Skip to main content
Should Banks Own Merchant Payment Risk, or Just Monitor It?Payment Ecosystem and Transaction Processing
5 min readFor Bank Information Security Officers

Should Banks Own Merchant Payment Risk, or Just Monitor It?

The Question at Hand

When your bank underwrites a merchant payment processing relationship, you're taking on fraud exposure, reputational risk, and regulatory scrutiny. The FDIC has issued new guidelines on how banks should supervise these relationships, but the guidance doesn't settle the core debate: should you treat merchant payment processing like direct lending, where you own the underwriting, control the exposure, and accept the consequences, or like third-party vendor management, where you set standards, audit compliance, and escalate when things go wrong?

This isn't just a philosophical question. It shapes your BSA/AML program design, your contract terms with payment processors, your internal audit scope, and how you allocate compliance resources. Get it wrong and you're either over-investing in relationships you don't truly control or under-investing in exposure that lands on your balance sheet when a merchant goes bust or commits fraud.

The Case for Owning Merchant Risk

If you underwrite the merchant relationship, you should own the risk. This camp argues that banks can't outsource accountability. When a merchant processes fraudulent transactions, engages in structuring, or operates as a front for money laundering, the SAR obligation falls on the bank. The FDIC examines your BSA/AML controls, not your processor's. Your reputation takes the hit when a data breach traces back to a merchant you enabled.

Under this model, you build merchant underwriting into your credit risk function. You assign CAMELS-style risk ratings to merchant portfolios. You require direct access to transaction data, not summary reports from your processor. You set reserve requirements based on chargeback history and industry risk. You don't just review the processor's due diligence, you conduct your own.

This approach treats fintech partnerships as extensions of your bank, not as arm's-length vendors. If a fintech brings you merchant relationships, you underwrite each merchant as if you'd sourced it directly. You enforce your KYC standards, your transaction monitoring thresholds, and your prohibited business lists. The fintech becomes a referral source, not a risk filter.

The practical advantage: you can act quickly when risk materializes. You don't need to negotiate with a processor to freeze a merchant account or demand additional documentation. You hold the funds, control the settlement timing, and can withhold disbursements if transaction patterns look suspicious.

The Case for Monitoring, Not Owning

The monitoring camp argues that banks shouldn't pretend to control what they can't actually see. Payment processors have direct merchant relationships, real-time transaction visibility, and specialized fraud detection infrastructure. Your bank sees aggregated settlement files, not individual card authorizations. You don't monitor the merchant's website for e-skimming scripts. You don't have staff who understand vertical-specific fraud patterns in online gaming or nutraceuticals.

Trying to "own" merchant risk when you lack operational control creates false confidence. You sign off on underwriting decisions based on stale financial statements and processor summaries, then discover six months later that the merchant pivoted to a higher-risk business model. Your transaction monitoring system flags unusual volumes, but you can't distinguish legitimate growth from card testing because you don't see decline rates or AVS mismatches.

This model treats the processor as a regulated third party under your vendor management program. You audit their KYC procedures, their transaction monitoring capabilities, and their merchant termination protocols. You require quarterly risk reports showing merchant concentrations, chargeback trends, and SAR filings. You set contractual standards for what constitutes acceptable merchant due diligence, then verify compliance through audits.

The fintech partnership becomes a managed channel. You define risk appetite, maximum merchant size, prohibited industries, geographic restrictions, and the fintech enforces those boundaries. You require notification when merchants exceed thresholds or when the fintech files SARs. You reserve the right to exit the partnership if their risk management deteriorates, but you don't pretend to underwrite individual merchants you've never met.

The practical advantage: you can scale payment processing relationships without building specialized expertise in every merchant vertical. You use the processor's fraud detection models, their industry benchmarking data, and their experience spotting synthetic identity fraud in merchant applications.

Where Practitioners Actually Land

Most banks operate in the messy middle. You own some aspects of merchant risk while relying on processors for others, and the division of responsibility shifts based on merchant size, relationship history, and how the partnership was structured.

For high-value merchants or those in elevated-risk industries, you typically conduct independent due diligence. You review business licenses, verify beneficial ownership, and run enhanced screening against OFAC lists and adverse media. You might require personal guarantees from merchant principals or set higher reserve percentages.

For smaller merchants onboarded through fintech partnerships, you rely more heavily on the processor's underwriting but require transparency into their methodology. You want to see their risk scoring model, understand their prohibited business list, and review their transaction monitoring rules. You audit a sample of merchant files annually to verify their due diligence actually matches their documented procedures.

Your BSA/AML program treats processor relationships as a distinct risk category. You file SARs when your transaction monitoring flags suspicious patterns in aggregated merchant settlements, but you also require processors to notify you when they file merchant-specific SARs. You don't duplicate their transaction-level monitoring, but you do analyze settlement trends for structuring patterns or sudden volume spikes that might indicate bust-out fraud.

Our Take

The FDIC's guidance reinforces what examination findings have shown for years: you can't outsource supervisory accountability. But that doesn't mean you need to replicate every control the processor maintains.

Build your program around what you can actually verify. If you don't have access to individual transaction data, don't pretend your monitoring program provides transaction-level fraud detection. Instead, focus on what you can measure: merchant concentration risk in your portfolio, chargeback rates relative to industry benchmarks, and whether processor controls are operating as designed.

Require processors to give you the data you need for your own BSA/AML obligations. That means aggregated transaction reporting that lets you spot structuring, beneficial ownership documentation that supports your KYC requirements, and timely notification of merchant terminations or SAR filings. Write these requirements into your contracts, not your policies, so you can enforce them.

Accept that some merchant relationships carry risk you can't fully control, and price accordingly. If a fintech partnership brings you merchant processing volume but limits your visibility into individual merchant underwriting, that's a higher-risk relationship. It might still make business sense, but don't treat it like a direct merchant relationship you underwrote yourself.

The FDIC isn't asking you to become a payment processor. They're asking you to know what risks you're taking on, verify that someone is actually managing those risks, and maintain the ability to exit relationships when risk exceeds your appetite. That's a monitoring standard you can meet without pretending to own risks you can't see.

You Might Also Like