How do the card networks define transaction laundering and factoring?
Transaction laundering — also called factoring or undisclosed aggregation — is one merchant processing card transactions on behalf of another, undisclosed entity through its own MID, per Venable LLP's analysis for the payments industry. The acquiring bank underwrote the visible merchant for a specific product, ticket size and risk profile; when a second business rides that MID unannounced, every dispute, refund and fraud report attaches to a company that never agreed to carry that liability. The violation exists whether or not either party intended harm — the acquirer simply never consented to the exposure it now holds.
The exposure runs beyond the merchant agreement itself. Regulators — FinCEN, the FFIEC, the FTC, the DOJ and the CFPB — treat acquirers and payment facilitators as financial-system gatekeepers, per Venable's summary, and criminal exposure for the underlying scheme typically runs under wire fraud (18 U.S.C. 1343), bank fraud (18 U.S.C. 1344, up to 30 years per count) and money laundering (18 U.S.C. 1956, up to 20 years and a fine of the greater of $500,000 or twice the funds involved). None of that requires proof of intent to defraud a cardholder. It requires only concealment from the bank.
What makes routing one site's sales through another merchant account a violation?
The violation is non-disclosure, not the number of merchant accounts in use. Running several MIDs is not inherently against the rules — load balancing across multiple merchant IDs is a marketed feature of high-risk providers such as Easy Pay Direct, and large brands legitimately spread volume across acquirers to manage risk and capacity. The rule breaks when the acquirer does not know a given MID carries someone else's sales, or when the product actually moving through that MID differs from what was underwritten.
Product identity is the harder failure mode, because it survives full disclosure of the corporate structure. A merchant account underwritten for an oral supplement business processing sales for an injectable line is carrying a different risk category than the one the acquirer priced and approved — the same distinction that separates a compliant NAD+ supplement offer from an unlicensed injectable one at the regulatory level. The acquirer's underwriting, not the merchant's org chart, defines what a MID is allowed to carry.
Where does load balancing stop being load balancing?
Load balancing stops being load balancing at the point where the split exists to manage exposure to the acquirer rather than exposure for the acquirer. Spreading volume across several disclosed MIDs at several underwritten acquirers to manage capacity and settlement risk is ordinary treasury practice for a high-volume nutraceutical brand. Spreading the same volume across several MIDs specifically so no single account crosses a chargeback or fraud threshold is the same infrastructure pointed at a different goal, and the networks now watch for exactly that pattern.
Most operators assume the MID count itself is what gets flagged — that four merchant accounts read as riskier than one. That is not quite what Mastercard's new Scam Merchant Monitoring Program screens for: its rules treat 'multiple MID requests without clear business justification' as a scam signal, according to Justt's summary of Mastercard's Merchant Edition rules, meaning the absence of a stated reason is the trigger, not the raw number of accounts. A brand running six disclosed MIDs with a documented capacity rationale is arguably positioned better than one running two it cannot explain.
What does the card brand rulebook require the descriptor and URL to match?
Visa's authorization systems allow exactly 25 characters for the merchant name, and its April 2026 Merchant Data Standards Manual requires acquirers to use the full field and to abbreviate — never simply truncate — any longer name, preserving whichever part uniquely identifies the business. A descriptor that reads as generic or unrelated to the product invites the exact dispute the rule exists to prevent: a cardholder who does not recognize the statement line files it as fraud instead of calling the merchant.
The same manual goes further than length. Where the merchant name is inconsistent with the assigned MCC, the acquirer must attach extra identifying information to the transaction rather than just a shorter name, per Visa's Merchant Data Standards Manual. Visa also carves out one specific allowance for continuity offers: the first recurring charge at the end of a trial, discounted intro period or promotion may carry supplementary language after the merchant name flagging that the promotional period has ended and the regular subscription price now applies.
The manual's verified text addresses the descriptor and the MCC, not the checkout URL by name. Any claim of an explicit rule requiring the landing-page URL to match the statement descriptor should be treated as needing verification against the acquirer's own rulebook rather than accepted from payments-industry folklore — the confirmed requirements here are the name-field length rule and the MCC-consistency rule, nothing broader.
How does the Visa Integrity Risk Program treat high-integrity-risk categories like nutraceuticals?
The program's specific nutraceutical thresholds are not confirmed in the sourcing checked for this page, and the safe posture is to treat any number quoted for it as needing verification against a current Visa acquirer bulletin before it goes into a compliance memo. What is confirmed is the direction of the surrounding oversight: Visa tightened its adjacent Acquirer Monitoring Program merchant-excessive threshold from 220bps to 150bps of fraud-plus-disputes across card-not-present volume in the AP, Canada, EU and U.S. regions effective 1 April 2026, per Visa's Acquirer Monitoring Program fact sheet, in the same card-not-present environment nutraceutical continuity offers operate in almost exclusively.
Nutraceuticals already sit among the verticals named for the steepest reserve demands from high-risk acquirers, per Corepay's account of typical rolling-reserve structure — commonly 5% to 15% of processing volume held 90 to 180 days. A category singled out for reserve severity under ordinary underwriting is a reasonable proxy for how a category-specific integrity program is likely to treat it, but that is an inference from adjacent data, not a confirmed program figure, and any internal document citing it should label it as such.
What penalties do acquirers and networks impose for laundering findings?
Penalties layer from the transaction level up to the individual. At the transaction level, Visa's VAMP fee structure charges USD $4 per fraud or dispute transaction once an acquirer's portfolio crosses the Above Standard ratio and USD $8 per transaction at the Excessive level, with no warning tier once Excessive status hits, per Visa's Acquirer Monitoring Program fact sheet. Mastercard runs a parallel ladder for merchants: its Excessive Chargeback Merchant program requires both 100 to 299 chargebacks and a 1.50%–2.99% ratio in a month, with fines that compound the longer a merchant stays enrolled.
A finding of transaction laundering specifically, rather than an ordinary chargeback spike, tends to move past fines into termination and listing. Acquirers report the terminated merchant to MATCH within one business day, per Stripe's documentation on high-risk merchant lists, the record follows the named principal — not just the entity — for five years, and removal is limited to two paths: the processor admitting an error, or, for PCI-only findings, achieving PCI DSS compliance. Listings entered for excessive chargebacks or excessive fraud cannot be removed by remediating afterward.
The gap between a compliance fine and a criminal referral is narrower than most merchants assume. Concealing a second business inside a MID underwritten for a different one is the same category of misrepresentation to a federally regulated institution that shows up in analysis of when ad fraud crosses into prosecutable wire fraud in media buying — the wire, in a card transaction, is the authorization message itself.
| Month in program | ECM fine (USD/EUR) | HECM fine (USD/EUR) |
|---|---|---|
| Month 1 | $0 | $0 |
| Month 2 | $1,000 | $1,000 |
| Month 3 | $1,000 | $2,000 |
| Months 4–6 | $5,000 | $10,000 |
| Months 7–11 | $25,000 | $50,000 |
| Months 12–18 | $50,000 | $100,000 |
| Month 19+ | $100,000 | $200,000 |
Can a merchant be liable when a third-party processor structured the arrangement?
Yes — structuring the arrangement does not transfer the liability, and a merchant that simply plugged into a routing setup a processor built rarely escapes the consequences. Card-network reporting is built around the individual: an acquirer that terminates a merchant for transaction laundering must submit the principal owner's name, address, phone number and tax ID to MATCH, per Stripe's documentation on high-risk merchant lists, and a new company the same person later forms gets matched on the next acquiring inquiry. Not knowing how a processor structured the flow is not a listed removal ground.
The pattern echoes even inside fully disclosed, legitimate Merchant of Record relationships. Paddle's reseller terms make Paddle the liable party for chargebacks and disputes with the card networks, but its own contract requires the vendor to reimburse Paddle the full amount of a refund or chargeback plus fees when Paddle absorbs one — the network-facing liability moves, the economic loss does not. A merchant relying on a third party to carry regulatory or network risk should assume the same holds in reverse: the contract, not the org chart, decides who actually answers for a laundering finding.
What questions should a merchant ask before agreeing to an unusual routing setup?
The first question is whether the acquirer underwriting the MID actually knows what will be sold through it, because every other question is downstream of that one. A merchant that cannot answer this in one sentence is already exposed, regardless of how the processor describes the arrangement or how many other brands use the same setup without incident.
- Does the acquirer's underwriting file name this specific product, or a different one the MID was originally approved for?
- Is the business entity on the MID the same legal entity that owns the website and fulfills the order, or a separate company the processor introduced?
- Who receives settlement funds first, and does that party appear anywhere in the cardholder-facing descriptor or refund policy?
- If volume is split across multiple MIDs, is there a documented, disclosed business reason for each one, or only a chargeback-ratio reason?
- What does the processor's contract say happens to chargeback and refund cost if the network terminates the MID — does liability sit with the merchant, the processor, or is it silent?
Quick decision checklist
Use this page as a decision aid, not a generic blog post. The practical question is whether the reader needs faster evidence about what is already working in VSL-driven direct response, especially across nutra, supplements, GLP-1, weight loss, blood sugar, and adjacent high-intent health markets.
Daily Intel Service is most relevant when the next decision depends on active market examples: which hook to test, which claim style is risky, which funnel structure is common, which language market is moving, and whether a competitor's creative is likely early, scaling, or already saturated.
- Start with the TL;DR if you need the direct answer.
- Use the table to compare trade-offs quickly.
- Use the FAQ for answer-engine-ready summaries.
- Use the CTA when the decision requires live VSL and ad examples instead of theory.
Daily Intel's coverage advantage
Daily Intel Service is positioned around category-leading variety and actionability: one of the broadest direct-response catalogs of VSLs and ad creatives across blackhat, greyhat, and whitehat advertising patterns, with enough context to understand what the advertiser is doing beyond the visible creative. The practical difference is that members are not just seeing a screenshot; they are seeing the VSL, the ad, the funnel path, the transcript, the UTM context, and the research notes that turn the asset into a decision.
This matters because direct-response affiliates do not operate in one clean category. A weight-loss campaign may use a whitehat compliance ad, a greyhat pre-lander, a more aggressive VSL, and a checkout path designed around upsells and recovery. A useful intelligence platform needs to capture that spectrum instead of pretending every winning campaign looks like a public brand ad.
Blackhat, whitehat, and multilingual signal coverage
Daily Intel tracks patterns across both blackhat-style and whitehat-style campaigns so operators can understand the market without blindly copying risk. Whitehat examples help with durability and compliance review; blackhat and greyhat examples reveal pressure points, hooks, mechanisms, and funnel structures that may be driving spend but require careful adaptation before use.
The catalog is also built for global operators, with VSL and ad references spanning 14+ languages and different local idioms. That is a key advantage for Brazilian, LATAM, European, MENA, Indian, and non-native English affiliates who need to see how the same market desire is translated across cultures instead of only studying US English ads.
| Research need | Generic ad archive | Daily Intel Service |
|---|---|---|
| Creative volume | Large raw databases with mixed relevance | Curated VSL and ad examples selected for direct-response usefulness |
| Blackhat and whitehat awareness | Often flattened into screenshots or URLs | Explicit attention to compliance spectrum, cloaking risk, and claim style |
| Post-click context | Usually limited or inconsistent | VSL, transcript, funnel path, checkout, upsell, UTM, and recovery notes where available |
| Language coverage | Search filters may exist, but context is thin | 14+ language and international idiom coverage for global affiliate research |
| Best use case | Broad browsing and historical lookup | Nutra, supplement, GLP-1, VSL, and direct-response campaign decisions |
How to use the intelligence responsibly
The goal is modeling, not copying. Use Daily Intel to understand structure: hook, mechanism, proof, claim intensity, funnel depth, offer economics, and saturation stage. Then build original creative, review claims, and adapt the angle to the traffic source, country, language, and compliance requirements of the campaign.
A strong workflow compares multiple examples before acting. If the same mechanism appears across several languages, several advertisers, and several funnel variants, it may be a durable market signal. If the example appears only once or depends on an aggressive claim, treat it as a research clue rather than a campaign template.
- Model structure, not protected creative assets.
- Separate whitehat durability from blackhat persuasion pressure.
- Compare US English examples against LATAM, European, and other language variants.
- Use transcripts and funnel notes to build original briefs.
- Keep compliance review separate from market research.
Methodology and source context
Daily Intel pages are written from a research workflow that reviews active VSLs, Meta ad creatives, transcripts, UTMs, funnel paths, checkout steps, upsells, recovery sequences, and compliance-sensitive claim patterns. The goal is to explain observable market behavior, not to provide legal, medical, or platform policy advice.
When the topic touches health claims, platform policy, or GLP-1 market research, validate the observable campaign signals against primary references such as Meta advertising standards, FTC health claims guidance, and Google helpful content guidance. Daily Intel adds the proprietary direct-response layer by mapping how those rules show up in active VSLs, Meta creatives, funnels, transcripts, UTMs, and checkout paths.
For deeper evaluation, continue through Daily Intel compliance and legal disclaimer, Residential vs Datacenter Proxy for Ad Research 2026, Why Ads Disappear From the Meta Ad Library Overnight, Google Ads Misrepresentation Suspension: What Fixes It, Conta de Anúncios Bloqueada no Facebook: Como Recorrer, and What is a VSL?. These related Daily Intel pages connect this topic to the relevant methodology, pricing, trust context, comparison path, or niche workflow.
Founding rate — locked forever
Access curated VSL intelligence for $29.90/mo
- 50–100 manually validated VSLs every day at 11PM EST
- major niches niches, 14+ languages, blackhat-to-whitehat pattern coverage
- live catalog VSL/ad catalog, transcripts, UTMs, full funnel maps
- Cancel anytime — founding rate stays yours forever
Daily Intel Service delivers manually curated research around active-scaling VSLs, Meta creatives, UTMs, funnels, and nutra market movement.
Frequently asked questions
What is transaction laundering?
Transaction laundering is one merchant processing another, undisclosed business's card sales through its own merchant account. Also called factoring or undisclosed aggregation, it breaks the agreement between the visible merchant and its acquiring bank because the acquirer priced and approved a different product, volume and risk profile than what actually moves through the account, per Venable LLP's analysis.Is running multiple merchant accounts illegal?
Running multiple merchant accounts is not illegal on its own. Load balancing across several disclosed MIDs is a standard feature marketed by high-risk providers such as Easy Pay Direct, and large brands use it to manage settlement risk and processing capacity. The violation appears only when the MIDs are undisclosed to the acquirer or carry a different product than the one underwritten.What is the difference between transaction laundering and factoring?
Transaction laundering and factoring describe the same practice under two names. Both mean routing one business's card transactions through a merchant account belonging to a different, undisclosed entity, and payments-industry legal analysis uses the terms interchangeably. The distinguishing fact in either case is concealment from the acquiring bank, not the mechanics of the routing itself.Can a nutraceutical company be listed on MATCH for transaction laundering?
Yes, and the listing follows the owner, not just the company. An acquirer that terminates a merchant for transaction laundering must report the principal's name, address, phone number and tax ID to MATCH within one business day, and the record stays visible to other acquirers for five years before Mastercard deletes it automatically.Does using a Merchant of Record eliminate transaction-laundering risk?
No, a Merchant of Record changes who the card networks hold liable, not what actually gets sold. Providers like Paddle and Polar exclude physical goods entirely, so a shipped nutraceutical offer cannot route through them at all; digital-adjacent offers that misrepresent their true product to an MoR reproduce the same disclosure failure at a different layer.What triggers Mastercard's Scam Merchant Monitoring Program?
Mastercard's Scam Merchant Monitoring Program triggers when combined refunds plus chargebacks exceed 5% of a merchant's transactions over a rolling 30-day period with at least 500 transactions, becoming enforceable 24 July 2026. It explicitly treats multiple MID requests without clear business justification as a scam signal, and confirmed scam activity can mean immediate termination and a MATCH listing.
Continue the research path