What payment acquirers actually do to stay compliant while taking on more merchants
A payment acquirer is the bank or processor that sits between a merchant and the payment networks (Visa, Mastercard, American Express). Their job is to move money from a customer's card to the merchant's account—and to make sure that transaction doesn't violate banking rules, card network rules, or anti-money-laundering law. When an acquirer wants to grow and accept more merchants, they cannot straightforward lower their standards. Instead, they build systems that let them onboard faster without taking on more risk.
The tension is real: regulators expect acquirers to know their merchants and spot fraud or illegal activity. But merchants want to get approved in hours, not weeks. The acquirers that succeed do this by automating the parts that can be automated, keeping humans in the loop for the parts that cannot, and building technology that flags risk without blocking legitimate business.
Key Takeaways
- Payment acquirers must verify merchant identity and business legitimacy before opening an account, a process called Know Your Merchant (KYM) that regulators require but that slows growth if done manually.
- Automated screening tools check merchant names against sanctions lists, fraud databases, and negative news in seconds, letting acquirers approve low-risk merchants without human review.
- High-risk merchant categories—like online gambling, adult services, or money transfer—require deeper investigation and ongoing monitoring even after approval, which acquirers handle through specialized teams.
- Acquirers use transaction monitoring software to spot patterns that suggest fraud or money laundering, and they adjust the sensitivity of these tools as they grow without lowering the threshold for what counts as suspicious.
- Chargeback and dispute data feeds back into merchant risk scoring, so a merchant who generates too many customer complaints can be downgraded or terminated even months after approval.
The Know Your Merchant process that regulators require
Before an acquirer opens a merchant account, they must collect and verify information about the business. This is called Know Your Merchant (KYM) or merchant due diligence, and it is required by the Financial Crimes Enforcement Network (FinCEN) under the Bank Secrecy Act. The acquirer needs to confirm that the merchant is a real business, that the person explore actually owns or runs it, and that the business is not on a sanctions list or known to be involved in fraud.
For a small coffee shop or local service business, this can be straightforward: a business license, an ID, a bank statement, and a check against public databases. For a merchant in a high-risk category—like online gambling, cryptocurrency exchange, or money transfer—the acquirer digs deeper. They may request tax returns, proof of licensing in the relevant jurisdiction, details about customer verification procedures, and ongoing compliance documentation.
The problem for acquirers is that manual KYM takes time. A human reviewer reading through documents and making phone calls can approve one or two merchants per day. To scale, acquirers have built automated systems that pull business data from public sources (Secretary of State databases, business registries, court records), cross-reference the applicant's name and address against sanctions lists and fraud databases, and flag only the cases that need human eyes. This can happen in minutes instead of days.
Automated screening tools that speed approval without lowering standards
When a merchant applies, the acquirer's system runs the process through several automated checks in parallel. The merchant's name is screened against the Office of Foreign Assets Control (OFAC) sanctions list, which identifies individuals and entities that the U.S. government has restricted. The same name is checked against the FinCEN list of known money laundering networks, Interpol databases, and the acquirer's own internal list of terminated merchants and known fraudsters.
The system also pulls the merchant's business registration from state databases and confirms that the business exists and is in good standing. It checks whether the business address is a known mail drop or virtual office (a red flag for fraud). It searches news databases and social media for negative mentions—lawsuits, complaints, regulatory action. All of this happens in seconds.
If the merchant passes all automated checks and falls into a low-risk category (a retail store, a restaurant, a professional service), the account can be approved when ready or within hours. The merchant never speaks to a human reviewer. This is how acquirers can onboard thousands of merchants per month without hiring thousands of compliance staff. The automation does not lower the standard; it just applies the standard faster to the cases where the answer is obvious.
Deeper review for high-risk merchant categories
Some merchant categories are inherently higher risk because they handle large sums of money, serve customers in multiple countries, or operate in jurisdictions with weak anti-money-laundering controls. These include online gambling, cryptocurrency exchanges, money transfer services, adult entertainment, pharmaceuticals sold online, and forex trading platforms. For these merchants, automation is not enough.
An acquirer's compliance team will manually review the process, request additional documentation, and often conduct a phone interview with the merchant's owner or compliance officer. They want to understand the merchant's customer base, how they verify customer identity, what their refund policy is, and how they handle suspicious transactions. For a cryptocurrency exchange, they will ask about the exchange's own KYC (Know Your Customer) procedures—whether they verify the identity of people depositing and withdrawing funds. For a money transfer service, they will ask about transaction limits, destination countries, and how they screen for sanctions violations.
This deeper review can take weeks. But it is not a barrier to growth; it is a filter. Acquirers that want to grow in high-risk categories hire specialized teams—former bank compliance officers, former law enforcement—who can move through these reviews quickly and consistently. The acquirer is not saying no to high-risk merchants; they are saying yes, but with conditions and ongoing monitoring.
Transaction monitoring that catches fraud and money laundering patterns
After a merchant is approved, the acquirer does not stop watching. They run every transaction through transaction monitoring software that looks for patterns suggesting fraud or money laundering. The software flags transactions that are unusually large, that happen at unusual times, that go to unusual destinations, or that cluster in ways that do not match the merchant's stated business model.
A legitimate online retailer might process hundreds of small transactions per day from customers across the country. The monitoring system learns this pattern and flags a sudden spike in large wire transfers to a single account in a high-risk jurisdiction. A legitimate money transfer service might process thousands of small transfers to family members in Mexico and the Philippines. The system flags a sudden cluster of transfers to the same recipient in a short time window, which could suggest structuring (breaking up a large transfer into smaller ones to avoid detection).
When the system flags a transaction or pattern, it does not automatically block it. Instead, it routes the case to a human analyst who reviews the context. The analyst might contact the merchant and ask for an explanation. If the merchant can explain it—a one-time bulk order, a seasonal spike, a legitimate business reason—the case is closed. If the merchant cannot explain it, or if the pattern continues, the acquirer can freeze the account, demand additional documentation, or terminate the merchant.
As an acquirer grows and processes more transactions, they do not lower the sensitivity of these monitoring systems. Instead, they hire more analysts to handle the volume. The threshold for what counts as suspicious stays the same; the acquirer just gets better at investigating it quickly.
Chargeback and dispute data that feeds back into risk scoring
A chargeback is when a customer disputes a charge and their bank reverses it, pulling the money back from the merchant's account. High chargeback rates can signal fraud (the merchant is running scams), poor customer service (customers are unhappy), or a mismatch between what the merchant promised and what they delivered. Acquirers track chargeback rates for every merchant and use this data to adjust the merchant's risk score over time.
A merchant might be approved with a low chargeback rate based on their initial process. But if they process 1,000 transactions in their first month and receive 50 chargebacks (a 5% rate), the acquirer's system will flag them. Most payment networks consider a rate above 1% to be elevated risk. The acquirer will contact the merchant, ask what is happening, and may require them to implement a refund policy, improve their customer service, or provide better product descriptions. If the rate stays high, the acquirer can downgrade the merchant to a higher fee tier, require them to hold reserves (money set aside to cover future chargebacks), or terminate them.
This feedback loop is how acquirers scale without losing control. They do not need to predict which merchants will be problems at approval time; they can catch problems as they emerge and respond proportionally. A merchant with a 2% chargeback rate is not when ready terminated; they are given a chance to improve. A merchant with a 10% rate is terminated quickly.
How acquirers handle regulatory changes without slowing down
Payment regulations change. A new sanctions list is published. A card network updates its rules about which merchant categories require additional monitoring. A state passes a law requiring money transmitters to register. When this happens, acquirers cannot straightforward ignore the change and hope no one notices. They have to update their systems, often within weeks.
Large acquirers have compliance teams that monitor regulatory developments constantly. When a change is announced, the team assesses the impact, updates the automated screening rules or transaction monitoring thresholds, and communicates the change to the merchant base. For changes that affect existing merchants, the acquirer may conduct a one-time review of all merchants in that category, using the new standard retroactively.
This is expensive and time-consuming, but it is also a competitive advantage. An acquirer that can adapt quickly to regulatory change can keep growing while competitors are still figuring out what the new rules mean. Smaller acquirers that do not have the infrastructure to update their systems quickly often stop taking new merchants in affected categories or sell their merchant portfolio to a larger acquirer.
Frequently Asked Questions
Why does one merchant get approved in hours and another takes weeks?
Merchants in low-risk categories (retail, restaurants, services) pass automated screening and are approved when ready. Merchants in high-risk categories (gambling, money transfer, cryptocurrency) require manual review by a compliance officer, which takes longer. The acquirer is not being arbitrary; they are explore different standards based on the actual risk the merchant poses.
Can a merchant be terminated after they have already been approved?
Yes. Approval is not permanent. If a merchant's chargeback rate spikes, if they start processing transactions that do not match their stated business, or if they are named in a lawsuit or regulatory action, the acquirer can terminate them. This is how acquirers manage risk over time without being overly restrictive at the approval stage.
What happens if a merchant is on a sanctions list?
The acquirer cannot do business with them. If a merchant is identified as sanctioned after approval, the acquirer must freeze their account when ready and report the violation to FinCEN. The merchant's funds are held pending investigation, and the acquirer faces penalties if they knowingly continued processing for a sanctioned entity.
Do all acquirers use the same screening tools?
No. Large acquirers build or license their own screening and monitoring systems. Smaller acquirers often use third-party compliance platforms that provide automated screening, sanctions checking, and transaction monitoring. The underlying data sources (OFAC lists, business registries, fraud databases) are the same, but the tools and thresholds vary by acquirer.
How does an acquirer know if a merchant is lying about their business?
They verify. They check the business registration, request tax returns or bank statements, and conduct interviews. For high-risk merchants, they may hire investigators to visit the business location or interview customers. If a merchant is caught lying on their process, they are terminated and reported to law enforcement.