Reference🏛️ The payments ecosystemIntermediate⏱ 17 min read

🔗 Merchant, acquirer, PSP

Gateway, processor, payment facilitator, payment institution: a precise map of the acceptance chain and its regulatory statuses.

Three roles that are often confused

Three distinct terms describe the players in the acceptance chain, and everyday usage often blurs them. The merchant (the “card acceptor” in scheme and ISO 8583 terms) is the business that accepts a payment instrument. The acquirer is the licensed provider that contracts with the merchant, carries the payment guarantee, and represents the merchant in the card schemes. PSP (payment service provider) is the EU legal category covering every firm licensed to provide payment services: banks, payment institutions, and e-money institutions.

🏬
Merchant
The business selling goods or services. It needs no license to accept payments, since it is a customer of an acquiring service. Its obligations are contractual (acceptance rules) and security-related (PCI DSS for card data).
🏛️
Acquirer
In scheme terms, the acquirer is the licensed acquiring member that submits transactions for clearing and guarantees settlement. Under PSD2, the term covers the PSP that provides the service of “acquiring of payment transactions” (Annex I, service 5).
⚙️
PSP
A generic term. In commercial usage, “PSP” often refers to an online merchant's technical and commercial provider (Stripe, Payplug, Mollie…), which may or may not be the acquirer in the strict sense.
The merchantmerchant: signs the contractTechnical service providergateway, orchestrator, POS terminalFunds: never touches themLicense: noneScheme: noPSP agentacts on behalf of a licensed PSPFunds: in the PSP's nameLicense: registeredScheme: noCollecting PSPcollects on the merchant's behalfFunds: safeguardedLicense: ACPRScheme: via a sponsorAcquirernetwork member bank or PIFunds: until payoutLicense: CI or PIScheme: memberThe schemeCB · Visa · Mastercard: the rulesThree questions separate these four layers: who holds the funds, who holds the license, who is a scheme member.
🔑
The question that sorts it all out
Three criteria place any firm in the acceptance chain. The first is the license it holds, and exactly what kind. The second is its scheme membership on the acquiring side. The third is whether it holds the funds between collection and payout. Together, these criteria separate a purely technical provider from a full-fledged acquirer.

Gateway, processor, payment facilitator

Three technical functions sit between the merchant and the acquirer. The gateway is the entry point: it collects the transaction from a payment page, an API, or a terminal, secures it, and routes it. The processor handles card processing on behalf of an acquirer or an issuer, which covers scheme connectivity, authorization, clearing, and file management. The payment facilitator (PayFac) is a contractual model in which a company signs up with an acquirer as a “master merchant,” then aggregates under its own contract the sub-merchants it onboards itself.

RoleFunctionHolds funds?License requiredExamples
Payment gatewayCollection, security (tokenization), routing to one or more acquirersNoNone (technical provider) if it never takes possession of fundsCybersource, PayZen, Axepta
ProcessorCard processing: authorization, clearing, back office for acquirers and issuersNo (acts on behalf of a client)None of its own, but supervised through its client (and the ECB's PISA framework)Worldline Financial Services, equens, TSYS
PayFacAggregates sub-merchants under its own acquiring contract, handles onboarding and payoutsYes (typically)PI or EMI as soon as it handles fundsStripe, Square, Mollie, SumUp
Full acquirerScheme member, payment guarantee, clears in its own nameYesCredit institution or payment institution + scheme licenseAdyen, Worldline, Crédit Agricole, Nexi
Functional comparison
An e-commerce transaction through the chain
Customer
Confirms the cart and enters card details on the payment page
The page is often hosted by the gateway (reducing the merchant's PCI DSS scope)
Payment gateway
Tokenizes the card and triggers 3-D Secure if required
The PAN never touches the merchant's servers
PSP / PayFac
Applies the merchant's routing and risk rules
Acquirer selection, retry logic, orchestration if used
Acquirer
Submits the authorization to the scheme
Under interchange++ or blended pricing, depending on the contract
Scheme
Routes to the issuer and returns the response
Issuer
Approves (or declines) and holds the funds
PSP
Notifies the merchant (webhook); will pay out at D+1 to D+3
Net or gross payout, with a reconciliation file
⚠️
The schemes' PayFac threshold
Visa and Mastercard rules require a sub-merchant that exceeds a certain annual volume, around $1M in transactions, to leave the aggregated model. It then signs a direct acquiring agreement and receives its own merchant ID. The move changes the merchant's pricing, its payment guarantee, and its reconciliation, so a fast-growing merchant on a PayFac should plan for it.
Creating a payment through a modern PSP's API (annotated example)
POST /v1/payments HTTP/1.1
Host: api.psp-example.com
Authorization: Bearer sk_live_51Hx...        <- merchant's secret key
Idempotency-Key: ord-2026-88412-p1           <- safe retry, no double charge

{
  "amount": 4990,                            <- EUR 49.90 in cents
  "currency": "EUR",
  "payment_method_types": ["card", "wero"],  <- methods offered to the customer
  "capture_method": "automatic",             <- or "manual" (pre-authorization)
  "statement_descriptor": "SHOP-XYZ",        <- text on the cardholder statement
  "metadata": { "order_id": "ORD-2026-88412" }
}

--> 201 Created
{
  "id": "pay_9f2c...",
  "status": "requires_action",               <- 3-D Secure triggered
  "next_action": { "type": "redirect_to_url", "url": "https://..." }
}

Regulatory status: PIs, EMIs, licensing, and passporting

A license becomes mandatory as soon as a firm takes possession of funds or provides a payment service listed in Annex I of PSD2. In France, the ACPR (Autorité de contrôle prudentiel et de résolution, the banking supervisor attached to the Banque de France, France's central bank) grants this license and supervises licensed firms. A license obtained in one member state works as a European passport, giving its holder the freedom to establish and to provide services throughout the EU.

License typeWhat it allowsMinimum initial capitalExamples
Credit institution (bank)All payment services + deposits + lending€5M (plus full prudential requirements)BNP Paribas, Adyen (banking license)
Payment institution (PI)Annex I payment services: acquiring, transfers, executing transactions…€20K (money remittance), €50K (initiation), €125K (full services, including acquiring)Payplug, Alma, Lemonway, Worldline France (PI entities)
E-money institution (EMI)Issuing e-money + payment services€350KTreezor, MangoPay (Luxembourg), Stripe (Ireland)
Account information service provider (AISP)Account aggregation only (registration, not full authorization)No capital: professional indemnity insuranceOpen banking aggregators
Overview of license types (initial capital requirements, PSD2/EMD2)
  • Safeguarding: a PI or EMI must protect customer funds through dedicated safeguarding accounts at a credit institution, investment in secure assets, or an insurance guarantee (Article L522-17 of the French Monetary and Financial Code for PIs, with an equivalent regime in Article L526-32 for EMIs). Customer funds are thus ring-fenced from the provider's insolvency.
  • Agents and distributors: a PI can operate through agents (registered with the national regulator, the ACPR in France) and an EMI through distributors. This setup is the legal foundation of banking as a service.
  • Exemptions: limited networks (single-brand gift cards), a commercial agent acting for only one of the two parties, intragroup transactions. Exemptions are interpreted narrowly and monitored by the national regulator (the ACPR in France).
  • The passport does not exempt firms from local anti-money laundering rules or, in practice, from closer host-country supervision of systemic players.
ℹ️
Why so many PSPs are based in Luxembourg, Ireland, or Lithuania
The European passport lets each firm choose its licensing authority, which explains why licenses are concentrated in a handful of member states. PayPal, licensed as a credit institution, and Amazon Payments are based in Luxembourg, Stripe is licensed as an EMI in Ireland, and a wave of fintechs obtained licenses in Lithuania. Since Brexit, UK firms have had to license an entity in the EU-27 to keep their passporting rights. Checkout.com and Revolut, among others, have strengthened their European entities.

Marketplaces: collecting payments on behalf of third parties

A marketplace collects the buyer's payment and then pays the corresponding share to third-party sellers. This collection on behalf of third parties is a payment service under EU law. PSD1 tolerated a broad reading of the “commercial agent” exemption, but PSD2 narrowed it to an agent acting for only one of the parties, the buyer or the seller. A marketplace that sits between the two can no longer rely on it, and must either get licensed or partner with a licensed provider.

⚠️
A legal risk that is easy to underestimate
In France, providing payment services without a license is a criminal offense: the unlawful practice of the profession of payment service provider. The ACPR issued formal notices to several platforms on this basis after 2018. Any marketplace, crowdfunding platform, or solution that collects and then redistributes funds must therefore structure its flows before launch.
Funds flow in a compliant marketplace (through a partner PI or EMI)
Buyer
Pays €100 on the marketplace
The payment is collected by the licensed PSP, not by the marketplace
Licensed PSP (PI/EMI)
Collects and safeguards the funds
Safeguarding accounts: the funds never become the platform's assets
Licensed PSP
Splits the payment: €85 to the seller, €15 commission to the marketplace
Split driven by API according to the platform's rules
Third-party seller
Receives the payout after the contractual delay
Often conditional on delivery or on the end of the cooling-off period
  • Option 1, own license: the platform becomes a PI or EMI (heavy: capital, compliance, ongoing AML/CFT). The choice of the very largest players (major integrated marketplaces).
  • Option 2, a PSP for platforms: MangoPay, Lemonway, Stripe Connect, and Adyen for Platforms carry the license, the safeguarding, and seller KYC. The dominant model.
  • Option 3, becoming an agent of a PI: the platform operates under a third party's license and is registered with the national regulator (the ACPR in France).
  • In every case, seller KYC (including beneficial owners) is unavoidable before paying out funds, and it is often the biggest operational workload.

Market map: who really does what

In the market, the “PSP” label covers very different profiles, which can be told apart by their degree of vertical integration. A full-stack player owns the gateway, the processing, and the acquiring license, so it handles the transaction end to end. A layered player owns only part of that chain and relies on third-party acquirers for the rest.

CompanyLicense typeModelHighlights
AdyenEuropean banking license (2017)Full-stack: gateway + processing + in-house acquiring, single platformLarge international accounts (Uber, Spotify…), unified commerce, no PayFac-style rolling reserve
StripeEMI (Ireland) + acquiring licensesPayFac turned acquirer, API-firstDe facto standard for developers, Connect for platforms, blended pricing by default
WorldlineCredit institution or PI, depending on the entityPan-European processor and acquirer spun off from Atos, merged with Ingenico (2020)Europe's largest acquirer by volume, processing for banks, terminals
NexiBank/PI (Italy)European consolidator: Italy, the Nordics, Central and Eastern Europe (Nets, SIA)Strong domestic acquiring in Italy and the Nordics
PayplugFrench PI (BPCE group)E-commerce and omnichannel PSP, native acquiring for Cartes Bancaires (CB), France's domestic schemeFocus on French SMEs and mid-caps, deep CB expertise
MolliePI (Netherlands)European PayFac focused on SMBsEasy onboarding, local European payment methods
Checkout.comEMI/PI (UK + EU)Full-stack, focused on large digital merchantsStrong crypto/digital presence, IC++ pricing
Positioning of representative players (as of 2026)
🔑
Full-stack vs. orchestration
Over 2024–2026, large merchants have stopped relying on a single PSP. They orchestrate several acquirers behind a routing layer, supplied by an orchestrator such as Primer or built in-house, to optimize authorization rates, costs, and resilience. Full-stack PSPs are responding by opening their gateways to third-party acquirers. Gateway, processing, and acquiring functions are being recombined from one provider to the next, and the lines between the layers are blurring.
≈ €175B
E-commerce sales in France in 2024 (goods and services)
FEVAD, 2025
> 40
Payment methods a pan-European PSP typically needs to support (cards, wallets, transfers, BNPL…)
Industry observations
1-3 %
Gap in authorization rates observed between acquirers on the same traffic, the real prize of orchestration
Orchestrator studies, 2024–2025

Choosing a PSP: the criteria that matter

How to assess an acquiring contract

  • Pricing: blended (a single all-in rate, easy to read but opaque) vs. interchange++ (actual interchange + actual scheme fees + a stated markup, transparent but variable). Above roughly €1M in annual card volume, IC++ almost always comes out ahead.
  • Authorization rates: ask for rates by country, scheme, and segment on comparable traffic; 1 percentage point of approvals is often worth more than 10 bps of fees.
  • Payout timing and currency, multicurrency handling, and FX fees.
  • Payment methods: coverage of wallets, bank transfers (including Wero), BNPL, and local methods in target countries.
  • Risk and dispute management: fraud tools included or billed separately, chargeback alerts, representment support.
  • Exit options: portability of card tokens (network tokens or PCI export), exit clauses, dependence on a single contract.
€100 paymentconsumer debit card, domesticthe acquirer deducts the MSCMSC (merchant service charge)withheld by the acquirer from the gross amountpaid to the merchantNet collected€100 − MSC, paid to the merchant3 separate recipientsInterchange→ the cardholder's issuing bankcap: 0.20% debit · 0.30% creditNetwork fees (scheme fees)→ Visa · Mastercard · CBno cap · network price listAcquirer / PSP margin→ acquirer, PSP, resellerthe only negotiable linecaps: Regulation (EU) 2015/751capped by lawfree: network price listnegotiable with the PSPcommercial card or non-EEA: no cap at all
ModelQuotedActual breakdownCost on €100
Blended1,2 % + 0,25 €Interchange 0.20% + scheme ≈ 0.10% + markup ≈ 0.90% + €0.251,45 €
Interchange++IC + SF + 0.35%Interchange 0.20% + scheme ≈ 0.10% + markup 0.35%0,65 €
Blended vs. interchange++ on a €100 order (CB debit card, e-commerce, orders of magnitude)
⚠️
Comparing two blended offers requires knowing the merchant's card mix: how its traffic splits between debit and credit, consumer and commercial cards, and domestic and international cards. Interchange and scheme fees vary across these categories, so the same headline rate can hide markups that differ by a factor of three from one merchant to the next.

Elsewhere in the world. The same mechanism, elsewhere.

The license required of a firm that takes possession of funds

In the US, there is no federal license equivalent to the EU payment institution. A nonbank PSP registers as a money services business with FinCEN, then obtains a money transmitter license from each state regulator, with net worth, surety bond, and permissible investment requirements set state by state. Since 2021, the Conference of State Bank Supervisors (CSBS) has promoted a model harmonization law, the Money Transmission Modernization Act, which 31 states have adopted in full or in part.

https://www.csbs.org/csbs-money-transmission-modernization-act-mtma

Singapore

In Singapore, the Payment Services Act 2019 replaces the PI/EMI pair with two licenses issued by the Monetary Authority of Singapore: the Standard Payment Institution (S$100,000 in base capital, capped at S$3 million in monthly transactions per service and S$5 million in e-money outstanding) and the Major Payment Institution (S$250,000 in base capital, no volume cap, and a security deposit with MAS).

Monetary Authority of Singapore, Guidelines on Licensing for Payment Service Providers (PS-G01) — https://www.mas.gov.sg/-/media/mas-media-library/regulation/guidelines/pso/ps-g01-guidelines-on-licensing-for-payment-service-providers/guidelines-on-licensing-for-payment-service-providers-updated-8-oct-2025.pdf

India

In India, a nonbank payment aggregator (the functional equivalent of a PayFac) must be authorized by the Reserve Bank of India, with a net worth of at least ₹15 crore when it applies and ₹25 crore by the end of the third financial year after authorization, maintained at all times. Banks carry out this activity without separate authorization.

Reserve Bank of India, Regulation of Payment Aggregators — Directions, 2025 (rbi.org.in)

After Brexit, the UK kept an architecture close to the EU's. An authorized payment institution is licensed by the FCA under the Payment Services Regulations 2017, with initial capital of €125,000 for services 1 to 5 (including acquiring), €50,000 for payment initiation only, and €20,000 for money remittance only.

https://www.fca.org.uk/publication/finalised-guidance/payment-services-electronic-money-approach.pdf

Protecting funds collected on behalf of third parties

In the UK, regulation 23 of the Payment Services Regulations 2017 requires a PSP to place the funds it receives in a separate safeguarding account with a credit institution, or to cover them with insurance or a guarantee, and never to use them on its own account. Small payment institutions are exempt, which is why it matters to check a provider's exact status.

https://www.fca.org.uk/firms/emi-payment-institutions-safeguarding-requirements

Brazil

In Brazil, Article 12 of Law 12.865/2013 makes e-money balances a segregated estate, out of reach of the issuer's creditors. The Banco Central also requires those balances to be held in full either as cash in a dedicated account at the central bank or in federal government securities registered with Selic.

https://www.planalto.gov.br/ccivil_03/_ato2011-2014/2013/lei/l12865.htm

Canada

In Canada, fund protection comes through registration rather than licensing. The Retail Payment Activities Act requires payment service providers to register with the Bank of Canada, and the obligations on operational risk management and safeguarding end-user funds took effect on September 8, 2025.

https://www.bankofcanada.ca/core-functions/retail-payments-supervision/retail-payments-supervision-key-milestones/

India

In India, an authorized aggregator must hold the amounts collected on behalf of merchants in an escrow account with a scheduled commercial bank. The Reserve Bank of India sets the permitted debits and credits on that account and the deadlines for paying merchants, and the account cannot receive any other flows.

Reserve Bank of India, Regulation of Payment Aggregators — Directions, 2025 (rbi.org.in)

The geographic reach of a payment license

The US has no passport. Licenses are issued state by state, so a nationwide acquirer or PayFac ends up holding around 50 licenses, processed through the Nationwide Multistate Licensing System (NMLS). Harmonization advances only through voluntary adoption of a model law, the Money Transmission Modernization Act, which 31 states have adopted in full or in part.

https://www.csbs.org/csbs-money-transmission-modernization-act-mtma

Canada

Canada has a single federal register. The Retail Payment Activities Act opened registration of payment service providers with the Bank of Canada from November 1 to 15, 2024, including for companies based outside Canada that serve Canadian users. Since then, the Bank has published notices of violation against noncompliant providers.

https://www.bankofcanada.ca/core-functions/retail-payments-supervision/supervisory-framework-registration/

Singapore

In Singapore, a single license issued by the Monetary Authority of Singapore under the Payment Services Act 2019 covers the whole country and the payment services expressly listed on the license. Extending its scope requires a new application to MAS, and the license has no effect outside Singapore.

Monetary Authority of Singapore, Guidelines on Licensing for Payment Service Providers (PS-G01) — https://www.mas.gov.sg/regulation/payments/licensing-for-payment-service-providers

India

In India, an authorization granted by the Reserve Bank of India under the Payment and Settlement Systems Act 2007 is valid nationwide, but it is segmented by activity. An aggregator that wants to handle cross-border flows needs a separate cross-border payment aggregator authorization, which comes with per-transaction amount limits.

Reserve Bank of India, Regulation of Payment Aggregators — Directions, 2025 (rbi.org.in)