Blog Main Image

September’s updates show merchant onboarding moving further away from point-in-time checks. Payment providers increasingly need better data upfront, consistent risk decisions, and ongoing monitoring across the merchant lifecycle, while keeping onboarding simple and frictionless for legitimate merchants.

In this update (for merchant onboarding and compliance teams):

What changed: September brought developments across payment authentication, sanctions, digital asset fraud, crypto regulation, gaming-sector AML enforcement, and payment-sector monitoring. Across these updates, regulators and networks are placing more attention on how businesses are verified, how risk is identified, and how controls continue after onboarding.

Why it matters: Merchant onboarding data now supports much more than the initial approval decision. Business activity, ownership, regulatory status, payment methods, screening results, and risk indicators need to be captured clearly and carried through KYB, KYC, AML, underwriting, and ongoing monitoring. Weak or incomplete information at onboarding can make it harder to identify financial crime risk, respond to changes, and explain decisions later.

Regulatory signals:

  • Sanctions and fraud risks reinforce the need for ongoing screening and monitoring, not just checks completed at onboarding.
  • Crypto developments are increasing the importance of understanding payment activity, regulatory permissions, and undeclared digital asset exposure.
  • AML enforcement is focusing on whether Customer Due Diligence (CDD), Enhanced Due Diligence (EDD), risk assessment, and monitoring controls work in practice, not simply whether policies exist.
  • Regulators are placing greater emphasis on timely risk detection, clear escalation, and strong audit trails across the customer lifecycle.

What to do next:

  • Capture complete, structured information about the merchant, ownership, business model, payment activity, and regulatory status from the start.
  • Connect KYB, KYC, AML, risk assessment, and underwriting so the same trusted information supports decisions across onboarding.
  • Use timely  risk signals and ongoing customer due diligence (OCDD) to identify changes in merchant activity, ownership, sanctions exposure, or risk after approval.
  • Keep clear audit trails showing what was checked, what risk was identified, what action was taken, and why each decision was made.

‍

🌎 Global

Industry Change: Visa Sunsets Digital Authentication Framework (DAF) 3-D Secure Program

Effective date: September 2026 (exact date not specified by Visa; DAF test cases became optional for certification starting 30 October 2025)

Issued by: Visa Inc.

Applies to: Merchants, acquirers, PSPs, and payment gateways using Visa Secure across the U.S., Canada, Asia Pacific, CEMEA, EU, and LAC regions.

Summary:

  • What: Visa is sunsetting its Digital Authentication Framework (DAF) 3-D Secure program in September 2026, shifting toward newer methods like Visa Payment Passkey.
  • Why: Visa is moving toward newer authentication methods designed to reduce payment friction while maintaining fraud controls. 
  • What's Next: Visa states that merchants currently using DAF 3DS should plan for the September 2026 sunset, and no new participants are being accepted into the program.

Key changes:

  • DAF 3DS is being retired globally across all Visa Secure regions, not just one market.
  • Visa is no longer accepting new participants into the DAF 3DS program. 
  • The Visa Token Service (VTS) DAF program will remain in place, with no impact to token transactions.
  • Visa Payment Passkey and other newer authentication methods are positioned as the direct replacement.

What this means for merchant onboarding teams:

‍Although the DAF sunset does not create new merchant onboarding requirements, it reflects the broader payments-industry shift toward lower-friction digital experiences. For onboarding teams, the parallel challenge is reducing unnecessary friction without weakening data quality, verification, risk assessment, underwriting, or ongoing controls. 

Recommended actions:

  • Review the full merchant onboarding journey to identify manual steps, duplicate data capture, and unnecessary silos that create friction.
  • Make sure application forms capture complete, structured merchant information upfront to support downstream KYB, KYC, AML, risk, and underwriting checks.
  • Automate verification and risk checks where possible so lower-risk applications can progress without unnecessary manual review.
  • Connect onboarding, underwriting, and compliance workflows so merchant information can move through the process without repeated collection or re-entry.
  • Extend the same risk-based approach beyond approval through ongoing monitoring and OCDD.

How OnBoard helps

‍OnBoard supports lower-friction merchant onboarding by connecting data capture, verification, risk assessment, underwriting, and ongoing monitoring in one end-to-end process.

  • Smart Forms capture complete, structured merchant information upfront and adapt the application journey based on merchant responses.
  • Automated KYB, KYC, and AML workflows verify businesses and individuals while reducing manual checks and repeated data collection.
  • OnBoard AIQ™ validation extracts and validates information from supporting documents in real time, helping reduce manual review and remediation.
  • Real-time risk scoring and the Automated Decision Engine support faster risk assessment, underwriting, and routing based on predefined rules.
  • Ongoing Customer Due Diligence (OCDD) extends the onboarding process beyond approval by monitoring changes in merchant information and risk over time.

Source: Visa Inc. 

‍

🇺🇸 United States

Sanctions Action: OFAC Specially Designated Nationals (SDN) List Update

Effective date: 8 September 2026 (designation date); published in the Federal Register 15 September 2026

Issued by: Office of Foreign Assets Control (OFAC), U.S. Department of the Treasury

Applies to: Banks, payment service providers, fintechs, merchant acquirers, and firms conducting sanctions screening on merchants, beneficial owners, or counterparties.

Summary:

  • What: OFAC added new individuals and entities to the Specially Designated Nationals (SDN) List on 8 September 2026.
  • Why: OFAC designations generally block the property and interests in property of designated persons within U.S. jurisdiction and prohibit U.S. persons from transacting with them unless authorized or exempted by OFAC. 
  • What's Next: The designations are already in effect. Firms should ensure sanctions screening reflects the updated SDN List and review potential direct or indirect exposure to newly designated persons and entities.  

Key changes:

  • New individuals and entities were added to the SDN List effective September 8, 2026. 
  • Property and interests in property within U.S. jurisdiction are blocked in accordance with the applicable sanctions.  
  • U.S. persons are generally prohibited from transactions involving blocked persons unless authorized or exempted by OFAC. 
  • Under OFAC’s 50 Percent Rule, entities owned 50% or more, directly or indirectly and in aggregate, by one or more blocked persons are also treated as blocked, even if they do not appear separately on the SDN List. 
  • Financial institutions should assess direct and indirect exposure through counterparties, beneficial ownership structures, and intermediaries when screening for sanctions risk. 

What this means for merchant onboarding teams:

Sanctions screening cannot be treated as a one-time check during merchant onboarding. As sanctions lists change, onboarding teams need to make sure new applications are screened against current information and existing merchants are re-screened through OCDD.

If a potential match is identified, it should be flagged and routed for review before an onboarding or ongoing-risk decision is made.

Recommended actions:

  • Make sure sanctions screening uses the latest SDN List for all new merchant applications.
  • Re-screen existing merchants as sanctions lists change, rather than relying only on checks completed at onboarding.
  • Include relevant individuals and entities captured through KYB and KYC in sanctions screening.
  • Route potential matches to the appropriate compliance team for review.
  • Keep a clear audit record of screening results, alerts, reviews, and final decisions. 

How OnBoard helps

‍OnBoard helps payment providers identify sanctions exposure across merchants, beneficial owners, related parties, and partner relationships throughout the customer lifecycle. 

  • PEP and Sanctions Screening checks merchants, beneficial owners, and related parties against more than 200 global sanctions and watchlists, helping identify newly designated parties as screening information changes. 
  • Automated KYB and business verification maps ownership structures to surface hidden ties to sanctioned or high-risk entities.
  • Ongoing Customer Due Diligence (OCDD) continues monitoring existing merchants as sanctions lists change. 
  • Automated Decision Engine routes potential matches to the right team for review. 
  • Audit-ready reporting maintains a clear record of screening results, alerts, reviews, escalation, and resolution. 

Source: Office of Foreign Assets Control, U.S. Department of the Treasury 

Regulatory Alert: FinCEN Alert on Digital Asset Investment Scam Centers

Effective date: 3 September 2026 (Alert FIN-2026-Alert005)

Issued by: Financial Crimes Enforcement Network (FinCEN), U.S. Department of the Treasury

Applies to: Banks, payment service providers, fintechs, crypto businesses, and firms onboarding or monitoring merchants and customers with digital asset exposure.

Summary:

  • What: FinCEN published an alert and analysis on digital asset investment scams run by overseas scam centers.
  • Why: FinCEN analyzed 33,904 Bank Secrecy Act reports filed between September 2023 and December 2025, identifying approximately $12.7 billion in financial activity linked to suspected digital asset investment scams. 
  • What's Next: Financial institutions are being encouraged to use FinCEN’s red flags to identify and report suspicious activity linked to these scams and share relevant information with other institutions where appropriate. 

Key findings:

  • FinCEN reviewed 33,904 Bank Secrecy Act reports filed between September 8, 2023 and December 31, 2025, covering about $12.7 billion in suspected scam-related financial activity.
  • Scam operators often use fake identities and pose as legitimate business contacts to build trust.
  • Fraudulent investment websites and mobile apps are used to make scam activity appear legitimate.
  • Shell companies and financial accounts are used to support and move scam-related funds.
  • Stablecoins and digital asset exchanges are also used to move proceeds through the financial system.

What this means for merchant onboarding teams:

‍FinCEN’s alert matters to merchant onboarding because scam networks can use fake identities, shell companies, and fake investment websites to look like legitimate businesses, especially where digital assets are involved.

For onboarding teams, this means checking that the business, owners, website, documents, and stated activities all match before approval. If something does not add up, the application should be flagged for further review.

The risk does not stop at onboarding. OCDD helps teams identify changes in merchant information or risk after approval.

Recommended actions:

  • Collect clear information about the merchant’s business model, owners, website, and digital asset activity.
  • Check that application forms, documents, websites, and ownership details all match.
  • Flag any application where the information does not add up.
  • Apply extra due diligence to higher-risk digital asset merchants or merchants linked to scam indicators.
  • Keep monitoring merchants after approval through OCDD so new risks can be identified early.

How OnBoard helps

‍OnBoard helps firms catch scam-related risk across the entire merchant and customer lifecycle, not just at the front door.

  • Automated KYB and KYC workflows verify the business, beneficial owners, and key individuals in real time, helping teams identify fake identities, unclear ownership, or shell companies that may be used to support scam activity.
  • OnBoard AIQ Site Scanner™ reviews merchant websites to check whether the products, services, and business activity shown online match what was declared during onboarding, helping identify fake or misleading investment businesses.
  • OnBoard AIQ™ validation reads and validates supporting documents in real time, helping flag information that is missing, inconsistent, or does not match the merchant’s application.
  • Real-Time Risk Scoring and the Automated Decision Engine bring these risk signals together to identify higher-risk digital asset merchants and route them for additional review before approval.
  • Ongoing Customer Due Diligence (OCDD) continues monitoring merchant information after onboarding, helping teams identify changes in ownership, business activity, or risk that may point to emerging scam exposure.

Source: Financial Crimes Enforcement Network, U.S. Department of the Treasury 

‍

🇬🇧 United Kingdom

Enforcement Action: FCA crackdown on Illegal Peer-to-Peer (P2P) Crypto Trading

Effective date: Enforcement action taken 10 September 2026; press release published 17 September 2026

Issued by: Financial Conduct Authority (FCA)

Applies to: Crypto trading platforms, peer-to-peer crypto services, and merchant onboarding teams assessing UK-facing crypto or P2P payment merchants.

Summary:

  • What: The FCA, working with HM Revenue & Customs (HMRC) and the Metropolitan Police, targeted three London premises in a renewed crackdown on peer-to-peer (P2P) crypto trading.
  • Why: The FCA says unregistered P2P crypto businesses can be used to move and launder criminal funds while avoiding anti-money laundering checks. 
  • What's Next: The FCA will keep working with law enforcement to find and disrupt illegal crypto activity.

Key findings:

  • The action follows an earlier FCA operation in April 2026, with evidence from that operation now being used in criminal investigations and other enforcement work. 
  • The FCA targeted three London-based P2P crypto trading premises, issuing cease and desist letters at all three.
  • Any business carrying out P2P crypto trading in the UK needs the appropriate FCA registration.
  • There are currently zero FCA-registered peer-to-peer crypto businesses operating in the UK.

What this means for merchant onboarding teams:

‍Although this action does not directly change merchant onboarding requirements, it highlights the need for payment providers to identify undeclared or changing crypto activity during onboarding and through ongoing monitoring, rather than relying only on what a merchant declared initially. 

Changes in payment activity, settlement methods, website content, or third-party relationships should be identified quickly and compared against the merchant’s approved business model. If new or unclear crypto exposure appears, it should be flagged and escalated for further review.

Recommended actions:

  • Capture whether a merchant accepts, settles, or has exposure to crypto as part of its payment setup.
  • Check that the merchant’s website, business model, and payment arrangements match what was declared during onboarding.
  • Review any third-party payment relationships where the crypto activity or regulatory status is unclear.
  • Flag undeclared or unclear crypto activity for further review before approval.
  • Keep monitoring existing merchants for changes in payment activity or business model after onboarding.

How OnBoard helps

‍OnBoard helps payment providers identify undeclared or unclear crypto exposure during merchant onboarding and monitor for changes after approval.

  • Smart Forms capture structured information about a merchant’s payment methods, crypto exposure, and third-party relationships from the start.
  • OnBoard AIQ Site Scanner™ reviews the merchant’s website and compares the activity shown online with what was declared during onboarding, helping flag undeclared crypto services or payment activity.
  • OnBoard AIQ™ validation reads supporting documents in real time and helps identify information that does not match the merchant’s application or stated business model.
  • Real-Time Risk Scoring and the Automated Decision Engine bring these risk signals together and route merchants with unclear or higher-risk crypto exposure for further review.
  • Ongoing Customer Due Diligence (OCDD) monitors merchant information after approval, helping teams identify changes in business activity, payment exposure, or risk over time.

Source: Financial Conduct Authority 

Regulatory Guidance: FCA Publishes Guidance Ahead of Cryptoasset Authorization Gateway

Effective date: Guidance published 16 September 2026; application gateway opens 30 September 2026, closes 28 February 2027

Issued by: Financial Conduct Authority (FCA)

Applies to: UK cryptoasset firms, FCA-authorized firms needing additional permissions, MLR-registered firms, e-money issuers, payment service providers, traditional finance firms entering crypto, and overseas firms serving UK consumers. 

Summary:

  • What: The FCA published new guidance explaining how the law underpinning the UK's future cryptoasset regime applies to firms, ahead of the authorization gateway opening on 30 September 2026.
  • Why: Firms that want to keep offering regulated crypto services in the UK will need the right FCA authorization when the new regime starts. The guidance helps them understand what they need to apply for and prepare in time.
  • What's Next: The application window opens on September 30, 2026 and closes on February 28, 2027 for firms that want to use the transitional arrangements.

Key changes:

  • The guidance covers which activities require FCA authorization, including issuing qualifying stablecoins, operating trading platforms, dealing and arranging deals, safeguarding cryptoassets, and arranging staking.
  • Firms carrying out these activities will need the appropriate FCA authorization. Firms that are already authorized may need to apply for additional permissions.
  • Being registered under the Money Laundering Regulations does not by itself authorize a firm to carry out the new regulated cryptoasset activities. MLR-registered firms that fall within scope will need to apply for FCA authorization.
  • The new cryptoasset regime will start on October 25, 2027.

What this means for merchant onboarding teams:

‍The FCA expects firms to understand which crypto activities they plan to offer, what permissions they will need, and where their current processes may need to change.

For payment providers, this can directly affect merchant onboarding. Onboarding workflows need to reflect the provider’s approved scope of services, capture which crypto-related services a merchant needs, and apply the right checks and risk rules from the start.

As providers update their permissions, business models, and compliance processes, merchant onboarding will also need to stay flexible so workflows can be updated without creating unnecessary manual work or delays.

Recommended actions:

  • Review which cryptoasset activities your payment business plans to offer and confirm what FCA permissions will be required.
  • Map those permissions to merchant onboarding so teams know which crypto-related services can be offered to each merchant.
  • Review onboarding workflows for gaps in data capture, verification, risk assessment, or approval rules linked to crypto services.
  • Update forms and workflows so merchants are routed based on the crypto services they need and the provider’s approved scope.
  • Set clear owners and timelines for onboarding changes so they are ready before the new regime takes effect.

How OnBoard helps

‍OnBoard supports merchant onboarding in the UK with configurable, risk-based workflows built around FCA authorization status and the evolving cryptoasset regime.

  • Smart Forms capture structured information about the crypto-related services a merchant wants to use, so the right requirements can be applied from the start.
  • Real-Time Risk Scoring and the Automated Decision Engine apply the provider’s risk rules and route merchants based on the services requested, risk level, and required approvals.
  • Automated KYB, KYC, and AML workflows apply the right verification and compliance checks based on the merchant type and crypto services being offered.
  • API-driven integrations help connect merchant onboarding with internal systems and external data sources as providers update their crypto services and regulatory processes.
  • Audit-ready reporting keeps a clear record of the information collected, checks completed, approvals made, and onboarding decisions as the provider moves into the new FCA regime.

Source: Financial Conduct Authority, Cryptoasset perimeter guidance, New cryptoasset regulatory regime

‍

🇨🇦 Canada

Enforcement Action: FINTRAC Gaming-Sector AML Penalties

Effective date: 3 September 2026

Issued by: Financial Transactions and Reports Analysis Centre of Canada (FINTRAC)

Applies to: Casinos, gaming and lottery corporations, and other reporting entities in Canada's gaming sector under the Proceeds of Crime (Money Laundering) and Terrorist Financing Act.

Summary:

  • What: FINTRAC fined two casino-sector reporting entities: New Brunswick Lotteries and Gaming Corporation ($399,712.50) and Nova Scotia Gaming Corporation ($231,826).
  • Why: The penalties involved failures in suspicious transaction reporting and, in the Nova Scotia Gaming Corporation case, deficiencies in compliance policies, procedures, and documented ML/TF risk assessment. 
  • What's Next: Gaming-sector reporting entities should review whether suspicious transaction reporting, compliance procedures, and documented ML/TF risk assessments are operating effectively in practice. 

Key changes:

  • New Brunswick Lotteries and Gaming Corporation got hit with $399,712.50 for a single, "very serious" violation involving failure to file suspicious transaction reports.
  • Nova Scotia Gaming Corporation got hit with $231,826 for three violations, including missed suspicious transaction reports, incomplete compliance policies, and no documented risk assessment.
  • Both entities have paid their penalties in full and the cases are closed.
  • The cited violations concerned suspicious transaction reporting, compliance policies and procedures, and documented ML/TF risk assessment. 

What this means for gaming compliance and onboarding teams:

‍These enforcement actions do not specifically concern member onboarding, but they reinforce a broader control expectation: risk assessment, suspicious activity detection, reporting, and compliance procedures need to work together throughout the customer relationship.

For gaming operators, onboarding can establish a reliable member identity and risk baseline that supports subsequent monitoring, escalation, investigation, and suspicious transaction reporting.

Recommended actions:

  • Ensure member onboarding establishes a reliable identity and initial risk profile.
  • Review documented ML/TF risk assessments and confirm they remain current and complete.
  • Ensure unusual activity identified during the relationship feeds into appropriate investigation and suspicious transaction reporting processes.
  • Review compliance policies and procedures against current operational practices.
  • Maintain clear records of alerts, investigations, reporting decisions, and risk-assessment updates.  

How OnBoard helps

OnBoard helps gaming venues connect member onboarding, ongoing AML checks, real-time risk response, and audit records in one controlled process.

  • Digital member onboarding and identity verification establish a verified member record from the start, supported by automated PEP and sanctions screening, risk assessment, and approvals.
  • Real-time risk-triggered checks can automatically run identity, PEP, and sanctions checks when a defined risk event occurs, such as unusual activity or a member reaching a set risk threshold.
  • Scheduled ongoing checks keep member screening and risk information current throughout the relationship, rather than relying only on checks completed at onboarding.
  • Centralized compliance records capture checks, risk information, outcomes, and actions in one place, creating a clear audit trail for oversight, investigation, and suspicious activity review.
  • Automated rules and workflows apply the same screening and decision process across venues and interactions, while routing exceptions to the appropriate team for further review.

Source: FINTRAC News Release for New Brunswick Lotteries and Gaming Corporation & Nova Scotia Gaming Corporation 

‍

🇿🇦 South Africa

Enforcement Action: Prudential Authority Sanctions Capitec for FICA Non-Compliance 

Effective date: 11 September 2026

Issued by: Prudential Authority, South African Reserve Bank (SARB)

Applies to: Banks and other accountable institutions in South Africa regulated under the Financial Intelligence Centre Act (FICA), including payment providers and merchant acquirers operating in the South African banking system.

Summary:

  • What: The Prudential Authority imposed administrative sanctions on Capitec Bank for non-compliance with the Financial Intelligence Centre Act following a 2023 inspection. 
  • Why: The inspection found weaknesses in several AML controls, including customer due diligence, enhanced and ongoing due diligence, staff training, and Capitec’s Risk Management and Compliance Programme. 
  • What's Next: Capitec has cooperated with the Prudential Authority and taken steps to address the compliance weaknesses identified. 

Key findings:

  • Capitec received five cautions and a R28 million financial penalty, with R5.5 million conditionally suspended.
  • The Prudential Authority identified gaps in how customer due diligence (CDD) was carried out on sampled client files.
  • It also identified weaknesses in enhanced and ongoing due diligence for higher-risk customers.
  • Further findings covered employee AML training and parts of Capitec’s Risk Management and Compliance Programme.
  • The action shows that firms need to be able to demonstrate that AML controls are working in practice, not just documented in policy.

What this means for merchant onboarding teams:

The Prudential Authority’s findings show that merchant onboarding controls need to work in practice, not just exist in policy. Payment providers need to make sure CDD is completed properly, higher-risk merchants receive the right level of enhanced due diligence, and onboarding decisions are supported by complete and consistent information.

The same applies after approval. Ongoing due diligence should keep merchant risk information up to date, while clear records should show what was checked, what risk was identified, and why each onboarding or review decision was made.

Recommended actions:

  • Review merchant onboarding to make sure CDD checks are completed consistently before approval.
  • Apply enhanced due diligence when a merchant is rated higher risk.
  • Keep merchant risk information up to date through ongoing due diligence after onboarding.
  • Make sure staff handling onboarding and AML reviews receive regular training on current requirements.
  • Keep a clear audit trail showing what checks were completed, what risks were identified, and how each decision was made.

How OnBoard helps

‍OnBoard helps payment providers address the control areas highlighted by the Prudential Authority, including consistent due diligence, risk-based escalation, ongoing monitoring, and auditable decision records. 

  • Smart Forms capture complete, structured merchant and beneficial ownership information upfront, helping reduce gaps in CDD records.
  • Automated KYB, KYC, and AML workflows verify merchants and related individuals and apply consistent screening checks during onboarding.
  • Real-Time Risk Scoring and the Automated Decision Engine identify higher-risk merchants and automatically route them for enhanced due diligence or additional approval.
  • Ongoing Customer Due Diligence (OCDD) keeps merchant information and risk profiles up to date after onboarding, supporting the ongoing due diligence expected for higher-risk relationships.
  • Audit-ready reporting keeps a clear record of checks, risk assessments, escalations, and decisions, helping teams show that AML controls were applied in practice. 

Source: Prudential Authority, South African Reserve Bank

‍

🇦🇺 Australia

Investigation: AUSTRAC Investigates Western Union’s Management of High-Risk Payment Activity

Effective date: Investigation announced September 1, 2026

Issued by: Australian Transaction Reports and Analysis Centre (AUSTRAC)

Applies to: Western Union Financial Services Australia Pty Ltd and The Western Union Company.

Summary

  • What: AUSTRAC launched an investigation into Western Union over concerns about how it manages high-risk payment channels, customers, and affiliates.
  • Why: AUSTRAC says international payment services face high money laundering and terrorism financing risks and expects providers to have effective controls to identify and manage those risks.
  • What’s Next: AUSTRAC will decide whether any further action is needed once the investigation is complete.

Key changes

  • The investigation will examine whether Western Union’s AML/CTF program effectively identifies, assesses, and manages money laundering and terrorism financing risk.
  • AUSTRAC will review Western Union’s transaction monitoring program, including its ability to identify known money laundering patterns.
  • The investigation will also examine governance arrangements, including the role of Western Union’s global head office in decisions affecting its Australian AML/CTF compliance.
  • AUSTRAC began the investigation after considering regulatory engagements, its own data and intelligence, and an external audit ordered in 2025.
  • The investigation is into Western Union, not its affiliates.

What This Means for Merchant Onboarding Teams

For payment providers, strong merchant onboarding is one of the first lines of defense against money laundering. Teams need to understand who the merchant is, how the business operates, how payments move, and where higher-risk relationships may exist before approval.

That risk assessment also needs to continue after onboarding through ongoing monitoring. . Changes in merchant activity, payment behavior, ownership, or other risk signals should be identified and escalated quickly. This helps payment providers reduce money laundering exposure, protect their reputation, and respond before emerging risk becomes a wider compliance issue.

Recommended actions:

  • Capture clear information about the merchant’s payment channels, business model, customer base, and relevant third-party relationships.
  • Use this information to identify higher-risk merchants during onboarding.
  • Apply additional due diligence where the merchant’s payment activity or risk profile requires it.
  • Make sure merchant risk information flows from onboarding into ongoing monitoring after approval.
  • Keep a clear audit trail of risk assessments, escalations, reviews, and final decisions.

How OnBoard helps

OnBoard helps payment providers build stronger merchant risk information at onboarding and carry that information into ongoing due diligence.

  • Smart Forms capture structured information about a merchant’s business model, payment activity, customer profile, and relevant third-party relationships from the start.
  • Automated KYB, KYC, and AML workflows verify the merchant and related individuals and apply consistent compliance checks before approval.
  • Real-Time Risk Scoring and the Automated Decision Engine bring onboarding risk signals together and route higher-risk merchants for additional review.
  • Ongoing Customer Due Diligence (OCDD) continues monitoring merchant information and risk after approval, helping teams identify changes that require further review.
  • Audit-ready reporting keeps a clear record of information collected, risk assessments, escalations, and onboarding decisions.

Source: AUSTRAC

‍

Cross-market signals for onboarding and compliance teams

September 2026 shows merchant onboarding becoming increasingly dependent on timely  risk visibility, stronger financial crime controls, and more connected decision-making across the merchant lifecycle. Across the month’s updates, regulators placed greater emphasis on whether firms can identify risk early, respond when it changes, and demonstrate that AML, sanctions, fraud, and due diligence controls are working in practice.

Several common themes emerged this month:

  • Sanctions and fraud risk do not stop at onboarding, increasing the importance of ongoing screening, OCDD, and timely escalation when merchant information or risk changes.
  • Crypto and digital asset activity require greater visibility, making payment methods, regulatory status, third-party relationships, and undeclared crypto exposure more important inputs into onboarding and risk assessment.
  • AML controls are being tested in practice, reinforcing the need for complete CDD, appropriate EDD, consistent risk assessment, and strong ongoing monitoring.
  • Real-time ongoing monitoring is becoming increasingly important, helping payment providers identify changes in ownership, business activity, payment behavior, or other risk indicators before they become wider compliance issues.
  • Frictionless onboarding still matters, but faster merchant journeys need to be supported by structured data, automated verification, and risk-based decisioning rather than weaker controls.

This month’s developments reinforce that merchant onboarding is not a one-time compliance event. Payment providers need to connect business information, ownership, payment activity, regulatory status, sanctions and AML screening, risk assessment, and ongoing monitoring so they can understand risk at approval and respond quickly when that risk changes.

OnBoard by MVSI supports this approach by bringing structured data collection, KYB and KYC verification, AML and sanctions screening, real-time risk scoring, automated decisioning, audit-ready reporting, and Ongoing Customer Due Diligence (OCDD) into one centrally governed process. This gives payment providers the connected evidence, visibility, and control needed to make trusted onboarding decisions and manage merchant risk throughout the relationship. 

‍

This content is provided for general information only and does not constitute legal or regulatory advice.

Frequently Asked Questions

No items found.
Scroll To Top Arrow