If they are running their own merchant accounts, then the "processor" (ie, netbilling, ccbill, epoch, etc) is not acting as an ipsp but only as a gateway to enable real-time processing and membership userid/pass generation. So I think they would not be responsible, but instead it would be between the company and the merchant account issuing bank, and prolly directly with the company and visa/mc.
Bookmarks