How to Start a Merchant Services or ISO Business
Starting an ISO means registering through an acquirer, not Visa, and budgeting real fees, fines, and PCI DSS obligations before your first merchant boards.

- You cannot register directly with Visa. An acquirer registers you as an Independent Sales Organization, and that acquirer is liable for your conduct.
- Registration runs $5,000 for an ISO, plus the acquirer's own due diligence on your finances, background, and PCI DSS status before you ever board a merchant.
- Operating unregistered carries a fine starting at $10,000 per agent, assessed to the acquirer that let you solicit without it.
- Becoming a Payment Facilitator instead of an ISO requires your acquirer to hold elevated capital standing and only work with PFs inside its own licensed jurisdiction, which is why ISO stays the faster path to actually boarding merchants.
Starting a merchant services or ISO business means finding an acquirer willing to register and sponsor you, not applying to a card network directly. Visa’s own rules are explicit on this point: a Third Party Agent, the category that covers an Independent Sales Organization, cannot register itself. The acquirer does it, and the acquirer is the one liable for what you do under that registration.
That single fact reshapes how the first ninety days of building an ISO actually go. The bottleneck is not incorporating a company or building a website. It is convincing an acquirer to sponsor you, then surviving the due diligence review that follows, well before you ever board your first paying merchant.
What registration actually requires
Visa’s Third Party Agent Registration Program FAQ defines an ISO as an entity that solicits merchant or cardholder accounts, discusses pricing or terms, or submits contracts to the acquirer on a client’s behalf. If you plan to do any of that, registration is not optional. The rules name four ISO sub-types: ISO Merchant, ISO Cardholder, ISO ATM, and ISO Prepaid, plus a separate High Risk ISO category for anyone signing brand-risk merchants.
The acquirer, not you, files the registration through Visa Membership Management, and only after enrolling in Visa Online. Before that filing happens, the acquirer is expected to have already finished its own review of your business model, financial condition, background, and PCI DSS compliance status. Most acquirers will not even start the VMM paperwork until their underwriting team has cleared you internally. The real work happens before registration, not during it.
One structural detail catches new agents off guard: a referral partner or sales representative who solicits under your registered ISO name does not need separate registration. The moment they solicit in their own name instead of yours, they need to be registered as an ISO themselves. If your growth plan depends on a network of sub-agents, decide now whether they operate under your brand or their own, because that decision determines who has to register.
What the acquirer’s due diligence review actually checks
Visa’s registration FAQ tells acquirers to review your “basic background, financial and operational” standing before filing, but it does not spell out what that review contains. Visa’s Payment Facilitator and Marketplace Risk Guide does, and while it is written for a stricter category of third party agent, the checklist it describes is the same shape of review most acquirers run on a prospective ISO, just at a lower bar.
The guide requires the acquirer to confirm the prospective agent is financially responsible and follows sound business practices, which in some jurisdictions means holding a money-transmission license before the acquirer will even open the file. It also requires a direct review of your business strategy, your merchant solicitation materials, your marketing collateral, and your online presence. The point is to confirm your sales and marketing practices are sound before you are let anywhere near a merchant. If your pitch deck, website, or sales scripts overstate what you can approve, or promise pricing an acquirer has not authorized, that is exactly what this review is built to catch. It catches it before registration, not after a complaint.
None of this is a one-time gate either. The guide requires the acquirer to monitor and periodically audit the third party agents it sponsors for operational risk exposure, checking ongoing compliance with the Visa Rules and the acquirer’s own Global Acquirer Risk Standards, known as GARS. An ISO that passes its initial review and then gets sloppy with sales materials or onboarding practices should expect that to surface at the next periodic review, not to go unnoticed indefinitely.
Make sure ISO is actually the category you need
Visa’s registration rules define several Third Party Agent categories, and it is worth confirming ISO is really the right one before you build a business plan around it. A Merchant Servicer stores, processes, or transmits Visa account numbers on behalf of a client’s merchant. That contract sits with the merchant, not the acquirer, and covers roles like payment gateways, online shopping carts, and hosting facilities. A Third Party Servicer does similar work, but contracts directly with the acquirer instead, handling back-office functions like authorization messages, chargeback processing, and cardholder accounting. An Encryption Support Organization is narrower still. It manages cryptographic keys for ATM and point-of-sale PIN devices, not merchant relationships at all.
If your actual plan is to build software, a gateway, or a back-office processing platform, rather than to solicit and sign merchants yourself, you may be building toward one of these categories instead of an ISO. Each carries a different registration fee and a different due diligence focus. Getting this classification wrong early costs you a second registration cycle later, once an acquirer’s underwriting team points out that what you are actually doing does not match what you registered as.
The real cost and timeline
Registration itself costs $5,000 for the initial filing and the same amount every year to renew it, assessed to the acquirer and typically passed through to you. That figure sits on top of whatever the acquirer charges for its own underwriting, which is not standardized and varies by acquirer and risk profile.
Visa’s stated processing window for a registration case is five to seven business days once the acquirer submits it. That number describes only the Visa-side processing, not the weeks an acquirer usually spends on due diligence before it ever files. Budget for the underwriting phase to be the longer one.
PCI DSS compliance is a parallel requirement, not a follow-up task. Any agent that stores, processes, or transmits cardholder data needs to validate compliance at registration, or show a Qualified Security Assessor engagement letter with a target completion date. Agents processing more than 300,000 Visa transactions a year need an annual on-site assessment. Below that threshold, a self-assessment questionnaire is enough. Either way, get this in motion before you approach an acquirer, not after.
Choosing where you actually sit in the value chain
Registering as an ISO is one entry point, not the only one. A referral arrangement carries no registration burden because you never solicit, price, or contract directly. A Payment Facilitator model sits at the other end, carrying its own registration category and the ability to settle funds directly with sponsored merchants. Which one fits depends on how much control, margin, and operational load you can actually carry on day one, a decision this site has broken down in more detail.
The gap between the two is not just paperwork. Visa’s rules require the acquirer sponsoring a Payment Facilitator to hold its own elevated Tier 1 capital standing. The exact threshold varies by the PF’s region and expected sales volume, and a separate, higher capital tier applies if that PF intends to solicit high-brand-risk merchants. An acquirer that has not cleared that bar for itself cannot sponsor a PF at all, no matter how ready the applicant is. Acquirers are also restricted to sponsoring PFs and marketplaces located within their own Visa-licensed jurisdiction. That is why a PF conversation with an acquirer outside your home region can stall before it starts. None of that capital or jurisdiction machinery applies to a standard ISO registration, which is a large part of why ISO remains the faster path to actually boarding merchants.
Most people who ask how to start a credit card processing company are really asking how to become an ISO, since that model gets you selling and earning residuals fastest without the capital and compliance headcount a registered Payment Facilitator requires. If ISO registration is the path, the operational setup work, from agreements to residual structures, is exactly what an ISO and agent setup consulting engagement exists to shorten.
The obligations you inherit once you’re registered
Registration is a beginning, not a finish line. The acquirer remains liable for your conduct for as long as you’re registered under them, which means their due diligence does not stop at onboarding. Visa’s rules obligate you to notify your sponsoring acquirer of changes to your legal name, address, ownership, or the services you offer, and PCI DSS compliance has to be revalidated every twelve months. Miss a revalidation and the acquirer’s exposure to fines starts climbing again, and that pressure comes straight back to you.
Even as a plain ISO rather than a Payment Facilitator, the merchant information you collect and hand to your acquirer has to hold up to the same Know Your Customer discipline Visa requires anywhere in the acquiring chain. That means applicable Anti-Money Laundering rules, local privacy law, and the acquirer’s own required data elements from GARS, all satisfied before that file moves forward. A merchant application with gaps in that information does not just slow down boarding. It is the kind of file an acquirer’s periodic audit is specifically designed to flag, and repeated gaps are what get an ISO’s registration reviewed rather than automatically renewed.
The back office work that keeps a registered ISO compliant, tracking residual accuracy, documenting merchant files, and managing the operational side of a growing portfolio, is where a lot of new ISOs underinvest early and pay for it later. That is the specific gap an ISO back office function is built to close once you’re past the registration stage and into running the business day to day.
Frequently Asked Questions
Can I register my company directly with Visa to start an ISO?
No. Only Visa’s acquiring clients can register a Third Party Agent, including an Independent Sales Organization. You apply to an acquirer, and that acquirer submits your registration through Visa Membership Management on your behalf.
How much does it cost to register as an ISO?
Visa assesses the acquirer $5,000 for initial ISO registration and the same amount annually to renew it. The acquirer typically passes this cost to you, on top of its own underwriting and due diligence fees, which vary by acquirer.
What happens if I solicit merchants before I’m registered?
The acquirer that let you solicit without registration is fined starting at $10,000 per agent under the Visa Rules, and that cost lands on you contractually in nearly every sponsorship agreement. Unregistered solicitation also voids any due diligence protection the acquirer would otherwise have.
What does an acquirer’s due diligence review actually check before registering an ISO?
It checks that you are financially responsible and follow sound business practices, reviews your business strategy, merchant solicitation materials, marketing collateral, and online presence for sound sales practices, and confirms any required licensing. It is not a one-time check either: acquirers are required to periodically audit the third party agents they sponsor for ongoing compliance.
Sources: Visa Third Party Agent Registration Program FAQs and the Visa Payment Facilitator and Marketplace Risk Guide.