (disputes, arbitration) requires the ARN, the only reference that stays stable after clearing. Internally, the system's order ID is mapped to all of the above. That mapping table is the foundation of any automated reconciliation.

ECI: the e-commerce authentication indicator

The ECI (Electronic Commerce Indicator) describes the authentication level of a card-not-present transaction: full 3-D Secure, attempted, or none. It determines the liability shift. On a properly authenticated transaction, stolen or compromised card fraud is the issuer's loss, not the merchant's. Each scheme uses its own scale, so the same authentication outcome carries a different code at Visa and at Mastercard.

Browserdevice data (~130 fields)3DS Servermerchant / PSP sideDSscheme directory serverACSissuing bankcollectionAReqAReqFrictionless≈ 90–95% of transactionsChallengeOTP, banking app, biometricsARes = Y (low risk)ARes = CCReq / CResThe customer authenticatesthrough their bankAuthentication successfulliability shift → the issuer bears the fraudRich, consistent data= more frictionless
CaseVisa / CBMastercardFraud liability
Successful 3DS authentication (frictionless or challenge)0502Issuer (liability shift applies)
Attempt: cardholder/issuer not enrolled, ACS unavailable (attempt)0601Issuer (per scheme rules)
No authentication (or 3DS failed but the transaction went ahead)0700Merchant
SCA exemption requested by the acquirer (TRA, low value, etc.)07 + exemption indicator00/06 + indicatorMerchant (the exemption does not shift liability)
MIT / transaction outside SCA scope (MOTO, one-leg-out)07 + MIT flags00 + MIT flagsMerchant, except in special cases
ECI values in e-commerce
⚠️
Exemption ≠ liability shift
A transaction exempted from SCA (acquirer TRA, low value) goes through without friction, but its ECI stays 07/00. If it turns out to be fraud, the merchant pays. Choosing between an exemption and authentication therefore means weighing the conversion gain against the expected cost of fraud and chargebacks. Some PSPs make that call transaction by transaction, based on the risk score and each issuer's observed behavior.

Transaction codes: the language of clearing

In clearing, every record carries a transaction code that identifies what kind of record it is. At Visa (Base II format) these are TCs, while at Mastercard (IPM) the MTI + function code combination plays the same role. These codes structure every clearing file and acquirer report, so you need to know them to read those files.

MTI 0100bitmap: which DEs are presentData elements presentAcquirerIssuer0100: authorization requestfunds held, no money moves0110: response (DE39 + DE38)00 approved · 05 declined · 51 insufficient funds0420: reversal advicecancels the phantom authorization0430: reversal responseno acknowledgment: repeat as 0421 (store-and-forward)0200/0210: financial requestauthorization + capture in a single message (ATM withdrawal)0100 left unansweredtimeout: 30 to 60 s at the terminalNEVER assume a decline0400/0410 · online reversal0800/0810 · sign-on, echo testMost “double charges” are a phantom authorization that was never reversed, followed by a successful retry.A field exists only if its bit is set in the bitmap; a retry carries a new STAN.
TCTypeDirection of funds
TC05Sale (sales draft)Issuer → acquirer
TC06Credit / refund (credit voucher)Acquirer → issuer
TC07Cash advance (cash disbursement)Issuer → acquirer
TC15 / 16 / 17Chargeback of a TC05 / TC06 / TC07Opposite of the original
TC25 / 26 / 27Presentment reversal of a TC05 / 06 / 07Cancels out the original
TC40Issuer fraud report (fraud advice)Informational; feeds scores and monitoring programs
TC10 / TC20Fee collection / funds disbursementVaries
Key Visa Base II transaction codes

Mastercard uses the following IPM equivalents. 1240 with function code 200 = first presentment, the equivalent of Visa's TC05. Then 1240/205 = second presentment, 1442/450-453 = chargeback and later cycles, 1740 = miscellaneous fees (fee collection), and 1644/603 = documentation request (retrieval request). Acquirer reports aggregate these records; breaking them back down to the individual record shows the underlying transactions.

ℹ️
TC40 / SAFE: the fraud radar
Every fraud a cardholder reports generates a TC40 (Visa) or a SAFE record (Mastercard), even without a chargeback. The schemes use them for their monitoring programs: VAMP at Visa, which replaced VFMP and VDMP in 2025, and ECP and EFM at Mastercard. A merchant can therefore be penalized for excessive reported fraud even while its chargeback rate stays within the thresholds. TC40s and chargebacks don't count the same events.

Reading a receipt and a merchant statement

The codes described above appear on two everyday documents: the receipt (sales slip), printed or digital, and the acquirer's monthly merchant statement. The first documents a single transaction. The second covers a full month of activity and the related billing.

Legal entitySIREN (French company ID): one or more contractsCard-present contractAcquirer ACard-not-present contractAcquirer B, via a PSPMID 4571120001Paris Rivoli · MCC 5651TID 00000001 · register 1TID 00000002 · register 2MID 4571120002Lyon Part-Dieu · MCC 5651TID 00000001 · register 1MID 8890455001FR site · EUR settlementTID 01 · websiteMID 8890455002UK site · GBP settlementTID 01 · mobile app1 MID = 1 reporting unitscheme thresholds counted per MIDMCC declared at MID levelToo few MIDs = flying blind; too many MIDs = multiplied fixed fees and admin.
CB merchant receipt, annotated line by line
        CARD PAYMENT
       CB CONTACTLESS             technology used (contact/contactless)
ON 07/11/26 AT 12:34:56           transaction date and time
DUPONT BAKERY                     merchant name (DE43)
75011 PARIS
1234567                           merchant contract number (MID)
00012345                          terminal number (TID)
############1234                  masked PAN (last 4 digits only)
A0000000421010  CB                AID: selected application (CB here)
                                  -> on a co-badged card, "VISA DEBIT" here
                                     would signal routing to the international brand
AUTH NO: 123456                   issuer authorization code (DE38)
001234  000012                    batch number / transaction number (STAN)
AMOUNT =
              12.50 EUR
DEBIT                             transaction direction (DEBIT/CREDIT)
      MERCHANT COPY               copy (merchant / customer)
   KEEP FOR 13 MONTHS             recommended retention period (disputes)
  • The AID reveals the routing: A0000000421010 = CB, A0000000031010 = Visa, A0000000041010 = Mastercard. On a co-badged card, this is where you see which brand was actually used, and therefore the cost (see the interchange topic).
  • The authorization code is printed on the receipt: it's what gets matched against the cardholder's bank statement when a customer disputes a payment they don't recognize.
  • Masked PAN: a merchant receipt that shows more than the last 4 digits (or an expiration date) indicates a noncompliant terminal and should be escalated immediately.
  • Contactless with no PIN line: a no-CVM transaction, which is easier to dispute; receipts for PIN transactions mention the verification.
Statement lineWhat it isWhat to check
Volume and count by brand (CB / Visa / MC)Actual routing mixUnusually low CB share = co-badging cost leak
Fees by card categoryItemized MSC (if unblended pricing was requested)Consistency with the contract price list, creep in commercial card share
Scheme fees passed throughNetwork lines (authorization, clearing, brand)Compare month over month: quiet increases are common
ChargebacksDisputes debited, plus handling feesMatch each ARN to its dispute
POS terminal rental, fixed fees, end-of-day batch uploadInfrastructure costsBilling for returned terminals, duplicate charges
Monthly merchant statement: the lines to check
🔑
A no-budget audit for savvy merchants
Together, the receipt, the batch journal, and the merchant statement cover 90% of a card acceptance audit for a merchant. They show how co-badged cards are routed (AID on receipts), the true cost per transaction (statement ÷ volume), funding times (batch to credit transfer), and disputes (ARN). These checks rely on the codes described above and require no expensive tools.