Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
Customer is required to maintain books and records in connection with the agreement for at least one year post-termination (or longer as required by law) and must make these available to Marqeta, the Issuer, Card Brands, Regulators, the KYC Service Provider, and any of their third-party designees for audit purposes. Customer bears all costs of record keeping and audit access.
This analysis describes what Marqeta's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision grants a broad set of parties, including Marqeta's third-party designees, audit access to Customer's business practices and compliance records for the duration of the agreement and at least one year after termination. Customer bears all associated costs, and the scope of business practices subject to audit is not limited solely to card program operations.
Under this clause, Customer must maintain compliance records and make them available to Marqeta, the Issuer, Card Brands, Regulators, the KYC Service Provider, and any of their third-party designees throughout the agreement term and for at least one year after termination. Customer is responsible for all costs of maintaining and providing access to these records.
Cross-platform context
See how other platforms handle Audit Rights and Records Retention and similar clauses.
Compare across platforms →Monitoring
Marqeta has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"During the term of the Agreement and for at least one (1) year thereafter (or longer if required by Applicable Law), Customer acknowledges and agrees that its compliance with the terms, conditions, and provisions of the Agreement, as well as its business practices, are subject to review and audit by Marqeta, Issuer, the applicable Card Brands, or a Regulator, and, when applicable, the KYC Service Provider (defined in Section F (KYC Services), or any third-party designee of Marqeta, Issuer, Card Brand, Regulator, or KYC Service Provider (the "Auditing Parties"), and Customer will keep, maintain, and make available books and records in connection with the Agreement so that the Auditing Parties can determine Customer's compliance with the terms, conditions, and provisions of the Agreement. Customer will be responsible for all costs and expenses for keeping, maintaining, and making available books and records.Excerpt from Marqeta's Terms of Use
1. REGULATORY LANDSCAPE: The audit right provision aligns with regulatory requirements under Card Brand Rules, PCI DSS, and Issuer compliance programs, each of which independently require audit access to card program participants. Regulators with supervisory authority over the Issuer, including the OCC, FDIC, or Federal Reserve, may exercise audit rights through this chain. The CFPB may also conduct examination activities with respect to card program operations through the Issuer or directly. 2. GOVERNANCE EXPOSURE: Medium. The inclusion of third-party designees of Marqeta, Issuer, Card Brands, and the KYC Service Provider as authorized auditing parties means Customer may be subject to audit by entities with no direct contractual relationship to Customer. The phrase business practices is broader than card program compliance and may encompass operational records outside the direct scope of the Marqeta services. Customer's obligation to bear all audit-related costs is operationally significant for frequent or extensive audit requests. 3. JURISDICTION FLAGS: Post-termination audit obligations must be mapped against applicable records retention laws in Customer's operating jurisdictions. California, New York, and federal financial regulations impose varying retention periods for financial records, and the agreement's one-year minimum may be shorter than statutory requirements in some contexts. GDPR and CCPA create tension between records retention obligations and data minimization or deletion rights. 4. CONTRACT AND VENDOR IMPLICATIONS: The audit rights provision should be flagged in Customer's vendor management framework, as the right extends to Marqeta's and the Issuer's third-party designees, creating an indirect access pathway for unspecified external parties. Customer should assess whether its information security policies permit this level of third-party access and what controls govern audit access logistics. 5. COMPLIANCE CONSIDERATIONS: Legal teams should establish a formal audit response protocol that addresses requests from each category of Auditing Party identified in the agreement. Records retention policies should be updated to reflect the one-year post-termination minimum and any longer periods required by applicable law. The interaction between this audit obligation and Customer's data protection obligations under GDPR or CCPA, particularly for records containing personal data, should be assessed to ensure audit compliance does not conflict with data subject rights.
Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.
Compliance Governance Intelligence
Need to monitor specific governance provisions?
Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
This provision grants a broad set of parties, including Marqeta's third-party designees, audit access to Customer's business practices and compliance records for the duration of the agreement and at least one year after termination. Customer bears all associated costs, and the scope of business practices subject to audit is not limited solely to card program operations.
Under this clause, Customer must maintain compliance records and make them available to Marqeta, the Issuer, Card Brands, Regulators, the KYC Service Provider, and any of their third-party designees throughout the agreement term and for at least one year after termination. Customer is responsible for all costs of maintaining and providing access to these records.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Marqeta.