An ISO is the middleman between your business and the bank that processes your card payments

ISO stands for Independent Sales Organization. In payment processing, an ISO is a company that sells payment processing services to merchants—that's you—but does not actually handle the money or own the processing network. Instead, the ISO partners with a bank (called an acquiring bank) and a payment processor to bundle those services together and resell them to small and medium-sized businesses.

When you swipe a card at a register or accept a payment online, the ISO is usually the company that signed you up, set up your equipment or software, trained your staff, and sends you the bill each month. They are not the bank, not the card network (Visa, Mastercard), and not the processor—but they coordinate all three on your behalf.

The reason ISOs exist is practical: a small coffee shop does not want to call Visa directly or negotiate with a bank. The ISO handles that complexity, bundles the services into one contract, and manages the relationship. You deal with one company instead of five.

Key Takeaways

  • An ISO is a sales and service company that connects your business to a bank and payment processor, but does not move the money itself.
  • ISOs set up your equipment or software, handle billing, and provide customer support—they are your main point of contact for payment processing.
  • The ISO makes money by taking a cut of the fees charged to you, so their incentive is to sign you up and keep you, not to negotiate the lowest rates.
  • You can work with an ISO, go directly to a processor, or use a payment platform like Square or Stripe that acts as its own ISO.
  • ISOs must be registered with Visa and Mastercard and follow strict rules about how they handle merchant data and disputes.

How an ISO fits into the payment chain

When a customer pays you by card, the money does not go directly from their bank to yours. It moves through several hands, and the ISO is one of them. The card network (Visa or Mastercard) sets the rules and routes the transaction. The processor—often a company like First Data or Worldpay—handles the technical side: it reads the card data, checks with the customer's bank, and confirms the payment went through. The acquiring bank is the bank that actually deposits the money into your account.

The ISO sits between you and all of those. You sign a contract with the ISO. The ISO has a contract with the processor. The processor has a contract with the acquiring bank. When something goes wrong—a dispute, a chargeback, a technical problem—the ISO is usually the first person you call, and they escalate it to the processor or bank if needed.

This layering adds a step, but it also means the ISO can customize the service. They might bundle in point-of-sale software, a terminal, training, or reporting tools. A large processor might not offer those extras to a single small merchant, but an ISO can assemble them as a package.

What ISOs charge and how they make money

An ISO does not charge you a flat fee for existing. Instead, they take a percentage of the fees that are already being charged by the processor and the acquiring bank. Those fees are called interchange (paid to the customer's bank) and assessment fees (paid to Visa or Mastercard). The ISO's cut comes out of the processing margin—the difference between what the customer pays and what the bank receives.

This structure creates a conflict of interest worth understanding. The ISO makes more money when you process more volume, so they have an incentive to sign you up and keep you. But they also make money by taking a larger cut of the fees, so they have less incentive to negotiate the lowest possible rates on your behalf. You are paying for convenience and service, not for the ISO to fight for your lowest cost.

The fees you see on your statement—typically 2 to 3 percent of each transaction plus a small per-transaction fee—are split among the processor, the acquiring bank, and the ISO. The ISO's portion is usually 0.5 to 1 percent, though it varies by industry and contract.

When you work with an ISO versus other options

You have three main routes to accept card payments. The first is to work with an ISO, which is what most small businesses do. The ISO handles setup, billing, and support. The second is to work directly with a payment processor or acquiring bank, which usually requires more technical knowledge and a larger transaction volume to be worth their time. The third is to use a payment platform like Square, Stripe, or PayPal, which acts as its own ISO and processor combined—you deal with one company, and they handle everything behind the scenes.

Payment platforms are often cheaper and simpler for very small businesses because they have no setup fees and no long-term contract. ISOs are more common when you need a physical terminal, custom reporting, or integration with existing software. Direct processor relationships are rare for businesses under a few million dollars in annual volume.

The choice depends on your size, your technical comfort, and what services you need. A food truck might use Square. A retail store might use an ISO with a terminal and point-of-sale system. A large restaurant might negotiate directly with a processor.

ISO registration and compliance requirements

Not every company can call itself an ISO. To legally operate as an ISO, a company must be registered with Visa and Mastercard through a program called the Visa Merchant Acquisition Program and the Mastercard Merchant Acquisition Program. Registration requires background checks, financial audits, and proof that the company has systems in place to protect merchant data and handle disputes fairly.

ISOs must also comply with PCI DSS (Payment Card Industry Data Security Standard), a set of rules about how card data is stored, transmitted, and protected. They cannot store full card numbers, cannot transmit card data over unencrypted connections, and must audit their systems regularly. If an ISO is breached and merchant or customer data is stolen, they are liable.

This regulation is why working with a registered ISO is safer than working with an unregistered payment company. You can verify an ISO's registration by checking Visa's and Mastercard's official lists of registered ISOs, though those lists are not public. Your bank or processor can confirm whether an ISO is legitimate.

Red flags when choosing an ISO

Because ISOs handle your payment processing and often your customer data, choosing the wrong one can be expensive or risky. Watch for ISOs that lock you into long-term contracts with early termination fees, charge hidden fees that only appear on your statement, or pressure you to sign before you have read the contract. Some ISOs also bundle in services you do not need—like insurance or software—and charge you for them whether you use them or not.

Another common problem is poor customer support. If your payment system goes down, you cannot process sales. An ISO with slow or unavailable support can cost you money. Before signing up, ask for references from other merchants and ask how quickly they respond to technical issues.

Finally, be wary of ISOs that promise unusually low rates. If the rate seems too good to be true, read the fine print. Some ISOs offer a low advertised rate but add per-transaction fees, monthly minimums, or PCI compliance fees that bring the real cost much higher.

How to read an ISO contract and what to negotiate

An ISO contract is a legal document, and you should read it before signing. The key sections to understand are the fee structure (what you pay per transaction and per month), the term length (how long you are locked in), the termination clause (what happens if you want to leave), and the liability section (what the ISO is responsible for if something goes wrong).

Most ISO contracts are not negotiable for small merchants—the ISO has a standard template and will not change it. But you can ask. If you are processing significant volume or have been with the ISO for years, you may be able to negotiate a lower rate or a shorter term. You can also shop around: get quotes from at least two or three ISOs before deciding.

One thing you cannot negotiate away is PCI compliance. Every ISO will require you to be PCI compliant, and they will charge you a fee (usually $10 to $50 per month) to cover their compliance audits. This is not optional and not a sign of a bad ISO—it is a legal requirement.

Frequently Asked Questions

Is an ISO the same as a payment processor?

No. An ISO sells payment processing services and manages the relationship with you, but a processor is the company that actually handles the technical side of the transaction—reading the card, checking with the bank, and confirming the payment. An ISO partners with a processor. You might never talk to the processor directly.

Can I switch ISOs if I am unhappy with mine?

Yes, but check your contract first. Some ISO contracts have early termination fees if you leave before the contract ends. If there is a fee, weigh it against how much you would save with a new ISO. Many merchants find that switching is worth the fee if they are paying significantly more than market rates.

What happens to my money if my ISO goes out of business?

Your money is held by the acquiring bank, not the ISO, so it is safe. The ISO is just the middleman. If an ISO closes, you will need to set up a new payment processing relationship, but your existing transactions and deposits are not at risk. The bank will continue to deposit your payments until you change processors.

Do I need an ISO if I use a payment platform like Square or Stripe?

No. Square and Stripe are their own ISOs—they handle the entire relationship with the bank and processor for you. You sign one contract with them, and they manage everything else. This is why they are simpler for small businesses, though their rates are usually higher than what you would pay through a traditional ISO.

How do I know if an ISO is legitimate?

Legitimate ISOs are registered with Visa and Mastercard. You can ask the ISO for their registration number or ask your bank to confirm. Be suspicious of any ISO that cannot provide proof of registration or that operates without a physical address or phone number you can verify.