payfac vs iso

Every software company that decides to earn from payments eventually runs into two acronyms: ISO and PayFac. Both describe a company that sits between a merchant and the acquiring bank. Both can put a payments line on your income statement. Beyond that, they are very different businesses, and picking the wrong one for your stage is one of the more expensive mistakes a platform can make.

The difference comes down to three questions. Who holds the merchant account? Who carries the risk when something goes wrong? And who controls the experience your customers actually see? This post walks through both models, compares them side by side, and closes with a way to decide.

What is an ISO?

An Independent Sales Organization is a registered reseller of an acquiring bank’s merchant accounts. The ISO finds merchants, helps them apply, and supports them once live. The acquirer does the underwriting, opens a dedicated merchant account for each business, settles funds directly to that merchant, and pays the ISO a residual share of the processing revenue.

For a software company, the ISO model looks like a referral or integrated partnership. Your platform sends merchants to the acquirer, the acquirer boards them, and you earn a share for the introduction and any ongoing support you provide. Your liability is limited to sales conduct and disclosure rules. Your control is limited too. You do not decide who gets approved, how long approval takes, what the merchant is charged, or what their statement looks like.

The ISO model suits platforms that want a payments revenue stream without building a payments operation. It fits early-stage companies, smaller merchant bases, and teams whose product roadmap does not depend on owning the checkout or onboarding experience.

What is a payment facilitator?

A payment facilitator, or PayFac, holds a master merchant account with an acquiring bank and boards its own customers as sub-merchants underneath it. Instead of sending each merchant through the acquirer’s application process, the facilitator onboards them directly, often in minutes, using underwriting rules agreed with its sponsor bank.

That structure changes who owns what. The facilitator decides who is approved, sets pricing, receives settlement from the acquirer, and distributes funds to sub-merchants. It also carries the liability. If a sub-merchant generates chargebacks it cannot cover, or turns out to be fraudulent, the loss sits with the facilitator, not the acquirer. Alongside the liability come the obligations: sponsor bank registration, know-your-customer and anti-money-laundering programs, PCI DSS compliance for the whole environment, and capital held in reserve.

The payoff is control. A facilitator owns the merchant relationship end to end, sees every transaction, and can design onboarding, pricing, and reporting as part of the product rather than as a handoff to someone else’s system.

PayFac vs. ISO: the differences that matter

The table below sets the two models side by side across the dimensions software companies usually care about.

 

ISO

Payment facilitator

Merchant account structure

Each merchant holds its own account with the acquiring bank

One master account; merchants board as sub-merchants beneath it

Onboarding speed

Days to weeks; full application and acquirer underwriting per merchant

Minutes to hours; the facilitator approves within sponsor-defined rules

Underwriting and risk ownership

Acquirer underwrites and carries the risk

Facilitator underwrites and carries liability for sub-merchant losses

Funding and settlement

Acquirer settles directly to each merchant

Facilitator receives settlement and distributes to sub-merchants

Merchant relationship

Sits with the acquirer; the ISO introduces and supports

Sits with the facilitator; merchant experience is fully owned

Revenue model

Residual share of processing revenue, set by the acquirer

Facilitator sets pricing and keeps the margin above cost

Compliance burden

Light; registration as an ISO plus sales and referral conduct rules

Heavy; sponsor bank registration, ongoing KYC, AML, PCI, and reserves

 

Where each model breaks down for software companies

The ISO model breaks down on control. Onboarding that takes days or weeks is a real cost when your product’s value depends on a merchant taking payments on day one. Application drop-off between sign-up and first transaction is common and largely invisible to you, because the process lives inside the acquirer’s system. You also lose data. Transaction detail, decline reasons, and settlement timing sit with the acquirer, which limits what you can build on top of payments. Every support question about a payment becomes a referral to someone else.

The PayFac model breaks down on operations. Becoming a registered facilitator means building underwriting, risk monitoring, compliance, and funding operations before the first sub-merchant boards, then staffing and auditing them indefinitely. It means holding reserves and absorbing losses. For most vertical software companies, the volume required to justify that investment is far above where they are today. We covered the numbers behind that decision in The Real Cost of Becoming Your Own Payment Facilitator, and the short version is that the fixed costs are large and mostly unrelated to how many merchants you serve.

So the honest position for many platforms is that the ISO model gives too little control and the full PayFac model demands too much operation. That gap is where a third structure has emerged.

The middle path: PayFac as a Service

PayFac as a Service lets a software company operate on the sub-merchant model without registering as a facilitator itself. The provider holds the master merchant account, the sponsor bank relationship, and the compliance umbrella. The platform gets what it actually wanted from the PayFac structure: fast onboarding inside its own product, ownership of the merchant relationship, visibility into transaction data, and a meaningful share of payments revenue. Registration, underwriting infrastructure, reserves, and PCI scope for the payment environment stay with the provider. Our PCI Scope for Software Platforms post explains how that division of responsibility works in practice.

This is also why the referral, integrated, and embedded models we described in The Three Ways Software Companies Monetize Payments map so neatly onto ISO and PayFac. Referral and integrated partnerships are ISO-shaped. Embedded payments through a PayFac as a Service provider give you the facilitator’s economics and experience without the facilitator’s balance sheet. The PayFac as a Service and ISV Solutions pages describe how each partnership structure is set up.

How to decide

Four questions usually settle it.

  1. How many merchants will you board, and how fast? If onboarding pace is a product requirement, the sub-merchant model wins. If you sign a handful of merchants a quarter, the ISO model’s slower path costs little.
  2. How much of the merchant experience do you want to own? If checkout, onboarding, reporting, and support are part of what you sell, you need the control that comes with the facilitator structure. If payments is a convenience, the ISO model is enough.
  3. What is your appetite for risk and compliance operations? Full PayFac registration means running those functions yourself. PayFac as a Service means someone else runs them. The ISO model means they never touch you.
  4. Is payments a product line or a referral fee? Platforms that treat payments as a product line, with its own roadmap and revenue target, consistently outgrow the ISO model. Platforms that treat it as a referral fee rarely need more.

Most vertical software companies answer these in a way that points to the middle path. They want speed, ownership, and revenue, and they do not want to become a regulated payments operation to get it.

Bringing it together

ISO and PayFac are not better or worse; they are different allocations of control, risk, and economics. The ISO model trades control for simplicity. The PayFac model trades simplicity for control. PayFac as a Service is built for platforms that want the second without paying the full price of the first. Constellation Payments offers it through CSIPay, a PCI DSS Level 1 platform serving 4,000+ merchants across the US and Canada, with partnership structures that scale from referral to full sub-merchant ownership. Our Security and Compliance page covers the certifications behind that.

If you are weighing these models for your own platform, get in touch with the partnerships team or write to [email protected]. We are happy to walk through where your merchant base and roadmap sit on this spectrum.

Share