Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› What do underwriters get wrong when evaluating merchant…
Governance, Ownership & Risk

What do underwriters get wrong when evaluating merchant applications?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 29, 2026 Domain: Governance, Ownership & Risk

A common mistake is treating merchant underwriting like a formality instead of a full risk review. Teams also get tripped up by vague business descriptions, mixed personal and business finances, weak documentation, and unrealistic volume projections. When the application does not match the actual business model, underwriters lose the evidence they need to judge stability and exposure accurately.

What underwriters often miss in the application itself

Merchant underwriting fails when teams treat the form as a compliance exercise instead of evidence about how the business actually operates. The application is supposed to explain the merchant, the product or service, the sales channel, and the expected transaction pattern. If those details are vague or inconsistent, the underwriter is no longer judging exposure, only guessing at it.

A useful way to frame the problem is that underwriting quality depends on narrative consistency. The declared business model should match the website, invoices, refund policy, pricing, fulfilment timeline, and transaction profile. When those inputs do not line up, the application is not simply incomplete, it is unreliable as a risk signal.

That is why generic descriptions create so much trouble. A merchant that says only “consulting” or “digital services” may be harmless, but it prevents the reviewer from understanding settlement timing, refund risk, chargeback likelihood, or whether the product is recurring, one-time, regulated, or high-dispute. The underwriting judgment gets weaker because the evidence is too broad to support a defensible decision.

Why financial commingling and weak documentation distort the risk view

One of the most common mistakes is mixing personal and business finances in ways that hide the merchant’s true operating pattern. Separate accounts, invoices, refund records, customer communications, and ownership records help establish that the business is real, stable, and operated at arm’s length. When those records are blurred, it becomes harder to tell whether revenue is repeatable or merely incidental.

Documentation matters because underwriting is not only about identity verification, it is about business credibility. A strong file gives the reviewer enough evidence to check cash flow consistency, fulfillment reality, and the merchant’s ability to handle disputes. Weak documentation forces the decision toward higher caution, delayed approval, or a less precise limit assignment.

Expectation-setting is another weak point. Projected volume should be plausible relative to the merchant’s stage, channel, and history. Unrealistic forecasts often signal either poor operator judgment or an attempt to push limits beyond what the evidence supports. In either case, the underwriting issue is not just size, it is whether the merchant can sustain the claimed activity without creating disproportionate loss exposure.

How to judge the file like a real risk review

Merchant underwriting works best when the reviewer compares the application against observable operating evidence, not just the requested limit or processor’s checklist. The question is whether the merchant can be understood well enough to forecast dispute behaviour, refund exposure, seasonality, concentration, and operational stability. That requires matching the business description to external and internal evidence, then testing whether the volume request fits the facts.

The same discipline applies to changes over time. A merchant that was low-risk at launch can become materially different once products, sales channels, or fulfilment methods change. Underwriting should therefore be treated as a living judgment, especially when the merchant scales quickly, adds subscriptions, moves cross-border, or changes ownership or fulfilment partners.

For broader control context, the same evidence-first logic appears in NIST SP 800-53 Rev 5 Security and Privacy Controls, which emphasizes structured control selection and verification, and in OWASP API Security Top 10, where broken authorisation and weak trust in supplied data create direct risk. NIST Cybersecurity Framework 2.0 is also useful as a reminder that good decisions depend on governance, identify, protect, and detect disciplines working together.

Risk and Threat Considerations

Merchant underwriting mistakes create direct financial exposure when merchants are approved on weak evidence, exaggerated volumes, or misleading operating descriptions. The practical risk is not just a bad approval, it is a bad limit, delayed detection of dispute-heavy activity, and poor visibility into whether the merchant model is actually sustainable.

Failure mechanism: The reviewer accepts an incomplete or inconsistent application as if it were a reliable business profile, then assigns pricing, reserves, or limits without enough evidence to bound dispute, refund, or volatility risk.

Impact: The acquirer or payment provider can inherit higher chargeback loss, operational remediation work, and faster escalation when the merchant’s actual behaviour diverges from the submitted profile.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5CA-7 — Continuous MonitoringMerchant profiles and activity should be checked against ongoing evidence of actual business behaviour.
RA-3 — Risk AssessmentUnderwriting is a risk assessment problem that depends on accurate business evidence and exposure analysis.
AU-6 — Audit Record Review, Analysis, and ReportingReviewing supporting records helps validate whether the merchant story matches transaction reality.
Recommendation — Monitor merchant activity and revise exposure when the operating profile diverges from the application. Assess merchant risk using documented business model, volume expectations, and dispute exposure. Review supporting records for inconsistencies before setting limits or approving the merchant.
NIST CSF 2.0GV.RM-01 — Risk Management StrategyUnderwriting decisions should align with a defined risk appetite and exposure strategy.
ID.RA-01 — Asset Vulnerabilities are Identified and DocumentedApplication gaps are risk indicators that should be documented as underwriting vulnerabilities.
Recommendation — Align merchant approval thresholds and reserve decisions to the organisation's risk appetite. Document application gaps, inconsistencies, and missing evidence as risk indicators.

Practitioner Guidance

What to verify: Confirm that the merchant’s stated business model matches the website, product pages, refund terms, invoices, fulfilment method, and expected transaction rhythm. If those sources disagree, treat the file as incomplete rather than merely messy.

Decision rule: If the application cannot explain how the merchant earns revenue, fulfils orders, and handles refunds in a way that matches observed evidence, delay approval or reduce exposure until the missing facts are cleared up.

Common mistake: Do not let a polished application or fast growth narrative override weak documentation. A high requested volume with thin operating evidence is usually a reason to slow down, not a reason to trust the projection.

Practitioner takeaway: Strong underwriting is less about accepting the form and more about proving that the submitted story, the operating evidence, and the requested exposure all describe the same business.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 29, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org