To accept cards, a merchant signs a contract. Behind that contract, four set-ups are possible, and the one who sold it is not always the one who answers for it.
No merchant deals with Visa or Mastercard directly. They go through an intermediary that signs them up, registers them with the networks (the schemes), carries their transactions and pays them their money. That business is acquiring.
Four tasks, two permissions, two authorities:
Two applications, two authorities, and a connection that is either built or bought.
Three layers, obtained separately. The merchant only ever sees one name.
Four different players can say “we do acquiring”. What sets them apart: who holds the permissions, who you sign with, and who answers for you to the network.
holds the permissions and answers for you to the network
underlined the name on your contract
A kitchen retailer sells a €8,000 kitchen, paid by card in store, delivery in three months. The company is liquidated in the meantime. The customer disputes the charge, their bank refunds them and recovers the money from the acquirer, who has no one left to turn to. The fee earned was a few dozen euros; the loss runs to thousands. In this chain, it is the only one that can lose a hundred times what it earned on the sale. And that was card-present, in a shop.
Except the acquirer knows this risk. With a merchant that gets paid before delivering, it has four defences:
None can be improvised on the day the loss hits: all of them assume it took a close look at who it was signing up.
The dispute window, meanwhile, stays long: on goods paid for in advance, the networks give the cardholder up to 120 days after the expected delivery date. That is also why accepting cards online costs more than in store. Not because of interchange (the European caps are the same on both channels), but because of fraud and a longer exposure.
Because it answers for its merchants, the acquirer chooses which ones it accepts, and it has to know who it is dealing with before signing. That is KYB (Know Your Business), due diligence on the business customer. It is not a commercial precaution; it is an anti-money-laundering and counter-terrorist-financing obligation, and the acquirer is accountable for it to its regulator. A commercially excellent application can be declined on that ground alone.
Otherwise: declined at the door, contract closed along the way.
The checks do not stop at onboarding: the merchant has to be monitored over time, to spot the one whose activity no longer matches what was declared. Every institution appoints a compliance officer, and the monitoring gets automated as portfolios grow. In Europe, the framework is tightening: the anti-money-laundering package adopted in 2024 moves most obligations into a directly applicable regulation, in force from July 2027, and creates a European supervisory authority, AMLA.
A payments concept that still escapes you?
Suggest the next topic