A merchant-acquiring compliance function your acquiring partner will sign off on.
Merchant underwriting, KYB onboarding, risk tiers, monitoring and governance for payment facilitators and payments companies that board merchants through an acquiring partner. Written as policy, run as an operating model, and evidenced so your partner can see it works.
Your Merchants Are Your Acquiring Partner's Risk
A payment facilitator boards merchants under its own relationship with an acquiring partner. The acquirer, and the bank behind it, rely on your underwriting, your KYB files and your monitoring to decide who gets to accept payments.
When a merchant turns out to be something other than what it said it was, the chargebacks, the fraud losses and the card network and NACHA rule consequences generally land on your acquiring partner and its bank first. Then they land on you.
So your acquiring partner reads your merchant program the way a bank reads a fintech's BSA/AML program. Is the policy written? Are the risk tiers defensible? Do the files match the policy? Does monitoring catch drift? Does anyone with authority act on it?
Merchant acquiring and payfac compliance is part of our bank and fintech compliance practice. We have built this function for a venture-backed U.S. payments and financial technology company.
Regulator-facing experience: direct engagement with FinCEN, state banking departments, FDIC and OCC exam teams and the DOJ, plus Big Four and national-firm validation work.
Where Clients Start
The signal that it is time to formalize merchant compliance is usually specific. Start where you are.
Onboarding with an acquiring partner
You are moving to a payment facilitator model, or signing a new acquiring partner, and its review asks for your underwriting policy, risk tiers, prohibited list and monitoring before it will board your first merchant.
Entering higher-risk verticals
Sales wants subscription merchants, nutraceuticals, CBD, gaming or digital assets. Your partner will allow some of them only under enhanced underwriting standards you have not written yet.
An acquirer finding
Your acquiring partner's review found thin KYB files, exceptions without approvals, or chargeback escalations that stalled. You need a remediation plan the partner will accept, and evidence that it closed.
Growth outrunning underwriting
Merchant volume is growing faster than the team that reviews it. Decisions live in inboxes, exceptions pile up, and nobody can show the partner a clean picture of the portfolio.
Six Parts of a Merchant Compliance Function
An acquiring partner signs off on a function, not a document. We build each part so it is written, owned, run and evidenced, and so each part feeds the next.
Underwriting Policy and Risk Tiers
- Risk appetite by vertical, business model and delivery timeframe
- Tier criteria, and what each tier requires before approval
- Approval authority by tier, with escalation to committee
- Risk mitigants such as reserves, volume caps and delayed funding
- Re-underwriting cadence set by tier
KYB Onboarding Operating Model
- Legal entity verification, beneficial owners and control persons
- Sanctions screening of the business and its principals
- Website, product, pricing and refund policy review
- Merchant category assignment checked against the actual business
- Who does what, in what order, with file standards and service levels
Prohibited and Restricted Merchants
- A prohibited list aligned to your partner's and the card networks' rules
- A restricted list, with enhanced underwriting conditions for each vertical
- How a restricted merchant is approved, and who can approve it
- How the lists are kept current as rules and appetite change
Monitoring and Escalation
- Volume, ticket size and velocity against the underwritten profile
- Chargeback and fraud ratios against card network monitoring program thresholds, and refund trends
- Business model drift and transaction laundering indicators
- Escalation paths: holds, reserves, limit changes and termination
- Escalations that reach your acquiring partner with the facts it needs
The Governance Layer
- A credit and compliance committee with a charter, quorum and minutes
- Exceptions that are approved, time-limited, tracked and reported
- Portfolio reporting to your acquiring partner on a set schedule
- Board reporting and annual policy review
Card-Network and NACHA Oversight
- Card network rules and the NACHA Operating Rules mapped to owners and controls
- Rule change tracking, so new obligations reach the right team
- ACH return rates and, where they apply, third-party sender obligations monitored
- PCI DSS status tracked and coordinated with your QSA
Oversight, not assessment. Our card-network, NACHA and PCI DSS work is at the oversight level: we map the rules to your controls, test that the controls run, and coordinate with the specialists who assess and validate. We do not perform PCI DSS assessments or issue attestations.
Verticals That Need Enhanced Underwriting
Many acquiring partners will not say yes or no to these verticals outright. They will ask what your enhanced standard is. Each partner sets its own appetite, and the standard has to meet it.
| Vertical | Why it needs more | What the underwriting file should show |
|---|---|---|
| Subscription and continuity billing | Recurring charges customers forget or never clearly agreed to drive disputes, and card network rules and state automatic renewal laws set disclosure and cancellation expectations. | Checkout and trial terms as the customer sees them, cancellation flow, billing descriptors, refund and chargeback history, and ongoing dispute ratio monitoring. |
| Nutraceutical | Health claims, trial offers and aggressive marketing often draw regulatory scrutiny and high chargeback rates. | Product and claims review, marketing and affiliate practices, fulfillment and refund terms, prior processing history and reserve terms where warranted. |
| Cannabis and CBD | Federal and state law diverge, and acquiring partners draw the line in different places for marijuana-related businesses and hemp-derived products. | What the product actually is, supporting documentation such as lab results, state licensing where it applies, where the merchant sells and ships, and the partner's written appetite. |
| Gaming and betting | Legality depends on the state and the activity, and federal rules on unlawful internet gambling generally expect payment system participants to have policies and procedures reasonably designed to identify and block restricted transactions. | State licenses for each jurisdiction served, geolocation and age controls, correct merchant coding, and the monitoring that confirms activity stays inside the license. |
| Digital assets | A merchant that buys, sells or holds crypto for customers may itself be a money transmitter, and brings sanctions and fraud exposure with it. | The merchant's own licensing and FinCEN registration position, its AML and sanctions program, wallet and on-ramp flows, and the partner's appetite for the activity. |
Where a merchant's licensing is in question, we flag it for your counsel and ask the merchant to document its own position. For your own licensing position as a payments company, start with money transmitter licensing. We walk through how tier criteria get written in merchant risk tiers for payment facilitators.
What Your Acquiring Partner Is Reading For
Files that match the policy. An acquirer review usually samples merchant files. It checks that each file meets the standard for its tier, that exceptions carry an approval, and that restricted merchants got the enhanced review your policy promises.
Monitoring that acts. Alerts are expected. What partners look for is what happened next: who reviewed the merchant, what was decided, how fast, and whether the partner heard about it when it should have.
Governance with teeth. A committee that meets, minutes that show real decisions, and someone with the authority to decline or terminate a merchant the business wants to keep.
The bank behind the acquirer. Card acquiring generally runs on a bank's card network membership, and that bank's examiners can review the third-party programs it supports. Findings travel up the chain.
If you are that bank, start with fintech partner oversight for sponsor banks. If you are a payments company facing bank diligence as well, start with sponsor bank readiness.
Top 25 U.S. Banking Institution
Conducted comprehensive 2LOD compliance testing and transactional reviews across the Banking division. Identified deficiencies and recommended actionable remediation strategies.
Assess, Write, Build, Evidence
We scope timing after the assessment, once we know what exists and what your acquiring partner expects, instead of quoting a number blind.
- 01
Assess
Read the program the way your acquiring partner will. We review policy, tiers, a sample of merchant files, monitoring output and governance records against the partner's requirements, and rank the gaps by what the partner will test first.
- 02
Write
Draft the underwriting policy, tier criteria, prohibited and restricted standards, procedures and committee charter, in language your underwriters can apply and your partner can test.
- 03
Build
Stand up the operating model: onboarding workflow and file standards, monitoring rules and thresholds, escalation paths, the exceptions log and the reporting pack your partner receives.
- 04
Evidence
Test merchant files and alerts against the new standard, document quality assurance, and assemble the evidence your acquiring partner needs to sign off.
Once the function runs, someone senior has to own it and the partner relationship. If you do not have that person yet, a fractional chief compliance officer can take it on.
Reading for Payments Companies Building a Merchant Program
Merchant risk tiers for payment facilitators: how underwriting standards get written
For payfacs writing, or rewriting, the tier criteria their acquiring partner will test.
Merchant risk tiers for payment facilitatorsThe partner bank compliance conversation fintech founders keep avoiding
For fintechs preparing for, or already inside, a bank partner relationship.
Partner bank compliance for fintechsQuestions we hear
What does an acquiring partner require from a payfac's compliance program?
Each partner writes its own requirements, but most expect the same core: a written merchant underwriting policy with risk tiers, KYB onboarding that verifies the business and the people who own and control it, prohibited and restricted merchant standards aligned to the partner's and the card networks' rules, and monitoring of transactions and merchants after boarding.
They also expect governance that shows who approves exceptions and who can terminate a merchant, regular portfolio reporting, prompt escalation of problem merchants, audit rights over your files, and evidence that you track card network and NACHA obligations and your PCI DSS status.
How do you tier merchant risk?
We start from your acquiring partner's appetite and your own. Then we set criteria a reviewer can apply the same way every time: the vertical and business model, how and when the customer receives what they paid for, expected volume and ticket size, refund and chargeback history, ownership and control, and how the merchant sells.
Each tier carries its own requirements: what the file must contain, who can approve, which mitigants apply, such as reserves or volume caps, and how often the merchant is re-underwritten. We cover the method in merchant risk tiers for payment facilitators.
Which verticals need enhanced underwriting?
The ones we are asked about most are subscription and continuity billing, nutraceuticals, cannabis and CBD, gaming and betting, and digital assets. Each has its own mix of dispute, fraud, legal and reputational risk, and acquiring partners set different appetites for each.
Enhanced underwriting means a written standard per vertical: what extra evidence the file needs, who can approve it, which mitigants apply, and what monitoring follows boarding. Some verticals your partner will not accept at all, and your prohibited list should say so plainly. The table above sets out enhanced underwriting standards by vertical.
Do you handle PCI DSS?
At the oversight level. We track your PCI DSS status and your sub-merchants' validation, map the requirements to owners in your compliance and governance program, and coordinate with your Qualified Security Assessor (QSA) and your security team.
We do not perform PCI DSS assessments or issue reports on compliance or attestations of compliance. That work sits with your QSA and your own security team.
Can you help after an acquirer finding?
Yes. We read the finding and the files behind it and trace the root cause, whether that is policy, process, people or systems. Then we write a remediation plan with owners and dates your acquiring partner can hold you to.
We help you fix what failed and test that the fix works before you report it closed, so the closure comes with evidence. We support you in the partner relationship; your management team answers for the program. Ethixera Advisory is not a law firm and does not provide legal advice, so questions about your contract with the acquirer go to your counsel.
An acquiring partner review on the calendar?
Tell us where your merchant program stands and what your acquiring partner has asked for. We will tell you what is missing and what it takes to close the gaps.
