.png)
On 7 May 2026 the FCA's supplementary safeguarding regime came into force, and whichever firm holds your merchants' money now has to reconcile it every business day and pass an annual audit. If you are a vertical SaaS platform weighing up PayFac as a Service, that matters more than any API comparison because it determines who takes responsibility for that operational and regulatory burden.
PayFac-as-a-Service is the model where you offer payments inside your own product, under your own brand, at your own prices, while a licensed provider holds the permission and carries the liability for your sub-merchants.
Most writing on the topic stops there. This is about what you are actually signing up for.
PayFac-as-a-Service, or PFaaS, is a managed arrangement in which a licensed payment facilitator lets your platform onboard and serve sub-merchants under its permission and its master merchant account, while the payment experience carries your name.
Your users apply for payments inside your product. KYB and KYC checks run in the background against the provider's risk policy. Card and open banking payments settle to the provider, which pays your merchants and pays you your share. Reporting, reconciliation and the disputes queue all sit in your interface.
What you are getting goes well beyond regulatory permission. It includes acquiring relationships, underwriting policy, operational infrastructure, and the people who step in when a merchant's payout is late. The API is only one part of the service.
Registering as a payment facilitator yourself is perfectly achievable, and for some platforms it can be the right route. It takes a card network registration, an acquiring sponsor, a risk function and a compliance team, before you write a line of product code.
This is what separates real PayFac-as-a-Service from a reseller arrangement, and it is worth pressing on with any provider.
The licence sits with your provider. In the UK that means authorisation from the Financial Conduct Authority, usually as an Authorised Payment Institution. Look the firm reference number up on the FCA register before the second sales call. Unipaas Financial Services Limited is an Authorised Payment Institution, number 929994, and PCI DSS Level 1 certified.
That regulated layer sits underneath, out of sight. What your merchants actually touch is yours: the onboarding form, the checkout, the payment dashboard, all pre-built Unipaas components you drop in and style to your own brand. Card data does not touch your servers, which is what keeps most platforms inside SAQ A rather than a full PCI assessment.
So does the money. Your merchants' funds are safeguarded by the licensed firm until payout rather than passing through your account, which keeps your platform out of the client money regime entirely.
The losses are the clause to read twice. Chargebacks and merchant defaults land on the provider first, under its sponsorship. Where they land after that depends on your contract. Some providers pass chargeback exposure back to the platform once a merchant's dispute ratio crosses a threshold, and a platform that has never seen its own dispute data cannot tell whether that threshold is generous or punitive. Ask for the number, and what happens the first time a merchant breaches it.
And then there is the support queue, which is easy to underestimate. When a nursery cannot see yesterday's takings, they call you. Whether your provider staffs that queue or hands you a ticketing portal can decide whether payments become a revenue line or another operational burden.
Four models get sold to platforms, and only two of them let you set your own pricing.
Gateway integration. The merchant holds their own permission and applies directly, the provider owns the brand, and chargebacks are the merchant's problem. You earn a referral fee or nothing, in days.
ISO or referral. The acquirer holds the permission and underwrites every merchant individually. Their brand, their liability, their support queue, your commission, in weeks.
PayFac-as-a-Service. Your provider holds the permission and carries chargeback and fraud liability, subject to contract. Onboarding runs inside your own UI, the brand is yours, your merchants call you, and you set the margin on volume. Live in 3 to 6 weeks.
Registered PayFac. You hold the permission, you underwrite, you carry the losses, and you keep the full spread minus costs. Network registration comes first, then the build.
Referral deals can be a reasonable answer at low volume. The economics only turn once enough of your customers process enough volume that a margin beats a flat commission.

The rules in PS25/12 came into force on 7 May 2026 as a new CASS 15 chapter, and they apply to whichever firm is safeguarding the funds. If that is your provider, the obligations are theirs. If you ever become a PayFac yourself, they are yours.
What the regime requires:
None of that is optional, and none of it is simple to run. It is a standing operational function with daily deadlines, and it is one of the areas platforms can underestimate when they compare an in-house build with a managed partner.
So a question that used to sound technical is now one of the most important to put to a provider: show me your safeguarding arrangement and your latest audit position.
That last one often gets skipped, but it can be the most expensive. Portability is a real switching cost in embedded payments: re-onboarding thousands of merchants becomes a re-acquisition exercise.
Unipaas provides AI-native embedded payments for vertical SaaS platforms in education and childcare, fitness and clubs, field service, accounting, transport, salons, health practice and property. Platforms launch a white-label payments offering under their own brand, typically in three to six weeks, while Unipaas runs onboarding, KYB and KYC, risk, payouts, reconciliation and disputes behind it.
The vertical detail is where a managed model earns its value. Tax-Free Childcare handling for nurseries. Terminals and QR codes for field teams collecting on site. Since January 2026, Unipaas MCP has exposed payment links, transaction search and payout management to AI agents over Model Context Protocol, which matters as more merchant admin gets done by an assistant.
ClubRight, a membership management platform, publishes its numbers: ARPU up 5x, and up to 10x from active users, with payout times down from up to 14 days to just under three business days.
Whether the same maths works for you depends on your merchant base.
PayFac-as-a-Service is a model where a licensed payment facilitator lets a software platform onboard sub-merchants and offer branded payments under the provider's regulatory permission. The platform owns the pricing and the merchant relationship. The provider owns the licence, the safeguarding obligation, the underwriting policy and the losses.
A registered PayFac holds its own card network registration and acquiring sponsorship, and it carries the losses. PFaaS gives you the branded merchant experience and the revenue share without any of that. The trade-off is margin. A full PayFac running its own book keeps more per transaction.
Three to six weeks is realistic with a managed provider, against six to twelve months to build the equivalent in-house. Registering as a PayFac yourself takes longer again, because network registration and an acquiring sponsor come first. Most of those weeks go on your onboarding journey and your reporting screens, not the payment rails.
No. Your provider holds the FCA permission and safeguards the funds, which is the main reason platforms choose the model. You will still carry contractual obligations around how you present the service and what you escalate.
You take a margin on the payment volume your merchants process, and you set the structure: flat transaction fees, tiered rates, segment pricing, or payments bundled into a higher subscription tier. Unlike a referral commission, it grows with your customers' businesses.
That depends entirely on your contract, which is why it belongs in the first conversation rather than at renewal. Ask whether sub-merchant records and KYB evidence are portable, or whether every merchant is re-onboarded from scratch.

.png)
.png)
.png)
.png)
.png)
.png)