MIT (Merchant Initiated Transaction)
A payment initiated by the merchant without the cardholder present (e.g., subscriptions, instalments), based on prior consent.

A merchant-initiated transaction, or MIT, is a card payment the shop sets off without the cardholder there or doing a thing at that moment. Visa's own notes define it as any payment a merchant starts as a follow-on to an earlier payment the cardholder made. A monthly plan charging on the first of the month. A hotel billing a no-show fee. A top-up when a prepaid balance runs low. All of these happen because the shop decided the moment had come, using card details it already holds.
The category exists because the other way round does not work. Repeat trade would fall over if every renewal needed the buyer to open an app and tap yes. Card networks saw that and built a formal framework rather than leave shops to make it up. Visa's stored credential transaction framework sets out how these payments should be flagged. It also sets out what has to happen before a shop may store card details at all. The framework is not optional, and the flagging rules have a real effect on how often a payment is approved.
The First Payment Comes From The Customer
An MIT cannot really stand on its own. It follows a first payment, known as a CIT, where the buyer took part and where the card details were stored. Visa asks the shop to send a payment at that point if a sum is due. If nothing is owed yet, it asks for an account check instead. Skip that step and the chain has no root.
Consent Is Not A Tick Box
Before storing card details, Visa expects the shop to have a deal with the cardholder on how those details will be used. That covers the sums, how often they fall due, how to cancel, and how the buyer will be told. It is a much higher bar than a tick box at checkout. Shops that treat consent as a formality tend to find the gap during a dispute, when the proof they need is the proof they did not take.
Why MITs Sit Outside The SCA Rules
This point gets stated wrongly more than almost anything else in European payments. The European Banking Authority's Q&A on payee-initiated card payments states that payments not started by the payer, but by the payee alone, fall outside strong customer authentication. That puts MITs out of scope rather than let off. An SCA exemption is a different lever with different results. Mixing the two up leads to wrong flags.
The Check Moves, It Does Not Vanish
The EBA is clear that where a mandate is set up down a remote channel, setting up that mandate needs a full check of its own. So the friction shifts to the first payment instead of going away. Its guidance on hotel scenarios makes this real. Card details taken at booking purely as a guarantee still need a full check at that point. Later charges for deposits, a late cancel or extras then fall under the general rules. This holds in the EEA, and other markets take other roads.
Recurring, Instalment And Unscheduled Types
Not all MITs behave the same, and the networks tell them apart. A scheduled recurring payment has a set sum and a set gap. An instalment run has a known total split across known dates. An unscheduled credential on file payment fires on a trigger rather than a date, such as a balance top-up. Flagging the wrong type is a common cause of declines that make no sense from the shop's side.
Linking Later Payments To The First
Networks expect a reference tying each MIT back to the first checked payment. An issuer can then see the chain rather than a stream of odd charges. Visa's framework brought in a set entry mode value at the till for stored card payments from October 2017. Visa's acceptance notes also say that in the European Union the Mastercard trace ID was needed on later payments. Rules differ by network and by region, so this is worth checking per market.
Why Correct Flagging Affects Approvals
An issuer judging a payment with no cardholder there leans hard on the flags and references it gets. A payment marked as a follow-on to a checked mandate reads very unlike an unflagged one. The second looks like a card-not-present payment nobody checked. Wrong labels tend to push payments towards a soft decline or a flat no. The shop then sees the symptom rather than the cause.
Practical Guidance For Getting MITs Right
Four things matter most. Store the card details properly at the CIT stage. Keep the consent record. Flag each later payment with the right type. Carry the linking reference. Beyond that, keeping stored details current matters, because out-of-date or replaced cards are a leading cause of failed renewals. That is why account updater services exist. finera.'s guidance on smart 3D Secure and reducing payment declines covers the checks side of the same problem, where the goal is the right treatment rather than the heaviest.
Frequently Asked Questions
The cardholder isn't actively participating. Visa defines an MIT as a transaction the merchant initiates as a follow-on to an earlier cardholder-initiated transaction, using credentials already stored. A standard payment involves the customer at the moment of the charge; an MIT doesn't.
In the EEA they're out of scope rather than exempt, which is an important distinction. The EBA states that transactions initiated by the payee only aren't subject to SCA. However, where the mandate is set up remotely, that initial setup does require authentication.
Visa expects an agreement with the cardholder covering how the credential will be used, including amounts, frequency, cancellation policy and notification procedures, plus either a payment transaction or an account verification authorisation to establish the credential.
Often because of flagging. An issuer seeing an unflagged transaction with no cardholder present and no link to an authenticated mandate assesses it much less favourably than a correctly identified follow-on transaction. Expired or reissued cards are the other main cause.
A recurring payment has a fixed amount and interval. An unscheduled credential-on-file transaction fires when a trigger occurs rather than on a schedule, such as topping up a balance that has run low. Networks treat them as distinct types and expect them flagged accordingly.

Still Have Questions?
Let’s Find the Right Solution for You
Stay Connected with Us!
Follow us on social media to stay up to date with the latest news, updates, and exclusive insights!


