A stalled product launch, among other reasons, also comes down to one bottleneck: “waiting for payment gateway approval”. 

Your product is ready, and the website is live, but the ad budget is sitting idle in a dashboard. The founder is refreshing an inbox, waiting for a “your account has been approved” email that should have arrived three days ago, and this means there is a delay in merchant onboarding. 

Merchant onboarding is the end-to-end process where a payment aggregator verifies a business’s identity, assesses its risk profile, and sets up the infrastructure for it to accept customer payments securely. Key steps include KYC verification, bank account linking, and compliance checks according to RBI guidelines.

Modern payment aggregators today work faster than ever to compress the timeline of merchant onboarding and have converted the process into a digital-first workflow that, for a well-documented business, can close out in hours. 

TL;DR

  • Merchant onboarding is the process through which a payment aggregator verifies a business, evaluates risk and activates it to accept live payments.
  • The usual checks cover the business entity, authorised signatory, beneficial owners, website or app, bank account and expected transaction profile.
  • Document requirements differ by entity type, industry, payment product and risk profile. A single universal checklist does not apply to every merchant.
  • Merchants can often test an integration in a sandbox while verification is in progress, but production activation follows successful compliance review.
  • Complete documents, consistent business details and clear customer-facing policies are the most reliable ways to avoid preventable delays.

What Is Merchant Onboarding?

Merchant onboarding is the end-to-end process of evaluating and activating a business for payment acceptance. It starts when the merchant creates an account and provides business information. It continues through identity verification, business due diligence, website or app review, bank-account verification, risk assessment and technical setup.

The purpose is not merely to collect documents. A payment aggregator needs enough evidence to answer five questions:

  1. Who operates the business?
  2. Is the business legally constituted and authorised to conduct the stated activity?
  3. What products or services will customers pay for?
  4. Does the expected payment activity match the business profile?
  5. Is the settlement account controlled by the correct merchant?

In India, the RBI’s 2025 Master Direction on Payment Aggregators consolidates the regulatory framework for payment aggregators, including authorisation, merchant due diligence, fund handling and governance requirements. The exact onboarding checks applied to a merchant may still vary according to risk and business circumstances.

Also read: KYC Procedures Involved in Merchant Onboarding

Who Is Involved in Merchant Onboarding?

The merchant

The merchant is the business applying to accept payments. It provides entity, ownership, bank-account, website and product information. It must keep these details accurate after activation, especially if ownership, business activity, domain or expected transaction volume changes.

The payment aggregator

The payment aggregator facilitates customer payments and settlement to onboarded merchants under the applicable regulatory framework. It performs merchant due diligence, assigns risk controls, monitors payment activity and manages the relationship needed to offer payment methods through one integration.

Cashfree Payments is an RBI-authorised payment aggregator. Businesses can review the current Cashfree account-activation process to understand the information and checks relevant to their entity type.

Banks and payment networks

Issuing banks approve or decline transactions for their customers. Acquiring banks support merchant acceptance and settlement arrangements. Card networks and payment systems define operating and security rules for their respective rails. These participants may apply transaction-level controls even after a merchant has completed onboarding.

The authorised signatory and beneficial owners

For non-individual entities, the person submitting the application must be authorised to act for the business. The payment aggregator may also need to identify and verify beneficial owners or controlling persons, depending on the entity and applicable KYC requirements.

Why Merchant Onboarding Matters

Faster access to live payments

A clear digital process reduces avoidable back-and-forth. Faster activation lets an eligible business launch checkout, validate demand and begin collecting revenue without leaving integration work until the end.

However, “go live in minutes” should be understood as an outcome for eligible, correctly documented use cases, not a guarantee for every applicant. Regulated or higher-risk industries, complex ownership structures and incomplete websites can require additional review.

Lower fraud and settlement risk

Onboarding helps prevent a payment account from being used by a shell business, impersonator, mule account or prohibited merchant. It also gives the aggregator a baseline against which future behaviour can be assessed.

The business description and expected payment pattern matter here. A merchant registered as a consulting firm but processing high-volume retail orders may trigger review because the activity no longer matches the profile approved at onboarding.

Better customer protection

Clear product descriptions, pricing, refund terms, delivery timelines and contact information help customers understand what they are purchasing. They also provide evidence when a refund request or dispute occurs.

Regulatory compliance

Payment aggregators must apply merchant due diligence and ongoing monitoring. Merchant onboarding therefore is not a one-time formality. Verification establishes the initial profile; post-activation monitoring checks whether the merchant continues to operate consistently with it.

Cashfree’s automated KYC solutions can support identity and business-verification journeys where those tools fit the merchant’s onboarding use case.

The Merchant Onboarding Process: Six Steps

1. Account creation and business profiling

The merchant creates an account and provides foundational information such as:

  • legal business name and entity type;
  • industry and product or service category;
  • registered and operating address;
  • website, app or sales channel;
  • expected transaction value and volume;
  • domestic or international payment requirements; and
  • authorised contact details.

This information helps determine the appropriate merchant category, document path and risk review. A vague description such as “online services” can slow the process. A precise description such as “monthly project-management software subscriptions for Indian SMEs” gives the reviewer a clearer picture of the intended payment flow.

2. KYC, KYB and ownership verification

KYC verifies the individuals connected to the application, while KYB verifies the business entity and its legal existence. Depending on the entity, checks may cover PAN, registration records, address, directors or partners, authorised signatory and beneficial ownership.

Digital verification can reduce manual entry, but automation does not remove review. A record mismatch, outdated registration, complex ownership chain or unavailable database response may require additional evidence.

The Cashfree onboarding FAQs list commonly accepted business proofs and explain why additional documents may be requested.

3. Business-model and website review

The payment aggregator reviews what the merchant sells, how customers place orders and whether the website or app supports the stated business model. The review may assess:

  • accurate product or service descriptions;
  • visible prices or a clear pricing mechanism;
  • delivery or fulfilment timelines;
  • refund and cancellation terms;
  • privacy policy and terms and conditions;
  • accessible customer-support information; and
  • consistency between the domain, brand and applying entity.

These pages should be written for customers, not merely added to satisfy a checklist. For example, a refund policy should explain eligibility, the request process and expected timeline. A contact page should provide a working channel through which a customer can reach the business.

Also read: Documents required for payment-gateway activation

4. Bank-account verification

The settlement account is checked to confirm that it is active and associated with the appropriate business or applicant. Verification methods can include bank records, account-proof documents or an API-based account check.

Penny Drop verification can return information such as account status and the beneficiary name held by the bank. The result still needs to be interpreted correctly. Minor name variations do not universally produce an automatic rejection; material mismatches may require supporting documents or manual review.

5. Risk assessment and approval

The aggregator combines the application information into a risk decision. Factors may include:

  • merchant category and restricted-business rules;
  • average order value and expected monthly volume;
  • delivery period and refund exposure;
  • domestic or cross-border activity;
  • ownership complexity;
  • website maturity and customer policies; and
  • consistency across documents and public information.

Approval may be unconditional or subject to product limits, monitoring rules, settlement terms or additional documentation. A rejected or paused application should be read as a risk decision for the submitted profile, not necessarily a judgment on the business itself.

6. Integration, testing and production activation

Technical teams can use the Cashfree Payment Gateway quickstart to create test orders, integrate checkout and validate payment responses. The Cashfree Dev Studio also lets developers explore integration flows and sample configurations.

Sandbox credentials are for testing. Production credentials should be generated and stored securely only after the account is eligible for live use. Cashfree’s API authentication guide explains the distinction between sandbox and production credentials.

Before launch, test successful, failed, pending and refunded payment states. Configure and verify payment webhooks so fulfilment is based on a trusted server-side status rather than a customer’s browser redirect.

Documents Required for Merchant Onboarding

The required documents depend on the constitution of the business, its industry and the products being activated. The table below is an indicative guide, not a universal or exhaustive checklist.

Business typeCommonly requested information or proof
Individual or sole proprietorshipProprietor PAN and identity details, business-existence proof where applicable, address details and bank-account proof
Partnership firmFirm PAN, partnership deed, partner or authorised-signatory details, registration or business proof where applicable and bank-account proof
LLPLLP incorporation or registration details, LLP agreement where requested, PAN, designated-partner or authorised-signatory details and bank-account proof
Private or public limited companyCertificate of incorporation, company PAN, constitutional or authorisation documents where requested, director or authorised-signatory details, ownership information and company bank-account proof
Trust, society or non-profit organisationRegistration document or trust deed, entity PAN, trustee or authorised-signatory information, applicable approval or exemption records and bank-account proof

GST registration is not a universal onboarding requirement for every business. Its applicability depends on the merchant’s activities and tax-registration obligations. Similarly, a board resolution, Udyam certificate, MOA/AOA or sector-specific licence may be required only for relevant entities or use cases.

The safest approach is to follow the entity-specific checklist shown inside the account and respond to any additional request based on the business profile.

Merchant Onboarding Under RBI’s Payment Aggregator Framework

The current RBI framework treats merchant onboarding as part of a wider control system. Three elements are particularly relevant to merchants.

Customer due diligence

Payment aggregators must perform due diligence appropriate to the merchant and follow applicable KYC requirements. This can include retrieving or updating records, verifying the business and its controlling individuals, and understanding the purpose of the relationship.

Risk-based monitoring

Approval does not end the review. Payment activity may be monitored against the merchant’s declared business profile, transaction limits and expected behaviour. A significant change in products, volumes, ownership or geography should be disclosed rather than allowed to appear as an unexplained anomaly.

Cashfree’s RiskShield helps eligible merchants apply payment-risk controls after activation, complementing the due diligence completed during onboarding.

Safeguarding and settlement

Payment aggregators that handle customer funds must follow the prescribed escrow and settlement framework. This separates merchant settlement money from the aggregator’s ordinary operating funds and defines how permitted credits and debits are managed.

These obligations sit with the regulated payment aggregator, but merchants still remain responsible for accurate application information, lawful sales, customer fulfilment, refunds and compliance relevant to their own business.

Domestic and Cross-Border Onboarding Are Not Identical

A merchant collecting payments only from customers in India follows a different risk and documentation path from an exporter or platform receiving international payments. Cross-border onboarding may require information about:

  • goods or services being exported;
  • countries served and supported currencies;
  • purpose-code classification;
  • fulfilment evidence and invoices;
  • foreign-exchange settlement; and
  • FEMA and sector-specific restrictions.

Cashfree’s international payment gateway explains the collection and settlement capabilities available to eligible Indian businesses. PA-CB authorisation provides the regulated payment-aggregation framework, but it does not transfer every FEMA, tax or export-compliance obligation away from the merchant.

How to Speed Up Merchant Onboarding

Use the exact legal name consistently

Check the legal name and entity type across PAN, registration records, bank proof, invoices and the application. Common abbreviations or trading names should be explained where they differ from the legal entity.

Prepare readable, current documents

Upload complete documents with all edges visible. Avoid glare, cropped fields, expired records and password-protected files unless the onboarding system explicitly supports them.

Describe the business precisely

Explain what is sold, who pays, typical order value, delivery timeline, refund conditions and expected monthly volume. Accurate information helps the risk team select the correct merchant category and controls.

Complete the customer-facing website

Publish product details, prices, fulfilment terms, refund or cancellation policy, privacy policy, terms and customer-support information before requesting review. Remove placeholder pages and test every contact channel.

Verify the settlement account early

Confirm the account number, IFSC and beneficiary name before submission. If the trading name differs from the bank-account name, keep documents ready to establish the relationship.

Start sandbox work in parallel

Do not wait for production activation to design the payment flow. Test order creation, checkout, webhooks, idempotency, refunds and reconciliation in the test environment so the technical work does not become the next bottleneck.

Also read: How to choose a payment gateway for your business

Common Reasons Merchant Applications Are Delayed

IssueWhy it creates frictionPractical fix
Name mismatchThe applicant, legal entity and settlement beneficiary cannot be connected confidentlyCorrect the record or provide supporting proof
Incomplete websiteReviewers cannot verify the offering, fulfilment or customer termsPublish complete product and policy pages
Vague business descriptionThe correct merchant category and risk controls are unclearState the product, customer, channel and payment flow precisely
Missing ownership informationControlling persons cannot be identifiedProvide the requested ownership structure and identity records
Unsupported business categoryThe activity may fall outside the provider’s permitted risk appetite or network rulesConfirm eligibility before investing in integration
Poor-quality documentsAutomated extraction or manual verification cannot read the evidenceUpload clear, complete and current files
Cross-border details missingPurpose, geography and settlement requirements remain unclearSupply export, invoice and transaction-flow information

How Cashfree Helps Businesses Go Live

Cashfree combines digital account activation, payment integration and ongoing payment operations within one platform. Eligible merchants can:

  • follow an entity-specific activation flow;
  • test checkout in a sandbox before production launch;
  • accept supported domestic payment methods through Cashfree’s payment gateway;
  • review the applicable payment gateway pricing before launch; and
  • manage payments, refunds, settlements and disputes from the dashboard after activation.

Activation time depends on business eligibility, the accuracy of submitted information and whether additional review is needed. Merchants should plan onboarding before the launch date instead of treating approval as a final-day task.

Conclusion

Merchant onboarding creates the verified business profile on which payment acceptance, monitoring and settlement depend. The fastest route is not to provide the least information. It is to provide complete, consistent and specific information that can be verified without unnecessary follow-up.

Prepare entity documents, settlement details and customer-facing policies early. Start sandbox integration in parallel, test the full payment lifecycle and keep the provider informed when the business model changes. That approach reduces preventable delays while preserving the checks required for a reliable payment ecosystem.

Ready to prepare your business for live payments?

Explore Cashfree’s payment gateway, complete your business verification and test the checkout flow before moving to production.

Explore Cashfree Payment Gateway

FAQs

What is merchant onboarding in payments?

Merchant onboarding is the process of verifying a business, assessing its risk and configuring it to accept and settle customer payments. It includes entity verification, KYC or KYB, website review, bank-account validation and technical activation.

How long does payment-gateway onboarding take?

There is no universal timeline. An eligible business with complete, verifiable information may be activated quickly, while regulated industries, complex ownership, mismatches or missing website information can extend the review.

Can I integrate a payment gateway before KYC approval?

Many providers allow sandbox testing before production activation. This lets developers build and test the integration, but live payment processing remains subject to successful account verification and approval.

Is GST registration mandatory for payment-gateway onboarding?

Not in every case. The requirement depends on the business’s tax obligations, entity type, products and provider checklist. Merchants should not claim an exemption without confirming that it applies to their business.

Why does a payment aggregator review my website?

The website or app helps verify the actual offering, pricing, customer-support channels, delivery terms and refund policy. It also allows the provider to check whether the public business activity matches the onboarding application.

What happens if the bank-account name does not match the business name?

A material mismatch can pause automated verification and lead to a request for corrected bank details or supporting evidence. The outcome depends on the entity structure and whether the relationship between the applicant and account holder can be established.

Can a sole proprietor apply for a payment gateway?

Yes, eligible sole proprietors can apply. They typically need proprietor identity details, proof that the business exists or operates, bank-account information and a clear website or sales channel. Requirements vary by industry and payment product.

Is merchant KYC required only once?

No. Initial KYC establishes the merchant profile, but the payment aggregator may request updated information and monitor transactions over time. Ownership, business-model, address, domain or settlement-account changes should be reported promptly.

Get 0% MDR*

Discover more from Cashfree Blog

Subscribe now to keep reading and get access to the full archive.

Continue reading