Fraud & Trust

What Happens in the Second Before a Payment Is Approved

The online payment approval process explained: the route a card payment travels, the checks banks run, and why the whole exchange takes about a second.

Your customer taps Pay at 9:14 on a Tuesday night. A spinner turns briefly. By 9:14 and one second, money in a bank account somewhere has been promised to you, a receipt exists, and a confirmation is on its way to two inboxes.

That single second is the busiest moment in online commerce. The online payment approval process packs an entire investigation into it: format checks, identity checks, fraud screening, and a final yes or no from the bank that issued the card. Once you understand the sequence, your declines stop looking random and your approvals stop looking automatic.

Here is the journey, hop by hop.

The route a card payment travels

A payment request never goes straight from your checkout to "approved". It moves through a chain, and every link gets a vote.

StopWho it isWhat happens there
CheckoutYour store or payment pageCard details are collected in a secure form and encrypted
Payment platformThe service you sell throughValidates the request, screens it, sends it onward
Card networkVisa or MastercardRoutes the request to the bank that issued the card
Issuing bankYour customer's bankChecks the money, the card's status, and the risk
The return tripThe same chain, reversedCarries the approval or decline back to your checkout

Each hop is measured in milliseconds. The slowest step in the whole exchange is usually the human one, when the customer's own bank asks them to confirm the purchase.

First check: do the details even make sense

Before anything reaches a bank, the payment platform rejects requests that can't possibly be real. Card numbers follow a mathematical pattern, so a mistyped digit fails instantly without troubling anyone's account. Expiry dates get checked against the calendar. The security code has to be present and the right length.

This is why a typo fails in a blink while a genuine decline takes a beat longer. Only requests that pass the sanity check spend real time in the pipeline.

The card number itself is protected from the first moment. It's encrypted when the customer submits it, and a serious platform never lets the merchant see or store the raw number at all. You receive an approval and a reference, never the card.

Second check: is this really the cardholder

A correct card number proves possession of digits, not identity. 3-D Secure is the card networks' authentication step, a quick exchange where the customer's bank confirms the person paying is the person who owns the card. Sometimes the bank is satisfied silently, using information it already has. Sometimes it interrupts with a one-time code or a tap-to-approve in its banking app.

When that challenge appears, the second stretches into a minute or two while the customer finds their phone. It feels like friction. It's actually the strongest protection in the whole chain, for both sides of the sale.

On Inkress, every card payment includes 3-D Secure with no exemptions, and only a fully verified authentication can lead to money moving. Our plain-language guide to 3-D Secure explains what customers see and why banks challenge some payments and not others.

Third check: the issuing bank's decision

With identity confirmed, the request lands at the issuing bank, and this is where the real authority lives. The issuer confirms the account can cover the amount. It checks the card's status: not expired, not frozen, not reported lost or stolen. It applies the cardholder's limits. And it runs its own risk assessment, comparing this purchase against what it knows about the cardholder's normal behaviour.

Any one of those checks can end the sale. The issuer's answer, a code meaning approved or one of many flavours of declined, rides the same chain back down to your checkout. The whole round trip still fits inside that second.

Merchants sometimes assume the payment platform declined their customer. Usually the platform only carried the message. The bank that issued the card holds the final vote, which is why our guide to failed card payments spends most of its time on issuer declines.

Fraud screening runs alongside everything

While the details and the identity checks are happening, the payment is also being screened. Platforms evaluate each payment before letting it complete, and they can allow it, block it, or require stronger verification. Issuing banks run their own screening on top. Two independent sets of eyes look at every transaction in that second.

You'll notice nobody publishes exactly what those screens look for. That's deliberate, because a checklist for passing fraud screening is a gift to fraudsters. What we can say publicly about how Inkress protects payments lives on the fraud defense page.

For a merchant, screening is quiet insurance. An order that would have become a chargeback next month gets stopped before you've boxed anything or paid a courier.

When the answer is no

Roughly one outcome in the chain is visible to your customer: approved or declined, with a short reason. Declines deserve calm reading rather than panic. Insufficient funds means try later or try another card. An authentication failure means the bank couldn't confirm the cardholder, and the polite response is to let the customer retry, not to hammer the same card repeatedly.

A decline is the system working. Every check that can say no before money moves is a check that doesn't become a refund, a dispute, or a fraud loss after money moves.

What the online payment approval process means for you

A few working conclusions worth keeping:

  • Speed is trust. Customers abandon slow or broken checkouts. A clean approval in about a second, with a receipt right behind it, reads as a real business.
  • The checks work for you. Authentication moves fraud liability toward the card issuer, and screening stops bad orders before you ship. The second is your first line of defense, not an obstacle.
  • Declines carry information. Track which kinds you see. Repeated authentication failures look very different from insufficient funds, and they call for different responses.

The next time that spinner turns on your checkout, picture the route: encrypted details, an identity handshake, two rounds of screening, and a bank making a decision, all before your customer's thumb leaves the screen.

If you'd rather have that whole second handled for you, from the encrypted card form to the verified approval, it comes built in with an Inkress account.

Common questions

How long does online payment approval take?

Typically a second or two. The request travels from the checkout through the payment platform and card network to the customer's bank and back. If the bank asks the customer to confirm with a code or app approval, the wait extends until they respond.

Who actually approves a card payment?

The bank that issued the customer's card has the final say. It checks available funds, the card's status, and its own risk assessment before answering. The payment platform and card network carry the request and response between the parties.

What checks happen before an online payment is approved?

Format validation of the card details, cardholder authentication such as 3-D Secure, fraud screening by the platform and the bank, and the issuing bank's checks on funds and card status.

Why do some payments ask for a verification code and others don't?

The customer's bank decides. When it's confident about the cardholder it approves the authentication silently. When it wants certainty it sends a one-time code or asks for approval in its banking app.