Payment Gateways for High-Risk Merchants: Choosing the Right Gateway and Acquirer
Published - 29 June 2017
Revised - 01 September 2026


Libby James is the founder and Managing Director of Merchant Advice Service. Since 2016, she has worked directly with businesses and payment providers across merchant accounts, card processing, payment gateways and complex provider requirements.
Libby specialises in high-risk, declined and harder-to-place merchants, as well as businesses requiring specialist payment methods, integrations or international support. She writes and reviews Merchant Advice Service content, drawing on practical experience gained from real merchant enquiries and provider relationships.
A high-risk payment gateway does not make a high-risk business acceptable to a payment provider.
That is the most important distinction to understand when searching for high-risk payment processing.
The payment gateway is the technology that helps move payment information between the customer, merchant and payment infrastructure. The decision about whether a business can actually process cards sits with the relevant payment provider, processor and/or acquiring bank through underwriting.
For a business with more complex or higher-risk requirements, the real question is therefore not:
“Which high-risk payment gateway should we use?”
It is:
“Which acquiring provider will support our business model, and which gateway or payment technology gives us the functionality we need?”
Getting those decisions in the wrong order can create unnecessary applications, integration work and provider changes.
This guide explains how high-risk payment gateways work, how they differ from merchant accounts and acquiring, which technical features matter, and how UK and European businesses can assess gateway and provider fit together.
If your main problem is securing provider approval rather than choosing payment technology, start with our High-Risk Merchant Account Applications guide. If you want to compare specialist provider types, see our High-Risk Payment Providers guide.
A payment gateway is technology used to securely transmit payment information and facilitate communication between a merchant's checkout and the wider payment-processing infrastructure.
The term high-risk payment gateway is commonly used to describe a gateway or payment platform capable of supporting businesses with specialist acquiring, fraud, transaction, integration or geographic requirements.
But there is not necessarily a separate technical category of gateway called “high risk”.
The more important issue is whether the gateway can connect the merchant to a payment provider or acquirer that has appropriate underwriting appetite.
A gateway could be technically excellent and still be useless to the merchant if its connected acquiring partners will not support the business.
For higher-risk ecommerce businesses, provider acceptance is only one part of the decision. Our Ecommerce Payment Providers UK guide explains how to compare technical integration, total cost, settlement, international capability and wider PSP fit.
MAS View
A high-risk gateway is only useful when the acquiring route behind it works for the merchant.
These terms are often used interchangeably, but they perform different roles.
| Payment component | Broad role |
|---|---|
| Payment gateway | Provides technology that securely captures and transmits payment information. |
| Payment service provider (PSP) | May combine gateway, processing, acquiring, payment methods, reporting and other payment services within one proposition. |
| Acquirer / acquiring bank | Provides the acquiring relationship enabling the merchant to accept card transactions and assumes relevant acquiring risk. |
| Merchant account / MID | The merchant-processing arrangement and identifier through which eligible card activity is processed and settled. |
In some modern payment propositions these layers are bundled together.
In others, the gateway and acquiring relationship can be separate.
That separation can be particularly useful for merchants with specialist underwriting requirements because the business may want to retain one technical gateway while changing or adding acquiring relationships.
For more on that architecture, see our Acquirer-Agnostic Payment Gateways guide.
High-risk classification is not simply a list of industries.
Providers may consider:
Two businesses operating in the same broad sector may therefore receive very different provider terms or underwriting outcomes.
Our High-Risk vs Low-Risk Merchant Accounts guide explains this distinction in more detail.
A common mistake is to choose the payment technology first.
The merchant finds a gateway with a good API, smart checkout, reporting, subscriptions, fraud tools and competitive gateway pricing.
Only afterwards does it discover that the available acquiring route does not support the business.
For a higher-risk merchant, we would normally reverse that order.
Understand why the merchant may require specialist acquiring.
Establish which providers are currently prepared to consider that specific business model.
Check whether the relevant acquiring route can work with the merchant's website, platform, API, subscriptions and wider payment requirements.
Assess fraud controls, authentication, tokenisation, reporting, chargeback tools and settlement.
Only then compare processing rates, gateway fees, reserves, settlement terms, chargeback fees and contract conditions.
For higher-risk merchants, the provider shortlist should normally get smaller before the price comparison begins.
Not every high-risk merchant needs every payment feature.
Depending on the business, relevant gateway capabilities can include:
The correct list should come from the merchant's actual payment journey, not from a generic gateway feature list.
Future delivery is not determined by MCC alone. Two merchants in the same sector can create very different acquiring exposure depending on when customers pay and when the goods or services are supplied. See our Future-Delivery Risk in Payments guide for worked examples and the MAS future-delivery exposure framework.
Hosted Checkout, Embedded Components or Direct API?
The payment page or substantial elements of the payment experience are provided by the payment provider. This can reduce development complexity and may reduce the amount of card data handled directly by the merchant.
Provider-controlled payment elements are embedded within the merchant's site or application, giving the customer a more integrated experience.
The merchant integrates more deeply with the provider's payment APIs and may control more of the payment journey and business logic.
This can be useful for complex merchants, but it also creates greater technical dependency and requires careful planning around security, tokens, webhooks and future provider migration.
For a deeper technical guide, see our Payment API Integration guide.
Using a third-party gateway does not mean a merchant can simply ignore PCI DSS.
The current PCI Data Security Standard is PCI DSS v4.0.1.
The PCI Security Standards Council has also published ecommerce guidance around payment-page scripts and e-skimming. Its current guidance makes clear that ecommerce merchants can retain PCI DSS responsibilities even when payment processing is outsourced.
See the PCI Security Standards Council's current PCI DSS documents.
PCI SSC's current SAQ A guidance also requires merchants to consider whether ecommerce pages are susceptible to script attacks, depending on the implementation.
Read PCI SSC's current SAQ A ecommerce guidance.
PCI scope depends on the merchant's specific architecture, so specialist compliance advice may be required where the position is unclear.
A strong fraud stack can improve payment quality and help detect or control activity such as stolen-card use, card testing, unusual transaction velocity, high-risk geographies, device anomalies and repeat fraud patterns.
But fraud controls do not remove other forms of merchant risk.
A business can have very little payment fraud and still be considered higher risk because of future delivery, refund exposure, high transaction values, regulation, subscription disputes, financial strength, sector-specific scheme rules or the acquirer's own portfolio appetite.
This is why “our fraud rate is low” does not automatically mean mainstream acquiring will be available.
For UK ecommerce, Strong Customer Authentication requirements form part of the wider payment and fraud-control environment.
The Financial Conduct Authority states that SCA rules apply when a payer initiates an electronic payment transaction, subject to the relevant framework and exemptions.
Read the FCA's Strong Customer Authentication guidance.
A gateway review should therefore consider:
For higher-risk merchants, authentication, fraud control and conversion should be designed together.
Visa's Acquirer Monitoring Program (VAMP) consolidates fraud and dispute monitoring for card-not-present Visa transactions.
Visa's published framework calculates a VAMP ratio using counts of relevant fraud and disputes relative to settled transactions, subject to the program rules.
Visa's current fact sheet states that from 1 April 2026 the Excessive Merchant VAMP ratio threshold for AP, Canada, EU and US regions is reduced to 150 basis points, with the published minimum monthly count criteria also applying.
Read Visa's current VAMP fact sheet.
Visa also monitors enumeration activity, including high-volume card-testing behaviour.
This matters when evaluating gateway technology because the merchant may need visibility and controls around fraud, disputes, enumeration, transaction velocity, authentication, decline behaviour, refunds and transaction-level reporting.
The gateway cannot guarantee that a merchant stays below scheme-monitoring thresholds, but poor visibility or weak controls can make managing the problem more difficult.
For additional context, see our VAMP guidance for high-risk merchants.
Many gateways promote chargeback or dispute-management features.
Those can be useful, but merchants should look beyond the existence of a dashboard.
Ask:
The gateway is one source of data, but reducing disputes can also require changes to customer communication, billing descriptors, refund processes, delivery, subscription cancellation, fraud controls and customer service.
A rolling reserve or other risk hold is generally part of the acquiring/provider commercial and risk arrangement rather than a technical feature of the gateway itself.
The gateway might provide the technology used for transactions, while the acquiring provider determines whether it requires a rolling reserve, delayed settlement, fixed reserve, volume restrictions, transaction-value limits or other risk controls.
High-risk merchants should therefore compare gateway technology and acquiring terms separately.
The cheapest quoted percentage can hide a materially different overall payment structure.
Compare:
A provider offering a slightly higher processing rate but materially better settlement or reserve terms can sometimes create a better commercial outcome.
For larger merchants, see our High-Turnover Payment Fee Audit guide.
High-risk merchants should also compare the complete payment cost rather than headline processing rates alone. Gateway charges, acquiring margin, reserves, fraud tools, chargebacks, cross-border fees and other commercial terms can materially affect the final cost.
For the wider fee structure, read our Payment Gateway Fees UK 2026 guide.
Recurring Payments Need Specialist Attention
Higher-risk subscription merchants should assess both underwriting and technical requirements.
The gateway may need to support initial customer authentication, tokenisation, card-on-file payments, merchant-initiated transactions where permitted, failed-payment retries, card updates, subscription changes, cancellations, refunds and payment credentials that remain usable if the provider changes.
The provider also needs to be comfortable with the merchant's subscription model, terms, trial structure, cancellation journey and dispute exposure.
For the wider payment requirements, see our Subscription Payment Processing guide.
A higher-risk merchant may need to change PSP because provider appetite changes, the merchant's risk profile changes, the business grows, a provider terminates a facility, international expansion changes the requirement or commercial terms become unsuitable.
If the business has stored customer credentials, switching can become significantly more complicated.
Before integrating a gateway, ask:
See our guide to moving stored cards, tokens and recurring payments between payment providers.
Potentially.
An acquirer-agnostic gateway can connect to more than one acquiring provider instead of tying the merchant to a single acquiring relationship.
This can be useful where provider risk appetite may change, different countries require different acquirers, the merchant has several MIDs, the business has specialist acquiring requirements, provider portability is important or the business genuinely needs a multi-acquirer architecture.
But an acquirer-agnostic gateway does not mean the merchant automatically gains access to several merchant accounts.
Each acquiring provider still applies its own underwriting.
Our Acquirer-Agnostic Payment Gateways guide explores this in detail.
Not automatically.
The old idea that every higher-risk business should “spread risk” across several merchant accounts is too simplistic.
There can be legitimate reasons for multiple merchant accounts or acquiring relationships, including different legal entities, countries, brands, product lines, MCC requirements, payment channels, resilience or regional acquiring.
But multiple providers also introduce more underwriting, contracts, reconciliation, reporting, settlement cycles, token complexity, refund complexity, technical work and operational management.
Using several payment providers should solve a defined business problem, not be used to obscure the merchant's real risk profile or circumvent provider terms.
Platform compatibility adds another layer to provider selection.
A specialist acquirer may be willing to support the merchant but still lack the integration required for the ecommerce platform.
Conversely, a gateway may integrate perfectly with Shopify, WooCommerce or another platform but have no appropriate acquiring route for the merchant's sector.
The merchant therefore needs:
platform compatibility + gateway compatibility + acquiring appetite.
For Shopify specifically, see our High-Risk Merchant Accounts for Shopify guide.
A gateway advertising support for many currencies does not automatically make it suitable for an international high-risk merchant.
International businesses should also consider customer countries, card-issuer countries, acquiring locations, legal entities, settlement currencies, FX, cross-border pricing, local payment methods, regional regulation, provider sector appetite, chargeback exposure and international fraud controls.
For broader international requirements, see our International Merchant Accounts & Payments guide.
For the specific relationship between UK/EU expansion and acquiring location, see our UK and European Local Acquiring guide.
A gateway migration and an acquiring termination are not necessarily the same thing.
If the gateway can connect to another appropriate acquirer, the technical payment layer may potentially be retained.
In other structures, gateway and acquiring are bundled together, meaning the business may need to replace both.
Before moving, establish why the facility was terminated, whether the gateway remains usable, whether stored credentials can move, how historic refunds and chargebacks will be handled, whether funds are being held, what happens to subscriptions and which providers have appropriate appetite going forward.
See our guide to terminated merchant facilities for more detail.
Is there an acquiring provider willing to support the business model, sector, MCC, geography and transaction profile?
Can the gateway support the merchant's ecommerce platform, API, mobile app, call centre, subscriptions or other payment channels?
Does the payment setup provide appropriate authentication, fraud, velocity, card-testing and dispute controls?
Can the business manage refunds, reporting, reconciliation, customer service and chargebacks effectively?
What is the complete cost once processing, gateway charges, settlement, reserves, FX and contract terms are included?
What happens if the merchant grows, enters another country, adds subscriptions or needs to change acquirer later?
The best high-risk payment gateway is not the one with the longest feature list. It is the gateway that sits inside a sustainable acquiring structure for the merchant's actual business.
| Area | Information |
|---|---|
| Business | Sector, products/services, legal entity and trading history |
| Processing | Current and expected monthly volume |
| Transactions | Average and maximum ticket size |
| Customers | UK/EU/international customer split |
| Fulfilment | Time between payment and delivery |
| Risk | Refund, fraud and chargeback history |
| Current provider | PSP, acquirer, gateway and reason for review |
| Technology | Website platform, API, subscriptions and integrations |
| Payments | Cards, wallets, recurring, MOTO and other methods |
| International | Currencies, countries and settlement requirements |
| Commercial | Rates, reserve, settlement and contract terms |
The more accurately this information is presented, the easier it is to distinguish realistic provider routes from technically attractive but commercially irrelevant options.
Merchant Advice Service does not start with a generic list of “high-risk gateways”.
The process is:
understand the merchant → identify the acquiring requirement → understand the technical integration → identify realistic provider routes → compare functionality and commercial terms.
This is particularly important for businesses that have already been declined, been terminated by a previous provider, have complex integrations, high monthly processing volumes, large transaction values, international customers, subscriptions, future-delivery risk or regulated/specialist business models.
MAS does not make underwriting decisions. Final approval, pricing, reserves and settlement terms remain with the relevant payment provider.
For more on the process, see How Merchant Advice Service Works and How MAS Researches and Compares Payment Providers.
Visa's current published information covering the VAMP framework, fraud, disputes, enumeration and merchant/acquirer monitoring.
Visa Acquirer Monitoring Program fact sheet
Visa's current background on the evolution of VAMP and its approach to fraud and dispute risk across the payment ecosystem.
The PCI SSC document library contains the current PCI DSS v4.0.1 standard and related ecommerce security guidance.
Current PCI SSC guidance explaining ecommerce payment-page script considerations for merchants using third-party payment providers.
FCA guidance on the UK's Strong Customer Authentication requirements for electronic payments.
FCA Strong Customer Authentication guidance
Merchant Advice Service is an independent payments information, comparison and provider-matching service.
MAS may receive commission or a referral fee from some payment providers where a business chooses to proceed following an introduction. This does not determine the factual information, provider-selection principles or technical considerations included in this guide.
The term “high risk” is used broadly across the payment industry. Merchant classification, sector appetite, underwriting criteria, pricing, reserves, settlement terms and gateway availability vary between providers and can change.
No payment gateway can guarantee merchant-account approval. Final underwriting and acceptance remain with the relevant payment provider or acquiring institution.
Payment gateways, fraud controls, 3D Secure and dispute-management tools cannot guarantee that fraud, chargebacks or scheme-monitoring ratios will remain below particular thresholds.
PCI DSS responsibilities depend on the merchant's payment architecture and circumstances. Businesses should establish their own compliance requirements and obtain specialist advice where appropriate.
Provider, scheme and regulatory requirements can change. Businesses should verify current terms before selecting or changing payment infrastructure.
Merchant Advice Service does not make provider underwriting decisions or guarantee acceptance, pricing, reserve levels, settlement terms or continued processing.
Scheme, regulatory and security information last checked: 26 August 2026
Article last reviewed: August 2026
This guide provides general payment information and should not be treated as legal, regulatory, compliance, security, financial or technical advice.
Written or reviewed by Libby James, founder of Merchant Advice Service and specialist in merchant payments and complex provider requirements.