Last Updated on September 16, 2026 by Team TBH
A vertical software company turns on payments, onboards 400 sub-merchants in a quarter, then finds that 6 of them were running card testing scripts from the first week. The disputes arrive 45 days later. Who absorbs that loss was settled long before any of those transactions were authorized, inside the underwriting rules and the contract language.
Finix operates at that decision point. The material below covers underwriting, risk scoring and compliance rather than checkout design or pricing tables, because those three functions determine where losses land across a merchant portfolio.
Approval Logic the Platform Writes Itself
Automated merchant underwriting went live in April 2024. The system collects merchant information, runs compliance checks, scores risk and can approve an account in seconds. Speed is the visible part. Configuration is the part with consequences. Platforms write their own logic rules instead of accepting a fixed approval path set by the processor.
The difference shows up across verticals. A platform serving licensed home services firms and one serving event ticketing carry different failure profiles. A single approval flow treats them identically. Configurable rules let a platform approve low-ticket accounts in a familiar category on the spot and hold anything above a set volume figure for human review. Risk appetite becomes an input rather than something inherited.
Most coverage of the company, including this Finix review, opens on pricing and checkout tooling, though the configuration layer is where a platform carrying merchant risk gets the most use. Rules can be written against a platform’s own dispute history, so approval thresholds track observed outcomes rather than a generic default. The tooling puts that work with the team closest to the merchant base, which is the team holding the account relationship.
What the Models Are Trained On
Risk tooling pairs machine learning models trained on network transaction data with rule sets built by the company’s internal risk staff. Coverage includes transaction scoring, geolocation signals, card testing alerts and email risk profiling. The two inputs work on different timescales, with the models reading volume patterns across the network and the rule sets encoding what analysts have seen resolve into losses.
Card testing is the most immediate of those. Attackers push high volumes of small authorizations through a weak sub-merchant to validate stolen card numbers. Many of those authorizations approve. The fraud reports follow. A platform that catches the pattern in hour 1 rather than day 3 avoids most of the downstream damage. Email risk profiling operates on a slower signal, scoring the age and reputation of an address supplied at signup. Geolocation signals sit between the two, flagging mismatches between a stated business address and the origin of the traffic.
Identity Checks and Watchlist Screening
Compliance covers identity document verification, screening against sanctions and watchlist databases, and account review for money laundering signals. Decisions route back to the platform for review rather than resolving invisibly inside the processor.
That visibility carries practical weight. A platform that receives a rejection with a reason attached can correct a false positive and explain the outcome to a customer the same day. Sanctions screening produces false positives at volume, often on common surnames or partial address matches, and the review work belongs with whoever holds the customer relationship.
Ongoing monitoring runs on the same principle. Screening at onboarding covers one moment. Watchlists change, beneficial ownership changes, and a merchant approved in March can look different by September. Periodic re-screening and transaction pattern review are expected of any party operating under a facilitator model, and the returned-decision model keeps the platform informed as those reviews happen.
Direct Acquirer Status Moves Work Inward
Finix registered as a payment processor in its own right in 2023 and connects directly to Visa, Mastercard, American Express and Discover. Direct acquirer status removes an intermediary from the chain and places more underwriting responsibility inside the company.
Two effects follow for platforms. Approval decisions and risk rules are handled by one party rather than negotiated across a sponsor bank relationship. The company also carries the network reporting duties and the anti-money laundering screening obligations attached to acquirer status, both of which have grown stricter.
What the 2026 Network Thresholds Changed
Card network monitoring tightened this year. Visa folded several older programs into a single acquirer monitoring framework built on a ratio of combined fraud and dispute counts divided by settled transactions. From 1 January 2026, acquirers were expected to hold that ratio below 0.5%, with penalties applied per transaction above the line. On 1 April 2026 the excessive threshold for merchants in the United States, Canada, the European Union and Asia-Pacific dropped from 2.2% to 1.5%, subject to a floor of 1,500 combined events a month. Mastercard runs separate programs with comparable intent.
The practical read is that a small number of poorly screened sub-merchants can pull an entire portfolio toward a threshold. Underwriting quality now functions as cost control. Automated underwriting tools that check owners against global sanctions lists and verify business details at signup reduce the number of accounts that later generate disputes, which is the same set of checks the automated flow runs before an approval is returned.
How Chargeback Liability Is Allocated
Under PayFac-as-a-Service the platform avoids the registration burden and capital requirements of operating its own facilitator entity. A facilitator holds a master merchant account and onboards sub-merchants beneath it, and the party holding that account answers for activity under it.
The split of chargeback and fraud liability between Finix and the platform is set in contract rather than by default. That leaves room to match terms to the risk profile of a specific merchant base. Two platforms on identical rails can hold different allocations depending on what each negotiated, so the contract section is worth reading alongside the pricing section.
What the Starter Plan Includes
PCI DSS obligations sit with the processor at Level 1, which removes the heaviest part of the security burden from the platform. Base fraud tools and PCI compliance are included from the Starter plan, priced near $250 per month. Service covers the United States and Canada.
The company reports 99.999% availability and more than 400 million transactions daily. Capterra shows a 4.7 rating across 42 reviews, with 4.8 for customer service, the highest of the rated categories.
Where the Stack Fits
The underwriting and risk stack suits platforms that want to set their own approval rules and can staff someone to act on returned decisions. Platforms that prefer a fixed path can run standard settings at the start and tighten the rules as their own dispute data builds. Compliance coverage and the Level 1 PCI position remove work from the platform side either way. The liability terms in the contract set out how chargeback allocation runs, and modeling a 1.5% dispute ratio across the intended merchant base shows what the underwriting settings are worth in practice.
To read more content like this, explore The Brand Hopper
Subscribe to our newsletter
