18+ --:--:-- UTC

The Payments Stack

By The economicsverified 2026-08-06next review 2027-08-06

Every deposit and withdrawal is a metered relay through paid intermediaries — banks, gateways and PSPs — each taking a slice before the money lands.

Money does not flow directly between a player and an operator; it passes through a stack of intermediaries — gateways, payment service providers, orchestration and compliance systems — that route it, retry it when banks decline, and take a fee at each step. Gambling is a high-risk merchant category with elevated declines and chargebacks, so the stack is engineered to lift acceptance while enforcing KYC, Strong Customer Authentication and anti-money-laundering duties. Its costs, like all others in the business, are ultimately covered by player losses.

Why gambling money is hard to move

Every deposit and withdrawal is a card, bank or e-wallet transaction that has to clear the same rails as any online purchase — but gambling sits in a high-risk merchant category, coded MCC 7995 by the card schemes. That label follows the money everywhere. Issuing banks see it and apply extra scrutiny; some block gambling outright, whether by customer choice, regulatory rule or internal risk policy. Volumes are punishing too: deposits arrive in small, frequent bursts, withdrawals must be paid back quickly to meet player expectations and licensing rules, and cross-border play multiplies the currencies and local methods involved. On top of that ride hard legal duties — know-your-customer identity checks, age verification for the 18-or-over rule, source-of-funds questions and anti-money-laundering monitoring — none of which an ordinary retailer carries. The result is a payment flow that is higher-risk, more heavily declined and more tightly regulated than almost any other online sector. Moving money for a gambling operator is therefore less a plumbing job than a continuous negotiation with banks, card schemes and regulators. This content is for adults aged 18 or over.

The PSP and the gateway

An operator does not connect to Visa, Mastercard or a national bank network directly. It plugs into a payment service provider (PSP) and its gateway — the intermediary that translates a player's 'deposit £20' into messages the card schemes, bank rails and e-wallets understand, and carries the authorisation response back. The gateway is the technical pipe; the PSP is the commercial and regulatory party that holds the acquiring relationships and moves the funds. For this, the PSP charges per transaction: typically a small percentage of the amount plus a fixed fee, with higher rates for a high-risk category like gambling. A single provider is rarely enough. Different PSPs are strong in different countries, support different local methods, and are accepted by different issuing banks, so operators integrate several. Each integration adds a counterparty that must itself be licensed, must run its own fraud and compliance checks, and must take its cut. The gateway is where the player's convenience — tap, deposit, play in seconds — is manufactured, and where the first slice of every pound is quietly taken before it ever reaches the operator's balance.

Orchestration and cascading

Because no single provider accepts every transaction, operators sit a payment orchestration layer above their PSPs. Orchestration is the routing brain: for each transaction it decides which provider to try first, based on the player's country, card type, amount and past success rates. When a transaction is declined, orchestration can retry it through a different provider — this is cascading. Picture a £50 deposit: it is offered to PSP A and declined; the orchestration layer immediately re-presents it to PSP B, which approves. The player sees one brief pause, not a failure. Cascaded across thousands of attempts, this lifts the overall acceptance rate — the share of deposit attempts that succeed — above what any single provider would deliver alone. The trade-off is cost and control: every retry can incur a fee, aggressive cascading can look like card-testing to banks, and routing logic must respect Strong Customer Authentication and fraud rules rather than simply hammering a declined card. Orchestration is sold as neutral infrastructure, but its real job is revenue defence — turning a would-be lost deposit back into a completed one, for another slice of the flow.

Declines and chargebacks

A decline is an issuing bank refusing a transaction, and in gambling the decline rate runs high relative to ordinary retail. Reasons stack up: the MCC 7995 code triggers caution, some banks bar gambling by policy or at the customer's request, spending limits and fraud filters fire more readily, and cross-border attempts look riskier. A chargeback is worse. Here a completed card payment is later disputed by the cardholder and clawed back by their bank, with the money reversed and often a fee charged to the operator. Some chargebacks are genuine fraud — a stolen card used to deposit — but others are players attempting to reclaim gambling losses, sometimes called 'friendly fraud'. Either way the operator loses the funds and gains a black mark: card schemes track chargeback ratios, and a provider whose ratio climbs too far faces penalties or removal. Chargebacks are therefore both a direct cost and a compliance signal — a spike can indicate stolen cards, account takeover or money-laundering patterns, and feeds straight into the operator's fraud and AML monitoring. Managing declines and chargebacks is a permanent tension between accepting more money and accepting more risk.

Settlement and the compliance layer

Approval is not payment. When a deposit is authorised the operator can let the player stake immediately, but the actual money settles later — the PSP batches transactions, deducts its fees, holds a reserve against future chargebacks, and pays the net amount to the operator days afterwards. Settlement is when the operator truly receives the cash, and it always arrives smaller than the headline deposits and slower than the play. Riding on the same rails is a compliance layer that the payments stack must enforce, not merely observe. Know-your-customer and age checks must clear before funds move freely; source-of-funds questions can pause a large or unusual deposit; Strong Customer Authentication, mandated for card payments under Europe's PSD2 rules, adds a verification step at the point of payment; and anti-money-laundering monitoring watches deposit and withdrawal patterns for structuring, rapid in-and-out cycling or mismatched sources. These duties are not optional extras — they are licence conditions, and failures draw regulatory penalties. The payments stack is thus doing two jobs at once: moving money efficiently, and policing it. Both cost money, and both are wired into the same providers taking their per-transaction fees.

The truth: everyone takes a slice

Trace a single pound through the stack and the pattern is unmistakable: it enters through a gateway that takes a fee, may be cascaded across PSPs that each take a fee, is screened by fraud and compliance systems that cost money to run, settles days later net of charges and reserves, and — if the player later withdraws — makes the return trip through paid rails again. Every deposit and withdrawal passes through paid intermediaries, and each one takes a slice. This is where convenience, fraud control and regulatory duty collide: players want instant deposits and fast payouts, banks and schemes want low fraud and chargebacks, and regulators want KYC, SCA and AML done properly — three pulls the operator must satisfy at once. None of these costs are absorbed by goodwill. Like every other expense in the business, they are ultimately covered by gross gaming revenue — the players' net losses. The payments stack is not a neutral convenience; it is a metered, regulated chain of paid hands, and the meter runs on money that players have already lost. This content is educational and for adults aged 18 or over, not promotional.

Key facts
Merchant categoryMCC 7995The card schemes' high-risk code for betting and gambling
Who takes a feeEvery layerGateway, PSP(s), orchestration, fraud and AML tooling
CascadingRetry a decline via another providerLifts the overall acceptance rate
ChargebackCardholder disputes a paid transactionMoney clawed back; a fraud and AML signal
SettlementNet of fees, days laterOperator receives less than headline deposits, and slower than the play
Compliance on the railsKYC, source-of-funds, SCA, AMLLicence conditions, not optional extras

Education, not advice. This explains how the iGaming industry works on the supply side — platforms, suppliers, payments, data and affiliates — as neutral education. iGamer is independent and non-promotional: nothing here recommends any operator, platform, supplier or affiliate. Every layer described is ultimately funded by player losses. 18+.