Your institution is. Outsourcing processing doesn't remove your regulatory or network responsibilities, even though processors may carry their own contractual and network-rule obligations. The license, the fee exposure and the audit answer stay with you, so the real job is knowing which mandates the processor covers, which need your configuration, and which were always yours.
You can outsource card processing. You can't outsource the accountability that comes with it.
Almost every issuer runs at least part of its book on a third-party processor. That isn't a small-institution trait, it's how the industry works. What differs by size is leverage, not dependency.
A large issuer has a named relationship team, contractual commitments on mandate support, and enough volume to get prioritized. A smaller one is on the standard release calendar and takes what arrives. Both have outsourced implementation. Only one can meaningfully influence it, and how much gets communicated back tends to track that leverage.
Outsourcing doesn't remove the institution's regulatory or network responsibilities, although processors can carry direct contractual and network-rule obligations depending on the arrangement. The license, the network relationship, the fee exposure and the audit answer all stay with you.
What network mandates is your processor actually handling?
So the job isn't implementation. It's knowing which announcements your processor is handling, which it isn't, which it will charge extra to handle, and being able to prove the answer when something goes wrong. That gets tracked far less often than it should, because the working assumption is that the processor has it covered. The assumption usually holds, right up until it doesn't.
The other half is volume. By Rivero's analysis, Visa and Mastercard published around 25% more bulletins in 2025 than the year before, close to 2,000 across the two networks. That stream is set by the networks, not by your balance sheet. A $3 billion bank or credit union reads the same volume as a $300 billion one. One has a network compliance team. The other has part of one person who also does three other jobs.
That makes the burden regressive, and it's why "we'll handle it internally" breaks down at the smaller end of the market rather than everywhere.
Test it. Take the mandates from the last Visa and Mastercard release cycle and ask your processor to map each one: implemented, needs your configuration, or out of scope. The last two columns are yours. If they can't produce the mapping, that's your answer too.
And remember many of the fee announcements never touch the processor. Those were always yours.
From a briefing I've written with Rivero on what network compliance actually costs. Download from our website here.
Related reading: which Visa and Mastercard bulletins actually apply to you, and why Visa and Mastercard scheme communications create hidden operational risk.