Why Card Payments Get Declined, and How Merchants Raise Their Approval Rate
A card decline is a refusal of a payment by the issuing bank, the card network or the merchant's own fraud screening, and a meaningful share of declines are false: the customer was genuine, had the funds, and the payment should have gone through. Most merchants measure fraud carefully and declines barely at all, even though every false decline is revenue that was earned and then refused, often from a customer who does not come back. The encouraging part is that approval rates are not fixed. They vary sharply by business model, and the causes are largely diagnosable from the decline codes merchants already receive. The discouraging part is that every lever that raises approvals also moves fraud and chargeback exposure. The target is therefore not a higher authorization rate on its own. It is more approved good transactions, measured by segment and by decline reason rather than as one blended number.

Key Takeaways
- Three parties can say no to a card payment: the issuer, on risk and funds; the network, on rules; and the merchant itself, through its fraud screening. Merchant-caused declines are often the largest controllable category and the least measured.
- Declines split into hard declines that should never be retried, soft declines that often succeed on a later attempt, and merchant fraud-screen declines. Visa's rules formalize this: its "issuer will never approve" category may not be reattempted, while temporary declines may be retried up to 15 times in 30 days.
- Approval rates differ by channel, geography, billing model and customer history. A blended approval rate hides all of that and is close to useless for diagnosis.
- The levers with the best effort-to-benefit ratio for stored-card merchants are network tokens and account updater. Visa reports a 4.8 percent increase in authorization rates and a 39.4 percent lower fraud rate for tokenized card-not-present transactions in 2025.
- Every approval lever trades against fraud and chargebacks. A program that raises approvals and also raises its dispute rate into a network monitoring program has not improved.

What Happens in an Authorization, and Who Can Say No
Card authorization is the real-time request, sent from the merchant through its acquirer and the card network to the issuing bank, asking whether a specific payment may proceed. The issuer answers with an approval or a decline and a response code, typically within a couple of seconds.
Three parties can stop the payment along the way.
The issuer is the bank that issued the card, and it makes most decisions. It checks that the account is open, that funds or credit are available, and that the transaction looks like the cardholder, using its own fraud models. The issuer's view of risk is the single largest driver of approval rates, and it depends heavily on how much the merchant tells it. The issuer side of this decision is explained in card issuing.
The network, such as Visa or Mastercard, applies rules: whether the merchant category, the transaction type and the region are permitted, whether required authentication was performed, and whether a retry complies with reattempt limits.
The merchant can decline before the authorization is ever sent, through its own fraud rules or a fraud vendor's model. These declines never appear as issuer declines, which is why they are so often missing from approval-rate reporting.
This distinction yields two metrics that merchants frequently conflate. The authorization rate is the share of authorization requests the issuer approves. The acceptance rate is the share of attempted purchases that end in a completed payment, including the ones the merchant blocked itself. A merchant can report an excellent authorization rate while its fraud screen rejects a large share of good customers before the issuer sees them.

The Decline Taxonomy That Matters
Response codes differ by network and processor, and many processors map them into their own categories. The useful grouping is by what the merchant should do next.
Hard declines mean the issuer will not approve this credential: the card is reported lost or stolen, the account is closed, or the card number does not exist. Retrying is pointless and, under network rules, penalized.
Soft declines mean the issuer will not approve this transaction now: insufficient funds, a temporary issuer or system outage, a velocity limit, or a need for additional authentication. Many succeed on a later attempt or after a data correction.
Merchant fraud-screen declines are refusals the merchant made itself. They have no issuer code, and the only way to tell whether they were right is to measure what happens to the customers refused.
Visa formalized the network side in rules introduced in April 2020 and updated in April 2021, grouping response codes into four categories: issuer will never approve, issuer cannot approve at this time, data quality, and generic responses. Per Visa's rule update, a merchant may not reattempt a transaction declined with a category one code, may reattempt a category two decline up to 15 times in 30 days, and must not reattempt with the same account number after a response code 14, invalid account number. Mastercard uses merchant advice codes returned with the decline, and its "do not try again" advice likewise prohibits retrying. Both networks charge fees for reattempts that break their rules.
| Category | Common examples | Typical cause | Retry? | Fix |
|---|---|---|---|---|
| Hard: credential unusable | Lost card, stolen card, closed account, invalid account number | Card replaced, cancelled or mistyped | Never on the same credential | Ask for another payment method; use account updater or network tokens for stored cards |
| Soft: funds | Insufficient funds, exceeds limit | Balance or credit limit at the time of the attempt | Yes, timed, within network limits | Retry when funds are likely, such as after typical pay dates; offer a smaller payment or alternative method |
| Soft: issuer or system | Issuer unavailable, system malfunction | Temporary outage at the issuer or processor | Yes, after a short delay | Retry once or twice; route through another processor if available |
| Soft: authentication required | Strong customer authentication required (Europe) | Issuer requires a challenge the transaction did not include | Yes, after authentication | Step up with 3-D Secure and resubmit |
| Data quality | Expired card, wrong expiry, security code mismatch | Stale or mistyped card data | Only after correcting the data | Account updater, network tokens, input validation at checkout |
| Generic | "Do not honor" and similar non-specific codes | Often issuer risk suspicion without a stated reason | Sparingly, and only with more data | Send richer data, authenticate, check fraud signals; ask the customer to contact the issuer |
| Merchant fraud screen | No issuer code; blocked before authorization | Merchant or vendor rules scoring the order as risky | Not applicable | Tune rules against measured outcomes; review borderline orders |
Why Approval Rates Differ So Much by Business
Two merchants with the same customers can see very different approval rates because of how they take payments. The main drivers:
Card-not-present versus card-present. In a store, a chip card generates a cryptogram that proves the physical card was present, so issuers approve with high confidence. Online, the issuer sees a card number and whatever data the merchant chooses to send, and approves less often.
Cross-border transactions. When the merchant's acquirer is in a different country from the issuer, issuers see higher fraud rates and approve less readily. The same transaction processed through a domestic acquirer is often approved more often.
Recurring billing. Subscriptions charge stored cards that expire, get replaced after fraud, and run into insufficient funds on the billing date. Without a process for these, a subscription business loses customers who never meant to leave, a problem usually called involuntary churn.
High-risk categories. Travel, digital goods, gaming and other categories with higher fraud and dispute rates face more cautious issuers regardless of the individual merchant's quality.
New versus returning customers. A first purchase from a new device and address looks riskier to both issuer and merchant than a repeat purchase on a known card. Approval rates on first orders are usually the weakest point in the funnel, and that is where false declines cost the most, because the customer has no reason to try again.
The Levers Merchants Actually Control
Ranked roughly from lowest to highest effort. Every lever below changes risk as well as approvals; the risk column in the table that follows is as important as the effect column.
1. Network tokens and account updater for stored cards
A network token replaces the card number with a network-issued credential that is updated automatically when the card is reissued, and each transaction carries a cryptogram tying it to the merchant. Issuers trust these transactions more. Per Visa's tokenization page, Visa's own network data for 2025 showed a 4.8 percent increase in authorization rates and a 39.4 percent lower fraud rate for tokenized card-not-present transactions compared with non-tokenized credentials, with Visa noting that individual merchant results vary. Account updater services from the networks provide new card details for stored cards that have been replaced. The mechanics are covered in network tokenization.
2. Send richer data with the authorization
Issuers approve what they can recognize. Correct merchant descriptors, billing address and security code, the right indicators for stored-credential and merchant-initiated transactions, and 3-D Secure authentication data where appropriate all give the issuer more reason to say yes. A recurring charge flagged correctly as a merchant-initiated transaction on a stored credential is treated differently from an unexplained card-not-present charge.
3. Smart retry timing and dunning for soft declines
For soft declines, when a retry happens matters more than how many. A retry seconds after an insufficient-funds decline will usually fail again; a retry timed for when funds are more likely to be available may succeed. For subscriptions, dunning combines timed retries with customer emails and in-app prompts to update a card. All of it must stay within network reattempt limits, and hard declines must never be retried.
4. Local acquiring for cross-border volume
Processing transactions through an acquirer in the customer's country makes them domestic to the issuer, which usually improves approvals and can lower interchange and cross-border fees. It requires acquiring relationships, and often a local entity, in each market, so it pays off only where cross-border volume is significant.
5. Routing across processors
Merchants with more than one processor can route transactions to the one with the best measured approval rate for a given card type and geography, and retry soft declines caused by processor outages through another. This is the core case for payment orchestration and multi-processor routing. The benefit depends on measured differences between processors, not on having two of them.
6. Tune the merchant's own fraud rules
The most under-examined lever. Rules written after a fraud spike tend to stay in place long after it passes, rejecting good customers who resemble the fraudsters. Tuning means measuring each rule's outcome, including the good customers it blocks, reviewing borderline orders rather than rejecting them, and testing looser thresholds on a controlled share of traffic while watching chargebacks.
| Lever | Typical effect | Effort | Risk it adds |
|---|---|---|---|
| Network tokens and account updater | Fewer stale-card declines; Visa reports a 4.8 percent authorization increase for tokenized CNP in 2025 | Low to medium, often a processor setting | Low; token fraud rates are lower per Visa |
| Richer authorization data | Fewer generic and risk-based declines | Low to medium, integration work | Low, if data is accurate |
| Smart retries and dunning | Recovers a share of soft declines, reduces involuntary churn | Medium | Network fees and penalties if limits are breached |
| Local acquiring | Better approvals on cross-border volume | High: contracts, entities, integration | Operational and compliance overhead per market |
| Multi-processor routing | Better approvals where processors differ; resilience to outages | Medium to high | Complexity; token and data portability issues |
| Fraud rule tuning | Fewer merchant-caused false declines | Medium, ongoing | Higher fraud and chargebacks if loosened carelessly |
The Tradeoff That Governs Everything
Every lever that makes approval easier also makes fraud easier, at least at the margin. Looser fraud rules approve more good customers and more fraudsters. Aggressive retries recover payments and generate network fees and issuer friction. Skipping authentication raises conversion and removes the liability shift that authentication provides.
The consequence of losing the balance is concrete. Fraudulent approvals become chargebacks, and chargebacks carry fees, lost goods and, above network thresholds, placement in card-network monitoring programs with fines and potential loss of card acceptance. The dispute side of this is covered in how chargebacks work.
The right objective is therefore approved good transactions: revenue from genuine customers, net of fraud losses and dispute costs. A change that raises the approval rate by two points and doubles the chargeback rate may reduce that number.
How to Measure It Properly
A single blended approval rate cannot tell a merchant what to fix. Useful measurement has four parts.
Segment the rate. Measure approvals separately by channel, card type, domestic versus cross-border, issuing country, new versus returning customer, first charge versus renewal, and processor. Problems concentrate in segments; averages dissolve them.
Break declines down by code. Group every decline into the categories in the table above. A rise in data-quality declines points to a checkout or stored-card problem; a rise in generic declines on one issuer points to a risk-signal problem; a rise in authentication-required declines points to a 3-D Secure configuration issue.
Count merchant blocks. Include orders the merchant's own screening rejected, and report acceptance rate alongside authorization rate. Without this, the most controllable category of decline is invisible.
Estimate false declines. Sample declined customers: how many retried with another card and succeeded, how many were approved on a later attempt, how many rejected orders a manual review would have passed. This is imprecise and still far better than assuming every decline was correct. The economics of what each approved transaction costs to accept, which frames how much an approval point is worth, are set out in interchange fees.
A Decision Framework by Merchant Type
| Merchant type | Main decline problem | First levers to pull |
|---|---|---|
| Subscription or SaaS billing | Stale cards and insufficient funds at renewal | Network tokens and account updater; correct stored-credential flags; timed retries and dunning |
| Domestic ecommerce retail | Generic and risk declines on first orders; over-strict fraud rules | Richer authorization data; 3-D Secure where it helps; fraud rule tuning with measured outcomes |
| Cross-border marketplace or retailer | Low issuer approval on foreign cards | Local acquiring in the largest markets; routing across processors by geography |
| High-risk category, such as travel or digital goods | Cautious issuers and high dispute exposure | Authentication and richer data first; loosen fraud rules only with chargeback monitoring in place |
| B2B payments on commercial cards | Limits and generic declines on large tickets | Pre-authorization checks with the buyer; enhanced commercial data; offer bank transfer for large invoices |
| Card-present retail | Few declines; mostly funds and technical | Terminal and connectivity reliability; clear handling of partial approvals; little else needed |
The position, and its tradeoff
For most online merchants, the most valuable first step is not a new processor or an orchestration layer. It is measuring declines properly by segment and code, then fixing stored credentials with tokens and account updater and auditing the merchant's own fraud rules. Those three steps address the declines the merchant controls most directly, at the lowest cost, before any routing complexity is added.
The tradeoff is that fraud rule tuning, the lever with the largest potential in many businesses, is also the one that can go wrong fastest. Loosening rules without watching chargebacks trades one invisible loss, false declines, for a visible one that the networks penalize. The discipline is to move one rule at a time on a controlled share of traffic and judge it by approved good transactions, net of fraud and disputes. Merchants willing to do that usually find revenue they were refusing. Merchants that chase the headline approval rate usually find it in their chargeback reports a few months later.
Frequently Asked Questions
Why was a customer's card declined when they had money in the account?
Most often because the issuer's fraud model judged the transaction unusual, or because the card details sent were incomplete or out of date, rather than because of funds. Generic codes such as "do not honor" commonly reflect issuer risk suspicion without a stated reason. Merchants can reduce these by sending richer data, authenticating with 3-D Secure where appropriate, and using network tokens for stored cards.
What is the difference between a soft decline and a hard decline?
A hard decline means the issuer will not approve that card credential at all, for example because it is reported lost or stolen, closed or invalid, and it must not be retried. A soft decline means the issuer will not approve this transaction now, for reasons such as insufficient funds, a temporary outage or a need for authentication, and it may succeed later or after a correction. Visa allows reattempts of temporary declines up to 15 times in 30 days and prohibits reattempting its "never approve" category.
What is a good card authorization rate?
There is no single good number, because rates vary widely by channel, geography, category and billing model, and published benchmarks mostly come from payment vendors measuring their own customer mix. A more useful approach is to track the rate by segment and decline code over time, compare processors on the same traffic, and judge changes by approved good transactions net of fraud and chargebacks rather than by the headline rate.
Do network tokens really improve approval rates?
Network data suggests they do. Visa reports that in 2025, tokenized card-not-present transactions had a 4.8 percent higher authorization rate and a 39.4 percent lower fraud rate than non-tokenized credentials, while noting that individual merchant results vary. Tokens help most for stored-card and recurring payments, because the credential updates automatically when a card is reissued.
Should merchants retry declined card payments?
Only soft declines, and only within network limits. Retrying hard declines is prohibited and incurs fees. For soft declines, timing matters more than frequency: a retry after insufficient funds works better days later than seconds later. Subscription businesses should combine timed retries with customer prompts to update payment details, and stay within Visa's and Mastercard's reattempt rules.
The Bottom Line
A declined payment is easy to treat as the customer's problem. It is often the merchant's. Some declines come from stale card data the merchant could have refreshed, some from missing information the issuer needed to say yes, and some from the merchant's own fraud rules rejecting customers who were never a threat. None of those appear in a fraud report, and most do not appear in a blended approval rate.
The merchants that raise approvals sustainably treat authorization as a funnel to be measured by segment and decline code, fix the cheapest causes first, and judge every change by approved good transactions after fraud and disputes. The approval rate follows. Chasing the rate directly, without watching what it does to chargebacks, tends to exchange one cost for another.