What is merchant underwriting, in plain terms?
Merchant underwriting is the process of deciding whether a business should be approved to accept card payments, and under what terms. It's the acquiring-side equivalent of loan underwriting: an evaluation of who the business is, whether it's legitimate, and how much risk it introduces to the sponsor bank, processor, and card networks if something goes wrong — a dispute wave, a fraud pattern, a business that turns out not to be what it claimed.
It's easy to think of underwriting as a single "approve or decline" moment, but it's really a sequence of distinct checks, several of which have nothing to do with each other and are often handled by different systems entirely.
What actually gets reviewed during underwriting?
A typical merchant application touches several distinct workstreams:
- KYC (know your customer) — verifying the identity of the individuals who own or control the business.
- KYB (know your business) — verifying the business itself exists, is registered as claimed, and matches the ownership structure on file.
- Financial review — assessing the business's financial standing, and in some cases its processing history if it's switching providers.
- Document collection — bank statements, government IDs, business licenses, and whatever else the program requires.
- Risk and fraud assessment — evaluating the business type, expected transaction volume, and industry-specific risk factors (a business selling physical goods with fast delivery looks different, risk-wise, than one selling high-ticket digital goods with delayed fulfillment).
- Card brand program checks — confirming the business and its principals don't appear on card network exclusion lists, and flagging industries subject to extra scrutiny.
Each of these can, in principle, move independently — identity verification might clear in minutes while a manual document review takes days — which is exactly why underwriting timelines vary so much even for seemingly similar businesses.
Why does underwriting take as long as it does?
The honest answer, at most ISOs, is that these workstreams live in different tools that don't share data. A KYC check might run through one vendor, KYB through another, document collection through a shared drive or email thread, and the actual decision made by a person manually assembling all of it into a judgment call. Every one of those handoffs adds time, and every additional data point that needs to be requested from the merchant adds a round trip.
None of this is necessarily bad underwriting — a careful reviewer working from fragmented tools can still make a correct decision. It's slow underwriting, and slowness has a direct cost: every hour an application sits in review is an hour a merchant might be evaluating a competitor, and every additional reviewer needed to keep up with volume is headcount growth tied directly to sales growth rather than decoupled from it.
What does a "review path" actually mean in an underwriting program?
Sponsor banks and FSPs typically define program-specific review paths — rules about which applications require additional scrutiny, additional documentation, or an escalation to a more senior reviewer. A merchant in a low-risk, well-understood category with a clean identity check might route through a lighter path; a merchant in a higher-risk category, or one that fails an initial check, routes through a heavier one.
This is a genuinely useful control — it means underwriting effort concentrates where the actual risk is, rather than treating every application identically. But it only works well if the underlying data (the KYC result, the KYB result, the document status) is actually available to route on, which again comes back to whether those workstreams share a data model or not.
Where technology actually changes the underwriting experience
The workstreams above don't go away with better technology — identity still needs verifying, documents still need reviewing, risk still needs assessing. What changes is whether an application arrives at a human underwriter already assembled (identity checked, documents collected, initial risk factors flagged) or arrives as a pile of separate, unconnected pieces the underwriter has to gather themselves.
That's the specific difference NGnair's merchant acquisition and underwriting infrastructure is built around: one onboarding environment where KYC, KYB, document collection, and program-specific review paths run together, so the work reaching a human underwriter is judgment, not assembly.
The short version
Merchant underwriting is a sequence of distinct checks — identity, business verification, financial review, documents, risk assessment, and card brand compliance — not a single decision. Most of the time it takes comes from these checks living in disconnected tools rather than from the checks themselves being slow. A well-designed review path concentrates effort where risk actually is, but only works as well as the data feeding it is actually connected.
Connecting those checks into one workflow is precisely what turns underwriting from a bottleneck into a faster, more consistent process — see how NGnair approaches it.