Payment Initiation Service Provider (PISP)
Abbreviation: PISP
Pronunciation: PAY-munt ih-nish-ee-AY-shun SUR-vuhs pruh-VY-der (PEE-EYE-ESS-PEE)
Also known as: Payment Initiation Service Provider, PISP
Definition
A Payment Initiation Service Provider is an authorized provider that, with the payer’s explicit consent, initiates a payment order from an account held at another payment service provider. Payment Initiation Service Provider (PISP) decisions should preserve authoritative evidence, timestamps, accountable ownership, exceptions, and the final security, compliance, or financial outcome. A PISP does not automatically hold the payer’s funds or control the servicing account. The workflow must preserve consent, authentication, payment order details, account-servicing provider responses, status evidence, liability boundaries, and revocation or exception handling.
Overview
A Payment Initiation Service Provider is an authorized provider that, with the payer’s explicit consent, initiates a payment order from an account held at another payment service provider. A PISP does not automatically hold the payer’s funds or control the servicing account. The workflow must preserve consent, authentication, payment order details, account-servicing provider responses, status evidence, liability boundaries, and revocation or exception handling. EU requirements continue to evolve through the proposed PSD3 and Payment Services Regulation.
A PISP submits a payment order through the account-servicing provider’s interface after obtaining the payer’s consent and authentication. It should not modify the amount, payee, or account after authorization, and it needs a durable link between the customer session, consent evidence, submitted instruction, bank response, and later payment status.
Timeouts and redirects create ambiguity because the bank may accept a payment after the PISP loses the response. Status recovery, idempotency, duplicate prevention, complaints, and liability handling should therefore be designed around the original payment reference rather than a new initiation attempt.
The implementation should not collapse it into Account Information Service Provider (AISP) and Payment Service Provider (PSP).
The most consequential risks are unclear roles, hidden subcontractors, weak sponsorship, custody ambiguity, concentration, inconsistent data rights, inadequate liquidity, processor dependency, customer-support gaps, and unresolved responsibility during incidents.
Controls should enforce uniqueness within the namespace, keep mappings immutable, separate test and production identifiers, avoid exposing secrets, protect credentials, and authenticate callbacks, with the control owner and exception path documented whenever Payment Service Provider (PSP) is involved.
Payment Initiation Service Provider (PISP) is a regulated provider role that initiates account payments with user consent under applicable open-banking rules.
Key Takeaway
A PISP initiates a payment from an account held elsewhere under the user’s authorization; consent, authentication, instruction integrity, status evidence, liability boundaries, and revocation rules must remain explicit.
Sources
- Directive (EU) 2015/2366 on Payment Services — European Union (2026-08-01)
- European Parliament Legislative Train: PSD3 Status — European Parliament (2026-08-01)