High-Risk Underwriting: What Acquirers Check Before a MID
High-risk underwriting explained check by check: KYB, KYC and the credit pull, website review, history and volumes, bank verification, sanctions screening, the call.
High-risk underwriting is a sequence of checks, each closing a question: does the entity exist, is the signer real and creditworthy, does the site match the model, how much exposure the volume creates, where settlements go, is anyone on a list, can one person explain it. Files fail when two checks disagree. A coherent file has one name, one state, one story, one reachable signer. The IBO package supplies entity, director and bank as one set.
High-risk underwriting is the acquirer's review of a merchant before it issues a MID: a sequence of checks, each closing one question. KYB confirms the entity exists and who controls it. KYC and a credit pull confirm the signer and guarantor are real, US-resident and reliable. The website review confirms the business on paper is the one customers see. Processing history, projected volumes and ticket size set the exposure the acquirer takes on. Bank verification confirms where settlements go. Sanctions screening confirms nobody in the file is on a list. The verification call confirms one person can explain all of it. A missing document usually pends a file; two checks that disagree are what decline it.
| Check | Question it closes | What the underwriter reads |
|---|---|---|
| KYB on the entity | Does this company exist, where, and who runs it? | Articles, operating agreement, EIN letter |
| KYC on the signer and guarantor | Is this person real, US-resident and accountable? | Government ID, proof of address, signed guarantee |
| Credit pull | Is the guarantor financially reliable? | The guarantor's credit file |
| Website review | Is the site the business on the application? | Products, prices, policies, checkout |
| Processing history | How did this merchant behave before? | Prior statements, or none for a fresh entity |
| Projected volumes and ticket size | How much exposure does this account create? | Monthly volume, average and highest ticket, billing model |
| Bank verification | Do settlements go to the applying entity? | Voided check, bank letter or statement |
| Sanctions screening | Is anyone in the file on a list? | Entity, signer and guarantor names |
| Verification call | Can the signer explain the business? | A call with the authorized signer |
KYB on the entity
KYB (Know Your Business) checks that the applying entity is a real company and that the people on the file are the ones who control it. The underwriter reads the articles for the legal name, state and formation date, the operating agreement or bylaws for who manages and signs, and the EIN letter for the tax ID tied to that name. The check looks for alignment: the name on the articles is the name on the EIN letter, the manager on the operating agreement is the person signing the application, and the state of formation matches where that person lives, because an entity formed in one state and run from another is a pattern underwriters associate with shells. In an IBOCore package the LLC or C-Corp is incorporated in the director's home state, the director is named on the formation documents and the EIN is issued before delivery, so this check reads one name and one state everywhere. The KYB guide on this blog covers how the review continues after approval.
KYC on the signer and guarantor, and the credit pull
The entity does not carry risk on its own; a person does. The authorized signer signs the merchant agreement and the personal guarantor accepts liability for what the account owes if the entity cannot pay. On a high-risk file they are usually the same person, and KYC runs on that person: a government photo ID and a proof of address that agree with each other and with the application. The credit pull follows: acquirers use the guarantor's credit file as a proxy for financial reliability, because a guarantee is only worth what the guarantor could pay. A background check comes next; a criminal record on a director is a decline for most acquirers. A non-resident cannot fill this line personally, so the profile of the person who does is the most important variable in the file. In an IBOCore package that person is the nominee director, the Independent Business Operator (IBO), a real and consenting US resident verified before the package is listed.
- Residency: a home address matching the ID and the state of the entity; every IBOCore director lives where the entity is incorporated.
- Record: zero criminal record, checked before a director enters inventory.
- Credit: a score of 650 or more on every director, because lower scores raise flags at the credit pull.
- Freshness: a guarantor already on many recent MIDs trips velocity checks; every IBO is exclusive to one merchant and never used on another file.
- Reachability: the director takes verification calls and signs what the acquirer sends for the active life of the package.
Need a director whose file already answers these checks?
Every IBOCore director is a real, KYC-verified US resident with a clean record and a credit score of 650 or more. Browse the inventory page or ask on Telegram.
Website review
The underwriter opens your website with the application next to it and reads the site as evidence, not as marketing. What is sold on the site is what the application describes, with no product the description omits. The risk in the model is disclosed: delivery times for physical goods (future-delivery exposure), recurring terms shown before checkout (undisclosed rebills drive subscription disputes), and a refund and cancellation policy customers can find. The site belongs to the applicant: legal name and contact details match the file, the email sits on the company domain, and the billing descriptor is one the cardholder will recognise. IBOCore ships a professional email on the company domain with every package and sells a document template pack ($499 one-time) with refund policy and terms of service templates; the store and its policies remain yours to build.
Processing history, projected volumes and ticket size
Processing history is the underwriter's best evidence of behaviour: previous statements show monthly volume, average ticket, refund ratio, dispute ratio and how the last relationship ended. A fresh entity has none, which is normal rather than failing; the weight moves to the signer, the website and the projections. What hurts is history from another entity attached without explanation, or a past termination the underwriter finds through a MATCH query rather than in the application. Projected volumes and ticket size are where the acquirer sizes its exposure. The average and highest ticket decide what one dispute costs. From these it sets a processing cap and a reserve (the rolling reserves guide on this blog covers both). Projections are read against the site and the description: one-time sales cannot sit next to a projection dominated by rebills. At IBOCore, subscription-heavy and continuity billing belongs on Grey Hat ($2,499 setup, then 9% of deposit volume); standard high-risk e-commerce, dropshipping and info-products sit on White Hat ($1,999 setup, then $4,499 per month). The volume type declared at purchase must be the one processed; a misclassification suspends the package.
Bank verification and sanctions screening
Bank verification answers one question: will settlements land in an account that belongs to the applying entity? A voided check, a bank letter or a recent statement must show three things: the account holder is the entity under its exact legal name, it is a business account, and the routing and account numbers match the application. An account in a personal name or another company's name is a third-party settlement account and is refused. The IBOCore package includes a business bank account opened at Bluebanc or Relay in the company's name, with full operational access handed to you: inbound and outbound wires, debit card, no minimum balance. Sanctions screening runs on every name in the file. The names are matched against sanctions lists, in the US primarily those maintained by OFAC, and against MATCH, the file of merchants terminated for cause. A hit on either is not explained on a call; it stops the file. MATCH is not a sanctions list but is queried at the same stage; a fresh entity with a director never used on another file carries no termination history for it to find.
Checks that end a file rather than pend it
A sanctions hit, a for-cause MATCH listing on the entity or the principal, products on the site the application omits, and a vertical the acquirer does not board. Each acquirer keeps its own list. IBOCore's is on the industries page: adult content and cam, online gambling, pharmacy and Rx, firearms and ammunition, crypto exchanges and custody, and anything fraudulent are refused.
The verification call
Once the documents agree, the acquirer's risk team calls the authorized signer. The call confirms that the person who signed exists, consents, and can describe the business. Typical questions: what is sold, to whom, how it is delivered and billed, the refund policy, who runs day-to-day operations. The call exposes two failures. A signer who cannot be reached is read as one who will not be reachable at the next dispute or re-verification, and the file stalls. A signer who answers but cannot explain the business is read as a signature bought for the application. In an IBOCore package the director takes the call personally, so the business description you write must be one the director has read and can repeat in plain words. The verification call guide on this blog lists the questions in detail.
What makes a file coherent
- One legal name, spelled the same way on the articles, the EIN letter, the bank document, the application and the website.
- One state: the entity is formed where the signer lives and holds a driver's license, and the proof of address says so.
- One person: the manager on the operating agreement, the signer, the guarantor, the bank signer and the voice on the call.
- One story: the description, the projections, the billing model on the site and the MCC your ISO assigns describe the same business.
- One settlement account, in the entity's name, that you control and keep free of personal transactions.
- Nothing hidden: a fresh entity presented as fresh, past terminations disclosed, every product on the site in the description.
Coherence is what a packaged file buys. The entity, the director and the bank account in an IBOCore package are built together, in the director's home state, with one legal name on every document and a director never used on another merchant's file. The website, description and projections are yours and must meet the same standard. You then apply through your own ISO or directly; IBOCore is processor-agnostic. The package ships the same day payment confirms, and the acquirer's onboarding typically takes 3 to 10 business days from there. That timeline is the acquirer's, and so is the decision. The document checklist guide on this blog lists the documents behind each check.
One file, one name, one reachable director
Packages ship the same day payment confirms. Bring your own ISO or apply directly, with a file built to agree with itself.
Questions merchants ask
How long does high-risk underwriting take?
The review belongs to the acquirer; its length depends on the vertical, the acquirer's queue and how fast pends are answered. On the IBOCore side, the package is delivered the same day payment confirms, acquirer onboarding then typically takes 3 to 10 business days, and monthly billing starts 30 days after delivery. A file that raises no questions on the first pass is what shortens it in practice.
Is a credit score of 650 enough for every acquirer?
650 is the minimum IBOCore requires on every director, because banks and processors use the score as a proxy for financial reliability and lower scores raise flags at the credit pull. Acquirers set their own thresholds and none reads the score alone: it is weighed with the record, the residency, the vertical, the volume and the guarantee. No provider can state what a given score will do at a given acquirer, and IBOCore does not.
What happens when the underwriter comes back with a pend?
A pend is a request for more before a decision: a certificate of good standing, a second proof of address, updated projections or a rewritten description. Anything the director must sign or say goes through the private Telegram group with your account manager; the director stays available for the active life of the package. Anything written by the business stays on your side. Answer quickly and keep the addition consistent with the file: a document that introduces a new name or address reopens questions the file had already closed.
High-risk MID metrics acquirers watch
Once live, your chargeback ratio (CB ratio) is chargebacks divided by transactions; Visa VDMP and Mastercard ECP programs trigger when you breach network thresholds. Rolling reserves (often 10% for 180 days) protect the acquirer against future disputes. MATCH (Terminated Merchant File) is the industry blacklist after a forced termination. MCC (Merchant Category Code) must reflect your real vertical; miscoding is a scheme violation.
- Representment: fighting a chargeback with delivery proof and logs.
- RDR / Ethoca alerts: pre-chargeback refund tools that protect your CB ratio.
- Statement descriptor: keep it recognizable to cut "friendly fraud" disputes.
- Processing cap: volume limit until the acquirer trusts your history.
MID stacking without structure
Spreading volume across many MIDs without separate entities looks like ratio gaming or transaction laundering to risk teams. The durable pattern is one IBO package per MID, clean descriptors, honest MCC, and reserves treated as a cost of doing high-risk volume.
FAQ: quick answers
How fast can I get an IBO package on IBOCore?
Available inventory ships the same day after payment. You receive Articles, EIN letter, registered agent details, bank onboarding pack and signer contact through your merchant dashboard. Processor onboarding typically follows over the next one to two weeks.
Where can I look up payment-processing jargon?
Use the Resources glossary on IBOCore (/resources) for 580+ definitions: MID, chargeback ratio, MATCH, rolling reserve, MCC, RDR, KYB and high-risk vertical vocabulary.
Ready for instant delivery?
Browse live IBO inventory or ask about your vertical on Telegram.