You've done it thousands of times: enter a card number, hit pay, watch a spinner for a second or two, see a checkmark. Nothing about it feels complicated. Underneath that spinner, though, a message is crossing at least five separate institutions — a gateway, an acquirer, a card network, an issuing bank, and back again — getting checked for fraud, validated against a real bank balance, and in Europe often authenticated against a regulatory standard, all before the round trip completes. The whole thing typically finishes in one to two seconds. Here's what's actually happening in that gap.

The Journey in Five Stops

The trip starts at the gateway, which is often confused with the acquirer or the processor but does a distinct job: it captures the card data at checkout, encrypts it, and packages it into an authorization request. That request needs to carry everything the issuer will eventually need to make a decision — the amount, the merchant, the card details, and a growing set of contextual signals about the device and session.

From there it goes to the acquirer — the merchant's bank, the institution that actually holds the merchant account — which forwards the request into the card network (Visa, Mastercard, or a local scheme). The network's job at this stage is pure traffic direction: it reads the first six to eight digits of the card number, the BIN, to identify exactly which bank issued it, anywhere in the world, and routes the request there. One industry write up calls this role plainly: the network is the "translator and policeman," making sure billions of these requests find their way home with millisecond precision.

The five stops a card payment makes during authorization: gateway, acquirer, card network, issuing bank, and back — completing in one to two seconds

Where the Time Actually Goes

"One to two seconds" sounds instant, but it's worth breaking apart, because it's not one continuous delay — it's five discrete hops, each doing real work, with cumulative network latency between institutions that can be scattered across different continents. The gateway's encryption and packaging step is typically the fastest part of the chain, often completing in well under a tenth of a second. The acquirer-to-network hop and the network's BIN-based routing add their own small increments, usually tens of milliseconds each on a healthy connection. The genuinely variable part is step four — the issuer's own decisioning — since a straightforward approval against a clean account can resolve almost instantly, while a transaction that trips a risk model, or one that requires a 3DS2 challenge step where the cardholder has to actively respond, adds real, sometimes multi-second time on top of the baseline round trip.

That variability is exactly why authorization speed itself is a meaningful signal. A merchant seeing authorization times creeping upward isn't just experiencing a UX annoyance — it's often an early indicator that a growing share of transactions are tripping additional risk review, which is the same underlying shift that eventually shows up as a declining approval rate.

What the Issuer Is Actually Checking

The decision itself happens at the fourth stop, inside the cardholder's own bank. This is where the real judgment call gets made, and it's doing several things simultaneously: confirming the card is valid and not reported lost or stolen, checking that the account has sufficient funds or available credit, and running fraud scoring against behavioral patterns, transaction velocity, and geographic signals — does this look like how this cardholder normally spends, from where they normally spend it.

In Europe, this is frequently also the moment Strong Customer Authentication kicks in under PSD2, and soon its successor PSD3 — routed through 3D Secure 2, which can trigger a challenge step (a one-time code, a banking app confirmation) that adds a beat of friction but also meaningfully raises the odds of an approval by proving the cardholder is really present. The issuer weighs all of this and returns one of roughly a dozen possible response codes, which collapse into two practical buckets for a merchant: approved, or declined for one of several distinct reasons.

What an issuing bank checks during payment authorization: card validity and available funds, fraud scoring, and Strong Customer Authentication in Europe

Not All Declines Are the Same

The response that comes back matters more than most checkout flows treat it. A decline isn't a single outcome — it splits into two categories that call for completely different responses, and conflating them is one of the more expensive mistakes a merchant can make.

Soft declines are temporary and often recoverable: an issuer's system hiccupped, a risk score landed just above a threshold on an otherwise fine transaction, a card had a brief authentication mismatch. In subscription businesses specifically, soft declines account for 70% to 90% of all failed transactions — which means the large majority of "lost" recurring revenue isn't actually lost, it's recoverable through smart retry logic and timing. Hard declines are different in kind, not just degree: an expired card, insufficient funds confirmed, a card reported stolen. Retrying a hard decline doesn't just fail again — it actively damages the merchant's standing with that issuer over time, since repeated retries against a genuinely bad card read as suspicious behavior in the issuer's own monitoring.

Soft declines versus hard declines: soft declines make up 70 to 90 percent of subscription payment failures and are recoverable, hard declines are not

Why This Two-Second Window Matters More for High-Risk Merchants

For a low-risk retailer, this whole journey mostly runs invisibly in the background — approval rates sit high and stable, and nobody thinks much about steps one through three. For a high-risk merchant, that same journey is where a meaningful share of the business's actual economics get decided. An issuer's fraud scoring at step four weighs category risk alongside behavioral signals, and adult-coded, subscription-heavy, or high-chargeback-history merchants start every authorization request from a more cautious baseline than a mainstream retailer does.

That's exactly why the signals sent in steps one through three carry outsized weight for this kind of business. A clean, consistent billing descriptor, properly configured 3DS2 authentication data, and routing through an acquirer that actually understands the vertical can measurably shift an issuer's decision at the margin — the difference between a borderline transaction landing as an approval or a decline often comes down to exactly this kind of upstream data quality, not the transaction itself. This is also where multi-acquirer routing earns its keep: if one acquirer's relationship with a particular issuer is producing soft declines that another acquirer's relationship wouldn't, an orchestration layer that can route intelligently across acquirers recovers revenue that a single-acquirer setup simply loses.

Authorization Isn't the Same as Getting Paid

It's worth clearing up a common misunderstanding built into that fast, clean check mark: no money actually moves during authorization. It's a verification step — a confirmation that the funds exist and the transaction is likely legitimate — not a transfer. The real movement of money happens later, in clearing and settlement, when authorized transactions get batched and submitted through the network from acquirer to issuer. That process typically takes one to two business days between the institutions themselves, and merchant funding — the money actually landing in the merchant's own account — usually takes another two to three days on top of that, depending on the acquiring agreement.

That gap is precisely why the quality of what happens in those two seconds matters so much. Everything a merchant's checkout sends in steps one through three — clean data, the right authentication signals, a well-configured gateway — shapes what the issuer decides in step four, before a single euro has actually changed hands.

MMG Corporation works with high-risk merchants across EU markets on exactly this kind of authorization performance — from gateway configuration to routing strategy. If your approval rates don't match what you'd expect given your actual fraud profile, that gap usually traces back to something in this two-second journey.

Get in touch

This article was researched and written with the help of AI tools as part of our content process, and reviewed and fact-checked by the MMG team before publication.