Reference🏛️ The payments ecosystemBeginner⏱ 16 min read

🧭 The four-party model

Cardholder, merchant, issuing bank, acquiring bank: how card payments are structured, with the scheme at the center.

Four corners, five players

The four-party model, also known as the four-corner model, has been the standard architecture for card payments since the 1970s. The name comes from the diagram used to depict it. The four corners are the cardholder, the merchant, the issuing bank, which is the cardholder’s bank, and the acquiring bank, which handles card acceptance for the merchant. In the center of the diagram sits a fifth player, the scheme (or network), such as CB, Visa, or Mastercard. It connects the other four and sets common rules for them.

👤
Cardholder
Holds the card and signs a cardholder agreement with their bank, which sets spending limits, the annual fee, and the terms of use. Never pays the merchant directly: the cardholder gives a payment instruction.
🏬
Merchant
Sells goods or services and accepts the card as a payment method under a card acceptance agreement (often called a merchant agreement) signed with its acquirer.
🏦
Issuing bank (issuer)
Issues the card to the cardholder, decides on every authorization, debits the cardholder’s account, and bears the credit risk and much of the fraud risk.
🏛️
Acquiring bank (acquirer)
Contracts with the merchant, collects its transactions, submits them for clearing, pays out the funds to the merchant, and charges it a fee (the MSC).
🔀
Scheme (network)
Sets the rules (acceptance, disputes, security), handles the routing of authorization messages and interbank clearing, and licenses issuers and acquirers.
Cardholderthe customer and their cardMerchantthe merchantIssuing bankissues the cardholder's cardAcquiring bankcollects on behalf of the merchantSchemeCB · Visa · Mastercard1 · Payment (card, wallet…)2 · Authorization request34567 · Approved (00)Account debitClearing & settlement (D+1) · interchangeAuthorization (~1 s)ResponseMoney flows (D+1)
🔑
The founding idea: interoperability
Interoperability means a card works regardless of which bank issued it and which bank serves the merchant. The four-party model achieves this by separating issuing from acquiring. Any card issued by any member bank is accepted at any merchant signed up with any member acquirer. The scheme guarantees this principle, and it explains why cards became universal. France processes more than 15 billion CB transactions a year (GIE CB, 2024).

The authorization flow: a few hundred milliseconds

The authorization flow is the exchange of messages through which the issuer approves or declines a transaction before the funds are collected. It is the first of the two circuits a card payment sets in motion; the second is the money flow described in the next section. The round trip happens in real time, typically 300 ms to 2 s end to end, and the answer is simply yes or no. No money moves at this stage. Only messages travel between the terminal, the acquirer, the scheme, and the issuer.

Authorizing an in-store card payment
Cardholder
Presents the card at the terminal (contact, contactless, or wallet)
The EMV chip generates a unique cryptogram (ARQC) for this transaction
POS terminal
Builds the authorization request and sends it to the acquirer
Amount, PAN, MCC, entry mode, EMV data (often through a payment switch)
Acquirer
Checks the message and routes it to the scheme
Technical checks: merchant is active, message format, acceptance limits
Scheme
Identifies the issuer from the BIN and forwards the request
The first 8 digits of the PAN (the BIN) identify the issuing bank
Issuer
Decides based on balance, limits, card blocks, fraud score, and cryptogram validation
Decision in 50 to 300 ms, often backed by a real-time scoring engine
Scheme → Acquirer → POS terminal
The response travels back down the chain: code 00 (approved) or a decline code
The receipt prints and the cardholder leaves, but their account has not been debited yet
Anatomy of an ISO 8583 authorization message (annotated, simplified)
0100                            MTI: authorization request
DE002  497010XXXXXX1234         PAN (card number, truncated here)
DE003  000000                   Processing code: purchase of goods/services
DE004  000000004250             Amount: EUR 42.50 (2 implied decimals)
DE007  0711093045               Transmission date/time (MMDDhhmmss)
DE018  5411                     MCC: grocery stores and supermarkets
DE022  051                      Entry mode: EMV chip + PIN
DE037  019200000042             RRN: unique transaction reference
DE041  TPE00042                 TID: terminal ID
DE042  000003560001             MID: merchant ID
DE055  9F26...                  EMV data, including the ARQC cryptogram

0110                            MTI: issuer response
DE038  A1B2C3                   Authorization code (keep it!)
DE039  00                       Response code: transaction approved
                                (05 = generic decline, 51 = insufficient
                                funds, 54 = expired card...)
⚠️
Authorization ≠ payment
An approved authorization holds the amount against the cardholder’s limit, and often against their available balance, but does not debit the account. It can expire without ever being submitted for clearing. The pre-authorizations used by hotels and gas stations rely on this principle. The reverse also happens. Some payments are cleared without online authorization: offline transactions below the EMV floor limits. The risk then falls on the merchant or the issuer, depending on the scheme’s rules.

Money flows: clearing and settlement

The money flow is the second circuit, the one through which funds actually move between banks. Authorization is immediate and handles one transaction at a time; the money flow is deferred and processed in bulk. At the end of the day, the merchant runs the end-of-day batch upload: the terminal sends the acquirer the day’s transactions as a single batch. The acquirer then submits those transactions for clearing, the stage where the scheme calculates multilateral net positions between banks. Settlement then takes place on the banks’ own accounts. In France, CB transactions clear through the CORE(FR) system run by STET, the French clearing house, and settle in central bank money through TARGET, the Eurosystem’s settlement system.

From receipt to merchant account
Merchant
End-of-day batch upload (D)
Sends the day’s transaction batch to the acquirer
Acquirer
Submits the transactions for clearing (D / D+1)
Clearing files sent to the scheme
Scheme
Calculates net positions and initiates settlement
Interchange is deducted at this stage: the acquirer receives the net amount
Issuer
Debits the cardholder’s account
Right away (immediate-debit card) or at month-end (deferred-debit card)
Acquirer
Credits the merchant’s account (typically D+1, business days)
Gross amount minus the MSC, per the contract
StepTimingWhat happens
AuthorizationReal time (< 2 s)Messages only; no money moves
End-of-day batch uploadD, end of dayTransaction batch sent to the acquirer
ClearingD to D+1Scheme calculates net interbank positions
SettlementD+1 (business day)Funds actually move between banks (central bank money)
Merchant payoutD+1 to D+3, per contractMerchant’s account credited, net or gross of fees
Cardholder debitD+1 or month-endDepends on immediate- or deferred-debit card
Typical timeline of a card transaction in France
ℹ️
Dual message vs. single message
In dual-message processing, a transaction generates an authorization message followed by a separate clearing message. Most European transactions work this way. Legacy debit networks, including Maestro and some US networks, use single-message processing: authorization and clearing are combined in one message, and the debit is immediate. The distinction still shapes technical formats, including for schemes migrating from ISO 8583 to ISO 20022.

Who pays what: interchange and fees

The merchant service charge (MSC) is what a merchant pays its acquirer on every card transaction. It holds the economics of the four-party model together: the revenue that the acquirer, the issuer, and the scheme earn on each transaction all comes out of it. The MSC has three components. The first is the interchange fee, which the acquirer passes on to the issuer. The second consists of the scheme fees charged by the network. The third is the acquirer’s margin, which pays for its service and its risk.

ComponentRecipientTypical rangePer €100
Interchange (IFR cap)Issuing bank0.20% (debit)0,20 €
Scheme feesNetwork (CB, Visa, Mastercard)0.05% to 0.15%≈ 0,10 €
Acquirer marginAcquirer / PSP0.10% to 0.50% + fixed fees≈ 0,25 €
Total MSC–≈ 0.3% to 0.8% card-present≈ 0,55 €
Typical MSC breakdown under interchange++ pricing (a €100 consumer debit card payment in France)
🔑
Which way interchange flows
Interchange is the fee paid by the acquirer to the issuer on every transaction. It compensates the issuer for the payment guarantee, fraud risk, and issuing services. The merchant ultimately bears it, because the acquirer passes it through in the MSC. Since the EU’s IFR of 2015, interchange has been capped at 0.2% for debit cards and 0.3% for consumer credit cards. Commercial (business) cards and three-party schemes are exempt from these caps.
0,2 %
EU interchange cap, consumer debit cards
Regulation (EU) 2015/751
0,3 %
EU interchange cap, consumer credit cards
Regulation (EU) 2015/751
≈ 0,5 %
Average card-present MSC in France (order of magnitude)
Industry estimates / Banque de France
> 15B
CB transactions per year in France
GIE CB, 2024 data
  • The cardholder pays an annual card fee and any other charges (withdrawals at other banks’ ATMs, currency conversion). In Europe, merchants may not surcharge consumer card payments at the point of sale (PSD2, Art. 62).
  • The merchant pays the MSC, the terminal rental or purchase, and any e-commerce gateway fees.
  • The issuer earns interchange plus cardholder fees. It pays for the card, fraud losses, authorization, and customer service.
  • The acquirer earns its margin. It carries the merchant risk (unpaid transactions, merchant failure before delivery, chargebacks).
  • The scheme charges membership and license fees, plus transaction fees on both sides (issuing and acquiring).

The three-party model: Amex, PayPal, and closed loops

In the three-party model (also called a closed loop), a single company acts as issuer, acquirer, and scheme at once. American Express is the classic example: Amex issues the cards, signs up merchants directly, and runs the network. PayPal applies the same logic to wallets, where both payer and payee hold PayPal accounts. A transaction there starts out as a set of internal book entries at PayPal.

Cardholderaccount holderMerchantaccepts the payment method1 · paymentClosed loop · three-party modelA single operatorit plays all three rolesissuernetwork and rulesacquirercardholder signs updebit or due datepayment submissionnet payoutno interchange to splitacceptance network built from scratchOne company sets the rules, carries the risk, and bills: the price can't be broken down.
CriterionFour-party (CB, Visa, Mastercard)Three-party (Amex, PayPal, Diners)
Cardholder relationshipIssuing bank (thousands of issuers)The scheme itself (direct relationship)
Merchant relationshipAcquiring bank / PSPThe scheme itself (or through licensees)
InterchangeExplicit; capped by the IFR in the EUNo formal interchange, but an all-in discount rate
Merchant cost≈ 0.3% to 0.8% card-present≈ 1.5% to 3% (Amex); 1.2% to 2.9% + fixed fee (PayPal)
DataSplit across players360° view of both sides of the transaction
UniversalityVery broad (interoperability)Narrower acceptance; must build its network alone
The two models compared
💳
Amex: the premium closed loop
Targets affluent customers, with generous rewards programs funded by a high discount rate. In Europe, Amex sometimes works through licensees (a hybrid known as the 3.5-party model), which can bring it back within the scope of the IFR.
🅿️
PayPal: the digital closed loop
A credit institution licensed in Luxembourg for the EU. Account top-ups often rely on the four-party model itself (cards) or on SEPA. Closed loops piggyback on interbank infrastructure.
ℹ️
Why IFR caps do not apply to Amex
The IFR caps interchange fees, meaning payment flows between an issuer and a separate acquirer. In a pure closed loop, no such flow exists in legal terms, because there are not two separate institutions on either side of the transaction. EU lawmakers therefore exempted three-party schemes from the caps. The exemption ends when such a scheme licenses third parties to issue or acquire cards; it is then treated as a four-party scheme.

Strengths and limits of the model

What the four-party model achieved

  • Universality: one card, tens of millions of acceptance points worldwide.
  • Competition at every corner: cardholders choose their issuer and merchants their acquirer, without breaking interoperability.
  • Payment guarantee: a merchant that follows the acceptance rules gets paid, even if the cardholder is insolvent or the card was used fraudulently.
  • Shared security: EMV, PCI DSS, 3-D Secure, and tokenization are rolled out across the entire network.

Its structural tensions

  • Pricing complexity: merchants struggle to break down their MSC. Scheme fees are not capped and have risen significantly (the UK’s Payment Systems Regulator, the PSR, documented increases of more than 30% over the five years from 2017 to 2022).
  • Reliance on international schemes: outside CB, Europe routes most of its payments through US networks. This sovereignty concern gave rise to the EPI/Wero project.
  • Race for scale: with four intermediaries per transaction, the infrastructure only pays off at massive volumes. Hence the consolidation of European acquirers and processors.
  • Friction from deferred settlement: the gap between real-time authorization and D+1 settlement creates risks (cancellations, disputes) that instant credit transfers avoid.
🔑
Key takeaways
The four-party model is a system of economic incentives as much as a technical infrastructure. Interchange, the payment guarantee, and dispute rules align four players whose interests diverge. Card payment regulation, led by the IFR, adjusts those incentives without breaking interoperability among network members.