What Is an ISO in Banking and How Do They Work?

In banking, an ISO (Independent Sales Organization) is a third-party company that connects businesses to the infrastructure needed to accept credit and debit card payments. An ISO sits between the merchant and the acquiring bank that settles the funds, handling sales, equipment, onboarding, and ongoing support. Banks use ISOs because maintaining a large sales force to chase small and mid-sized business accounts is expensive, so they outsource that work to specialists who can sign merchants up quickly and keep them running.

You’ll sometimes see the term Merchant Service Provider (MSP) used for the same thing. Visa uses “ISO” in its classification system; Mastercard uses “MSP.” The terms are interchangeable.

Where an ISO Sits in the Payment Chain

When a customer pays with a card, the transaction moves through several parties before the money reaches the business. The card network (Visa, Mastercard, and others) routes the authorization. The issuing bank, which is the customer’s bank, approves or declines. The acquiring bank, which is the merchant’s bank, settles the funds. The ISO handles everything on the merchant’s side of that chain: finding the business, signing it up, providing the hardware or software to accept payments, and supporting it afterward.

The ISO is who the business actually talks to. The acquiring bank sets the rules and holds the licenses; the ISO operates as its supervised extension in the market.

Why an ISO Needs a Sponsoring Bank

An ISO cannot operate on its own. Every ISO must be sponsored by a registered acquiring bank, sometimes called a member bank. The card networks require this. Without a sponsoring bank, a company cannot offer merchant processing services, because the bank is the entity that holds the license to participate in card network transactions.

The sponsoring bank carries ultimate liability for every merchant account the ISO signs. If a merchant commits fraud, produces excessive chargebacks, or leaks cardholder data, the bank answers to the card networks. That liability is why banks don’t hand out sponsorships casually; they perform ongoing due diligence on the ISO’s finances, compliance procedures, and the quality of merchants being brought in.

Registration with the card networks runs through the sponsoring bank, not the ISO itself. Visa’s Third Party Agent Registration Program explicitly requires that only Visa clients (issuers and acquirers) can register the agents they work with; an ISO cannot register itself. Each sponsoring bank pays Visa a $5,000 fee for initial registration of an ISO and $5,000 annually to renew, and typically passes some or all of that cost to the ISO. That cost is one reason the barrier to entry stays high enough to filter out undercapitalized operators.

What an ISO Does for a Business

The services an ISO provides go beyond signing a contract. At the basic level, an ISO supplies and configures the equipment a business uses to accept cards, whether that’s a countertop terminal, a mobile reader, or a full point-of-sale system. For online businesses, the ISO sets up the payment gateway that connects the shopping cart to the card network so transactions can be authorized in real time.

Ongoing technical support is often the reason merchants pick an ISO over a direct bank relationship. When a terminal stops communicating or a batch fails to settle overnight, the ISO is the first call. That direct access to someone who understands both the hardware and the processing backend matters, especially for small businesses without dedicated IT staff.

ISOs also guide merchants through PCI Data Security Standard compliance. The merchant bears responsibility for protecting cardholder data, but the ISO provides documentation, self-assessment tools, and advice on meeting the standard. Acquirers are required to ensure that their merchants and service providers comply with PCI DSS, so the ISO has a financial incentive to get this right.

One of the most consequential things an ISO does is structure the merchant’s pricing. The three common models are interchange-plus (a fixed markup on top of the actual interchange rate, the most transparent option), flat rate (a single percentage on every transaction, used by companies like Square and Stripe), and tiered pricing (transactions sorted into qualified, mid-qualified, and non-qualified buckets, the least transparent because the ISO controls which bucket each transaction lands in).

How an ISO Makes Money

The core of an ISO’s revenue is residual income: a small share of every transaction a merchant processes, paid monthly for as long as that merchant keeps the account active. The residual comes from the processor markup, which is the difference between what the ISO charges the merchant and what the ISO pays the acquiring bank and card networks. On an interchange-plus deal, this is the “plus” portion.

A merchant’s total processing cost has three layers:

  • Interchange fees, set by the card networks and paid to the bank that issued the customer’s card. They vary by card type, transaction method, and merchant category, and are not negotiable.
  • Assessment fees, charged by the card networks themselves as a percentage of volume. Also set by the networks.
  • Processor markup, which is the ISO’s margin. This is the only negotiable component.

Beyond transaction residuals, ISOs generate revenue from ancillary fees: monthly statement fees, PCI compliance fees, gateway access charges, and hardware sales or leases. Some are legitimate costs passed through from the processor; others are padding. A well-run ISO earns most of its money from residuals tied to merchant volume rather than from incidental fees.

Merchant contracts typically run for a fixed term, and canceling early triggers an early termination fee, which can range from a flat $100 to $500 up to thousands of dollars under a liquidated damages formula. Some contracts also auto-renew if the merchant misses a narrow cancellation window.

Risk Controls That Shape How ISOs Operate

Because the sponsoring bank is liable for its merchants’ behavior, risk management is built into the entire ISO model. It shows up in underwriting, reserves, network monitoring, and the industry blacklist.

Underwriting

Before a merchant account goes live, the acquiring bank (or the ISO on its behalf) underwrites the business. Federal rules require financial institutions to identify and verify the beneficial owners of any legal entity opening an account. The merchant submits business formation documents, identification for its principals, bank statements, and any prior processing history. The underwriter evaluates the business type, chargeback risk, financial stability, and whether the merchant sells products or services with delayed delivery, which creates refund exposure.

Reserve Accounts

For merchants flagged as higher risk, acquirers commonly set up reserve accounts, also called holdback reserves. The bank funds the reserve either by collecting a lump sum upfront or by withholding a percentage of each day’s processing proceeds until a target balance is reached. These reserves protect the bank and ISO from losses if the merchant generates chargebacks or shuts down with unfulfilled orders. OCC guidance notes that bank policy should establish when holdback accounts are appropriate and that contracts with ISOs should require security deposits from the ISO itself if its financial condition is weak or the quality of its merchants is poor.

Network Monitoring

Visa and Mastercard track fraud and dispute ratios at both the acquirer and merchant level. Under Visa’s Acquirer Monitoring Program (VAMP), as of April 2026, a merchant is flagged as “excessive” when its VAMP ratio (reported fraud and disputes divided by total settled transactions) reaches or exceeds 1.5% in the U.S., Canada, Asia-Pacific, and EU regions. Acquirers face a lower threshold: 0.7% is “excessive” and 0.5% is “above standard.”

Merchants enrolled in VAMP are assessed $8 per fraudulent or disputed transaction. First-time violations within a rolling twelve-month period get a three-month grace window before formal enrollment, after which fees and remediation requirements begin. If an acquirer’s portfolio consistently runs hot, Visa can impose fines or restrict the acquirer’s ability to onboard new merchants. That cascading pressure is why ISOs monitor their merchants’ chargeback ratios closely and will often terminate a merchant relationship before it reaches network thresholds.

The MATCH List

When an acquiring bank terminates a merchant for cause, such as excessive chargebacks, fraud, or money laundering, it must report the merchant to Mastercard’s MATCH database (Member Alert to Control High-risk Merchants), formerly called the Terminated Merchant File. Placement on MATCH makes it extremely difficult to open a new merchant account anywhere. Most processors check MATCH during underwriting and decline listed applicants outright. Processors willing to take on high-risk merchants charge significantly higher fees and impose stricter reserves. Merchants stay on the list for five years from their most recent entry.

ISO vs. Payment Facilitator

If you’ve used Stripe, Square, or PayPal, you’ve worked with a payment facilitator (PayFac), not a traditional ISO. The distinction matters. A PayFac operates under a single master merchant account and creates sub-accounts for each business it serves. An ISO sets up individual merchant accounts for each business through its sponsoring bank.

The practical differences:

  • Onboarding speed. A PayFac can have a business accepting payments within hours because the sub-account sits under an existing master account. An ISO’s onboarding takes longer because each merchant goes through individual underwriting.
  • Pricing. PayFacs typically offer flat-rate pricing with no negotiation. ISOs can tailor interchange-plus or other structures to the merchant’s volume and business type.
  • Control. An ISO relationship gives the merchant its own merchant ID and more control over settlement timing, chargeback management, and reporting. A PayFac relationship is simpler but more opaque.

For a freelancer processing a few hundred dollars a month, a PayFac’s simplicity fits. For an established business doing meaningful monthly card volume, the savings from an ISO’s interchange-plus pricing usually outweigh the longer setup.

Signs of a Trustworthy ISO

Not all ISOs operate with the same level of transparency. A few things worth checking before signing:

  • Registered status. Ask which acquiring bank sponsors the ISO and confirm registration with Visa and Mastercard through that bank. Legitimate ISOs will name their sponsoring bank without hesitation.
  • Pricing transparency. An ISO offering interchange-plus pricing and willing to show a sample statement is a better bet than one pushing tiered pricing with vague rate categories.
  • Contract terms. Check the length of the initial term, whether it auto-renews, the cancellation window, and the early termination fee. A flat ETF of a few hundred dollars is reasonable; a liquidated damages clause tied to projected future revenue is not.
  • Equipment. Buy your terminal outright when possible. Some ISOs lease terminals under non-cancellable 36- to 60-month contracts where the total cost runs several times the retail price of the same equipment.
  • Fee schedule. Request the full list of monthly and incidental fees before signing. PCI non-compliance fees, batch fees, and monthly minimums are common. Fees labeled “regulatory” or “network access” with no further explanation are often margin padding.

The best ISOs build long-term residual portfolios by keeping merchants happy, which aligns their incentives with the business’s. An ISO that churns merchants through aggressive contracts and hidden fees is optimizing for short-term revenue at the merchant’s expense, and the difference between the two is usually clear in the first conversation about pricing.