FTC Fines Nuvei Nearly 5 Million Dollars Over Merchant Screening
If I walk into your office on a Tuesday and ask to see the vetting file for a merchant you onboarded last November, what do you actually show me?
Do not tell me about your "onboarding framework." Do not point me toward a high-level policy document that says the firm is committed to preventing fraud. I want the ticket. I want the timestamped verification of the merchant's identity and the specific risk-rating assigned before the first transaction hit the rails.
This is precisely where Nuvei tripped up. The FTC just squeezed them for nearly 5 million dollars because their merchant screening wasn't actually happening—or at least, it wasn't happening in a way that left a trail. They weren't just fined for the fraud that slipped through; they were fined for the gap between what they claimed to be doing and what they could prove they did.
I’ve sat on both sides of this table. The business side always argues that at high volumes, you can't possibly vet every single entity with a magnifying glass. They call their process "mature." Whenever I hear a compliance officer describe a programme as mature, my internal alarm goes off. Usually, it means they've stopped questioning the process and have started trusting the software.
The claim from payment processors is usually that they have automated filters to catch the bad actors. But automation isn't a control; it's a tool. The actual control is the human oversight of those filters. If you can't produce a sample of "false negatives" that were reviewed and actioned, your control doesn't exist.
The evidence in the Nuvei case suggests a systemic failure to oversee merchants. When the FTC sees a pattern of fraud facilitating, they don't look at the individual fraudulent transactions as isolated incidents. They see them as samples. If three out of ten sampled merchants show zero evidence of due diligence, the auditor assumes the other 90% are just as empty.
Some will argue that it's unfair to penalize a processor for the dishonesty of its merchants. That’s a misunderstanding of the risk. The regulator isn't blaming the processor for the existence of fraud; they're blaming them for the lack of evidence that they tried to stop it.
The implication here is simple: your "mature" automated screening is a liability if you can't prove you've tested its efficacy. If your system flags 1,000 merchants and you ignore the alerts because you're chasing growth targets, that isn't an operational choice. It's a documented failure of internal control.
This creates a nasty second-order effect for the firms providing the audit sign-offs. When a processor pays a multi-million dollar settlement for "inadequate oversight," every auditor who signed off on those specific controls over the last three years is suddenly in a very uncomfortable position.
We're moving toward a period where professional indemnity insurance for auditors specializing in fintech will likely spike. Insurers aren't interested in your audit methodology; they're interested in the fact that you told a client their controls were effective, only for the FTC to prove they weren't. The auditor becomes the next target for the firm's board when the clawbacks start hitting the balance sheet.
We've seen this fragility elsewhere this week too. Look at General Fusion Group correcting a liability overstatement of over 411 million dollars in their Q1 projections. That isn't just a math error. It's a failure of the review process. Someone signed off on that number without checking the underlying calculation.
The common thread is the obsession with the "system" over the "evidence."
If you are running a screening programme, stop looking at your dashboard and start looking at your files. Pick five merchants from six months ago. Try to reconstruct the logic of why they were approved using only the documents available in the folder.
If you have to call a former employee to explain how it was done, you've failed.
The regulator doesn't care about the conversation you had with your colleague in June. They care about what is written down and timestamped.
Watch the SEC's move on private fund reporting delays. If they decide to push through those requirements despite the shrinking filing pool, the scrutiny on "how" these funds are managed will intensify. The firms that have spent the last year polishing their policy manuals instead of cleaning up their evidence trails are going to find out very quickly that a policy is not a piece of evidence.
It's just a piece of paper.
Sources
The reporting this piece was written from. Check the originals before relying on anything here.
- Payment Processor Nuvei Must Implement Robust Merchant Screening Practices and Pay $4.85 Million to Settle FTC Charges that the Firm Facilitated Merchant Fraud FTC Press Releases
- Ireland fines HSE €645,000 over failures in personal data protection - Digital Watch Observatory Data Privacy (Google News)
- SEC, CFTC Delay Private Fund Reporting as Filing Pool May Shrink 43% - TradingView Compliance Week (Google News)
- General Fusion Group Revises Q1 2026 Financials, Corrects $411.3 Million Liability Overstatement - Kalkine Media PCAOB
- Federal Court Says AI Child Sex Abuse Images Are Constitutionally Protected - Billy Graham Evangelistic Association Data Privacy (Google News)
- French Hospital Data Breach Draws €500,000 Fine Over 727,000 Records - Safestate Data Privacy (Google News)
- Congress Unveils Stop Rogue AI Act After OpenAI Agents Ran Loose Online - Startup Fortune InfoSec Compliance (Google News)
- Irenic Acquisition (IACQ) reports auditor switch and control weakness - Stock Titan PCAOB