Use Cases

Enhanced Due Diligence & Third-Party Risk Assessment: A Fintech Partner Onboarding Case Study

Case Study: Enhanced Due Diligence

How a Payments Platform Used Enhanced Due Diligence to Assess Fintech Partners Before Onboarding

Some platform businesses onboard other fintechs. Payment aggregators, banking-as-a-service providers and embedded finance platforms all do this. Consequently, they carry a due diligence burden that goes beyond standard KYB. Each fintech partner brings its own customer base, transaction flows and risk profile onto the platform’s rails. Inadequate due diligence on a partner can therefore expose the platform to its own regulatory, financial crime, operational and reputational risks.

Below, this case study explains how Compliance7 applied Enhanced Due Diligence for a payments platform. At the time, that platform was expanding its network of fintech partners. The engagement combined Enhanced Due Diligence with a structured third-party risk assessment, allowing the platform to assess ownership, financial crime exposure, business model risk and the partner’s compliance capability before onboarding.

Engagement at a Glance

  • Platform: UK payments platform
  • Partners assessed: Smaller payment and lending fintechs
  • Existing control: Standard Know Your Business (KYB) check
  • Service: Enhanced Due Diligence and third-party risk assessment
  • Output per partner: Assessment report with risk rating and recommendations

The Problem

Standard KYB Answered the Wrong Questions

The platform operator was based in the UK. It was expanding its network of fintech partners. Specifically, these were smaller payment and lending businesses. They plug into the platform’s infrastructure to reach end customers. Each new partner had already passed a standard Know Your Business (KYB) check. That check covered incorporation documents, registered address and basic ownership disclosure.

Standard KYB, however, was not designed to answer the questions that mattered most for this segment. Who ultimately controls each fintech partner, beyond the first layer of disclosed ownership? Did any directors or beneficial owners have adverse media history or sanctions/PEP exposure? Did the partner’s own business model introduce risk the platform had not yet assessed?

That last question mattered here. Some partners involved sub-agent networks, cross-border remittance flows or higher-risk customer segments.

Standard KYB was also silent on how each partner managed compliance itself. Did the partner run an in-house AML or compliance function? How did funds actually flow through its model and where did they originate? What financial crime risk did its own customer base carry? Above all, what compliance standard should the platform expect before granting a partner access to its rails?

Onboarding an entire partner portfolio on standard KYB alone left the platform unable to demonstrate, to its own regulator or banking partners, that it understood who it was actually doing business with.

The Solution

How Compliance7 Ran the Enhanced Due Diligence

Compliance7 conducted Enhanced Due Diligence across the fintech partner portfolio. Critically, it treated each partner as an individual risk assessment. A single portfolio-wide check would not have been enough.

Assessing the Partner’s Own Compliance Capability

Weaknesses in a partner’s controls can increase the platform’s own financial crime, regulatory and operational exposure. Compliance7 therefore assessed whether each partner maintained an appropriate AML or compliance function, taking into account the partner’s scale, business model and risk profile. The review also considered how funds moved through the partner’s model and relevant source-of-funds considerations. Finally, the assessment helped the platform establish the level of compliance capability and control it should expect before granting a partner access to its infrastructure.

Risk Rating and Recommendation

Compliance7 assigned each partner an assessment report with risk rating, supported by the underlying evidence. It then made a specific recommendation to the client’s authorised decision-makers. That recommendation took one of three forms:

  • Approve.
  • Approve subject to defined risk mitigation or monitoring measures.
  • Escalate for further information and enhanced review.

As a result, the platform’s leadership had a consistent, defensible basis for onboarding decisions across the portfolio. A series of individually inconsistent judgment calls would not have achieved that.

Outstanding Questions

Sometimes a partner’s structure or ownership required further clarification. In those cases, Compliance7 documented the specific outstanding questions and the evidence still required. Consequently, the platform could return to the partner with a precise request for information rather than a general one.

What the Enhanced Due Diligence Covered

For each entity, the review followed the same structure. That consistency is what allowed the platform to compare partners against one another.

Review ElementScope
Beneficial ownershipVerified beyond the first disclosed layer
Sanctions and PEP screeningDirectors and ultimate beneficial owners
Adverse mediaSearches against directors and beneficial owners
Business model riskAssessment of the partner’s business model and relevant risk indicators
Partner compliance capabilityAssessment of the AML/compliance function and its appropriateness for the partner’s scale and risk profile
Flow of fundsReview of how funds move through the partner’s business model and relevant source-of-funds considerations
Source of funds or wealthWhere relevant, particularly for higher-risk ownership structures

Each element was documented with the underlying evidence supporting that partner’s risk rating.

The Result

A Mixed Outcome, Consistently Reached

The review produced different outcomes across the portfolio, reflecting the underlying risk factors identified during the assessment. Most partners cleared the review without material concerns, which supported an approval recommendation. However, a smaller subset was flagged. Some had ownership structures that required further clarification before a decision. Others had risk factors that supported onboarding under defined ongoing monitoring conditions, rather than an outright decline.

The value of the exercise did not lie in producing a predetermined number of approvals or escalations. Instead, it lay in applying a consistent, evidence-based methodology that differentiated risk across the portfolio. Where risk factors required further clarification or enhanced monitoring, Compliance7 documented those issues. The platform then incorporated them into the onboarding decision.

Some businesses onboard third parties onto their own infrastructure. Platforms, aggregators and similar operators all fall into this group. For them, structured and documented EDD may be necessary as part of a risk-based approach to onboarding and managing a growing partner network. Furthermore, that need may not stop at initial onboarding. It can continue throughout the business relationship, where risk factors warrant ongoing review.

Compliance7 designs Enhanced Due Diligence programs calibrated to the platform’s risk appetite and the applicable regulatory framework. These include applicable UK regulatory and financial crime compliance requirements, FIU-IND/PMLA requirements in India, applicable UAE AML/CFT regulatory requirements and other FATF-aligned frameworks.

Frequently Asked Questions (FAQ)

What is Enhanced Due Diligence and how is it different from standard KYC/KYB?

Standard KYC/KYB confirms basic identity and ownership information. Enhanced Due Diligence goes further for higher-risk relationships. Specifically, it examines beneficial ownership beyond the first disclosed layer. It also covers sanctions and adverse media exposure, source of funds or wealth and business model risk factors.

When does a business need EDD on its own clients or partners rather than just standard KYB?

EDD is typically warranted where a client or partner presents elevated risk factors. These include complex or opaque ownership structures, cross-border activity, higher-risk business models or PEP/sanctions exposure. Furthermore, a regulator, a bank or the platform’s own risk appetite may require it.

Is it normal for an EDD review to flag some clients or partners and clear others?

Yes. Depending on the portfolio and underlying risk factors, an EDD review may result in different outcomes. These include approval, approval subject to enhanced monitoring or additional controls, or escalation for further information. Above all, the objective is to apply a consistent, risk-based methodology rather than treat every relationship identically.

Managing Risk Across a Partner or Client Portfolio?

Does your business onboard other regulated entities, merchants or high-risk clients at scale? If so, Compliance7 can design and run an Enhanced Due Diligence process calibrated to your risk profile and jurisdiction. That process covers beneficial ownership, sanctions and adverse media screening as well as documented risk-based decisioning.

Ajith Abraham is a Financial Crime Compliance professional with over 14 years of experience in Anti-Money Laundering (AML), Counter-Terrorist Financing (CFT), KYC, Customer Due Diligence (CDD), Enhanced Due Diligence (EDD), Transaction Monitoring, Sanctions Screening and Financial Crime Investigations. He is a Certified Anti-Money Laundering Specialist (CAMS) and Merkle Science Certified Crypto Investigator (CCI). Ajith has worked with Big Four consulting firms and advises Financial Institutions, fintechs, DNFBPs and Virtual Asset Service Providers (VASPs) on AML/CFT compliance, risk assessments, regulatory audits, financial crime risk management, crypto compliance, blockchain investigations and FATF-aligned compliance frameworks through Compliance7 Consulting LLP.