Risk & Compliance Holds
The issuer or network is enforcing a risk-management, regulatory, or compliance rule that blocks the transaction.
3-D Secure / Strong Customer Authentication Failed
This decline happens when 3-D Secure or Strong Customer Authentication (SCA) fails or isn't completed during checkout — increasingly required under regulations like PSD2 in Europe. There's no distinct network code for this scenario; the issuer typically declines the underlying authorization with a generic response such as "05 Do Not Honor."
Risk & Compliance HoldsMerchant Category Restricted by Issuer
This decline occurs when a cardholder's issuer or card program blocks entire categories of merchants — such as gambling, cryptocurrency, adult content, or cannabis — at the account level. It shares the same underlying network code as a general "transaction not permitted to cardholder" decline, but merchants in these verticals encounter it often enough that it deserves its own explanation.
Risk & Compliance HoldsRestricted Card
A Restricted Card decline means the issuer has placed a specific limitation on this card — such as a geographic usage restriction, sanctions screening flag, or card-program limitation — unrelated to available funds or general fraud suspicion. Some variants instruct the merchant to retain the physical card.
Risk & Compliance HoldsSecurity Violation
A Security Violation decline means the issuer detected a security-related problem with the transaction, such as a failed cryptographic check or a violation of a required security protocol, rather than a general suspicion of fraud. It typically points to a technical integrity issue in how the transaction was submitted.
Risk & Compliance HoldsTransaction Not Permitted to Cardholder
This decline means the issuer does not allow this specific cardholder's card to be used for the type of transaction attempted — for example, a debit card blocked from card-not-present purchases, or a card restricted from certain merchant categories such as gambling. The restriction is set by the issuer on the cardholder's account, not by the merchant.
Risk & Compliance HoldsTransaction Not Permitted to Terminal/Merchant
This decline means the merchant's terminal or merchant category is not permitted to accept this type of transaction under network or issuer rules. Unlike a cardholder-side restriction, the limitation sits on the merchant or terminal configuration itself, such as a terminal not provisioned for a certain card product or transaction type.
Risk & Compliance HoldsTransaction Violates Law
This decline means the issuer or card network determined that completing the transaction would violate a law or regulation, such as sanctions or OFAC screening, or restrictions on goods and services in the cardholder's or merchant's jurisdiction. It is a compliance-driven block rather than a fraud or funds-related decline.