Cardholder-Initiated Transaction
A Cardholder-Initiated Transaction (CIT) is a card payment that the cardholder actively starts and takes part in, such as entering their card details or authenticating a purchase. It contrasts with a Merchant-Initiated Transaction (MIT), which a merchant processes later without the cardholder being present. The distinction matters because card brand rules treat these transaction types differently, particularly when a card is stored for future use.
A Cardholder-Initiated Transaction (CIT) is a transaction within the card brand CIT/MIT framework in which the cardholder is actively present and participates in the payment flow, including providing payment credentials and, where applicable, authenticating the transaction. Under this framework, a CIT typically serves as the initial transaction that establishes cardholder consent and may create a stored credential (credential-on-file), after which subsequent follow-on transactions processed by the merchant without cardholder participation must be flagged and processed as Merchant-Initiated Transactions (MITs) according to the applicable MIT framework. The specific requirements for indicators, consent capture, and stored-credential handling are defined by individual card brand and network rules, which vary by region and change over time; practitioners should confirm current requirements against the relevant card brand specifications rather than assuming fixed rules. The CIT/MIT distinction governs transaction identification and processing and is separate from PCI DSS data-protection requirements for cardholder data and sensitive authentication data.
Why it matters
The Cardholder-Initiated Transaction (CIT) distinction is foundational to how card brands and networks want stored credentials handled. When a cardholder actively participates in a payment and consents to store their card for future use, that CIT typically establishes the consent and the credential-on-file relationship. Every follow-on transaction the merchant later processes without the cardholder present must then be identified and processed as a Merchant-Initiated Transaction (MIT) under the applicable MIT framework. Misclassifying these transactions can lead to declines, higher authorization friction, and non-compliance with card brand stored-credential requirements.
For merchants and processors, getting the CIT/MIT flagging right affects both approval rates and regulatory alignment. Correctly signaling that a transaction is cardholder-initiated—and capturing the required consent when a credential is first stored—helps issuers make better authorization decisions and supports downstream MIT processing. Because the specific indicators, consent-capture rules, and stored-credential handling requirements are defined by individual card brands and vary by region and over time, teams cannot assume a fixed rule set; they must confirm current requirements against the relevant card brand specifications.
It is important to keep the CIT/MIT framework separate from data-protection obligations. The framework governs transaction identification and processing, not how cardholder data or sensitive authentication data is stored and secured. PCI DSS data-protection requirements apply independently, and correctly flagging a transaction as a CIT does nothing to relieve a merchant of its obligations around protecting cardholder data or refraining from storing sensitive authentication data after authorization.
Who it's relevant to
Inside CIT
Common questions
Answers to the questions practitioners most commonly ask about CIT.