Why third-party payment processor relationships remain one of the harder due diligence problems in transaction banking
A bank can run flawless know your customer checks on every account it opens and still have no idea whose money is actually moving through a meaningful share of its payment volume. This is not a hypothetical gap. It is a structural feature of how third-party payment processors operate, and it has been sitting in plain sight in AML guidance for well over a decade without a fully satisfying fix.
A third-party payment processor, generally abbreviated TPPP, contracts with issuing and acquiring banks to provide payment processing services to merchants and other businesses. Historically, TPPPs helped retailers with physical locations collect payments from customers, primarily through credit card transactions, ACH debits, and remotely created checks. As internet commerce expanded, TPPPs began serving a much wider range of merchants, including online retailers, prepaid travel businesses, and internet gaming operators, many of which never have a direct banking relationship with the institution actually processing their funds.
That last point is the regulatory problem in a single sentence. The bank's contractual and account relationship is with the TPPP. The bank's actual exposure, in terms of whose transactions are flowing through its systems, is with the TPPP's merchant clients, businesses the bank has typically never onboarded, screened, or even identified individually.
What the regulatory position actually is
It is worth being precise here, because this is an area where the line between legal requirement and prudent practice gets blurred often. TPPPs themselves are frequently not directly subject to AML and counter terrorist financing requirements in the way a bank or a registered money services business is. The obligation sits instead with the bank maintaining the TPPP relationship. Under a typical bank secrecy and AML statutory framework, a bank is required to apply customer due diligence to its actual customer, and where that customer is a TPPP rather than the underlying merchant, the bank's due diligence has to reach further to be meaningful. This is not a separate TPPP specific statute. It is the ordinary CDD and enhanced due diligence obligation, applied to a customer type that happens to obscure a second layer of parties behind it.
This distinction matters practically. A bank cannot discharge its obligations by treating the TPPP itself as a low risk customer simply because the TPPP is, on paper, a payment processing company rather than an operating business with its own transaction risk. Guidance in this area consistently frames TPPPs as a customer category requiring heightened scrutiny specifically because of what sits behind them, not because of what the TPPP itself does on the surface.
Why the risk concentrates here
Several factors compound the visibility problem. A TPPP might maintain banking relationships at multiple institutions simultaneously, which is sometimes a genuine business efficiency and sometimes a deliberate structure used by TPPPs engaged in suspicious activity specifically to prevent any single bank from seeing enough of the total picture to recognize a pattern. When a TPPP spreads volume across several banks, each individual institution sees only a fraction of the activity, and the aggregation that would reveal a problem never happens anywhere.
The merchant categories a TPPP serves also shift the risk profile considerably. TPPPs providing services to telemarketing operations, online and physical gambling businesses, and various internet based merchants carry a higher exposure to consumer fraud and money laundering than a TPPP serving conventional brick and mortar retail. This is not a statement about telemarketing or online gambling being inherently criminal enterprises. It is a recognition that these sectors have historically generated disproportionate volumes of unauthorized transactions and consumer complaints, which is itself a measurable indicator worth monitoring.
That measurable indicator is return rates. TPPPs involved in suspicious activity often show elevated return rates tied to unauthorized transactions. The complication is where that elevation becomes visible. At the level of an individual merchant, return rates might look acceptable when measured against the TPPP's total transaction volume. It is only when a bank compares an individual originator's return rate against the broader pattern that the anomaly becomes apparent, which requires a level of transaction level analysis many banks are not structured to perform on TPPP relationships specifically.
What changed, and why banks cannot treat this as a solved problem
Nothing about this risk is new. What has changed is scale. As TPPPs have expanded from serving physical retailers to serving a global mix of online merchants, the volume of transactions flowing through a single processing relationship has grown well past what manual review can meaningfully cover. A bank monitoring a TPPP relationship is, in practice, monitoring an aggregated stream representing dozens or hundreds of underlying businesses, most of which it will never directly identify unless something specific triggers a deeper look.
This creates a genuine tension for compliance teams. Rejecting all TPPP relationships outright removes a legitimate and, for many merchants, necessary payment channel, and it is not what regulatory guidance in this space asks for. The guidance instead points toward risk based differentiation: understanding what categories of merchants a given TPPP serves, requiring transparency into that merchant base to the extent reasonably obtainable, and applying transaction monitoring calibrated to the elevated risk categories rather than treating every TPPP relationship identically.
It is also worth being honest about what credit card and TPPP related laundering typically looks like in practice, because it rarely resembles the placement stage most AML training focuses on first. The Government Accountability Office, a national congressional watchdog body, has noted that the extent of money laundering conducted through credit cards is itself difficult to measure precisely, and the mechanisms that do surface tend to sit in the layering and integration stages rather than placement, since the card industry generally restricts cash payments at the point of use. A launderer who has already placed funds into the banking system might prepay a credit card balance, request a refund to create a seemingly legitimate credit transaction, and then use the combination of the original deposit and the refund to fund an ordinary purchase, obscuring the original source of funds through what looks, transaction by transaction, like routine account activity.
How guidance in this area has evolved
Regulatory attention to TPPP relationships intensified notably after a wave of enforcement actions in the early 2010s in which banks were found to have processed payments for unlicensed online lenders, telemarketing fraud operations, and other high risk merchants entirely through a TPPP intermediary, with the bank itself having no direct visibility into the underlying merchant conduct. That period produced guidance emphasizing that a bank's obligation to know its customer does not diminish simply because the customer happens to be a processor rather than an operating merchant. If anything, the guidance framed the intermediary structure as a reason for heightened diligence, not reduced diligence, precisely because the structure itself creates the visibility gap.
This has practical consequences for how a compliance function should be organized around TPPP relationships. A bank that treats TPPP due diligence as a onetime onboarding exercise, verifying the processor's own licensing and financial standing, without building an ongoing mechanism to understand the merchant portfolio behind it, has satisfied a formal requirement without addressing the underlying risk the requirement exists to manage.
Comparing stronger and weaker TPPP oversight programs
A stronger oversight program typically requires the TPPP to provide a categorized breakdown of its merchant portfolio by industry type, with particular attention to categories associated with elevated fraud and money laundering risk, and requires that breakdown to be refreshed periodically rather than accepted once at onboarding and never revisited. It also includes transaction monitoring rules specifically calibrated to detect the return rate anomalies and volume patterns associated with TPPP abuse, rather than relying on the same generic monitoring scenarios applied to conventional commercial accounts. And it includes a contractual right, actually exercised when warranted, to request underlying merchant information when a specific transaction or pattern raises concern, rather than treating the TPPP relationship as an impenetrable layer the bank has no ability to look behind.
A weaker program, by contrast, tends to treat the TPPP itself as the full extent of the customer relationship, applying standard commercial account monitoring without adjustment for the aggregation risk described above, and lacking any contractual mechanism to obtain merchant level detail even when a transaction pattern suggests it is needed. The distinction between these two approaches rarely shows up in whether a bank technically has a TPPP policy. It shows up in whether that policy actually produces visibility when visibility is required.
What this means in practice for compliance teams
A bank maintaining a TPPP relationship needs due diligence that goes beyond verifying the TPPP entity itself. It needs visibility, to whatever extent contractually and practically achievable, into the merchant categories the TPPP serves, the geographic distribution of that merchant base, and whether the TPPP maintains parallel relationships at other institutions that could be splitting volume to avoid detection. It also needs monitoring calibrated specifically to the risk categories most associated with TPPP abuse, telemarketing, online gambling, and high volume internet commerce, with particular attention to return rate patterns measured at the individual originator level rather than only at the aggregate TPPP level.
None of this requires treating TPPPs as inherently suspicious. The overwhelming majority of payment processing relationships exist to serve legitimate merchants who genuinely benefit from not having to maintain direct banking relationships for every transaction they process. The risk is not the TPPP model itself. It is the specific structural blind spot the model creates, and that blind spot does not close on its own simply because a bank has completed standard onboarding on the processor sitting in front of it.
For a compliance officer reviewing this relationship category, the useful question is rarely whether to maintain TPPP relationships at all. It is whether the institution's due diligence actually reaches past the processor to the merchant activity generating the risk, or whether it stops at the first layer because that is where the paperwork happened to end.
Disclaimer: Content posted is for informational and knowledge sharing purposes only, and is not intended to be a substitute for professional advice related to tax, finance or accounting. The view/interpretation of the publisher is based on the available Law, guidelines and information. Each reader should take due professional care before you act after reading the contents of that article/post. No warranty whatsoever is made that any of the articles are accurate and is not intended to provide, and should not be relied on for tax or accounting advice.Contributor
Related Posts

UAE, 21 August, 2026: The UAE Federal Tax Authority (FTA) has introduced a new Advance Pricing ...
Read More
In May 2019, a federal court sentenced John D. Leontaritis to twenty years in prison. The case again...
Read More
Strong controls exist across the diamond trade. The real compliance question is whether every partic...
Read More