For card schemes
For card schemes
Merchant-monitoring work for card scheme compliance teams.
Card schemes
The fear
Enforcement built on evidence from a party that earns from the flow can be impeached.
The answer
An independent evidence source that processes no payments and takes no revenue from any investigated party.
What your acquirers are now bound by
- 01 Jan 2026Mastercard merchant-monitoring requirements effective; violations reportable within five business days.Binds — AcquirersSource — Mastercard Security Rules and Procedures — Merchant Edition, §7.2.1, 4 Aug 2026, p.82
- 01 Jan 2026Visa Integrity Risk Program — high-integrity-risk merchant registration and monitoring obligations apply to acquirers, with MCC 7995 in Tier 1.Binds — AcquirersSource — Visa Integrity Risk Program
What you cannot see
A miscoded merchant is invisible in your own data by construction. The transaction arrives coded 5399 and clears as 5399; nothing in the authorisation message says the customer was buying a casino deposit.
Your monitoring programmes read what the acquirer submits. The acquirer reads what the merchant declares at onboarding. Nobody in that chain is looking at the cashier the customer actually reached.
Test-purchase programmes run by an interested party can be impeached on that ground alone, and an acquirer under assessment will make exactly that argument.
What we supply
A transaction-level record of a declared code tested against the service actually delivered, with the cashier state, the authorisation and the settlement record for each collection.
Attribution to the acquiring BIN, so a finding lands against a registered participant rather than against a storefront that will be renamed by the weekend.
A right-of-reply file for every named party, served before the finding is filed, so enforcement opens on a record that has already survived a response window.
How it is commissioned
Three ways to commission the work: a named set of targets, a market kept current, or a programme funded jointly.
How engagements work →