Trading-service due diligence: a reproducible checklist before you pay
This checklist turns a trading service's promotional claims into verifiable records before money or account access changes hands. It covers entity identity, regulator permission scope, clone-firm checks, claim ledgers, performance arithmetic, review independence, commercial terms, account-access risk, an evidence completeness score and go, pause or reject workflow states that can be rerun when facts change.
The evidence chain behind every trading-service claim
Before any paid trading service takes your money or your account access, each promotional statement should be traceable through a chain of records: the claim itself, the exact entity making it, any permission the activity requires in your jurisdiction, the contract that governs delivery, the beneficiary of the payment, the delivery record, and the eventual outcome. A polished website proves only that someone built a website. A real firm reference number pasted into a footer proves only that the number exists. An impressive dashboard proves only what the dashboard displays at that moment. Each link in the chain must be verified on its own terms. [1] [2]
This guide sets out a reproducible process you can run yourself, document, and rerun when facts change. It does not declare any service fraudulent, endorse any service as safe, or set return thresholds. A red flag here is a question or an evidence burden, never a verdict.
Step 1: Classify exactly what is being sold
Marketing labels often hide different activities under similar names. Start by writing down which category the service falls into, because the category determines which questions matter most:
- Execution or custody: the service places trades or holds funds, where permission requirements are most likely to apply depending on jurisdiction and facts. [1] [3]
- Regulated advice or discretionary management: someone recommends or manages investments for you. The activity may require specific permission held by a named firm or individual, so check the exact activity and jurisdiction. [1] [4]
- Signals: trade ideas delivered by message, app or platform. Their regulatory classification depends on what the service actually does, the jurisdiction and the facts, not the label alone.
- Software or bot: automated execution tools, whether licensed software, a hosted bot or an API strategy. [6]
- Education or community: courses, mentorship, chat groups and coaching. [8]
- Prop-firm evaluation: paid challenges promising funded accounts, where the deliverable is an evaluation outcome rather than market access itself.
- Data or analytics: feeds, screeners, backtesting tools and research subscriptions.
- Affiliate introduction: the site introducing you may be paid per sign-up, creating a material relationship to record and evaluate when you assess its claims. [7]
Record the classification in your notes. Legal classification depends on jurisdiction and facts, so this step identifies what to verify next rather than deciding regulatory status for anyone.
Step 2: Separate four independent questions
- Is the exact contact genuine? The person or page messaging you must match official records, not merely carry a plausible brand name.
- Is the exact entity permitted for the relevant activity? Where the activity requires permission in your jurisdiction, the named entity must hold permission for that specific service. [1] [3]
- Are the commercial terms workable? Deliverable, price, renewal, cancellation, refunds, data ownership and dispute route must be written down and acceptable to you.
- Does the performance evidence support the claim? Results need denominators, cost accounting and complete time series, not screenshots.
A yes to one question is not a yes to all four. A genuine contact can sell an unworkable contract; a permitted broker can publish unverifiable marketing returns.
Step 3: Run the identity check
Collect and record each of the following, marking each item as supplied, matched or missing:
- Exact legal name of the contracting entity, distinct from any trading name or brand. [1]
- Licence or reference number and the regulator that issued it, where one exists for the relevant activity. [1] [3]
- Permitted services: the register entry should show permission for the specific service you would use, such as handling client money, not just general authorisation. [1]
- Status and history of the firm and, where relevant, the individuals involved, including employment history and disclosures. [1] [4]
- Official domain, phone number and email address taken from the regulator's records, not from an advert or message. [1] [2]
- Registered address and company number where applicable. [1]
- Complaints route stated in the contract.
- Payment beneficiary: the exact account name that would receive your money.
Scope matters when choosing tools. The FCA Firm Checker and Financial Services Register cover UK firms and individuals and show permissions such as the ability to handle client money. NFA BASIC is the CFTC-directed tool for checking registration, disciplinary history and financial information for certain US derivatives activity. FINRA BrokerCheck is a free US tool covering investment professionals, brokerage firms and investment adviser firms, with reports that can include registration history, qualifications and disclosures such as customer disputes and disciplinary events. None of these is a global registry; use the tool that matches the jurisdiction and activity actually involved. [1] [3] [4]
Step 4: Run the clone check
Clone firms can copy the name, address, website and firm reference number of a genuine authorised firm while substituting their own phone number, email address or payment details. A genuine registration number copied into a website does not prove the contact is genuine.
- Start from the regulator's own domain. Type the regulator's web address directly rather than following links from emails, adverts or social posts. [1] [2]
- Search the Firm Checker or equivalent register, select the specific service, and check the permissions listed. [1] [2]
- Compare the contact details you were given against the official record character by character: domain spelling, email domain, phone number, company number. [2]
- Compare the bank beneficiary name on any payment instruction against the registered entity name.
- For mobile apps, compare the app-store publisher name against the registered entity.
If you need to confirm anything by phone or post, use the contact details published on the regulator's record, never those supplied in the advert, message or page you are checking. [2]
Step 5: Read the regulatory record correctly
Registration is neither a profitability certificate nor a clean bill of health. Authorised status with correct permissions reduces some risks but does not remove all risk. A clean disciplinary record does not protect against fraud, although the CFTC notes that most scams involve unregistered entities, people and products, which makes the registration check worth doing even though it settles nothing on its own. [1] [3]
Read the content of a record, not just its count. A disclosure in a BrokerCheck report, such as a customer dispute or regulatory event, may be pending, disputed or unrelated to the service you are assessing. Pending allegations may be unproven. Note what the entry says, its status and its date, then decide how much weight it carries for your decision. [4]
Step 6: Build the claim ledger
Every material claim gets a ledger row. For each claim, record:
- The exact quoted wording, including numbers and qualifiers.
- An archived URL, capture date and version, so later edits cannot erase what was shown.
- The claimant: the named entity or individual making the claim, and their relationship to the seller.
- The product definition: instrument, account type, currency, leverage, period covered and market conditions.
- The sample: how many trades, accounts or subscribers, and the denominator behind any percentage.
- Whether results were live, simulated, selected or independently verified, and who did the verifying.
- Costs: fees, spreads, financing, slippage assumptions, withdrawal charges and any revisions to previously published figures.
Do not create target return or drawdown thresholds here. The ledger documents what was claimed and what evidence backs it; it does not judge whether a return figure is good or bad.
Step 7: Check the performance arithmetic
These are evidence requirements, not accusations. Ask for each item before accepting a headline figure:
- Total return without cash flows can mislead: deposits and withdrawals change the arithmetic, so ask for time-weighted or money-weighted figures with the cash-flow record.
- Win rate alone lacks average win size, average loss size and the number of trades, so a high win rate says little on its own.
- Gross results omit costs; ask for net figures after fees, spreads, financing and slippage.
- A percentage return needs a capital base to be meaningful.
- A single account screenshot lacks a complete time series; request the full equity curve with dates.
- Hypothetical or backtested results need disclosed assumptions, and simulated performance has inherent limitations as a predictor of live outcomes.
Step 8: Interrogate bot and AI claims
The CFTC warns that fraudsters use AI language to promote bots, signal strategies and crypto schemes promising unreasonable or guaranteed returns, and states plainly that AI cannot predict the future or sudden market changes. Treat AI or proprietary language as a claim that needs evidence, not as proof of fraud and not as proof of performance. AI can have legitimate uses in trading workflows; the label alone cannot guarantee future returns. [6]
Ask the seller for: the exact role of AI in the system; the training data window; the out-of-sample test period; live deployment dates; failure controls and kill switches; broker and instrument dependencies; latency and cost assumptions; a model-change log; and complete live results since deployment. Guaranteed-return language attached to any automated system is a warning pattern requiring verification. [5] [6]
Step 9: Test testimonials and reviews
Reviews are evidence with provenance. For each testimonial or review cluster, record: [7]
- Platform and reviewer history: does the reviewer have other activity, or a profile created around one product? [7]
- Purchase or usage evidence where disclosed. [7]
- Incentive: compensation conditioned on positive sentiment, free accounts, affiliate commissions or contest entries all shape incentives. [7]
- Relationship: affiliate links, employee status or a controlled review entity presented as independent. [7]
- Date clusters and repeated wording across supposedly independent reviewers. [7]
- Suppressed negatives: filtered critical reviews, deleted threads or ratings pages that show only positives. [7]
- Whether a ranking or comparison site is controlled by the seller it ranks. [7]
These signals raise questions; they do not prove reviews are fake. The US Consumer Reviews and Testimonials Rule addresses fake or false reviews, compensation tied to sentiment, review suppression and false indicators of independence, and treats incentivised reviews as potential testimonials. Use it to understand why source, incentive and independence matter, not to make a legal determination about a specific review outside the US. [7]
Step 10: Map the promotion funnel
A public social post, a private group invitation, a direct message and a sales call can form one funnel. The FCA's guidance on financial promotions on social media describes harm from both legal but non-compliant promotions and illegal ones, including influencers who may be compensated and private groups that move users into chats where advice or products are sold. Whether content is a financial promotion does not depend on follower count. [8]
Archive each handoff: screenshot the public post, save the group invitation, record the direct-message thread, note any payment prompt, disclosure, risk warning and referral code, with dates. Follower count or the presence of a disclaimer alone cannot determine the legal status of a post or service. [8]
Step 11: Watch withdrawal and advance-fee patterns
Fraudulent trading websites may promise guaranteed high returns, little or no risk and instant withdrawals, display fake profits, and then demand additional purported taxes or fees before releasing non-existent proceeds. These are advance-fee patterns. Use them as warning patterns that require verification, not as proof that every withdrawal fee or delay is fraudulent. [5]
A display balance is not proof of withdrawable funds. If you choose to test the stated withdrawal process, do so only within an exposure limit you set yourself, and remember you can decide not to test at all. Save the withdrawal request and the full response. If a new tax or release fee appears, verify the demand through the authority's independently published contact details before paying anything. [5]
Step 12: Audit the commercial terms
Read the contract before payment and record answers to each of these:
- Exact deliverable: what precisely will be provided, and by when.
- Access period, renewal mechanics and renewal price.
- Cancellation process and refund conditions, including any conditions that make refunds practically unavailable.
- Price, currency and who bears exchange and payment fees.
- Any tax or deduction the seller says applies to the service or a withdrawal; verify it independently.
- Data ownership: who owns your trade history, journal data and uploaded materials.
- Account portability if you leave.
- Service levels, support hours and response commitments.
- Dispute route, governing jurisdiction and forum.
- Unilateral-change clause: can the seller alter terms, prices or rules without notice?
- Suspension rights: on what grounds can the seller freeze your access or account?
- What happens to your records after cancellation.
Step 13: Audit the requested account access
List every permission the service asks for and classify it: view-only data read, API trading permission, withdrawal permission, remote desktop control, seed phrase, account password, one-time codes or identity documents. Never share a seed phrase or account password with any third-party service. Minimise permissions to what the deliverable genuinely requires, and prefer provider-approved revocable access, such as a scoped API key you can revoke, over broad credentials. This checklist cannot offer a security guarantee; it defines what to record before granting anything.
Step 14: Score evidence completeness
Score eight categories, each 0, 1 or 2: 0 means not supplied, 1 means supplied but not independently matched, 2 means matched to a primary record such as a register entry, archived original or signed document. The total runs from 0 to 16 and measures completeness only. It is not a safety score, and no threshold in this guide separates good services from bad ones.
Step 15: Assign go, pause or reject as workflow states
These are workflow states, not recommendations. Go means proceed to the next check because the required evidence for your chosen scope is matched to primary records. Pause means a material item is unresolved and you wait or gather more. Reject means the seller will not supply a required item, the payment or contact details conflict with primary records, or the requested access exceeds the documented limit you set. Any state can be re-evaluated later with new evidence; reject today does not mean reject forever, and a completed check does not freeze the file.
Step 16: Monitor changes after purchase
Entities, domains, payment beneficiaries, terms, prices, strategies, personnel, app publishers, permission scopes and account access can all change after purchase. When any of these changes, rerun only the affected checks and preserve earlier versions of your records so you can compare. A change in bank beneficiary or app publisher, for example, triggers the clone check again even if nothing else has moved. [2]
The one-page due-diligence packet
Keep everything in a single packet you can rerun whenever facts change:
- Classification: category of service, jurisdiction, date classified.
- Identity sheet: legal name, trading name, reference number, regulator, permitted services, principals, official contacts, registered address, complaints route, payment beneficiary, each marked matched or unmatched. [1] [2] [3] [4]
- Clone-check log: register screenshots, character-level contact comparisons, app-publisher comparison, dates. [2]
- Claim ledger: quoted claims, archive links, claimants, definitions, samples, verification status, costs.
- Performance file: complete time series, cash flows, net-of-cost figures, assumption disclosures.
- Review file: platforms, reviewer histories, incentives, relationships, date clusters, suppression notes. [7]
- Funnel log: archived posts, group invitations, messages, payment prompts, warnings, referral codes. [8]
- Terms extract: deliverable, price, renewal, cancellation, refund, data ownership, dispute route, change clauses.
- Access log: every permission requested, granted or refused, with revocation method.
- Score sheet: eight categories scored 0 to 2, total out of 16, dated.
- State record: current go, pause or reject, reasons, and conditions for re-evaluation.
Frequently asked questions
- Is a regulated service automatically trustworthy?
- No. Authorised status with correct permissions reduces some risks but does not remove all risk, and authorised status is not a performance endorsement. Registration and a clean disciplinary record also do not protect against fraud. Use registers to verify identity and permission scope, then continue with the rest of the checklist.
- Does a clean regulator record prove performance?
- No. A clean record shows no recorded disciplinary events at the time you looked; it says nothing about profitability. Conversely, a disclosure entry may be pending, disputed or unrelated to the service being assessed. Read the content, status and date of each record rather than counting entries.
- Can a dashboard screenshot verify returns?
- No. A single screenshot lacks a complete time series, cash flows, cost accounting and a capital base. Ask for the full dated equity curve, deposit and withdrawal records, net-of-cost figures and disclosed assumptions for any hypothetical results.
- Are AI trading bots always scams?
- No. The CFTC warns that fraudsters use AI language to promote bots and schemes promising unreasonable or guaranteed returns, and that AI cannot predict the future or sudden market changes. That makes AI labels claims needing evidence, not proof of fraud. AI can have legitimate trading uses; the label alone guarantees nothing about future returns.
- How can I check whether reviews are independent?
- Record the platform, reviewer history, any disclosed purchase evidence, incentives, affiliate or employee relationships, date clusters, repeated wording, suppressed negatives and whether a ranking site is controlled by the seller. Incentivised reviews count as testimonials under the US rule, and a business must not misrepresent a controlled review entity as independent. These signals raise questions; they do not prove a specific review is fake.
- What should stop a payment immediately?
- Under this workflow, reject applies when the seller will not supply a required item, the payment beneficiary or contact details conflict with primary records, or the requested access exceeds your documented limit. Advance-fee demands for purported taxes or release fees before withdrawing displayed balances are warning patterns to verify through independent official channels first.