You may have a legitimate business, quality products, loyal customers, and a solid sales history. But when a payment processor or acquiring bank reviews your website, they are looking at something different.
They are looking for risk.
And sometimes, the things that make a website look risky aren’t obvious to the merchant.
A product description that goes a little too far. A missing refund policy. An outdated Certificate of Analysis. A product added after the account was approved. Even language that seems completely normal from a marketing perspective can create questions during a compliance review.
For businesses operating in regulated or higher-risk industries, your website isn’t just your storefront. It’s part of what processors and banks use to determine whether they are comfortable processing your transactions.
So, what exactly are they looking for?
Your Website and Your Merchant Account Are Connected
When a processor approves a merchant account, it isn’t simply approving the company behind it. It is also evaluating what the business sells and how those products are represented online.
That distinction matters.
A processor may review your website during onboarding, but the site can also be reviewed again after processing begins. Websites change constantly: new products are added, descriptions are rewritten, promotions are launched, and policies get updated.
Something that wasn’t present when the account was originally approved can therefore create risk later.
This is one reason website compliance should be treated as an ongoing part of payment processing rather than a task completed during onboarding.
1. Product Claims That Go Too Far
One of the fastest ways to attract compliance attention is through product claims.
Words such as “treat,” “cure,” “prevent,” “heal,” or “diagnose” can dramatically change how a product is represented.
The issue isn’t limited to obvious claims, either.
Processors may look at:
- Product names and descriptions
- Category names
- Images and graphics
- FAQs
- Blog content
- Customer testimonials
- Usage instructions
- Metadata and other website content
A merchant may carefully write compliant product descriptions while an older blog post, customer testimonial, or promotional banner tells a very different story.
From a risk perspective, processors can look at the website as a whole.
2. Products That Don’t Match the Approved Business
Processors want to understand what they are processing payments for.
If a merchant is approved to sell one category of products and the website suddenly begins offering something significantly different, that can create an immediate question:
Was this product part of the business the processor agreed to support?
This becomes especially important in industries where individual ingredients, product formats, or categories may have different compliance requirements.
Adding products to a website isn’t necessarily a problem. Adding products that fall outside the processor’s approved parameters can be.
For higher-risk merchants, product expansion should therefore include a compliance question alongside the commercial one:
Can my current processing program support this product?
3. Missing or Incomplete Website Policies
Processors aren’t only interested in your products.
They also want to understand how you operate.
A legitimate ecommerce website should make important business information easy to find. Depending on the business and processing program, reviewers may look for things such as:
- Terms and Conditions
- Privacy Policy
- Refund or Return Policy
- Shipping Policy
- Customer service information
- Business contact information
- Required disclaimers
Missing, contradictory, or extremely vague policies can make a website appear less transparent.
Even small inconsistencies matter. If one page says customers have 30 days to request a refund while another says all sales are final, that creates unnecessary uncertainty for both customers and reviewers.
4. Missing Age or Location Controls
For certain regulated product categories, who can purchase and where they are located matters.
A website may therefore require controls such as age verification, geographic restrictions, or product-specific purchasing rules.
Simply adding a disclaimer that says “must be 21+” may not always satisfy the requirements of a particular processor or program if the business is expected to actively restrict access or transactions.
The same applies to geographic restrictions.
If a product cannot be sold into a particular jurisdiction, the website should have controls appropriate to the merchant’s processing and compliance requirements rather than relying entirely on the customer to know the rules.
5. Certificates of Analysis That Are Missing or Outdated
For product categories where Certificates of Analysis (COAs) are required, documentation can become an important part of website compliance.
A processor or compliance reviewer may need to confirm that the documentation corresponds with the products being sold and meets the requirements of the processing program.
Problems can arise when COAs are:
- Missing
- Expired or outdated
- Difficult to locate
- Associated with the wrong product
- Missing required testing information
- Inconsistent with the product shown on the website
The important point is that uploading a COA once doesn’t necessarily solve the problem forever.
Products, batches, testing requirements, and documents change. Documentation needs to remain current.
6. Marketing and Compliance Tell Different Stories
This is a surprisingly common problem.
The compliance language says one thing.
The marketing says another.
A disclaimer might carefully explain the intended purpose of a product, while the headline above it strongly implies a different use. A product description may be conservative, while a testimonial makes a claim the merchant would never put in the description itself.
Processors aren’t required to evaluate each sentence in isolation.
They may consider the overall impression created by the website.
This is why compliance shouldn’t live exclusively in the footer or Terms and Conditions. It needs to be consistent with the way products are actually presented.
7. A Website That Changed After Approval
Here’s one of the biggest misconceptions about payment compliance:
“The processor already approved my website.”
Yes—but which version?
The website reviewed six months ago may not resemble the website operating today.
Since approval, the merchant may have:
- Added new products
- Changed product descriptions
- Created new categories
- Published new blogs
- Added customer testimonials
- Changed suppliers
- Updated packaging
- Launched new marketing campaigns
Every change can potentially introduce something that wasn’t part of the original review.
That’s why treating compliance as a one-time onboarding exercise creates unnecessary risk.
8. Trying to Hide What a Product Actually Is
Creative naming may be useful for branding. Using names specifically to disguise the nature of a restricted product is a very different issue.
Processors and acquiring banks need to understand what is actually being sold.
Renaming, abbreviating, miscategorizing, or otherwise presenting a product in a way intended to bypass compliance requirements can create significantly more concern than simply asking whether the product is permitted.
Transparency matters.
If you’re unsure whether a product is supported, check before listing it.
A “Risky” Website Isn’t Necessarily a Bad Business
This is an important distinction.
Compliance teams aren’t necessarily deciding whether your company is good or bad. They’re evaluating whether the business fits within the rules and risk parameters of a particular processing program.
A merchant can be operating in good faith and still have website issues.
In many cases, the problem is simply that ecommerce moves faster than compliance.
Marketing launches a new campaign. Purchasing adds a new supplier. Someone uploads a new product. An old COA expires. A freelancer rewrites a description.
Individually, these changes seem small.
Together, they can make the website the processor sees very different from the website that was originally approved.
The Best Time to Find a Compliance Problem Is Before Your Processor Does
Website compliance shouldn’t begin when an underwriter sends an email asking about a product.
It should happen as the website changes.
That means reviewing new products, keeping documentation current, maintaining required restrictions, checking website language, and making sure the business continues operating within the parameters of its processing program.
For regulated and higher-risk merchants, this isn’t just about passing an initial review.
It’s about keeping the merchant account supportable over time.
Where WAAVE Fits In
WAAVE was built around that reality.
Instead of treating website compliance as a checklist merchants complete once during onboarding, WAAVECompliance helps merchants maintain the controls required by their processing program as their business evolves.
From product and website reviews to COA management, age controls, geographic restrictions, and ongoing compliance requirements, WAAVE connects compliance with the payment environment rather than treating them as two separate problems.
Because getting approved for processing is only the beginning.
The real goal is staying compliant while your business grows.


