Page 30 - gs260802
P. 30
Insights and Expertise
Merchant risk has place. In higher-risk categories, small changes can matter.
A modified product claim, a new fulfillment partner or a
outgrown static related website can create exposure for payment compa-
nies, banking partners and card networks. Those changes
may not trigger an obvious red flag on their own, espe-
underwriting cially when risk professionals are reviewing accounts
through scheduled checks or isolated alerts.
Manual monitoring and traditional rules can catch some
issues, but they often depend on the right signal appear-
ing at the right time. Rules are useful for known pat-
terns. They're less effective when the risk comes from a
new combination of merchant behavior, website changes
and connected entities. Merchant risk is prone to drift. It
doesn't stop at approval. The harder work is identifying
when new activity changes the risk profile enough to re-
quire review.
By Dan Frechtling Companies' fragmented risk data impedes response
LegitScript Payments companies often have useful information
erchant risk used to be treated largely as spread across the organization. Underwriting files,
a front-end decision. Payments companies website monitoring, transaction activity, adverse media,
reviewed a merchant at onboarding, made regulatory updates, and outside risk intelligence may each
M an underwriting call, and returned to the show part of the picture.
account only when a scheduled review or a warning sign
raised concern. That model worked better when merchant The problem is that those sources are often reviewed
behavior changed more slowly. Advances in technol- separately, which makes it harder to understand how one
ogy, particularly in AI-driven fraud, are upending this change relates to another. A website update may sit in one
approach and forcing companies processing payments to workflow, transaction activity in another, and related-en-
think differently. tity research somewhere else. By the time those signals are
connected, the exposure may already be harder to contain.
Today, a business can appear compliant at onboarding but
quickly change once they are through the door. A mer- Merchant risk programs need a way to connect those sig-
chant can pass review, begin processing payments, and nals throughout the relationship. Risk professionals need
then create new exposure through tactics such as changed to see what changed, understand why it matters, and de-
product offerings, new affiliated entities, or altered mar- cide whether the account still fits the company's risk toler-
keting claims. Initial underwriting still matters, but it can ance.
no longer carry the full burden of merchant risk manage-
ment. AI agents connect data and speed response
Agentic AI has become part of the merchant risk conversa-
If AI is core to driving problematic merchant behavior, it is tion because it can do more than basic automation. Instead
also the key to stopping it. McKinsey's 2026 AI Trust Ma- of waiting for a single trigger, a lifecycle-based system can
turity Survey (see https://tinyurl.com/2ebkr84d) found that compare signals across the merchant relationship and flag
responsible AI maturity is improving, even as governance when a business begins to look materially different from
and agentic AI controls still lag. Security and risk concerns the one originally approved.
remain the top barrier to scaling agentic AI, while active
mitigation continues to trail risk awareness across nearly The riskiest cases rarely come from a single data point.
every AI risk category. For payments companies, the take- A website change, transaction pattern or corporate record
away is practical. Merchant risk now requires monitoring may mean little on its own. Viewed alongside other sig-
that continues after approval, with AI governed by the nals, the same data point can indicate a change that de-
oversight and domain intelligence needed to make deci- serves review. AI is most useful when it gives risk profes-
sions defensible. sionals a clearer case file earlier in the process. Routine
One-time reviews miss merchant reviews can move with less friction, while more complex
risk 'drift' post-approval merchant activity can be routed to experienced reviewers
before a decision is made.
Initial underwriting remains an important control, but it Generic AI doesn't work without context
can only assess the merchant as presented at a given mo-
ment. Bad actors understand that limitation. Some pres- AI tools are only as effective as the foundational data
ent a compliant version of the business during onboard- they've been trained on. For assessing merchant risk effec-
ing, then shift their activity once payment processing is in
30

