Skip to main content

Cards & Card Schemes

Overview

Payment cards (debit and credit) are one of the most widely used payment methods globally. They operate on card schemes โ€” networks that define rules, standards, and infrastructure for card transactions. Understanding card payments is fundamental for any banking professional.

4-Party Card Payment Scheme & Interchange Fee Engine
1. Cardholder
Payer / Customer
2. Merchant
POS / Online Store
3. Acquirer Bank
Merchant's Bank
4. Scheme Network
Visa / Mastercard
5. Issuer Bank
Customer's Bank
โšก Step 1: Real-Time Authorization (Sub-Second)
  • Cardholder taps card at POS terminal.
  • POS forwards Auth Request to Acquiring Bank.
  • Acquirer passes to Card Scheme Network (Visa/MC).
  • Scheme routes to Issuing Bank.
  • Issuing Bank checks CVV/3DS, PIN, & places a HOLD on funds.
  • Returns 6-digit Auth Code back through chain to terminal.
๐ŸŒ™ Step 2: Clearing & Settlement (Overnight Batch)
  • Merchant submits end-of-day batch of Auth Codes to Acquirer.
  • Acquirer sends clearing records to Scheme.
  • Scheme calculates net interchange fees & notifies Issuer.
  • Issuer converts account hold into a final ledger debit.
  • Acquirer credits Merchant account (net of MDR fee).

Card Types

TypeDescriptionFunding Source
Debit CardDirectly debits customer's bank accountOwn funds (transaction/savings account)
Credit CardDraws on a credit limit; pay laterCredit extended by issuing bank
Prepaid CardPre-loaded with a fixed amountPre-funded, not linked to bank account
Charge CardBalance must be paid in full monthlyCredit extended; no revolving balance
Virtual CardCard number without physical cardDigital โ€” for online/API use

Major Card Schemes

SchemeOriginNetwork TypeKnown For
VisaUSAOpen (4-party)Largest global network
MastercardUSAOpen (4-party)Second largest; Cirrus/Maestro
American Express (Amex)USAClosed (3-party)Premium, high spend
eftposAustraliaDomesticLow-cost AU debit; proprietary
UnionPayChinaOpen/ClosedLargest by cardholders
JCBJapanClosedJapan-focused, global acceptance

4-Party vs 3-Party (Closed Loop) Models

4-Party (Open Loop) โ€” Visa / Mastercard

Operates with distinct Issuing Banks (Customer) and Acquiring Banks (Merchant) connected via global scheme networks.

3-Party (Closed Loop) โ€” Amex / eftpos (domestic)

Single network acts as both Issuer and Acquirer, controlling the entire payment lifecycle end-to-end.


Card Transaction Flow (4-Party, Online)

Step / StageActing ParticipantMessage / PayloadSettlement & Ledger Impact
1. PresentmentCustomer โž” POS TerminalCard Tap / EMV Chip readEncrypted PAN and track-2 data read.
2. Auth RoutingTerminal โž” Acquiring BankISO 8583 / ISO 20022 Auth RequestMerchant's bank forwards to Visa/Mastercard scheme.
3. Scheme SwitchCard Scheme NetworkDual-message routingSwitches authorization to the customer's card issuer.
4. Issuance CheckIssuing Bank (Customer's Bank)Balance, CVV, PIN & Fraud scoringAPPROVED: Places temporary authorization hold on customer's account balance.
5. Response LoopIssuer โž” Scheme โž” Acquirer โž” POSAuth Response Code (00 = Approved)POS terminal prints receipt; merchant receives auth code.
6. Batch SettlementMerchant โž” Acquirer โž” SchemeEnd-of-day clearing batchScheme nets multi-party obligations; issuer converts holds into permanent posted debits.

Key Card Payment Concepts

Authorization vs Settlement

AUTHORIZATION:
- Happens in real-time at point of sale
- Issuing bank places a HOLD on the account
- Funds NOT yet moved
- Auth code returned (6-digit)
- Auth is valid for typically 7โ€“30 days

CLEARING:
- Merchant submits transaction data to acquirer
- Scheme processes and matches to authorization
- Interchange fees calculated

SETTLEMENT:
- Actual funds movement
- Issuing bank converts hold to final debit
- Acquirer credits merchant's account
- Net settlement via scheme

Interchange Fees

Cardholder pays $100 to Merchant

Scheme fee: $0.30 (goes to Visa/MC)
Interchange fee: $0.60 (goes to Issuing Bank โ€” card reward funded here)
Acquirer margin: $0.20 (Acquiring Bank keeps)
โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
Merchant receives: $98.90 (Merchant Discount Rate = 1.1%)

MDR (Merchant Discount Rate) = Interchange + Scheme fee + Acquirer margin

Card Networks and Least-Cost Routing (LCR)

In Australia, merchants can route debit transactions over eftpos (cheaper) instead of Visa/Mastercard:

Customer's debit card supports: Visa Debit AND eftpos

Merchant terminal routes via eftpos (cheaper interchange)
โ†’ Issuing Bank processes as eftpos transaction
โ†’ Lower cost to merchant

This is called Least-Cost Routing (LCR) โ€” mandated to be available in Australia.


Card Security

EMV Chip

  • EMV = Europay, Mastercard, Visa standard
  • Chip generates a unique cryptogram per transaction (cannot be cloned like magnetic stripe)
  • Chip + PIN is more secure than swipe + signature

CNP (Card Not Present) โ€” Online Transactions

  • Higher fraud risk since card is not physically present
  • Controls:
    • CVV/CVC (3โ€“4 digit card verification value)
    • 3D Secure (3DS) โ€” additional authentication via bank (OTP, biometric)
    • Address Verification Service (AVS)

Tokenisation

Real card number: 4111 1111 1111 1111
Token: 9876 5432 1098 7654 (merchant stores this, not real PAN)

Mapping only held by: Card scheme token vault / issuing bank
Benefit: Merchant breach doesn't expose real card numbers

PCI-DSS

Payment Card Industry Data Security Standard โ€” compliance required for any entity that stores, processes, or transmits card data:

  • 12 core requirements including encryption, access controls, monitoring
  • Annual audit (QSA) for large merchants; self-assessment for small
  • Non-compliance: fines and losing ability to accept cards

Card Disputes & Chargebacks

When a cardholder disputes a transaction:

1. Cardholder contacts issuing bank:
"I didn't make this transaction" / "Item not received"

2. Issuing Bank:
โ”œโ”€โ”€ Provisional credit to cardholder
โ””โ”€โ”€ Initiates chargeback via scheme

3. Scheme routes chargeback to Acquiring Bank

4. Acquiring Bank:
โ”œโ”€โ”€ Notifies merchant
โ””โ”€โ”€ Debits merchant's account (provisional)

5. Merchant can:
โ”œโ”€โ”€ ACCEPT chargeback (no dispute, merchant loses funds)
โ””โ”€โ”€ DISPUTE with evidence (proof of delivery, signed receipt)

6. Scheme arbitrates if both sides disagree

7. Final outcome:
โ”œโ”€โ”€ Cardholder wins โ†’ funds returned to cardholder
โ””โ”€โ”€ Merchant wins โ†’ merchant keeps funds, cardholder recharged

Chargeback Reason Codes (Visa examples)

CodeReason
10.1EMV Liability Shift โ€” counterfeit fraud
10.4Other Fraud โ€” Card Absent Environment
11.1Card Recovery Bulletin
12.1Late Presentment (too late to settle)
13.1Merchandise / Services Not Received
13.3Not as Described
13.6Credit Not Processed

eftpos (Australian Domestic Scheme)

eftpos is Australia's domestic debit card scheme:

Network: Proprietary (domestic AU)
Operator: eftpos Payments Australia Limited (ePAL)
Card type: Debit only
Key feature: Lower interchange fees than Visa Debit/Mastercard Debit
Cashout: eftpos supports cashout at point of sale (unique to AU)
Availability: POS terminals; limited online acceptance

eftpos CHQ โ†’ debit from cheque/transaction account
eftpos SAV โ†’ debit from savings account

Note: eftpos is being upgraded with digital capabilities
(eftpos token, online payments) to compete with Visa/MC

Java Spring Notes

// Card authorization request processing
@Service
public class CardAuthorizationService {

public AuthorizationResponse authorize(AuthorizationRequest request) {
// Validate card
Card card = cardRepository.findByPan(request.getTokenizedPan())
.orElseThrow(() -> new CardNotFoundException());

if (card.getStatus() != CardStatus.ACTIVE) {
return AuthorizationResponse.decline(DeclineCode.CARD_BLOCKED);
}

// Check balance / credit limit
Account account = accountService.getLinkedAccount(card);
if (!account.hasSufficientFunds(request.getAmount())) {
return AuthorizationResponse.decline(DeclineCode.INSUFFICIENT_FUNDS);
}

// Fraud check
FraudDecision fraud = fraudService.assess(request, card, account);
if (fraud == FraudDecision.BLOCK) {
return AuthorizationResponse.decline(DeclineCode.FRAUD_SUSPECTED);
}

// Place hold
String holdId = accountService.createHold(
account.getId(),
request.getAmount(),
request.getMerchantId()
);

String authCode = authCodeGenerator.generate();

return AuthorizationResponse.approve(authCode, holdId);
}
}

  • fraud.md โ€” Card fraud and CNP fraud
  • account_types.md โ€” Debit cards linked to transaction accounts
  • inbound.md โ€” Merchant settlement is an inbound credit
  • outbound.md โ€” Card debit is an outbound from customer's perspective
  • aml_kyc.md โ€” KYC required for card issuance

Interview Questions

  1. How do you reduce card fraud while preserving checkout conversion rates?
  2. What trade-offs drive scheme routing decisions between domestic and international rails?
  3. How do you design chargeback operations to control losses and customer friction?
  4. Which controls are required for PCI scope reduction in modern card platforms?

Short answer guide:

  • Use layered controls: risk scoring, 3DS strategy, and tokenization.
  • Route by cost, acceptance, and dispute profile constraints.
  • Standardize evidence workflows and reason-code analytics.
  • Minimize PAN exposure and segment systems rigorously.
Interview Focus

Connect auth, clearing, settlement, and chargeback operations into one coherent lifecycle.

Interview Trap

Treating authorization approval as equivalent to settled funds.

๐Ÿ“–
Track Page Progress0 / 635 Read
Knowledge Base Completion0%