Skip to main content
Compliance is the gate between having API access and being able to transact. Before you can issue a card to a customer or move money on their behalf, Rain has to verify them. Use this page as your roadmap. Each card links to the guide for that step.

Compliance and risk at Rain

Enterprise compliance was built into Rain from the start. Our four-layer compliance matrix covers:
  • Partner vetting: every program is reviewed before it goes live.
  • Customer vetting: identity checks on every customer. Know Your Customer (KYC) and Know Your Business (KYB) cover cardholders and the businesses behind them, and account-owner checks cover payments customers.
  • Sanctions and PEP screening: every party checked against sanctions, PEP, and watchlist sources.
  • Ongoing monitoring: continuous transaction monitoring for suspicious activity and fraud.
Rain goes further than traditional payment infrastructure by operating onchain. Every transaction is recorded on an immutable ledger, giving our compliance team real-time visibility, so Rain reacts in seconds when something needs attention. Rain is PCI- and SOC 2-certified, and a Visa and Mastercard Principal Member trusted by 100+ programs worldwide.

Enterprise-grade compliance, built for what's next.

How verification works at Rain

Rain runs two separate verification pipelines. Clearing one does not clear the other. A customer approved to issue cards may still need to complete verification before they can move money. Each pipeline unlocks a different capability:
  • Cards (KYC and KYB): verifies every person with a KYC application, whether that’s a consumer cardholder or a corporate UBO. A corporate program also runs a separate KYB application on the company itself. Approval unlocks card issuance.
  • Payments: verifies the account owner behind money movement, through account-owner identification (CIP), transaction monitoring, and on-chain screening. Approval unlocks moving money, opening virtual accounts, and creating payment routes, independently of card approval.
Both pipelines run differently depending on your compliance model:
  • Standard Compliance: Rain collects and verifies customer identity directly (documents, selfie and liveness, and screening).
  • Hybrid Compliance: you verify customers in your own compliance program first. Rain still runs AML, sanctions, and PEP screening on every party.
Your compliance model is separate from your management model. Rain-Managed and Partner-Managed describe how collateral and funds are handled, not who verifies your customers. See Who verifies what for a side-by-side comparison of the two compliance models.
Onboarding a subdeveloper (subtenant)? They complete their own KYC/KYB before your program goes live. See Managing subtenants.
The next three sections walk the Cards pipeline in order, from working out what Rain needs through to handling a rejection. Payments compliance follows and stands on its own. Work through a pipeline in order, or jump to the step you are on.

Understand compliance

Start here. Work out which pipeline applies to you, who is responsible for collecting and verifying identity, and what Rain needs before an application can be approved.

Who verifies what

Whether Rain or your own compliance program collects identity, verifies it, and screens each party.

Verification requirements

What to collect for a person and for a business, how country rules apply, and how Rain screens every applicant.

Ultimate Beneficial Owner (UBO)

Who counts as a UBO in a corporate application, and how UBOs differ from representatives.

Collect and submit

Send Rain the identity data and documents for each customer. If you already verified them somewhere else, reuse that verification instead of collecting it again.

KYC/KYB documents

Which documents Rain accepts for a person and for a business, and the quality checks that run on upload.

Submit pre-collected documents

Upload identity documents you already hold, then submit the application.

Reuse an existing verification

Share a verification you already ran with Sumsub, Persona, or another vendor. Sumsub and Persona token sharing are Consumer only.

Encrypted KYC submission

Send KYC data as an encrypted payload using hybrid RSA-AES encryption.

Track a decision

An application moves through a series of states before it reaches an outcome. Poll for the status or listen for a webhook, and gate your own features on it. Not every application is approved: some rejections are fixable and some are permanent, so read the label before you ask a customer to try again.

Application states

Every state, why an application lands in it, what to do, and which transitions to expect.

Rejection reasons

Look up a label from a webhook payload, with its severity and the recommended action.

Rejection catalog

Every rejection reason by group, temporary and final, as it appears in the Dashboard.

Troubleshoot verification

Fix common problems in the hosted verification flow, and force an outcome in sandbox.

Identity and compliance webhooks

The user.updated and company.updated payloads that tell you a status changed.

Onboard a cardholder

Where compliance sits in the card issuing flow, from application to an issued card.

Payments compliance

Money movement is gated separately from cards. A customer cleared to spend on a card is not automatically cleared to move money.

Payments compliance

Account owner identification, transaction monitoring, and on-chain screening.

Restrictions & availability

Regional, country, and industry limits on payment routes.
Lookup pages for specific fields and codes: