Unit 03 · Chapter 1 · 15 min read

Underwrite the merchant business

Understand what is sold, when it is delivered, and who absorbs a failure.

The concept at a glance

Underwrite the open promise

Two timelines compare a coffee shop collecting and delivering almost immediately with a concert promoter collecting well before delivery. A long shaded band marks the promoter’s open delivery obligation. A cancellation can turn that obligation into refund demand before future revenue arrives.

Enlarge to read every label and explore the connections

The time between collection and delivery shapes merchant exposure. A registered business can still fail to fulfill its promises.

  1. Compare collection and delivery timing.

  2. Read the shaded band as an open promise.

  3. Ask who can fund refunds if delivery fails.

A concert promoter collects cash today for a show six months away. A coffee shop collects cash for a drink handed over now. Both accept cards. Their risk can be very different because the promise stays open for very different lengths of time.

Start with the economic promise

Start with the economic promise — the flow
Start with the economic promise Start with the economic promise — the flow Follow the sequence. Identify refund and loss exposure. Offer Identify the promised product Delivery Locate when the obligation is met Failure Identify refund and loss exposure
  1. OfferIdentify the promised product
  2. DeliveryLocate when the obligation is met
  3. FailureIdentify refund and loss exposure
Follow the sequence. Identify refund and loss exposure. Chapter sources · Open image

Merchant underwriting evaluates the business and the exposure created by processing for it. Identify the product, customer, delivery timing, refund promise, and payment flow. A business registration proves that an entity exists; it does not prove the entity can fulfill its promises.

Write the model in one sentence: this merchant collects this amount from these customers for this service at this time. Then test the sentence against the website, contracts, financial records, and transaction plan. If the explanation changes across documents, resolve the discrepancy before deciding which controls are suitable.

A merchant application often describes a product category. Underwriting needs the actual promise made to customers. A business that sells a book for immediate shipment has a different exposure timeline from one that sells a course beginning in six months. Both may have the same monthly payment volume, but the second holds more unfulfilled obligations at a given moment.

Lantern therefore maps order creation, customer payment, fulfillment, refund rights, and merchant payout on one timeline. The distance between collecting money and delivering value is a source of exposure. The analysis then asks what resources remain if the merchant stops trading during that interval. Revenue growth can make the business look stronger while increasing the amount the platform may need to return to customers.

Inside the mechanism. Start with what the customer buys and when the merchant finishes the promise. A digital download, annual subscription, travel booking, and future event ticket leave different open obligations. Measure unfulfilled value by cohort and expected completion date. Revenue received today may support obligations far into the future. The underwriting question is therefore not only whether sales are growing, but what the platform may owe if fulfillment stops at the worst point.

A concrete example. The merchant collects fees now for classes delivered over several months. The payment stream and the unfulfilled service obligation move on different schedules. The case has $690,000 of exposure. Its stated one-year PD and LGD imply $17,077.50 of expected loss, while the cover analysis leaves $504,000.00 of stress exposure. Monthly cash coverage is 1.33×. These are separate measures: one describes an average under probability assumptions, one describes available cover, and one describes a period’s funding capacity.

When the assumption fails. New sales grow while the backlog of undelivered classes also grows. Measure open promises and stress cancellation exposure instead of using sales as a substitute for capacity. The following worked sequence shows the reference condition, a stress condition, and a response condition with explicit synthetic data. These are comparative assumptions, not measured causal effects.

Follow a worked case3 conditions · 36 figures

The merchant collects fees now for classes delivered over several months. The payment stream and the unfulfilled service obligation move on different schedules.

Start with the economic promise — the distinction
Start with the economic promise Start with the economic promise — the distinction These concepts answer different questions. Read each definition in the context of the section. Entity existence Business is registered Operating viability Business can fulfill its promises
Entity existence
  • Business is registered
Operating viability
  • Business can fulfill its promises
These concepts answer different questions. Read each definition in the context of the section. Chapter sources · Open image
Promoter business model
Start with the economic promise Promoter business model Fictional teaching record. Potential correlated exposure. Promoter business model Illustrative data; not a real customer record or a prescribed policy. Sale concert ticket Customer buys future access Delivery six months later Long open obligation Failure refund demand Potential correlated exposure Registration alone cannot establish fulfillment ability
Fictional educational excerpt / Not for execution

Promoter business model

Illustrative data; not a real customer record or a prescribed policy.

  1. Saleconcert ticket

    Customer buys future access

  2. Deliverysix months later

    Long open obligation

  3. Failurerefund demand

    Potential correlated exposure

Registration alone cannot establish fulfillment ability

Fictional teaching record. Potential correlated exposure. Chapter sources · Open image
Start with the economic promise — control and failure modes
Start with the economic promise Start with the economic promise — control and failure modes Registration alone cannot establish fulfillment ability. The branches show why alternative designs fail. Control design Underwrite the operating promise. Registration alone cannot establish fulfillment ability. Failure mode 1 Approve from the certificate only. It does not show the business model. avoid Failure mode 2 Treat all card merchants alike. Delivery and liability differ. avoid Failure mode 3 Ignore refund terms. They shape the open obligation. avoid
Control design

Underwrite the operating promise. Registration alone cannot establish fulfillment ability.

Failure mode 1avoid
Approve from the certificate only. It does not show the business model.
Failure mode 2avoid
Treat all card merchants alike. Delivery and liability differ.
Failure mode 3avoid
Ignore refund terms. They shape the open obligation.
Registration alone cannot establish fulfillment ability. The branches show why alternative designs fail. Chapter sources · Open image

Map the payment and liability chain

Map the payment and liability chain — the flow
Map the payment and liability chain Map the payment and liability chain — the flow Follow the sequence. Assign refunds and losses. Contract Identify the seller and obligations Funds Trace settlement and payouts Liability Assign refunds and losses
  1. ContractIdentify the seller and obligations
  2. FundsTrace settlement and payouts
  3. LiabilityAssign refunds and losses
Follow the sequence. Assign refunds and losses. Chapter sources · Open image

Determine who is merchant of record, who receives settlement, who pays suppliers, and who bears refunds and chargebacks. A marketplace can present one brand while several entities perform these functions. Contracts and actual fund flows must agree.

Create a flow diagram with every legal entity and account boundary. Include refunds, reserves, and partner fees, not just incoming sales. A mismatch between the contractual seller and the visible checkout can confuse customers and complicate disputes. Escalate unclear models to the responsible legal and compliance owners before treating an account identifier as a complete answer.

Inside the mechanism. Trace who contracts with the customer, who receives proceeds, who performs the service, and who bears refunds or disputes. A marketplace label does not answer those questions by itself. Record partner agreements and actual operating behavior separately where they differ. A platform can retain customer-facing obligations while depending on a merchant or supplier for recovery. That dependency belongs in the exposure model and in the evidence needed for approval.

A concrete example. The platform connects buyers and several sellers while contracts allocate different refund and payment responsibilities. A customer-facing brand does not reveal the final loss bearer. The case has $940,000 of exposure. Its stated one-year PD and LGD imply $15,510.00 of expected loss, while the cover analysis leaves $656,000.00 of stress exposure. Monthly cash coverage is 1.33×. These are separate measures: one describes an average under probability assumptions, one describes available cover, and one describes a period’s funding capacity.

When the assumption fails. A seller defaults and the platform’s contingent obligation becomes payable. Map the legal promise, cash location, recovery rights, and concentration before assigning cover. The following worked sequence shows the reference condition, a stress condition, and a response condition with explicit synthetic data. These are comparative assumptions, not measured causal effects.

Follow a worked case3 conditions · 36 figures

The platform connects buyers and several sellers while contracts allocate different refund and payment responsibilities. A customer-facing brand does not reveal the final loss bearer.

Map the payment and liability chain — the distinction
Map the payment and liability chain Map the payment and liability chain — the distinction These concepts answer different questions. Read each definition in the context of the section. Brand on screen Customer-facing name Merchant of record Entity responsible in the payment arrangement
Brand on screen
  • Customer-facing name
Merchant of record
  • Entity responsible in the payment arrangement
These concepts answer different questions. Read each definition in the context of the section. Chapter sources · Open image
Marketplace chain
Map the payment and liability chain Marketplace chain Fictional teaching record. Must match the actual arrangement. Marketplace chain Illustrative data; not a real customer record or a prescribed policy. Checkout Lantern Visible platform Seller vendor-12 Underlying supplier Refund owner contract-defined Must match the actual arrangement Both are needed to understand responsibility
Fictional educational excerpt / Not for execution

Marketplace chain

Illustrative data; not a real customer record or a prescribed policy.

  1. CheckoutLantern

    Visible platform

  2. Sellervendor-12

    Underlying supplier

  3. Refund ownercontract-defined

    Must match the actual arrangement

Both are needed to understand responsibility

Fictional teaching record. Must match the actual arrangement. Chapter sources · Open image
Map the payment and liability chain — control and failure modes
Map the payment and liability chain Map the payment and liability chain — control and failure modes Both are needed to understand responsibility. The branches show why alternative designs fail. Control design Match agreements to actual fund flows. Both are needed to understand responsibility. Failure mode 1 Assume the logo owns every obligation. Branding does not determine all legal roles. avoid Failure mode 2 Ignore supplier payouts. They can remove funds needed for refunds. avoid Failure mode 3 Use only the bank account nickname. It does not establish the legal entity. avoid
Control design

Match agreements to actual fund flows. Both are needed to understand responsibility.

Failure mode 1avoid
Assume the logo owns every obligation. Branding does not determine all legal roles.
Failure mode 2avoid
Ignore supplier payouts. They can remove funds needed for refunds.
Failure mode 3avoid
Use only the bank account nickname. It does not establish the legal entity.
Both are needed to understand responsibility. The branches show why alternative designs fail. Chapter sources · Open image

Test fulfillment and concentration

Test fulfillment and concentration — the flow
Test fulfillment and concentration Test fulfillment and concentration — the flow Follow the sequence. Estimate a correlated refund event. Cohort Group open customer promises Dependency Find shared failure causes Stress Estimate a correlated refund event
  1. CohortGroup open customer promises
  2. DependencyFind shared failure causes
  3. StressEstimate a correlated refund event
Follow the sequence. Estimate a correlated refund event. Chapter sources · Open image

Delivery exposure depends on how much business remains unfulfilled and how failures correlate. A merchant with many tickets for one event has concentration even if it has thousands of customers. Customer count is not the same as independent risk.

Estimate undelivered value by cohort and delivery date. Identify common suppliers, venues, platforms, and geographic events that can disrupt many orders together. Ask how the merchant would handle a cancellation or supplier failure. The point is to test a plausible loss path, not to forecast every possible disaster.

Inside the mechanism. Concentration matters along the failure mechanism: one event, supplier, customer, destination, or funding source can dominate a portfolio that appears diversified by merchant count. Group obligations by the common cause that could fail together. Test the effect of delayed or cancelled fulfillment at the relevant time. Averaging across merchants can hide the peak open promise precisely when cash has already left the platform.

A concrete example. Several merchants use one supplier for popular seasonal inventory. Their account names are different but a common shipment delay can affect all of them. The case has $1,250,000 of exposure. Its stated one-year PD and LGD imply $34,375.00 of expected loss, while the cover analysis leaves $862,000.00 of stress exposure. Monthly cash coverage is 1.33×. These are separate measures: one describes an average under probability assumptions, one describes available cover, and one describes a period’s funding capacity.

When the assumption fails. The shared supplier stops shipping during the peak sales period. Aggregate the common exposure and connect limits and payout terms to fulfillment evidence. The following worked sequence shows the reference condition, a stress condition, and a response condition with explicit synthetic data. These are comparative assumptions, not measured causal effects.

Follow a worked case3 conditions · 36 figures

Several merchants use one supplier for popular seasonal inventory. Their account names are different but a common shipment delay can affect all of them.

Test fulfillment and concentration — the distinction
Test fulfillment and concentration Test fulfillment and concentration — the distinction These concepts answer different questions. Read each definition in the context of the section. Many buyers Large customer count Diversified exposure Losses do not depend on one common event
Many buyers
  • Large customer count
Diversified exposure
  • Losses do not depend on one common event
These concepts answer different questions. Read each definition in the context of the section. Chapter sources · Open image
Event concentration
Test fulfillment and concentration Event concentration Fictional teaching record. Correlated delivery obligation. Event concentration Illustrative data; not a real customer record or a prescribed policy. Customers 4000 Many individual buyers Venue one Shared dependency Open ticket value 320000 USD Correlated delivery obligation Many customers can still share one failure cause
Fictional educational excerpt / Not for execution

Event concentration

Illustrative data; not a real customer record or a prescribed policy.

  1. Customers4000

    Many individual buyers

  2. Venueone

    Shared dependency

  3. Open ticket value320000 USD

    Correlated delivery obligation

Many customers can still share one failure cause

Fictional teaching record. Correlated delivery obligation. Chapter sources · Open image
Test fulfillment and concentration — control and failure modes
Test fulfillment and concentration Test fulfillment and concentration — control and failure modes Many customers can still share one failure cause. The branches show why alternative designs fail. Control design Measure shared delivery dependencies. Many customers can still share one failure cause. Failure mode 1 Use customer count as diversification proof. The venue can fail for everyone. avoid Failure mode 2 Ignore future delivery dates. They determine the exposure window. avoid Failure mode 3 Assume insurance always pays. Coverage and exclusions need evidence. avoid
Control design

Measure shared delivery dependencies. Many customers can still share one failure cause.

Failure mode 1avoid
Use customer count as diversification proof. The venue can fail for everyone.
Failure mode 2avoid
Ignore future delivery dates. They determine the exposure window.
Failure mode 3avoid
Assume insurance always pays. Coverage and exclusions need evidence.
Many customers can still share one failure cause. The branches show why alternative designs fail. Chapter sources · Open image

Verify the story with proportional evidence

Verify the story with proportional evidence — the flow
Verify the story with proportional evidence Verify the story with proportional evidence — the flow Follow the sequence. Document the remaining uncertainty. Claim Name the fact that matters Evidence Choose a relevant independent source Resolve Document the remaining uncertainty
  1. ClaimName the fact that matters
  2. EvidenceChoose a relevant independent source
  3. ResolveDocument the remaining uncertainty
Follow the sequence. Document the remaining uncertainty. Chapter sources · Open image

Evidence should test the important claims. Bank activity can support cash-flow claims, supplier agreements can support delivery plans, and complaint records can challenge the customer experience. No single document tells the whole story.

Use a documented discrepancy process. A missing document may be a simple administrative gap; a contradiction may be more serious. Record the question being resolved, acceptable evidence, and the decision owner. Avoid collecting a large pile of unrelated documents because it looks thorough. More data increases handling cost and privacy exposure without necessarily improving the decision.

Evidence is most useful when it tests a specific part of the business story. A sample of supplier records can support a claim about access to stock; fulfillment records can support a claim about delivery timing; financial information can support an estimate of repayment capacity. None proves the entire application. Record the claim, the evidence examined, its date, and the unresolved limitation. This makes a conditional approval understandable to the next reviewer and reduces the chance that a polished presentation substitutes for the operating facts.

Inside the mechanism. Evidence should test the specific business story. Inventory records help one merchant type; supplier capacity or service completion evidence may matter more for another. Reconcile claimed sales to payment and fulfillment observations where appropriate and authorized. A polished document is not an independent confirmation. Keep the source, date, and limitations of each item so later monitoring can identify which part of the original approval assumption has changed.

A concrete example. A merchant’s explanation is tested against evidence appropriate to its activity. A document is useful when it supports a specific claim rather than merely filling a checklist. The case identifies 986 eligible records from a source population of 1,450. The required workflow completes for 956, but 14 completed records miss the illustrative internal target. Another 30 remain incomplete. Communication evidence covers 946 generated notices. Scope, completion, timeliness, and delivery are four separate properties of the customer outcome.

When the assumption fails. A polished business plan substitutes for evidence of stock, delivery, and repayment resources. Tie each material claim to dated evidence and preserve any unresolved limitation. The following worked sequence shows the reference condition, a stress condition, and a response condition with explicit synthetic data. These are comparative assumptions, not measured causal effects.

Follow a worked case3 conditions · 36 figures

A merchant’s explanation is tested against evidence appropriate to its activity. A document is useful when it supports a specific claim rather than merely filling a checklist.

Verify the story with proportional evidence — the distinction
Verify the story with proportional evidence Verify the story with proportional evidence — the distinction These concepts answer different questions. Read each definition in the context of the section. Missing evidence A claim remains unsupported Contradictory evidence Sources disagree on the same claim
Missing evidence
  • A claim remains unsupported
Contradictory evidence
  • Sources disagree on the same claim
These concepts answer different questions. Read each definition in the context of the section. Chapter sources · Open image
Fulfillment evidence
Verify the story with proportional evidence Fulfillment evidence Fictional teaching record. Stock receipt still unproven. Fulfillment evidence Illustrative data; not a real customer record or a prescribed policy. Claim stock already purchased Merchant statement Support supplier invoice Purchase evidence Gap delivery confirmation absent Stock receipt still unproven Each request should improve the decision
Fictional educational excerpt / Not for execution

Fulfillment evidence

Illustrative data; not a real customer record or a prescribed policy.

  1. Claimstock already purchased

    Merchant statement

  2. Supportsupplier invoice

    Purchase evidence

  3. Gapdelivery confirmation absent

    Stock receipt still unproven

Each request should improve the decision

Fictional teaching record. Stock receipt still unproven. Chapter sources · Open image
Verify the story with proportional evidence — control and failure modes
Verify the story with proportional evidence Verify the story with proportional evidence — control and failure modes Each request should improve the decision. The branches show why alternative designs fail. Control design Request evidence tied to the unresolved claim. Each request should improve the decision. Failure mode 1 Collect unrelated personal records. They may add no useful support. avoid Failure mode 2 Treat absence as automatic fraud. Missing and false are different. avoid Failure mode 3 Ignore contradictions after one positive check. The conflict still needs resolution. avoid
Control design

Request evidence tied to the unresolved claim. Each request should improve the decision.

Failure mode 1avoid
Collect unrelated personal records. They may add no useful support.
Failure mode 2avoid
Treat absence as automatic fraud. Missing and false are different.
Failure mode 3avoid
Ignore contradictions after one positive check. The conflict still needs resolution.
Each request should improve the decision. The branches show why alternative designs fail. Chapter sources · Open image

Make approval conditional and reviewable

Make approval conditional and reviewable — the flow
Make approval conditional and reviewable Make approval conditional and reviewable — the flow Follow the sequence. Revisit broken assumptions. Approve scope State the permitted model Set conditions Define measurable boundaries Monitor change Revisit broken assumptions
  1. Approve scopeState the permitted model
  2. Set conditionsDefine measurable boundaries
  3. Monitor changeRevisit broken assumptions
Follow the sequence. Revisit broken assumptions. Chapter sources · Open image

An underwriting result can approve a defined model with limits, reserve terms, review triggers, and prohibited changes. Document the scope so the merchant and operations teams know what was approved. A vague approved status is hard to enforce when the business changes.

Connect conditions to monitoring. If the approval assumes delivery within seven days, the team needs evidence when delivery extends to ninety days. Conditions should have an owner, data source, and response. Review restrictions for proportionality and customer impact. The goal is a sustainable relationship whose assumptions remain visible.

Inside the mechanism. An approval can define an operating envelope: product scope, currencies, expected volume, average and maximum ticket, fulfillment horizon, payout terms, and review triggers. Store the reasons and evidence behind the envelope. Monitoring can then detect a material departure rather than applying an arbitrary generic threshold. A condition must have an owner and a response; an unenforced condition in an approval memo is not an operating control.

A concrete example. An approval can permit a limited amount of activity under conditions that respond to the actual exposure. Review triggers need to be observable after launch. The case has $385,000 of exposure. Its stated one-year PD and LGD imply $8,046.50 of expected loss, while the cover analysis leaves $273,000.00 of stress exposure. Monthly cash coverage is 1.32×. These are separate measures: one describes an average under probability assumptions, one describes available cover, and one describes a period’s funding capacity.

When the assumption fails. The merchant changes products and delivery timing without updating its approved terms. Reassess amount, duration, reserves, and monitoring when the economic promise changes. The following worked sequence shows the reference condition, a stress condition, and a response condition with explicit synthetic data. These are comparative assumptions, not measured causal effects.

Follow a worked case3 conditions · 36 figures

An approval can permit a limited amount of activity under conditions that respond to the actual exposure. Review triggers need to be observable after launch.

Make approval conditional and reviewable — the distinction
Make approval conditional and reviewable Make approval conditional and reviewable — the distinction These concepts answer different questions. Read each definition in the context of the section. One-time status Approved without operating context Conditional approval Defined model and review triggers
One-time status
  • Approved without operating context
Conditional approval
  • Defined model and review triggers
These concepts answer different questions. Read each definition in the context of the section. Chapter sources · Open image
Approval record
Make approval conditional and reviewable Approval record Fictional teaching record. Responsible reviewer. Approval record Illustrative data; not a real customer record or a prescribed policy. Model immediate-delivery goods Approved scope Change trigger advance sales Different exposure Owner merchant underwriting Responsible reviewer Unobserved conditions cannot be enforced reliably
Fictional educational excerpt / Not for execution

Approval record

Illustrative data; not a real customer record or a prescribed policy.

  1. Modelimmediate-delivery goods

    Approved scope

  2. Change triggeradvance sales

    Different exposure

  3. Ownermerchant underwriting

    Responsible reviewer

Unobserved conditions cannot be enforced reliably

Fictional teaching record. Responsible reviewer. Chapter sources · Open image
Make approval conditional and reviewable — control and failure modes
Make approval conditional and reviewable Make approval conditional and reviewable — control and failure modes Unobserved conditions cannot be enforced reliably. The branches show why alternative designs fail. Control design Tie conditions to measurable monitoring. Unobserved conditions cannot be enforced reliably. Failure mode 1 Approve all future business models. The original evidence may not support them. avoid Failure mode 2 Set a limit without an owner. Breaches may receive no response. avoid Failure mode 3 Keep conditions hidden from operations. The team cannot apply them consistently. avoid
Control design

Tie conditions to measurable monitoring. Unobserved conditions cannot be enforced reliably.

Failure mode 1avoid
Approve all future business models. The original evidence may not support them.
Failure mode 2avoid
Set a limit without an owner. Breaches may receive no response.
Failure mode 3avoid
Keep conditions hidden from operations. The team cannot apply them consistently.
Unobserved conditions cannot be enforced reliably. The branches show why alternative designs fail. Chapter sources · Open image

Chapter connections

Continue with Credit risk and repayment capacity to follow the next part of the system. Use the glossary for terminology and risk mathematics for formulas and worked calculations.

Sources

Reviewed 2026-09-17
  1. OCC Comptroller’s Handbook: merchant processing
  2. Stripe: how disputes work (provider example)