Compliance Briefing

The Hidden Cost of Network (Scheme) Compliance

What network compliance actually costs a bank, which announcements carry a price, and who owns the exposure in a sponsored card program.

In short

Network compliance cost is real, continuous, and almost never measured. It shows up in two places: capacity consumed by manually screening and routing card network announcements, and fees that accrue because nobody acted on an announcement that carried a price.

CardTraq network fee reviews typically identify 7 to 15% of total network fee spend as reducible, and roughly half of that opportunity comes from announcements nobody was required to act on. In sponsored card programs the exposure is structurally worse, because liability sits with the party furthest from awareness and implementation.

Download the full briefing

The complete Rivero and CardTraq white paper, including the maturity model, the leadership diagnostic, and the full frameworks. The complete text is also published on this page.

By submitting you agree to CardTraq's privacy policy. We will not share your details.

What does network compliance cost?

Visa, Mastercard and the other card networks issue a steady stream of bulletins, mandates, technical specifications, fee notifications, and release announcements. Each one has to be read, understood, judged for relevance, and routed to whoever needs to act.

Network compliance, also known as scheme compliance outside the US, covers the same work either way: tracking network bulletins, mapping mandates to your programs, and coordinating teams to act on time. This briefing uses network throughout.

By Rivero's analysis, Visa and Mastercard issued approximately 25% more bulletins in 2025 than in the prior year, close to 2,000 announcements across the two networks, in addition to the thousands of pages of technical documentation they publish annually.

The operating model in most teams has not kept pace. Bulletins are still pulled manually from network portals, reviewed by someone who screens each update and interprets technical language. Status is tracked in spreadsheets and distribution happens over email. None of this is unusual, which is the point.

The relevance problem

A large share of bulletins do not apply to a given bank, product, or market. But it is difficult to know which ones matter until someone has read them. The team pays the reading cost on every bulletin in order to act on a minority. That is an inefficient use of scarce, skilled resources.

Who does a missed network mandate actually affect?

The instinct is to file network compliance under the compliance team's problem. In practice it touches almost every function in the payments organization.

Where network change lands across the organization
FunctionWhat a late-discovered change costs
IT and deliveryMandates arrive with fixed timelines. Late discovery turns planned delivery into a scramble, consuming engineering capacity and delaying internal projects.
ProductNew capabilities can enable first-to-market features and deprecated ones can break products. Teams that spot updates early plan ahead; teams that learn late react.
Risk and auditWhen tracking lives in spreadsheets and inboxes, oversight suffers and audit questions are hard to answer without a clear trail.
FinanceUnnoticed fee changes and missed opt-out windows create recurring margin leaks that surface only on invoices.
Customer operationsMandates can change cardholder messaging, processes, and authentication. When support learns late, the first signal is confused customers.

Which network announcements actually cost money?

Both networks classify what they publish. Mastercard prints a metadata block on the face of its announcements covering type, category, audience, region, brand, affected system, and an action indicator. Visa organizes by publication channel and release calendar, and distinguishes mandatory from recommended requirements in its program documentation.

Both are trying to answer the same question: what action does this require, and who takes it. Neither answers the question a CFO asks, which is what this costs and when it hits.

THE ANNOUNCEMENT COST AXIS Tier 1 Priced and immediate Tier 2 Priced by inaction Tier 3 Priced downstream Tier 4 Priced by threshold WHERE THE COST LANDS Next invoice Recurring, from the election date forward Engineering capacity and roadmap Later, from portfolio performance
Four tiers, sorted by where the cost lands
TierWhat it is
1. Priced and immediateThe announcement changes a rate, introduces a billing event, or revises how an existing fee is assessed. The difficulty is attribution rather than awareness: when the invoice moves, most institutions cannot trace it back to the announcement that caused it.
2. Priced by inactionCost accrues from not acting. Default enrollment in a service, a fee structure that penalizes an unused or misconfigured asset, or a cheaper option that requires an affirmative election. No deadline is missed and no rule is breached, which is precisely why nothing flags it.
3. Priced downstreamNo fee attaches, but implementation is obligated and the cost surfaces as engineering capacity and displaced roadmap. The best-organized tier in most institutions.
4. Priced by thresholdStanding monitoring programs where cost is a function of portfolio performance against a moving bar. Nothing requires action on the day the announcement arrives.
7-15%
of total network fee spend is typically reducible, identified in a CardTraq network fee review
~half
of that opportunity sits in Tier 2 alone, priced by inaction

“The expensive announcements are rarely the ones marked mandatory. They are the optional programs with an opt-out window that nobody was watching.”

Steven Leitman, CEO, CardTraq

The implication

A process built around deadlines and required-action labels handles Tiers 1 and 3 well and systematically underweights 2 and 4. Those are the two that cost money rather than capacity, and Tier 2 is the one that pays for the process change on its own.

“Most banks can tell you what they paid in network fees last quarter. Very few can tell you why fees changed and which announcement caused the change.”

Steven Leitman, CEO, CardTraq

What does non-compliance cost?

Framing it solely as a risk of fines understates the impact. Networks can apply financial consequences and escalating scrutiny when obligations are missed, and penalties can range from tens of thousands to over a million dollars. But the larger costs are quieter: audit exposure when a team cannot show what was done and when, delivery drag when late-spotted mandates displace planned work, and the reputational effect of being flagged by a network partner.

Non-compliance is rarely one large, visible event. It is a series of smaller costs that are individually tolerable and collectively significant. Because each is survivable in isolation, the aggregate is rarely measured, and what is not measured does not get prioritized.

The standing cost

Delaying change because fines have not yet occurred simply means the team has not experienced a visible failure. It does not mean the cost is zero. Capacity drain, standing exposure, and delivery drag are being paid continuously. Thomson Reuters reports that 45% of financial services organizations do not formally track the total cost of compliance across their firm.

How does this look in the US market?

Sponsorship is more developed here

The US has a well-developed bank-fintech sponsorship market, extensive reliance on third-party technology providers, and sustained regulatory attention on bank-fintech arrangements. Many sponsor banks operate well below the size at which a dedicated network compliance function is affordable. The accountability split described above is not a theoretical structure in this market. It is a common operating model.

Processing is outsourced, accountability is not

Outsourcing processing does not remove the institution's regulatory or network responsibilities, although processors may carry direct contractual and network-rule obligations depending on the arrangement. Reliance on third-party processing is widespread, and for many community banks and credit unions the platform largely determines what gets implemented and when. The license, the network relationship, the fee exposure, and the audit answer stay with the institution regardless.

What differs by size is leverage, not dependency. A large issuer has a named relationship team, contractual commitments on mandate support, and enough volume to move a release date. A smaller institution is on the standard release calendar and takes what arrives. The institution's real job is therefore not implementation. It is knowing which announcements the processor is handling, which it is not, which it will charge extra to handle, and being able to prove the answer when issues arise.

The cost of staying current does not scale

The volume of network announcements is set by the networks, not by your balance sheet. A three billion dollar bank or credit union reads the same stream as a three hundred billion dollar one. What differs is that one has a network compliance team and the other has part of one person who also does three other jobs. That makes the burden regressive, and it is why the internal-handling answer breaks down at that end of the market specifically rather than as a general principle.

What does mature network compliance look like?

A maturity model for network compliance
ReactiveManagedStrategic
ProcessAd-hoc, deadline-driven, no central workflowCentralized screening, assigned ownershipAutomated surfacing and routing, impact assessment supported
ToolingManual portal pulls, spreadsheets, emailCentral bulletin hub with ownership tracking and audit trailSingle source of truth across functions, full traceability
Risk visibilityBlind until failure, resilience rests on individualsDeadlines and ownership tracked, no longer memory-dependentLive view of exposure, early warning to IT, product, and finance
Team activityManual review and administrative triageInterpretive work, lighter admin loadPrioritization, planning, cross-team coordination

Questions for the leadership team

A short diagnostic is often more useful than a long report. If the answers are uncomfortable, that is the signal.

  1. If a mandate slipped today, how long would it take to notice, and who would be accountable?
  2. Could you show an auditor what was done, when, and who approved it, without reconstructing it from inboxes and spreadsheets?
  3. How many skilled hours each week go into manual and administrative work rather than acting on it?
  4. When a change requires engineering work, how much lead time does the team typically get?
  5. If the person who manages the process leaves next month, what would you lose?

Sources and method

This briefing draws on Rivero's analysis of Visa and Mastercard bulletin volume, the Thomson Reuters Cost of Compliance report, FluxForce AI's The Cost of Compliance in 2026, and published Visa and Mastercard announcements. Framework material draws on CardTraq's network fee review work and Rivero's platform data.

It makes no assessment of any institution's actual fee or compliance position and contains no product claims. It is informational and is not legal advice.

— Partnership —
CardTraq×Rivero

This briefing is published jointly by CardTraq and Rivero. Rivero builds Kajo, the payment network knowledge and compliance platform used by institutions including Worldline, Rabobank, PostFinance, and SIX. CardTraq is Rivero's strategic partner in the Americas and brings the network fee economics.

— Frequently asked —

Network compliance questions

1Who is responsible for compliance when a bank sponsors a fintech card program?

The sponsor bank holds the network license and therefore the network-facing responsibility, but compliance in a sponsored program is really four separate responsibilities: awareness of the announcement, implementation of the change, evidence that it was done, and financial liability when it is not. In most arrangements these sit with different parties, with the sponsor carrying liability while the program manager or processor controls implementation.

2What happens if a program manager misses a network mandate?

The network bills the license holder, so fines and assessments land on the sponsor bank regardless of which party failed to act. Whether the sponsor recovers that cost downstream depends on its contracts and its ability to attribute the charge to a specific program, and in practice many sponsors recover only part of it.

3Can a BIN sponsor pass network fees through to its programs?

Contractually usually yes, practically often not in full. The obstacle is attribution: roughly half of network costs are universal rather than directly linked to a transaction, attaching instead to BINs, licenses, registrations, product enrollments, data quality performance, or cross-border activity, several of them assessed above the level of any individual program. Accurate pass-through requires an apportionment methodology built for the sponsor's own book rather than a per-transaction split.

4How many bulletins do Visa and Mastercard publish each year?

Close to 2,000 announcements a year across the two networks, and the volume is rising. Rivero's analysis found approximately 25% more bulletins in 2025 than in the prior year, on top of the thousands of pages of technical documentation the networks publish annually. A bank running across several networks can see well over 100 publications a month.

5Which network announcements actually cost money?

Four kinds, and the expensive ones are not always the ones marked mandatory. Fee changes that hit the next invoice, fees that accrue from not acting such as default enrollments and unused assets, mandates with no fee but real implementation cost, and monitoring programs where cost is a function of portfolio performance against a threshold. The second category produces the most avoidable spend because no deadline is missed and nothing flags it.

6How much do banks typically overpay in network fees?

CardTraq network fee reviews typically identify 7 to 15% of total network fee spend as reducible, and roughly half of that opportunity comes from fees that accrue through inaction rather than from anything that was mandated. Recovering it requires no negotiation and no change in volume.

7What is the difference between network compliance and scheme compliance?

They are the same thing. Network compliance is common North American usage and scheme compliance is the term used in the UK, Europe, and Australia. Both describe tracking network bulletins, mapping mandates to your programs, and coordinating teams to act before the deadline.

8Who is responsible if a processor fails to implement a network mandate?

Outsourcing processing does not remove the institution's regulatory or network responsibilities, although processors may carry direct contractual and network-rule obligations depending on the arrangement. The license, the network relationship, the fee exposure, and the audit answer stay with the institution, which makes knowing what the processor is and is not handling part of the institution's own job.

9How much time do banks spend managing network bulletins?

Enough that it displaces the work the same people are meant to be doing. FluxForce AI's 2026 research puts manual logging, filtering, and routing at 47 or more hours per week for a dual-network issuer, and around 300 person-days a year parsing network documentation at a mid-size issuer or acquirer.

10What does good network compliance look like?

A single place where every bulletin is captured, classified, assigned an owner, and tracked to completion with an audit trail, plus a view of which announcements carry a fee consequence and which do not. The practical test is whether leadership can say how fast a missed mandate would be spotted, and whether an auditor could be shown what was done and when without reconstructing it from inboxes.

About CardTraq

CardTraq is a CRG business, the payment economics business behind your card program. We help banks, credit unions, acquirers, and BIN sponsors take control of Visa and Mastercard network compliance and materially reduce network fees. The two are the same problem viewed from different ends. Network announcements drive obligations, and those obligations drive cost.

On the compliance side, CardTraq distributes Kajo as Rivero's strategic partner in the Americas, providing a US-based point of contact along with network compliance consulting and implementation support. On the economics side, the CardTraq platform ingests network invoices and automatically flags new, increased, and misapplied fees. Fee reviews typically identify 7 to 15% of total network fee spend that can be avoided or eliminated. Analysis runs in weeks, requires no core integration, and processes no sensitive cardholder data.

About Rivero

Rivero is a Swiss fintech founded in 2019 and headquartered in Zurich, specializing in streamlining payment operations for the regulated payments industry. A Visa Fintech Partner, Rivero builds SaaS solutions for dispute management, fraud recovery, and payment scheme compliance through its products Amiko and Kajo.

Kajo is an AI-powered payment knowledge and compliance platform that centralizes bulletins and network references from Visa, Mastercard, Amex, JCB, Discover, and UnionPay in one hub, automates impact assessment, prioritizes actions, assigns owners, and tracks progress from publication to completion with a full audit trail. Kajo is PCI DSS compliant and ISO 27001 certified. It is used by institutions including Worldline, Rabobank, PostFinance, SIX, Cembra, Viseca, Enfuce, and Advanzia.

Related reading: Card Network (Scheme) Fees Under Regulatory Scrutiny · Card Network (Scheme) Fees Explained · Network Compliance Tracking

Version 1.0 · Published 5 August 2026 · Last reviewed August 2026. The current version of this briefing is always published at this URL.

Ready to see what your announcements are costing you?

We can show you which announcements carried a fee consequence, what you paid, and what was recoverable. Book a review or talk to us about compliance tracking.