Skip to content

Onlayer

Onlayer (formerly PCI Checklist) is a London-based merchant risk platform combining PCI DSS compliance automation with fraud, AML, and sanctions screening for e-commerce businesses.

Visit Website ↗ + Add to Compare
52/100Incremental Innovator

Overview

Onlayer began life as PCI Checklist, a self-service tool that walked e-commerce merchants through PCI DSS Self-Assessment Questionnaires (SAQs) and lightweight external vulnerability scanning. The company has since rebranded and broadened its scope into a merchant risk management platform: PCI DSS compliance tracking sits alongside MCC monitoring, transaction fraud scoring, and AML/sanctions screening, aimed primarily at payment service providers, acquirers, and e-commerce platforms that need to onboard and continuously monitor merchant accounts.

The core pitch is consolidation: instead of separate tools for PCI attestation tracking, ASV scan document management, and merchant fraud/AML checks, Onlayer puts them in one dashboard with a guided workflow for selecting the correct SAQ type and uploading Attestation of Compliance (AoC) documentation. For payment facilitators and PSPs managing large merchant portfolios, that consolidation reduces the operational overhead of chasing compliance paperwork across hundreds or thousands of sub-merchants.

Onlayer is a small, venture-backed company rather than an established enterprise GRC vendor, and its independent evaluation footprint is thin — most available performance and accuracy figures originate from the company itself rather than third-party testing. It is best understood as a compliance-workflow and merchant-risk-screening tool for the payments industry specifically, not a general-purpose GRC platform.

Innovation Matrix Assessment

Innovation Velocity 6/10

The product has expanded meaningfully from a single-purpose PCI SAQ checklist tool (its original identity as PCI Checklist) into a broader merchant risk suite covering fraud, AML, and sanctions screening within a few years, showing real roadmap movement.

Operational Value 5/10

Onlayer is a small London-based team (est. 11-50 employees) running a SaaS platform with modest venture funding ($9.2M); it has operational reach into payments/e-commerce but lacks the scale or track record of established GRC vendors.

Market Momentum 5/10

The company’s rebrand from PCI Checklist to Onlayer alongside expanded product scope (MCC monitoring, fraud, AML) signals active growth, though public funding and customer-count disclosures are sparse, limiting visibility into the pace of adoption.

Category Disruption 6/10

Bundling PCI DSS attestation tracking with merchant fraud and AML/sanctions screening in one workflow is a meaningful convenience play for PSPs and acquirers who otherwise stitch together multiple point tools, though the underlying compliance and scanning techniques are not novel.

Real-World Efficacy 4/10

Vendor-published figures (e.g., claimed reductions in false positives and server load versus conventional scanning) have not been corroborated by independent testing or named customer case studies found in public sources, so efficacy evidence is limited to self-reported claims.

Enduring Relevance 5/10

Highly relevant to a specific niche — payment service providers and e-commerce platforms managing PCI DSS obligations across merchant portfolios — but narrower in applicability than enterprise-wide GRC platforms.

Why CISOs Should Care

For CISOs or compliance leads at PSPs, acquirers, or e-commerce platforms managing many merchant accounts, Onlayer consolidates PCI SAQ tracking, ASV scan document management, and merchant fraud/AML screening into one workflow instead of several disconnected tools.

What Makes It Different

Unlike single-purpose PCI scanning tools, Onlayer pairs compliance-workflow automation with fraud and sanctions screening aimed specifically at the merchant-onboarding and portfolio-monitoring use case in payments.

The Matrix Verdict

52/100 — INCREMENTAL INNOVATOR

A useful, narrowly-scoped compliance and merchant-risk workflow tool for the payments industry rather than a broad enterprise security platform; solid fit for PSPs and acquirers, but its efficacy claims rest mostly on vendor marketing rather than independent validation.

Editorial Note: Claims vs. Verified Findings

The company's performance claims (percentage reductions in false positives and server impact versus conventional scanning) are vendor-self-reported and were not found corroborated by independent test labs or named third-party case studies. The rebrand history (PCI Checklist to Onlayer) and funding total ($9.2M) are independently corroborated across multiple business-data sources (Tracxn, ZoomInfo).

Sources