Merchant Acquiring, Marketplaces and Payment Facilitators
Merchant acquiring enables a merchant to accept card payments and receive settlement under the relevant scheme and contractual arrangements. A payment facilitator can onboard sponsored merchants under an acquiring arrangement. A marketplace may connect buyers and sellers, arrange payments or act as merchant of record. These models differ; a platform's commercial label does not establish who sells goods, holds funds or bears regulatory duties.
Know the actual merchant and underlying activity. Transaction laundering occurs when one merchant processes payments for another undisclosed or unauthorised business, concealing the true seller or product. A legitimate-looking website and low chargeback rate do not prove that submitted transactions match the approved business.
Bank AML duties, payment-service regulation, card-scheme requirements, consumer protection and fraud controls overlap but are distinct. A scheme merchant category code (MCC) is useful context, not a legal determination of the AML perimeter or proof of legitimate activity. National law and the actual service determine regulatory duties.
At onboarding establish merchant ownership, business model, goods/services, websites, expected volumes, geography, settlement account and any sponsored merchant or seller structure. Delegation to a facilitator does not remove the acquirer's own applicable obligations or its need for adequate oversight and data.
Follow the sale before following the payment
An acquiring investigation begins with the commercial transaction. Who offered the goods, who contracted with the buyer, who delivered the goods or service, and who earned the receivable? Those questions can produce different names in a platform model. The buyer may visit a marketplace, purchase from an independent seller, see the marketplace name on a statement, and receive delivery from another business. That can be legitimate. The bank needs an explanation of those roles that remains consistent across the customer contract, checkout experience, submitted transaction and payout record.
Consider two arrangements. In the first, a platform buys inventory and sells it to buyers on its own account. Its suppliers are ordinary trade creditors, although supplier and goods risks may remain relevant. In the second, the platform arranges sales by hundreds of independent sellers and distributes proceeds to them. Looking only at the platform company misses a material part of the second arrangement. The control design should follow the actual rights, obligations and value movement, rather than reusing the first arrangement's customer questionnaire because both businesses call themselves marketplaces.
The acquirer, processor and facilitator also have different functions. An acquirer participates in the acceptance and settlement arrangement. A processor can supply technical routing without becoming the seller or the holder of every customer relationship. A facilitator can operate a sponsored-merchant model within contractual and scheme arrangements. A payout provider can distribute funds after card settlement. Each role affects available data, intervention points and obligations. The same corporate group may perform several roles through different legal entities; the assessment needs entity-specific facts.
The resulting map should show the customer of the bank, the contracting merchants or facilitator, the approved seller populations, relevant processors, collection and settlement accounts, payout arrangements and places of operation. Record where those facts came from and who confirmed them. A relationship manager's description is useful context, but the operating agreement, sample transaction records and settlement instructions should support the picture. If the commercial account of the model and the actual transactions disagree, that disagreement becomes a review question.
Establish a merchant profile that can be tested
An onboarding profile should explain enough of the merchant's economics for later monitoring to recognise meaningful changes. Product range, typical order size, delivery timing, customer geography, distribution channel, seasonality, anticipated refunds and payout arrangement can matter. The objective is a plausible business story supported by proportionate evidence. A small local shop should not be forced into the same information burden as a facilitator launching several cross-border seller categories. Conversely, a large platform cannot use a generic description such as online services to avoid explaining its business.
Merchant category codes help organise acceptance and risk analysis, but they are a coarse representation. A merchant classified as a general retailer can sell several types of goods with different legal or financial-crime implications. The code should be compared with the actual website, inventory or service proposition and known transaction patterns. A mismatch may arise from a genuine reclassification error, an expanding product range or concealed activity. Analysts should establish which explanation is supported before calling it laundering.
Website review should examine the path a real buyer would take: advertised product, checkout, legal seller, descriptor, delivery promise, returns policy and contact details. A static screenshot of a home page can miss a checkout that sends value to a different seller or a storefront that redirects certain customers. Access can also vary by geography, language or customer login. The bank should record the limits of its review and use additional evidence when those limits matter. It should not represent a crawler's successful connection as verification of every underlying sale.
The settlement account is another proposition to verify. Identify who owns it and why that party should receive acquiring proceeds. A shared account can reflect a disclosed group treasury arrangement or a legitimate payout intermediary, but it can also conceal unrelated recipients. The reviewer needs the commercial explanation, authority and applicable contractual or legal conditions. Matching a bank-account name to a merchant name is useful; a mismatch should be explained rather than automatically rejected or ignored.
Risk exists in the transformation from gross sale to net payout
The payment lifecycle can contain authorisation, capture, clearing, settlement, reserve allocation, chargeback, refund and seller payout. Those events do not occur at the same time and do not have the same accounting meaning. An authorisation is not evidence that the merchant has received final proceeds. A captured transaction can later be refunded or disputed. A net settlement credit can conceal large gross sales and substantial offsets. Monitoring that uses only net amounts can therefore miss economically significant activity.
For a fictional daily example, a platform records 400,000 of gross captured sales, 25,000 of refunds, 8,000 of fees and 12,000 added to a reserve, with other agreed adjustments excluded from the example. The resulting 355,000 settlement is arithmetically consistent. That arithmetic does not establish which sellers generated the sales, whether refunds went to the original purchase instruments, whether the goods existed, or whether the reserve allocation followed the contract. Reconciliation should preserve both financial agreement and the underlying identity and activity questions.
Payout timing adds another layer. A marketplace can receive a single settlement today and distribute seller proceeds tomorrow, while holding some proceeds because delivery is incomplete. A payout account may change between sale and distribution. The bank needs effective-dated links, so an investigator can establish the account instruction that applied to each payout rather than seeing only today's account master. Historical links matter especially when a seller closes, merges, changes ownership or reappears under another trading name.
Risk controls should have defined intervention points. The bank may be able to stop a new merchant from going live, decline an unapproved routing arrangement, suspend a particular payout under lawful authority, or refer a settled transaction for investigation. It may not be able to reverse a completed sale simply by changing the merchant status in an onboarding system. Requirements should describe the payment and ledger states affected by each action and the limits imposed by law, scheme rules and contracts.
Understand transaction laundering without confusing it with every anomaly
Transaction laundering involves an approved merchant or payment relationship being used to process activity for an undisclosed or unauthorised business. The concealed business might sell prohibited goods, avoid required onboarding, evade contractual restrictions or hide the actual recipient of proceeds. The mechanism is more specific than a merchant having poor financial records or receiving many complaints. An investigation should seek evidence connecting submitted transactions to the concealed commercial activity.
Useful evidence can include an unexpected checkout domain, an order receipt naming another seller, descriptor patterns, shared technical infrastructure, inconsistent fulfilment records, settlement instructions to unrelated parties, or communications showing one merchant accepts payments for another. Each has benign alternatives. Shared hosting is common; groups use central treasury accounts; descriptors can be abbreviated; fulfilment can be outsourced. The analyst should test those alternatives and avoid claiming that a relationship graph alone proves a disguised merchant.
Chargeback and fraud metrics provide part of the picture. High disputes can identify nonexistent goods or deceptive sales, but they can also arise from genuine service failures. Low disputes can coexist with laundering if buyers receive what they intended to buy and have no reason to complain. Scheme performance, fraud losses and AML understanding therefore need separate measures and a route to combine evidence when a case crosses those boundaries.
The response should reflect the established concern. Missing seller data can justify additional information, delayed activation or an approved restriction. Evidence of deliberate concealment can require a deeper investigation and decisions under applicable reporting rules. Confirmed sanctions exposure needs its own legal disposition. Commercial termination, scheme notification and suspicious reporting are separate decisions with separate owners. A bank should preserve that separation even when the same incident triggers all three.
Use delegated onboarding with explicit control boundaries
A facilitator's speed depends partly on performing onboarding close to the seller. That can improve local knowledge and customer experience, but it can leave the acquirer dependent on data it does not hold. The bank should understand what has been delegated, what evidence standards apply, which exceptions require bank approval, and how records are retrieved. A contractual promise of compliance is not enough if the facilitator cannot demonstrate coverage or the bank cannot obtain the information required for its own duties.
Distinguish an operational service provider from a third party relied upon for specified CDD measures where local law permits reliance. FATF Recommendation 17 supplies a standards framework for reliance, but national law determines its availability and conditions. An outsourcing contract does not automatically create lawful reliance. Neither structure should be described as removing the bank's own responsibilities. Record the legal classification of the arrangement and the actual evidence and oversight that support it.
Sponsored merchants need stable identities and meaningful change controls. A rejected seller should not re-enter unnoticed by changing its contact address, website or account identifier. At the same time, similar names or shared professional advisers should not automatically exclude legitimate sellers. The control should use reliable identifying attributes, history and documented relationship analysis, with a review path for uncertain matches. Approved seller populations should reconcile with live transaction populations, including migrated portfolios.
Practitioner decision standard
Before approving or reviewing an acquiring relationship, be able to explain the commercial model, actual seller population, bank role, applicable obligations, evidence coverage, funds flow and available control points. Then explain the limitations: information not visible in normal messages, records held by another party, unverified assertions and decisions requiring specialist interpretation. Those limits should shape conditions, oversight and testing rather than disappear behind a green onboarding status.
The strongest file allows another practitioner to reconstruct the reasoning. It identifies facts, sources, legal or policy basis, unresolved gaps, approved conditions and downstream controls. It also shows how the bank will notice that the original model changed. An acquiring relationship is understood when the bank can connect the seller's activity to the submitted transaction and lawful recipient of proceeds, while keeping fraud, scheme, AML and sanctions decisions within their proper scope.
Merchant-to-payout visibility
Map the buyer payment, merchant identifier, facilitator, acquirer, settlement account, platform ledger and final seller payout. Distinguish gross sales, refunds, fees, chargebacks, reserves and net payouts. A single settlement credit can represent many sellers and transactions; the bank needs sufficient visibility to assess its actual exposure.
Monitor changes in website activity, MCC, transaction size, countries, refund patterns, descriptor use and payout destinations. Compare them with the approved profile and investigate discrepancies. High refunds may reflect genuine returns, abuse or laundering; the pattern and context matter.
For sponsored merchants, require governed onboarding information, change notifications and retrievable records appropriate to the arrangement. Test whether closed or rejected sellers can return under a new identifier. A facilitator's aggregate dashboard cannot prove submerchant identity or risk coverage.
When a merchant concern arises, coordinate fraud, scheme, AML and legal owners. Reserve retention and settlement withholding have contractual and legal limits and are not interchangeable with sanctions freezing. Any SAR decision remains separate from scheme reporting or commercial termination. Preserve relevant data and plan outstanding refunds, chargebacks and lawful payout obligations.
Build the identity links before designing the alerts
An acquiring control estate needs several identities, each with a defined meaning. The legal customer identifies the bank relationship. A merchant identifier identifies the acceptance arrangement. A submerchant or seller identifier identifies an underlying business within a sponsored or marketplace population. A website or application identifier identifies a sales channel. A settlement-account identifier identifies where acquiring proceeds first arrive. A payout-beneficiary identifier identifies who ultimately receives a distribution. Those identifiers can be linked, but they should not be treated as substitutes for one another.
For each link, preserve an effective period and source. A merchant can operate several websites and a website can change legal operator. A seller can have several payout accounts. One payout account can belong to a disclosed group service company serving several sellers. The data model should represent those relationships without forcing an artificial one-to-one mapping. It should also retain an unresolved state when the relationship is not adequately established. Inserting a convenient default company into every missing seller field produces apparent completeness while destroying analytical value.
Identity resolution should support investigation rather than silently rewrite history. Suppose two seller records are discovered to belong to the same legal business. The system can create a governed relationship and, where appropriate, merge current servicing records, but historical transactions should remain traceable to the identifiers originally submitted. Conversely, a reused identifier must not cause a new seller to inherit the old seller's verification and risk approvals. Preserve the original record, reason for change, approving role and downstream consequences.
Define data quality against the control that needs the data
Required data depends on the service, jurisdiction and control purpose. A bank does not need every conceivable website or device field for every merchant. It does need the information required to identify its customer, understand relevant underlying activity and fulfil applicable duties. A data contract should state which seller populations are included, required fields, conditional fields, source, timeliness, update events, retrieval rights and exception handling. The contract should distinguish information supplied for legal obligations from contextual information used under bank policy.
Measure completeness using the correct denominator. If the facilitator reports that 99 percent of active sellers have a current payout account, establish whether active means approved, transacting, unsettled or visible in the reporting database. A dormant seller receiving a refund-related adjustment can still matter. A seller created yesterday may be outside a periodic report but already transacting. Coverage should reconcile against the actual population relevant to the control, with documented exclusions and their reasons.
Quality is also semantic. A populated country field can mean incorporation, seller residence, website audience, shipping destination or payout-bank location. Those are different facts. A populated business-type field can be a customer assertion rather than an independently corroborated classification. Source lineage allows analysts to judge the evidential strength of each field. It also helps delivery teams avoid making legal decisions from data originally collected for a different commercial purpose.
Reconcile settlement without erasing commercial detail
Reconciliation should connect transaction records, settlement batches, merchant balances and payouts. Start with the underlying transaction status and currency. Identify fees, refunds, disputes, reserves and other adjustments separately, including their dates and contractual basis. Then explain the net position. A single unexplained adjustment category can hide transactions, operational errors or inappropriate value transfers even when the final bank balance agrees with the platform's total.
Currency conversion needs its own traceability. If sales occur in one currency and sellers are paid in another, preserve original amounts, applied rates, conversion dates and fees. An apparent payout discrepancy can result from ordinary conversion and timing, while an unexplained difference can reveal a data or accounting defect. Financial-crime analysts should have access to the relevant reconciliation explanation, rather than treating every difference as suspicious or accepting every difference as an exchange-rate effect.
Exceptions should reach the correct owners. A duplicate settlement batch may be an operational incident. A payout account changed without verification may involve fraud or a control breach. A merchant systematically receiving proceeds for unidentified sellers may require AML review. A designated recipient may require sanctions action. The same reconciliation exception can trigger more than one route, but it should retain the factual record and distinct decisions. Do not allow an operations ticket marked resolved to close an AML investigation automatically.
Model refunds as movements of value
A refund is not merely a negative sale. Identify the original purchase, initiating merchant, refund reason, destination, amount, timing and relationship to the original payment instrument. An ordinary refund should be explainable from the commercial event and permitted routing. Departures may be legitimate under applicable arrangements, but they need the right controls. An analyst should not assume that a refund to a different instrument is laundering without understanding scheme, contractual and operational possibilities.
Patterns can become meaningful when linked. Several merchants receiving card purchases and refunding to one destination may indicate a shared service arrangement, an operational migration or an abusive value-transfer mechanism. Investigate ownership, customer identity, purchase evidence and refund instructions. The strongest case explains both the observed pattern and the reasons ordinary explanations do or do not fit. A high refund ratio alone gives less information than a coherent sequence connecting purchase, refund and recipient.
Closure does not remove refund and dispute obligations. A suspended merchant can still have buyers awaiting legitimate refunds and disputes arriving later. The bank should understand what remains executable, who funds outstanding obligations, what records remain available and which restrictions apply. A system that deletes merchant access and records at termination can prevent both customer servicing and later investigation. Plan those states before an incident forces the question.
Connect website intelligence to actual transactions
Website analysis is most useful when it is tied to the merchant identity and transaction evidence. Record the reviewed domain, access conditions, date, relevant pages and visible seller information. Compare the offered goods and checkout flow with the approved profile. If a merchant submits transactions for a new domain, establish whether the domain belongs to the same business, represents a disclosed sales channel or introduces another seller. An alert should present that relationship question clearly.
Automated tools have limitations. A crawler may fail because of ordinary access controls, regional restrictions or technical changes. A successful crawl may cover only a public catalogue and miss a restricted checkout path. Classifiers can misunderstand language, context or product descriptions. Escalation should be proportionate to the risk and evidence available. The bank should test tool coverage and accuracy for the populations it serves rather than assuming that vendor detection categories correspond exactly to local legal prohibitions.
Analysts should preserve snapshots or other evidence according to applicable retention and privacy rules. A website can change between alert and investigation. Recording only a live URL can leave a reviewer unable to reconstruct the original concern. Preserve the relevant observation and its limitations, while avoiding unnecessary collection of unrelated personal data. The evidence should support a proposition, such as checkout identifies an undisclosed seller, rather than merely prove that many pages were downloaded.
Manage facilitator exceptions as decisions
Delegated onboarding creates a need for consistent exception routing. Define which seller types, evidence gaps, ownership complexities, jurisdictions or transaction capabilities require additional review under the applicable arrangement. A facilitator should know which exceptions it can resolve, which require acquirer approval and which cannot go live. The acquirer should be able to retrieve the decision record and demonstrate that live routing obeyed it.
An exception register should distinguish unresolved evidence, policy deviation, technical failure and approved condition. Those states have different consequences. A missing document may need alternative evidence. A technical outage may require a controlled retry. A proposed business outside appetite may need commercial decline. An approved temporary condition should have scope, owner, expiry and review criteria. Treating all four as an override makes the bank unable to explain why a merchant was allowed to transact.
Capacity matters. If the acquirer receives more exceptions than specialists can review, the bank should assess exposure and lawful interim controls rather than permit the queue to become an unrecorded approval mechanism. Track aged cases, live activity while pending and material evidence gaps. A low exception rate can be misleading if the facilitator is suppressing referrals or using broad acceptance categories. Sampling ordinary approvals helps test whether the referral rules work.
Prepare for outages, migration and termination
An outage plan should identify which control loses visibility and which transactions can still occur. The platform may continue card acceptance while the seller-risk feed is unavailable. That creates a different exposure from a full payment outage. Approved contingency procedures should specify permissible scope, monitoring, evidence preservation and escalation, based on applicable obligations and risk. They should also define how queued or late events are reconciled after recovery.
Migration is a high-risk change because identifiers, status histories and mappings can be lost. Reconcile pre-migration and post-migration merchant populations, including closed merchants with residual obligations. Test whether rejected sellers remain rejected, whether restrictions reach new channels and whether past transactions remain linked to the correct evidence. Compare transaction volumes and field quality before and after migration; a successful login or settlement test does not prove analytical continuity.
Termination should preserve access to required records, unresolved cases, financial positions and outstanding customer obligations. Identify the contractual basis for continued evidence retrieval and test it. If the facilitator ceases trading, the bank should still be able to reconstruct relevant sellers and transactions from lawfully retained information. Business continuity includes control continuity: the ability to investigate and apply required actions after the commercial relationship has ended.
Control effectiveness has several dimensions
An effective acquiring programme can demonstrate population coverage, data quality, decision quality, execution and learning. Population coverage asks whether relevant merchants and sellers enter the controls. Data quality asks whether the necessary facts are reliable and current. Decision quality asks whether investigations distinguish evidence from assumptions. Execution asks whether approved actions reach transactions and payouts. Learning asks whether repeated defects change onboarding, monitoring or partner oversight.
No single metric proves all five. Chargeback rates measure a different aspect from seller evidence retrieval. Alert closure time does not prove sound reasoning. Balanced settlement does not prove correct merchant identity. Management reporting should make those differences visible and connect material gaps to accountable action. The deep operating question is whether the bank can reconstruct a sale, identify the businesses involved, explain the flow of proceeds and show that its decisions actually controlled the relevant activity.
Testing transaction laundering and platform changes
Use a fictional merchant approved for books that submits transactions for an unrelated high-risk seller. Test how website review, descriptor analysis, sales patterns and submerchant data reveal the mismatch. Avoid relying on one signal: a changed descriptor alone may have a legitimate explanation.
Test a newly added seller category, changed bank account, facilitator outage and missing seller identifiers. Determine whether the acquirer can stop affected onboarding or routing within the approved model and still reconcile funds already received.
Assess outcomes with evidence quality and uncovered seller populations alongside fraud and chargeback metrics. Successful scheme compliance does not automatically establish AML effectiveness.
Case method: separate observation, hypothesis and action
The following cases are fictional. Amounts, time periods and operational choices are illustrative teaching facts, not regulatory thresholds. A live decision depends on the actual acquiring agreement, scheme rules, jurisdiction, legal entity, evidence and applicable reporting or restriction duties. Work each case by identifying what the bank knows, what explanation it is testing, what evidence could distinguish alternatives and what action is justified at the current stage. An alert is the beginning of that reasoning.
Case 1: the bookseller with an unfamiliar checkout
Riverside Books was approved as a domestic online bookseller. Website review shows an ordinary catalogue and the merchant's legal name in the footer. Transaction monitoring later identifies a sharp rise in evening sales and several descriptors not previously used. A customer complaint includes a receipt for a subscription sold by another business, with a payment link that routed through Riverside's checkout. The commercial team argues that disputes remain low and asks operations to close the alert.
The decisive observation is the receipt and checkout relationship, not the evening sales pattern. Analysts should preserve the receipt, transaction reference, reviewed pages and descriptor history. They should obtain Riverside's explanation of the other business, examine contracts and identify who fulfilled the subscription. They should also establish whether the transaction was submitted under Riverside's merchant arrangement and where the proceeds went. A genuine group product expansion differs from an unrelated seller using Riverside's acceptance facility without approval.
The investigation might establish that Riverside recently bought the subscription business, retained its trading name and failed to notify the acquirer. That supports a change-control breach and a review of the expanded activity; it does not automatically prove transaction laundering. Alternatively, messages and payout records might show Riverside sells no subscriptions and transfers proceeds to an unrelated business for a processing fee. That would support the concealed-processing hypothesis and require decisions under the applicable arrangement and reporting framework.
The bank should record the scope of any lawful restriction, including whether it applies to the new sales channel, all new transactions or specific payouts. It must separately manage outstanding refunds and disputes. Commercial ownership cannot override mandatory legal action, and a low chargeback rate cannot answer the underlying seller question. The control lesson is to connect website and receipt evidence to transaction submission and recipient identity before deciding the case.
Case 2: several sellers share a payout account
A marketplace reports hundreds of independent sellers. A network alert identifies twelve sellers paying into the same account, although their declared names and products differ. The shared account belongs to a logistics company. Some sellers are newly formed, while others have several years of activity. The pattern could reflect consolidation of fulfilment and treasury services, a common owner, account takeover or concealed beneficiaries.
Begin with the effective-dated payout instructions and account ownership evidence. Ask who authorised the shared arrangement and what contractual right the logistics company has to receive proceeds. Obtain the relevant seller relationships and compare ownership, addresses and fulfilment arrangements where proportionate and lawful. Look at whether funds are later distributed to the sellers, retained as payment for genuine services, or sent to unrelated recipients. The fact that the logistics company delivers goods explains one role; it does not by itself explain why it receives all sales proceeds.
The analyst should avoid assuming that shared bank details mean all twelve sellers are one customer or that each is controlled by the logistics company. Those are propositions requiring evidence. If reliable contracts and statements support a disclosed collections arrangement, the bank can assess it under the applicable rules and policy, update the profile and apply appropriate conditions. If sellers deny authorising the change, the priority may shift toward fraud containment and verification of instructions.
If the marketplace cannot establish the arrangement, the bank should retain the unresolved state and decide what lawful interim controls are available. Suspicious reporting requires its own threshold assessment. The case record should show which sellers and payouts were affected, what historical period was reviewed and how the bank tested alternative explanations. The lesson is that a payout network is an investigative starting point, not an ownership conclusion.
Case 3: balanced settlement hides missing seller identities
A facilitator's settlement file reconciles exactly with the acquiring bank's ledger. During a schema migration, however, the submerchant identifier became optional for one transaction type. The platform reports that the missing field affects only a small percentage of rows. The bank's monitoring team discovers that those rows account for a much larger percentage of value and include several seller categories requiring closer oversight under its policy.
First establish the affected population. Identify the deployment time, transaction types, seller categories, channels and amount range. Reconcile counts and value against the original transaction source, rather than relying on the facilitator's percentage. Determine whether another reliable identifier can reconstruct the seller links. Preserve the old and new schema, transformation rules and sample records. A balanced net settlement does not remove the identity-coverage defect.
The immediate response should address the actual gap. The bank may require corrected records, suspend activation of affected new sellers or apply another approved control within lawful bounds. It should assess transactions already processed and distinguish missing data from evidence of misconduct. An incident review should identify whether screening and monitoring populations were reduced, whether alerts were missed and which cases require reopening or lookback. Those conclusions need evidence, not a blanket assumption that every affected transaction was suspicious.
Recovery requires more than restoring the field in future files. Reconcile the historical population, document unrecoverable records and ensure downstream controls receive corrected links. Test repeated delivery and late arrival so corrected files do not create duplicate transactions or silently overwrite original evidence. The lesson is that accounting completeness and financial-crime data completeness are separate acceptance criteria, and both need accountable owners.
Case 4: a genuine product expansion creates a new risk question
A merchant approved for household goods starts selling high-value industrial components after obtaining a new distribution agreement. Average transaction size increases and buyers appear in new countries. The initial monitoring alert describes the change as unexplained business-model drift. The relationship manager provides the distribution agreement, manufacturer invoices, warehouse records and customer orders. The evidence is commercially coherent.
Coherent evidence can resolve the initial unexplained-change concern without resolving every legal question. The bank should assess whether the new goods, destinations, buyers and services create applicable sanctions or export-control issues, and whether its own role is captured by relevant duties. The merchant's clean name screen and genuine distributor status are useful facts but do not authorise all goods-related activity. Equally, the bank should not claim that every industrial component is controlled or that ordinary payment staff must classify complex technology without specialist support.
The review can update the merchant profile, relevant category or acceptance conditions and monitoring expectations. If technical classification matters, route the question to competent expertise and record the basis of any bank service decision. Distinguish the customer's exporter obligations from obligations applying to the acquirer or another bank entity. Any permission must be tested for actual scope and effective dates.
The outcome may be continued service with a revised profile and controls if no applicable prohibition remains and the risk is manageable. It may also require restricted product categories or refusal of a specific activity under law or appetite. A reporting assessment remains separate. The lesson is that legitimate growth should not be criminalised, but a verified commercial explanation can introduce a new control perimeter requiring deliberate approval.
Case 5: refunds become an alternative payout channel
A merchant has ordinary card purchases followed by frequent refunds. Most refunds relate to genuine returns and go back through the expected route. A smaller group goes to instruments not clearly linked to the original purchases. The merchant says a system migration required alternative destinations. Operations can show the refund totals agree with its ledger, but cannot retrieve the authorisations for the alternative instructions.
Define the disputed population and distinguish it from ordinary returns. Link each refund to the original purchase, customer, reason, destination and approval. Identify the migration period and the scheme or contractual rules that applied. Confirm what alternative refund methods were actually permitted and what evidence the bank required. The absence of records is a control defect; it is not yet proof that the funds were laundered.
Test the explanation using original customer communications, merchant records and destination relationships where lawfully available. Repeated refunds to one unrelated recipient, inconsistent customer identities or instructions contradicting the buyer's request can support a more serious hypothesis. Genuine migration records and verified customer instructions may support remediation without suspicion. Analysts should document the difference and avoid treating the entire refund population alike.
Containment should address the alternative route if that is where the defect sits. Blocking all legitimate refunds can increase customer harm and outstanding obligations. The bank should decide lawful scope with operations, legal, fraud and financial-crime owners, preserve the evidence and assess historical exposure. The lesson is to treat refunds as accountable movements of value with traceability, rather than assume negative amounts are inherently lower risk.
Case 6: a closed seller returns under a new identity
A seller was terminated for deliberately processing another business's activity. Three months later, a new application appears with a different company name and website. It shares a director, support telephone number and payout account with the former seller. The sales team argues that the new company is a separate legal entity and should start with a clean record. The onboarding system does not carry the previous case into the new application.
Separate legal identity from relevant relationship history. The new company may be a genuinely new enterprise, a lawful restructuring or an attempt to continue the prohibited arrangement. Shared attributes justify review, but they do not establish that every company with that director must be rejected. Retrieve the previous decision and its actual grounds, then test the new business model, ownership, goods, checkout and payout arrangement. Determine whether the former concern has been remedied or reproduced.
Any decision should use the applicable policy and contractual authority, while respecting legal requirements and fair treatment. If the new business is materially different and evidence supports it, the bank may consider service within appetite, possibly with conditions. If the same concealed processing continues, the relationship history becomes direct supporting evidence. The record should identify which facts are current and which derive from the earlier case.
Testing should confirm that known-risk history can be surfaced without turning a similarity match into automatic rejection. Stable entity and connected-party links, approved retention and controlled access are important. The lesson is that identifier changes should not erase relevant evidence, while relatedness should remain an evidence-based review question rather than a universal ban.
Compare the cases across control boundaries
Each case contains an observable pattern, but the useful decision comes from the evidence sequence. A descriptor change is not the same as an undisclosed seller. A shared payout account is not the same as common control. Missing identifiers are not the same as suspicious transfers. A real product expansion is not the same as legal permission. Alternative refunds are not automatically laundering. A related new company is not automatically the old company. Analysts should explain the proposition they are testing and the evidence required to move it from hypothesis to conclusion.
For delivery teams, convert that discipline into case states and acceptance criteria. Preserve observations, alternatives, unresolved gaps, legal or policy basis, approver and actual execution. A case can close the original anomaly while creating a new customer-profile task. A fraud concern can coexist with an AML assessment. An approved commercial restriction can coexist with outstanding refund obligations. Systems should support those separate outcomes rather than forcing one final label to stand for the entire incident.
The practical quality test is reconstruction. Give a colleague the case evidence and ask them to identify the actual seller, the submitted transaction, the value recipient, the applicable decision basis and the bank action. If they must infer those facts from scattered screenshots or a generic narrative, the investigation is not yet complete. If the evidence contradicts the original hypothesis, a strong analyst changes the conclusion and records why.
Worked marketplace case
A fictional marketplace settles to one account but pays hundreds of sellers. Several sellers share an unexplained payout account and their goods differ from the marketplace's approved profile. Investigate the commercial relationships, ownership and underlying transactions before deciding the cause.
Explain what the bank needs from the platform and why aggregate settlement totals alone cannot answer the seller-risk question.
Prepare an investigation brief that asks answerable questions
Use the marketplace case to practise a short investigation brief. Start with the trigger: several seller identifiers share a payout account, and their goods appear inconsistent with the approved profile. State what is observed, when it was observed and which source supports it. Do not begin with a conclusion that the sellers are a laundering network. Identify the live exposure, including pending payouts, new transactions and residual obligations, so operations understands the practical urgency.
Then list the decisive questions. Who owns the shared account? What authority permits it to receive the sellers' proceeds? Are the sellers connected through ownership, a collections service or another commercial arrangement? Which goods were actually sold in the transactions under review? Did the platform notify the bank of the relevant changes? Which law, contractual term or bank policy is relevant to each question? Avoid an undirected request for every record the platform holds.
The evidence plan should identify sources and owners. The platform can supply seller profiles, payout instructions and transaction links. The bank can supply settlement, account and previous relationship records. Specialist teams may help assess ownership, goods restrictions or legal intervention authority. Record what can be obtained independently and what remains a customer assertion. A well-scoped request reduces delay because the recipient understands both the information needed and the proposition it will test.
Choose an interim action with a defined scope
An interim decision should state why it is needed, what it affects, who approved it and when it will be reviewed. If the concern is confined to twelve sellers' payout instructions, assess whether a lawful targeted control can address it while ordinary marketplace activity continues. If the platform cannot identify any sellers reliably, the exposure may be broader. Scope should follow evidence and available control capability, subject to applicable obligations.
Do not use sanctions terminology for an ordinary contractual reserve or review pause. A legal freeze has a specific basis and consequences. A commercial withholding decision has contractual and legal limits. A fraud intervention may aim to prevent unauthorised loss. An AML restriction may follow different rules. These actions can overlap, but the case record and ledger should identify the actual basis. Operations must not invent a property-freeze status because the case is difficult.
Customer communication also needs an approved basis. The platform may need to understand which information to provide and which activity remains available. Protected reporting or investigation details may have disclosure constraints. Give enough information to support a lawful next step without exposing prohibited material or offering a misleading explanation. Record the communication decision separately from the restriction so later reviewers can assess both.
Write a conclusion that can survive challenge
A defensible conclusion has four parts: established facts, unresolved matters, decision basis and action. For example, reliable records might show the logistics company operates a disclosed collections arrangement for the twelve sellers, but the platform failed to notify a new product category. The shared account concern may be resolved, while the new activity requires a separate profile and policy review. That is more precise than closing the entire case as false positive or treating every finding as suspicious.
If evidence remains insufficient, say what is missing and why it matters. An unresolved state is not an analyst failure when the relevant facts cannot yet be established. It becomes a governance failure if it has no owner, review date or lawful control plan. Management should decide whether the bank can continue the service within its obligations and appetite, based on the actual limitations and alternatives.
Where suspicion is considered, use the applicable reporting framework and authorised decision process. Scheme reporting, fraud referral, commercial termination and suspicious reporting should each have a documented assessment where relevant. The same evidence can support different decisions, but one decision should not be copied into another without applying its own test. Reporting should never be used as a substitute for executing a legally required restriction or managing outstanding funds correctly.
Delivery requirements for seller visibility
A business analyst should express seller visibility as concrete behaviour. A submitted transaction that requires a seller link under the approved arrangement should either carry the required identifier or enter the defined exception path. The system should not silently map missing values to the platform itself. Acceptance evidence should show the originating record, validation result, relevant exception and transaction disposition. Include a legitimate case where a platform is itself the seller, so the design does not wrongly demand an unrelated submerchant.
Payout-account changes should preserve the old instruction, new instruction, effective time, verification and approver. A payout already scheduled under an old instruction requires an explicit rule for how the change affects it. Test changes arriving before scheduling, after scheduling and after execution. The expected result should come from approved requirements rather than from current system behaviour. Investigators need to reconstruct the instruction used at the actual event time.
Restrictions should reach the channels they claim to control. If a seller is suspended for new acceptance, test direct checkout, mobile application, recurring transactions and any alternative route in scope. If the restriction applies only to a payout, prove ordinary unrelated activity is not accidentally stopped. Test status delivery failures and retries. A restriction flag on a customer screen is not proof that payment execution obeys it.
Build a meaningful test pack
Include positive and negative scenarios. Positive scenarios can include concealed seller routing, missing required submerchant data, an unapproved payout destination, a seller returning with materially linked history and refunds inconsistent with approved arrangements. Negative scenarios can include a genuine product expansion, disclosed group collections, ordinary seasonal growth, legitimate returns and unrelated businesses using the same hosting provider. The test pack should exercise judgement and control boundaries, not simply repeat keywords from the implementation.
Operational scenarios should include a delayed seller-data feed, a schema change, facilitator outage, duplicate settlement batch, currency-conversion difference and termination with outstanding refunds. Specify the expected case, transaction and ledger states. A test is incomplete if it confirms an alert but does not check whether the bank can retrieve evidence or execute the approved outcome. Test recovery as well as failure, including replay of corrected records without duplicate value movement.
Measure results using covered populations, known expected outcomes and data quality. Alert volume reduction can be useful, but it is insufficient if the change makes concealed sellers harder to detect. Balanced settlement can be useful, but it is insufficient if required seller identities are missing. A sound test report explains the exposure tested, limitations, failed scenarios, accepted residual risk and accountable remediation.
Knowledge checks with explained answers
A marketplace settles through one account. Does that establish one merchant risk? No. The actual model may contain independent sellers, a merchant-of-record arrangement or another structure. Identify commercial roles, customer relationships and payout recipients before deciding what data and controls the bank needs.
Several sellers share an account. Does that prove common beneficial ownership? No. A shared account can support a hypothesis about connection or value routing, but ownership and control require their own evidence and applicable tests. Investigate the account authority and commercial arrangement without turning a network link into a legal conclusion.
The facilitator passes every chargeback target. Can AML oversight be reduced automatically? No. Chargeback performance measures a different dimension. It does not establish seller identity, legitimate underlying activity or monitoring coverage. Any calibration should follow the assessed risk, applicable obligations and evidence of control effectiveness.
Can a settlement reserve be called a sanctions freeze? Only if the applicable legal basis actually requires that sanctions action. Contractual reserves, operational holds, fraud interventions and legal freezes are distinct. Record the correct ground and execute its specific consequences.
What is the most useful evidence in a suspected concealed-processing case? Evidence linking the actual sale, submitted transaction, businesses involved and recipient of proceeds. Website indicators, descriptors and payout links become stronger when they support that chain and plausible alternatives have been tested.
Working glossary
Merchant of record identifies a role in the commercial and payment arrangement; its exact obligations follow the contract and applicable law. Sponsored merchant describes a merchant accepted within a facilitator arrangement. Transaction laundering describes concealed or unauthorised processing for an underlying business. Gross-to-net reconciliation explains how sales and separate adjustments become settlement. Payout provenance preserves the source, authority and effective time of the recipient instruction. Coverage gap means a relevant population or required fact is absent from the control; it does not itself prove criminal activity.
Requirements for accountable acquiring
Maintain links between merchant, submerchant, website, scheme identifiers, customer transactions, ledger entries and payout accounts. Preserve identity changes and avoid recycling identifiers without history. Data contracts should specify coverage, timeliness, completeness and retrieval after termination.
Acceptance tests cover unidentified sellers, changed payout accounts, duplicate payments, refunds after closure and reconciliation of gross-to-net settlement. Assign owners for commercial approval, financial-crime review, scheme obligations, transaction execution and assurance.
The effective control understands who actually sells, who receives value and whether activity remains within the approved arrangement.
Govern acquiring as a complete operating model
An acquiring programme should have an accountable business owner who understands the commercial model and accepts responsibility for operating within approved boundaries. That owner is not the person who makes every AML or sanctions decision. Compliance interprets and challenges applicable control requirements, specialist investigators assess cases within their remit, operations executes actions and independent assurance tests the chain. Governance should connect those roles without collapsing their responsibilities into one generic risk committee.
The programme should maintain an inventory of material arrangements: direct acquiring, facilitator sponsorship, marketplace collection, payout services and relevant outsourced processing. Record the legal entities, jurisdictions, contractual model, seller populations, data sources and control owners. New arrangements should be assessed against that inventory. A product launch that looks like a pricing variation can materially change who sells, who receives funds or which entity performs onboarding. Approval needs to follow those changes.
Senior management should be able to ask why the bank can manage the arrangement, not only how profitable it is. The answer should identify relevant risks, available evidence, controls, partner oversight, intervention capability and residual limits. Conditions should have owners and measurable completion criteria. A launch decision should not rely on a future data capability that has no delivery commitment while transactions are permitted immediately. If phased scope is approved, systems and commercial teams should obey it.
Challenge the partner before and after appointment
Partner due diligence should assess actual capability. Review the facilitator's onboarding methods, accepted seller categories, ownership verification, screening, monitoring, exception management, record retrieval and change controls as relevant to the arrangement. Ask for examples and demonstrate retrieval, rather than accepting a policy document as proof of execution. A partner can have a well-written programme and still fail to identify a material part of its live seller population.
Commercial incentives should be understood. Fast activation, volume growth and low referral rates can create pressure to treat uncertain seller information as complete. The bank should assess how the partner measures staff performance and handles rejected applicants, overrides and complaints. An incentive concern is not evidence of misconduct by itself, but it helps explain where assurance should look. Effective challenge tests ordinary approvals as well as escalated exceptions.
After appointment, oversight should reflect actual risk and change. Review material incidents, seller-population shifts, product additions, subcontractor changes and data-quality trends. Retrieve sampled evidence from live and closed sellers. Compare the partner's reports with bank-held populations. If a partner says it stopped a seller, test whether transactions ceased through every relevant route. Oversight should produce concrete conclusions and action rather than a recurring meeting with an unchanged dashboard.
Design management information around unanswered questions
Management information should make limitations visible. Useful measures can include relevant seller coverage, required-field quality, evidence retrieval success, aged unresolved cases, changes outside approved scope, execution failures, repeated overrides and historical populations requiring remediation. Fraud loss, scheme compliance and chargeback measures remain useful but should not substitute for financial-crime effectiveness. Each metric needs a definition, denominator, source and owner.
Segment results where aggregation hides the exposure. A platform-wide completeness rate can look strong while one newly added cross-border category has poor seller visibility. A low average case age can conceal a small set of high-value unresolved payouts. A high evidence retrieval success rate can be misleading if samples exclude terminated sellers. Management should ask which material populations are missing from the statistic and whether that omission is justified.
The report should support decisions. If seller identifiers are absent from a live channel, identify the value and population affected, interim controls, legal implications and remediation plan. If a partner repeatedly breaches approved scope, identify whether conditions, reduced service or termination should be considered under the actual arrangement. A red indicator without an accountable decision becomes background noise; a green indicator without a meaningful denominator creates false confidence.
Preserve independence while sharing evidence
Fraud, scheme, AML and sanctions teams should share relevant facts through lawful, controlled processes. A fraud investigation can identify concealed seller routing. A scheme review can identify prohibited goods. AML analysis can find suspicious payout networks. Sanctions specialists can determine that a person or activity is legally restricted. The shared fact record improves consistency, but each team must apply its own decision basis and retain the resulting rationale.
Access should reflect sensitivity and purpose. Protected reporting decisions may need restricted access, while operations needs enough instruction to execute an approved action. Relationship teams may need a lawful explanation for customer requests without receiving confidential reporting details. Design those interfaces deliberately. Overly broad access can create disclosure risk; overly narrow access can prevent necessary execution. The objective is appropriate evidence flow, not unrestricted visibility for every user.
Independent assurance should be able to challenge both the evidence and the outcome. It should not accept a case closure simply because the approved reviewer signed it. Reconstruct the seller, activity, transaction and payout chain. Check whether alternatives were tested, the correct jurisdictional requirements were applied and the approved action reached the relevant systems. A legally sound conclusion that failed in execution remains a serious control problem.
Treat regulatory, scheme and contractual change separately
The change inventory should distinguish law, supervisory guidance, card-scheme requirements, contractual terms and bank policy. Each has different legal status, scope and implementation conditions. A scheme rule does not automatically define the statutory AML perimeter. A bank policy can be stricter than a legal minimum, but the customer and operational decision should identify that policy basis accurately. Training should preserve these distinctions.
Effective dates matter. Assess who and what a change affects, which facts or fields are required, which decisions need revision and whether existing portfolios need review. A requirement adopted for future implementation should not be presented as already binding. Conversely, a current obligation should not be postponed because the technology release calendar is inconvenient. Legal and policy owners should approve a traceable implementation plan with tested interim arrangements where appropriate.
Change testing should cover the entire chain. A revised seller category may alter onboarding questions, monitoring, exception routing, transaction acceptance and partner reports. Testing only the changed form proves little about downstream behaviour. Retain the source of the change, approved interpretation, requirements, tests, release evidence and any lookback decision. This gives assurance a coherent explanation of why the bank's operating model changed.
Conduct an acquiring incident exercise
In a tabletop exercise, assume a facilitator has processed an undisclosed seller population for six weeks. The data feed has seller identifiers for only part of the period. Some proceeds remain pending, some have been paid out and some buyers seek refunds. The facilitator's compliance lead is unavailable. Commercial management wants a complete shutdown, while operations warns that the requested action could stop unrelated customer refunds.
The exercise should force the team to establish facts and authority before action. Identify affected sellers, dates, transactions and positions. Determine which legal and contractual grounds permit each intervention. Separate new acceptance, pending payouts, settled funds and residual obligations. Establish an escalation route for unavailable decision makers. Preserve data and communications. Decide which reporting assessments and partner notifications are required without assuming they all have the same threshold or deadline.
Then test recovery. Can the bank retrieve historic seller evidence, reconcile corrected data, identify missed controls and implement a proportionate remediation? Can it distinguish legitimate activity from concealed processing as facts emerge? Can it restore permitted service without erasing the incident record? The exercise succeeds when it reveals specific weaknesses and accountable repairs, rather than demonstrating that everyone knows a crisis meeting would be convened.
Final assurance questions
An executive or auditor should be able to select a seller and ask: who is the legal business, what does it sell, what arrangement permits it to transact, which bank duties apply, what evidence was relied upon and who approved it? They should then be able to select a transaction and ask: which sale does this represent, which parties submitted and received value, how did the gross amount become settlement and payout, and what restrictions or reviews applied at the relevant time?
Finally, ask what could make the original decision wrong today. Ownership, goods, channels, jurisdiction, payout accounts, legal requirements and partner capability can all change. The programme should identify how those changes are detected and acted upon. Release readiness for acquiring is a demonstrated ability to maintain that evidence and decision chain throughout the relationship, including incidents and termination, rather than an initial approval followed by years of unexamined settlement.
References and further reading
Reviewed 2 October 2026. FATF provides international standards; applicable national law determines binding duties. The operating examples are fictional teaching cases.
- FATF Recommendations, updated June 2026 — relevant anchors: 1, 10, 17 and 20; apply the national perimeter to actual activities.