Restricted list
This list changes as sanctions programs are updated. Treat it as indicative rather than authoritative in your own code — always handle a
rejected outcome at runtime instead of pre-filtering against a hardcoded copy.What gets checked
Screening is evaluated against the cardholder’s identity data, not their IP address or the country your platform operates from:- Residence country —
residenceCountryCodeon the cardholder, or the address extracted from their KYC session - Nationality and document issuing country — taken from the verified identity document
How rejection surfaces
When the cardholder is rejected,cardholder.rejected fires:
kycStatus moves to "rejected" and no cardholder.approved event follows. Cards cannot be issued to a rejected cardholder. The reason field is present only when the provider supplies one, and is redacted to a safe summary.
Rejection is terminal for that cardholder. Resubmitting the same identity produces the same outcome — do not retry.
Handling it in your integration
POST /partner/cardholders.
Related
- Card holders — creating and updating cardholders
cardholder.rejected— cardholder verification outcome- Errors — error format and status codes