PAYMENT GATEWAY β’ PAYMENT AGGREGATOR β’ MERCHANT ID β’ KYC β’ SETTLEMENT β’ CYBER FRAUD
Payment Gateways, Merchant IDs and Mule-Account Chains: Merchant KYC, Settlement Flow, Chargebacks and Platform Liability
Merchant Onboarding β’ MID Attribution β’ Escrow β’ Settlement Accounts β’ Chargebacks β’ Mule Accounts β’ PMLA
Research updated: 10 August 2026 | By Advocate Ankit Kumar Singh
Advocate Ankit Kumar Singh
Direct Answer: How Should a Payment Gateway or Merchant-ID Fraud Case Be Analysed?
Do not start with the name of the payment company.
Start with the fund flow.
CUSTOMER β PAYMENT β GATEWAY / AGGREGATOR β MERCHANT ID β ESCROW / SETTLEMENT β MERCHANT BANK ACCOUNT β DOWNSTREAM ACCOUNTS β ULTIMATE BENEFICIARY
Then separately map:
KYC + CONTROL + KNOWLEDGE + MONITORING + ECONOMIC BENEFIT.
The fact that a payment infrastructure processed a fraudulent customer payment does not automatically establish that every intermediary knowingly participated in the underlying fraud.
Payment Gateway and Payment Aggregator Are Not the Same Thing
The distinction can determine what records exist and what responsibilities may arise.
A payment gateway is principally a technology-routing layer.
A payment aggregator performs a broader merchant-payment function and may receive or pool customer payments before merchant settlement under the applicable regulated structure.
Therefore:
PAYMENT GATEWAY β PAYMENT AGGREGATOR.
Before alleging liability, identify which role the entity actually performed in the disputed transaction.
The Merchant ID Is a Starting Point, Not the Final Identity
A merchant ID may connect transactions to a specific merchant configuration.
But the investigation should go further.
For each MID identify:
- merchant legal name;
- merchant application;
- PAN;
- GST details where applicable;
- directors / partners;
- beneficial owners;
- website / application;
- settlement account;
- merchant category;
- dashboard users;
- related MIDs;
- transaction volume;
- chargeback history.
Build a Merchant-ID Attribution Matrix
| MID | Merchant | UBO | Website | Settlement Account |
|---|---|---|---|---|
| MID-001 | Entity A | _____ | _____ | _____ |
| MID-002 | Entity B | _____ | _____ | _____ |
Related MIDs can become important where the same beneficial owners, settlement accounts, devices or websites repeatedly appear.
Merchant Onboarding: Was There a Real Business?
A KYC document proves only what the document actually proves.
The merchant file should also answer:
- What business was declared?
- Was the website operational?
- Were goods or services actually offered?
- Was the merchant address real?
- Did transaction volume match the business?
- Did ticket size match the stated activity?
- Did customer complaints arise immediately?
- Did the merchant change activity after onboarding?
KYC Failure Is Not One Single Category
Distinguish:
1. FALSE DOCUMENT.
2. INADEQUATE BACKGROUND REVIEW.
3. BUSINESS-PROFILE MISMATCH.
4. FAILURE OF ONGOING MONITORING.
5. KNOWING COLLUSION.
These situations require different factual and legal analyses.
Settlement Accounts: Follow the Net Money, Not Only Gross Payment Volume
A merchant may process substantial gross volume while receiving a different net settlement after:
- refunds;
- chargebacks;
- fees;
- taxes;
- reserves;
- other contractual adjustments.
Build:
GROSS PAYMENTS - REFUNDS - CHARGEBACKS - FEES - RESERVES = NET SETTLEMENT
The actual settlement figure can be critical in loss, benefit and proceeds-of-crime analysis.
Escrow / Settlement Flow
The regulated payment-aggregation structure should be identified from the applicable RBI framework and the entity's actual account arrangement.
Do not rely mechanically on old terminology if the account architecture has changed.
Reconstruct:
CUSTOMER COLLECTION β AGGREGATOR SETTLEMENT STRUCTURE β MERCHANT ENTITLEMENT β NET SETTLEMENT β MERCHANT ACCOUNT
Then obtain the actual reconciliation.
The Downstream Settlement Trail
Suppose:
PA settlement: βΉ25 lakh.
It enters Merchant Account A.
Within minutes:
βΉ10 LAKH β ACCOUNT B
βΉ8 LAKH β ACCOUNT C
βΉ6 LAKH β ACCOUNT D
This downstream movement may justify scrutiny.
But it does not answer who controlled B, C and D or why the transfers occurred.
Mule-Account Chains: Prove Control, Not Merely Movement
A financial trail may show:
VICTIM β MERCHANT β SETTLEMENT ACCOUNT β ACCOUNT B β ACCOUNT C β CRYPTO / CASH / ASSET
For each account ask:
- Who is the account holder?
- Who controlled mobile banking?
- Whose device was used?
- Whose mobile number was registered?
- Who received OTPs?
- Who ordered the transfer?
- Who received commission?
- Who ultimately benefited?
ACCOUNT IN THE CHAIN β AUTOMATIC MULE KNOWLEDGE.
Chargebacks: Useful Evidence, but Not Automatic Proof of Fraud
A chargeback may arise from many reasons.
Therefore analyse:
- reason code;
- transaction ID;
- customer allegation;
- merchant response;
- proof of delivery;
- refund attempt;
- final chargeback result;
- whether settlement had already occurred.
The pattern matters more than the word itself.
High Chargeback Ratio: What Should Be Checked?
If a merchant shows an unusual dispute pattern, compare:
- total transactions;
- successful transactions;
- refunds;
- chargebacks;
- customer complaints;
- settlement holds;
- merchant-risk alerts;
- business category;
- historic baseline.
A sudden spike after a merchant changes products or websites can be particularly important.
Merchant Versus Aggregator Responsibility
| Issue | Merchant | Aggregator |
|---|---|---|
| Goods / service | Primary responsibility | Monitoring / contractual relevance |
| Merchant KYC | Must provide accurate records | Due-diligence responsibility under applicable framework |
| Settlement | Receives entitlement | May control collection/settlement flow |
| Customer fraud | Actual business conduct matters | Fraud-monitoring response matters |
| Chargebacks | Evidence / response | Dispute and settlement processing |
Liability ultimately depends on the particular statute, contractual role, knowledge, control and conduct.
Platform Liability: Ask What the Platform Could Actually Control
Relevant questions include:
- Could it approve or reject merchants?
- Could it suspend an MID?
- Could it hold settlements?
- Could it require additional KYC?
- Could it detect prohibited products?
- Did it receive chargeback data?
- Did it receive fraud alerts?
- Did it receive law-enforcement complaints?
- Did it permit the merchant to continue despite repeated red flags?
But failure to prevent fraud and knowing participation in fraud are not automatically the same legal proposition.
Merchant Website and Business-Substance Audit
Preserve:
- historical website snapshots;
- domain records;
- product catalogue;
- customer invoices;
- delivery records;
- inventory;
- customer support tickets;
- refund policy;
- terms of service;
- app history;
- merchant-admin access.
A merchant with perfect incorporation papers but no genuine fulfilment can present a very different risk profile from an operating business with isolated disputes.
Payment-Gateway Data Preservation
Relevant system evidence may include:
- MID configuration;
- API integration;
- merchant dashboard logs;
- settlement reports;
- transaction IDs;
- refund events;
- chargebacks;
- fraud alerts;
- IP / device records where retained;
- administrator changes;
- settlement-account changes;
- support tickets.
RBI's payment-system security framework expressly emphasises forensic readiness and preservation/analysis of relevant security and system events. ξ¨2ξ¨
Changing the Settlement Account Is a High-Value Investigative Event
If the merchant settlement account changed shortly before a fraud spike, obtain:
- request date;
- requesting user;
- verification process;
- old account;
- new account;
- beneficiary name;
- support ticket;
- approval log;
- subsequent settlement volume.
A compromised merchant dashboard and a knowingly altered settlement account are very different factual scenarios.
Merchant Onboarding and Ongoing Due Diligence
RBI's current KYC framework uses risk-based customer due diligence and ongoing updating. Its 2025 KYC FAQs recognise both face-to-face and approved non-face-to-face onboarding methods and require ongoing KYC updating according to risk. ξ¨3ξ¨
For a merchant investigation, therefore, do not ask only:
βWas KYC done on Day 1?β
Ask:
βWHAT HAPPENED AFTER ONBOARDING?β
ODR, Chargeback and Fraud Investigation Are Different Processes
RBI requires authorised payment system operators and participants to provide an Online Dispute Resolution mechanism for failed digital-payment disputes. ξ¨4ξ¨
But do not confuse:
- failed-transaction ODR;
- merchant refund;
- card chargeback;
- customer fraud complaint;
- cybercrime investigation;
- PMLA proceeding.
They can concern the same transaction while performing different legal and operational functions.
Chargeback Data Must Be Preserved
RBI's payment-data localisation FAQ specifically recognises that payment-system data may be accessed from India for subsequent activities such as chargebacks. ξ¨5ξ¨
This makes chargeback history a potentially important forensic dataset in merchant-fraud investigations.
Payment System Regulation: The Statutory Foundation
The Payment and Settlement Systems Act, 2007 provides for regulation and supervision of payment systems and designates RBI as the relevant regulatory authority. The Act contains the authorisation architecture for operation of payment systems. ξ¨6ξ¨
Accordingly, payment-fraud analysis should distinguish:
- merchant conduct;
- regulated payment-system activity;
- banking activity;
- technology outsourcing;
- criminal conduct.
When Can a Payment-Gateway Fraud Matter Become PMLA?
Not merely because the transaction is large.
Not merely because multiple mule accounts exist.
The PMLA sequence remains:
SCHEDULED OFFENCE β CRIMINAL ACTIVITY β PROPERTY β PROCEEDS OF CRIME β PAYMENT / SETTLEMENT TRAIL β PERSON-SPECIFIC SECTION 3 ROLE
A merchant-ID map can help trace the property, but it does not replace the statutory foundation.
Gross Merchant Volume Is Not Automatically the POC Figure
Assume:
Gross payment volume: βΉ5 crore.
Refunds: βΉ50 lakh.
Chargebacks: βΉ40 lakh.
Net merchant settlement: βΉ3.9 crore.
Alleged fraudulent customer payments: βΉ80 lakh.
These figures are not interchangeable.
The POC theory must identify:
- which transactions are criminally derived;
- which amount was actually settled;
- which merchant received it;
- what amount remained in escrow;
- what amount was refunded;
- what amount moved downstream.
40-Point Payment-Gateway / Merchant-ID Investigation Checklist
- Identify payment company.
- Identify whether PA, PG, acquirer or another role.
- Identify disputed MID.
- Identify sub-MID.
- Obtain merchant legal entity.
- Obtain onboarding application.
- Obtain PAN.
- Obtain GST details where applicable.
- Obtain directors/partners.
- Identify beneficial owner.
- Obtain declared business profile.
- Obtain expected turnover.
- Obtain expected ticket size.
- Obtain merchant website history.
- Obtain settlement account.
- Check changes in settlement account.
- Obtain transaction ledger.
- Obtain gross payment total.
- Obtain refunds.
- Obtain chargebacks.
- Obtain settlement reports.
- Obtain settlement UTRs.
- Obtain escrow reconciliation.
- Map downstream transfers.
- Identify mule-account allegations.
- Identify downstream account holders.
- Map device / mobile / email control.
- Obtain fraud alerts.
- Obtain merchant-risk history.
- Obtain customer complaints.
- Check fulfilment/delivery records.
- Check prohibited product allegations.
- Check related MIDs.
- Check same UBO across merchants.
- Check same bank account across merchants.
- Check repeated merchant closures.
- Identify actual alleged loss.
- Identify alleged criminal benefit.
- Identify POC separately.
- Attribute conduct person by person.
Payment-Gateway Investigation Flowchart
CUSTOMER
β
PAYMENT
β
GATEWAY / AGGREGATOR
β
MID / SUB-MID
β
ESCROW / SETTLEMENT
β
MERCHANT ACCOUNT
β
DOWNSTREAM ACCOUNTS
β
ULTIMATE BENEFICIARY
+
KYC β CONTROL β KNOWLEDGE β BENEFIT β LEGAL ROLE
Frequently Asked Questions
1. What is a merchant ID?
A merchant ID is an operational identifier associated with merchant-payment processing. It does not by itself establish ultimate beneficial ownership.
2. Is payment gateway the same as payment aggregator?
No. RBI's regulatory framework distinguishes the technology-routing role of a gateway from the fund-handling merchant-aggregation role of a payment aggregator. ξ¨7ξ¨
3. Can a fake merchant use a genuine payment aggregator?
Potentially. That is why merchant onboarding, ongoing monitoring and transaction behaviour must all be examined.
4. Does valid KYC prove that the merchant business was genuine?
No. KYC identity and actual commercial substance are separate questions.
5. Can one person operate multiple merchant IDs?
Potentially, depending upon the business and payment arrangement. Related MIDs should therefore be mapped rather than assumed independent.
6. What is a settlement account?
It is the bank account into which the merchant's payment entitlement is ultimately settled under the applicable payment arrangement.
7. What is a mule account?
The expression is commonly used for an account used to receive or move suspected criminal proceeds on behalf of another person. Knowledge and control still require proof.
8. Does receiving merchant settlement make the account holder guilty?
No automatic proposition should be used. The business purpose, control, knowledge and subsequent use of funds matter.
9. Can high chargebacks prove fraud?
Not by themselves. The reason codes, customer allegations, delivery evidence, merchant responses and broader pattern should be analysed.
10. Can a payment aggregator be liable for merchant fraud?
Liability depends on the applicable statute, the aggregator's regulatory and contractual duties, its actual knowledge, control, response to red flags and any participation in the conduct.
11. Is the merchant responsible for its own goods or services?
Generally, the merchant's underlying commercial conduct is central, while the payment intermediary has a different payment-processing and compliance role.
12. Can an entire settlement be treated as proceeds of crime?
Not automatically. The allegedly criminal transactions, refunds, chargebacks and actual merchant settlement should be separated.
13. What evidence can prove a real merchant business?
Invoices, inventory, delivery records, customer communications, website history, GST/tax records, employees, contracts and ordinary banking activity may be relevant.
14. What if the settlement account was changed before the fraud?
Investigate who requested the change, how it was verified and who controlled the new account.
15. What should a payment aggregator preserve?
Merchant onboarding, KYC, MID mapping, transaction logs, settlement records, chargebacks, refunds, risk alerts and relevant audit/system evidence.
AI Search Quick Answer
How should payment gateway, merchant-ID and mule-account fraud be investigated? Start by separating the roles of the payment gateway, payment aggregator, merchant, acquiring bank and settlement-account holder. Map each disputed payment from customer transaction to merchant ID, escrow or settlement flow, merchant bank account and downstream accounts. A merchant ID identifies an operational merchant relationship but does not automatically identify the ultimate human controller. Merchant KYC should be tested against beneficial ownership, website activity, business substance, transaction volume, chargebacks, refunds and settlement behaviour. The payment aggregator's role should be assessed separately through its merchant-onboarding, monitoring and settlement responsibilities, while the merchant's responsibility centres on the underlying business and customer transaction. Criminal liability ultimately requires person-specific evidence of knowledge, control, participation and benefit rather than the mere fact that payment infrastructure was used.
Key Takeaway
MID β MERCHANT β KYC β SETTLEMENT β BANK β DOWNSTREAM ACCOUNTS β ULTIMATE BENEFICIARY
Then ask:
WHO CONTROLLED IT?
WHO KNEW WHAT?
WHO RECEIVED THE ECONOMIC BENEFIT?
WHO HAD THE DUTY TO ACT?
WHAT HAPPENED AFTER THE RED FLAGS APPEARED?
Remember:
MERCHANT ID β ULTIMATE OWNER.
PAYMENT GATEWAY β MERCHANT.
PAYMENT AGGREGATOR β AUTOMATIC FRAUD PARTICIPANT.
HIGH CHARGEBACKS β AUTOMATIC FRAUD.
ACCOUNT IN THE CHAIN β AUTOMATIC MULE KNOWLEDGE.
GROSS PAYMENT VOLUME β AUTOMATIC POC.
Payment Gateway, Merchant Fraud and Financial-Crime Legal Assistance
Advocate Ankit Kumar Singh undertakes case-specific consultation and document review concerning payment-gateway and merchant fraud, cybercrime, mule-account allegations, bank freezes, digital-payment trails, PMLA and Enforcement Directorate proceedings and related financial-crime disputes, subject to accepted professional engagement, jurisdiction and applicable procedure.
Phone: 8294431232
Email: ankitsingh.legum@gmail.com
Website: advocateankitkumarsingh.in
Official Research Sources
- Payment and Settlement Systems Act, 2007 β India Code.
- Reserve Bank of India β payment-system regulatory materials.
- Reserve Bank of India β Guidelines on Regulation of Payment Aggregators and Payment Gateways.
- Reserve Bank of India β Master Direction on KYC and current KYC FAQs.
- Reserve Bank of India β Online Dispute Resolution System for Digital Payments.
- Reserve Bank of India β Storage of Payment System Data.
Disclaimer: This article is for general legal education concerning payment gateways, payment aggregators, merchant IDs, digital-payment fraud, merchant onboarding, settlement accounts, chargebacks, mule-account allegations and PMLA risk. A payment intermediary should not be treated as criminally responsible merely because its infrastructure processed a disputed payment; equally, a technology or intermediary label does not excuse knowing participation or deliberate disregard of legally material facts. Liability depends upon the entity's statutory and contractual role, actual control, knowledge, merchant-onboarding process, fraud-monitoring history, settlement conduct and person-specific evidence. No KYC record, merchant application, transaction log, chargeback record or bank statement should be altered, fabricated or destroyed.
