Platform
Solutions
Resources
Company
Resources
Solutions

MASAK compliance in e-commerce, merchant and buyer risk

MASAK's guide for e-commerce intermediary service providers looks beyond payment flows: product price, return rate, review patterns, buyer behavior, and geographic concentration. TruvaLI aggregates order, payment, return, and user behavior data into a single customer view. Deployment is available in the cloud, private cloud, or on-premise.

E-commerce intermediary service providers are obliged parties under Law No. 5549. The distinguishing feature of the sector is that money laundering manifests not in the transaction itself, but in the authenticity of the product, price, and parties: payment for a product that is never actually delivered is recorded as a regular sale.

Who does the guide target?

E-commerce intermediary service providers are obliged parties under Law No. 5549 on Prevention of Laundering Proceeds of Crime, and MASAK publishes a dedicated suspicious transaction report guide for this group.

The guide defines its scope around intermediary service providers, meaning platforms where third parties make sales. An e-commerce business selling its own products on its own website is not the direct target of this guide. However, most of the indicators listed in the guide point to risks that have equivalents in any e-commerce structure that accepts payments: merchant and buyer behavior, product and price discrepancies, and the use of fake cards.

Which indicators does the guide list?

GroupNumber of typesWhat it looks at
Customer profile16Declarations, documents, and avoidance of declaration
Sector-specific32Merchant, buyer, product, price, and feedback
Terrorist organizations and risky countries18Parties and geography
Non-profit organizations6Actions of administrators and financial officers
Financing of weapons of mass destruction17Sanctions regime

Indicators on the payment side

T-020-2.31 lists transactions made using fake credit card information and the detection of fake products being purchased alongside these transactions. T-020-2.21 adds a buyer or merchant performing an unusually high number of return transactions.

Both show that fraud control and money laundering control look at the same data. The chargeback rate is read not just as a payment issue, but also as a money laundering indicator.

Buyer behavior

T-020-2.27 lists buyers making sudden and high-value purchases outside their normal shopping habits, T-020-2.25 lists an unreasonable number of customers purchasing the same product within specific timeframes outside of special circumstances like discounts or campaigns, and T-020-2.29 lists a high volume of purchase transactions occurring from a specific region in a short period without a reasonable explanation.

None of the three can be detected by looking at a single order: they require the buyer's history, collective behavior around the same product, and geographic concentration.

Product and price

T-020-2.20 lists the sale of prohibited or dangerous products, T-020-2.22 lists the offering of identical or similar products for sale far outside market prices, T-020-2.30 lists frequent and sudden price changes incompatible with market conditions, and T-020-2.23 lists encountering different, fake, or completely undelivered products instead of the ordered item.

All four demonstrate that the product catalog and price history constitute risk data. A monitoring structure that only looks at the payment flow will not detect any of them.

Merchant side

TypeWhat it says
T-020-2.19A normally low-volume merchant suddenly making very high-value sales or experiencing a sudden spike in transaction volume in a short period
T-020-2.24The merchant providing incomplete or incorrect information required to operate in the marketplace
T-020-2.26Detection of fake positive reviews or manipulated feedback about the merchant
T-020-2.28The merchant receiving an above-average number of customer complaints and failing to take necessary actions against them
T-020-2.32A merchant inactive for a long time suddenly and unusually becoming active during a specific period

For a business selling in its own store, these indicators correspond to the supplier and distributor side; for a platform operating a marketplace, they apply directly to their merchant onboarding process.

Who is the real party?

The first eighteen types in the guide share the same common core as other sectoral guides: concealing the ultimate beneficial owner (UBO) (T-020-2.11), the third party directing the transaction not being a party to official documents (T-020-2.9), the lack of a logical commercial link between the parties (T-020-2.12), and complex, multi-jurisdictional structures (T-020-2.13).

What does the reporting form require?

Suspicious matters that do not contain monetary value are written in the description section of the form, not the suspicious transaction section. This means a case must also be able to carry non-monetary events.

A report can be based on a single transaction or on multiple transactions within a specific date range; in the case of multiple transactions, the total amount and date range are reported together.

How is the suspicion category selected?

When making a report, the suspicion is placed into one of the categories in MASAK's reference table, and each category is mapped to the relevant legal regulation. This means case management must operate with this taxonomy rather than its own free-form tags.

What is the threshold for reports with a suspension request?

The regulation based on Article 19/A of Law No. 5549, titled "Suspension of transactions", governs the suspension of transactions based on a report. The guide sets a clear threshold for this: rather than mere suspicion, there must be documents or serious indications supporting the suspicion that the assets subject to the transaction are related to money laundering or terrorist financing, and these must be submitted along with the justifications.

This threshold directly generates a system requirement: evidence must be attached to the case, the justification must be written, and the identity of the decision-maker must be recorded.

How does TruvaLI meet these requirements?

Reading payment and user behavior in the same place

Order, payment, return, and chargeback data are aggregated with the user's device, IP, and contact data in the same customer view. Email and IP scores calculated at onboarding become inputs for subsequent rules.

Product and price data as rule inputs

When product category, price history, and catalog data can be connected, T-020-2.22, T-020-2.30, and T-020-2.20 become rules. Prohibited product lists are set up as internal lists and integrated into the screening flow.

Relationship network

The relationship network between buyers and merchants is mapped through shared IP, device, contact information, and payment instruments. Types looking at collective behavior, such as T-020-2.25 and T-020-2.29, cannot be detected through individual order checks.

Case, evidence, and category

An alert turns into a case with an owner, duration, and evidence. The suspicion category is selected from MASAK's taxonomy, the evidence and decision justification are written to an immutable audit trail, and the four-eye approval is executed via maker/checker. The report draft is prepared from the same case data, and the signature remains within the institution.

Related flows: merchant onboarding, chargeback and payment fraud, marketplaces, ongoing monitoring, and regulatory reporting. The framework is on the MASAK obligations page, and relationship analysis is on the fraud detection page.

Source

MASAK, "Suspicious Transaction Report Guide for E-Commerce Intermediary Service Providers", version 1.0.

This page does not constitute legal interpretation; it conveys the indicators and procedures listed in the guide. Rules, thresholds, and actions are configured according to the institution's own risk policy and obligations.

Common questions

Does this guide also cover businesses selling from their own websites?
The guide defines its scope around intermediary service providers, meaning platforms where third parties make sales. A business selling its own products on its own website is not the direct target, but most of the indicators listed have equivalents in any e-commerce structure that accepts payments.
Why is the chargeback rate considered a money laundering indicator?
The guide lists an unusually high number of return transactions under T-020-2.21, and the use of fake cards along with the detection of fake product purchases under T-020-2.31. Fraud control and money laundering control look at the same data.
Are product and price data also subject to monitoring?
Four types in the guide are directly related to products and prices: the sale of prohibited products, off-market pricing, frequent and sudden price changes, and sending different or fake products instead of the ordered item. A system that only looks at the payment flow will not detect any of them.
Does customer data leave the institution?
Not in an on-premise deployment. The software runs on the institution's own infrastructure, data remains within the institution's information systems, and keys and the audit trail are under the institution's control.
Are e-commerce intermediary service providers obliged parties?
Yes. They are obliged parties under Law No. 5549 and are subject to MASAK's relevant sectoral guide.
How does money laundering manifest in e-commerce?
Not in the transaction itself, but in the authenticity of the product, price, and parties. Payment for a product that is never actually delivered is recorded as a regular sale.
Can product and price data be included in rules?
Yes. Product category, price, and cart contents are rule inputs; a price that significantly deviates from market value is an indicator.
Can the link between buyer and merchant be detected?
Yes. The relationship network between the parties is mapped through shared device, IP, payment instrument, and address.

Related