Who Is Actually On Your Platform?
I remember the early days of SOX, back in '02 and '03, when half the C-suite thought a signed memo from the CFO counted as a control. It didn't. It was just paper theatre. We spent three years scrubbing that delusion out of the system. Now, looking at the payment processing sector, it feels like we're seeing the same performance, just with better software.
The FTC recently came for Nuvei. The processor agreed to pay just under $5 million to settle charges that they essentially rolled out the red carpet for merchant fraud. The core of the failure wasn't a technical glitch or a sophisticated hack. It was a failure of merchant screening.
In plain English: they didn't actually check who they were letting onto their platform.
When I look at a finding, I only care about one thing: what does this cost you at year-end? For Nuvei, the immediate hit is the fine. But that's the small number. The real cost of poor control design in merchant screening isn't a regulatory settlement; it's the total loss of trust from the acquiring banks.
If you are a processor and you can't prove your KYC (Know Your Customer) process actually filters out bad actors, you aren't a partner to the banks. You're a liability.
The industry loves to talk about "automated onboarding" and "frictionless experiences." That's usually code for "we've disabled the controls that actually slow things down so we can grow our volume faster." They replace a human reviewer with a piece of software that checks if a tax ID exists, then they tick a box and call it done.
That isn't a control. It's a formality.
A real control doesn't just verify that a document exists; it verifies that the information in the document is true and that the entity behind it isn't a shell company designed to wash fraudulent transactions. If your screening process can be bypassed by a slightly modified corporate registry filing, you haven't designed a control. You've designed a suggestion.
The common objection here is that strict screening kills conversion rates. The argument is that if you make the onboarding too hard, the merchants will just go to a competitor who is more "flexible."
Fine. Go be flexible. Just don't act surprised when the FTC decides your flexibility looks like facilitating fraud.
The cost of a lost lead is a few hundred dollars in potential commission. The cost of an FTC settlement and a degraded reputation with card networks is millions. I'll take the lost lead every single time.
There is a second-order effect here that most firms are ignoring. When a major processor gets hammered for inadequate screening, the regulators don't just stop at one firm. They start looking at the entire chain. The next target won't be the processor; it'll be the third-party risk management firms who signed off on those "automated" processes.
If you're an auditor providing a SOC 2 report for a screening tool, you better hope your tests actually challenged the logic of the software rather than just confirming the software was running. If the SEC or FTC finds that a "certified" control was effectively useless, they won't just blame the client. They'll ask why the assurance provider missed it.
We've moved into an era where "automated" is being used as a shield to hide a lack of oversight. It's the same theatre I saw twenty years ago, just shifted from spreadsheets to APIs.
The question for any payment professional this week is simple: if you had to manually verify every single merchant on your books by Friday, how many would you have to offboard immediately?
If that number makes you sweat, your controls are broken.
Sources
The reporting this piece was written from. Check the originals before relying on anything here.
- Payment Processor Nuvei Must Implement Robust Merchant Screening Practices and Pay $4.85 Million to Settle FTC Charges that the Firm Facilitated Merchant Fraud FTC Press Releases
- SEC Moves to Rescind Pay-to-Play Rule for Advisors - Wealth Management Compliance Week (Google News)
- AI Privacy Rules Beyond GDPR: Council of Europe Draft Covers 55 Nations - Tech Times Compliance Week (Google News)
- SEC Returns to Its Accounting Enforcement Roots: New Financial Reporting and Accounting Unit Signals Focus on Disclosure Integrity, Accounting Fraud, and Audit Oversight - Freshfields Compliance Week (Google News)
- FBI investigates breach of 153 million driving license records at IDscan.net - csoonline.com Data Privacy (Google News)
- SEC’s Accounting Unit Seen as Core Fraud Enforcement Engine - Bloomberg Law News Compliance Week (Google News)
- EU bishops’ conferences await ruling on erasing baptismal entries - The Pillar Data Privacy (Google News)
- NFRA Forms Advisory Panel on Audit Quality & Technology - Rediff MoneyWiz PCAOB