Skip to main content
Category: Payment Ecosystem

Acquiring Bank

Also known as: Acquirer, Merchant Bank
Simply put

An acquiring bank is a bank or financial institution that processes credit and debit card payments on behalf of a merchant. It represents the merchant in the payment process, moving card transactions through the payment flow so the business can be paid for sales. It contrasts with an issuing bank, which represents the cardholder or customer.

Formal definition

An acquiring bank, or acquirer, is the financial institution that maintains the merchant's account and processes card transactions on the merchant's behalf, facilitating authorization, settlement, and the transfer of funds owed to the merchant. In the four-party card model, the acquirer represents the merchant side of a transaction, while the issuing bank represents the cardholder side; the two interact through the card networks. As the entity that contracts with merchants and routes transaction data, the acquirer typically imposes contractual obligations related to card acceptance and applicable security requirements, though the specific standards, liability terms, and network rules governing these relationships are defined by the card brands and networks and vary by region and over time.

Why it matters

The acquiring bank is the merchant's entry point into the card payment ecosystem, and it is typically the entity that passes down card acceptance and security obligations to the businesses it serves. Because the acquirer contracts directly with merchants and routes their transaction data, it often functions as the enforcement point for requirements such as PCI DSS validation, monitoring merchant risk, and managing the flow of authorization and settlement. Compliance officers and merchant risk teams frequently interact with acquirers first when questions of card acceptance, data handling, or contractual security terms arise.

Understanding the acquirer's distinct role matters because it sits opposite the issuing bank in the four-party model. The acquirer represents the merchant side of a transaction while the issuer represents the cardholder side, and the two interact through the card networks. Conflating these roles can lead to misunderstandings about who bears responsibility for a given control, dispute, or liability outcome. The specific standards, liability terms, and network rules that govern the acquirer-merchant relationship are defined by the card brands and networks, and they vary by region and change over time, so exact obligations should be confirmed against current network and brand documentation rather than assumed.

For fraud and risk functions, the acquirer is also a key participant in how transaction data moves and how card acceptance obligations are imposed. Because the acquirer maintains the merchant account and routes transactions, it is positioned to apply contractual security requirements and to act on merchant risk. The precise division of responsibility for fraud losses, chargebacks, and liability, however, depends on card brand and network rules that differ by region and evolve, and should not be treated as fixed.

Who it's relevant to

Merchant risk and compliance teams
Merchants interact with the acquirer as the institution that maintains their account, routes their transactions, and passes down card acceptance and security obligations. Compliance and risk staff should understand what contractual and security requirements the acquirer imposes, recognizing that the specific standards and terms are set by the card brands and networks and vary by region and over time.
Payment processors and acquiring-side operations
Those operating on the acquiring side facilitate authorization, settlement, and the transfer of funds owed to merchants, routing transaction data through the card networks. A clear grasp of the acquirer's position on the merchant side of the four-party model helps ensure transaction flows and responsibilities are correctly attributed relative to the issuing side.
Fraud analysts
Because the acquirer maintains the merchant account and routes transactions, it is a relevant participant when assessing merchant-side risk and card acceptance. Analysts should note that responsibility for fraud outcomes, chargebacks, and liability is governed by card brand and network rules that differ by region and change over time, rather than being fixed by the acquirer role alone.
Security engineers
Engineers designing systems that transmit or process card transactions should understand that the acquirer routes transaction data and typically imposes security-related contractual obligations. The applicable requirements are defined by the card brands and networks and should be confirmed against current published standards rather than assumed to be static.

Inside Acquiring Bank

Merchant Account Provisioning
The acquiring bank (acquirer) establishes and maintains the merchant account that enables a business to accept card payments, including underwriting, risk assessment, and the terms governing settlement of funds.
Authorization Routing
The acquirer receives authorization requests from the merchant's payment environment and routes them through the card networks to the issuing bank for approval or decline, then returns the response.
Clearing and Settlement
The acquirer participates in clearing transaction data and settling funds to the merchant, less applicable fees, in accordance with card brand and network rules that vary by region and change over time.
Chargeback and Dispute Handling
The acquirer processes chargebacks and represents merchants in dispute cycles governed by card brand and network rules, which differ by region and are subject to change.
Compliance and Risk Oversight
The acquirer holds responsibility for overseeing merchant adherence to applicable card brand requirements, including validation of PCI DSS compliance for merchants in its portfolio, and for monitoring merchant fraud and chargeback risk.

Common questions

Answers to the questions practitioners most commonly ask about Acquiring Bank.

Does the acquiring bank issue the payment cards it processes transactions for?
No. The acquiring bank (or acquirer) maintains the merchant's account and processes card transactions on the merchant's behalf, but it does not issue cards to cardholders. Card issuance is the role of the issuing bank, which holds the cardholder relationship. Confusing the two roles obscures where liability and certain fraud responsibilities sit, since acquirers and issuers have distinct obligations under card brand and network rules.
Is the acquiring bank the same thing as a payment processor or payment gateway?
Not necessarily. An acquiring bank is the financial institution that holds the merchant account and is a member of the card networks. A payment processor or gateway may provide the technical connectivity and message routing, sometimes on the acquirer's behalf. A single entity can play more than one role, but the terms are not interchangeable, and contracts and compliance responsibilities should identify which party performs which function.
What are an acquiring bank's responsibilities regarding merchant PCI DSS compliance?
Acquirers commonly manage the process by which their merchants validate PCI DSS compliance, including determining applicable validation requirements based on the merchant's level and transaction profile. The specific obligations, reporting expectations, and validation methods are shaped by card brand and network programs, which vary by region and change over time. Confirm current requirements against the applicable card brand programs and the current published PCI DSS rather than assuming fixed criteria.
How does the choice of acquirer affect a merchant's PCI DSS scope?
The acquirer relationship itself does not automatically define scope; scope depends on how cardholder data is handled, transmitted, and stored across the merchant's environment and its service providers. However, the acquirer may influence which validation path applies and may support integrations such as tokenization or point-to-point solutions that, depending on implementation and validation, can affect scope. Whether a given approach reduces scope depends on the specific implementation and its validation, not on the label alone.
What role does the acquiring bank play in chargebacks and dispute handling?
The acquirer typically represents the merchant in the dispute and chargeback process, receiving chargebacks initiated through the issuer and card network and facilitating any representment. The timelines, reason codes, evidence requirements, and any liability shift are governed by card brand and network rules, which vary by region and change over time. Merchants should confirm the current applicable network rules through their acquirer rather than relying on generalized dispute procedures.
What information does an acquiring bank generally need from a merchant during onboarding?
Onboarding commonly involves underwriting and risk assessment, so acquirers typically request business and ownership details, expected transaction volumes and profiles, and information relevant to the merchant's risk category. Acquirers also generally establish how the merchant will validate and evidence PCI DSS compliance. The precise documentation and controls required depend on the acquirer's programs and the applicable card brand and network requirements, which should be confirmed directly.

Common misconceptions

The acquiring bank and the issuing bank are the same entity or interchangeable roles.
They are distinct parties. The acquirer maintains the merchant relationship and processes transactions on the merchant side, while the issuer holds the cardholder relationship and authorizes or declines transactions. A single financial institution may act in both roles for different portfolios, but the functions are separate.
The acquiring bank assumes PCI DSS compliance responsibility on behalf of its merchants.
The acquirer typically oversees and validates merchant compliance as required by card brand rules, but the merchant remains responsible for meeting the applicable PCI DSS requirements for its own environment. Confirm current obligations against the published standard and the acquirer's program, as requirement numbering and wording differ between PCI DSS versions.
Chargeback and liability-shift outcomes are set by the acquiring bank.
Chargeback processes and liability shift are governed by card brand and network rules, which vary by region and change over time. The acquirer administers these processes for the merchant but does not unilaterally define the underlying rules.

Best practices

Confirm the division of responsibilities between merchant and acquirer in writing, including who validates PCI DSS compliance and against which current published version of the standard.
Verify the acquirer's supported authorization, clearing, and settlement flows and ensure they align with the merchant's payment environment and scope.
Establish clear procedures with the acquirer for chargeback and dispute handling, recognizing that governing rules are set by card brands and networks and vary by region.
Monitor merchant-level fraud and chargeback metrics in coordination with the acquirer's risk program, and treat detection thresholds as trade-offs subject to false positives and false negatives.
Do not rely on the acquiring relationship to satisfy PCI DSS obligations; maintain and evidence the merchant's own compliance for its cardholder data environment.
Reconcile settlement reporting against expected funds and fees regularly, and confirm any rule or program changes with the acquirer as card brand requirements evolve.