Website Checklist Before You Apply for a MID: What Underwriters Read
A page-by-page website checklist for a merchant account application: domain and HTTPS, product pages, about and contact pages, footer policy links, a test-mode checkout, claims language, and what a mismatch triggers.
Underwriters read your website next to the application. Check every page before applying: a live domain on HTTPS, product pages with prices and delivery terms, an about page with the exact legal entity name, a contact page with the business address, policies linked in the footer, a checkout that completes in test mode, no claims the vertical cannot carry, no placeholders. Small mismatches usually pend the file; structural ones can decline it.
Before a merchant account application reaches a decision, the underwriter opens your website next to the application and reads it as evidence. The checklist is a page-by-page pass: a live domain on HTTPS, product pages with prices and delivery terms, an about page with the exact legal name of the US entity, a contact page with the business address and a company-domain email, policies linked from the footer, a checkout that completes in test mode, claims the vertical can carry, and no placeholder page. A gap usually pends the file; a site that describes a different business than the application is grounds for a decline.
| Page | What the underwriter reads | Must match |
|---|---|---|
| Domain and home page | HTTPS, valid certificate, what is sold and to whom | URL, descriptor, business description |
| Product pages | Prices, descriptions, delivery or access terms | Average and highest ticket projected |
| About page | The legal entity, its state, what it does | Articles and EIN letter |
| Contact page | Business address, support email, phone if shown | Contact details on the application |
| Footer | Links to terms, privacy, refund and shipping policies | Policies attached to the file |
| Checkout | Working cart, total before the final button, recurring terms | Billing model declared |
Domain, HTTPS and the home page
The underwriter opens the URL on the application and expects a site that loads on HTTPS with a certificate issued for that domain. A certificate warning, a parked page, a password wall or a coming-soon banner leaves nothing to review, and the file waits until the site is up. Domain, store name and descriptor do not have to be identical, but a cardholder billed under a name other than the one they bought from is far more likely to file a dispute. The support email sits on the store domain or the company domain, not on free webmail; the IBOCore package includes a professional email on the company domain. The home page then answers the first question of the file: what is sold and to whom. If that differs from the vertical on the application, the rest of the review is a search for the reason.
Product pages: price, description and delivery terms
Product pages are where the underwriter sizes the exposure of the account. Each product needs a visible price in the processing currency, a description of what the buyer receives, and a delivery or access term: a shipping window for physical goods, the access method for a course or software, the session format for coaching. The prices are compared with the average and highest ticket on the application; a projected average ticket several times higher than the most expensive product on the site is a contradiction the underwriter will ask about. Every product on the site must be in the business description; a second product line the description omits is read as undisclosed products.
- Price on every product, in the processing currency, with taxes and shipping shown before the final step.
- Delivery or access terms on the page: shipping window, access method, session length, membership period.
- Nothing outside the declared vertical, and nothing on the refused list; the industries page names what IBOCore does not onboard.
About and contact pages: the entity behind the store
The about page names the business that will hold the MID. The underwriter looks for the legal entity: its exact name as written on the articles and the EIN letter, and the state where it is formed. A store that never names its operating company, or names one that differs from the applicant, breaks the link between the site and the file. The contact page carries the business address on the application, a support email on the company domain and, if a phone number is shown, one that answers. In an IBOCore package the entity is a US LLC or C-Corp incorporated in the director's home state, EIN issued; copy the legal name and the state from its documents, character for character.
- Legal name, exactly: same spelling, suffix and punctuation as the articles and the EIN letter; a store brand appears next to it, not instead of it.
- Business address identical to the application, not a second address the file has never seen.
- One story: the about page, the business description and what the director says on the verification call describe the same business.
Get the entity the site has to match
Every IBOCore package ships a US LLC or C-Corp in the director's home state, EIN issued, with a professional email on the company domain. Browse the inventory page or ask on Telegram.
Footer links and a checkout that completes in test mode
The footer carries the policy links: terms of service, privacy policy, refund and cancellation policy, and a shipping policy for physical goods. Each link opens a page that names the entity, and the content matches what the application says about refunds and delivery. What each policy must contain is the subject of the policies checklist guide on this blog; this article stops at the footer: the links exist, they open, and the copyright line names the same entity as the about page. Then test the checkout yourself, in the gateway's test mode, so no live charge runs through another company's account.
- Add a product from its page, open the cart, and confirm the line item, quantity and price match the page.
- Reach the final screen: total with shipping and taxes, the processing currency, HTTPS, and a link to the refund policy next to the button.
- If the model is a subscription or a trial, the sentence disclosing the price, the frequency and how to cancel is on this screen, not only in the terms. The IBO package costs $999 setup, then $2,999 per month from 30 days after delivery, whatever the vertical or the billing model.
- Complete the test order, check the confirmation page and email for the store name, the entity name and the support contact, and keep screenshots; underwriters often ask for them.
Claims language and placeholder pages
Claims are read against the vertical. Acquirers typically refuse medical claims on supplements, skincare and wellness products; income promises and earnings screenshots on courses and coaching; guaranteed results of any kind; and wording that implies licensed activity the business does not hold, such as exchange or custody language on a crypto education site. Search the site for the absolute words: cure, treat, guaranteed, risk-free, a stated income per month. Then the underwriter looks for what should not be there: lorem ipsum, a template privacy policy naming another company, a sample product left in the catalogue, a 404 in the main menu. A placeholder reads as a site not yet operating, which cannot be underwritten as the business on the application.
- Health, wellness and nutra: no cure, treat, prevent or diagnose language, no disease name next to a product, no before-and-after results presented as typical.
- Info-products, coaching, financial and real estate education: no income figure presented as an expected outcome, no earnings screenshot used as a promise.
- Crypto-adjacent: education, signals and software only; nothing that offers to hold, exchange or move customer funds.
What a mismatch between the site and the application triggers
A mismatch is any point where the site and the application answer the same question differently. The file is pended with a request, or declined when policy does not allow the difference. Small mismatches pend: a price range that differs from the projections, a policy page without the entity name. Structural mismatches are grounds for a decline: products the description omits, a site that names another operating company, a subscription checkout on a one-time application, claims the vertical cannot carry. When the checkout runs through another company's account, the underwriter reads it as transaction laundering, and a corrected page rarely clears that. After approval the live site is typically compared with the snapshot taken at review; the KYB guide on this blog covers that monitoring.
| Mismatch | How it reads | Usual outcome |
|---|---|---|
| Site not live, certificate error, parked domain | Nothing to review | Pend until the site is up |
| Policy pages naming another company | Template copied, site not operating | Pend: rewrite the policies |
| Products the description omits | Undisclosed products | Decline, or pend with a new description |
| About page names another operating company | Site does not belong to the applicant | Decline until it does |
| Recurring checkout on a one-time application | Undisclosed billing model | Decline; reapply on the right model |
| Checkout through another company's account | Transaction laundering | Decline; the question returns on later files |
Do the review before the package arrives, not after
The website is the one part of the file only you can build, so run this checklist before you acquire the package. An IBOCore package ships the same day the payment confirms, from inventory that is permanently in stock: a US LLC or C-Corp incorporated in the director's home state, EIN issued; a nominee director who is an Independent Business Operator (IBO), real, KYC-verified, with a credit score of 650 or more and exclusive to one merchant; a business bank account with full operational access; a professional email on the company domain; 24/7 support in a private Telegram group. Monthly billing starts 30 days after delivery, and a package with no merchant account opened in those 30 days can be reclaimed, setup fee not refunded. With the site ready, you apply on delivery day, through your own ISO or directly; acquirer onboarding then typically takes 3 to 10 business days, on the acquirer's timeline. The document template pack ($499 one-time) carries refund policy and terms of service templates; it does not replace real products, real prices and a checkout that completes.
Apply on delivery day with the website already checked
Packages ship the same day payment confirms.
Questions merchants ask
Does the website have to be live before I submit the application?
For practical purposes, yes. The website review is one of the first checks; a parked domain, a password wall or a coming-soon page gives the underwriter nothing to compare with the application, so the file waits. Some ISOs accept a staging link for a pre-launch store, but the underwriter still expects real product pages, real policies and a checkout that completes in test mode. Building the site after acquiring the package spends the 30 days before billing starts.
Does the director's name have to appear on the website?
No. The site names the legal entity, its state, its business address and a support contact; it does not need to name an officer, and many stores do not. The director's name appears where the file needs it: on the state filing and the EIN, and as the authorized signer on the application. On beneficial ownership reporting, one line: a US-formed LLC or corporation is a domestic reporting company, and under FinCEN's interim final rule of March 2025 domestic companies and US persons are exempt from BOI reporting, while companies formed under foreign law that register in a US state remain subject to it; that is the status at the time of writing, so verify current FinCEN guidance with a professional. IBOCore does not give legal or tax advice.
Can the store use a brand name that differs from the legal entity name?
Yes, and many stores do. The brand is the trade name the cardholder sees; the legal entity is the applicant. The site carries both: the brand in the header, the legal name in the about page, the policies and the footer, with a line stating that the brand is operated by the entity. The descriptor then carries the brand, or both, so the statement line matches what the cardholder remembers buying. The billing descriptor guide on this blog covers how to build one.
Compliance touchpoints that survive audit
Clean setups disclose beneficial ownership, file BOI, use genuine IDs, and keep the IBO informed of website and descriptor changes. Processors re-scan for prohibited products, undisclosed aggregation, and transaction laundering. Violations land on MATCH and kill future MID applications.
- AML / CDD: customer due diligence on the merchant entity.
- PEP screening: politically exposed persons get enhanced review.
- OFAC / SDN: sanctions lists checked on owners and signers.
- Website compliance: refund policy, terms, pricing visible before checkout.
Compliance shortcuts that trigger MATCH
Fake guarantors, borrowed SSNs, cloaked websites, and third-party processing through your MID are the fastest paths to MATCH listings. Recovery requires legal work and years of delay. Disclose, document, and keep the IBO in the loop.
FAQ: quick answers
How fast can I get an IBO package on IBOCore?
Available inventory ships the same day after payment. You receive Articles, EIN letter, registered agent details, bank onboarding pack and signer contact through your merchant dashboard. Processor onboarding typically follows over the next one to two weeks.
Where can I look up payment-processing jargon?
Use the Resources glossary on IBOCore (/resources) for 580+ definitions: MID, chargeback ratio, MATCH, rolling reserve, MCC, RDR, KYB and high-risk vertical vocabulary.
Ready for instant delivery?
Browse live IBO inventory or ask about your vertical on Telegram.