Short answer
Your payment providers are third parties, and third parties have to be overseen. Under DORA, the EU regulation formally called the Digital Operational Resilience Act, in force since 17 January 2025, and under long-standing bank guidance in the US, a financial business is expected to manage the risk of the providers it depends on, audit them against their contracts, and keep evidence of that oversight. Most oversight programs collect evidence about a provider's security and uptime. Almost none collect evidence that the provider billed what the contract says. Fee verification is that missing evidence, on the commercial side, produced per transaction.
Here is the gap, mapped to what oversight actually asks for.
| What oversight expects | What most programs use as evidence | What fee verification proves |
|---|---|---|
| The contract's terms are honored | A signed contract and a vendor questionnaire | Each charge matches the contracted rate, transaction by transaction |
| Ongoing monitoring of the provider | uptime dashboards and a SOC 2 report | The provider is still billing correctly, this month and every month |
| Documented, reviewable evidence | Attestations filed once a year | A dated, per-charge record you can hand an auditor |
| The right to audit against the contract | A clause in the agreement, rarely exercised | The audit, actually run, on every transaction |
Every row on the left is a real oversight expectation. Every entry in the middle is real evidence. None of it answers the question in the right-hand column.
Your payment providers are already a third party
Nothing about this argument is a stretch. A payment provider is an external party your business relies on to function, which is the definition of a third party in every risk framework that exists.
The US banking regulators put third-party relationships through a defined lifecycle: planning, due diligence and selection, contract negotiation, ongoing monitoring, and termination. Their 2023 interagency guidance, issued jointly by the Federal Reserve, the FDIC, and the OCC, replaced the agencies' earlier rules and applies across all of those stages. Regulators have been specific about payment processors in particular. The FDIC's guidance on payment processor relationships states plainly that these accounts require careful due diligence and monitoring, and that an institution should build policies and procedures around the ongoing monitoring of those relationships.
In the EU, the Digital Operational Resilience Act took this further for its own scope. DORA requires financial entities to manage the risk of their providers, to keep a register of every provider contract, and to hold access and audit rights over them. It is important to be precise about that scope: DORA is written about ICT risk, the technology and operational-resilience side of a provider relationship. It does not address fees.
The point is the shape of the obligation, not its exact subject. Across both regimes, the expectation is the same: you are responsible for your providers, you must be able to audit them against their agreements, and you must keep evidence that you did.
The evidence most oversight programs collect
Walk into a mature third-party risk program and look at what sits in the file for each provider. You will find a security questionnaire. You will find compliance certifications, usually a SOC 2 report and often ISO 27001. You will find continuous monitoring of the provider's security posture, and a record of uptime.
This is good evidence, and it is the right evidence for what it covers. It tells you whether the provider is secure, whether its controls are sound, whether it stays up, and whether it handles data correctly. For the risks it addresses, security and operational resilience, it is exactly what an auditor wants to see.
It is also, almost universally, the whole file. The evidence a third-party risk program collects is scoped to cybersecurity, compliance, resilience, and data handling. It is not scoped to whether the provider billed you the amount your contract specifies.
The line that evidence never crosses
A SOC 2 report does not tell you your provider charged the contracted rate. Neither does an uptime dashboard, a security questionnaire, or an ISO 27001 certificate. They were never designed to. They answer questions about how the provider operates, not about what the provider charged.
So a payment provider can pass every check in your oversight program and still bill you incorrectly, month after month, and your file would show a clean, well-monitored, fully-attested relationship the entire time. The overcharge is a commercial failure, and the commercial side of the relationship is the one part your evidence file is silent on.
This is the blind spot: a gap in what diligence has ever been asked to look at.
What sound oversight already asks for
The interesting part is that the principle covering this is already written down. Sound third-party oversight does not stop at collecting attestations. It reserves the right to audit the provider against the contract.
The US interagency guidance is explicit that a third-party contract should let the institution audit the provider, receive audit reports, and address remediation when an audit finds something. It names the kinds of reports an institution should be entitled to, and that list includes not only security and PCI reports but financial and operational reviews. DORA, in its own domain, requires access, inspection, and audit rights over providers, exercised against the terms of the arrangement.
Read those together and the shape is clear. Oversight is supposed to include checking a provider against its contract, and receiving evidence of that check. The frameworks already endorse the principle. What they leave to you is the instrument.
Fee verification as the commercial evidence
Fee verification is that instrument, pointed at the commercial terms. It reconstructs what each transaction should have cost under the provider contract and compares it to what was actually charged, per transaction, and it produces a dated, exportable record of every match and every discrepancy.
Set that against the oversight expectations. Contract terms honored: verification checks every charge against the rate the contract sets. Ongoing monitoring: verification runs continuously, not once a year. Documented evidence: verification produces a per-charge record an auditor can read. The right to audit against the contract: verification is that audit, actually executed, on every transaction rather than reserved in a clause and never run.
It is worth saying clearly what this is and is not. No regulation requires fee verification. DORA does not mandate it, the FDIC does not mandate it, and the interagency guidance does not mandate it. The claim is narrower and, we think, harder to argue with: overseeing a provider means auditing it against its contract and keeping the evidence, the frameworks already say so, and fee verification is the natural way to do that on the one part of the relationship your security file never covers.
That is the job Bluefyn is built for. Bluefyn verifies that providers charge exactly what they agreed to charge, reconstructing contract pricing and checking fees transaction by transaction. It analyzes transaction and provider data. It never moves, holds, or custodies funds.
A payment provider is a third party. You already oversee it. The only question is whether your evidence covers what it charges, or stops at whether it stays up.
Frequently asked questions
Are payment providers a third-party risk?
Yes. A payment provider is an external party your business depends on, which makes it a third party under every risk framework. US banking regulators run third-party relationships through a defined lifecycle and single out payment processor relationships as requiring due diligence and ongoing monitoring, and the EU's DORA requires financial entities to manage and audit the providers they rely on.
Does DORA require fee verification?
No. DORA is scoped to ICT risk, the technology and operational-resilience side of a provider relationship, and it does not address fees. What DORA does require is that financial entities manage their providers, keep a register of provider contracts, and hold access and audit rights over them. Fee verification is not a DORA requirement. It is a way to exercise the same audit-against-the-contract principle on the commercial side.
What evidence do third-party risk programs usually collect?
Typically a security questionnaire, compliance certifications such as SOC 2 and ISO 27001, and continuous monitoring of security posture and uptime. This evidence covers cybersecurity, compliance, and operational resilience. It does not cover whether a provider billed the amount its contract specifies.
Why doesn't a SOC 2 report catch an overcharge?
Because it was never meant to. A SOC 2 report attests to how a provider operates its controls, not to what it charged you. A provider can hold a clean SOC 2, strong uptime, and full attestations while still billing above the contracted rate, because the overcharge is a commercial issue and those reports are scoped to security and operations.
How does fee verification fit into third-party oversight?
It supplies the evidence your other checks do not. Sound oversight already calls for auditing a provider against its contract and documenting the result. Fee verification does exactly that on the fee side: it reconstructs the expected charge per transaction, compares it to the actual charge, and produces a dated record of every match and discrepancy that an auditor can review.



