iGaming Payment Processing Explained: How the Money Actually Moves in 2026
What exactly is iGaming payment processing and why is it different from regular e-commerce?
iGaming payment processing is the full chain of technology and banking relationships that authorizes, settles and reconciles deposits and withdrawals for online gambling operators. It differs from standard e-commerce because gambling is classified as a restricted or prohibited merchant category by Visa and Mastercard, meaning every participant in the chain — gateway, acquirer, PSP — must be explicitly licensed or approved to handle gambling transactions.
In a standard e-commerce checkout, a merchant can spin up a Stripe or Adyen account in a day. iGaming operators don't have that luxury. Visa MCC 7995 and Mastercard's equivalent gambling codes require the acquiring bank to hold a specific gambling license or operate under a jurisdiction that permits it. Most tier-1 banks in the US, UK and EU have blanket policies against onboarding gambling merchants — not because it's illegal, but because the chargeback rates and regulatory overhead aren't worth it to them.
The practical consequence is that iGaming operators are forced into a smaller pool of specialist acquirers and PSPs — names like Payvision (now ING-owned but still active in gaming), Nuvei, Paysafe, Safecharge (now Nuvei), and a cluster of Maltese, Cypriot and offshore acquirers that have built their entire business around high-risk verticals. These providers charge a premium for that access, and they enforce it through higher rolling reserves (typically 5–10% of monthly volume held for 90–180 days) and stricter chargeback monitoring.
There's also a jurisdictional layer that pure e-commerce doesn't have. A Curaçao-licensed operator accepting players from Germany needs to understand that German banks may block gambling transactions at the issuer level regardless of what your acquirer approves. The Netherlands, Sweden and several US states have implemented transaction blocking at the issuing bank side. Your payment stack has to account for that reality — routing around blocked issuers, offering alternative methods, and tracking decline reasons granularly enough to act on them.
How does a casino deposit actually flow from a player's card to the operator's bank account?
A card deposit travels through five distinct layers in roughly 2–8 seconds: the player's browser or app, your payment gateway, the acquiring bank, the card network (Visa/Mastercard), and the issuing bank. Each layer adds latency, a fee, and a potential failure point. Understanding where declines happen is the difference between a 60% and an 80% approval rate.
When a player clicks 'Deposit,' the gateway tokenizes the card details (PCI DSS compliance lives here) and fires an authorization request to the acquirer. The acquirer formats it into a network message and sends it to Visa or Mastercard, which routes it to the issuing bank. The issuer runs its fraud rules, checks available funds, and returns an authorization code — or one of roughly 30 decline reason codes. That round trip is typically under three seconds. Settlement — the actual movement of money — happens separately, usually T+1 or T+2.
The fees stack up at each hop. The issuing bank takes interchange (the biggest component, set by the card networks — roughly 1.5–2% for consumer credit in the EU, higher in the US). The acquirer takes their margin on top, plus scheme fees charged by Visa/Mastercard directly. Your PSP or gateway charges a per-transaction fee and often a percentage. By the time a €100 deposit clears, the operator might net €94–97 depending on the card type and the acquirer deal. On withdrawals, the cost structure is different but the principle is the same.
What most operators don't model at launch is the float. Rolling reserves mean a percentage of your gross processing volume is withheld by the acquirer for months. If you're processing €1M per month at a 10% rolling reserve held for 180 days, you have €600K tied up in reserve at any given time. That's working capital you can't use. Negotiate the reserve percentage and release schedule before you sign — it's far easier to push back before you're live than after you're dependent on that acquirer.
Which payment methods should an iGaming operator offer in 2026?
At minimum, launch with credit/debit cards, at least one major e-wallet, and a local payment method relevant to your primary market. In 2026, crypto (particularly USDT, BTC, ETH) is no longer optional for offshore operators — it's a primary deposit method for a significant segment of players and carries none of the card network restrictions.
Cards remain the highest-volume method globally, but approval rates for gambling transactions vary wildly by market. In the UK, the Gambling Commission's credit card ban (in force since April 2020) means you're limited to debit cards. In several EU markets, issuer-level blocking means card approval rates for offshore operators can drop below 50%. You need alternatives or you'll lose those players at checkout.
E-wallets — Skrill, Neteller (both Paysafe), PayPal (in licensed markets only), MiFinity — act as a buffer. The player funds the e-wallet with their bank, and the e-wallet transacts with the casino. This sidesteps issuer blocking and often delivers better approval rates and faster settlement. The trade-off is that Skrill and Neteller have their own KYC requirements and can restrict gambling-related accounts, and their fees aren't cheap — expect 1.9–2.5% on deposits.
Crypto is genuinely transformative for offshore operators. A USDT TRC-20 deposit costs cents in network fees, settles in seconds, and requires no banking relationship. Platforms like CoinsPaid, UtorgPay and B2BinPay have built iGaming-specific crypto processing infrastructure with AML screening baked in. The volatility risk is manageable if you settle to stablecoins. The regulatory risk is real — some jurisdictions explicitly prohibit crypto gambling — but for Curaçao, Anjouan and similar offshore licenses, it's table stakes in 2026.
Local payment methods (LPMs) are where operators consistently leave money on the table. In Brazil, Pix is now the dominant payment rail and any operator targeting Brazilian players without Pix integration is handing deposits to competitors. In Mexico, SPEI and OXXO cash vouchers matter. In Colombia, PSE bank transfers and Efecty are critical. Your PSP or payment orchestration layer should support these natively — if they don't, find one that does before you enter that market.
| Method | Best Markets | Typical Deposit Fee | Approval Rate (Gambling) | Settlement Speed |
|---|---|---|---|---|
| Visa/Mastercard (debit) | Global | 3–5% (operator cost) | 55–75% offshore; 80%+ in licensed markets | T+1 to T+2 |
| Skrill / Neteller | EU, LATAM, Asia | 1.9–2.5% | 85–92% | Instant to same-day |
| PayPal | UK, licensed EU markets | Negotiated | 90%+ | Instant |
| Pix | Brazil | <1% | 95%+ | Instant |
| Crypto (USDT, BTC, ETH) | Offshore / global | <0.5% (network fees) | N/A — no issuer friction | Minutes |
| Bank transfer / SPEI | Mexico, LatAm | Flat fee | High (no blocking) | Hours to next day |
| Voucher/cash (OXXO, Efecty) | Mexico, Colombia | 3–5% | Very high | Minutes after payment |
What is a payment orchestration platform and does an iGaming operator actually need one?
A payment orchestration platform sits above your individual PSPs and acquirers, routing each transaction to the provider most likely to approve it based on real-time rules — card BIN, player country, transaction size, time of day. For any operator processing meaningful volume across multiple markets, orchestration isn't a luxury; it's the difference between 65% and 82% approval rates.
Without orchestration, you pick one or two PSPs and every transaction goes through them. When one PSP has a technical outage, or their acquirer starts declining a specific card BIN, you lose those deposits. With an orchestration layer — providers like Xtremepush-integrated stacks, Paydoo, or the orchestration modules inside platforms like SoftSwiss Payments or EveryMatrix's CashierEngine — you define routing rules and fallback logic. A UK Visa debit card that declines at PSP A gets retried at PSP B automatically, in under a second, with no player-facing friction.
The business case is straightforward. If you're processing €500K per month and orchestration lifts your approval rate by 10 percentage points, that's €50K in additional deposits per month that were previously declined. Even at a 30% margin, that's €15K in additional GGR monthly. The orchestration platform costs a fraction of that. The math is obvious — the only question is whether your volume justifies the integration effort at launch, or whether you add it at scale.
For operators launching on a white-label platform like SoftSwiss, EveryMatrix or BetConstruct, some orchestration capability is often bundled into the cashier module. The caveat: the white-label provider controls the PSP relationships, which means you're dependent on their negotiated rates and their approved provider list. As you grow, you'll want to bring your own PSP contracts and plug them into the platform — most white-label agreements allow this after a certain volume threshold, but read the contract carefully before you sign.
What does iGaming payment processing actually cost — and what are the hidden fees?
Expect to pay 3–6% of deposit value in processing fees for card transactions through a specialist iGaming acquirer, plus rolling reserves of 5–10% withheld for 90–180 days. The headline rate is rarely the real cost — scheme fees, chargeback fees, monthly minimums and integration costs add up fast and are rarely front-and-center in a PSP's sales deck.
The fee structure on a typical iGaming acquiring deal breaks down like this: interchange (set by Visa/Mastercard, non-negotiable, roughly 1.5–2.5% depending on card type and region) plus the acquirer's margin (0.5–2%) plus scheme fees (Visa/MC charges, roughly 0.1–0.3%) plus gateway or PSP fees (0.1–0.5% plus a per-transaction flat fee of €0.10–0.30). Stack those up and a €100 deposit might cost the operator €3.50–6.00 in processing fees alone. E-wallets are cheaper on a percentage basis but have their own fee schedules.
Rolling reserves are the hidden cash flow killer. A 10% rolling reserve on €1M monthly volume means €100K per month is withheld. After six months at that rate, you have €600K sitting in a reserve account you can't touch. Some acquirers will negotiate this down to 5% or release it on a 90-day rolling basis instead of 180 — push hard on this in contract negotiations, especially if you can show a clean chargeback history from a previous operation.
Chargeback fees are brutal and often buried in the contract. A typical iGaming acquirer charges €20–50 per chargeback, regardless of whether you win the dispute. If you're processing high volume and your fraud controls are weak, chargebacks can cost more than the interchange. Then there are monthly minimums — some acquirers require a minimum monthly fee of €500–2,000 even if your volume doesn't generate that in fees. For a new operator ramping up volume, that's dead money in the early months.
| Fee Component | Who Charges It | Typical Range | Negotiable? |
|---|---|---|---|
| Interchange | Card network (via acquirer) | 1.5–2.5% (EU); 1.8–3.5% (US) | No — set by Visa/MC |
| Acquirer margin | Acquiring bank | 0.5–2.0% | Yes — key negotiation lever |
| Scheme fees | Visa / Mastercard | 0.1–0.3% | No |
| Gateway / PSP fee | Your PSP/gateway | 0.1–0.5% + €0.10–0.30 per txn | Partially |
| Rolling reserve | Acquiring bank | 5–10% held 90–180 days | Yes — negotiate hard |
| Chargeback fee | Acquiring bank | €20–50 per dispute | Partially |
| Monthly minimum | Acquiring bank or PSP | €500–2,000/month | Yes — waive or reduce |
How do chargebacks work in iGaming and how do you stay below the termination threshold?
A chargeback occurs when a player disputes a transaction with their issuing bank rather than contacting the casino. Visa and Mastercard set hard thresholds — typically 1% chargeback ratio for standard merchants, with lower thresholds for high-risk categories. Breach those thresholds and your acquirer will terminate your account. In iGaming, chargebacks are endemic; managing them is a core operational function, not an afterthought.
The most common chargeback triggers in iGaming are friendly fraud (player claims they didn't authorize a transaction after losing), stolen card use, and 'transaction not recognized' disputes where a player's bank statement shows a generic merchant name rather than the casino brand. That last one is surprisingly fixable — work with your acquirer to ensure your descriptor is recognizable. A player who doesn't recognize 'NTLMT LTD MALTA' on their statement will dispute it; one who sees 'CasinoXYZ.com' usually won't.
Your first line of defense is fraud screening at deposit. Tools like Kount, Sift, or the fraud modules built into platforms like SoftSwiss or EveryMatrix screen transactions in real time against device fingerprints, velocity rules, BIN-country mismatches and behavioral signals. A strong fraud layer keeps stolen card deposits out entirely — those always become chargebacks. Expect to pay €0.05–0.15 per transaction for a dedicated fraud tool, which is cheap compared to a €30 chargeback fee plus the risk of account termination.
For chargebacks that do arrive, build a representment process. Collect transaction logs, IP data, KYC documents, session recordings and any player communication that proves the transaction was authorized. Win rates on well-documented representments in iGaming run 40–60%. That's not great, but it keeps your net chargeback ratio manageable. Dedicated chargeback management services like Chargebacks911 or CB-ALERT can handle this at scale for operators who don't want to build the internal capability.
The hard number to watch is your chargeback ratio calculated as chargebacks received in a given month divided by transactions processed in the prior month. Visa's standard program triggers at 1%; their High-Risk program (which iGaming operators are typically enrolled in) has lower tolerance. Check your specific thresholds with your acquirer — some will issue a warning at 0.75% and terminate at 1.0%. If you hit 0.5% and it's trending up, that's an emergency, not a KPI to review quarterly.
How does licensing affect which payment processors will work with you?
Your gambling license is the single biggest factor in which PSPs and acquirers will onboard you, what rates they'll offer, and whether you can accept players from specific markets. An MGA or UKGC license opens doors that a Curaçao license simply doesn't — both in terms of tier-1 PSP access and issuer-level acceptance rates in regulated markets.
MGA (Malta Gaming Authority) and UKGC (UK Gambling Commission) licenses are the gold standard for payment relationships. PSPs like Worldpay, Adyen and Checkout.com will consider MGA-licensed operators. Acquiring banks in the EU are more willing to engage. More importantly, issuing banks in regulated markets are less likely to block transactions from MGA-licensed merchants — some issuers maintain whitelists of licensed gambling operators and route those transactions differently from unrecognized gambling merchants.
Curaçao eGaming (now operating under the revised 2023 framework with the Gaming Control Board of Curaçao) and Anjouan licenses are workhorses for offshore operators, but they come with payment trade-offs. Most tier-1 acquirers won't touch you. You're working with a smaller pool of offshore and high-risk specialist acquirers, your card approval rates in regulated EU markets will be lower due to issuer blocking, and some APM providers (including PayPal) won't onboard you at all. Crypto and e-wallets become disproportionately important in your payment mix as a result.
US state licenses (New Jersey DGE, Pennsylvania PGCB, Michigan MGCB, etc.) are the most restrictive in terms of payment requirements but also the most commercially valuable. US-licensed operators can work with regulated US payment processors and, critically, can accept ACH bank transfers — the dominant deposit method in the US market. ACH is cheap (flat fee, no percentage), has low fraud rates in a licensed environment, and avoids the card network restrictions entirely. Getting there requires the full state licensing process, which is a 12–24 month exercise and costs hundreds of thousands of dollars, but the payment stack you get on the other side is genuinely cleaner.
What is PCI DSS compliance and how does it apply to casino operators?
PCI DSS (Payment Card Industry Data Security Standard) is the security framework mandated by Visa and Mastercard for any entity that stores, processes or transmits cardholder data. Most iGaming operators achieve compliance by using a tokenizing gateway that keeps raw card data off their servers entirely — meaning the operator qualifies under SAQ A (the simplest self-assessment), not the full QSA audit.
The practical implication is straightforward: don't store raw card numbers on your platform. Use a gateway that tokenizes card data at the point of entry — the player's browser communicates directly with the gateway's hosted fields or JavaScript library, and your servers only ever see a token. Providers like Nuvei, Paysafe and Checkout.com all offer hosted payment pages or JavaScript SDKs that handle this. If you do this correctly, your PCI scope is minimal and annual compliance is a self-assessment questionnaire rather than an expensive on-site audit.
Where operators get into trouble is when they build custom checkout flows that inadvertently route card data through their own servers — even briefly. That puts you in PCI scope at a much higher level (SAQ D or full QSA audit), which can cost €20,000–100,000 annually and requires quarterly vulnerability scans and penetration testing. It's not worth it. Use the hosted fields. The UX compromise is minimal and the compliance savings are enormous.
PCI DSS v4.0 became the mandatory standard in March 2024. The new requirements add more granular controls around web-skimming attacks (targeting the JavaScript supply chain) and tighter requirements on multi-factor authentication for cardholder data environments. If you're building a new platform in 2026, build to v4.0 from day one — retrofitting is always more expensive than building right the first time.
How should an operator handle player withdrawals — and why do they fail so often?
Withdrawals fail primarily because of three things: KYC not completed before withdrawal is requested, mismatched payment methods (player deposited via card but wants to withdraw to a different account), and acquirer restrictions on refunds to cards. A clean withdrawal flow requires a clear KYC gate, a same-method-first policy, and at least one e-wallet or bank transfer option as a fallback.
Regulatory requirements in most jurisdictions mandate that withdrawals go back to the original deposit method first — this is an AML control, not just a platform policy. If a player deposited €200 via Visa, the first €200 of any withdrawal must go back to that Visa card. Only the net profit above the deposit can go to an alternative method. Many operators implement this incorrectly, either ignoring the rule (regulatory risk) or implementing it so rigidly that it creates terrible UX (operational risk). The right approach is to automate the same-method check in your cashier logic and surface it clearly to the player before they request the withdrawal.
Card withdrawals (technically 'original credit transactions' or OCTs) are not universally supported by all acquirers. Some iGaming acquirers only process deposits and require you to use a separate payout provider for withdrawals — Paysign, Hyperwallet, Nuvei Payouts, or similar. This adds another integration and another fee layer but is often unavoidable. Budget for it and factor it into your unit economics from the start.
Withdrawal speed is a competitive differentiator that operators consistently underestimate. Players in 2026 expect withdrawals within 24 hours; many crypto-native players expect minutes. Your KYC process is the bottleneck — if first-time withdrawal verification takes 48–72 hours because a compliance analyst is manually reviewing documents, you'll get negative reviews regardless of how good your game selection is. Invest in automated KYC (Jumio, Onfido, Sumsub are the standard providers) and set SLAs for manual review queues. The cost of a fast withdrawal process is far lower than the cost of player churn from slow ones.
How do AML and KYC requirements intersect with the payment stack?
AML (Anti-Money Laundering) and KYC (Know Your Customer) obligations are embedded directly into the payment flow — not bolted on afterward. Every licensed operator must verify player identity before processing significant transactions, screen against sanctions lists in real time, and monitor transaction patterns for suspicious activity. Your payment platform and your compliance stack have to be integrated, not siloed.
The practical integration points are: identity verification triggered at registration or before first withdrawal (depending on jurisdiction), sanctions screening on every transaction against OFAC, UN, EU and local lists, source of funds checks for high-value deposits, and ongoing transaction monitoring for structuring, velocity anomalies and politically exposed persons (PEPs). In the EU, the 6th Anti-Money Laundering Directive (6AMLD) sets the framework; in the UK, the POCA 2002 and the Gambling Commission's AML guidance are the operative documents.
For the payment stack specifically, this means your cashier needs to communicate with your KYC/AML system in real time. A player who hasn't completed enhanced due diligence shouldn't be able to deposit above a threshold (e.g., €2,000 cumulative in the MGA framework) without triggering a verification request. Your PSP or payment orchestration layer should be able to flag or hold transactions pending compliance clearance. Most modern iGaming platforms — SoftSwiss, EveryMatrix, Softgamings — have this wired in, but you need to configure the thresholds correctly for your license jurisdiction.
Crypto deposits add a specific AML wrinkle: blockchain analytics. If you're accepting crypto, you need a tool like Chainalysis, Elliptic or CipherTrace to screen incoming wallet addresses against known illicit sources. CoinsPaid and B2BinPay both offer some level of built-in screening, but for a licensed operator, a dedicated blockchain analytics subscription is the safer choice. Regulators are increasingly asking for evidence of crypto AML controls in licensing applications and audits — don't skip this.
What should an operator look for when evaluating an iGaming payment platform or PSP?
Evaluate PSPs on five dimensions: geographic coverage for your target markets, supported payment methods, card approval rates (ask for actual iGaming benchmarks, not generic rates), integration quality (API documentation, sandbox environment, support responsiveness), and contract terms including reserve requirements, chargeback fees and termination clauses. A PSP that scores well on four but has a punishing reserve policy will hurt your cash flow for years.
The first question to ask any PSP is: show me your actual approval rate data for iGaming merchants in [your target market] over the last 12 months. Any reputable PSP can produce this. If they hedge or give you marketing numbers, that's a red flag. Approval rates vary enormously between acquirers for the same card BINs — a 10-point difference in approval rate on a €500K/month volume is €50K in missed deposits. This is the most important commercial metric and it's rarely discussed upfront.
Integration quality matters more than operators expect. A PSP with a clean REST API, a functional sandbox, Postman collections and a responsive technical support team will save your dev team weeks of integration time. A PSP with a SOAP API, a sandbox that doesn't match production behavior, and a support team that responds in 72 hours will cost you months of launch delays and post-launch debugging. Ask for references from other operators who have integrated with them recently — not references the PSP hand-picks for you, but names you can reach out to independently.
Contract terms deserve a lawyer's eye, specifically: rolling reserve percentage and release schedule, minimum monthly fees, chargeback fee structure, termination notice periods (some contracts require 90–180 days notice, which locks you in even if the relationship sours), and data portability — can you export your transaction data and tokenized card vault if you switch providers? That last point is critical. If your card tokens are locked in a PSP's vault and they hold the tokenization keys, switching acquirers means asking all your existing players to re-enter their card details. That's a conversion disaster. Look for PSPs that support network tokenization (Visa Token Service, Mastercard Digital Enablement Service) which makes tokens portable across acquirers.
Comments
No comments yet, be the first.