
| ""After more than 30 years in payments, I believe one of the biggest constraints on our industry's future is something we've become so accustomed to using that we've stopped questioning it." - Noah Fitzgerald, CPP, CRO Qredible, Inc. |

I've Spent More Than Three Decades Watching Payments Evolve
I entered the payments industry in the early 1990s.
Since then, I've watched nearly everything about commerce transform.
We moved from dial-up terminals to connected commerce.
From paper applications to digital onboarding.
From countertop terminals to smartphones.
From physical storefronts to global e-commerce.
From batch processing to real-time authorization.
From domestic acquiring to global platforms.
From simple retail categories to merchants selling hundreds of thousands of products across websites, marketplaces, apps, social platforms, subscriptions, wholesale channels, and physical locations.
Our technology became exponentially more sophisticated.
Our merchants became exponentially more complicated.
Our regulations became exponentially more complex.
And yet, at the center of how we still describe a merchant sits something remarkably simple:
Four digits.
The Merchant Category Code.
After more than 30 years in this industry, I think it is time we challenge whether that is enough.
It isn't.
MCCs serve an important purpose.
They provide standardized categorization across an extraordinarily complex global payments ecosystem and support functions ranging from interchange and reporting to card-network rules and transaction processing.
We need them.
But somewhere along the way, the industry began asking MCCs to tell us things they were never designed to tell us.
We started using merchant categories as proxies for:
And that is where the model begins to break down.
The problem isn't the MCC.
The problem is everything we've built on top of it.
Consider a health and wellness retailer.
What does it sell?
Maybe vitamins.
Maybe protein powder.
Maybe CBD.
Maybe functional mushrooms.
Maybe nootropics.
Maybe peptides.
Maybe weight-loss products.
Maybe cosmetics.
Maybe all of them.
The business may have one MCC.
But those products can have completely different regulatory requirements, processor policies, sponsor-bank considerations, documentation requirements, and risk profiles.
So what exactly does the MCC tell us?
It tells us what category the merchant broadly resembles.
It does not necessarily tell us what we actually need to know.
This is the foundational problem.
Classification is not intelligence.
Assigning a merchant to a category makes that merchant easier to organize.
It does not mean we understand the business.
Think about the difference.
A category tells us:
"This is a health and wellness merchant."
Intelligence tells us:
"This merchant sells 428 products across six categories, including 37 regulated products. Four require additional documentation, two are inconsistent with current policy, and the remaining catalog is supportable."
Those are radically different levels of understanding.
One organizes.
The other enables a decision.
This is where the problem becomes more than academic.
Traditional merchant acceptance frequently begins with a question like:
What industry is this merchant in?
That classification then influences whether the organization:
Accepts it.
or
Declines it.
CBD?
High risk.
Vape?
High risk.
Nutraceuticals?
Elevated risk.
Telehealth?
Elevated risk.
Online lending?
Elevated risk.
Dating?
Elevated risk.
And entire industries can become difficult to support because organizations don't possess sufficient intelligence to distinguish one business from another.
This creates an enormous problem.
Category-level risk encourages category-level decisions.
And category-level decisions are often unnecessarily blunt.
I've spent much of my career working with businesses that the payments industry describes as high risk.
I've never particularly liked the term.
Because "high risk" often tells us less about the merchant than it tells us about our ability to understand the merchant.
Consider two merchants operating in the same industry.
One has:
The other has none of those things.
Yet at the category level, they may look identical.
Same MCC.
Same industry.
Same "risk classification."
Are they really the same risk?
Of course not.
The difference is intelligence.
It's Revenue.
This is where I believe the conversation needs to move into the executive suite.
Every time we use broad classifications instead of precise intelligence, we potentially create one of two mistakes.
Mistake One: Accepting Risk We Don't Understand
A merchant fits the category, passes underwriting, and gets approved.
But products, claims, licenses, or activities inside the business create risks the category never revealed.
Mistake Two: Rejecting Revenue We Could Have Supported
A merchant operates in an elevated-risk category, so the organization declines the entire business even though the underlying products and operations may be perfectly supportable.
One mistake creates risk.
The other destroys opportunity.
Both are intelligence failures.
It's Greater Precision
This distinction matters.
I am not advocating that banks or payment companies loosen their risk standards.
Quite the opposite.
I believe we can become significantly more precise about risk.
Instead of asking:
"Do we support CBD?"
ask:
"Which CBD products, merchant models, jurisdictions, documentation standards, marketing practices, and operating characteristics fit our policy?"
Instead of:
"Do we support nutraceuticals?"
ask:
"What exactly is being sold, what claims are being made, and which products create exposure?"
Instead of:
"Do we support telehealth?"
ask:
"What services are being provided, by whom, under what licensing structure, with which fulfillment model?"
That is a fundamentally different approach to merchant acceptance.
It replaces category risk with risk precision.
For most of payments history, we treated the merchant as the fundamental unit of analysis.
That made sense.
Today, it increasingly doesn't.
The modern risk hierarchy looks more like:
Portfolio
↓
Merchant
↓
Business Model
↓
Channel
↓
Product or Service
↓
Claim / Ingredient / Activity
↓
Evidence
Risk can exist at any layer.
Yet much of our infrastructure still attempts to compress all of that complexity back into a merchant category.
We're taking multidimensional businesses and flattening them into four digits.
Then we're surprised when the answer isn't precise enough.
Merchant Intelligence Tells Us What It Actually Is.
There is another problem I've watched throughout my career.
Businesses change.
A merchant boards today selling one set of products.
Six months later, it adds another.
A year later, it enters another market.
Then it adds subscriptions.
Then wholesale.
Then a new website.
Then a new product category.
The MCC may never change.
The business certainly did.
This is why merchant classification cannot substitute for Continuous Merchant Intelligence™.
One describes a category.
The other describes reality.
Sometimes the best way to expose a legacy assumption is to explain it to someone who didn't grow up with it.
Imagine telling a technology executive:
Their first question would probably be:
"What other data do you use?"
And that's exactly the question our industry should be asking.
Because today we have access to:
The issue isn't whether more intelligence exists.
The issue is whether our operating models are designed to use it.
This is the question I keep coming back to.
Forget how payments works today.
Imagine we're sitting in a room designing the global merchant acceptance infrastructure from scratch.
Someone asks:
"How should we determine whether a business is supportable?"
Would our answer really be:
"First, let's put every business in the world into a few hundred broad categories."
Probably not.
We would build a multi-dimensional intelligence model.
We would understand:
And we would continuously update that understanding.
In other words:
We would build Merchant Intelligence.
This isn't just an underwriting conversation.
It's a revenue conversation.
I've spent decades watching sales organizations find a merchant, submit an application, and then wait to discover whether underwriting can approve it.
Think about how backwards that is.
We should know far more before the first sales conversation ever occurs.
Imagine giving a sales professional intelligence about:
before they call the merchant.
Sales changes.
The conversation changes.
Placement changes.
Conversion changes.
Merchant experience changes.
Intelligence moves underwriting upstream into revenue generation.
That is one of the most significant opportunities I see for the payments industry.
Instead of asking underwriters to discover everything manually, intelligence arrives with the merchant.
The underwriter becomes less of an investigator and more of a decision-maker.
That's where experienced underwriting professionals create the greatest value.
Not opening browser tabs.
Not searching websites.
Not chasing documents.
Not assembling spreadsheets.
Making informed judgments.
Technology should do the gathering.
Intelligence should provide the context.
Humans should make the decisions that require judgment.
Now take the same intelligence beyond onboarding.
Imagine being able to ask:
Suddenly, the portfolio is no longer a collection of merchant IDs and MCCs.
It becomes a living intelligence environment.
That changes risk management completely.
When regulations change today, many organizations begin an investigation.
Who is affected?
Which merchants?
Which products?
What needs to change?
Who needs remediation?
How long will this take?
But if the portfolio is already understood at the merchant and product level, regulatory response becomes fundamentally different.
You aren't beginning with discovery.
You begin with intelligence.
That may become one of the defining capabilities of the next generation of payments infrastructure.
This is ultimately where I believe the greatest transformation occurs.
For decades, risk and revenue have often appeared to sit on opposite sides of the table.
Sales wants to approve more merchants.
Risk wants to protect the portfolio.
Compliance wants to satisfy requirements.
Operations wants efficiency.
Leadership wants growth.
Better intelligence changes that equation.
Because the objective becomes:
That's not "taking more risk."
That's understanding risk well enough to stop leaving good revenue on the table.
Not the Answer.
This is where I believe the future ultimately lands.
MCCs aren't going away.
Nor should they.
But their role should change.
An MCC should be one attribute among many within a much richer merchant intelligence model.
Imagine a merchant profile incorporating:
Identity + Ownership + MCC + Business Model + Products + Services + Geography + Regulation + Evidence + Behavior + Change
Now we're getting somewhere.
MCC remains valuable.
It simply stops carrying the burden of explaining the merchant by itself.
When we began building Qredible, we could have built another underwriting workflow.
We didn't.
Because we believed the industry's challenge wasn't simply how merchants move through underwriting.
The larger challenge was how organizations understand merchants in the first place.
That led us toward a fundamentally different architecture centered on:
The objective isn't to eliminate the MCC.
It's to put the MCC in its proper place.
As one signal inside a much richer intelligence environment.
I've seen this industry reinvent itself many times.
I've watched technologies that once seemed indispensable become obsolete.
I've watched entire business models emerge that none of us could have imagined when I entered payments.
And I've learned something important along the way.
Legacy systems rarely disappear because they stop working.
They become obsolete because the world around them changes.
MCCs still work.
But commerce has outgrown what MCC-level thinking can tell us.
The next transformation in payments won't simply be:
Faster payments.
Better terminals.
More APIs.
More AI.
It will be a transformation in how deeply we understand the businesses we enable.
And perhaps the most uncomfortable question:
I don't believe the MCC is dead.
But I believe MCC-first thinking should be.
Four digits cannot adequately represent a modern business.
They cannot tell us everything it sells.
They cannot tell us whether those products comply.
They cannot tell us how the business changed yesterday.
They cannot tell us whether the merchant fits a particular institution's policies.
And they certainly cannot tell us whether the merchant represents sustainable revenue.
For more than three decades, I've watched payments become extraordinarily sophisticated at moving money.
Now we need to become equally sophisticated at understanding the businesses behind that money.
The next generation of merchant acceptance will not be built around categories.
It will be built around intelligence.
And that may fundamentally change underwriting, risk management, compliance—and the economics of merchant growth itself.
Qredible is redefining merchant underwriting through Merchant Risk Intelligence (MRI)—a product-first approach that continuously analyzes what businesses sell, how they market those products, and the evidence required to support compliant payment acceptance. By moving beyond static industry classifications, Qredible helps banks, payment processors, ISOs, and sponsor banks make faster, more informed, and more defensible underwriting decisions while reducing manual effort and strengthening ongoing portfolio oversight. Learn more about Qredible's product-first automated compliance management platform for regulated industries →