Depending on the card, the issuer advances the cardholder's money for a day or a month. It blocks amounts it never actually takes. And when its servers stop answering, it has often already said yes.
On the merchant side, the card presented changes nothing about the settlement timeline: they get paid under their acquiring contract, whatever the card. On the cardholder side, everything depends on the card type. Either way, it is the issuer who advances the money.
In blue: the period during which the issuer carries the money.
Immediate debit. The account is debited when the transaction is processed, usually the next day. The issuer advances the money for barely a day.
Deferred debit. The account is debited only once a month, on the statement date. Since each cardholder is debited once a month, the issuer permanently carries half a month's spending across its whole portfolio.
Credit. The cardholder repays whenever they choose and pays interest. The balance never empties.
An issuer does not issue a card. It opens a line of risk, and holds it for years.
When you fill up the tank or check into a room, nobody yet knows how much you will owe. So the merchant asks for authorisation on an estimated amount, the pre-authorisation. That amount is reserved against what your card can still commit, the limit. Nothing has actually left, your balance is unchanged.
The second message replaces the first. The surplus never left the account.
The actual amount arrives in a second message, and the surplus then has to be released. At a fuel pump, network rules count that delay in minutes. On a hotel room or a car rental, the reservation can stay valid for thirty days.
In August 2025, the authorisation servers of several major French banks went down. For more than two hours, their customers could not pay or withdraw by card. Logical enough: the issuer had stopped answering. And yet a payment can go through without the issuer ever answering. There are two mechanisms for that, and in both cases it is the issuer who set the rules in advance.
| Where | Who decides in its place |
|---|---|
| In the chipoffline payment | the card and the terminal, without calling anyone |
| At the networkstand-in | the network, within limits the issuer has entrusted to it |
In the chip. When the card is manufactured, the issuer writes its rules into it. Below certain thresholds, the card and the terminal decide on their own, without calling anyone: that is offline payment, a standard mechanism defined by the EMV specification. CB has used it since its early days, initially to limit calls to the server and cut costs.
At the network. When the transaction goes out for online authorisation, a resilience mechanism is needed too. The issuer sets limits that the network applies in its place if it does not answer in time: that is stand-in (STIP). The message reaches the network but not the issuer.
That day in August exposed the limit: contactless, now the majority of payments, cannot do without an answer from the issuer. Acceptance resilience has become a critical issue for the whole industry.
The previous episode said it: you start under someone else's licence, then go and get your own. What it did not say is where. An authorisation obtained in one European Economic Area state is valid in the other twenty-nine: that is the passport. So the country is a choice, and a single trajectory is enough to see what it turns on.
A country of authorisation is not a permanent address: it is an operating trade-off, redone every time scale changes.
A payments concept that still escapes you?
Suggest the next topic