Skip to main content

Merchant Services Ltd

Visa Account Updater and Mastercard ABU: Keeping Card-on-File Billing Alive When Cards Expire or Get Reissued | Visa Account Updater for Merchants
By Marcus Jennings October 7, 2026

Visa Account Updater for merchants and Mastercard ABU help keep legitimate recurring payments working when stored cards expire, are replaced, or are reissued. Participating issuers provide credential changes or account-status information through the networks and supporting payment providers, allowing eligible merchants to refresh stored credentials without requiring every customer to enter new card details manually.

A subscription can be fully authorized by the customer and still fail months later because the stored payment credential is stale. The card may have expired, been replaced after fraud, changed after a lost-card report, or moved through another issuer account-management event.

A card account updater service addresses that credential-lifecycle problem. It does not guarantee authorization, and it does not give a merchant permission to keep billing after a customer cancels. Its job is narrower: help an existing, authorized card-on-file relationship use current payment credentials.

What Visa Account Updater for Merchants Actually Does

Visa Account Updater for merchants is a credential-lifecycle service that lets participating issuers provide updated account information to enrolled card-on-file merchants through Visa and participating acquirers or processors.

Visa currently documents Visa Account Updater, or VAU, as supporting account-number changes, expiration-date changes, closed-account advice, and contact-cardholder advice. Visa also documents several delivery channels, including batch VAU, the VAU Acquirer API, Real Time VAU, and a Push Subscribe Service.

Visa’s current official material is available in its Visa Account Updater documentation.

The basic ecosystem has six roles. The cardholder establishes the payment relationship. The issuer manages the card account and reports supported changes. The card network operates the updater infrastructure. The acquirer or processor connects the merchant to that infrastructure. A gateway or token platform may automate storage and retrieval of updates. Finally, the merchant billing system decides what to do with the result.

That last point matters. Receiving an updated PAN or expiration date is only useful if the merchant’s vault, subscription record, retry logic, and cancellation status stay synchronized.

Merchants reviewing the broader difference between ecommerce, card-not-present, and recurring-payment account structures can also reference recurring billing merchant account structures.

Visa Account Updater vs. Mastercard Automatic Billing Updater

Visa and Mastercard both operate account-updater programs, but merchants should not treat the programs as technically identical.

Mastercard continues to identify its program as Automatic Billing Updater (ABU). Mastercard’s current materials describe ABU as a way for acquirers and merchants to receive updated payment credentials when cards expire or are renewed, while Mastercard’s rules describe ABU as communicating account-information changes to merchants participating in account-on-file and recurring-payment transactions.

Mastercard also continues to list Automatic Billing Updater in its developer product catalog.

Feature Visa Account Updater Mastercard Automatic Billing Updater
Network Visa Mastercard
Main purpose Maintain eligible stored credentials and provide account-status updates Maintain eligible account-on-file and recurring-payment credentials
Typical merchant use Recurring and other supported credential-on-file relationships Recurring and account-on-file relationships
Updated information PAN and/or expiration changes; closed-account and contact-cardholder advice Account changes supplied through the ABU ecosystem
Batch support Yes Yes; ABU documentation describes acquirer inquiry workflows
Real-time capability Visa specifically documents Real Time VAU and an Acquirer API Availability depends on the provider/API implementation used by the merchant
Pricing Provider and commercial-agreement dependent Provider and commercial-agreement dependent
Enrollment Generally implemented through a participating acquirer, processor, or supported provider Generally implemented through a participating acquirer, processor, gateway, or other supported provider

Mastercard’s published ABU summary describes the traditional flow as issuer → ABU → acquirer → merchant. Participating merchants provide account data through their acquirer, Mastercard matches inquiries against issuer-submitted account changes, and the results return through the acquiring channel.

How a Card Account Updater Service Works Step by Step

Card account updater service process from card reissue through merchant vault and recurring payment update

A card account updater service fits between credential storage and the next authorized card-on-file transaction.

  1. The merchant obtains valid authorization to store and later use an eligible card credential or payment token.
  2. The customer continues using the subscription, membership, installment plan, or other card-on-file relationship.
  3. The issuer later renews, replaces, reissues, or closes the underlying account.
  4. Where the issuer and program support it, the issuer makes the relevant credential change or status information available through the network updater ecosystem.
  5. The merchant’s acquirer, processor, gateway, token platform, or another supported intermediary checks eligible stored credentials.
  6. An updater response is returned or written into the provider’s vault.
  7. A valid new PAN or expiration date is applied to the authorized stored credential where appropriate.
  8. Closed, unusable, unavailable, or contact-cardholder results are routed into suppression or customer-contact logic instead of being treated as successful updates.

Visa states that participating issuers submit changes and enrolled merchants, through their acquirers, can request the latest account information. Visa also makes clear that participation and availability vary; merchants should not assume every reissued card will produce an update.

What Information Can an Account Updater Return?

Updater output needs to be translated into business logic rather than merely stored in a database.

Updater result What it means Recommended merchant action
New credential/account number A replacement account credential is available Update the authorized stored credential through the supported vault or billing platform
New expiration date The account remains usable with refreshed validity information Update expiry data where required
Account closed/no longer usable The credential should not be treated as a normal renewable payment method Suppress automated rebilling against that credential and seek a valid payment method where appropriate
Contact cardholder Customer involvement is required Pause automated recovery that depends on the stale credential and contact the customer
No change/no update No usable change was returned Continue only with normal authorized billing and compliant decline handling
Provider-specific status Gateway or processor maps network output into its own categories Follow the provider’s documented mapping and test it before production

Visa explicitly documents PAN updates, expiration updates, closed-account advice, and contact-cardholder advice. Its Acquirer API documentation also identifies outcomes including closed account, opt-out, and contact-cardholder information.

Do not build billing logic around assumed universal response codes. Your processor or gateway may translate network results into proprietary statuses, API fields, reports, or vault events.

Expired Card Recurring Billing: Why Expiration Does Not Tell the Whole Story

Expired card recurring billing problems are only one category of stale-credential failure. A customer may receive a routine renewal with a new expiration date, a completely new PAN after loss or fraud, or a replacement card following an issuer account change.

An account can also be closed rather than renewed. In that case, an updater should not be treated as a mechanism for inventing another valid credential.

This is why expired card recurring billing workflows should separate credential problems from ordinary authorization declines. Insufficient funds, issuer risk decisions, authentication problems, account restrictions, and other causes can still produce declines even when the stored credential itself is current.

Batch Account Updater vs. Real-Time Account Updater

Data processing flowchart comparison diagram

The practical distinction is when the merchant learns about the change.

Batch updater

Batch processing checks portfolios or scheduled subsets of stored credentials before billing. Visa’s acquirer documentation specifically gives the example of monthly recurring merchants submitting accounts scheduled for billing in the next several days.

Batch updating is therefore useful when renewal dates are predictable and the merchant wants the credential refreshed before authorization.

Providers may manage the entire process. Braintree, for example, documents rolling account-updater checks for eligible vaulted cards based on expiry, upcoming recurring billing, and certain transaction activity.

Real-time account updater

A real-time account updater checks for credential changes at or close to payment processing rather than waiting for the next scheduled portfolio file.

Visa’s Real Time VAU is particularly clear: for eligible credential-on-file transactions, VisaNet can check VAU during processing, update account information before the authorization is sent to the issuer, and return update information with the transaction response.

Provider implementations can differ. Adyen, for example, documents a Real Time Account Updater that checks for updates after an eligible refused payment and, when an update is available, retries using the refreshed details during the payment flow.

Billing pattern Likely updater approach
Monthly subscription batch Pre-billing batch updater can fit well
Annual renewal Pre-renewal credential check can prevent avoidable stale-card failures
Frequent recurring payments Automated lifecycle management, provider-managed updates, or network tokens may be stronger
Decline-triggered recovery Real-time/request-based updating may help where the provider supports it
Hosted-gateway merchant Provider-managed updating is often operationally simpler

A merchant should not assume that “real time” means direct access to a network API. In many setups, the gateway or processor owns the network integration.

How Account Updaters Reduce Involuntary Churn

Involuntary churn occurs when a customer intends to remain subscribed but payment fails for an operational reason. Voluntary churn occurs when the customer actually chooses to leave.

To reduce involuntary churn, card updates should happen before avoidable stale credentials turn into failed renewals. The updater fixes one part of the failure problem without weakening cancellation controls.

That distinction is important for any reduce involuntary churn card updates strategy: recovering a payment from a customer who still wants the service is useful; recovering a payment after that customer revoked authorization is not.

Example: Assume a subscription merchant has 5,000 monthly renewals. For illustration only, suppose its provider checks all 5,000 credentials at a hypothetical total updater cost of $250. Assume valid updater activity helps recover 60 renewals that otherwise would have failed, and each recovered renewal contributes $20 after the direct cost of providing the service.

Recovered contribution is 60 × $20 = $1,200. After the hypothetical $250 updater cost, the incremental contribution is $950.

No recovery percentage in that example is an industry benchmark. Merchants should use their own updater results, renewal economics, and contribution margin.

What Do Visa Account Updater and Mastercard ABU Cost?

There is no single universal merchant price for Visa Account Updater for merchants or Mastercard ABU.

Visa’s developer material directs production users to obtain commercial details through Visa and their participating program relationships. At the merchant level, gateways, processors, acquirers, and billing platforms can package updater costs differently.

Commercial structures can include per inquiry, per successful update, per API request, monthly platform charges, bundled gateway pricing, or provider markup.

A current public example illustrates why merchant pricing should be treated as provider-specific: Authorize.net lists an Account Updater fee of $0.25 per update. 

Its Account Updater documentation says merchants are charged for successful updated responses rather than every card on file. That is an Authorize.net price, not a universal Visa or Mastercard tariff.

Braintree takes a different approach publicly: its documentation says Account Updater pricing varies according to the merchant’s pricing model and directs merchants to contact the provider for fees.

For context on separating add-on fees from interchange, assessments, processor markup, and gateway charges, see how payment processing fees are structured.

Merchant pricing for account updater services varies by gateway, acquirer, processor, transaction volume, geography, and contract. Ask for the fee schedule in writing before activation.

Cost-versus-recovered-renewal formula

Updater ROI = contribution margin from recovered legitimate renewals − updater service cost

Use contribution margin rather than gross payment volume. A $100 recovered transaction is not worth $100 in profit if fulfillment, software, licensing, commissions, support, or other variable costs consume part of the revenue.

Visa Account Updater for Merchants and Network Tokens

Stored PAN account updater compared with network token lifecycle management for recurring billing

Visa Account Updater for merchants and network tokenization solve overlapping credential-lifecycle problems, but they are not the same technology.

With traditional PAN storage, an updater may return a replacement PAN or new expiration date. With a network token, the merchant or token requestor uses a network-issued payment token associated with the underlying account and limited by applicable token-domain controls.

Visa specifically separates VAU from Visa Digital Credential Updater. Visa describes VDCU as managing token lifecycle changes and helping keep network tokens current when PAN updates occur. Visa also documents that issuers participating in VAU and Visa Token Service can allow updated cardholder data to flow into token lifecycle updates.

Mastercard likewise describes network tokenization through Mastercard Digital Enablement Service and states that tokens can be maintained as underlying card credentials change.

Credential model How updates may occur
Stored PAN Traditional updater can return PAN/expiry changes or account status
Network token Token lifecycle management may keep the token relationship current where supported
Gateway token representing a PAN The gateway may run an updater behind the scenes while keeping the merchant-facing token unchanged
Closed/canceled relationship Tokenization or updating must not be treated as permission to keep billing

A useful internal security reference is tokenization and online payment security practices. Network tokens can reduce payment-data exposure, but tokenization does not automatically remove every account-updater use case.

How to Enroll in Visa Account Updater for Merchants and Mastercard ABU

For most merchants, updater enrollment starts with the company that controls the stored-payment vault or acquiring connection rather than with an attempt to build a direct network integration.

  1. Identify where stored credentials actually live: gateway, processor vault, billing platform, or merchant-controlled environment.
  2. Ask whether the provider supports VAU and Mastercard Automatic Billing Updater.
  3. Confirm whether the feature is already enabled or requires merchant/MID enrollment.
  4. Determine whether both networks are covered.
  5. Ask which batch, API, push, or real-time capabilities are actually available to your account.
  6. Obtain the full pricing schedule.
  7. Request the exact updater-result categories exposed by the provider.
  8. Map each result to a billing-system action.
  9. Determine whether the vault uses stored PANs, gateway tokens, network tokens, or a combination.
  10. Test successful PAN updates, expiration updates, no-update results, and stop/closed scenarios.
  11. Assign operational ownership for monitoring updater activity.
  12. Review recovered renewals and updater expense after complete billing cycles.

Visa states that production VAU participation requires an eligible licensed issuer/processor or acquirer, or sponsorship from an eligible licensed Visa acquirer. That is one reason ordinary merchants commonly access the service through their acquiring/payment-provider stack.

Mastercard gateway documentation similarly illustrates provider-managed configuration in which merchant identifiers and Account Updater functionality are configured at the merchant-acquirer relationship.

Questions to Ask Your Processor or Gateway

Before enabling Visa Account Updater for merchants, get operational answers rather than simply asking whether “account updater” is supported.

  • Do you support both Visa VAU and Mastercard Automatic Billing Updater?
  • Is updating automatic, opt-in, or tied to a specific MID or vault?
  • Do you offer batch, request-based, real-time, or provider-managed lifecycle updates?
  • Are valid updates automatically written back to my token vault?
  • Can my billing system receive updater results through an API, webhook, or report?
  • What exact result suppresses further automated billing?
  • How are closed accounts and contact-cardholder results mapped?
  • How are gateway tokens distinguished from network tokens?
  • What is charged per inquiry, update, stored credential, API request, or month?
  • Are network costs bundled or passed through?
  • Can canceled and inactive customer records be excluded?
  • What testing environment or certification process is available?
  • How do I report recovered renewals separately from ordinary retries?

Setup Prerequisites Merchants Often Miss

An updater cannot compensate for a badly designed recurring-billing system.

Visa Account Updater for merchants works best when the underlying credential-on-file relationship is properly established, recurring or stored-credential indicators are correctly passed by the payment provider, customer identifiers are stable, and cancellation status is synchronized with the billing vault.

Visa’s stored-credential framework requires an agreement before credentials are stored for future use and ties future merchant-initiated transactions to the cardholder’s agreement. Mastercard’s recurring-payment rules similarly define recurring transactions as payments made pursuant to an agreement between the cardholder and merchant.

For merchants selling into markets with authentication requirements, stored credentials, recurring billing and merchant-initiated transaction handling provides useful additional context.

PCI scope also remains relevant. An account updater does not exempt a merchant from PCI DSS. PCI SSC states that PCI DSS applies wherever payment account data is stored, processed, transmitted, or where systems can affect the security of the cardholder data environment.

The authoritative PCI DSS resources from the PCI Security Standards Council should be used when defining scope. A more operational explanation is available in the PCI DSS v4.0.1 requirements overview.

What an Updater Response Should Trigger in Your Billing System

Receiving data is only half of the implementation. Business logic determines whether Visa Account Updater for merchants actually improves billing.

System state Billing action
Updated PAN Replace or refresh the authorized credential in the supported vault; preserve required customer/subscription linkage
Updated expiration Refresh expiry information where the platform requires it
No change Do not invent an update; process only under normal authorized billing rules
Update unavailable Route through normal decline/recovery logic when a transaction actually fails
Closed-account result Suppress further automated attempts against that credential and request a valid new method when appropriate
Customer already canceled Do not bill, regardless of whether a valid replacement credential exists
Token lifecycle update Continue using the valid token through the provider’s supported token flow
Contact-cardholder result Request customer action rather than treating the result as a successful credential update

Updater logic should be evaluated before retry logic. Otherwise a merchant can waste retries against credentials already identified as unusable.

Do Not Use Account Updater Services to Override a Cancellation

A newly updated card number does not create new customer authorization.

Visa’s stored-credential guidance states that a merchant should not complete stored-credential transactions beyond the agreed duration or after the cardholder cancels under the agreed cancellation policy. Mastercard’s recurring rules describe future recurring payments as authorized by the cardholder’s underlying agreement and require accessible cancellation mechanisms for subscription billing.

If a customer has canceled, revoked permission, terminated the relevant subscription, or otherwise validly instructed the merchant to stop recurring billing, the system should suppress future charges. An updater result is credential information, not a replacement consent record.

The same principle applies to closed-account and stop-style responses. Repeatedly hammering an unusable credential is not a sound payment-recovery strategy.

Common Account Updater Implementation Mistakes

Common failures include enabling only one network, checking credentials too late, receiving updated PAN data without updating the vault reference, failing to distinguish gateway tokens from network tokens, and ignoring closed-account or contact-cardholder outcomes.

Other mistakes include sending inactive subscriptions through the updater, interpreting “no update” as permission for unlimited retries, letting cancellation status drift between CRM and billing systems, or measuring recovered gross revenue without subtracting updater expense and contribution costs.

Providers also differ in coverage and timing. Do not assume every issuer participates equally or that every gateway exposes the network result in the same format.

Practical Billing Workflow

A disciplined recurring-payment flow is straightforward:

  1. Confirm that the subscription or billing agreement is active.
  2. Remove canceled, expired, suspended, and otherwise ineligible customer relationships.
  3. Run the supported credential-update process at the appropriate time.
  4. Apply valid PAN, expiration, vault, or token-lifecycle updates.
  5. Suppress closed-account and stop-billing outcomes.
  6. Submit the authorized recurring charge using the correct credential-on-file indicators.
  7. Process the issuer’s authorization response normally.
  8. Route eligible soft declines through the provider’s compliant retry strategy.
  9. Ask the customer for a new payment method when updater and retry paths cannot resolve the failure.
  10. Record which successful renewals were attributable to credential updating.

How to Measure Whether the Service Is Paying for Itself

A monthly updater scorecard should separate operational activity from actual financial recovery.

Metric Why track it
Eligible credentials checked Shows updater usage
PAN changes Measures material credential replacement
Expiration-only changes Shows routine renewal activity
Closed/unusable results Measures accounts removed from futile retry paths
Contact-cardholder results Quantifies cases requiring outreach
Renewals recovered after update Core recovery measure
Recovered revenue Shows payment volume restored
Recovered contribution margin Better economic measure than gross revenue
Updater fees Captures direct service cost
Payments still declining after update Shows updater limitations
Customer contacts avoided Indicates operational savings

Do not count every credential update as recovered revenue. An update only creates financial value when it changes the outcome of a legitimate payment or reduces another measurable operating cost.

Expert perspective: Account updater services work best when they are treated as part of payment lifecycle management, not merely as a decline-retry tool. A merchant still needs clean consent records, cancellation controls, token-vault hygiene, and sensible retry logic.

Key Takeaways

  • Visa Account Updater for merchants can refresh eligible Visa card-on-file credentials and return supported account-status information before or during recurring-payment processing.
  • Mastercard Automatic Billing Updater performs a comparable credential-maintenance role for eligible Mastercard account-on-file relationships, but implementation details should not be assumed to be identical.
  • A batch updater is useful before predictable billing runs; a real-time account updater can address credential changes closer to authorization where the network/provider configuration supports it.
  • Account updating can help reduce involuntary churn; card updates should complement, not replace, good retry and customer-contact logic.
  • Network-token lifecycle management may keep tokenized credentials current, but network tokens do not eliminate every traditional updater scenario.
  • Pricing varies by provider and contract; calculate value using recovered contribution margin, not gross revenue.
  • A replacement credential never overrides a valid cancellation or revoked recurring-payment authorization.

Frequently Asked Questions

What is a Visa Account Updater for merchants?

Visa Account Updater for merchants is Visa’s service for exchanging supported card-account changes between participating issuers and enrolled credential-on-file merchants through participating acquiring/payment infrastructure. Updates can include a replacement PAN, a new expiration date, closed-account advice, or contact-cardholder advice.

What is Mastercard Automatic Billing Updater?

Mastercard Automatic Billing Updater, or ABU, is Mastercard’s service for communicating supported account changes to participating account-on-file and recurring-payment merchants through the acquiring ecosystem.

Do Visa Account Updater and Mastercard ABU automatically replace expired cards?

Not universally. A supported issuer and account must produce an eligible update, and the merchant’s payment provider must participate and correctly process the result.

Can an updater provide a customer’s new card number?

Yes, in supported circumstances. Visa specifically documents updated PAN and expiration information. Mastercard ABU also supports communication of account changes through participating issuer/acquirer relationships.

What happens when the account has been closed?

Do not treat a closed-account response as another retry opportunity. Suppress automated billing against that credential and seek a valid new payment method when the customer’s underlying relationship remains active.

Is a card account updater service the same as network tokenization?

No. A traditional updater communicates changes to stored account credentials. Network tokenization substitutes a network token for the underlying PAN and can include its own lifecycle-management mechanisms.

Do network tokens update automatically when a card is reissued?

They can remain current through supported lifecycle-management processes, but not every token is guaranteed to survive every account event. Behavior depends on issuer action, token status, token-requestor configuration, network capabilities, and provider implementation.

What is a real-time account updater?

A real-time account updater checks for supported credential changes during or close to transaction processing instead of relying solely on scheduled batch files. Visa explicitly documents Real Time VAU; some payment providers also expose real-time updater behavior through their own integrations.

How much does Visa Account Updater cost?

There is no universal merchant price. Your gateway, processor, acquirer, market, and contract determine the commercial terms. For comparison only, Authorize.net currently publishes a $0.25 per-update Account Updater fee.

How much does Mastercard Automatic Billing Updater cost?

Merchant pricing depends on the provider and commercial arrangement. Ask the processor or gateway for a written fee schedule rather than assuming Mastercard ABU carries a universal merchant rate.

Can account updater services reduce involuntary churn?

Yes, they can reduce avoidable failures caused by outdated credentials. They cannot prevent every recurring billing decline, because authorization can still fail for insufficient funds, risk controls, account restrictions, or other reasons.

Does a merchant need a direct relationship with Visa or Mastercard to enroll?

Often no. Ordinary merchants commonly receive updater capability through an acquirer, processor, gateway, or token platform that manages the network connection. The exact enrollment structure depends on the provider.

Can I keep billing if the updater gives me a replacement card after the customer canceled?

No. Credential validity does not override the customer’s cancellation or withdrawal of permission. A replacement PAN should only support an otherwise valid, continuing payment relationship.

Does account updater enrollment change my PCI DSS responsibilities?

No. Your PCI DSS scope still depends on how payment account data is stored, processed, transmitted, and how systems can affect the cardholder data environment.

Using Visa Account Updater for Merchants Without Losing Billing Control

Visa Account Updater for merchants and Mastercard ABU are most valuable when they sit inside a controlled recurring-payment lifecycle: valid card-on-file authorization, accurate cancellation status, properly configured billing indicators, secure vaulting, sensible token lifecycle management, and clear updater-response rules.

The strongest implementation does not measure success by how many card records change. It measures how many legitimate renewals are recovered, how much contribution margin is retained, how many unnecessary retries disappear, and whether customers who canceled actually remain canceled.

Start by asking your processor or gateway five things: which updater networks are enabled, which batch or real-time modes your account can use, which response categories reach your billing system, how network tokens are maintained, and exactly what you will be charged.