Payer
The person or organization whose account, balance or credit line funds the payment.
The global payments graph
How a payment actually works. Payments are not a single line from A to B. They are a graph of customer experiences, rules, institutions, infrastructure, identifiers, messages, money movements and controls. This guide gives you the model to read that graph.
01 · The payment graph
It is the choice visible in a wallet, app, terminal or checkout: for example Visa Debit, Apple Pay, Pix, a bank-transfer experience or a voucher.
A method uses one or more schemes and systems.A scheme defines participation, message and operating rules, liability, disputes and sometimes pricing. Card schemes and credit-transfer schemes are different products, even when they share infrastructure.
A scheme governs; it is not the infrastructure itself.Systems include retail batch and instant systems, card systems and large-value infrastructure. One payment can touch several systems before final settlement.
A system executes technical payment functions.An operator may govern rules, provide infrastructure or do both. EBA CLEARING, for example, operates RT1 and STEP2; one operator can be connected to several graph nodes.
An operator is an organization, not a transaction stage.Read these as graph relationships, not four consecutive transaction hops. A method can use multiple schemes, a scheme can run across multiple systems, and an operator can run several methods, schemes or systems. In arrangements such as UPI or Pix, one branded ecosystem may fulfil several roles; Aurato keeps those roles separately queryable.
Organizations can perform more than one role. A PSP may also be an acquirer; a scheme operator may also operate infrastructure; a bank can issue, acquire and settle.
The person or organization whose account, balance or credit line funds the payment.
The recipient of the payment and the party that must reconcile the sale or transfer.
Provides the card or account, authenticates the payer and decides whether a card authorization or account instruction can proceed.
Connects the merchant to acceptance and receives or settles funds on the merchant side.
Provides the merchant integration and may combine gateway, processing, acquiring, orchestration, fraud and reporting services.
Defines or enforces the legal and supervisory perimeter, licenses participants and oversees market or systemic risk.
02 · Transaction lifecycle
The payer or payee starts the payment and selects a method, amount, currency and recipient.
A card, account, wallet token, alias, mandate or voucher credential identifies the funding source. Tokenization is used where the product supports it; it is not a universal step.
The system establishes that the person is entitled to use the credential, for example with a PIN, biometrics, a banking app or 3D Secure.
The issuer, bank or provider checks status, funds or credit, limits, fraud signals and scheme rules. An approval reserves or validates value; it is not yet final settlement.
For cards, the merchant confirms an authorized transaction for clearing. In other flows, confirmation may be part of initiation or occur only after the receiving party is credited.
Participants exchange and reconcile payment data and calculate the obligations or net positions that must be settled.
Money moves between settlement accounts and is posted toward the payee. Settlement can be gross or net, real-time or deferred; merchant funding may still happen later.
Ledgers, fees and payouts are matched. Refunds, returns, reversals, disputes and chargebacks follow their own rules and do not simply replay the original payment backwards.
03 · Payment methods
A card credential draws on debit funds, credit, charge or prepaid value. Four-party and three-party operating models distribute issuing, acquiring and network roles differently.
The payer moves funds from an account to another account through a credit-transfer scheme. Instant customer confirmation does not always mean real-time gross settlement.
The payee collects from the payer’s account under a mandate. Clearing, settlement, return windows and refund rights differ from credit transfers.
Pass-through wallets present a tokenized underlying credential; stored-value wallets maintain a balance or internal ledger. One brand can support both models.
A credit product embedded at checkout. The provider pays or guarantees the merchant and collects from the consumer under an installment or deferred-payment agreement.
A code or stored entitlement is exchanged for value. Funding may have happened earlier through cash, card, bank transfer or payroll.
Cash and cash-assisted methods can begin or end outside a native digital flow, even when a digital reference, barcode or agent network coordinates the transaction.
Channel is not a rail. QR, contactless, in-app, web and in-person describe how a payment is initiated or accepted. The same QR code can initiate a card payment, bank transfer or wallet-ledger transfer.
| Lifecycle dimension | Card | Instant A2A | Direct Debit |
|---|---|---|---|
| Primary instruction | Authorize and later capture a card transaction | Push a credit transfer from one account to another | Collect from the payer under a mandate |
| Who typically starts | Payer at checkout; merchant captures | Payer | Payee |
| Customer confirmation | Usually authorization first | Often immediate for instant schemes | Often notification rather than real-time approval |
| Settlement | Usually separated from authorization and often netted | Can be real-time gross, real-time net or deferred net | Commonly batch and net |
| Typical exceptions | Reversal, refund, dispute, chargeback | Reject, return, recall, reimbursement | Reject, return, refund under scheme or legal rights |
04 · Data & routing
Identifies an issuer and account range for card routing and enrichment. Six- and eight-digit representations coexist, while product attributes may require more granular account-range data.
An 8- or 11-character identifier for an organization or branch used in financial messaging and participant reference data.
A domestic bank or branch routing identifier. Its format, authority and use are market-specific rather than globally uniform.
A four-digit classification of a merchant’s primary activity used in acceptance, pricing, rewards, controls and risk decisions.
A message format family widely used in card authorization, clearing and related exchanges. Implementations are network-specific.
A shared financial-services data model and message catalogue, commonly serialized as XML. Market practice determines which fields and messages are actually used.
Specifications for chip, contactless, QR and other payment-acceptance interactions.
A protocol for exchanging authentication data in card-not-present payments; it is distinct from the issuer’s authorization decision.
A security standard for protecting payment account data in environments that store, process or transmit it.
Replaces a sensitive credential with a constrained token. Device, merchant, gateway and network tokens have different domains and lifecycle controls.
05 · Economics
When applicable, a fee transferred between acquiring and issuing sides under scheme or regulatory rules.
Charges for participation, switching, processing, clearing, settlement, assessments or specific services.
Commercial pricing for acceptance, processing, risk services, reporting, support and the merchant relationship.
Cross-border assessments, FX, financing, fraud, disputes, refunds, reserves, payout timing and operational costs can materially change the all-in cost.
The issuer may carry credit and account risk; the acquirer may carry merchant and chargeback exposure; the PSP operates controls and the integration; the merchant carries delivery, refund and some fraud risk; scheme and legal rules decide how losses can move between them.
06 · Risk & compliance
Requirements for identifying and verifying customers and businesses, establishing beneficial ownership, assessing risk and applying enhanced or ongoing due diligence.
Requirements protecting payment users through transparent conduct, error resolution, complaint handling, refund rights, ombudsman access and fair outcomes.
Authoritative designation lists and guidance for screening customers, counterparties, owners and payments against sanctions restrictions.
Requirements for risk-based AML/CFT programmes, payment transparency, transaction monitoring, investigations and suspicious-activity reporting.
Requirements for resilient payment operations, ICT risk management, incident response, business continuity, outsourcing and supervisory reporting.
Requirements governing payment and personal data collection, storage, localisation, transfer, retention and information-security safeguards.
Core legal frameworks defining which payment activities are regulated, who must be licensed or registered and how providers are supervised.
Rules governing interchange, card acceptance, routing choice, merchant fees and the transparency or fairness of payment pricing.
Requirements for authentication, confirmation of payee, scam prevention, liability allocation and reimbursement when payment fraud occurs.
07 · Worked examples
Card + pass-through wallet
Instant account-to-account
Multi-app A2A ecosystem
Keep these distinctions
Authorization is a decision or reservation. Clearing, settlement, posting and merchant funding are separate states.
The customer can receive an immediate result while participant obligations settle gross, net or on a different timetable.
A wallet may pass through a card or bank-transfer rail, use its own stored-value ledger, or combine several funding paths.
A scheme governs rights and obligations; a system performs technical processing, clearing or settlement functions.
The operator owns or runs a graph node. A transaction message does not necessarily pass through the operator as a separate participant.
A wallet or checkout overlay and its underlying card or bank transfer can describe the same transaction. Analytics must define the counting layer to avoid double counting.