By Anthony Lewis September 6, 2026
A CBD merchant account terminated after approval can feel contradictory. Underwriting reviewed the business, approved the products, activated the account, and allowed transactions to run—so why would the same account be questioned or closed months later?
The reason is that high-risk merchant approval is better understood as a snapshot of the business at a particular point in time. It is not permanent approval of every product, URL, marketing change, fulfillment arrangement, or cannabinoid the merchant might add later.
Post-approval monitoring can compare the live business with the business originally presented to underwriting. Depending on the acquirer, processor, card-network requirements, merchant agreement, and risk program involved, that can include website or URL monitoring, catalog reviews, transaction-pattern analysis, dispute monitoring, document refreshes, and follow-up underwriting.
Mastercard’s current rules, for example, expressly recognize merchant website URL monitoring as a Merchant Monitoring Service Provider function. Mastercard’s February 2026 Security Rules also describe a Merchant Monitoring Program under which participating acquirers use approved monitoring providers to scan and persistently monitor merchant activity and URLs.
Those provisions should not be interpreted as a universal CBD review schedule, but they demonstrate why merchants should assume that a website can be reviewed again after onboarding.
For a CBD merchant trying to survive a review, the operational objective is straightforward: keep the live business consistent with the risk profile that was approved, document material changes before launching them, maintain usable product and COA records, respond to underwriting requests on time, and preserve financial evidence immediately if restrictions or termination occur.
Why CBD Merchant Account Terminated After Approval
Initial approval answers a limited question: Is the merchant that underwriting reviewed acceptable under the processor’s current policies and risk appetite?
It does not necessarily answer a much broader question: “Will every future version of this merchant remain acceptable?”
At onboarding, an underwriter may have reviewed a defined legal entity, DBA, website, product list, expected processing volume, fulfillment model, refund policy, ownership structure, supplier information, sales channels, and supporting documentation. The merchant that exists six or twelve months later may look materially different.
That difference is the heart of a post-approval underwriting review CBD merchants should understand.
A business originally approved for hemp-derived CBD tinctures, capsules, and topicals could later:
- add new cannabinoid categories;
- launch delta-8 or THCA products;
- create a subscription program;
- change fulfillment providers;
- start shipping into additional jurisdictions;
- alter refund or cancellation terms;
- substantially increase transaction volume;
- change its website claims;
- add additional domains or landing pages;
- experience a rise in disputes or refunds; or
- allow COA documentation to become stale or inaccessible.
Any one of those developments may create questions because the merchant being monitored is no longer identical to the merchant represented during onboarding.
This is why merchants should separate initial underwriting from ongoing risk acceptance.
For a deeper explanation of the original onboarding stage, see how to set up a CBD merchant account rather than treating this article as another initial-approval guide.
Approval also does not override the merchant agreement. The agreement may contain ongoing duties concerning truthful disclosure, permitted products, prohibited activity, changes in ownership or business model, disputes, security, website operation, or cooperation with reviews.
What a CBD Account Periodic Review Actually Re-Checks

A CBD account periodic review should not be pictured as one standardized checklist that every high-risk processor runs every 30, 60, or 90 days. There is no universal review interval that applies to every CBD merchant.
Monitoring may instead be continuous, event-driven, processor-specific, acquirer-specific, network-driven, or performed when risk indicators change.
Mastercard’s current Merchant Monitoring Program is useful evidence of how sophisticated monitoring can operate. Participating acquirers must use approved Merchant Monitoring Service Providers for specified monitoring functions, and Mastercard’s rules describe merchant website and URL content monitoring as part of that ecosystem.
For a CBD merchant, possible review areas include:
| Review Area | What Processor May Look At | Merchant Record to Keep |
| Website | Products, claims, policies, business identity, URLs | Archived pages, screenshots, change log |
| Product catalog | Newly added SKUs or categories | Approved product matrix |
| COAs | Batch coverage, report availability, product matching | COA library and archived PDFs |
| Transactions | Material changes in volume, ticket size or patterns | Monthly processing statements |
| Chargebacks | Dispute volume and reasons | Chargeback reports and evidence |
| Refunds | Refund activity or complaint patterns | Refund logs and policies |
| Fulfillment | Delays, complaints or delivery issues | Tracking and fulfillment records |
| Descriptor | Whether customers can identify charges | Statement descriptor documentation |
| Documents | Ownership, suppliers, bank records or registrations | Review-readiness folder |
The key question is usually not merely, “Does this merchant still sell CBD?”
It is closer to, “Does this merchant still resemble the business we agreed to acquire?”
That distinction matters because two merchants selling similar products can have very different post-approval risks. One may operate the same catalog, maintain good records, answer reviews promptly, and disclose every material change.
Another may have doubled its product categories, changed fulfillment practices, introduced new cannabinoids, and allowed supporting documents to fall behind.
A processor may also examine payment performance independently of product compliance. A merchant can sell products that remain within the approved scope and still trigger attention because disputes, refunds, fraud indicators, customer complaints, or fulfillment problems deteriorate.
For a more focused discussion of dispute controls, see handling chargebacks in the CBD industry.
How CBD Website Compliance Rescans Work

A CBD website compliance rescan can reveal changes that would never appear on an old merchant application.
The website is the public representation of what the merchant actually sells today. It can therefore provide an acquirer or monitoring provider with evidence that the live business differs from underwriting records.
Mastercard’s current rules identify merchant website URL content monitoring as a formal monitoring-provider function and describe monitoring for activity that was not fully disclosed to the acquirer or payment facilitator.
Depending on the review, monitored material can include:
- homepage content;
- product and collection pages;
- active SKUs;
- ingredient descriptions;
- product categories;
- COA links;
- refund and return policies;
- shipping terms;
- customer-service details;
- legal-business and DBA identity;
- subscription disclosures;
- checkout representations;
- age controls where applicable;
- additional URLs associated with the merchant; and
- material marketing claims.
A site can be acceptable at onboarding and problematic later without anyone intentionally trying to circumvent underwriting.
Marketing teams change copy. A developer replaces a COA application. A product manager adds a category. An old lab removes a hosted report. A fulfillment team changes shipping policies. An SEO contractor republishes old claims.
These are ordinary business events—but in a high-risk acquiring relationship, ordinary changes can alter the underwriting record.
Broken links are more important than they look
Suppose a product page correctly linked to a batch report when underwriting reviewed it. Six months later, the lab redesigns its website and the old URL returns a 404 error.
The merchant may still possess a legitimate COA. But a compliance reviewer following the public link now sees missing documentation.
That creates an avoidable question: does the supporting report still exist?
Merchants should therefore test public COA links rather than merely checking whether a “Lab Results” button appears on the page.
A separate cbdoilmerchantservices.com guide examines card-network rules and CBD health-claim reviews, which is the better place for an extended discussion of advertising claims.
For current regulatory context, FDA continues to state that it has approved only one CBD prescription drug and continues to raise concerns about unapproved CBD products and unproven medical claims. FTC guidance separately requires health-related advertising claims to be truthful, non-misleading, and appropriately substantiated.
Product Drift: When Your Catalog No Longer Matches the Approved Account
Product drift occurs when the business being processed gradually moves away from the products, services, sales channels, or risk characteristics that underwriting originally evaluated.
It often happens incrementally.
Consider this simplified example.
Originally approved catalog:
- CBD tinctures;
- CBD capsules;
- CBD topicals.
Later the merchant adds:
- delta-8 gummies;
- THCA flower;
- other intoxicating or higher-risk hemp-derived products.
The question is not whether all those products have one universal legal classification. They do not, and product treatment can differ by jurisdiction, formulation, processor, sponsor bank, card network, and other facts.
The acquiring issue is that the catalog may now present a materially different risk profile from the one originally approved.
| Change | Potential Underwriting Significance | Re-Underwriting Needed? |
| New flavor of an already approved formulation | Often limited | Ask processor if uncertain |
| New CBD format | Could alter documentation requirements | Processor-specific |
| New supplier | May affect product documentation | May require notification |
| New cannabinoid category | Potentially material | Confirm before launch |
| Delta-8 products | Potentially material/high-risk | Obtain processor direction first |
| THCA products | Potentially material/high-risk | Obtain processor direction first |
| HHC/emerging cannabinoid | Potentially material | Obtain processor direction first |
| New subscription model | Changes billing behavior | Review processor/network requirements |
| New domain or sales channel | Alters monitored business footprint | Disclose as required |
“Re-underwriting needed?” cannot responsibly be answered with a universal yes/no rule for every row. The merchant agreement and processor’s current policies control that relationship.
The operational principle is stronger than guessing: material changes should be disclosed before they become live transaction activity.
Why Adding Delta-8 or THCA Can Trigger Re-Underwriting or Termination

Searches involving adding delta-8 merchant account termination often begin with a mistaken assumption: “My processor approved hemp-derived CBD, therefore every hemp-derived cannabinoid is automatically covered.”
That assumption can create substantial acquiring risk.
A processor may distinguish between non-intoxicating CBD merchandise and products involving delta-8 THC, THCA, HHC, hemp-derived THC formulations, or other emerging cannabinoid categories.
The distinctions can reflect legal uncertainty, sponsor-bank policy, network risk programs, product composition, state restrictions, marketing practices, fulfillment locations, or the processor’s own risk appetite.
Policies also change. A product that one provider accepts does not establish what another provider must accept.
Why underwriting cares about the distinction
Underwriting is not simply approving the word “hemp.”
It is evaluating a defined merchant and a defined business model.
If the submitted product matrix showed CBD oils, capsules, and lotions, an underwriter’s decision may have been based on that product mix. Adding an intoxicating cannabinoid category can therefore raise a different question regardless of whether the merchant considers both categories part of the same hemp business.
The reviewer may need to evaluate new:
- labels;
- ingredient data;
- COAs;
- cannabinoid profiles;
- supplier records;
- product URLs;
- shipping restrictions;
- age-related controls where relevant;
- fulfillment arrangements; and
- jurisdictional limitations.
There is no responsible universal statement that adding delta-8 or THCA automatically produces termination. Some acquiring programs may prohibit a category; others may subject it to separate underwriting; policies can change.
The dangerous operational move is launching first and asking later.
If monitoring detects a materially different catalog before the merchant discloses it, the issue can become both product acceptability and whether the merchant accurately represented its activity.
Mastercard’s rules are particularly relevant to the disclosure principle because its monitoring framework includes attention to activity that was not fully disclosed to an acquirer or payment facilitator.
COA Expiration, Missing Batch Reports, and Broken Links
A COA expiration merchant account problem is frequently misunderstood because there is not one universal card-network rule saying every Certificate of Analysis “expires” after a fixed number of days.
A COA can nevertheless become operationally stale.
For example:
- the report applies to an old batch no longer being sold;
- a new batch is live without corresponding documentation;
- the SKU name no longer matches the report;
- the batch number cannot be reconciled;
- the merchant changed suppliers;
- the lab-hosted URL disappeared;
- the product formulation changed;
- the public COA page points to a superseded document.
The compliance problem is therefore less about inventing a universal expiration date and more about whether current products can be connected to relevant, current supporting documentation.
Why batch matching matters
Imagine that a merchant’s storefront sells “CBD Sleep Gummies – Batch 2408,” but the available COA relates to Batch 2311.
The document may be authentic, but it does not necessarily document the inventory currently being offered.
That mismatch can surface during a catalog review.
A better control is a traceable chain:
active SKU → active batch or lot → applicable report → public link → archived internal copy
This also helps the merchant answer underwriting quickly instead of searching through email attachments after a review notice arrives.
How to Maintain a Current COA Library
A usable COA library should function as an operational database rather than an unsorted cloud folder.
Track at least the information needed to identify the product and applicable report.
| Field | Why Keep It |
| SKU | Matches documentation to storefront item |
| Batch/Lot | Connects inventory to a particular report |
| Lab | Identifies the testing source |
| Test date | Helps show when testing occurred |
| Cannabinoid profile | Preserves relevant product results |
| Contaminant-testing record | Preserves available safety-test documentation |
| Public URL | Allows storefront/reviewer access |
| Internal copy | Preserves evidence if external URL disappears |
| Archive date | Shows when the merchant retained the document |
| Product status | Active, discontinued or pending |
A practical internal record might look like this:
| SKU | Batch | Test Date | Public Link | Status |
| CBD-TIN-1000 | LOT-A125 | Recorded | Verified URL | Active |
| CBD-CAP-030 | LOT-C219 | Recorded | Verified URL | Active |
| CBD-TOP-500 | LOT-T087 | Recorded | Needs update | Hold internally |
| CBD-GUM-OLD | LOT-G041 | Recorded | Archived | Discontinued |
Do not rely exclusively on a third-party lab URL.
If the laboratory redesigns its portal, changes vendors, restructures URLs, or removes historical reports, the merchant could lose access to documentation it previously supplied.
Maintain an internal read-only archive as well.
Website COA Links and Catalog Matching
Website compliance becomes easier when the product catalog and documentation system use the same identifiers.
Every active product should be traceable to its supporting records. Rebranded products, bundles, size variants, duplicate SKUs, and discontinued products deserve particular attention because they can create mismatches between what a reviewer sees and what the merchant can document.
For discontinued merchandise, decide whether the page remains publicly purchasable, remains indexed for informational purposes, redirects elsewhere, or has been removed.
Do not leave an obsolete product page accepting orders simply because inventory management and website management were handled by different teams.
A useful internal monthly check asks:
- Which products are purchasable today?
- Which batch or lot is currently shipping?
- Which documentation supports each one?
- Does the public URL work?
- Does the product name match the report?
- Have any formulations or suppliers changed?
- Is underwriting approval on file for material category changes?
That process is much more reliable than waiting for an acquirer to identify the mismatch first.
Chargeback and Refund Monitoring During Periodic Reviews
Product documentation is only one side of post-approval monitoring.
Payment performance matters too.
A merchant whose products remain within the approved catalog can still generate additional risk if customers increasingly dispute transactions, request refunds, complain about fulfillment, or say they did not understand recurring charges.
A review may therefore consider:
- dispute activity;
- chargeback reasons;
- refund activity;
- fraud patterns;
- delivery complaints;
- transaction-ticket changes;
- recurring-billing complaints;
- customer-service failures; and
- descriptor confusion.
This article intentionally does not publish a universal chargeback ratio and call it “the termination threshold.” Card-network monitoring programs and acquirer tolerances have specific definitions and can change, while processors may impose contractual controls beyond network programs.
Instead, CBD merchants should monitor their own trend line.
If disputes rise sharply after a new subscription program, fulfillment partner, product category, advertising campaign, or billing descriptor change, investigate the operational cause before a periodic review forces the issue.
What a Post-Approval Underwriting Review Request May Ask For
A post-approval review request can range from a narrow question about one URL to a broader document refresh.
Depending on the situation, a processor or acquirer may request some combination of:
- updated product list;
- active website URLs;
- COAs;
- supplier invoices;
- labels;
- product specifications;
- fulfillment records;
- shipping information;
- bank statements;
- processing statements;
- chargeback reports;
- refund policy;
- terms and conditions;
- subscription terms;
- ownership information;
- business registrations or licenses where applicable;
- written explanation of catalog changes.
Do not assume that every reviewer will request all of these.
The merchant’s first task is to answer exactly what was requested rather than dumping a disorganized folder of irrelevant records into an email.
A simple response tracker helps:
| Requested Item | Source | Status | Submission Date |
| Current product matrix | Compliance folder | Ready | Record when sent |
| Product URLs | Website export | Ready | Record when sent |
| COAs | COA library | Needs validation | Record when sent |
| Supplier invoices | Accounting | Requested internally | Record when sent |
| Processing statements | Processor portal | Downloaded | Record when sent |
| Refund policy | Website archive | Verified | Record when sent |
How to Respond Before the Deadline
Review notices can contain a stated response deadline. There is no responsible universal rule that every CBD processor gives 48 hours, five days, seven days, or another fixed period.
Use the deadline in the actual notice.
The response workflow should be:
- Read the request line by line. Separate each requested document or action.
- Identify the stated deadline. Put it on the operational calendar immediately.
- Assign one internal owner. Avoid parallel, contradictory responses from multiple employees.
- Freeze unapproved material catalog changes. Do not add another risk variable while the account is under review.
- Gather requested documents.
- Test all URLs. Especially product, policy, contact and COA links.
- Resolve documentation gaps.
- Explain catalog changes accurately.
- Submit one organized package where the processor permits it.
- Retain proof of delivery.
- Track every follow-up request.
Do not omit an actively sold product merely because you think it will concern underwriting. Deliberate nondisclosure can make a manageable product question into a credibility problem.
Hold vs. Suspension vs. For-Cause Termination
“Frozen,” “held,” “suspended,” and “terminated” are often used interchangeably by merchants even though they can describe very different operational situations.
Processor terminology varies, so the actual notice and merchant agreement control. As a working framework:
| Status | Processing | Funding | Account Status | Immediate Action |
| Hold | May continue | Some payouts may be delayed | Usually still open | Identify funds affected and review reason |
| Suspension | May be temporarily restricted | May also be restricted | Relationship may remain open | Confirm whether transactions must stop |
| Termination | Stops or winds down | Final settlement subject to agreement | Relationship ended | Preserve all records immediately |
| For-cause termination | Usually ended | Reserve/funding treatment may be affected | Relationship ended for stated risk/compliance reason | Obtain reason and preserve documentation |
Hold
A hold typically concerns access to funds rather than automatically proving that the merchant relationship has ended.
The exact structure matters.
Ask:
- Are new transactions still authorized?
- Are all payouts delayed or only certain funds?
- Is an existing reserve involved?
- What documents are required?
- What is the stated reason?
- What happens to refunds and disputes during the review?
Suspension
A suspension may temporarily restrict transaction acceptance, funding, or both.
Do not assume that a temporarily unavailable MID can be replaced by quietly routing the same activity through another undisclosed merchant account.
Transactions should be processed only through properly approved accounts for the actual merchant activity involved.
Termination
Termination ends the acquiring relationship under the terms of the agreement and notice.
The merchant should immediately determine:
- final processing date;
- treatment of unsettled transactions;
- pending refunds;
- dispute access;
- reserve treatment;
- portal-access period;
- recurring-payment implications; and
- document-retention needs.
For-Cause Termination
A for-cause termination generally indicates that the closure is being attributed to a particular contractual, risk, compliance, fraud, or other serious event rather than a routine commercial exit.
Its consequences depend on the facts and agreement.
Do not assume that every for-cause termination means MATCH reporting. Mastercard MATCH uses defined reporting circumstances.
MATCH Exposure and Why Termination Reason Matters
Mastercard describes MATCH as a system that gives acquirers risk information concerning certain previously terminated merchants. Current Mastercard materials should be consulted for the precise applicable framework rather than relying on generic statements that MATCH is simply a blacklist.
Mastercard’s February 3, 2026 Security Rules contain specific MATCH reason-code criteria and reporting provisions. That alone demonstrates why “account terminated” and “merchant placed on MATCH” are not equivalent statements.
Mastercard has also introduced MATCH Pro, and its March 2026 privacy notice describes the service as supporting financial institutions’ handling of merchant fraud-risk information.
If an account is closed, document:
- processor’s stated termination reason;
- dates of notices;
- correspondence;
- products involved;
- remediation requested;
- remediation completed;
- final processing date;
- financial reconciliation;
- any information the acquirer provides concerning network reporting.
Do not attempt to evade legitimate MATCH screening by creating misleading entities, undisclosed websites, nominee ownership, or misrepresented merchant applications.
Accurate records are more useful. A future underwriter may ask what occurred, and a documented explanation is substantially better than guessing months later.
Product Removal After a Review Starts
If underwriting flags a SKU, obtain clear instructions.
A processor may ask that a product be removed from sale while it evaluates the account. If so, document:
- SKU;
- affected URL;
- instruction received;
- time sales were disabled;
- advertising changes made where appropriate;
- inventory disposition;
- screenshots;
- follow-up submission.
Preserve the underlying records.
Do not delete transaction history, supplier invoices, COAs, or inventory records merely because the product has been removed from the public site.
Likewise, do not temporarily hide the product until the compliance review ends and then quietly restore it without authorization. That defeats the purpose of remediation and may create a more serious disclosure problem.
Website Changes During Review
Legitimate remediation should make the live business accurately reflect what the merchant says it is doing.
Changes might include:
- repairing broken COA links;
- updating product records;
- correcting outdated policies;
- updating contact details;
- fixing subscription disclosures;
- removing material the processor has directed the merchant to stop offering;
- correcting unsupported marketing representations.
Document every material change.
Save:
- before screenshots;
- after screenshots;
- page URL;
- change date;
- person responsible;
- reason for the change;
- processor ticket or email reference where relevant.
Do not make cosmetic changes designed to conceal the real catalog, send monitoring systems to alternate content, or show different products to reviewers and customers.
How to Expand Your CBD Product Line Without Surprising Underwriting
Catalog growth should have a change-management workflow.
Do not wait until after launch to discover whether the acquiring program considers the new category acceptable.
Use this sequence:
- Identify the proposed SKU or category.
- Gather supporting product documents and current COAs.
- Review applicable shipping and jurisdictional restrictions.
- Ask the processor whether the change requires re-underwriting.
- Provide requested product lists, labels and URLs.
- Obtain written approval or confirmation where available.
- Complete any MID, gateway or underwriting changes required.
- Only then make the new category available for processing.
For a significant product expansion, underwriting may request:
- updated product matrix;
- cannabinoid profile;
- COAs;
- packaging/labels;
- website URLs;
- supplier information;
- fulfillment details;
- shipping controls;
- additional business documentation.
Approval is never guaranteed.
Approval in Writing Matters
A casual telephone comment such as “that sounds fine” is weak evidence if a compliance reviewer later asks who approved a materially different product category.
Whenever possible, keep written evidence such as:
- processor emails;
- support tickets;
- compliance correspondence;
- updated product matrices;
- underwriting confirmations;
- addenda where provided.
Not every provider will issue a formal amendment for every product change. The goal is to preserve the strongest evidence actually available.
Website Rescan Checklist
Before a major launch, after material site changes, and periodically as an internal compliance practice, inspect:
- Active product URLs
- Approved product categories
- No undisclosed material SKUs
- Working COA links
- Current product/batch mapping
- Accurate product labels
- Current shipping restrictions
- Refund and return policy
- Privacy policy
- Terms and conditions
- Subscription terms where applicable
- Customer-support contact information
- No misleading medical claims
- Consistent legal entity and DBA identity
- Accurate fulfillment information
- Functional checkout and policy links
This is an internal risk-control cadence, not a representation of how frequently any processor will rescan a merchant.
Product-Catalog Change Log
A simple catalog log can prevent the phrase “we don’t remember when that product went live” from appearing during an underwriting review.
| Date | SKU Added/Removed | Risk Category | Processor Notified? | Approval Reference |
| YYYY-MM-DD | CBD SKU | Existing category | If required | Email/ticket |
| YYYY-MM-DD | New cannabinoid SKU | Material change | Yes/No | Reference |
| YYYY-MM-DD | Discontinued SKU | Removal | As applicable | Internal record |
Add columns for supplier, URL, batch documentation, employee approving the release, and processor response if those details matter to your operation.
This creates evidence that catalog changes were deliberate and controlled rather than silently introduced.
Build a Periodic Review Readiness File
The best time to assemble underwriting evidence is before the review request arrives.
Maintain a secure folder containing:
- merchant agreement;
- approved product list;
- onboarding submissions;
- processor approval correspondence;
- later product-change approvals;
- COA library;
- supplier invoices;
- fulfillment records;
- refund policy;
- shipping policy;
- subscription disclosures;
- monthly processing statements;
- funding reports;
- reserve reports;
- chargeback reports;
- refund reports;
- website change log;
- processor correspondence.
Use versioned filenames instead of continually overwriting the same document.
For example:
Refund-Policy-2026-08-15.pdf
is more useful for an audit trail than:
refund-policy-final-FINAL2.pdf.
What to Do if the Account Is Placed on Hold
First determine what “hold” means in the processor’s notice.
Identify whether:
- processing continues;
- funding has stopped;
- only certain transactions are affected;
- a reserve is being increased;
- a specific payout is under review;
- refunds remain available.
Then request the exact document list and reason provided by the processor.
Avoid reacting to a funding hold by suddenly changing product categories, opening undisclosed processing routes, or restructuring the website in ways that make the business harder to understand.
At the same time, protect cash flow.
Export current receivables, settlement records, outstanding refund obligations, reserve balances, payroll commitments, tax obligations, and accounts-payable requirements so management understands the liquidity impact.
Keep customer service operating. A funding restriction can become a larger dispute problem if customers cannot obtain delivery updates or legitimate refunds.
No one can responsibly promise that a hold will be released.
What to Do if Processing Is Suspended
If transactions are suspended, establish whether new card sales must stop immediately.
Do not repeatedly test customer cards against a disabled account or route sales through an unrelated or undisclosed MID.
If contingency processing is necessary, it should be through an account that has properly underwritten and approved the actual merchant, products, URLs, sales channels, and transaction activity.
Continue working the review:
- confirm outstanding questions;
- supply requested records;
- document product remediation;
- confirm website changes;
- preserve correspondence;
- record the date of every submission.
Operational discipline becomes especially important because a suspension can affect customer communication, recurring orders, refunds and fulfillment simultaneously.
What to Do in the First Week After Termination
The following is an operational response plan, not a legal or network-mandated timetable.
The purpose is to preserve information before portal access, staff memory, settlement visibility, or supporting records become harder to retrieve.
| Timeframe | Action | Why It Matters |
| Day 1–2 | Save termination notice and agreement | Establishes governing records |
| Day 1–2 | Export processing/funding statements | Preserves transaction history |
| Day 1–2 | Export reserve records | Supports later reconciliation |
| Day 1–2 | Save chargeback history | Preserves dispute evidence |
| Day 1–2 | Capture portal screenshots | Documents balances/status |
| Day 2–4 | Request final funding status | Clarifies outstanding money |
| Day 2–4 | Confirm refund/dispute access | Helps serve existing customers |
| Day 2–4 | Identify vault/token owner | Important for subscriptions |
| Day 4–7 | Build future underwriting file | Supports a transparent new application |
| Day 4–7 | Reconcile pending settlements | Finds missing or withheld amounts |
| Day 4–7 | Document remediation | Preserves explanation of closure |
Day 1–2: Preserve evidence first
Download:
- termination notice;
- merchant agreement;
- amendments;
- monthly statements;
- daily settlement reports;
- payout reports;
- reserve reports;
- fee statements;
- chargeback reports;
- processor correspondence.
Take screenshots of important portal pages showing account status, balance, reserve information, unsettled transactions, open disputes, and other relevant information.
Do not assume portal access will remain unchanged indefinitely.
Day 2–4: Understand the financial tail
Ask the processor for available written information concerning:
- final settlements;
- withheld funds;
- reserve balance;
- applicable reserve-release provisions;
- outstanding disputes;
- refunds;
- dashboard access;
- final statement availability.
Do not assume that stopping processing causes every held dollar to be paid immediately. Reserve and settlement treatment depends on the agreement and the underlying risk exposure.
Day 4–7: Prepare for the next underwriting conversation
If seeking a new processor is appropriate, assemble a truthful account history.
Include:
- reason given for termination;
- products sold;
- material catalog changes;
- remediation completed;
- recent statements;
- chargeback history;
- current COAs;
- supplier documentation;
- current URLs;
- updated product matrix.
Do not characterize a compliance termination as a voluntary processor switch if that is not what happened.
Preserve Funding and Reserve Records
Financial records deserve separate attention because termination creates a long settlement tail.
Save:
- daily funding reports;
- monthly statements;
- reserve ledgers;
- reserve deductions;
- fee reports;
- chargeback deductions;
- refund deductions;
- withheld balances;
- final settlement information;
- bank deposits corresponding to processor payouts.
Reconcile three amounts separately:
- what transactions were processed;
- what the processor reports as payable or reserved;
- what actually reached the bank.
A later disagreement becomes difficult to investigate if the only evidence existed in a portal that is no longer available.
Preserve Chargeback and Refund Records
Cardholder disputes can continue to require attention after the merchant stops accepting new transactions.
Keep:
- dispute notices;
- representment submissions;
- delivery records;
- tracking;
- refund records;
- customer-service communications;
- invoices;
- subscription consent where applicable;
- cancellation records;
- transaction identifiers.
The records may also be useful when a future underwriter asks about historical dispute performance.
Recurring Billing After Termination
Termination can disrupt more than the MID itself.
A subscription merchant should determine:
- whether scheduled transactions will stop;
- who owns or controls the payment vault;
- whether gateway access remains available;
- whether tokens are portable;
- whether token migration is technically and contractually supported;
- how customer billing consent records are retained.
Never respond by exporting unprotected card numbers into spreadsheets or insecure files.
PCI SSC’s current document library lists PCI DSS v4.0.1, published in June 2024, as the current PCI DSS standard. Its future-dated v4.x requirements became effective on March 31, 2025.
Visa’s current public rules also contain requirements for stored credentials and recurring arrangements, including information that must be established in cardholder agreements depending on transaction type.
The focus after termination should therefore be controlled migration and continued protection of account data—not insecure PAN extraction.
Common CBD Periodic Review Mistakes
Many post-approval failures are process failures rather than dramatic one-time events.
| Mistake | Why It Creates Risk | Better Approach |
| Treating approval as permanent | Business can drift from underwriting profile | Maintain approved baseline |
| Adding delta-8/THCA without notice | Category may fall outside approved scope | Ask before launch |
| Stale COAs | Current inventory may not map to documentation | Maintain batch-level library |
| Broken COA links | Reviewer cannot reach supporting report | Test links regularly |
| Marketing-copy drift | Site no longer matches reviewed presentation | Add compliance review to publishing |
| Ignoring review email | Processor cannot complete review | Log and respond by stated deadline |
| Partial document response | Creates additional questions | Map every request to evidence |
| Confusing hold with termination | Merchant may take wrong operational action | Confirm exact restriction |
| Deleting payout records | Makes reconciliation difficult | Export before access changes |
| Temporarily hiding flagged SKUs | Conceals rather than resolves issue | Remove only as directed and seek approval |
| No written approval records | Later reviewer cannot verify product change | Retain emails/tickets/addenda |
| Undisclosed fallback MID | Can create serious acquiring concerns | Use properly approved contingency processing |
Practical Periodic Review Survival Workflow
A repeatable process reduces the chance that a normal business change turns into an emergency.
- Maintain the product list underwriting actually approved.
- Keep a current COA library organized by SKU and batch.
- Record every material catalog change.
- Review website compliance before product launches.
- Monitor chargebacks and refunds for deterioration.
- Preserve monthly processing statements.
- Retain processor and underwriting correspondence.
- Notify the processor before material product expansion.
- Complete re-underwriting where required.
- Respond to review requests before the stated deadline.
- Correct documented deficiencies accurately.
- Preserve screenshots and evidence of remediation.
- If funds are held, determine precisely what funding is affected.
- If processing is suspended, do not route transactions through undisclosed accounts.
- If the account is terminated, preserve compliance and financial records immediately.
The broader lesson is that a mature CBD payment operation needs a change-control process.
Product, marketing, fulfillment, finance, customer service, and payments cannot work as completely independent functions when changes in one area can alter merchant-account risk.
CBD Periodic Review Readiness Checklist
Before the next CBD account periodic review, verify that you can check every applicable item below:
- Keep the originally approved product list on file.
- Track every material SKU or category change.
- Maintain current COAs by product and batch.
- Check public COA links regularly.
- Retain internal copies of COAs.
- Review website claims and policies.
- Verify current product URLs.
- Monitor chargebacks and refund trends.
- Keep current supplier documentation.
- Save monthly processing statements.
- Preserve underwriting emails and approvals.
- Maintain a product-catalog change log.
- Notify the processor before material product expansion.
- Complete re-underwriting when required.
- Respond to review requests by the stated deadline.
- Keep proof of every document submission.
- Document remediation with dates and screenshots.
- If an account is held, determine the exact funding restriction.
- If processing is suspended, stop using the affected account as directed.
- Do not send transactions through undisclosed replacement accounts.
- If terminated, preserve payout, reserve, refund and chargeback records immediately.
- Confirm ownership/control of recurring-billing tokens and vaults.
- Keep the merchant agreement and all amendments accessible.
Frequently Asked Questions
Why was my CBD merchant account terminated months after approval?
Because approval reflects the business underwriting evaluated at that time. Later product changes, website changes, documentation gaps, dispute problems, fulfillment issues, or other risk developments can trigger another review.
A CBD merchant account terminated after approval therefore does not necessarily mean the original underwriting was meaningless. It may mean the processor believes the current business no longer matches the originally accepted profile or its current requirements.
Do CBD processors periodically re-review accounts?
They can, but there is no universal schedule.
Reviews may be periodic, event-driven or supported by monitoring systems. Mastercard’s current rules expressly recognize merchant website URL monitoring and, for participating acquirers in its Merchant Monitoring Program, persistent monitoring by approved providers.
What does a CBD website compliance rescan check?
A review may examine active products, URLs, product descriptions, policies, COA links, business identity, subscriptions, customer-service information and material marketing content. The exact scope depends on the processor, acquirer, monitoring program and reason for review.
Can adding delta-8 cause merchant account termination?
It can create re-underwriting or termination risk if the processor does not permit the category or if the product materially changes the approved risk profile. It is not accurate to state that every processor automatically terminates every merchant selling delta-8.
Can adding THCA trigger re-underwriting?
Yes, it may.
An acquirer may treat THCA products differently from the CBD catalog it originally approved. Policies are provider-specific, so disclose the proposed category and obtain the processor’s current requirements before processing sales.
Do CBD COAs expire for merchant-account purposes?
There is no single universal card-processing expiration period for every CBD COA. A COA can nevertheless become operationally stale when it applies to an old batch, no longer matches the active SKU, reflects an outdated formulation, or becomes inaccessible.
How current should my COA library be?
It should accurately support the products and batches you are currently selling and retain historical records needed for your audit trail. Do not use an arbitrary number of months as a substitute for batch and product matching.
What documents might a processor request during a periodic review?
Possible requests include product lists, URLs, COAs, labels, supplier invoices, fulfillment evidence, financial statements, processing statements, policies, ownership information and registrations where relevant. Respond according to the actual request rather than assuming every review uses the same checklist.
How quickly do I need to respond to a review request?
Use the deadline stated in the processor’s communication. There is no universal CBD review-response period. Acknowledge the request, identify each requested item, assign an internal owner and retain proof of submission.
What is the difference between a hold and a suspension?
A hold may affect access to settlement funds while some processing continues. A suspension may restrict the ability to accept new transactions or otherwise use the account. Terminology varies, so confirm precisely what the notice says.
Does a for-cause termination mean I will be placed on MATCH?
Not automatically.
Mastercard MATCH uses defined reporting circumstances and reason criteria. A terminated merchant should obtain and retain the processor’s stated reason rather than assuming every for-cause closure produces MATCH reporting.
Should I notify my processor before adding new cannabinoids?
Yes when the new category could materially change what underwriting approved. Provide sufficient product detail for the processor to determine whether approval, additional documentation or re-underwriting is required.
Can I remove a flagged product and keep processing?
Possibly, depending on the processor’s instructions and review outcome. If instructed to disable a SKU, document its removal and provide evidence. Do not assume that temporarily hiding it authorizes relisting it after the review.
What should I save immediately after a termination notice?
Preserve the termination notice, merchant agreement, monthly statements, settlement reports, reserve ledger, chargeback records, refund information, underwriting correspondence, portal screenshots and product/compliance records. Also establish what access will remain available after closure.
Can I apply for a new processor after being terminated?
A termination does not by itself mean no provider can ever approve the business.
A new processor will perform its own underwriting and may ask for prior processing history and the reason for closure. Provide accurate information and disclose material product categories rather than attempting to recreate the same undisclosed risk elsewhere.
Conclusion
A CBD merchant approval is not a permanent exemption from underwriting. It is an approval of a particular merchant, product profile, website and operating model at a particular point in time.
Post-approval monitoring can test whether that profile still matches reality.
Website and catalog changes, new cannabinoid categories, deteriorating dispute performance, inaccessible COAs, or incomplete responses to underwriting requests can all create new questions months after an account becomes active.
Product drift deserves special attention. Adding delta-8, THCA, HHC or another materially different cannabinoid category should not be treated as automatically covered because an account was originally approved for CBD. Determine the processor’s requirements before launch and preserve written confirmation where available.
Likewise, keep COAs organized by current product and batch, verify public links, maintain internal copies, and record catalog changes.
If a review becomes a hold, suspension or termination, determine exactly what restriction applies. And if the account is terminated, preserve processing statements, reserve records, chargeback evidence, processor correspondence and portal data immediately.
The strongest post-approval strategy is not avoiding monitoring. It is maintaining a business that can explain and document what changed.
