Kitty and Chris sit down with Steve Levinson of LHC Advisors to unpack PCI service-provider scope, why ISVs can have PCI responsibilities without storing card data, and why relying on a compliant payment vendor does not make responsibility disappear.



For service providers, PCI compliance is not just a security checkbox. It is a legal, financial, and contractual defense layer when card data risk becomes real.

Kitty and Jason sit down with Allen Kopelman of Nationwide Payment Systems to discuss complex merchant onboarding, flow-of-funds explanations, synthetic identity fraud, underwriting context, and why legitimate businesses can look risky when the operating model is not clearly explained.




Nationwide Payment Systems helps growing, regulated, high-volume, and complex businesses accept and manage payments across cards, ACH, POS, invoicing, embedded payments, and custom workflows with real human support.
AI agents are starting to initiate commerce and payments, but platforms still need clear authorization, controls, dispute paths, monitoring, and accountability when something goes wrong.

Mastercard’s scam merchant monitoring push signals a shift from after-the-fact chargeback cleanup to earlier detection, faster investigations, and more responsibility for acquirers, PayFacs, PSPs, and platforms.

Real-time payments can improve cash flow and customer experience, but they also expose weak fraud controls, messy reconciliation, poor support workflows, and unclear exception handling faster than slower rails ever did.

Becoming a PayFac can unlock payments revenue, tighter customer relationships, and more control, but the model also brings underwriting, risk monitoring, disputes, reserves, sponsor oversight, support complexity, and operational accountability.

Nacha’s 2026 ACH fraud-monitoring rules signal a major shift for banks, platforms, Originators, Third-Party Senders, and service providers. ACH fraud prevention is becoming more distributed, more operational, and harder to ignore.
