Payment Facilitator
A payment facilitator (PayFac) is a merchant services business that lets platforms and software providers accept card and other non-cash payments on behalf of the businesses that use them. Instead of each individual business setting up its own merchant account, the PayFac aggregates them as sub-merchants under its own arrangement, simplifying onboarding and payment processing. The PayFac typically handles integration and paying out funds to those sub-merchants.
A Payment Facilitator (PayFac) is a merchant services entity that aggregates payment processing for multiple sub-merchants under its own master merchant relationship with an acquiring bank, rather than each sub-merchant holding a direct merchant account. In this model the PayFac takes on payment integration and acts in a processing capacity on behalf of its onboarded users, and it directly handles disbursement of funds to sub-merchants. Most operational requirements applicable to PayFacs are defined and enforced by the card networks and acquiring banks, and vary by network and region; readers should confirm current obligations against the applicable card brand and acquirer rules. Note that a PayFac's role in aggregating and processing cardholder data may bring it within the scope of applicable PCI DSS obligations, which should be assessed against the current published standard.
Why it matters
The payment facilitator model has reshaped how software platforms and marketplaces bring businesses online, because it removes the need for each individual business to establish its own direct merchant account. By aggregating many sub-merchants under a single master merchant relationship with an acquiring bank, a PayFac can dramatically simplify and speed up onboarding. For security and compliance teams, this consolidation matters because it concentrates responsibility: the PayFac sits in the flow of cardholder data and funds for potentially large numbers of sub-merchants, which shifts where risk, controls, and oversight need to be applied.
Because a PayFac aggregates and processes cardholder data on behalf of its sub-merchants, its role may bring it within the scope of applicable PCI DSS obligations. The nature and extent of those obligations depend on how the PayFac handles, stores, or transmits cardholder data and must be assessed against the current published standard rather than assumed. PCI DSS is distinct from other standards in the PCI portfolio, and the specific validation path for a PayFac should be confirmed with its acquirer and the relevant card networks.
Operationally, most of the requirements that govern PayFacs are defined and enforced by the card networks and acquiring banks, and these rules vary by network and region and change over time. This means a PayFac's obligations around sub-merchant onboarding, monitoring, and fund disbursement are not fixed by a single universal rulebook; teams should confirm current obligations against the applicable card brand and acquirer rules rather than relying on generalized descriptions.
Who it's relevant to
Inside PayFac
Common questions
Answers to the questions practitioners most commonly ask about PayFac.