What merchant onboarding is designed to establish, and what it establishes
Was die Händlerprüfung feststellen soll — und was sie feststellt
Before a business can accept card payments, it is checked. Documents are collected, ownership is traced, the trading model is described, a risk category is assigned. The process is presented as establishing who the merchant is and what they sell. It reliably establishes the first. Whether it establishes the second is a different question, and the answer explains a great deal about how prohibited businesses end up with working payment accounts.
What the checks actually verify
Onboarding — know your business, in the industry’s phrase — is built on documentary and database verification.
The provider confirms the legal entity exists by checking a company register. It identifies the beneficial owners above a threshold and screens them against sanctions and politically-exposed-person lists. It verifies the identity of directors. It checks the bank account into which settlement will be paid. It collects a description of the business model, a website, and expected volumes. It assigns a merchant category code.
Every one of those is a check against a record. The company register says a company exists. The identity documents say a person is who they claim. The bank account confirms a settlement destination. These are strong checks, and they establish identity and legal existence well.
What none of them establishes is what the business actually sells. That is asserted by the applicant, evidenced by a website that the applicant controls, and categorised by a code the applicant effectively selects. The most consequential field in the file is the one with the weakest verification behind it.
The category code problem
The merchant category code determines interchange, risk treatment, monitoring thresholds, and whether the business is permitted at all. It is a four-digit number.
It is assigned at onboarding from the applicant’s description, and once assigned it is rarely revisited. Nothing in the process periodically re-establishes that a business categorised as a software vendor three years ago is still selling software. A business that changes what it sells does not automatically change its code, and there is no routine mechanism that would notice.
The gap is systematically exploitable and is systematically exploited. An operation in a prohibited category obtains acceptance under a permitted description, presenting a website that matches the description, and then routes the actual business through the same acceptance. The technique is old, well documented, and requires no sophistication — the entire attack consists of describing yourself as something else at the one moment anybody is checking.
Why the checks are shaped this way
It would be easy to conclude that providers are negligent. That conclusion does not survive contact with the economics.
Documentary verification scales. It can be automated, performed in minutes, and priced at a few euros per application. Establishing what a business genuinely does requires human judgement — someone looking at the site, testing the checkout, reading the terms, forming a view. That costs orders of magnitude more, and it does not scale to the volume of applications a modern provider processes.
And the commercial pressure runs the other way. Onboarding friction loses applicants. Providers compete on how quickly a merchant can start accepting payments, and “approved in minutes” is a selling proposition. Every additional check is a conversion cost paid immediately against a risk cost that is probabilistic and deferred.
So the process optimises for what can be verified cheaply and at scale, and accepts assertion for what cannot. That is not negligence. It is the predictable equilibrium, and it would take either a regulatory floor or a liability shift to move it.
Where the responsibility actually sits
The chain matters here. A payment facilitator onboards sub-merchants under its own acceptance agreement with an acquirer, and the acquirer holds the licence and the ultimate liability. So the party doing the checking is often not the party bearing the loss.
A facilitator competing on onboarding speed has a direct commercial incentive to check less, and a portion of the consequence lands on the acquirer above it. The acquirer manages this through portfolio monitoring and contractual recourse rather than by reviewing individual applications, which means the control operates statistically rather than case by case.
That works adequately for aggregate risk and poorly for the specific case. An individual prohibited merchant inside a large, otherwise clean portfolio does not move the portfolio ratios enough to be noticed. It is detected, if at all, by a complaint, a journalist, an advocacy organisation or a card network’s own monitoring — which is to say, from outside the system that was supposed to catch it.
What would improve it
Three changes with plausible effect, and one popular suggestion that would not work.
Periodic re-verification of what is sold. Not a full re-onboarding — a lightweight, automated check that the website still matches the declared category, run at intervals. Most category drift would be visible to a system that simply looked again.
Testing the checkout, not the homepage. A site’s public pages are what the applicant wants seen. What the checkout actually sells, and what the confirmation email describes, is closer to the truth. This is checked far less often than the marketing pages.
Treating volume and pattern shifts as re-review triggers. A merchant whose average transaction value, geography or refund pattern changes materially has changed its business. That is observable in data the provider already holds, and it is a better signal than any document.
The suggestion that would not work on its own is more documentation at onboarding. Documents establish identity, and identity is not the weak point. Adding pages to an application form increases cost and friction without touching the field that is actually unverified.
The honest summary
Merchant onboarding is good at establishing who is behind a business and poor at establishing what that business does. Both facts are structural, and the second is not a secret within the industry.
The practical implication for anyone relying on the check — an acquirer, a network, a regulator, a journalist — is to be precise about what it proves. “The merchant passed onboarding” means the entity exists, the owners are identified and unlisted, and the settlement account is real. It does not mean anyone has established what is being sold. Those are different claims, and the process is routinely cited as though it made the second one.
Bevor ein Unternehmen Kartenzahlungen annehmen darf, wird es geprüft. Unterlagen werden erhoben, Eigentumsverhältnisse nachverfolgt, das Geschäftsmodell beschrieben, eine Risikokategorie vergeben. Der Vorgang wird so dargestellt, als stelle er fest, wer der Händler ist und was er verkauft. Das Erste stellt er zuverlässig fest. Ob er das Zweite feststellt, ist eine andere Frage — und die Antwort erklärt einiges darüber, wie verbotene Geschäfte zu funktionierenden Zahlungskonten kommen.
Was die Prüfungen tatsächlich belegen
Die Aufnahmeprüfung — im Branchenjargon „know your business” — beruht auf Urkunden- und Datenbankabgleich.
Der Anbieter bestätigt anhand eines Handelsregisters, dass die juristische Person existiert. Er ermittelt die wirtschaftlich Berechtigten oberhalb einer Schwelle und gleicht sie mit Sanktions- und PEP-Listen ab. Er prüft die Identität der Geschäftsführung. Er verifiziert das Bankkonto, auf das ausgezahlt wird. Er erhebt eine Beschreibung des Geschäftsmodells, eine Website und erwartete Volumina. Er vergibt einen Händlerkategorie-Code.
Jede dieser Prüfungen ist ein Abgleich gegen einen Datensatz. Das Register sagt, dass eine Gesellschaft existiert. Die Ausweisdokumente sagen, dass eine Person die ist, die sie zu sein behauptet. Das Bankkonto bestätigt ein Auszahlungsziel. Das sind starke Prüfungen, und sie belegen Identität und rechtliche Existenz gut.
Was keine davon belegt, ist, was das Unternehmen tatsächlich verkauft. Das wird vom Antragsteller behauptet, durch eine Website belegt, die der Antragsteller kontrolliert, und mit einem Code eingeordnet, den der Antragsteller faktisch selbst wählt. Das folgenreichste Feld der Akte hat die schwächste Verifikation hinter sich.
Das Problem des Kategorie-Codes
Der Händlerkategorie-Code bestimmt das Interbankenentgelt, die Risikobehandlung, die Überwachungsschwellen und ob das Geschäft überhaupt zulässig ist. Er ist eine vierstellige Zahl.
Er wird bei der Aufnahme aus der Beschreibung des Antragstellers vergeben und danach selten überprüft. Nichts im Verfahren stellt regelmäßig erneut fest, dass ein vor drei Jahren als Softwareanbieter eingestuftes Unternehmen noch Software verkauft. Wer ändert, was er verkauft, ändert nicht automatisch seinen Code — und es gibt keinen Routinemechanismus, der es bemerken würde.
Die Lücke ist systematisch ausnutzbar und wird systematisch ausgenutzt. Ein Betrieb in einer verbotenen Kategorie erhält die Akzeptanz unter einer erlaubten Beschreibung, zeigt eine dazu passende Website und leitet dann das eigentliche Geschäft über dieselbe Akzeptanz. Die Technik ist alt, gut dokumentiert und verlangt keinerlei Raffinesse — der gesamte Angriff besteht darin, sich in dem einen Moment, in dem jemand hinsieht, als etwas anderes zu beschreiben.
Warum die Prüfungen so aussehen
Es wäre leicht zu schließen, die Anbieter seien nachlässig. Dieser Schluss übersteht die Ökonomie nicht.
Urkundenprüfung skaliert. Sie lässt sich automatisieren, in Minuten durchführen und für wenige Euro je Antrag anbieten. Festzustellen, was ein Unternehmen wirklich tut, verlangt menschliches Urteil — jemand sieht sich die Seite an, testet die Kasse, liest die Bedingungen, bildet sich eine Meinung. Das kostet um Größenordnungen mehr und skaliert nicht auf die Antragsmengen eines modernen Anbieters.
Und der wirtschaftliche Druck zeigt in die andere Richtung. Reibung bei der Aufnahme kostet Antragsteller. Anbieter konkurrieren darüber, wie schnell ein Händler mit dem Annehmen beginnen kann, und „in Minuten freigeschaltet” ist ein Verkaufsargument. Jede zusätzliche Prüfung ist ein sofort anfallender Abschlusskostenposten gegen ein Risiko, das wahrscheinlichkeitsbehaftet und aufgeschoben ist.
Also optimiert das Verfahren auf das, was sich billig und in Menge prüfen lässt, und nimmt für den Rest eine Behauptung hin. Das ist keine Nachlässigkeit. Es ist das vorhersehbare Gleichgewicht, und es zu verschieben bräuchte entweder einen regulatorischen Boden oder eine Haftungsverschiebung.
Wo die Verantwortung tatsächlich liegt
Hier zählt die Kette. Ein Zahlungsabwickler nimmt Unterhändler unter seinem eigenen Akzeptanzvertrag mit einem Acquirer auf, und der Acquirer hält Lizenz und letztliche Haftung. Die prüfende Partei ist also oft nicht die tragende.
Ein Abwickler, der über Aufnahmegeschwindigkeit konkurriert, hat einen unmittelbaren wirtschaftlichen Anreiz, weniger zu prüfen — und ein Teil der Folgen landet beim Acquirer darüber. Der Acquirer steuert das über Portfolioüberwachung und vertraglichen Rückgriff statt über die Durchsicht einzelner Anträge, womit die Kontrolle statistisch statt fallweise arbeitet.
Für aggregiertes Risiko genügt das leidlich, für den Einzelfall schlecht. Ein einzelner verbotener Händler in einem großen, ansonsten sauberen Portfolio bewegt die Portfolioquoten nicht genug, um aufzufallen. Entdeckt wird er, wenn überhaupt, durch eine Beschwerde, eine Journalistin, eine Interessenorganisation oder die Überwachung eines Kartennetzwerks — also von außerhalb des Systems, das ihn hätte fangen sollen.
Was es verbessern würde
Drei Änderungen mit plausibler Wirkung und ein populärer Vorschlag, der nicht trüge.
Regelmäßige Nachprüfung dessen, was verkauft wird. Keine vollständige Neuaufnahme — eine leichte, automatisierte Prüfung in Intervallen, ob die Website noch zur angegebenen Kategorie passt. Das meiste Abdriften wäre für ein System sichtbar, das schlicht noch einmal hinsieht.
Die Kasse prüfen, nicht die Startseite. Die öffentlichen Seiten sind das, was der Antragsteller gesehen haben will. Was die Kasse tatsächlich verkauft und was die Bestätigungsmail beschreibt, ist näher an der Wahrheit. Das wird weit seltener geprüft als die Marketingseiten.
Volumen- und Musterwechsel als Anlass zur Nachprüfung. Ein Händler, dessen durchschnittlicher Zahlungsbetrag, dessen Regionen oder dessen Erstattungsmuster sich deutlich ändern, hat sein Geschäft geändert. Das ist in Daten sichtbar, die der Anbieter ohnehin hält, und es ist ein besseres Signal als jede Urkunde.
Der Vorschlag, der für sich allein nicht trägt, sind mehr Unterlagen bei der Aufnahme. Unterlagen belegen Identität, und Identität ist nicht die Schwachstelle. Weitere Seiten im Antragsformular erhöhen Kosten und Reibung, ohne das Feld zu berühren, das tatsächlich ungeprüft ist.
Die ehrliche Zusammenfassung
Die Händleraufnahme ist gut darin festzustellen, wer hinter einem Geschäft steht, und schlecht darin festzustellen, was dieses Geschäft tut. Beides ist strukturell, und das Zweite ist in der Branche kein Geheimnis.
Praktisch heißt das für jeden, der sich auf die Prüfung stützt — Acquirer, Netzwerk, Aufsicht, Presse — präzise zu sein, was sie beweist. „Der Händler hat die Aufnahmeprüfung bestanden” heißt: Die Gesellschaft existiert, die Eigentümer sind identifiziert und nicht gelistet, das Auszahlungskonto ist echt. Es heißt nicht, dass irgendjemand festgestellt hätte, was verkauft wird. Das sind verschiedene Aussagen, und das Verfahren wird regelmäßig zitiert, als leiste es die zweite.