What is Issuer?
The bank that issues a payment card to a cardholder and authorises or declines transactions on it.
An issuer, or issuing bank, is the financial institution that provides a payment card (credit, debit, or prepaid) to a cardholder and maintains the customer's account.
As members of card schemes like Visa and Mastercard, issuers are responsible for underwriting the consumer or business, setting credit limits or managing deposit accounts, and handling all aspects of the cardholder relationship, including billing, rewards, and customer service.
They bear the primary credit and fraud risk in the payment ecosystem, a risk for which they are compensated via the interchange fee collected on every transaction.
During a transaction, the issuer is the ultimate decision-maker. After an authorisation request travels from the merchant's acquirer through the card scheme network, it arrives at the issuer.
The issuer's systems must then analyse the request in real-time, typically within milliseconds.
This decision involves checking for sufficient funds or available credit, verifying security data like the CVV and AVS, assessing the 3D Secure authentication result (if present), and running the transaction against sophisticated internal fraud and risk-scoring models.
A common misconception amongst merchants is that their acquirer or gateway is responsible for most declines.
In reality, the vast majority of declines, particularly vague soft declines like '05: Do Not Honor', originate from the issuer's own risk tolerance and proprietary models, making them a challenging variable for merchants to manage.
Worked example
A cardholder with a Credit card from HSBC UK (the issuer) attempts to make a €2,000 purchase from an online watch dealer in France. The transaction is flagged as high-value and cross-border.
The authorisation request reaches HSBC with data including the merchant's MCC, the purchase amount, and a frictionless 3DS2 authentication result (ECI '06').
Although the cardholder has a €10,000 credit limit, HSBC's internal risk engine flags this as anomalous spending behaviour compared to the cardholder's usual pattern. It automatically returns a Soft decline with issuer decline code '05: Do Not Honor' and reason 'suspected fraud'.
The cardholder receives a push notification from their HSBC app asking them to verify the purchase attempt. After they confirm it, the second attempt is approved by HSBC.
Scheme notes
Issuers are the primary users of scheme-provided risk tools like Visa's VAA (Visa Advanced authorisation) and Mastercard's Decision Intelligence (DI) scores, which provide an additional risk assessment on incoming authorisations. However, the final approve or decline decision rests with the issuer.
For disputes, the issuer is the cardholder's representative, responsible for initiating a chargeback against the acquirer. Both schemes set time limits for this, typically 120 days from the transaction date for fraud (e. g.
Visa reason code 10.4) or consumer disputes (e. g. Mastercard reason code 4853).
American Express, which often acts as its own issuer, is known for its cardmember-centric dispute policies, which can sometimes translate to a higher chargeback risk for merchants.
Why it matters for merchants
The issuer is the ultimate gatekeeper of a merchant's revenue. Every transaction's success depends on the approval of one of thousands of issuing banks globally, each with its own unique risk thresholds and systems.
A high rate of issuer declines, particularly soft declines, is a major cause of Involuntary churn and lost sales. Analysing issuer decline codes is essential for building effective recovery strategies, such as intelligent retries or prompting customers for an Alternative Payment Method.
Using Cardflo's smart routing to process payments via local acquirers with strong regional issuer relationships can significantly reduce these declines and lift authorisation rates, as transactions appear less risky to the issuer.
Frequently asked
Why does an issuer decline a transaction despite the cardholder having sufficient funds?
Issuers may decline transactions due to internal risk models that flag unusual geographic locations, high-velocity spending patterns, or technical mismatches in CVV and expiry dates.
Additionally, if a transaction lacks the required 3DS authentication for SCA compliance, the issuer is likely to reject the request to satisfy regulatory mandates.
What role does the issuer play in the settlement and Funding cycle?
The issuer provides the funding for a transaction by sending the net amount to the card scheme, which then passes it to the acquirer for merchant payout.
This process typically occurs within 24 to 48 hours of the transaction being cleared, with the issuer assuming the risk of collecting the funds from the cardholder at a later date.
What is the most common reason an issuer declines a transaction?
Besides '51: Insufficient Funds', the most frequent decline is '05: Do Not Honor'. This is a generic Soft decline that indicates the issuer is unwilling to accept the transaction, often due to their internal fraud scoring.
It does not mean the card is bad, and retrying the transaction, sometimes after a short delay or through a different acquirer, can be successful.
Can I, as a merchant, contact the issuer to find out why a transaction was declined?
No, merchants have no direct relationship with the cardholder's issuer and cannot contact them for privacy and security reasons.
Only the cardholder can contact their issuer (the bank that provided their card) to inquire about a decline, authorise a specific merchant, or resolve an issue with their account.
Under PSD2 SCA, what is the issuer's liability?
When a transaction requires Strong Customer Authentication, the issuer is responsible for performing the authentication (the 'challenge'). If the issuer authenticates a transaction that later proves to be fraudulent, the liability for the chargeback generally remains with the issuer, not the merchant.
This is known as a liability shift. The exception is if the merchant incorrectly applied for an exemption that was not valid.
Why would my regular customer's subscription renewal suddenly be declined by their issuer?
This can happen for several reasons. The issuer may have tightened its risk rules, the card might have expired and not been updated via Account Updater services, or the transaction might randomly be flagged by the issuer's fraud engine.
This is why having Dunning and Retry logic in place is critical for subscription businesses to combat Involuntary churn.
Do different issuers in the same country have different approval rates?
Yes, significantly. A large, traditional bank might have a more conservative risk appetite than a modern challenger bank or fintech issuer.
Their customer demographics, fraud experiences, and technical capabilities all influence their authorisation behaviour. This is why granular analysis of declines by BIN/issuer is so valuable for optimising payments.
See how Issuer plays out in practice
Industries and regions where this term drives real acquiring, routing, or dispute decisions.
Related terms
The licensed bank or financial institution that holds the merchant's MID and settles card transactions on the merchant's behalf.
An authorisation response refusing to fund a transaction, returned by the issuer with a reason code.
A transient decline (e.g. insufficient funds, do-not-honour, generic) that can usually be recovered with retries.
A terminal decline (e.g. lost/stolen, pickup card, invalid account) that must not be retried.
Related guides.
Ready to improve your payments setup?
Tell us about your business. We'll match you with the right acquiring partners and the right route, typically inside a week.