If you’ve ever opened a corporate bank account for a fintech, crypto platform, gambling business, or anything else that makes onboarding teams nervous, you already know the pain. The bank sends a due diligence pack. It looks harmless at first. Then you open it.
Forty questions. Maybe sixty. Attach this. Explain that. Upload group charts, source of funds evidence, AML documents, customer journey screenshots, processor agreements, director IDs, forecasts, licences, policies. Suddenly your “simple” bank application turns into a forensic exercise.
And here’s the bit founders get wrong. The pack is almost never just asking what it says on the page.
It’s asking whether your business makes sense, whether your story stays consistent across documents, and whether the compliance officer on the other side can defend approving you. That’s the real test.
What the bank is actually trying to figure out
Banks don’t build these packs to annoy you. Well, not only for that. They build them because high-risk and cross-border clients can blow up fast if the facts don’t line up.
So every question usually maps back to a few simple concerns:
- Who really owns and controls this business?
- What exactly does it do, and where does the money come from?
- Who are the customers, and how risky are they?
- Which countries are involved?
- Is the AML setup real, or just a template someone downloaded at 1am?
- Will this account behave in the way the client claims it will?
That’s it. Strip out the jargon and that’s the whole exercise.
If you answer every question with that in mind, your pack gets alot better very quickly.
The first trap: answering the literal question, not the real one
Let’s say the bank asks, “Please describe business activities.”
A weak answer says: “We provide software services to international clients.”
That tells them almost nothing. Are you a B2B SaaS tool? A payment orchestration layer? A white-label casino platform? A crypto OTC desk wrapped in a software company? Big difference.
A better answer sounds more like this: you explain the service, who pays you, where the users are, how funds move, whether you ever touch client money, and what counterparties sit around the transaction. Short. Specific. Human.
Same with “expected monthly turnover.” Don’t just throw in a number. Explain the logic behind it. New business, pilot stage, projected onboarding of three merchants, average ticket size, expected volumes from EEA customers, settlement cycles twice weekly. Now it feels believable.
Banks are trying to spot fiction. Generic answers read like fiction.
What usually sits inside a due diligence pack
The exact pack changes from bank to bank, and check current requirements because some institutions go much deeper than others. But most of them cluster around the same themes.
- Corporate structure – incorporation documents, register extracts, shareholder chain, UBO details, board information
- Business model – products, services, flow of funds, customer types, delivery channels, key markets
- Compliance controls – AML policy, KYC procedures, sanctions screening, monitoring setup, MLRO details
- Commercial reality – contracts, invoices, website, terms and conditions, pitch deck, financial projections
- Payment behaviour – expected incoming and outgoing payments, currencies, average transaction values, counterparties, PSPs
- Risk footprint – high-risk geographies, regulated activities, crypto exposure, gambling links, chargeback profile
If you’re still at pre-launch stage, that’s fine. But say that plainly. Pretending you’re further along than you are is a terrible idea because the rest of the evidence won’t match.
Corporate structure questions are really a trust test
This section kills plenty of applications. Not because the structure is bad, necessarily. Because the explanation is messy.
If you have a holding company in one country, an operating company in another, a payments entity somewhere else, and contractors spread across three more places, the bank wants to know why. “Tax efficiency” on its own won’t help you much. Honestly, it can make things worse.
You need a coherent story. For example: the holding company holds IP and investor rights, the Lithuanian operating company signs EU client contracts, and a separate support entity employs dev staff. That’s understandable. It may still get extra review, but at least it makes commercial sense.
If your structure is more layered, read Why your holding company’s jurisdiction matters more than you think. Founders usually focus on formation speed and ignore how the stack looks to banks later. Big mistake.
And if you’re still setting up the group, sort the structure before the banking run, not after. A clean setup beats a clever one. If you need help building it properly, Company Formation in Multiple Jurisdictions is the sort of support that saves a lot of back-and-forth later.
The business model section needs screenshots, not poetry
I’ve seen founders write two beautiful paragraphs about “bridging traditional finance and digital assets” and still get declined. Why? Because nobody could tell what the product actually did.
Show the thing.
Include website screenshots, onboarding flow, account dashboard, payment page, merchant journey, app store link, sample invoices, contract templates, even a simple flowchart. If you’re a crypto business, show where fiat enters, where crypto moves, who custodies what, and whether you ever control customer assets. If you’re gambling-adjacent, explain whether you’re operator, affiliate, software supplier, payment intermediary, or white-label partner. Those are not interchangeable.
For fintechs, one question comes up again and again: are you safeguarding, settling, collecting on behalf of merchants, or just providing software? The answer changes the bank’s risk analysis completely.
If your setup mixes an EMI account, settlement account, and operational account, this helps frame it properly: EMI vs traditional bank account: what a fintech actually needs.
AML questions are looking for proof you can control your customer base
This part isn’t about whether you own a policy PDF. Everybody has a PDF.
The bank wants to know if your controls match your actual risk. If you onboard non-face-to-face customers from multiple countries, do you use identity verification tools? Do you screen for sanctions and PEPs? Who reviews alerts? What’s enhanced due diligence in your business, in practice, not theory?
A few tips here:
- Don’t send a 90-page generic AML manual with no summary. Add a one-page overview explaining your controls
- Name the systems you use for screening, monitoring, or document verification if you have them
- If parts are manual today, say so and explain volume levels and reviewer responsibility
- Make sure your policy matches the customer journey shown on your site and forms
That last one matters more than people think. I’ve seen this kill a banking application. The website says instant onboarding in 2 minutes for global users, but the AML policy describes manual onboarding for low-volume EEA corporate clients only. So which is true?
If you don’t have an in-house compliance lead yet, fix that before you start spraying applications around. Outsourced AML Officer & Compliance as a Service can cover that gap without forcing an early-stage business into a full-time hire it doesn’t need.
Source of funds and source of wealth – answer like an adult
Founders get weirdly defensive here. Don’t.
If the bank asks where startup capital came from, just explain it cleanly. Founder savings from prior software exit. Angel investment under SAFE documents. Intercompany funding from the parent. Retained earnings from an existing services business. Fine. Normal.
What the bank hates is vagueness. “Private funds.” “Personal income.” “Business proceeds.” From what, exactly?
For beneficial owners, source of wealth questions can feel intrusive, but for higher-risk sectors they’re standard. Give a short factual explanation and back it with documents if requested. Keep it proportional. Keep it consistent. Don’t overshare random paperwork they didn’t ask for.
Expected activity is where people accidentally wave a red flag
Banks compare your forecast with your stage, your site, your licences, your geography, and your team. If a brand-new company with no licence, no live product, and no distribution expects seven-figure monthly volume from 20 countries on day one, someone will raise an eyebrow. Fair enough.
So build a simple assumptions sheet. Nothing fancy.
Show:
– number of expected customers or merchants
– average transaction size
– expected monthly transaction count
– top sending and receiving countries
– currencies used
– whether funds are operational, client, settlement, or mixed
This turns a made-up number into a reasoned projection. Much easier to underwrite.
Consistency beats perfection
You do not need a flawless business. You do need a believable one.
If you’re pre-revenue, say pre-revenue. If licensing is in progress, say in progress. If a policy is being updated, say updated version will be provided. Banks can work with incomplete businesses. They struggle with slippery answers.
And keep one person owning the full submission. Otherwise legal says one thing, founder says another, sales deck says a third, and the application starts to look stitched together from seperate realities.
Before you send the pack, do this quick stress test
Read every answer and ask:
- Would a stranger understand what we do in under 2 minutes?
- Does our site match our application?
- Do our forecasts make commercial sense?
- Is the ownership chain obvious without detective work?
- Have we explained why this bank account is needed and how it will be used?
If the answer to any of those is “sort of,” you’re not ready yet.
The real job is making approval easy
That’s the whole game, really. A due diligence pack is not a box-ticking exercise. It’s a memo the onboarding team is quietly writing in their head: does this client look understandable, controlled, and worth the risk?
Your job is to make “yes” easy.
Clear structure. Clear flows. Clear ownership. Evidence that matches the story. No dramatic claims. No fuzzy language. No mystery around who gets paid, by whom, and for what.
Do that, and the pack stops being a random pile of admin. It becomes what it should’ve been from the start – a convincing case that your business is bankable.