A payment processor can authorise a card payment, screen for fraud and settle funds into your account. It may not repay every loss linked to the sale.
A £500 chargeback, a day-long checkout outage or stolen customer data can leave your business carrying costs. Those costs may sit outside the provider’s terms.
Processors & PSP Cover is not one policy or promise. It combines your provider’s contract, security controls, regulatory status and your own insurance.
For UK SMEs, the gaps matter. Failures, fraud or a breach can stop sales quickly.
Payment processor cover: who actually pays?
A provider protects parts of a transaction. It does not protect every loss around it.
The main specialist sources, the FCA, card schemes and cyber insurers agree on one point. FCA status, PCI DSS compliance and fraud tools are controls, not a blanket merchant guarantee.
The merchant agreement usually decides how far the provider must compensate you.
Does a PSP repay every fraud loss?
A PSP does not normally repay every fraud loss. It may refund an unauthorised payment in defined cases.
A card payment accepted by your shop can still become a chargeback. A chargeback means the card issuer reverses payment after a dispute.
Visa and Mastercard rules give merchants a process for submitting evidence. They do not promise that the merchant will win.
Delivery proof, customer messages and the right response deadline matter. A late reply can mean an automatic loss.
Where does your own risk begin?
A customer-data incident creates a separate problem. Names, addresses, account logins or cardholder data may be exposed.
Your firm may need to assess notification duties under UK GDPR and the Data Protection Act 2018. This can apply even when the processor handled the card processing.
Protection map: the PSP handles agreed payment tasks; card schemes govern disputes; the FCA regulates certain firms; your insurance may meet selected costs. No single layer replaces the others.
A payment service provider (PSP) combines one or more payment services for a merchant. These can include gateway access, fraud screening, acquiring links and settlement reports.
A PSP may also offer alternative payment methods. Think of it as a payment hub with several possible jobs.
In a typical card transaction, the customer enters payment details at checkout. The payment gateway encrypts and sends the request.
The processor routes it to the acquirer and card scheme. The card issuer then approves or declines it.
Approval means the issuer is prepared to honour the transaction. It does not mean final settlement.
The transaction is cleared and settled over the following business days. Fees, refunds, reserves and later chargebacks can affect that process.
A PSP may perform several of these functions. It may not act as the acquirer or hold the merchant’s funds.
Payment models decide who holds the risk
The payment model decides where funds and liability sit.
Is a gateway the same as a processor?
A payment gateway is a secure digital route for payment details. It sends details from checkout to the relevant payment systems.
A payment processor handles message flow and approval steps. Merchant acquiring lets a business accept cards and receive settlement.
These roles can sit with one firm. They can also sit with different firms.
Who holds funds in each model?
An e-money institution can issue electronic money. It can hold customer funds under safeguarding rules in the Electronic Money Regulations 2011.
Safeguarding aims to separate relevant client funds from the firm’s own money. It is not Financial Services Compensation Scheme deposit protection.
| Model | Usually holds settlement funds? | Risk the SME should check |
|---|
| Gateway | Usually no | Data flow, uptime and support limits |
| Acquirer | Usually yes | Reserves, settlement timing and chargebacks |
| PayFac | Often yes | Sub-merchant rules and account suspension |
| Merchant of record | Often yes | Who owes the customer refund or tax |
| E-money institution | Can hold safeguarded funds | Safeguarding terms and withdrawal access |
The model can change your access to cash. The next section shows where contract terms can create that pressure.
Compare PSP contracts before choosing on fees
A lower transaction fee can prove more costly. The terms may allow a broad reserve, low liability cap or weak outage support.
For a microbusiness, a reserve between 5% and 15% of card takings can affect cash flow. It can delay stock purchases, VAT payments and payroll.
Some higher-risk trading models face a larger percentage. A hold may last between 90 and 180 days, depending on the contract and review.
Which clauses can freeze your cash?
Read sections headed reserve, set-off, settlement, prohibited business and termination. These clauses can decide whether cash stays available during a dispute.
A set-off clause lets the provider deduct a claimed amount from money it holds for you. It avoids sending you an invoice later.
The most common error is comparing fees without reading the reserve terms. A low rate cannot replace access to working cash.
What should an outage SLA promise?
A service-level agreement, or SLA, states the service standard the provider promises. Look for uptime measures and maintenance notices.
Also check the incident contact route and sub-processor reliance. Check the remedy when the service fails.
| Contract check | Question to ask | Why it affects cover |
|---|
| Reserve right | What percentage, trigger and release date apply? | Controls working cash during disputes |
| Liability cap | Is it limited to fees paid in 12 months? | May be far below lost turnover |
| Chargeback support | Who submits evidence and by what deadline? | Late evidence can lose the claim |
| Incident support | Is there a 24-hour contact and named escalation? | Speed limits payment disruption |
| Termination | Can the firm close the account without long notice? | Affects ability to switch provider |
🎯Useful for this topic
A USB NFC security key adds a physical check when staff sign in to payment dashboards. It can reduce the risk from a stolen password.
- Requires a physical key as well as the dashboard password
- Can protect administrator access to refunds and settlement settings
- Works as a backup sign-in method where compatible with the provider
Find on Amazon →
Choose a PSP for the way customers actually pay. Do not compare headline card rates alone.
Check support for cards, digital wallets, Open Banking and recurring payments. Also check local methods used in your target markets.
A UK retailer expanding into Europe may need euro settlement and local-language checkout. It may also need proper SCA handling and clear UK GDPR data-transfer terms.
Technical fit matters too. An off-the-shelf plug-in may suit a small e-commerce shop.
A SaaS platform or marketplace may need APIs, tokenisation and webhooks. It may also need split payments and role-based dashboard access.
Ask which compliance tasks remain with your business. Focus on PCI DSS, refunds and customer messages after fraud or outages.
Contract wording shows your immediate financial exposure. UK rules explain what regulation can, and cannot, do for you.
UK rules protect payments, not every loss
UK payment rules require certain firms to protect customers and manage payment risks. They do not make an FCA-regulated provider an insurer of every merchant loss.
Does FCA authorisation protect merchants?
FCA authorisation means the regulator supervises permitted activities. It does not mean the FCA repays your lost turnover.
It also does not reverse every commercial dispute. It cannot guarantee every service promise.
The Financial Ombudsman Service can handle eligible complaints in defined cases. A limited company should not assume it has the same route as a personal consumer.
Check the provider’s terms and your business eligibility.
Does PCI DSS replace cyber security?
PCI DSS is the card industry’s security standard. It applies to firms that store, process or transmit cardholder data.
The Payment Card Industry Security Standards Council maintains the standard. UK GDPR duties cover personal data more widely.
After Brexit, UK and EEA rules remain closely aligned in many areas. Separate legal and regulatory regimes administer them.
UK firms should consider the Payment Services Regulations 2017, FCA expectations and UK SCA requirements. Services into the EEA may need an authorised EEA entity.
Another lawful structure may also be needed. UK firms cannot rely on the former EU passporting model.
This matters when a PSP, acquirer or e-money institution serves merchants in both regions. It also matters for euro payments or EEA sub-processors.
Confirm which group company contracts with you. Check where data and settlement funds are handled.
Also check whether regulatory permissions cover the countries where you sell. These checks lead directly to the payer in each incident.
Fraud, chargebacks and outages: find the payer
Each incident has a different likely payer.
Who pays after fraud or chargebacks?
A chargeback is a card payment reversed through the card scheme after a customer dispute. It can follow stolen-card use or goods not received.
It can also follow refund disputes or subscription confusion. So-called friendly fraud occurs when a genuine buyer disputes a valid purchase.
The merchant normally needs evidence. For physical goods, this may mean a tracked delivery record.
For digital services, access logs and accepted terms may help. Evidence needs differ by reason code and scheme rules.
Who pays after a breach or outage?
A PSP outage is different from fraud. The provider’s platform may be unavailable while your own systems remain safe.
Cyber business interruption cover may not respond in that case. Many policies require a defined insured cyber event.
This is where the provider’s liability cap can matter most.
A day without checkout can damage cash flow. The next section explains which cyber costs a policy may meet.
Cyber insurance covers selected payment gaps
Cyber insurance can pay defined costs after a covered cyber event. It is not a chargeback guarantee or a replacement for a PSP contract.
A waiting period is the time before business-interruption cover starts. It is often between 8 and 24 hours.
A short processor outage may cause real lost sales. It may still give no payment under that section.
Which cyber costs can be insured?
Many cyber policies can include incident response costs and digital forensics. They can also include legal support, data restoration and customer notification.
Cyber extortion and third-party liability may also be included. Cover remains subject to the policy limit, excess and conditions.
This works well in theory, but wording decides the outcome. Ask what event must happen before each cover section responds.
Which payment losses are often excluded?
Chargebacks and voluntary bank transfers are frequent pressure points. Contractual penalties and losses assumed only by contract can also be excluded.
Some policies have a financial loss exclusion. It can limit claims for money lost through payment instructions or trading activity.
Crime or fidelity cover may suit employee theft and some funds transfer fraud. Professional indemnity may matter if a SaaS platform allegedly failed in its service.
Professional indemnity is also called errors and omissions cover. Directors’ and officers’ cover addresses different management claims.
Your business model decides which of these gaps matters most. The next examples show how that changes in practice.
Four SME payment models and their gaps
Your operating model changes the risk map.
Online shops and SaaS subscriptions
An e-commerce shop may lose stock and payment after card-not-present fraud. A later chargeback can remove the sale.
The original postage cost is also unlikely to return.
A SaaS firm has another weakness: recurring billing. Strong Customer Authentication, or SCA, adds an identity check for many electronic payments.
For example, customers may approve a purchase in a banking app. Poor handling of SCA exemptions can cause failed renewals and customer churn.
For a firm selling £5,000 to £20,000 online each month, a two-day checkout failure can hurt cash flow. Keep a tested alternative payment route.
Check that refund records and customer messages stay consistent across both systems.
Marketplaces and international sellers
A marketplace that splits payments between sellers has more moving parts. It may onboard sellers, hold funds and decide refund rules.
It may face claims from buyers and sellers if an account freezes.
A merchant-of-record arrangement can simplify card acceptance. It can also change who contracts with the customer.
It may change who controls tax, refunds and chargebacks. Do not treat this model as a risk-free wrapper.
International sales bring currency conversion and local authentication questions. They also raise cross-border data questions.
Open Banking payments can reduce card fees in some cases. They create a different customer journey and refund process.
A practical review before renewal
Use this short review with your provider and insurance documents. It is a decision checklist, not legal, regulatory or insurance advice.
- Confirm the legal entity, FCA status and exact payment model used for your account.
- Ask for the reserve trigger, maximum percentage, release period and termination rule in writing.
- Find the liability cap and identify whether it excludes lost sales, indirect loss and sub-processors.
- Test the chargeback evidence route and name the person who can respond outside office hours.
- Ask your broker whether cyber cover includes contingent supplier failure, social engineering fraud and business interruption.
Before buying or renewing cyber insurance, give the broker your PSP terms. Also give the largest likely weekly payment volume.
Name essential checkout suppliers too. This gives a clearer discussion than asking whether a policy “covers payments”.
This guidance is less relevant if your business does not accept digital payments or process customer payment data. It is not a substitute for regulated legal, compliance or insurance advice. Seek that advice if you act as a PSP, PayFac, e-money institution or marketplace handling client funds.
What people ask
Does PSD2 still apply in the UK?
UK payment rules retain many PSD2-derived requirements through the Payment Services Regulations 2017. These include Strong Customer Authentication.
UK firms should assess FCA rules and permissions. They should not rely on EU passporting assumptions.
Is PayPal a payment service provider?
PayPal can act as a payment service provider for merchants. Its role depends on the product and agreement used.
Check settlement, dispute, reserve and account-limitation terms. Those terms define the precise service.
Are chargebacks covered by cyber insurance?
Chargebacks are often excluded from cyber insurance unless the policy clearly says otherwise. Cyber cover may pay breach-response costs.
Card-scheme disputes usually remain a merchant trading loss.
Can a PSP cover regulatory fines?
A PSP’s service terms rarely promise to cover regulatory fines imposed on your business. Insurance cover for fines is limited by law and wording.
Obtain advice from an authorised adviser for your circumstances.
What matters most:- A familiar PSP name does not transfer every fraud, outage or customer-data loss away from the merchant.
- The payment model and merchant agreement show who holds funds, controls reserves and takes dispute risk.
- FCA status and PCI DSS compliance are useful checks, but they are not insurance policies.
- Cyber insurance may pay breach and recovery costs. Chargebacks and third-party outages need separate wording checks.
Related sources
These articles can help you explore the topic in more depth: