Back to Glossary

Entry · KPIs

Card Authorisation Rate

Card authorisation rate is the share of card payment attempts submitted for issuer or network authorisation that are approved. It is commonly calculated as approved attempts divided by eligible submitted attempts. Its denominator differs from a wider checkout or payment-success rate that includes failures before authorisation.

From the Money Master HQ dictionary, founded by Shihan Sheriff (FCMA, VP of Finance at Nomod, CFO at Esanjo Ventures). How these definitions are written.

What it means

A customer may want to buy but the card payment can fail, and not all failures reach the issuer. Card authorisation rate focuses on attempts submitted into the authorisation process and the approvals returned.

For example, 9,300 approvals from 10,000 eligible network attempts give 93%, and the numerator and denominator must cover the same period and payment population. Stripe distinguishes network authorisation rate from payment success rate, and its authorisation denominator excludes attempts blocked before reaching the network, such as some authentication failures or processor blocks.

This matters because a merchant can improve issuer approvals while losing more customers before submission, so review both metrics before claiming that customers can pay more easily. Authentication and authorisation are also separate steps, as a customer can fail a 3-D Secure challenge before the issuer receives an authorisation request, and other payment methods and regions may have different steps.

Issuer declines can reflect insufficient funds, expired credentials, suspected fraud or restrictions on a transaction, and some response codes are generic. Not every decline is a lost valid sale, because some attempts are fraudulent or should be rejected, so the goal is to reduce false declines while keeping risk controls appropriate.

Segment the rate by card country, issuer, product, amount, transaction type and time, since a blended average can hide one route with unusually low approvals, and compare enough volume to avoid chasing random noise. Recurring billing needs special attention, because stored card details can become outdated and a renewal may occur without the customer present, although card updater services or network tokens may help in some cases.

Retries should follow response advice and programme rules: a temporary insufficient-funds decline might support a later retry with customer permission, whereas a lost or stolen card response does not, and repeated blind attempts can create fees or harm approval performance. Stripe's analytics can show a raw rate and a deduplicated rate that groups attempts for one purchase, since a customer fixing a mistyped security code may create multiple raw attempts but one eventual successful purchase.

Authorisation is not the same as settlement, since an approved transaction may later fail capture, be refunded or disputed, and payment gateways and acquirers may report slightly different definitions, so check whether both include retries, pre-network blocks and test transactions alike before comparing two processors. Use a funnel from checkout start to successful paid order that counts attempts that never reached authorisation, network declines and post-approval failures.

A merchant might correct address or card data collection and see fewer avoidable declines, or adjust fraud settings, but lowering checks without evidence can raise chargebacks, so test changes with risk and approval metrics together. Local routing can affect results because cross-border transactions may have different issuer responses, so investigate actual issuer and acquirer data rather than assuming every foreign card fails for the same reason.

A good rate depends on industry, geography, amount, customer mix and fraud profile, and a two-point increase in approvals does not automatically equal a two-point increase in revenue, since ticket sizes, retries and fraud matter, so estimate net successful orders and contribution instead. For a subscription business, track involuntary churn separately, because a failed renewal might later recover through a valid retry or updated card, and the first failed attempt and the recovered subscription should not both be counted as permanent lost revenue, while the rate itself remains a diagnostic for one stage of payment acceptance whose value comes from a clear denominator, sensible segmentation and fixes that do not weaken protection against invalid transactions.

In practice

Real-world examples.

1

Example

A merchant submits 10,000 eligible card attempts and receives 9,300 approvals, a 93% authorisation rate by attempt.

2

Example

A subscription firm separates initially declined renewals from those later recovered with updated card details.

3

Example

An online seller checks whether one issuer or region is driving a decline in network approvals.

Formula

Calculation

Card authorisation rate = Approved eligible network attempts / Eligible attempts submitted for authorisation x 100 Worked example. A fictional merchant submits 10,000 eligible attempts and receives 9,300 approvals. - Authorisation rate = 9,300 / 10,000 x 100 = 93%. - Suppose 800 of the 10,000 attempts were retries for 500 purchases, so the deduplicated count is 10,000 - 800 + 500 = 9,700 purchases, and 9,000 of them were eventually approved: deduplicated rate = 9,000 / 9,700 = 92.8%. - At an average order of $50, each extra percentage point of approvals on 10,000 attempts is 100 more approvals, worth up to 100 x $50 = $5,000 of sales before fraud, returns and margin. - Define how retries and deduplication are handled before comparing periods.

Case study

Seen in the real world.

This entirely fictional case follows Hazel Fitness, an invented subscription service. It found a lower approval rate for stored-card renewals than for new purchases and reviewed issuer response patterns. The team tested card updates and permitted retries while tracking fraud and eventual paid renewals. No real uplift or churn reduction is claimed.

Watch out

Common mistakes.

  • Using all checkout visits as the authorisation denominator.
  • Retrying every issuer decline regardless of response advice.
  • Treating approval as a completed, settled and non-fraudulent sale.

Questions

People also ask.

How does it differ from payment success rate?

Authorisation focuses on requests reaching the network; wider payment success also captures some failures earlier in the journey.

Does a high rate always mean good controls?

No. Weak fraud controls may approve invalid payments, so assess disputes and losses too.

Can retries improve it?

Appropriate retries can recover some valid payments, but follow issuer advice, customer permission and network rules.

Was this explanation helpful?

From the founder's library

Accounting Fundamentals: A Non-Finance Manager's Guide to Finance and Accounting, by Shihan Sheriff

Take it further with the book.

Build your financial confidence beyond this definition. Shihan's full-length guide, Accounting Fundamentals, takes the same plain-English approach and turns it into a complete, practical playbook for non-finance managers, business owners and students - with chapter-end quiz answers and presentation slides included.

US$2.24US$2.99

25% off with code MMHQ25, applied at checkout. Priced in USD - checkout may show the equivalent in your local currency.

View the book and save 25%
Last updated · October 8, 2026
Browse all terms →

Disclaimer

The information provided in this finance dictionary is for educational and informational purposes only. It should not be construed as financial, investment, legal, or tax advice. Always consult with a qualified professional before making any financial decisions. Money Master HQ makes no representations or warranties about the accuracy, completeness, or suitability of this information. Use of this content is at your own risk.