What a payment gateway checks before approving a merchant
Underwriting explained from the decision-maker’s side: what gets assessed, what causes rejection, and how to prepare a file that passes first time.
Being declined by a payment service provider rarely has anything to do with the quality of the business. It has to do with risk — and, more often than people think, with missing information nobody explicitly asked for.
What is actually being assessed
Merchant onboarding measures three things.
Credit risk. If you charge today and deliver in six months, the provider is exposed to chargebacks should the company fold in between. Services delivered immediately face less friction than pre-orders, long subscriptions or advance bookings.
Fraud and chargeback risk. There are sector benchmarks. Consistently exceeding roughly 1% chargebacks puts an account into monitoring programmes; sitting well below that is an argument in your favour worth presenting, if you have the history.
Regulatory and reputational risk. This is where the provider verifies that the activity is lawful in the jurisdiction, that it does not fall into a card-scheme prohibited category, and that beneficial owners do not appear on sanctions lists.
What gets checked on the website
The website is the first piece of documentary evidence, and it is examined seriously:
- Full company identification. Legal name, registered office, registration number and tax number. In Portugal this is not best practice: it is a statutory obligation for commercial companies.
- A clear description of what is sold, with prices or, at minimum, an understandable pricing model.
- Terms and conditions, privacy policy and cookie policy reachable without having to buy anything.
- Refund and cancellation policy, written in language a consumer understands.
- Real contact details — email and, preferably, phone and address. An isolated form with nothing else is a red flag.
- A secure connection and no content or claims that breach card-scheme rules.
Half of all rejections are resolved by half an hour of work on these points.
What gets requested in documentation
The core is the same as a banking file: registry certificate, beneficial ownership, identification of directors, proof of address, recent bank statements. Frequently added:
- Processing history, if you have processed payments with another provider. Include volumes, chargeback rate and the reason for switching. Omitting a previously terminated account is the fastest way to lose credibility — providers share databases of terminated merchants.
- A written business model, with average ticket, expected monthly volume and customer countries.
- Delivery flow: how long passes between payment and service delivery.
How to prepare a file that passes
Answer before you are asked. A two-page document with the activity description, the pricing model, the delivery timeline, expected volume and corporate structure saves three rounds of email.
Be specific with numbers and conservative with projections. A merchant declaring EUR 20,000 a month and processing 8,000 raises fewer questions than the reverse — underestimating is not penalised, exceeding what you declared is.
And keep the website, the application form and the documents consistent with one another. Inconsistency is the one signal that, on its own, fails a file.