How should a B2C platform design merchant onboarding review?
Merchant onboarding should be tiered by the harm a merchant can cause, not reduced to one fixed “machine plus human” flow. Wavesteam first determines what a merchant can publish, charge, and access and the loss from impersonation. That evidence determines the documents, authoritative sources, human decisions, and re-review. Licence OCR enters text; it does not prove authenticity, representative authority, or continuing compliance.
Existence, document authenticity, representative authority, permission to operate the category, and continuing suitability require different evidence. Check a unified social credit code against registration data; validate document source and expiry; establish the operator's authority through an enterprise administrator, authorization letter, or corporate channel; confirm sector scope; and respond to changes, anomalies, and complaints after approval.
When designing review rules, enforcement, and appeal evidence, also compare How can leaderboards and rewards resist manipulation and organized abuse? and When does a product need real-name verification or facial identity checks?; the linked guidance adds context that should be considered in the same decision.
| Risk tier | Capability | Default review | Ongoing signals |
|---|---|---|---|
| Low-risk profile | Publishes information only; no trade or sensitive data | Entity field and contact checks, sampling | Impersonation, information change, abnormal posts |
| Ordinary merchant | Orders, payment, fulfilment | Authoritative registration, representative authority, settlement, exception queue | Refunds, complaints, account changes, transaction anomalies |
| Regulated sector | Health, education, food, or similar | Base review plus human confirmation of licence scope and expiry | Expiry, business-scope change, regulator action |
| High-harm capability | Large funds, sensitive data, high-risk service | Strong identity link, dual review, pilot or limits | Related accounts, money and behavior, periodic review |
Clear, structured low-risk cases can pass automated conditions. Blurred images, name conflicts, unclear authority, complex licences, and high risk go to people. Sampling rates should change with observed error, miss, and loss. A model score does not prove safety, and litigation or association data is a lead rather than a permanent rejection without verification.
China's E-Commerce Law addresses platform verification and records for platform merchants; applicability depends on the actual model. Prefer authoritative registration such as the National Enterprise Credit Information Publicity System or a lawfully authorized interface over uploaded screenshots.
Collection of legal representative or operator identity, phone, face, or bank information also needs necessity, basis, notice, access, retention, and deletion under the Personal Information Protection Law. Not every merchant needs liveness or four-factor bank verification. Match intrusion to harm and provide a reasonable exception route for legitimate merchants who cannot use one method.
The review workspace should support correction rather than only approve or reject. States can include draft, submitted, automated check, human review, material required, approved, restricted, suspended, and terminated. Retain rule version, source, operator, reason, and time. Changes to legal entity, settlement account, or critical licence trigger review again; rejection identifies the missing or inconsistent item.
Measure pass, correction, and rejection by tier; machine decisions overturned by people; later confirmed fraud or expired qualifications among approved merchants; handling time; appeal reversal; and expiry reminders and actions. Accuracy names sampling and ground-truth source rather than treating a successful API response as truth.
Wavesteam builds configurable rules, authoritative lookup integration, review workspace, expiry and change review, audit, and appeal as one evidence chain. The client's compliance and operations owner decides allowed sectors, accepted risk, and final action. Wavesteam implements and tests confirmed policy without claiming administrative authority or legal judgment.