Payments glossary. The language of the trade, defined term by term.

Every term has its own entry: the definition, cross-references to related concepts, and the guides where it appears. Search for a word or browse the alphabet.

151 payments terms. The full vocabulary, with cross-references.

3

3-D Secure

Cardholder authentication protocol for remote card payments, specified by EMVCo (EMV 3DS 2.x; version 1 was decommissioned in October 2022). It connects the merchant’s 3DS Server, the scheme’s Directory Server, and the issuer’s ACS to authenticate the customer or apply an exemption. An authenticated transaction generally triggers a liability shift to the issuer for fraud.

A

A2A (account-to-account)

Account-to-account payment: funds move directly from the payer’s account to the payee’s, bypassing card rails. Built on instant credit transfers, PSD2 payment initiation, and wallets such as Wero, it eliminates interchange and scheme fees. It is the leading contender to disintermediate cards in Europe.

Account Updater

Scheme service (Visa Account Updater, Mastercard Automatic Billing Updater) that automatically updates the PANs and expiration dates of cards stored with a merchant when those cards are reissued. It sharply reduces failures on recurring payments and subscriptions. Network tokens make the mechanism native, since the network itself handles the update.

ACP (Agentic Commerce Protocol)

Open agentic commerce protocol published by OpenAI and Stripe in September 2025. It lets a conversational agent (ChatGPT) buy directly from a merchant through the Instant Checkout feature. The merchant remains the merchant of record and receives a Shared Payment Token, a delegated payment token issued by Stripe, instead of raw card data. A direct competitor to Google’s AP2, it turns the AI model into a new checkout surface.

ACPR

France’s prudential supervision and resolution authority (Autorité de contrôle prudentiel et de résolution), housed within the Banque de France (France’s central bank). It licenses and supervises French credit institutions, payment institutions, and e-money institutions, and checks in particular that safeguarding and AML/CFT rules are met. Any payment services business in France needs its license, its registration, or an EU passport notified to it.

Acquirer

Institution (a bank or payment institution) that signs up merchants, collects their transactions, guarantees their payouts, and bears the financial risk of chargebacks. It is a scheme member on the acquiring side and earns its revenue from the merchant service charge (MSC). Examples in France: the incumbent banks, Worldline, Adyen, and Stripe.

ACS

Access Control Server: the issuer’s authentication server in the 3-D Secure protocol. It assesses transaction risk, chooses between a frictionless flow and a challenge, and authenticates the cardholder (push notification in the banking app, biometrics, OTP). Its availability and configuration directly affect merchants’ conversion rates.

AI payment agent

Autonomous software agent, usually driven by an AI model, that searches, compares, and initiates payments on a user’s behalf. Not to be confused with a “payment agent” under PSD2, which is a registered agent acting for a PSP. The rise of AI agents spawned dedicated protocols in 2025 (Google’s AP2, OpenAI and Stripe’s ACP, Coinbase’s x402) and raised the question of a verifiable mandate linking the agent to an auditable human intent. The core security challenge is to authenticate the agent and limit its authority, hence the concept of Know Your Agent.

AISP

Account Information Service Provider: a regulatory status created by PSD2. With the customer’s consent, it has read access to their payment accounts through bank APIs (account aggregation, budgeting tools, credit scoring). In France, it requires only a lighter registration with the ACPR.

AML/CFT

Anti-money laundering and countering the financing of terrorism: customer due diligence (KYC/KYB), transaction monitoring, suspicious activity reports to Tracfin (France’s financial intelligence unit), asset freezes, and sanctions screening. The EU AML package adopted in 2024 creates a single, directly applicable regulation and a new authority, AMLA, in Frankfurt (ramping up from 2025 to 2028, with direct supervision of the riskiest firms). Payment institutions are among the most closely inspected entities supervised by France’s banking supervisor (ACPR).

AP2 (Agent Payments Protocol)

Agent Payments Protocol: an open protocol unveiled by Google in September 2025 with more than 60 partners (Mastercard, PayPal, American Express, Coinbase, and others). It extends the A2A and MCP protocols to payments initiated by AI agents. It relies on Mandates, cryptographically signed verifiable credentials that capture the user’s intent and form an auditable chain of authorization. Payment-method agnostic, it covers cards, credit transfers, and stablecoins, the latter through an x402 extension.

ARN

Acquirer Reference Number: a 23-digit reference that the acquirer assigns when a card transaction is cleared. It lets the transaction be traced end to end through the scheme’s and the issuer’s systems. It is the standard proof that a refund was issued when a customer says they never received it.

Authorization

Real-time request to the issuer (ISO 8583 messages) to check that the card is valid, not blocked, and funded, and to assess fraud risk. An approved authorization reserves the amount against the cardholder’s limit but moves no money: capture, then settlement, are what complete the payment. The response code (00 = approved, 05 = declined, etc.) determines the next step.

Authorized push payment (APP) fraud

Authorized push payment fraud: victims execute a credit transfer themselves after being manipulated, for example by a fake bank adviser, fake supplier bank details, or a fake listing. The OSMP (France’s payment security observatory) ranks it as the leading cause of credit transfer fraud, and the irrevocability of instant payments makes it worse. Responses under way: mandatory Verification of Payee, stronger liability sharing in the PSD3/PSR package, and mandatory reimbursement in the UK since October 2024.

AVS

Address Verification Service: a check that compares the billing address entered by the buyer with the one on file at the issuer and returns a match code (full, partial, or none). Widely used in the US, the UK, and Canada, it is virtually nonexistent in France. It is a fraud signal that complements CVV, not an authentication method.

B

Batch

A batch of captured transactions that the merchant (or its terminal or PSP) sends to the acquirer for clearing, usually at the end of the day. For in-store payments in France, terminals send it through an end-of-day batch upload (télécollecte). The batch’s contents and the submission cut-off time determine when the merchant receives the funds.

BIC

Business Identifier Code (ISO 9362), also called the SWIFT code: an 8- or 11-character identifier for a financial institution (bank, country, location, branch). It routes messages over the SWIFT network and historically accompanied the IBAN in SEPA. Since the “IBAN only” rule (2016), it can no longer be required for SEPA payments.

BIN

Bank Identification Number: the first 6 to 8 digits of the PAN (8 digits since the ISO/IEC 7812 revision implemented by the schemes in April 2022). It identifies the issuer, the scheme, the product type (debit, credit, commercial, prepaid), and the country of issue. BIN tables feed routing, pricing, and fraud rules at acquirers and PSPs.

BIN sponsor

Principal member of a scheme that lends its BINs, scheme license, and regulatory authorization to non-member firms (fintechs, neobanks) so they can issue cards or acquire transactions. The sponsor remains accountable to the scheme and the regulator, notably for its partners’ AML/CFT compliance. It is the building block behind the explosion of white-label card programs.

BNPL

Buy Now, Pay Later: split payment (3 or 4 installments) or deferred payment offered at checkout, provided in France by Alma, Klarna, Oney, and Floa. Long outside the scope of consumer credit because its term is under 90 days, BNPL is brought into scope by the revised Consumer Credit Directive (EU) 2023/2225, now being transposed (deadline November 2025, application in 2026). The model relies on a high merchant fee (1.5% to 4%) in exchange for a higher average order value.

C

camt.053

ISO 20022 end-of-day account statement message (Bank to Customer Statement), the structured successor to the MT940. It details every entry with machine-readable references (end-to-end ID, UMR, gross and net amounts), which makes it the raw material for reconciliation. Its companion messages: camt.052 (intraday report) and camt.054 (debit/credit notification, including batch details).

Capture

The merchant’s confirmation, sent to the acquirer in a batch, that an authorization should actually be charged. In e-commerce it often happens at shipment (authorization at order, capture when the package ships), in full or in part. An uncaptured authorization expires, usually after 7 days (longer for certain MCCs such as hotels).

Card payments

The French term for all electronic processing of card payments: issuing, acquiring, authorization, clearing, terminals, and cryptographic security. By extension, it covers the whole card ecosystem, from the GIE CB to processors and terminal manufacturers. The word has no true English equivalent; English speakers simply say cards or payments.

Card testing

Fraud that tests stolen or generated card numbers in bulk on poorly protected sites, using micro-transactions or zero-amount authorizations. It shows up as sudden spikes in declined attempts and damages the MID’s reputation with issuers. Countermeasures: CAPTCHA, velocity checks, mandatory CVV, and blocking BINs that see abnormal traffic.

Card-on-file (COF)

Card stored by a merchant or its PSP for future payments: one-click checkout, subscriptions, top-ups. COF transactions fall under the schemes’ CIT / MIT framework, which requires an authenticated initial payment and then the chaining of transaction references. Best practice is to store a token (ideally a network token) rather than the PAN.

Cardholder

The person who holds the card (cardholder), bound to the issuer by the cardholder agreement. In France, if a lost or stolen card is used with the PIN before the cardholder reports it, the cardholder’s liability is capped at €50. Remote fraud must be fully refunded unless the cardholder was grossly negligent or acted fraudulently (Article L. 133-19 of the French Monetary and Financial Code). Strong customer authentication has shifted the debate to what counts as gross negligence.

Cartes Bancaires (CB)

“Cartes Bancaires,” France’s domestic card scheme, created in 1984 and governed by GIE CB: about 76 million cards and roughly 15 billion transactions a year. Nearly all CB cards are co-badged with Visa or Mastercard, with CB used as the priority brand for domestic transactions. Its domestic interchange is lower than that of the international schemes, which gives French merchants a cost advantage.

Cash application

Line-by-line matching of invoices to their payments (or of debit entries to credit entries) in the accounts receivable and accounts payable ledgers. It can be automated using the references payments carry: invoice number, the end-to-end ID of credit transfers, and the UMR of direct debits. Clean cash application is a prerequisite for reliable bank reconciliation.

CB2A

French card messaging protocol between the point of acceptance (POS terminal, payment server) and the acquirer, derived from ISO 8583: authorization requests and end-of-day batch upload files. Each acquirer maintains its own implementation, which complicates terminal certification. It is gradually migrating to the European nexo standards, based on ISO 20022.

Chargeback

Card dispute process: at the cardholder’s request (fraud, goods not received, service not as described), the issuer claws the funds back from the acquirer, which debits the merchant. Scheme rules govern the process, with dispute windows of around 120 days and standardized reason codes. The real cost to the merchant: the lost amount, plus a handling fee (€15 to €50), plus a higher chargeback ratio.

Chargeback ratio

The share of a merchant’s transactions that are disputed (the number of disputes divided by the month’s transactions). The card networks run threshold-based monitoring programs, such as Visa’s VAMP (consolidated in April 2025, combining reported fraud and disputes) and Mastercard’s ECP, with merchant thresholds of about 1.5% (2.2% in CEMEA for Visa). A merchant over the threshold faces remediation plans, fines, and ultimately termination of its acquiring agreement and a place on the network’s blacklists.

CIT / MIT

Visa and Mastercard’s standardized distinction between transactions initiated by the customer (customer-initiated transactions) and by the merchant (merchant-initiated transactions: recurring, installment, no-show, incremental). MITs fall outside the scope of SCA, provided the initial CIT was authenticated and subsequent transactions are chained through the scheme references. A misapplied MIT flag leads to soft declines at scale.

Clearing

The exchange of transaction data between participants and the calculation of each party’s net position, before the funds are actually settled. For cards, the schemes handle clearing; for SEPA credit transfers and direct debits, CSMs such as STET or EBA Clearing do. Clearing and settlement are two separate steps: information is exchanged first, and money is settled afterward.

CNP

Card Not Present: a transaction in which the card is not physically presented (e-commerce, MOTO, subscriptions). This is where most card fraud is concentrated: the OSMP (France’s payment security observatory, hosted by the Banque de France) measures a fraud rate on remote payments about 20 times higher than for in-person payments, hence the SCA requirement. 3-D Secure combined with tokenization is the market’s standard response.

Co-badged card

Card carrying two payment brands; in France, typically CB (the domestic scheme) + Visa or CB + Mastercard. The Interchange Fee Regulation (IFR, Art. 8) gives cardholders the right to choose the brand at the point of sale, while merchants can set a default brand on their terminal. The issue is cost: routing through CB or through an international scheme does not cost the merchant the same.

Commercial card

Business or corporate card issued for business expenses. It is exempt from the IFR interchange caps, so interchange rates are often between 1.3% and 2%, passed on in the MSC. It is also one of the few cases where surcharging remains legal in some EU countries.

CSM

Clearing and Settlement Mechanism: infrastructure that clears and settles SEPA payments between PSPs. Examples: STET in France, EBA Clearing’s STEP2 and RT1 at the pan-European level, and the Eurosystem’s TIPS for instant payments in central bank money. A PSP must be reachable on a CSM, directly or indirectly, for every scheme it participates in.

CVV

Card security code (CVV2/CVC2): 3 digits on the back of the card (4 on the front for American Express), checked by the issuer on remote payments. It proves physical possession of the card at the time of entry. PCI DSS strictly prohibits storing it after authorization, even encrypted, and doing so is one of the most frequently penalized compliance failures.

D

DCC

Dynamic Currency Conversion: when paying abroad, the terminal or ATM offers to charge in the card’s currency instead of the local currency. The acquirer performs the conversion, often with markups of 3% to 12%, almost always to the cardholder’s detriment. Regulation (EU) 2019/518 requires the markup over the ECB reference rate to be disclosed; the golden rule is still to pay in the local currency.

Deferred debit

French arrangement in which a month’s card payments are aggregated and debited in a single charge at month-end, interest-free. Under the Interchange Fee Regulation, a deferred debit card is treated as a credit card (interchange capped at 0.3%). It differs from revolving credit: there is no revolving balance and no cost to the cardholder, only a cash-flow delay.

Digital euro

The ECB’s retail central bank digital currency (CBDC) project: a digital equivalent of banknotes, free for individuals, usable online and offline with a high level of privacy. The preparation phase, which began in November 2023, ended in October 2025, when the Eurosystem moved to the next phase; the EU legislative framework is still under discussion, and issuance is not envisaged before the end of the decade. Banks fear deposit outflows, which a holding limit is designed to cap.

Digital wallet

An electronic wallet. There are two types: pass-through wallets (Apple Pay, Google Wallet), where a tokenized card (DPAN) runs over the standard card rails, and staged or balance-based wallets (PayPal, stored-value accounts), which place an account between the customer and the merchant. In France, the OSMP, the Banque de France’s payment security observatory, closely monitors card enrollment in wallets, a known fraud vector when authentication is weak.

Directory Server (DS)

Core component of the 3-D Secure protocol, operated by each scheme. It maintains the directory of enrolled BINs and routes authentication messages between the merchant’s 3DS Server and the issuer’s ACS. For any given PAN, it knows which ACS to query and which protocol version to use. If the ACS is unavailable, it can return an attempt response.

DORA

Digital Operational Resilience Act, Regulation (EU) 2022/2554, applicable since January 17, 2025. It harmonizes ICT risk management across the EU financial sector: governance, major incident reporting, resilience testing, and oversight of critical third-party providers such as cloud vendors. Payment institutions, EMIs, and PSPs are fully in scope, under the supervision of the ACPR and the European supervisory authorities. A major operational incident must now be reported to the regulator within strict deadlines.

DPAN

Device PAN: a device-specific token provisioned in a wallet (Apple Pay, Google Wallet) in place of the real PAN when the card is enrolled. It is stored in the phone’s Secure Element or managed via HCE, and can be revoked remotely without reissuing the physical card. The merchant never sees the underlying PAN, which reduces its PCI exposure.

Drop-in component

Prebuilt integration component provided by a PSP (Adyen Drop-in, Stripe Payment Element, Braintree Drop-in) that automatically displays the available payment methods and handles data collection, redirects, and 3-D Secure with minimal code. It usually relies on hosted fields in iframes, which keeps the merchant in a reduced PCI scope. It is the usual middle ground between a hosted payment page, which is simple but hard to customize, and a full API integration, which is flexible but compliance-heavy.

Dynamic linking

PSD2 RTS requirement for remote electronic payments: the authentication code generated during SCA must be dynamically linked to the amount and payee shown to the payer. Any change to either invalidates the authentication, which defeats transaction-tampering attacks. In practice, the banking app displays “Pay €149.90 to Merchant X” before biometric approval.

E

E-money institution (EMI)

EMI: an institution licensed (by the ACPR in France) to issue e-money, meaning stored value held on a device or in an account and redeemable at any time (balance-based wallets, prepaid cards). The regime, which dates from the 2009 Second E-Money Directive (EMD2), is set to merge with the payment institution regime under the PSD3 package. Funds collected must be safeguarded.

EBICS

Electronic Banking Internet Communication Standard: a secure file-transfer protocol between companies and their banks, adopted in France in 2010 to replace ETEBAC (and also used in Germany, Switzerland, and Austria). It carries pain.001 credit transfer batches, pain.008 direct debits, and camt.053/MT940 statements. The French EBICS TS variant adds a separate electronic signature for payment orders.

ECI

Electronic Commerce Indicator: the code returned at the end of a 3-D Secure flow that indicates the level of authentication achieved. For Visa: 05 (authenticated), 06 (attempted), 07 (not authenticated); for Mastercard: 02, 01, and 00, respectively. The ECI determines liability shift and how the issuer handles the transaction.

EMV

Global standard for chip and contactless cards, managed by EMVCo (Visa, Mastercard, Amex, JCB, Discover, UnionPay). Each transaction generates a dynamic cryptogram, which makes chip cloning impractical, so fraud has shifted massively to remote channels (CNP). EMVCo also specifies 3-D Secure, payment tokenization, and EMV QR codes.

End-of-day batch upload

The transfer, historically overnight, of the batches stored in the POS terminal to the acquirer for clearing, using the CB2A protocol in France. Each session uploads the transactions, updates the terminal’s parameters remotely and refreshes its security tables. The move from dial-up to IP made it more reliable, and always-connected terminals are shifting toward continuous submission.

EPI

European Payments Initiative: an alliance of European banks launched in 2020 to build a pan-European payment solution independent of Visa and Mastercard. After dropping its card component, EPI acquired iDEAL and Payconiq in 2023 and launched the Wero wallet in 2024, built on instant account-to-account transfers. Notable shareholders: BNP Paribas, Crédit Agricole, BPCE, Société Générale, Deutsche Bank, ING, and Worldline.

F

Fallback

Switch to a degraded mode: reading the magnetic stripe when the EMV chip cannot be read, keying in the PAN manually, or authorizing offline below a floor limit when the network is down. Fallback transactions are riskier and are often excluded from payment guarantees. The schemes restrict them sharply, and the magnetic stripe itself is being phased out.

Four-party model

The standard structure of a card transaction: the cardholder and the issuer on one side, the merchant and the acquirer on the other, and the scheme in the middle, setting the rules and routing the flows. It contrasts with the three-party model (historically American Express), in which a single company both issues cards and signs up merchants. Nearly all Visa, Mastercard, and CB volume runs on the four-party model.

Fraud scoring

Real-time risk assessment of a transaction that combines expert rules, machine learning, device fingerprinting, velocity checks and behavioral signals. The score determines whether the transaction is approved outright, sent to a 3-D Secure challenge or declined, and it supports requests for the TRA exemption. PSP fraud engines pool signals from thousands of merchants, a decisive edge over standalone tools.

Frictionless flow

3-D Secure flow with no cardholder interaction: the ACS authenticates based solely on the risk data it receives (device, history, IP address, amount) or applies an exemption. A challenge, by contrast, requires action from the customer: approval in the banking app, biometrics, or an OTP. Raising the frictionless rate, through rich 3DS data and the TRA exemption, is a major conversion lever.

Friendly fraud

“Friendly” fraud: the legitimate cardholder disputes a transaction they actually made, whether a forgotten purchase, a family member’s subscription they don’t recognize, or deliberate abuse. It accounts for a large share of e-commerce chargebacks and is hard to distinguish from true fraud at the time of the dispute. Visa tightened its evidence rules with Compelling Evidence 3.0 (2023), which lets a fraud chargeback be reclassified using the customer’s order history.

G

GENIUS Act

Guiding and Establishing National Innovation for U.S. Stablecoins Act: the first US federal stablecoin law, signed on July 18, 2025. It creates a regulatory status for issuers of payment stablecoins fully backed by liquid reserves (cash, Treasury bills), with monthly disclosure of reserves and a ban on paying interest to holders. It is the US counterpart of MiCA’s stablecoin rules, whose adoption accelerated the entry of banks and payment giants into this market.

GIE CB

Cartes Bancaires economic interest grouping (GIE), created in 1984. It governs the CB scheme (operating rules, security, equipment approval, interbank interoperability) for about 100 members, both banks and payment institutions. It does not process transactions itself: authorizations flow between members, and clearing goes through STET. It is the historical architect of French interbank interoperability and a textbook case of a resilient domestic scheme.

H

Hosted fields

Card entry fields hosted by the PSP and embedded as iframes in the merchant’s own page. The customer appears to stay on the merchant’s site, but card data goes straight to the PSP without ever touching the merchant’s servers. This architecture keeps the merchant at SAQ A or SAQ A-EP, whereas a direct API integration moves it to SAQ D. It offers more design control than a fully redirected payment page.

Hosted payment page

A page, or iframe-hosted fields, served by the PSP, where the customer enters card details that never touch the merchant’s servers. It is the simplest way to reduce PCI DSS scope (making the merchant eligible for SAQ A). The alternative, a direct API integration, gives more control over the experience but moves the merchant to SAQ D, with far heavier obligations.

HSM

Hardware Security Module: a tamper-resistant hardware device that generates, stores, and uses cryptographic keys without ever exposing them. It handles PIN verification, EMV cryptograms, tokenization, and signing. Certified to FIPS 140-2/3 and PCI PTS HSM, HSMs are essential at issuers, acquirers, and processors. The security of card processing ultimately rests on these devices and their key ceremonies.

I

IBAN

International Bank Account Number (ISO 13616): the international account identifier. In France it has 27 characters: FR, a mod-97 check number, then the bank code, branch code, account number, and RIB key (the French national check digits). It is the universal key for SEPA payments. Refusing an IBAN from another SEPA country (“IBAN discrimination”) is illegal, but some creditors still do it.

Instant credit transfer

The everyday name for SCT Inst: funds reach the payee in under 10 seconds, at any time, every day. Under the Instant Payments Regulation (IPR), it cannot cost more than a standard transfer, and most French banks have in fact offered it free since January 2025, which sent usage soaring. Because it is irrevocable, it is a prime target for authorized push payment scams, hence the parallel requirement for Verification of Payee.

Interchange

The fee the acquirer pays the issuer on every card transaction, meant to pay for the payment guarantee and the risk the issuer carries on the cardholder side. The Interchange Fee Regulation caps it in the EEA at 0.2% for consumer debit cards and 0.3% for consumer credit cards. It is the largest component of the merchant service charge (MSC), ahead of scheme fees.

Interchange Fee Regulation (IFR)

Regulation (EU) 2015/751: caps interchange on consumer cards (0.2% for debit, 0.3% for credit), requires schemes to keep separate accounts for their processing activities, guarantees the choice of application on co-badged cards, and requires acquirers to itemize their fees for merchants. Commercial cards and pure three-party schemes are exempt from the caps. It drove down the cost of acceptance, partly offset by rising scheme fees.

Interchange++

A transparent acquiring pricing model: the merchant pays actual interchange plus actual scheme fees plus an explicit acquirer markup (the “++”). It contrasts with blended pricing, a single opaque rate that averages out the differences between cards. IC++ makes sense as soon as volumes justify it: the merchant benefits directly from the regulatory caps and sees the true cost of each card type.

IPR

Instant Payments Regulation, Regulation (EU) 2024/886: makes instant credit transfers universal in the euro area. Banks must be able to receive them since January 9, 2025, and to send them since October 9, 2025. Pricing is capped at the price of a standard transfer, verification of payee (VoP) is mandatory, and sanctions screening runs daily rather than per transaction. Countries outside the euro area follow on later deadlines (2027).

ISO 20022

The global standard for structured financial messages in XML, organized into families: pain (customer to bank), pacs (interbank), and camt (reporting). It underpins SEPA, TARGET, and the migration of SWIFT cross-border payments (coexistence with MT messages ended in November 2025). Its rich data, including structured remittance information, LEIs, and standardized addresses, improves reconciliation, compliance, and screening.

ISO 8583

The long-standing standard for card payment messages: message types (0100 authorization, 0110 response, 0400 reversal, and so on) and numbered fields such as 2 (PAN), 4 (amount), 11 (STAN), 37 (RRN), and 39 (response code). Every scheme and every domestic protocol, including CB2A, derives its own dialect from it. It remains the backbone of card networks, despite the rise of ISO 20022 and APIs.

Issuer

Bank or institution that issues the payer’s card (or holds the account). It authorizes transactions, carries credit and fraud risk on the cardholder side, and earns interchange. It also operates the ACS for 3-D Secure authentication. In the four-party model, it sits opposite the acquirer, connected through the scheme.

K

KYA (Know Your Agent)

Know Your Agent: extends KYC and KYB principles to AI agents. It means identifying an autonomous agent, verifying its mandate and the scope of its authority, and linking it to an accountable person or entity. The concept emerged in 2025 alongside agentic payment protocols, which use verifiable credentials to prove an agent’s identity and authority. The goal is to stop a compromised or hijacked agent from making payments the user never consented to.

KYB

Know Your Business: verification of a business customer, covering legal existence, ultimate beneficial owners (UBOs), sanctions, whether the business is real, and whether it matches the declared MCC. Acquirers and PayFacs perform it when onboarding each merchant, then on an ongoing basis through transaction monitoring. Weak KYB exposes them to merchant fraud (sham websites, laundering through fake sales) and to regulatory penalties.

KYC

Know Your Customer: identifying and verifying a customer’s identity at onboarding and on an ongoing basis, through ID documents, liveness detection, and PEP and sanctions screening. It is the operational foundation of AML/CFT for every PSP. In France, remote onboarding relies on certified identity verification providers (the PVID framework of ANSSI, France’s cybersecurity agency) or on digital identity.

L

Liability shift

The transfer of fraud liability: to the issuer when the transaction was authenticated with 3-D Secure (or attempted, depending on the ECI), and to the less EMV-compliant party for in-person payments. It covers only fraud (stolen card, impersonation), never commercial disputes, which the cardholder can still charge back. It is the economic incentive that drove adoption of the chip, then of 3DS.

M

Marketplace

A platform that connects buyers with third-party sellers and collects payments on the sellers’ behalf. Collecting funds for third parties is a payment service: it requires a license (as a payment institution), agent status, or a specialist PSP that safeguards the funds and handles payouts. PSD2 closed the old “commercial agent” exemption that platforms had been abusing.

MCC

Merchant Category Code (ISO 18245): a 4-digit code that classifies a merchant’s business, such as 5411 for grocery stores, 5812 for restaurants, and 7995 for gambling. It determines applicable interchange, risk rules, some acceptance bans, and issuers’ cashback programs. A misreported MCC breaches scheme rules and is a red flag for merchant fraud.

Merchant

Any business or entity that accepts a payment method as payment for goods or services, bound to its acquirer by a merchant agreement. Not to be confused with the acquirer: the merchant makes the sale and collects payment, while the acquirer processes the transaction and provides the financial guarantee. Each acceptance point is identified by a MID.

Merchant of record

The entity that is legally the seller to the end customer: it collects payment, collects the VAT, takes on compliance, fraud, and chargebacks, and appears on the customer’s bank statement. Some companies (Paddle, app resellers) offer this model as a turnkey service to software vendors. Not to be confused with a PayFac, which facilitates the payment but is never a party to the sale.

MiCA

Markets in Crypto-Assets Regulation, Regulation (EU) 2023/1114: the first harmonized EU framework for crypto-assets. Its stablecoin rules, covering e-money tokens (EMTs) and asset-referenced tokens (ARTs), have applied since June 30, 2024, and the rest of the framework since December 30, 2024. Issuers and crypto-asset service providers (CASPs) are licensed and supervised by national authorities (the AMF and the ACPR in France), coordinated by ESMA and the EBA.

MID

Merchant ID: the identifier of a merchant’s acceptance agreement with its acquirer. A single merchant often holds several, by channel (in-store or e-commerce), currency, brand, or legal entity. It is the unit scheme monitoring programs work with: fraud and chargeback ratios are calculated per MID.

MOTO

Mail Order/Telephone Order: a remote payment in which the merchant itself keys in the card details, taken by phone or by mail. MOTO transactions are outside the scope of SCA, but they have no authentication and no liability shift, so the merchant bears the fraud. Keep them to controlled flows, such as call centers with secure DTMF entry, or offer payment links instead.

MSC

Merchant Service Charge: the total fee a merchant pays its acquirer. It is made up of interchange (passed on to the issuer), scheme fees (passed on to the network), and the acquirer’s markup. In France it ranges from under 0.2% for large grocery chains on CB to more than 1.5% for a small online merchant taking international cards. Its structure is negotiated as either blended or Interchange++ pricing.

MT940

The SWIFT MT end-of-day account statement: long established and compact, but poorly structured, since transaction details sit in field 86 as semi-free text, which makes automation hard. The natively structured ISO 20022 camt.053 is gradually replacing it. Many corporate treasury teams still use it because their existing systems have not been migrated.

N

Network token

A token issued by the card network (Visa Token Service, Mastercard Digital Enablement Service) that replaces the PAN for a specific merchant or wallet. The network manages its life cycle: the token survives card reissuance and updates automatically. Measured benefits: 2 to 3 points higher authorization rates on stored-credential payments, and sometimes more favorable interchange.

nexo

Open standards from the nexo standards association that unify card payment messaging across Europe: the terminal application specification (nexo FAST), the terminal-to-acquirer protocol (nexo Acquirer), and the POS-to-terminal protocol (nexo Retailer), all built on ISO 20022. They are gradually replacing domestic protocols such as CB2A, with a single certification valid in several countries. Large pan-European terminal rollouts (retail, fuel) were the first to adopt them.

NFC

Near Field Communication: the short-range radio technology behind contactless payments, by card or phone. In France, the limit is €50 per card transaction (above that, the card must be inserted and the PIN entered), with no limit on mobile payments verified by biometrics (CDCVM). Contactless accounts for about two-thirds of in-store card payments in the euro area, according to ECB studies.

O

On-us

A transaction in which the card issuer and the merchant’s acquirer are the same institution. It can be authorized and cleared internally, without going through the scheme, at lower cost, subject to the network’s reporting rules. On-us volume is significant in concentrated banking markets.

Open banking

The opening of payment accounts to licensed third parties through APIs, mandated by PSD2: account information services (AISPs) and payment initiation services (PISPs). Banks must provide dedicated, high-performing interfaces under regulatory oversight. The upcoming EU framework (FIDA and the PSD3 package) is set to extend data sharing beyond payments, into savings, credit, and insurance, toward open finance.

OSMP

The OSMP is France’s payment security observatory, chaired by the Banque de France. It publishes the benchmark annual report on fraud involving non-cash payment methods, which put fraud at €1.195 billion in 2023, with a card fraud rate of 0.053%. It brings together banks, merchants, consumer groups, and public authorities, and issues authoritative recommendations on topics such as securing wallet enrollment, VoP, and authentication. Its full French name is Observatoire de la sécurité des moyens de paiement.

P

pain.001

The ISO 20022 credit transfer initiation message (Customer Credit Transfer Initiation) that a company sends to its bank, typically over EBICS. It carries the batches, execution dates, payee IBANs, and end-to-end references that will show up on the creditor’s statements. Its counterpart for collecting direct debits is pain.008.

PAN

Primary Account Number: the card number, 12 to 19 digits long (usually 16), made up of the BIN, the account identifier, and a Luhn check digit. It is the most sensitive data element in the card ecosystem and the focus of PCI DSS requirements. The long-term trend is to stop handling it in the clear altogether and use tokens instead.

PAR

Payment Account Reference (EMVCo): a 29-character reference that links a PAN to all the tokens derived from it (wallet tokens, network tokens). It lets companies recognize the same card account across its different forms, for loyalty, fraud management, or reconciliation, without ever exposing the PAN. It cannot be used to initiate a payment.

Passkey

A FIDO2/WebAuthn credential: a cryptographic key pair unique to each site, unlocked on the device by biometrics or a PIN, and phishing-resistant by design. It combines possession (the device) and inherence (biometrics), which makes it a strong candidate for banking SCA and wallet authentication. The card networks are rolling it out in Click to Pay, and issuers are starting to accept it for 3DS.

Pay-per-crawl

A mechanism Cloudflare launched in July 2025 (in beta) that lets publishers charge AI crawlers for each request to access their content, instead of blocking them or letting them scrape it for free. It reuses the HTTP status code 402 Payment Required to tell the crawler the price, paving the way for pay-per-use monetization between agents and websites. It is part of the same wave as the x402 machine-to-machine payment protocol.

PayFac

Payment Facilitator: a company that aggregates sub-merchants under its own acquiring agreement (a master MID) and its own KYB, allowing onboarding in minutes rather than days. Stripe and Square popularized the model. The PayFac carries the financial and compliance risk of its sub-merchants toward the acquirer and the card networks. In Europe, in practice, the business requires payment institution or agent status.

Payment gateway

The technical layer that carries the transaction from the merchant’s website or POS to the acquirer or processor, handling encryption, format conversion, and 3-D Secure orchestration. Unlike the acquirer, it never touches the funds and bears no financial risk. Modern PSPs bundle gateway, acquiring, and fraud prevention into a single offering.

Payment institution (PI)

PI: a status created by the first Payment Services Directive (PSD1, 2007, transposed in France in 2009) that allows a firm to provide payment services (acquiring, transfers, payment initiation, account information) without being a bank. Licensed and supervised by the ACPR, a PI is subject to capital requirements, safeguarding of funds, and AML/CFT rules, but it can neither take deposits nor grant credit except under narrow exceptions. Most European PSPs and PayFacs operate under this status.

Payment orchestration

A technical layer that sits on top of several PSPs and acquirers: smart transaction routing, cascading retries to a second acquirer after a decline, centralized tokenization (an independent vault), and unified reconciliation and reporting. It reduces dependence on a single provider and optimizes both costs and payment success rates. Providers include Payrails, Gr4vy, and Primer; large merchants also build their own.

PCI DSS

Payment Card Industry Data Security Standard: the security standard for card data (12 requirements covering networks, encryption, access, logging, and testing), managed by the PCI Security Standards Council, which the card networks founded. Version 4.0 has been mandatory since March 31, 2024, and its “future-dated” requirements since March 31, 2025 (v4.0.1 was published in June 2024). Any entity that stores, processes, or transmits card data must comply, with a validation level based on volume.

PIN

Personal Identification Number: the cardholder’s secret code, verified either online by the issuer or offline by the EMV chip. It only ever travels encrypted, in standardized PIN blocks (ISO 9564) handled by HSMs end to end. In France, it is required for contactless card payments above €50, and it remains the standard verification method for in-person payments.

PISP

Payment Initiation Service Provider: a licensed third party (under PSD2) that initiates a credit transfer directly from the payer’s bank account, with the payer’s consent, through open banking APIs. It is the foundation of pay by bank: combined with instant payments, it competes with cards in e-commerce, for large purchases, and for bill payments. The PSR (part of the PSD3 package) is meant to improve the quality and consistency of the APIs it relies on.

POS terminal

The in-store card acceptance device (known in France as a TPE, or terminal de paiement électronique). It reads chip and contactless cards, captures the PIN, requests authorization and uploads batches. It is certified under PCI PTS for hardware security and approved by the schemes it accepts (CB in France). The market is moving toward app-rich Android terminals, hardware-free SoftPOS and unified nexo protocols.

Pre-authorization

An authorization that reserves funds (a “hold”) without immediate capture, used by hotels, rental companies, and gas stations: the estimated amount ties up the cardholder’s available limit until the transaction is completed for the final amount or the hold expires. The card networks set how long it can last (from a few days to 30 days depending on the MCC) and require unused funds to be released. A pre-authorization that is never closed out is a classic source of cardholder disputes.

Processor

A technical provider that processes transactions on behalf of an issuer (issuer processing: authorizations, card portfolio management, card blocks) or an acquirer (acquiring processing: acceptance, clearing, disputes). Examples include Worldline, Fiserv, Global Payments, and Marqeta for next-generation issuing. The Interchange Fee Regulation requires schemes to separate their processing activities.

PSD2

Directive (EU) 2015/2366 on payment services, applicable since January 2018: mandatory strong customer authentication (the SCA RTS, rolled out across e-commerce in 2021), access to accounts for third parties via APIs (AISP/PISP), a ban on surcharging consumer cards, and a cap on payer liability. It made open banking a regulatory obligation rather than a commercial choice.

PSD3

Legislative package proposed by the European Commission in June 2023, combining a PSD3 directive (licensing, supervision) and a directly applicable Payment Services Regulation, or PSR (user rights, SCA, fraud). Key measures: stronger payee verification, shared liability for manipulation fraud, direct access to payment systems for payment institutions, and a merger of the e-money regime into the payment institution regime. A political agreement was reached on November 27, 2025; application is expected in the second half of 2028 at the earliest, after final adoption and a 21-month transition period.

PSP

Payment Service Provider: under PSD2, any provider of payment services, whether a bank, a payment institution, or an e-money institution. In commercial usage, the term means an online payment acceptance provider (Stripe, Adyen, Worldline, Checkout.com, and others) that combines a gateway, acquiring, fraud prevention, and reporting. The choice of PSP determines a merchant’s payment success rate, costs, and PCI scope.

R

R-transactions

The family of SEPA transactions that are sent back, each identified by an ISO reason code: reject (before settlement), return (after settlement), refund (requested by the debtor), and recall (by the originator’s bank). Their rate is the key indicator of a direct debit flow’s quality, since returned SDDs (insufficient funds, disputes) each incur a fee. R-transaction files feed collections and mandate updates.

RDR

Rapid Dispute Resolution: a Verifi (Visa) service that resolves disputes automatically before they become chargebacks. The merchant sets rules (amount, reason, MCC) under which it refunds automatically, which stops the formal chargeback before it is created. It saves case fees and representment work. Non-fraud disputes resolved this way drop out of the VAMP dispute count, but fraud reports on those transactions still count toward the VAMP ratio. The Mastercard equivalent is Ethoca Alerts.

Reason code

A standardized chargeback code, specific to each card network. At Visa, the 10.x series covers fraud (e.g., 10.4, card-absent fraud), 12.x processing errors, and 13.x consumer disputes (e.g., 13.1, merchandise not received). At Mastercard, examples are 4837 (no cardholder authorization) and 4853 (cardholder dispute). The reason code determines which evidence is admissible and the deadlines for representment. Analyzing the mix of codes guides chargeback reduction plans.

Reconciliation

End-to-end matching of orders, transactions as seen by the PSP, payouts received at the bank, and accounting entries. It relies on the PSP’s settlement reports, camt.053 statements, and shared references (RRN, ARN, end-to-end ID). It is what catches missing transactions, fee discrepancies, and duplicate payouts, a time-consuming job that orchestration and ISO 20022 data greatly reduce.

Refund

A credit the merchant sends back to the customer’s card or account after settlement. It is a separate transaction, not a cancellation of the original one, and it posts within 2 to 5 business days. The golden rule: refund to the original payment method. A refund sent separately by bank transfer does not stop a chargeback from succeeding, and the merchant ends up paying twice. The refund’s ARN serves as evidence if the cardholder disputes the charge.

Representment

Second presentment: the acquirer’s challenge to a chargeback, resubmitting the transaction with evidence supplied by the merchant, such as proof of delivery, 3-D Secure logs, customer correspondence, and order history. Response deadlines are strict (roughly 20 to 30 days depending on the network), and the case must directly address the reason code cited. Visa Compelling Evidence 3.0 now lets a merchant get alleged fraud reclassified as friendly fraud using two earlier undisputed transactions.

Request to Pay (SRTP)

SEPA Request-to-Pay, an EPC scheme live since 2021: a standardized payment request sent to the payer, who accepts it and triggers a credit transfer, ideally an instant one, in return. It is not a payment method but a messaging layer that structures A2A payments for e-invoicing, e-commerce, and the point of sale. Wero and several European banks use it as an underlying building block.

Retrieval request

A request for documentation (copy request) that the issuer sends before a potential chargeback, to obtain the sales receipt or supporting documents for the transaction. It has become rare as receipts went digital and scheme rules were simplified, but it survives for some disputes and at some networks. Missing the response deadline can lead to a chargeback with no right to representment.

Reversal

Cancellation of an authorization or transaction before clearing: the held amount is released back to the cardholder’s available limit, and no funds move. Distinct from a refund, which comes after settlement and is a separate credit transaction. The schemes require merchants to reverse unused authorizations as a matter of good practice.

Rolling reserve

Rolling reserve: the acquirer or PSP holds back a percentage of the merchant’s sales (typically 5% to 15%) for a rolling period of 90 to 180 days, to cover future chargebacks and returned payments. It is standard in high-risk sectors and those with delayed delivery: travel, ticketing, long-term subscriptions, crypto. Its terms (rate, duration, release) are negotiated in the acquiring agreement.

RRN

Retrieval Reference Number: a 12-character reference (field 37 in ISO 8583 messages) assigned to a transaction at authorization, which follows it through to settlement. It is the most widely used reconciliation key between merchant, acquirer, and issuer systems. It is printed on terminal receipts and appears in most back-office systems.

S

Safeguarding

Requirement for payment institutions and e-money institutions to protect customer funds, either by depositing them in a segregated account at a credit institution or by covering them with a guarantee or insurance policy. Safeguarded funds are out of reach of the institution’s creditors if it fails. It is the mechanism that protects the funds marketplaces and PSPs collect on behalf of third parties.

SAQ

Self-Assessment Questionnaire: the PCI DSS self-assessment form for merchants that are not subject to an on-site audit by a QSA. The applicable type depends on the integration: SAQ A (payment fully outsourced, via redirect or iframe), SAQ A-EP (the merchant’s website can affect the payment flow), and SAQ D (the merchant handles card data, with hundreds of requirements). Choosing a payment architecture is therefore first and foremost a decision about compliance scope.

SCA

Strong Customer Authentication: the strong authentication required by PSD2, based on at least two independent factors from among knowledge (a PIN or password), possession (a phone, a card), and inherence (biometrics). It applies to electronic payments initiated by the payer, with defined exemptions: low-value payments (up to €30), transaction risk analysis (TRA), and trusted beneficiaries; MITs are out of scope. Its full rollout in France in 2021 sharply reduced authenticated e-commerce fraud, at the cost of friction the industry has been working to reduce ever since.

Scheme

A payment network that defines brands, rules and infrastructure. It covers international card schemes (Visa, Mastercard, Amex), domestic ones (Cartes Bancaires (CB) in France, girocard in Germany, Bancomat in Italy), and the SEPA interbank schemes run by the EPC (SCT, SCT Inst, SDD, SRTP). The scheme sets interchange (within regulatory caps), arbitrates disputes and earns its revenue from scheme fees. Joining one requires a license, compliance and participation in settlement.

Scheme fees

Fees that card networks (Visa, Mastercard, CB and others) charge issuers and acquirers for authorization, clearing, brand licensing and optional services. They are a growing and opaque part of the MSC: the UK’s Payment Systems Regulator (PSR) found that Visa and Mastercard’s average core fees to acquirers rose by at least 25% in real terms between 2017 and 2023, with no matching improvement in service. Interchange++ pricing lets merchants see them line by line.

SCT

SEPA Credit Transfer: the standard euro credit transfer, an EPC scheme launched in 2008 and credited by the next business day (D+1) at the latest. It carries 140 characters of remittance information plus end-to-end references, and is exchanged through clearing and settlement mechanisms (CSMs). It is still the workhorse for salaries, pensions and supplier payments, though instant payments are steadily taking share.

SCT Inst

SEPA Instant Credit Transfer (2017): a euro transfer credited in under 10 seconds, 24 hours a day, 365 days a year. The scheme’s €100,000 cap was lifted as part of compliance with the Instant Payments Regulation (IPR), and each PSP now sets its own limits. It made up about 20% of euro area credit transfers in early 2025, and adoption has accelerated sharply since the IPR required it to cost no more than a standard transfer.

SDD

SEPA Direct Debit: the SEPA direct debit, based on a mandate the debtor signs in favor of the creditor (identified by its SEPA creditor identifier and the unique mandate reference). It comes in two versions. Core serves any debtor, with a no-questions-asked refund right for 8 weeks and 13 months for an unauthorized debit. B2B is for businesses only, with no refund right and a mandate registered with the debtor’s bank. Returned payments flow back as R-transactions, and the creditor is charged for them.

SEPA

Single Euro Payments Area: the single area for euro payments, covering some 40 countries (the EU, the EEA, the UK, Switzerland and microstates), where credit transfers and direct debits follow the same standards: IBAN, ISO 20022 messages and EPC schemes. Migration away from national formats was completed in 2014 in the euro area. A cross-border SEPA payment must cost the same as a domestic one.

SEPA creditor ID (SCI)

SEPA Creditor Identifier: uniquely identifies the party collecting SEPA direct debits (SDD). In France it has 13 characters (FR, check digits, a 3-character business code, and a 6-digit national creditor number), and the creditor obtains it through its bank from the Banque de France (France’s central bank). Combined with the UMR, it uniquely identifies each direct debit mandate across the SEPA area.

Settlement

Settlement: the actual transfer of funds between parties, after clearing. For a merchant, it is the payout from the acquirer (typically D+1 to D+3), net or gross of fees depending on the contract. For systemically important infrastructures, it happens in central bank money (TARGET, TIPS). The PSP’s settlement reports are the cornerstone of reconciliation.

Smart routing

Dynamic routing of each transaction to the best acceptance path: choosing the brand on a co-badged card (CB or an international network), choosing the acquirer (cost, approval rate by BIN or currency), and failing over automatically to a second acquirer after a technical error. Typical gains are a few tenths of a point of payment success rate and substantial MSC savings at high volume. It is the main selling point of payment orchestration platforms.

Soft decline

A “soft,” recoverable authorization decline: the issuer is not rejecting the card but asking for an action, typically authentication (response code 1A / 65, “SCA required”). The right move is to resubmit the transaction immediately through a 3-D Secure flow. A hard decline (stolen card, closed account, invalid card number), by contrast, must never be retried as is; the schemes penalize excessive retries.

Soft descriptor

The text that appears on the cardholder’s bank statement, configurable per transaction with most acquirers. A clear descriptor, with a recognizable business name, city or contact details, significantly reduces “unrecognized transaction” chargebacks, the leading source of unintentional friendly fraud. The schemes set rules for its format (length, PayFac prefix for sub-merchants).

SoftPOS

Turning a merchant’s smartphone or tablet into a contactless acceptance terminal with no dedicated hardware (“Tap to Pay on iPhone/Android”). Security is governed by the PCI MPoC standard, which notably allows PIN entry on the touchscreen (PIN on Glass). It is the go-to option for micro-merchants, tradespeople and delivery drivers.

Stablecoin

A crypto-asset whose value is stabilized by a peg to a currency (most often the US dollar) and backed by reserves, unlike volatile crypto-assets. The market was worth just over $300 billion in early 2026, led by Tether’s USDT and Circle’s USDC. In the EU, stablecoins fall under MiCA (as EMTs or ARTs) and, in the US, under the GENIUS Act. Their use as a payment and settlement rail is growing fast, notably for AI agents via x402.

STAN

System Trace Audit Number: a 6-digit counter (field 11 of ISO 8583 messages) assigned by the message originator and unique per day and per system or terminal. Combined with the date, time and TID, it unambiguously identifies a message exchange during incident investigations and reconciliation. It is also used to match a reversal request with the original authorization.

Stand-in

Stand-In Processing (STIP): the scheme, or the processor, authorizes transactions on the issuer’s behalf when the issuer is unavailable or responds too slowly, using pre-agreed parameters (per-transaction and per-period limits, allowed MCCs, CVV verification). It keeps the network available but shifts risk to the issuer, which only sees the transactions after the fact. Stand-in parameters are negotiated as part of scheme membership.

STET

A clearing and settlement mechanism (CSM) created by France’s major banks. It clears French retail payments (credit transfers, direct debits and CB card transactions, through its CORE(FR) system), about 30 billion transactions a year, which makes it one of Europe’s largest retail payment systems. Final settlement takes place in central bank money through TARGET. It also offers pan-European SEPA clearing and instant payment processing.

Surcharging

An extra charge a customer pays for using a particular payment method. In the EU, it is banned on consumer cards whose interchange is capped by the Interchange Fee Regulation (IFR), under a ban set by PSD2; France bans it outright for every payment method. Some countries still allow it on commercial cards, capped at the merchant’s actual cost.

SWIFT

A Belgian cooperative that runs the global interbank financial messaging network, connecting more than 11,000 institutions in more than 200 countries. It carries cross-border payment messages (the legacy MT format, then MX/ISO 20022, with coexistence ending in November 2025) but never holds the funds. SWIFT gpi has brought most international transfers under 30 minutes, with end-to-end tracking.

T

TID

Terminal ID: the identifier the acquirer assigns to a terminal, or to a logical point of acceptance, and links to a MID. It appears on customer receipts and in authorization messages, and pinpoints a transaction within a multi-lane store. It is essential for technical support, internal fraud prevention and reconciliation by point of sale.

TIPS

TARGET Instant Payment Settlement: the Eurosystem service (2018) that settles instant credit transfers in central bank money, around the clock, one transaction at a time, within seconds. The Instant Payments Regulation (IPR) and ECB decisions are pushing every euro area PSP to be reachable in it, directly or through a CSM. Unlike deferred settlement models, it removes interbank credit risk from instant payments.

Tokenization

Replacing sensitive data, above all the PAN, with a token that is worthless if stolen, while the mapping is kept in a secure vault. It comes in two forms with different life cycles: PSP proprietary tokens and scheme network tokens. Benefits: a drastic reduction in PCI DSS scope, data breaches rendered harmless, and stored credentials that keep working.

TRA

Transaction Risk Analysis: an SCA exemption based on the overall fraud rate of the PSP requesting it, up to €100 if its fraud rate is ≤ 0.13%, €250 if ≤ 0.06%, and €500 if ≤ 0.01%. The issuer can still refuse the exemption and return a soft decline requiring authentication. Key point: when the acquirer side requests the exemption, the merchant keeps the fraud liability. It is a trade-off between conversion and risk.

Trusted beneficiary

Whitelisting mechanism under PSD2: the payer adds a merchant or a transfer payee to a list held by their issuer or bank. Subsequent transactions to that payee can then be exempt from SCA. Only the payer’s bank manages the list, never the merchant.

U

UMR (mandate reference)

Unique Mandate Reference: an identifier (up to 35 characters) that the creditor assigns to each SEPA direct debit mandate. Together, the SEPA creditor identifier (SCI) and the UMR identify the mandate uniquely across the SEPA area, and they must appear in every SDD collection and in the pre-notification sent to the debtor. Changing the UMR without issuing a new mandate causes rejects.

V

Verifiable credential

A tamper-proof, cryptographically signed digital credential whose data model (W3C Verifiable Credentials Data Model 2.0) has been a W3C Recommendation since May 2025. It lets the holder prove an attribute, such as identity, authorization or a mandate, selectively and verifiably, without contacting the issuer online. A building block of the European Digital Identity Wallet (eIDAS 2.0), it also underpins mandates in agentic payment protocols such as AP2.

Verification of Payee (VoP)

A check that the payee name entered by the payer matches the actual holder of the IBAN, returning match, close match (with the closest name shown) or no match before the transfer is confirmed. It has been mandatory in the euro area since October 9, 2025 under the Instant Payments Regulation (IPR), for both instant and standard transfers. It is the main defense against fake bank details fraud and typos. The EPC has standardized the scheme and its interbank APIs.

W

Wero

EPI’s European payment wallet, built on instant account-to-account transfers: no card, so no interchange and no international scheme. Launched in 2024 for person-to-person payments (Germany, France, Belgium), it replaces Paylib in France and is expanding to e-commerce and then to in-store payments over 2025–2027. It is European banks’ bet on payment sovereignty versus Visa, Mastercard and US wallets.

X

x402

An open payment protocol launched by Coinbase in May 2025 that revives HTTP status code 402 Payment Required to build payments directly into web requests. It enables per-request micropayments settled in stablecoins (USDC), with no account and no redirect, which makes it a rail of choice for AI agents and pay-per-use APIs (including pay-per-crawl). It is one of the building blocks of a web where machines pay machines.