
| "Your payment processor should not be the first person to tell you your product is out of compliance." - Noah Fitzgerald, CPP, CRO Qredible, Inc. |
We Have a Responsibility Problem in Regulated Commerce

After more than three decades in payments, I believe there is a conversation our industry needs to have.
And some merchants aren't going to like it.
For years, banks, payment processors, ISOs, underwriters, and risk teams have assumed an enormous amount of responsibility for discovering compliance problems that should have been identified by merchants long before an underwriter ever opened their website.
Expired COAs.
Missing laboratory reports.
Questionable products.
Unsupported claims.
Licensing problems.
Incorrect labels.
Prohibited ingredients.
Products added after underwriting.
Products that no longer meet processor policy.
Website content that creates regulatory concerns.
In far too many cases, who discovers the problem?
The payment company.
An underwriter finds it during onboarding.
A risk analyst discovers it during monitoring.
A sponsor bank identifies it during an audit.
Or worse, a card brand or regulator finds it after the merchant has already been operating.
Then the scramble begins.
Emails.
Phone calls.
Document requests.
Spreadsheets.
Remediation.
Escalation.
Account holds.
Processing interruptions.
Sometimes termination.
We have normalized this process for so long that we rarely stop to ask the obvious question:
Why is the financial institution discovering the merchant's compliance problem before the merchant?
Something about that model is fundamentally backwards.
Let's be clear about something important.
Banks, acquirers, payment processors, sponsor banks, and other financial institutions have their own responsibilities.
They must perform appropriate due diligence.
They must establish risk appetite.
They must maintain appropriate oversight.
They must comply with applicable law, card-brand requirements, sponsor-bank requirements, and internal policies.
Technology does not eliminate those responsibilities.
Nor should merchants simply be allowed to declare themselves compliant.
But there is an enormous difference between institutional oversight and making the institution responsible for discovering basic product-compliance failures that the merchant should already be managing.
A merchant selling regulated products should arrive at underwriting prepared.
Its products should be documented.
Required testing should be current.
Licenses should be current.
Marketing should be reviewed.
Required evidence should be organized.
Product changes should be managed.
Compliance shouldn't begin when the application reaches underwriting.
It should begin before the merchant ever applies.
This is particularly important in industries such as:
These businesses operate in environments where the details matter.
What is in the product?
How is it formulated?
How is it tested?
What does the label say?
What claims are being made?
Where is it being sold?
What documentation supports it?
Has that documentation expired?
Have regulations changed?
The answer cannot be:
"We'll find out when our processor tells us."
That's not a compliance strategy.
That's outsourced reaction.
Consider Certificates of Analysis.
For many product categories, laboratory documentation can be a critical component of product transparency and compliance management.
Yet the process is frequently fragmented.
COAs sit in:
Products change.
Batches change.
Documents expire or become outdated.
URLs break.
The merchant grows.
Eventually, somebody asks for documentation.
Then everyone starts looking for it.
This isn't primarily a COA problem.
It's an infrastructure problem.
Businesses are trying to manage dynamic regulated products with static documents and disconnected workflows.
And payment companies have inherited the consequences.
Talk to enough underwriting and risk teams serving regulated merchants and you'll hear versions of the same stories.
"We had to tell them their COAs were expired."
"We found products they never disclosed."
"We had to explain which content needed to come off the website."
"They added products after approval."
"We couldn't get the documentation."
"We had to chase them three times."
Think about what that means operationally.
Highly trained payment and compliance professionals are spending time teaching merchants how to maintain the basic evidence required to support their own businesses.
That's expensive.
It slows onboarding.
It creates friction.
It frustrates merchants.
And it doesn't scale.
The payment company should verify.
It should evaluate.
It should monitor.
It should challenge.
But it should not have to become the merchant's filing cabinet, calendar, compliance coordinator, and product administrator.
The operating model needs to change.
The merchant should own the ongoing management of its:
Products
What is being sold and when it changes.
Testing
What testing is required and whether supporting documentation remains current.
Documentation
The evidence supporting products, claims, licensing, and compliance.
Marketing
What the business says about its products across websites and other channels.
Transparency
Whether customers and partners can access appropriate product information.
Regulatory Readiness
Whether changes affecting the business have been identified and addressed.
Remediation
When an issue appears, whether it gets corrected before it becomes somebody else's problem.
That is what responsible regulated commerce should look like.
Here's where I also think the financial industry needs to acknowledge its side of the problem.
We cannot tell merchants to "stay compliant" and then give them PDFs, spreadsheets, email reminders, and document-upload portals.
That's not infrastructure.
If we're going to place greater first-line responsibility on merchants, we need to give them technology capable of carrying that responsibility.
Merchants need systems that help them:
Responsibility without infrastructure is just another manual process.
This is the gap the industry needs to close.
This is one of the primary reasons we built MyCOA™.
Not as another processor compliance tool.
As infrastructure the merchant itself uses.
The concept is straightforward:
Create and maintain a persistent digital compliance record around the products the merchant sells.
Rather than waiting for somebody downstream to ask for information, the merchant continuously maintains it.
Products.
COAs.
Laboratory documentation.
Supporting evidence.
Product information.
Transparency.
Compliance status.
The merchant becomes an active participant in maintaining a cleaner commerce ecosystem instead of a passive participant waiting for the next compliance request.
Consider how different the relationship becomes.
The legacy model:
Six months pass.
Everything may now be outdated.
A merchant-owned model:
That is a fundamentally healthier relationship.
Compliance becomes a state of readiness instead of an emergency response.
I would make this a standard for every regulated merchant.
Before your processor sees it.
Before your bank sees it.
Before your marketplace sees it.
Before your insurance company sees it.
Before your sponsor bank sees it.
Before a card brand sees it.
Before a regulator sees it.
You should see it.
And you should have the tools to fix it.
That's what mature compliance looks like.
Merchant-owned compliance doesn't eliminate payment-company oversight.
It makes oversight better.
Instead of payment companies spending their resources collecting basic information, they can focus on what they're actually good at:
In other words:
The merchant manages compliance.
The financial institution validates and oversees risk.
That is a far more scalable division of responsibility.
Imagine two merchants applying for processing.
Merchant A sends:
A website.
A product spreadsheet.
Thirty-seven PDF COAs.
Several email attachments.
And an assurance that everything is current.
Merchant B arrives with:
A structured product inventory.
Current supporting evidence connected to those products.
Organized testing records.
Product transparency.
A maintained compliance history.
Which merchant creates greater confidence?
Which merchant is easier to evaluate?
Which merchant is more likely to move through underwriting efficiently?
Which merchant would you rather have in your portfolio?
Compliance maturity can become part of merchant quality.
That's a significant shift.
This is where the model becomes particularly interesting.
Historically, regulated merchant compliance creates cost for payment companies.
More underwriting.
More reviews.
More monitoring.
More merchant outreach.
More compliance personnel.
More remediation.
What if some of that infrastructure could instead become a merchant service?
Payment providers can give regulated merchants access to technology designed to help them manage their own compliance responsibilities—and potentially resell that technology as a value-added service.
The economics begin to change:
Compliance Cost
becomes
Merchant Service
which can become
Recurring Revenue
while simultaneously supporting a cleaner, more transparent portfolio.
That's a rare alignment.
The merchant gets better infrastructure.
The payment company gets better visibility.
Underwriting gets better information.
Risk gets cleaner merchants.
The sponsor bank gets greater confidence.
And the payment provider can create a new recurring revenue stream.
The payments industry has traditionally monetized elevated-risk merchants primarily by charging more for processing.
Higher fees.
Higher reserves.
More underwriting costs.
More monitoring costs.
But perhaps there is another model.
What if payment providers also monetized helping merchants become better businesses?
Compliance technology.
Product transparency.
Merchant readiness.
Continuous documentation.
Certification.
Regulatory infrastructure.
That creates revenue by delivering value rather than merely pricing for risk.
And I believe that is a much more sustainable model for regulated commerce.
Of course, organizations can keep doing what they're doing.
Merchants can maintain spreadsheets.
Processors can request documents.
Risk teams can manually inspect websites.
Compliance departments can chase merchants.
Sponsor banks can perform portfolio reviews.
Teams can scramble whenever regulations change.
And when something gets missed:
Processing may be interrupted.
Merchant accounts may be terminated.
Revenue may disappear.
Portfolios may require remediation.
Sponsor banks may escalate concerns.
Card-brand scrutiny may increase.
Regulatory issues may become considerably more expensive.
Then everyone asks:
"How did we miss this?"
The answer is often painfully simple.
The operating model was designed to discover problems after they existed rather than prevent them from existing in the first place.
This becomes even more important as regulated commerce accelerates.
A merchant may add products tomorrow.
A manufacturer may change a formulation.
A new COA may replace an old one.
A website claim may change this afternoon.
A state may change its requirements.
A federal rule may alter an entire product category.
A sponsor bank may update policy.
A card brand may change its monitoring expectations.
Compliance cannot keep operating as:
Underwrite → Approve → File → Revisit Later.
It must become:
Prepare → Validate → Maintain → Monitor → Remediate → Prove.
And the merchant needs to participate in that process every day.
I believe we're moving toward an era where compliance becomes part of the underlying infrastructure of selling regulated products.
Not something bolted on after the product launches.
Not something addressed when underwriting asks.
Not something fixed when a regulator arrives.
Built in from the beginning.
Product created.
Evidence connected.
Requirements understood.
Transparency established.
Commerce enabled.
Changes monitored.
Compliance maintained.
That's what we mean at Qredible when we talk about Compliant-First Commerce™.
It isn't compliance standing in the way of commerce.
It's compliance becoming infrastructure that makes sustainable commerce possible.
For payment companies and banks serving regulated-product merchants, I believe the conversation should now be:
And the question I think every regulated merchant should be asking is much simpler:
Why am I waiting for my payment processor to tell me there's something wrong with my business?
The future requires a clearer division of responsibility.
Merchants
Own compliance readiness.
Maintain products, documentation, evidence, transparency, and remediation.
Payment Companies
Own risk oversight.
Verify, evaluate, monitor, enforce policy, and manage portfolio exposure.
Sponsor Banks
Own institutional oversight.
Establish risk appetite and ensure appropriate governance and controls.
Technology
Connect the ecosystem.
Make information structured, continuous, searchable, verifiable, and actionable.
Each participant still has responsibilities.
But they no longer need to perform everyone else's work.
Why We Built MyCOA™
MyCOA was built around a simple belief:
The best time to fix a compliance problem is before someone else discovers it.
We want regulated merchants to have infrastructure that helps them manage their products and compliance evidence continuously—not simply when a bank, processor, regulator, or customer asks for it.
And we want payment companies to have a different relationship with those merchants.
Less chasing.
Less manual review.
Less reaction.
More transparency.
More readiness.
More intelligence.
More sustainable revenue.
MyCOA is not intended to replace the independent compliance responsibilities of financial institutions.
It is designed to make the merchant a stronger first line of defense.
That is a distinction I believe regulated commerce desperately needs.
Learn More about MyCOA: www.qredible.com
For too long, regulated commerce has operated with an unspoken assumption:
The merchant sells.
The payment company checks.
Risk finds the problems.
Compliance cleans them up.
That model needs to change.
If you manufacture regulated products, compliance is part of manufacturing.
If you distribute regulated products, compliance is part of distribution.
If you market regulated products, compliance is part of marketing.
And if you sell regulated products:
Banks and payment companies must continue to perform appropriate oversight.
But they should not have to be the first ones to discover that the merchant isn't doing its job.
Give merchants responsibility.
Give them the technology to carry it.
Give financial institutions the intelligence to verify it.
And build an ecosystem where compliance problems are identified before they become payment problems.
Because the future of regulated commerce cannot be built around waiting to get caught.
It must be built around staying ahead.
Qredible is redefining merchant underwriting through Merchant Risk Intelligence (MRI)—a product-first approach that continuously analyzes what businesses sell, how they market those products, and the evidence required to support compliant payment acceptance. By moving beyond static industry classifications, Qredible helps banks, payment processors, ISOs, and sponsor banks make faster, more informed, and more defensible underwriting decisions while reducing manual effort and strengthening ongoing portfolio oversight. Learn more about Qredible's product-first automated compliance management platform for regulated industries →