Onboarding is where most merchant risk decisions are made, and where they are most often made inconsistently. A review that works for fifty applications a month can quietly break at five hundred. The fix is not more effort per case; it is a structure that makes each decision repeatable and each outcome explainable.

Start with what "know your business" actually means

Know Your Business (KYB) is the business-facing counterpart to Know Your Customer. For a merchant it usually covers four questions: who legally operates the business, who ultimately owns or controls it, what the business actually sells, and whether any of that touches restricted or prohibited activity. A scalable review answers those four questions the same way every time.

  • Legal identity. Registered name, company or tax number, registered address, and trading status against an official registry where one is available.
  • Ownership and control. Beneficial owners above your ownership threshold, plus directors and controllers, screened against sanctions and politically exposed person (PEP) lists.
  • Business model. What is sold, to whom, at what price points, through which channels, and how fulfilment works. This is the part most often skipped and most often wrong.
  • Category alignment. Whether the stated activity matches the merchant category code (MCC) being requested and whether it falls inside your accepted-business policy.

Tier before you review

Not every merchant needs the same depth of review. A low-risk retailer selling physical goods domestically does not need the scrutiny a high-risk, subscription-billing, cross-border merchant does. Define two or three tiers up front, each with its own document checklist and evidence bar. Tiering is what lets volume grow without the review queue collapsing: most applications flow through a light path, and analyst time concentrates where risk actually sits.

A useful test: if two analysts reviewed the same application independently, would they collect the same evidence and reach the same risk tier? If not, the criteria are still living in people's heads rather than in the process.

Make evidence a requirement, not a by-product

Every decision should leave a record of what was checked, what was found, and why the conclusion followed. This is not bureaucracy for its own sake. When a merchant is later questioned, or a regulator or scheme asks how it was approved, the onboarding file is the answer. Capture the source of each check, the date, and the analyst, and store the actual artefacts (registry extract, website capture, screening result) rather than a note that they were seen.

Decision, not just a score

A risk score is an input, not a decision. The output of onboarding should be an explicit decision (approve, approve with conditions, refer, or decline) tied to the evidence. "Approve with conditions" is often the most valuable outcome: it lets you take on a merchant while setting the monitoring triggers, limits, or review dates that its risk warrants.

Build in quality control

As volume rises, sample completed reviews and re-check them against the criteria. A small, regular QA sample catches drift early: a checklist item quietly being skipped, a tier being applied too loosely, evidence going uncaptured. QA is how a process stays consistent after the people who designed it have moved on.

What good looks like

A scalable onboarding review has a written accepted-business policy, tiered checklists, mandatory evidence capture, explicit decisions with conditions, and a QA loop. None of it is exotic. The discipline is in applying it the same way on the five-hundredth application as on the fifth.