Payment Facilitator Compliance Checklist

Reviewed by WeiJun Tang

  • ChatGPT
  • Claude
  • Grok
  • Perplexity
  • Google Gemini

Last updated: August 14th, 2026

Insights

Use this checklist to map the ten compliance areas a registered payment facilitator must own — from card-network registration and PCI DSS Level 1 to KYC/AML, money transmitter licensing, sub-merchant underwriting, reserves, chargebacks, reporting, documentation, and PayFac-as-a-Service alternatives.

Becoming a payment facilitator (PayFac) means taking on the compliance that a traditional merchant account normally pushes onto the bank. You register with the card networks, you validate at the highest PCI level, you underwrite and monitor every sub-merchant, and you report to Visa and Mastercard on an ongoing basis.

This checklist maps the ten areas you need to cover. It's a planning tool, not legal advice — confirm specifics with your sponsor bank, a QSA, and qualified counsel before you launch.

New to the model first? Start with the full guide, then come back here to plan the compliance work.

Before you use this checklist

This applies to companies pursuing the fully registered PayFac model. You may not need most of it if:

  • You use PayFac-as-a-Service / managed PayFac — your provider carries most of the obligations below.
  • You only need to accept payments across multiple countries — that's cross-border local acquiring, not the card-network PayFac model. More on that at the end.

If you are becoming a registered PayFac, here's the map.

Overview graphic showing the ten compliance areas a registered payment facilitator must cover, including card-network registration, PCI DSS Level 1, KYC/AML, licensing, underwriting, reserves, chargebacks, reporting, documentation, and PayFac-as-a-Service.

1. Card-network registration

You cannot operate as a PayFac without a sponsor bank and card-network registration.

  • Secure a sponsor (acquiring) bank willing to register you as a payment facilitator.
  • Register with Mastercard through its registration program and complete the required risk/anti-fraud onboarding. Mastercard runs a Mastercard Registration Program (MRP) and a Business Risk Assessment and Mitigation (BRAM) program covering this.
  • Register with Visa as a payment facilitator / service provider.
  • Renew registrations annually and budget for the per-network fees.

Authoritative rules are linked in the Sources section of the main guide: Payment Facilitator Guide

The Mastercard MATCH list: the 11 reason codes

MATCH (Mastercard Alert To Control High-risk Merchants) is where acquirers record terminated merchants — and where your sub-merchants can end up if underwriting fails. Mastercard's Security Rules and Procedures (chapter 11) defines eleven reason codes (01–14; 02, 07 and 11 are unused); codes 04 and 05 are the only MATCH codes with published numeric thresholds:

Code

Reason

Published standard

01

Account Data Compromise

Unauthorized access to or disclosure of account data, subsequently used fraudulently

03

Transaction Laundering

Submitting transactions that don't arise from the merchant's own acceptance agreement

04

Excessive Chargebacks

Chargebacks over the previous three months exceeded 1.5% of that month's Mastercard sales transactions and totalled USD 5,000 or more

05

Excessive Fraud

Fraud-to-sales dollar volume ratio of 8% or more over the previous three months, and 10 or more fraudulent transactions equal to or greater than USD 5,000 in that period

06

Coercion

Transactions arising from threats or unlawful taking of property

08

Questionable Merchant Audit Program

Determined to be a Questionable Merchant under that program's criteria

09

Liquidation / Insolvency

Unable, or likely to become unable, to discharge its financial obligations

10

Violation of Standards

Breach of Mastercard Standards

12

PCI DSS Noncompliance

Failure to comply with PCI Data Security Standards

13

Illegal Transactions

Transactions that are illegal

14

Identity Theft

The acquirer has reason to believe the identity of the listed merchant or its principal owner(s) was unlawfully assumed

Records stay on the MATCH Pro system for five years, then purge automatically; the acquirer (as a MATCH Pro authorized user) must keep its own records for at least two years after the merchant agreement ends (§11.10).

Scheme monitoring programs at a glance

Scheme

Program

Where it lives

Thresholds

Visa

Visa Acquirer Monitoring Program (VAMP)

Visa Core Rules 10.4.3.1

Not published — defined in the VAMP Guide

Visa

Visa Integrity Risk Program (VIRP)

Referenced throughout Visa Core Rules

Not published — defined in the VIRP Guide

Mastercard

Business Risk Assessment and Mitigation (BRAM)

Security Rules and Procedures §8.8

Not published

Mastercard

Merchant Monitoring Program (MMP)

Security Rules and Procedures §8.9

Not published

Mastercard

Specialty Merchant Registration

Security Rules and Procedures chapter 9

Mastercard

MATCH

Security Rules and Procedures chapter 11

Published — see the table above

Two details worth knowing: Visa can evaluate a PayFac at aggregated-merchant or sponsored-merchant level under VAMP, and a PayFac deemed high-integrity-risk must register as a High-Integrity Risk Payment Facilitator even if already registered.


2. PCI DSS Level 1

Card networks classify PayFacs as service providers, and a PayFac is generally held to PCI DSS Level 1 — the highest validation tier.

  • Complete a Level 1 assessment validated by a Qualified Security Assessor (QSA) through an onsite assessment, not just a self-assessment questionnaire.
  • Be compliant before you process your first transaction — many acquirers won't sign you without proof.
  • Meet the v4.x requirements now in force. The "future-dated" requirements of PCI DSS v4.x became mandatory on March 31, 2025. v4.0.1, published June 2024, was a clarifying revision that did not change that date and added no new requirements. Key items now enforced include:
    • Req. 6.4.3 — all payment-page scripts are authorized, integrity-assured, and inventoried.
    • Req. 11.6.1 — a change-and-tamper detection mechanism on payment pages, evaluated at least weekly or on a frequency set by a targeted risk analysis.
    • Expanded MFA for all access into the cardholder data environment (CDE).
    • Stronger password standards and formal targeted risk analyses (TRA) for control frequencies.
    • Encryption that renders PAN unreadable at the file/column/field level. Disk-level encryption alone no longer qualifies, except for removable media.
  • Understand PCI does not "pass through." Each sub-merchant is a separate legal entity with its own PCI obligations. Where your solution covers requirements on their behalf, document it in your Report on Compliance and in the sub-merchant's SAQ.

Sub-merchant PCI detail: What Is a Sub-merchant?


3. KYC / AML / sanctions screening

You own the decision to onboard each sub-merchant, so you own the screening.

  • Verify identity (KYC) for each sub-merchant: legal entity, business model, and ultimate beneficial owners (UBO).
  • Screen against sanctions lists such as OFAC before onboarding and on an ongoing basis.
  • Check the MATCH list — Mastercard's Member Alert to Control High-risk Merchants — before approving a sub-merchant.
  • Maintain a BSA/AML program appropriate to your jurisdiction, with suspicious-activity processes.
  • Re-screen periodically, not just at onboarding.

4. Money transmitter licensing (US)

This is the most commonly underestimated cost.

  • Determine whether you "touch" merchant funds. If settlement flows through you before reaching the sub-merchant, money transmitter licensing (MTL) may apply.
  • Map state-by-state requirements via NMLS; obligations and costs vary widely by state.
  • Consider structural alternatives, such as having the bank settle directly to sub-merchants, to reduce MTL exposure.
  • Budget surety bonds and ongoing reporting where licensing applies.

Outside the US, licensing is jurisdiction-specific — confirm local requirements in each market you operate in.


5. Sub-merchant underwriting policy

Underwriting is how you keep risk out before it enters your portfolio.

  • Write a documented underwriting policy: business types accepted, prohibited/high-risk verticals, data collected.
  • Assess each applicant's risk: business model, financials, credit, fraud/chargeback history, billing practices.
  • Apply graduated controls — conservative limits, reserves, or delayed funding for higher-risk merchants; expansion as they prove performance.

6. Funds flow and reserves

  • Define your settlement model and document how funds move from acquirer to your master account to sub-merchants.
  • Establish a reserve policy — rolling or fixed — in writing, including how and when reserves are applied and released.
  • Keep reconciliation accurate and real-time — chargebacks and adjustments are typically debited from settlement flows.
  • Disclose reserve and funding-hold terms clearly in the sub-merchant agreement to avoid disputes.

7. Chargeback and dispute management

  • Build dispute workflows aligned to card-network timelines.
  • Monitor chargeback ratios against network thresholds; exceeding them can put you into network monitoring programs.
  • Define who covers what — remember the PayFac bears the ultimate loss if a sub-merchant can't fund a chargeback.

8. Ongoing reporting and monitoring

Compliance is continuous, not a one-time gate.

  • File required reports to Visa and Mastercard on the cadence they specify.
  • Re-validate PCI annually with a QSA onsite assessment for Level 1.
  • Monitor sub-merchant activity continuously for fraud, volume spikes, and prohibited activity.
  • Run internal audits of your underwriting and risk controls.

9. Documentation you must maintain

  • Underwriting policy, risk policy, reserve policy
  • AML/BSA program and training records
  • Incident response plan
  • PCI Report on Compliance (ROC) and sub-merchant SAQ references
  • Sub-merchant agreements with required disclosures
  • Network registration and renewal records

10. The shortcut: PayFac-as-a-Service / managed PayFac

If sections 1–9 look like a multi-year program — they are. The full registered model is commonly estimated at hundreds of thousands to several million dollars upfront and 12–24 months before onboarding the first sub-merchant, which is why it usually only makes sense at large scale.

  • Evaluate PayFac-as-a-Service / managed PayFac, where a provider already holds the registrations, PCI Level 1 posture, and much of the risk — and you integrate in weeks rather than building for a year-plus.

Who carries the liability: PayFac, sub-merchant, or acquirer?

Both card networks answer this in almost the same words, and the chain ends at the acquirer. Note the rulebooks use the term sponsored merchant for what the industry calls a sub-merchant.

Question

What the rules say

Where it's written

Whose acts are a sub-merchant's?

A sponsored merchant's acts and omissions are treated as those of its payment facilitator

Visa Core Rules 5.3.1.2

Whose acts are a PayFac's?

A payment facilitator's (or sponsored merchant's) acts are treated as those of its acquirer

Visa Core Rules 5.3.1.2

Who is ultimately liable to the network?

The acquirer — for all acts, omissions and adverse conditions of its PayFacs and their sponsored merchants (Visa expressly includes legal costs and settlement obligations)

Visa Core Rules 5.3.1.2; Mastercard Rules 7.6.5

Whose merchant is the sub-merchant?

A sponsored merchant is treated as a merchant of its payment facilitator's acquirer

Visa Core Rules 5.3.1.2

That does not make the PayFac's obligations decorative. The rules assign it specific duties — written into its acquirer and sub-merchant agreements as required terms:Card-network registration

PayFac obligation

Source

Ensure sponsored merchants comply with PCI DSS and the PCI Software Security Framework

Visa Core Rules 5.3.1.1

Not contract with a sponsored merchant whose acceptance was terminated at the direction of Visa or a government agency

Visa Core Rules 5.3.1.1

Provide principals' names and countries of domicile, and transaction reports, to its acquirer and Visa on request

Visa Core Rules 5.3.1.1

Assign a unique ID to each sponsored merchant; authorization messages carry both the PayFac and sponsored-merchant identifiers, clearing records the PayFac identifier

Visa Core Rules 5.3.1.3

Own the card-acceptance policies and procedures of its sponsored merchants

Mastercard Rules 7.8.1.1(3)

Accept that sponsored-merchant agreements terminate automatically if the PayFac is deregistered or its acquirer loses its license

Mastercard Rules 7.8.1.1(4)

One caveat for US readers: Mastercard notes that modifications to rule 7.6.5 appear in its United States Region chapter, so US-specific programs should be checked against that chapter.

Cross-border merchants: you may not need any of this

If your actual goal is getting paid across many countries — Pix in Brazil, GCash and GoPay in Southeast Asia, UPI in India, Mada/STC Pay in the Middle East — the PayFac compliance program above may be solving the wrong problem. What you usually need is cross-border local acquiring: a provider that already has the local payment methods, local clearing, and licensing in each market.

HaiPay is a licensed payment provider — regulated across the Philippines, Indonesia, the US, and Canada — that facilitates cross-border local acquiring with local payment methods and local payout across its supported markets.

See how cross-border local acquiring works: Pay-ins Acquiring


Last updated June 2026. This checklist is for planning only and is not legal or compliance advice. Verify requirements with your sponsor bank, a QSA, and qualified counsel.

Sources

Compliance facts here are based on primary card-network and PCI sources. These are updated periodically — always consult the current version.

FAQ

  • Registered PayFacs are generally validated at Level 1 with a QSA onsite assessment, as card networks treat them as service providers. Confirm exact scope with your acquirer and QSA.

  • Yes — they became mandatory on March 31, 2025. v4.0.1, published June 2024, was a clarifying update and did not move that date.

  • Mastercard's Member Alert to Control High-risk Merchants list, which PayFacs check before onboarding sub-merchants.MATCH has eleven reason codes (01 through 14, with 02, 07 and 11 unused) — not thirteen, as often repeated — and within the MATCH table only the excessive-chargeback and excessive-fraud codes carry published numeric thresholds; see the reason-code table above.

  • It depends on whether you touch merchant funds and on each state's rules. Many PayFacs structure funds flow to limit this; confirm with counsel.

  • HaiPay operates a payment-facilitation model as a licensed payment provider, regulated across the Philippines, Indonesia, the US, and Canada. It facilitates cross-border payments for merchants under its own licenses, rather than by registering with the Visa or Mastercard card networks.

Back to blog