Vendor Onboarding Manual

Last Updated: Aug 12, 2026
Version: 1.0
Document Type: Internal Operations and Compliance Manual

1. Purpose

This Vendor Onboarding Manual establishes the internal procedures, documentation requirements, review standards, approval process, and ongoing compliance controls for onboarding vendors to the All Things Universal LLC marketplace platform (“ATU,” “Company,” “we,” “our,” or “us”). This Vendor Onboarding Manual serves as the definitive operational and legal playbook for third-party sellers joining the ATU’s e-commerce platform. Its primary purpose is to standardize the Vendor operations, mitigate platform risk and safeguard the customer experience as the marketplace scales.

The purpose of this Manual is to help ATU:

  • Verify vendor legitimacy.
  • Confirm vendor identity and business authority.
  • Protect customers.
  • Reduce fraud and fake vendor activity.
  • Prevent prohibited or restricted activity.
  • Support sanctions, AML, anti-bribery, and restricted-country compliance.
  • Confirm relevant business, tax, licensing, and insurance information.
  • Maintain marketplace integrity.
  • Apply vendor approval standards consistently.
  • Support international marketplace operations.
  • Document approval, rejection, suspension, and review decisions.

This Manual is an internal operational document and should be used together with ATU’s Terms of Use, Vendor Terms of Service, Vendor Marketplace Agreement, Privacy Policy, Cookie Policy, Refund and Subscription Policy, DMCA and Intellectual Property Policy, and Prohibited and Restricted Categories Policy.

2. Applicability

This Manual applies to all vendor applicants and approved vendors, including:

  • Retail vendors.
  • Product sellers.
  • Service providers.
  • Manufacturers.
  • Distributors.
  • Wholesalers.
  • Professional service providers.
  • Independent businesses.
  • International sellers.
  • Local sellers.
  • Advertisers or promoted listing participants.
  • Any business or individual seeking vendor access to the ATU marketplace.

This Manual applies whether the vendor sells products, provides services, advertises a business, operates a vendor storefront, purchases a subscription plan, or uses ATU as a business directory listing platform.

3. Core Onboarding Principles

ATU’s vendor onboarding process should be based on the following principles:

  • Vendors must be real, identifiable, and legally accountable.
  • Vendors must provide accurate and current information.
  • Vendors must be legally authorized to operate.
  • Vendors must be responsible for their own products, services, taxes, licenses, customer obligations, and legal compliance.
  • Higher-risk vendors may require enhanced review.
  • Vendor approval is not permanent.
  • Vendor approval does not mean ATU guarantees the vendor’s products, services, licensing, quality, or customer outcomes.
  • Vendor decisions should be documented.
  • Vendor review standards should be applied consistently and without discrimination.
  • ATU may reject, suspend, restrict, or terminate vendors where legal, compliance, payment, customer safety, marketplace trust, or reputational risks exist.

4. Internal Roles and Responsibilities

ATU may assign onboarding responsibilities to internal team members, contractors, service providers, or compliance reviewers.

Vendor Onboarding Team

Responsible for:

  • Reviewing vendor applications.
  • Checking submitted documents.
  • Requesting missing information.
  • Communicating with vendor applicants.
  • Maintaining onboarding records.
  • Preparing files for approval or escalation.

Compliance Reviewer

Responsible for:

  • Reviewing higher-risk applications.
  • Checking sanctions, restricted countries, prohibited industries, and suspicious activity indicators.
  • Reviewing professional licensing requirements.
  • Reviewing rejected or escalated applications.
  • Documenting compliance decisions.

Platform Administrator

Responsible for:

  • Activating approved vendor accounts.
  • Restricting or suspending accounts when needed.
  • Confirming vendor dashboard setup.
  • Confirming category permissions.
  • Maintaining vendor access controls.

Management or Compliance Review Committee

Responsible for:

  • Approving high-risk vendors.
  • Reviewing escalated applications.
  • Reviewing appeals.
  • Approving exceptions.
  • Updating onboarding standards as the marketplace grows.

ATU may operate with a smaller team during launch, but approval decisions should still be documented.

5. Vendor Onboarding Process Overview

The onboarding process consists of the following phases:

  • Phase 1: Pre-Application Screening
  • Phase 2: Application Submission
  • Phase 3: Identity and Authorized Representative Verification
  • Phase 4: Beneficial Ownership Verification
  • Phase 5: Business Verification
  • Phase 6: Tax Verification
  • Phase 7: Licensing, Permit, and Insurance Review
  • Phase 8: Product, Service, and Category Review
  • Phase 9: Sanctions, AML, Fraud, and Compliance Screening
  • Phase 10: Payment and Billing Verification
  • Phase 11: Risk Assessment
  • Phase 12: Approval, Conditional Approval, Rejection, or Escalation
  • Phase 13: Final Activation
  • Phase 14: Ongoing Monitoring and Re-Verification

6. Phase 1: Pre-Application Screening

Before a vendor application is fully reviewed, ATU may conduct basic screening to determine whether the vendor appears suitable for onboarding.

Pre-application screening may include:

  • Checking whether the vendor’s country is permitted.
  • Checking whether the vendor’s industry is prohibited or restricted.
  • Checking whether the vendor offers regulated products or services.
  • Checking whether the vendor appears to require professional licensing.
  • Checking whether the vendor’s business model conflicts with ATU policies.
  • Checking whether the vendor appears to create legal, safety, fraud, reputational, or platform risk.

If the vendor clearly falls into a prohibited category, ATU may reject the application without proceeding to full onboarding.

7. Phase 2: Application Submission

Vendor must complete the ATU vendor application accurately and completely.

Required application information may include:

Basic Vendor Information

  • Legal name.
  • Business name.
  • Trading name or DBA, if applicable.
  • Business address.
  • Country of operation.
  • Country of registration.
  • Telephone number.
  • Email address.
  • Website, if applicable.
  • Social media pages, if applicable.
  • Primary contact person.
  • Authorized representative.

Business Details

  • Type of business.
  • Industry classification.
  • Product categories.
  • Service categories.
  • Years in operation.
  • Countries served.
  • Customer type.
  • Business registration status.
  • Number of locations, if applicable.
  • Description of products or services.
  • Expected use of the ATU marketplace.
  • Whether the vendor sells products, services, or both.

Platform Plan Details

  • Subscription plan selected.
  • Advertising or promotional package selected, if applicable.
  • Requested product or service categories.
  • Requested language or country targeting, if applicable.

Applications containing incomplete, inaccurate, inconsistent, or unclear information may be rejected, delayed, or returned for correction.

8. Phase 3: Identity and Authorized Representative Verification

Each vendor owner, director, officer, beneficial owner, or authorized representative may be required to provide identity information.

Acceptable identity documents may include:

  • Passport.
  • National identification card.
  • Driver’s license.
  • Other government-issued photo identification approved by ATU.

Identity documents should:

  • Be valid and unexpired.
  • Clearly display the person’s name.
  • Clearly display the person’s photo.
  • Clearly display the issuing authority.
  • Clearly display the expiration date, where applicable.
  • Match the information provided in the vendor application.

ATU may request proof that the person submitting the application is authorized to act on behalf of the vendor.

Authorization documents may include:

  • Corporate resolution.
  • Authorization letter.
  • Partnership authorization.
  • Director or officer confirmation.
  • Business registration documents showing authority.
  • Other proof acceptable to ATU.

9. Phase 4: Beneficial Ownership Verification

For corporate entities, companies, partnerships, and other legal structures, ATU may require beneficial ownership information.

Vendor may be required to disclose:

  • Owners with 25% or greater ownership interest, or lower thresholds where required by law or ATU policy.
  • Directors.
  • Officers.
  • Managers.
  • Authorized signatories.
  • Controlling persons.
  • Ultimate beneficial owners.
  • Parent companies or related entities.

ATU may request documents to verify ownership structures, including:

  • Shareholder register.
  • Ownership chart.
  • Articles of incorporation.
  • Operating agreement.
  • Partnership agreement.
  • Corporate registry extract.
  • Beneficial ownership declaration.
  • Government registry documents.
  • Other supporting records.

ATU may apply enhanced review where ownership is unclear, layered, offshore, nominee-based, or inconsistent with submitted documents.

10. Phase 5: Business Verification

Vendor must provide applicable business documentation based on its legal structure and jurisdiction.

Corporations

May be required to provide:

  • Certificate of incorporation.
  • Articles of incorporation.
  • Certificate of good standing, if available.
  • Business license.
  • Tax registration.
  • Proof of registered address.

Limited Liability Companies

May be required to provide:

  • Articles of organization.
  • Certificate of formation.
  • Operating agreement, if requested.
  • Certificate of good standing, if available.
  • Business license.
  • Tax registration.
  • Proof of registered address.

Partnerships

May be required to provide:

  • Partnership registration.
  • Partnership agreement, if requested.
  • Tax registration.
  • Business license.
  • Proof of business address.

Sole Proprietorships

May be required to provide:

  • Business registration certificate.
  • Trade name registration, if applicable.
  • Tax registration.
  • Proof of business address.
  • Owner identification.

Informal or Unregistered Businesses

ATU may choose whether to allow informal or unregistered businesses depending on launch market, business model, risk level, and legal advice.

Where unregistered businesses are permitted, ATU may require:

  • Owner identity verification.
  • Proof of business activity.
  • Proof of address.
  • Tax registration where applicable.
  • Category restrictions.
  • Lower-risk listing permissions.
  • Additional monitoring.

11. Phase 6: Tax Verification

Vendor may be required to provide tax documentation, depending on jurisdiction and business type.

United States Vendors

May be required to provide:

  • EIN confirmation letter.
  • IRS Form W-9.
  • Sales tax registration, where applicable.
  • State business registration, where applicable.

Non-U.S. Vendors

May be required to provide:

  • IRS Form W-8, where applicable.
  • VAT registration.
  • GST registration.
  • Business tax registration.
  • Local tax identification number.
  • Digital services tax registration, where applicable.
  • Other tax documentation requested by ATU.

Vendor remains solely responsible for determining, collecting, reporting, filing, and paying its own income taxes, sales taxes, VAT, GST, customs duties, import/export taxes, withholding taxes, and other applicable taxes.

ATU does not provide tax advice.

12. Phase 7: Licensing, Permit, and Insurance Review

The licensing review process ensures that offering regulated goods, professional services, licensed products, or restricted categories through ATU’s e-commerce marketplace possess all required licenses, permits, certifications, registrations and regulatory approvals necessary to legally conduct their business activities.

ATU conducts licensing reviews as part of its vendor’s onboarding, compliance risk assessment and ongoing monitoring obligations to protect customers, maintain marketplace integrity and comply with laws and regulations.

Vendors offering regulated products or services may be required to provide proof of licensing, permits, registrations, certifications, or insurance.

Regulated categories may include:

  • Legal services.
  • Medical services.
  • Financial services.
  • Insurance services.
  • Real estate services.
  • Engineering services.
  • Construction and trade services.
  • Health and wellness services.
  • Beauty and personal care services.
  • Transportation services.
  • Childcare or education-related services.
  • Food-related services.
  • Import/export businesses.
  • Any other industry requiring authorization.

ATU may request:

  • Professional license.
  • Business license.
  • Permit.
  • Certification.
  • Insurance certificate.
  • Proof of professional registration.
  • Proof of regulatory approval.
  • Expiration dates and renewal confirmations.

Licensing Verification Process

ATU may perform licensing verification through one or more of the following methods:

(a) Regulatory Database Verification

ATU may verify licenses through publicly available government or regulatory databases

(b) Direct Confirmation

ATU may contact licensing authorities, professional bodies or certification organizations to confirm

  • Validity
  • Ownership
  • Status
  • Scope of authorization
  • Expiration date
  • Disciplinary history

(c) Document Review

ATU may review submitted documents for

  • Authenticity
  • Completeness
  • Consistency with Vendor information
  • Permitted business activities
  • Jurisdictional validity

(d) Third-Party Verification

ATU may use independent compliance providers, verification services or industry specialists to validate licensing information.

Cross-Jurisdiction Review

Where Vendors conduct business in multiple countries or states, ATU’s compliance team shall verify that the Vendor possesses all licenses required in each applicable jurisdiction.

Licences issued in one jurisdiction shall not be presumed valid in another unless expressly recognized by law.

Vendor must immediately report any license suspension, revocation, disciplinary action, expired permit, insurance lapse, or regulatory restriction.

ATU may suspend or reject vendors that cannot prove required authorization.

Foreign Vendors

Foreign Vendors shall provide:

  • Equivalent foreign licences
  • Translations where required
  • Legalization or apostille where appropriate
  • Import/export authorizations
  • Local regulatory approvals
  • Evidence that products may legally be sold in destination countries.

13. Phase 8: Product, Service, and Category Review

ATU should review the vendor’s proposed products and services before approval.

The review should consider:

  • Whether the products or services are lawful.
  • Whether they fall into prohibited or restricted categories.
  • Whether they require licenses or permits.
  • Whether they involve children, health, finance, legal, safety, or regulated claims.
  • Whether they create product safety concerns.
  • Whether they involve intellectual property risks.
  • Whether they involve import/export restrictions.
  • Whether they create reputational risk for ATU.
  • Whether they align with ATU’s marketplace standards.

ATU may approve, restrict, or reject specific product or service categories even if the vendor itself is approved.

14. Prohibited Businesses and Activities

The following businesses, products, services, or activities are prohibited unless ATU expressly approves a restricted exception in writing and legal counsel confirms that the activity is permitted:

  • Illegal drugs, controlled substances, or drug paraphernalia.
  • Counterfeit goods or unauthorized replicas.
  • Stolen property or unlawfully obtained goods.
  • Human trafficking, exploitation, escort services, or illegal adult services.
  • Child exploitation materials or harmful, sexual, or exploitative content involving minors.
  • Illegal gambling, betting, lotteries, or games of chance.
  • Pyramid schemes, Ponzi schemes, fraudulent investment programs, or deceptive business opportunities.
  • Terrorist organizations, terrorist financing, or extremist materials.
  • Sanctioned products, sanctioned services, or dealings with restricted parties or countries.
  • Weapons, firearms, ammunition, explosives, or regulated self-defense items.
  • Prescription drugs, unauthorized medical products, or regulated medical devices without authorization.
  • Hazardous chemicals, toxic substances, recalled goods, or unsafe products.
  • Fake documents, false IDs, forged certificates, or credential manipulation.
  • Financial, investment, lending, crypto, insurance, or money-service activities without required authorization.
  • Any business activity prohibited by ATU policy or applicable law.

Applications involving clearly prohibited activities should be rejected immediately and documented.

15. High-Risk Industries

Enhanced due diligence may apply to vendors in higher-risk industries.

High-risk industries may include:

  • Financial services.
  • Cryptocurrency or digital asset businesses.
  • Money services or payment businesses.
  • Precious metals or high-value goods dealers.
  • Healthcare providers.
  • Medical products or wellness products.
  • Import/export businesses.
  • Telecommunications providers.
  • Travel or transport businesses.
  • Professional services.
  • Construction and trade services.
  • Beauty, wellness, or health-related services.
  • Businesses involving age-restricted goods.
  • Businesses involving high chargeback or fraud risk.
  • Businesses operating in higher-risk jurisdictions.

Enhanced due diligence may include additional document requests, management approval, category restrictions, insurance requirements, periodic re-verification, or rejection.

16. Phase 9: Sanctions, AML, Fraud, and Compliance Screening

All vendors should undergo appropriate compliance screening before approval.

Screening may include:

Sanctions Screening

Review against applicable sanctions and restricted-party lists, including:

  • OFAC lists.
  • United Nations sanctions lists.
  • European Union sanctions lists, where applicable.
  • United Kingdom sanctions lists, where applicable.
  • Other government watchlists or restricted-party lists where relevant.

Restricted Country Review

ATU should confirm whether the vendor, beneficial owners, customers, products, services, or transactions involve prohibited or restricted countries, regions, or territories.

AML Regulations Purpose

ATU is committed to maintaining a marketplace that complies with all applicable Anti-Money Laundering (AML), Counter-Terrorist Financing (CFT), sanctions, anti-corruption and financial crime laws and regulations. Every vendor, merchant, supplier and marketplace participant is required to comply with these requirements as a condition of using ATU’s platform.

Failure to comply with this policy may result in suspension, termination, reporting to competent authorities and other legal remedies.

Vendor Certification

Each Vendor represents and warrants that:

  • It is legally organized and authorized to conduct business in its jurisdiction of incorporation;
  • It complies with all applicable AML, CFT, sanctions, anti-bribery, anti-corruption, fraud prevention and financial crime laws;
  • Neither the Vendor, its owners, directors, officers, employees, nor any beneficial owner is subject to sanctions, asset freezes or trade restrictions imposed by any applicable governmental authority.
  • No proceeds generated through ATU’s marketplace will originate from unlawful activities.
  • Products and services offered through the marketplace are lawfully acquired and may legally be sold in each applicable jurisdiction.

Fraud Screening

Fraud screening may include review for:

  • Identity inconsistencies.
  • Suspicious documentation.
  • Mismatched business and bank information.
  • False addresses.
  • Duplicate accounts.
  • Related suspended accounts.
  • Unusual ownership structures.
  • Prior fraud indicators.
  • Fake websites or fake business profiles.
  • Suspicious product categories.
  • Suspicious payment behavior.
  • High complaint history.

Regulatory Screening

Regulatory screening may include:

  • Professional license checks.
  • Business registry checks.
  • Tax registration review.
  • Public disciplinary records.
  • Product safety alerts.
  • Government warnings.
  • Public adverse media where appropriate.

ATU should document the screening result and any escalation decision.

17. Phase 10: Payment and Billing Verification

Where ATU collects subscription fees, advertising fees, listing fees, promotional fees, or other amounts from vendors, ATU may verify billing and payment information.

Vendor may be required to provide:

  • Payment method details through an approved payment processor.
  • Billing contact information.
  • Billing address.
  • Payment confirmation.
  • Tax or invoice information.
  • Payment processor verification.
  • Bank information where required for a specific vendor service.

Where bank verification is required, ATU may request:

  • Bank name.
  • Account holder name.
  • Account type.
  • Bank letter.
  • Voided check.
  • Bank statement.
  • Payment processor verification.
  • Other verification required by ATU or the payment processor.

Bank or payment information should match the verified vendor, business owner, or authorized entity where applicable.

If ATU does not process vendor-customer payments, the onboarding process should clearly distinguish between:

  • Fees vendors pay to ATU.
  • Payments customers make directly to vendors.
  • Any future payment model that may require separate legal review.

18. Privacy and Data Retention Rules

Purpose

ATU is committed to protecting the privacy, confidentiality, integrity, and security of Vendor information. These Privacy and Data Retention Rules establish the requirements governing the collection, use, disclosure, storage, retention, transfer, and disposal of Vendor data obtained during onboarding and throughout the Vendor relationship.

All Vendor information shall be processed in accordance with applicable data protection, privacy, cybersecurity, and records management laws.

Scope

These Rules apply to:

  • prospective Vendors;
  • approved Vendors;
  • beneficial owners;
  • directors and officers;
  • authorized representatives;
  • employees whose information is collected during onboarding;
  • third-party service providers involved in Vendor due diligence.

The Rules apply to all personal data, business information, financial records, licensing documents, compliance records, and electronic communications collected by ATU.

Categories of Information Collected

Business Information

  • legal business name;
  • business registration details;
  • tax identification numbers;
  • registered office address;
  • banking information;
  • business licenses;
  • regulatory registrations;
  • insurance information.

Personal Information

  • names of directors and officers;
  • authorized signatories;
  • beneficial owners;
  • government-issued identification;
  • contact information;
  • signatures;
  • photographs where required for identity verification.

Compliance Information

  • KYB documentation;
  • AML/CTF screening results;
  • sanctions screening records;
  • PEP screening;
  • licensing verification;
  • fraud prevention information;
  • audit reports;
  • compliance investigations.

Technical Information

  • IP addresses;
  • device identifiers;
  • authentication logs;
  • login history;
  • system access records;
  • cybersecurity monitoring logs.

Lawful Basis for Processing

Vendor information may be processed where necessary to:

  • evaluate Vendor applications;
  • verify identity;
  • comply with legal and regulatory obligations;
  • perform contractual obligations;
  • prevent fraud and financial crime;
  • protect marketplace users;
  • maintain platform security;
  • exercise or defend legal claims;
  • pursue ATU's legitimate business interests where permitted by law.

Use of Vendor Information

Vendor information may be used for:

  • onboarding;
  • KYB verification;
  • professional licensing review;
  • tax verification;
  • payment processing;
  • transaction monitoring;
  • sanctions screening;
  • fraud detection;
  • cybersecurity;
  • customer support;
  • regulatory reporting;
  • dispute resolution;
  • risk management;
  • legal compliance;
  • internal audits.

Vendor information shall not be used for purposes incompatible with those disclosed without an appropriate legal basis or required notice.

Information Sharing

Vendor information may be disclosed only where necessary to:

  • payment processors;
  • financial institutions;
  • identity verification providers;
  • AML screening providers;
  • cloud hosting providers;
  • logistics partners;
  • external auditors;
  • legal advisers;
  • regulators;
  • law enforcement authorities;
  • courts or governmental agencies;
  • affiliated companies where permitted by law.

All third parties receiving Vendor information shall be subject to appropriate confidentiality, security, and data protection obligations.

Cross-Border Data Transfers

Where Vendor information is transferred outside the jurisdiction in which it was collected, ATU shall implement appropriate safeguards, including:

  • contractual data protection clauses;
  • adequacy decisions where available;
  • approved transfer mechanisms;
  • technical and organizational security measures;
  • vendor risk assessments.

Cross-border transfers shall comply with applicable data protection laws.

Information Security

ATU shall implement administrative, technical, and physical safeguards designed to protect Vendor information against unauthorized access, disclosure, alteration, destruction, or loss.

Security measures may include:

  • encryption;
  • multi-factor authentication;
  • access controls;
  • role-based permissions;
  • network monitoring;
  • vulnerability management;
  • audit logging;
  • backup and disaster recovery procedures.

Vendor Responsibilities

Each Vendor shall:

  • provide accurate information;
  • keep information current;
  • promptly notify the Company of material changes;
  • protect account credentials;
  • report suspected security incidents immediately;
  • comply with applicable privacy and cybersecurity laws.

Data Retention

Vendor information shall be retained only for as long as necessary to:

  • fulfil contractual obligations;
  • satisfy legal and regulatory requirements;
  • resolve disputes;
  • complete audits;
  • investigate fraud;
  • comply with tax, accounting, AML, and recordkeeping obligations.

Unless a longer period is required by applicable law, ATU will generally retain:

Record Category Recommended Minimum Retention Period
Vendor onboarding records 7 years after termination
KYB documentation 7 years after termination
AML and sanctions screening records 5–7 years after the last transaction or as required by law
Beneficial ownership records 7 years after termination
Professional licensing records 7 years after expiration or termination
Tax documentation 7 years
Transaction records 7 years
Payment records 7 years
Audit reports 7 years
Security logs 12–24 months unless required longer
Customer complaints relating to Vendors 7 years

Where litigation, investigations, or regulatory proceedings are pending, relevant information shall be preserved until the matter is fully resolved.

Data Disposal

Upon expiration of the applicable retention period, Vendor information shall be securely destroyed, anonymized, or permanently deleted using methods appropriate to the sensitivity of the information, unless continued retention is required by law or a valid legal hold.

Vendor Privacy Rights

Subject to applicable law, Vendors may have the right to:

  • access their personal information;
  • request correction of inaccurate information;
  • request deletion where legally permissible;
  • object to certain processing activities;
  • request restriction of processing;
  • receive information in a portable format where applicable;
  • withdraw consent where processing is based on consent;
  • lodge complaints with the appropriate supervisory authority.

Requests shall be handled in accordance with applicable legal requirements.

Data Breach Management

ATU shall maintain procedures for identifying, investigating, documenting, mitigating, and reporting personal data breaches.

Where required by law, affected individuals and competent regulatory authorities shall be notified within the applicable statutory timeframes.

Legal Holds

Where litigation, regulatory investigations, law enforcement inquiries, or audits are anticipated or pending, ATU may suspend routine deletion of relevant records until the legal hold is lifted.

Compliance and Monitoring

ATU may periodically review compliance with these Rules through audits, risk assessments, security testing, and records management reviews. Vendors shall cooperate with reasonable requests for information relating to privacy and data protection compliance.

Policy Review

These Privacy and Data Retention Rules shall be reviewed periodically and may be amended to reflect changes in applicable law, regulatory guidance, technology, business operations, or industry best practices.

19. Phase 11: Risk Assessment

ATU should assign vendors a risk classification before approval.

Low Risk

Examples may include:

  • Standard retail businesses.
  • Low-risk service providers.
  • Businesses with clear documentation.
  • Businesses operating in permitted jurisdictions.
  • Businesses with no regulated categories.
  • Businesses with no adverse screening results.

Medium Risk

Examples may include:

  • Vendors offering services requiring some licensing.
  • Vendors in categories with moderate customer complaint risk.
  • Vendors with incomplete but curable documentation.
  • Vendors selling imported products.
  • Vendors in countries requiring additional review.
  • Vendors with higher customer data exposure.

High Risk

Examples may include:

  • Regulated professional services.
  • Financial, health, wellness, or safety-related services.
  • Vendors in restricted or higher-risk jurisdictions.
  • Vendors with complex ownership structures.
  • Vendors with inconsistent documents.
  • Vendors with adverse media.
  • Vendors with products requiring safety certifications.
  • Vendors with sanctions, AML, fraud, tax, licensing, or customer safety concerns.

High-risk vendors should be escalated for enhanced due diligence or management approval before activation.

20. Enhanced Due Diligence

Enhanced due diligence may include:

  • Additional identity verification.
  • Additional ownership documentation.
  • License verification.
  • Insurance verification.
  • Supplier verification.
  • Product authenticity review.
  • Product safety documentation.
  • Tax documentation.
  • Proof of business activity.
  • Adverse media review.
  • Legal review.
  • Compliance committee review.
  • Category restrictions.
  • Limited initial approval.
  • Shorter re-verification period.

Enhanced due diligence may result in approval, conditional approval, rejection, suspension, or restricted access.

21. Compliance Review Committee

ATU may establish a Compliance Review Committee or assign a designated management reviewer.

The committee or reviewer may be responsible for:

  • Reviewing high-risk vendors.
  • Approving restricted categories.
  • Investigating concerns.
  • Reviewing appeals.
  • Recommending account restrictions.
  • Recommending rejections.
  • Reviewing vendor suspensions.
  • Approving exceptions.
  • Updating onboarding standards.

Committee or reviewer decisions should be documented.

Where ATU operates with a small team, a designated reviewer may perform this role until a formal committee is created.

22. Approval Outcomes

After review, ATU may issue one of the following decisions:

Approved

Vendor may proceed to activation.

Conditional Approval

Vendor may proceed subject to conditions, such as:

  • Limited categories.
  • Limited listing permissions.
  • Additional documents required.
  • Insurance required before listing.
  • License renewal required.
  • Shorter review period.
  • Monitoring period.
  • Manual approval for certain listings.

Pending

Vendor application requires additional review or missing information.

Rejected

Vendor application is rejected due to failure to satisfy onboarding requirements.

Escalated

Vendor application is referred to management, compliance, or legal counsel.

All decisions should be recorded with the reason for the decision.

23. Anti-Discrimination and Fair Review Standards

ATU vendor approval decisions should be based on objective business, legal, compliance, safety, risk, documentation, platform integrity, and policy-related criteria.

ATU should not approve, reject, restrict, or suspend vendors based on unlawful discrimination or personal bias.

Reasons for rejection, restriction, or suspension should be documented.

Examples of objective reasons may include:

  • Incomplete documentation.
  • False information.
  • Failure to verify identity.
  • Failure to verify business registration.
  • Prohibited product or service category.
  • Restricted country concerns.
  • Sanctions or fraud concerns.
  • Licensing failure.
  • Insurance failure where required.
  • Tax documentation failure.
  • Safety concern.
  • Intellectual property concern.
  • Customer protection concern.
  • Violation of ATU policy.

24. Final Approval and Activation

Upon successful completion of onboarding, vendor may receive access to:

  • Vendor account.
  • Vendor dashboard.
  • Vendor storefront or business page.
  • Approved listing categories.
  • Product listing permissions.
  • Service listing permissions.
  • Vendor support tools.
  • Subscription plan features.
  • Approved promotional or advertising tools.

Before activation, ATU should confirm:

  • Required documents are collected.
  • Identity checks are completed.
  • Business verification is completed.
  • Sanctions screening is completed.
  • Prohibited category review is completed.
  • Subscription or billing setup is completed.
  • Vendor has accepted applicable agreements.
  • Vendor has agreed to ATU policies.
  • Vendor profile information is complete enough for launch.
  • Vendor risk classification is recorded.
  • Approval decision is documented.

Activation is subject to ongoing compliance.

25. Vendor Agreement Acceptance

Before activation, vendor should accept or acknowledge:

  • Terms of Use.
  • Vendor Terms of Service.
  • Vendor Marketplace Agreement, if separate.
  • Privacy Policy.
  • Cookie Policy.
  • Refund and Subscription Policy.
  • DMCA and Intellectual Property Policy.
  • Prohibited and Restricted Categories Policy.
  • Any category-specific rules.
  • Any plan-specific billing terms.
  • Any consent required for KYB, verification, sanctions screening, and ongoing monitoring.

Acceptance may be recorded electronically through checkbox, clickwrap, dashboard confirmation, written agreement, email confirmation, or other legally acceptable method.

26. Ongoing Monitoring

Vendor approval is not permanent.

ATU may conduct ongoing monitoring, including:

  • License verification.
  • Sanctions screening.
  • Fraud monitoring.
  • Customer complaint analysis.
  • Product or service review.
  • Payment dispute review.
  • Chargeback review.
  • Review manipulation monitoring.
  • Intellectual property complaint monitoring.
  • Restricted category monitoring.
  • Regulatory review.
  • Adverse media review.
  • Account activity review.
  • Data privacy or customer misuse review.

ATU may suspend, restrict, or terminate vendors based on ongoing monitoring results.

27. Annual Re-Verification

ATU may require vendors to update information periodically, including annually or more frequently for higher-risk vendors.

Re-verification may include updates to:

  • Identification documents.
  • Business registrations.
  • Tax information.
  • Beneficial ownership information.
  • Banking or billing information.
  • Licensing documentation.
  • Insurance documentation.
  • Product or service categories.
  • Country of operation.
  • Contact information.
  • Compliance certifications.

Failure to complete re-verification may result in suspension, restriction, or termination.

28. Material Change Reporting

Vendors must promptly notify ATU of material changes, including:

  • Change of ownership.
  • Change of business name.
  • Change of business address.
  • Change of beneficial owners.
  • Change of authorized representative.
  • Change of tax status.
  • Change of licensing status.
  • License suspension or revocation.
  • Insurance cancellation or lapse.
  • New regulated product or service category.
  • Regulatory investigation.
  • Product recall.
  • Sanctions concern.
  • Significant customer complaint issue.
  • Data breach involving customer information received through ATU.

ATU may require re-review after a material change.

29. Suspension of Applications or Accounts

ATU may suspend, delay, restrict, or reject applications or active vendor accounts where:

  • Information is incomplete.
  • Information is inaccurate.
  • Documentation is fraudulent.
  • Documents cannot be verified.
  • Identity concerns exist.
  • Business legitimacy concerns exist.
  • Sanctions concerns exist.
  • Fraud concerns exist.
  • Regulatory restrictions apply.
  • Prohibited products or services are involved.
  • Licensing is missing or invalid.
  • Insurance is missing where required.
  • Customer safety concerns exist.
  • Intellectual property concerns exist.
  • Payment or billing concerns exist.
  • Vendor fails to cooperate.
  • Approval would create legal, compliance, financial, reputational, security, or marketplace trust risk.

ATU reserves discretion to determine appropriate action.

30. Appeals and Reconsideration

Rejected applicants may submit additional documentation for review where ATU allows reconsideration.

Appeals or reconsideration requests should include:

  • Vendor name.
  • Application reference.
  • Reason for rejection, if known.
  • Explanation of why vendor believes the decision should be reviewed.
  • Additional documents or corrections.
  • Updated contact information.

Submission of additional information does not guarantee approval.

ATU may decline appeals where the vendor involves prohibited activity, sanctions concerns, serious fraud concerns, threats to user safety, or repeated false submissions.

Appeal decisions should be documented.

31. Vendor Communication Standards

ATU should communicate clearly with vendor applicants regarding:

  • Application receipt.
  • Missing documents.
  • Verification requirements.
  • Approval status.
  • Conditional approval terms.
  • Rejection reasons where appropriate.
  • Suspension reasons where appropriate.
  • Re-verification deadlines.
  • Required corrective actions.
  • Contact method for questions.

ATU may limit the detail provided where disclosure could compromise security, fraud prevention, sanctions screening, law enforcement, compliance review, or platform integrity.

32. Record Retention

ATU shall maintain onboarding and vendor records for compliance, legal, tax, accounting, fraud prevention, dispute resolution, and business purposes.

Records may include:

  • Vendor applications.
  • Identification documents.
  • Business documents.
  • Tax documents.
  • Licensing documents.
  • Insurance records.
  • Beneficial ownership information.
  • Screening results.
  • Approval decisions.
  • Rejection decisions.
  • Suspension decisions.
  • Appeal records.
  • Vendor communications.
  • Risk classification.
  • Re-verification records.
  • Compliance review notes.

Access to onboarding records should be restricted to authorized personnel.

Retention periods should be determined with legal counsel based on applicable privacy, tax, regulatory, and business requirements.

33. Confidentiality and Data Protection

Vendor information collected during onboarding should be treated as confidential and protected in accordance with ATU’s Privacy Policy, internal data protection procedures, information security controls, and applicable privacy laws.

ATU should apply reasonable safeguards, including:

  • Restricted access.
  • Secure storage.
  • Password protection.
  • Multi-factor authentication where appropriate.
  • Encryption where appropriate.
  • Limited sharing with approved service providers.
  • Staff confidentiality obligations.
  • Secure deletion or retention procedures.
  • Incident response procedures.

Vendor personal information and business documents should not be accessed, used, shared, or retained beyond what is necessary for legitimate business, legal, compliance, fraud prevention, billing, tax, or security purposes.

34. Third-Party Verification Providers

ATU may use third-party service providers for identity verification, business verification, payment verification, sanctions screening, fraud prevention, document review, data storage, or compliance tools.

Where third-party providers are used, ATU should ensure appropriate contractual, privacy, and security controls are in place.

Third-party providers should only receive information needed to perform their services.

35. Staff Training Requirements

ATU personnel responsible for vendor onboarding should receive training appropriate to their role.

Training may include:

  • Vendor application review.
  • Fraud detection.
  • Document review.
  • Sanctions screening.
  • AML red flags.
  • Anti-bribery and corruption red flags.
  • Data privacy.
  • Information security.
  • Confidentiality.
  • Restricted products and services.
  • Professional licensing review.
  • Customer protection.
  • Anti-discrimination standards.
  • Escalation procedures.

Training should be documented.

36. Red Flags and Escalation Triggers

Vendor applications should be escalated where red flags appear.

Examples of red flags include:

  • Unverifiable identity.
  • Unverifiable business registration.
  • Mismatched names across documents.
  • Mismatched bank, billing, and business information.
  • Suspicious ownership structure.
  • False or altered documents.
  • Use of fake addresses.
  • High-risk country involvement.
  • Sanctions list match or possible match.
  • Adverse media involving fraud or regulatory violations.
  • Products that appear counterfeit.
  • Services requiring licenses without proof.
  • Unclear product sourcing.
  • Prior account suspension.
  • High-risk financial activity.
  • Customer safety concerns.
  • Attempts to pressure staff to bypass review.
  • Refusal to provide documents.
  • Multiple failed verification attempts.

Escalated applications should not be approved until the concern is resolved or management/compliance approves the decision.

37. Internal Review and Updates

This Manual will be reviewed periodically and updated as ATU’s marketplace grows.

38. Governing Law

This Manual shall be governed by the laws of the State of Delaware, United States, except where mandatory laws in another applicable jurisdiction require otherwise.

39. Contact Information

Vendor onboarding questions may be directed to:

Vendor Compliance Department
All Things Universal LLC
Website: www.allthingsuniversal.com
Email: onboarding@allthingsuniversal.com
Hours: Mon-Fri 9.00 am – 6.00 pm EST
Telephone: 1(786) 743-7526
Business Address: 1688 Meridian Avenue, Suites 600 & 700, Miami Beach, Miami, 33139, United States of America