Modern regulated commerce means frequent product policy changes. Are you still using point-in-time audits to monitor for changes? They only measure a point in time and are instantly obsolete. Qredible's Merchant Intelligence Operating System offers continuous monitoring of your portfolio risk.

Your Policy Changed. Did Your Portfolio?

Author: Noah Fitzgerald, CPP
Date: September 1, 2026

Your Policy Changed. Did Your Portfolio?

Why Every New Compliance Rule Creates a Portfolio-Wide Problem Most Payment Companies Aren't Built to Solve

"Updating a policy is easy. Proving that thousands of existing merchants comply with it is where the real work begins."
- Noah Fitzgerald, CPP, CRO Qredible, Inc.

 


The Email Arrives Monday Morning

Noah Fitzgerald, CPP - Chief Revenue Officer, Qredible, Inc.
Imagine you're leading risk or compliance at a payment processor.

Your sponsor bank sends an updated policy.

Effective immediately, any merchant selling Acme Product must satisfy a new product requirement.

Additionally, merchants cannot use certain language when marketing Acme Product on their websites or social media.

Your team reviews the requirement.

Legal weighs in.

Compliance updates the policy.

Underwriting gets new procedures.

The onboarding workflow gets another checkbox.

Sales receives a notification.

Done.

Right?

Not even close.

Because you don't just have tomorrow's merchants.

You have yesterday's 10,000 merchants.

Somewhere inside that portfolio are merchants selling Acme Product.

Some disclosed it.

Some didn't.

Some didn't sell it when you underwrote them but added it later.

Some sell it inside a much larger product catalog.

Some may meet the new requirement.

Others won't.

Some may be using prohibited marketing language.

And your sponsor bank just asked you to make sure they're compliant.

So now answer the question:

How in the hell are you going to do that?

Welcome to one of the least discussed and most consequential problems in modern merchant compliance.

The Portfolio Re-Audit Problem.


A Policy Change Is Not an Underwriting Change

This distinction matters.

When regulations, card-brand requirements, sponsor-bank policies, or internal risk standards change, organizations naturally update onboarding.

That's necessary.

But it's only half the problem.

Your existing merchants don't magically inherit the new controls because somebody updated the underwriting manual.

If the requirement applies to existing commerce, you need to determine:

  • Which merchants are affected?
  • Which products are affected?
  • Which merchants already comply?
  • Which don't?
  • What evidence proves compliance?
  • Which marketing needs remediation?
  • When must remediation occur?
  • Did the merchant actually remediate?
  • Did the prohibited product or claim come back later?

That's not policy management.

That's portfolio intelligence.

And most legacy compliance infrastructure wasn't designed to do it.


Every Regulatory Change Creates a Search Problem

Strip away all the complexity and this is fundamentally what happens.

Someone changes a rule.

Then your organization has to answer:

Where does this rule intersect with our portfolio?

That's the hard part.

If the rule applies broadly to every merchant, identifying the population may be relatively straightforward.

Product-specific changes are different.

Imagine the requirement applies to:

A particular cannabinoid.

A specific vape manufacturer.

A mushroom constituent.

A nutraceutical ingredient.

A particular product claim.

A pharmaceutical compound.

A restricted SKU.

A particular category of hemp beverage.

Suddenly an MCC isn't enough.

A merchant application isn't enough.

A list of “high-risk merchants” isn't enough.

You need to know what your merchants actually sell.

And that's where the operational nightmare begins.

Option One: Send Everyone a Letter

This is probably the easiest response.

Identify the broad merchant population and send a communication:

  • “Due to updated requirements, merchants selling Acme Product must comply with the following…”

Simple.

Fast.

Relatively inexpensive.

And potentially almost impossible to validate.

First, you may unnecessarily alarm thousands of merchants who don't sell the product.

Some will call their sales representative.

Others will call support.

Agents will start asking questions.

Merchants may interpret the communication as a change in your appetite for their industry.

Competitors may use the confusion against you.

You can create unnecessary merchant anxiety and potentially damage your brand.

But there's a bigger problem.

What happens after they receive the email?

Did they read it?

Did they understand it?

Do they sell the product?

Did they evaluate the requirement correctly?

Did they remove a prohibited claim?

Did they replace a noncompliant product?

Did they provide updated evidence?

How do you know?

A notification demonstrates communication.

It doesn't necessarily demonstrate compliance.

Option Two: Audit the Portfolio Internally

Fine.

Let's actually check.

Compliance identifies the potentially affected merchants.

Analysts begin opening websites.

Searching product catalogs.

Reviewing product pages.

Checking ingredients.

Looking at labels.

Reviewing COAs.

Searching marketing language.

Checking social media.

Documenting findings.

Creating cases.

Contacting merchants.

Tracking remediation.

Following up.

Then revisiting websites to verify the changes were actually made.

This can work.

It has worked for decades.

But let's acknowledge what it actually requires.

People.

Lots of them.

And not inexpensive people.

Experienced underwriting, risk, and compliance professionals are now performing repetitive discovery work across potentially thousands of merchants and tens or hundreds of thousands of products.

Meanwhile:

New merchants still need underwriting.

Existing alerts still need review.

Chargebacks still happen.

Fraud still happens.

Sponsor-bank requests still arrive.

Audits still occur.

Regulations continue changing.

Your team didn't suddenly get another 500 hours in the week because a policy changed.

Something has to give.


And When You Finish?

Congratulations.

You completed the audit.

Everything is clean.

Tuesday morning, one merchant adds Acme Product back to its website.

Another introduces it next month.

A third changes its marketing copy.

A fourth adds a new brand.

A fifth launches another website.

Your completed audit begins aging the moment it ends.

That's the part nobody likes discussing.

A point-in-time audit proves a point in time.

It does not create continuous compliance.

Option Three: Hire Someone Else to Do It

The third option is outsourcing.

Bring in consultants.

Auditors.

Temporary personnel.

Specialized compliance firms.

There can be legitimate advantages.

You gain capacity.

You may gain specialized expertise.

Your internal teams remain focused on core responsibilities.

But the underlying problem hasn't necessarily changed.

Someone is still:

Opening websites.

Finding products.

Reviewing documents.

Recording findings.

Building spreadsheets.

Contacting merchants.

Checking remediation.

And now you're paying external rates to do it.

Then the engagement ends.

You receive the report.

Everyone celebrates.

And the portfolio starts changing again.

You have successfully outsourced the labor.

You haven't necessarily solved the operating model.


We Keep Solving Continuous Problems With One-Time Projects

This is the fundamental failure.

Commerce is continuous.

Compliance change is continuous.

Merchant change is continuous.

Product change is continuous.

Yet our response is frequently:

Project.

Audit.

Remediate.

Close.

Repeat.

That architecture made sense when technology couldn't economically maintain continuous visibility.

But we're living in 2026.

The technology exists.

The information exists.

The computing power exists.

AI exists.

Machine learning exists.

Web intelligence exists.

Document intelligence exists.

Regulatory data exists.

Automated monitoring exists.

The question isn't whether we can build a better model.

The uncomfortable question is:

Why haven't we?


I Think Part of the Answer Is Economic

After more than 30 years in this industry, I've learned that organizations generally optimize around what they're rewarded for.

Compliance infrastructure costs money today.

The financial consequences of inadequate infrastructure may happen tomorrow.

That creates an unfortunate incentive.

Don't disrupt merchants unnecessarily.

Don't increase operating costs.

Don't add friction to sales.

Don't make underwriting harder.

Don't spend money unless required.

And perhaps most dangerously:

Don't look too deeply unless somebody forces us to.

Because deeper visibility creates another problem.

Once you know something exists, you have to deal with it.

Sometimes ignorance feels operationally cheaper.

Until it isn't.


The Fear of What We Might Find

I believe this deserves its own discussion.

Suppose you're a processor with 50,000 merchants.

Leadership approves a comprehensive product-level audit.

What happens if you discover:

2,000 policy violations?

Hundreds of merchants requiring remediation?

Products your sponsor bank won't support?

Undisclosed regulated activity?

Website claims that should have been identified years ago?

Suddenly you have a major operational project.

Merchant relationships are at risk.

Revenue may be affected.

Agents may become angry.

Sales may push back.

Management has difficult decisions to make.

It is understandable why organizations hesitate.

But avoiding the answer does not eliminate the exposure.

It simply determines who discovers it first.

Your team.

Your sponsor bank.

A card brand.

A regulator.

Or a plaintiff's attorney.

I know which one I'd rather have.


Plausible Deniability Is Becoming an Increasingly Dangerous Strategy

There has long been a version of plausible deniability within payments.

The merchant was compliant when we underwrote them.

They changed later.

We didn't know.

They added the product after approval.

Their website changed.

They didn't disclose it.

At one time, those explanations could reflect genuine technological limitations.

It was impossible for a human compliance team to inspect every page, product, claim, document, and change across thousands of merchants every day.

But technology changes what is reasonably knowable.

That matters.

The question increasingly isn't simply:

“Did you know?”

It becomes:

“Did you have reasonable controls designed to find out?”

That's a much more uncomfortable question.


A Policy You Cannot Enforce Isn't Much of a Control

Think about this from a sponsor bank's perspective.

You have a policy saying Acme Product requires Requirement X.

Great.

Now I ask:

Which merchants sell Acme Product?

You don't know.

Which products did you review?

You don't know.

Which merchants violated the requirement?

You don't know.

Which merchants remediated?

You have emails.

Are they still compliant today?

You'd need to check again.

Then what exactly does the policy accomplish?

It establishes an expectation.

But without visibility, detection, remediation, and evidence, the institution has limited ability to demonstrate that the expectation is operating effectively.

That's the difference between:

Policy

and

Control.


Stop Building Compliance Around Documents

This is where I believe our industry's thinking needs to change.

The objective shouldn't be to maintain more policies.

It should be to operationalize them.

A modern compliance control should increasingly work something like this:

RULE CHANGES

POLICY IS UPDATED

REQUIREMENT BECOMES MACHINE-READABLE CRITERIA

PORTFOLIO IS EVALUATED

AFFECTED MERCHANTS & PRODUCTS ARE IDENTIFIED

EXCEPTIONS ARE PRIORITIZED

MERCHANTS ARE REMEDIATED

EVIDENCE IS CAPTURED

COMPLIANCE IS RE-VERIFIED

ONGOING MONITORING CONTINUES

That's an operating system.

Not a PDF.


Product-Level Policy Requires Product-Level Intelligence

Our hypothetical Acme Product example exposes the central issue.

If the policy applies to a product, you need product intelligence.

If it applies to an ingredient, you need ingredient-level intelligence.

If it applies to a marketing claim, you need content intelligence.

If it applies to geography, you need geographic context.

If it requires evidence, you need evidence attached to the relevant product or merchant.

You cannot reliably manage increasingly granular regulatory requirements with only:

Merchant → MCC → Industry → Policy

The model needs to become:

Merchant

Product

Attribute / Ingredient / Claim

Evidence

Applicable Rule

Institutional Policy

Compliance Status

Remediation

Continuous Monitoring

That's what modern commerce increasingly requires.


The Real Asset Is Not the Audit

It's What You Learn During It.

Suppose you have no choice today.

You need to audit 5,000 merchants manually.

Do it.

But don't waste the work.

Every product you identify should become structured intelligence.

Every document should be connected.

Every website should be mapped.

Every product category should be classified.

Every compliance finding should become data.

Every remediation should become part of the record.

Every policy relationship should be retained.

Because six months from now another rule will change.

If all of today's work ended up in a spreadsheet, you're going to do it again.

If today's audit created a persistent product-intelligence layer, next time you may be able to ask:

“Show me every affected merchant.”

That is an entirely different operating model.


There Is No Such Thing as a Permanently “Clean Portfolio”

I would challenge another phrase we use.

Clean portfolio.

A portfolio can be clean at a point in time.

It cannot remain clean without controls.

Merchants change.

Products change.

Websites change.

Ownership changes.

Regulations change.

Licenses expire.

Documents expire.

Policies change.

A clean portfolio is therefore not a destination.

It's a continuously maintained condition.

That distinction changes the technology you need.


The Cost of Getting This Wrong Is Bigger Than Lost Processing Revenue

When portfolio compliance fails, organizations often focus on merchant attrition or lost processing revenue.

Those may be the smallest costs.

Depending on the circumstances, consequences can include:

  • Sponsor-bank remediation
  • Regulatory scrutiny
  • Card-brand action
  • Fines and assessments
  • Legal expenses
  • Outside audit costs
  • Additional compliance staffing
  • Merchant remediation
  • Reserves and financial exposure
  • Partner disruption
  • Agent attrition
  • Reputational damage
  • Executive distraction
  • Lost growth opportunities

Across financial services, major compliance and control failures have produced extraordinarily large financial consequences over the years.

But the hardest cost to quantify may be trust.

Once a bank, regulator, card brand, partner, or merchant loses confidence in your controls, rebuilding that confidence is expensive.


Now Let's Talk About the Opportunity Everyone Is Missing

This is where I disagree with the idea that better compliance simply means more expense.

Better compliance infrastructure can create competitive advantage.

Imagine being the processor that can tell a sponsor bank:

  • “When your policy changes, we can identify the affected merchant and product population, initiate remediation, capture evidence, and continuously monitor for recurrence.”

Imagine telling an ISO:

  • “We can support this regulated vertical because we understand the products rather than simply categorizing the merchants.”

Imagine telling a merchant:

  • “We aren't going to shut you down because something changed. We'll identify the issue and give you a structured path to remediation.”

Imagine telling sales:

  • “Here are the merchants your competitors can't support because their compliance infrastructure doesn't scale.”

Now compliance isn't merely protecting revenue.

It's enabling revenue.


The Organizations That Solve This First Will Have an Unfair Advantage

For years, payments companies have competed on:

Price.

Residuals.

Technology.

Customer service.

Funding speed.

Integrations.

All important.

But as commerce becomes more regulated and more complex, I believe another competitive differentiator is emerging:

Who can understand and safely support commerce that others cannot?

That's a very different race.

The organization with superior Product Intelligence™ can potentially:

Enter markets others avoid.

Approve good merchants others decline.

Reduce unnecessary portfolio exits.

Respond faster to regulatory changes.

Reduce compliance operating costs.

Strengthen sponsor-bank relationships.

Improve underwriting.

Create new merchant services.

Increase portfolio visibility.

Turn regulatory complexity into competitive advantage.

The companies avoiding investment because compliance costs money may ultimately discover they were protecting today's margin at the expense of tomorrow's market share.


The Next Audit Is Already Coming

Maybe it won't be Acme Product.

Maybe it will be:

A cannabinoid.

A vape manufacturer.

A peptide.

A mushroom ingredient.

A nutraceutical claim.

A state restriction.

An FDA action.

A card-brand requirement.

A sponsor-bank policy.

Something will change.

Then someone will walk into your office and ask:

“How many merchants are affected?”

That moment will tell you almost everything you need to know about the maturity of your compliance infrastructure.

If the answer is:

“Give us several weeks.”

you have a project-based compliance model.

If the answer is:

“We sent everyone an email.”

you have a communication model.

If the answer is:

“We don't know yet.”

you have a visibility problem.

The destination should be:

  • “Here are the affected merchants. Here are the affected products. Here are the violations. Here is the evidence. Here is the remediation status. And we're monitoring for recurrence.”

That's intelligence.


Questions Risk & Compliance Leaders Should Be Asking

  • When our next policy changes, can we immediately identify the affected population?
  • Do we know what products our merchants actually sell today?
  • Can we search the portfolio below the MCC and merchant-category level?
  • Can our policies be mapped to products, ingredients, claims, evidence, and jurisdictions?
  • How much does a full portfolio re-audit currently cost us?
  • How many employee hours does it consume?
  • What happens to the intelligence collected after the audit?
  • Can we verify merchant remediation automatically or efficiently?
  • How do we detect recurrence?
  • Are our controls continuous or point-in-time?
  • Are we avoiding deeper portfolio visibility because of what we might discover?
  • What could our organization support if compliance became more scalable?
  • Are we treating compliance technology as an expense—or as infrastructure for growth?

And the question I'd put in front of every executive team:

  • If a sponsor bank changed a product-level policy tomorrow morning, how long would it take us to identify every affected product and merchant—and prove what we did about it?

Know that answer before someone above you asks.


Final Thought

For decades, our industry has responded to compliance change with people.

More analysts.

More spreadsheets.

More reviews.

More consultants.

More merchant emails.

More audits.

That model survived because there wasn't a better alternative.

There is now.

We live in an information economy with unprecedented access to data, computing power, automation, AI, regulatory intelligence, and continuous digital monitoring.

Yet parts of merchant compliance still operate as if the internet were something an analyst had to manually inspect one browser tab at a time.

That isn't sustainable.

And eventually it won't be defensible.

The next generation of compliance isn't about writing policies faster.

It's about turning policy into intelligence, intelligence into controls, controls into evidence, and evidence into continuously maintained trust.

The companies that understand this now will not simply have cleaner portfolios.

They will move faster.

Underwrite smarter.

Support more complex commerce.

Build stronger bank relationships.

And enter markets their competitors cannot economically manage.

The industry can continue waiting until the next major enforcement action reminds everyone why this matters.

Or we can finally acknowledge what modern commerce has been telling us for years:

You cannot manage a continuously changing portfolio with point-in-time compliance.

The technology exists.

The opportunity exists.

The only question left is who decides to move first.

 

About Qredible

Qredible is redefining merchant underwriting through Merchant Risk Intelligence (MRI)—a product-first approach that continuously analyzes what businesses sell, how they market those products, and the evidence required to support compliant payment acceptance. By moving beyond static industry classifications, Qredible helps banks, payment processors, ISOs, and sponsor banks make faster, more informed, and more defensible underwriting decisions while reducing manual effort and strengthening ongoing portfolio oversight. Learn more about Qredible's product-first automated compliance management platform for regulated industries →



crossmenu