Merchant agreements: card-present vs. card-not-present
The merchant agreement (or card acceptance agreement) binds the merchant to its acquirer. It authorizes the merchant to accept cards from one or more schemes (CB, Visa, Mastercard…). It sets the merchant service charge (MSC), payout timing, and security obligations. In France, accepting Cartes Bancaires (CB), the domestic card scheme, has traditionally required a CB membership agreement signed with an acquiring bank that belongs to GIE Cartes Bancaires, which processes more than 15 billion transactions a year.
Merchant agreements come in at least two very different forms: the card-present agreement (in person, POS terminal) and the card-not-present (CNP) agreement (remote sales). The risk the acquirer carries differs sharply from one to the other. According to the OSMP, the payment security observatory run by the Banque de France (France’s central bank), the card fraud rate is about 0.010% for in-person payments, vs. about 0.16% for remote sales. That is a factor of 16.
| Dimension | Card present (in person) | Card not present (remote) |
|---|---|---|
| Acceptance channel | Certified POS terminal (PCI PTS), contactless, SoftPOS | Payment page, API, payment link, MOTO |
| Proof of consent | PIN entry or tap (CDCVM) | 3-D Secure, security code, transaction data |
| Typical fraud rate (OSMP) | ≈ 0,010 % | ≈ 0,16 % |
| Default liability | Issuer (chip-and-PIN authenticated transaction) | Merchant, unless 3DS/liability shift |
| Required safeguards | Rare (low risk) | Common: rolling reserve, deposit, longer payout delay |
| KYB underwriting | Standard | Enhanced: delivery model, fulfillment lead time |
| Indicative MSC (France, SMEs) | 0,3 % – 0,8 % | 0.8%–2.0% + fixed fees per transaction |
| Key risk for the acquirer | POS terminal fraud, skimming (residual) | Chargebacks + non-delivery risk (delivery risk) |
In the four-party model, the merchant agreement embodies the merchant ↔ acquirer corner. Everything the merchant negotiates, such as the MCC, guarantees, and payouts, falls under this contractual relationship. The costs it bears also flow through it, whether chargebacks or scheme fines that the acquirer passes on.
MIDs and TIDs: how identifiers are structured
The MID (Merchant ID) identifies the contractual point of acceptance with the acquirer and the schemes. The TID (Terminal ID) designates each logical terminal attached to a MID: a physical POS terminal, a checkout lane, but also an e-commerce “line.” A single merchant can hold dozens of MIDs and thousands of TIDs.
- Legal entity (SIREN number in France, the French company ID, or the equivalent national registration number elsewhere) → one or more agreements with the acquirer;
- MID → one per relevant combination: channel (card-present/CNP), store brand, country, settlement currency, sometimes MCC;
- TID → one per logical terminal; in e-commerce, a TID can represent a platform, a site, or a channel (web/app).
Entity: MODETEX SAS (SIREN 512 345 678)
│
├── Card-present agreement — Acquirer A
│ ├── MID 4571120001 (Paris Rivoli store, MCC 5651 clothing)
│ │ ├── TID 00000001 (POS terminal, register 1)
│ │ └── TID 00000002 (POS terminal, register 2)
│ └── MID 4571120002 (Lyon Part-Dieu store, MCC 5651)
│ └── TID 00000001
│
└── CNP agreement — Acquirer B (via PSP)
├── MID 8890455001 (FR site, EUR settlement, MCC 5651)
└── MID 8890455002 (UK site, GBP settlement, MCC 5651)
Rule of thumb: 1 MID = 1 unit for reporting, reconciliation,
and fraud rate monitoring. Too few MIDs = flying blind;
too many MIDs = fixed fees and admin multiplied.Standard practice is to separate MIDs at least by channel and by settlement currency. Authorization and fraud rates are then measured on consistent scopes, which makes them meaningful to track. A spike in chargebacks on the website stays confined to the CNP MID and leaves the card-present agreement untouched. This separation also makes a later move to multi-acquiring easier.
KYB: the onboarding process and required documents
KYB (Know Your Business) covers all the checks an acquirer runs to identify a merchant before opening card acceptance. It is the counterpart of KYC for legal entities. The acquirer is bound by it as an entity subject to AML/CFT rules. The obligation comes from the EU anti-money laundering directives, transposed in France into the Monetary and Financial Code and into each member state’s national law. The checks cover the merchant’s identity, its beneficial owners, and the real nature of its business.
- Kbis extract (French company registration certificate, or the equivalent from a trade register) less than 3 months old;
- Signed, up-to-date articles of association;
- ID documents for directors and authorized representatives;
- Beneficial ownership register: identification of anyone holding more than 25% of the capital or voting rights;
- IBAN (with a RIB, the French bank account details form, in France) for the payout account, in the contracting entity’s name;
- Proof of business activity: website URL, terms and conditions of sale, delivery and refund policy, any industry licenses;
- Processing history (3 to 6 months of statements from the previous acquirer: volumes, chargeback rates) for existing merchants;
- Financial statements (balance sheet, income statement) for large volumes or sectors with non-delivery risk.
Financial guarantees and payout timing
The financial guarantees an acquirer requires are sums it withholds or freezes to protect itself against merchant default. Between the payment and the end of the chargeback window, the acquirer carries credit risk on the merchant: it will have to refund cardholders if the merchant can no longer do so. This window runs for 120 days after the transaction. For some Visa/Mastercard reason codes, the clock starts from the expected delivery or service date, up to a limit of 540 days after the transaction. The contractual guarantees that cover this risk are sized during underwriting and can be revised later.
| Instrument | Mechanism | Typical range | Impact on merchant cash flow |
|---|---|---|---|
| Rolling reserve | A % withheld from each payout, released on a rolling basis | 5–10% withheld for 90–180 days | High: a permanent drain on working capital |
| Fixed security deposit | Sum frozen at signing | 0.5 to 2 months of estimated volume | High, but capped and predictable |
| On-demand bank guarantee | Guarantee issued by the merchant’s bank | Negotiated amount, costs 0.5–2%/year | Low in cash terms, uses up bank credit lines |
| Longer payout delay | Settlement at D+7 to D+30 instead of D+1/D+2 | Varies | Equivalent to an implicit reserve |
| Processing caps | Cap on monthly volume or ticket size | Set in the agreement | Limits growth; renegotiate quickly |
The standard payout delay in France is D+1 to D+3 business days after clearing, on a net basis (gross amount – fees – chargebacks – reserve). Some PSPs offer daily or weekly payouts. Others trigger them when a threshold is reached. Every extra day of delay amounts to a cash facility the merchant grants its acquirer, since the collected funds stay with the acquirer.
- Check whether the reserve is calculated on the gross or the net amount;
- Cap the reserve’s absolute amount in the agreement;
- Require monthly reporting on the reserve balance and releases;
- Include an automatic review clause for guarantees, indexed to the actual chargeback rate.
Termination and the MATCH list
Termination ends the merchant agreement and removes the merchant’s right to accept cards from the schemes concerned. Either the merchant or the acquirer can initiate it. On the merchant side, the contractual notice period is often 1 to 3 months, and the agreement may include exit fees and volume commitments. The acquirer, for its part, can terminate without notice in case of proven fraud, sustained breaches of the schemes’ chargeback program thresholds (VAMP at Visa, ECP at Mastercard), or misrepresentation of business activity.
A termination for risk reasons leads to a listing in an industry-wide file. A Mastercard acquirer is required to list the merchant in MATCH (Member Alert to Control High-risk merchants). Every acquirer checks it during onboarding. Visa runs an equivalent system (a terminated merchant file, historically TMF, now VMSS). The acquirer makes the listing with a reason code, and it stays visible for 5 years.
| Code | Reason | Typical situation |
|---|---|---|
| 01 | Account data compromise | Card data compromised at the merchant |
| 02 | Common point of purchase | The merchant is identified as a common point of fraud |
| 03 | Laundering | Processing transactions on behalf of a third party (unauthorized factoring) |
| 04 | Excessive chargebacks | Over 1% of transactions and $5,000+ in chargebacks in a single month |
| 05 | Excessive fraud | Fraud rate above the program thresholds |
| 07 | Fraud conviction | A principal convicted of fraud |
| 09 | Bankruptcy / insolvency | Insolvency proceedings |
| 10 | Violation of standards | Breach of Mastercard rules (MCC, illegal content…) |
| 12 | PCI DSS non-compliance | Persistent PCI DSS non-compliance |
When the acquirer threatens to terminate over chargebacks, the usual path is to negotiate a remediation plan. It combines tighter fraud rules, systematic 3DS, and a larger reserve. The agreement stays in force. The merchant thus avoids the MATCH listing that comes with a termination for risk reasons.
Choosing an acquirer or PSP: the evaluation grid
Card acceptance comes in two main delivery models. The bank acquirer sells a direct acquiring agreement, sometimes paired with a technical gateway. The full-stack PSP (Adyen, Stripe, Checkout.com, Worldline in its packaged offering…) combines gateway, acquiring, fraud prevention, and payouts in a single agreement. The first model optimizes unit cost at high volume, while the second prioritizes time to market and international coverage.
| Criterion | Questions to ask | Approximate size |
|---|---|---|
| Pricing | Interchange++ or blended? Fees on declines? Chargeback fees (€15–30 per dispute)? Monthly/per-MID fees? | 20 % |
| Payment success rate | Authorization rate observed on my BIN/country mix? Network token support? Soft decline handling? Verifiable benchmarks? | 20 % |
| Coverage | Schemes (CB included?), local methods (iDEAL, Bancontact, Wero…), presentment and settlement currencies? | 15 % |
| Payouts & cash | D+1/D+3 timing? Settlement currency? Reserves required? Usable settlement reporting (reconciliation files)? | 15 % |
| Risk & compliance | Fraud tools included? 3DS/TRA exemption management? Chargeback support (representment)? | 10 % |
| Technical | API/docs quality, uptime (SLA ≥ 99.95%), webhooks, test environment, tokenization? | 10 % |
| Contract | Minimum term? Notice period? Guarantee review clauses? Reversibility (token export!)? | 10 % |