There are certain industries that payment processors keep a close eye on. Categories like GLP-1 telehealth, nutraceuticals and supplements, CBD, high-dispute subscription boxes, adult products, travel, and gambling-adjacent businesses are all on that list right now.Â
If you’re a fast-growing business that sells products in any of those categories, you can get the same review notice, reserve requirement, or closure letter as its neighbors, in the same week, for the same reason.
Even if you have a spotless dispute record, processors re-underwrite whole categories at once, and any merchant caught inside one rides the wave with the rest regardless of its own conduct.
This article outlines what sets off these reviews, what they cost in cash and time, and the two fixes that keep an operator ahead of the next wave instead of scrambling through it.
What does it mean for a merchant to get "de-risked"?
Getting de-risked means a payment processor restricts, delays, or ends its relationship with a merchant, through an account review, a new reserve requirement, or closure. Usually the processor is re-underwriting an entire category, and your account gets caught in that wave.
A clean compliance record doesn't guarantee protection. Growing quickly inside a category that processors are watching can put you on their radar on its own, because growth itself is one of the signals they track when they reassess a category.
There's a difference between a merchant-specific fraud finding and a category-wide re-underwriting, and you’ll need a different approach to address each of them.Â
A fraud finding calls for a fix to your own controls: tighter fraud-screening rules, updated KYC checks, or a revised dispute-response process, whatever actually went wrong.Â
A category-wide re-underwriting calls for something more durable: a card vault you own and backup gateways you've already tested, so the next wave doesn't force an emergency migration no matter what triggers it.
Why does de-risking keep recurring?
De-risking is a category-wide phenomenon. Payment processors regularly conduct re-underwriting across entire industry verticals driven by network rule updates, portfolio-wide losses, or high-profile failures of competitors within the sector. When this occurs, every merchant in that vertical is affected, regardless of their individual account performance or spotless processing history.
Underwriting is the risk review a processor runs on a merchant, weighing its business model, transaction volume, and dispute history to decide whether to approve the account and on what terms. It isn't a one-time check at signup. Processors repeat it on a rolling basis, often at the level of an entire category, and a category-wide result re-rates every merchant in it at once.
Risk categorization moves in waves
Visa folded five separate fraud and dispute programs into one portfolio-level framework, VAMP, in April 2025, then cut the "excessive" threshold from 2.2% to 1.5% in April 2026 across most regions in a single move. Every merchant in scope was re-rated at once, whether its own dispute rate had changed or not.
Elevated dispute rates keep a category on the list
Mastercard's Scam Merchant Monitoring program, enforceable globally from July 24, 2026, is a second network-level system that can trigger action on category signals rather than individual conduct. Its existence tells processors which verticals to watch more closely before they even open an individual account review.
Regulatory attention shifts risk appetite for everyone at once
The FTC's Click-to-Cancel rule reshaped how processors underwrite negative-option and subscription billing broadly, independent of any one merchant's conduct. A processor doesn't wait for a specific complaint before adjusting its appetite for an entire billing model.
Single-processor dependency turns one decision into a single point of failure
One underwriting call can freeze an entire revenue stream overnight. If you’re running all your volume through one acquirer, you end up with no fallback the day that acquirer decides the category isn't worth the exposure.
These factors operate autonomously from one another. You might fully satisfy a card network's monitoring guidelines yet still face disruption from regulatory intervention. Even with clean compliance across networks and regulators, your business is still vulnerable to losing its account if its sole processor chooses to withdraw from that market segment entirely.
What does de-risking cost your business?
The actual overhead of de-risking often exceeds initial projections. Revenue streams stall during account reviews, sudden reserve mandates lock up essential liquidity, and abrupt closures can sever the connection to your subscriber base before a transition is even possible. A few things you might experience:Â
- Frozen or delayed payouts during the review period.
- New reserve requirements set with little warning.
- Short-notice account closure.
- Inability to recharge existing subscribers if closure happens before a migration completes.
If you’re processing $1 million a month and get hit with a 10% rolling reserve held for 180 days that means $300,000 to $600,000 in continuous capital locked up. That money isn't available for growth, inventory, or marketing.
Reserves can escalate further once a relationship actually ends. Acquirers commonly raise holdings to 20% or even 100% of pending funds, held for a minimum of 180 days, when a processor exits mid-settlement. That protects the acquirer against chargebacks that surface after the account is already closed.
The ceiling case is the final boss of unexpected revenue loss. An account termination severe enough to land a merchant and its principals on Mastercard's MATCH list can block mainstream processing access for up to five years. A single harmful account action can restrict your choice of payment processors for years.
What are the businesses handling this well doing differently?
There’s a simple, two-pronged approach to managing de-risking well. And they’re not anything that a business who sells goods and services online shouldn’t be doing anyway, so taking these steps is the right move at any stage of the game.Â
Step 1: Own your tokenized card data.Â
Standard processor-issued tokens belong to that processor. If you decide to switch providers, or get cut off, without a portability plan you have to ask every customer to re-enter their card manually. The result? A potential subscription churn of 15% to 30% overnight.
Network tokens, issued directly by Visa and Mastercard rather than a processor, add a second advantage. They update automatically when a card is lost, stolen, or reissued. This can mean a potential 4.6% lift in approval rates and up to a 28% reduction in fraud, on top of the portability benefit.
Vault independence is standard payment-orchestration hygiene, the same logic as running more than one cloud region. It's infrastructure you build once to keep you running against a whole range of negative outcomes.
Step 2: Maintain tested, redundant backup gatewaysÂ
Run two or three backup gateways, configured and actually carrying production volume before they're needed. A gateway that hasn’t processed a live transaction isn't a real backup. It's an unverified assumption sitting in a contract and probably more of a vulnerability as a result.Â
An orchestration layer sitting between checkout and the processors can catch a soft decline, a temporary, retriable failure like a timeout or a temporary hold. Smart routing can retry the transaction through a backup processor and the customer is never the wiser.Â
A hard decline, like a stolen card or a closed account, should be left alone rather than retried, to protect your standing with the networks rather than manufacture a false recovery.
Real testing means simulating outages in staging first. An executed agreement with a secondary payment processor lacks material value on its own. A cascading architecture that’s unverified in a production environment inevitably reveals its vulnerabilities during an initial operational transition, at the exact moment when it’s supposed to be sustaining your live transaction volume.
Now you're moving your time, effort, and money away from crisis response to the infrastructure you should have in the first place. You end up with a fixed, planned cost instead of an emergency migration with a 30-day notice.Â
And if you’re treating vault portability and gateway redundancy as a standing line item, it’s going to cost a fraction of what a rushed migration is going to ding you in engineering hours, lost transactions, and customer re-entry churn during an actual closure.
Here’s what to do right now
Separate your card data from any single processor's vault. Get a second and third gateway live and tested in production. A signed contract alone isn't enough. Make sure your billing logic can trigger charges against a stored token on your own schedule, independent of any processor's calendar.
Watch your reserve terms and your gateway failover rate now, before a review notice forces the question. And you should read our token migration playbook to learn how to move off a processor without losing the ability to bill your own customers.
Can a merchant with a clean dispute record still get de-risked?
Yes. Processors re-underwrite whole verticals at once, driven by network rule changes, portfolio losses, or a competitor's public failure. Your individual account performance isn't the input. Fast growth inside a watched category can put you on the radar by itself, because growth is one of the signals processors track when they reassess a segment.
How much capital does a reserve requirement actually lock up?
A merchant processing $1 million a month under a 10% rolling reserve held for 180 days has $300,000 to $600,000 tied up on a continuous basis. Reserves climb once a relationship ends. Acquirers exiting mid-settlement commonly hold 20% to 100% of pending funds for at least 180 days to cover chargebacks that surface after closure.
What happens to stored cards if a processor drops you?
Processor-issued tokens belong to that processor, so without a portability plan you have to ask every customer to re-enter their card. That can cost 15% to 30% of a subscription base overnight. A vault you own, paired with network tokens issued directly by Visa and Mastercard, keeps the credentials portable and updates them automatically when a card is reissued.









