Referral, ISO, or PayFac: the decision most platforms get backwards · Midcore Operations
Midcore Operations
Embedded payments

Referral, ISO, or PayFac: the decision most platforms get backwards

Choosing between referral, ISO, and PayFac models means hundreds of basis points of margin and years of operational commitment, decided without a sales pitch.

Published
14 July 2026
Reading time
9 min read
Author
Payments & Fintech Advisory practice
Topic
Embedded payments
Key takeaways
  • Referral, ISO, PayFac-as-a-Service, and Registered PayFac carry very different liability, control, and margin trade-offs.
  • Visa requires an acquirer sponsoring a payment facilitator to meet minimum Tier 1 capital requirements that scale with the facilitator's region and volume, and a separate, higher Tier 1 standard applies to a high-risk internet payment facilitator soliciting high-brand-risk merchants.
  • An acquirer may only contract with payment facilitators or marketplaces located within its own licensed jurisdiction, which rules out registered-PayFac status with an out-of-region acquirer no matter how ready the applicant is.
  • Most PayFac-as-a-Service programs only become economic above roughly $25M to $50M in annual processing volume.
  • Termination and data portability terms should be read before the revenue share, not after.

Referral, ISO, PayFac-as-a-Service, or a registered PayFac: every software platform with transacting customers eventually has to pick one, and the choice is worth hundreds of basis points of margin. It also commits you to an operating model you will live with for years.

The problem is who usually answers it. Processor sales teams recommend the structure they sell. Peer founders describe what worked at their volume, in their vertical, three years ago. Neither is your answer, and neither substitutes for reading Visa’s own rulebook, which is where the real, non-negotiable constraints on each of these four structures actually live, well before any partner’s sales deck gets involved.

The four structures, honestly described

  • Referral. You simply introduce customers and receive a share. No liability, no operations, and the smallest slice of the economics. Frequently the right answer for platforms below meaningful volume.
  • ISO. You resell under a processor’s registration, set pricing within limits, and take on some servicing. More margin, more work, and agreements with residual terms that deserve real scrutiny.
  • PayFac-as-a-Service. You operate entirely under a partner’s registration and sponsor bank, with your own brand, your onboarding flow, and your pricing. PayFac-style economics without the registration, capital, and compliance headcount.
  • Registered PayFac. You hold the registration. Twelve to eighteen months and a seven-figure budget before the first merchant boards, plus permanent compliance and risk staffing.

What registration actually costs, on Visa’s own fee schedule

The referral and ISO ends of this decision are not equally free. Visa’s Third Party Agent Registration Program assesses a $5,000 registration fee for an ISO or a payment facilitator, charged to the acquirer and renewed annually, against a $1,000 fee for the narrower Encryption Support Organization and Third Party Servicer categories. A referral arrangement carries none of this, since a referral partner never registers as a third party agent at all. That fee difference is small relative to the platform’s overall economics, but it is real, it recurs every year the registration stays active, and it typically gets passed through by the acquirer rather than absorbed.

The capital and jurisdiction bar most platforms never see

Moving up from ISO to PayFac-as-a-Service or a registered PayFac does not just add operational scope. It requires the platform’s sponsoring acquirer to clear a capital bar that has nothing to do with the platform’s own balance sheet. Visa’s Payment Facilitator and Marketplace Risk Guide states plainly that in order to sponsor a payment facilitator or marketplace, an acquirer must meet minimum Tier 1 capital requirements set out in the Visa Rules, and that those requirements vary by the facilitator’s region and sales volume. A separate, higher Tier 1 standard applies specifically to a high-risk internet payment facilitator intending to solicit high-brand-risk merchants. None of this is visible from the platform’s side of the negotiation. An acquirer that has not cleared its own capital bar simply cannot sponsor a PayFac program at all, no matter how well-built the platform’s application is.

Jurisdiction adds a second constraint that catches platforms even later in the process. Visa issues acquirer licenses for a specific jurisdiction or region, and the rules state it directly: an acquirer may only contract with payment facilitators or marketplaces located within its own licensed jurisdiction. For a sponsored merchant under a payment facilitator, the requirement goes further still, requiring the facilitator, its acquirer, and the sponsored merchant to all be located in the same country. A platform that has found a willing acquirer everywhere except its own region will find that willingness does not matter. The conversation stalls not on program quality but on a jurisdiction line neither party can negotiate around.

Volume is the first filter, not the last

Most PayFac-as-a-Service programs become economic somewhere around $25M to $50M in annual processing volume, or with a credible path to it. Below that, the operational overhead usually outweighs the incremental margin, and a better-negotiated referral or ISO agreement produces more money for less work.

This is the part founders resist. Moving up the value chain feels like progress. But a PayFac program you cannot staff, sponsored by an acquirer that has not cleared its own capital and jurisdiction bar, is worse than a referral deal you renegotiate.

If a partner tells you their program fits any volume, they are describing their sales motion, not your economics.

Who actually absorbs a loss

Choosing a structure is not only choosing a revenue share. It determines who underwrites your customers, who carries loss liability, who owns the merchant relationship on paper, how fast onboarding can be, and what happens to your portfolio if you want to leave.

Visa’s own guide is explicit about how that liability cascades once something goes wrong. It states that the acts and omissions caused by a sponsored merchant are treated as those of the payment facilitator, and that the acts and omissions of a payment facilitator or a sponsored merchant are treated as those of the acquirer, which is fully liable for resulting losses to Visa, its clients, or other stakeholders. The guide also walks through the scenario directly: if a sponsored seller takes payment in advance and cannot deliver, or cannot fund a refund because it has run out of money or closed, the payment facilitator is the one obligated to fund the resulting disputes and settlement obligations on the seller’s behalf.

Run that cascade against the four structures. A referral partner sits entirely outside it, since a referral never touches settlement or sponsorship. An ISO sits closer to it than most founders expect, because reselling under a processor’s registration still means the processor absorbed responsibility for boarding your merchants correctly, and a poorly underwritten book reflects on that relationship even without formal PayFac-style liability. Under PayFac-as-a-Service, your platform is the sponsored entity whose conduct becomes your partner’s liability, and under a registered PayFac, your platform is the one left holding a failed seller’s disputes directly. Margin increases as you move down that list. So does the amount of someone else’s bad debt you are contractually first in line to cover, which is precisely the trade a five-year model should price honestly rather than assume away.

What “more servicing work” actually means for an ISO

An ISO agreement is often described to founders as a small step up from a referral, and the fee schedule reinforces that impression: five thousand dollars a year against zero is not a large gap. The operational gap is much larger than the fee gap. Reselling under a processor’s registration means setting pricing within limits the processor allows, taking first-line responsibility for merchant questions the processor would otherwise field directly, and owning enough of the underwriting conversation that a badly boarded merchant reflects on your judgment, not just the processor’s.

Residual agreements are where this operational gap shows up most concretely, month after month. An ISO’s income is a spread between what the processor charges and what the merchant pays, tracked account by account, and that spread is only real if the residual statement calculating it is accurate. An ISO that treats the agreement’s servicing obligations as paperwork, rather than as the actual job, tends to discover the gap the same way most residual disputes start: months later, in a statement that quietly does not match what the underlying agreement says it should.

Data and termination terms, negotiated once

Data ownership and portability terms are negotiated once, at the beginning, when nobody is thinking about the end. The same is true of the capital and jurisdiction constraints above: they are far cheaper to check before a term sheet is signed than to discover mid-negotiation, which is exactly the kind of structural review an embedded payments strategy engagement is built to run before a platform commits.

How to run the decision

  • Model all four paths over five years using your own volume and merchant mix, not a vendor’s illustration.
  • Cost the operational requirements honestly: underwriting, disputes, support, and reconciliation are headcount, not line items.
  • Confirm your prospective acquirer’s own capital standing and licensed jurisdiction before assuming a PayFac program is available to you at all.
  • Read the termination and portability terms before the revenue share.
  • Decide what you want to control. If onboarding speed is your product differentiator, that narrows the field immediately.

The recommendation should follow the numbers. For many platforms, the right answer is a better referral or ISO agreement, arrived at through PayFac-as-a-Service consulting or a straight ISO and agent setup engagement rather than a registered-PayFac build that the numbers, the capital bar, or the jurisdiction rule was always going to rule out. That is a perfectly good outcome, arrived at deliberately rather than by default.

The founders who get this decision wrong almost never get it wrong on the economics. They get it wrong by skipping the capital and jurisdiction check entirely, spending months building a PayFac program around a partner who was never eligible to sponsor it, and only discovering the mismatch once the term sheet is on the table. Running that check first costs an afternoon. Skipping it costs the better part of a year.

Frequently Asked Questions

What’s the difference between a referral deal and becoming an ISO?

A referral pays a share for introducing customers with no liability or operations. An ISO resells under a processor’s registration, sets pricing within limits, and takes on real servicing work in exchange for more margin, and Visa assesses a $5,000 registration fee for the ISO itself, renewed annually.

How much processing volume do I need before PayFac-as-a-Service makes sense?

Most PayFac-as-a-Service programs become economic somewhere around $25M to $50M in annual processing volume, or with a credible path to it. Below that, a better-negotiated referral or ISO deal usually produces more money for less work.

What’s the real difference between PayFac-as-a-Service and becoming a registered PayFac?

PayFac-as-a-Service runs under a partner’s registration and sponsor bank with your brand and onboarding flow. A registered PayFac holds the registration itself, which requires its acquirer to meet minimum Tier 1 capital standards and takes twelve to eighteen months, a seven-figure budget, and permanent compliance and risk staffing.

Can any acquirer sponsor a registered PayFac in any country?

No. Visa licenses acquirers for a specific jurisdiction or region, and an acquirer may only contract with payment facilitators or marketplaces located within its own licensed jurisdiction. A platform seeking registered-PayFac status with an acquirer outside its home region will not clear that bar regardless of how strong its program is.

Sources: Visa Payment Facilitator and Marketplace Risk Guide and Visa Third Party Agent Registration Program FAQs.

Payments & Fintech Advisory practiceMidcore Operations · 14 July 2026
All insights
Free consultation

Get your free Assess

Tell us what is happening. We reply within one business day with a US-based practice lead, not a salesperson.

  1. 01Within 1 business dayA US-based practice lead replies and books a 30 minute call.
  2. 02On the callWe map the problem, the volume, the partners, and the constraints.
  3. 03After the callYou get a written read of one to three pages, yours to keep.
  • Handled under NDA
  • Written, not a slide deck
  • No obligation to continue

No obligation. We will tell you if you do not need us.

Before you go

Take the written read with you

Every engagement opens with an Assess: a written read of what is happening, what it costs, and what to do about it. It is quoted on its own and you can stop after it.

+1 (786) 619-0152