Key Takeaways
- Categorize every business on four axes: sector, business model, regulatory exposure, and risk tier — the same framework works for KYB, AML tiering, and vendor due diligence.
- Fintech, crypto, SaaS, and cybersecurity each need a different classification lens because traditional codes like NAICS, SIC, and MCC weren’t built for digital, borderless business models.
- Risk tier — not sector label — should decide how much diligence a vendor or counterparty gets. A payments company and a budgeting app share a sector but need very different checks.
- On-chain data adds behavioral evidence for crypto counterparties (wallet clustering, counterparty exposure, contract behavior) but complements KYB rather than replacing legal-entity verification.
- A repeatable seven-step due-diligence workflow — classify, verify, screen, assess, review on-chain (for crypto), decide, and monitor — keeps categorization consistent and defensible across reviewers.
To categorize businesses across fintech, crypto, SaaS, and cybersecurity, sort each company on four axes: sector (what it does), business model (how it makes money and touches funds or data), regulatory exposure (which rules apply), and risk tier (how much diligence it needs). That single framework works for KYB, AML tiering, and vendor due diligence.
Most people classify these businesses for a compliance or diligence reason, not academic curiosity. You need to know whether a counterparty is a regulated money transmitter, a data processor, or a security vendor before you onboard, lend to, or pay it. SoluLab builds the classification and on-chain risk-scoring systems behind that decision, and our blockchain development company team designs them for fintechs, exchanges, and banks.
How Do You Categorize Businesses Across Fintech, Crypto, SaaS, and Cybersecurity?
You categorize them with a repeatable four-axis framework, then let the axes drive the compliance workload. A payments processor and a security consultancy can share a sector label yet land in completely different risk tiers once you score fund flows and regulatory exposure. The framework keeps that judgment consistent across every reviewer.
The Four Classification Axes
Use these four axes for any business you assess:
- Sector. The primary market: fintech, crypto, SaaS, or cybersecurity. This is the coarse bucket.
- Business model. How the company earns and whether it touches customer money, custody, or sensitive data. A neobank holding deposits is not the same as a budgeting app that only reads them.
- Regulatory exposure. Which regimes apply: money transmission, securities, data protection, or none. This is where crypto and SaaS break traditional codes.
- Risk tier. The output. Low, medium, or high, based on the three axes above, mapped to the diligence and monitoring each tier requires.
The rest of this guide works axis by axis, then hands you a decision table and a due-diligence workflow you can run tomorrow. For the compliance backbone (KYB and AML), the FATF risk-based approach guidance is the standard most regulators map back to.
What Are the Main Categories Inside Fintech?
Fintech splits into a handful of models that each carry a distinct risk profile, so treating “fintech” as one bucket is the first mistake. The sub-category tells you whether the business holds funds, extends credit, or just moves data, and that drives everything downstream.
Core Fintech Categories
- Payments and money movement. Processors, acquirers, PSPs, and money transmitters. High regulatory exposure because they touch funds directly and often need money-transmitter licences.
- Lending and credit (fintech lending). Digital lenders, BNPL, and marketplace lending. Credit risk plus consumer-protection rules. SoluLab has shipped fintech lending platforms, including an instant-loans app for small-business lending.
- Wealthtech and investing. Robo-advisors, brokerages, trading apps. Securities regulation applies, so exposure is high.
- Insurtech. Digital insurance and claims. Insurance regulation, medium-to-high depending on underwriting.
- Neobanking and BaaS. App-first banks and banking-as-a-service. High exposure; they hold or route deposits and inherit bank-grade obligations.
A payments company and a wealthtech app both sit under “fintech,” yet they answer to different regulators. Categorize on the model, not the label.

How Do Crypto Businesses Break Traditional Classification Codes?
Crypto businesses break traditional codes because systems like NAICS, SIC, and merchant category codes (MCC) were built for physical, jurisdiction-bound commerce, and a DeFi protocol has neither a fixed jurisdiction nor a clean revenue line. A centralized exchange might get slotted into a generic “financial services” or “software” code that tells a reviewer almost nothing about custody, counterparty, or sanctions risk.
Where the Mismatch Shows Up
- Exchanges. Custody plus trading plus fiat rails. One MCC cannot capture all three risk surfaces at once.
- Custodians and wallets. Holding keys is a distinct risk that legacy codes do not name. SoluLab has built compliance-aware wallets, including a VARA-compliant crypto wallet, and the risk model there is custody-first.
- DeFi protocols. No company, no employees in the traditional sense, sometimes no identifiable operator. Traditional business codes assume a legal entity that DeFi may not have.
- Token issuers and stablecoins. May be a securities matter, a payments matter, or both. SoluLab’s work on stablecoin infrastructure treats reserve and compliance posture as core classification data, not an afterthought.
Because the codes fail here, most teams add a crypto-specific overlay: is this custody or non-custody, on-chain or off-chain settlement, and is there an identifiable operator. Global regulators lean on the FATF definition of a virtual asset service provider (VASP) to bring these actors back into scope.
How Do You Classify a SaaS Business by Model and Data Sensitivity?
You classify a SaaS business on two questions: what its software does (horizontal or vertical, B2B or B2C) and what data it touches (its role in processing and the sensitivity of that data). The data role usually matters more for risk than the product category, because it decides which privacy and security obligations attach.
The Classification Cuts
- Horizontal vs vertical. Horizontal SaaS (CRM, analytics) serves many industries. Vertical SaaS (health, legal, financial) inherits the compliance weight of the industry it serves, so a health SaaS carries far more diligence than a generic project tool.
- B2B vs B2C. B2C SaaS holds consumer personal data at volume; B2B may hold another company’s data under contract. Different breach and privacy consequences.
- Data-processing role. Is the vendor a controller (decides how data is used) or a processor (handles it on your behalf)? This distinction drives data-protection duties and is a required KYB and vendor-review input.
- Data sensitivity. Payments data, health records, and identity documents raise the tier regardless of what the product nominally does.
A vertical fintech SaaS that processes payment data is a high-tier vendor even if the sales deck says “productivity tool.” Score the data, not the pitch.
Where Do Cybersecurity Firms Fit as a Business Category?
Cybersecurity firms are a service-and-product category whose defining risk is supply-chain reach: because they hold privileged access to their clients’ systems, a compromise at the vendor cascades to everyone it protects. Classify them by what they sell and how deep their access runs.
Main Cybersecurity Sub-Categories
- Security product vendors. Sell software (EDR, SIEM, firewalls). Risk sits in the code and update channel — a compromised update ships to every customer.
- Managed security service providers (MSSPs). Run security operations for clients, often with standing remote access. High supply-chain and insider risk.
- Consultancies and pen-test firms. Project-based access, narrower blast radius, but still handle sensitive findings.
- Identity and compliance tooling. Sit inside the trust boundary (KYC, KYB, IAM), so they see the data you are trying to protect.
The classification question that matters for a cybersecurity vendor is not “product or service” but “how much of my environment do they touch, and what happens if they are breached.” That access level sets the tier.
How Do You Assign a Risk Tier Once a Business Is Categorized?
You assign a risk tier by combining the three input axes (sector, business model, regulatory exposure) into a single rating, then attaching a fixed set of controls to each tier so onboarding is consistent and defensible. Low tier gets streamlined checks; high tier gets enhanced due diligence and ongoing monitoring. The table below maps category to model, exposure, tier, and the controls each tier demands.
| Category | Typical Business Model | Regulatory Exposure | Risk Tier | Required Controls |
| Payments / money transmitter | Moves and holds funds | High (money transmission, AML) | High | Full KYB, UBO, sanctions, source-of-funds, ongoing monitoring |
| Fintech lending | Extends credit | Medium to high (consumer credit, AML) | Medium to high | KYB, UBO, credit and consumer-protection review |
| Wealthtech / brokerage | Holds or trades assets | High (securities) | High | KYB, UBO, licence verification, market-conduct checks |
| Crypto exchange / custodian | Custody plus trading | High (VASP, AML) | High | Enhanced KYB, on-chain screening, sanctions, travel rule |
| DeFi protocol | Non-custodial software | Uncertain / evolving | High (uncertainty premium) | Contract audit, on-chain analysis, operator identification |
| Horizontal SaaS (low-sensitivity) | Subscription software | Low | Low | Basic KYB, security questionnaire |
| Vertical SaaS (regulated data) | Subscription, sensitive data | Medium to high (privacy, sector) | Medium to high | KYB, data-processing review, SOC 2 / ISO 27001 evidence |
| Cybersecurity MSSP | Managed access to systems | Medium | Medium to high | KYB, access-scope review, breach-history and insurance check |
Tiering is a judgment, not a formula. Two reviewers should reach the same tier from the same inputs, which is exactly what the axes give you. For the AML side of that judgment, industry references such as the LSEG AML and KYC glossary keep terminology consistent across teams.
How Does Categorization Drive KYB and AML Compliance?
Categorization drives KYB and AML by deciding which checks are mandatory and how deep they go: the category and tier tell you whether you need standard verification or enhanced due diligence with source-of-funds and continuous monitoring. Know your business (KYB) verifies the entity, its owners, and its legitimacy, and AML risk tiering decides how hard you look.
The Checks a Category Triggers
- Entity verification. Registration, licensing, and operating status for every business. Baseline for all tiers.
- Ultimate beneficial owner (UBO). Who really owns and controls the entity. Mandatory for medium and high tiers, deeper for money transmitters and crypto.
- Sanctions and PEP screening. Screen the entity, owners, and (for crypto) associated wallet addresses.
- Source of funds and source of wealth. Required for high-tier and cash-intensive categories.
- Ongoing monitoring. High-tier categories need continuous re-screening, not a one-time check.
KYB verifies the business; KYC verifies the people; AML risk tiering sets the intensity of both. Getting the category right first is what makes the AML program proportionate instead of one-size-fits-all. Reference explainers like Moody’s on what KYB is and Merkle Science on KYC, AML, and CFT are useful for aligning definitions across a compliance team.
Can On-Chain Data Improve How You Classify and Score a Crypto Business?
Yes. On-chain data lets you classify and score a crypto business from behavior, not just paperwork, because wallet activity and smart-contract interactions are public and hard to fake. You can see whether a claimed “custodial exchange” actually holds funds, whether an address touches sanctioned or mixer-linked wallets, and how a protocol really moves value.

What On-Chain Analysis Adds
- Wallet clustering. Group addresses that belong to the same operator to confirm whether an entity is custody or non-custody, and how concentrated its holdings are.
- Counterparty exposure. Trace who an address transacts with to flag sanctions, mixer, or high-risk exposure before onboarding.
- Contract behavior. Read what a smart contract actually does versus what its docs claim, which is decisive for classifying DeFi protocols.
- Real-time risk signals. Score continuously as new transactions land, instead of relying on a static onboarding snapshot.
SoluLab builds this layer. Our team builds enterprise-grade blockchain risk detection platforms that tie on-chain automation to off-chain intelligence for fintechs, exchanges, and banks, and we have integrated AI-powered fraud detection into crypto exchanges. On-chain analytics complements traditional KYB; it does not replace legal-entity verification.
What Does a Vendor Due-Diligence Workflow Look Like by Category?
A vendor due-diligence workflow runs the same steps for every vendor but scales the depth to the assigned tier: low-tier vendors clear a light-touch path, high-tier vendors get enhanced checks and sign-off. Categorize first, tier second, then execute the steps below.
The Workflow, Step by Step
- Classify the vendor. Assign sector, business model, regulatory exposure, and risk tier using the four-axis framework.
- Verify the entity (KYB). Confirm registration, licences, and operating status.
- Identify owners (UBO) and screen. Run sanctions and PEP screening on the entity and its owners; add wallet screening for crypto.
- Assess controls to tier. Request SOC 2 or ISO 27001 evidence for data-sensitive SaaS and security vendors; request source-of-funds for high-tier fintech and crypto.
- For crypto, add on-chain review. Cluster wallets, check counterparty exposure, and analyze contract behavior.
- Decide and document. Approve, approve with conditions, or reject, and record the rationale against the tier.
- Set the monitoring cadence. Re-screen high-tier vendors continuously, medium-tier periodically, low-tier at renewal.
The point of tiering is proportionality: you spend enhanced-diligence effort where the risk actually is, and you can prove why.
How Does SoluLab Help Build Classification and Risk-Scoring Systems?
SoluLab builds the classification, KYB, and on-chain risk-scoring systems that turn this framework into working software, combining blockchain, AI, and cloud engineering. We work end-to-end with fintechs, exchanges, and banks, from mapping the risk model to shipping the platform that runs it.
Where SoluLab Fits
- On-chain risk platforms. We build enterprise blockchain risk detection platforms that surface bad patterns early by tying on-chain data to off-chain intelligence.
- Blockchain and Web3 engineering. Core builds run through our blockchain development company and Web3 development teams.
- Permissioned and enterprise chains. For compliance-heavy, controlled-access systems, our Hyperledger blockchain development services fit regulated deployments.
- Cloud and data infrastructure. Risk-scoring systems need scalable data pipelines; SoluLab pairs blockchain work with cloud computing consulting.
- AI in fintech. We have delivered generative-AI builds for banking and finance, described in our AI in fintech case study.
If you are weighing build versus buy for KYB or on-chain scoring, the deciding factors are usually data-source cost, on-chain data reliability, and how custom your risk model needs to be.
Frequently Asked Questions
Chintan leads SoluLab's highest-level AI consulting conversations, assessing whether a client's business problem actually justifies an AI investment before any solutioning begins.