Business · Chapter 09
What to do if you're rejected anyway
Most rejections arrive as a generic line with nothing underneath. Work out whether it was a hard (policy) or soft (documentation) decline - they call for opposite responses - and never resubmit the same unchanged file.
~6 min
The issue
Even a well-prepared file gets declined sometimes. Compliance teams are rarely allowed to explain exactly why - AML "tipping-off" rules restrict what they can disclose - so most rejections arrive as a generic line ("does not meet our risk criteria") with nothing underneath. That silence is frustrating, but it isn't a dead end if you read it correctly.
Every decline is one of two things, and they call for opposite responses. A hard decline: your sector, country, or structure is explicitly excluded by that provider's published policy - no amount of extra documentation changes a policy exclusion, so reapplying there with a better file is wasted effort; the fix is a provider whose published rules actually include your profile. A soft decline: the decision was really about clarity and documentation - a vague description, a mismatched website, a missing proof point - and a cleaner, more complete file has a real chance the second time.
Why institutions ask
When you can't get a straight answer - the most common outcome - read the shape of what happened. A decline within minutes or hours of submission, with no document requests in between, is almost always automated and policy-based: a hard decline. A decline after multiple rounds of document requests or weeks of review is far more likely a soft decline that never quite got resolved.
What usually helps
- Ask once, professionally, whether the decision was about risk appetite/policy or about documentation - many providers won't give detail, but some will confirm the category, and that alone tells you whether to fix-and-retry or move on.
- Fix everything fixable before touching another application: business description, website coherence, missing-document alternatives, proof of activity.
- After a soft decline, wait a reasonable interval before reapplying to the same institution. After a hard decline, don't wait at all - apply to a provider whose published criteria genuinely fit.
- Keep your file consistent everywhere: materially different answers to different providers is its own red flag if ever compared.
And when documents are requested again a year or two later, it isn't an alarm bell: institutions run periodic KYC refreshes on a schedule tied to your risk profile - lower-risk profiles are typically revisited every one to three years, higher-risk ones more often (industry practice at this guide's review; cadence varies by institution). Respond promptly and completely, and it normally closes without incident. It escalates only when this time's answers don't match last time's - one more reason to keep a copy of exactly what you originally submitted.
Your actions
I've worked out (or professionally asked) whether my decline was policy-based or documentation-based, and chosen fix-and-retry or move-on accordingly.
I've fixed everything fixable - description, website coherence, missing-document alternatives, proof of activity - before reapplying anywhere.
My answers are materially consistent across every provider I've applied to.
I've kept a copy of exactly what I submitted at onboarding, in case of a future periodic review.
These become trackable items in your checklist once your personalized plan is generated.