EXCLUSIVE: "Why the Payments Industry Needs to Rethink 'High-Risk'" - Serhii Zakharov, PayDo in 'The Paytech Magazine'
By Lauren Towner · 21 September 2026

Serhii Zakharov, CEO & Founder of payment ecosystem PayDo, makes a compelling case for recalibrating screening by applying some simple human intelligence to complex business cases
‘High-risk’ is the laziest phrase in payments. One label, doing far too much work.
It gets applied to problematic actors and to entirely legitimate, well-run, fast-growing businesses in the same breath, on the same basis, with the same outcome: a declined application and a closed account. The industry treats the phrase as a risk assessment. Most of the time it is the absence of one.
The problem with ‘high-risk’ industries is usually not the risk. It is the label. The providers that get this right will be the ones that replace blanket categories with judgement, assessing businesses on how they actually operate, not simply on the sector they belong to.
The label is a shortcut, not a finding, and to understand why it persists, you have to understand how most payment platforms are built.
Mass-market providers scale by standardising and automating everything, including risk. That model is genuinely good at what it was designed for: processing huge volumes of predictable, low-complexity transactions at low cost. As an engineering model, it’s a triumph.
But an automated risk engine has one instinct when it meets something it does not recognise, and that is to decline. Complexity, to a system optimised for scale, reads as risk, because complexity is expensive to understand and cheap to reject.
So a business gets classified not on the basis of what it actually does, but on the basis of a category its model happens to sit near. The label is applied, the shutter comes down, and no human ever asks whether the assessment was correct.
This is not risk management. It is risk avoidance wearing the vocabulary of risk management, and avoiding a category has never been the same thing as understanding a business.
What ‘complex’ really means
Strip the word ‘risk’ away and look at what these industries have in common, and a different picture appears. What they share is operational complexity, not moral hazard.
High transaction velocity. Multiple jurisdictions at once, each with its own rules. Refund or dispute patterns that are a feature of the business model rather than a warning sign. Newer structures that do not map onto frameworks written for a simpler era. These are operational characteristics. They describe how a business moves money, not whether it should be allowed to.
Take a video games platform processing millions of small payments: in-game purchases, regional pricing, refunds, and chargebacks. The velocity and the refund pattern look alarming against a model built for one-off retail, but are simply the economics of the business.
Or a skin marketplace for gamers where players buy, sell and trade in-game virtual cosmetic items at high volume, a flow that looks exotic to a category model but is just a functioning secondary market.
Or even a travel platform, where customers pay months before they travel, leaving a long window of chargeback exposure on a business that is entirely legitimate and simply runs a long fulfilment cycle.
Every one of those is operationally awkward. None of them is evidence of anything. But a model that cannot separate the awkwardness from the risk hands all three the same label. And the cost of that is not abstract. Legitimate businesses lose reliable access to payments, which is to say they lose the ability to operate.
Meanwhile, the risk that the label was supposed to contain does not disappear. It migrates to whichever provider will take it on with the least scrutiny, which is precisely the outcome the label was meant to prevent.
More understanding, not less caution
Here is where the framing gets backwards. You do not serve a complex industry by asking your compliance team to accept more exposure, any more than you serve it by asking the commercial team to accept every client. You serve it by understanding that exposure well enough to make a better decision.
That is an infrastructure problem before it is a policy problem, and it is where modern electronic money institutions are quietly rebuilding the category.
Start with where compliance sits. Treated as a paperwork layer bolted onto the product, it can only gate decisions after the fact. Built into the product architecture, it becomes the thing that makes the decision possible. Reserves, governance, anti-money-laundering controls, monitoring, reporting: these are not obstacles to serving complex industries. They are the capabilities that make it possible to serve them safely.
Then be honest about what automation is measuring. The failure in most risk engines is not that they are automated. It is what they have been pointed at. They assess category membership rather than observed behaviour, comparing a refund pattern to a sector average instead of to what is normal for that particular operation. The output looks confident and contains very little information.
So the fix is not less automation. What is missing is a correctly defined baseline for the machine to work against, and defining that baseline is where human expertise earns its cost. A specialist establishes what normal looks like for a specific business. Monitoring against that baseline is then a job for automation, because no human can watch transaction flow at volume and no one should try. Get the sequence right and you catch genuine anomalies a category-average model would miss entirely, without flagging ordinary activity a hundred times a day.
I have sat in enough of these reviews to know what actually settles them. It is rarely the sector. It is 12 months of transaction history and a straightforward question: which of these can you not explain to me? Businesses that can explain their own numbers are usually fine. The ones that can’t are going to be a problem in any sector, including the ones nobody calls high-risk.
Human judgement, in this context, should not be confused with subjective judgement. It means experienced onboarding teams asking sharper questions before the automated monitoring starts, so that what the model is measuring is accurate in the first place. That work is expensive at the front end and cheap for years afterwards, which happens to invert the economics most platforms are built around.
Working from the same facts
This also changes the relationship between the compliance and commercial sides of the business. The two should not be working towards opposing outcomes, with compliance trying to minimise exposure and commercial trying to maximise revenue.
Both should be working from the same understanding of the client. What does the business do? How does money move through it? Where is the real risk and what controls are in place to manage it?
The commercial team brings context into the assessment; compliance brings the discipline to decide whether that business can be supported safely. When those perspectives come together, the result is neither a softer risk standard nor a slower sales process. It is a better decision.
This does not lower the bar. It raises the quality of the decision about where the bar should be set.
The last piece is owning the infrastructure rather than renting it. Direct participation in the payment systems, real regulatory authorisation, direct connection to the card and banking rails – these are what give a provider the room to make a nuanced decision at all.
A firm reselling someone else’s rails inherits someone else’s risk appetite, and that appetite is almost always ‘decline the complicated thing’.
Mind the gap
The structural gap in payments is not where people assume. The problem is not that risky businesses cannot find providers. It is that complex, legitimate, high-growth businesses, the ones most likely to build something significant, are least well served by an industry optimised for the simple and the predictable.
These are the companies for whom uninterrupted payment processing is the difference between scaling and collapsing, and they are the ones handed a blanket ‘no’ by systems that never looked closely enough to say anything else.
Closing that gap is not a matter of being braver about risk. The requirement is to be better at it.
The EMIs that understand this are building rails that are safe and scalable at the same time, having worked out that at sufficient depth of understanding, the trade-off between the two mostly dissolves.
The next decade belongs to judgement
The payments market is maturing, and the automated, one-size-fits-all model is running into its own ceiling. The simple, predictable customers it was designed for are already spoken for. The growth now sits in the industries that require someone to understand them properly.
So my argument to the industry is simple. Retire the phrase ‘high-risk’. It tells you nothing about a business, except that a system somewhere found it inconvenient to assess.
Replace it with the questions that matter. What does this business do? How does its money move? What controls make it safe to support?
Answer those, and most of what the market has been calling high-risk turns out to be something far more useful: complex, underserved, and ready to scale with a provider prepared to understand their needs.
None of this work is quick, and it does not fully automate. But the alternative is an industry that keeps declining businesses it never troubled to understand and calling the decline a risk policy. We have done that for long enough.