Not for hours. Sometimes not for days. What actually happens between the tap and the money landing is a five-party relay over a promise — and understanding it explains why rewards cards cost more, and why an entire country's card payments once vanished for ten hours.
When your card is approved in under a second, where did the money go?
Nowhere. Not yet. What just happened is called authorization — a question sent to your bank asking "will you honor this?" and a one-word answer sent back. No money changes hands during authorization. It's a promise, checked and recorded.
The actual movement of funds is a separate event called settlement, and it almost always happens later — hours or days later. Five parties are involved in even the simplest tap, and it helps to name them before anything else makes sense.
| Cardholder | You. The person tapping. |
| Merchant | The business getting paid. |
| Acquirer | The merchant's bank or processor — takes the sale request in. |
| Network | Visa or Mastercard. Routes the message. Never holds the money. |
| Issuer | Your bank — the one who actually answers "yes" or "no." |
Watch the request travel. Each hop below is a real message crossing a real institutional boundary — this is a stylized walk-through of the route, not a live network trace, but the number of hops and their order are accurate.
Notice the last row. It doesn't change. That's the entire point of this section — the approval and the payment are two different events, separated by more than just time.
If Visa "runs" card payments, why does your bank make the decision?
Visa and Mastercard are not banks. They never hold your money, and they don't decide whether your card gets approved. What they run is the rulebook and the switch — the shared rails that let a bank in one city talk to a bank in another, in a common language, in under a second.
Taps or types a card number
Terminal or checkout page sends the request
Merchant's bank, forwards the ask
Visa / Mastercard — routes and enforces rules
Your bank — approves or declines
The reply travels back along the exact same chain, in reverse. This is called the "four-party model" in payments literature — cardholder, merchant, acquirer and issuer are the four parties; the network is the switch that connects them, which is why some diagrams count it as a fifth.
Here's the detail that matters for everything that follows: this same chain runs twice. Once immediately, for authorization — a yes/no answer in under a second. And again later, for clearing and settlement — when the merchant's bank submits a batch of the day's approved transactions and the real transfer of money finally begins, bank to bank, along a completely separate process.
The network runs the rails. Does the network keep the toll?
Barely any of it. When settlement happens, the merchant doesn't receive the full sale amount — a fee is deducted first, and it splits between parties in a very lopsided way. The biggest piece, called the interchange fee, goes to your issuing bank — the one that gave you the card, not the one the merchant banks with. The network keeps a much smaller assessment fee for itself, for running the rails at all.
Interchange isn't one number. It's set by published schedules that change by card type, and the differences are large. Try it below with real, current US rates.
This shows interchange and the network's assessment fee only — the two components set by published schedule. On top of both, the merchant's own processor adds a separately negotiated margin, which isn't published and varies merchant to merchant, so it's left out here on purpose.
Slide the card type from Regulated debit to Premium rewards on the same $100 purchase. The fee moves from about a quarter to nearly two dollars — roughly a seven-fold difference — for the exact same tap, at the exact same merchant, on the exact same terminal. The only thing that changed is which bank issued the card sitting in someone's wallet. The merchant has almost no say in this at all.
If authorization already happened, what is everyone waiting for?
Clearing. At the end of the business day (or in a batch on some fixed schedule), the merchant's bank submits every approved transaction from that day as a group. The issuing bank then actually sends the funds — not to the merchant directly, but through the network, to the acquirer, who finally credits the merchant's account. Pick a purchase date below and watch the real gap.
The sentence to remember: "approved" is your bank promising to pay, not your bank paying. Domestic card settlement in the US typically clears in one to two business days after the batch is submitted. Cross-border adds currency conversion and correspondent banking on top, which is why the gap grows and gets less predictable — sometimes by several more days.
Rewards cards cost merchants more to accept. Who actually funds the rewards?
Merchants rarely charge different prices for cash versus card, so the higher interchange a rewards card generates gets baked into the price of everything, for everyone who shops there — including the person paying cash. Economists at the Federal Reserve Bank of Boston measured this directly, tracking it down to the household level.
| Income | Net transfer, per year |
|---|---|
| Under $20,000 | pays $21 |
| $20,000 – $150,000 | roughly balanced |
| Over $150,000 | receives $750 |
Not everyone agrees on the exact size of this effect — one industry-funded rebuttal argues the framing overstates it — but every independent study over more than fifteen years has found the same direction: card rewards are funded by a transfer from cash and debit users to rewards-card users, and because rewards use rises with income, the transfer runs from lower-income to higher-income households on net. A 2026 Harvard Business School working paper estimates the aggregate transfer at roughly $30 billion a year in the US alone.
Five institutions review every tap. Does that make the system resilient?
Not automatically. On Friday, June 1, 2018, a single hardware component failed inside one of Visa's two UK data centers. Those two centers were each built to independently handle 100% of Visa's European transaction volume — textbook redundancy. But the failing switch also broke the synchronization that lets the backup center take over automatically, so the standby never fully kicked in.
For roughly ten hours, cards stopped working across Europe. Some UK shops and pubs switched to cash-only on the spot. Visa later confirmed it wasn't a cyberattack or fraud — just one rare hardware fault, in one building, that the redundancy plan didn't anticipate.
| Duration | ≈ 10 hours (June 1, 2018) |
| Transactions attempted (Europe) | 51.2 million |
| Transactions that failed | 5.2 million (≈10%) |
| Failure rate, two "peak disruption" windows (10 min + 50 min) | 35% |
| Failure rate, rest of the incident | 7% |
| Cause | Hardware — one switch component |
Those two failure rates — 35% during roughly an hour of peak disruption, 7% for the other nine — are the real, published numbers from Visa's own account to the UK Parliament. Run the simulation below: it samples thousands of transaction attempts using nothing but those two rates and the real proportion of time each applied, and see what overall failure rate falls out.
Run it a few times — random sampling means it won't land on exactly the same number twice, but it should keep converging close to the real ~10% Visa reported. That convergence is the point: the outage's overall damage is fully explained by those two published rates and how long each was in force, nothing more exotic.
The deeper lesson isn't about Visa specifically — it's about the shape of the system. Five institutions touch every tap, which looks distributed. But underneath, transaction volume for an entire continent still funneled through two physical buildings. Distributed-looking is not the same thing as actually distributed.
The US has had instant bank-to-bank payments since 2017. Why didn't cards switch?
They genuinely could, technically. RTP, launched by The Clearing House in 2017, and FedNow, launched by the Federal Reserve in 2023, both settle in seconds, 24 hours a day, every day of the year. Neither has anything resembling the one-to-two-day gap this whole piece has been describing.
The catch is what instant buys you: irrevocability. Once an RTP or FedNow payment is sent, it cannot be pulled back — there is no built-in "take-back." Cards work the opposite way on purpose. The gap between authorization and settlement isn't just processing lag; it's also the window that makes chargebacks and dispute rights possible, which US law gives cardholders under Regulations E and Z.
| Rail | Typical settlement | Reversible after the fact? |
|---|---|---|
| Card networks | 1–2 business days | Yes — chargebacks |
| ACH | Same day to 1–2 days | Limited window |
| RTP / FedNow | Seconds, 24/7 | No |
So the honest answer is: it's a genuine trade-off, not an oversight. An instant, irrevocable rail is a worse fit for a consumer-protection model built around the right to dispute a charge after the fact. Whether that trade-off should be resolved differently — with new dispute mechanisms layered onto instant rails, for instance — is a live debate among regulators and payment companies, not a settled question, and reasonable people land in different places on it.
Authorization is not settlement. "Approved" means your bank made a promise. The money moves later, on a separate rail, on its own schedule.
The fee is set by policy, not by your merchant. Interchange comes from a published schedule keyed to card type. The business you're buying from has almost no control over which number applies to your card.
Rewards are funded by someone — usually not the bank. Higher interchange on premium cards gets priced into everything a merchant sells, spread across every customer, cash-payers included.
Check it yourself. Next time you tap, compare your banking app's "pending" transaction to when it actually posts. You're watching authorization and settlement happen to your own money, days apart, in real time.