Reference🛠️ Merchant setupIntermediate⏱ 16 min read

📝 Merchant agreements and onboarding

Card-present and card-not-present agreements, MIDs and TIDs, KYB, financial guarantees, payouts, termination, and the MATCH list: everything that happens before the first transaction.

Merchant agreements: card-present vs. card-not-present

The merchant agreement (or card acceptance agreement) binds the merchant to its acquirer. It authorizes the merchant to accept cards from one or more schemes (CB, Visa, Mastercard…). It sets the merchant service charge (MSC), payout timing, and security obligations. In France, accepting Cartes Bancaires (CB), the domestic card scheme, has traditionally required a CB membership agreement signed with an acquiring bank that belongs to GIE Cartes Bancaires, which processes more than 15 billion transactions a year.

Merchant agreements come in at least two very different forms: the card-present agreement (in person, POS terminal) and the card-not-present (CNP) agreement (remote sales). The risk the acquirer carries differs sharply from one to the other. According to the OSMP, the payment security observatory run by the Banque de France (France’s central bank), the card fraud rate is about 0.010% for in-person payments, vs. about 0.16% for remote sales. That is a factor of 16.

DimensionCard present (in person)Card not present (remote)
Acceptance channelCertified POS terminal (PCI PTS), contactless, SoftPOSPayment page, API, payment link, MOTO
Proof of consentPIN entry or tap (CDCVM)3-D Secure, security code, transaction data
Typical fraud rate (OSMP)≈ 0,010 %≈ 0,16 %
Default liabilityIssuer (chip-and-PIN authenticated transaction)Merchant, unless 3DS/liability shift
Required safeguardsRare (low risk)Common: rolling reserve, deposit, longer payout delay
KYB underwritingStandardEnhanced: delivery model, fulfillment lead time
Indicative MSC (France, SMEs)0,3 % – 0,8 %0.8%–2.0% + fixed fees per transaction
Key risk for the acquirerPOS terminal fraud, skimming (residual)Chargebacks + non-delivery risk (delivery risk)
Card-present vs. card-not-present agreements: the structural differences
🔑
An omnichannel merchant signs (at least) two agreements
A retailer that runs stores and an e-commerce site usually holds a separate card-present agreement and a separate CNP agreement, often with different acquirers. The MIDs are then distinct. Pricing, guarantees, and payout terms are negotiated separately for each agreement. Processing CNP traffic under a card-present agreement is a misrepresentation of business activity, which the acquirer punishes by terminating the agreement.
Cardholderthe customer and their cardMerchantthe merchantIssuing bankissues the cardholder's cardAcquiring bankcollects on behalf of the merchantSchemeCB · Visa · Mastercard1 · Payment (card, wallet…)2 · Authorization request34567 · Approved (00)Account debitClearing & settlement (D+1) · interchangeAuthorization (~1 s)ResponseMoney flows (D+1)

In the four-party model, the merchant agreement embodies the merchant ↔ acquirer corner. Everything the merchant negotiates, such as the MCC, guarantees, and payouts, falls under this contractual relationship. The costs it bears also flow through it, whether chargebacks or scheme fines that the acquirer passes on.

MIDs and TIDs: how identifiers are structured

The MID (Merchant ID) identifies the contractual point of acceptance with the acquirer and the schemes. The TID (Terminal ID) designates each logical terminal attached to a MID: a physical POS terminal, a checkout lane, but also an e-commerce “line.” A single merchant can hold dozens of MIDs and thousands of TIDs.

Legal entitySIREN (French company ID): one or more contractsCard-present contractAcquirer ACard-not-present contractAcquirer B, via a PSPMID 4571120001Paris Rivoli · MCC 5651TID 00000001 · register 1TID 00000002 · register 2MID 4571120002Lyon Part-Dieu · MCC 5651TID 00000001 · register 1MID 8890455001FR site · EUR settlementTID 01 · websiteMID 8890455002UK site · GBP settlementTID 01 · mobile app1 MID = 1 reporting unitscheme thresholds counted per MIDMCC declared at MID levelToo few MIDs = flying blind; too many MIDs = multiplied fixed fees and admin.
  • Legal entity (SIREN number in France, the French company ID, or the equivalent national registration number elsewhere) → one or more agreements with the acquirer;
  • MID → one per relevant combination: channel (card-present/CNP), store brand, country, settlement currency, sometimes MCC;
  • TID → one per logical terminal; in e-commerce, a TID can represent a platform, a site, or a channel (web/app).
Sample identifier hierarchy (omnichannel retailer)
Entity: MODETEX SAS (SIREN 512 345 678)
│
├── Card-present agreement — Acquirer A
│   ├── MID 4571120001  (Paris Rivoli store, MCC 5651 clothing)
│   │   ├── TID 00000001  (POS terminal, register 1)
│   │   └── TID 00000002  (POS terminal, register 2)
│   └── MID 4571120002  (Lyon Part-Dieu store, MCC 5651)
│       └── TID 00000001
│
└── CNP agreement — Acquirer B (via PSP)
    ├── MID 8890455001  (FR site, EUR settlement, MCC 5651)
    └── MID 8890455002  (UK site, GBP settlement, MCC 5651)

Rule of thumb: 1 MID = 1 unit for reporting, reconciliation,
and fraud rate monitoring. Too few MIDs = flying blind;
too many MIDs = fixed fees and admin multiplied.
⚠️
The MCC is not a formality
The acquirer declares the MCC (Merchant Category Code, 4 digits, ISO 18245) when it creates the MID. A wrong MCC exposes the merchant to repricing, since interchange and scheme fees depend on the MCC. It also triggers scheme fines (up to tens of thousands of euros for deliberate miscoding) and issuer declines, because corporate and fleet cards are configured by MCC. “High-risk” MCCs (7995 gambling, 5966 outbound telemarketing, 4722 travel agencies…) trigger enhanced underwriting and dedicated monitoring programs.

Standard practice is to separate MIDs at least by channel and by settlement currency. Authorization and fraud rates are then measured on consistent scopes, which makes them meaningful to track. A spike in chargebacks on the website stays confined to the CNP MID and leaves the card-present agreement untouched. This separation also makes a later move to multi-acquiring easier.

KYB: the onboarding process and required documents

KYB (Know Your Business) covers all the checks an acquirer runs to identify a merchant before opening card acceptance. It is the counterpart of KYC for legal entities. The acquirer is bound by it as an entity subject to AML/CFT rules. The obligation comes from the EU anti-money laundering directives, transposed in France into the Monetary and Financial Code and into each member state’s national law. The checks cover the merchant’s identity, its beneficial owners, and the real nature of its business.

  • Kbis extract (French company registration certificate, or the equivalent from a trade register) less than 3 months old;
  • Signed, up-to-date articles of association;
  • ID documents for directors and authorized representatives;
  • Beneficial ownership register: identification of anyone holding more than 25% of the capital or voting rights;
  • IBAN (with a RIB, the French bank account details form, in France) for the payout account, in the contracting entity’s name;
  • Proof of business activity: website URL, terms and conditions of sale, delivery and refund policy, any industry licenses;
  • Processing history (3 to 6 months of statements from the previous acquirer: volumes, chargeback rates) for existing merchants;
  • Financial statements (balance sheet, income statement) for large volumes or sectors with non-delivery risk.
The customer: SAS Alphalegal entity to identify (KYB)Holding Blegal entityMr. Dupontnatural personSCI Gammalegal entity60%20%20%Ms. Martinnatural personFund Dlegal entityMr. Dupontthe same natural person50%50%90%the same personbranch completelegal entity ⇒ keep going upMs. Martin: 60% × 50% = 30%Mr. Dupont: 20% + 20% × 90% = 38%over 25% ⇒ beneficial owneradd up every branchA branch that ends at a legal entity isn't finished: keep multiplying down to natural persons.
Typical onboarding process at an acquirer/PSP
Merchant
Submits the KYB application
Form + supporting documents + volume estimates
PSP / acquirer
Automated screening
Sanctions lists, PEPs, adverse media, MATCH/VMSS check
Underwriting team
Risk scoring
MCC, delivery model, fulfillment lead time, financial health, chargeback history
Risk committee
Decision and conditions
Approval, decline, or conditional approval (reserve, caps, payout delay)
Acquirer
MID/TID setup and scheme enrollment
MID registered with CB/Visa/Mastercard, MCC, currency, and descriptor configured
Merchant
Go-live
End-to-end testing, first transaction, enhanced monitoring period (30–90 days)
24–48 hrs
onboarding with a fully digital full-stack PSP (standard application)
market practice, 2025
2–6 wks
onboarding with a traditional bank acquirer
market practice, 2025
> 25 %
ownership threshold that triggers beneficial owner identification
EU Directive 2015/849
ℹ️
Underwriting is sector-specific
CNP underwriting focuses mainly on the time between payment and delivery of the goods or service, rather than on fraud risk. The sectors concerned are travel, ticketing, events, training, and made-to-order furniture. If the merchant goes bankrupt before delivering, cardholders get their money back through chargebacks, and the acquirer bears the cost. This delivery risk explains the guarantees described in the next section.

Financial guarantees and payout timing

The financial guarantees an acquirer requires are sums it withholds or freezes to protect itself against merchant default. Between the payment and the end of the chargeback window, the acquirer carries credit risk on the merchant: it will have to refund cardholders if the merchant can no longer do so. This window runs for 120 days after the transaction. For some Visa/Mastercard reason codes, the clock starts from the expected delivery or service date, up to a limit of 540 days after the transaction. The contractual guarantees that cover this risk are sized during underwriting and can be revised later.

InstrumentMechanismTypical rangeImpact on merchant cash flow
Rolling reserveA % withheld from each payout, released on a rolling basis5–10% withheld for 90–180 daysHigh: a permanent drain on working capital
Fixed security depositSum frozen at signing0.5 to 2 months of estimated volumeHigh, but capped and predictable
On-demand bank guaranteeGuarantee issued by the merchant’s bankNegotiated amount, costs 0.5–2%/yearLow in cash terms, uses up bank credit lines
Longer payout delaySettlement at D+7 to D+30 instead of D+1/D+2VariesEquivalent to an implicit reserve
Processing capsCap on monthly volume or ticket sizeSet in the agreementLimits growth; renegotiate quickly
Common guarantee instruments and typical sizes

The standard payout delay in France is D+1 to D+3 business days after clearing, on a net basis (gross amount – fees – chargebacks – reserve). Some PSPs offer daily or weekly payouts. Others trigger them when a threshold is reached. Every extra day of delay amounts to a cash facility the merchant grants its acquirer, since the collected funds stay with the acquirer.

⚠️
The trap of a poorly negotiated rolling reserve
A 10% rolling reserve over 180 days ties up, at cruising speed, ~5% of annual card revenue. For a low-margin online merchant, that amount can exceed the year’s net income. Negotiations cover four points: the rate, the rolling period, and review clauses that lower the reserve after 6–12 months of clean history. The fourth is what happens to the reserve on termination. On that last point, standard practice is to require release after the chargeback window, rather than leaving it to the acquirer’s discretion. In travel, some acquirers withhold up to 100% of funds until the departure date. Build this holdback into the cash flow plan before signing.
  • Check whether the reserve is calculated on the gross or the net amount;
  • Cap the reserve’s absolute amount in the agreement;
  • Require monthly reporting on the reserve balance and releases;
  • Include an automatic review clause for guarantees, indexed to the actual chargeback rate.

Termination and the MATCH list

Termination ends the merchant agreement and removes the merchant’s right to accept cards from the schemes concerned. Either the merchant or the acquirer can initiate it. On the merchant side, the contractual notice period is often 1 to 3 months, and the agreement may include exit fees and volume commitments. The acquirer, for its part, can terminate without notice in case of proven fraud, sustained breaches of the schemes’ chargeback program thresholds (VAMP at Visa, ECP at Mastercard), or misrepresentation of business activity.

A termination for risk reasons leads to a listing in an industry-wide file. A Mastercard acquirer is required to list the merchant in MATCH (Member Alert to Control High-risk merchants). Every acquirer checks it during onboarding. Visa runs an equivalent system (a terminated merchant file, historically TMF, now VMSS). The acquirer makes the listing with a reason code, and it stays visible for 5 years.

CodeReasonTypical situation
01Account data compromiseCard data compromised at the merchant
02Common point of purchaseThe merchant is identified as a common point of fraud
03LaunderingProcessing transactions on behalf of a third party (unauthorized factoring)
04Excessive chargebacksOver 1% of transactions and $5,000+ in chargebacks in a single month
05Excessive fraudFraud rate above the program thresholds
07Fraud convictionA principal convicted of fraud
09Bankruptcy / insolvencyInsolvency proceedings
10Violation of standardsBreach of Mastercard rules (MCC, illegal content…)
12PCI DSS non-compliancePersistent PCI DSS non-compliance
Main MATCH reason codes (Mastercard)
⚠️
MATCH: the blacklist that is nearly impossible to leave
A merchant listed in MATCH is virtually ineligible with any Mastercard acquirer for 5 years, and the few “high-risk” acquirers that accept it charge 3 to 10 times the market price. Only the acquirer that made the listing can remove or correct it, in case of a proven error or, for code 12, once the merchant is PCI compliant. The practice is therefore to settle open disputes with the current acquirer before switching. A termination that ends badly follows the merchant for 5 years.

When the acquirer threatens to terminate over chargebacks, the usual path is to negotiate a remediation plan. It combines tighter fraud rules, systematic 3DS, and a larger reserve. The agreement stays in force. The merchant thus avoids the MATCH listing that comes with a termination for risk reasons.

Choosing an acquirer or PSP: the evaluation grid

Card acceptance comes in two main delivery models. The bank acquirer sells a direct acquiring agreement, sometimes paired with a technical gateway. The full-stack PSP (Adyen, Stripe, Checkout.com, Worldline in its packaged offering…) combines gateway, acquiring, fraud prevention, and payouts in a single agreement. The first model optimizes unit cost at high volume, while the second prioritizes time to market and international coverage.

The merchantmerchant: signs the contractTechnical service providergateway, orchestrator, POS terminalFunds: never touches themLicense: noneScheme: noPSP agentacts on behalf of a licensed PSPFunds: in the PSP's nameLicense: registeredScheme: noCollecting PSPcollects on the merchant's behalfFunds: safeguardedLicense: ACPRScheme: via a sponsorAcquirernetwork member bank or PIFunds: until payoutLicense: CI or PIScheme: memberThe schemeCB · Visa · Mastercard: the rulesThree questions separate these four layers: who holds the funds, who holds the license, who is a scheme member.
CriterionQuestions to askApproximate size
PricingInterchange++ or blended? Fees on declines? Chargeback fees (€15–30 per dispute)? Monthly/per-MID fees?20 %
Payment success rateAuthorization rate observed on my BIN/country mix? Network token support? Soft decline handling? Verifiable benchmarks?20 %
CoverageSchemes (CB included?), local methods (iDEAL, Bancontact, Wero…), presentment and settlement currencies?15 %
Payouts & cashD+1/D+3 timing? Settlement currency? Reserves required? Usable settlement reporting (reconciliation files)?15 %
Risk & complianceFraud tools included? 3DS/TRA exemption management? Chargeback support (representment)?10 %
TechnicalAPI/docs quality, uptime (SLA ≥ 99.95%), webhooks, test environment, tokenization?10 %
ContractMinimum term? Notice period? Guarantee review clauses? Reversibility (token export!)?10 %
Acquirer/PSP selection grid (criteria, questions to ask, indicative weight)
🏪
Small merchant
A bundled bank offer or a simple PSP (terminal + light CNP). Prioritize simplicity, all-in pricing, and card processing built into the point of sale. Blended pricing is acceptable below ~€300,000 in annual card volume.
🛒
Growing online merchant
An international full-stack PSP, for payment method coverage, optimized 3DS, network tokens, and API reporting. Check token portability before signing, because that clause determines your future freedom.
🏬
Large retailer / platform
Multi-acquiring run through an orchestrator, with 2–3 acquirers, BIN/currency routing, interchange++ negotiation, and an in-house payments team. The agreement becomes a portfolio of agreements.
🔑
Interchange++ as soon as volume allows
With blended pricing, the merchant pays a single rate on all its transactions. That rate bundles interchange, scheme fees, and the acquirer’s margin, without showing the share of each component. In the EEA, the IFR (Regulation 2015/751) caps interchange at 0.2% (debit) and 0.3% (credit). With interchange++, each component is passed through at cost and the acquirer’s margin appears separately, which makes costs manageable line by line. Above ~€1 million in annual card volume, the second model almost always wins.