Payments shift from one-time checks to continuous oversight
Payments firms are replacing one-time merchant checks with continuous monitoring after rises in AI-enabled fraud, synthetic identities and transaction laundering; networks and regulators place liability on acquirers.
Payments firms and sponsor banks are moving away from single-point merchant verification toward continuous oversight after increases in AI-enabled fraud, synthetic identities and transaction laundering. Card networks now require ongoing monitoring, and regulatory and network accountability is focused on acquirers and sponsor banks even when onboarding is handled by third parties.
Previously, many payments companies relied on upfront identity and business checks and then on transaction monitoring to surface problems. That process is failing as criminal groups create misrepresented or non-existent businesses at scale, open merchant accounts with synthetic identities, and present convincing storefronts and content that pass traditional checks.
Advances in AI allow rapid generation of product pages, images, video testimonials and reviews that can hide fraudulent intent. Deepfake technology has been used in high-confidence frauds, including an early-2024 case in which a finance employee was induced to transfer $25 million after interacting with a fabricated video of colleagues. Credit agencies report a sustained increase in synthetic identities in financial applications, and the average charged-off loss per known synthetic identity is about $13,000.
Card networks are consolidating monitoring expectations into formal programs. Visa’s Acquirer Monitoring Program combines fraud and dispute metrics with continuous thresholds and remediation requirements. Networks set standards across the ecosystem, but operational and legal responsibility for enforcement and remediation continues to sit with acquirers and sponsor banks. Regulators and networks are asking which entity managed a portfolio over time, not only who approved an account at onboarding.
Firms are adjusting oversight to treat approval as the start of a relationship. Lifecycle oversight models continuously assess identity, transaction patterns, product mixes and content to detect merchant drift. Human review is used for escalations and enforcement. Decisions and the evidence behind them must be recorded so they remain auditable months after approval.
Some companies are adopting provisional approvals that allow processing under limits after initial automated checks while further vetting continues. These models apply risk controls such as reserves, delayed funding and increased monitoring within structured limits, and they include clear review and termination procedures to prevent provisional access from becoming permanent.
Privacy and data rules shape how continuous monitoring is designed. Data minimization and retention limits restrict how much identity information can be collected and how long it can be kept. Regulators focus on why data is collected, how it is secured and how long it is retained. Monitoring systems that rely on transient, lower-retention signals can operate within those constraints.
Payments firms must be able to produce documented evidence showing why a merchant was accepted, what was monitored afterward, what changed, and when remediation actions were taken. Networks and sponsor banks request that evidence when elevated fraud or dispute rates occur. Continuous oversight programs are being implemented to meet those monitoring and documentation requirements.








