Choosing the wrong payment gateway costs UK merchants real money: declined transactions, inflated fees, failed compliance audits, and customers who abandon checkout rather than retry. The right gateway, by contrast, raises authorisation rates, reduces effective per-transaction cost, satisfies PCI DSS and PSD2/SCA obligations, and opens access to local payment methods that card networks cannot match on price. This guide covers every dimension of that decision:
- Conversion and approval rates — how routing, network tokens and account updaters change the percentage of transactions that actually complete.
- Effective fees and settlement speed — why headline rates hide the true cost, and how cashflow timing affects working capital.
- Security and compliance — PCI DSS scope, PSD2/SCA readiness, and GDPR obligations for payment data.
- Integration and migration effort — API depth, plugin options, token export policies, and realistic engineering timelines.
- Fraud protection and chargeback management — included versus bolt-on screening, and the conversion cost of aggressive decline rules.
- UK-specific considerations — local acquiring, routing, and how to question vendors about approval-rate uplift for UK transactions.
Key takeaways
Choosing the right payment gateway for a UK business requires modelling the full cost, validating authorisation-rate performance with real data, and confirming token portability before signing any contract.
| Point | Details |
|---|---|
| Authorisation rates vary materially | Industry analysis shows a 4–8 percentage-point gap between well-tuned and poorly-tuned gateway setups. |
| Local methods reduce cost significantly | Adyen data shows local payment methods average 49% lower cost than credit and debit cards. |
| PCI scope depends on integration type | Hosted gateways qualify for SAQ A; direct API integrations may require SAQ D with 200-plus controls. |
| Token export is a migration prerequisite | Token migrations typically take 10–14 days when vendors cooperate; confirm export policy before signing. |
| MedwayWebDesign integrates gateway and checkout | The team supports UK merchants with gateway integration, checkout optimisation, and migration planning. |
This article is general information, not a substitute for advice from a qualified financial advisor. Consult a qualified financial professional about your own circumstances before acting on anything here.
Table of Contents
- What a payment gateway is, and the main types merchants choose
- How gateway selection changes conversion, approval rates and customer experience
- Security, compliance and legal basics UK merchants must check
- Fees, settlement speed and the true total cost of ownership
- Integration options, developer effort and platform compatibility
- Fraud protection, chargeback handling and operational impacts
- How to evaluate and choose the right gateway for your business
- Why local acquiring and routing matter specifically for UK merchants
- Providers commonly used by UK merchants
- Short action steps for small business owners
- Gateway choice is a checkout design decision, not just a technical one
- MedwayWebDesign supports merchants through gateway integration and checkout optimisation
- Sources
What a payment gateway is, and the main types merchants choose
A payment gateway is the technology layer that encrypts and transmits card and payment data from a merchant’s checkout to the acquiring bank, receives the authorisation response, and returns the result to the customer. It sits between the customer’s browser or app and the financial network that ultimately approves or declines the transaction. Understanding gateway types and their practical trade-offs is the first step in matching a solution to your business model.
Hosted (redirect) gateways send the customer to a third-party payment page, such as PayPal’s standard checkout. The merchant’s PCI DSS scope is minimal because card data never touches the merchant’s server. The trade-off is reduced control over the checkout experience and a visible redirect that some customers distrust.
Integrated (API/on-site) gateways keep the customer on the merchant’s domain throughout. Stripe, Adyen, Checkout.com, and Worldpay all offer direct API integration. The checkout experience is fully branded, conversion tends to be higher, and the merchant can pass additional data fields that improve authorisation rates. The cost is greater PCI DSS scope and meaningful developer effort to implement correctly.
Aggregator gateways pool merchants under a single master merchant account. Square is the clearest UK example. Onboarding is fast, pricing is simple, and no underwriting is required upfront. The limitation is that aggregators can hold or terminate accounts with less notice than a dedicated merchant account, and per-transaction rates are often higher at volume.
Pro Tip: Choose your gateway type based on your technical resource and your customers’ expectations. If you have no developer and sell under £10,000 per month, a hosted or aggregator model reduces compliance burden and setup time. If you are building a branded checkout experience for a growing e-commerce store, an API-integrated gateway gives you the control that drives conversion.
How gateway selection changes conversion, approval rates and customer experience
Authorisation rates are the most underappreciated metric in gateway selection. Industry analysis shows routine 4–8 percentage-point differences in authorisation rates between well-tuned and poorly-tuned gateway setups. For a merchant processing £500,000 per year, a 5-point improvement in authorisation rate translates directly to tens of thousands of pounds in recovered revenue that would otherwise have been declined.

The mechanisms behind those differences include multi-acquirer routing, network tokenisation, and account updater services. Multi-acquirer routing sends a transaction to whichever acquirer is most likely to approve it, based on card type, issuing bank, and transaction history. Network tokens replace the primary account number with a payment-network-issued token that issuers trust more than a raw PAN, typically producing higher approval rates on card-on-file and subscription transactions. Account updaters automatically refresh stored card credentials when a customer’s card is reissued, reducing involuntary declines on recurring billing.
For subscription businesses in particular, the ability to manage dunning, network tokens and account updaters drives retention and reduces involuntary churn in ways that a basic gateway simply cannot replicate.
Checkout UX also matters. A payment page that loads slowly, lacks Apple Pay or Google Pay, or forces a redirect on mobile will lose customers who would otherwise have completed the purchase. The ecommerce checkout page checklist from MedwayWebDesign covers the specific friction points that cause abandonment at the payment step, and most of them are directly influenced by which gateway you have integrated.
| Measure to request from vendors | Why it matters |
|---|---|
| Authorisation rate by card type and issuing country | Reveals whether the gateway performs well for your specific customer mix |
| Multi-acquirer routing support | Indicates ability to optimise approval rates dynamically |
| Network token adoption rate | Proxy for card-on-file and subscription performance |
| Account updater coverage | Reduces involuntary churn on recurring billing |
| Local payment method support and cost | Affects both conversion and effective per-transaction cost |
Statistic: Adyen reports that local payment methods are, on average, 49% cheaper than credit and debit cards. For merchants with significant volumes of bank transfers, iDEAL, or other local methods, the cost difference is material enough to justify gateway selection on this criterion alone.
Security, compliance and legal basics UK merchants must check
PCI DSS, PSD2/SCA, and GDPR are not optional considerations for UK merchants. They define liability, scope, and in some cases the legal right to process payment data at all.
PCI DSS has four merchant validation levels, determined by annual transaction volume. Most small businesses fall into Level 4 (fewer than 20,000 Visa e-commerce transactions per year) and complete a Self-Assessment Questionnaire rather than a full audit. However, the SAQ type depends on your integration method: a hosted gateway typically qualifies for SAQ A, the simplest form, while an API-integrated gateway may require SAQ D, which has over 200 controls. Choosing a hosted gateway is therefore a legitimate compliance strategy, not just a technical shortcut. For a detailed breakdown of merchant validation levels and what each SAQ requires, the PCI DSS compliance guide from Secure Techies covers the obligations clearly.
PSD2/SCA mandates Strong Customer Authentication for most UK card-not-present transactions. Gateways must support 3D Secure 2 (3DS2) flows and handle exemption logic correctly. A gateway that applies SCA to every transaction without exemption management adds unnecessary friction; one that fails to trigger SCA where required creates regulatory exposure. Ask vendors specifically how they handle SCA exemptions (low-value, trusted beneficiary, transaction risk analysis) and what their documented SCA decline rate looks like.
GDPR applies to any personal data processed during a transaction, including IP addresses, device fingerprints, and billing details. Confirm that your gateway provider acts as a data processor under a signed Data Processing Agreement, and that their data residency is compatible with your privacy policy.
Compliance checklist for vendor due diligence:
- PCI DSS Level 1 Service Provider attestation (the highest level — request the Attestation of Compliance, not just a self-declaration).
- SOC 2 Type II report (confirms operational security controls are operating effectively over time, not just at a point in time).
- Published 3DS2 / SCA flow documentation and exemption management capability.
- GDPR Data Processing Agreement available before contract signature.
- Published uptime SLA and, critically, peak-day performance data.
- Independent security audit or penetration test results available on request.
Hosted gateways reduce PCI DSS scope significantly because card data is captured and processed on the gateway provider’s infrastructure rather than the merchant’s. A merchant using a fully hosted checkout can typically complete SAQ A, which has fewer than 25 controls, compared with the 200-plus controls in SAQ D for direct API integrations. This scope reduction is one of the most commercially significant but least-discussed reasons to favour a hosted approach for merchants without dedicated security resource.
Who holds PCI responsibility? The merchant always retains ultimate responsibility for PCI DSS compliance, even when using a hosted gateway. What changes is the scope of that responsibility. A gateway provider certified as a PCI DSS Level 1 Service Provider handles the controls that apply to their infrastructure; the merchant is still responsible for the controls that apply to their own systems, staff, and processes.
Fees, settlement speed and the true total cost of ownership
Headline per-transaction rates are rarely the number that matters most. The true cost of a gateway emerges when you model your specific volume, card mix, and feature requirements against the full fee schedule. J.P. Morgan identifies cost structure as one of the primary selection criteria, alongside security, scalability, and integration capability.
The fee lines to model include: per-transaction percentage (which varies by card type — consumer debit, consumer credit, and commercial cards carry different interchange costs), fixed per-transaction fee (often £0.20–£0.30 on top of the percentage), monthly minimum or platform fee, authorisation-attempt fee (charged even on declined transactions by some providers), settlement or batch fee, chargeback fee (typically £15–£25 per dispute), and add-on feature charges for fraud screening, account updater, or advanced reporting.
A worked modelling approach: take your last three months of transaction data, segment by card type and average order value, and apply each gateway’s full published rate card to that mix. Then add the monthly platform fee and an estimated chargeback cost based on your dispute rate. The result is a comparable effective cost per transaction that makes headline rates irrelevant.
Statistic: Because local payment methods average 49% lower cost than cards, a gateway that supports Open Banking payments or bank transfer methods for UK customers can materially reduce effective cost for merchants whose customers are willing to pay by those methods.
Settlement timing directly affects working capital. Stripe and Checkout.com offer two-day rolling settlement as standard for UK merchants; Adyen and Worldpay offer configurable settlement cycles. Same-day or next-day settlement is available from some providers at a premium. For businesses with tight cashflow, a two-day versus five-day settlement difference can require a meaningful working capital buffer.
Pro Tip: When negotiating with gateway providers, focus on the statement-level fees that are rarely listed on public pricing pages: authorisation-attempt fees, batch fees, and the cost of add-on fraud tools. Request a full sample statement from a comparable merchant before signing. Providers that refuse to share one are signalling that the real cost is higher than the headline rate.
Integration options, developer effort and platform compatibility
The integration path you choose determines both the initial engineering cost and the ongoing maintenance burden. The four main approaches carry materially different effort profiles.
Plugins and pre-built connectors (WooCommerce, Shopify, Magento, BigCommerce) require minimal developer time, typically a few hours to configure. Stripe, PayPal, Square, and Worldpay all publish maintained plugins for the major platforms. The limitation is that plugin-based integrations offer less control over the checkout flow and fewer opportunities to pass enriched data that improves authorisation rates.
Hosted checkout SDKs (Stripe Checkout, PayPal’s hosted fields, Checkout.com’s Frames) sit between a plugin and a full API integration. They keep the customer on the merchant’s domain while the gateway handles card data capture, reducing PCI scope. Setup typically takes one to three days for a developer familiar with the platform.
Direct API integration gives full control over the payment flow, data enrichment, and UX. It also requires the most engineering time: a basic implementation takes one to two weeks; a production-grade integration with webhook handling, idempotency, retry logic, and reconciliation tooling takes four to eight weeks. This is the appropriate path for custom-built platforms and merchants with specific routing or reporting requirements.
Integration checklist for operations and development teams:
- Idempotency key support (prevents duplicate charges on network retries).
- Signed webhooks with replay and retry tooling (critical for reliable order fulfilment).
- Sandbox environment that mirrors production behaviour, including 3DS2 flows.
- SDK support for your primary development language (Node.js, Python, PHP, Ruby, Java).
- Webhook delivery SLA and failure alerting.
- Developer documentation quality and community support availability.
- Token export format and migration tooling (ask before you sign).
Token portability deserves specific attention. Token export delays are a common cause of vendor lock-in, and practical migrations often take 10–14 days for token ingest when vendors cooperate. Ask every vendor: “Can you export our token vault in a standard format, and what is your documented timeline for doing so?” A vendor that cannot answer clearly is one that expects you to stay.
Fraud protection, chargeback handling and operational impacts
Fraud screening and chargeback management are where the gap between gateway tiers becomes most operationally significant. Modern gateways bundle tokenisation, fraud detection, and reporting as included capabilities; older or simpler gateways treat them as paid add-ons. At scale, bolt-on per-transaction fraud tools add materially to cost.

Stripe’s Radar uses machine learning trained on its global transaction network and is included in standard pricing. Adyen’s RevenueProtect combines rule-based and ML screening with risk scoring at the transaction level. Checkout.com offers a similar in-line screening product. Worldpay and PayPal include basic fraud filters, with more sophisticated tools available at additional cost. Square’s fraud protection is included but less configurable, which suits lower-risk retail merchants and less so high-risk or high-volume e-commerce.
The operational questions that matter most for chargeback management are: Does the gateway provide pre-populated dispute evidence packs? Does it integrate with your order management system to pull transaction metadata automatically? What is the average response time for dispute notifications, and does the dashboard support bulk representment? Merchants who manage disputes manually lose a disproportionate number of winnable cases simply because the evidence is assembled too slowly.
Pro Tip: For small merchants, the most common mistake is setting fraud rules too aggressively to avoid chargebacks, then losing more revenue to false positives than the chargebacks would have cost. Start with the gateway’s default ML rules, monitor your false-positive rate for 30 days, and only tighten rules on the specific card types or geographies where your actual fraud is concentrated.
How to evaluate and choose the right gateway for your business
A structured evaluation prevents the most common mistake: choosing a gateway based on brand recognition rather than fit for your specific payments mix, business model, and technical resource.
Step-by-step evaluation checklist:
- Define your payments mix: card types, average order value, transaction volume, recurring versus one-off, and target geographies.
- Model total cost: apply each shortlisted gateway’s full fee schedule to your actual transaction data, including add-on features you will need.
- Request authorisation-rate data: ask vendors for approval-rate benchmarks for merchants with a similar profile, segmented by card type and issuing country.
- Validate uptime with peak-day metrics: request Black Friday and Cyber Monday uptime and transaction success data, not just annual averages.
- Test the sandbox: run your full checkout flow, including 3DS2 and declined-card scenarios, before committing.
- Ask about token export: confirm format, timeline, and any fees for token migration before signing.
- Review the support SLA: confirm response times for critical payment failures, not just general queries.
Vendor questions covering security and compliance:
- What PCI DSS level are you certified at, and can you provide your current Attestation of Compliance?
- How do you handle SCA exemption management, and what is your documented SCA decline rate?
- What is your Data Processing Agreement, and where is payment data stored?
Red flags that should stop a shortlisting:
- No token export capability or refusal to confirm export timelines.
- Fee schedules that are not published or require a sales call to obtain.
- No published peak-day uptime data.
- Fraud screening available only as a paid add-on with per-transaction pricing.
- No SOC 2 Type II report available on request.
Gateway evaluation matrix:
| Dimension | What to assess | Questions to ask |
|---|---|---|
| Security and compliance | PCI DSS level, SCA support, SOC 2 | Request AoC and DPA before signing |
| Payment method coverage | Cards, wallets, Open Banking, local methods | Which methods are live in the UK today? |
| Pricing shape | Effective cost at your volume and card mix | Request a sample statement from a comparable merchant |
| Integration complexity | Plugin, SDK, or API; estimated engineering days | What is the sandbox environment like? |
| Authorisation rate support | Routing, network tokens, account updater | Show me approval-rate data for UK merchants |
| Fraud and chargeback tools | Included or add-on; ML versus rule-based | What is the false-positive rate on default settings? |
| Settlement timing | Days to settlement; configurable cycles | What is the standard settlement cycle for UK merchants? |
| Token portability | Export format, timeline, migration tooling | Can you export our token vault, and in how long? |
Why local acquiring and routing matter specifically for UK merchants
Local acquiring is one of the most commercially significant factors in gateway selection for UK merchants, and one of the least discussed in generic gateway comparisons. When a transaction is routed through a UK acquirer rather than an international one, the issuing bank recognises the transaction as domestic, which typically produces a higher approval rate and avoids cross-border processing fees. Gateway choice directly affects access to local acquiring, and the selection priorities differ by business model.
Statistic: Local payment methods are, on average, 49% cheaper than credit and debit cards. For UK merchants with customers who use Open Banking payments or bank transfer methods, the cost advantage of supporting those methods is substantial enough to influence gateway selection independently of other criteria.
Adyen, Checkout.com, and Worldpay all maintain direct UK acquiring relationships, which means transactions from UK-issued cards can be processed domestically without routing through an international network. Stripe processes UK transactions through its UK entity and holds FCA authorisation. PayPal routes UK merchant transactions through its Luxembourg entity for card processing, which can affect approval rates on some UK-issued cards. Square’s UK acquiring is handled through its UK entity, though its routing optimisation is less configurable than enterprise-grade alternatives.
The vendor question to ask directly is: “Can you show me local acquiring coverage for UK transactions, and do you have approval-rate uplift data comparing local versus international routing for merchants with a similar profile to ours?”
Pro Tip: Validate vendor uptime claims with peak-day data, not annual averages. Ask for documented transaction success rates on the highest-volume days of the previous year.
Providers commonly used by UK merchants
The following notes describe the capabilities that well-known gateway providers tend to emphasise for UK merchants. They are not a ranking; they are a capability map to help you identify which vendors to investigate for your specific requirements.
- Stripe is widely used by technology-forward merchants and SaaS businesses. Its API is extensively documented, its fraud screening (Radar) is included in standard pricing, and its network token and account updater support is mature. Gateway selection priorities differ by business model, and Stripe’s recurring billing and dunning features make it a natural fit for subscription-first businesses.
- Adyen targets mid-market and enterprise merchants. Its multi-acquirer routing, local acquiring coverage, and omnichannel capability (unified online and in-store) are its primary differentiators. Its pricing is interchange-plus, which is more transparent at volume but harder to model for small merchants.
- Worldpay (FIS) has deep UK market presence and long-standing relationships with UK acquirers. It is commonly used by established UK retailers and businesses that need a dedicated merchant account with configurable settlement. Its integration options range from hosted to direct API.
- Checkout.com emphasises authorisation rate optimisation and local acquiring in its positioning. It publishes approval-rate data and offers configurable routing rules, which suits merchants for whom a percentage-point difference in authorisation rate has material revenue impact.
- PayPal remains the highest-recognition payment brand among UK consumers. Its hosted checkout reduces PCI scope and its buyer protection programme increases consumer confidence. Per-transaction rates are higher than interchange-plus alternatives at volume, but the conversion uplift from PayPal’s brand recognition can offset that cost for certain merchant categories.
- Square suits UK merchants with lower transaction volumes, physical retail, or both. Its aggregator model means fast onboarding and simple flat-rate pricing, with no monthly fee on the standard plan. It is less suited to high-volume e-commerce or merchants requiring configurable fraud rules.
The capability question to ask yourself: does your business need recurring billing and dunning (Stripe), omnichannel and local acquiring at scale (Adyen), deep UK market relationships (Worldpay), authorisation-rate optimisation (Checkout.com), consumer brand recognition (PayPal), or simple flat-rate onboarding (Square)? That answer should drive your shortlist, not brand familiarity.
Regardless of which provider you shortlist, ask about token export and API translation tools before signing. Vendor lock-in through token vaults is a documented and common problem, and the cost of migration without token portability is significant.
Short action steps for small business owners
The following steps convert the analysis above into a practical sequence. Each step has a suggested owner and a realistic time estimate.
- Model your fees (Finance lead, 2–3 hours): Pull three months of transaction data, segment by card type and average order value, and apply each shortlisted gateway’s full rate card. Include add-on feature costs.
- Request performance evidence (Finance or Operations lead, 1–2 days): Ask each vendor for authorisation-rate data for comparable merchants, peak-day uptime metrics, and a sample statement from a live merchant.
- Run a sandbox checkout test (Developer or Technical lead, 1–2 days): Complete your full checkout flow in each gateway’s sandbox, including 3DS2 and declined-card scenarios. Note any friction points.
- Check token export policy (Technical or Legal lead, 1 hour): Confirm in writing the format, timeline, and any fees for token export before signing any contract.
- Plan migration effort (Technical lead, 2–4 hours): If switching from an existing gateway, map the token migration timeline, integration rebuild effort, and any parallel-running period needed to avoid transaction disruption.
Gateway choice is a checkout design decision, not just a technical one
The framing of payment gateway selection as a purely technical or financial decision misses the most important dimension: every gateway choice is also a checkout design decision. The gateway determines which payment methods appear at checkout, how the payment form renders on mobile, whether the customer is redirected or stays on your domain, and how quickly the confirmation page loads. Each of those factors affects conversion directly.
From a web design and conversion optimisation perspective, the gateway integration is the point where technical infrastructure and customer experience intersect most visibly. A checkout that loads slowly because the gateway’s JavaScript is unoptimised, or that fails to render Apple Pay because the integration is incomplete, loses customers at the highest-intent moment in the purchase journey. The mobile ecommerce shopping experience and the reasons cart abandonment happens are both directly shaped by the gateway integration quality.
MedwayWebDesign works with UK merchants on exactly this intersection: the technical integration of payment gateways into e-commerce builds, the UX design of checkout flows that reduce abandonment, and the conversion testing that validates whether a gateway change has produced the expected uplift. The team’s experience across WooCommerce, Shopify, and custom-built platforms means gateway selection recommendations are grounded in real integration effort, not theoretical comparisons.
MedwayWebDesign supports merchants through gateway integration and checkout optimisation
For UK merchants who need more than a gateway shortlist, MedwayWebDesign offers practical support across the full implementation: e-commerce website design and gateway integration for new builds, checkout flow optimisation for existing sites, and migration planning for merchants switching providers. The team handles the engineering complexity of API integration, 3DS2 configuration, and webhook reliability so that the merchant’s focus stays on trading rather than troubleshooting.

Where a gateway change is part of a broader site redesign or platform migration, MedwayWebDesign coordinates the technical and design workstreams together, reducing the risk of a gateway switch that improves authorisation rates but introduces checkout friction that offsets the gain. Contact the team to schedule a checkout audit, or visit the custom web design guide for small businesses to understand how a bespoke build can incorporate gateway selection from the ground up.
Sources
The following sources were used to compile this guide. When citing them in an RFP or vendor evaluation, ask vendors to respond to the specific claim or metric the source contains, not just acknowledge the source.
- Stripe resources — payment gateway comparison
- Adyen — payment gateway knowledge hub
- J.P. Morgan insights — payment gateways: what they are and how to choose one
- PayPal — what is a payment gateway
- NMI — payment gateways for modern business
- Choosing a payment gateway in 2026: a merchant’s buyer’s guide · Superior Payments
When a vendor cites any of these sources in a sales conversation, ask them to provide their own equivalent metric: their specific authorisation-rate data for UK merchants, their own AoC, or their documented peak-day uptime. A source reference without vendor-specific evidence is a marketing claim, not a performance commitment.
Recommended
- Best website builders for small business: UK guide 2026 – Medway Web Design
- Best digitalweb.co.uk alternatives for UK small businesses – Medway Web Design
- Ecommerce checkout page checklist for higher conversions – Medway Web Design
- Why mobile-friendly websites matter for small businesses – Medway Web Design