So You Want to Embed Payments Into Your Platform?
Here’s what usually happens. A startup gets traction maybe a marketplace, a gig app or a SaaS tool. Revenue is climbing. Then someone on the team asks: ‘Why are we sending users to Stripe? Why don’t we just become the payment processor ourselves?’ It sounds logical. And honestly, it can be. But the gap between ’embedding payments’ and ‘becoming a PayFac’s wider and legally thornier than most founders expect.
This article breaks down exactly what the PayFac model is, what it demands operationally, where the legal landmines are and whether the economics actually justify the risk. Read it before you sign any acquirer agreement.
The PayFac Model, Explained Without the Jargon
A Payment Facilitator PayFac is a company that aggregates multiple smaller merchants (called sub-merchants) under one master merchant account. Instead of each sub-merchant going through the months-long process of getting their own Merchant ID from an acquiring bank, they onboard through the PayFac. Faster. Simpler. But the PayFac absorbs all the risk.
Think of it like this: the acquiring bank sees only one merchant. That’s the PayFac. Every transaction your sub-merchants run flows through that master account. Which means if a sub-merchant commits fraud, processes a wave of chargebacks or gets caught running illegal transactions the PayFac is on the hook. Not the bank. Not the sub-merchant. You.
The model took off in the late 1990s. Companies like Square, Stripe and PayPal helped define what it looks like at scale fast onboarding, embedded APIs, instant approvals. What you don’t see from the outside is the compliance infrastructure holding all of that together.
The Basic Workflow
When a sub-merchant applies, the PayFac runs due diligence background checks, identity verification, business verification, risk scoring. If approved, that sub-merchant starts processing under the master account. Transactions aggregate, the PayFac deducts fees and funds get disbursed.
| Stage | Who Does It | What Can Go Wrong |
| Application & KYC | PayFac (you) | Incomplete identity checks open fraud exposure |
| Underwriting | PayFac + Acquirer | Approving high-risk MCCs without registration |
| Transaction Processing | Acquirer / Card Network | Velocity spikes going undetected |
| Settlement & Disbursement | PayFac | Commingling funds, timing disputes |
| Dispute / Chargeback Handling | PayFac (primary) | Exceeding Visa VDMP thresholds triggers penalties |
Why Platforms Do This — The Business Case
Revenue is the obvious answer. PayFacs typically mark up interchange rates, charge per-transaction fees or take a percentage spread. Stripe’s PayFac infrastructure reportedly generates 2–5x the revenue compared to traditional referral models. That’s real money.
But it’s not only about fees. Control matters too. When you’re the PayFac, you own the onboarding experience. You decide how fast merchants get approved. You control the checkout flow, the payout timing, the dispute process. For platforms where payments are core to the product, that control compounds into a serious competitive advantage.
| Feature | What It Enables | Business Benefit |
| Aggregated Master MID | Sub-merchants skip individual bank enrollment | Onboarding in days, not months |
| API / SDK Integration | Payments embed directly into platform UI | Seamless user experience, higher retention |
| Custom Fee Structures | Tiered plans, markup on interchange | Multiple revenue streams per transaction |
| Chargeback & Fraud Tools | Real-time monitoring, velocity checks | Lower dispute ratios, fewer network penalties |
| Multi-Currency Support | Cross-border transactions | International market expansion without new entities |
The Liability Picture — This Is Where It Gets Serious
No good PayFac article skips this part and you shouldn’t either. The core issue is simple: as the merchant of record, you assume liability for everything your sub-merchants do. Fraud, chargebacks, regulatory violations all of it flows upward to you.
In 2019, the FTC settled with Allied Wallet for $110 million. The allegation? They processed payments for fraudulent merchants they should have caught during underwriting. That’s not an outlier case. It’s a cautionary benchmark that compliance teams point to constantly.
| ⚖️ Attorney’s Note: Liability doesn’t just mean civil exposure. Depending on jurisdiction and transaction type, PayFac operators can face criminal referrals under the Bank Secrecy Act, AML statutes and state money transmitter laws. Don’t assume your acquirer agreement indemnifies you read it closely. |
The Main Risk Categories
- Financial risk: Chargeback ratios above Visa’s Dispute Monitoring Program (VDMP) threshold trigger fines and potential program termination.
- Fraud liability: Account takeovers, transaction laundering and micro-transaction probing all run through your master MID and you’re responsible.
- Reputational risk: One sub-merchant processing payments for a prohibited MCC (say, unlicensed gambling) can get your entire program flagged.
- Operational risk: Building compliant infrastructure costs $500,000–$1,000,000+ upfront, plus $200,000+/year for PCI audits alone.

The Regulatory Stack — What You’re Actually Signing Up For
Each jurisdiction has different regulations and that difference counts a great deal. US PayFac and an EU PayFac do have significantly different compliance frameworks. Here’s a high-level map.
United States
- Money Transmitter Licenses (MTLs): You need these in most states when you are transferring money. Multi-state compliance is between $150,000/year. Money Services Business (MSB) registration by FinCEN is federal in nature.
- PCI DSS Level 1: QSA audits, penetration testing, network segmentation, the entire program, on an annual basis. Requirements at pcisecuritystandards.org.
- AML/KYC and OFAC Screening: Sub-merchant identities should be checked and scanned with the lists of the sanctions provided by the OFAC. The suspicious activity has to be filed as SARS under the USA PATRIOT Act.
- Card Network Rules: Visa and Mastercard (~$5,000) annual registration. Outlawed categories of MCC are gambling (MCC 7995), adult materials and some types of drugs (MCC 5122). Immediate termination is based on transaction laundering.
- IRS Form 1099-K: This is obligatory to sub-merchants who pay more than 20,000 or make more than 200 payments per year. The lines are moving – refer to IRS.gov to get updated.
European Union
- PSD2 (Payment Services Directive 2): Payers must have a Payment Institution (PI) or E-Money Institution (EMI) license in order to operate as a PayFac. Online transactions are required to be done through Strong Customer Authentication (SCA).
- GDPR: The processing of sub-merchant and cardholder data has to adhere to the EU data protection law. The penalties due to violation culminate to 4% of yearly world turnover.
| ⚖️ Attorney’s Note: Cross-border operations are generally restricted to the acquirer’s licensed jurisdiction. A US acquirer sponsoring a PayFac typically can’t extend that coverage to EU sub-merchants without separate licensing. If your platform operates internationally, this is a foundational conversation to have before you build anything. |
PayFac vs. Other Models — The Quick Comparison
Because the question always comes up: why not just become an ISO? Or use a Merchant of Record provider? Here’s how the models stack up.
| Model | Merchant Aggregation? | Who Holds Liability? | Onboarding Speed | Revenue Potential |
| PayFac | Yes — all under master MID | PayFac bears full risk | Days (after PayFac approval) | High — markup + fees |
| ISO (Independent Sales Org) | No — individual MIDs | Acquirer holds primary risk | Weeks to months | Moderate — referral/residual |
| Payment Processor | No — facilitates only | Processor / Acquirer | Standard bank timeline | Low — infrastructure fees |
| Merchant of Record (MOR) | No — acts as seller | MOR for taxes / compliance | Varies | Variable — depends on model |
If You’re Moving Forward — What Good Compliance Actually Looks Like
Forget the checklist-as-a-formality approach. Real compliance in the PayFac world is an operational discipline, not a paperwork exercise. Here’s what firms that do it well consistently get right.
Underwriting and Onboarding
- Build risk tiers before you onboard anyone. Low-risk merchants (standard e-commerce, SaaS) get streamlined review. High-risk MCCs require enhanced due diligence and sometimes special Visa registrations like the High-Risk Internet PayFac (HRIPF) designation.
- Screen all candidates using VMSS (Visa Merchant Screening Service) and Mastercard MATCH. These databases put a flag on those merchants which were terminated by other acquirers due to fraud or high chargebacks.
- Gather and confirm: legal name of business, tax identification, beneficial ownership (owner of 25% or more), banking information and the description of the business model.
Ongoing Monitoring
- Velocity checks – alert on suspicious spikes in the number of transactions, average ticket price or refunds, in real-time. Never wait until the end of the month.
- Periodic website reviews for sub-merchants that could drift into prohibited content categories.
- AI-assisted anomaly detection is increasingly standard for platforms processing above $50M annually. It’s not optional if you’re trying to stay under Visa’s dispute thresholds.
Chargeback Management
- Dispute ratios above 1% of transactions trigger Visa’s VDMP monitoring program. Above 2% and you’re in the high-risk program, which comes with fines and potential program termination.
- Reject and report the non-compliant sub-merchants to VMSS. Allowing a bad actor to operate in the meantime that you are investigating leaves you to the downstream liability.

How Long Then does it Really Take?
Realistically? Between six to eighteen months in case of a conventional setup. The quickest route is to collaborate with a PayFac-as-a-Service provider (Stripe Connect, Adyen for Platforms, WePay) – the latter can shorten the schedule to weeks, but at the price of sharing revenue and customization. Completely in-house provides as much control as possible and the highest margin, but you need to have the entire compliance stack on the first day.
| Step | Timeline | Key Action |
| 1. Feasibility Assessment | Month 1–2 | Evaluate costs, volumes, build-vs-buy decision |
| 2. Acquirer Sponsorship | Month 2–4 | Apply for sponsor bank, negotiate agreement terms |
| 3. Card Network Registration | Month 3–5 | Visa / Mastercard PayFac program registration |
| 4. PCI DSS Certification | Month 4–8 | Engage QSA, gap analysis, remediation, audit |
| 5. AML/KYC Program Build | Month 4–7 | Policies, procedures, screening tools, SAR infrastructure |
| 6. Infrastructure Build | Month 3–12 | Payment gateway, monitoring tools, onboarding workflows |
| 7. Launch and Monitor | Month 12–18+ | Go live, ongoing risk management, periodic audits |
The Bottom Line
Becoming a PayFac isn’t a decision to make because the economics look attractive on a spreadsheet. It’s a structural commitment to compliance infrastructure, to liability absorption, to the ongoing operational work of monitoring hundreds or thousands of sub-merchants. Platforms that do it well, do it intentionally.
If you’re at the stage where this conversation is live, the first call you make should be to payments counsel. Not a consultant. Not a payments-industry blogger. Actual legal counsel who understands your acquirer agreement, your jurisdiction’s MTL requirements and your card network registration obligations.
The Electronic Transactions Association’s compliance resources (electran.org) are a reasonable starting point for self-education. For US-specific licensing questions, FinCEN’s guidance at fincen.gov lays out the MSB registration framework clearly. But neither replaces jurisdiction-specific legal advice.
Done right, the PayFac model is a genuine competitive advantage. Done carelessly, it’s an FTC investigation waiting to happen.
Disclaimer: This article is for informational purposes only and does not constitute legal advice. PayFac regulation is jurisdiction-specific and changes frequently. Contact qualified legal counsel before making structural decisions about payment facilitation.