Platform
Solutions
Resources
Company
Resources
Solutions

MASAK compliance and merchant risk in marketplaces

E-commerce intermediary service providers are obliged parties under Law No. 5549, and MASAK publishes a dedicated suspicious transaction report guide for this group. A significant portion of the 32 sector-specific types focus not on the platform's own customers, but on the merchant operating on the platform. TruvaLI keeps merchant onboarding, merchant behavior, and buyer transactions within the same risk framework. Deployment is done in the cloud, private cloud, or on-premise.

In marketplaces, because the intermediary service provider facilitates transactions for goods it does not sell itself, it is responsible for verifying the authenticity of both the merchant and the buyer. Intermediary service providers are obliged parties under Law No. 5549.

Why is the intermediary service provider an obliged party?

E-commerce intermediary service providers are obliged parties under Law No. 5549 on Prevention of Laundering Proceeds of Crime. MASAK publishes a dedicated suspicious transaction report guide for this group and expects reports to be submitted electronically via the MASAK.Online system.

The sector-specific section of the guide lists 32 types, and a significant portion of these focus not on the platform's own customer, but on the merchant operating on the platform. This is where a marketplace's risk surface lies: in the merchants it accepts.

Which indicators does the guide list?

GroupNumber of typesWhat it monitors
Customer profile16Declarations, documents, and avoidance of declaration
Sector-specific32Merchant, buyer, product, price, and feedback
Terrorist organizations and risky countries18Parties and geography
Non-profit organizations6Actions of directors and financial officers
Financing of weapons of mass destruction17Sanctions regime

Indicators related to the merchant

TypeWhat it says
T-020-2.19A normally low-volume merchant unexpectedly making very high-value sales in a short period, or a sudden increase in the number of transactions
T-020-2.24The merchant providing incomplete or incorrect information required to operate on the marketplace
T-020-2.26Detection of unrealistic positive reviews or manipulated feedback about the merchant
T-020-2.28The merchant receiving higher-than-normal customer complaints and failing to take necessary action against these complaints
T-020-2.32A merchant that has been inactive for a long time suddenly and unusually becoming active during a specific period

None of these five are visible at the time of onboarding. They are all read from data generated after the merchant begins operating on the platform: volume curves, complaint rates, review patterns, inactivity, and sudden activity.

T-020-2.26 is particularly striking because it lists review manipulation as a laundering indicator. This means that the marketplace's own reputation system is also a data source that must be monitored.

Indicators related to products and prices

T-020-2.20 lists the sale of prohibited or dangerous products on the platform, such as materials that terrorist organizations could procure. T-020-2.22 adds offering the same or similar products for sale at abnormal prices far outside standard market rates, while T-020-2.30 adds frequent and sudden changes in a product's price that are inconsistent with market conditions.

T-020-2.23 lists customers encountering different, counterfeit, or undelivered products instead of the ordered product, while T-020-2.31 lists transactions made using fake credit card details and the detection of counterfeit products being purchased through these transactions.

These five show that the product catalog and price history are also risk data. A monitoring structure that only looks at the payment flow will miss all of them.

Indicators related to the buyer

T-020-2.21 lists a buyer or merchant performing an unusually high number of return transactions, T-020-2.25 lists an unreasonable number of customers purchasing the same product within specific timeframes outside of special circumstances like discounts or campaigns, T-020-2.27 lists buyers making sudden and high-value purchases outside of their normal shopping habits, and T-020-2.29 lists a high volume of purchase transactions originating from a specific region in a short period without a reasonable explanation.

None of these four can be detected by looking at a single order: they require comparison with the buyer's history, collective behavior around the same product, or geographical concentration.

Who is the actual party?

The first eighteen types in the guide are identical to the common core in other sector guides: concealing the ultimate beneficial owner (UBO) in the transaction (T-020-2.11), the third party directing the transaction not being a party to official documents (T-020-2.9), the lack of a logical commercial link between the parties (T-020-2.12), and complex, multi-jurisdictional structures (T-020-2.13).

In a marketplace, this means that merchant onboarding is a KYB task: these four types cannot be addressed without resolving the ownership structure of the company behind the store.

What does the reporting form require?

Suspicious matters that do not contain monetary value are written in the description section of the form, not the suspicious transaction section. This means a case must also be able to carry non-monetary events.

A report can be based on a single transaction or on multiple transactions within a certain date range; in the case of multiple transactions, the total amount and the date range are reported together.

How is the suspicion category selected?

When making a report, the suspicion is placed into one of the categories in MASAK's reference table, and each category is mapped to the relevant legal regulation. This means that case management must operate with this taxonomy rather than its own free-form tags.

What is the threshold for reports with a suspension request?

The regulation based on Article 19/A of Law No. 5549, titled "Suspension of transactions", governs the suspension of transactions based on a report. The guide sets a clear threshold for this: rather than mere suspicion, there must be supporting documents or serious indications that the asset subject to the transaction is related to the crime of money laundering or terrorist financing, and these must be submitted along with the justifications.

This threshold directly generates a system requirement: the evidence must be attached to the case, the justification must be written, and there must be a record of who made the decision.

How does TruvaLI address this?

Merchant onboarding

In the KYB flow, the ownership structure is resolved to identify the ultimate beneficial owner (UBO), and authorized persons and the company record are screened against sanctions, PEP, and internal lists. Any incompleteness or inconsistency in the declared information is recorded in the justification for the onboarding decision; T-020-2.24 requires this.

The merchant's public profile

When the merchant's own website or store page is provided, the content can be scraped and extracted end-to-end, and adverse media and open-source records about the merchant are classified by risk type. Prohibited product lists are set up as internal lists and integrated into the screening flow.

Integrating platform data into rules

Volume curves, complaint rates, return rates, price change frequencies, and review patterns are fed into the rule engine. Thanks to nested logic and flexible aggregation windows, rules such as 'if the number of transactions in the last 7 days exceeds the average of the previous 90 days by X times' can be set up within a single rule, and the rule can be tested on historical traffic via rule simulation before going live.

A network of relationships between buyers and merchants is mapped out using shared IPs, devices, contact information, and payment methods. Types that look at collective behavior, such as T-020-2.25 and T-020-2.29, cannot be detected through individual order checks.

Case, evidence, and category

An alert turns into a case with an owner, a deadline, and evidence. The case also carries non-monetary events. The suspicion category is selected from MASAK's taxonomy, the evidence and decision justification are written to an immutable audit trail, and four-eye approval is managed via maker/checker. The report draft is prepared from the same case data, and the signature remains on the platform.

Related flows: merchant onboarding, e-commerce, chargeback and payment fraud, ongoing monitoring, and regulatory reporting. The framework is on the MASAK obligations page, and relationship analysis is on the fraud detection page.

Source

MASAK, "Suspicious Transaction Reporting Guide for Electronic Commerce Intermediary Service Providers", version 1.0.

This page does not constitute legal advice; it conveys the indicators and procedures listed in the guide. Rules, thresholds, and actions are configured according to the platform's own risk policy and obligations.

Common questions

Where is the primary risk surface of a marketplace?
The majority of the guide's sector-specific types focus on the merchant. Volume spikes, incomplete or incorrect registration details, manipulated reviews, failure to act on complaints, and sudden activity after prolonged inactivity are listed individually.
Why is review manipulation considered a laundering indicator?
Under T-020-2.26, the guide considers the detection of unrealistic positive reviews or manipulated feedback about a merchant to be an indicator of suspicion. This means that the platform's own reputation system is also a data source that must be monitored.
Is merchant onboarding a KYB task?
Yes. Concealing the ultimate beneficial owner (UBO), the third party directing the transaction not being a party to documents, and complex multi-jurisdictional structures are separate types in the guide. They cannot be addressed without resolving the ownership structure of the company behind the store.
Does platform data leave the organization?
Not with an on-premise deployment. The software runs on the platform's own infrastructure, data remains within the platform's information systems, and keys and the audit trail are controlled by the platform.
Why is the intermediary service provider an obliged party?
Because it facilitates transactions for goods it does not sell itself, it is responsible for verifying the authenticity of both the merchant and the buyer; it is an obliged party under Law No. 5549.
What is reviewed during merchant onboarding?
Identity and ownership structure, activity category, consistency between declared information and public footprint, and links to previously closed merchant accounts.
Can it be detected if the buyer and the merchant are the same person?
Yes. A network of relationships established through shared devices, IPs, payment methods, and addresses reveals these connections.
Can platform data be integrated into rules?
Yes. Platform-specific fields such as product category, price, shipping, and return behavior are used as rule inputs.

Related