Merchant onboarding process flowchart (application to go-live)
Merchant onboarding process template for application intake, policy-based KYB and due diligence, risk decisions, account setup, integration testing, go-live and monitoring handoff.
What the merchant onboarding process flowchart (application to go-live) process is
Merchant onboarding starts before a risk decision. Sales or the account owner records the merchant's requested products and intended activity, while Merchant Operations checks whether the application is complete enough for review. Missing information returns to the merchant instead of moving forward as an assumption. Compliance or the due diligence owner then performs the KYB, ownership, business and other checks applicable under the organization's policy and risk program. Those requirements vary by merchant type, product, geography, channel and applicable obligations, so the chart deliberately names the control without prescribing a universal evidence list. Evidence that is incomplete loops back for clarification, while a concern that cannot be resolved reaches a recorded rejection rather than disappearing from the queue.
Once due diligence can proceed, Fraud / Risk / Underwriting assesses fraud, dispute, financial and operating exposure. Standard cases remain within documented authority; higher-risk or unusual cases receive enhanced underwriting and escalation. The decision has three explicit outcomes: approve, conduct further review, or reject. Approval does not mean immediate activation. Sales records the commercial terms and conditions, Merchant Operations configures the account, limits and controls, and a separate verification gate returns incorrect settings for repair. Engineering then issues integration and acceptance requirements, the merchant implements them, and failed functional, security or transaction tests loop back for defect correction before any production activity begins.
Production activation waits for a controlled handoff. Merchant Operations passes the approved risk profile, controls, alert plan and named monitoring ownership to the receiving team; that owner must acknowledge both the material and operational readiness before Engineering enables processing. Monitoring access, alert configuration and response ownership therefore sit inside the go-live gate alongside support and settlement readiness, not in a task scheduled after launch. The handoff joins this workflow to merchant risk assessment and monitoring. Once transactions begin, reconciliation checks processing and settlement records, while exception management handles ambiguous, failed or mismatched events. Adapt the roles, authorities and controls to the actual business rather than treating one KYB or monitoring sequence as universal.
What this flowchart covers
In this template
- Six stage lanes from application intake through due diligence, risk decision, account setup, integration testing, and go-live with a monitoring handoff
- Six actor lanes for Merchant, Sales / Account, Merchant Operations, Compliance / Due Diligence, Fraud / Risk / Underwriting, and Engineering / Integration
- Application completeness and policy-based KYB or due diligence checks, including evidence requests and an explicit route when requirements cannot be satisfied
- Approve, further review and reject outcomes, followed by controlled commercial terms, account settings, limits and a configuration correction loop
- Integration testing and defect remediation followed by a pre-activation handoff of the approved profile, controls, alert plan and monitoring ownership
- A monitoring-owner acknowledgement gate that includes support, settlement and monitoring readiness before production activation
When to use this template
- Merchant applications move between sales, operations, compliance, risk and engineering without one owner for the end-to-end status
- Incomplete evidence enters underwriting and creates repeated questions, inconsistent decisions or undocumented exceptions later in onboarding
- Commercial approval is being mistaken for permission to activate an account before configuration and integration controls have been verified
- Integration defects or launch-readiness gaps are discovered after production processing begins rather than at a defined acceptance gate
- The merchant risk assessment and merchant monitoring teams receive a live account without the approved conditions, controls or review plan
How it works
Define the application and completeness standard
List the business, ownership, product, geography, channel, volume and settlement information needed to begin review. Separate information that is mandatory for intake from evidence that may be requested after risk triage. Give Merchant Operations authority to return an incomplete application, and record the reason so Sales and the merchant can respond to one consolidated request rather than a sequence of unrelated emails.
Tailor due diligence to policy and risk
Replace the generic due diligence box with the checks, sources, evidence owners and refresh rules approved for your products and merchant segments. State where KYC or KYB applies, how beneficial ownership or business activity is evaluated, and who may resolve a discrepancy. Do not copy a fixed checklist from this template or another provider; requirements depend on internal policy, risk and applicable obligations.
Write decision authority and escalation criteria
Name who can approve a standard case, who conducts enhanced underwriting, and who can accept specific controls or restrictions. Define what sends a case to further review and what evidence returns it to the decision gate. Keep approval, further review and rejection as separate recorded outcomes so a pending escalation cannot be reported as an approval.
Connect approval to account configuration
Map each approved commercial or risk condition to an account setting, limit, reserve, capability or operational action, then require a second check that the configuration matches the decision. Record who can change those settings and how the change is approved. This prevents an accurately documented risk decision from being implemented incorrectly in the payment platform.
Set acceptance and monitoring handoff criteria
Define representative functional, security, failure and transaction tests, the evidence required to pass, and the owner for each defect. Before activation, hand over the approved profile, limits, controls, alert plan and named monitoring ownership. Require the receiving owner to acknowledge access, alert configuration and response readiness alongside support contacts, settlement setup, communications and launch timing.
Frequently asked questions
What are the main stages of merchant onboarding?
A practical sequence is application intake, completeness review, applicable due diligence, fraud and underwriting assessment, an approve, further-review or reject decision, commercial and account configuration, integration implementation, acceptance testing, monitoring handoff and acknowledgement, then production activation. The exact checks and authorities must be adapted to the merchant, product, risk program and applicable obligations.
Are KYC and KYB requirements the same for every merchant?
No. The relevant checks, evidence, depth and refresh cadence vary with the legal relationship, merchant type, ownership structure, products, geography, channels, risk profile and applicable obligations. This template makes due diligence and unresolved evidence visible but does not prescribe a universal checklist. Compliance and risk owners should approve the version used by the organization.
Why are approval and go-live separate decisions?
Approval establishes that the relationship may proceed under recorded terms and controls. Go-live also requires correct configuration, passed acceptance tests, support and settlement readiness, and an acknowledged monitoring handoff with working alerts and named response ownership. Keeping these decisions separate prevents commercial or risk approval from bypassing technical and operational safeguards.
What should be handed from onboarding to merchant monitoring?
The handoff should include the current merchant profile, approved products and channels, risk tier, controls, limits, reserves or restrictions, expected activity, alert plan, review cadence, open conditions and named owners. The monitoring owner should acknowledge receipt, access and readiness before activation, so actual behavior can be compared with the authorizing decision from the first production event.
Where this process fits
In most operations this process hands off to Merchant risk assessment process flowchart (profile to monitoring).
It is one step in Merchant onboarding and risk.
Step 1: Merchant onboarding process flowchart (application to go-live) You are here
Merchant onboarding process template for application intake, policy-based KYB and due diligence, risk decisions, account setup, integration testing, go-live and monitoring handoff.
Step 2: Merchant risk assessment process flowchart (profile to monitoring)
Merchant risk assessment template for profile data, policy-based due diligence, fraud, dispute, financial and operational analysis, tiering, controls, decisions and review.
Step 4: Merchant monitoring process flowchart (signals to risk feedback)