Network compliance cost is real, continuous, and almost never measured. It shows up in two places: capacity consumed by manually screening and routing card network announcements, and fees that accrue because nobody acted on an announcement that carried a price.
CardTraq network fee reviews typically identify 7 to 15% of total network fee spend as reducible, and roughly half of that opportunity comes from announcements nobody was required to act on. In sponsored card programs the exposure is structurally worse, because liability sits with the party furthest from awareness and implementation.
Download the full briefing
The complete Rivero and CardTraq white paper, including the maturity model, the leadership diagnostic, and the full frameworks. The complete text is also published on this page.
- What does network compliance cost?
- Who does a missed mandate affect?
- Who owns compliance in a sponsored program?
- Which announcements cost money?
- What does non-compliance cost?
- How does this look in the US?
- What does mature compliance look like?
- Questions for the leadership team
- Sources and method
- Frequently asked questions
What does network compliance cost?
Visa, Mastercard and the other card networks issue a steady stream of bulletins, mandates, technical specifications, fee notifications, and release announcements. Each one has to be read, understood, judged for relevance, and routed to whoever needs to act.
Network compliance, also known as scheme compliance outside the US, covers the same work either way: tracking network bulletins, mapping mandates to your programs, and coordinating teams to act on time. This briefing uses network throughout.
By Rivero's analysis, Visa and Mastercard issued approximately 25% more bulletins in 2025 than in the prior year, close to 2,000 announcements across the two networks, in addition to the thousands of pages of technical documentation they publish annually.
The operating model in most teams has not kept pace. Bulletins are still pulled manually from network portals, reviewed by someone who screens each update and interprets technical language. Status is tracked in spreadsheets and distribution happens over email. None of this is unusual, which is the point.
A large share of bulletins do not apply to a given bank, product, or market. But it is difficult to know which ones matter until someone has read them. The team pays the reading cost on every bulletin in order to act on a minority. That is an inefficient use of scarce, skilled resources.
Who does a missed network mandate actually affect?
The instinct is to file network compliance under the compliance team's problem. In practice it touches almost every function in the payments organization.
| Function | What a late-discovered change costs |
|---|---|
| IT and delivery | Mandates arrive with fixed timelines. Late discovery turns planned delivery into a scramble, consuming engineering capacity and delaying internal projects. |
| Product | New capabilities can enable first-to-market features and deprecated ones can break products. Teams that spot updates early plan ahead; teams that learn late react. |
| Risk and audit | When tracking lives in spreadsheets and inboxes, oversight suffers and audit questions are hard to answer without a clear trail. |
| Finance | Unnoticed fee changes and missed opt-out windows create recurring margin leaks that surface only on invoices. |
| Customer operations | Mandates can change cardholder messaging, processes, and authentication. When support learns late, the first signal is confused customers. |
Who owns compliance in a sponsored card program?
The question gets asked often and answered badly, usually as a contractual matter. The contract determines who is liable to whom. It does not determine who notices.
Compliance in a sponsored program is not one responsibility. It is four, and in almost every arrangement they sit with different parties.
| Component | What it means | Where it usually sits |
|---|---|---|
| Awareness | Reading the announcement, judging whether it applies to this BIN, product, and program, and routing it. | Sponsor, who holds the license and the portal credentials |
| Implementation | Making the change. A common failure mode is that neither party has direct access to the source document and both work from a forwarded summary. | Program manager, processor, or both |
| Evidence | Showing an auditor what was done, when, by whom, and on what authority. | Discovered missing rather than assigned |
| Financial liability | Paying the fee, the assessment, or the fine. | Sponsor, because the network bills the license holder |
Whether the sponsor recovers that cost downstream is a separate question with a separate answer, and in CardTraq's experience working with BIN sponsors globally, many recover nowhere close to all of it.
The obstacle is rarely willingness. It is attribution. To pass a fee through accurately, the sponsor has to know which program generated it, and for a significant share of network fees the driver is not obvious from the billing record. Roughly half of network costs are universal, meaning they are not directly linked to a transaction and have to be apportioned before they can be allocated to anyone. Some fees are volume or transaction-count driven and allocate cleanly. Many are not. They attach to BINs, licenses, registrations, product enrollments, data quality performance, cross-border activity, or account ranges, and several are assessed at a level above any individual program. Splitting those correctly requires an apportionment methodology built for the sponsor's specific book, not a per-transaction divide.
There is a reasonable argument that a sponsor should absorb much of the non-compliance cost when it has not put the right structure in place. If the sponsor holds the license, receives the announcements, and has not built the visibility or the allocation to manage the exposure, the failure is structural and it belongs to the party that owns the structure.
Where the structure fails
The failure mode is not that any one component is unowned. It is that liability sits with the party furthest from awareness and implementation. The sponsor carries the network relationship, the standing, and the invoice, while the decisions that generate the exposure are made inside a partner's engineering backlog the sponsor cannot see.
“Sponsors are being held accountable for their partners' compliance without any real visibility into it. That gap is going to produce some unpleasant surprises.”
Steven Leitman, CEO, CardTraq
There is a simpler test that takes an afternoon. Take the monthly network invoice total and compare it against what was invoiced out to clients for network fees over the same month. The delta is the share the sponsor is absorbing. In most BIN sponsored models it is surprisingly large, and the size of it is usually news to the people who set the pricing.
Which network announcements actually cost money?
Both networks classify what they publish. Mastercard prints a metadata block on the face of its announcements covering type, category, audience, region, brand, affected system, and an action indicator. Visa organizes by publication channel and release calendar, and distinguishes mandatory from recommended requirements in its program documentation.
Both are trying to answer the same question: what action does this require, and who takes it. Neither answers the question a CFO asks, which is what this costs and when it hits.
| Tier | What it is |
|---|---|
| 1. Priced and immediate | The announcement changes a rate, introduces a billing event, or revises how an existing fee is assessed. The difficulty is attribution rather than awareness: when the invoice moves, most institutions cannot trace it back to the announcement that caused it. |
| 2. Priced by inaction | Cost accrues from not acting. Default enrollment in a service, a fee structure that penalizes an unused or misconfigured asset, or a cheaper option that requires an affirmative election. No deadline is missed and no rule is breached, which is precisely why nothing flags it. |
| 3. Priced downstream | No fee attaches, but implementation is obligated and the cost surfaces as engineering capacity and displaced roadmap. The best-organized tier in most institutions. |
| 4. Priced by threshold | Standing monitoring programs where cost is a function of portfolio performance against a moving bar. Nothing requires action on the day the announcement arrives. |
“The expensive announcements are rarely the ones marked mandatory. They are the optional programs with an opt-out window that nobody was watching.”
Steven Leitman, CEO, CardTraq
The implication
A process built around deadlines and required-action labels handles Tiers 1 and 3 well and systematically underweights 2 and 4. Those are the two that cost money rather than capacity, and Tier 2 is the one that pays for the process change on its own.
“Most banks can tell you what they paid in network fees last quarter. Very few can tell you why fees changed and which announcement caused the change.”
Steven Leitman, CEO, CardTraq
What does non-compliance cost?
Framing it solely as a risk of fines understates the impact. Networks can apply financial consequences and escalating scrutiny when obligations are missed, and penalties can range from tens of thousands to over a million dollars. But the larger costs are quieter: audit exposure when a team cannot show what was done and when, delivery drag when late-spotted mandates displace planned work, and the reputational effect of being flagged by a network partner.
Non-compliance is rarely one large, visible event. It is a series of smaller costs that are individually tolerable and collectively significant. Because each is survivable in isolation, the aggregate is rarely measured, and what is not measured does not get prioritized.
Delaying change because fines have not yet occurred simply means the team has not experienced a visible failure. It does not mean the cost is zero. Capacity drain, standing exposure, and delivery drag are being paid continuously. Thomson Reuters reports that 45% of financial services organizations do not formally track the total cost of compliance across their firm.
How does this look in the US market?
Sponsorship is more developed here
The US has a well-developed bank-fintech sponsorship market, extensive reliance on third-party technology providers, and sustained regulatory attention on bank-fintech arrangements. Many sponsor banks operate well below the size at which a dedicated network compliance function is affordable. The accountability split described above is not a theoretical structure in this market. It is a common operating model.
Processing is outsourced, accountability is not
Outsourcing processing does not remove the institution's regulatory or network responsibilities, although processors may carry direct contractual and network-rule obligations depending on the arrangement. Reliance on third-party processing is widespread, and for many community banks and credit unions the platform largely determines what gets implemented and when. The license, the network relationship, the fee exposure, and the audit answer stay with the institution regardless.
What differs by size is leverage, not dependency. A large issuer has a named relationship team, contractual commitments on mandate support, and enough volume to move a release date. A smaller institution is on the standard release calendar and takes what arrives. The institution's real job is therefore not implementation. It is knowing which announcements the processor is handling, which it is not, which it will charge extra to handle, and being able to prove the answer when issues arise.
The cost of staying current does not scale
The volume of network announcements is set by the networks, not by your balance sheet. A three billion dollar bank or credit union reads the same stream as a three hundred billion dollar one. What differs is that one has a network compliance team and the other has part of one person who also does three other jobs. That makes the burden regressive, and it is why the internal-handling answer breaks down at that end of the market specifically rather than as a general principle.
What does mature network compliance look like?
| Reactive | Managed | Strategic | |
|---|---|---|---|
| Process | Ad-hoc, deadline-driven, no central workflow | Centralized screening, assigned ownership | Automated surfacing and routing, impact assessment supported |
| Tooling | Manual portal pulls, spreadsheets, email | Central bulletin hub with ownership tracking and audit trail | Single source of truth across functions, full traceability |
| Risk visibility | Blind until failure, resilience rests on individuals | Deadlines and ownership tracked, no longer memory-dependent | Live view of exposure, early warning to IT, product, and finance |
| Team activity | Manual review and administrative triage | Interpretive work, lighter admin load | Prioritization, planning, cross-team coordination |
Questions for the leadership team
A short diagnostic is often more useful than a long report. If the answers are uncomfortable, that is the signal.
- If a mandate slipped today, how long would it take to notice, and who would be accountable?
- Could you show an auditor what was done, when, and who approved it, without reconstructing it from inboxes and spreadsheets?
- How many skilled hours each week go into manual and administrative work rather than acting on it?
- When a change requires engineering work, how much lead time does the team typically get?
- If the person who manages the process leaves next month, what would you lose?
Sources and method
This briefing draws on Rivero's analysis of Visa and Mastercard bulletin volume, the Thomson Reuters Cost of Compliance report, FluxForce AI's The Cost of Compliance in 2026, and published Visa and Mastercard announcements. Framework material draws on CardTraq's network fee review work and Rivero's platform data.
It makes no assessment of any institution's actual fee or compliance position and contains no product claims. It is informational and is not legal advice.