The Third Party Pays First: Risk You Can’t See
PSPs sit between the acquirer and the merchant, control neither, and absorb the consequences of both. That position is getting more expensive, and the usual response makes it worse.
There’s a comfortable story PSPs tell about their position in the payment chain: we’re infrastructure. We move money between parties. The merchant owns the customer relationship, the issuer makes the authorisation decision, the acquirer holds the licence, and we connect them.
It’s a clean story. It also describes a set of responsibilities that has almost nothing to do with where the losses actually land.
Start with the mechanics everyone in the industry already knows but rarely states plainly.
A sub-merchant in your portfolio starts pushing dispute volume. Maybe their marketing got aggressive, maybe their fulfilment slipped, maybe they got hit by a fraud ring. Whatever the cause, it wasn’t your decision, it wasn’t your traffic, and you had no say in the product being sold.
But when that merchant crosses a card network threshold, the fines, the scheme monitoring and the unexpected loss provisions land on you. You get the reserves, the holds, the awkward conversation with your acquiring bank. The merchant’s risk is your balance sheet.
And the thresholds keep moving. VAMP replaced VDMP in April 2025, and the merchant threshold tightened to 1.5% in April 2026. Each tightening narrows the band in which a portfolio you don’t fully control has to stay.
Scale makes this harder, not easier. A PSP with thousands of sub-merchants has thousands of independent risk profiles moving simultaneously, and the tooling to watch them is typically assembled from disparate sources that make portfolio health hard to see in one place, which delays intervention. By the time a merchant shows up on a dashboard, the ratio damage is done.
The second asymmetry is the one that matters more, and gets discussed less.
You don’t control the checkout. You don’t see how the customer browsed, what they abandoned, how they’ve behaved across previous purchases, or what happened after the goods shipped. You see a transaction arrive and a transaction settle. Everything that would let you distinguish a good buyer from a bad one happens on either side of your window.
This has a direct operational consequence at dispute time. Aggregated account structures limit network access for dispute evidence, which means the party carrying the liability is often the party with the weakest hand in defending it. You’re liable for an outcome you can’t see coming and can’t argue against effectively once it arrives.
Compare that to the merchant’s position. They may be less sophisticated about payments, but they know their customer, their product, their return patterns and their fulfilment. They have context. You have a transaction record.
Here’s the part that costs the most and appears in no risk model.
When an order is declined, the merchant’s customer complains to the merchant, and the merchant complains to you. It doesn’t matter that the issuer made the call, or that a fraud engine you licensed from someone else scored the transaction, or that the decline was technically correct. You are the payments company in the relationship. Declines are a payments problem. You own it by default.
That perception is why approval rate has quietly become the thing PSPs compete on. Fees are commoditised and every competitor’s pricing page says roughly the same thing. What a merchant actually notices, month after month, is how many of their sales went through.
If you were hoping the liability picture would loosen, it’s going the other way.
The provision that should concentrate the mind is narrower and sharper. Where a PSP delegates Strong Customer Authentication functions to a third party — a wallet provider, a gateway, a fraud vendor — the PSR explicitly classifies that as outsourcing, and the delegating PSP retains full liability for SCA failures, along with an obligation to maintain audit rights over the provider.
Read that again with the vendor relationship in mind. You can outsource the function. You cannot outsource the consequence. The regulator has now written down what the commercial reality already was.
Which leads to the thing PSPs are starting to work out for themselves.
The traditional split — PSPs process payments, fraud vendors manage fraud — is dissolving, and the reason is that outsourcing risk means handing over control of authorisation rates, false positives, merchant approval speed, portfolio profitability and scheme monitoring exposure. Those aren’t fraud metrics. They’re your business metrics. Every one of them determines whether a merchant renews.
So the calculation changes. A fraud vendor that runs a black-box model and hands back accept/decline verdicts isn’t reducing your exposure — it’s relocating the decision while leaving the liability exactly where it was, and now with an audit obligation attached.
The structural problem is that a PSP’s window onto each transaction is too narrow and closes too early. Widening it doesn’t require owning the checkout. It requires signals that exist outside the authorisation moment:
What happens after settlement. Delivery and fulfilment behaviour, whether goods are used or returned, how an account behaves over its lifetime. These are the signals that actually separate a good buyer from a bad one, and they’re all available after the transaction rather than during it.
Direct contact with the accountholder. When risk surfaces on a specific transaction, the fastest way to resolve it is to ask the person who made it. A human answer beats any inference a model draws from a device fingerprint — and getting it doesn’t require blocking the sale first.
Per-merchant risk visibility, continuously. Not a monthly portfolio report, but the ability to see a sub-merchant’s ratio drifting while there’s still time to intervene, rather than after a scheme monitoring letter arrives.
None of this is exotic. It’s what the merchant already has and the PSP structurally doesn’t — and closing that gap turns the PSP from the party who finds out last into the party who can warn everyone else.
The story PSPs tell about being infrastructure is a description of how money flows, not of how risk flows. Risk flows toward whoever has the least visibility and the most liability, and in card-not-present commerce, that’s you.
Fixing the visibility side is what makes the liability side survivable. It also happens to be what a merchant is willing to pay more for: a provider that can explain why an order was declined, recover the ones that shouldn’t have been, and flag trouble before it becomes a fine.
This is the gap FUGU was built to close. Decoupling acceptance from verification gives the PSP something the pre-authorisation window structurally cannot: information that arrives after the decision would have had to be made, and a direct line to the buyer when it matters.
The merchants in your portfolio will keep generating risk you didn’t choose. The question is whether you find out about it from your own systems, or from your acquirer.