Skip to main content
Category: Payment Ecosystem

Acquirer

Also known as: Acquiring bank, Merchant acquirer, Credit card acquirer
Simply put

An acquirer is a bank or financial institution that processes and settles card payments on behalf of merchants. It acts as an intermediary between a merchant, the card payment networks such as Visa and Mastercard, and the customer's card-issuing bank, giving the merchant the ability to accept and collect card payments.

Formal definition

An acquirer is a financial institution licensed by one or more card networks to enter into merchant agreements and process and settle card-based transactions on behalf of merchants. Functioning as the intermediary between the merchant, the card networks, and issuers, the acquirer submits authorization and clearing/settlement messages, funds the merchant for approved transactions, and manages the merchant account relationship. In a card payment security context, the acquirer typically bears responsibility for its merchants' adherence to card network and PCI DSS requirements; the specific compliance validation and reporting obligations imposed on merchants are governed by individual card brand rules, which vary by network and region and should be confirmed against current published requirements. Note that the term 'acquirer' is also used more generally in corporate finance to mean an entity that obtains rights to a company through a transaction; that usage is distinct from the payments meaning defined here.

Why it matters

The acquirer is the entity through which a merchant gains access to the card payment networks, so it sits at the center of both the commercial and the security relationship that allows card payments to be accepted, authorized, and settled. Without an acquirer, a merchant cannot submit authorization and clearing/settlement messages to networks such as Visa and Mastercard or receive funds for approved transactions. This makes the acquirer a foundational participant in the payment ecosystem and a natural point of accountability for how a merchant handles payment card data.

From a security and compliance standpoint, the acquirer typically bears responsibility for ensuring that its merchants adhere to card network and PCI DSS requirements. The specific validation and reporting obligations imposed on any given merchant are set by individual card brand rules, which vary by network and region and change over time; these should always be confirmed against current published requirements rather than assumed. Because the acquirer manages the merchant account relationship, it is also the channel through which compliance expectations, and the consequences of non-compliance, are communicated and enforced.

It is worth distinguishing this payments meaning of 'acquirer' from the corporate finance sense, in which an acquirer is an entity that obtains rights to a company or business relationship through a friendly or hostile transaction. The two usages are unrelated, and conflating them can cause confusion in documentation and contracts that touch both payments operations and corporate structure.

Who it's relevant to

Merchants
Merchants rely on an acquirer to gain the ability to accept and collect card payments and to receive funds for approved transactions. The acquirer is also the counterparty through which a merchant's PCI DSS and card network compliance obligations are typically communicated and enforced, with the specific validation requirements varying by card brand and region.
Compliance officers and merchant risk teams
Because the acquirer typically bears responsibility for its merchants' adherence to card network and PCI DSS requirements, compliance and risk teams work with acquirer relationships to understand and meet applicable validation and reporting obligations, which should be confirmed against current published card brand rules rather than assumed to be fixed.
Payment processors and payment ecosystem participants
Processors, issuers, and card networks interact with the acquirer as the intermediary that submits authorization and clearing/settlement messages and manages the merchant account relationship. Understanding the acquirer's role is essential to mapping where transactions flow and where responsibility for merchant compliance sits within the ecosystem.

Inside Acquirer

Acquiring bank (acquirer)
A financial institution, licensed by one or more card brands, that maintains merchant accounts and enables merchants to accept card payments by facilitating authorization, clearing, and settlement of card transactions.
Merchant relationship and underwriting
The acquirer's function of onboarding, underwriting, and monitoring merchants, including assessing merchant risk, assigning merchant category codes, and holding responsibility for merchant behavior under card brand rules.
Settlement and funds flow
The acquirer's role in receiving transaction data from the merchant, routing it through the card networks, and settling funds into the merchant account, typically net of fees and any withheld reserves.
PCI DSS compliance oversight
The acquirer's responsibility to require and track its merchants' PCI DSS validation, often driving the merchant's validation level and reporting obligations, though the specific requirements are defined by the current published PCI DSS and card brand programs rather than by the acquirer alone.
Chargeback and dispute handling
The acquirer's participation in the dispute lifecycle, representing the merchant side against the issuer, where chargeback and liability rules are governed by card brand and network rules that vary by region and change over time.
Distinction from processor
The acquirer holds the card brand license and merchant risk, while a payment processor may handle the technical transaction routing; a single entity may perform both roles but they are conceptually separate functions.

Common questions

Answers to the questions practitioners most commonly ask about Acquirer.

Is the acquirer the same as the payment processor?
Not necessarily. The acquirer is the financial institution that holds the merchant relationship and is licensed by the card brands to acquire transactions, while a payment processor performs the technical handling of transaction messages. A single entity may perform both roles, but they are distinct functions and are often provided by different organizations. Payment facilitators and independent sales organizations may also sit between the merchant and the acquirer, so the labels should be confirmed for a given arrangement rather than assumed.
Does the acquirer set the chargeback and liability-shift rules that apply to my transactions?
No. Chargeback processes and liability-shift outcomes are governed by the card brand and network rules, which vary by region and change over time. The acquirer administers and applies those rules within the merchant relationship and passes disputes and representments between the parties, but it does not define them. Merchants should confirm current dispute rights and timeframes against the applicable brand rules rather than treating the acquirer as the source of those rules.
How does an acquirer relationship affect a merchant's PCI DSS validation obligations?
Acquirers commonly require merchants to validate PCI DSS compliance and may specify the validation level, reporting method, and deadlines based on transaction volume and channel, consistent with card brand programs. The specific requirements and how they are reported can differ between acquirers and card brands, and requirement numbering and wording differ between PCI DSS versions. Merchants should confirm their assigned validation level and reporting obligations directly with their acquirer and against the current published standard.
What information do I need to provide an acquirer during merchant onboarding?
Onboarding typically involves underwriting and risk review, which may call for business and ownership details, expected processing volumes, the sales channels used (card-present versus card-not-present), and information about the payment technology and any intermediaries such as processors or payment facilitators. The exact requirements depend on the acquirer's risk policies and applicable brand and regulatory rules, so confirm the specific documentation with the acquirer.
How does the choice of acquirer interact with tokenization or point-to-point encryption for scope reduction?
Some acquirers offer or partner on tokenization services or PCI P2PE-validated solutions that can reduce the merchant's PCI DSS scope, but tokenization, encryption, and P2PE affect scope differently and only when properly implemented and validated. The label alone does not determine the scope impact. Merchants should confirm which solution is offered, whether it is validated under the relevant standard, and how the acquirer expects scope reduction to be documented.
Who do I coordinate with on fraud monitoring and chargeback thresholds under an acquirer relationship?
Acquirers generally monitor merchant activity for fraud and chargeback ratios and may enforce card brand monitoring programs, applying remediation steps or fees when thresholds are exceeded. These thresholds and program details are set by the card brands and applied by the acquirer and can vary by region and change over time. Merchants should coordinate with their acquirer's risk team to understand current thresholds, reporting, and any required corrective actions.

Common misconceptions

The acquirer and the payment processor are the same thing.
The acquirer is the licensed institution holding the merchant account and the underlying merchant risk, while a processor provides technical transaction handling. One organization may perform both roles, but the functions are distinct and can be provided by different parties.
The acquirer defines the merchant's PCI DSS obligations.
The acquirer administers and enforces validation and reporting for its merchants, but the actual requirements come from the current published PCI DSS and the card brands' compliance programs. Requirement numbering and wording differ between versions, so obligations should be confirmed against the current standard.
The acquirer sets and controls chargeback and liability outcomes.
The acquirer represents the merchant in disputes, but chargeback processes, liability shift, and related rules are governed by card brand and network rules that vary by region and change over time.

Best practices

Clarify contractually and operationally which entity holds the acquiring license and merchant risk versus which entity provides technical processing, so responsibilities are not assumed based on labels.
Track each merchant's PCI DSS validation level and reporting status against the current published standard and applicable card brand programs, rather than relying on a fixed requirement number or prior version.
Apply risk-based underwriting and ongoing monitoring of merchants, including merchant category and transaction patterns, to help reduce exposure to fraud and portfolio risk.
Ensure dispute and chargeback workflows reference the current card brand and network rules for the relevant region, since liability shift and chargeback rules vary and change.
Coordinate with merchants on scope-reducing controls such as tokenization, truncation, or P2PE, recognizing that their effect on PCI DSS scope depends on implementation and validation, not the label.
Confirm that merchants do not retain sensitive authentication data after authorization, distinguishing it from cardholder data that may be stored under defined controls.