
Gateway Selection
Payment gateways and processors
Compare online payment arrangements by checkout integration, card-acceptance responsibilities, fees and payout records.
Choose an online payment setup by checking the checkout experience, the card-acceptance arrangement and the records your store receives after a sale. A gateway passes an online payment request and its response. The word gateway alone does not tell you who arranges acceptance, when funds become available or how to trace a bank deposit.
Follow the payment beyond checkout
For card payments, the acquiring side connects the merchant to the relevant card network; the issuer responds on the cardholder’s side. Gateway, processing and acquiring functions may come from different organisations or be bundled by one provider.
At a high level, the customer submits a checkout request and the gateway encrypts and forwards the payment data to the processor. The processor routes it through the relevant card network to the issuer, then carries the response back; the acquiring side supplies the merchant’s card-acceptance arrangement.
The RBA describes acquirers as providing card acceptance through network membership, processing transactions for merchants and supporting online acceptance through a payment gateway. Airwallex is an example of a provider offering gateway and processing functions on one platform, so confirm the actual contracting and payout roles for the offer.
An approved attempt, a completed checkout and a bank deposit are different events. Depending on the arrangement, the store may also need to track capture, refunds, disputes and pending payments. Ask each candidate which status and reference it provides at each stage.
Payment Flow from Checkout to Bank Deposit
- Customer submits checkout requestPayment data encrypted and sent via gateway
- Processor routes to card networkIssuer approves or declines the transaction
- Response returned to merchantGateway delivers result to store system
- Funds held in provider accountStatus: 'paid' means funds are available
- Payout to business bank accountSettlement timing varies; linked to payout record
Check record fields and availability
Ask to inspect the provider’s actual transaction record or API response, including which field can carry your order or cart reference and how the provider identifies the payment. A Stripe Checkout Session, for example, has a unique ID, a client reference field that can hold a cart or customer ID, a currency field and a payment status.
Its documented statuses are paid, unpaid and no payment required. Stripe says paid means funds are available in the account, while unpaid means they are not yet available.
The Stripe Session object also includes line items and metadata, and can include a PaymentIntent ID for a payment-mode session. Check how these provider identifiers can be retrieved alongside your own order reference.
A paid status indicates funds are available in the provider account; it does not by itself confirm that a bank deposit has arrived. Ask how the separate payout record identifies the deposit and connects it to transaction records.
If your accounting software is part of the operating arrangement, confirm whether transaction data is fed into it and what your team must still handle. Xero, for example, says Stripe feeds transactions to Xero to support reconciliation; check that the specific connection offered suits your own systems and account.
Define the arrangement you need
Start with your store platform and any existing acquiring contract. Can you use a bundled service, or must a gateway connect to a particular acquirer? Identify who contracts with the merchant for card acceptance, provides payment support and sends payouts. Confirm these responsibilities for the account being offered, rather than assuming every product in a provider’s catalogue is included.
Names to include in an Australian shortlist include Stripe, Square, Shopify Payments, PayPal, Adyen, Airwallex, Pin Payments and Afterpay. These appear among options for small businesses, but do not assume each name supplies the same mix of gateway, processing, acquiring or payment services; verify the roles and fit of the specific offer.
Then choose the customer-facing integration. A hosted page, an embedded provider form and configurable components differ in how the buyer enters details and how much interface work your team must maintain. Check whether the proposed option supports your platform’s requirements, such as redirects and changes to the payable amount, and what payment-state handling your team must maintain.
Test the customer-facing checkout
A checkout that is secure but cumbersome can still cost completed orders. Stripe’s overview cites a survey of online shoppers in which 18% of abandoned carts were attributed to a checkout process that felt too long or complicated. Use the demonstration to judge the buyer’s experience as well as the technical handoff.
Check where payment details are entered and whether the proposed page or embedded form feels clear and straightforward. Ask to see the actual proposed page or embedded form, not just a description of its integration type.
Pre-Contract Due Diligence Checklist for Payment Setup
- Test actual checkout interfaceVerify clarity, flow and security of payment entry
- Confirm PCI compliance statusCheck if iframe or hosted page affects SAQ A eligibility
- Validate order-reference mappingEnsure cart or customer ID is carried through session
- Review payout linkageConfirm how bank deposit references connect to transactions
- Check accounting software syncVerify integration with Xero, MYOB or other platforms
Compare candidates with the same questions
| Requirement | Ask the candidate to show |
|---|---|
| Acceptance | Methods and acquiring arrangement available to your account. |
| Order handoff | How order and payment references map, including failed or pending outcomes. |
| Operations | Who can find payments, capture where supported, refund and resolve exceptions. |
| Payouts | How transactions, fees and adjustments link to payouts and bank references. |
| Ownership | Who handles integration, incidents, disputes, reports and account changes. |
For a like-for-like shortlist, assess e-commerce platform integration, API quality, accounting connections, multi-currency support, POS compatibility, PCI DSS security, fraud protection, local support and sandbox availability. Check these against your store’s requirements rather than treating any feature list as a substitute for testing the proposed arrangement.
Request the full fee schedule for your expected transaction and currency mix. Ask which charges appear per transaction, in a payout or on a separate invoice. Use the provider’s current offer for the contract decision.
Ask where card details are collected and who supplies each payment-page element. A hosted page or provider iframe can affect the merchant’s card-data exposure, but an embedded label does not establish a PCI assessment category.
PCI Security Standards Council guidance makes SAQ A eligibility for an iframe conditional on where the relevant payment-page elements originate and on the other eligibility criteria. Assess the actual implementation under the current requirements and acquiring arrangement.
Give shortlisted candidates the same sample order and questions. Request examples of the resulting transaction and payout records, including a pending outcome where the supported method permits one. Note what was demonstrated in a permitted test environment and what still needs contract or live-account confirmation.
Settlement speed is a practical selection factor. Ask each provider for the expected payout timing for the arrangement and how its payout record connects to transactions; confirm the applicable terms for your account.
Key Payment Arrangement Factors for Australian Merchants
- Acceptance
- Methods and acquiring arrangement available to your account
- Order handoff
- How order and payment references map, including failed or pending outcomes
- Operations
- Who can find payments, capture where supported, refund and resolve exceptions
- Payouts
- How transactions, fees and adjustments link to payouts and bank references
- Ownership
- Who handles integration, incidents, disputes, reports and account changes
Understand the price categories
A broad price indication in Australian small-business coverage is roughly 1.5% to 2.6% plus a fixed amount per transaction for leading options. Treat that as a guide, not a quote for every provider or transaction; compare the current fee schedule for your expected mix.
The RBA describes blended plans as combining some transaction categories under a price while retaining different prices for different types. For example, a plan could apply one rate to debit transactions across eftpos, Mastercard and Visa, and another rate to credit transactions across Mastercard and Visa. Ask the provider which categories your quoted rates cover and how each will appear in its charges.
If you are considering passing card costs on to customers, check the applicable surcharge rules as part of the commercial decision. Section 55B of the Competition and Consumer Act 2010 prohibits an excessive card payment surcharge: the surcharge is excessive if it is higher than the merchant’s cost of accepting the relevant designated-network card. The ACCC can investigate and take enforcement action over alleged excessive surcharging.
In this guide
- Gateway, processor and acquirer: distinguishing the rolesDistinguish gateway, processor and acquirer roles in an online card payment, even when one provider bundles the services.
- Comparing gateway integration optionsCompare hosted pages, embedded forms and configurable components using documented limits, merchant work and order handoff needs.
- Checking payment settlement reporting during vendor selectionAsk payment vendors to demonstrate transaction, fee and payout records, including report access and limits that affect reconciliation.


