Glossary
Payment Authorisation

Payment Authorisation

Payment Authorisation is the step where the issuer approves or declines a transaction request before funds are captured.

GLOSSARY
What is a
Payment Authorisation

Payment authorisation is the step where the customer's bank decides whether a payment can go ahead. The request leaves the shop, travels through the card network, and reaches the bank that issued the card. That bank checks the account, the balance or credit line, and its own risk signals, then answers yes or no. When the answer is yes, the amount is usually held against the account rather than taken. No money has moved. That happens later, at capture.

Two things get run together here and are worth keeping apart. There is the technical approval just described, and there is the legal question of whether the customer agreed to the payment at all. UK payment rules treat a payment as authorised only where the payer has consented to it, and regulation 67 sets out how that consent may be given and withdrawn. So a payment can be approved by the bank and still be unauthorised in law, and that gap is the basis of most fraud claims a shop will meet.

What The Bank Weighs In Under A Second

The bank looks at several things at once. Whether the card is valid and not reported lost. Whether funds or credit are there. Whether the amount, the shop type and the place fit the account's usual pattern. Whether the shopper has been checked, and to what standard. All of that is scored in a fraction of a second and comes back as a code, and that code carries more meaning than a plain yes or no. Reading the decline code matters as much as counting approvals.

Approval Holds, Capture Takes

Approval reserves the money. Capture is the separate instruction that moves it. Many shops capture when goods leave the warehouse, not when the order is placed, and that is the job delayed capture does. Holds do not last forever. They run out after a period that varies by card type and by market, and once one has gone the business has to ask again with a fresh chance of refusal. On made-to-order goods and long lead times, that is a real risk rather than a theoretical one.

When The Final Amount Is Not Yet Known

Hotels, car hire firms and fuel stations all face the same problem. They need comfort that the customer can pay before anyone knows the figure. A pre-authorisation hold covers that gap. The EU law behind much of this treats blocked funds with care. Article 75 says the payer must consent to the exact amount blocked, and that the funds are to be released without undue delay once the real figure is known. UK rules follow the same shape, and the detail differs by market.

The Identity Check Attached To The Request

In the UK and the EU many remote payments carry an identity check before the bank will decide. The technical standards say a code may be accepted only once, and that a new code must not be workable out from an old one. Article 4 of those standards sets out both points. Passing that check usually moves fraud risk towards the bank that issued the card. Liability shift rules vary by card network and are updated periodically, so merchants should confirm current rules with their acquirer or the relevant card scheme.

What Staff See At The Counter

From the shop's side the answer arrives as a code and a short message. An approval carries a reference that has to be kept, because the capture and any later refund both point back to it. A refusal carries a reason, though how much of that reason survives the journey varies by bank and by route. Front line staff see none of this. They see a screen saying the card was declined, which is why a simple script beats a detailed one, and why suggesting a different card beats trying the same one again.

Local Decisions When The Bank Cannot Be Reached

The request does not get through on every occasion. Offline authorisation lets a terminal and a chip card decide on the spot, inside limits loaded in advance. Voice authorisation covers a phone call for a manual code. Both are narrower than they once were, and both carry more risk to the business, because the bank has not seen the payment at the moment it was accepted.

Refusals That Have Nothing To Do With Money

A large share of declines have no link to the balance on the account. A bank may refuse because the amount passes a per-payment ceiling, because several payments have run in a short window, or because the shop's category does not fit the account's history. Limit management on the business side and speed rules on the bank side both shape this. A zero amount authorisation offers a way to check a card is live without holding anything at all.

Habits That Lift Approval Rates

Send full data with every request. A thin request gives the bank less to work with, and thin requests decline more. Capture close to dispatch, and watch for holds about to run out. Read decline codes and act on the reason given. Where a carve-out from the identity check applies, know who carries the fraud risk when you use it. And review approval rates by market, card product and route, not as one blended figure. That is the approach in this guide to maximising card approval rates. A payment gateway is where most of these settings live, and payment analytics is designed to help make the pattern visible.

‍

Table of contents

Frequently Asked Questions

Is an approved payment the same as a paid one?

No. Approval reserves the amount and signals that the bank is willing to release it. The money moves at capture, which can be moments later or days later. Many retailers capture when goods are dispatched. Until then the customer sees a hold rather than a completed charge, which is a common source of confusion.

How long does an approval stay valid?

It expires after a period that varies by card type, by market and by merchant category. Once it lapses the business has to ask again, and the second request can be refused even though the first was approved. Monitoring holds that are approaching expiry avoids that outcome on longer fulfilment cycles.

Why do payments get declined when funds are available?

Often for reasons unrelated to the balance. The amount may exceed a per-transaction ceiling, several payments may have run in a short window, or the merchant category may not fit the account's usual pattern. Reading the decline code rather than assuming a funding problem is what makes these cases fixable.

What is the difference between authorisation and consent?

Authorisation is the bank's technical decision. Consent is the customer's agreement. UK payment rules treat a payment as authorised only where the payer has consented to it. A payment can therefore be approved by the bank and still be unauthorised in law, which is the basis of most fraud claims.

Does passing an authentication check change who pays for fraud?

Generally it shifts fraud risk towards the bank that issued the card, but the detail varies by card network and the rules are updated periodically. Merchants should confirm current rules with their acquirer or the relevant card scheme rather than relying on a general position.

Still Have Questions?

Let’s Find the Right Solution for You

Share this article
Glossary

Stay Connected with Us!

Follow us on social media to stay up to date with the latest news, updates, and exclusive insights!