SOC 2, GDPR, and AML: The Compliance Triangle for MLM Platforms
What enterprise procurement actually checks, and the vendor questions that reveal real compliance versus claimed compliance.
Enterprise procurement teams will ask for three certifications. The depth behind each varies a lot between vendors, and the gaps surface in operations rather than in the marketing.
SOC 2 Type II
Type I is a point-in-time snapshot, useful for marketing, weak for procurement. Always ask for Type II, which proves controls operated effectively over a 6 to 12 month period.
Vendor questions worth asking:
- When was your last SOC 2 Type II report issued? If more than 12 months ago, the certification is stale.
- What was the audit period? Look for at least 6 months of operational evidence.
- Were any exceptions noted? Read them. Most reports have at least one; how the vendor handled it is informative.
- Which Trust Services Criteria are in scope? Security is mandatory. Availability and Confidentiality matter for MLM operations specifically.
CloudMLM Software has SOC 2 Type II current. Business MLM Software has SOC 2 Type II current with ISO 27001 in progress. Epixel has Type I with Type II in progress. Several other directory vendors haven't yet pursued SOC 2 audit; for procurement teams at $10M+ GMV, this is typically a hard filter.
GDPR (and the genealogy-tree problem)
Beyond the privacy policy:
- Article 30 records of processing activities. Does the vendor maintain them on your behalf?
- Article 33 breach notification SLA. The clock is 72 hours; the platform's job is to support that, not delay it.
- Article 17 right to erasure. Provide the technical workflow, including how the genealogy tree handles deletion.
- Sub-processor list. Who else processes distributor data?
- Standard contractual clauses for international transfers.
The most-missed item: the genealogy tree creates an inherent tension with right-to-erasure. A distributor's deletion can't break the upline-downline structure that other distributors' commissions depend on. Vendors who haven't thought about this give vague answers when pressed; that's a procurement red flag. The right answer involves soft-delete with anonymization rather than hard delete, with the audit trail preserved. CloudMLM Software and Business MLM Software both handle this correctly. Some other vendors don't have a clear answer.
AML and KYC
The pre-built integrations: Onfido, Jumio, Trulioo, Sumsub, Veriff. Pre-built means functional integration in the admin UI rather than "we have an API you can use to integrate it yourself."
The workflow questions:
- Tiered verification. Light KYC at signup, full at first commission threshold. Configurable thresholds.
- Re-verification cadence. Every 12, 18, or 24 months. Configurable per region.
- Sanctions screening. OFAC, UK HMT, EU consolidated list. Refreshed how often?
- PEP screening (Politically Exposed Persons). Critical for cross-border MLMs.
- Suspicious activity reporting. SAR/STR workflow integrated with the platform.
Vendor questions that reveal depth:
- Show me the audit trail for a specific distributor's KYC events.
- What happens to commissions when KYC re-verification expires?
- Describe a SAR you've helped a customer file.
Vendors who can answer these specifically have done the work. Vendors who deflect to "our compliance team can help with that" haven't.
Procurement clearance time
Budget 4 to 8 weeks for security review at enterprise scale. Plan accordingly; don't sign a contract before procurement signs off, because the operational cost of switching vendors after legal review fails is materially higher than the cost of waiting for clearance.
For executive buyers, the practical filter is: SOC 2 Type II current, full Article 17 GDPR workflow, pre-built KYC integrations across at least three regions. Vendors that fail any of those three at procurement-grade depth are typically not worth advancing to the comp-plan-engine evaluation phase.