August 21, 2026
PayFac as a service moved sub-merchant onboarding from weeks to minutes. That single change is why software companies adopted the model so quickly, and why the risk conversation around it has become urgent. Approval got faster by orders of magnitude. The exposure that comes with approving a fraudulent merchant did not move at all.
This guide covers what the model is, what changed in the market, and what it asks of the risk teams carrying merchant liability underneath it.
In June 2026, Robert Kraal joined our board as an independent director. He co-founded Silverflow, was COO at Adyen, and before that worked at Bibit, the early global PSP later acquired by Worldpay. He has built payment infrastructure through three distinct eras of the industry, and he did not join a payments company. He joined a fraud company.
We are not writing about PFaaS from the outside. We provide fraud and AML detection to payment infrastructure providers including Silverflow, Spell and Akurateco, companies building the rails this article describes.
He did not come to this from the outside either. Silverflow integrates Fraudio directly as a core fraud and risk management partner, so Robert had a first-hand view of how the product performs across live processing environments before he joined the board.
His reasoning, as reported at the time, is the argument of this article made by someone who has run the operations side of it. Across a career scaling global payments infrastructure, he has seen traditional, rigid fraud rules struggle against modern distributed networks. He describes turning interconnected data into real-time fraud prevention as "exactly where the industry needs to go."
PayFac as a service is a model in which a registered payment facilitator supplies its payment facilitation capabilities to another company as infrastructure. The software company onboards sub-merchants and processes payments under its own brand, without registering with the card networks directly. The provider carries the acquiring sponsorship, compliance framework, underwriting and settlement.
The alternative is registering as a payment facilitator directly, which means building compliance, underwriting and settlement in-house and answering to the schemes in your own name. That path takes months. PFaaS takes weeks.
That difference in speed is the entire commercial case for the model. It is also where the risk question begins.
Mastercard and Cardstream published a white paper on the rise of PayFac as a Service in February 2025 that remains the clearest read on where this market is going. Their framing is worth taking seriously: PFaaS is not a passing trend but a structural change in how the payments industry works, pushing traditional processors to innovate and turning ISVs into genuine participants in payments.
Three findings from that paper matter most to anyone carrying risk.
Time to market for a new PayFac collapsed from months to weeks. What used to be a long compliance build is now a procurement decision.
Merchant onboarding went from weeks to minutes. This is the headline benefit for software companies. It is also, precisely, the new attack surface.
Formation volume is accelerating. The paper anticipates hundreds of new PayFac formations per quarter, expansion into new verticals, and further innovation in risk assessment and fraud prevention.
That last clause is the one most commentary skips. The same paper that celebrates the speed names risk assessment and fraud prevention as the areas that have to evolve next.
McKinsey's 2025 Global Payments Report frames the same shift from the acquiring side. Merchant payments providers, it argues, have to move from enabling acceptance to offering autonomous payment infrastructure, where smart routing, real-time settlement and automated compliance stop being differentiators and become expectations.
Here is the tension at the heart of the model.
A traditional payment facilitator underwrote merchants slowly because underwriting was manual. Slowness was expensive, but it was also, accidentally, a control. Documents were reviewed. Businesses were verified. A person looked at the application.
PFaaS removes the slowness. It does not remove the exposure. What has changed is that a bad actor can be approved and processing in under an hour, at scale, across a book that may be adding thousands of merchants a month.
In our portfolio data, roughly 3% of newly digitally onboarded SMEs turn out to be fraudulent. At a hundred merchants a month, that is a manageable investigation queue. At ten thousand, it is a structural problem that no rules-based system and no team of analysts can absorb.
Two failure modes account for most of the damage in fast-growing books.
A merchant processes high volumes of legitimate-looking transactions, collects settlement, and disappears before the chargebacks land. By the time the disputes arrive, the funds and the merchant are gone. The liability stays behind.
Nothing in the transaction stream looks wrong while this is happening. The payments are real, the cards are valid, the authorizations succeed. What gives it away is the shape of the merchant's behavior over weeks, not the content of any single payment.
A merchant onboards claiming to sell low-risk goods and then processes payments for something else entirely. This one carries scheme fines on top of the losses, and it is invisible to any control that examines transactions in isolation.
Both of these are entity problems rather than transaction problems. Every individual payment can look clean while the merchant behind them is not. That distinction is the whole game.
It is also what the card schemes now grade you on. Visa VAMP and Mastercard SMMP both tightened in 2026, and both punish the same weakness: not knowing a merchant has gone bad until it is too late to act.
The final row is where books get hurt. Companies frequently assume that because the provider handles compliance onboarding, it also handles ongoing merchant-level fraud monitoring. Those are different capabilities.
Onboarding checks who a merchant claims to be at a single point in time. Merchant monitoring watches what they actually do, continuously, afterwards. A merchant can pass every onboarding check honestly and turn fraudulent in month four.
This is the question most PFaaS marketing answers vaguely, and it deserves a direct answer: it depends on the contract, and you have to read it.
Some providers hold scheme risk as the registered payment facilitator and say so plainly. Others supply infrastructure while the software company retains sub-merchant exposure. Both models exist and both are sold under the same three letters.
What does not vary is this. Whoever is registered with the schemes answers to the schemes. Under Visa's Acquirer Monitoring Program, the portfolio ratio is graded at the registered level, and one concentrated book of risky merchants pulls the whole portfolio across the line. Under Mastercard's Scam Merchant Monitoring Program, the registered acquirer or payment facilitator has 72 hours to investigate a flagged merchant, and answers for the onboarding decision that let them in.
So the question to ask a prospective provider is not whether they handle risk. It is which specific exposures they hold, which they pass through, and what monitoring runs on the book after a merchant is approved.
For anyone running risk on a book growing through PFaaS rails, the requirements are specific.
Monitor entities across time, not only events. A merchant's risk profile is a trajectory. Refund ratios drifting, settlement patterns changing, volumes ramping ahead of peers in the same category. None of that shows up in a single-transaction score.
Compare against peers, not only against thresholds. A fixed threshold either flags every fast-growing legitimate merchant or misses the fraudulent one sitting just underneath it. Peer-group deviation is far harder to game.
Detect before settlement, not after chargebacks. Chargeback data arrives weeks late. Any control depending on it is a post-mortem rather than a defense. Working with Viva Wallet, we surfaced fraud attempts three weeks earlier than their previous setup, which is the difference between withholding settlement and writing off losses.
Deploy in days, not quarters. A book onboarding thousands of merchants a month cannot wait five to fourteen months for a risk system to integrate. Our own integrations run three to fourteen days.
Support multi-tenancy properly. A PFaaS provider is not managing one book. It is managing its customers' books, each needing isolated views, its own configuration and its own rules, without losing the cross-portfolio signal that makes detection work.
None of this is a contrarian position. McKinsey lists moving intelligence to the edge among its six strategies for the next era of payments, arguing that decision-making has to happen at the point of transaction, with fraud detection embedded directly into APIs and workflows rather than centralized in batch systems or led by humans. The same report calls for compliance to become programmable, with modular policy engines replacing manual workflows and hard-coded rule books.
That last point is where a centralized model earns its keep. Because our AI learns across billions of transactions from every connected provider rather than from each customer's isolated history, a fraud pattern appearing in one book sharpens detection for all of them. For a new PFaaS operation with no fraud history of its own, that is the difference between protection from the first transaction and a ramp-up measured in months, which are the same months PFaaS was adopted to avoid.
Three things make Fraudio a different answer to this problem.
Our patented centralized AI learns across billions of transactions from every connected acquirer, PSP and issuer, so a new customer is protected from the first transaction rather than after a training period. Our Merchant Initiated Fraud Detection assesses merchants as entities over time rather than scoring isolated payments, which is what catches bust-out and transaction laundering weeks before the chargebacks arrive. And integration runs three to fourteen days, against the five to fourteen months quoted by enterprise incumbents.
This is built for acquirers, payment facilitators and PSPs managing sub-merchant risk at onboarding velocity, not for companies looking for payment rails.
Fraudio processes 2 billion transactions a year across 188 countries for more than 2 million merchants, and is ISO 27001 certified. Proven at Viva Wallet: 8x ROI, 600% increase in fraud team efficiency, fraud caught three weeks earlier than legacy tools. Pay per use, with no setup, implementation or maintenance fees.
See how Fraudio detects merchant fraud →
PayFac as a service is a model in which a registered payment facilitator supplies its payment facilitation capabilities to another company as infrastructure. The company onboards sub-merchants and processes payments under its own brand, without registering with the card networks directly. The provider handles acquiring sponsorship, compliance onboarding, underwriting and settlement. Launch takes weeks rather than the months a direct registration requires.
The difference between PayFac as a service and a traditional payment facilitator is registration. A traditional payment facilitator registers directly with the card networks and builds its own compliance, underwriting and settlement infrastructure, which takes months. PFaaS supplies that infrastructure as a service, so a company can operate as a payment facilitator without direct registration. Onboarding drops from weeks to minutes and launch from months to weeks.
Whether the PFaaS provider takes on sub-merchant fraud liability depends on the provider and the contract. Some hold scheme risk as the registered payment facilitator. Others supply infrastructure while the software company retains exposure. Both models are sold under the same name, so this is the single most important item to confirm before signing. Whoever is registered with the schemes answers to the schemes.
Merchant fraud monitoring is usually not included in a PFaaS package, though onboarding compliance normally is. They solve different problems: onboarding verifies who a merchant claims to be at one point in time, while monitoring watches what they do continuously afterwards. A merchant can pass every onboarding check honestly and turn fraudulent months later. Confirm which monitoring runs on the book after approval.
PayFac as a service is worth it for SaaS companies that want payment economics and control of the merchant relationship without a months-long compliance build. The model captures revenue that would otherwise go to a third-party processor and removes the need to register with the card networks. The cost is exposure to sub-merchant fraud at onboarding velocity, at a baseline of roughly 3% of digitally onboarded SMEs proving fraudulent.
The benefits of PayFac as a service for SaaS companies are speed, branding and payment economics. Launch drops from months to weeks and sub-merchant onboarding from weeks to minutes, according to Mastercard and Cardstream. Payments run under the company's own brand rather than a third party's. The company captures a share of processing revenue instead of referring it away.
A scaling business should expect roughly 3% of newly digitally onboarded SMEs to prove fraudulent, based on our portfolio data. The absolute number scales with onboarding velocity, which is exactly what PFaaS is designed to increase. At a hundred merchants a month that is a review queue. At ten thousand it is a structural problem that manual review cannot absorb.
Onboarding checks are not enough because they verify identity at a single point in time, while fraud is a behavior that develops afterwards. A bust-out merchant passes onboarding honestly, processes clean-looking volume for weeks, collects settlement and disappears before the chargebacks arrive. Nothing in the individual transactions looks wrong while it happens. Only continuous entity-level monitoring, comparing a merchant against its own history and its peer group, catches the drift in time to withhold settlement.
How about trying our solution and experiencing the next generation for yourself?