Payment Processor Accountability Under the Microscope
The Federal Trade Commission announced a $4.85 million settlement with payment processor Nuvei on September 5, 2026, marking a significant escalation in regulatory enforcement around merchant screening practices and fraud prevention obligations. The settlement alleges that Nuvei and its subsidiaries knowingly processed payments for merchants engaged in fraudulent activity, highlighting the expanding compliance burden on payment intermediaries and the businesses that rely on them.
This enforcement action arrives at a moment when the FTC Safeguards Rule and related consumer protection frameworks are receiving renewed attention. For small and mid-sized businesses—particularly those in financial services, e-commerce, and any sector handling payment processing—the Nuvei case offers critical lessons about due diligence, vendor risk management, and the regulatory expectations surrounding fraud prevention.
What the Nuvei Settlement Reveals About Compliance Expectations
The FTC's complaint centers on Nuvei's alleged failure to implement adequate merchant screening and monitoring practices. According to the agency, the company processed transactions for merchants the firm knew or should have known were engaged in deceptive or fraudulent practices. The $4.85 million penalty is accompanied by requirements for Nuvei to establish robust merchant vetting procedures going forward.
This settlement underscores several compliance principles that extend well beyond payment processors:
Know Your Business Partners
The FTC is holding intermediaries accountable for the conduct of the merchants they serve. This "know your customer" principle—long established in banking through Bank Secrecy Act and anti-money laundering regulations—is now being enforced more aggressively in the broader payment ecosystem. Businesses that accept payments through third-party processors should understand that their processor's compliance posture directly affects their own risk exposure.
Ongoing Monitoring, Not Just Onboarding
The allegations suggest Nuvei's failures were not limited to initial merchant screening but extended to ongoing transaction monitoring. Modern compliance frameworks increasingly require continuous risk assessment, not just point-in-time checks. This aligns with evolving requirements under PCI DSS 4.0, SOC 2, and the FTC Safeguards Rule itself, all of which emphasize continuous monitoring and regular risk reassessment.
Willful Blindness Is Not a Defense
The FTC's language—that Nuvei "knowingly" processed for fraudulent merchants—signals that regulators will not accept claims of ignorance when red flags are present. This principle applies across compliance frameworks: HIPAA, NYDFS Part 500, and the Gramm-Leach-Bliley Act all impose affirmative obligations to investigate and respond to indicators of potential violations.
The FTC Safeguards Rule: Current State and Enforcement Trends
The FTC Safeguards Rule, which applies to financial institutions under the agency's jurisdiction, underwent significant amendments that took full effect in June 2023. The updated rule requires covered institutions to:
- Designate a qualified individual to oversee the information security program
- Conduct periodic risk assessments
- Implement multi-factor authentication for any individual accessing customer information
- Encrypt customer information at rest and in transit
- Maintain an incident response plan
- Implement secure software development practices
- Conduct annual penetration testing and vulnerability assessments
The Nuvei settlement demonstrates that the FTC is moving beyond guidance and into active enforcement. Financial institutions, payment processors, and businesses that handle consumer financial data should expect heightened scrutiny of their security programs.
Cross-Framework Implications: When One Violation Triggers Multiple Exposures
The Nuvei case also illustrates how compliance failures in one area can create cascading liability across multiple frameworks. A payment processor that fails to screen merchants properly may face:
- FTC enforcement under Section 5 of the FTC Act and the Safeguards Rule
- PCI DSS violations if fraudulent transactions compromise cardholder data
- State-level enforcement under consumer protection statutes and data breach notification laws
- Civil litigation from affected consumers and business clients
- Reputational damage that affects customer trust and market position
For businesses subject to multiple frameworks—a healthcare provider that accepts credit cards (HIPAA + PCI DSS), a financial services firm operating in New York (NYDFS Part 500 + FTC Safeguards), or a defense contractor (CMMC + FTC)—the interconnected nature of these requirements means that a single control failure can trigger violations across the board.
Practical Action Steps for Small and Mid-Sized Businesses
Whether you're directly subject to the FTC Safeguards Rule or simply want to align with emerging regulatory expectations, here's what to prioritize:
Immediate Actions (Next 30 Days)
- Review your payment processing agreements. Understand what fraud monitoring and merchant screening your processor performs. If you're a merchant, ensure your processor's compliance program is robust. If you use a processor, verify they're meeting their obligations.
- Audit third-party vendor risk management. The Nuvei case is fundamentally about vendor accountability. Review your vendor risk assessment process for all critical service providers, especially those handling customer data or financial transactions.
- Document your information security program. If you haven't already designated a qualified individual to oversee information security, do so now. This is a hard requirement under the FTC Safeguards Rule and a best practice under virtually every other framework.
Medium-Term Priorities (Next 90 Days)
- Conduct or update your risk assessment. Identify where customer financial information flows through your systems, who has access, and what controls protect it. This assessment should inform your security roadmap.
- Implement or verify multi-factor authentication. MFA for any system accessing customer information is non-negotiable under the updated Safeguards Rule and is rapidly becoming table stakes across all frameworks.
- Schedule penetration testing and vulnerability assessments. Annual testing is required under the Safeguards Rule. Many organizations also need this for SOC 2, PCI DSS, and NYDFS Part 500 compliance.
Ongoing Compliance Practices
- Establish continuous monitoring. Move beyond annual assessments to ongoing log review, security information and event management (SIEM), and regular vulnerability scanning.
- Update incident response plans. The FTC expects covered entities to have documented, tested plans for responding to security events. Review and tabletop-test your plan at least annually.
- Train your team. Security awareness training should cover fraud indicators, social engineering tactics, and proper handling of customer information. Make it relevant to your staff's actual roles.
The Broader Regulatory Landscape in 2026
The Nuvei settlement doesn't exist in isolation. It's part of a broader trend of aggressive regulatory enforcement across cybersecurity and data protection:
- SEC cyber rules now require public companies to disclose material cybersecurity incidents within four business days and to provide annual disclosures about cyber risk management
- NYDFS Part 500 continues to evolve, with recent amendments strengthening requirements around governance, access controls, and incident response
- CMMC 2.0 implementation is proceeding for defense contractors, with certification requirements phasing in throughout 2026 and 2027
- State privacy laws continue to proliferate, with comprehensive frameworks now in effect in more than a dozen states
Businesses that take a reactive, compliance-checkbox approach are finding themselves exposed. The organizations that fare best treat security and compliance as integrated business functions, not afterthoughts.
Building a Resilient Compliance Posture
The lesson from the Nuvei settlement is clear: regulators expect businesses to take affirmative steps to prevent fraud and protect customer information, and they're willing to impose significant penalties when those steps are inadequate. For small and mid-sized businesses, this means investing in security controls, conducting regular assessments, and maintaining robust vendor management programs.
Compliance isn't about checking boxes—it's about building systems that actually reduce risk. When your security program is designed around real threats and genuine controls, regulatory compliance often follows naturally.
If your organization needs help navigating the FTC Safeguards Rule, conducting required penetration testing, or building a compliance program that spans multiple frameworks, Vici Tech Solutions can help you develop and implement a security posture that meets regulatory requirements and protects your business.