The Green Sheet Online Edition
August 24, 2026 • 26:08:02
Merchant risk has outgrown static underwriting
Merchant risk used to be treated largely as a front-end decision. Payments companies reviewed a merchant at onboarding, made an underwriting call, and returned to the account only when a scheduled review or a warning sign raised concern. That model worked better when merchant behavior changed more slowly. Advances in technology, particularly in AI-driven fraud, are upending this approach and forcing companies processing payments to think differently.
Today, a business can appear compliant at onboarding but quickly change once they are through the door. A merchant can pass review, begin processing payments, and then create new exposure through tactics such as changed product offerings, new affiliated entities, or altered marketing claims. Initial underwriting still matters, but it can no longer carry the full burden of merchant risk management.
If AI is core to driving problematic merchant behavior, it is also the key to stopping it. McKinsey's 2026 AI Trust Maturity Survey (see tinyurl.com/2ebkr84d) found that responsible AI maturity is improving, even as governance and agentic AI controls still lag. Security and risk concerns remain the top barrier to scaling agentic AI, while active mitigation continues to trail risk awareness across nearly every AI risk category. For payments companies, the takeaway is practical. Merchant risk now requires monitoring that continues after approval, with AI governed by the oversight and domain intelligence needed to make decisions defensible.
One-time reviews miss merchant risk 'drift' post-approval
Initial underwriting remains an important control, but it can only assess the merchant as presented at a given moment. Bad actors understand that limitation. Some present a compliant version of the business during onboarding, then shift their activity once payment processing is in place. In higher-risk categories, small changes can matter. A modified product claim, a new fulfillment partner or a related website can create exposure for payment companies, banking partners and card networks. Those changes may not trigger an obvious red flag on their own, especially when risk professionals are reviewing accounts through scheduled checks or isolated alerts.
Manual monitoring and traditional rules can catch some issues, but they often depend on the right signal appearing at the right time. Rules are useful for known patterns. They're less effective when the risk comes from a new combination of merchant behavior, website changes and connected entities. Merchant risk is prone to drift. It doesn't stop at approval. The harder work is identifying when new activity changes the risk profile enough to require review.
Companies' fragmented risk data impedes response
Payments companies often have useful information spread across the organization. Underwriting files, website monitoring, transaction activity, adverse media, regulatory updates, and outside risk intelligence may each show part of the picture.
The problem is that those sources are often reviewed separately, which makes it harder to understand how one change relates to another. A website update may sit in one workflow, transaction activity in another, and related-entity research somewhere else. By the time those signals are connected, the exposure may already be harder to contain.
Merchant risk programs need a way to connect those signals throughout the relationship. Risk professionals need to see what changed, understand why it matters, and decide whether the account still fits the company's risk tolerance.
AI agents connect data and speed response
Agentic AI has become part of the merchant risk conversation because it can do more than basic automation. Instead of waiting for a single trigger, a lifecycle-based system can compare signals across the merchant relationship and flag when a business begins to look materially different from the one originally approved.
The riskiest cases rarely come from a single data point. A website change, transaction pattern or corporate record may mean little on its own. Viewed alongside other signals, the same data point can indicate a change that deserves review. AI is most useful when it gives risk professionals a clearer case file earlier in the process. Routine reviews can move with less friction, while more complex merchant activity can be routed to experienced reviewers before a decision is made.
Generic AI doesn't work without context
AI tools are only as effective as the foundational data they've been trained on. For assessing merchant risk effectively, AI tools need to have been fed vast repositories of historical merchant data and then trained by expert analysts.
Common problems with general-purpose AI include cold starts, where insufficient training makes AI models unaware of risks outside the mainstream. Another pitfall is gray areas, where agents can't distinguish products and services across jurisdictions. Through adversarial testing, bad actors find the thresholds of AI moderation logic, then find "bypasses" (for example, leetspeak, which substitutes numbers or symbols for letters) to exploit.
Without sufficient context, agents can spawn false positives and negatives; without controls, they operate without guardrails
AI-supported risk systems need intelligence that reflects how merchant risk actually appears in the payments system. This intelligence, known as context in AI systems, comes from regulations, card brand rules, enforcement patterns, knowledge of bad-actor networks, and human-in-the-loop feedback from experienced analysts.
Faster decisions still need a record
Speed only helps when a payment company can stand behind its decisions. A bank, card network or regulator may later ask why a merchant was approved, restricted or removed from processing. The answer can't depend on a score alone. AI-driven merchant risk programs can provide an extensive audit trail that shows how decisions were reached.
The record makes clear which evidence shaped the outcome and where human judgment entered the process.
Underwriting will remain an essential component of merchant risk management, but approval is no longer the endpoint. Payments companies need decisioning models that continue to monitor for meaningful changes after onboarding and provide risk professionals with a defensible basis for action.
Agentic AI can strengthen merchant risk decisioning when it's built on merchant-specific intelligence and governed by clear boundaries. Used that way, it gives risk professionals a better way to support growth while keeping hidden exposure from accumulating in the portfolio.
Dan Frechtling is a veteran risk leader serving as senior vice president of Product and Strategy at LegitScript, https://legitscript.com, where he drives product innovation, grows the company's expertise in merchant intelligence, and strengthens partnerships with leading platforms, marketplaces, and payment companies. He brings over a decade of experience in mitigating merchant, seller, and advertising risk, having held leadership roles such as president of G2 Risk Solutions and CEO of Boltive. Contact him via LinkedIn at linkedin.com/in/frechtling.
Notice to readers: These are archived articles. Contact information, links and other details may be out of date. We regret any inconvenience.



