Blog Main Image

PayFacs and ISOs operate through different acquiring structures in the US, which affects how merchant onboarding, underwriting, risk, and compliance responsibilities are managed. The exact responsibilities can vary based on each party’s acquiring relationship and assigned functions.

In the US merchant onboarding ecosystem, payment facilitators (PayFacs) and independent sales organizations (ISOs) both help businesses access card payment processing, but they do so through different acquiring structures.

The PayFac vs ISO distinction becomes particularly important during merchant onboarding. A PayFac typically has more direct control over onboarding and managing the sub-merchants in its program, while an ISO’s role can vary depending on its agreement with an acquirer or payment processor.

As a result, their responsibilities for collecting merchant information, assessing risk, supporting underwriting, and managing compliance can differ throughout the merchant relationship. In both models, the goal is not simply to verify individual data points, but to determine whether the merchant relationship represents acceptable risk within the PayFac, ISO, acquirer, and sponsor bank model.

This article explains how those responsibilities differ in the US, how acquiring relationships shape them, and why changing risk is pushing PayFacs and ISOs toward more connected, end-to-end merchant onboarding.

Platforms such as OnBoard by MVSI are designed for this shift, helping regulated payments, fintech, and financial services teams connect merchant applications, KYB, KYC, AML screening, underwriting, approvals, and ongoing due diligence (OCDD) in one controlled workflow.

Key Takeaways

  • PayFacs and ISOs operate through different acquiring structures. PayFacs onboard businesses as sub-merchants within their programs, while ISOs typically support businesses in establishing individual merchant accounts through an acquiring relationship.
  • PayFacs typically have more direct control over merchant onboarding. ISO merchant onboarding responsibilities can vary depending on the functions assigned under the acquiring or processor relationship.
  • Merchant onboarding responsibilities extend beyond verification. Applications, KYB and KYC, screening, risk assessment, underwriting, approvals, and ongoing due diligence can all form part of the merchant journey.
  • Acquiring relationships shape onboarding and compliance responsibilities. The exact requirements can depend on contractual terms, card-network rules, applicable requirements, risk policies, and the functions assigned to each party.
  • Changing risk makes connected onboarding increasingly important. As fraud and financial crime evolve, PayFacs and ISOs need merchant information and risk decisions to carry from application through onboarding and ongoing monitoring.

What is the difference between a payment facilitator (PayFac) and an independent sales organization (ISO)?

What is a payment facilitator (PayFac)?

A payment facilitator (PayFac) is a payment service provider that works with an acquiring bank and allows businesses to accept payments as sub-merchants under its master merchant account. This means each sub-merchant can accept payments without setting up their own individual merchant account.

In the US, this relationship places the PayFac within an acquiring structure where it onboards and manages businesses as sub-merchants within its program. This typically gives the PayFac a more direct role in sub-merchant onboarding, risk management, compliance operations, and ongoing monitoring, although the exact responsibilities depend on its acquiring relationship, card-network rules, and program requirements.

A PayFac may control more of the merchant journey, but it still operates within the requirements, oversight, and risk appetite of its acquiring relationship.

What is an independent sales organization (ISO)?

An independent sales organization (ISO) is a third-party company that works with acquiring banks to offer payment processing services to businesses. It acts as an intermediary between businesses and acquiring banks, helping businesses set up individual merchant accounts so they can accept card payments.

Unlike a PayFac, an ISO does not bring merchants under a shared master merchant account. Instead, it facilitates the creation of a dedicated merchant account directly with the acquiring bank in the US. The ISO may also communicate pricing, terms, and other information to the merchant before passing the merchant's details to the processor.

The structural difference between a PayFac and an ISO

The structural difference comes down to how each model connects the merchant to the acquiring relationship:

  • PayFac: Merchants are onboarded as sub-merchants under the PayFac's program, rather than establishing their own individual merchant account.
  • ISO: Merchants are supported in establishing their own merchant account with the acquiring bank, with the ISO acting within that acquiring relationship.

How does merchant onboarding differ between a PayFac and an ISO?

The main difference is how much control each model has over the merchant onboarding process. A PayFac typically takes more direct responsibility for onboarding sub-merchants within its approved program. With ISO merchant onboarding, the ISO's role can vary depending on its agreement with the acquirer or processor.

This difference affects who collects merchant information, performs verification and risk checks, supports underwriting, makes approval decisions, and manages the merchant after onboarding.

PayFac vs ISO merchant onboarding comparison

The table below compares the main differences between PayFac and ISO merchant onboarding in the US.

PayFac ISO
Merchant account structure Businesses operate as sub-merchants under the PayFac's master merchant account. Each business has its own merchant account with the acquiring bank.
Onboarding complexity Can be faster and more streamlined. Usually involves more paperwork and detailed underwriting.
Risk responsibilities Takes a more direct role in managing sub-merchant risk. Risk responsibilities depend on the ISO's role and acquiring arrangement.
Control and flexibility Provides a more standardized payment setup. Can provide more control over rates, terms, and payment configurations.
Support Support is typically provided through the PayFac. The ISO can act as the merchant's account manager and support contact.
Scalability Can scale through a standardized sub-merchant model. Suitable for high transaction volumes and more tailored payment setups.
Pricing approach Often uses simplified or program-level pricing. Pricing can be more flexible and negotiated based on factors such as transaction volume.
Best suited for Can suit smaller businesses that value simpler setup and faster onboarding. Can suit businesses that need more tailored pricing, acquiring arrangements, or payment configurations.

The exact responsibilities of a PayFac or ISO can depend on the acquiring relationship, contractual terms, card-network rules, applicable requirements, and the functions assigned to each party.

Payment facilitator onboarding requirements

Payment facilitator onboarding requirements typically involve collecting and reviewing the information needed to decide whether a business can join the PayFac's program as a sub-merchant. Because the PayFac manages merchants within its program, PayFac compliance obligations can extend across onboarding, merchant risk, and ongoing monitoring.

A typical merchant onboarding process may include:

  • Merchant application: Collect business, ownership, banking, processing, and product or service information.
  • Business verification: Confirm that the business exists and that the information provided is accurate.
  • Ownership and identity checks: Collect and verify relevant information about ultimate beneficial owners and other relevant individuals associated with the business, where required.
  • Screening: Complete relevant PEPs and sanctions screening based on the program and applicable requirements.
  • Risk assessment: Review the merchant's business model, MCC, expected processing volume, location, fraud and chargeback exposure, merchant credit risk, and restricted or prohibited activities.
  • Merchant underwriting: Assess the information collected to determine whether the merchant meets the program's risk requirements.
  • Decision and activation: Approve, decline, or send the application for review before activation.

The faster onboarding associated with the PayFac model still requires strong controls. As merchant volumes grow, PayFacs need consistent decision rules, automated review, exception handling, clear approval authority, and records of how decisions were made.

In the US, the exact checks can depend on the PayFac's acquiring relationship, card-network rules, applicable requirements, and its own risk policies.

For teams evaluating how to manage PayFac onboarding at scale, see Payment Facilitator Onboarding.

ISO Merchant Onboarding

ISO merchant onboarding is typically built around helping a business establish its own merchant account rather than onboarding it as a sub-merchant. Because each merchant has an individual account, the setup can involve more paperwork and a more detailed underwriting process.

Depending on its arrangement, an ISO may:

  • collect the merchant application and supporting documents
  • check submitted information
  • perform an initial risk review
  • take part in underwriting
  • send merchant information to the acquirer or processor
  • support merchant activation
  • provide ongoing merchant service

The important distinction is that an ISO does not always control each of these steps. Its responsibilities depend on the functions assigned to it within the acquiring arrangement. In some models, the acquirer or processor keeps more direct control over merchant underwriting and approval.

This can make ISO merchant onboarding less standardized than the PayFac model, but it can also allow for more tailored merchant account setups and ongoing support depending on the arrangement.

For teams managing ISO-led merchant acquisition and onboarding workflows, see ISO Merchant Onboarding.

How are onboarding requirements changing for PayFacs and ISOs?

PayFacs and ISOs have different merchant onboarding and compliance responsibilities, and both may set their own internal risk standards based on the role they perform. However, those standards still need to operate within the requirements and risk appetite of their sponsoring acquirers.

These requirements are not fixed. As fraud, financial crime, and regulatory expectations change in the US, acquirers may need to adjust the standards they expect PayFacs and ISOs to follow. Recent developments can include:

  • Fraud remains a major risk: FinCEN's July 2026 update highlights fraud as a major focus and the need to adapt to new and emerging illicit-finance threats. For acquirers, changing fraud patterns can influence the risk standards they expect payment programs to meet.
  • AI is changing how fraud is carried out: The US Treasury's 2026 National Money Laundering Risk Assessment highlights how criminals are using artificial intelligence to increase the scale and speed of their schemes. This can raise the level of confidence needed in merchant and identity information during onboarding.
  • Controls are becoming more risk-focused: FinCEN is working to modernize the Bank Secrecy Act regime so financial institutions can focus resources on information and activity that is most useful for detecting financial crime. This reinforces the wider shift toward controls that respond to actual risk rather than relying only on standard checks.

For PayFacs and ISOs, the downstream effect can include changes to KYB requirements, what merchant information is collected, how risk is assessed, when extra review is needed, and how merchants are monitored after approval. This reflects a wider shift toward controls that respond to the level of risk involved.

This is pushing merchant onboarding beyond standalone verification checks and creating a greater need for trusted decisions throughout the merchant relationship.

For a broader view of how US payment providers can reduce onboarding friction while strengthening compliance controls, see Merchant Onboarding in the US: Best Practices for Payment Providers.

How can PayFacs and ISOs build a trusted end-to-end merchant onboarding journey?

PayFacs and ISOs have different merchant onboarding and compliance obligations within the US acquiring ecosystem. But both need to manage merchant information, risk, and compliance across the full merchant journey while meeting the requirements of their acquiring relationships.

An end-to-end merchant onboarding approach connects these responsibilities, so each stage builds on the information and decisions made before it.

For PayFacs and ISOs, this means connecting:

  • Application and data collection: Capture merchant information based on factors such as business type, industry, company size, ownership, locations, products, and the onboarding program.
  • KYB, KYC, and AML screening: Verify businesses and relevant people, with PEP, sanctions, and other screening brought into the same process.
  • Risk and underwriting: Bring merchant data, verification results, and risk signals together to support underwriting and risk-based decisions.
  • Review and approval: Route applications through the right checks and approval paths based on the merchant, program, and level of risk.
  • Ongoing customer due diligence (OCDD): Continue monitoring merchant information and risk after onboarding, rather than treating approval as the end of compliance.

The value comes from connecting these stages. Information collected during the application can support verification, verification results can inform risk and underwriting, and the merchant profile created during onboarding can provide a baseline for ongoing due diligence. This helps build trust throughout the merchant journey, rather than relying on standalone checks.

For PayFacs, ISOs, and partner-led payment programs, this is also where white label onboarding can support growth without weakening control. A branded onboarding journey can be delivered across partners, agents, verticals, or regions, while KYB, AML screening, underwriting, approvals, OCDD, workflows, and reporting remain centrally governed.

OnBoard by MVSI supports this approach for regulated payments, fintech, and financial services by bringing digital onboarding, KYB and KYC, AML screening, underwriting, and ongoing due diligence (OCDD) into one system. Its configurable workflows can support different merchant types, products, markets, partners, and risk requirements, helping US PayFacs and ISOs manage their different responsibilities while operating within the requirements of their acquiring relationships.

For a broader view of how connected onboarding works across US payment providers, PayFacs, ISOs, lenders, banks, and regulated businesses, see Merchant Onboarding in the US.

Conclusion

The PayFac vs ISO difference in the US comes down to more than how merchants access payment processing. Their different roles within the acquiring relationship shape how much responsibility they may have for merchant onboarding, underwriting, risk, and ongoing compliance.

But neither model operates alone. PayFacs and ISOs need to manage merchant risk and payment processing compliance within the requirements and risk appetite of their acquiring relationships. As fraud, financial crime, and regulatory expectations evolve, those requirements can change, making a flexible, risk-based approach to merchant onboarding increasingly important.

For both models, the goal is not just to complete checks. It is to make trusted, auditable decisions across the merchant journey. Connecting merchant data, KYB and KYC, AML screening, underwriting, approval, and ongoing due diligence allows information and risk decisions to carry through from application to ongoing monitoring.

OnBoard by MVSI brings these stages together in one end-to-end merchant onboarding and compliance platform, with configurable workflows that can support the different requirements of US PayFac and ISO programs.

Learn how OnBoard by MVSI helps US PayFacs and ISOs connect merchant onboarding, underwriting, KYB, AML screening, approvals, and ongoing due diligence in one controlled workflow.

Disclaimer: This article is provided for general informational purposes only and does not constitute legal, regulatory, compliance, or financial advice. PayFac and ISO responsibilities can vary based on acquiring relationships, contractual arrangements, card-network rules, applicable requirements, and the functions assigned to each party. Organizations should seek appropriate legal, compliance, or professional advice when determining the requirements that apply to their specific payment program.

Related Merchant Onboarding Resources

Looking to improve merchant onboarding performance across your US payment program? Explore these additional resources:

Merchant Onboarding in the US

Learn how OnBoard helps US payment providers, PayFacs, ISOs, lenders, banks, and regulated businesses manage merchant onboarding, KYB, AML screening, underwriting, and ongoing due diligence in one connected workflow.

Merchant Onboarding in the US: Best Practices for Payment Providers

Explore how US payment providers can reduce onboarding delays, strengthen compliance controls, and build a more scalable end-to-end merchant onboarding process.

Business Lending Onboarding in the US: Managing Compliance, Risk, and Growth

Learn how US business lenders streamline onboarding, strengthen risk-based decision-making, and improve operational efficiency through connected onboarding and compliance workflows.

Frequently Asked Questions

What is the main difference between a PayFac and an ISO?

A PayFac typically onboards businesses as sub-merchants within its program, while an ISO generally helps businesses establish individual merchant accounts with an acquiring bank. This structural difference affects how merchant onboarding, underwriting, risk, and compliance responsibilities are managed.

How does merchant onboarding differ between a PayFac and an ISO?

A PayFac typically has more direct control over onboarding sub-merchants within its approved program. In ISO merchant onboarding, the ISO's role can vary depending on its agreement with the acquirer or processor, including which party handles verification, underwriting, approval, and ongoing merchant management.

How do PayFac and ISO onboarding responsibilities differ?

PayFac and ISO onboarding responsibilities differ based on who controls the merchant relationship, who performs underwriting, who manages risk reviews, and who maintains ongoing monitoring. PayFacs typically have a more direct role for sub-merchants in their program, while ISO responsibilities depend on the acquiring or processor relationship, sponsor bank requirements, card-network rules, and assigned functions.

What are the payment facilitator onboarding requirements?

Payment facilitator onboarding requirements can include collecting a merchant application, verifying the business and relevant individuals, completing applicable screening, assessing merchant risk, underwriting the application, and making an approval or activation decision. The exact checks depend on the PayFac's acquiring relationship, applicable requirements, card-network rules, and risk policies.

What does ISO merchant onboarding involve?

ISO merchant onboarding generally supports a business in establishing its own merchant account. Depending on the acquiring arrangement, an ISO may collect applications and supporting documents, check merchant information, perform an initial risk review, participate in underwriting, support activation, and provide ongoing merchant service.

How do acquiring relationships affect PayFac and ISO compliance obligations?

PayFac and ISO responsibilities operate within the requirements and risk appetite of their acquiring relationships. The exact responsibilities can depend on contractual terms, card-network rules, applicable requirements, internal risk policies, and the functions assigned to each party.

Scroll To Top Arrow