Due diligence
What is due diligence?
Due diligence is the investigation and verification process a regulated financial institution runs on a business or individual before entering a commercial relationship, to confirm identity, legitimacy, and risk exposure. In payments, acquiring banks and apply it to merchants at onboarding and repeat it for as long as the account stays open.
The checks pull registry data, submitted documents, and screening results into a single risk picture: who owns the business, whether it's licensed to sell what it sells, how it earns revenue, and whether anyone connected to it appears on a sanctions or watch list. That picture decides whether the merchant gets a , at what pricing, and under which processing limits.
Key facts
- Also known as: DD; customer due diligence (CDD) when the subject is an individual
- Performed by: banks, acquiring banks, payment service providers, and other regulated financial institutions
- Legal basis: obligations and rules, which require regulated firms to know who they do business with
- Core inputs: incorporation documents, ownership structure down to the , financial statements, licences, processing history, and a review of the live website and refund policy
- Timing: at onboarding, then on a risk-based review cycle or whenever ownership, business model, or processing behaviour changes
How due diligence works
- Collection. The applicant submits incorporation documents, ownership details, financial statements, prior processing history, and settlement bank details.
- Identity verification. checks confirm the individuals behind the application; checks confirm the legal entity against company registries and licensing bodies.
- Screening. Directors and beneficial owners are run against sanctions databases, government watchlists, and politically exposed person (PEP) lists, which flag people whose public office raises bribery and corruption exposure.
- Risk assessment. The reviewer scores the merchant on industry (captured by the ), geography, business model, dispute history, and expected volume. This score feeds directly into .
- Decision and record-keeping. The file closes as an approval, an approval with conditions such as a rolling reserve or volume cap, or a decline. The evidence is retained so a supervisor or auditor can reconstruct why the decision was made.
- Ongoing monitoring. Screening reruns on a schedule and transaction behaviour is watched against the profile declared at onboarding, so a shift in volume, geography, or product triggers a fresh review.
Types of due diligence
Regulated firms work with three levels of depth, each matched to the risk the counterparty presents:
- Simplified due diligence (SDD). Reduced checks for counterparties assessed as low risk, such as listed companies or regulated financial institutions in well-supervised markets. Identity is still verified; the supporting evidence is lighter.
- Customer due diligence (CDD). The default level: identity verification, ownership mapping, sanctions screening, and a documented risk rating.
- Enhanced due diligence (EDD). Applied to , PEPs, opaque ownership chains, and higher-risk jurisdictions. It adds source-of-funds and source-of-wealth evidence, senior management sign-off, and shorter review intervals.
Why it matters
- Ownership screening exposes shell structures used to disguise a terminated merchant reapplying under a new legal entity, which is the standard route into transaction laundering.
- The risk rating produced at onboarding sets pricing, reserve requirements, and volume caps, so a thin or unverifiable file results in tighter limits rather than a faster launch.
- Card schemes hold the acquiring bank responsible for the merchants it signs, so an unvetted merchant that breaches scheme rules or collapses leaves the acquirer covering unpaid .
- Supervisors examine the onboarding file itself, not just the outcome, so missing UBO evidence or unrecorded screening results is a finding even when the merchant turns out to be legitimate.


