OpenDD
← All articles

License Due Diligence: Required vs. Held

Compliance · Updated July 2026

A company can be genuinely real, financially healthy and litigation-free and still be operating illegally — because it never obtained a license its business requires. License due diligence answers a deceptively simple question: does this company hold the permits, registrations and licenses its line of business actually needs? For regulated industries, the gap between "required" and "held" is where the risk lives.

First, figure out what the business even needs

You can't spot a missing license until you know which licenses apply, and that depends entirely on what the company does. A payments company likely needs state money-transmitter licenses and NMLS registration; a broker needs FINRA and SEC registration; a drug maker needs FDA registration and possibly DEA controlled-substance handling; a telecom needs FCC licenses. The industry classification (a company's SIC or NAICS code) plus a read of what it actually sells is where the required-license list comes from.

Then find what it actually holds

Held licenses live in two places. The first is public registries — FINRA BrokerCheck, the SEC's investment-adviser database, NMLS Consumer Access, the FCC's licensing system, FDA establishment registrations, state professional boards. The second is the company's own disclosures: many regulated firms, especially fintechs, publish a dedicated licenses page listing every state and license number, because no single government registry aggregates them.

Self-declared versus registry-verified

Not all evidence of a license is equal. A number printed on the company's own website is a claim; the same number confirmed in a government registry is a fact. The two usually agree, but the whole reason you check is the case where they don't — a license that was surrendered, suspended, or never actually granted can still sit on a marketing page long after it stopped being true.

Treat a self-declared list as a checklist of things to confirm, not as the confirmation itself. For each entry, the goal is to trace it back to the issuing authority's own record and note the status, the entity name it's held under, and the states or activities it covers. Where the registry contradicts the disclosure, the registry wins.

The gap analysis is the whole point

Listing required licenses and listing held licenses is only useful when you line them up against each other. For each license the business needs, is there matching evidence that it holds one? "Covered," "partial," or "not found" — that mapping is the deliverable. A money-transmitter operating in forty states but licensed in twenty-five isn't unlicensed, but it has a twenty-five-state problem you'd want to understand before closing.

Documents fill the gaps registries miss

Registries are incomplete, and some licenses simply aren't in any public database. This is where documents the company provides — license certificates, regulatory correspondence, compliance attestations — earn their keep. Folding those into the analysis alongside the public record gives you the fullest picture of what's actually held, and flags where you're relying on the company's own say-so versus an independent source.

Lapses, wrong entities, and stale registrations

A license isn't a permanent state; most have to be renewed on a schedule, and they can lapse quietly when a filing is missed or a fee goes unpaid. A registry that shows an "expired," "inactive," or "terminated" status is telling you the company may be operating without cover right now, which is a very different finding from a clean, current license.

Watch the name a license is held under, too. In group structures a license is often granted to a specific subsidiary, and if the entity you're acquiring or onboarding isn't that subsidiary, the license may not travel with the deal. A registration held by a former corporate name, a predecessor, or an affiliate is worth flagging rather than counting as covered.

Run the required-vs-held check. OpenDD's License Due Diligence module identifies a company, infers the licenses its business needs, checks what it holds across disclosures and documents you provide, and flags the gaps. Start a license check →

Why it matters in M&A and vendor onboarding

In an acquisition, a missing or lapsed license is a liability you inherit at closing, and it can hold up the deal in ways that are expensive to unwind. Regulators can impose fines, force a wind-down of the unlicensed activity, or require re-application, and a buyer who didn't catch it during diligence has little recourse against anyone but themselves. Confirming licenses early lets you price the risk or make it a condition of the deal.

For vendor and partner onboarding the calculus is similar but the exposure is reputational and contractual. If a payments processor, lender, or data handler you rely on turns out to be operating without a required license, the disruption and the compliance questions land on you. License checks belong in the same onboarding pass as verifying the company exists and screening for enforcement history.

Where inference ends and verification begins

Inferring which licenses a business "should" hold is judgment, not certainty — regulatory requirements are jurisdiction-specific and change, and coverage is strongest for financially- and federally-regulated sectors. Use the analysis to build the checklist and surface the obvious gaps, then verify each license at the issuing authority before you rely on it. This is general guidance, not legal or regulatory advice.

Related guides

Regulatory Enforcement Checks → Corporate Due Diligence: Verify a Company → Third-Party & Vendor Due Diligence →