The Five Risks of Payments
Part V · Players and Risks (Chapters 20–25) Builds on: Chapter 2 (settlement risk), Chapter 7 (chargebacks), Chapter 9 (returns), Chapter 18 (prefunding), Chapter 22 (ledger risk) New concepts in this chapter: rolling reserve, delayed settlement, liquidity risk
1. The Question the Previous Chapter Left Open¶
The previous chapter ended with a list of things that sound alike and are completely different: a user tricked into sending money, a merchant that takes payment and vanishes, users withdrawing at once faster than funds can be moved, a payee on a sanctions list.
They trigger under different conditions, land on different parties, and call for different defenses. Lump them together and you will make wrong product decisions.
This chapter sorts them into five kinds.
2. The Five Risks at a Glance¶
| Risk | One-sentence definition | Typical scene | Who mainly bears it |
|---|---|---|---|
| Credit risk | The other side promised to pay and can't | A merchant takes the money, never delivers, and folds | The acquirer, or the PayFac (a payment facilitator — an aggregator that plugs a batch of small merchants into acquiring) |
| Fraud risk | The transaction wasn't made by the real customer — or the real customer was deceived into making it | Stolen cards, account takeover, authorized push payment fraud | Issuer or merchant, per the liability-shift rules |
| Settlement risk | The counterparty defaults in the gap between clearing completing and settlement completing | The paying bank fails before end-of-day settlement | The receiving bank |
| Liquidity risk | The money is sufficient — just not available here and now | A country's pool drained dry (the Wise model) | The institution itself |
| Compliance risk | Doing something the regulator forbids | Paying out to someone on a sanctions list | The institution itself |
The way to use this table: when something goes wrong, classify first, then choose the tool. The common failure is the wrong tool — throwing a risk model at a liquidity problem, or adding verification against scams (the user is transferring willingly; verification can't stop them).
3. Credit Risk: Why Acquirers Hold Back Merchants' Money¶
Credit risk's most typical shape in payments: a merchant collects money upfront and doesn't deliver.
The timing gap looks like this:
| When | What happens |
|---|---|
| Day 1 | A consumer cards a plane ticket for a flight three months out; the money settles to the merchant |
| Day 60 | The merchant goes under |
| Day 90 | The consumer files a chargeback (the card transaction lifecycle); the money is pulled back out of the acquirer's account |
| Day 91 onward | The acquirer goes to collect from the merchant; the merchant no longer exists |
So the loss lands, in the end, on the acquirer. This is the flip side of "the money follows the risk" from interchange: the 0.37% the acquirer takes is priced against exactly this risk.
Three tools of defense:
| Tool | How it works | The cost |
|---|---|---|
| Rolling reserve | Withhold a percentage of every settlement (say 5%) and release it 90 days later | The merchant's cash flow is tied up |
| Delayed settlement | Stretch the settlement cycle from T+2 to T+7 or longer | Same as above |
| Pricing by delivery lag | Prepaid, long-delivery industries pay higher rates | The merchant's costs rise |
To judge how risky a merchant is, look at one thing only: the gap between when it collects the money and when it delivers. A coffee shop delivers on the spot — near-zero risk. A gym selling annual memberships, a travel agency selling advance tickets — extremely high. Whether the industry is "respectable" has nothing to do with it.
4. Fraud Risk: Three Forms to Keep Apart¶
The card-not-present chapter covered one of these; here is the full set.
| Form | Mechanism | Who bears it | Can technology stop it? |
|---|---|---|---|
| Stolen-card fraud | A third party transacts with stolen card details | Issuer or merchant, per the liability shift (with strong authentication like 3DS, the issuer; without it, the merchant) | Yes — 3DS and tokenization |
| Account takeover | An attacker seizes the user's account and operates it | Usually the institution | Yes — login risk controls and device recognition |
| Authorized push payment (APP) fraud | The user is deceived and initiates the transfer themselves | Rules differ by country; historically the user | Mostly, no |
The third is the problem the four US rails flagged. What makes it frightening is that every technical check passes — because it really is the customer at the controls: their device, their password, their face.
This is also how fraud changed as instant payments spread: the target moved from the system to the person. The harder the system is to break, the more scammers work on talking people into sending the money themselves.
Since 2024 the UK has required the banks on both sides of a payment — sending and receiving — to share these losses. The logic: if technology can't block it, make the institutions capable of anomaly detection carry part of the loss, and let the economics push them to invest.
5. Settlement Risk: The Exposure from Clearing and Settlement¶
As clearing and settlement covered: in the window after clearing completes and before settlement does, the receiving bank has already given its customer the money — and hasn't yet received it from the paying bank.
How big the exposure is depends on how far apart clearing and settlement sit.
| Rail | Gap between clearing and settlement | Settlement risk |
|---|---|---|
| Fedwire (the four US rails) | None — simultaneous | Near zero |
| ACH | Hours to days | Present |
| Cards | One to two days | Present — managed through the card networks' rules and collateral requirements |
| On-chain transfers (covered later in the course) | None — simultaneous | Near zero |
Shrinking this gap is how settlement risk gets killed. It is the shared source of value behind instant-clearing systems and on-chain settlement — and the thread the course picks back up when it reaches stablecoins.
6. Liquidity Risk: The Money Is There but You Can't Get It Out¶
This one is the easiest to overlook, because it has nothing to do with losing money — on paper the money is all there. It just can't be produced here and now.
The example from the Wise model is the textbook case: flow on a corridor turns sharply one-way, and the pool being paid out of gets sucked dry. The company's total assets haven't changed — but users in that country can't get their money out.
| Scenario | What it looks like |
|---|---|
| A country's pool runs dry | Users in that country queue to withdraw |
| Too much money prefunded | Poor capital efficiency, high opportunity cost (the four cost sources) |
| Too little money prefunded | One surge away from failing to pay |
This is the trade-off from clearing and settlement yet again: capital tied up vs. exposure left open. You have now met it in four places — the RTGS-or-DNS choice: fully fund every transfer, or net at day's end and live with the exposure (clearing and settlement); RTP making banks park money upfront in a shared pool (the four US rails); prefunded liquidity in cross-border (the four cost sources); and here. The shape is different every time. The trade-off is the same one.
7. Three Ways Money Can Be Clawed Back¶
These three were covered separately in the card transaction lifecycle and push and pull; only side by side do they come into focus.
| Chargeback (cards) | Return (ACH) | Wire | |
|---|---|---|---|
| Who initiates | The cardholder | The receiving bank, or the consumer | No one — wires have no such mechanism |
| Time window | Commonly 120+ days | 2 days for insufficient funds; up to 60 days for unauthorized debits | Not applicable |
| Does the payee give the money back? | Yes — plus a dispute fee on top | Yes | No; you can only hope they return it voluntarily |
| Can the payee contest it? | Yes, with evidence | Limited | Not applicable |
When you build a product, the moment you recognize revenue should come from this table, not from "the money arrived." Money collected over ACH is not final for 60 days.
8. The Question This Chapter Leaves Open¶
Of the five risks, the first four come with controls the institution holds in its own hands — tune the reserves, add risk models, shorten the settlement cycle, park more liquidity.
Only the fifth doesn't. The rules of compliance risk are written by regulators, and failing them is not a question of how much money is lost — it is the license revoked, the business stopped, executives personally on the hook.
That is why it gets a chapter of its own. The next chapter cuts compliance into three blocks and shows what the work actually is.
9. Self-check questions¶
- An e-commerce merchant sells on preorder: $500 average order, 90-day delivery window. How should its acquirer set the rolling reserve? Give your reasoning.
- Why is "add more verification" the wrong tool against authorized push payment fraud?
- A cross-border company has ample total assets, yet users in one country try to withdraw en masse and can't. Which risk is this? What tools apply?
10. Answers¶
Answer for yourself before reading on.
- The hold period must cover at least delivery window + chargeback window. Delivery takes 90 days and chargeback windows commonly run past 120, so the hold should be 180 days or more — otherwise the reserve is released before the chargebacks arrive, and the acquirer is exposed all over again. On the percentage: it has to cover the expected chargeback rate plus the total of undelivered orders if the merchant collapses — and on a preorder model that number can be very large. This is why merchants like this commonly see reserve rates above 10%, or are simply refused acquiring altogether.
- Because in APP fraud, every check passes: the real customer is operating, on their own device, entering their own password and biometrics. Verification answers the question "is this you?" — and here the honest answer is yes. Solving it takes anomaly detection (is this payee, this amount, this timing out of pattern?), transaction delays and cooling-off periods, and blocks on high-risk recipient accounts — capabilities that answer a different question entirely: "are you being scammed?"
- Liquidity risk. The tools are treasury moves: rebalance from pools in other countries, draw on credit lines, temporarily raise that corridor's fees or limits to choke the flow. Note that it is neither credit risk nor fraud risk, so strengthening risk models or raising reserves does nothing — the textbook "wrong tool" case from the top of this chapter.
Previous: Chapter 22 · Neobank Anatomy: Where Your Money Actually Lives Next: Chapter 24 · The Compliance Skeleton: Licenses, Identity, and Monitoring