How I would run due diligence on APAC partners before launch, and a working desk that checks a partner’s identity, licence, ownership and lists against public registers.
Clear international fintechs and financial institutions to launch on a US broker’s API: collect and review the file, reconcile it against outside sources, route questions to Compliance, AML and Legal, and keep a record that stands up later.
Who runs KYC. In a fully disclosed or omnibus set-up the partner screens the end customers, so the partner’s own AML programme carries the risk. The depth of the review follows the model.
A desk that tracks five fictional partners to launch and checks any real entity live: LEI record and parents, OFAC, UK and UN lists, four APAC alert lists, four licence registers, Singapore’s ACRA register and FATF. Hits are cleared on a second identifier, near-exact names need a second reviewer, and the file is sealed with SHA-256.
| Takeaway | Why it matters for partner DD |
|---|---|
| Identity is reconciled across sources | Certificate, LEI record and licence register must name the same entity. A licence held by a sister company is a common and fixable finding. |
| Ownership is multiplied along every path | A person with 20% direct and two indirect stakes can hold 48.5% while each line on the register stays under 25%. |
| A name hit is a question | Every hit needs a second identifier, and the reason it was cleared goes on file. Brand clones on regulator lists make this routine work. |
| Permission is per market | A partner licensed at home may still need a licence or an opinion for each market it sells into. That check sits next to the launch date. |
The public Broker API docs describe four set-ups. Who runs CIP and KYC decides what the due diligence file must prove.
| Model | Who runs KYC | What due diligence reviews | US rules in play |
|---|---|---|---|
| Fully disclosed | The partner, as locally licensed broker of record. Data passes through the account API, and the broker screens every account against its own blocklist. | “A thorough review of your CIP/KYC/AML program” (docs). Licence, onboarding flow, screening procedure, audit. | CIP 31 CFR 1023.220; beneficial ownership 1010.230; foreign correspondent DD 1010.610; FINRA 3310, 4311 |
| Omnibus | The partner. End customers are undisclosed; orders carry a per-customer sub-tag. | AML programme in full, sub-tagging in sandbox, tax status (QI or FFI), monitoring and alert handling. | 1010.610; 1010.230; FINRA 3310; OFAC |
| OmniSub | The partner: “solely responsible for all end-customer compliance” (docs). Sub-accounts sit on the broker’s ledger without PII. | “Your AML program will be reviewed during onboarding.” Plus a settlement limit sized with Treasury for post-trade netting. | 1010.610; 1010.230; FINRA 3310 |
| RIA or trading app | The broker approves each account, unless the partner’s programme has been vetted. | The partner’s licence to advise or market, disclosures, onboarding flow, vendors. | CIP run by the broker; FINRA 2090, 2111; Notice 21-29 on vendors |
Model descriptions and quotes: Broker API use cases, OmniSub, account opening. Rule texts: FINRA 3310, FINRA 4311, Notice 21-29.
Partners named in Alpaca’s own announcements fall into five archetypes. Each needs a different answer to one question: is this firm permitted to offer this product to these residents?
| Archetype | Public examples | The permission question | What I would ask first |
|---|---|---|---|
| Licensed incumbent broker | SBI Securities (Japan), Upstox (India), Daishin (Korea, memorandum) | Usually settled at home. The work is model fit, order flow and tax status. | Licence scope for foreign securities; QI or FFI status |
| Offshore-licensed fintech | Gotrade (Labuan dateline) | Which residents the offshore licence lets it serve, and where its marketing reaches. | Licence conditions and a market-by-market legal opinion |
| Licensed in a neighbouring regime | PT Valbury Asia Futures (Bappebti futures licence; US stocks through OmniSub) | Does the home regulator characterise the product the same way the partner does? | The regulator’s written view, or a counsel opinion on product scope |
| Bank adding investing or crypto | GoTyme Bank (Philippines, crypto) | Bank permissions and any separate crypto registration. | Central bank approval, crypto licence, Travel Rule procedure |
| App or adviser without a broker licence | Investing apps and RIAs across the region | The broker runs KYC, so the review moves to marketing, disclosures and the adviser licence. | Adviser licence, disclosure set, complaints process |
Partners as announced on the Alpaca blog: Valbury, Gotrade, GoTyme, Upstox, SBI Securities. Market notes from the same blog: MAS in-principle approval for a Singapore entity (Sep 2026), an IDX memorandum for PALN access (Sep 2026).
Brokerage infrastructure is a short list. A partner who has onboarded elsewhere arrives with expectations about the file, so a light, clear request list is part of the product.
| Provider | Model | Due diligence angle |
|---|---|---|
| Alpaca | US self-clearing broker with Broker API and OmniSub; local entities in Japan, Europe and the Bahamas; Singapore and India in progress | Four models on one file standard; partners often sell into several markets at once |
| DriveWealth | US broker-dealer offering embedded, fractional US equities by API | The same core question: who owns KYC for the end customer |
| Interactive Brokers | Introducing broker and white-branding programmes on its own platform | Partners use IBKR’s account opening; review centres on the introducing firm |
| Apex Fintech Solutions | US clearing and custody for fintech brokers | A clearing relationship under carrying agreements, the Rule 4311 pattern |
| Saxo | White label and OpenAPI for banks and brokers | Bank-grade partners; heavier contract review, lighter per-customer flow |
| Upvest | Investment API for European fintechs under a German licence | A reference for how a regulated API firm publishes partner requirements |
| Futu (moomoo), Tiger | Licensed under their own brands in Singapore, Hong Kong, Australia and the US | Compete for the same end users; also among the most cloned brands on APAC alert lists |
Positioning from each provider’s public product pages, October 2026. Futu and Tiger licences checked on the SFC and MAS registers in the demo.
Each row reproduces in the demo. Every source is a public register or list, dated in the Method tab.
| Observation | Evidence | Weight | Owner |
|---|---|---|---|
| The registration body is named differently in two places | Alpaca’s About page describes AlpacaJapan’s licence as a JSDA “Registration Number. 3024”. The FSA register lists AlpacaJapan株式会社 as 関東財務局長(金商)第3024号, a Kanto Regional Finance Bureau registration, with JSDA as an association membership. A one-line wording fix that partners’ counsel would notice. | low | Legal, web |
| Partner brands are cloned on regulator lists | The SFC Hong Kong list carries 11 Futu or moomoo lookalike websites (Dec 2020 to Oct 2025). SC Malaysia lists clones of moomoo, Webull and an “Upstox Pro” clone (2023). A brand-impersonation baseline and the partner’s takedown route belong in the file and in periodic review. | medium | DD, AML |
| Name-only hits need a second identifier | A current partner brand scores 90% against an SFC unlicensed-entity entry listed in 2006, years before the brand existed. The desk keeps a hit open until an analyst clears it with a reason, and logs the reason. | process | DD |
| LEI records cross scripts and can omit parents | Futu Securities International (Hong Kong) holds its legal name on GLEIF in Chinese, with English only as a transliteration, and reports no consolidating parent. Identity matching has to work across scripts, and ownership comes from the share register even for listed groups. | process | DD |
| FATF lists move every plenary | June 2026: Myanmar under a call for action with enhanced due diligence; Vietnam, Lao PDR and Nepal under increased monitoring. Partners selling into these markets need EDD and a re-check after each plenary. | medium | Compliance |
Demo: alpaca-dd.leverlabs.workers.dev (Live entity check tab; the Method and sources tab lists every source with its as-of date).
| JD line | How I would do it | Shown in |
|---|---|---|
| Support due diligence reviews for new and existing partners | One file per partner, one standard per model. Checks grouped as identity, licence, ownership, screening, jurisdiction, documents and consistency, each naming its source and date. | Case file tab |
| Communicate with partners on requirements, timelines and documents | One chaser per round: what is missing, what is stale and why, the launch date, one shared folder. Questions phrased so a partner can answer without a call. | Partner chaser output |
| KYC, KYB, EDD, policy and onboarding flow reviews, risk assessments | Effective ownership along every path; 25% owners and a control person evidenced; PEP and FATF triggers for EDD; the onboarding flow reviewed against the model’s KYC split. | Ownership, rating |
| Review documents for completeness, consistency and risk indicators | The cross-checks a reviewer does by hand: names and numbers across certificate, LEI and register; dates that cannot all be true; signatories against the director register. | Consistency checks |
| Track onboarding and follow up ahead of launch deadlines | Pipeline ranked by launch risk: open items against days left, routed by owning team. | Pipeline tab |
| Answer partner questions, escalate as appropriate | Routing per case: Legal for licence scope, AML for programme gaps, Treasury for settlement limits, Compliance for EDD sign-off. | Routing card |
| Work with Operations, Compliance, AML, Legal, Product and PM | A shared file and memo format, so AML’s ongoing monitoring starts from the record the launch was approved on. | Approval memo |
| Identify process gaps and recurring partner questions | Track which documents come back stale or incomplete, and turn the top five into a pre-filled request pack per model. | Document rules |
| Maintain records of reviews, decisions and approvals | Every status change and cleared hit is timestamped with its reason; the memo lists every source with its as-of date. | Audit trail output |
The decision ladder the desk applies. Any partner can be placed on it in one read of the memo.
| Level | Trigger | Action |
|---|---|---|
| stop | Embargoed country or FATF call-for-action jurisdiction in scope | Decline and record the reason |
| fail | Identity or licence does not reconcile; a 25% owner unidentified; an open sanctions match | Hold launch until resolved |
| EDD | PEP, FATF increased monitoring, regulator alert-list match | Enhanced review and senior sign-off |
| warn | Stale or expiring documents; inconsistencies with an innocent explanation | Approve with conditions and dates |
| unverified | A source could not be read | Checked by hand with a dated capture before approval |
A missing list or an unreadable register leaves the check unverified. Approval needs every source answered.
Pre-launch due diligence and AML’s ongoing monitoring of introducing brokers and omnibus partners share one record.
High risk every 12 months, medium 24, low 36, and on any trigger: new market, new product, ownership change, adverse news.
| When | Work | Output |
|---|---|---|
| Days 1 to 30 | Learn the current questionnaire, risk scoring and approval path; shadow live APAC files; read recent partner launches and the questions partners asked most. | A map of the APAC pipeline with blockers per partner. |
| Days 31 to 60 | Request packs per model and market; a register and alert-list check sheet per APAC regulator; standard chaser and memo templates agreed with Compliance and AML. | Shorter first-round requests and fewer rounds per partner. |
| Days 61 to 90 | Periodic review calendar for live partners; a brand-impersonation baseline for each; recurring questions turned into partner-facing guidance with Product and PM. | Files that stay current after launch, and a record ready for audit. |
The demo is my own work, built for this application. Its five partners are fictional, and nothing in it is Alpaca’s process or data.
Independent homework for the Alpaca Due Diligence Analyst (APAC) role · 2026 · edwardtay.com