OpenDD
← All articles

License Due Diligence: Required vs. Held

Compliance · Updated July 2026

A company can be genuinely real, financially healthy and litigation-free and still be operating illegally — because it never obtained a license its business requires. License due diligence answers a deceptively simple question: does this company hold the permits, registrations and licenses its line of business actually needs? For regulated industries, the gap between "required" and "held" is where the risk lives.

First, figure out what the business even needs

You can't spot a missing license until you know which licenses apply, and that depends entirely on what the company does. A payments company likely needs state money-transmitter licenses and NMLS registration; a broker needs FINRA and SEC registration; a drug maker needs FDA registration and possibly DEA controlled-substance handling; a telecom needs FCC licenses. The industry classification (a company's SIC or NAICS code) plus a read of what it actually sells is where the required-license list comes from.

Then find what it actually holds

Held licenses live in two places. The first is public registries — FINRA BrokerCheck, the SEC's investment-adviser database, NMLS Consumer Access, the FCC's licensing system, FDA establishment registrations, state professional boards. The second is the company's own disclosures: many regulated firms, especially fintechs, publish a dedicated licenses page listing every state and license number, because no single government registry aggregates them.

The gap analysis is the whole point

Listing required licenses and listing held licenses is only useful when you line them up against each other. For each license the business needs, is there matching evidence that it holds one? "Covered," "partial," or "not found" — that mapping is the deliverable. A money-transmitter operating in forty states but licensed in twenty-five isn't unlicensed, but it has a twenty-five-state problem you'd want to understand before closing.

Documents fill the gaps registries miss

Registries are incomplete, and some licenses simply aren't in any public database. This is where documents the company provides — license certificates, regulatory correspondence, compliance attestations — earn their keep. Folding those into the analysis alongside the public record gives you the fullest picture of what's actually held, and flags where you're relying on the company's own say-so versus an independent source.

Run the required-vs-held check. OpenDD's License Due Diligence module identifies a company, infers the licenses its business needs, checks what it holds across disclosures and documents you provide, and flags the gaps. Start a license check →

Where inference ends and verification begins

Inferring which licenses a business "should" hold is judgment, not certainty — regulatory requirements are jurisdiction-specific and change, and coverage is strongest for financially- and federally-regulated sectors. Use the analysis to build the checklist and surface the obvious gaps, then verify each license at the issuing authority before you rely on it. This is general guidance, not legal or regulatory advice.

Related guides

Regulatory Enforcement Checks → Corporate Due Diligence: Verify a Company → Third-Party & Vendor Due Diligence →