Purpose of This Template
You need a structured way to evaluate payment processors, fintechs, and financial intermediaries before they handle your organization's money. This template provides a practical framework for documenting due diligence on third-party payment services, especially those operating across borders or in higher-risk jurisdictions.
Recent investigations have shown how billions of dollars moved through major global banks via a Russian fintech using forged documents and front companies to evade sanctions. This scheme relied on document forgery rather than sophisticated technology. Your payment processor risk assessment should identify these red flags before you authorize any transactions.
This template is designed for compliance teams evaluating new payment vendors, finance teams reviewing existing relationships, and security awareness teams building training scenarios around financial crime risks.
Prerequisites
Before using this template, gather:
- The payment processor's corporate registration documents and ownership structure
- A list of all jurisdictions where they're licensed to operate
- Their customer onboarding procedures and know-your-customer protocols
- Sample transaction documentation they provide to clients
- Their policies on sanctions screening and transaction monitoring
- References from at least two current clients in your industry
You'll also need clarity on your organization's risk tolerance for cross-border payments, sanctions exposure, and the types of transactions you'll route through this processor.
The Template
THIRD-PARTY PAYMENT PROCESSOR DUE DILIGENCE CHECKLIST
Processor Name: _______________
Evaluation Date: _______________
Evaluator: _______________
Proposed Use Case: _______________
SECTION 1: Corporate Structure and Ownership
- Ultimate beneficial owners identified and verified
- No ownership by sanctioned individuals or entities
- Corporate registry documentation matches claimed structure
- No shell company characteristics (minimal staff, no physical presence, opaque ownership)
- Ownership hasn't changed hands in past 12 months without clear business rationale
Red flags identified: _______________
Mitigation steps required: _______________
SECTION 2: Licensing and Regulatory Standing
- Holds valid money transmitter or payment services license in all operating jurisdictions
- License numbers verified directly with issuing regulators
- No recent regulatory actions, fines, or consent orders
- Submits to regular audits by financial regulators
- Maintains required capital reserves for payment services
Licenses held: _______________
Regulators contacted: _______________
Outstanding concerns: _______________
SECTION 3: Sanctions Screening and Transaction Monitoring
- Uses commercially recognized sanctions screening software
- Screens against OFAC, EU, UN, and UK sanctions lists at minimum
- Screens both transaction parties and underlying beneficial owners
- Real-time screening occurs before payment authorization
- Has documented procedures for handling screening hits
- Can provide evidence of screening results for sample transactions
Screening tools used: _______________
False positive rate: _______________
Last screening system update: _______________
SECTION 4: Documentation and Record-Keeping
- Provides complete transaction documentation to clients
- Documentation includes payer, payee, and purpose details
- Maintains records for a minimum of five years
- Can produce an audit trail for any transaction on request
- Uses verifiable authentication on transaction documents (not easily forged stamps or signatures)
- Digital document security includes tamper-evident features
Sample documents reviewed: _______________
Authentication methods verified: _______________
Concerns about document integrity: _______________
SECTION 5: Front Company and Shell Entity Risk
- Requires proof of legitimate business activity from all transaction parties
- Flags transactions involving newly formed entities
- Verifies physical business addresses (not just registered agent addresses)
- Checks for patterns of circular payments or round-tripping
- Has a process for identifying beneficial owners behind corporate veils
How they verify legitimate business activity: _______________
Red flags in their client base: _______________
SECTION 6: Cross-Border Payment Controls
- Documents the full payment chain for cross-border transactions
- Identifies all correspondent banks involved
- Verifies that correspondent banks maintain adequate AML controls
- Flags jurisdictions on FATF high-risk lists
- Requires additional documentation for payments to/from high-risk jurisdictions
High-risk jurisdictions they serve: _______________
Correspondent banking relationships: _______________
Additional controls for high-risk payments: _______________
SECTION 7: Incident History and Transparency
- No known involvement in money laundering investigations
- Willing to discuss past compliance failures and remediation
- Provides annual Attestation and Certification from an independent auditor
- Has a designated compliance officer with direct board access
- Publishes transparency reports on suspicious activity reporting
Known incidents: _______________
Remediation actions taken: _______________
Compliance officer contact: _______________
OVERALL RISK RATING:
[ ] Low Risk, Approve for use
[ ] Medium Risk, Approve with enhanced monitoring
[ ] High Risk, Require additional controls before approval
[ ] Prohibitive Risk, Do not engage
Justification: _______________
Required monitoring frequency if approved: _______________
Next review date: _______________
Approver signature: _______________
Customizing the Template
Start with Section 3 (Sanctions Screening) and Section 5 (Front Company Risk) if you're evaluating processors handling international payments. These sections address tactics revealed in recent cases where schemes relied on forged documents and front companies.
If you're using the processor for domestic payments in low-risk jurisdictions, you can simplify Section 6. However, don't skip it entirely. Payment routing can change, and a processor that starts domestic may expand internationally.
Add industry-specific requirements to Section 1. If you're in healthcare, consider HIPAA requirements. If you're in defense contracting, include ITAR compliance checks. The template provides a financial crime baseline; you add sector-specific risks.
Adjust the monitoring frequency based on transaction volume and payment destinations. High-volume processors moving money to jurisdictions with weak AML enforcement need quarterly reviews, not annual ones.
For the documentation section, specify what "verifiable authentication" means in your context. Digital signatures with certificate authorities? Blockchain-based transaction records? Be clear about what you'll accept as proof that a document hasn't been forged.
Validation Steps
Before finalizing your assessment, take these verification actions:
Contact regulators directly. Don't rely solely on the processor's claim that they're licensed. Call or email the financial regulator in their primary operating jurisdiction to confirm the license status. This takes 15 minutes and catches fabricated credentials.
Test their screening. Ask the processor to run a test transaction against a known sanctioned entity. They should catch it immediately and document the hit. If they can't demonstrate their screening in real-time, that's a deal-breaker.
Request transaction samples. Ask for redacted examples of their transaction documentation. Look for signs of template reuse, generic descriptions, or authentication methods that could be easily forged (like a simple stamp or signature without digital verification).
Check correspondent banking relationships. If they use correspondent banks for cross-border payments, verify that those banks are well-regulated. A payment processor is only as strong as its weakest correspondent bank link.
Talk to their other clients. The references they provide will be positive. Ask those references specific questions: "Have you ever had a payment delayed for compliance review? How did they handle it?" A processor that never flags anything suspicious isn't doing adequate monitoring.
Review your contract termination rights. Make sure you can exit the relationship quickly if their risk profile changes. Some schemes involve operations that develop over time. You need the contractual ability to walk away when red flags emerge.
This template won't catch every sophisticated sanctions-evasion scheme, but it will catch those relying on forged stamps, shell companies, and inadequate due diligence. These schemes succeed because someone didn't ask the basic questions this template forces you to document.




