Compliance is an Operational Function, not Just an Onboarding Checkbox
Most merchants treat compliance as something that happens at onboarding and resurfaces when a problem arrives. The merchants who avoid account-level problems treat it as a continuous operation. StreamPayments partners with our merchants on monitoring scheme thresholds, tracking regulatory changes, managing dispute ratios, and acting before pressure from an acquirer or card scheme leads to a processing freeze.
Risk and compliance in payments is not a department. It is the operational layer that determines whether your merchant account stays open, your acquiring relationships hold under pressure, and your payment infrastructure performs when it matters most.
Chargeback Management and Representment
Chargebacks cost revenue twice, once when the funds are reversed, and again when the ratio climbs toward a scheme monitoring threshold. StreamPayments reviews incoming disputes, assesses representment viability by reason code, prepares evidence packages, and manages submissions through to resolution. For merchants in iGaming, subscriptions, and digital services, a structured chargeback management process is one of the most direct levers for protecting both revenue and acquiring account stability.
ASV Scanning Tool
Quarterly ASV scanning is a PCI DSS requirement most merchants either overlook or manage inconsistently through an independent vendor. StreamPayments provides scheduled scans performed by a PCI SSC-approved vendor, with results reviewed by our compliance team and remediation guidance where vulnerabilities are identified. Passing scan results are maintained as part of the merchant's ongoing PCI DSS compliance record, removing a requirement that routinely falls through the gaps.
Scheme Monitoring
Visa and Mastercard publish compliance mandates on a continuous cadence, each carrying a comply-by date and an operational impact that most merchants only discover after an acquirer raises a concern. StreamPayments monitors scheme publications continuously, assesses their relevance against each merchant relationship we manage, and coordinates the operational response before deadlines arrive. When a chargeback or fraud ratio trends toward a monitoring program threshold, we act before the scheme does.
What Continuous Compliance Operations Should Look Like
Most ISOs meet the minimum. Here at StreamPayments, we go well beyond the standard approach because we recognize that non-compliance will quietly compromise your entire business operation. Here is what payment compliance operations looks like when it runs continuously across every area that affects your merchant account.
| Factor | Applying Directly or Through a Generic ISO | Through StreamPayments |
|---|---|---|
| Acquirer Matching | Merchants submit applications to available acquirers without a structured assessment of fit. In complex verticals, submitting to the wrong acquirer wastes weeks and leaves a paper trail of declines that the next acquirer will ask about. | We assess the merchant's business model, processing history, chargeback ratios, and compliance posture before identifying which acquiring partners currently have appetite for that profile. Applications go to acquirers where the fit is confirmed, not to a generic list. Fewer declines, shorter timelines, and no unnecessary paper trail. |
| Underwriting Preparation | Merchants are given a document checklist and expected to produce what is requested. Common gaps include beneficial ownership declarations, AML frameworks, and scheme compliance evidence. These are identified by the acquirer during review, creating delays and multiple back-and-forth cycles. | We prepare merchants for what acquirers actually need, not what they nominally ask for on an application form. Beneficial ownership declarations, processing history, KYC frameworks, and licensing evidence where applicable are reviewed and organized before submission. What looks like an acquirer being slow is usually a merchant being underprepared. |
| Onboarding Timeline | Timelines are driven by acquirer review processes with little visibility or intervention from the introducing party. Delays accumulate from documentation gaps, acquirer-specific requirements that surface mid-review, and mismatches between the merchant's setup and the underwriting criteria. | We manage the onboarding process actively: anticipating acquirer-specific requirements, addressing documentation gaps before they surface in review, and maintaining direct communication with the acquiring bank throughout. Merchants know where they are in the process and why, rather than waiting on a timeline they cannot see. |
| Multi-Acquirer Setup and Redundancy | Most merchants start with a single acquiring relationship and add a second only after experiencing a disruption. At that point, the routing infrastructure needed to switch traffic between acquirers often does not exist. | Wherever volume warrants it, we build with more than one active acquiring connection from the start. Banks change their risk appetite, impose volume caps, and sometimes exit verticals with little notice. Smart routing across multiple acquirers means that when one connection is disrupted, processing continues through the others automatically. |
| Ongoing Account Management | Once live, the merchant account is largely self-managed. The introducing party's involvement ends at onboarding. Issues surface when the merchant notices them, by which point the acquirer or card scheme has often already acted. | Chargeback ratios, fraud patterns, scheme threshold proximity, and acquirer relationship health are tracked continuously across every account we manage. Issues are identified and addressed before they become the merchant's problem to solve. The acquiring relationship is a managed asset, not a connection that only gets attention when a problem surfaces. |
| Chargeback Ratio Monitoring | Merchants receive chargeback notifications from their acquirer or payment gateway. Threshold proximity is rarely communicated proactively. Scheme monitoring program enrollment typically arrives as a surprise. | Chargeback ratios are tracked against Visa and Mastercard scheme thresholds continuously across all merchant accounts we manage. When a ratio trends toward a monitoring program threshold, we act before the scheme does. We review dispute patterns, adjust fraud parameters, and work with the merchant on the operational changes needed to keep performance within range. Scheme monitoring program enrollment should never be a surprise. |
| Scheme Rule Compliance | Merchants are responsible for tracking Visa and Mastercard scheme updates independently. Most updates are not addressed until a compliance issue surfaces or an acquirer raises a concern. | Visa and Mastercard scheme publications are tracked continuously across our full merchant portfolio. Impact is assessed for each relationship we manage and the operational response is coordinated before comply-by dates arrive. This applies to monitoring program threshold changes, recurring billing rule updates, SCA requirements, and any mandate that affects how merchants in specific verticals must present transactions. |
| Reserve and Settlement Management | Rolling reserve requirements are presented as standard acquirer terms. Settlement timelines and reserve release conditions are accepted as given rather than negotiated as part of the relationship. | Reserve structures, settlement timelines, and release conditions are reviewed and managed as part of the overall acquiring relationship. Merchants understand the cash flow implications of reserve requirements before they become an operational constraint. Where reserve terms can be improved as a merchant's processing record develops, we work with the acquiring bank to adjust them accordingly. |
| Cross-Border and Multi-Jurisdiction Acquiring | Merchants expanding into new European markets often use their existing acquiring relationship to process cross-border volume, regardless of whether that acquirer has strong issuer relationships in the target markets. Approval rates suffer as a result. | We have established acquiring relationships in Malta for iGaming operators, in Cyprus for EU-regulated acquiring, and across broader EU and UK markets. Cross-border expansion is addressed by building acquiring architecture appropriate to where volume actually flows. Acquiring connections are matched to geographies. One relationship processing all markets regardless of issuer proximity is not infrastructure, it is a compromise. |
| Acquiring Disruption Response | When an acquiring relationship is disrupted through termination, volume caps, or compliance action, merchants scramble to find a replacement. Processing stops while a new onboarding process begins from scratch. | Merchants with multi-acquirer setups managed through StreamPayments do not stop processing when one acquiring relationship is disrupted. Routing logic shifts traffic to the available connection automatically. A replacement acquiring relationship is identified and onboarded while the remaining connection keeps processing live. What would otherwise be a payment outage becomes a managed transition. |
The Security Layer Behind Every Transaction
-

PCI DSS Level 1
The StreamPayments gateway operates at the highest PCI DSS certification level. Card data is encrypted in transit and tokenized within the gateway environment. Your servers never handle raw card data.
-

Fraud Monitoring
Transaction-level fraud screening runs in real time across all merchant accounts we manage. Velocity checks, BIN screening, and configurable risk rules identify anomalies before they reach your acquirer.
-

Data Encryption
All sensitive data transmitted through the StreamPayments gateway uses TLS encryption. Card data does not persist in an unencrypted state at any point in the transaction flow.
Risk and Compliance FAQs
-
Risk management and compliance are related but address different problems. Risk management is concerned with identifying and reducing financial exposure from fraud, chargebacks, and transaction disputes that could result in direct losses or acquiring account instability. Compliance is concerned with adherence to card scheme rules, regulatory requirements, and the operational standards set by acquiring banks. In practice they overlap: a merchant whose chargeback ratio exceeds the thresholds defined in Visa's monitoring programs has both a risk management failure and a compliance problem. Managing them as separate workstreams is less effective than treating compliance as a structural input to risk management, which is what payment compliance operations actually means in practice.
-
Visa and Mastercard operate monitoring programs that track chargeback and fraud ratios across merchant accounts on an ongoing basis. When a merchant's ratios exceed defined thresholds, they are enrolled in a monitoring program. For merchants in Europe, the most relevant are Visa's VAMP (Visa Acquirer Monitoring Program) and Mastercard's equivalent programs, which track the same chargeback and fraud metrics. Once enrolled, the merchant typically faces ongoing fees that increase with the duration of enrollment, and the acquiring bank faces its own compliance obligations in relation to the enrolled merchant. Visa has also introduced evidentiary frameworks that allow merchants to challenge specific categories of fraud disputes by demonstrating prior legitimate transactions with the same cardholder. These frameworks change the representment approach for merchants with clean transaction histories in subscription and digital commerce verticals. iGaming operators, subscription merchants, and adult content platforms are among the business models most commonly affected. The time between a ratio breach and scheme notification can be short, which is why continuous chargeback monitoring rather than periodic review is the appropriate operational standard.
-
Understanding how card scheme rules for merchants define and calculate chargeback ratios is the starting point for any serious compliance monitoring program. A chargeback ratio is calculated as the number of chargebacks received in a given month divided by the total number of transactions processed in that same month. Visa and Mastercard apply their own calculation methodologies, which differ slightly in how they count transactions and chargebacks. Merchants should not assume their internally calculated ratio matches the scheme's view. Visa's VAMP program defines specific chargeback and fraud ratio thresholds that trigger enrollment. These thresholds are published in Visa's scheme rules and updated periodically. Merchants should verify current thresholds directly with their acquiring bank or payment partner rather than relying on figures that may have changed since any given piece of content was written. Mastercard operates its own equivalent monitoring programs with a similar threshold structure. These thresholds apply at the merchant category code and acquiring bank level, meaning the same merchant may have different exposure depending on how transactions are coded and through which acquirer they process.
-
Anti-money laundering compliance requires merchants to have documented processes for identifying customers, monitoring transaction patterns for suspicious activity, and reporting suspicious transactions to the relevant financial intelligence authority. In the EU, AML obligations derive from the Anti-Money Laundering Directives and are implemented through national legislation. The EU's AML framework is evolving, with new supranational oversight structures being introduced. Merchants should monitor updates to AML requirements through their acquiring bank and legal advisors, as the regulatory environment governing these obligations continues to develop. For merchants operating in regulated verticals, including iGaming, crypto, and financial services, AML requirements are more extensive and typically include transaction monitoring thresholds, customer due diligence at specified value levels, and enhanced due diligence for higher-risk customers. Acquiring banks require merchants to demonstrate adequate AML controls as part of onboarding and ongoing account maintenance.
-
Know Your Customer requirements mandate that financial institutions, payment institutions, and other regulated entities verify the identity of their customers before establishing a business relationship. In the context of merchant acquiring, KYC applies at two levels: the acquirer's KYC of the merchant during onboarding, and the merchant's own KYC obligations toward its end customers where applicable. The mechanisms for conducting KYC have evolved alongside digital onboarding, with electronic verification tools now widely accepted by acquirers for standard documentation. The obligation itself has not changed, but how merchants fulfill it continues to develop. For merchants in regulated industries, failure to demonstrate adequate KYC processes is a material risk to the acquiring relationship. Acquirers are required to conduct ongoing due diligence on their merchant portfolio, which means KYC is not a one-time onboarding exercise. It is a continuous obligation that requires documented processes and periodic review.
-
Strong Customer Authentication under PSD2 requires that electronic payments be authenticated using at least two of three factors: something the customer knows such as a password or PIN, something they own such as a phone or card reader, or something they are such as a biometric. SCA applies to customer-initiated online card transactions within the European Economic Area. There are defined exemptions, including low-value transactions below the threshold defined in the applicable regulatory technical standards, merchant-initiated transactions, and transactions assessed as low-risk through transaction risk analysis, but these exemptions are subject to conditions and issuer discretion. Merchants should confirm current exemption thresholds with their payment partner. Merchants whose payment infrastructure is not correctly configured for SCA compliance face higher decline rates from issuers applying authentication requirements. SCA requirements are set to evolve as PSD2 is superseded by updated EU payment services regulation. The core authentication principle of two-factor verification is expected to continue, but merchants should monitor regulatory developments through their acquirer or compliance advisor.
-
Fraud chargebacks, classified under reason codes related to unauthorized transactions, occur when a cardholder states they did not authorize a payment. Dispute chargebacks cover a broader category including non-delivery of goods or services, goods not as described, and processing errors. The distinction matters for two reasons. First, fraud chargebacks feed directly into the scheme fraud ratio calculations that trigger monitoring programs. Dispute chargebacks contribute to the overall chargeback ratio but do not feed the fraud ratio, which is tracked and monitored separately by the card schemes. Second, the representment strategy, meaning the process of challenging a chargeback, differs depending on the reason code. For fraud chargebacks specifically, Visa has introduced evidentiary frameworks that allow merchants to challenge disputes by demonstrating prior legitimate transaction history with the same cardholder. These frameworks apply to specific dispute reason codes and have changed the representment approach for merchants in subscription and digital commerce verticals. Treating all chargebacks the same operationally is a common error that leads to preventable losses and unnecessarily elevated ratios.
-
Representment is the process of formally disputing a chargeback by submitting evidence to the card scheme that the original transaction was valid and authorized. A successful representment results in the funds being returned to the merchant. However, under the card scheme monitoring program calculations, chargebacks are counted when they are filed. A successful representment recovers revenue but does not remove the dispute from the ratio calculation. This means representment is a financial recovery tool, not a ratio management strategy. A merchant with a structurally elevated chargeback ratio cannot resolve that through representment alone. The underlying causes of the chargebacks must be addressed operationally. For merchants enrolled in or approaching a scheme monitoring program, the priority is reducing the volume of incoming chargebacks, not winning representments on existing ones. Representment addresses individual disputes. Monitoring program exit requires addressing the operational patterns generating them.
-
Subscription payment compliance encompasses the full set of scheme rules, notification requirements, and billing presentation standards that recurring merchants must meet to maintain compliant merchant accounts. Visa and Mastercard have both published updated rules governing recurring transactions that require merchants to notify cardholders before charging, provide clear cancellation mechanisms, and present recurring transactions with specific descriptor formats that allow cardholders to identify the charge. Free trial billing, negative option billing, and auto-renewal models all have specific requirements that are updated periodically as card schemes respond to consumer complaint patterns in these billing models. Non-compliance is a primary driver of elevated chargebacks in subscription verticals because cardholders who do not recognize a charge, or who believe they cancelled, dispute the transaction rather than contacting the merchant. Subscription merchants represent one of the business models most frequently enrolled in card scheme monitoring programs as a direct result of recurring billing compliance failures. The operational overlap between subscription compliance and chargeback ratio management means that billing compliance is not a regulatory checkbox. It is a direct input to acquiring account stability. Compliance with recurring billing rules is therefore both a regulatory obligation and a practical chargeback reduction strategy.
-
Scaling compliance alongside volume is one of the defining challenges of merchant payment operations, and the gap between the two is where most avoidable consequences originate. Compliance obligations do not scale automatically with volume. They require deliberate operational investment. A merchant processing low volume can manage scheme thresholds informally. A merchant processing significant volume across multiple acquirers and markets needs documented monitoring processes, clear escalation paths for emerging threshold risks, and a compliance function that operates continuously rather than reactively. The merchants who face the most damaging compliance consequences are typically those who grew their volume without updating their compliance operations to match. The point at which compliance becomes a dedicated operational function rather than a periodic review is earlier than most merchants expect. These are the patterns StreamPayments monitors across every merchant relationship we manage, and the point at which we typically intervene is before volume growth exposes a compliance gap, not after.
The Compliance Layer Across Your Entire Payment Infrastructure
The risk and compliance work StreamPayments does is not separate from the payment gateway and acquiring relationship management we provide. It runs through all of it. The fraud parameters on the gateway are configured for your vertical. The 3DS setup accounts for your transaction types. The chargeback monitoring tracks the same ratios your acquirer watches. The scheme update monitoring covers the rules that apply to your merchant category. This is what we mean when we describe compliance as an operational function rather than a support service. It is built into how the payment infrastructure operates, not layered on top of it after the fact.
