fact_check Compliance

Merchant Verification Policy

What every supplier is verified on before it can sell through DorskoPay, and how that verification is maintained afterwards.

Version 1.0 · Effective 20 August 2026 · Last updated 20 August 2026
Current status: DorskoPay is not issuing production accounts today. This policy is DORSKO LIMITED's adopted verification standard and describes the process a supplier goes through for production approval. Sandbox access is granted on registration and involves none of this — it is a test environment, and it carries no approval of any kind.

The short version

  • check Every supplier is verified as a business, as a set of people, and as a product before it can sell.
  • check Because DorskoPay is the seller of record, an unverified supplier is not merely a risk to buyers — it is a liability DorskoPay carries directly.
  • check Verification is not a one-off: accounts are monitored continuously and re-reviewed periodically and on trigger.
  • check We publish what we check and why. We do not publish thresholds, scores or decision rules, because that would tell the people we screen for exactly how to pass.

1. Why verification is strict here

On a conventional payment gateway, a merchant sells to its customer and the gateway moves the money. If the merchant misbehaves, the gateway's exposure is a chargeback and a reputational problem.

Under the Merchant of Record model, DorskoPay is the seller. DorskoPay's name is on the contract, the receipt, the tax documentation and the buyer's statement. A supplier that does not deliver creates a debt owed by DorskoPay to a buyer. A supplier selling something it has no right to sell creates a claim against DorskoPay. A supplier laundering transactions creates a financial-crime exposure for DorskoPay.

So verification here is not a compliance formality performed on someone else's behalf. It is DorskoPay underwriting its own counterparty risk, and it is proportionate to the fact that DorskoPay cannot disclaim what a supplier does.

2. Sandbox is not approval

Anyone can register for a sandbox account. It exists so that a developer can build and test an integration against simulated transactions, and it involves no verification, no approval and no ability to take real money.

Production access is a separate decision, reached through the process in this policy. A sandbox account carries no expectation of approval, and building an integration is not a commitment by DorskoPay to approve the business behind it.

3. Corporate identity

We verify that the business exists, that it is what it says it is, and that it is in good standing.

  • Registered legal name and legal form.
  • Company registration number, and the register it is held on.
  • Country and date of incorporation.
  • Registered office address.
  • Trading name, where it differs from the legal name.
  • Tax identification or VAT number where the business holds one.
  • Good standing on the relevant register, and whether the entity is subject to insolvency or strike-off proceedings.

Registry data is checked against what the applicant told us. A discrepancy is not automatically fatal, but it must be explained.

4. Where the business actually operates

A registered office is a legal address, not evidence of an operating business. We verify the principal place of business separately: where the business is actually run from, where its people are, and whether that is consistent with its incorporation, its banking, its website and its customer base.

A mismatch between the country of incorporation, the country of operation, the payout account and the customer base is a pattern we look at closely. It is common in entirely legitimate businesses, and it is also the shape of a shell arrangement, so it is examined rather than assumed either way.

5. Ownership, directors and beneficial owners

We verify who owns and controls the business, not just who signed up.

  • The shareholding structure, including intermediate holding entities up to the ultimate level.
  • Ownership percentages.
  • All ultimate beneficial owners meeting the applicable threshold, and the basis of their control where control is exercised other than through shareholding.
  • Directors and officers.
  • The authorised representative accepting the Supplier Agreement, and evidence of their authority to bind the company.

Where ownership is held through a chain of entities or a nominee arrangement, we follow it to the natural persons at the top. An ownership structure that cannot be explained is a reason to decline.

6. Identity verification of individuals

For directors, beneficial owners and the authorised representative, we verify identity:

  • Government-issued photographic identity document.
  • Verification that the person presenting the document is its holder, where a liveness or biometric check is used.
  • Evidence of residential address, from a document dated within an acceptable period.
  • Nationality and country of residence.
  • Date of birth.
Identity verification is designed to run through an approved third-party verification provider. The platform ships with verification simulated and no provider credentials configured, so where a check has not been run through a live provider, that is recorded as such against the account rather than presented as a completed check.

7. Screening

The business, its directors and its beneficial owners are screened against:

  • Sanctions lists applicable to DORSKO LIMITED and to its payment partners.
  • Politically exposed person (PEP) status, and close associates and family members where the data is available.
  • Adverse media, where available, for financial crime, fraud, regulatory action or insolvency history.

A sanctions match is decisive: we do not onboard, and we are required to act on it. A PEP or adverse-media match is not automatically disqualifying — it triggers enhanced due diligence under clause 12 and a documented decision.

Screening is repeated on an ongoing basis, not only at onboarding, because status changes.

8. The product, the website and the offer

Because DorskoPay resells the product, the product itself is underwritten:

  • What the product is, what it does, and whether it exists in a usable form we can see.
  • The supplier's right to sell it — ownership or a valid licence.
  • The website: whether it is live, whether it describes the product accurately, whether it has working contact details, and whether its terms are consistent with what is sold.
  • Pricing and, for subscriptions, the renewal price, interval, trial terms and cancellation route.
  • The delivery method and timing, and whether delivery is verifiable.
  • The supplier's own refund policy and consumer terms, and whether they are consistent with DorskoPay's buyer-facing commitments.
  • Whether the product falls within the Acceptable Use Policy, and whether it needs approval as a restricted category.
  • Support: whether there is a real route for a buyer to get help.

A product whose website does not work, whose description does not match what it does, or whose cancellation route cannot be found is not approved until it is fixed.

9. Trading and processing history

Where a supplier has processed payments before, we ask for the history, because past processing is the best available evidence of future behaviour:

  • Current and previous payment processors, and the standing of each account.
  • Whether the supplier has been terminated, suspended or placed on a card scheme monitoring programme by any processor, and the reason given.
  • Recent processing statements covering a representative period.
  • Monthly total processing volume and transaction count.
  • Average transaction value.
  • Refund volume and refund rate.
  • Chargeback volume and chargeback rate.
  • Fraud volume and fraud rate.
  • Currency mix, buyer countries and card-issuer geography.
  • The proportion of volume that is subscription rather than one-off.
  • Seasonality and any history of volume spikes.

A supplier with no processing history is not disqualified — new businesses have to start somewhere — but it changes what the file rests on, and it is a factor in whether a reserve applies under the Supplier Agreement.

10. Financial and payout verification

  • The payout bank account, verified as belonging to the verified legal entity — not to a director personally, not to a related company, and not to a third party.
  • The country and currency of the account, and its consistency with where the business operates.
  • Financial information proportionate to the expected volume, which may include financial statements or management accounts.
  • Whether the business can absorb its own refund and chargeback exposure, which informs the reserve decision.

A change of payout account after approval triggers re-verification, and payouts may be paused until it completes. This is a standard control against account takeover and it is not waived on request.

11. Tax and regulatory exposure

We assess where the supplier's buyers are, what tax treatment that implies for a sale made by DorskoPay as seller of record, whether the product's tax category is correctly stated, and whether the supplier or its product requires a licence, registration or permission in any market it sells into.

12. Enhanced due diligence

Some files get more scrutiny. Enhanced due diligence is applied where the risk assessment indicates it — for example where there is a PEP or adverse-media match, an opaque or multi-jurisdictional ownership structure, a higher-risk country connection, a restricted product category, a prior termination by another processor, or a projected profile materially out of line with the business's size or history.

Enhanced due diligence means more evidence, corroboration from independent sources, an explanation of the structure and the source of funds where relevant, and a decision recorded with its reasons at a senior level.

13. Decision

A verification file results in one of four outcomes, each recorded with its reasons:

Approved
The supplier may sell approved products, on the commercial terms issued to it.
Approved with conditions
Approved subject to conditions — a reserve, a volume or geography limit, a restricted product set, a shorter review cycle, or a specific fix to the website or product presentation before going live.
Enhanced review
Not yet decided; more evidence required. The file stays open and the applicant is told what is outstanding.
Declined
Not approved. The applicant is told, and told what they can do about it, to the extent we are permitted to say.

Approval is not permanent. It is a decision on the evidence available at the time, and it is revisited under clause 14.

14. Ongoing monitoring

Verification does not stop at onboarding. Live accounts are monitored on an ongoing basis:

  • Transaction monitoring — volume, transaction count, average transaction value, currency mix, buyer and card-issuer geography, and time-of-day patterns.
  • Refund, chargeback and fraud rates, tracked against the account's own baseline and against scheme thresholds.
  • Delivery performance — whether fulfilment is actually happening after a sale.
  • Complaints — volume and themes, under the Complaints Policy.
  • Website monitoring — whether the site, the product, the pricing, the terms and the cancellation route are still what was approved.
  • Screening refresh — sanctions, PEP and adverse-media screening repeated on an ongoing basis.
  • Registry monitoring — changes in ownership, directors, or company status.

A material change in the processing profile — a volume spike, a shift in geography, a change in average transaction value, a change in product mix — triggers review in its own right.

15. Periodic review

Every supplier is re-reviewed periodically, on a cycle set by its risk classification: higher-risk accounts more often, lower-risk accounts less often, and every account within a defined maximum interval.

A periodic review refreshes the verification data, re-screens the individuals, re-checks the website and product, and reassesses the risk classification and any reserve.

16. Changes that trigger re-review

The Supplier Agreement requires a supplier to notify us of these; each one reopens the file:

  • A change of legal entity, ownership, ultimate beneficial owner, director or authorised signatory.
  • A material change to a product, its price structure, its delivery method or its refund treatment.
  • A new product or a new business model.
  • A change of payout bank account.
  • A material change in volume, average transaction value, geography or customer profile.
  • Insolvency, an investigation, an enforcement action or a material legal claim.
  • Termination or suspension by another processor, acquirer or platform.

Failing to notify us of one of these is itself a breach, and is treated more seriously than the change would usually have been.

17. Suspension and re-verification

Where monitoring or a review raises a concern, we may request information, apply or increase a reserve, restrict products, territories or volume, suspend new transactions, suspend payouts pending investigation, or suspend or terminate the account.

Where verification lapses — a document expires, a re-screening cannot be completed, a requested item is not provided within the period specified — access may be restricted until it is restored.

A supplier can ask for a decision to be reviewed under the Complaints Policy, and the review is carried out by someone other than the person who made the original decision.

18. What we do not publish

This policy sets out what we check and why. It does not publish the thresholds, scores, rules or risk models behind those checks.

That is deliberate and it is not evasion: publishing the thresholds at which a transaction is held, an account is flagged or a reserve is applied would hand a template to exactly the applicants the process exists to catch. The detail is documented internally, and it is available to an acquiring partner, an auditor or a competent authority on request.

19. Data protection

Verification involves personal data about directors, beneficial owners and representatives. What is collected, the legal basis for it, who receives it, how long it is kept and what rights the individual has are set out in the Privacy Policy.

Verification data is used for verification, financial-crime prevention and the operation of the account. It is not used for marketing.

Related documents

DORSKO LIMITED trading as DorskoPay · Company No 15104126 · Registered in England and Wales

Registered office: Unit A, 82 James Carter Road, Mildenhall, Suffolk, IP28 7DE

support@dorskopay.com