XPndAI builds bespoke high-risk merchant compliance software for acquiring banks, PSPs, payment orchestrators, and ISOs managing high-risk merchant portfolios — adult, gambling, crypto, nutraceuticals, travel, subscriptions. KYB onboarding, merchant risk scoring, transaction monitoring, chargeback velocity alerts, Visa/Mastercard BRAM programme compliance, investigation workflow, and evidence for card scheme audits — in one platform. Source code ownership. From $70,000.
High-risk merchant onboarding must be more rigorous than standard merchant onboarding. XPndAI builds a structured KYB onboarding workflow: entity verification (company registration certificate, certificate of incorporation, articles of association — automated company registry API check where available; manual for jurisdictions without APIs), Ultimate Beneficial Owner (UBO) identification and verification (identify all UBOs above 25% ownership threshold; government ID + proof of address for each UBO; PEP and sanctions screening against World-Check/ComplyAdvantage; adverse media search), business model review (what products/services is the merchant selling? is the business model consistent with their stated MCC? is the website live and operating lawfully?), licence verification (gambling operator — verified against UKGC/MGA/applicable registry; adult platform — verify applicable age verification compliance declarations; cannabis — state licence verified; crypto exchange — FCA/applicable registration verified), bank account verification (business bank account in entity name — open banking verification or micro-deposit), and risk scoring (composite merchant risk score from entity type, jurisdiction, business model, UBO profiles, industry risk — determines monitoring intensity tier).
Ongoing transaction monitoring is the primary BRAM compliance requirement. XPndAI builds merchant-level transaction monitoring: chargeback ratio monitoring (real-time calculation of chargeback ratio per MID — alert when approaching Visa/Mastercard programme thresholds: Visa 0.9% early warning, 1.0% standard monitoring, 1.5% excessive; Mastercard 1.5% excessive chargeback programme), refund velocity monitoring (unusually high refund rate may indicate customer dissatisfaction, product non-delivery, or potential fraud), fraud ratio monitoring (fraud-to-sales ratio per MID — Visa 0.65% early warning threshold), transaction velocity anomalies (sudden volume spike — could indicate card testing, fraud scheme, or undisclosed new product launch), average ticket size deviation (significant shift from established average ticket — could indicate product change or card testing), geographic anomaly (transactions suddenly concentrating from unusual countries — potential fraud or programme violation), and settlement pattern anomaly (unusual settlement requests, multiple settlement bank changes — potential fund flight risk).
Both Visa and Mastercard operate programmes that place acquirers on notice when merchants in their portfolio breach thresholds — and fine acquirers when those merchants are not remediated. XPndAI builds BRAM-specific compliance management: Visa Chargeback Monitoring Programme (VCMP) and Visa Fraud Monitoring Programme (VFMP) tracking — alert when a merchant crosses programme thresholds, track programme status (standard/excessive/high-excessive), and manage within-programme remediation timeline; Mastercard Excessive Chargeback Programme (ECP) tracking — similar threshold monitoring and timeline management; programme notification management (when Visa/Mastercard places a merchant in a programme, XPndAI logs the notification, triggers the remediation workflow, and tracks the 12-month programme timeline); acquirer fines accumulation tracking (BRAM programmes impose monthly fines on the acquirer while a merchant is in programme — XPndAI tracks accumulated fines per merchant to support termination decision-making); and BRAM audit evidence package (structured evidence of monitoring activities, remediation actions taken, and merchant communications — required when card scheme compliance teams conduct acquirer programme reviews).
When monitoring triggers an alert, a structured investigation determines whether to remediate or terminate. XPndAI builds a merchant investigation workflow: alert triage (automated classification of alert severity — low/medium/high/immediate — based on threshold proximity, trend direction, and merchant risk tier), case creation (alert → case with full merchant context: transaction history, prior alerts, KYB documents, communication history, prior remediation actions), investigation actions (merchant contact — request explanation for chargeback spike / unusual pattern; additional KYB — if business model appears to have changed; site review — is the website still operating lawfully?; chargeback dispute — are the chargebacks being fought where legitimate?), remediation options (merchant education and corrective action plan; MID restriction — limit processing volume or specific product categories; rolling reserve increase; partial termination — close specific MIDs; full merchant termination), decision documentation (risk officer decision recorded with justification — required for acquirer risk management audit trail and potential card scheme enquiry), and termination workflow (MATCH/VMAS reporting — Visa/Mastercard require acquirers to report terminated merchants to industry databases; XPndAI manages this filing).
High-risk merchants frequently change their business model, add new products, or begin operating in breach of their merchant agreement without notifying their acquirer — which creates programme and compliance risk for the acquirer. XPndAI builds continuous merchant monitoring: automated website monitoring (periodic review of merchant's active URL — has the site changed significantly? new products? new jurisdictions? compliance claims still present?), descriptor monitoring (is the merchant's billing descriptor consistent with their approved business model? misleading descriptors drive chargeback spikes), product category change detection (merchant approved for Category A adds Category B — undisclosed business model change triggers re-underwriting), brand new MCC application (merchant requests new MCC for new product line — triggers KYB review of the new line), and adverse media monitoring (news alerts for merchant entity name — criminal charges, regulatory action, consumer complaints). Automated monitoring reduces the manual review burden while ensuring continuous surveillance of the merchant portfolio.
Acquirers must be able to demonstrate to Visa, Mastercard, and banking regulators that their merchant risk management programme functions as documented. XPndAI builds the portfolio intelligence and evidence layer: portfolio risk dashboard (real-time view — how many merchants at each risk tier, how many in programme, fines accumulating, trending towards threshold), monthly risk management report (for risk committee — MID count by risk tier, programme notifications received, remediation actions taken, terminations, fines paid — structured for board risk reporting), card scheme audit evidence package (when Visa/Mastercard compliance team conducts an acquirer review — structured evidence of KYB onboarding standards, ongoing monitoring activities, investigation records, remediation actions, MATCH/VMAS filings; formatted to address the acquirer's BRAM programme audit framework), regulatory evidence (for banking regulator examination — acquirer's merchant risk management framework demonstrated through systematic monitoring and documented decision-making), and merchant portfolio analytics (which industry verticals have highest chargeback rates? which geographies? which business model types? — drives underwriting criteria refinement).
XPndAI's merchant compliance OS is built around the specific programme requirements of both major card schemes: Visa: (1) Visa Chargeback Monitoring Programme (VCMP) — merchants above 0.9% (early warning) or 1.0% (standard) or 1.5% (excessive) chargeback ratio placed into programme; acquirer receives monthly fine notifications; 12-month programme; XPndAI tracks each merchant's chargeback ratio in real-time and triggers alerts as thresholds approach, logs programme entry, manages remediation timeline, tracks accumulated fines; (2) Visa Fraud Monitoring Programme (VFMP) — merchants above 0.65% fraud ratio; similar tracking and remediation workflow; (3) Visa Acquirer Monitoring Programme (VAMP) — new 2025 Visa programme that assesses acquirers at portfolio level, not just individual MIDs; XPndAI builds portfolio-level fraud and dispute metrics for VAMP compliance. Mastercard: (1) Excessive Chargeback Programme (ECP) — 1.5% chargeback ratio threshold; (2) Excessive Fraud Merchant Programme (EFM) — fraud ratio thresholds; (3) MATCH programme — Mastercard Alert To Control High-Risk Merchants list; XPndAI manages MATCH filing for terminated merchants. Both schemes: acquirer programme review — Visa and Mastercard periodically review acquirer risk management programmes; XPndAI generates the evidence package for these reviews. All programme definitions and thresholds follow the card scheme rules as of the most recent rule publication; schemes update rules periodically and the system is updated accordingly.
MATCH (Mastercard Alert To Control High-Risk Merchants) and Visa's equivalent (VMAS — Visa Merchant Alert Service) are industry shared databases of merchants terminated by acquirers for cause. Acquirers are required to report merchants terminated for specific reasons (fraud, excessive chargebacks, illegal activity) to these databases, and required to check new merchant applications against these databases. XPndAI builds the MATCH/VMAS compliance workflow: (1) Onboarding check — new merchant application triggers an automated MATCH query for all business principals; a MATCH hit triggers enhanced due diligence and risk officer review before approval; MATCH hit is not automatically disqualifying but must be investigated and documented; (2) Termination filing — when a merchant is terminated for a MATCH-reportable reason (reason codes defined by Mastercard — fraud, excessive chargebacks, merchant collude, illegal transaction, etc.), XPndAI generates a structured termination record; the risk officer reviews and approves the MATCH filing; XPndAI submits the filing (via Mastercard Connect or the acquirer's processor's API) and records the submission date, confirmation, and reported reason code; (3) Audit trail — both onboarding MATCH checks and termination filings are maintained in the merchant case file — evidence of compliance with MATCH reporting obligations for card scheme audits. Note: MATCH filing is a compliance obligation; incorrect filings (wrong merchant, wrong reason code) create legal liability — all filings reviewed and approved by the acquirer's risk officer before submission.
Tell us your company type (acquiring bank/PSP/ISO), high-risk merchant count, primary risk categories, and current compliance gap (BRAM programme notification, card scheme audit preparation, new high-risk vertical entry). We scope and demo within 5 business days.
XPndAI · High-Risk Merchant Compliance OS · Visa/Mastercard BRAM Compliance · Acquiring Banks · PSPs · ISOs · Source Code Ownership · From $70,000 · +91-9625368140