Most scheme bulletins don't apply to you – Define your compliance perimeter

Scheme Compliance
Jul 23, 2026
Stop reading every bulletin define your compliance perimeter instead

Ask a scheme compliance manager what their week looks like, and the answer is rarely "interpreting the rules". It's logging in to the Visa, Mastercard, and other networks’ portals, downloading new bulletins, saving them to a shared drive, opening each bulletin in turn, and analysing whether they are relevant to the bank and who should be informed.

That's the part the payment industry rarely talks about. The conversation around scheme compliance fixates on the bulletins you must not miss: the mandate with the hard deadline, the fee change buried in paragraph four, which matters. But the daily cost of payment network compliance isn't the handful of bulletins that apply to you, but the hours your team spends reading, triaging, and distributing the information.

The volume keeps climbing. The team stays the same

Global payment networks like Visa and Mastercard publish bulletins on a weekly cadence. Someone has to monitor Visa Business News and the Mastercard bulletin feed, read what lands, and translate it into internal action. At the same time, the number of incoming bulletins is increasing more bulletins year on year, with no matching increase in staffing.

So the queue grows. And because nobody can be certain about the impact of each update on their organisation, the safe response is to read all of them, find the relevant ones, then prioritise them based on the deadline and impact. Reading everything, given the increasing number of updates, does not guarantee the team can read them in time or avoid missing a relevant one. We've written before about the hidden cost of scheme compliance complexity this creates for compliance functions more broadly.

The real question card issuers and acquirers are asking

In our conversations with banks, the first thing compliance teams usually raise is not "help us never miss a bulletin". It's a sharper, more practical question: how can we prioritise processing those that are actually within our perimeter, have the closest due date, or have the highest financial impact?

One payment compliance team put it plainly: there are many documents we're not interested in because they're not within our perimeter. If we don't use a given service, every bulletin about that product is noise to us. How can we know that?

That question is worth sitting with. The burden is relevance: a bank that doesn't offer a particular product, isn't licensed for a particular scheme, or doesn't operate in a particular geography is reading a large share of announcements only to confirm they can be set aside.

Note the change to the Visa Acquirer Monitoring Program (VAMP), where the Excessive Merchant threshold dropped to 1.5% in April 2026, while the acquirer "Above Standard" threshold remained at 0.5%. For an issuer inside that programme's scope, it's essential reading. For one outside it, it's another bulletin opened, assessed and closed. The work of discounting it still happened. It just produced nothing.

What a compliance "perimeter" actually is

The way out isn't to read faster, but to define what applies before the reading starts.

A bank's compliance perimeter is the specific intersection of a few things it already knows about itself: the licences it holds, the schemes it participates in, the products it issues, and the geographies it operates in. Map that once, and an unbounded reading task becomes a bounded, prioritised queue. Bulletins that fall outside the perimeter can be set aside with confidence to be read later, rather than reading the updates as they come in: first in, first out. Bulletins within your compliance scope should move to the top, ranked by deadline and impact on your business.

The shift is from "read everything as they come in" to "read what matters the most, financially and compliance-wise". The scheme compliance team’s expertise shifts from triage to judgement and prioritisation, where their knowledge actually enables the business.

Filtering is not the same as removing the human’s expertise

One caution: automating applicability is not the same as automating the decision. The four-eyes principle exists for good reason, and nothing here replaces it.

Scoping a perimeter should accelerate the compliance manager's work, not substitute for their experience and judgement. The goal is to remove the hours lost confirming irrelevance, so the expert attention left over goes to the bulletins that genuinely require interpretation, assignment and sign-off. The human still decides. They just stop tracking through the noise to get there.

Where Kajo fits

This is the problem Kajo was built to solve. Kajo maps each issuer's or acquirer's perimeter, then highlights relevant mandates and their impact on the business across Visa, Mastercard and other networks. Kajo also has a built-in AI assistant summarising what a given bulletin means, the key dates, and what actually requires action. Kajo AI assistant goes beyond one bulletin and enables teams to research payments or compliance topics relevant to their business and across multiple networks.

Expert review sits on top, and every compliance action is tracked from publication through completion with a full audit trail. Teams using Kajo can typically reclaim a substantial share of the hours currently spent on manual screening. The point is to stop reading what was never yours to act on. For teams building the internal case for this shift, we've also looked at how to quantify the value of scheme compliance modernisation.

If your team is still opening every bulletin to find the few that matter, or if you lack a directory of payment network knowledge to inform strategic decisions and enable a more proactive approach to your product roadmap or business strategy, it's worth talking with our team and seeing the Kajo product for yourself.