
| "Updating a policy is easy. Proving that thousands of existing merchants comply with it is where the real work begins." - Noah Fitzgerald, CPP, CRO Qredible, Inc. |
The Email Arrives Monday Morning

Imagine you're leading risk or compliance at a payment processor.
Your sponsor bank sends an updated policy.
Effective immediately, any merchant selling Acme Product must satisfy a new product requirement.
Additionally, merchants cannot use certain language when marketing Acme Product on their websites or social media.
Your team reviews the requirement.
Legal weighs in.
Compliance updates the policy.
Underwriting gets new procedures.
The onboarding workflow gets another checkbox.
Sales receives a notification.
Done.
Right?
Not even close.
Because you don't just have tomorrow's merchants.
You have yesterday's 10,000 merchants.
Somewhere inside that portfolio are merchants selling Acme Product.
Some disclosed it.
Some didn't.
Some didn't sell it when you underwrote them but added it later.
Some sell it inside a much larger product catalog.
Some may meet the new requirement.
Others won't.
Some may be using prohibited marketing language.
And your sponsor bank just asked you to make sure they're compliant.
So now answer the question:
How in the hell are you going to do that?
Welcome to one of the least discussed and most consequential problems in modern merchant compliance.
The Portfolio Re-Audit Problem.
This distinction matters.
When regulations, card-brand requirements, sponsor-bank policies, or internal risk standards change, organizations naturally update onboarding.
That's necessary.
But it's only half the problem.
Your existing merchants don't magically inherit the new controls because somebody updated the underwriting manual.
If the requirement applies to existing commerce, you need to determine:
That's not policy management.
That's portfolio intelligence.
And most legacy compliance infrastructure wasn't designed to do it.
Strip away all the complexity and this is fundamentally what happens.
Someone changes a rule.
Then your organization has to answer:
Where does this rule intersect with our portfolio?
That's the hard part.
If the rule applies broadly to every merchant, identifying the population may be relatively straightforward.
Product-specific changes are different.
Imagine the requirement applies to:
A particular cannabinoid.
A specific vape manufacturer.
A mushroom constituent.
A nutraceutical ingredient.
A particular product claim.
A pharmaceutical compound.
A restricted SKU.
A particular category of hemp beverage.
Suddenly an MCC isn't enough.
A merchant application isn't enough.
A list of “high-risk merchants” isn't enough.
You need to know what your merchants actually sell.
And that's where the operational nightmare begins.
Option One: Send Everyone a Letter
This is probably the easiest response.
Identify the broad merchant population and send a communication:
Simple.
Fast.
Relatively inexpensive.
And potentially almost impossible to validate.
First, you may unnecessarily alarm thousands of merchants who don't sell the product.
Some will call their sales representative.
Others will call support.
Agents will start asking questions.
Merchants may interpret the communication as a change in your appetite for their industry.
Competitors may use the confusion against you.
You can create unnecessary merchant anxiety and potentially damage your brand.
But there's a bigger problem.
What happens after they receive the email?
Did they read it?
Did they understand it?
Do they sell the product?
Did they evaluate the requirement correctly?
Did they remove a prohibited claim?
Did they replace a noncompliant product?
Did they provide updated evidence?
How do you know?
A notification demonstrates communication.
It doesn't necessarily demonstrate compliance.
Option Two: Audit the Portfolio Internally
Fine.
Let's actually check.
Compliance identifies the potentially affected merchants.
Analysts begin opening websites.
Searching product catalogs.
Reviewing product pages.
Checking ingredients.
Looking at labels.
Reviewing COAs.
Searching marketing language.
Checking social media.
Documenting findings.
Creating cases.
Contacting merchants.
Tracking remediation.
Following up.
Then revisiting websites to verify the changes were actually made.
This can work.
It has worked for decades.
But let's acknowledge what it actually requires.
People.
Lots of them.
And not inexpensive people.
Experienced underwriting, risk, and compliance professionals are now performing repetitive discovery work across potentially thousands of merchants and tens or hundreds of thousands of products.
Meanwhile:
New merchants still need underwriting.
Existing alerts still need review.
Chargebacks still happen.
Fraud still happens.
Sponsor-bank requests still arrive.
Audits still occur.
Regulations continue changing.
Your team didn't suddenly get another 500 hours in the week because a policy changed.
Something has to give.
Congratulations.
You completed the audit.
Everything is clean.
Tuesday morning, one merchant adds Acme Product back to its website.
Another introduces it next month.
A third changes its marketing copy.
A fourth adds a new brand.
A fifth launches another website.
Your completed audit begins aging the moment it ends.
That's the part nobody likes discussing.
A point-in-time audit proves a point in time.
It does not create continuous compliance.
Option Three: Hire Someone Else to Do It
The third option is outsourcing.
Bring in consultants.
Auditors.
Temporary personnel.
Specialized compliance firms.
There can be legitimate advantages.
You gain capacity.
You may gain specialized expertise.
Your internal teams remain focused on core responsibilities.
But the underlying problem hasn't necessarily changed.
Someone is still:
Opening websites.
Finding products.
Reviewing documents.
Recording findings.
Building spreadsheets.
Contacting merchants.
Checking remediation.
And now you're paying external rates to do it.
Then the engagement ends.
You receive the report.
Everyone celebrates.
And the portfolio starts changing again.
You have successfully outsourced the labor.
You haven't necessarily solved the operating model.
This is the fundamental failure.
Commerce is continuous.
Compliance change is continuous.
Merchant change is continuous.
Product change is continuous.
Yet our response is frequently:
Project.
Audit.
Remediate.
Close.
Repeat.
That architecture made sense when technology couldn't economically maintain continuous visibility.
But we're living in 2026.
The technology exists.
The information exists.
The computing power exists.
AI exists.
Machine learning exists.
Web intelligence exists.
Document intelligence exists.
Regulatory data exists.
Automated monitoring exists.
The question isn't whether we can build a better model.
The uncomfortable question is:
Why haven't we?
After more than 30 years in this industry, I've learned that organizations generally optimize around what they're rewarded for.
Compliance infrastructure costs money today.
The financial consequences of inadequate infrastructure may happen tomorrow.
That creates an unfortunate incentive.
Don't disrupt merchants unnecessarily.
Don't increase operating costs.
Don't add friction to sales.
Don't make underwriting harder.
Don't spend money unless required.
And perhaps most dangerously:
Don't look too deeply unless somebody forces us to.
Because deeper visibility creates another problem.
Once you know something exists, you have to deal with it.
Sometimes ignorance feels operationally cheaper.
Until it isn't.
I believe this deserves its own discussion.
Suppose you're a processor with 50,000 merchants.
Leadership approves a comprehensive product-level audit.
What happens if you discover:
2,000 policy violations?
Hundreds of merchants requiring remediation?
Products your sponsor bank won't support?
Undisclosed regulated activity?
Website claims that should have been identified years ago?
Suddenly you have a major operational project.
Merchant relationships are at risk.
Revenue may be affected.
Agents may become angry.
Sales may push back.
Management has difficult decisions to make.
It is understandable why organizations hesitate.
But avoiding the answer does not eliminate the exposure.
It simply determines who discovers it first.
Your team.
Your sponsor bank.
A card brand.
A regulator.
Or a plaintiff's attorney.
I know which one I'd rather have.
There has long been a version of plausible deniability within payments.
The merchant was compliant when we underwrote them.
They changed later.
We didn't know.
They added the product after approval.
Their website changed.
They didn't disclose it.
At one time, those explanations could reflect genuine technological limitations.
It was impossible for a human compliance team to inspect every page, product, claim, document, and change across thousands of merchants every day.
But technology changes what is reasonably knowable.
That matters.
The question increasingly isn't simply:
“Did you know?”
It becomes:
“Did you have reasonable controls designed to find out?”
That's a much more uncomfortable question.
Think about this from a sponsor bank's perspective.
You have a policy saying Acme Product requires Requirement X.
Great.
Now I ask:
Which merchants sell Acme Product?
You don't know.
Which products did you review?
You don't know.
Which merchants violated the requirement?
You don't know.
Which merchants remediated?
You have emails.
Are they still compliant today?
You'd need to check again.
Then what exactly does the policy accomplish?
It establishes an expectation.
But without visibility, detection, remediation, and evidence, the institution has limited ability to demonstrate that the expectation is operating effectively.
That's the difference between:
Policy
and
Control.
This is where I believe our industry's thinking needs to change.
The objective shouldn't be to maintain more policies.
It should be to operationalize them.
A modern compliance control should increasingly work something like this:
RULE CHANGES
↓
POLICY IS UPDATED
↓
REQUIREMENT BECOMES MACHINE-READABLE CRITERIA
↓
PORTFOLIO IS EVALUATED
↓
AFFECTED MERCHANTS & PRODUCTS ARE IDENTIFIED
↓
EXCEPTIONS ARE PRIORITIZED
↓
MERCHANTS ARE REMEDIATED
↓
EVIDENCE IS CAPTURED
↓
COMPLIANCE IS RE-VERIFIED
↓
ONGOING MONITORING CONTINUES
That's an operating system.
Not a PDF.
Our hypothetical Acme Product example exposes the central issue.
If the policy applies to a product, you need product intelligence.
If it applies to an ingredient, you need ingredient-level intelligence.
If it applies to a marketing claim, you need content intelligence.
If it applies to geography, you need geographic context.
If it requires evidence, you need evidence attached to the relevant product or merchant.
You cannot reliably manage increasingly granular regulatory requirements with only:
Merchant → MCC → Industry → Policy
The model needs to become:
Merchant
↓
Product
↓
Attribute / Ingredient / Claim
↓
Evidence
↓
Applicable Rule
↓
Institutional Policy
↓
Compliance Status
↓
Remediation
↓
Continuous Monitoring
That's what modern commerce increasingly requires.
It's What You Learn During It.
Suppose you have no choice today.
You need to audit 5,000 merchants manually.
Do it.
But don't waste the work.
Every product you identify should become structured intelligence.
Every document should be connected.
Every website should be mapped.
Every product category should be classified.
Every compliance finding should become data.
Every remediation should become part of the record.
Every policy relationship should be retained.
Because six months from now another rule will change.
If all of today's work ended up in a spreadsheet, you're going to do it again.
If today's audit created a persistent product-intelligence layer, next time you may be able to ask:
“Show me every affected merchant.”
That is an entirely different operating model.
I would challenge another phrase we use.
Clean portfolio.
A portfolio can be clean at a point in time.
It cannot remain clean without controls.
Merchants change.
Products change.
Websites change.
Ownership changes.
Regulations change.
Licenses expire.
Documents expire.
Policies change.
A clean portfolio is therefore not a destination.
It's a continuously maintained condition.
That distinction changes the technology you need.
When portfolio compliance fails, organizations often focus on merchant attrition or lost processing revenue.
Those may be the smallest costs.
Depending on the circumstances, consequences can include:
Across financial services, major compliance and control failures have produced extraordinarily large financial consequences over the years.
But the hardest cost to quantify may be trust.
Once a bank, regulator, card brand, partner, or merchant loses confidence in your controls, rebuilding that confidence is expensive.
This is where I disagree with the idea that better compliance simply means more expense.
Better compliance infrastructure can create competitive advantage.
Imagine being the processor that can tell a sponsor bank:
Imagine telling an ISO:
Imagine telling a merchant:
Imagine telling sales:
Now compliance isn't merely protecting revenue.
It's enabling revenue.
For years, payments companies have competed on:
Price.
Residuals.
Technology.
Customer service.
Funding speed.
Integrations.
All important.
But as commerce becomes more regulated and more complex, I believe another competitive differentiator is emerging:
Who can understand and safely support commerce that others cannot?
That's a very different race.
The organization with superior Product Intelligence™ can potentially:
Enter markets others avoid.
Approve good merchants others decline.
Reduce unnecessary portfolio exits.
Respond faster to regulatory changes.
Reduce compliance operating costs.
Strengthen sponsor-bank relationships.
Improve underwriting.
Create new merchant services.
Increase portfolio visibility.
Turn regulatory complexity into competitive advantage.
The companies avoiding investment because compliance costs money may ultimately discover they were protecting today's margin at the expense of tomorrow's market share.
Maybe it won't be Acme Product.
Maybe it will be:
A cannabinoid.
A vape manufacturer.
A peptide.
A mushroom ingredient.
A nutraceutical claim.
A state restriction.
An FDA action.
A card-brand requirement.
A sponsor-bank policy.
Something will change.
Then someone will walk into your office and ask:
“How many merchants are affected?”
That moment will tell you almost everything you need to know about the maturity of your compliance infrastructure.
If the answer is:
“Give us several weeks.”
you have a project-based compliance model.
If the answer is:
“We sent everyone an email.”
you have a communication model.
If the answer is:
“We don't know yet.”
you have a visibility problem.
The destination should be:
That's intelligence.
And the question I'd put in front of every executive team:
Know that answer before someone above you asks.
For decades, our industry has responded to compliance change with people.
More analysts.
More spreadsheets.
More reviews.
More consultants.
More merchant emails.
More audits.
That model survived because there wasn't a better alternative.
There is now.
We live in an information economy with unprecedented access to data, computing power, automation, AI, regulatory intelligence, and continuous digital monitoring.
Yet parts of merchant compliance still operate as if the internet were something an analyst had to manually inspect one browser tab at a time.
That isn't sustainable.
And eventually it won't be defensible.
The next generation of compliance isn't about writing policies faster.
It's about turning policy into intelligence, intelligence into controls, controls into evidence, and evidence into continuously maintained trust.
The companies that understand this now will not simply have cleaner portfolios.
They will move faster.
Underwrite smarter.
Support more complex commerce.
Build stronger bank relationships.
And enter markets their competitors cannot economically manage.
The industry can continue waiting until the next major enforcement action reminds everyone why this matters.
Or we can finally acknowledge what modern commerce has been telling us for years:
You cannot manage a continuously changing portfolio with point-in-time compliance.
The technology exists.
The opportunity exists.
The only question left is who decides to move first.
Qredible is redefining merchant underwriting through Merchant Risk Intelligence (MRI)—a product-first approach that continuously analyzes what businesses sell, how they market those products, and the evidence required to support compliant payment acceptance. By moving beyond static industry classifications, Qredible helps banks, payment processors, ISOs, and sponsor banks make faster, more informed, and more defensible underwriting decisions while reducing manual effort and strengthening ongoing portfolio oversight. Learn more about Qredible's product-first automated compliance management platform for regulated industries →