Join our Newsletter — 33% off our NHI Course
Home FAQ Governance, Ownership & Risk Who should be accountable for keeping POS merchants…
Governance, Ownership & Risk

Who should be accountable for keeping POS merchants compliant with registration requirements?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 19, 2026 Domain: Governance, Ownership & Risk

Accountability should sit with the institution that sponsors or re-onboards the merchant, because that team controls the decision to allow activity to continue. Compliance, operations, and onboarding teams all play a role, but one owner must track evidence, enforce deadlines, and stop exceptions. Shared responsibility only works when a single group is clearly answerable for merchant eligibility.

Who owns merchant compliance in practice

Accountability should sit with the institution that sponsors or re-onboards the merchant, because that is the party with the authority to keep the merchant active, suspend it, or block continued processing when requirements are not met. In practice, compliance, onboarding, and operations all contribute evidence and checks, but one owner must be able to enforce deadlines and close exceptions.

The key distinction is between participation and accountability. Multiple teams can help collect documents, verify status, and follow up on gaps, but if ownership is split, merchants often remain live while everyone assumes another team is tracking the case. A single accountable sponsor avoids that gap by tying registration status to the decision to continue doing business.

That structure also matters because merchant eligibility is not a one-time onboarding task. Registration, re-onboarding, and periodic review all create points where the sponsor can confirm whether the merchant still meets requirements. When that ownership is unclear, stale records, missed renewals, and unresolved exceptions tend to accumulate until a control failure becomes visible only after a dispute or audit finding.

What breaks when accountability is shared but not owned

Shared responsibility works only when it is backed by a named owner who can act. Without that, teams may treat compliance as a documentary exercise instead of an operational control, which leaves merchants able to continue processing while evidence is incomplete, expired, or not independently verified.

Another common failure is that no one owns the decision to stop activity. A team may gather documents, another may record them, and a third may review them, but if none can enforce suspension or escalate exceptions, the organisation effectively accepts risk by default. That is why the accountable sponsor must control the final go or no-go decision.

Where merchant populations are large, the problem scales quickly. Even small review delays can create a backlog of expired registrations, and the longer the delay, the more likely the organisation is to rely on outdated status information. For teams that want a broader identity and governance lens on this pattern, NHIMG’s Ultimate Guide to NHIs is useful because it frames ownership, lifecycle control, and evidence tracking as operational responsibilities rather than paperwork.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV.RM — Risk Management StrategyMerchant compliance ownership is a risk governance decision affecting continued exposure.
Recommendation — Assign a single accountable owner to manage merchant registration exceptions and enforce suspension when eligibility lapses.
CIS Controls v85.3 — Account ManagementMerchant registration requires an owner to track status, review eligibility, and remove stale approvals.
Recommendation — Maintain one accountable owner for merchant eligibility, review, and deactivation decisions.

Practitioner Guidance

What to verify: Make sure the sponsoring or re-onboarding team is the only group that can approve continuation after a registration lapse, because accountability without enforcement authority is not real accountability. The owner should be able to show current status, pending exceptions, and the date each merchant must be reviewed or stopped.

What good looks like: Each merchant has one named accountable owner, a clear evidence trail, and a defined escalation path if registration is not current. Compliance can advise, operations can execute, and onboarding can gather inputs, but the sponsor must own the final decision and the follow-through.

Decision rule: If a merchant cannot prove it still meets registration requirements, treat the case as an active exception, not an administrative delay. The business decision should be to pause, restrict, or re-onboard rather than allow continued processing on the assumption that the missing evidence will arrive later.

Practitioner takeaway: The control fails when responsibility is collective but action is diffuse, so the practical objective is to assign one owner who can both evidence compliance and stop activity when the merchant is no longer eligible.

Risk and Threat Considerations

Merchant registration gaps create a control weakness, not just an administrative issue. If nobody owns enforcement, an ineligible merchant can remain active long enough to increase exposure to financial loss, audit findings, and downstream compliance failures.

Failure mechanism: Responsibility is split across teams, so evidence is collected but no one is accountable for expiry tracking, exception closure, or suspension when registration is incomplete or stale.

Impact: The organisation may continue processing for merchants that should have been paused or re-onboarded, which increases operational risk and weakens the credibility of the registration control.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 19, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org