Every ISO we audit is bleeding somewhere. Not because anyone is careless — because payments billing is built to drift. Contracts change, processors migrate, splits get renegotiated verbally and never make it into the system. Here are the five leaks we find almost every time.
1. Residual splits that drifted
The split you negotiated is not the split you are being paid. Migrations, portfolio sales, and "temporary" adjustments pile up until the effective rate is points below the contract. We reconcile the actual deposits against the signed schedule — the gap is usually visible in the first month we check.
2. Fees nobody renegotiated
Processor fee schedules age badly. The rates that made sense at signing become the expensive default nobody re-opens. If your agreement is more than two years old, you are almost certainly paying for 2024’s risk profile with 2026’s volume.
3. Billing that doesn’t match the contract
Merchant-level billing drifts the same way residuals do: annual fees that stopped being billed, PCI non-compliance fees applied inconsistently, monthly minimums forgotten after a platform change. Each one is small. Portfolio-wide, they compound into real money — in either direction.
4. Free equipment that never came back
Terminals and gateways deployed as retention tools, never recovered, never written off, still accruing fees. The hardware ledger is nobody’s job, which is exactly why it leaks.
5. Attrition you measured wrong
Most ISOs measure merchant count, not residual-weighted attrition. Losing forty small accounts hurts less than losing one anchor — but the dashboard says the opposite. Weight your churn by residual contribution and the retention priorities reorder themselves overnight.
We find these because we run the same audit on our own companies every month — the tooling exists because our own P&L demanded it. If you want it pointed at your book, that’s The Operator’s Audit.