Skip to content
PAY-072 Payments & Banking

What is an issuing bank?

An issuing bank is the institution that provides the payment card or card account to the customer.

Avoid this assumption: The issuing bank holds every record needed to explain the merchant side of the transaction.

The issuer may authorise or decline card payments, manage the customer account, apply fraud controls and record card status, authentication and disputes.

Relevant records may include the cardholder relationship, card number or token, authorisation request, response code, authentication result, device-wallet provisioning, fraud alerts, declines, reversals and chargebacks.

The issuing bank can often explain how the payment affected the customer account and what security checks were applied.

It may not hold the merchant’s detailed order, delivery, staff or CCTV records.

Those may sit with the merchant, payment processor, gateway or acquiring bank.

The issuer’s timestamp may represent authorisation or posting rather than the merchant’s sale or settlement time. Its merchant information may also be abbreviated, incomplete, delayed, transformed or supplied through another provider.

Successful authorisation does not prove the cardholder personally made the payment.

Preserve the issuer’s transaction reference, authorisation code, card or token details, merchant descriptor, amount, date, time and status.

Ask the issuer whether the transaction was card-present, card-not-present, tokenised, recurring or merchant-initiated.

Where attribution matters, request authentication, device and account-security records.

When reporting, distinguish what the issuer recorded from what the merchant recorded.

Operational takeaway

Use issuing-bank records to explain the card account, authorisation and authentication, and obtain merchant-side evidence separately where the purchase or user is in issue.


Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.