For many payment providers, a CBD merchant approved six months ago may look exactly the same today.
The website is still online. Processing volumes appear normal. Chargebacks remain within acceptable ranges.
On paper, nothing has changed.
In reality, everything may have changed.
One of the most common compliance blind spots in high-risk commerce occurs when a merchant expands its product catalog after underwriting. A business that was originally approved to sell CBD products can introduce THCA products, alternative cannabinoids, or other regulated items without ever notifying its processor, ISO, or acquiring bank.
What appears to be a simple product addition can dramatically alter a merchant’s compliance profile and create exposure throughout the payment ecosystem.
The Merchant Was Originally Approved for CBD
The merchant completed underwriting as a standard hemp-derived CBD seller.
The website contained:
- CBD tinctures
- Topicals
- Gummies
- Basic wellness products
The business model aligned with what had been reviewed during onboarding. Documentation matched the products being sold, and the processor felt comfortable with the risk profile.
The merchant was approved and began processing.
Months later, the merchant decided to expand.
The Introduction of THCA Products
Like many businesses operating in competitive markets, the merchant was looking for new revenue opportunities.
The company launched a new product category featuring THCA flower, pre-rolls, and concentrates.
From the merchant’s perspective, the change seemed straightforward.
The website was updated.
New inventory was added.
Marketing campaigns were launched.
Sales increased.
What the merchant did not realize was that the addition fundamentally changed how regulators, card networks, processors, and banks could view the business.
Why THCA Creates Additional Risk
THCA products exist within a rapidly evolving regulatory landscape.
While some jurisdictions permit certain hemp-derived products, others have implemented restrictions, testing requirements, potency limitations, age-verification obligations, or outright bans.
The challenge for payment providers is that regulations can vary significantly by state and continue changing at a rapid pace.
A merchant that was previously operating within one compliance framework may suddenly require:
- Different underwriting standards
- Additional monitoring
- Geographic sales restrictions
- Enhanced age verification controls
- Ongoing product-level reviews
Without visibility into these changes, payment providers may unknowingly support activity that falls outside their approved risk appetite.
The Discovery
The processor did not learn about the new products from the merchant.
The discovery occurred during a routine compliance review.
Analysts identified new website content, product categories, and promotional language that had not existed during underwriting.
The merchant’s approved business description no longer matched the actual products being sold.
At that point, several questions emerged:
Was the merchant still operating within approved guidelines?
Were products being shipped into restricted jurisdictions?
Were additional controls required?
Should the merchant have been re-underwritten?
These questions created immediate operational and compliance concerns.
The Hidden Problem: Approval Drift
This situation highlights a growing issue across payment portfolios known as approval drift.
Approval drift occurs when a merchant gradually moves away from the conditions that existed during underwriting.
The change is rarely dramatic.
A new product category is added.
A few marketing claims are updated.
A different fulfillment partner is introduced.
Over time, the merchant becomes materially different from the business that originally received approval.
The processor, however, may still be relying on information collected months or years earlier.
Why Manual Reviews Often Miss These Changes
Most underwriting reviews capture a single moment in time.
Once a merchant is approved, monitoring often becomes periodic rather than continuous.
For portfolios containing hundreds or thousands of merchants, manually checking every website for product changes is practically impossible.
As a result, product expansions frequently go unnoticed until:
- A bank review occurs
- A network inquiry is received
- Regulatory scrutiny emerges
- Chargeback patterns change
- A compliance audit uncovers the issue
By then, exposure may already exist.
The Compliance Lesson
The problem was not necessarily that the merchant added THCA products.
The problem was that the change occurred without visibility, review, or updated risk assessment.
For processors, ISOs, PayFacs, and acquiring banks, the greatest risk often comes from not knowing that a merchant’s business has changed.
A merchant approved for one category can become a very different risk profile over time.
Without ongoing monitoring, those changes remain invisible.
Moving Beyond Static Underwriting
Modern compliance programs increasingly recognize that underwriting is not a one-time event.
Merchant websites, product catalogs, marketing language, and business models evolve continuously.
The institutions that manage risk most effectively are the ones that can identify those changes as they occur rather than months later.
Because in high-risk commerce, exposure rarely begins with a chargeback or enforcement action.
It usually begins with a change that nobody noticed.
How RegX Helps
RegX.ai was built to help processors, ISOs, PayFacs, and acquiring banks identify merchant changes after approval. By continuously monitoring merchant websites, products, categories, and compliance signals, RegX helps organizations detect risk shifts before they become portfolio-wide problems, creating visibility between underwriting and enforcement.

