BlackOak

Compliance posture

Monitored against the published thresholds.

BlackOak is being designed as the merchant of record, which means the portfolio's conduct is BlackOak's conduct. That structure decides how onboarding, monitoring and reserves have to work — and it is why they are built the way they are.

Request early access
01

Merchant of record is a structure, not a label.

Because sub-merchants have no individual identifier of their own, dispute and monitoring ratios attribute at portfolio level. One participant's conduct is therefore everyone's exposure, which is the reason per-participant monitoring exists at all: it protects the whole book rather than policing a single account.

01

Rule-driven review, with the reasons shown

Applications are assessed against named rules rather than an opaque score, and an applicant sees every trigger with its own value. Automatic decline is reserved for four hard gates — a sanctions match, a prohibited category, a confirmed synthetic identity, and a fraud listing. Everything else reaches a human.

02

Ownership to the standard, not to a guess

Beneficial ownership is collected to the 25% threshold with a named control person, and percentages must reconcile. Non-documentary verification is used where it is permitted and held to the same standard for owners as for applicants, with document capture as a step-up rather than a default.

03

Network programs, watched daily

Visa's VAMP and Mastercard's Excessive Chargeback program both publish their thresholds and both report about a month late. The design is to carry BlackOak's own daily estimate beside the network's own figure, so a participant learns where they stand before the network tells them.

04

Reserves from exposure, with notice

A reserve is computed from measured exposure — delivery lag, dispute and return history, refund rate, concentration, and time on book — rather than from a category label. Each input is shown with the participant's own current value, and a material change carries advance notice naming the input that moved.

The programs and rules in scope

Card network monitoring
Visa VAMP · Mastercard ECM
Customer due diligence
31 CFR 1020.220 · 1010.230
Beneficial ownership
25% threshold plus control person
Credit bureau inquiry
None in the application
Consent and signature
E-Sign, separately authorized

Two halves of
one program.

Compliance decides what BlackOak is obliged to collect and monitor. Security decides what happens to it afterwards, and who is able to see it.

Diligence · Partners · Program sponsors

Ask the harder questions.

If you are assessing BlackOak as a bank, network, processor, or program sponsor, the useful conversation is the specific one. Start it and we will bring the detail this page deliberately does not publish.

Start a diligence conversation