> ## Documentation Index
> Fetch the complete documentation index at: https://docs.valiant.finance/llms.txt
> Use this file to discover all available pages before exploring further.

# Risk Factor Assessments

> How Valiant automatically evaluates business legitimacy, applicant identity, and transaction integrity

# Risk factor assessments on the Valiant platform

<Divider />

Valiant's intelligent risk assessment engine automatically evaluates 50+ risk factors to assess business legitimacy, applicant identity, and transaction integrity throughout the quoting and application processes – filtering out potential fraud before it reaches your underwriting team.

## Balancing speed with security

Traditional financing workflows force a difficult choice, either slow down approvals with extensive manual reviews, or risk fraud by approving and processing applications too quickly.

For finance programs serving SMBs across multiple markets and regions, this challenge is amplified by:

* **Volume scale** – Processing thousands of applications across different regions
* **Resource constraints** – Limited underwriting capacity for growing loan portfolios
* **Fraud evolution** – Increasingly sophisticated bad actors targeting SMB lending
* **Partner expectations** – Program partners demanding both speed, quality and approvals

## Front-loaded risk intelligence

Valiant's risk assessment framework moves verification and fraud detection to the earliest possible stage – before applications even reach finance partners. By running 50+ automated checks as data becomes available, we:

* **Accelerate good applications** – Fast-track clearly legitimate opportunities
* **Protect partner resources** – Filters out obvious fraud before underwriting review
* **Provide transparent reasoning** – Give underwriters context for flagged items
* **Complement existing process** – Supplement and accelerate existing compliance process
* **Maintain flexibility** – Customize risk criteria per program, market and region

## Benefits

By automating early-stage risk detection, we reduce friction for legitimate businesses while protecting all stakeholders from fraud exposure. Each participant in the financing process experiences specific advantages:

* **Finance partners** – Receive pre-screened, higher-quality finance applications with detailed risk context, allowing underwriters and compliance teams to focus on complex credit decisions rather than basic fraud detection
* **Program managers** – Gain visibility into fraud patterns and portfolio risk trends, enabling data-driven program optimization and proactive risk management
* **Vendors and manufacturers** – Experience faster approvals for legitimate transactions while building stronger relationships with customers through streamlined financing options
* **Compliance teams** – Maintain comprehensive audit trails and consistent risk standards across programs, simplifying regulatory reporting and risk governance

## Risk factors vs. credit policy eligibility

It's important to distinguish between Valiant's risk factor assessments and traditional credit policy-based eligibility conditions.

Risk factors evaluate **potential fraud** and **transaction authenticity** – concerns that apply universally regardless of the finance partner or specific finance product. These assessments are global for a given quote or application and focus on whether a quote or application represents legitimate business activity and poses acceptable operational risk.

In contrast, credit policy eligibility conditions are finance partner-specific requirements such as minimum time in business, acceptable business structures, or industry restrictions. These criteria determine whether an applicant **qualifies** and is eligible for a particular loan product based on the finance partner's risk appetite and portfolio strategy. While there may be some overlap between the two (for example, both systems might flag very recently formed businesses), pure credit policy-informed filters are considered part of product eligibility rather than risk factor assessment.

Valiant's risk factors operate independently of finance partner credit policies, ensuring consistent fraud protection and operational risk management across all programs via an additional screening stage while allowing each partner to maintain their unique underwriting standards and eligibility requirements. Risk factors are often only run if a customer is considered eligible from a credit product perspective.

# How it works

<Divider />

Our risk assessment engine operates through continuous, data-driven evaluation rather than discrete stages. As application information becomes available, whether from initial form submission, document upload, or third-party data enrichment, the engine will automatically:

1. **Detects data changes** – Monitors for new or updated information across all application fields
2. **Trigger data enrichment** – Runs relevant data enrichment workflows
3. **Runs risk tests** – Automatically runs applicable risk factor assessments on most current data
4. **Updates risk outcomes** – Dynamically adjusts the overall risk assessment outcome

If the required data is not available, the test will not be run or may result in an indeterminate outcome if no run is acceptable.

This means risk evaluation happens continuously throughout the application lifecycle, ensuring decisions are always based on the most complete and up-to-date information available. A single application might trigger dozens of risk assessments as different data points become available, from initial business verification through final document analysis.

<Note>
  **Important:**

  * Effective risk assessment requires a fully enriched quote or application record. The list outlined below assumes a fully enriched record with all required data available
  * Different risk factor assessments are run at different stages of the process based on available data. Some may be run up front while others may be run as more data becomes available throughout the application process
  * Data required for some assessments may not be available in some regions
  * Some risk factor tests or functionality outlined below may be in development or currently on our roadmap
  * For security and competitive reasons, specific test criteria, thresholds and data sources are not disclosed in public documentation
</Note>

# Risk categories

<Divider />

Our comprehensive risk factor framework is organized into four main categories, each targeting different vectors of potential fraud and business risk. This multi-layered approach ensures thorough evaluation while maintaining processing efficiency.

* **Business risk** – digital footprint, business registration, addresses, etc.
* **Contact and signer risk** – identity, contact details, etc.
* **Vendor quote risk** – source document analysis, product basket, etc.
* **Cross-category risk** – corroboration of data across categories

<div className="p-4 border rounded-lg bg-gray-50 dark:bg-gray-900 mb-8">
  <Tabs>
    <Tab title="Business risk">
      ### Organizational legitimacy and stability

      Evaluates the authenticity, stability, and operational legitimacy of the applying business entity.

      Core assessment areas include:

      * **Digital footprint analysis** – Website quality, domain history, social media presence, and online reputation
      * **Business registration verification** – Corporate filings, licensing status, tax registrations, and regulatory compliance
      * **Physical presence validation** – Business addresses, location verification, and operational indicators
      * **Financial history and relationships** – Vendor purchase history and program participation
      * **Industry and market context** – Business industry risk, market presence, and competitive positioning

      #### Why this matters

      Fraudulent applications often involve shell companies, recently formed entities, or businesses with inconsistent digital presence. These tests help distinguish established, legitimate businesses from potential fraud attempts.
    </Tab>

    <Tab title="Contact and signer risk">
      ### Individual identity and authority

      Verifies the identity, legitimacy, and authorization of individuals associated with the application.

      Core assessment areas include:

      * **Identity verification** – Name validation, ID document and number authentication, biometrics
      * **Contact information validation** – Email deliverability, phone verification, and communication channel legitimacy
      * **Authority and role verification** – Corporate officer status, signing authority, and business relationship validation
      * **Behavioral and technical analysis** – Application patterns, device fingerprinting, and interaction behaviors
      * **Regulatory compliance screening** – PEP (Politically Exposed Person) checks, sanctions lists, and regulatory exclusions

      #### Why this matters

      Even legitimate businesses can be compromised by unauthorized individuals or fraudulent signers. These assessments ensure the right people are making financial decisions and that contact information enables proper communication throughout the loan lifecycle.
    </Tab>

    <Tab title="Vendor quote risk">
      ### Transaction authenticity and quality

      Analyzes the specific transaction details, documentation, and commercial reasonableness of the financing request.

      Core assessment areas include:

      * **Document integrity analysis** – PDF authenticity, metadata validation, and format verification against known vendor templates
      * **Product and service validation** – Basket composition analysis, pricing reasonableness, and product category risk assessment
      * **Commercial logic testing** – Purchase quantities, shipping logistics, and business use case validation
      * **Vendor relationship verification** – Purchase history, relationship depth, and transaction pattern analysis
      * **Geographic and delivery analysis** – Shipping address validation, delivery feasibility, and location risk assessment

      #### Why this matters

      Fraudulent applications often involve fabricated quotes, unrealistic purchase scenarios, or documents that don't match legitimate vendor patterns. These tests ensure the underlying transaction is authentic and commercially reasonable.
    </Tab>

    <Tab title="Cross-category risk">
      ### Pattern detection across categories

      Beyond individual category assessments, our framework identifies risk patterns that emerge across categories:

      * **Consistency validation** – Information alignment across digital footprint, business registration, contact details, and transaction specifics
      * **Timeline correlation** – Temporal relationships between business formation, digital presence creation, officeholder appointment and application timing
      * **Pattern recognition** – Behavioral signatures that may indicate coordinated fraud attempts or application farming
      * **Geographic clustering** – Location-based risk patterns and regional fraud trend identification

      #### Why this matters

      Advanced fraud often involves orchestrated deception across multiple risk vectors. By correlating risk signals across categories and corroborating data across multiple sources, we can detect sophisticated fraud schemes that might appear legitimate when examining each category in isolation. This cross-category analysis provides a holistic view of application integrity and helps identify coordinated fraud rings or sophisticated bad actors.
    </Tab>
  </Tabs>
</div>

# Criteria and results

<Divider />

Risk factor tests are individually contained tests that assess a specific set of related data points with known risk factors with the goal of flagging key risk implications as early on in the process as possible.

## Test configurability

There is no one-size-fits-all solution regarding test criteria, and each test is deeply configurable to match program requirements and risk appetite.

Tests are often configured on a program-by-program basis and evolve in accordance with:

* **Program-specific priorities** (e.g., transaction-focused vs. relationship-focused lending)
* **Market conditions** (e.g., increased focus on business stability during economic uncertainty)
* **Emerging fraud patterns** (e.g., heightened document verification during periods of template fraud)
* **Regulatory requirements** (e.g., enhanced identity verification in certain jurisdictions)

## Test archetypes

Our risk tests are built around several proven archetypes that can be combined and customized.

<Warning>
  **Note:** For security and competitive reasons, specific test criteria, thresholds, and data sources are not disclosed in public documentation. The examples illustrated include the types of assessments performed without revealing exact implementation details.
</Warning>

<div className="p-4 border rounded-lg bg-gray-50 dark:bg-gray-900 mb-8">
  <Tabs>
    <Tab title="Acceptable values">
      ### Static allow/block lists

      Tests against predefined lists of acceptable or unacceptable values, typically for categorical data where clear boundaries exist.

      Examples include:

      * **Shipping address category** – Commercial, residential, PO Box, etc.
      * **Email provider type** – Corporate, free or disposable email service
      * **Business entity type** – LLC, Corporation, Partnership, Sole Proprietorship
      * **Phone line type** – Landline, mobile, VoIP, toll-free numbers
      * **Industry codes** – Acceptable vs. restricted industries
      * **Geographic regions** – Approved states/countries/territories
    </Tab>

    <Tab title="Value thresholds">
      ### Quantitative boundaries

      Tests against numeric ranges or percentage limits, often with multiple threshold levels (pass/warning/fail).

      Examples include:

      * **Soft costs as % of quote basket** – Accessories, warranties, insurance as percentage of total
      * **Business registration age** – Minimum months/years since incorporation
      * **Quote value relative to business size** – Large purchases relative to estimated annual revenue
      * **Distance calculations** – Distance between shipping address and vendor location
      * **Financial ratios** – Debt-to-income, loan-to-value, or other program-specific metrics
    </Tab>

    <Tab title="Date and time thresholds">
      ### Temporal risk factors

      Tests based on timing, recency, or duration calculations that may indicate elevated risk.

      Examples include:

      * **Time since officeholder was nominated** – Recently appointed executives may indicate business instability
      * **Domain expiration proximity** – Websites expiring soon may indicate abandoned businesses
      * **Last social media activity** – Dormant accounts suggesting inactive businesses
      * **Recent address changes** – Frequent business relocations within short timeframes
      * **Document creation vs. submission time** – Quotes created and submitted within minutes may indicate fraud
      * **Business license renewal dates** – Expired or soon-to-expire professional licenses
    </Tab>

    <Tab title="Pattern matching">
      ### Behavioral and structural analysis

      Tests that evaluate patterns, consistency, or structural elements rather than single data points.

      Examples include:

      * **Cross-field consistency** – Business name matching across registration, website, social media
      * **Document formatting patterns** – PDF structure matching known vendor quote templates
      * **Contact information alignment** – Phone area code matching business address region
      * **Digital footprint coherence** – Website age, social media history, and business registration timeline alignment
      * **Application behavior patterns** – Time spent on forms, revision patterns, etc.
    </Tab>

    <Tab title="Enrichment-dependent tests">
      ### Third-party data validation

      Tests that rely on data existing in a specific external (most often official) sources to verify or enhance application information.

      Examples include:

      * **Business verification** – Confirming active registration status with government databases
      * **Identity verification** – Cross-checking personal information against official records
      * **Address validation** – Verifying deliverability and occupancy status
      * **Phone reputation** – Checking against spam/fraud databases
      * **Email deliverability** – Testing actual email address validity
      * **Professional licensing** – Verifying contractor licenses, permits, or certifications
    </Tab>
  </Tabs>
</div>

## Test results

Test results and outcomes are communicated using a simple traffic-light style system:

* <span className="text-green-500 font-bold">✅ Pass</span> – Test passed with acceptable result, team member or customer may proceed
* <span className="text-amber-500 font-bold">⚠️ Warning</span> – Test passed but with a boundary or uncertain result, may trigger additional verification steps, including document requests, manual review, or enhanced monitoring
* <span className="text-red-500 font-bold">🚩 Fail</span> – Test failed, team member or customer will be blocked from progressing in the UI
* <span className="text-blue-500 font-bold"> ℹ️ Info</span> – Test was run, but either data not available or the result indeterminate – i.e., no data does not equate to a fail as in some other tests

All tests are weighted equally – one test failure means the entire quote / application is considered to have failed.

<Note>
  **Program Customization:**

  All test rules (i.e., thresholds, limits, acceptable values, etc.) and outcomes (i.e., what constitutes a pass, warning or fail) can be customized on a program-by-program basis by Valiant as per preference or requirement from program stakeholders.

  For example, one program may allow goods being shipped to residential shipping addresses to be funded (<span className="text-green-500 font-bold">pass</span>) while another may require additional documentation (<span className="text-amber-500 font-bold">warning</span>) and another may not allow it (<span className="text-red-500 font-bold">fail</span>).
</Note>

# Valiant risk factor test examples

<Divider />

The below describes a range of example tests that we run and are evaluated as data becomes available during quoting and application workflows on the Valiant platform.

<Warning>
  **Note:** For commercial, competitive and security reasons, specific test criteria, thresholds and data sources are not disclosed in public documentation.
</Warning>

## Business risk factors

<div className="p-4 border rounded-lg bg-gray-50 dark:bg-gray-900 mb-8">
  <Tabs>
    <Tab title="Web domain">
      * Domain resolves and has identifiable name servers
      * Domain has been registered for an acceptable period
      * Domain is registered by same entity as related business registration
      * Domain is registered at reputable registrar
      * Domain expiry is within an acceptable period
      * Domain is linked to known business apps and services
    </Tab>

    <Tab title="Website content">
      * Website has valid metadata with titles and descriptions related to business
      * Website metadata infers valid brand assets
      * Website highlights customer reviews (trusted providers, links, embeds, content, etc.)
      * Website contains valid and verifiable business details
      * Website has valid contact details or form
      * Website infers social media presence (links, embeds, etc.)
      * Website has a valid sitemap for indexing by robots
    </Tab>

    <Tab title="Social media">
      * Social media accounts exists
      * Social media accounts are actively maintained
      * Social media account branding and metadata match website and business properties
      * Social media accounts have robust history that align with time in business
    </Tab>

    <Tab title="Business registration">
      * Business registration found
      * Business has active registration
      * Business has been registered for acceptable time period
      * Business has valid DBA filings (where relevant)
      * Business has an SBA profile (US-only)
      * Business has valid industry licences, permits or registrations (sales tax, FMSCA, etc.)
    </Tab>

    <Tab title="Business addresses">
      * Address is valid
      * Address type is acceptable (commercial, residential, etc.)
      * Address is acceptable distance from vendor location (store or other geo bound location)
      * Address is not vacant
      * Address is deliverable
    </Tab>

    <Tab title="Vendor history">
      * Customer has existing last 12 month spend with vendor
      * Customer has existing lifetime spend with vendor
      * Customer has appropriate history
    </Tab>

    <Tab title="Program history">
      * Customer has existing Opportunities in the Program
      * Customer has funded Opportunities in the Program
      * Customer does not have Opportunities from multiple vendor locations
    </Tab>
  </Tabs>
</div>

## Contact and signer risk factors

<div className="p-4 border rounded-lg bg-gray-50 dark:bg-gray-900 mb-8">
  <Tabs>
    <Tab title="Email address">
      * Email address is deliverable
      * Email address provider type is acceptable (free, disposable, etc.)
      * Email address aligns with business web domain
      * Email address is likely used for business activity
    </Tab>

    <Tab title="Phone number">
      * Phone number is currently active
      * Phone number registered on reputable telco network
      * Phone number has no risk of being involved in SMS pumping fraud
      * Phone caller ID is strong match to contact or business name
      * Phone line type is acceptable (landline, mobile, fixed VOIP, etc.)
      * Phone number last SIM swap within acceptable time frame (if mobile)
      * Phone number does not unconditionally forward calls
      * Phone number aligns with known business phone numbers
    </Tab>

    <Tab title="Identity">
      * Contact has valid and verifiable identification documentation
      * Contact is not on any officially published sanction lists (OFAC, Interpol, EU FSF, UNSC, etc.)
      * Contact matches registered officeholder
      * Contact name appears to be a valid name (no placeholders, place names or nicknames)
      * Contact is not a politically exposed person (PEP)
      * Contact has been appointed an officeholder for acceptable time period (if officeholder)
    </Tab>
  </Tabs>
</div>

## Quote risk factors

<div className="p-4 border rounded-lg bg-gray-50 dark:bg-gray-900 mb-8">
  <Tabs>
    <Tab title="Quote documentation">
      * Quote PDF is a valid PDF document and complies with PDF spec
      * Quote PDF has not been modified since creation
      * Quote PDF metadata aligns with expected values for given program
      * Quote PDF matches format and structure of known and trusted training data
    </Tab>

    <Tab title="Product basket">
      * Product basket line items match known quote training data
      * Product basket soft costs (insurance, accessories, etc.) within acceptable ranges
      * Product basket value acceptable for given shipping address type
      * Product basket quantities acceptable for given shipping address type
    </Tab>

    <Tab title="Shipping address">
      * Address is valid
      * Address type is acceptable (commercial, residential, etc.)
      * Address is acceptable distance from vendor location (store or other geo bound location)
      * Address is not vacant
      * Address is deliverable
    </Tab>
  </Tabs>
</div>
