← Back to InsightsPayments

Merchant risk tiers for payment facilitators: how underwriting standards get written

Tiers decide which merchants get a standard file, which get enhanced review and which you decline. Here is how to write criteria a reviewer can apply consistently, what each tier should require, and the evidence your acquiring partner will test.

When a payment facilitator signs with an acquiring partner, the merchant underwriting policy is typically among the first documents the partner reads, and the risk tiers get close attention. Reserves, monitoring thresholds and review cycles commonly key off the tier.

The weak points are rarely the number of tiers. They are criteria no two underwriters apply alike, tiers that change nothing downstream, and files that do not show the tier was applied. Each partner sets its own appetite, so treat what follows as a method, not a template.

Why your acquiring partner cares how you tier

A payment facilitator is sponsored into the card networks by its acquirer, and under network rules the acquirer generally answers for the merchants the payfac boards. When one of them runs up disputes, commits fraud or sells something the networks prohibit, the networks typically look to the acquirer first, and an acquiring bank answers to its own examiners. Your tiers become part of the acquirer's risk controls.

So acquiring agreements commonly set minimum standards: a prohibited list, required KYB elements, merchant types that need the acquirer's approval or network registration, reporting and audit rights. Your tiers have to sit inside the partner's appetite, not beside it.

Whether your model needs a money transmitter license turns largely on how funds flow and on state law. That question belongs with your counsel, as Ethixera Advisory is not a law firm. We cover the compliance side under money transmitter licensing.

Criteria a reviewer can apply the same way twice

Tiers express appetite, so start with three lists: never board, board only under conditions, and the most exposure you will hold for one merchant. Then write criteria that name something observable in the file. “Established business” is an adjective. “Two years of processing statements with dispute ratios inside our standard” is a criterion.

CriterionWhat it measuresWhat typically moves a merchant up
Vertical and business modelThe dispute, fraud, legal and reputational risk of what the merchant sells, and how.A restricted vertical, card-not-present sales, recurring billing or regulated products.
Delivery timeframeHow long customers wait for what they paid for, and so what is owed back if the merchant fails.Payment taken weeks or months ahead: pre-orders, prepaid memberships, travel, events.
Volume and financial strengthThe scale of potential loss, and whether the merchant can absorb refunds and disputes.Projections that do not fit the business's age or size, or bank statements that do not support them.
Processing historyHow the merchant has performed with other processors.High dispute or refund ratios, a prior termination, or no history.
Ownership and controlWho is accountable, and whether anyone raises sanctions or fraud concerns.Ownership that is hard to trace, adverse history on a principal, a recent change of control.
Sales and marketingHow customers are found and what they are told before paying.Free-trial offers, affiliate or telemarketing channels, claims the merchant cannot support.

Programs commonly combine a scorecard, which weights each criterion and sums to a tier, with override rules that force a tier regardless of score: any restricted vertical is at least elevated, any unresolved sanctions concern is a decline. Overrides matter because a score alone lets a strong answer on volume hide a weak one on ownership. Write the method down so a reviewer outside the team could reach the same tier from the same file.

For ownership, a common benchmark is the beneficial ownership standard in FinCEN's customer due diligence rule, written for banks and certain other financial institutions: each individual owning 25 percent or more, directly or indirectly, plus one individual with significant control. OFAC sanctions apply to U.S. persons generally, so programs typically screen every merchant and its principals, whatever the tier.

What each tier requires

A tier that changes nothing downstream is a label, not a control. Each tier should set the file contents, approver, mitigants, monitoring and re-underwriting cycle. The structure below is illustrative.

TierTypical profileWhat the file needsWho approvesCommon mitigants
StandardLower-risk vertical, delivery at payment, volume that fits the business, owners verified.Core KYB: entity, owners and control person, sanctions screening, website and product review, merchant category checked against the business.An underwriter under delegated authority.Standard monitoring.
ElevatedOne or two elevated criteria, such as recurring billing or some future delivery.Core KYB plus processing and bank statements, and refund and cancellation terms.A senior underwriter or credit lead.Volume or ticket caps, and a reserve where history is thin.
High or restrictedA restricted vertical, significant future delivery, or explained adverse history.The enhanced standard for the vertical, plus anything the partner requires.A credit and compliance committee, and the partner where the agreement requires it.Reserves, delayed funding, caps and tighter monitoring.
DeclineA prohibited vertical, unverifiable owners, an unresolved sanctions concern, or anything outside the partner's appetite.The reason, recorded.As the policy sets.Not boarded.

Approval authority. Authority should rise with the tier, and no one should approve a merchant they are paid to sell. Exceptions go above the normal approver, carry an expiry date, sit on a log, and reach the partner when the agreement requires.

Restricted verticals. Each needs its own written standard. Common examples include subscription and continuity billing, nutraceuticals, cannabis and CBD, gaming and betting, and digital assets. Some carry their own rules. The card networks require acquirers to register certain higher-risk merchant types. Regulation GG, which implements the Unlawful Internet Gambling Enforcement Act, generally requires non-exempt card system participants to have policies and procedures reasonably designed to identify and block or otherwise prevent restricted transactions, commonly through merchant due diligence and accurate merchant coding. See enhanced underwriting standards by vertical.

Monitoring keeps the tier honest

A tier is set at boarding, largely on the merchant's own projections. Monitoring compares actual activity with the underwritten profile: volume, ticket size, velocity, refunds, disputes, fraud, and signs the business has changed. Transaction laundering, where a merchant processes payments for a business never underwritten, deserves its own rule.

The card networks run dispute and fraud monitoring programs whose thresholds change. Take current figures from your partner and set your own triggers below them, so you act before a merchant enters a network program. If you also process ACH payments for merchants, the NACHA Operating Rules add return rate thresholds and, where you act as a third-party sender, obligations of their own.

Each trigger should name the response, from re-tiering to reserves, holds or termination, and who decides. Re-underwriting runs on two clocks: a schedule set by tier, and events such as a change of ownership, a new product or adverse information.

What an acquiring partner tests

An acquirer review typically starts with the policy, then samples merchant files. Reviewers commonly check for:

  • Tier criteria with a current approval date.
  • Files where the tier on record matches the criteria as written.
  • Restricted merchant files with every enhanced item the standard requires.
  • Approvals and exceptions signed at the right level, with exceptions dated and time-limited.
  • Monitoring alerts with a decision, a date and a named decision-maker.
  • Re-underwriting on schedule, and event reviews that fired.
  • Committee minutes and partner reporting that show real decisions, including declines and terminations.

My background is in this kind of testing: reading a written due diligence standard, pulling a sample and checking each customer file against it. That work was mostly for banks, and the method carries over to merchant files. A common finding is not a missing policy but files that do not show it was followed. So we write tier standards a reviewer can test a file against, and test a sample of files before the partner does. We bring that approach to payments work, including for a venture-backed U.S. payments and financial technology company.

Multi-Year Consent Order

Top 10 U.S. Financial Institution

Directed BSA/AML testing and MRA validation across a multi-year remediation program. Managed quality assurance across the KYC customer file refresh program evaluating CDD/EDD standards.

Engagement via Big 4 Advisory Firm

What to do this quarter

  1. Get your acquiring partner's current requirements in writing, from prohibited lists to audit terms.
  2. Write your appetite as three lists: never board, board under conditions, and maximum exposure per merchant.
  3. Rewrite each criterion so it names something observable, and document the scoring and override method.
  4. Set each tier's file, approver, mitigants, monitoring and review cycle, so each asks for more than the one below.
  5. Write an enhanced standard for every restricted vertical you board or plan to.
  6. Test a sample of recent files against their tier, and log every open exception with an owner and an expiry date.
  7. Ask your counsel to confirm your licensing position and the audit and termination terms in your acquiring agreement.

Written this way, tiers let underwriters move quickly on ordinary merchants and show the partner why each merchant sits where it does.

Related: how Ethixera builds merchant acquiring and payment facilitator compliance programs, and the wider bank and fintech compliance practice they sit in.

Writing or rewriting your merchant risk tiers?

Tell us what your acquiring partner has asked for and how your tiers work today. We can help you see where the criteria, files and approvals may not hold up, and what it takes to fix them.