ISO Industry Update: Regulations & Compliance
Key 2025 regulatory changes — including PCI DSS continuous compliance, a growing patchwork of state privacy laws, and tightened AML requirements — demand proactive attention from ISOs and payment professionals.
The regulatory environment for payments is never static, but 2025 has brought an unusually concentrated set of significant changes across security standards, privacy law, and anti-money-laundering requirements. For ISOs and payment service providers, staying current with these developments is not just good practice — it is a prerequisite for maintaining card-brand relationships and avoiding material compliance risk.
This update covers the most important regulatory developments payment professionals need to understand heading into the second half of 2025.
PCI DSS 4.0.1: What Changed
The Payment Card Industry Data Security Standard has undergone a significant philosophical shift with version 4.0 (and the 4.0.1 revision published in June 2024), whose future-dated requirements became mandatory on March 31, 2025. The traditional model of annual assessment and point-in-time compliance has given way to an expectation of continuous monitoring — organizations are now expected to demonstrate ongoing compliance posture rather than passing a periodic audit.
Multi-factor authentication requirements have been expanded under the new standard, now applying to a broader set of access scenarios including non-console administrative access and remote access to cardholder data environments. Organizations that relied on legacy single-factor authentication for certain privileged access scenarios will need to remediate those configurations.
- Continuous monitoring replaces annual point-in-time assessment as the compliance model
- Expanded MFA requirements apply to more access scenarios than previous versions
- Software development practices face new scrutiny around security testing and code review
- Organizations should assess gaps against the new standard and build remediation roadmaps now
State Privacy Laws: The Patchwork Expands
In the absence of comprehensive federal privacy legislation, a growing number of US states have enacted their own consumer data privacy laws. As of mid-2025, 19 states have comprehensive privacy statutes in effect or taking effect imminently. While many of these laws share structural similarities with the California Consumer Privacy Act, there are meaningful differences in scope, exemptions, and enforcement mechanisms.
For payment processors and ISOs that handle consumer data across multiple states, the patchwork creates operational complexity. A single compliance program designed around the most stringent requirements provides the simplest path forward, but organizations must verify that their approach actually satisfies each state's specific requirements rather than assuming uniformity.
- 19 states have comprehensive consumer privacy laws in effect or taking effect
- Material differences exist between state laws despite structural similarities
- Data subject rights — access, deletion, portability, opt-out — require operational processes to fulfill
- Payment processors should audit data flows and vendor contracts for cross-state compliance gaps
Anti-Money Laundering (AML) Updates
Anti-money laundering compliance has been strengthened significantly with the implementation of the Corporate Transparency Act and enhanced know-your-business (KYB) requirements. The CTA requires most US companies to report beneficial ownership information to FinCEN, creating new onboarding data requirements for payment processors and ISOs that must verify this information as part of their compliance programs.
Enhanced KYB standards require more thorough verification of business customers at onboarding — going beyond basic entity verification to confirm ownership structure, beneficial owners, and the nature of the business activity. For ISOs with large merchant portfolios, updating onboarding workflows to meet these requirements is a significant operational undertaking.
- The Corporate Transparency Act requires beneficial ownership reporting to FinCEN
- Enhanced KYB standards require more thorough business customer verification at onboarding
- Ongoing transaction monitoring obligations have been strengthened
- ISOs should review onboarding workflows and existing merchant portfolios for CTA compliance
The Beneficial Ownership Registry
The FinCEN Beneficial Ownership Registry, established under the Corporate Transparency Act, represents a significant new data resource for AML compliance. Payment processors and ISOs that previously struggled to verify ownership structures through publicly available sources can now access the registry as part of their customer due diligence processes.
Integration with the registry — whether directly or through compliance data providers — should be a near-term priority for organizations that conduct KYB on business customers. The registry is not a silver bullet for KYB, but it substantially improves the reliability of beneficial ownership verification compared with relying solely on self-reported information.
- The FinCEN registry provides a centralized source for beneficial ownership data
- Registry access should be integrated into KYB and ongoing monitoring workflows
- Registry data should be used in conjunction with other verification sources, not as a standalone check
- Periodic re-verification against the registry supports ongoing due diligence obligations
Surcharging and Durbin Amendment Updates
Surcharging rules and Durbin Amendment interpretations have continued to evolve in 2025, with ongoing litigation and regulatory guidance creating uncertainty in some areas. The basic framework — ISOs and merchants can apply surcharges for credit card acceptance subject to card-brand rules and state law restrictions — remains in place, but the specific compliance requirements vary meaningfully by jurisdiction and card type.
The Durbin Amendment's routing mandate for debit transactions has been the subject of new guidance, particularly around card-present and card-not-present transaction routing. ISOs advising merchants on surcharging programs should ensure they are working from current guidance rather than assumptions based on older interpretations.
- Credit card surcharging is permitted subject to card-brand rules and state law
- State law restrictions on surcharging vary — confirm applicability in each merchant's jurisdiction
- Debit routing requirements under Durbin have been clarified with new guidance
- Disclosure and signage requirements for surcharging programs must be followed precisely
Preparing for What's Next
The common thread across these regulatory developments is the increasing expectation of continuous, automated compliance rather than periodic manual review. Organizations that have invested in compliance automation — automated KYB workflows, continuous PCI monitoring, real-time transaction screening — are better positioned to absorb regulatory changes without proportional increases in compliance cost.
ISOs and payment professionals should engage qualified compliance counsel to assess their current posture against the specific requirements described in this update. The cost of proactive compliance investment is consistently lower than the cost of remediation after a finding or enforcement action.
- Compliance automation reduces the cost of absorbing new regulatory requirements
- Engage qualified counsel to assess posture against specific 2025 requirements
- Document compliance policies and procedures to demonstrate good-faith effort to regulators
- Peer networks and industry associations are valuable sources of practical compliance guidance
