Inside the Systems Behind Issuing, Authorization, Clearing, and Settlement
Introduction: What Happens When You Swipe a Card
- Why This Book Exists
- How This Book Is Organized
- What This Book Does Not Cover
- How to Read This Book
Chapter 1: The Landscape of Card Issuing
- The Anatomy of a Payment Transaction
- Issuers, Acquirers, Networks, and Processors
- The Four-Party Model Explained
- What Card Issuing Actually Means
- Physical vs Virtual Cards
- Credit vs Debit vs Prepaid
Chapter 2: Card Networks: Visa, Mastercard, and Beyond
- What Card Networks Actually Own and Operate
- Network Rules and Compliance Requirements
- Transaction Message Flow Through the Network
- BIN Ranges and Issuer Identification
- Network Fee Structure and Interchange
- Regional and Alternative Networks
Chapter 3: Issuing Processors and the Processor Model
- The Role of the Issuing Processor
- Major Issuing Processor Models
- What the Processor Provides vs What You Build
- SPI and Network Direct Integration Paths
- Sponsor Banks and Program Managers
- Cost Structures and Contract Considerations
Chapter 4: Core Banking and Cardholder Account Management
- Core Banking System Responsibilities
- Account Structures: Primary, Sub, and Virtual Accounts
- Ledger Design for Card Accounts
- Balances, Available vs Posted Amounts
- Integration Between Core Banking and Card Systems
- Customer Onboarding and KYC Integration
Chapter 5: Card Product Design and Configuration
- Card Product Definition and Parameters
- Currency, Region, and Network Configuration
- Card Controls: Spending Limits, Blocks, and Rules
- Fee Structures: Interchange Pass-Through, Monthly Fees, FX
- Rewards, Cashback, and Points Program Architecture
- Launching a New Card Product
Chapter 6: Identity Verification, KYC, and AML
- Regulatory Requirements for Issuers
- KYC Flows: Document Verification and Identity Proofing
- AML Screening and Watchlists
- PEP Screening and Risk Categorization
- Integration with Identity Providers
Chapter 7: Card Number Generation and PAN Management
- How PANs Are Structured: IIN, Account, Check Digit
- The Luhn Algorithm and PAN Validation
- BIN Allocation and Management
- PAN Assignment and Account Mapping
- Virtual Card Number Generation Strategies
- PAN Tokenization at the Issuer Level
Chapter 8: Physical Card Production and Personalization
- The Card Manufacturing Supply Chain
- Personalization Bureaus and HSM Integration
- EMV Chip Personalization
- PIN Generation and Secure Delivery
- Card Packaging, Shipping, and Tracking
- Production Failures and Rework
Chapter 9: Digital Card Provisioning and Tokenization
- Virtual Card Issuance and Instant Activation
- Apple Pay, Google Pay, and Samsung Pay Tokenization
- Token Service Providers and Network Tokenization
- Device Binding and Provisioning Flows
- Ephemeral and Single-Use Virtual Cards
- Tokenization Technical Deep Dive: How Network Tokens Work
- Push Provisioning and Remote Token Enrollment
- Tokenization and Authorization Rate Improvement
Chapter 10: The Authorization System
- The Authorization Request: From Terminal to Issuer
- ISO 8583 and Modern API Protocols
- The Authorization Decision Engine
- Real-Time Balance and Limit Checking
- Velocity Checks and Pattern Analysis
- Response Codes and Decline Reasons
- Decision Engine Architecture
- Pre-Checks and Post-Checks in Authorization
- Handling Edge Cases and Partial Failures
- Authorization Analytics and Continuous Optimization
Chapter 11: Fraud Detection and Risk Systems
- Rule-Based Fraud Detection
- Machine Learning Models in Fraud Scoring
- Device Fingerprinting and Behavioral Biometrics
- Real-Time Decisioning and Latency Constraints
- Advanced Fraud Patterns and Detection Strategies
- Feature Engineering for Fraud Detection
- Fraud Feedback Loops and Model Retraining
- Managing False Positives and Cardholder Experience
Chapter 12: 3-D Secure and Authentication Flows
- What 3-D Secure Is and Why It Exists
- 3DS 1.0 vs 2.0 Architecture
- The Authentication Flow: DS, ACS, and Interoperability Server
- Liability Shift and Exemption Criteria
- Frictionless vs Challenge Flows
- 3DS and Digital Wallets
- Technical Deep Dive: 3DS 2.0 Protocol Messages and Cryptography
- Operational Considerations for Issuers
Chapter 13: Holds, Authorizations, and Pre-Authorizations
- Authorization Holds and Pending Balances
- Capture and Settlement Timing
- Partial Authorizations and Partial Captures
- Authorization Reversals and Voids
- Extended Holds: Hotels, Rental Cars, Gas Stations
- Hold Expiration and Balance Recovery
Chapter 14: Clearing: The Batch That Moves Transaction Details
- Authorization vs Clearing: Why Two Steps
- Clearing File Formats and Schedules
- The Clearing Cycle: Cut-off Times and Deadlines
- Merchant Clearing and Acquirer Roles
- Network Clearing Rules and Validation
- Clearing Exceptions and Rejections
- Clearing File Formats and Standards
- The Clearing Pipeline: Step-by-Step Processing
- Clearing Reconciliation and Discrepancy Resolution
Chapter 15: Settlement: When Money Actually Moves
- Settlement vs Clearing: The Critical Distinction
- Net Settlement and Offset Calculations
- Reserve Accounts and Liquidity Management
- Settlement Timing: T+1, T+2, and Beyond
- FX Settlement and Multi-Currency Clearing
- Settlement Failures and Reconciliation
- Float Management and Settlement Economics
- Settlement Banks and Fund Transfer Mechanisms
- Settlement Accounting and Ledger Updates
Chapter 16: Fees, Interchange, and Revenue
- Interchange Fee Structure and Rate Tables
- Assessments and Network Fees
- Scheme vs Member Fees
- Processor Pricing Models
- Revenue Attribution and Allocation
- Fee Pass-Through and Merchant Incentives
Chapter 17: Reconciliation and Operations
- What Reconciliation Means in Card Issuing
- Three-Way Reconciliation: Authorization, Clearing, Settlement
- Exception Handling and Unreconciled Items
- Batch Reconciliation Jobs and Scheduling
- Operational Controls and Auditing
- Common Reconciliation Pain Points
Chapter 18: Refunds, Reversals, and Returns
- Refunds vs Voids vs Reversals vs Credits
- The Refund Transaction Flow
- Partial Refunds and Timing
- Refunds After Expiration
- Network Recall and Recall-For-Payment
- Accounting Treatment of Reversals
Chapter 19: Disputes and Chargebacks
- What a Chargeback Is and When It Happens
- Chargeback Reasons and Representment
- The Dispute Lifecycle: Filing, Response, Arbitration
- Evidence Gathering and Compelling Evidence Standards
- Chargeback Fees and Financial Impact
- Representment Automation and Strategy
- The Chargeback Lifecycle: End-to-End Workflow
- Evidence Gathering and Compelling Evidence Standards
- Backend Dispute Management Systems
- Chargeback Fees and Financial Impact
- Representment Automation and Strategy
- Liability Shift Scenarios and 3-D Secure Impact on Disputes
Chapter 20: Card Lifecycle Management
- Card Expiration and Renewal Cycles
- Lost and Stolen Card Blocking
- Card Replacement Workflows
- Card Controls: Freezing, Unfreezing, Temporary Limits
- Account Closure and Fund Return
- Card Status Transitions and State Machine
Chapter 21: ATM and Cash Transactions
- ATM Network Processing vs POS Networks
- PIN Verification and PIN Blocks
- Cash Advance Authorization and Fees
- ATM Settlement and Cash Loading
- International ATM Fees and Networks
- Cashback at POS
Chapter 22: Cross-Border and Multi-Currency Processing
- Currency Identification and FX Rates
- Dynamic Currency Conversion
- Issuer FX Markup and Conversion Logic
- Cross-Border Interchange and Regulations
- Multi-Currency Cards and Accounts
- Sanctions and Geopolitical Constraints
Chapter 23: System Architecture for Modern Card Issuing
- Event-Driven Architecture for Card Issuing
- Microservices: Which Services Split, Which Stay Monolithic
- Real-Time Data Stores and Ledger Design
- Idempotency, Consistency, and Transaction Safety
- API Design: Internal vs External
- Observability: Logging, Tracing, and Monitoring
- Infrastructure Patterns for Card Issuing
- Scalability Patterns and Throughput Management
- Development Practices and Release Management
- Processor Architecture: Monolith vs Microservices
- Edge Services and Global Authorization Routing
Chapter 24: Security, Compliance, and Resilience
- PCI-DSS for Issuers and Processors
- HSMs and Cryptographic Key Management
- Data Privacy: GDPR, CCPA, and Beyond
- Network Security and Threat Protection
- Disaster Recovery and High Availability
- Regulatory Auditing and Examination
Chapter 25: Failure Modes and Edge Cases
- Network Outages and Fallback Processing
- Duplicate Transaction Handling
- Race Conditions in Authorization and Balance Updates
- Reconciliation Discrepancies and Recovery
- Mass Failure Scenarios and Incident Response
- Operational Runbooks and Escalation
Conclusion: The Future of Card Issuing
- Real-Time Issuing and Instant Card Activation
- Embedded Finance and B2B2C Issuing
- Account-Based Payments and Card Competition
- Tokenization and the Death of the PAN
- Regulatory Trajectory
- What This Means for Practitioners