What BNM Requires of Merchant Acquirers

Paragraph 18.45 of Bank Negara Malaysia's policy document on merchant acquiring services sets a plain limit: appointing a third party, including one you engage to assess your own controls, does not reduce or eliminate your accountability for the security and reliability of the systems that move payments. Registration under the Financial Services Act 2013 makes you the party BNM will hold responsible. It does not let you pass that responsibility down the chain to the facilitators and merchants you onboard.

That is the working principle behind BNM/RH/PD 028-119, issued on 15 September 2021. Read it as a compliance filing and you will treat registration as the finish line. Read it as an operator and you will see a continuing obligation: you carry the security exposure of entities you do not control, and the question BNM will ask is not whether you signed them up correctly, but whether you can show you keep watching them.

Start by listing every party in your acquiring chain, the facilitators and the merchants they bring in included, and mark which ones you hold evidence on beyond the day they were onboarded.

What registration actually commits you to

An acquirer under 028-119 is any person registered under sections 17(1) and 18 of the Financial Services Act 2013 to provide merchant acquiring services and who meets the criteria in paragraph 2.1: you contract with merchants, you move funds to them or instruct their settlement, you facilitate their acceptance of payment instruments, and you are a direct participant in a payment network. Meeting those criteria is what makes you an acquirer, and what makes paragraph 14.3 apply to you.

Paragraph 14.3 requires due diligence on any service provider before you formalise an outsourcing arrangement. This is not a reference check. The standard names capacity and financial strength, risk management and IT security controls, data protection measures, the provider's own reliance on sub-contractors, and its ability to comply with the law and with this policy. Paragraph 18.45 then closes the exit: engaging that provider, even for independent assessment, does not dilute your responsibility for the systems involved.

Registration makes you the party BNM holds responsible. It does not let you pass that down the chain.

Before you rely on any provider in your payment flow, run the 14.3 assessment against them and file the result where an examiner can retrieve it without asking you twice.

Where a payment facilitator sits in your chain

A payment facilitator is an entity you appoint to perform merchant acquiring services on your behalf. Under 028-119 it can be an existing acquirer or a third party acquirer, and the moment you appoint one, the definition of merchant widens: it now includes every merchant the facilitator acquires for you. Those sub-merchants are yours in BNM's reading, even though you never signed them directly.

Paragraph 15.1 makes you responsible for ensuring the parties you contract with, facilitators named explicitly, can manage the payment and settlement risk they introduce. Paragraph 15.2 goes further. Those parties must hold adequate operational and risk-management policies, including their own due diligence on the merchants they onboard, safeguards for timely and complete settlement, and the ability to keep customer data confidential and secure at all times.

The written confirmation is the part firms skip. A facilitator telling you it screens its merchants is not evidence; a dated record of the screening criteria it applies, the volume it onboarded in the period, and the exceptions it rejected is. Where a facilitator cannot produce that, the gap is yours, because 15.1 reads the risk those sub-merchants introduce back onto your registration.

Map each facilitator to the sub-merchants it has brought in, confirm in writing that the facilitator is running the 15.2 checks on them, and only then count that part of the chain as covered.

Two limits the policy draws hard

Paragraph 15.4 sets a bar that is easy to breach without noticing: a payment facilitator may not appoint another payment facilitator to acquire a merchant. The chain stops at one facilitator layer. If a facilitator is quietly sub-appointing, you are outside the policy and will not know until an assessment finds it for you.

Paragraph 15.3 puts the settlement risk back on you. If a facilitator fails to settle to its merchants, you are responsible for fulfilling that obligation. Paragraph 14.11 does the same for compliance: where a provider engages a sub-contractor, you must implement controls to ensure the sub-contractor meets the requirements as well. The obligation does not thin out as it travels down the chain.

A payment facilitator may not appoint another payment facilitator. The chain stops at one layer.

Add a contractual clause and a periodic check confirming no facilitator in your book has appointed another, and treat any breach of 15.4 as a finding rather than a formality.

What "PCI DSS at all times" actually requires

BNM does not write its own card-security standard. It points to PCI DSS and requires you to carry it into your contracts. Appendix 2 of 028-119, which sets the minimum contents of any outsourcing agreement, requires the agreement to bind the service provider to maintain compliance with applicable security standards, naming PCI DSS, at all times. Appendix 4 adds the device layer: payment acceptance devices must be certified to standards such as PCI PTS and PCI SPoC.

The phrase carrying the weight is "at all times". PCI DSS v4.0.1, the version mandatory for every assessment after 31 March 2025, is validated at a point in time. An Attestation of Compliance describes the state of an environment on the assessment date and nothing after it. A signed attestation collected at onboarding is not evidence that a facilitator is compliant today. This is where oversight most often breaks in the chains we assess: the acquirer holds a certificate from eighteen months ago and treats it as a live control.

The harder gap is the year between assessments. PCI DSS validation is annual, but a facilitator can drift out of compliance the week after it signs, through an unpatched system, a new payment page script, or a change in the merchants it accepts. "At all times" means your oversight has to reach into that gap, which is why an annual certificate on file is a starting point and not the control itself.

Record the assessment date and expiry of every provider's PCI validation, set a review that flags each one before it lapses rather than after a breach surfaces it, and build in at least one interim check between validations for the facilitators carrying your highest sub-merchant volume.

Proving oversight instead of asserting it

Paragraph 15.5 is the clause that turns all of this from paperwork into practice. It requires you to periodically monitor the parties in your chain through transaction monitoring, site visits, or audit assessment, and to rectify weaknesses promptly. Paragraph 18.46 sets what that assessment must cover for a technology provider: data leakage, service disruption, processing errors, physical security breaches, cyber threats, over-reliance on key personnel, mishandling of confidential information, and concentration risk.

Together these clauses answer the question the policy is really asking. Not whether you onboarded correctly, but whether you can produce, on the day BNM asks, the evidence that you have kept watching. A folder of onboarding attestations does not answer it. A monitoring schedule with dated results does.

Build that schedule now: name each party, name the check, name the cadence, and keep the output somewhere it can be handed over without a week of preparation first.


Sources

  1. Bank Negara Malaysia, "Merchant Acquiring Services (BNM/RH/PD 028-119)", issued 15 September 2021. https://www.bnm.gov.my/documents/20124/943361/PD_Merchant_Acquiring_Services.pdf

  2. PCI Security Standards Council, "Payment Card Industry Data Security Standard: Requirements and Testing Procedures, Version 4.0.1", June 2024. https://www.pcisecuritystandards.org/document_library/

  3. Laws of Malaysia, "Financial Services Act 2013 (Act 758)", Attorney General's Chambers of Malaysia. https://lom.agc.gov.my/


Disclaimer

This article is for general information and does not constitute legal, regulatory, or professional advice. Requirements under BNM/RH/PD 028-119 and PCI DSS v4.0.1 are summarised here for clarity and may not reflect the full text or the latest amendments. Acquirers should verify their obligations against the current policy document and standard, and seek qualified advice for their specific circumstances. Paragraph references were confirmed against the policy document at the time of writing.


FAQ: Malaysia's Rules for Payment Acquirers

Frequently asked questions

Malaysia's rules for payment acquirers

What BNM/RH/PD 028-119 requires of registered acquirers overseeing payment facilitators, sub-merchants, and PCI DSS across the chain.

  • BNM's merchant acquiring rules are set out in policy document BNM/RH/PD 028-119, "Merchant Acquiring Services", issued on 15 September 2021, and they govern how registered acquirers onboard, oversee, and settle with merchants and payment facilitators. In practice the rules treat registration as the start of a continuing duty: an acquirer must be able to evidence ongoing oversight of every party in its payment chain, not merely a clean file from the day each one was onboarded.

  • Under BNM 028-119, a payment facilitator is an entity appointed by an acquirer to perform merchant acquiring services on the acquirer's behalf, and it can be either an existing acquirer or a third party acquirer. Appointing one extends the acquirer's responsibility to every sub-merchant the facilitator brings in, so the facilitator's onboarding standards become the acquirer's exposure.

  • Yes. BNM 028-119 requires acquirers to bind their service providers, through the outsourcing agreement, to maintain compliance with applicable security standards such as PCI DSS at all times. Enforcement means more than collecting an Attestation of Compliance at onboarding, because that attestation reflects a single point in time and must be tracked to its expiry to satisfy the "at all times" requirement.

  • Paragraph 14.3 of BNM 028-119 requires an acquirer to assess a facilitator's capacity, financial strength, risk management and IT security controls, data protection measures, reliance on sub-contractors, and ability to comply with the law before formalising the arrangement. That assessment is not a one-off: paragraph 15.5 requires periodic monitoring through transaction monitoring, site visits, or audit assessment for as long as the relationship runs.

  • The registered acquirer remains accountable when a sub-merchant is breached, because BNM 028-119 states that appointing a facilitator or other third party does not reduce or eliminate the acquirer's responsibility for the security of the payment chain. The facilitator may have onboarded the sub-merchant, but the acquirer carries the exposure and must be able to show it was overseeing that part of the chain.

Next
Next

Business Email Compromise: The Quiet Heist