A primary account number, or PAN, is the string of digits printed or embossed on a credit, debit, or prepaid card that uniquely identifies the account behind it. Most cards carry 15 or 16 digits, and the international standard allows up to 19. The number does more than label your account: its opening digits tell the terminal which payment network to route the transaction through, its middle digits identify your specific account at the issuing bank, and its final digit is a math check that catches typos before any data leaves the card reader.
The Three Parts of a PAN
Every PAN is built under ISO/IEC 7812, a standard maintained jointly by the International Organization for Standardization and the International Electrotechnical Commission. The standard splits the number into three segments: an Issuer Identification Number at the front, an individual account number in the middle, and a single check digit at the end.
Issuer Identification Number
The first several digits form the Issuer Identification Number (IIN), which older documentation calls the Bank Identification Number. The original standard set the IIN at six digits. A 2017 revision to ISO/IEC 7812-1 expanded it to eight to accommodate the growing number of card issuers worldwide.1International Organization for Standardization. ISO/IEC 7812-1:2017 – Identification Cards – Identification of Issuers – Part 1: Numbering System Issuers must apply for their IIN through authorized registration bodies, so no two institutions share the same prefix.
The first digit used to be a Major Industry Identifier that classified the issuer’s business category, but the 2017 revision formally removed that designation.1International Organization for Standardization. ISO/IEC 7812-1:2017 – Identification Cards – Identification of Issuers – Part 1: Numbering System In practice, the leading digit still identifies the network: Visa cards start with 4, Mastercard with 2 or 5, American Express with 3, and Discover with 6.
Individual Account Number
The digits between the IIN and the check digit are the individual account number, generated internally by the issuer to distinguish one customer from another. This segment reveals nothing about the cardholder personally. Under the current standard, it can run up to 12 digits, and the full PAN can reach 19.2Pay.UK. Issuer Identification Number
Check Digit
The last digit is a check digit calculated using the Luhn algorithm. It exists solely to catch data-entry errors before a transaction reaches the network.
How Many Digits Each Network Uses
Digit counts differ across networks, and the differences matter for processing. Visa, Mastercard, and Discover cards carry 16 digits. American Express uses 15. Diners Club International cards have 14, though Diners cards issued in the U.S. and Canada usually follow the 16-digit Mastercard format. Some Visa and Mastercard cards issued recently extend to 19 digits, though 16 remains the norm.
Payment terminals identify the network from the opening digits and apply the expected length. If a number doesn’t match, the terminal rejects it before transmitting anything.
How the Check Digit Catches Typos
The final digit is calculated using a formula named for IBM scientist Hans Peter Luhn. The Luhn algorithm creates a mathematical relationship among all the digits so that accidental errors, like transposing two numbers or mistyping one, are caught immediately.
Working right to left, every second digit is doubled. If doubling produces a number 10 or higher, the two resulting digits are added together. All the digits, doubled and undoubled, are then summed. A valid card number produces a total divisible by 10. If it doesn’t, the number is invalid. The check runs locally on the terminal or in the browser before anything is sent, so obviously wrong numbers never consume network resources.
The Luhn check is not a security measure. Anyone who understands the formula can generate a number that passes it, which is why additional authentication layers exist.
How the PAN Routes a Payment
When you tap or swipe a card, the terminal reads the IIN to determine which payment network should receive the authorization request. The data travels from the merchant’s payment processor to that network, which uses the IIN to identify the issuing bank. The issuer checks whether the account has sufficient funds or available credit, then sends approval or denial back through the same chain, usually within a few seconds.
This routing infrastructure is what interchange fees pay for. Interchange is the fee a merchant’s bank pays the cardholder’s bank on each transaction. For debit cards from issuers with $10 billion or more in assets, the Durbin Amendment caps interchange at 21 cents plus 0.05 percent of the transaction, with an additional 1-cent fraud-prevention adjustment for qualifying issuers.3Federal Register. Debit Card Interchange Fees and Routing Credit card interchange has no equivalent federal cap and varies by network, card type, and merchant category.
How Mobile Wallets Hide the PAN
When you add a card to Apple Pay, Google Pay, or a similar wallet, the actual PAN is not stored on your phone. The system generates a substitute value called an EMV Payment Token, which replaces the PAN for transactions made through that device. Load the same card onto a second device and a different token is created. A token looks like a card number and flows through the same payment rails, but it is useless to anyone who intercepts it because it only works within narrowly defined parameters.
EMVCo, the standards body behind chip card technology, designed token domain restriction controls that tie each token to a specific device, merchant, or transaction type. A token provisioned for in-store tap payments on your phone cannot be reused for an online purchase or on a different device.4EMVCo. EMV Payment Tokenisation Quick Reference Guide When the token reaches the network, a token service provider maps it back to the real PAN so the issuer can authorize the charge against the correct account. The merchant never sees the actual card number, which is why a breach at a retailer using tokenized transactions exposes far less than one involving raw PANs.
What You Owe If Your PAN Is Stolen
The financial consequences of a stolen card number depend on whether it is a credit card or a debit card, and on how fast you report the problem. The rules differ, and the debit rules are far less forgiving.
Credit Cards
Federal law caps your liability for unauthorized credit card charges at $50, provided the issuer gave adequate notice of potential liability and a way to report loss or theft.5Office of the Law Revision Counsel. 15 USC 1643 – Liability of Holder of Credit Card Every major issuer offers zero-liability policies that waive even that $50, but the statutory floor matters with a smaller issuer sticking to the legal minimum. Once you notify the issuer, you have no liability for charges after notification.
Debit Cards
Debit card liability follows a three-tier structure under Regulation E, and timing decides everything:
- Within 2 business days of learning of the loss, your liability is capped at $50 or the total unauthorized charges, whichever is less.
- After 2 business days but within 60 days of your statement being sent, liability rises to as much as $500.
- After 60 days from when the statement was sent, you can be liable for the entire amount of unauthorized transfers occurring after the 60-day window, with no cap.
That unlimited exposure in the third tier is why monitoring debit statements closely matters more than most people realize. A stolen credit card number is an inconvenience. A stolen debit card number you don’t catch for two months can drain your checking account with no legal right to recover the late-reported transactions.6eCFR. 12 CFR 1005.6 – Liability of Consumer for Unauthorized Transfers
How Receipts and Stored Card Data Must Be Handled
Two overlapping regimes control what businesses can do with your PAN after a transaction. A federal statute governs what appears on receipts, and an industry standard governs how card numbers can be stored.
FACTA Receipt Requirements
The Fair and Accurate Credit Transactions Act requires that any electronically printed receipt show no more than the last five digits of the card number and no expiration date at all.7Office of the Law Revision Counsel. 15 USC 1681c – Requirements Relating to Information Contained in Consumer Reports The rule applies to electronic receipts only, not handwritten slips or manual imprints. Willful violations carry statutory damages between $100 and $1,000 per receipt, plus potential punitive damages.8Office of the Law Revision Counsel. 15 USC 1681n – Civil Liability for Willful Noncompliance
PCI DSS Storage Requirements
The Payment Card Industry Data Security Standard, maintained by the PCI Security Standards Council, sets technical rules for any business that stores, processes, or transmits cardholder data. The core requirement for PAN protection is that the full number must be rendered unreadable anywhere it is stored, whether in a database, a backup, a log file, or data sent over a wireless network. Acceptable methods include strong one-way hashing, truncation, index tokens with securely stored pads, and strong encryption.9PCI Security Standards Council. PCI DSS Quick Reference Guide When a PAN is displayed on a screen, PCI DSS 4.0 requires role-based access controls so only personnel with a legitimate business need can see the full number.
PCI DSS is not a law. Enforcement runs through the card networks: a business that suffers a breach and is found noncompliant faces fines from Visa, Mastercard, or the relevant network, higher processing fees, and in severe cases loss of the ability to accept card payments. State data breach notification laws add another layer of potential liability when card numbers are exposed.