In regimes built on MiFID and its descendants, a firm offering complex products such as CFDs on a non-advised basis has to assess whether the client has the knowledge and experience to understand the risks involved. The assessment is called appropriateness, it is narrower than a suitability assessment, and it sits at the front of the relationship. What it looks like in practice is a set of questions during sign-up, and what it looks like in most firms is a set of questions with obvious right answers.
Where the test belongs in the flow
Put it before the account is funded and before any trading is possible, and after identity is established well enough that answers can be attached to a real person. That ordering sounds obvious and gets violated constantly, because funding is the step everyone optimises. A firm that lets a client deposit first and answer later has created a situation where the honest response to a failed test is refunding money, and firms under commercial pressure do not do that consistently.
The other placement decision is whether it runs before or after client categorisation. It has to be after, because the category determines whether the assessment is required at all and how the answers are treated. Running the test first and the classification second means re-running the test for anyone whose category is not what the form assumed.
Questions that can actually be failed
The design problem is writing questions a knowledgeable client answers correctly and an inexperienced one does not, without signalling the right answer in the wording. Questions of the form "do you understand that CFDs are leveraged and you may lose more than you expect" are useless, because the client can see what they are supposed to say. Questions that ask what happens to margin when a position moves against the client, or how a stop is affected by a gap, or what the client's actual trading frequency has been over the last two years, produce a distribution.
The areas the applicable rules generally point at are the types of products the client is familiar with, the nature and frequency of prior transactions, and the client's level of education and profession or former profession. A firm cannot invent a scoring model and call it compliance, but within those areas it has real freedom about how demanding the questions are, and how they are randomised so answers cannot be shared and copied.
Which clients require an appropriateness assessment, what it must cover and what a firm must do after a negative outcome are set by each firm's regulator. This article describes the mechanism. Take your own legal advice on the rules that apply to you.
What a failed test has to trigger
This is the part firms build badly. In several regimes, a negative outcome does not automatically bar the client. It obliges the firm to warn the client that the product may not be appropriate for them, and then the firm has to decide, under its own policy, whether to proceed. Some firms proceed on an acknowledged warning. Some decline. Some allow trading on a restricted basis. Each of those is a defensible policy. What is not defensible is a system where a failed test silently becomes a pass because the client was allowed to resubmit the form until the answers changed.
So the control is retry handling. Immediate unlimited retries with the same questions is the single most common weakness, and it turns the whole exercise into a memory game. Reasonable designs impose a cooling-off period before reassessment, present a different question set, keep every attempt in the record rather than only the last one, and flag serial attempts to compliance. The firm may still choose to onboard the client, but it will do so knowingly and with the trail intact.
The evidence has to outlive the form
What needs to be retrievable years later is not just pass or fail. It is the exact question set and version presented, the answers given, the timestamp, the outcome, whether a warning was shown, the exact wording of that warning, and whether the client acknowledged it. If your onboarding form is a third-party builder that stores only the final submission, you cannot produce most of that, and it will be asked for the first time in the context of a complaint.
Store it the way you would store a compliance audit trail, versioned, immutable, keyed to the client and the date. Firms who treat onboarding answers as marketing data lose them in the first form redesign.
Jurisdiction changes the question set, not just the wording
Appropriateness obligations differ across regimes. Firms operating under an EU authorisation, a UK authorisation, and an offshore licence with clients in several regions cannot run one form. The reasonable structure is one assessment engine with a per-jurisdiction question set, per-jurisdiction pass logic and per-jurisdiction warning text, keyed to the same country of residence field that drives platform restrictions by jurisdiction. It is the same principle throughout this stack: one engine, many rule sets, versioned.
Translation is a live risk here. A question translated loosely into a local language can lose the discrimination that made it a test, and a warning translated loosely can stop being the warning the rules required. Localised versions need the same review as the English source, and the version identifier has to be per language.
The conversion argument, answered honestly
Every growth team says the same thing: each additional onboarding step costs applicants. That is true. It is also true that clients who fail an appropriately hard test are, on average, the clients who generate complaints, chargebacks and payment problems. A firm whose acquirer sees a rising chargeback ratio discovers that the cost of a weak front door is charged later, at a much worse exchange rate, in reserves and in account terminations.
My position: build the test to fail people, publish the policy for what happens when it does, and accept the conversion cost. A firm that cannot survive a real appropriateness test is not being held back by compliance, it is being held up by clients it should not have taken.
"If nobody ever fails your appropriateness test, you have not built a control. You have built a conversion step with compliance vocabulary on it."
— Roman Onta, Executive Director, SINGUARD
Key Takeaways
- The assessment belongs after categorisation and before funding, so a negative outcome never requires refunding money already taken.
- Questions with obvious right answers do not assess anything; ask about mechanics and prior activity, and randomise the set.
- A failed test triggers a warning and a documented firm decision, and unlimited immediate retries destroy the whole control.
- Keep the question version, the answers, the timestamp, the warning text and the acknowledgement, not just a pass or fail flag.
Frequently Asked Questions
Is an appropriateness test the same as a suitability assessment?
No. Appropriateness asks whether the client has the knowledge and experience to understand the risks of a complex product on a non-advised basis. Suitability is a wider assessment tied to advice or portfolio management. Which applies depends on the service and the regime, and firms should take their own legal advice.
Can a client trade after failing the assessment?
In several regimes a negative outcome obliges the firm to warn the client rather than automatically refuse them, and the firm then decides under its own policy whether to proceed. What matters is that the warning was given, acknowledged and recorded, and that the decision was deliberate.
How should retries be handled?
Not with an immediate identical re-take. Reasonable designs apply a waiting period, present a different question set, keep every attempt on file and flag repeated attempts to compliance, so the firm knows it is dealing with a client who has been assessed more than once.
About the Author
Roman Onta is an Executive Director at SINGUARD. He builds the Prop Firm CRM, the Broker CRM, Scalegram and CopySignals side by side with his brother Alex Onta, and he helped on the design of eTrader, the division Alex built and leads. His ground is worldwide payment processing, AML compliance and the corporate structures brokers are built on, work the two of them carry together, shaped by executive roles in the UAE and international corporates. He lives and works in Dubai for most of the year. Meet the executive duo leading Singuard's five divisions.