ISO/MSP in payments: what they are and how the model works

8 min

The compound ‘ISO/MSP’ comes from a disclosure line: registered companies have to name their sponsoring bank on merchant agreements, and the phrase stuck. The two halves of it came from different eras, though. Visa registers these companies as Independent Sales Organizations. Mastercard did too — MSP was its older umbrella term, from the years when it was a membership association and its licensees were called Members.

Knowing which is which matters more than it sounds, because the category you register under decides what you are allowed to touch and what obligations follow. This guide covers that, then the model as it operates: who does what, why nothing moves without a sponsor bank, what registration costs, and what it takes to launch.

What ISO and MSP mean in payments

An Independent Sales Organization (ISO) is a non-bank company that contracts with an acquirer, or with a processor acting for one, to sell and service card acceptance to merchants. It finds merchants, submits their applications, prices them within limits the acquirer sets, and supports them afterward.

Itʼs not a card network member. It doesnʼt hold merchant funds, settle transactions, or issue merchant IDs. Those functions belong to the acquiring bank, and registration does not transfer them.

MSP means Member Service Provider — Mastercard's umbrella term for a registered third party serving a member bank, from the era when Mastercard was a membership association owned by its banks. Mastercard went public in 2006. Its licensees are now Customers rather than Members, and Chapter 7 of the Mastercard Rules is titled Service Providers, with Independent Sales Organization listed as one category among a dozen.

So MSP is not Mastercard's word for an ISO. It’s Mastercard's retired word for the whole category that an ISO belongs to. It survives in US contracts and in the sponsor disclosure line on merchant agreements, which is why the compound ISO/MSP outlived the term inside it.

Which category you register under

Each network runs its own registration framework, and ISO sits inside both as one category among many. Visa's umbrella term is Third Party Agent; Mastercard's is Service Provider. Which category applies to you is decided by what you do and what data you touch.

If you

Visa registers you as

Mastercard registers you as

Sell and service merchants, without touching card data

Independent Sales Organization

Independent Sales Organization

Sell to high-risk merchants

High Risk ISO

ISO, with additional merchant registration

Store, process or transmit cardholder data

Merchant Servicer or Third Party Servicer

Data Storage Entity or Third Party Processor

Sign sub-merchants and disburse their funds

Payment Facilitator

Payment Facilitator

Both networks also register a long tail of specialist categories — terminal servicers, encryption support, token services, currency conversion — that rarely apply to a merchant-facing ISO.

What an ISO/MSP does

The ISO's product is distribution and service. It finds merchants the acquirer would not economically reach on its own, packages acceptance for them, and stays on the phone afterward.

A typical sequence: the ISO sources the merchant, collects the application and supporting documents, prices the account within the cost schedule its processor has set, submits the file for underwriting, coordinates boarding and terminal or gateway setup, and then owns the relationship. Renewals, pricing changes, statement questions, dispute handling, and equipment problems all come back to the ISO first.

Value-added services sit on top: PCI programs, chargeback tools, reporting, loyalty, capital advances, sometimes payroll or booking software in vertical plays. For many ISOs, these carry better margins than the processing itself.

What an ISO doesn’t do

  • Settle funds. The acquirer pays the merchant. An ISO never sits in the money path.
  • Issue merchant IDs. MIDs come from the acquirer.
  • Make the underwriting decision. The acquirer or processor approves the merchant. Mature ISOs sometimes get delegated authority within tight parameters, but the risk decision is not theirs by default.
  • Touch cardholder data. Both networks define the ISO category as services performed without access to it. An entity that stores, processes, or transmits cardholder data registers as something else, with different obligations.

Who does what, from merchant to issuing bank

Most arguments about what an ISO ‘is’ dissolve once the responsibilities are laid out. Here is the same set of functions mapped across the participants a merchant might encounter.

Two rows deserve attention. The first is chargeback loss. Some guides claim that because an ISO never touches funds, it carries no fraud or chargeback liability. That’s not how the contracts work. The acquirer bears liability to the network, and then passes exposure down: registered ISOs typically indemnify their sponsor for merchant losses, and sponsors frequently require reserves, guarantees or personal guarantees from principals. If it were genuinely risk-free, sponsors wouldn’t run financial due diligence on the people signing.

The second is PCI scope, which is conditional rather than automatic, and which is a decision the ISO makes when it chooses its technology.

Why an ISO needs a sponsor bank

Card networks contract with licensed members. Everything downstream of that happens under a member's sponsorship, and the member answers for it. Visa states plainly that its clients are liable for their agents and must perform their own due diligence before registering one.

This is the single fact that reframes the whole business. An ISO does not apply to Visa. It applies to an acquirer, and the acquirer applies to Visa on its behalf.

What the sponsor is responsible for:

  • Registering the agent with each network, in each region where it operates
  • Due diligence covering background, financial condition, operational capability and PCI status, under the Visa Acceptance Risk Standards
  • Ongoing monitoring of the agent's conduct and portfolio
  • Network liability for whatever the agent does

Because the sponsor carries that, its appetite determines what an ISO can sell. A sponsor that will not touch a vertical is a wall, not a negotiation.

The contracts, and why the cost schedule beats the split

A sponsorship arrangement usually involves a sponsorship or ISO agreement, a processing agreement, a cost schedule setting the wholesale rates the ISO buys at, residual or revenue-share terms, brand and disclosure obligations, data security terms, and often reserve or guarantee provisions.

Founders negotiate hardest on the residual split, which is the wrong lever. A generous-sounding percentage applied to a rich cost schedule pays less than a modest percentage on a lean one, because every line item on that schedule comes out before the split. Read the schedule first.

ISO registration with Visa and Mastercard

Visa's own documentation is explicit that only Visa clients, meaning issuers and acquirers, can register agents, and that agents cannot register directly. Mastercard works the same way. Registration is something a sponsor does for you, after it has decided to take you on.

Visa's Third Party Agent Registration Program

Visa registers agents through Visa Membership Management, an online tool its clients access via Visa Online. The framework is current: the Visa Core Rules and Visa Product and Service Rules of 18 April 2026 carry Third Party Agent requirements in sections 1.9.8 and 10.2.2, and Visa has a further update to agent registration taking effect on 24 October 2026, requiring members to supply every numerical identifier associated with each of their agents.

Agent types matter, because the one you register under determines your obligations:

Category

What it covers

Independent Sales Organization

Merchant or cardholder solicitation, sales, service, terminal deployment. No cardholder data

High-Integrity Risk ISO

An ISO contracting with an acquirer to serve high-integrity risk merchants

Merchant Servicer, Third Party Servicer

Entities that store, process or transmit cardholder data. PCI DSS validation required

Payment Facilitator, High-Integrity Risk Payment Facilitator

Entities signing sponsored merchants and receiving settlement on their behalf

Encryption Support Organization

PIN encryption and key management

Fees are a different matter. Visa omits fee schedules from the public edition of its Rules, so the only published figures come from Visa's Third Party Agent Registration Program FAQ: $5000 for ISO registration and $5000 annually to renew, assessed per client, per agent, per region, and $1000 for Encryption Support Organizations and Third Party Servicers. Registration cases are processed within five to seven business days of receipt, and fines for using an unregistered agent start at $10000 per agent, assessed to the acquirer.

Mastercard's Service Provider registration

Mastercard registers ISOs through the same principle: the Customer registers the Service Provider, and a Service Provider may only perform the services it is registered to perform.

The category boundary is sharper than Visa's. Mastercard's ISO category covers merchant and cardholder solicitation, application processing, merchant education, terminal deployment, customer service and statement preparation — all performed without access to cardholder data. Store, process, or transmit that data, and you are a Data Storage Entity or a Third Party Processor instead, with PCI validation and audit obligations attached.

Mastercard doesn’t publish an ISO registration fee schedule the way Visa does. The numbers circulating online cite each other rather than Mastercard, and the fee reaches you through your sponsor anyway, so get the figure from your sponsor agreement before you budget.

The main ISO business models

The networks see one category. The industry uses half a dozen labels for what sit inside it, and they describe commercial arrangements rather than regulatory status.

  • Registered ISO. The baseline. Registered with the networks through a sponsor, owns the merchant relationship, prices within a cost schedule, does not underwrite. Builds a portfolio it can sell.
  • Wholesale ISO. Industry shorthand for an ISO that buys processing at a cost basis and runs the merchant program end to end, including support and often its own technology. Highest margin, highest operational load.
  • Retail ISO. Resells a processor's packaged program under the processor's brand. Faster to start, thinner margin, less control over pricing and product.
  • Sub-ISO. Sells under another ISO's program. Whether it needs its own registration depends on how it markets and what it does, per the test above.
  • Sales agent and referral partner. Individuals or firms selling in the registered ISO's name, or generating leads in their own. No registration, no infrastructure, commission and residual split. The key question is whether the contract grants portfolio ownership, because that determines whether the agent is building an asset or renting one.
  • Software-led ISO. Payments attached to a software product, where the software drives merchant acquisition. Higher acquisition cost, dramatically better retention.
  • Vertical ISO. Specializes in one industry and its risk profile, pricing conventions, and workflow. Specialization commands premium pricing and survives commoditization better than generalist resale.

What technology an ISO needs

An ISO can run on almost nothing or on a full platform, and where it lands on that spectrum determines both its margin and its compliance obligations. It helps to think about the stack in three tiers.

  • What merchants see. The checkout, the payment links, the portal where they watch transactions and reconcile settlements, and the onboarding flow that got them there. This tier is the product as far as the merchant is concerned, and it’s where an ISO either differentiates or gets treated as interchangeable. Almost nobody builds it from scratch anymore; it’s inherited from the processor, which means the processor's brand shows up in front of your merchants, or licensed under your own.
  • What you run the business on. A CRM that handles sales and agent management, a residual engine that calculates splits across agents and sub-ISOs, and reporting that matches authorizations to settlements to fees to payouts. These are unglamorous, and they are where ISOs quietly break. Residual calculation in particular starts as a spreadsheet and stops working somewhere around a hundred merchants, usually at the worst possible moment. Buy this tier.
  • What sits underneath. Connectivity to processors and acquirers, routing and cascading logic if you work with more than one, and risk and fraud tooling. Provider connectivity is the hardest thing on this list to build and the easiest to underestimate: each integration is a certification project, and the second one costs more than the first because now you own the differences between them. Routing only becomes relevant once you have multiple providers, but that is where any ISO of scale eventually arrives, because sponsor concentration is a risk and merchants ask for acquirers you don’t carry.

Build vs buy is a compliance decision

Here is the part that gets missed. An ISO that stays out of the cardholder data environment registers as an ISO and carries no PCI DSS validation obligation. The moment it stores, processes, or transmits cardholder data, it becomes a Merchant Servicer or Third Party Servicer with Visa, or a Data Storage Entity or Third Party Processor with Mastercard.

That is a different registration category, with annual PCI validation, listing requirements, and audit exposure attached. Building your own gateway is not just an engineering budget and a roadmap. It is a decision to change what you are, in the eyes of both networks, and to take on the obligations that come with it.

Which is why most ISOs license rather than build. White-label infrastructure for ISOs gives you a branded merchant portal, provider connectivity, routing, and reporting that you configure rather than code, while your acquiring relationships, MIDs, and commercial terms stay yours entirely. One Corefy client, an FCA-licensed payment provider, went from demo to first live transaction in two weeks with dozens of payment methods and currencies available from day one, and added around 20 custom provider integrations over the following years as merchants asked for them.

How a client built a thriving payment business with Corefy

Learn more

How to start an ISO?

Every step here is well documented, and none of them is individually hard. The difficulty is structural: one step decides everything that follows, and you can't set its timing. Until an acquirer agrees to sponsor you, nothing else you build matters.

Phase 1: decide what you are selling

  • Choose the model first. Agent, sub-ISO, registered ISO, software-led — this determines your capital requirement, your registration obligations, your technology bill, and how long the whole thing takes. An agent selling under someone else's registration can be earning in weeks. A registered ISO with its own sponsor and its own platform is a different order of commitment. Founders often skip this decision by defaulting to "registered ISO" because it sounds like the real version, then discover six months later that an agent arrangement would have tested the same hypothesis for a fraction of the cost.
  • Pick a segment and a vertical, specifically. This is the first question a sponsor asks, and ‘small business’ doesn't survive it. Sponsors underwrite you partly on how well you understand the merchants you claim you can sign — their risk profile, their chargeback patterns, their seasonality, what they currently pay, and why they would switch. A founder who can describe the pricing conventions in restaurant POS or in cross-border e-commerce is a credible applicant. A founder who cannot is a portfolio the sponsor will have to monitor closely.
  • Incorporate and capitalize. Straightforward as paperwork, less so as preparation. Sponsors run financial due diligence on the entity and credit checks on the principals, so the state of your personal finances becomes relevant in a way most founders do not expect. Get financial statements in order before you start conversations, not during them.

Phase 2: find a sponsor

  • Choose processors. Often this comes bundled with the sponsor, which is convenient and also the moment your cost schedule gets set. Even if you start with one, design your operations as though you will eventually have several, because ISOs of any scale end up multi-sponsor and multi-processor.
  • Register with the networks through your sponsor. Once the sponsor has decided, this part is administrative. Visa processes registration cases in five to seven business days. The paperwork was never the bottleneck.

What sponsors want to see is a business plan with realistic volume projections, a defined vertical, financial statements, clean principal backgrounds, marketing materials they can review, and a clear account of who will be selling for you. What kills applications is vagueness about the merchant base, high-risk verticals the sponsor does not serve, thin capitalization, and anything in a principal's history that turns up in a background check. Expect a real sales process: multiple conversations, unexplained rejections, and long silences.

Phase 3: build the operating business

  • Stand up compliance before you need it. KYB procedures, AML support obligations, a prohibited merchant policy, monitoring processes, and a deliberate decision about your PCI posture. Sponsors ask to see these during due diligence, so this work often runs in parallel with phase two rather than after it.
  • Build or license the technology stack. Covered in the previous section, with one thing worth repeating here: this is where you decide whether you enter PCI scope and change your registration category. Make it consciously.
  • Define your risk and pre-screening processes. Even when the acquirer makes the underwriting decision, you are screening merchants the moment you decide which applications to submit. Doing that deliberately protects your relationship with the sponsor. Submitting everything and letting the acquirer sort it out is how ISOs acquire a reputation that follows them to the next sponsor.
  • Build merchant onboarding with actual service levels. Application, document capture, submission, boarding, MID, activation. Attach timelines to each stage and measure them, because onboarding speed is one of the few things an ISO controls that merchants notice immediately.
  • Negotiate pricing properly. The cost schedule, the splits, the termination terms, and — most importantly — portfolio ownership and transferability. That last clause determines whether you are building an asset you can eventually sell or renting merchants from your sponsor. It is worth more than several points of residual split, and it is easier to negotiate before you have signed merchants than after.

Phase 4: sell, launch, and watch the portfolio

  • Build the sales channel. Direct sales, sub-agents, referral partners such as accountants and POS dealers, or software partnerships. Each has a different cost of acquisition and a different retention profile, and most ISOs end up running two or three.
  • Launch. Your first merchants are also your first test of every process above, so keep the cohort small enough that you can fix things by hand.
  • Monitor continuously. Attrition rate, dispute ratios against network thresholds, residual accuracy against what actually lands in your account, and concentration risk — both by merchant and by sponsor.

How long does it take to launch an ISO?

One number here is documented. Visa clears agent registration cases in 5 to 7 business days of receipt. Everything else is a range, and the ranges are wide because they depend on a decision someone else is making about you.

Planning and model selection take 2 to 8 weeks, most of which is spent working out which merchants you can credibly claim to reach. Sponsor search and negotiation runs anywhere from 1 to 6 months and is the phase that sets your launch date. Due diligence adds 4 to 12 weeks once a sponsor is actually engaged, and it often overlaps with negotiation rather than following it. Technical integration takes 4 to 16 weeks depending almost entirely on whether you license a stack or build one. Compliance setup runs in parallel with all of this, typically 4 to 8 weeks of work spread across the process.

Most operators report 3 to 9 months from decision to first live merchant.

How the ISO model is changing

Two shifts are worth knowing about before you commit to this model.

  • Software is now the default channel in the US. McKinsey's merchant acquiring survey of more than 1500 small and medium businesses found that roughly 90% of US merchants use an integrated software vendor for payments or business management, up from 48% in 2022. Payment processing revenue flowing through ISVs in the US has grown 20% a year for five years, reaching a projected $16 billion in 2025 — about 60% of all acquiring revenue available from that segment. The channel is growing three times faster than traditional distribution.
  • Europe is at a different point entirely. The same survey puts average ISV adoption across France, Italy, Spain and the UK at 23%, against 90% in the US. Around 45% of small UK merchants use an ISV, compared with under 15% of larger ones. The ‘software ate merchant acquiring’ narrative is largely a US narrative, and applying it to a European portfolio would be a mistake.

Both shifts push in the same direction. An ISO whose pitch is a lower rate, aimed at merchants who could open a Square account instead, has a harder business every year — in the US already, elsewhere eventually. An ISO that knows one vertical properly, partners with the software its merchants already run, or operates its own branded platform is selling something those merchants cannot get self-serve: underwriting judgment, local acquiring, and a named contact when settlement goes wrong.

The model survives. What narrows is the set of merchants worth an ISO's time, and what grows is how much technology you need to own to serve them.

Key takeaways

  • MSP stands for Member Service Provider, not Merchant Service Provider. It’s Mastercard's retired umbrella term from its days as a membership association — and both networks today register these companies as Independent Sales Organizations.
  • Your registration category is decided by what you touch, not what you call yourself. Sell and service merchants without handling card data, and you are an ISO. Store, process, or transmit that data, and you become a Merchant Servicer or Data Storage Entity, with PCI validation attached.
  • An ISO cannot register itself. Only a sponsoring acquirer can, which makes finding a sponsor the real barrier. Visa clears registration cases in five to seven business days; the sponsor's decision is what takes months.
  • Registered ISOs are not free of chargeback exposure. The acquirer carries liability to the network and passes it down — ISOs typically indemnify their sponsor for merchant losses, and sponsors often require reserves or personal guarantees.
  • Read the cost schedule before the residual split. A generous percentage on a rich schedule pays less than a modest one on a lean schedule, because every line item comes out before the split.
  • Portfolio ownership is the clause that matters most. It decides whether you are building an asset you can sell or renting merchants from your sponsor, and it is far easier to negotiate before you have signed any.
  • Building your own gateway changes what you are. It moves you into a different registration category with annual PCI validation and audit exposure, which is why most ISOs license infrastructure rather than build it.
  • Single-sponsor concentration is the quiet risk. Your merchants are contracted to the acquirer, not to you, so a sponsorship that ends is a negotiated migration, not a right.

Ready to boost your business to the next level?

Our scalable white label solution provides you with all the tools needed to scale your business. Book a demo with us to see it with your very eyes.

Frequently asked questions

We're here to help.

Still have questions? Here are clear, practical answers to some of the most common things people want to know about this topic.

In most cases, no — but the answer depends on funds flow rather than on the ISO label. An ISO that never takes possession of merchant funds generally sits outside US money transmitter licensing, because it is selling and servicing rather than moving money. Change that and the analysis changes: if funds pass through your accounts, licensing questions arrive immediately. In the UK and EU the threshold is the same but the regime is stricter, requiring authorization under PSD2 and the Payment Services Regulations 2017. Card-network registration is not a substitute for any of it.

Cookie Settings