What problem does it solve?
Every merchant accepted for card payments brings risk with it. The merchant may sell something the card schemes or the law prohibit, never ship the goods, launder transactions for another business or go out of business with open refunds and chargebacks. Visa requires the acquirer, the financial institution with the direct relationship with the merchant, to run compliance checks before a merchant can accept Visa payments, and the acquirer removes merchants engaged in illegal commerce that cannot comply with Visa's rules and applicable law. Visa's Acquirer Monitoring Program, effective April 2025, also consolidates earlier fraud and dispute programs and sets fraud thresholds and enumeration criteria for acquirers and their merchants.
The traditional answer is manual. At onboarding an analyst checks the business registration, reads the website, looks up reviews and decides; after onboarding a small team works through exports of balances, refunds and chargebacks in spreadsheets. It does not scale: platforms with embedded payments sign up thousands of small merchants, keyword screening of websites produces many false alarms, and only a small sample of the portfolio is ever looked at. Coris reports that before automation only about 3% of Weave's merchants received any manual scrutiny. That leaves room for what Visa describes as merchants who fraudulently conceal the true nature of their businesses to avoid its compliance requirements.
How does it work?
- Collect the application and the footprint. The system takes the application data and enriches it with business registry records, the merchant's website, online reviews, adverse media and, where relevant, credit data.
- Understand what the merchant sells. A language model reads the website and product descriptions in context, distinguishes allowed goods from prohibited ones and checks that the declared business and merchant category match what is actually offered.
- Score and decide at onboarding. A risk score combines identity, footprint and category signals. Low risk merchants are approved automatically within policy; the rest go to an analyst with a summary of the evidence and a proposed decision, such as approve, approve with a reserve or payout delay, request documents, or decline.
- Monitor every active merchant. Models watch processing behaviour (volume spikes, refunds, chargebacks, negative balances, concentration of card numbers, changes to the website) and score each merchant daily, so analysts start with the riskiest accounts instead of a random sample.
- Act and record. Analysts decide on payout holds, reserves, outreach or offboarding, with the agent drafting the merchant message and the case note, and every decision is kept for the acquirer, the sponsor bank and the card schemes.
- Audience
- Back office
- Autonomy
- Supervised agent
- Adoption
- Early adopters
- Channels
- Internal tools, API and system to system
What is it worth?
Benchmarks are computed from the public deployments below: one data point per organization per KPI, with who made each claim.
| KPI | Median | Reported range | Data points | Claimed by |
|---|---|---|---|---|
| Alert volume reduction | Too few to pool | 70% to 89% | 2 | 2 vendor |
| Detection improvement | Too few to pool | 5x | 1 | 1 organization |
| False positive reduction | Too few to pool | 50% | 1 | 1 organization |
Value drivers: Risk and loss reduction, Employee productivity, Speed and cycle time, Compliance quality, Lower cost to serve.
Indicative value
A software platform with embedded payments onboarding 20,000 merchants a year
USD 106,667 to USD 350,000
Onboarding review effort avoided per year
How this is calculated
Formula: merchants * minutesPerReview / 60 * reviewReduction * costPerHour. The low scenario uses every low input, the high scenario every high input.
| Input | Low | High | Basis |
|---|---|---|---|
| New merchant applications per year merchants, applications per year | 20,000 | 20,000 | The reference platform. Replace with your own application volume. |
| Analyst minutes per manual review today minutesPerReview, minutes per application | 20 | 30 | Editorial assumption for web searches, registry checks and a decision. Replace with your own time study. |
| Share of manual reviews the AI removes reviewReduction, fraction of reviews | 0.4 | 0.5 | The high end matches Airwallex's early result of 50 percent fewer websites needing a manual check at onboarding. Coris reports 70% fewer manual reviews at Tekmetric and about 89% fewer daily reviews at Weave, but those vendor figures include ongoing monitoring, so they are not used as the ceiling. |
| Fully loaded risk analyst cost per hour costPerHour, USD per hour | 40 | 70 | Editorial assumption, replace with your own. |
What it leaves out: Onboarding labour only. It leaves out the fraud and credit losses prevented by catching bad merchants earlier, the effort saved in ongoing monitoring, faster activation of good merchants, fewer breaches of card scheme thresholds, and the cost of the data sources, the models and the integration.
Who already uses it?
4 public deployments, strongest evidence first. Grades: A regulator or audit, B the organization itself, C vendor case study, D anonymous or estimate.
Visa
United States · Payments and cards · 2024
Visa monitors merchant activity across its network for illegal commerce and acts through the acquirer that holds the merchant relationship; acquirers must remove merchants that cannot comply with Visa's rules and applicable law. Visa says that, using its AI tools and machine learning models, it saw a fivefold increase in acquirer remediation and terminations for merchant noncompliance between 2020 and 2024. Visa also monitors acquirers that serve high risk categories to check that their controls work.
- Detection improvement: 5x, 2020 to 2024; counts acquirer remediation and termination actions, a proxy for detection rather than a measured detection rate
"Using our AI tools and machine learning models, we have seen a 5x increase in acquirer remediation and terminations for merchant noncompliance between 2020 and 2024."
Claimed by: organization
Airwallex
Global · Payments and cards · 2023
Airwallex, a global payments and financial platform for businesses, announced in December 2023 early results from a generative AI tool it uses in its know your customer and onboarding process. The tool scans new customers' websites to check what they really sell and whether it fits Airwallex's acceptable use policies. Compared with its earlier rules based and NLP scanner, Airwallex says the model can better distinguish, for example, a retailer selling a military style jacket from a merchant selling prohibited military goods. Early results from Airwallex's internal analysis show 50 percent fewer false positives on average and 20 percent more customers passing through onboarding without human intervention.
- False positive reduction: 50%, early results, website screening in onboarding, against the earlier rules based scanner; Airwallex's footnote defines the reduction as fewer customers whose websites need a manual check for red flags
"The new tool reduces ‘false positives’ by 50 percent on average, while boosting the number of customers that pass through the onboarding process without human intervention by 20 percent [1]."
Claimed by: organization
Tekmetric
United States · Technology and software · 2025
Tekmetric, a cloud based auto repair shop management platform, offers Tekmetric Payments on Stripe Connect. It replaced underwriting and monitoring based on static credit reports, spreadsheets and manual emails with the Coris risk platform: every active merchant is scored daily, each alert gets an AI generated recommendation and summary, and onboarding approvals and dispute reminders are sent to merchants automatically. Coris reports 70% fewer manual reviews and faster onboarding.
- Alert volume reduction: 70%, manual merchant risk reviews after go live
"Discover how Tekmetric reduced manual risk reviews by 70% and accelerated onboarding with Coris’ AI-driven workflows and real-time monitoring."
Claimed by: vendor
Weave Communications
United States · Technology and software · 2025
Weave, a customer experience and payments software company for dental, optometry, veterinary and other local healthcare practices, runs Weave Payments mainly on Stripe Connect. It replaced manual merchant reviews from spreadsheet exports with the Coris risk platform, which scores merchants and transactions, ranks an alert queue by risk and triggers workflows such as payout pauses and outreach. Coris reports that daily reviews fell from about 80 to 9 or 10 accounts, and that automated checks now cover nearly all merchants with meaningful volume, against about 3% of merchants reviewed manually before.
- Alert volume reduction: about 89%, daily merchant reviews, within a week of switching primary triage to Coris
"AI triage cut daily reviews by ~89% (from ~80/day to ~9–10/day), so analysts spend time where judgment matters most."
Claimed by: vendor
How do you implement it?
A model agnostic playbook: what to prepare, the order to build in, and what goes wrong.
Data you need
- A written risk appetite with prohibited and restricted categories and the action per risk level
- Historical merchant applications with outcomes (approved, declined, later terminated, losses)
- Processing data per merchant (volumes, refunds, chargebacks, balances, payouts)
- Access to business registry, credit and adverse media data sources
Systems to integrate
- Onboarding or application system
- Payment processor or acquirer APIs and dashboards (for example connected account data)
- Payout and reserve controls
- Case management or CRM for analyst reviews and merchant outreach
- Messaging or ticketing tool for merchant communication
Complexity: Medium
Scoring and website review can start on application data and public sources with little integration. The harder part is ongoing monitoring, which needs processing data from every acquirer or processor the platform uses, and a clear risk policy that says which score leads to which action.
- 1
Write the policy before the model
Agree the prohibited and restricted categories, the risk levels and the action for each (approve, reserve, delay payouts, request documents, decline) with the sponsor bank or acquirer. The AI applies the policy; it does not invent it.
- 2
Start with website and category screening
Let the model read the merchant's website and product descriptions and compare them with the declared business. Keyword rules on websites produce many false alarms, and Airwallex reports that its generative AI website scanner halved them in early results.
- 3
Run in parallel before you switch
Score new applications and the existing portfolio alongside the current manual process for a few weeks, compare decisions and losses, and tune thresholds before the AI queue becomes the primary one.
- 4
Extend to the whole portfolio
Monitor every active merchant daily, not a sample, and rank the queue by risk so analysts start with the top decile. Add automated actions such as payout holds only for clear, high confidence signals, with an analyst review the same day.
- 5
Feed outcomes back
Label every decision with its outcome (losses, chargebacks, terminations) and use the labels to retrain and to prune rules that only add noise.
Guardrails
- Declines, terminations and reserves above a set level always need an analyst decision
- Every score comes with the evidence behind it, so the analyst and the merchant can be told why
- Website and document content is treated as data, never as instructions to the model
- Sole traders' personal data is limited to what the risk policy needs, and masked in prompts and logs
- Regular checks that approval and decline rates do not differ unfairly between comparable merchant groups
KPIs to instrument
- Share of applications approved automatically and time from application to approval
- Manual reviews per week and share of reviews that lead to an action
- False positive rate of website and category screening
- Losses from merchants terminated for fraud or credit, per 1,000 merchants onboarded
- Chargeback and fraud ratios against the card scheme thresholds
Human in the loop
Analysts decide every decline, termination and material reserve or payout hold, and review a sample of automatic approvals each week. The risk policy owner approves every change to categories, thresholds or automated actions, and the sponsor bank or acquirer can audit the decisions.
Common failure modes
- Fraudsters who look good on paper
- Generated websites, fake reviews and borrowed business identities pass a one time check. Keep monitoring after onboarding and watch for website and behaviour changes.
- Automatic declines of good small businesses
- Thin footprints and unusual categories push legitimate merchants into declines. Route uncertain cases to an analyst and track appeals.
- Rules and models that fight each other
- Rules added on top of the score without review double the alert volume. Review the combined queue and remove rules that do not change decisions.
- A queue that nobody trusts
- Analysts ignore scores they cannot explain. Show the drivers and the evidence with every score.
What are the risks and rules?
EU AI Act
Depends on design
Assessing businesses and detecting fraud is not an Annex III use as such, and Annex III point 5(b) excludes systems used to detect financial fraud. If the system evaluates the creditworthiness of a natural person, for example a sole trader applying to accept payments, it can fall under Annex III point 5(b), which covers evaluating the creditworthiness of natural persons or establishing their credit score, and be high risk. Keep credit assessment of individuals separate or treat it as a high risk system.
Rules that apply
Guidance
- Introducing the Visa Acquirer Monitoring Program (Visa, Global). Visa's acquirer program, effective April 2025, consolidates earlier fraud and dispute programs and sets fraud thresholds and enumeration criteria for acquirers and their merchants.
- Visa Network Integrity (Visa, Global). Describes how Visa monitors acquirers in high risk categories and how acquirers must remove merchants engaged in illegal commerce.
Controls to put in place
- Documented risk policy with prohibited categories, thresholds and approved automated actions
- Model inventory entry, validation and drift monitoring for the scoring models
- Audit trail of every score, the evidence shown and the decision taken, per merchant
- Periodic fairness and outcome review of approvals, declines and terminations
- Oversight by the sponsor bank or acquirer, including access to decisions and samples
Frequently asked questions
- What does generative AI add to merchant underwriting?
- Reading websites and documents in context. Airwallex says its generative AI website scanner can better distinguish a retailer selling a military style jacket from a merchant selling prohibited military goods, and that early results from its own internal analysis show 50 percent fewer false positives on average than its earlier rules based model.
- Is monitoring after onboarding really needed?
- Yes. A check at signup only sees what the merchant chooses to show, and Visa says some merchants conceal the true nature of their businesses to avoid compliance requirements. Coris reports that Weave went from manual scrutiny of about 3% of merchants to automated checks across nearly all merchants with meaningful volume, while cutting daily reviews by about 89%. Visa says that, using its AI tools and machine learning models, it saw a fivefold increase in acquirer remediation and terminations for merchant noncompliance between 2020 and 2024.
- Can the AI decline merchants on its own?
- It should not decline or terminate on its own. Let it approve clear low risk cases within policy and send everything else, with the evidence, to an analyst. If the assessment covers the creditworthiness of a sole trader, check whether it is high risk under the EU AI Act.
How to cite this page
Blits.ai AI Use Case Library, "AI for merchant underwriting and risk monitoring", last verified 27 September 2026, https://www.blits.ai/ai-use-cases/merchant-underwriting-and-risk-monitoring. Licensed under CC BY 4.0. Method: how we verify use cases.
Changelog
- 27 September 2026: First published