Checklist · IB Commission Operations
Self-Referral Review: Evidence Without Automatic Accusations
Review a possible affiliate self-referral using the actual policy, reliable evidence and documented exceptions without treating one match as proof.
Published Updated
Published by FxTrusts, a supplier of brokerage and prop firm technology. Prepared with AI-assisted research and drafting; reviewed against the cited public sources. Examples are illustrative. Product links describe our services.
Quick answer
A self-referral review checks whether a partner’s referral breaches a defined program rule about referring themselves or connected people. A shared address, device or network can be a review signal, but it does not by itself establish identity, intent or a contractual violation. Record evidence and a reasoned decision.

Read the actual prohibited relationship
A policy might exclude the partner’s own account, employees, controlled entities or certain household relationships. Those are different tests. Identify the exact agreement clause, effective version and customer event under review. Do not widen an own-account exclusion into a ban on every person sharing an address. If the rule is ambiguous, obtain an interpretation from the responsible program owner before applying it to a payout. The review record should say what question it is trying to resolve.
Separate a matching signal from a verified fact
A shared IP address may identify an office or shared connection rather than one individual. Similar names may belong to different people. Record the source and reliability of each signal and seek proportionate corroboration through authorized evidence. The ICO’s UK guidance distinguishes factual records from opinions and stresses the accuracy of personal data. That guidance is jurisdiction-specific, but the distinction is useful when designing a review record that must not present an unconfirmed suspicion as a fact.
Sources for this section
Restrict evidence and provide a review route
People reviewing commission eligibility should see only information appropriate to their role and task. Identity files and account access must not become available merely because someone can edit a partner record. OWASP authorization guidance supports explicit permission checks on the resources involved. Keep the explanation of an eligibility decision separate from restricted evidence where necessary. Define who can resolve the case, how a factual correction is submitted and how an authorized exception is recorded.
Sources for this section
- OWASP Authorization Cheat Sheetcheatsheetseries.owasp.org
Keep the payout consequence tied to the decision
Use distinct states such as review requested, evidence incomplete, policy match confirmed and exception approved. If a temporary hold is allowed, record its basis, scope and review deadline. A hold is not a final accusation. A confirmed breach should affect only the entitlement covered by the rule and approved decision. If new evidence changes the outcome, preserve the earlier reasoning and linked correction rather than leaving contradictory labels in customer and partner systems.
A review record that avoids an automatic accusation
In this fictional case, partner P and customer C share a workplace IP address. The program excludes the partner’s own account but does not exclude unrelated colleagues. The signal opens a review; it does not establish that C is P. An authorized reviewer checks the permitted identity evidence, records that the identities differ and documents any remaining uncertainty. If no other evidence supports the excluded relationship, the original IP match alone cannot demonstrate this particular rule was broken.
| Record field | Illustrative entry |
|---|---|
| Observed signal | Same workplace network at registration |
| Rule being tested | Partner may not refer their own account |
| Corroborated fact | Authorized identity review records different people |
| Decision scope | No own-account violation established by this evidence |
Implementation checklist
- Identify the exact relationship prohibited by the agreement.
- Label observations, inferences and verified facts separately.
- Use authorized evidence and record the reviewer’s reasoning.
- Provide a correction route and review any temporary hold.
Sources
These documents support the reference. Check the original publication for current requirements and the limits of its scope.
- ICO: accuracy of personal-data records and opinionsico.org.uk
- OWASP Authorization Cheat Sheetcheatsheetseries.owasp.org
Continue with the broader guides
Connect this reference to platform selection and the wider operating workflow.
