Vendor Onboarding

Last updated: 16 Feb 2026

Payward uses Zip as our vendor intake platform. If your services have been requested by Payward, you’ll receive a system-generated invitation from <[email protected]> with the subject line “[Action Required] You’ve been invited to complete tasks for Payward, Inc.”, to complete onboarding.

You’ll be asked to submit the following via the secure Zip Vendor Portal:

  • Basic Company Information

  • Tax Documents as needed (e.g., W-9, W-8)

  • Bank Details (including proof such as a voided check or letter from your bank)

 

These items are required for:

  • Payment readiness

  • Regulatory compliance

  • Financial audit preparation

  • IRS and global tax reporting obligations

 

If you need to update your company information (e.g., address, tax ID, banking), please email your main point of contact from Payward and the Payward's Accounts Payable (A/P) team. A/P will initiate a re-validation and a new portal invite.

Vendor Risk Management & Due Diligence

You’ll be asked to submit the following via the secure Zip Vendor Portal:

  • Basic Company Information

  • Tax Documents as needed (e.g., W-9, W-8)

  • Bank Details (including proof such as a voided check or letter from your bank)

 

These items are required for:

  • Payment readiness

  • Regulatory compliance

  • Financial audit preparation

  • IRS and global tax reporting obligations

 

If you need to update your company information (e.g., address, tax ID, banking), please email your main point of contact from Payward and the Payward's Accounts Payable (A/P) team. A/P will initiate a re-validation and a new portal invite.

  • Information Security – network/application security, access control, encryption, vulnerability/patch management, incident response.

  • Privacy & Data Protection – GDPR/UK GDPR, state privacy laws, data residency, DPA terms, data subject rights.

  • Anti-Bribery & Corruption (FCPA/ABC) – policies, training, third-party oversight, gifts & entertainment controls.

  • Regulatory & Compliance Fit – sector rules applicable to the service (e.g., DORA/MiCA for EU crypto/ops resiliency; SEC/FINRA where relevant).

  • Financial Viability – going-concern indicators, adverse media/litigation, insurance coverage.

  • Business Continuity / Disaster Recovery (BC/DR) – RTO/RPO, test cadence and results, dependency mapping.

  • Workforce Integrity (as applicable) – background checks for staff in scope (esp. temp labor/staff aug).

Provide via AuditBoard; if your policy prohibits uploads, share via secure links or your trust portal.

  • Security Assurance: SOC 2 Type II (or ISO/IEC 27001 certificate + SoA), recent pen-test summary & remediation status, vulnerability management policy, incident response plan.

  • Privacy & Data: Privacy Notice, DPA, subprocessors list, data-flow diagrams (collection → processing → storage → transfer → deletion), data residency statement, retention schedule.

  • Technical Controls: encryption at rest/in transit details, key management, access control/SSO/MFA, logging/monitoring, SDLC/secure coding, change management.

  • BC/DR: BCP/DRP summary, most recent BC/DR test report with outcomes/RTO/RPO, dependency mapping (cloud/third parties).

  • Regulatory Artifacts (as applicable): PCI AoC (if cardholder data), HIPAA/BAA (if PHI), DORA operational resilience attestation (if service supports EU operations), export control/sanctions screening posture.

  • Financial & Corporate: latest financials or credit report, insurance (Cyber/Tech E&O/GL; limits & carriers), legal entity details, ultimate parent/ownership.

  • People & ABC: ABC/anti-corruption policy & training overview; background-check attestations where persons access Kraken sensitive data or facilities.

Vendors will receive a welcome email from AuditBoard ([email protected]) containing their login credentials (example shown below). Shortly after, a second email will provide access to their assigned due diligence questionnaires (DDQs).

These questionnaires are tailored to the nature and risk level of the services being provided. Vendors can add additional contacts within AuditBoard to assist with completion, or contact <[email protected]> for support with the tool.

Data Handling and Security Within AuditBoard

  1. 1

    Data Access

    Data submitted via AuditBoard is accessible only to authorized Payward personnel. AuditBoard personnel do not access customer environments in the ordinary course of business. Any limited access for technical support is performed under strict confidentiality and data-protection controls defined in AuditBoard’s DPA.

  2. 2

    Data Storage

    AuditBoard is a cloud-based SaaS platform hosted on Amazon Web Services (AWS). Data is encrypted in transit (TLS 1.2/1.3) and at rest (AES-256) using AWS Key Management Service (KMS). No vendor data is stored on Kraken premises.

  3. 3

    Data Retention

    Data retention is governed by Payward’s internal policy settings. AuditBoard retains data only as long as required to provide contracted services or to meet legal and regulatory obligations, then deletes or anonymizes it in accordance with its retention policy and DPA.

  4. 4

    Attachments

    Uploading documents to AuditBoard is supported but not mandatory. Vendors may instead provide secure links to their trust portals or complete the Excel DDQ offline if preferred.

  5. 5

    Platform Certifications

    AuditBoard has undergone Payward's third-party risk review and maintains ISO/IEC 27001 certification, SOC 2 Type II reporting, and annual independent penetration testing.

    Please respond to these requests promptly. These evaluations are essential to ensure business continuity, mitigate third-party risk, and satisfy regulatory requirements.

Contracting Process

  • Complete the onboarding process via the Zip Vendor Portal

  • Undergo required due diligence reviews (as assigned by AuditBoard)

  • Have a fully executed contract in place (e.g., MSA, SOW, Order Form)

Kraken’s Procurement and Legal teams will initiate the appropriate agreement based on the engagement type. All contracts must:

  • Be reviewed and approved by Kraken’s Procurement and Legal teams

  • Be executed via DocuSign with valid signature authority

Once the agreement is signed and onboarding is complete, a Purchase Order (PO) will be issued.

For any contract questions, contact your Kraken business sponsor.

Languages & Localization

The Zip Vendor Portal is localized and available in:

  • English

  • Chinese

  • French

  • German

  • Japanese

  • Portuguese

  • Spanish

You can change the language via the dropdown menu at the top of the portal.

Next Steps After Onboarding

Once you’ve completed your vendor onboarding and registration in Zip, the next step is to familiarize yourself with Payward's Purchase Order (PO) and Invoice Submission process. This ensures your work begins only after proper approvals and that your invoices are submitted correctly for timely payment. You can find the full guide here: PO & Invoice Submission Guide.

Perlu bantuan lebih lanjut?