Legal

Compliance Procedure

The practical steps we follow to onboard customers, monitor activity and manage compliance incidents.

Last updated: 14 August 2026

1. Onboarding due diligence

Every merchant application begins with a risk-based questionnaire and document collection. Required documents typically include incorporation papers, ownership structure, proof of identity for directors and beneficial owners, and a description of the business model.

Applications are assigned a risk rating and reviewed by compliance. Higher-risk applications are escalated to enhanced due diligence before approval.

2. Ongoing monitoring

Once approved, accounts are monitored continuously for transaction velocity, chargeback ratios, sanctions exposure, adverse media and changes in ownership or business activity. Automated alerts are triaged daily and reviewed by trained analysts.

3. Enhanced due diligence triggers

EDD is triggered by factors such as large transaction volumes, jurisdictions requiring enhanced scrutiny, complex ownership structures, PEP exposure, unusual transaction patterns or requests to increase limits. EDD may include source-of-funds documentation, additional verification and senior management sign-off.

4. Suspicious activity reporting

When suspicious activity is identified, it is documented internally and escalated to the nominated reporting officer. Where required by law, a suspicious activity or transaction report is filed with the relevant regulator.

Customers are not notified when a suspicious activity report is made or under investigation, as tipping off is prohibited.

5. Customer cooperation

Customers must respond promptly to compliance requests for information, documentation or clarification. Failure to cooperate may result in transaction restrictions, account suspension or termination of services.

6. Audit and review

Our compliance procedures are reviewed at least annually and after any material change in regulation, business model or risk appetite. Reviews include internal audit, external consultancy input where appropriate, and updates to training and systems.

For procedure-related questions or to submit a compliance request, email compliance@paysumo.io.

Get in touch

Questions about this document? Talk to our team

Our compliance team is happy to clarify anything you read here.