Merchant Audit
Pronunciation: MUR-chunt AW-dit
Definition
A merchant audit evaluates a merchant's records, controls, transactions, products, compliance, security, and fulfillment against defined criteria and scope. Merchant Audit provides bounded assurance rather than a permanent guarantee; conclusions apply only to the reviewed scope, criteria, configuration, evidence, and time period. Merchant Audit must define its objective, scope, criteria, system or control population, evidence period, test method, assessor independence, exceptions, and required remediation or reporting.
Overview
A merchant audit provides structured assurance about how a merchant operates and meets specified obligations. The scope may cover payment processing, financial records, customer treatment, refunds, fraud controls, licenses, data security, sanctions, or contractual requirements.
Auditors use documents, interviews, samples, analytics, system evidence, and transaction tracing. Conclusions are limited by the selected criteria, period, locations, evidence quality, and sampling, so an audit should not be generalized beyond its declared scope.
Providers should define objectives, preserve independence, document findings, assign remediation, and verify closure. Merchant changes in ownership, products, geography, processors, or risk can justify additional review before the next scheduled audit. Audit evidence should connect policy statements with actual transaction and customer outcomes.
For Merchant Audit, production scope should name the relevant customers, merchants, orders, credentials, payment instructions, balances, refunds, and settlement obligations, the decision being supported, the accountable owner, and the time and jurisdiction boundaries.
A merchant audit evaluates a merchant’s records, controls, transactions, products, compliance, security, and fulfillment against defined criteria and scope. Merchant Audit must define its objective, scope, criteria, system or control population, evidence period, test method, assessor independence, exceptions, and required remediation or reporting. A merchant audit provides scoped evidence at a point or period, not permanent proof that every activity remains compliant and controlled.
Implementation of Merchant Audit should map evaluation of a merchant’s records, controls, transactions, products, compliance, security, and fulfillment against defined criteria and scope to the applicable entity, product, customer, transaction, and jurisdictional scope. Evidence for merchant’s records, controls, and transactions should preserve the governing requirement, policy version, control execution, exception decision, owner, and review date. Material changes affecting the Merchant Audit context and merchant’s records, controls, and transactions should trigger reassessment instead of silent reuse of an outdated conclusion.
Key Takeaway
A merchant audit provides scoped evidence at a point or period, not permanent proof that every activity remains compliant and controlled.
Sources
- NIST Documentation: Cyberframework — NIST (2026-07-30)
- FATF Documentation: Virtual Assets — FATF (2026-07-30)