Compliance is an Operational Function, not Just an Onboarding Checkbox

Most merchants treat compliance as something that happens at onboarding and resurfaces when a problem arrives. The merchants who avoid account-level problems treat it as a continuous operation. StreamPayments partners with our merchants on monitoring scheme thresholds, tracking regulatory changes, managing dispute ratios, and acting before pressure from an acquirer or card scheme leads to a processing freeze.

scheme-update.json
assessment.json
Compliance Ops
Scheme Update Bulletin NEW
Mastercard · Bulletin MC-2026-047
Updated Requirements for Investigation of Potential Scam Activity
Published
2026-05-12
Effective
2026-07-24
Priority
High
Category
Monitoring
Impacted Areas
Transaction Monitoring
Internal process update required
Fraud Reporting
New reporting obligations
Acquiring Relationships
Acquirer notification required
Chargeback Process
No change required
Internal Assessment IN PROGRESS
Relevance to Portfolio
High · Applies to all iGaming and digital merchant accounts
Assessment covers 14 active merchant relationships in scope
Operational Impact
Internal monitoring and reporting processes require strengthening
Fraud pattern reporting cadence to be updated · Acquirer briefings scheduled
Assigned To
Head of Compliance · Risk Systems
Review deadline: 2026-07-01 · 23 days ahead of effective date
Action Status
Bulletin identified and relevance confirmed
2026-05-14
Impact assessment completed across merchant portfolio
2026-05-19
Monitoring process updates in progress
In progress
Acquirer notifications and merchant briefings
Due 2026-07-01
Compliance confirmed ahead of effective date
Due 2026-07-24

Risk and compliance in payments is not a department. It is the operational layer that determines whether your merchant account stays open, your acquiring relationships hold under pressure, and your payment infrastructure performs when it matters most.

Chargeback Management and Representment

Chargebacks cost revenue twice, once when the funds are reversed, and again when the ratio climbs toward a scheme monitoring threshold. StreamPayments reviews incoming disputes, assesses representment viability by reason code, prepares evidence packages, and manages submissions through to resolution. For merchants in iGaming, subscriptions, and digital services, a structured chargeback management process is one of the most direct levers for protecting both revenue and acquiring account stability.

Transaction Risk Assessment
TXN-9C4F2A81
Live
Card Payment · iGaming Deposit
Visa · DE issuer · EU merchant · 2026-08-07 09:41:22Z
€125.00
Transaction value
14
/ 100
Risk Score
Low risk. All fraud signals within acceptable range. No velocity anomalies detected.
Low Risk
AML Screening
No sanctions matches · Transaction pattern normal
Cleared
3DS2 Authentication
Frictionless · ECI 05 · Liability shift active
Authenticated
Chargeback Ratio
Current 0.41% · VAMP threshold not approached
Within threshold
Final Decision
All checks passed · Proceeding to authorization
Approved for Auth

ASV Scanning Tool

Quarterly ASV scanning is a PCI DSS requirement most merchants either overlook or manage inconsistently through an independent vendor. StreamPayments provides scheduled scans performed by a PCI SSC-approved vendor, with results reviewed by our compliance team and remediation guidance where vulnerabilities are identified. Passing scan results are maintained as part of the merchant's ongoing PCI DSS compliance record, removing a requirement that routinely falls through the gaps.

ASV Scan Report
PCI DSS Q3 2026
Passed
Quarterly ASV Scan · External Network
ACC-EU-00847 · Completed 2026-08-07 04:22:31 UTC
PASS
PCI SSC compliant result
0
Critical
0
High
2
Medium
4
Low
External Network Perimeter
14 hosts scanned · No critical or high vulnerabilities detected
Clean
Payment Page Endpoints
TLS 1.3 confirmed · Certificate valid · No exposed card data paths
Compliant
API Endpoints
Authentication verified · No unauthenticated access paths detected
Secure
Informational Findings
6 low-severity items logged · No remediation required for PCI compliance
Reviewed
Next Scheduled Scan
Quarterly requirement · Managed by StreamPayments
2026-11-07

Scheme Monitoring

Visa and Mastercard publish compliance mandates on a continuous cadence, each carrying a comply-by date and an operational impact that most merchants only discover after an acquirer raises a concern. StreamPayments monitors scheme publications continuously, assesses their relevance against each merchant relationship we manage, and coordinates the operational response before deadlines arrive. When a chargeback or fraud ratio trends toward a monitoring program threshold, we act before the scheme does.

scheme-update.json
assessment.json
Compliance Ops
Scheme Update Bulletin NEW
Mastercard · Bulletin MC-2026-047
Updated Requirements for Investigation of Potential Scam Activity
Published
2026-05-12
Effective
2026-07-24
Priority
High
Category
Monitoring
Impacted Areas
Transaction Monitoring
Internal process update required
Fraud Reporting
New reporting obligations
Acquiring Relationships
Acquirer notification required
Chargeback Process
No change required
Internal Assessment IN PROGRESS
Relevance to Portfolio
High · Applies to all iGaming and digital merchant accounts
Assessment covers 14 active merchant relationships in scope
Operational Impact
Internal monitoring and reporting processes require strengthening
Fraud pattern reporting cadence to be updated · Acquirer briefings scheduled
Assigned To
Head of Compliance · Risk Systems
Review deadline: 2026-07-01 · 23 days ahead of effective date
Action Status
Bulletin identified and relevance confirmed
2026-05-14
Impact assessment completed across merchant portfolio
2026-05-19
Monitoring process updates in progress
In progress
Acquirer notifications and merchant briefings
Due 2026-07-01
Compliance confirmed ahead of effective date
Due 2026-07-24

What Continuous Compliance Operations Should Look Like

Most ISOs meet the minimum. Here at StreamPayments, we go well beyond the standard approach because we recognize that non-compliance will quietly compromise your entire business operation. Here is what payment compliance operations looks like when it runs continuously across every area that affects your merchant account.

Factor Applying Directly or Through a Generic ISO Through StreamPayments
Acquirer Matching Merchants submit applications to available acquirers without a structured assessment of fit. In complex verticals, submitting to the wrong acquirer wastes weeks and leaves a paper trail of declines that the next acquirer will ask about. We assess the merchant's business model, processing history, chargeback ratios, and compliance posture before identifying which acquiring partners currently have appetite for that profile. Applications go to acquirers where the fit is confirmed, not to a generic list. Fewer declines, shorter timelines, and no unnecessary paper trail.
Underwriting Preparation Merchants are given a document checklist and expected to produce what is requested. Common gaps include beneficial ownership declarations, AML frameworks, and scheme compliance evidence. These are identified by the acquirer during review, creating delays and multiple back-and-forth cycles. We prepare merchants for what acquirers actually need, not what they nominally ask for on an application form. Beneficial ownership declarations, processing history, KYC frameworks, and licensing evidence where applicable are reviewed and organized before submission. What looks like an acquirer being slow is usually a merchant being underprepared.
Onboarding Timeline Timelines are driven by acquirer review processes with little visibility or intervention from the introducing party. Delays accumulate from documentation gaps, acquirer-specific requirements that surface mid-review, and mismatches between the merchant's setup and the underwriting criteria. We manage the onboarding process actively: anticipating acquirer-specific requirements, addressing documentation gaps before they surface in review, and maintaining direct communication with the acquiring bank throughout. Merchants know where they are in the process and why, rather than waiting on a timeline they cannot see.
Multi-Acquirer Setup and Redundancy Most merchants start with a single acquiring relationship and add a second only after experiencing a disruption. At that point, the routing infrastructure needed to switch traffic between acquirers often does not exist. Wherever volume warrants it, we build with more than one active acquiring connection from the start. Banks change their risk appetite, impose volume caps, and sometimes exit verticals with little notice. Smart routing across multiple acquirers means that when one connection is disrupted, processing continues through the others automatically.
Ongoing Account Management Once live, the merchant account is largely self-managed. The introducing party's involvement ends at onboarding. Issues surface when the merchant notices them, by which point the acquirer or card scheme has often already acted. Chargeback ratios, fraud patterns, scheme threshold proximity, and acquirer relationship health are tracked continuously across every account we manage. Issues are identified and addressed before they become the merchant's problem to solve. The acquiring relationship is a managed asset, not a connection that only gets attention when a problem surfaces.
Chargeback Ratio Monitoring Merchants receive chargeback notifications from their acquirer or payment gateway. Threshold proximity is rarely communicated proactively. Scheme monitoring program enrollment typically arrives as a surprise. Chargeback ratios are tracked against Visa and Mastercard scheme thresholds continuously across all merchant accounts we manage. When a ratio trends toward a monitoring program threshold, we act before the scheme does. We review dispute patterns, adjust fraud parameters, and work with the merchant on the operational changes needed to keep performance within range. Scheme monitoring program enrollment should never be a surprise.
Scheme Rule Compliance Merchants are responsible for tracking Visa and Mastercard scheme updates independently. Most updates are not addressed until a compliance issue surfaces or an acquirer raises a concern. Visa and Mastercard scheme publications are tracked continuously across our full merchant portfolio. Impact is assessed for each relationship we manage and the operational response is coordinated before comply-by dates arrive. This applies to monitoring program threshold changes, recurring billing rule updates, SCA requirements, and any mandate that affects how merchants in specific verticals must present transactions.
Reserve and Settlement Management Rolling reserve requirements are presented as standard acquirer terms. Settlement timelines and reserve release conditions are accepted as given rather than negotiated as part of the relationship. Reserve structures, settlement timelines, and release conditions are reviewed and managed as part of the overall acquiring relationship. Merchants understand the cash flow implications of reserve requirements before they become an operational constraint. Where reserve terms can be improved as a merchant's processing record develops, we work with the acquiring bank to adjust them accordingly.
Cross-Border and Multi-Jurisdiction Acquiring Merchants expanding into new European markets often use their existing acquiring relationship to process cross-border volume, regardless of whether that acquirer has strong issuer relationships in the target markets. Approval rates suffer as a result. We have established acquiring relationships in Malta for iGaming operators, in Cyprus for EU-regulated acquiring, and across broader EU and UK markets. Cross-border expansion is addressed by building acquiring architecture appropriate to where volume actually flows. Acquiring connections are matched to geographies. One relationship processing all markets regardless of issuer proximity is not infrastructure, it is a compromise.
Acquiring Disruption Response When an acquiring relationship is disrupted through termination, volume caps, or compliance action, merchants scramble to find a replacement. Processing stops while a new onboarding process begins from scratch. Merchants with multi-acquirer setups managed through StreamPayments do not stop processing when one acquiring relationship is disrupted. Routing logic shifts traffic to the available connection automatically. A replacement acquiring relationship is identified and onboarded while the remaining connection keeps processing live. What would otherwise be a payment outage becomes a managed transition.

The Security Layer Behind Every Transaction

  • PCI DSS Level 1

    The StreamPayments gateway operates at the highest PCI DSS certification level. Card data is encrypted in transit and tokenized within the gateway environment. Your servers never handle raw card data.

  • Fraud Monitoring

    Transaction-level fraud screening runs in real time across all merchant accounts we manage. Velocity checks, BIN screening, and configurable risk rules identify anomalies before they reach your acquirer.

  • Data Encryption

    All sensitive data transmitted through the StreamPayments gateway uses TLS encryption. Card data does not persist in an unencrypted state at any point in the transaction flow.

Risk and Compliance FAQs

The Compliance Layer Across Your Entire Payment Infrastructure

The risk and compliance work StreamPayments does is not separate from the payment gateway and acquiring relationship management we provide. It runs through all of it. The fraud parameters on the gateway are configured for your vertical. The 3DS setup accounts for your transaction types. The chargeback monitoring tracks the same ratios your acquirer watches. The scheme update monitoring covers the rules that apply to your merchant category. This is what we mean when we describe compliance as an operational function rather than a support service. It is built into how the payment infrastructure operates, not layered on top of it after the fact.