Chip and PIN

Chip and PIN combines EMV chip processing with a personal identification number to authenticate a card-present payment and its cardholder.

Chip and PIN is a card-present payment method that combines EMV chip processing with a personal identification number as the cardholder-verification method. The chip helps authenticate the payment device and transaction data, while the PIN helps verify that the person presenting it is authorized to use the card.

The two controls solve different problems. A valid chip exchange does not prove who entered the PIN, and a correct PIN does not guarantee that the issuer will authorize the payment or that settlement will be final.

Key Takeaways

  • Chip authentication and PIN verification are separate controls within one payment workflow.
  • EMV supports several cardholder-verification methods, so not every chip transaction is Chip and PIN.
  • A PIN can be checked through online issuer processing or, in some EMV configurations, by the chip.
  • Authorization, merchant capture, clearing, settlement, refunds, and disputes occur after or around authentication.
  • Chip and PIN reduces some counterfeit and unauthorized-use risks but does not eliminate fraud.
  • Entry mode, cardholder-verification result, fallback, and issuer response are important transaction evidence.

How Chip and PIN Works

A typical contact-chip transaction proceeds as follows:

  1. The customer inserts the card into an EMV-capable terminal.
  2. The chip and terminal exchange application and transaction data.
  3. The transaction selects a permitted cardholder-verification method.
  4. The customer enters a PIN on an approved device when PIN is required.
  5. The PIN result and other transaction data support the authorization decision.
  6. The issuer or approved transaction logic approves or declines the payment.
  7. The merchant captures the approved transaction for clearing and settlement.

The card normally remains in contact with the reader while the chip exchange is completed. Removing it too early can interrupt processing even after the customer has entered a PIN.

Online and Offline PIN

The label Chip and PIN can cover different verification paths:

PIN methodSimplified descriptionEvidence to review
Online PINEncrypted PIN-related data is routed for verification through the issuer’s processing environmentTerminal security, message routing, issuer response, and PIN result
Offline PINA compatible chip and terminal perform PIN verification locally under EMV rulesCard and terminal capabilities, try counter, verification result, and later authorization data
Consumer-device verificationA phone or wearable verifies the user through a passcode or biometricDevice-verification result, token data, wallet record, and issuer response

These methods are not interchangeable. Payment networks and markets determine which methods are supported for a particular card, terminal, amount, and transaction type.

Chip and PIN vs. Similar Methods

MethodPayment-device authenticationCardholder verification
Chip and PINEMV contact or compatible chip exchangePIN
Chip and signatureEMV chip exchangeSignature where supported
Contactless cardOften EMV contactless chip exchangeMay use no verification, PIN, or another method depending on rules
Mobile-wallet tapTokenized or provisioned credential through a contactless deviceOften passcode or biometric on the consumer device
Magnetic-stripe and PINStatic stripe dataPIN, without the normal EMV chip exchange

A payment can use a PIN without being an EMV chip transaction, and it can use EMV without requiring a PIN.

Practical Example: PIN Failure

A customer inserts a chip card for a $480 purchase and enters a PIN. The terminal reports that verification failed, so the payment is not completed. The customer then asks the cashier to swipe the card instead.

The merchant should not assume that a magnetic-stripe fallback is automatically appropriate. The review should check:

  • whether the chip was read successfully;
  • the recorded cardholder-verification method and result;
  • whether another permitted method was available;
  • whether fallback is allowed under the terminal and network rules;
  • issuer authorization and decline codes;
  • terminal messages and operator actions; and
  • whether the customer should contact the issuer.

Bypassing a failed PIN through a weaker entry method can undermine the reason the verification step exists.

PIN Security and Operational Controls

PIN security extends beyond asking customers to cover the keypad. Payment participants need secure PIN-entry devices, encryption and key management, restricted access, monitoring, device inspection, and controlled exception handling.

The PCI Security Standards Council’s PIN Security Standard addresses secure PIN management, processing, and transmission and the associated cryptographic keys. Its point-of-interaction standards address devices used to protect PINs and other payment data.

For customers, practical precautions include:

  • do not share the PIN or store it with the card;
  • shield PIN entry from observation;
  • inspect unfamiliar terminals for obvious damage or attachments;
  • review transaction alerts and statements;
  • report a lost card or suspected disclosure promptly; and
  • follow the issuer’s replacement and dispute instructions.

These precautions reduce risk but do not determine liability in a specific dispute.

How to Review a Chip-and-PIN Transaction

  1. Identify the card, merchant, terminal, date, amount, and transaction entry mode.
  2. Separate chip authentication, PIN result, issuer authorization, and merchant capture.
  3. Check whether the PIN was online, offline, bypassed, failed, or not required.
  4. Review fallback indicators, repeated attempts, reversal messages, and terminal exceptions.
  5. Trace the approved amount through clearing, settlement, posting, refund, or chargeback.
  6. Apply the current issuer, acquirer, network, consumer-protection, and jurisdictional rules.

Risks and Common Mistakes

  • Treating Chip and PIN as a synonym for every EMV transaction.
  • Assuming a correct PIN proves the customer authorized the purchase.
  • Confusing issuer authorization with final settlement.
  • Allowing magnetic-stripe fallback without investigating a working chip and failed PIN.
  • Claiming Chip and PIN eliminates stolen-card, account-takeover, or e-commerce fraud.
  • Ignoring compromised terminals, shoulder surfing, social engineering, and PIN reuse.
  • Assuming cardholder protections and liability allocation are universal.
  • Storing PIN data or cryptographic material outside approved controls.

Official Resources

Technical standards do not by themselves determine whether a transaction is authorized, reversible, or legally binding. Review the applicable agreement and current rules.

FAQs

Is Chip and PIN the same as EMV?

No. EMV is the broader chip-payment framework. Chip and PIN is an EMV transaction that uses a PIN as the cardholder-verification method.

Can a contactless payment use a PIN?

Yes, depending on the card, terminal, amount, market, and payment rules. Other contactless transactions may use device authentication or no cardholder-verification method.

Does entering the correct PIN guarantee approval?

No. The issuer can still decline because of account status, funds or credit, fraud controls, transaction restrictions, or processing problems.
  • EMV Technology: Framework for chip-card and compatible payment-device communication and authentication.
  • Personal Identification Number: Secret numeric credential used in one cardholder-verification method.
  • Contactless Payment: Tap-based card, phone, or wearable payment interface.
  • NFC: Short-range communication used by many contactless terminals and mobile devices.
  • Magnetic Stripe Card: Static-data card technology that may appear in fallback transactions.

Educational Use

This article provides general financial education. It is not payment-security, merchant, banking, fraud, chargeback, legal, or compliance advice.

Browse Financial Technology