Merchant Compliance Requirements
What the merchant application collects, and the two compliance documents the portal takes.
Compliance data for a merchant is collected in two places: the application wizard (structured data, at submission) and the Compliance pages (document uploads, before go-live).
What the application collects
The New Merchant wizard (Partner Portal → Payments → Merchants) collects the underwriting data as structured fields — business details (legal name, contact email, MCC), principals and beneficial owners, funding/banking details, and the processing profile. There is no free-form document checklist: the wizard's required fields are the requirements, and it will not submit without them.
The two document uploads
| Where | Document | Needed when |
|---|---|---|
| Compliance → PCI SAQ | The completed, signed PCI SAQ | All partners, before go-live |
| Compliance → HIPAA BAA | The signed Business Associate Agreement | Healthcare merchants |
Both feed the merchant's go-live gate (PCI_SAQ,
HIPAA_BAA items).
Expiry and renewal
The platform does not send document-expiry reminders. A SAQ is an annual obligation — keep your own renewal calendar, and re-upload when you renew.
When Cresora asks for more
Review can pause at AWAITING_CLARIFICATION with a question shown on the merchant's
page (clarification_message); answer it there to resume. Enhanced due diligence for
high-risk categories is handled through your account manager, case by case.