Introduction

Payment compliance is the regulatory framework that governs how businesses accept, process, and store financial data. It encompasses PCI DSS (data security), KYC (customer identity verification), and AML (anti-money laundering) regulations. Failing to maintain compliance results in massive fines, data breaches, and the immediate termination of your merchant account, particularly for high-risk businesses operating in heavily regulated industries.

Compliance is the invisible foundation of the global payment ecosystem.

When a customer enters their credit card number on your website, they are trusting you with their most sensitive financial information. When an acquiring bank underwrites your merchant account, they are trusting that you are operating a legitimate, legal enterprise.

Payment compliance is the mechanism that enforces this trust.

For many merchants, compliance is viewed as a bureaucratic nightmare—a series of endless forms, confusing acronyms, and expensive audits that distract from the core business of generating revenue.

This perspective is dangerous.

In the modern ecommerce landscape, compliance is not optional. It is a strict prerequisite for survival. If you fail to secure your customers’ data (PCI), if you fail to verify who you are doing business with (KYC), or if you inadvertently facilitate the movement of illicit funds (AML), the consequences are catastrophic.

You will not just face a slap on the wrist. You will face six-figure fines from the card networks, class-action lawsuits from compromised customers, and criminal investigations from federal regulators. Your acquiring bank will terminate your merchant account, freeze your funds, and place you on the MATCH list, effectively exiling you from the payment industry.

This comprehensive guide will demystify the complex world of payment compliance. We will break down the three core pillars of compliance—PCI DSS, KYC, and AML—explaining exactly what they are, why they exist, and how you can implement them within your business. We will also explore the specific, heightened compliance requirements for high-risk industries like CBD, gaming, and offshore processing.

Whether you are a startup launching your first ecommerce store or an enterprise merchant scaling globally, this guide will provide the roadmap you need to navigate the regulatory maze, protect your customers, and secure your merchant account.


Table of Contents

  1. Introduction
  2. Chapter 1: PCI DSS (Payment Card Industry Data Security Standard)
  3. Chapter 2: KYC (Know Your Customer)
  4. Chapter 3: AML (Anti-Money Laundering)
  5. Chapter 4: Industry-Specific Compliance Requirements
  6. Chapter 5: The Role of the ISO in Compliance
  7. Chapter 6: The Consequences of Non-Compliance (Fines, Freezes, and the MATCH List)
  8. Chapter 7: Building a Culture of Compliance
  9. Chapter 8: The Future of Payment Compliance (2026 and Beyond)
  10. Chapter 9: Frequently Asked Questions (FAQ)
  11. Chapter 10: The Intersection of Compliance and Chargebacks
  12. Chapter 11: Navigating International Compliance (Cross-Border Processing)
  13. Chapter 12: The Cost of Compliance vs. The Cost of Ignorance
  14. Conclusion: Partnering for Compliance Success
  15. Chapter 13: The Impact of Compliance on Customer Experience

Chapter 1: PCI DSS (Payment Card Industry Data Security Standard)

PCI DSS is a set of security standards mandated by Visa, Mastercard, and other card networks to ensure that all companies that accept, process, store, or transmit credit card information maintain a secure environment. Compliance requires implementing firewalls, encrypting data, restricting access, and utilizing tokenization to prevent catastrophic data breaches and massive network fines.

If you accept credit cards, you must be PCI compliant. There are no exceptions.

The Payment Card Industry Data Security Standard (PCI DSS) was created in 2004 by the major card brands (Visa, Mastercard, Discover, American Express, and JCB) to combat the rising tide of credit card fraud and data breaches.

It is important to understand that PCI DSS is not a federal law; it is an industry mandate. However, the card networks enforce it with the severity of a law, utilizing massive fines and the threat of network expulsion to ensure compliance.

The 12 Requirements of PCI DSS

The PCI DSS framework is built upon 12 core requirements, organized into six broader goals. While the technical implementation can be complex, the underlying principles are straightforward:

Build and Maintain a Secure Network and Systems

  1. Install and maintain a firewall configuration to protect cardholder data.
  2. Do not use vendor-supplied defaults for system passwords and other security parameters.

Protect Cardholder Data 3. Protect stored cardholder data (encryption).

Encrypt transmission of cardholder data across open, public networks.

Maintain a Vulnerability Management Program 5. Protect all systems against malware and regularly update anti-virus software or programs. 6. Develop and maintain secure systems and applications (patch management).

Implement Strong Access Control Measures 7. Restrict access to cardholder data by business need to know. 8. Identify and authenticate access to system components. 9. Restrict physical access to cardholder data.

Regularly Monitor and Test Networks 10. Track and monitor all access to network resources and cardholder data. 11. Regularly test security systems and processes (vulnerability scans and penetration testing).

Maintain an Information Security Policy 12. Maintain a policy that addresses information security for all personnel.

PCI Compliance Levels

Not all merchants are subjected to the same level of scrutiny. The PCI Security Standards Council categorizes merchants into four levels based on their annual transaction volume.

  • Level 1 (Over 6 million transactions/year): The most stringent level. Requires an annual on-site assessment by a Qualified Security Assessor (QSA) and a formal Report on Compliance (ROC).
  • Level 2 (1 to 6 million transactions/year): Requires an annual Self-Assessment Questionnaire (SAQ) and may require quarterly network scans by an Approved Scanning Vendor (ASV).
  • Level 3 (20,000 to 1 million ecommerce transactions/year): Requires an annual SAQ and quarterly network scans.
  • Level 4 (Under 20,000 ecommerce transactions/year): The vast majority of small businesses. Requires an annual SAQ and, depending on the setup, quarterly network scans.

The Cost of Non-Compliance

If you suffer a data breach and forensic investigators determine you were not PCI compliant at the time of the breach, the financial penalties are devastating.

  • Network Fines: Visa and Mastercard can fine your acquiring bank $5,000 to $100,000 per month for compliance violations. The bank will pass these fines directly to you.
  • Card Replacement Costs: You may be forced to pay the cost of reissuing new credit cards to every customer whose data was compromised (often $3 to $5 per card).
  • Forensic Audits: You will be required to hire an expensive forensic investigator to determine the scope of the breach.
  • Account Termination: Your acquiring bank will likely terminate your merchant account and place you on the MATCH list.

How to Simplify PCI Compliance (Tokenization)

For most Level 3 and Level 4 ecommerce merchants, achieving full PCI compliance on their own servers is technically difficult and prohibitively expensive.

The solution is to outsource your compliance by ensuring that raw credit card data never touches your servers.

  • Hosted Payment Pages: Use a checkout page hosted entirely by your payment gateway (like NMI or Authorize.Net). The customer enters their data on the gateway’s secure server, not yours.
  • Tokenization: If you need to store cards for recurring billing, use tokenization. The gateway encrypts the raw card number and returns a secure “token” (a random string of characters) to your server. You use the token to bill the customer in the future. If your server is hacked, the criminals only steal useless tokens, not actual credit card numbers.

By utilizing hosted pages and tokenization, you drastically reduce your “PCI scope,” allowing you to complete a much simpler Self-Assessment Questionnaire (SAQ A) and avoid the need for expensive quarterly vulnerability scans.


Chapter 2: KYC (Know Your Customer)

KYC (Know Your Customer) is a mandatory regulatory process used by financial institutions and acquiring banks to verify the identity of their clients. It requires merchants to provide government-issued IDs, corporate formation documents, and proof of address during underwriting to prevent identity theft, fraud, and the onboarding of sanctioned individuals or businesses.

When you apply for a merchant account, you are asking a financial institution to underwrite your business and process potentially millions of dollars on your behalf.

Before they agree to take on that risk, they must know exactly who you are.

This process is known as KYC (Know Your Customer). It is a fundamental component of global anti-money laundering (AML) regulations and is strictly enforced by federal agencies like the Financial Crimes Enforcement Network (FinCEN) in the United States.

The Purpose of KYC

The primary goal of KYC is to prevent financial institutions from being used, intentionally or unintentionally, by criminal elements for money laundering activities.

Specifically, acquiring banks use KYC to:

  1. Verify Identity: Ensure the individual applying for the account is who they claim to be (preventing identity theft).
  2. Verify the Business: Ensure the corporate entity is legally registered and operating in good standing.
  3. Understand the Nature of the Business: Determine exactly what products or services the business sells to assess the associated risk.
  4. Screen Against Sanctions: Ensure the individuals and the business are not on any government watchlists (e.g., the OFAC Specially Designated Nationals list) or the MATCH list.

The KYC Documentation Requirements

During the underwriting process, your ISO (like Numus Payments) will request a comprehensive packet of KYC documentation. Failing to provide accurate and complete documents will result in an instant decline.

For the Principal Owners (Individuals with 25%+ ownership):

  • Government-Issued ID: A clear, color copy of a valid passport or driver’s license.
  • Proof of Address: A recent utility bill or bank statement (usually within the last 90 days) showing the owner’s residential address.
  • Social Security Number (SSN): Required for US citizens to run a background and credit check.

For the Business Entity:

  • Articles of Incorporation/Organization: Official documents filed with the state proving the legal existence of the LLC or Corporation.
  • Employer Identification Number (EIN): The IRS confirmation letter (SS-4) showing the business’s tax ID.
  • Certificate of Good Standing: A document from the state confirming the business is authorized to operate and is up-to-date on its taxes and filings.
  • Business Bank Statements: 3 to 6 months of recent statements to verify financial stability and cash flow.
  • Processing Statements: 3 to 6 months of statements from a previous processor to verify volume and chargeback history.

The Beneficial Ownership Rule

In 2018, FinCEN implemented the Customer Due Diligence (CDD) Final Rule, which significantly strengthened KYC requirements regarding “Beneficial Ownership.”

Acquiring banks are now legally required to identify and verify the identity of any individual who owns 25% or more of the legal entity, as well as one individual who has significant responsibility to control the entity (e.g., a CEO or Managing Member).

This means you cannot hide behind complex corporate structures or shell companies. The bank must drill down to the actual human beings who control the money.

KYC for Your Customers (When Merchants Must Perform KYC)

While acquiring banks perform KYC on you (the merchant), certain high-risk industries require the merchant to perform KYC on their customers.

If you operate in industries like online gaming, cryptocurrency exchange, or high-value B2B transfers, you are often legally required to verify the identity of the people buying your products or services to prevent money laundering on your platform.

This requires integrating third-party identity verification software (like Jumio or Onfido) into your checkout process to scan customer IDs and verify their addresses before allowing them to transact.


Chapter 3: AML (Anti-Money Laundering)

AML (Anti-Money Laundering) is a set of laws and regulations designed to prevent criminals from disguising illegally obtained funds as legitimate income. Acquiring banks enforce AML by monitoring merchant transaction patterns for suspicious activity, such as sudden spikes in volume, unusually large transactions, or frequent refunds to different credit cards.

Money laundering is the process of taking “dirty” money (funds generated from illegal activities like drug trafficking, terrorism, or fraud) and passing it through a complex sequence of banking transfers or commercial transactions. The goal is to make the money appear “clean” (legitimate) so it can be integrated into the formal financial system without raising suspicion.

The global financial system, including the payment processing industry, is the primary battleground in the fight against money laundering.

Acquiring banks, ISOs, and payment gateways are legally obligated to implement robust Anti-Money Laundering (AML) programs. If they fail to detect and report suspicious activity, they face massive fines from regulatory bodies like FinCEN (in the US) or the FCA (in the UK), and their executives can face criminal prosecution.

The Three Stages of Money Laundering

To understand how AML regulations apply to ecommerce, you must understand the three stages of money laundering:

  1. Placement: The physical introduction of illicit cash into the financial system. (This is less common in ecommerce, as the funds are usually already digitized).
  2. Layering: The complex movement of funds to distance them from their illegal source. This often involves transferring money between multiple accounts, jurisdictions, or shell companies.
  3. Integration: The re-introduction of the laundered funds into the legitimate economy. The criminal uses the “clean” money to purchase assets (real estate, luxury goods) or fund legitimate businesses.

Ecommerce merchants are most vulnerable during the Layering and Integration stages.

How Criminals Use Ecommerce for Money Laundering

Criminals exploit vulnerabilities in the payment processing ecosystem to launder money. Two common methods include:

  • Transaction Laundering (Factoring): A criminal sets up a legitimate-looking ecommerce website (e.g., selling cheap t-shirts) and secures a merchant account. However, they use that merchant account to process payments for a hidden, illegal business (e.g., selling unregulated pharmaceuticals or illegal pornography). The acquiring bank thinks they are processing t-shirt sales, but they are actually laundering money for an illegal enterprise.
  • The Refund Scheme: A criminal uses stolen credit cards to make large purchases on a legitimate ecommerce site. Before the items ship, they cancel the order and request a refund. However, they ask the merchant to refund the money to a different credit card or via a wire transfer. The merchant unwittingly converts stolen funds into clean funds deposited into the criminal’s account.

AML Monitoring and Suspicious Activity Reports (SARs)

To combat these schemes, acquiring banks employ sophisticated AML monitoring systems that analyze every transaction processed by their merchants.

These systems look for “red flags” or anomalies that deviate from the merchant’s expected processing behavior (which was established during the KYC underwriting process).

Common AML Red Flags:

  • Sudden Volume Spikes: A merchant approved to process $50,000 a month suddenly processes $500,000 in a single week.
  • Unusually Large Transactions: A merchant whose average ticket size is $50 suddenly processes multiple $5,000 transactions.
  • High Velocity of Transactions: A massive number of small transactions processed in a very short period, often indicative of card testing or micro-structuring (smurfing).
  • Frequent Refunds: A high volume of refunds, especially if the refunds are directed to different payment methods than the original purchase.
  • International Anomalies: A US-based merchant who only ships domestically suddenly receives a massive influx of transactions from high-risk jurisdictions (e.g., Eastern Europe, parts of Africa or Asia).

If the AML system flags a merchant’s activity, the acquiring bank’s risk department will investigate.

If the investigation cannot resolve the suspicion (e.g., the merchant cannot provide invoices or proof of delivery for the sudden spike in volume), the bank is legally required to file a Suspicious Activity Report (SAR) with FinCEN (or the relevant national authority).

Crucially, it is illegal for the bank to inform the merchant that a SAR has been filed against them (this is known as “tipping off”). The bank will simply freeze the merchant’s funds, terminate the account, and allow law enforcement to take over.

The Merchant’s AML Responsibilities

While the acquiring bank bears the primary regulatory burden for AML, merchants also have responsibilities, particularly in high-risk industries.

  • Accurate Underwriting: You must provide accurate projections of your processing volume and average ticket size during the application process. If your business model changes significantly, you must inform your ISO before the new volume hits your account.
  • Strict Refund Policies: Never refund a transaction to a different credit card or via a different payment method (like a wire transfer or check). Always refund the original card used for the purchase.
  • Monitor Your Own Activity: Utilize your payment gateway’s reporting tools to monitor your transaction velocity and geographic distribution. If you notice a sudden, unexplained spike in international orders, proactively contact your ISO to explain the anomaly (e.g., “We just launched a new ad campaign in the UK”).

Chapter 4: Industry-Specific Compliance Requirements

High-risk industries face stringent, specialized compliance requirements beyond standard PCI, KYC, and AML. CBD merchants must provide independent lab testing (COAs) to prove THC levels are below 0.3%. Online gaming operators must hold valid licenses for every jurisdiction they target. Telemedicine providers must comply with HIPAA regulations regarding patient data privacy.

The baseline requirements of PCI, KYC, and AML apply to every merchant. However, if you operate in a high-risk industry, you are subject to an additional layer of intense regulatory scrutiny.

Acquiring banks are highly risk-averse. They will not underwrite a business if there is any ambiguity regarding the legality of its products or services.

To secure and maintain a high-risk merchant account, you must proactively demonstrate that your business complies with all relevant federal, state, and industry-specific regulations.

1. CBD, Hemp, and Nutraceuticals

The CBD industry is one of the most heavily scrutinized sectors in ecommerce due to its association with cannabis and the complex, constantly evolving legal landscape (e.g., the 2018 Farm Bill in the US).

The Compliance Requirements:

  • Certificates of Analysis (COAs): This is the most critical requirement. You must provide up-to-date COAs from an independent, accredited third-party laboratory for every single product you sell. The COA must definitively prove that the Delta-9 THC concentration is below the federal legal limit (0.3% in the US).
  • Marketing and Claims Audits: The FDA strictly prohibits CBD and nutraceutical companies from making medical claims. You cannot state or imply that your products diagnose, treat, cure, or prevent any disease (e.g., “Cures anxiety” or “Treats chronic pain”). Acquiring banks will audit your website, your social media, and your product labels. If they find prohibited claims, your account will be terminated immediately.
  • Age Verification: Depending on the jurisdiction and the specific product (e.g., CBD vape cartridges), you may be required to implement robust age verification gateways on your website to prevent sales to minors.

2. Online Gaming, Casinos, and Sports Betting

The online gambling industry is subject to massive regulatory oversight to prevent money laundering, underage gambling, and problem gambling.

The Compliance Requirements:

  • Licensing: You must hold a valid, active gaming license from a recognized regulatory body (e.g., the UK Gambling Commission, the Malta Gaming Authority, or specific state regulators in the US). You can only accept payments from customers located in jurisdictions where your license is valid.
  • Geo-Fencing: You must implement strict geo-location technology to ensure that users cannot access your platform or process payments from restricted territories.
  • Enhanced KYC/AML: Gaming operators must perform rigorous KYC on their users, verifying their identity and age before allowing them to deposit funds. They must also implement sophisticated AML monitoring to detect suspicious betting patterns or rapid deposit/withdrawal cycles.

3. Telemedicine and Online Pharmacies

The intersection of healthcare and ecommerce creates significant compliance challenges, primarily centered around patient privacy and the legal dispensing of medication.

The Compliance Requirements:

  • HIPAA Compliance (US): If you collect, store, or transmit Protected Health Information (PHI), your entire payment and data infrastructure must comply with the Health Insurance Portability and Accountability Act (HIPAA). This requires stringent data encryption, access controls, and Business Associate Agreements (BAAs) with your payment processors.
  • Prescription Verification: If you sell prescription medications, you must prove that a valid prescription was issued by a licensed medical professional following a legitimate consultation.
  • Pharmacy Licensing: You must provide proof of licensing for the pharmacy dispensing the medication and ensure you are legally permitted to ship to the customer’s location.

4. Adult Entertainment and Dating

The adult industry faces intense scrutiny from card networks (particularly Mastercard’s BRAM program and Visa’s GBPP) to prevent the distribution of illegal content.

The Compliance Requirements:

  • Content Monitoring: You must implement robust systems to monitor all user-generated content on your platform to ensure it complies with card network rules (e.g., no non-consensual content, no underage content).
  • Record Keeping (2257 Compliance): In the US, producers of adult content must comply with 18 U.S.C. § 2257, which requires strict record-keeping to verify the age and identity of all performers. Acquiring banks will require proof of this compliance.

5. Tech Support and Credit Repair

These industries are considered high-risk due to historically high rates of consumer fraud and deceptive marketing practices.

The Compliance Requirements:

  • Telemarketing Sales Rule (TSR): In the US, credit repair companies must comply with the FTC’s TSR, which strictly prohibits charging upfront fees before the promised services are fully delivered and documented.
  • Marketing Transparency: You must provide clear, unambiguous descriptions of your services, realistic timelines, and transparent pricing. Acquiring banks will heavily scrutinize your sales scripts and marketing materials for deceptive claims.

Chapter 5: The Role of the ISO in Compliance

An Independent Sales Organization (ISO) acts as the crucial intermediary between the merchant and the acquiring bank. A reputable high-risk ISO (like Numus Payments) does not just sell merchant accounts; they actively guide merchants through the complex underwriting process, ensuring all KYC, AML, and industry-specific compliance requirements are met before the application is submitted to the bank.

Navigating the labyrinth of payment compliance is not something a high-risk merchant should attempt alone.

The underwriting departments of acquiring banks are notoriously rigid. If you submit an application with incomplete KYC documentation, a poorly worded refund policy, or a website that inadvertently violates a card network rule, your application will be instantly declined.

Once declined by a bank, it becomes significantly harder to get approved by another bank, as the decline is often recorded in shared industry databases.

This is where a specialized high-risk Independent Sales Organization (ISO) becomes your most valuable asset.

The ISO as Your Compliance Advocate

A standard, low-risk payment aggregator (like Stripe or PayPal) uses automated algorithms to underwrite accounts. They do not review your compliance documentation until after you start processing (which is why they frequently freeze accounts without warning).

A high-risk ISO, however, performs manual, proactive underwriting.

Before they submit your application to their banking partners, the ISO’s internal risk team will conduct a comprehensive compliance audit of your business.

1. The Pre-Underwriting Audit

The ISO will review your website exactly as an acquiring bank would. They will check for:

  • Clear, accessible Terms and Conditions and Privacy Policies.
  • A robust, unambiguous Refund and Cancellation Policy.
  • Accurate billing descriptors that match your DBA.
  • Secure checkout pages (HTTPS/SSL).
  • Any prohibited marketing claims (e.g., medical claims for CBD products).

2. KYC Document Preparation

The ISO will ensure your KYC packet is flawless. They will verify that your corporate documents match your ID, that your bank statements are recent and legible, and that your processing history is accurately represented. If a document is missing or unclear, they will work with you to correct it before the bank sees it.

3. AML Risk Mitigation

The ISO will help you structure your processing volume projections to align with your actual business model, reducing the risk of triggering AML alerts during your first few months of processing. They will also advise you on implementing velocity filters and 3DS2 to prevent the types of fraudulent transactions that often lead to AML investigations.

4. Bank Matching

Perhaps most importantly, a high-risk ISO knows which acquiring banks are currently accepting which industries. Bank risk appetites change constantly. A bank that loved CBD last year might be rejecting all CBD applications this year due to a shift in their internal compliance policies. The ISO will route your perfectly prepared application to the bank most likely to approve it, saving you weeks of frustration and potential declines.

The Ongoing Compliance Partnership

The ISO’s role does not end once your account is approved.

Compliance is an ongoing requirement. Card network rules change, federal regulations evolve, and your business model will likely expand.

A reputable ISO will act as your long-term compliance partner. They will notify you of upcoming regulatory changes (e.g., a new Visa mandate regarding subscription billing), help you complete your annual PCI SAQ, and assist you in responding to any compliance inquiries or audits from the acquiring bank.


Chapter 6: The Consequences of Non-Compliance (Fines, Freezes, and the MATCH List)

The consequences of failing to maintain payment compliance are severe and often fatal to a business. They include massive financial penalties from card networks (up to $100,000/month for PCI violations), the immediate freezing of operating funds (often for 180 days), account termination, and placement on the MATCH list (TMF), which bans the merchant from processing payments for five years.

Compliance is not a suggestion; it is a mandate enforced by the most powerful financial institutions in the world.

When a merchant violates compliance protocols—whether intentionally (e.g., transaction laundering) or accidentally (e.g., failing to update a firewall, leading to a data breach)—the reaction from the acquiring bank and the card networks is swift, severe, and punitive.

1. Financial Penalties (Network Fines)

Visa and Mastercard do not fine merchants directly; they fine the acquiring bank. The acquiring bank, in turn, passes those fines directly to the merchant, often with an additional administrative markup.

  • PCI Non-Compliance Fines: If you suffer a data breach and are found to be non-compliant with PCI DSS, the fines can range from $5,000 to $100,000 per month until the compliance issue is resolved.
  • Rule Violation Fines: If you violate a specific card network rule (e.g., Visa’s rules regarding negative option billing or Mastercard’s BRAM program regarding prohibited content), the fines can be exorbitant, often starting at $25,000 per violation.

2. The 180-Day Fund Freeze

When an acquiring bank terminates a merchant account for compliance violations (or excessive chargebacks), they do not simply close the account and send the merchant their remaining money.

They freeze the funds.

  • The Justification: The bank is financially liable for any chargebacks that occur after the account is closed. Because consumers typically have up to 180 days to dispute a charge, the bank will hold the merchant’s funds in a non-interest-bearing reserve account for the entire 180-day window to cover their exposure.
  • The Impact: For a growing ecommerce business, having $50,000 or $100,000 in operating capital suddenly frozen for six months is usually a death sentence. They cannot pay suppliers, they cannot run ads, and they cannot make payroll.

3. The MATCH List (Terminated Merchant File)

The ultimate consequence of severe compliance violations is placement on the MATCH list (Member Alert to Control High-Risk Merchants), also known as the Terminated Merchant File (TMF).

  • The Blacklist: The MATCH list is a shared database maintained by Mastercard and used by all acquiring banks globally. If your business, your personal name, or your Social Security Number is added to this list, you are effectively blacklisted from the payment processing industry.
  • The Five-Year Exile: You remain on the MATCH list for exactly five years. During this time, it is nearly impossible to secure a new merchant account with any reputable domestic acquiring bank. Your only option is to utilize extremely expensive, high-risk offshore processors that charge exorbitant rates and require massive rolling reserves.

4. Legal and Criminal Liability

In cases of severe AML violations or intentional fraud (e.g., transaction laundering), the consequences extend beyond the payment industry.

Acquiring banks are legally required to file Suspicious Activity Reports (SARs) with federal authorities (like FinCEN in the US). This can trigger investigations by the FBI, the IRS, or the Department of Justice, leading to asset seizure, civil lawsuits, and criminal prosecution for the principal owners of the business.


Chapter 7: Building a Culture of Compliance

Compliance cannot be treated as a one-time checklist; it must be integrated into the core operations of the business. Merchants must build a culture of compliance by appointing a dedicated compliance officer, conducting regular internal audits, training employees on data security (PCI) and fraud detection (AML), and maintaining open, transparent communication with their ISO and acquiring bank.

The most successful high-risk merchants do not view compliance as an obstacle to growth; they view it as a competitive advantage.

By building a robust compliance infrastructure, they protect their revenue, secure their merchant accounts, and build trust with their customers and banking partners.

1. Appoint a Compliance Officer

Even in a small ecommerce business, one individual must be explicitly responsible for maintaining compliance.

This person (often the founder or the COO) must stay informed about changes in PCI DSS requirements, card network rules, and industry-specific regulations (e.g., FDA guidelines for CBD). They are responsible for completing the annual PCI SAQ, managing the relationship with the ISO, and ensuring that all marketing materials and website copy remain compliant.

2. Conduct Regular Internal Audits

Do not wait for your acquiring bank to audit you. Conduct your own internal audits quarterly.

  • Website Audit: Review your Terms and Conditions, Privacy Policy, and Refund Policy to ensure they are accurate, accessible, and compliant with current regulations.
  • Marketing Audit: Review your ad copy, social media posts, and product descriptions to ensure you are not making prohibited claims or engaging in deceptive marketing practices.
  • Security Audit: Ensure your SSL certificates are up-to-date, your firewalls are configured correctly, and your employees are using strong, unique passwords and two-factor authentication (2FA) for all systems that access customer data.

3. Employee Training

Your compliance infrastructure is only as strong as your weakest employee.

  • Data Security Training: Train all employees on the principles of PCI DSS. They must understand how to identify phishing emails, why they should never write down a customer’s credit card number, and the importance of physical security in the office.
  • Fraud Detection Training: Train your customer service and fulfillment teams to recognize the red flags of fraud and money laundering (e.g., a customer requesting a refund to a different credit card, or a sudden influx of high-value orders from a high-risk country).

4. Maintain Transparent Communication

The worst mistake a merchant can make is attempting to hide a compliance issue or a significant change in their business model from their ISO or acquiring bank.

If you are planning to launch a new product line, significantly increase your processing volume, or expand into international markets, contact your ISO before you make the change.

A reputable ISO will help you navigate the transition, ensuring that your acquiring bank is aware of the changes and that your account remains in good standing. Transparency builds trust, and trust is the currency of the high-risk payment industry.


Chapter 8: The Future of Payment Compliance (2026 and Beyond)

The future of payment compliance is defined by the integration of Artificial Intelligence (AI) and Machine Learning (ML) into AML monitoring, the global expansion of Open Banking (PSD2/PSD3), and the increasing regulatory scrutiny of cryptocurrency and decentralized finance (DeFi). Merchants must adapt to real-time, automated compliance checks and biometric identity verification (eKYC) to remain competitive and secure.

Compliance is not a static set of rules; it is a constantly evolving landscape driven by technological innovation, shifting consumer behavior, and the relentless ingenuity of cybercriminals.

As we move deeper into the 2020s, the regulatory burden on merchants and acquiring banks is increasing exponentially. The days of manual underwriting and static fraud filters are over.

To survive and thrive, high-risk merchants must understand the macro trends shaping the future of payment compliance.

1. AI-Driven AML and Fraud Detection

The sheer volume of global ecommerce transactions makes manual AML monitoring impossible.

Acquiring banks and payment gateways are increasingly relying on Artificial Intelligence (AI) and Machine Learning (ML) to analyze millions of data points in real-time.

  • Behavioral Biometrics: AI systems no longer just look at the transaction data (amount, location, CVV); they analyze how the user interacts with the device. How fast do they type? Do they use a mouse or a touchscreen? Do they hesitate before entering their CVV? This behavioral data creates a unique “fingerprint” that is nearly impossible for a bot or a fraudster to replicate.
  • Predictive AML: Instead of reacting to a sudden spike in volume, ML algorithms predict suspicious activity before it happens by identifying complex, hidden patterns across multiple merchant accounts and jurisdictions.

2. eKYC and Biometric Identity Verification

The traditional KYC process (uploading a scanned copy of a passport and a utility bill) is slow, cumbersome, and vulnerable to sophisticated forgery (deepfakes).

The future of identity verification is eKYC (Electronic Know Your Customer).

  • Liveness Detection: When a merchant (e.g., an online casino or a crypto exchange) needs to verify a user’s identity, the user is prompted to take a selfie video using their smartphone. The eKYC software uses AI to verify that the person is real (liveness detection) and matches their face to the photo on their government-issued ID in real-time.
  • Frictionless Onboarding: eKYC reduces the onboarding time from days to seconds, significantly improving conversion rates while simultaneously enhancing compliance and reducing fraud.

3. Open Banking and PSD3 (Europe and Beyond)

In Europe, the Revised Payment Services Directive (PSD2) revolutionized the payment industry by mandating Strong Customer Authentication (SCA) and forcing banks to open their APIs to third-party providers (Open Banking).

As regulators draft PSD3, the focus is shifting toward even stricter consumer protection and data privacy.

  • The Global Impact: While PSD2/PSD3 are European regulations, their impact is global. US-based merchants selling to European customers must comply with SCA (typically via 3D Secure 2.0). Furthermore, regulators in the US, Canada, and Australia are closely monitoring the European Open Banking experiment and are beginning to draft similar frameworks.

4. The Regulation of Cryptocurrency and DeFi

The most significant compliance challenge of the decade is the integration of cryptocurrency and Decentralized Finance (DeFi) into the traditional payment ecosystem.

For years, crypto operated in a regulatory gray area. That era is ending.

  • The Travel Rule: The Financial Action Task Force (FATF) has mandated that Virtual Asset Service Providers (VASPs), including crypto exchanges and wallets, must comply with the “Travel Rule.” This requires them to collect and share the personal information of the sender and receiver for any transaction over a certain threshold (typically $1,000), mirroring the AML requirements of traditional wire transfers.
  • Stablecoin Scrutiny: As stablecoins (like USDC and Tether) become increasingly popular for cross-border B2B payments, regulators are demanding that the issuers maintain 1:1 fiat reserves and submit to rigorous, traditional banking audits.

Merchants who wish to accept cryptocurrency must partner with specialized gateways (like BitPay or CoinBase Commerce) that handle the immense KYC/AML burden associated with digital assets.


Chapter 9: Frequently Asked Questions (FAQ)

This section addresses common questions regarding payment compliance, including the definition of PCI DSS, the consequences of failing a KYC audit, the purpose of AML regulations, and the specific compliance requirements for high-risk industries like CBD and online gaming.

What is PCI DSS and who does it apply to?

Answer: The Payment Card Industry Data Security Standard (PCI DSS) is a set of security mandates created by Visa, Mastercard, and other card networks. It applies to any business that accepts, processes, stores, or transmits credit card information, regardless of their size or transaction volume. Compliance requires firewalls, encryption, and strict access controls to prevent data breaches.

What happens if I am not PCI compliant?

Answer: If you suffer a data breach and are found to be non-compliant, you face catastrophic financial penalties. Visa and Mastercard can fine your acquiring bank $5,000 to $100,000 per month, which is passed directly to you. You will also be liable for the cost of reissuing compromised cards, forensic audits, and your merchant account will likely be terminated.

What is KYC (Know Your Customer)?

Answer: KYC is a mandatory regulatory process used by acquiring banks to verify the identity of the merchants they underwrite. It requires the submission of government-issued IDs, corporate formation documents (Articles of Incorporation, EIN), and proof of address. The goal is to prevent identity theft, fraud, and the onboarding of sanctioned individuals.

What is AML (Anti-Money Laundering)?

Answer: AML refers to the laws and regulations designed to prevent criminals from disguising illegally obtained funds as legitimate income. Acquiring banks enforce AML by monitoring merchant transaction patterns for suspicious activity, such as sudden volume spikes, unusually large transactions, or frequent refunds to different credit cards.

What is a Suspicious Activity Report (SAR)?

Answer: If an acquiring bank’s AML system detects unresolved suspicious activity on a merchant’s account (e.g., potential transaction laundering), the bank is legally required to file a SAR with federal authorities (like FinCEN). The bank cannot inform the merchant that a SAR has been filed; they will simply freeze the funds and terminate the account.

How do I reduce my PCI compliance burden?

Answer: The easiest way for ecommerce merchants to simplify PCI compliance is to use hosted payment pages and tokenization. By ensuring that raw credit card data never touches your own servers (the customer enters it directly on the gateway’s secure server), you drastically reduce your “PCI scope” and can complete a much simpler Self-Assessment Questionnaire (SAQ A).

What are the specific compliance requirements for CBD merchants?

Answer: CBD merchants face intense scrutiny. The most critical requirement is providing up-to-date Certificates of Analysis (COAs) from independent labs proving that the Delta-9 THC concentration in every product is below the federal legal limit (0.3% in the US). Furthermore, CBD merchants are strictly prohibited by the FDA from making any medical claims (e.g., “cures anxiety”).

What is the MATCH list (TMF)?

Answer: The MATCH list (Member Alert to Control High-Risk Merchants) is a blacklist maintained by Mastercard. If your acquiring bank terminates your account for severe compliance violations, excessive chargebacks, or illegal activity, you are added to this list. You will be banned from opening a new domestic merchant account for five years.

What is eKYC?

Answer: Electronic Know Your Customer (eKYC) is the modern, automated version of identity verification. It often utilizes AI and biometric “liveness detection” (e.g., requiring the user to take a selfie video) to match the user’s face to their government-issued ID in real-time, significantly speeding up the onboarding process while reducing fraud.

Why do I need an ISO for compliance?

Answer: A specialized high-risk Independent Sales Organization (ISO) acts as your compliance advocate. They conduct a pre-underwriting audit of your website and documents, ensuring your KYC packet is flawless and your business model aligns with the specific risk appetite of their banking partners, drastically reducing the chance of an application decline.


Chapter 10: The Intersection of Compliance and Chargebacks

Compliance and chargeback management are deeply intertwined. Failing to comply with card network rules (e.g., unclear billing descriptors or hidden subscription terms) directly causes friendly fraud chargebacks. Conversely, excessive chargebacks trigger compliance audits from acquiring banks, often leading to account termination and placement on the MATCH list.

Many merchants view compliance and chargeback management as two separate, unrelated departments. Compliance is handled by the legal or IT team, while chargebacks are handled by customer service or finance.

This siloed approach is a critical mistake.

In the eyes of Visa, Mastercard, and your acquiring bank, compliance and chargebacks are two sides of the same coin. They are both metrics used to measure the operational competence and risk profile of your business.

How Non-Compliance Causes Chargebacks

The vast majority of “friendly fraud” chargebacks are not malicious; they are the direct result of a merchant failing to comply with basic card network rules regarding transparency and communication.

  • The Billing Descriptor Rule: Visa and Mastercard mandate that your billing descriptor (the name that appears on the customer’s credit card statement) must clearly identify your business. If you use a confusing LLC name instead of your website’s DBA, you are violating a compliance rule. The direct result? The customer doesn’t recognize the charge and initiates a chargeback.
  • The Subscription Billing Mandate: In recent years, card networks have implemented strict compliance rules for negative option billing (free trials that convert to paid subscriptions). You must provide a clear, explicit receipt, send a reminder email before the trial ends, and offer a frictionless cancellation method. If you fail to comply with these rules, you will be hit with a massive wave of “Canceled Recurring Transaction” chargebacks.
  • The Refund Policy Rule: Your refund policy must be clearly displayed on your checkout page, and the customer must actively acknowledge it (e.g., by checking a box) before completing the purchase. If your policy is hidden in the footer of your website, you are non-compliant, and you will lose every “Significantly Not as Described” chargeback you receive.

How Chargebacks Trigger Compliance Audits

Conversely, a high chargeback ratio is the fastest way to trigger a devastating compliance audit from your acquiring bank.

Acquiring banks use chargeback ratios as an early warning system. If your ratio spikes above the 1.00% threshold, the bank assumes that something is fundamentally wrong with your business operations.

  • The AML Trigger: A sudden spike in chargebacks, particularly if they are concentrated in a specific geographic region or associated with a specific product line, will often trigger the bank’s AML monitoring system. The bank will suspect that you are either the victim of a massive fraud ring or that you are actively participating in transaction laundering.
  • The Deep Dive Audit: Once your account is flagged for excessive chargebacks, the bank’s risk department will conduct a deep dive into your compliance posture. They will scrutinize your website, your marketing materials, your KYC documentation, and your PCI status.
  • The Domino Effect: Often, the bank will discover a compliance violation during this audit (e.g., they find a prohibited medical claim on your CBD website). They will then terminate your account, not just for the chargebacks, but for the compliance violation, making it significantly harder for you to secure a new merchant account.

The Unified Risk Management Strategy

To protect your merchant account, you must integrate your compliance and chargeback management efforts into a single, unified risk management strategy.

  1. The Feedback Loop: Your chargeback management team must communicate directly with your compliance team. If you are losing chargebacks because your refund policy is unclear, the compliance team must immediately update the policy on the website.
  2. The Pre-Emptive Audit: Before launching a new product line or marketing campaign, conduct a joint audit. Ensure the marketing claims are compliant (FDA/FTC rules) and that the fulfillment process is robust enough to prevent “Item Not Received” chargebacks.
  3. The ISO Partnership: Work closely with your high-risk ISO (like Numus Payments). A reputable ISO will provide you with the tools and guidance needed to manage both compliance and chargebacks simultaneously, ensuring your account remains healthy and profitable.

Chapter 11: Navigating International Compliance (Cross-Border Processing)

Processing payments internationally introduces massive compliance complexity. Merchants must navigate conflicting data privacy laws (GDPR in Europe vs. CCPA in California), varying AML thresholds, and complex cross-border tax regulations (VAT/GST). Failing to comply with international regulations can result in seized funds, blocked IP addresses, and massive fines from foreign governments.

Ecommerce is inherently global. A merchant based in the United States can easily sell digital products to customers in Europe, Asia, and South America.

However, while the internet has erased physical borders, regulatory borders remain rigid and complex.

When you process a cross-border transaction, you are no longer just subject to the laws of your home country; you are subject to the laws of the customer’s country, the jurisdiction of the acquiring bank, and the international rules of the card networks.

1. Data Privacy: GDPR vs. The World

The most significant compliance challenge in cross-border processing is data privacy.

  • The GDPR (Europe): The General Data Protection Regulation (GDPR) is the strictest data privacy law in the world. If you process payments from European citizens, you must comply with GDPR, regardless of where your business is located. This requires explicit consent for data collection, the right for the customer to be “forgotten” (having their data deleted), and strict protocols for reporting data breaches.
  • The CCPA (California): The California Consumer Privacy Act (CCPA) provides similar, though slightly less stringent, protections for California residents.
  • The Conflict: Maintaining compliance across multiple, conflicting privacy frameworks requires sophisticated data management systems. You must know exactly where your customers’ data is stored, who has access to it, and how to delete it upon request.

2. Cross-Border AML and Sanctions

Anti-Money Laundering (AML) regulations vary significantly by jurisdiction.

  • The FATF Standards: While the Financial Action Task Force (FATF) sets global AML standards, individual countries implement them differently. A transaction that is considered low-risk in the US might trigger an AML alert in the UK.
  • Global Sanctions Lists: You must screen your international customers against multiple sanctions lists, not just the US OFAC list. This includes the UN Security Council Consolidated List and the EU Consolidated List of Sanctions. Processing a payment from a sanctioned individual or country (e.g., Iran, North Korea) is a severe federal crime.

3. International Tax Compliance (VAT and GST)

When you sell products internationally, you are often responsible for collecting and remitting local taxes.

  • The VAT (Value Added Tax): In the European Union, you must collect VAT on digital and physical goods sold to EU consumers, even if your business is based in the US. This requires registering for a VAT number and filing regular returns.
  • The GST (Goods and Services Tax): Similar to VAT, countries like Australia, Canada, and India require foreign merchants to collect and remit GST on sales to their citizens.
  • The Compliance Burden: Failing to collect and remit international taxes can result in your website being blocked by foreign ISPs, your funds being seized by international acquiring banks, and massive financial penalties.

4. The Solution: Merchant of Record (MoR)

For many high-risk merchants, the complexity of international compliance is overwhelming. The most effective solution is to partner with a Merchant of Record (MoR).

  • How It Works: An MoR (like Paddle or FastSpring) acts as a reseller. The customer buys the product from the MoR, and the MoR buys the product from you.
  • The Benefit: Because the MoR is the legal entity processing the transaction, they assume the entire burden of international compliance. They handle the GDPR data privacy, they calculate and remit the global VAT/GST taxes, and they manage the cross-border AML screening. You simply receive a clean payout, free from international regulatory liability.

Chapter 12: The Cost of Compliance vs. The Cost of Ignorance

Investing in compliance infrastructure (PCI audits, legal counsel, specialized ISOs) is expensive, but the cost of ignorance is catastrophic. A single compliance failure can result in a $100,000 network fine, a 180-day fund freeze, and placement on the MATCH list. Compliance is not an operational expense; it is an insurance policy on your business’s survival.

Many merchants, particularly startups and fast-growing SMEs, view compliance as a burdensome expense that detracts from their marketing budget and profit margins.

They ask: “Why should I pay $5,000 for a legal review of my website, or $2,000 for a PCI vulnerability scan, when I haven’t had any issues yet?”

This mindset is the equivalent of refusing to buy fire insurance because your house hasn’t burned down yet.

The True Cost of Compliance

Building a robust compliance infrastructure requires a financial investment.

  • Legal Counsel: Hiring an attorney specializing in ecommerce and payment processing to review your Terms and Conditions, Privacy Policy, and Refund Policy.
  • Security Infrastructure: Investing in secure hosting, SSL certificates, and potentially third-party penetration testing to ensure PCI compliance.
  • Specialized Software: Paying for eKYC identity verification tools, chargeback alert networks (Ethoca/Verifi), and automated representment software.
  • The ISO Partnership: Partnering with a high-risk ISO often involves slightly higher processing rates than a low-risk aggregator (like Stripe), but this premium pays for the proactive underwriting and ongoing compliance support.

The Catastrophic Cost of Ignorance

Now, compare the cost of compliance to the cost of a single, severe compliance failure.

Let’s assume a high-risk merchant processing $250,000 a month decides to cut corners. They use a cheap, non-compliant shopping cart, they hide their refund policy to boost conversions, and they fail to verify the age of their customers.

The Scenario:

  1. The Trigger: The hidden refund policy leads to a spike in friendly fraud chargebacks. The ratio hits 1.50%.
  2. The Audit: The acquiring bank notices the spike and conducts a compliance audit.
  3. The Discovery: The bank discovers the non-compliant shopping cart (a PCI violation) and the lack of age verification (a severe regulatory violation).
  4. The Fines: Visa fines the acquiring bank $50,000 for the PCI violation. The bank passes the fine to the merchant.
  5. The Freeze: The bank immediately terminates the merchant account and freezes the remaining $150,000 in the operating account for 180 days to cover potential future chargebacks.
  6. The MATCH: The bank places the merchant on the MATCH list (TMF).

The Final Tally:

  • Immediate Cash Loss: $50,000 (Network Fine).
  • Frozen Capital: $150,000 (Unavailable for 6 months).
  • Lost Revenue: $250,000/month (The business cannot process payments).
  • Long-Term Damage: Banned from the payment industry for 5 years.

The business is completely destroyed.

The ROI of Compliance

When viewed through this lens, the Return on Investment (ROI) of compliance is massive.

Every dollar spent on legal review, security infrastructure, and a reputable ISO partnership is a dollar spent protecting your revenue stream, your operating capital, and your ability to remain in business.

Compliance is not a bureaucratic hurdle; it is the foundation upon which sustainable, long-term ecommerce success is built.


Conclusion: Partnering for Compliance Success

Navigating the complex web of PCI, KYC, and AML regulations is impossible without expert guidance. High-risk merchants must partner with a specialized Independent Sales Organization (ISO) like Numus Payments. We provide proactive underwriting, continuous compliance monitoring, and direct access to acquiring banks that understand and support your specific industry, ensuring your business remains secure and profitable.

The regulatory landscape governing the payment processing industry is vast, complex, and unforgiving.

From the technical mandates of PCI DSS to the rigorous identity verification of KYC and the global monitoring of AML, the burden placed on merchants is immense. For high-risk industries, this burden is magnified by additional layers of federal, state, and card network scrutiny.

Attempting to navigate this labyrinth alone is a recipe for disaster. A single misstep—a poorly worded refund policy, a missing COA, or a failure to implement 3DS2—can result in massive fines, frozen funds, and the permanent loss of your merchant account.

You need a partner who understands the rules of the game.

Contact Numus Payments today for a comprehensive compliance audit.

Our team of high-risk payment experts will review your website, analyze your KYC documentation, and ensure your business model aligns with the specific risk appetites of our global network of acquiring banks. We don’t just provide merchant accounts; we provide the compliance infrastructure you need to scale your business securely and sustainably.


Chapter 13: The Impact of Compliance on Customer Experience

While compliance measures like 3DS2 and KYC verification add friction to the checkout process, they are essential for protecting both the merchant and the consumer. The key is balancing security with user experience (UX). By utilizing modern, frictionless authentication methods (like biometric eKYC and network-level tokenization), merchants can maintain rigorous compliance without sacrificing conversion rates.

A common complaint among ecommerce merchants, particularly those in high-risk industries, is that strict compliance measures kill conversion rates.

They argue that forcing a customer to verify their identity with a selfie video (eKYC) or requiring them to authenticate a transaction via their banking app (3DS2) creates too much friction. The customer gets frustrated, abandons their cart, and buys from a competitor with a less secure checkout process.

This is a valid concern, but it is based on an outdated understanding of compliance technology.

The Evolution of Friction

In the early days of ecommerce, security and user experience (UX) were mutually exclusive.

  • The Old Way (High Friction): To verify a customer’s identity, a merchant might require them to email a scanned copy of their driver’s license and a utility bill. This process took days, required manual review, and resulted in massive cart abandonment.
  • The Old Way (3DS1): The original 3D Secure protocol redirected the customer to a clunky, unbranded pop-up window where they had to remember a static password they created years ago. If they forgot the password, the transaction failed.

The Modern Balance (Frictionless Security)

Today, the payment industry has recognized that security cannot come at the expense of commerce. Modern compliance tools are designed to be invisible, or at least, highly intuitive.

  • The New Way (eKYC): Modern identity verification takes seconds. The customer uses their smartphone camera to scan their ID and take a selfie. The AI verifies the liveness and matches the face instantly. While it is an extra step, it is a familiar, mobile-native interaction that modern consumers are increasingly comfortable with.
  • The New Way (3DS2): The updated 3D Secure protocol is designed for mobile commerce. It analyzes dozens of data points in the background. If a transaction is deemed low-risk, it is approved frictionlessly (no challenge required). If a challenge is needed, it is often completed via a simple biometric scan (FaceID or fingerprint) on the customer’s banking app.

The Trust Factor

Furthermore, consumers are becoming increasingly aware of data privacy and security.

A checkout process that feels too easy, especially on a new or unfamiliar website, can actually deter a purchase. When a customer sees the “Verified by Visa” logo or is asked to authenticate a high-value transaction, it signals that the merchant takes their security seriously.

Compliance, when implemented correctly, is not a conversion killer; it is a trust builder.

Optimizing the Compliance UX

To balance compliance and conversion, merchants must optimize the user experience of their security protocols.

  1. Communicate Clearly: If you require identity verification (e.g., for age-restricted products like CBD or gaming), explain why you need it early in the checkout process. Do not surprise the customer at the final step. Use clear, reassuring language: “To comply with federal regulations and protect your identity, we need to quickly verify your age.”
  2. Use Native Integrations: Ensure your eKYC and 3DS2 tools are fully integrated into your checkout flow. Do not redirect the customer to a third-party website if it can be avoided. The entire process should feel like a seamless part of your brand experience.
  3. Offer Alternative Payment Methods: If a customer struggles with a 3DS2 challenge on their credit card, offer alternative payment methods like Apple Pay or Google Pay. These digital wallets utilize biometric authentication natively, satisfying the Strong Customer Authentication (SCA) requirements while providing a frictionless checkout experience.

By embracing modern compliance technology and prioritizing the user experience, high-risk merchants can protect their businesses from fraud and regulatory fines while simultaneously building trust and maximizing conversions.

Related Articles

PCI Compliance Guide: What Merchants Need to Know (2026)

KYC Requirements for Merchants: The 2026 Compliance Guide