A 4 digit code - the MCC Code - is no longer a satisfactory means of quantifying and assigning merchant risk. Modern commerce is dynamic and requires Merchant Intelligence and Product Intelligence to properly assess a merchant's risk portfolio. Get both from Qredible.

The Death of MCC Codes

Author: Noah Fitzgerald, CPP
Date: August 13, 2026

The Death of MCC Codes

We Cannot Build the Future of Merchant Acceptance Around Four Digits

""After more than 30 years in payments, I believe one of the biggest constraints on our industry's future is something we've become so accustomed to using that we've stopped questioning it."
- Noah Fitzgerald, CPP, CRO Qredible, Inc.

 


Noah Fitzgerald, CPP - Chief Revenue Officer, Qredible, Inc.
I've Spent More Than Three Decades Watching Payments Evolve

I entered the payments industry in the early 1990s.

Since then, I've watched nearly everything about commerce transform.

We moved from dial-up terminals to connected commerce.

From paper applications to digital onboarding.

From countertop terminals to smartphones.

From physical storefronts to global e-commerce.

From batch processing to real-time authorization.

From domestic acquiring to global platforms.

From simple retail categories to merchants selling hundreds of thousands of products across websites, marketplaces, apps, social platforms, subscriptions, wholesale channels, and physical locations.

Our technology became exponentially more sophisticated.

Our merchants became exponentially more complicated.

Our regulations became exponentially more complex.

And yet, at the center of how we still describe a merchant sits something remarkably simple:

Four digits.

The Merchant Category Code.

After more than 30 years in this industry, I think it is time we challenge whether that is enough.

It isn't.


Before Everyone Gets Angry: MCCs Aren't Actually Dying

MCCs serve an important purpose.

They provide standardized categorization across an extraordinarily complex global payments ecosystem and support functions ranging from interchange and reporting to card-network rules and transaction processing.

We need them.

But somewhere along the way, the industry began asking MCCs to tell us things they were never designed to tell us.

We started using merchant categories as proxies for:

  • Risk
  • Acceptability
  • Compliance
  • Underwriting
  • Product exposure
  • Regulatory obligations
  • Portfolio segmentation
  • Processor placement
  • Revenue opportunity

And that is where the model begins to break down.

The problem isn't the MCC.

The problem is everything we've built on top of it.


Four Digits Cannot Explain a Modern Business

Consider a health and wellness retailer.

What does it sell?

Maybe vitamins.

Maybe protein powder.

Maybe CBD.

Maybe functional mushrooms.

Maybe nootropics.

Maybe peptides.

Maybe weight-loss products.

Maybe cosmetics.

Maybe all of them.

The business may have one MCC.

But those products can have completely different regulatory requirements, processor policies, sponsor-bank considerations, documentation requirements, and risk profiles.

So what exactly does the MCC tell us?

It tells us what category the merchant broadly resembles.

It does not necessarily tell us what we actually need to know.


We Have Confused Classification With Understanding

This is the foundational problem.

Classification is not intelligence.

Assigning a merchant to a category makes that merchant easier to organize.

It does not mean we understand the business.

Think about the difference.

A category tells us:

"This is a health and wellness merchant."

Intelligence tells us:

"This merchant sells 428 products across six categories, including 37 regulated products. Four require additional documentation, two are inconsistent with current policy, and the remaining catalog is supportable."

Those are radically different levels of understanding.

One organizes.

The other enables a decision.


MCC Thinking Encourages Binary Risk Decisions

This is where the problem becomes more than academic.

Traditional merchant acceptance frequently begins with a question like:

What industry is this merchant in?

That classification then influences whether the organization:

Accepts it.

or

Declines it.

CBD?

High risk.

Vape?

High risk.

Nutraceuticals?

Elevated risk.

Telehealth?

Elevated risk.

Online lending?

Elevated risk.

Dating?

Elevated risk.

And entire industries can become difficult to support because organizations don't possess sufficient intelligence to distinguish one business from another.

This creates an enormous problem.

Category-level risk encourages category-level decisions.

And category-level decisions are often unnecessarily blunt.


"High Risk" May Be One of the Most Expensive Labels in Payments

I've spent much of my career working with businesses that the payments industry describes as high risk.

I've never particularly liked the term.

Because "high risk" often tells us less about the merchant than it tells us about our ability to understand the merchant.

Consider two merchants operating in the same industry.

One has:

  • Strong compliance
  • Transparent ownership
  • Proper licensing
  • Compliant products
  • Current supporting documentation
  • Responsible marketing
  • Strong operating history

The other has none of those things.

Yet at the category level, they may look identical.

Same MCC.

Same industry.

Same "risk classification."

Are they really the same risk?

Of course not.

The difference is intelligence.


The Cost Isn't Just Risk

It's Revenue.

This is where I believe the conversation needs to move into the executive suite.

Every time we use broad classifications instead of precise intelligence, we potentially create one of two mistakes.

Mistake One: Accepting Risk We Don't Understand

A merchant fits the category, passes underwriting, and gets approved.

But products, claims, licenses, or activities inside the business create risks the category never revealed.

Mistake Two: Rejecting Revenue We Could Have Supported

A merchant operates in an elevated-risk category, so the organization declines the entire business even though the underlying products and operations may be perfectly supportable.

One mistake creates risk.

The other destroys opportunity.

Both are intelligence failures.


The Future of Risk Isn't Lower Risk

It's Greater Precision

This distinction matters.

I am not advocating that banks or payment companies loosen their risk standards.

Quite the opposite.

I believe we can become significantly more precise about risk.

Instead of asking:

"Do we support CBD?"

ask:

"Which CBD products, merchant models, jurisdictions, documentation standards, marketing practices, and operating characteristics fit our policy?"

Instead of:

"Do we support nutraceuticals?"

ask:

"What exactly is being sold, what claims are being made, and which products create exposure?"

Instead of:

"Do we support telehealth?"

ask:

"What services are being provided, by whom, under what licensing structure, with which fulfillment model?"

That is a fundamentally different approach to merchant acceptance.

It replaces category risk with risk precision.


The Merchant Is No Longer the Smallest Unit of Risk

For most of payments history, we treated the merchant as the fundamental unit of analysis.

That made sense.

Today, it increasingly doesn't.

The modern risk hierarchy looks more like:

Portfolio

Merchant

Business Model

Channel

Product or Service

Claim / Ingredient / Activity

Evidence

Risk can exist at any layer.

Yet much of our infrastructure still attempts to compress all of that complexity back into a merchant category.

We're taking multidimensional businesses and flattening them into four digits.

Then we're surprised when the answer isn't precise enough.


MCCs Tell Us What a Merchant Was Supposed to Be

Merchant Intelligence Tells Us What It Actually Is.

There is another problem I've watched throughout my career.

Businesses change.

A merchant boards today selling one set of products.

Six months later, it adds another.

A year later, it enters another market.

Then it adds subscriptions.

Then wholesale.

Then a new website.

Then a new product category.

The MCC may never change.

The business certainly did.

This is why merchant classification cannot substitute for Continuous Merchant Intelligence™.

One describes a category.

The other describes reality.


Imagine Trying to Explain This to Someone Outside Payments

Sometimes the best way to expose a legacy assumption is to explain it to someone who didn't grow up with it.

Imagine telling a technology executive:

  • "We have millions of businesses operating across incredibly complex digital ecosystems. We classify each one primarily using a four-digit code, and that classification plays an important role in determining how we evaluate and manage them."

Their first question would probably be:

"What other data do you use?"

And that's exactly the question our industry should be asking.

Because today we have access to:

  • Websites
  • Product catalogs
  • Regulatory databases
  • Licensing records
  • Ownership information
  • Product documentation
  • Laboratory results
  • Consumer reviews
  • Marketing content
  • Social media
  • Legal records
  • Transaction behavior
  • Geographic intelligence
  • AI
  • Machine learning

The issue isn't whether more intelligence exists.

The issue is whether our operating models are designed to use it.


If We Invented Merchant Acceptance Today, We Would Never Build It This Way

This is the question I keep coming back to.

Forget how payments works today.

Imagine we're sitting in a room designing the global merchant acceptance infrastructure from scratch.

Someone asks:

"How should we determine whether a business is supportable?"

Would our answer really be:

"First, let's put every business in the world into a few hundred broad categories."

Probably not.

We would build a multi-dimensional intelligence model.

We would understand:

  • Who operates the business.
  • What the business does.
  • What it sells.
  • Where it sells.
  • How it markets.
  • What regulations apply.
  • What evidence supports compliance.
  • How the business changes.
  • Whether it fits our specific policies.

And we would continuously update that understanding.

In other words:

We would build Merchant Intelligence.


This Changes Sales Too

This isn't just an underwriting conversation.

It's a revenue conversation.

I've spent decades watching sales organizations find a merchant, submit an application, and then wait to discover whether underwriting can approve it.

Think about how backwards that is.

We should know far more before the first sales conversation ever occurs.

Imagine giving a sales professional intelligence about:

  • Business model
  • Products
  • Potential regulatory issues
  • Website concerns
  • Likely MCC
  • Documentation gaps
  • Policy compatibility
  • Placement considerations
  • Remediation requirements

before they call the merchant.

Sales changes.

The conversation changes.

Placement changes.

Conversion changes.

Merchant experience changes.

Intelligence moves underwriting upstream into revenue generation.

That is one of the most significant opportunities I see for the payments industry.


It Changes Underwriting

Instead of asking underwriters to discover everything manually, intelligence arrives with the merchant.

The underwriter becomes less of an investigator and more of a decision-maker.

That's where experienced underwriting professionals create the greatest value.

Not opening browser tabs.

Not searching websites.

Not chasing documents.

Not assembling spreadsheets.

Making informed judgments.

Technology should do the gathering.

Intelligence should provide the context.

Humans should make the decisions that require judgment.


It Changes Portfolio Management

Now take the same intelligence beyond onboarding.

Imagine being able to ask:

  • Which merchants sell a particular product?
  • Which merchants added a newly restricted product this month?
  • Which merchants are making a particular marketing claim?
  • Which licenses expire next quarter?
  • Which merchants no longer fit sponsor-bank policy?
  • Which merchants could become supportable with remediation?

Suddenly, the portfolio is no longer a collection of merchant IDs and MCCs.

It becomes a living intelligence environment.

That changes risk management completely.


It Changes Regulatory Response

When regulations change today, many organizations begin an investigation.

Who is affected?

Which merchants?

Which products?

What needs to change?

Who needs remediation?

How long will this take?

But if the portfolio is already understood at the merchant and product level, regulatory response becomes fundamentally different.

You aren't beginning with discovery.

You begin with intelligence.

That may become one of the defining capabilities of the next generation of payments infrastructure.


It Changes the Economics of Merchant Acceptance

This is ultimately where I believe the greatest transformation occurs.

For decades, risk and revenue have often appeared to sit on opposite sides of the table.

Sales wants to approve more merchants.

Risk wants to protect the portfolio.

Compliance wants to satisfy requirements.

Operations wants efficiency.

Leadership wants growth.

Better intelligence changes that equation.

Because the objective becomes:

  • Find the greatest amount of sustainable revenue that fits within the organization's defined risk appetite.

That's not "taking more risk."

That's understanding risk well enough to stop leaving good revenue on the table.


MCC Should Become an Attribute

Not the Answer.

This is where I believe the future ultimately lands.

MCCs aren't going away.

Nor should they.

But their role should change.

An MCC should be one attribute among many within a much richer merchant intelligence model.

Imagine a merchant profile incorporating:

Identity + Ownership + MCC + Business Model + Products + Services + Geography + Regulation + Evidence + Behavior + Change

Now we're getting somewhere.

MCC remains valuable.

It simply stops carrying the burden of explaining the merchant by itself.


Why We Built Qredible Differently

When we began building Qredible, we could have built another underwriting workflow.

We didn't.

Because we believed the industry's challenge wasn't simply how merchants move through underwriting.

The larger challenge was how organizations understand merchants in the first place.

That led us toward a fundamentally different architecture centered on:

  • Merchant Intelligence™
  • Product Intelligence™
  • Regulatory Intelligence™
  • Website Intelligence™
  • Portfolio Intelligence™
  • Continuous Monitoring
  • Evidence
  • Trust

The objective isn't to eliminate the MCC.

It's to put the MCC in its proper place.

As one signal inside a much richer intelligence environment.


After 30+ Years, This Is What I Believe

I've seen this industry reinvent itself many times.

I've watched technologies that once seemed indispensable become obsolete.

I've watched entire business models emerge that none of us could have imagined when I entered payments.

And I've learned something important along the way.

Legacy systems rarely disappear because they stop working.

They become obsolete because the world around them changes.

MCCs still work.

But commerce has outgrown what MCC-level thinking can tell us.

The next transformation in payments won't simply be:

Faster payments.

Better terminals.

More APIs.

More AI.

It will be a transformation in how deeply we understand the businesses we enable.


Questions I Think Every Payments Executive Should Be Asking

  • Are MCCs helping us classify merchants—or causing us to oversimplify them?
  • How many good merchants are we declining because of broad category policies?
  • How much hidden risk exists inside merchants we've already classified as acceptable?
  • Do we know what our merchants actually sell?
  • Can we search our portfolio below the merchant level?
  • Can our sales organization understand merchant supportability before submission?
  • Can we immediately identify which merchants are affected when regulations change?
  • Are our underwriters gathering information—or making decisions?
  • Are we managing merchant categories or managing merchant intelligence?

And perhaps the most uncomfortable question:

  • How much revenue are we leaving on the table because our ability to understand merchants hasn't kept pace with our ability to process their transactions?

Final Thought

I don't believe the MCC is dead.

But I believe MCC-first thinking should be.

Four digits cannot adequately represent a modern business.

They cannot tell us everything it sells.

They cannot tell us whether those products comply.

They cannot tell us how the business changed yesterday.

They cannot tell us whether the merchant fits a particular institution's policies.

And they certainly cannot tell us whether the merchant represents sustainable revenue.

For more than three decades, I've watched payments become extraordinarily sophisticated at moving money.

Now we need to become equally sophisticated at understanding the businesses behind that money.

The next generation of merchant acceptance will not be built around categories.

It will be built around intelligence.

And that may fundamentally change underwriting, risk management, compliance—and the economics of merchant growth itself.

 

About Qredible

Qredible is redefining merchant underwriting through Merchant Risk Intelligence (MRI)—a product-first approach that continuously analyzes what businesses sell, how they market those products, and the evidence required to support compliant payment acceptance. By moving beyond static industry classifications, Qredible helps banks, payment processors, ISOs, and sponsor banks make faster, more informed, and more defensible underwriting decisions while reducing manual effort and strengthening ongoing portfolio oversight. Learn more about Qredible's product-first automated compliance management platform for regulated industries →



crossmenu