Merchant Risk6 min readJune 2026

Continuous Merchant Monitoring: Why Payment Aggregators Need More Than Annual Reviews

The merchant that passed your annual review in January is not the same merchant today.

That is not a metaphor. Ownership structures change. Beneficiary accounts change. Transaction patterns shift as volume grows into categories nobody underwrote for. Your risk file has not moved since January.

Annual review measures a moment. Fraud moves in the eleven months between moments.

What an Annual Cycle Actually Covers - and What It Misses

A review cycle answers one question: was this merchant clean on the day it was checked? It says nothing about what happens next.

That gap is where sub-merchant fraud, mule networks, and coordinated onboarding schemes operate. They are built to survive a point-in-time check and evolve in the space where no one is watching.

Picture the merchant that cleared review clean in Q1. By Q3, its payout patterns have shifted toward a beneficiary account shared with two other merchants on your platform. Nothing in your annual cycle catches this, because nothing in your annual cycle is watching between cycles.

Why Rule-Based Checks Cannot See Merchant Networks

A rule-based check asks whether this merchant, today, looks like the merchant it was at onboarding. That is a useful question. It is also a narrow one.

It cannot ask whether this merchant's beneficiary account now overlaps with a merchant flagged six months ago in a different review cycle. It cannot see that three seemingly unrelated merchants share a device fingerprint from onboarding, filed weeks apart. Those questions require comparing merchants against each other continuously - not against their own history once a year.

RBI's Master Direction on Regulation of Payment Aggregators requires ongoing merchant due diligence and continuous transaction monitoring across PA-O, PA-P, and PA-CB categories. An annual review satisfies a calendar. It does not satisfy an ongoing obligation - and the gap between those two things is exactly where an examiner will look first.

The Operational Reality That Makes This Hard

A PSP processing for thousands of merchants cannot manually re-review every relationship every month. The volume makes continuous review by hand structurally impossible - which is why most aggregators default to the annual cycle in the first place.

It is not that continuous monitoring is undervalued. It is that doing it manually was never realistic. The question is not whether to monitor continuously. The question is which infrastructure makes it operationally possible.

How Verafye Makes Continuous Monitoring Operationally Possible

Verafye's continuous merchant monitoring capability evaluates merchant relationships as new signals arrive - a new beneficiary account, a new device match, a new connection to a previously flagged entity - without requiring a scheduled review to trigger the comparison.

When merchant B's payout pattern shifts to a beneficiary account already linked to merchant A (flagged four months ago), that connection surfaces within the current signal cycle. Not at the next annual review. Not through a manual analyst trace. Automatically, as the relationship forms.

For payment aggregators under RBI's ongoing monitoring requirements, this is the operational difference between a programme that runs continuously and a documentation exercise that claims to. The graph-native network risk intelligence layer Verafye provides maps every merchant relationship continuously - beneficiary accounts, device fingerprints, ownership connections, proximity to flagged entities - and flags changes as they happen.

The audit trail Verafye generates - every relationship change, every flagged connection, every review decision - is the evidence an examiner is looking for when they ask how the programme works between scheduled cycles. If you want to see where your current monitoring has relationship blind spots between review cycles, the Verafye Risk Shadowing Review is a practical starting point.

What Eleven Months of Silence Costs

Every month between reviews is a month a coordinated network has to establish trust, build transaction history, and recruit additional merchants into the same pattern before anyone looks again. By the time the next annual cycle catches something, the fraud is rarely a single bad merchant. It is a cluster that formed entirely inside the blind spot the calendar created.

The compliance cost compounds. An examiner asking how a merchant relationship was monitored between reviews will not accept "we checked it in January" if the fraud clearly developed in April. That is not a documentation gap. It is evidence the monitoring programme was never actually continuous - whatever the policy document claims.

Fragmented monitoring produces a second, quieter cost: fraud and AML teams working from the same annual snapshot but different interpretations of it, neither positioned to catch what changed in the months neither team was watching.

The Question Worth Asking Before Your Next Review Cycle

Not whether your last review found anything. Whether your programme would catch a relationship that formed the week after that review closed.

If the honest answer is no, the review cycle was never the safeguard it was assumed to be. It was a snapshot mistaken for a monitoring programme, and the eleven months of silence around it were always the actual exposure.

V

Vasuki

Co-Founder & CPO, Verafye

Verafye is a graph-native network risk intelligence platform built for lean fraud, AML, and risk teams at payment aggregators, PSPs, MSBs, and regulated fintech platforms.

Explore on Verafye

Payment Processors Psps PayfacsGraph IntelligenceTransaction MonitoringRisk Shadowing Review

See where your monitoring stack has blind spots

The Risk Shadowing Review maps your current coverage against relationship-level gaps.

Request a Review

Related Articles

6 min read · May 2026Merchant Due Diligence for Payment Aggregators: How to Reduce Alert Fatigue Without Increasing Risk8 min read · March 2026Third-Party Payout Risk: What Payment Aggregators Need to Know About Sub-Merchant Fraud
Back to Blog