Payment service providers are essential to digital commerce. They become a financial-crime, operational or consumer-protection risk when rapid payment flows, outsourced functions and complex merchant networks are not matched by effective controls. The right question is not whether PSPs are inherently “part of the problem,” but which provider performs each function, what risks it creates and who remains accountable.
Map the payment chain before assessing risk
Identify the merchant, gateway, acquirer, payment institution or e‑money institution, card scheme, settlement bank, agents, distributors and technical subcontractors. Record which entity onboards the customer, holds funds, screens transactions, handles chargebacks and reports suspicious activity. A licence held by one company does not automatically cover every affiliate, brand or service.
| Risk area | Evidence to examine |
|---|---|
| Authorisation | Official register entry, legal entity, permissions, territories and appointed agents |
| Merchant risk | Business model, ownership, websites, products, jurisdictions and complaint history |
| Money movement | Settlement accounts, pooled funds, reserves, refunds, chargebacks and counterparties |
| Outsourcing | Contracts, audit rights, incident reporting, data location and exit arrangements |
Why payment firms can carry elevated financial-crime risk
Speed, high transaction volumes, occasional customers, remote onboarding, cross-border corridors and agent networks can make payment services attractive for layering or fraud. The European Banking Authority’s sector assessment found that money-laundering and terrorist-financing risks were not always managed effectively, while stressing that exposure differs by business model.
Effective controls connect verified customer and beneficial-owner data to merchant monitoring, sanctions screening, transaction behaviour and investigation outcomes. Trider’s transaction-pattern workflow explains why an alert is a prompt for documented review rather than proof of wrongdoing.
Test onboarding and ongoing merchant monitoring
Verify the merchant’s legal entity, controllers, domains, products, target markets, expected volumes and source of funds. Then check whether live activity still matches that profile. Warning signs include undisclosed high-risk products, sudden volume spikes, excessive refunds, repeated descriptor changes, payments routed through unrelated entities and activity from prohibited markets.
For gambling clients, responsibility can be fragmented between operator, platform and payment companies. Mapping those roles is also central to investigating white-label gambling operations and higher-risk financial relationships.
Safeguarding is different from deposit protection
Where a payment or e‑money firm holds customer funds, confirm the applicable safeguarding regime, reconciliation process, account designations, third-party bank due diligence and wind-down plan. In the UK, the FCA’s current safeguarding guidance requires relevant firms to protect customer funds through prescribed arrangements. The FCA also explains that funds at a non-bank PSP are generally not protected by the Financial Services Compensation Scheme in the same way as bank deposits.
Investigate incidents with evidence, not provider labels
For a frozen settlement, missing funds or suspicious merchant, preserve transaction files, API logs, settlement reports, communications and rule versions. Reconcile gross receipts through fees, reserves, refunds and transfers to the final bank account. Separate a technical outage, contractual reserve, compliance hold, safeguarding shortfall and suspected criminal flow: each requires different evidence and remedies.
A Malta Business Report discussion of governance, transparency and investor confidence offers useful cross-sector context. It is not PSP-specific regulatory guidance, so authorisation, safeguarding and AML conclusions should remain anchored in official registers, applicable law and primary supervisory material.
Govern the provider relationship throughout its life
Contracts should define service scope, liability, audit access, sub-outsourcing, data protection, incident deadlines, reserves, termination and data return. Monitor outages, unresolved complaints, chargebacks, alert quality, reconciliation breaks and concentration exposure. Maintain a tested exit plan or alternative route where interruption would materially harm customers or the business.