Published by Capital Insight Ltd · Nicosia Herausgegeben von Capital Insight Ltd · Nikosia
The Banking Dossier
Regulation

The sales channel is registered. It is not published.

Der Vertriebskanal ist registriert. Veröffentlicht ist er nicht.

The company that sells a shop its card acceptance, trains its staff, prints its statements and collects its fees is, in the card networks’ own documents, an agent of somebody else. It must be registered before it may do any of that. The register is not public. Mastercard’s own category table shows why: the one merchant-facing category is one of only two that carries “N/A” where every other category carries a data-security validation requirement — and the monthly list Mastercard does publish is built entirely out of those validations. Registration exists. Publication does not follow from it. The two are not the same thing, and almost the entire distribution layer of card acceptance lives in the gap between them.

What an ISO is, in the networks’ own words

Visa set the definitions out in a document of its own, “Beyond the Acquirer: Additional Visa Acceptance Entities”, dated 15 February 2024. An Independent Sales Organisation, it says, is engaged by acquirers for “seller account or transaction processing solicitation, sales, customer service, seller training activities or solicitation and sales of POS terminals, mPOS devices or other acquirer acceptance solutions.” Then the sentence that decides everything downstream: “ISOs operate as agents on behalf of acquirers, meaning that when sellers sign services contracts with an ISO they are signing with the acquirer.”

The limits are equally explicit. ISOs “do not process transactions, receive settlement funds, nor do they have access to the seller’s customer’s data or the transaction processing environment.” An entity that does process transactions is reclassified as a Third Party Servicer. One that contracts directly with the merchant rather than through the acquirer becomes a Merchant Servicer — and here Visa’s own comparison table produces an oddity worth pausing on. A Merchant Servicer has no contract with the acquirer at all, yet still requires “Registration & Approval with Visa”, and the duty to disclose its existence is placed on the shop: “sellers must inform their acquirer of Merchant Servicers that they have contracted with.” The acquirer registers a company it has never contracted with, on the strength of what the merchant tells it.

Over all of this Visa places a single liability rule: “the acquirer remains responsible for the acts and obligations of not only sellers, but any other entities operating between or on behalf of the acquirer and seller.” Nothing in that sentence is soft. It is the load-bearing beam of the whole arrangement, and it is the reason the arrangement can function at all without the intermediaries being licensed in their own right.

The category with nothing to validate

Mastercard’s equivalent document, “Service Provider Categories and PCI” (dated 30 January 2019), sets out ten service-provider categories in a grid. Under Independent Sales Organisation it lists the “Program Service” content: cardholder and/or merchant solicitation including application processing; customer service “not affording access to account data, transaction data, or both, including the collection of any fee or other obligation associated with the customer’s program”; statement preparation; merchant education and training; terminal deployment; and “any other service determined by Mastercard in its sole discretion to be ISO Program Service.”

That is the entire commercial relationship as a small shop experiences it — who sold to it, who answers the phone, who explains the statement, who takes the money. Two rows down, the grid asks whether the category “Must be registered by a Mastercard customer”. For the ISO: Yes. The next row asks whether it “Must validate compliance with the PCI DSS”. For the ISO: N/A. Of the ten categories in the table, exactly two carry N/A there — the ISO and the Merchant Monitoring Service Provider. Every other one carries a validation obligation, most of them with an annual on-site assessment by a Qualified Security Assessor.

Taken on its own, that is defensible and probably correct. An ISO does not touch cardholder data; validating it against a cardholder-data standard would validate nothing. But the same document explains what the public list is made of: “To be listed on The Mastercard SDP Compliant Registered Service Provider List, updated monthly, a Service Provider must have been registered by one or more Mastercard customers and have submitted a fully executed copy of their AOC by a QSA reflecting validation of PCI compliance.” An ISO has no AOC to submit. It therefore cannot appear on the list, not because anyone decided to hide it, but because the list was built on a criterion the category is exempt from. The merchant-facing layer is invisible on the public register as a by-product of a scoping decision made about encryption.

The duty to check, given to the party who cannot

Visa’s document ends its registration section with two sentences in sequence. “Visa clients must ensure that all entities are registered with Visa as outlined in the Visa Rules. Sellers must ensure the service providers they use are registered by their Visa acquirer.”

The second sentence transfers a verification duty to the shop. The register against which the shop would verify is held by Visa and by the acquirer; the shop’s route to it is to ask the acquirer, which is to say, to ask the counterparty of the company it is checking. This is the same structural shape as a rule that binds payees while supervision watches banks: the obligation is placed on one party and the machinery to discharge it sits with another. The difference is that in the IBAN case there is at least a supervisor in the picture. Here there is a contract and a private list.

European law runs the sequence the other way

Directive (EU) 2015/2366 handles the same problem — a licensed firm distributing through unlicensed intermediaries — and reaches the opposite arrangement on every point that matters.

Article 19(1) requires a payment institution that intends to use an agent to give the competent authority the agent’s name and address, a description of its internal anti-money-laundering controls, the identity of its directors with evidence that they are “fit and proper persons”, the services the agent is mandated for, and the agent’s identification code. Article 19(2) then fixes the order of operations: the authority tells the institution whether the agent has been entered in the register, and “Upon entry in the register, the agent may commence providing payment services.” Registration precedes trading, and the register is the public one under Article 14, feeding the EBA’s central register under Article 15.

Article 19(7) adds the disclosure that the card rules never require: “Payment institutions shall ensure that agents or branches acting on their behalf inform payment service users of this fact.” The user is entitled to know that the entity in front of them is an agent. And Article 20(2) carries the liability in almost the same words Visa uses: Member States “shall require that payment institutions remain fully liable for any acts of their employees, or any agent, branch or entity to which activities are outsourced.”

So Europe has identical unlimited principal liability and, on top of it, public registration and a disclosure duty. The EBA’s own register page lists nine categories of person it covers, and “Agents” as legally defined in Article 4(38) is the sixth of them; the whole register can be searched or downloaded free of charge. It also carries a disclaimer worth reading twice: the register “has no legal significance and confers no rights in law”, and responsibility for accuracy “lies with the competent authorities at national level”. The public list disclaims legal effect. The private network list decides whether a company may trade next week. Both statements are true at the same time.

Where a supervisor does publish the channel, the numbers are unflattering

No supervisor publishes a count of card ISOs. One publishes a count of a comparable delegated population, and it is worth using precisely because it is the only one that exists. The UK Financial Conduct Authority’s appointed representatives data page, last updated 5 June 2026 and refreshed every six months from principals’ own Add/Change/Terminate forms and REP025 returns, reports that at the end of March 2026 there were 2,431 principals and 33,347 appointed representatives — 20,728 full ARs and 12,619 introducer ARs. Against March 2025 that is 137 fewer principals (down 5.3 per cent) and 224 fewer ARs (down 0.7 per cent).

From the FCA’s own figures and its own stated changes, the March 2025 population was 2,568 principals and 33,571 ARs. That gives, as my own calculation, 13.7 appointed representatives per principal in 2026 against 13.1 a year earlier. One authorised firm, thirteen or fourteen faces the customer actually meets.

The revenue split is the part that should be quoted more often than it is. The FCA reports that in calendar 2025 ARs generated around £13.1bn in regulated financial services revenue, £0.9bn more than in 2024, up 7.3 per cent. It reports in the next paragraph that ARs also generated around £24.5bn in non-regulated financial services revenue — £8bn from wholesale markets ARs, £9.3bn from general insurance and protection, £3.7bn from consumer finance. My own arithmetic on those two published figures: of the £37.6bn the delegated population earns in financial services, 65 per cent sits outside the regulated perimeter. The supervisor collects the number and publishes it. It does not supervise the larger half of it.

A second calculation from the same page: regulated revenue per AR rose from roughly £363,000 in 2024 to roughly £393,000 in 2025, up 8.1 per cent, while the AR count fell. The FCA draws the same conclusion in its own words — “a greater concentration of regulated activity among a smaller number of AR-principal relationships.”

The government’s own description of the gap

On 12 February 2026 HM Treasury opened a consultation on reforming the AR regime, closing on 9 April 2026. I have not read the consultation document itself; what follows is reported consistently by several law firms writing on it, and should be treated as their account rather than as the text. The central proposal is a new permission for acting as a principal, on the reasoning that firms can today act as principals and appoint representatives with no additional authorisation to do so. Existing principals would be deemed to hold the permission, which the FCA could then vary or withdraw. The consultation is also reported to propose extending the Financial Ombudsman Service’s jurisdiction to ARs directly in some circumstances and bringing ARs within the Senior Managers and Certification Regime.

Strip the mechanics away and a government has written down, forty years into the regime, that the right to appoint a distribution network was never itself authorised. That is the same gap the card networks fill with a private registration — except that in the UK case somebody has now named it.

What it looks like when the channel fails

Three United States enforcement actions in fifteen months show where the liability lands when merchants onboarded through this layer turn out to be fraudulent.

On 4 September 2026 the Federal Trade Commission announced that Nuvei Corporation and four subsidiaries would pay $4.85m to settle allegations that they opened and maintained accounts for merchants they knew or should have known were deceptive. The FTC’s complaint alleges Nuvei processed more than $30m in consumer payments for Reimage, an offshore tech-support scheme, between 2017 and 2023, and that it furnished accounts to overseas schemes “through its merchant acquiring bank registered in Cyprus”. The order bans tech-support processing, prohibits “tactics to avoid fraud or risk monitoring programs established by banks or credit card networks, including load balancing”, and requires enhanced investigation of clients above stated chargeback limits. The Commission vote was 2-0. My own comparison of the two published figures: the payment is about 16 per cent of the volume the FTC attributes to a single named scheme — and that scheme is one of several the complaint lists.

Four days later the FTC announced a proposed order against Humboldt Merchant Services requiring $12m and a permanent ban on processing for four categories of merchant. The complaint alleges Humboldt processed for more than 1,000 shell entities fronting for fraudulent companies, opened those accounts despite red flags, and that the accounts “typically incurred chargebacks at rates that were almost 10 times higher than what credit card brands view as excessive”. It further alleges Humboldt moved those accounts onto a lower-risk bank identification number used by an affiliated entity to raise approval rates. In June 2025 the FTC had settled with Paddle for $5m over its merchant-of-record platform, in the same Reimage matter.

Every one of those orders binds a sponsor. None of the press releases names the sales agent who found and signed those merchants, and no public register would let a reader find out. That is not an allegation that agents were at fault in these cases; it is an observation that the question is unanswerable from outside, by construction.

The case for the arrangement, at its strongest

The argument for leaving the channel unpublished is better than it first sounds, and Visa makes most of it in the same document. Intermediaries “reduce the cost of onboarding small/long-tail sellers or those with unique needs”, “broaden the number and type of sellers eligible for electronic payment acceptance, away from cash or checks”, and “offer cost-effective electronic payment acceptance for small retailers”. A bank that had to originate every corner shop itself would not originate corner shops. The economics of what an acquirer actually earns on a small merchant do not support a direct salesforce, and the real price of a payment licence is time rather than capital — which is exactly why an agency model is the rational route to market rather than an evasion.

Single-point accountability is a feature and not an accident. One sponsor with unlimited liability is a better counterparty for an aggrieved merchant than fourteen thinly capitalised agents, and both PSD2 Article 20(2) and Visa’s acquirer-responsibility sentence are designed to make sure the merchant never has to chase the small company. A published list of every sales agent would also be a ready-made target list — for competitors poaching portfolios, and for fraudsters impersonating a name the merchant has been told to trust. And the PCI exemption really is correct scoping: validating a company against a cardholder-data standard it never touches would produce a certificate that means nothing.

None of which requires the count to be unavailable. How many ISOs each acquirer has registered, how many registrations were refused, how many terminated and under which of the networks’ own grounds — none of that discloses cardholder data, and none of it is a trade secret worth the name. The absence is not a position anyone has defended in public. It has simply never been asked for, and the machinery that would answer it already exists inside every acquirer’s registration file.

What this does not tell you

First, there is no causal claim here. I cannot show that an unpublished channel produces more merchant fraud than a published one, because the denominator does not exist in either direction. The FTC orders name sponsors, so the channel’s share of those failures is unmeasured, not small.

Second, the two populations are not the same. The FCA’s appointed representatives are insurance, consumer finance and investment intermediaries, not card ISOs. I use them because they are the only delegated distribution population a supervisor publishes at all — which is itself the finding — and not because a general insurance AR and a payments ISO are interchangeable. The 65 per cent figure describes ARs, and nothing else.

Third, several sources here were not read in the original. Visa’s rulebook is not what I read: “Beyond the Acquirer” is Visa’s own explanatory document and says so, stating that “In the event of any conflict, the Visa Rules govern.” Mastercard’s category table is dated 30 January 2019 and may since have been superseded. HM Treasury’s consultation is taken entirely from law-firm reporting. And I could not establish a European agent count: the EBA register is downloadable but behind a click-through I did not complete, so no EU-wide number appears above — where the figure would have been most useful, there is a gap, and it is mine rather than the register’s.

Three answers to one question

The industry has three different mechanisms for saying who a company is, and they were built for different purposes by parties who never had to reconcile them. A licence is public, attaches to the entity, and travels. A registration is private, attaches to a relationship, and can be revoked by one side. A sponsorship is a contract, is invisible from outside, and is the only one of the three that determines whether a business can accept a card tomorrow morning.

Almost everything a merchant experiences is governed by the third. Almost every reform of the last decade has improved the first. The same pattern has shown up in this publication before — the terminal turning from a device with a certification date into a permission granted continuously by a background service — and it has the same signature each time: the thing that actually controls access stops being a published status and becomes a private, revocable, continuously re-issued decision, while the statistics keep counting the published status.

Liability without visibility is not a scandal. It is a design, and a coherent one. But it has a predictable consequence: when the cheapest thing on the market is someone else’s permission, the market will buy a great deal of it, and nobody outside the contract will be able to say how much.

Das Unternehmen, das einem Laden die Kartenannahme verkauft, sein Personal schult, seine Abrechnungen aufbereitet und seine Entgelte einzieht, ist nach den eigenen Unterlagen der Kartennetze der Vertreter eines anderen. Registriert sein muss es, bevor es irgendetwas davon tun darf. Das Register ist nicht öffentlich. Mastercards eigene Kategorientabelle zeigt, warum: die einzige händlerzugewandte Kategorie ist eine von nur zweien, die dort „N/A” trägt, wo jede andere eine Datensicherheitsprüfung verlangt — und die Liste, die Mastercard monatlich veröffentlicht, besteht ausschließlich aus diesen Prüfungen. Die Registrierung gibt es. Die Veröffentlichung folgt daraus nicht. Und in der Lücke zwischen beidem sitzt fast die gesamte Vertriebsschicht der Kartenannahme.

Was ein ISO ist, in den Worten der Netze selbst

Visa hat die Begriffe in einem eigenen Papier festgehalten: „Beyond the Acquirer: Additional Visa Acceptance Entities” vom 15. Februar 2024. Eine Independent Sales Organisation, heißt es dort, wird von Acquirern eingesetzt für „seller account or transaction processing solicitation, sales, customer service, seller training activities or solicitation and sales of POS terminals”. Dann der Satz, an dem alles Weitere hängt: „ISOs operate as agents on behalf of acquirers, meaning that when sellers sign services contracts with an ISO they are signing with the acquirer.” Wer beim Vertriebspartner unterschreibt, unterschreibt beim Acquirer.

Die Grenzen sind ebenso deutlich. ISOs wickeln keine Zahlungen ab, erhalten kein Abrechnungsgeld und haben keinen Zugang zu den Kundendaten des Händlers oder zur Verarbeitungsumgebung. Wer Transaktionen verarbeitet, wird als Third Party Servicer geführt. Wer direkt mit dem Händler kontrahiert statt über den Acquirer, wird zum Merchant Servicer — und hier produziert Visas eigene Vergleichstabelle eine Merkwürdigkeit. Ein Merchant Servicer hat überhaupt keinen Vertrag mit dem Acquirer, braucht aber trotzdem „Registration & Approval with Visa”, und die Pflicht, ihn überhaupt zu erwähnen, liegt beim Laden: „sellers must inform their acquirer of Merchant Servicers that they have contracted with.” Der Acquirer registriert also ein Unternehmen, mit dem er nie einen Vertrag geschlossen hat, auf Grundlage dessen, was der Händler ihm erzählt.

Über allem steht eine einzige Haftungsregel: „the acquirer remains responsible for the acts and obligations of not only sellers, but any other entities operating between or on behalf of the acquirer and seller.” Daran ist nichts weich formuliert. Es ist der tragende Balken der ganzen Konstruktion und der Grund, warum sie funktionieren kann, ohne dass die Zwischenhändler selbst eine Erlaubnis brauchen.

Die Kategorie, an der es nichts zu prüfen gibt

Mastercards Gegenstück, „Service Provider Categories and PCI” vom 30. Januar 2019, ordnet zehn Dienstleisterkategorien in einem Raster. Unter Independent Sales Organisation steht, was die Kategorie umfasst: Anwerbung von Karteninhabern und Händlern einschließlich Antragsbearbeitung; Kundenbetreuung ohne Zugriff auf Konto- oder Transaktionsdaten, „including the collection of any fee or other obligation associated with the customer’s program”; Aufbereitung von Abrechnungen; Schulung und Ausbildung von Händlern; Terminalaufstellung; und „any other service determined by Mastercard in its sole discretion to be ISO Program Service.”

Das ist die gesamte Geschäftsbeziehung, so wie ein kleiner Laden sie erlebt: wer verkauft hat, wer ans Telefon geht, wer die Abrechnung erklärt, wer das Geld einzieht. Zwei Zeilen tiefer fragt das Raster, ob die Kategorie von einem Mastercard-Kunden registriert werden muss. Beim ISO: ja. Die nächste Zeile fragt, ob sie die Einhaltung des PCI DSS nachweisen muss. Beim ISO: N/A. Von zehn Kategorien tragen dort genau zwei ein N/A — der ISO und der Merchant Monitoring Service Provider. Alle übrigen tragen eine Nachweispflicht, die meisten mit jährlicher Vor-Ort-Prüfung durch einen zugelassenen Prüfer.

Für sich genommen ist das vertretbar und vermutlich richtig. Ein ISO fasst keine Karteninhaberdaten an; ihn gegen einen Karteninhaberdaten-Standard zu prüfen, würde nichts prüfen. Nur erklärt dasselbe Dokument, woraus die öffentliche Liste besteht: Um auf der monatlich aktualisierten „SDP Compliant Registered Service Provider List” zu stehen, muss ein Dienstleister registriert sein und eine von einem Prüfer unterzeichnete Konformitätsbescheinigung eingereicht haben. Ein ISO hat keine, die er einreichen könnte. Er kann auf der Liste also gar nicht erscheinen — nicht weil jemand ihn verbergen wollte, sondern weil die Liste auf einem Kriterium aufbaut, von dem die Kategorie befreit ist. Die händlerzugewandte Schicht ist im öffentlichen Verzeichnis unsichtbar, als Nebenwirkung einer Entscheidung über Verschlüsselung.

Die Prüfpflicht liegt bei dem, der sie nicht erfüllen kann

Visas Papier beendet seinen Registrierungsabschnitt mit zwei aufeinanderfolgenden Sätzen. „Visa clients must ensure that all entities are registered with Visa as outlined in the Visa Rules. Sellers must ensure the service providers they use are registered by their Visa acquirer.”

Der zweite Satz schiebt eine Prüfpflicht zum Laden. Das Register, gegen das der Laden prüfen müsste, liegt bei Visa und beim Acquirer; sein Weg dorthin führt über den Acquirer — also über die Vertragspartei genau des Unternehmens, das er prüfen soll. Das ist dieselbe Bauform wie bei einer Regel, die den Zahlungsempfänger bindet, während die Aufsicht die Banken beobachtet: die Pflicht liegt bei der einen Partei, das Werkzeug zu ihrer Erfüllung bei der anderen. Der Unterschied ist, dass es im IBAN-Fall wenigstens eine Aufsicht gibt. Hier gibt es einen Vertrag und eine private Liste.

Das europäische Recht dreht die Reihenfolge um

Die Richtlinie (EU) 2015/2366 behandelt dasselbe Problem — ein zugelassenes Unternehmen vertreibt über nicht zugelassene Vermittler — und kommt in jedem Punkt, auf den es ankommt, zum Gegenteil.

Artikel 19 Absatz 1 verlangt von einem Zahlungsinstitut, das einen Agenten einsetzen will, gegenüber der zuständigen Behörde: Name und Anschrift des Agenten, eine Beschreibung seiner internen Kontrollmechanismen gegen Geldwäsche, die Identität seiner Geschäftsleiter samt Nachweis, dass sie „fit and proper persons” sind, die Dienste, für die er beauftragt ist, und seine Kennnummer. Artikel 19 Absatz 2 legt dann die Reihenfolge fest: Die Behörde teilt mit, ob der Agent in das Register nach Artikel 14 eingetragen wurde, und „upon entry in the register, the agent may commence providing payment services.” Die Eintragung kommt vor dem Geschäft, und das Register ist das öffentliche, das über Artikel 15 in das Zentralregister der EBA einfließt.

Artikel 19 Absatz 7 fügt die Offenlegung hinzu, die die Kartenregeln nirgends verlangen: Zahlungsinstitute müssen sicherstellen, „that agents or branches acting on their behalf inform payment service users of this fact.” Der Nutzer hat ein Recht darauf zu erfahren, dass sein Gegenüber ein Vertreter ist. Und Artikel 20 Absatz 2 trägt die Haftung in fast denselben Worten wie Visa: Die Mitgliedstaaten schreiben vor, dass Zahlungsinstitute „remain fully liable for any acts of their employees, or any agent, branch or entity to which activities are outsourced.”

Europa hat also dieselbe unbegrenzte Haftung des Auftraggebers und darüber hinaus die öffentliche Eintragung und eine Offenlegungspflicht. Die Registerseite der EBA nennt neun Personenkategorien, „Agenten” im Sinne von Artikel 4 Nummer 38 sind die sechste; das gesamte Register lässt sich kostenlos durchsuchen und herunterladen. Sie trägt auch einen Vorbehalt, den man zweimal lesen sollte: Das Register habe „no legal significance and confers no rights in law”, und die Verantwortung für die Richtigkeit liege bei den nationalen Behörden. Die öffentliche Liste bestreitet ihre eigene Rechtswirkung. Die private Netzliste entscheidet, ob ein Unternehmen nächste Woche noch Geschäfte machen darf. Beides stimmt gleichzeitig.

Wo eine Aufsicht den Kanal doch veröffentlicht

Niemand veröffentlicht, wie viele Karten-ISOs es gibt. Eine einzige Aufsicht veröffentlicht die Zahl einer vergleichbaren Vertreterpopulation, und man sollte sie gerade deshalb benutzen, weil es die einzige ist, die es gibt. Die britische Financial Conduct Authority hat ihre Datenseite zu den Appointed Representatives am 5. Juni 2026 aktualisiert; sie wird halbjährlich aus den Meldeformularen der Auftraggeber und den REP025-Meldungen gespeist. Ende März 2026 gab es danach 2.431 Auftraggeber und 33.347 Vertreter — 20.728 mit vollem Umfang, 12.619 reine Vermittler. Gegenüber März 2025 sind das 137 Auftraggeber weniger (minus 5,3 Prozent) und 224 Vertreter weniger (minus 0,7 Prozent).

Aus den Zahlen der Aufsicht und ihren eigenen Veränderungsangaben ergibt sich für März 2025 eine Population von 2.568 Auftraggebern und 33.571 Vertretern. Das macht, als eigene Rechnung, 13,7 Vertreter je Auftraggeber im Jahr 2026 gegenüber 13,1 ein Jahr zuvor. Ein zugelassenes Unternehmen, dreizehn oder vierzehn Gesichter, die der Kunde tatsächlich zu sehen bekommt.

Die Aufteilung der Erlöse ist der Teil, der öfter zitiert werden sollte. Die Aufsicht berichtet, dass die Vertreter im Kalenderjahr 2025 rund 13,1 Mrd. Pfund an Erlösen aus regulierten Finanzdienstleistungen erzielt haben, 0,9 Mrd. mehr als 2024, ein Plus von 7,3 Prozent. Im nächsten Absatz berichtet sie, dass dieselben Vertreter rund 24,5 Mrd. Pfund aus nicht regulierten Finanzdienstleistungen erzielten — 8 Mrd. aus dem Großkundengeschäft, 9,3 Mrd. aus Sach- und Personenversicherung, 3,7 Mrd. aus Verbraucherfinanzierung. Meine eigene Rechnung aus diesen beiden veröffentlichten Werten: Von den 37,6 Mrd. Pfund, die die Vertreterpopulation im Finanzgeschäft verdient, liegen 65 Prozent außerhalb des regulierten Bereichs. Die Aufsicht erhebt die Zahl und veröffentlicht sie. Beaufsichtigt wird die größere Hälfte nicht.

Eine zweite Rechnung aus derselben Quelle: Der regulierte Erlös je Vertreter stieg von rund 363.000 Pfund (2024) auf rund 393.000 Pfund (2025), ein Plus von 8,1 Prozent, während die Zahl der Vertreter sank. Die Aufsicht zieht denselben Schluss mit eigenen Worten und spricht von einer stärkeren Konzentration regulierter Tätigkeit auf weniger Beziehungen.

Die Regierung beschreibt die Lücke selbst

Am 12. Februar 2026 hat das britische Finanzministerium eine Konsultation zur Reform dieses Regimes eröffnet, Frist bis zum 9. April 2026. Ich habe das Konsultationspapier nicht im Original gelesen; was folgt, berichten mehrere Kanzleien übereinstimmend, und es ist als deren Wiedergabe zu behandeln, nicht als Text. Kern des Vorschlags ist eine eigene Erlaubnis für das Auftreten als Auftraggeber — mit der Begründung, dass Unternehmen heute Vertreter bestellen können, ohne dafür eine zusätzliche Zulassung zu brauchen. Bestehende Auftraggeber sollen die Erlaubnis als erteilt gelten lassen dürfen, die Aufsicht sie aber ändern oder entziehen können. Berichtet werden außerdem eine Ausweitung der Ombudsstelle auf die Vertreter selbst und die Einbeziehung in das Regime für Führungskräfte.

Lässt man die Mechanik weg, hat eine Regierung vierzig Jahre nach Einführung des Regimes aufgeschrieben, dass das Recht, ein Vertriebsnetz zu bestellen, selbst nie genehmigungspflichtig war. Es ist dieselbe Lücke, die die Kartennetze mit einer privaten Registrierung füllen — nur dass sie im britischen Fall jetzt jemand benannt hat.

Wie es aussieht, wenn der Kanal versagt

Drei amerikanische Verfahren aus fünfzehn Monaten zeigen, wo die Haftung landet, wenn über diese Schicht angebundene Händler sich als betrügerisch erweisen.

Am 4. September 2026 teilte die Federal Trade Commission mit, dass Nuvei Corporation und vier Tochtergesellschaften 4,85 Mio. Dollar zahlen, um Vorwürfe beizulegen, sie hätten Konten für Händler eröffnet und geführt, von deren Täuschung sie wussten oder hätten wissen müssen. Die Klageschrift wirft Nuvei vor, zwischen 2017 und 2023 mehr als 30 Mio. Dollar an Verbraucherzahlungen für Reimage abgewickelt zu haben, ein im Ausland ansässiges Schema angeblicher technischer Hilfe, und Konten „through its merchant acquiring bank registered in Cyprus” bereitgestellt zu haben. Die Anordnung verbietet die Abwicklung für diesen Sektor, untersagt Techniken zur Umgehung der Risikoüberwachung von Banken und Kartennetzen einschließlich der Lastverteilung auf mehrere Konten und verlangt vertiefte Prüfung oberhalb festgelegter Rückbelastungsgrenzen. Die Kommission stimmte mit 2 zu 0. Mein eigener Vergleich der beiden veröffentlichten Zahlen: Die Zahlung entspricht rund 16 Prozent des Volumens, das die Behörde einem einzigen benannten Schema zuordnet — und die Klageschrift führt mehrere auf.

Vier Tage später kündigte dieselbe Behörde eine Anordnung gegen Humboldt Merchant Services an: 12 Mio. Dollar und ein dauerhaftes Verbot, für vier Händlerkategorien abzuwickeln. Humboldt soll für mehr als 1.000 Briefkastenfirmen abgewickelt haben, die als Fassade betrügerischer Unternehmen dienten, und die Konten trotz Warnzeichen eröffnet haben; sie hätten typischerweise Rückbelastungen „at rates that were almost 10 times higher than what credit card brands view as excessive” verursacht. Weiter soll Humboldt diese Konten auf eine als risikoärmer geltende Bankkennung eines verbundenen Unternehmens umgezogen haben, um die Genehmigungsquote zu heben. Im Juni 2025 hatte sich Paddle in derselben Reimage-Sache für 5 Mio. Dollar verglichen.

Jede dieser Anordnungen bindet einen Sponsor. Keine der Mitteilungen nennt den Vertriebspartner, der diese Händler gefunden und unterschrieben hat, und kein öffentliches Register würde einem Leser erlauben, es herauszufinden. Das ist kein Vorwurf gegen Vertriebspartner in diesen Fällen; es ist die Feststellung, dass die Frage von außen konstruktionsbedingt unbeantwortbar ist.

Die Gegenseite, in ihrer stärksten Form

Das Argument für einen unveröffentlichten Kanal ist besser, als es zunächst klingt, und Visa trägt es in demselben Papier größtenteils selbst vor. Zwischenhändler senken die Kosten, kleine Händler und Nischenanbieter anzubinden, erweitern den Kreis derer, die überhaupt elektronisch annehmen können, „away from cash or checks”, und bieten kleinen Einzelhändlern eine bezahlbare Annahme. Eine Bank, die jeden Kiosk selbst gewinnen müsste, würde keine Kioske gewinnen. Die Rechnung dahinter, was ein Acquirer an einem kleinen Händler tatsächlich verdient, trägt keinen eigenen Außendienst, und der wahre Preis einer Zahlungslizenz ist Zeit, nicht Kapital — genau deshalb ist das Vertretermodell der vernünftige Marktzugang und keine Umgehung.

Dass die Haftung an einer einzigen Stelle gebündelt ist, ist eine Eigenschaft und kein Versehen. Ein Sponsor mit unbegrenzter Haftung ist für einen geschädigten Händler ein besserer Gegner als vierzehn dünn kapitalisierte Vertreter, und sowohl Artikel 20 Absatz 2 als auch Visas Haftungssatz sind gerade dazu da, dem Händler die Jagd auf die kleine Firma zu ersparen. Eine veröffentlichte Liste aller Vertriebspartner wäre außerdem eine fertige Zielliste — für Wettbewerber, die Portfolios abwerben, und für Betrüger, die sich als ein Name ausgeben, dem der Händler vertrauen soll. Und die PCI-Befreiung ist tatsächlich sauber abgegrenzt: Ein Unternehmen gegen einen Standard zu prüfen, dessen Gegenstand es nie berührt, brächte eine Bescheinigung ohne Aussage.

Nichts davon verlangt allerdings, dass die Anzahl unbekannt bleibt. Wie viele Vertriebspartner ein Acquirer registriert hat, wie viele Registrierungen abgelehnt und wie viele aus welchem der netzeigenen Gründe beendet wurden — nichts davon offenbart Karteninhaberdaten, und nichts davon ist ein Geschäftsgeheimnis von Gewicht. Das Fehlen ist keine Position, die jemand öffentlich verteidigt hätte. Es ist nur nie verlangt worden, und die Unterlagen, aus denen sich die Antwort ergäbe, liegen in jeder Registrierungsakte bereits vor.

Was daraus nicht folgt

Erstens wird hier keine Ursache behauptet. Ich kann nicht zeigen, dass ein unveröffentlichter Kanal mehr Händlerbetrug hervorbringt als ein veröffentlichter, weil der Nenner in beide Richtungen fehlt. Die amerikanischen Anordnungen benennen Sponsoren; der Anteil des Kanals an diesen Fällen ist damit nicht gemessen, nicht klein.

Zweitens sind die beiden Populationen nicht dieselben. Die britischen Vertreter sind Versicherungs-, Kredit- und Anlagevermittler, keine Karten-ISOs. Ich benutze sie, weil sie die einzige Vertreterpopulation sind, die eine Aufsicht überhaupt veröffentlicht — das ist der Befund selbst —, und nicht, weil ein Versicherungsvertreter und ein Zahlungsvertrieb austauschbar wären. Die 65 Prozent beschreiben die britischen Vertreter und sonst nichts.

Drittens sind mehrere Quellen nicht im Original gelesen. Visas Regelwerk habe ich nicht gelesen: „Beyond the Acquirer” ist Visas eigenes Erläuterungspapier und sagt das auch — bei Widersprüchen gelten die Visa Rules. Mastercards Kategorientabelle trägt das Datum 30. Januar 2019 und kann überholt sein. Die britische Konsultation stammt vollständig aus Kanzleiberichten. Und eine europäische Agentenzahl konnte ich nicht belegen: Das EBA-Register ist herunterladbar, aber hinter einer Bestätigungsseite, die ich nicht durchlaufen habe — dort, wo die Zahl am meisten genützt hätte, steht deshalb keine, und die Lücke gehört mir, nicht dem Register.

Drei Antworten auf eine Frage

Die Branche hat drei verschiedene Verfahren, um zu sagen, wer ein Unternehmen ist, und sie sind von Parteien gebaut worden, die sie nie miteinander abgleichen mussten. Eine Erlaubnis ist öffentlich, hängt am Unternehmen und reist mit. Eine Registrierung ist privat, hängt an einer Beziehung und kann von einer Seite widerrufen werden. Eine Sponsorschaft ist ein Vertrag, von außen unsichtbar, und die einzige der drei, die darüber entscheidet, ob morgen früh noch eine Karte angenommen werden kann.

Fast alles, was ein Händler erlebt, regelt die dritte. Fast jede Reform des letzten Jahrzehnts hat die erste verbessert. Dasselbe Muster ist an dieser Stelle schon einmal aufgetaucht — als aus dem Terminal mit Zulassungsdatum eine Erlaubnis wurde, die ein Hintergrunddienst laufend erteilt — und es hat jedes Mal dieselbe Signatur: Was den Zugang tatsächlich steuert, hört auf, ein veröffentlichter Status zu sein, und wird eine private, widerrufliche, fortlaufend neu erteilte Entscheidung, während die Statistik weiter den veröffentlichten Status zählt.

Haftung ohne Sichtbarkeit ist kein Skandal. Es ist ein Entwurf, und ein in sich schlüssiger. Aber er hat eine vorhersehbare Folge: Wenn das Billigste am Markt die Erlaubnis eines anderen ist, wird der Markt sehr viel davon kaufen — und niemand außerhalb des Vertrages wird sagen können, wie viel.