A digital payments system moves monetary value between two parties electronically, with no cash changing hands. Four actors are always present: the payer, the payee, their financial institutions, and a network that routes the instruction between them. The front end completes in milliseconds. The money can take until the next business day, and in the euro area it increasingly does not. This article walks each stage of that journey, the economic logic that produced the architecture, and the trade-offs an institution actually faces when it picks a rail.

The architecture of a digital payment: from instruction to settlement

The system is layered for a reason, and the layers answer to different rules, timelines and risk frameworks. That is why a contactless payment feels instant while the merchant's balance may not reflect it until the following morning, and why payment orchestration exists as a discipline: someone has to decide which rail an instruction takes, what happens when it fails, and where the record of that decision lives.

  1. Authorisation. The issuer checks funds and fraud signals and returns an approval code, typically in under 200 milliseconds. Nothing has moved yet.
  2. Clearing. The network aggregates transactions and calculates net positions between acquirers and issuers, usually in batch cycles.
  3. Settlement. Central bank money actually moves, in the euro area over T2.
  4. Reconciliation. Both sides match what they think happened against what the statement says, and the exceptions become work.

Authorisation is a reservation, not a transfer, and that distinction is where most product misunderstandings start. Settlement is the moment the payment becomes unconditional, and in the EU that moment is not a matter of convention: Article 3 of the Settlement Finality Directive (98/26/EC) makes transfer orders enforceable and binding on third parties from the point defined by the system's own rules, which is why those rules are drafted as carefully as they are. T2, the Eurosystem's real-time gross settlement service, replaced TARGET2 on 20 March 2023 and moved to ISO 20022 in the same cutover.

The volumes make this a macroeconomic instrument, not only a technical one. The ECB recorded 149.7 billion non-cash payments in the euro area in 2024, worth €230.4 trillion, with cards accounting for roughly 56 to 57% of the number of transactions and a small fraction of the value. In Parkin's macroeconomic framework, aggregate payment volume is a proxy for spending velocity; in his microeconomics, the pricing decisions inside the system shape behaviour at the till. Articles 3 and 4 of the Interchange Fee Regulation (EU) 2015/751 cap interchange at 0.2% of value for consumer debit and 0.3% for consumer credit, a structural cost difference between European merchants and those in unregulated markets.

Tokenisation sits underneath all of it. The network replaces the primary account number with a token scoped to one device or one merchant, so a breach of the merchant's system yields nothing reusable. It is the single control that most reduced the value of stolen card data, and it is invisible to the cardholder.

Payment rails compared: cards, account-to-account and real-time systems

Not all digital payments travel the same route. The rail decides speed, cost, reversibility and who carries the fraud risk, and those differences compound as volume grows.

Rail

Speed

Cost to merchant

Consumer protection

Reversibility

Card, consumer debit

Instant authorisation, next-day funds

Interchange capped at 0.2% in the EU

Chargeback rights

Reversible for months

Card, consumer credit

Instant authorisation, next-day funds

Interchange capped at 0.3% in the EU

Chargeback rights

Reversible for months

SEPA Instant credit transfer

Under 10 seconds, end to end

Near zero, and cannot exceed a standard transfer

Verification of payee, no chargeback

Effectively irrevocable

Correspondent banking, cross-border

One to several days

Fixed fees plus FX spread

Contractual, varies by corridor

Recall is a request, not a right

The Instant Payments Regulation (EU) 2024/886 turned the third row from an option into an obligation. Euro-area payment service providers have had to receive instant transfers since 9 January 2025 and send them since 9 October 2025, at a price no higher than a standard credit transfer, with verification of payee free on every euro credit transfer from the same date. Non-euro-area providers follow in January and July 2027. The microeconomic effect is a supply-side shift: a merchant paying near zero instead of interchange can price differently. The macroeconomic effect is the end of float, which compresses the cash conversion cycle for small businesses that used to finance themselves on the gap. The asymmetry is protection. A card payment can be pulled back through chargeback. An instant transfer is a push, and once it lands it is gone.

Risk, regulation and the economics of trust in digital payments

A payments system is worth exactly the trust placed in it, and that trust is engineered rather than spontaneous. The joint EBA and ECB fraud report of December 2025 put total payment fraud in the EEA at €4.2 billion in 2024, against €3.5 billion in 2023: credit transfers at €2.2 billion, up 16% year on year, and cards issued in the EU and EEA at €1.3 billion, up 29%. Most of the machinery a user never sees exists to hold that number down.

Strong customer authentication is the largest single piece of it. Under PSD2 and Delegated Regulation (EU) 2018/389, an electronic payment needs at least two independent factors from knowledge, possession and inherence. The two exemptions people confuse are separate rules: Article 11 covers contactless at the point of sale, up to €50 per transaction with a cumulative limit of €150 or five consecutive payments; Article 16 covers remote low-value payments at €30, cumulative €100 or five. The same report shows what SCA is worth: card fraud rates ran about ten times higher when the acquirer sat outside the EEA, and roughly seventeen times higher where SCA does not apply.

  • PCI DSS, for anything that touches card data
  • PSD2 and strong customer authentication, for the payment journey itself
  • AML and KYC under the AML directives, with the AML Regulation (EU) 2024/1624 applying from 10 July 2027
  • GDPR, for the personal data the payment generates
  • local authorisation, as a payment institution or an electronic money institution

Layering those regimes is where smaller institutions underestimate the cost. A medical practice taking card payments is the clearest example. Practice-administration references treat card handling as a front-desk routine; in the EU it is two regimes at once, PCI DSS on the card data and GDPR on the patient data it is attached to, where health information is a special category under Article 9 and a breach carries a 72-hour notification duty under Article 33. One incident, two clocks, two authorities.

Network and statutory rules also work as economics. PSD2 Article 74(2) places the loss on the payee's payment service provider when it fails to accept strong customer authentication, pricing the incentive into the party best placed to fix it. The card networks reached the same result with chip liability through rules rather than legislation. Underneath both is Parkin's externality argument: fraud losses fall on parties who were never in the fraudulent transaction and surface as a risk premium in everyone's pricing, which is the standard justification for intervening at all.

What happens when a payment fails: error handling and dispute resolution

A payment failure is a category, not an event. Declined authorisations, failed settlements, duplicate charges and fraud each have a different resolution path and a different party carrying the initial cost. The card chargeback lifecycle is the most formalised: the cardholder disputes, the issuer provisionally credits the account, the acquirer debits the merchant, and the merchant has a defined window, commonly 30 days, to submit representment evidence. Win and the funds come back. Lose and the merchant absorbs the transaction value plus an acquirer fee of roughly €15 to €50. Ratios matter more than any single dispute: Visa's dispute monitoring programme starts at a 0.9% ratio with at least 100 disputes a month and Mastercard's at 1.5%, and entering one brings fines and eventually the loss of card acceptance.

That fee is a price signal in Parkin's sense, pushing merchants towards fraud prevention and accurate product descriptions. For account-to-account payments the machinery is thinner by design, which is why verification of payee arrived first and why the PSD3 package, which reached final agreement in April 2026 and is awaiting publication in the Official Journal, spends so much of its text on fraud liability.

The future of digital payments: CBDCs, tokenised assets and embedded finance

A central bank digital currency is a structural change rather than a faster rail: central bank money moving directly between wallets, with the clearing layer removed rather than accelerated. The ECB Governing Council decided in October 2025 to move the digital euro to its next phase, with a pilot operational phase from the second half of 2027 and a possible first issuance during 2029, conditional on the Regulation being adopted. Programmability is the part with macroeconomic consequences: money that expires if unspent would be a policy instrument no existing infrastructure can offer. H.G. Wells got there first, though he did not have the ECB in mind.

Two other shifts are already commercial. Tokenised real-world assets settle fractions of securities or property in seconds rather than on a T+2 cycle. Embedded finance puts acceptance directly inside non-financial platforms, in commerce and logistics software, so the merchant never meets a payment gateway at all. Both move the same work in the same direction: out of a separate payments project and into the product.

Looking for the product idea, not just the rail?

Our free guide collects more than 40 fintech app ideas that users actually keep, with the payment and compliance mechanics behind each one set out plainly.

Get the free guide

Building or consolidating a payment stack?

WislaCode builds regulated payment software: gateway and scheme integration, orchestration across rails, SCA journeys and the reconciliation nobody demos but everyone needs.

Talk to our engineers
Frequently asked questions
What is a digital payments system in simple terms?

It is an electronic mechanism for moving money without physical cash. Four actors are involved: the payer, the payee, each of their banks, and the network that carries the instruction between them. Everything else in the system exists to decide whether the payment is allowed and to prove afterwards that it happened.

How does a contactless card payment actually work, step by step?

The terminal sends an authorisation request through the acquirer to the card network, which routes it to the issuing bank. The issuer checks available funds and fraud signals and returns an approval code, usually in under 200 milliseconds. That is a reservation, not a transfer: clearing and settlement follow later, which is why the merchant's balance moves after the customer has left.

What is the difference between clearing and settlement in payments?

Clearing is the calculation of what each bank owes the others once transactions are netted off. Settlement is the actual movement of central bank money that discharges those obligations, in the euro area over T2. Clearing is the scorecard, settlement is paying the bill.

Why do some payments take days to clear even though they feel instant?

Authorisation is instant, but clearing runs in batch cycles and settlement depends on the operating hours of the underlying system. SEPA Instant credit transfers are the exception: they settle end to end in under ten seconds, and under Regulation (EU) 2024/886, euro-area providers have had to send them since 9 October 2025 at no extra cost.

What is an interchange fee and who pays it?

Interchange is the fee the merchant's bank pays the cardholder's bank on each card transaction. In the EU, Articles 3 and 4 of Regulation (EU) 2015/751 cap it at 0.2% of value for consumer debit cards and 0.3% for consumer credit cards. The merchant absorbs it, and it reaches the consumer through pricing rather than as a line item.

How do digital payment systems prevent fraud?

Three layers do most of the work: tokenisation, which replaces the card number with a device or merchant-specific token so stolen data is unusable; strong customer authentication under PSD2, requiring two independent factors; and real-time transaction monitoring. The joint EBA and ECB report of December 2025 found card fraud rates roughly seventeen times higher on payments where SCA does not apply.

What is a chargeback and how does it affect merchants?

A chargeback is a forced reversal initiated by the cardholder's bank. A merchant that loses one absorbs the transaction value plus an acquirer fee, typically around €15 to €50. Ratios matter more than individual cases: Visa's dispute monitoring programme begins at a 0.9% ratio with at least 100 disputes a month and Mastercard's at 1.5%, and both bring fines.

What is a CBDC and how is it different from existing digital payments?

A central bank digital currency is central bank money held directly by the user, rather than commercial bank money moving over private rails, which removes the clearing layer instead of speeding it up. The ECB decided in October 2025 to move the digital euro forward, with a pilot from the second half of 2027 and a possible first issuance during 2029 if the Regulation is adopted.

Is an account-to-account payment safer than paying by card?

They fail differently. Cards carry chargeback rights, so a disputed payment can be pulled back. An instant transfer is a push payment and is effectively irrevocable once it lands. The gap narrowed on 9 October 2025, when verification of payee became free and mandatory on euro credit transfers, warning the payer before the money leaves rather than after.