Compliance isn't the bank's job. It's the merchant's job. Yet many don't have the tools on hand to discover compliance issues before they become a problem. Qredible's Merchant Intelligence Operating System™ and MyCOA® provide the infrastructure for modern commerce to stay ahead.

Stop Making Banks Police Your Products

Author: Noah Fitzgerald, CPP
Date: August 23, 2026

Stop Making Banks Police Your Products

It's Time to Put First-Line Product Compliance Responsibility Back Where It Belongs: With the Merchant

"Your payment processor should not be the first person to tell you your product is out of compliance."
- Noah Fitzgerald, CPP, CRO Qredible, Inc.

 


We Have a Responsibility Problem in Regulated Commerce

Noah Fitzgerald, CPP - Chief Revenue Officer, Qredible, Inc.
After more than three decades in payments, I believe there is a conversation our industry needs to have.

And some merchants aren't going to like it.

For years, banks, payment processors, ISOs, underwriters, and risk teams have assumed an enormous amount of responsibility for discovering compliance problems that should have been identified by merchants long before an underwriter ever opened their website.

Expired COAs.

Missing laboratory reports.

Questionable products.

Unsupported claims.

Licensing problems.

Incorrect labels.

Prohibited ingredients.

Products added after underwriting.

Products that no longer meet processor policy.

Website content that creates regulatory concerns.

In far too many cases, who discovers the problem?

The payment company.

An underwriter finds it during onboarding.

A risk analyst discovers it during monitoring.

A sponsor bank identifies it during an audit.

Or worse, a card brand or regulator finds it after the merchant has already been operating.

Then the scramble begins.

Emails.

Phone calls.

Document requests.

Spreadsheets.

Remediation.

Escalation.

Account holds.

Processing interruptions.

Sometimes termination.

We have normalized this process for so long that we rarely stop to ask the obvious question:

Why is the financial institution discovering the merchant's compliance problem before the merchant?

Something about that model is fundamentally backwards.


Compliance Should Start Before Underwriting

Let's be clear about something important.

Banks, acquirers, payment processors, sponsor banks, and other financial institutions have their own responsibilities.

They must perform appropriate due diligence.

They must establish risk appetite.

They must maintain appropriate oversight.

They must comply with applicable law, card-brand requirements, sponsor-bank requirements, and internal policies.

Technology does not eliminate those responsibilities.

Nor should merchants simply be allowed to declare themselves compliant.

But there is an enormous difference between institutional oversight and making the institution responsible for discovering basic product-compliance failures that the merchant should already be managing.

A merchant selling regulated products should arrive at underwriting prepared.

Its products should be documented.

Required testing should be current.

Licenses should be current.

Marketing should be reviewed.

Required evidence should be organized.

Product changes should be managed.

Compliance shouldn't begin when the application reaches underwriting.

It should begin before the merchant ever applies.


If You Sell a Regulated Product, Compliance Is Part of Your Product

This is particularly important in industries such as:

  • CBD and hemp
  • Vape and e-cigarettes
  • Tobacco and nicotine
  • Nutraceuticals
  • Functional mushrooms
  • Nootropics
  • Peptides
  • Pharmaceuticals
  • Cannabis
  • Alcohol
  • Other regulated and emerging product categories

These businesses operate in environments where the details matter.

What is in the product?

How is it formulated?

How is it tested?

What does the label say?

What claims are being made?

Where is it being sold?

What documentation supports it?

Has that documentation expired?

Have regulations changed?

The answer cannot be:

"We'll find out when our processor tells us."

That's not a compliance strategy.

That's outsourced reaction.


The COA Problem Illustrates the Bigger Failure

Consider Certificates of Analysis.

For many product categories, laboratory documentation can be a critical component of product transparency and compliance management.

Yet the process is frequently fragmented.

COAs sit in:

  • Email
  • Shared drives
  • Manufacturer portals
  • Dropbox folders
  • Websites
  • Spreadsheets
  • PDFs
  • Individual employee computers

Products change.

Batches change.

Documents expire or become outdated.

URLs break.

The merchant grows.

Eventually, somebody asks for documentation.

Then everyone starts looking for it.

This isn't primarily a COA problem.

It's an infrastructure problem.

Businesses are trying to manage dynamic regulated products with static documents and disconnected workflows.

And payment companies have inherited the consequences.


Payment Companies Have Become the Compliance Help Desk

Talk to enough underwriting and risk teams serving regulated merchants and you'll hear versions of the same stories.

"We had to tell them their COAs were expired."

"We found products they never disclosed."

"We had to explain which content needed to come off the website."

"They added products after approval."

"We couldn't get the documentation."

"We had to chase them three times."

Think about what that means operationally.

Highly trained payment and compliance professionals are spending time teaching merchants how to maintain the basic evidence required to support their own businesses.

That's expensive.

It slows onboarding.

It creates friction.

It frustrates merchants.

And it doesn't scale.

The payment company should verify.

It should evaluate.

It should monitor.

It should challenge.

But it should not have to become the merchant's filing cabinet, calendar, compliance coordinator, and product administrator.


The Merchant Should Be the First Line of Defense

The operating model needs to change.

The merchant should own the ongoing management of its:

Products

What is being sold and when it changes.

Testing

What testing is required and whether supporting documentation remains current.

Documentation

The evidence supporting products, claims, licensing, and compliance.

Marketing

What the business says about its products across websites and other channels.

Transparency

Whether customers and partners can access appropriate product information.

Regulatory Readiness

Whether changes affecting the business have been identified and addressed.

Remediation

When an issue appears, whether it gets corrected before it becomes somebody else's problem.

That is what responsible regulated commerce should look like.


Merchants Need Better Tools Before We Demand Better Outcomes

Here's where I also think the financial industry needs to acknowledge its side of the problem.

We cannot tell merchants to "stay compliant" and then give them PDFs, spreadsheets, email reminders, and document-upload portals.

That's not infrastructure.

If we're going to place greater first-line responsibility on merchants, we need to give them technology capable of carrying that responsibility.

Merchants need systems that help them:

  • Organize products
  • Associate evidence with individual products
  • Manage COAs and laboratory reports
  • Track documentation
  • Identify missing or outdated information
  • Maintain product transparency
  • Manage changes
  • Understand compliance requirements
  • Correct issues
  • Demonstrate compliance to partners

Responsibility without infrastructure is just another manual process.

This is the gap the industry needs to close.


Enter Merchant-Owned Compliance Infrastructure

This is one of the primary reasons we built MyCOA™.

Not as another processor compliance tool.

As infrastructure the merchant itself uses.

The concept is straightforward:

Create and maintain a persistent digital compliance record around the products the merchant sells.

Rather than waiting for somebody downstream to ask for information, the merchant continuously maintains it.

Products.

COAs.

Laboratory documentation.

Supporting evidence.

Product information.

Transparency.

Compliance status.

The merchant becomes an active participant in maintaining a cleaner commerce ecosystem instead of a passive participant waiting for the next compliance request.


From "Send Me Your COAs" to Continuous Readiness

Consider how different the relationship becomes.

The legacy model:

  • Processor requests documents.
  • Merchant searches for them.
  • Documents are emailed.
  • Underwriter reviews them.
  • Something is missing.
  • Merchant is contacted.
  • New document arrives.
  • Spreadsheet is updated.
  • Merchant is approved.

Six months pass.

Everything may now be outdated.

A merchant-owned model:

  • The merchant maintains its products and supporting documentation continuously.
  • The information is organized around the product.
  • Missing or aging evidence can be surfaced earlier.
  • Changes become part of an ongoing compliance workflow.
  • When a payment partner needs evidence, the merchant is already prepared.

That is a fundamentally healthier relationship.

Compliance becomes a state of readiness instead of an emergency response.


The Goal Should Be to Find the Problem Before Your Processor Does

I would make this a standard for every regulated merchant.

Before your processor sees it.

Before your bank sees it.

Before your marketplace sees it.

Before your insurance company sees it.

Before your sponsor bank sees it.

Before a card brand sees it.

Before a regulator sees it.

You should see it.

And you should have the tools to fix it.

That's what mature compliance looks like.


This Changes the Role of the Payment Processor

Merchant-owned compliance doesn't eliminate payment-company oversight.

It makes oversight better.

Instead of payment companies spending their resources collecting basic information, they can focus on what they're actually good at:

  • Verification
  • Risk analysis
  • Policy enforcement
  • Exceptions
  • Portfolio intelligence
  • Emerging risk
  • Continuous oversight

In other words:

The merchant manages compliance.

The financial institution validates and oversees risk.

That is a far more scalable division of responsibility.


It Also Changes Underwriting

Imagine two merchants applying for processing.

Merchant A sends:

A website.

A product spreadsheet.

Thirty-seven PDF COAs.

Several email attachments.

And an assurance that everything is current.

Merchant B arrives with:

A structured product inventory.

Current supporting evidence connected to those products.

Organized testing records.

Product transparency.

A maintained compliance history.

Which merchant creates greater confidence?

Which merchant is easier to evaluate?

Which merchant is more likely to move through underwriting efficiently?

Which merchant would you rather have in your portfolio?

Compliance maturity can become part of merchant quality.

That's a significant shift.


It Changes the Economics for Payment Companies Too

This is where the model becomes particularly interesting.

Historically, regulated merchant compliance creates cost for payment companies.

More underwriting.

More reviews.

More monitoring.

More merchant outreach.

More compliance personnel.

More remediation.

What if some of that infrastructure could instead become a merchant service?

Payment providers can give regulated merchants access to technology designed to help them manage their own compliance responsibilities—and potentially resell that technology as a value-added service.

The economics begin to change:

Compliance Cost

becomes

Merchant Service

which can become

Recurring Revenue

while simultaneously supporting a cleaner, more transparent portfolio.

That's a rare alignment.

The merchant gets better infrastructure.

The payment company gets better visibility.

Underwriting gets better information.

Risk gets cleaner merchants.

The sponsor bank gets greater confidence.

And the payment provider can create a new recurring revenue stream.


Stop Monetizing Risk Only Through Higher Pricing

The payments industry has traditionally monetized elevated-risk merchants primarily by charging more for processing.

Higher fees.

Higher reserves.

More underwriting costs.

More monitoring costs.

But perhaps there is another model.

What if payment providers also monetized helping merchants become better businesses?

Compliance technology.

Product transparency.

Merchant readiness.

Continuous documentation.

Certification.

Regulatory infrastructure.

That creates revenue by delivering value rather than merely pricing for risk.

And I believe that is a much more sustainable model for regulated commerce.


The Alternative Is the Same Cycle We've Been Running for Years

Of course, organizations can keep doing what they're doing.

Merchants can maintain spreadsheets.

Processors can request documents.

Risk teams can manually inspect websites.

Compliance departments can chase merchants.

Sponsor banks can perform portfolio reviews.

Teams can scramble whenever regulations change.

And when something gets missed:

Processing may be interrupted.

Merchant accounts may be terminated.

Revenue may disappear.

Portfolios may require remediation.

Sponsor banks may escalate concerns.

Card-brand scrutiny may increase.

Regulatory issues may become considerably more expensive.

Then everyone asks:

"How did we miss this?"

The answer is often painfully simple.

The operating model was designed to discover problems after they existed rather than prevent them from existing in the first place.


Compliance Cannot Be an Annual Event

This becomes even more important as regulated commerce accelerates.

A merchant may add products tomorrow.

A manufacturer may change a formulation.

A new COA may replace an old one.

A website claim may change this afternoon.

A state may change its requirements.

A federal rule may alter an entire product category.

A sponsor bank may update policy.

A card brand may change its monitoring expectations.

Compliance cannot keep operating as:

Underwrite → Approve → File → Revisit Later.

It must become:

Prepare → Validate → Maintain → Monitor → Remediate → Prove.

And the merchant needs to participate in that process every day.


The Future Is Compliant-First Commerce™

I believe we're moving toward an era where compliance becomes part of the underlying infrastructure of selling regulated products.

Not something bolted on after the product launches.

Not something addressed when underwriting asks.

Not something fixed when a regulator arrives.

Built in from the beginning.

Product created.

Evidence connected.

Requirements understood.

Transparency established.

Commerce enabled.

Changes monitored.

Compliance maintained.

That's what we mean at Qredible when we talk about Compliant-First Commerce™.

It isn't compliance standing in the way of commerce.

It's compliance becoming infrastructure that makes sustainable commerce possible.


What Payment Executives Should Be Asking

For payment companies and banks serving regulated-product merchants, I believe the conversation should now be:

  • How much of our compliance workload exists because merchants aren't managing their own information effectively?
  • How many underwriting hours are spent chasing documents?
  • How frequently do we discover issues merchants should have identified first?
  • Can our merchants continuously maintain product-level compliance evidence?
  • Can we identify product changes after onboarding?
  • What happens when regulations suddenly affect hundreds of merchants?
  • Can merchants remediate issues without creating manual work for our teams?
  • Are we giving merchants the technology required to meet the standards we're imposing on them?
  • Could merchant compliance infrastructure improve both portfolio quality and merchant retention?
  • Could compliance services become a revenue stream instead of remaining purely a cost center?

And the question I think every regulated merchant should be asking is much simpler:

Why am I waiting for my payment processor to tell me there's something wrong with my business?


The Responsibility Reset

The future requires a clearer division of responsibility.

Merchants

Own compliance readiness.

Maintain products, documentation, evidence, transparency, and remediation.

Payment Companies

Own risk oversight.

Verify, evaluate, monitor, enforce policy, and manage portfolio exposure.

Sponsor Banks

Own institutional oversight.

Establish risk appetite and ensure appropriate governance and controls.

Technology

Connect the ecosystem.

Make information structured, continuous, searchable, verifiable, and actionable.

Each participant still has responsibilities.

But they no longer need to perform everyone else's work.

Why We Built MyCOA™

MyCOA was built around a simple belief:

The best time to fix a compliance problem is before someone else discovers it.

We want regulated merchants to have infrastructure that helps them manage their products and compliance evidence continuously—not simply when a bank, processor, regulator, or customer asks for it.

And we want payment companies to have a different relationship with those merchants.

Less chasing.

Less manual review.

Less reaction.

More transparency.

More readiness.

More intelligence.

More sustainable revenue.

MyCOA is not intended to replace the independent compliance responsibilities of financial institutions.

It is designed to make the merchant a stronger first line of defense.

That is a distinction I believe regulated commerce desperately needs.

Learn More about MyCOA: www.qredible.com


Final Thought

For too long, regulated commerce has operated with an unspoken assumption:

The merchant sells.

The payment company checks.

Risk finds the problems.

Compliance cleans them up.

That model needs to change.

If you manufacture regulated products, compliance is part of manufacturing.

If you distribute regulated products, compliance is part of distribution.

If you market regulated products, compliance is part of marketing.

And if you sell regulated products:

Compliance is part of selling them.

Banks and payment companies must continue to perform appropriate oversight.

But they should not have to be the first ones to discover that the merchant isn't doing its job.

Give merchants responsibility.

Give them the technology to carry it.

Give financial institutions the intelligence to verify it.

And build an ecosystem where compliance problems are identified before they become payment problems.

Because the future of regulated commerce cannot be built around waiting to get caught.

It must be built around staying ahead.

 

About Qredible

Qredible is redefining merchant underwriting through Merchant Risk Intelligence (MRI)—a product-first approach that continuously analyzes what businesses sell, how they market those products, and the evidence required to support compliant payment acceptance. By moving beyond static industry classifications, Qredible helps banks, payment processors, ISOs, and sponsor banks make faster, more informed, and more defensible underwriting decisions while reducing manual effort and strengthening ongoing portfolio oversight. Learn more about Qredible's product-first automated compliance management platform for regulated industries →



crossmenu