As a merchant, your priority is offering your customers a positive experience, and that includes the payments process. Customers want a payment experience that feels secure, familiar and fast. Research by KPMG found that the payment features they value the most are ease of use (66%) and speed (57%).
But it's not only customers who want a smooth payments process – merchants want payments to be efficient and cost-effective to reduce operational costs and improve cash flow.
To optimize the payments experience for your customers and your business, you need to understand the ins and outs of payment infrastructure.
In this payments infrastructure handbook, we cover the following:
- What is payments infrastructure?
- Who makes up the payments ecosystem?
- How are payments processed?
- Key infrastructure processes and terms to know
- Where can payment ecosystem failures occur?
- How is payment risk managed?
- How to choose the right payments setup for your travel business

What is Payments Infrastructure?
Behind payments is a complex chain of banks, networks and technology providers that check transactions are legitimate and that funds have arrived in the right place. That chain is referred to as ‘payments infrastructure’ or ‘the payments ecosystem’.How your payment infrastructure is set up affects decline rates, processing costs, settlement speed and which markets and payment methods your business can offer.
Who Makes Up the Payments Ecosystem?
The payments ecosystem is made up of several parties:
Customers and Businesses
Customers, who can be private individuals or companies, use payment services to move money, pay bills and make purchases in person and online. Businesses accept customer payments for the goods and services they offer in person and online.
Card Networks
Card networks such as Visa and Mastercard facilitate cashless transactions between different parties, such as banks and credit card companies. They provide the infrastructure and technical standards that allow payments to be processed, and they define interchange fee structures and the movement of transaction data between banks. Card networks don't hold funds themselves, but act as a coordinator for global card payments.
Issuing Banks/Card Issuers
Issuing banks, also known as card issuers, provide payment cards like credit and debit cards to customers. They underwrite the financial risk associated with the cards they distribute by setting credit limits and managing cardholder accounts. Card issuers are a vital component of payments infrastructure because they authorize transactions, meaning they take responsibility for funds in the payment process.
Acquiring Banks
Acquiring banks, also known as merchant banks or acquirers, are the financial institutions that allow businesses to accept card payments. They set up and maintain the business's merchant account, settle transactions and move funds from the cardholder's account into the business's account.
Payment Processors
Payment processors handle the technical side of transactions on behalf of businesses and their acquiring banks – they authorize, clear and settle payments between issuing banks, acquiring banks and businesses. Payment processors also check payments are valid to increase security and reduce instances of fraud.
Payment Gateways
Payment gateways allow businesses to securely accept payments online, connecting a website or point-of-sale system to an acquiring bank or payment processor to authorize and facilitate transactions between customers and businesses. Payment gateways play a vital role in payments infrastructure, because they ensure sensitive payment data is securely exchanged.
Merchant Services Providers (MSPs)
A merchant service provider is a business that offers a range of payment services to businesses, including payment processing, point-of-sale (POS) systems, individual merchant accounts, payment gateways, fraud prevention and detection tools and reporting capabilities. Unlike a PayFac, an MSP usually arranges a dedicated merchant account for each business through an acquiring bank rather than grouping businesses under one shared account.
Payment Service Providers (PSPs)
A payment service provider allows businesses to accept electronic payments without setting up a merchant account directly with an acquiring bank. A PSP bundles the gateway, processing and merchant account access into a single service that includes authorization, fraud monitoring and settlement on behalf of the merchant.
Regulators
Regulators, such as the Financial Conduct Authority (FCA), European Central Bank (ECB) and the European Banking Authority (EBA), set the standards of the payments ecosystem and monitor compliance. These parties work together to allow a wide range of transactions to be made quickly and securely. Payments infrastructure is far from static – regulations change, consumer behavior shifts and new technology alters how the payment ecosystem operates.

How are Payments Processed?
Processing a payment involves the cooperation of several of the parties defined above. Here's what happens behind the scenes when a customer makes a payment:
- Customer: The process begins when a customer chooses to pay for goods or services in-person or online.
- Business: The customer presents their chosen payment method (such as a credit card or digital wallet) by tapping or inserting their card at a POS terminal or entering their payment details online.
- Payment Gateway: The payment gateway securely transmits the customer's payment information from the business's website to the payment processor.
- Payment Processor: The payment processor receives the payment details and forwards them to their chosen payment network.
- Payment Network: The payment network receives the payment details and routes them to the issuing bank, who is responsible for authorizing the transaction.
- Issuing Bank: The issuing bank checks the transaction details and either approves or declines it before sending the decision back to the payment network.
- Payment Network: The payment network receives the decision from the issuing bank and forwards the decision (approval or decline) to the payment processor.
- Payment Processor: The payment processor receives the decision from the network and sends it to the business.
- Business: The business receives the response and, in the event of approval, completes the transaction. The approved transaction is added to a batch.
- Settlement: At the end of a given period, the business sends the batch of approved transactions to the payment processor for settlement purposes. The payment processor then forwards the batch of approved transactions to the payment network, which routes the batch to the relevant issuing banks.
- Issuing Bank: The issuing bank transfers the funds for the transactions to the acquiring bank, which generally takes between one and three business days.
- Acquiring Bank: The acquiring bank deposits the funds (minus applicable fees) into the business's account.
It's a complex process that, for customers, appears to happen in the blink of an eye. But behind the scenes, payment processors, payment networks, issuing banks and acquiring banks are working together to keep transactions flowing seamlessly.
Key Payment Infrastructure Processes and Terms to Know
A few concepts in payments don't link directly to a single institution the way an acquirer or issuer does. They describe patterns and processes in how payments get built, combined or routed, and it's important to know what they mean and how they affect payments infrastructure.
What is Open Banking?
Open banking allows third-party service providers to access consumer data from traditional banking systems through APIs, increasing transparency, competition and innovation in the payments ecosystem.
Why is Open Banking Necessary?
Open banking came into being because bank data was historically locked inside individual banks – there was no standard mechanism for other companies to access the information securely. Companies tried to find workarounds. For example, screen scraping in Germany’s SOFORT service asked customers to hand over their banking login details to a third party, which was effective for information sharing but insecure.
In 2007, the European Commission unveiled the first Payment Services Directive (PSD1), which was designed to create competition in the financial sector, improve service quality and protect consumers. PSD1 had far-reaching consequences:
- Created the regulatory framework that allows non-banks to execute financial transactions.
- Created payment service providers (PSPs), a new payment industry category.
- Introduced transparency rules requiring banks and PSPs to disclose services and fees clearly.
- Stimulated the growth of the fintech sector.
How Does Open Banking Impact Consumers, Businesses and Financial Institutions?
Here's what open banking means for different groups in the payments ecosystem:
For Consumers
Open banking gives consumers more control over their financial information – they decide who gets access to their banking data and the specific level of access. Open banking also allows consumers to share their bank account data with third-party providers, who then use that information to create tailored products and services that better align with consumers’ wants and needs.
For Businesses
Open banking gives businesses access to financial data to allow them to understand and better manage their money, including financial forecasting and speeding up the payments process. It also provides an alternative way to make and receive account-to-account (A2A) payments that may be more cost-effective than card payments that come with various fees.
For Financial Institutions
Banks are required to build and maintain the APIs that make the data sharing open banking demands possible, which introduces new competition from fintechs and PSPs offering account information and payment initiation services. Many banks now offer these services themselves, while all providers have stricter data security and consent management obligations.
What are Embedded Payments?
During your research into payments infrastructure, you're sure to come across the term ‘embedded payments’. Confusingly, though, embedded payments has several meanings:
- Embedded Payments for the End Customer: When shopping on websites, consumers choose their preferred payment method and pay through an embedded link. The ‘embedding’ here is from the customer's point of view.
- Embedded Payments for Platform Users: Rather than sourcing and managing their own payments provider, businesses that use a software platform, such as a marketplace or booking tool, can accept payments directly through the platform itself. The ‘embedding’ here is from the platform's business customer’s point of view, not the end consumer's.
Embedded payments have many benefits for businesses and consumers, including:
- Reducing cart abandonment.
- Making the experience frictionless by removing third-party redirects.
- Creating new revenue models by monetizing their user base (e.g., taking a percentage of each transaction).
What is Payment Orchestration?
Another term you'll come across is payment orchestration, which is the ability to manage the providers involved in payment processing, including PSPs, a range of payment methods (such as cards and digital wallets), fraud prevention and detection and other payment flow services through a single platform.
Payment orchestration allows merchants to take control of how transactions are handled across all of these providers based on defined conditions. This means they can manage their payment stack more easily and optimize payment performance.
Without payment orchestration, merchants will experience:
- Higher Declined Transaction Rates: Relying on a single PSP means every transaction takes one fixed path, with no way to retry through a different acquirer if the path is a poor fit for the card or region.
- Increased Cart Abandonment: Declined customers may not retry the payment, and a single provider limits which payment method and currencies are available. Unsupported customer preferences translate directly to lost sales.
- More Operational Friction: Without automated routing and failover, managing multiple providers to ensure redundancy requires a huge amount of manual effort.
What are the Benefits of Payment Orchestration?
- Generate More Revenue: Control how transactions are routed across providers and benefit from higher authorization rates and fallback logic to retry failed payments.
- Change Your Payment Strategy Without Redoing Integrations: Connect new providers without building and maintaining separate integrations. This means you can introduce new payment methods, improve performance and move into new markets quickly.
- Reduce Payment Costs: With a clear view of fees and performance across payment providers, you can devise new routing strategies that use the most cost-efficient provider based on specific transaction characteristics.
- Reduce Fraud: Payment orchestration allows you to integrate fraud detection and prevention tools to manage how fraud checks are carried out across your entire payment flow.

Where Can Payment Ecosystem Failures Occur (And How to Avoid Them)
There are dozens of ways payments can fail across such a vast ecosystem: the customer provides incorrect payment information, or perhaps the payment gateway has poor network connectivity during the time the transaction is attempted.
The most common payment failures include:
User Error
- The customer inputs the wrong payment information.
- The customer's card is expired.
- The customer doesn't have sufficient funds in their bank account.
How to Avoid User Error Failures
- Validate card details at checkout before the customer submits. For example, flag that a user has entered too few characters.
- Show specific error messages instead of a generic ‘payment declined’ message.
- Offer to securely save card details for faster future checkouts.
Technical Failures
- The payment gateway experiences poor connectivity.
- The business or their payment processor experiences a technical glitch that affects their payments system, such as a system outage.
- The website can't handle the volume of transactions at a given time.
How to Avoid Technical Failures
- Build in retry logic for failed transactions.
- Maintain redundant connections to more than one gateway or processor, so if one experiences downtime, another can process the transaction.
- Load test checkout systems ahead of peak periods to ensure they can handle a high volume of transactions.
Security and Risk Concerns
- A payment processor blocks transactions due to a spending limit being exceeded, as it could point to fraud.
- Fraud detection tools block a transaction after deeming it fraudulent.
- The customer fails the 3D Secure authentication process.
How to Manage Security and Risk Concerns
- Tune fraud detection tools on real transaction data instead of relying on default settings.
- Use lower-friction 3D Secure methods, such as biometric authentication (fingerprint or facial scanning), instead of typed codes that customers may mistype or forget.
- Monitor decline reason codes to tell fraud-related declines apart from false declines.
What Happens When a Payment Fails or Gets Disputed?
Putting payment failure and chargeback reduction measures in place means they happen less, but you can't eliminate them completely. Here's what you can do if a payment does fail or a customer disputes a charge:
If the Transaction Fails Outright
Most payment systems retry the transaction automatically, sometimes after a short delay or by routing the payment through a different acquirer (if payment orchestration is in place). If the retry also fails, the customer will see a decline message, and it's up to the business to prompt them to try a different payment method.
If a Customer Disputes a Charge
It happens to all travel businesses at some point, no matter how much time and effort you put into reducing chargebacks: the customer contacts their bank to request a chargeback. The issuer refunds the customer provisionally and takes the disputed amount from the acquiring bank, who deducts it from the merchant's business account, along with a chargeback fee.
The business is notified and is given a specific length of time (usually between 20 and 45 days) to either accept the loss or contest it with evidence such as a signed agreement. The issuing bank reviews the merchant's evidence and decides whether to reverse or uphold the chargeback. If the business misses the window, the chargeback is upheld by default.
A Transaction is Flagged as Fraudulent
Fraud detection tools either block the transaction outright, send it for manual review or hold it pending an additional verification check, like 3D Secure. If the customer fails the additional checks, the payment is declined.
A Provider in the Payment Ecosystem Experiences an Outage
If a business has redundant connections and payment orchestration in place, transactions can be automatically routed to an alternative provider with little to no disruption. Without that redundancy, payments will fail until the affected provider recovers – this leaves the business without the ability to process transactions in the meantime.

How is Payment Risk Managed?
Beyond preventing payment failures, businesses across the payments ecosystem use several mechanisms to keep payments secure:
PCI DSS Standards
PCI DSS are the security standards created to protect cardholder data during transactions, reducing the risk of fraud and data breaches. Any business that stores, processes or transmits card data must comply with PCI DSS standards.
The level of scrutiny is tied to transaction volume: large entities (for example, those processing over 6 million transactions per year) require comprehensive third-party validation, while smaller businesses below the transaction threshold ensure compliance through a self-assessment questionnaire.
Tokenization
Payment providers keep sensitive card details under lock and key through tokenization. Tokenization replaces a card number with a random string of characters, making it useless to anyone who manages to steal it. This allows businesses across the payments ecosystem to store details for repeat customers without ever storing their actual card details.
3D Secure 2 and Strong Customer Authentication (SCA)
3D Secure 2 (3DS2) is the main method for authenticating online card payments to meet Strong Customer Authentication (SCA) requirements. 3D Secure 2 builds on its first iteration to provide more data on transactions to the cardholder's bank, such as the delivery address, device ID and transaction history. This allows the cardholder's bank to more accurately assess the transaction's risk level to the benefit of many parties in the payment ecosystem.
Payment Fraud Monitoring
Every participant in the payments ecosystem uses fraud detection and prevention tools. However, their specific objectives vary depending on where they sit in the payment flow. For example, issuing banks that provide cards to consumers use authentication and AI tools to analyze behavioral biometrics and authenticate cardholders in real-time.
Payment processors run automated security checks, evaluating IP addresses and device fingerprints to filter out suspicious activity before routing to card networks. Merchants, on the other hand, tend to rely on fraud detection tools provided by the payment gateway they use to block fraudulent payments and prevent costly chargebacks.
Finally, card networks monitor merchants directly through merchant monitoring programs, like Visa's Acquirer Monitoring Program (VAMP) and Mastercard's Excessive Chargeback Program (ECP). These schemes encourage merchants to keep fraud and chargeback ratios as low as possible, otherwise they receive financial penalties, or, in the most serious cases, account termination by acquirers.

How to Choose the Right Payments Setup for Your Travel Business
Travel is treated as high risk by many payment providers, and the reasons for this are structural. Customers often pay months in advance, transaction values tend to be high and the average chargeback rate for travel is between 0.89% and 1.10% – one of the highest across all sectors.
A generic setup priced for a retailer doesn't account for the realities of running a travel business. As a result, travel merchants often end up with harsh terms: high processing fees, steep reserves held for too long and frozen or even terminated merchant accounts.
A travel-specific merchant account allows merchants to access the tools they need to accept payments and protect their revenue. Here are the features merchants gain access to when they use a travel merchant account:
Chargeback Management and Insolvency Protection
A travel merchant account gives you access to chargeback management tools built around travel-specific dispute patterns, rather than treating every chargeback like a standard retail one. Some travel merchant account providers also include insolvency protection, which secures customer funds separately from the business's own accounts. This lowers the acquirer's risk exposure to your business, which tends to translate into better processing rates.
Risk Mitigation and Diversified Acquiring
Rather than depending on a single acquiring bank, travel-specific merchant account providers typically maintain relationships across multiple acquirers. If one changes its risk appetite or ends the relationship, transactions keep processing through another acquirer, so the business never loses the ability to take payments. This builds resilience into every transaction.
Cross-Border and Multi-Currency Processing
Routing international transactions through a single bank can cost more and may result in lower authorization rates than acquiring locally. Local acquiring partnerships in key markets, combined with multi-currency settlement, avoids high costs and the negative impact on conversions.
Transparent, Competitive Pricing
Know what you're getting by choosing a provider with clear, upfront pricing that details all costs, such as processing fees, international transaction fees, currency conversion rates, chargeback fees and reserve requirements. The best travel merchant account providers offer transparent pricing that you can actually understand.
Integration Capabilities
A travel merchant account that easily integrates with the systems you rely on saves you time on manual entry, reduces errors and simplifies the reconciliation process. API access, pre-built integrations and technical support when things don't go as planned will go a long way to keeping your payments running smoothly.
Cash Flow Management
Control account services give you financial visibility over funds across travel's long booking-to-fulfillment windows, and this helps you manage cash rather than just wait for it. This matters because excessive reserves make the problem worse – holding 20% of every transaction for 180 days is effectively an interest-free loan to your payment processor, at exactly the point you need that cash to fulfill services.
Making Your Payments Infrastructure Work for Your Travel Business
As a travel business grows into new markets, adds booking channels and scales transaction volume, a payment setup that worked at launch starts to show its limits in the form of falling authorization rates, reserve terms that no longer make sense and reconciliation that takes longer every month. Revisiting your payments infrastructure periodically is part of managing it well.
The concepts covered throughout this handbook, including who is involved in transactions, why payments fail and how payment risk gets managed, apply just as much to choosing a travel merchant account as they do any other part of the payments ecosystem. Used properly, they turn payments from a constant source of friction into infrastructure that works for the business instead of against it.
Ready to optimise transaction costs, safeguard funds from booking to fulfillment and manage risk proactively? Contact the Repayd team today.



